This version supersedes the previous Privacy Policy dated December 24, 2025. The Data Processing Agreement in Part B forms an integral part of this document.
Dalil AI Ltd ("Dalil AI", "we", "us", or "our") is a company registered in the Dubai International Financial Centre (DIFC), Dubai, UAE, under License No. CL8158. We provide the Dalil AI Sales OS platform (the "Services"). This Privacy Policy explains what personal data we collect, why we collect it, on what legal basis, who receives it, where it goes, how long we keep it, and what rights you have.
We comply with the EU General Data Protection Regulation ("GDPR"), the UK GDPR and Data Protection Act 2018, the DIFC Data Protection Law No. 5 of 2020, the UAE Federal Personal Data Protection Law No. 45 of 2021, and other applicable data protection laws, including US state privacy laws such as the CCPA/CPRA.
Part A: Privacy Policy
1. Our Two Roles
Dalil AI as controller. When you visit our website, create an account, subscribe, contact us, or receive our communications, Dalil AI decides how and why your data is processed. This Privacy Policy (Part A) describes that processing.
Dalil AI as processor. When our customers upload, connect or sync data about their own contacts, leads and conversations into the platform, the customer is the data controller and Dalil AI acts as processor on their instructions. That processing is governed by our Data Processing Agreement (Part B below).
If your data appears in a customer's workspace (for example, you received an email or LinkedIn message from a company that uses Dalil AI), please direct any request to that company. We will assist them in responding as required by law. You can also write to privacy@usedalil.ai and we will forward your request to the relevant customer.
2. Data We Collect as Controller
Website visitors. Usage data (pages visited, referrer, approximate location derived from IP, device and browser information) and cookie data as described in Section 11.
Account holders and users. Name, business email, phone number, job title, company, password (hashed), workspace settings, billing details (processed by Stripe; we do not store full card numbers), support conversations, and product usage data (features used, logins, activity logs).
Prospects and marketing contacts. Business contact details you provide (for example when booking a demo) or that we obtain from publicly available professional sources for business-to-business outreach.
We do not knowingly collect data from individuals under 18, and our Services are not directed at them. We do not intentionally collect special categories of personal data.
3. Why We Process It and on What Legal Basis
| Purpose | Legal basis |
|---|---|
| Providing the Services, account management, support | Performance of a contract |
| Billing, invoicing, tax compliance | Performance of a contract; legal obligation |
| Securing the platform, preventing fraud and abuse | Legitimate interests |
| Product analytics and improvement (aggregated where possible) | Legitimate interests |
| Marketing communications to business contacts | Legitimate interests or consent, depending on your jurisdiction; you can opt out at any time |
| Legal claims and regulatory compliance | Legal obligation; legitimate interests |
We do not use your personal data for automated decision-making that produces legal or similarly significant effects concerning you.
4. AI Features
The platform includes AI features that analyse the content of records and communications our customers connect (such as emails, LinkedIn and WhatsApp messages) to generate drafts, replies, summaries, scores and recommendations ("AI Output").
- AI features are powered exclusively by frontier, industry-recognized large language models from OpenAI, Anthropic and Google (Gemini models accessed through Google Cloud Vertex AI under enterprise terms), listed in the sub-processor list in Part B, Annex 3, under contracts that prohibit them from retaining the data or using it to train or improve their models
- AI features are designed in accordance with the principle of data minimization: we transmit to AI providers only the data reasonably necessary to generate the output requested by the user, and we do not intentionally give AI features access to personal or sensitive information beyond what the requested output reasonably requires
- We do not use customer data to train AI models
- AI Output consists of suggestions that require human review; the Services do not make automated decisions with legal or similarly significant effects
- AI-generated outputs are deleted together with the underlying account data upon deletion
5. Data Enrichment
Customers can enrich contact records using our enrichment provider (Airscale), which aggregates professional data (name, role, employer, business contact details) from publicly available or licensed business sources. If your professional data appears in a customer's workspace through enrichment, it was obtained from such sources, and you can contact us or the relevant customer to access, correct or delete it.
6. Who Receives Your Data
We share personal data only with:
- Sub-processors that help us deliver the Services, listed with purposes, locations and safeguards in Part B, Annex 3 (Google Cloud, OpenAI, Anthropic, Twilio, Unipile, Airscale)
- Stripe, our payment processor, for billing
- Professional advisers and authorities where required by law
We do not sell or share personal information within the meaning of the CCPA/CPRA, and we do not permit advertisers to access your data.
7. International Transfers
Customer data is hosted on Google Cloud Platform in the United Kingdom (London region). The UK benefits from an EU adequacy decision. Some sub-processors process data in the USA and EEA; those transfers are protected by Standard Contractual Clauses and provider data processing agreements, as detailed in Part B.
If the EU adequacy decision for the UK is suspended or revoked, we will implement alternative safeguards and, where required to maintain compliance, migrate hosting to the EEA. EEA data residency may be offered as a configuration option under an order form.
8. Retention
| Data | Retention |
|---|---|
| Account and workspace data | Life of the account; deleted within 7 business days of a deletion request |
| Backups | Rolling 7 days, then automatically deleted |
| Billing and tax records | As required by applicable tax and accounting law |
| Marketing data | Until you opt out or object |
| Support conversations | 24 months after closure |
Residual copies in backups are fully purged no later than 7 days after primary deletion.
9. Security
Data is encrypted in transit (TLS 1.3) and at rest (AES-256). Production access is restricted through identity-aware proxies, role-based access control and two-factor authentication. Each workspace is logically isolated. We maintain an Incident Response Plan and undergo third-party penetration testing. Full technical and organisational measures are set out in Part B, Annex 2. We will notify affected customers within 48 hours of detecting any personal data breach affecting their data.
10. Your Rights
Depending on your jurisdiction, you have the right to access, rectify, erase, restrict, and port your personal data, to object to processing based on legitimate interests, and to withdraw consent at any time without affecting prior processing. To exercise any right, write to privacy@usedalil.ai. We respond within the timeframes required by law and may need to verify your identity.
Complaints. You may lodge a complaint with your local supervisory authority, including the Garante per la Protezione dei Dati Personali (Italy), the Information Commissioner's Office (UK), the DIFC Commissioner of Data Protection, or your EEA supervisory authority.
US residents. California and other US state residents may exercise access, deletion and correction rights via privacy@usedalil.ai. We do not sell or share personal information and we do not discriminate against you for exercising your rights.
11. Cookies
Our website uses:
- Essential cookies, required for the site and app to function (always active)
- Analytics cookies, to understand site usage (used only with your consent where required)
- Marketing cookies, to measure campaigns (used only with your consent where required)
You can manage preferences through the cookie banner or your browser settings. Withdrawing consent does not affect the lawfulness of prior processing.
12. Changes to This Policy
We will provide notice of material changes to this Privacy Policy through the platform or by email, at least 30 days in advance where the change materially affects your rights. The effective date at the top indicates the latest revision.
13. Contact
Data protection matters: privacy@usedalil.ai General enquiries: info@usedalil.ai Postal address: Dalil AI Ltd, DIFC Innovation One, AI Campus, Dubai International Financial Centre, Dubai, UAE Data Protection Officer: Sagnik Nath (privacy@usedalil.ai) EU Representative (Art. 27 GDPR): Giuseppe Manzone (privacy@usedalil.ai) UK Representative (Art. 27 UK GDPR): Giuseppe Manzone (privacy@usedalil.ai)
Part B: Data Processing Agreement
This Data Processing Agreement ("DPA") forms part of, and is incorporated into, the Terms of Service, Master Services Agreement, subscription agreement, order form, or other written or electronic agreement (the "Principal Agreement") between the Customer and Dalil AI Ltd, a company incorporated in the Dubai International Financial Centre (DIFC), Dubai, United Arab Emirates, under License No. CL8158 ("Dalil", "we", "us"), for the provision of the Dalil AI Sales OS platform (the "Services").
This DPA applies automatically to all customers whose use of the Services involves the processing of Personal Data subject to Data Protection Laws. No signature is required: by using the Services, the Customer accepts this DPA. Customers who require a countersigned copy for their records can request one at privacy@usedalil.ai.
In the event of any conflict between this DPA and the Principal Agreement, this DPA prevails with respect to the subject matter of data protection.
1. Definitions
"Data Protection Laws" means all laws and regulations applicable to the Processing of Personal Data under this DPA, including: (i) the EU General Data Protection Regulation (Regulation (EU) 2016/679) ("GDPR"); (ii) the UK GDPR and the UK Data Protection Act 2018; (iii) the DIFC Data Protection Law No. 5 of 2020; (iv) the UAE Federal Personal Data Protection Law No. 45 of 2021; (v) the Saudi Arabian Personal Data Protection Law and its Implementing Regulations, where applicable; (vi) applicable US state privacy laws, including the California Consumer Privacy Act as amended ("CCPA"); and (vii) any implementing or successor legislation, in each case as amended or replaced from time to time.
"Controller", "Processor", "Data Subject", "Personal Data", "Processing", "Personal Data Breach" and "Supervisory Authority" have the meanings given to them in the GDPR. For Customers subject to the CCPA, "Controller" includes "Business", "Processor" includes "Service Provider", and "Personal Data" includes "Personal Information".
"Customer Personal Data" means any Personal Data that Dalil Processes on behalf of the Customer in connection with the provision of the Services, as further described in Annex 1.
"Sub-processor" means any third party engaged by Dalil to Process Customer Personal Data in connection with the Services.
"Standard Contractual Clauses" or "SCCs" means (i) the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission in Decision (EU) 2021/914; and (ii) where UK data is concerned, the UK International Data Transfer Addendum issued by the UK Information Commissioner (the "UK Addendum").
"EEA" means the European Economic Area.
The Annexes form an integral part of this DPA.
2. Roles of the Parties and Scope
2.1 For the purposes of the Data Protection Laws, the Customer is the Controller and Dalil is the Processor with respect to Customer Personal Data. Where the Customer acts as a processor on behalf of a third-party controller, Dalil acts as a sub-processor.
2.2 Dalil Processes Customer Personal Data only for the purpose of providing the Services and only in accordance with this DPA and the Customer's documented instructions, including with regard to international transfers, unless required to do otherwise by applicable law. In that case, Dalil will, where legally permitted, inform the Customer of that legal requirement before Processing.
2.3 The subject matter, duration, nature and purpose of the Processing, the types of Personal Data and the categories of Data Subjects are set out in Annex 1.
2.4 The Principal Agreement, together with the Customer's use and configuration of the Services (including any settings, uploads, imports, sync options and integrations the Customer enables), constitutes the Customer's complete documented instructions to Dalil. Additional instructions require prior written agreement between the Parties.
2.5 Dalil will inform the Customer without undue delay if, in Dalil's opinion, an instruction infringes the Data Protection Laws. Dalil has no obligation to actively monitor the Customer's compliance with Data Protection Laws.
2.6 The Customer warrants that it has a valid lawful basis under the Data Protection Laws for the Processing of Customer Personal Data, including for: (i) any outbound communications (email, LinkedIn, WhatsApp or other channels) initiated through the Services; (ii) any conversations, inboxes or channels the Customer chooses to connect or synchronise to the Services; and (iii) any contact data the Customer uploads, imports or enriches. The Customer warrants that it has provided all required notices to Data Subjects and, where applicable, obtained all necessary consents.
2.7 Dalil does not sell or share Customer Personal Data within the meaning of the CCPA, and does not retain, use or disclose Customer Personal Data for any purpose other than providing the Services, including any commercial purpose of its own.
3. Obligations of Dalil
3.1 Confidentiality. Dalil ensures that persons authorised to Process Customer Personal Data are bound by an appropriate duty of confidentiality, whether contractual or statutory. This obligation survives the termination of their engagement.
3.2 Security. Dalil implements and maintains the technical and organisational security measures set out in Annex 2, having regard to the state of the art, the costs of implementation, and the nature, scope, context and purposes of Processing, as well as the risk to Data Subjects.
3.3 Data Subject rights. Taking into account the nature of the Processing, Dalil assists the Customer by appropriate technical and organisational measures, insofar as reasonably possible, in fulfilling the Customer's obligation to respond to requests by Data Subjects exercising their rights under Chapter III of the GDPR and equivalent provisions of other Data Protection Laws (including rights of access, rectification, erasure, restriction, portability and objection). Where a Data Subject request is received directly by Dalil, Dalil promptly forwards it to the Customer and does not respond directly except on the Customer's documented instruction or as required by law.
3.4 Compliance assistance. Dalil assists the Customer in ensuring compliance with its obligations under Articles 32 to 36 of the GDPR (security, breach notification, data protection impact assessments and prior consultation), taking into account the nature of Processing and the information available to Dalil.
3.5 Breach notification. Dalil notifies the Customer without undue delay, and in any event within forty-eight (48) hours of becoming aware of a Personal Data Breach affecting Customer Personal Data. The notification describes, to the extent known: the nature of the breach; the categories and approximate number of Data Subjects and records concerned; the likely consequences; and the measures taken or proposed to address it. Dalil provides further information in phases as it becomes available. Dalil's notification of a Personal Data Breach is not an acknowledgement of fault or liability.
3.6 No secondary use. Dalil does not use Customer Personal Data for its own purposes. In particular, Dalil does not use Customer Personal Data to train or improve any artificial intelligence or machine learning model, for marketing, or for profiling, and does not sell or disclose Customer Personal Data to any third party except as permitted under this DPA.
3.7 Government access requests. If Dalil receives a legally binding request from a public authority for access to Customer Personal Data, Dalil will, unless legally prohibited, promptly notify the Customer, challenge overbroad or unlawful requests where reasonably possible, and disclose only the minimum data required.
4. Artificial Intelligence Processing
4.1 The Services incorporate AI features powered exclusively by frontier, industry-recognized large language models from OpenAI, Anthropic and Google, as listed in Annex 3. These features may transmit the minimum necessary Customer Personal Data to those providers for the sole purpose of generating outputs requested by the Customer, such as message drafting, reply suggestions, summarisation of correspondence, scoring and enrichment.
4.2 The Customer acknowledges that AI features involve automated analysis of the content of messages and records that the Customer connects or uploads to the Services. The Customer is responsible for ensuring an appropriate lawful basis for this Processing and for informing Data Subjects as required by Data Protection Laws.
4.3 Dalil warrants that each AI Sub-processor is engaged under terms that contractually prohibit: (i) the retention of Customer Personal Data beyond what is necessary to return the requested output; and (ii) the use of Customer Personal Data to train or improve the provider's models.
4.4 AI-generated outputs (such as drafts and summaries) form part of Customer Personal Data and are subject to the deletion and return obligations in Clause 8, including deletion of AI-derived outputs upon account deletion.
4.5 The Services do not use Customer Personal Data for automated decision-making producing legal or similarly significant effects concerning Data Subjects within the meaning of Article 22 GDPR. AI outputs are suggestions that require human review and action by the Customer's users.
4.6 AI features are designed in accordance with the principle of data minimisation. Dalil transmits to AI Sub-processors only such Customer Personal Data as is reasonably necessary to generate the output requested by the Customer's user, and does not intentionally provide AI features with access to personal or sensitive information beyond what the requested output reasonably requires.
5. Sub-processors
5.1 The Customer grants Dalil general written authorisation to engage the Sub-processors listed in Annex 3 for the Processing of Customer Personal Data.
5.2 Dalil imposes on each Sub-processor, by way of a written contract, data protection obligations that are no less protective than those set out in this DPA, in particular sufficient guarantees to implement appropriate technical and organisational measures. Dalil remains fully liable to the Customer for the performance of each Sub-processor's obligations.
5.3 Dalil notifies the Customer of any intended addition or replacement of a Sub-processor at least thirty (30) days in advance, giving the Customer the opportunity to object on reasonable data protection grounds. If the Customer reasonably objects and the Parties cannot agree a resolution, the Customer may, as its sole remedy, terminate the affected Services without penalty.
5.4 The current list of Sub-processors is maintained in Annex 3 and on this page. Customers can subscribe to change notifications by writing to privacy@usedalil.ai.
6. International Transfers and Data Residency
6.1 Dalil hosts and stores Customer Personal Data on Google Cloud Platform infrastructure located in the United Kingdom (London region). Primary storage and Processing of Customer Personal Data take place within the UK. The UK benefits from an EU adequacy decision, permitting transfers of Personal Data from the EEA to the UK without additional safeguards.
6.2 If the EU adequacy decision for the UK is suspended, revoked or invalidated, Dalil will, at no additional cost to the Customer, implement an alternative lawful transfer mechanism and, where required to maintain compliance, migrate Customer Personal Data to hosting infrastructure within the EEA. Dalil may also offer EEA data residency as a configuration option; where agreed in an order form, that option prevails over Clause 6.1.
6.3 To the extent that the provision of the Services involves a transfer of Customer Personal Data to a country outside the EEA or the UK that is not the subject of an adequacy decision, including access to Customer Personal Data by Dalil as a DIFC-based entity or by a Sub-processor located outside the EEA/UK, such transfer is governed by the Standard Contractual Clauses, which are incorporated into this DPA by reference and completed as set out in Annex 4.
6.4 For transfers subject to the EU SCCs, Module Two (Controller to Processor) applies. Where the Customer itself acts as a processor, Module Three (Processor to Processor) applies. The UK Addendum applies to transfers of Personal Data subject to the UK GDPR. For Customers subject to the DIFC Data Protection Law, transfers are made in accordance with Articles 26 and 27 of that law. For Customers subject to the Saudi PDPL, transfers are made in accordance with its data transfer provisions, and KSA data residency options can be agreed in an order form.
6.5 In the event of any conflict between the SCCs and this DPA, the SCCs prevail. If the transfer mechanisms in this Clause are held invalid or insufficient by a competent authority, the Parties shall cooperate in good faith to implement an alternative lawful transfer mechanism.
7. Records and Audit
7.1 Dalil makes available to the Customer all information reasonably necessary to demonstrate compliance with the obligations set out in Article 28 of the GDPR and this DPA.
7.2 Dalil allows for and contributes to audits, including inspections, conducted by the Customer or an independent auditor mandated by the Customer, no more than once per calendar year (save where required by a Supervisory Authority or following a Personal Data Breach), subject to at least thirty (30) days' prior notice, during normal business hours, and subject to confidentiality obligations. Dalil may first satisfy audit requests by providing its then-current security documentation, certifications held by its infrastructure providers, third-party penetration test attestations, and the Dalil AI Security Whitepaper.
8. Return and Deletion of Data
8.1 Upon termination or expiry of the Services, Dalil will, at the Customer's choice, delete or return all Customer Personal Data, and delete existing copies, unless applicable law requires continued storage.
8.2 Upon account termination and Customer request, all Customer data, including synced conversations, attachments, AI-generated outputs, backups and logs relating to the Customer, is irreversibly deleted within seven (7) business days. Encrypted backups are retained for a rolling period of seven (7) days in the UK region and are then automatically deleted, so residual copies in backups are fully purged no later than seven (7) days after primary deletion.
8.3 If deletion is not requested, the account may be kept in stasis to give the Customer the option to reactivate it in the future. Dalil is not obligated to keep the account in stasis for any period of time and may delete it at any point after termination or expiry, upon reasonable notice to the Customer's registered email address.
8.4 Dalil will, upon the Customer's written request, certify in writing that it has complied with this Clause 8.
9. Liability, Term and General
9.1 Each Party's liability arising out of or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Principal Agreement. For clarity, and consistent with the Principal Agreement, claims relating to Personal Data Breaches are subject to the aggregate liability cap set out in the Principal Agreement, which is not increased or disapplied by this DPA. Nothing in this Clause limits the rights of Data Subjects or the powers of Supervisory Authorities under Data Protection Laws.
9.2 This DPA takes effect on the effective date of the Principal Agreement and continues for as long as Dalil Processes Customer Personal Data, notwithstanding termination of the Principal Agreement.
9.3 If any provision of this DPA is held to be invalid or unenforceable, the remaining provisions continue in full force and effect.
9.4 This DPA is governed by the law governing the Principal Agreement. Where the Principal Agreement is silent, the laws of the Dubai International Financial Centre (DIFC) apply and the Parties submit to the exclusive jurisdiction of the DIFC Courts. Nothing in this Clause limits the rights of Data Subjects or Supervisory Authorities under the Data Protection Laws, or the governing law provisions of the Standard Contractual Clauses.
Annex 1: Details of Processing
Subject matter. Provision of the Dalil AI Sales OS platform, including sales records management, multi-channel outreach (email, LinkedIn, WhatsApp), unified inbox, workflow automation and AI-assisted features, to the Customer.
Duration. For the term of the Principal Agreement and until deletion of Customer Personal Data in accordance with Clause 8.
Nature and purpose. Storage, organisation, structuring, retrieval, enrichment, AI-assisted drafting and summarisation, transmission of outbound communications, synchronisation of connected channels, analytics, and related sales operations functions performed on behalf of the Customer.
Categories of Data Subjects. The Customer's employees, contractors and authorised users; the Customer's contacts, leads, prospects and customers; other individuals whose data the Customer uploads, connects, syncs or generates in the Services.
Types of Personal Data. Identification and contact data (name, business email, phone, job title, employer); professional and social profile data (e.g. LinkedIn profile URL and publicly available details); communications content and metadata (messages, replies, timestamps, engagement data) from channels the Customer connects; sales records (notes, deal and opportunity data, tasks, activity history); account and usage data of authorised users.
Special categories. The Services are not intended to Process special categories of Personal Data (Article 9 GDPR) or data relating to criminal convictions (Article 10 GDPR). The Customer shall not upload such data unless expressly agreed in writing. The Services are not directed at children and the Customer shall not upload Personal Data of individuals under 18.
Frequency. Continuous, for the duration of the Services.
Annex 2: Technical and Organisational Measures
These measures are described in further detail in the Dalil AI Security Whitepaper, which is incorporated by reference and updated from time to time. Dalil may update these measures provided the overall level of security is not reduced.
| Domain | Measures |
|---|---|
| Infrastructure | Hosted entirely on Google Cloud Platform (UK region). GCP maintains ISO 27001, SOC 2 and GDPR-aligned certifications. |
| Encryption in transit | All data transmitted between clients and servers is encrypted using TLS 1.3. HTTPS-only traffic is enforced. |
| Encryption at rest | Customer data is stored in Cloud SQL and encrypted at rest using AES-256. |
| Network security | Servers, applications and databases are secured behind Virtual Private Networks (VPNs). Application logic runs in isolated Kubernetes (GKE) clusters within private subnets, without external network exposure. |
| Access control | Access to production is restricted to authorised personnel using identity-aware proxies, role-based access controls (RBAC) and two-factor authentication (2FA). |
| Tenant isolation | Each customer workspace is logically isolated with separate database schemas to prevent data leakage or unauthorised cross-tenant access. |
| Monitoring and logging | Continuous monitoring of infrastructure and application logs via Google Cloud Operations Suite, with alerting for intrusion attempts, data exfiltration patterns and unusual API usage. Secure audit trails are maintained. |
| Resilience | Documented Incident Response Plan (IRP) and Business Continuity Plan (BCP). Encrypted daily backups retained for 7 days in the UK region. |
| Abuse prevention | Rate limiting and API throttling to prevent abuse. |
| Data minimisation | Only the minimum necessary data is Processed; redundant data is deleted after defined retention periods under automated GCP lifecycle policies. |
| Personnel | Confidentiality undertakings for all staff with access to Customer Personal Data; access on a need-to-know basis; third-party penetration tests performed. |
Annex 3: List of Sub-processors
The Customer authorises Dalil to engage the following Sub-processors in connection with the Services:
| Sub-processor | Purpose | Processing location | Safeguard |
|---|---|---|---|
| Google Cloud Platform | Cloud hosting, storage, compute and operational logging | United Kingdom | UK adequacy; SCCs where applicable |
| Google (Gemini models via Google Cloud Vertex AI) | AI model inference under enterprise terms; no training reuse | USA / EEA | SCCs and provider DPA |
| OpenAI | AI model inference (drafting, summarisation); no training reuse | USA | SCCs and provider DPA |
| Anthropic | AI model inference; no training reuse | USA / EEA | SCCs and provider DPA |
| Twilio | Messaging and communications delivery | USA / EEA | SCCs and provider DPA |
| Unipile | Connectivity to LinkedIn, WhatsApp and email channels | EEA | EEA processing under GDPR |
| Airscale | Contact data enrichment; does not connect to any Customer email or LinkedIn account | EEA | EEA processing under GDPR |
Provider privacy documentation: Google Cloud (cloud.google.com/privacy), OpenAI (privacy.openai.com), Anthropic (privacy.claude.com), Twilio (twilio.com/en-us/privacy), Unipile (unipile.com/privacy-policy), Airscale (as published by the provider).
The AI Sub-processors above are engaged under terms prohibiting retention of Customer Personal Data for model training or improvement.
Annex 4: Standard Contractual Clauses (Completion Details)
Where the SCCs apply under Clause 6, they are completed as follows:
| Item | Completion |
|---|---|
| Modules | Module Two (Controller to Processor) applies where the Customer is a Controller. Module Three (Processor to Processor) applies where the Customer acts as a Processor for a third-party controller. |
| Data exporter | The Customer (and its Affiliates), as identified in the Principal Agreement. |
| Data importer | Dalil AI Ltd, and non-EEA/UK Sub-processors listed in Annex 3. |
| Clause 7 (Docking) | Applies; the optional docking clause is included. |
| Clause 9 (Sub-processors) | Option 2 (general written authorisation) applies, with a minimum 30 days' prior notice of changes as set out in Clause 5.3. |
| Clause 11 (Redress) | The optional independent dispute resolution provision does not apply. |
| Clause 17 (Governing law) | The law of the Republic of Ireland applies to the EU SCCs. |
| Clause 18 (Jurisdiction) | The courts of the Republic of Ireland for the EU SCCs; for the UK Addendum, the courts of England and Wales. |
| UK Addendum Tables | Table 1 (Parties) and Table 3 (Appendix) are populated by reference to this DPA and its Annexes; Table 2 selects the EU SCCs above; Table 4 (ending the Addendum): neither Party may end the Addendum other than as set out therein. |
| Annex I / II / III of SCCs | Populated by reference to Annex 1 (details of processing), Annex 2 (technical and organisational measures) and Annex 3 (sub-processors) of this DPA respectively. |
Contact for Data Protection Matters
Email: privacy@usedalil.ai Postal address: Dalil AI Ltd, DIFC Innovation One, AI Campus, Dubai International Financial Centre, Dubai, UAE Data Protection Officer: Sagnik Nath (privacy@usedalil.ai) EU Representative (Article 27 GDPR): Giuseppe Manzone (privacy@usedalil.ai) UK Representative (Article 27 UK GDPR): Giuseppe Manzone (privacy@usedalil.ai)