Data Processing Addendum
Effective date: 15 September 2026. Last updated: September 2026.
This Data Processing Addendum (“DPA”) applies whenever ORIETUR CONSULTANCY - FZCO, trading as SetMyClaw (“we”, “us”), processes personal data on behalf of a client (“you”). It forms part of our Terms of Service and of your Engagement Terms.
A signed version of this DPA is available on request. Write to info@setmyclaw.com.
1. Scope and Roles
This DPA applies to personal data that we process for you when we build, host or support a system for you. It applies alongside the UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data and its Executive Regulations, and alongside the EU or UK GDPR where those apply to the processing.
- You are the controller. You decide why and how the personal data in your system is processed.
- We are the processor. We process that data only on your documented instructions.
- You are responsible for having a lawful basis for the data you put into the system, for giving the required privacy notices to your own data subjects, and for obtaining any consent that is needed.
- You are responsible for the accuracy of the data you give us and for making sure you have the right to share it.
- We do not use your data for our own purposes or for other clients, and we do not sell it. Any model training or tuning for your own system is done only on your instructions.
Personal data that we handle as a controller in our own right, such as your staff contact details and billing records, is covered by our Privacy Policy instead.
2. Processing Details
- Subject matter: the provision of the AI systems, hosting, configuration and support described in the Engagement Terms.
- Duration: the term of the engagement, plus the deletion or return period in section 3.
- Nature and purpose: collecting, storing, organising, retrieving, analysing and generating content from your business data so the system can perform the functions you asked for. Depending on the engagement this may include reading and drafting email, handling chat or voice conversations, extracting information from documents, building knowledge bases and search indexes, producing briefings and reports, and sending messages you have authorised.
- Types of personal data: as specified in the Engagement Terms. Typically contact details, message and email content, call audio and transcripts, document content, calendar entries, account identifiers and usage logs.
- Categories of data subjects: as specified in the Engagement Terms. Typically your staff, your customers and prospects, your suppliers, and anyone who contacts you or whose details appear in the data you supply.
- Special category data: not expected. If your engagement involves it, it must be named in the Engagement Terms so that the right controls can be agreed.
3. Our Obligations as Processor
- Instructions. We process personal data only on your documented instructions, including the instructions contained in the Engagement Terms and in the configuration of your system, unless the law requires otherwise. If we think an instruction breaks data protection law, we will tell you.
- Confidentiality. Everyone we allow to access your data is bound by confidentiality duties and is trained on how to handle it.
- Security. We apply appropriate technical and organisational measures, described in section 6.
- Data subject requests. If a data subject contacts us directly about data we process for you, we will forward the request to you and will not respond except to confirm we passed it on. We will give you reasonable help to answer requests, taking the nature of the processing into account.
- Assessments. We will give you reasonable help with data protection impact assessments and with any prior consultation with a regulator, so far as the information relates to our processing.
- Personal data breach. If we become aware of a personal data breach affecting your data, we will tell you without undue delay and in any case within 72 hours. We will describe what happened, what data is involved so far as we know, the likely consequences and the steps we are taking. You remain responsible for any notification you owe to a regulator or to data subjects.
- Deletion or return. Within 30 days after the engagement ends, we delete your personal data or return it to you, at your choice, and delete existing copies. We may keep data where the law requires it, and it stays protected by this DPA for as long as we hold it.
- Information and audit. On reasonable notice, and no more than once a year unless a regulator or a breach makes another check necessary, we will give you the information you need to show that we meet this DPA, and will allow an audit or inspection by you or an auditor you appoint. Audits happen during business hours, must not disrupt our operations or the confidentiality of other clients, and are at your cost. We may satisfy an audit by providing our own documentation and our providers' reports where these answer your questions.
4. Subprocessors and Your Own Providers
Two kinds of third party can touch your data, and they are treated differently.
- Providers you choose or hold in your own name. Your own AI subscription or API keys, your own Microsoft or Google tenant, your own cloud server or storage account. These are your providers, not our subprocessors. Your agreement with each of them governs what they do with your data, and we are not responsible for them. Where you ask us to run a system on your own AI subscription rather than on a business API, that choice and its terms are yours.
- Subprocessors we engage for a system we host. Providers we select and pay for to run a hosted system for you. You give us general authorisation to use them. We put data protection terms in place with each of them as the law requires. We tell you about material changes to the providers used for your system and give you 14 days to object on reasonable data protection grounds; if we cannot offer a workable alternative, either of us may end the affected part of the engagement, with no penalty for work not yet delivered.
The categories of provider we work with are below. The list is not exhaustive and changes as our services change. The providers that apply to your system, and which of them are yours and which are ours, are named in your Engagement Terms.
| Category | Examples | Location |
|---|---|---|
| AI models | Anthropic, and others where an engagement specifies them | USA and other regions |
| Speech and real-time audio | Deepgram, LiveKit, Groq | USA, EU |
| Servers and hosting | Hetzner, Cloudflare, Vercel | EU, USA, global |
| Databases and storage | Supabase, Cloudflare R2 | Region per engagement |
| Messaging platforms | Meta (WhatsApp), Telegram | Global |
| Mailbox and workspace access | Microsoft Graph, Google Workspace APIs | Per client tenant |
| Payments and business tools | Stripe, Google Workspace | USA, EU, global |
Last updated: September 2026.
5. International Transfers
Our providers operate in several countries, including the United States and the European Union. Personal data we process for you may be processed outside the United Arab Emirates and outside your own country.
Where that happens we rely on contractual safeguards. We sign the data processing agreements our providers offer and we select providers that maintain appropriate security. Where the EU or UK GDPR applies to a transfer, the EU Standard Contractual Clauses are incorporated into this DPA, with you as data exporter and us as data importer, module three applying to onward transfers to our subprocessors, and the UK Addendum applying to UK transfers. Where the PDPL applies, we transfer only on a basis the PDPL and its Executive Regulations allow.
The locations in section 4 are indicative of where these categories of provider process data. You can ask us which locations apply to your engagement.
6. Security Measures
We apply technical and organisational measures appropriate to the system, the data and the risk. The measures that apply to your system are set out in the Engagement Terms. Depending on the engagement, they typically include:
- Encryption of data in transit using current TLS. Encryption at rest on managed databases and storage, and on servers where the platform supports it.
- Access limited to staff who need it, on a least privilege basis, reviewed and removed when no longer needed.
- Multi-factor authentication on accounts that support it, and strong unique credentials.
- Key-based access to servers we manage, with password login disabled where the setup allows it.
- Secrets and API keys kept out of source code, in environment configuration with restricted access, and never shared in plain text.
- Separation of client environments and of client data within shared systems.
- Official sign-in flows with the narrowest access that does the job wherever a service offers them. Where credentials are shared with us, they are received through an encrypted vault, stored with restricted access, and changed or removed on request.
- Access and system logging, retained for investigation, with review after any suspected incident.
- Prompt application of security updates to the systems we run, and removal of unused services and access.
- Backups where the Engagement Terms provide for them, held with the same protections as live data.
- An internal process for spotting, escalating and recording security incidents.
- Provider accounts and settings for your system chosen and documented in the Engagement Terms, including what each provider may do with content.
These are examples, not a fixed list. We may change the measures as technology and the system evolve, provided the overall level of protection does not fall.
7. Liability
Each party's liability under this DPA is subject to the limitations and exclusions in our Terms of Service, including the cap on total liability at the fees paid in the 12 months before the claim. Nothing here excludes liability that cannot be excluded by law, and nothing limits a data subject's rights under data protection law.
8. Term and Precedence
This DPA starts when we first process personal data for you and continues until we have deleted or returned that data under section 3.
On data protection matters, this DPA prevails over our Terms of Service and over the Engagement Terms if they conflict, unless the Engagement Terms expressly amend this DPA for that engagement. On all other matters the order in our Terms of Service applies. Where a separately signed data processing agreement is in place between us, that signed agreement prevails.
If a court finds part of this DPA invalid, the rest continues to apply. We may update this DPA to reflect changes in the law or in our services, and we will tell clients about material changes.
9. Contact
ORIETUR CONSULTANCY - FZCO, IFZA Properties, DSO-IFZA, Dubai Silicon Oasis, Dubai, United Arab Emirates.
For data protection questions, subprocessor notices, audit requests or a signed copy of this DPA, write to info@setmyclaw.com.
See also our Terms of Service and our Privacy Policy.