DATA POLICY & DATA PROCESSING ADDENDUM (DPA) Mubdie LLC – mubdie.net
0.1. B2B‑Only Application This Policy and Data Processing Addendum (“Policy”, “DPA”) applies exclusively to business customers (B2B). All references to “Client”, “you”, or “your” refer to a business entity or its authorized representative acting in a commercial capacity. This Policy does not apply to individual consumers, and consumer protection laws do not apply to our Services.
0.2. Business Client A “Business Client” is a legal business entity, or an authorized representative acting on behalf of such entity, entering into a commercial agreement with Mubdie LLC.
0.3. Authority By using our Services or approving the Invoice, you represent and warrant that you are authorized to act on behalf of the business entity you represent and to enter into binding commercial agreements, including this DPA.
This Data Policy and Data Processing Addendum (“Policy”, “DPA”) forms part of the Terms of Service between Mubdie LLC, a Wyoming limited liability company (“Company”, “we”, “us”, or “our”), and the Client (“Client”, “you”, or “your”).
This Policy governs how data is collected, processed, stored, and protected when using our Services, including websites, booking systems, and subscription‑based platforms such as Eyadaat.
This Policy is designed to comply with:
U.S. privacy laws, including state‑level requirements
GDPR (EU General Data Protection Regulation)
UK GDPR
GCC privacy regulations (Saudi PDPL, UAE DP Law, Qatar DPL, Bahrain PDPL, Kuwait & Oman frameworks)
International data transfer standards
Refers to Mubdie LLC, the service provider and data processor for certain Services.
Refers to the business entity purchasing Services and acting as the Data Controller for its own users.
The entity that determines the purpose and means of processing personal data. The Client is the Data Controller.
The entity that processes personal data on behalf of the Data Controller. Mubdie LLC is the Data Processor.
Any information relating to an identified or identifiable individual.
Any operation performed on personal data, including storage, access, transmission, or deletion.
This Policy applies to: 3.1.1. Websites developed or hosted by the Company 3.1.2. Booking systems for professionals 3.1.3. Business websites for clinics or service providers 3.1.4. Eyadaat subscription platform (non‑medical SaaS) 3.1.5. Any digital service where the Company processes data on behalf of the Client
The Company does not process medical diagnoses, treatment data, or protected health information (PHI). We provide booking systems and business websites only — not medical systems.
Processing may include: 3.3.1. Hosting and storage 3.3.2. Technical support 3.3.3. System configuration 3.3.4. Data backup and security 3.3.5. Account management
The Client is responsible for: 4.1.1. Determining what data is collected 4.1.2. Compliance with applicable laws 4.1.3. Providing privacy notices to users 4.1.4. Obtaining required consents 4.1.5. Managing user access/deletion requests
The Company will: 4.2.1. Process data only according to Client instructions 4.2.2. Not use Client data for any other purpose 4.2.3. Maintain confidentiality and security 4.2.4. Assist the Client when feasible
Data is stored on secure cloud servers such as: 5.1.1. Kinsta (Google Cloud Platform) 5.1.2. U.S.‑based data centers 5.1.3. Global CDN networks
5.2.1. Data in transit is encrypted (HTTPS/TLS) 5.2.2. Certain data may be encrypted at rest
5.3.1. Restricted to authorized personnel 5.3.2. Multi‑layer authentication
Automated backups may be maintained for continuity.
By using the Services, the Client consents to data being stored and processed in the U.S.
For EU/EEA Clients, transfers rely on: 6.2.1. Standard Contractual Clauses (SCCs) 6.2.2. Technical and organizational measures
The Company adheres to GCC data transfer requirements, including: 6.3.1. Saudi PDPL 6.3.2. UAE DP Law 6.3.3. Qatar DPL 6.3.4. Bahrain PDPL
Users may have rights including: 7.1.1. Access 7.1.2. Correction 7.1.3. Deletion 7.1.4. Restriction 7.1.5. Portability 7.1.6. Withdrawal of consent
The Client is responsible for responding to user requests. The Company assists when technically feasible.
May include: 8.1.1. Hosting providers 8.1.2. Payment processors 8.1.3. Email delivery services 8.1.4. Domain registrars
All sub‑processors must maintain appropriate security and confidentiality.
Data is retained only as long as necessary for: 9.1.1. Service delivery 9.1.2. Legal compliance 9.1.3. Accounting obligations
Upon written request, the Company will: 9.2.1. Delete Client data when feasible 9.2.2. Provide data export
In case of a breach, the Company will: 10.1.1. Notify the Client without undue delay 10.1.2. Provide available details 10.1.3. Assist in mitigation
The Company does not provide medical systems or handle PHI.
The Client is solely responsible for: 11.2.1. Website content 11.2.2. Booking system usage 11.2.3. Legal compliance 11.2.4. User data practices
The Company may update this Policy at any time.
Continued use of the Services constitutes acceptance of the updated Policy.
support@mubdie.net
MUBDIE LLC is a US‑registered company based in Wyoming, providing digital technology and business services to corporate clients.
All services are offered exclusively to business customers (B2B).
Prices are listed exclusive of VAT. Where applicable, VAT must be accounted for by the customer under the reverse‑charge mechanism.
By using this website or purchasing our services, you confirm that you are acting as a business entity.

