DATA POLICY & DATA PROCESSING ADDENDUM (DPA)

DATA POLICY & DATA PROCESSING ADDENDUM (DPA) Mubdie LLC – mubdie.net

 

0. Business Use & Legal Capacity

0.1. B2B‑Only Application This Policy and Data Processing Addendum (“Policy”, “DPA”) applies exclusively to business customers (B2B). All references to “Client”, “you”, or “your” refer to a business entity or its authorized representative acting in a commercial capacity. This Policy does not apply to individual consumers, and consumer protection laws do not apply to our Services.

0.2. Business Client A “Business Client” is a legal business entity, or an authorized representative acting on behalf of such entity, entering into a commercial agreement with Mubdie LLC.

0.3. Authority By using our Services or approving the Invoice, you represent and warrant that you are authorized to act on behalf of the business entity you represent and to enter into binding commercial agreements, including this DPA.

 

1. Introduction

This Data Policy and Data Processing Addendum (“Policy”, “DPA”) forms part of the Terms of Service between Mubdie LLC, a Wyoming limited liability company (“Company”, “we”, “us”, or “our”), and the Client (“Client”, “you”, or “your”).

This Policy governs how data is collected, processed, stored, and protected when using our Services, including websites, booking systems, and subscription‑based platforms such as Eyadaat.

This Policy is designed to comply with:

  • U.S. privacy laws, including state‑level requirements

  • GDPR (EU General Data Protection Regulation)

  • UK GDPR

  • GCC privacy regulations (Saudi PDPL, UAE DP Law, Qatar DPL, Bahrain PDPL, Kuwait & Oman frameworks)

  • International data transfer standards

 

2. Definitions

2.1. “Company”

Refers to Mubdie LLC, the service provider and data processor for certain Services.

2.2. “Client”

Refers to the business entity purchasing Services and acting as the Data Controller for its own users.

2.3. “Data Controller”

The entity that determines the purpose and means of processing personal data. The Client is the Data Controller.

2.4. “Data Processor”

The entity that processes personal data on behalf of the Data Controller. Mubdie LLC is the Data Processor.

2.5. “Personal Data”

Any information relating to an identified or identifiable individual.

2.6. “Processing”

Any operation performed on personal data, including storage, access, transmission, or deletion.

 

3. Scope of Processing

3.1. Services Covered

This Policy applies to: 3.1.1. Websites developed or hosted by the Company 3.1.2. Booking systems for professionals 3.1.3. Business websites for clinics or service providers 3.1.4. Eyadaat subscription platform (non‑medical SaaS) 3.1.5. Any digital service where the Company processes data on behalf of the Client

3.2. No Medical Data Processing

The Company does not process medical diagnoses, treatment data, or protected health information (PHI). We provide booking systems and business websites only — not medical systems.

3.3. Nature of Processing

Processing may include: 3.3.1. Hosting and storage 3.3.2. Technical support 3.3.3. System configuration 3.3.4. Data backup and security 3.3.5. Account management

 

4. Roles and Responsibilities

4.1. Client as Data Controller

The Client is responsible for: 4.1.1. Determining what data is collected 4.1.2. Compliance with applicable laws 4.1.3. Providing privacy notices to users 4.1.4. Obtaining required consents 4.1.5. Managing user access/deletion requests

4.2. Company as Data Processor

The Company will: 4.2.1. Process data only according to Client instructions 4.2.2. Not use Client data for any other purpose 4.2.3. Maintain confidentiality and security 4.2.4. Assist the Client when feasible

 

5. Data Storage and Security

5.1. Hosting Infrastructure

Data is stored on secure cloud servers such as: 5.1.1. Kinsta (Google Cloud Platform) 5.1.2. U.S.‑based data centers 5.1.3. Global CDN networks

5.2. Encryption

5.2.1. Data in transit is encrypted (HTTPS/TLS) 5.2.2. Certain data may be encrypted at rest

5.3. Access Controls

5.3.1. Restricted to authorized personnel 5.3.2. Multi‑layer authentication

5.4. Backups

Automated backups may be maintained for continuity.

 

6. International Data Transfers

6.1. Transfers to the United States

By using the Services, the Client consents to data being stored and processed in the U.S.

6.2. GDPR Safeguards

For EU/EEA Clients, transfers rely on: 6.2.1. Standard Contractual Clauses (SCCs) 6.2.2. Technical and organizational measures

6.3. GCC Compliance

The Company adheres to GCC data transfer requirements, including: 6.3.1. Saudi PDPL 6.3.2. UAE DP Law 6.3.3. Qatar DPL 6.3.4. Bahrain PDPL

 

7. Data Subject Rights

7.1. Rights Under GDPR and Global Laws

Users may have rights including: 7.1.1. Access 7.1.2. Correction 7.1.3. Deletion 7.1.4. Restriction 7.1.5. Portability 7.1.6. Withdrawal of consent

7.2. Client Responsibility

The Client is responsible for responding to user requests. The Company assists when technically feasible.

 

8. Sub‑Processors

8.1. Approved Sub‑Processors

May include: 8.1.1. Hosting providers 8.1.2. Payment processors 8.1.3. Email delivery services 8.1.4. Domain registrars

8.2. Sub‑Processor Obligations

All sub‑processors must maintain appropriate security and confidentiality.

 

9. Data Retention and Deletion

9.1. Retention Periods

Data is retained only as long as necessary for: 9.1.1. Service delivery 9.1.2. Legal compliance 9.1.3. Accounting obligations

9.2. Client Requests

Upon written request, the Company will: 9.2.1. Delete Client data when feasible 9.2.2. Provide data export

 

10. Security Incidents

10.1. Notification

In case of a breach, the Company will: 10.1.1. Notify the Client without undue delay 10.1.2. Provide available details 10.1.3. Assist in mitigation

 

11. Limitations

11.1. No Medical Liability

The Company does not provide medical systems or handle PHI.

11.2. Client Responsibility

The Client is solely responsible for: 11.2.1. Website content 11.2.2. Booking system usage 11.2.3. Legal compliance 11.2.4. User data practices

 

12. Amendments

12.1. Updates

The Company may update this Policy at any time.

12.2. Continued Use

Continued use of the Services constitutes acceptance of the updated Policy.

 

13. Contact Information

13.1. Privacy & Data Requests

support@mubdie.net

 
mubdie-llc-logo-w

MUBDIE LLC

MUBDIE LLC is a US‑registered company based in Wyoming, providing digital technology and business services to corporate clients.
All services are offered exclusively to business customers (B2B).
Prices are listed exclusive of VAT. Where applicable, VAT must be accounted for by the customer under the reverse‑charge mechanism.
By using this website or purchasing our services, you confirm that you are acting as a business entity.

Feature Services

تصميم وتطوير - شركة مبدع 2026 © Mubdie LLC