דלג לתוכן הראשי
--:--:--
Enterprise addendum · EU hosting · GCC-aware

GCC Data Residency Addendum

Last updated: July 2026 · Effective on Order acceptance

1. Purpose

This Addendum supplements the Master Subscription Agreement and the Data Processing Agreement (DPA) between the Customer and GARAAGRISAFE Ltd. ("Provider"). It documents the current data-residency posture of the Service for Customers located in the Gulf Cooperation Council (GCC) region, and the safeguards applied while an in-region hosting option is under development.

2. Current hosting region

Personal Data and Customer Content are hosted in the European Union — Frankfurt, Germany (AWS eu-central-1 via the managed backend provider).

The hosting region is chosen for GDPR adequacy, mature security certifications (ISO 27001, SOC 2 Type II) and lowest measured round-trip latency from the GCC (typically 90–130 ms).

No Personal Data is replicated to United States or United Kingdom regions for production workloads.

3. Transfer mechanism

Where Personal Data of a GCC data subject is transferred from a GCC country to the EU hosting region, the Provider relies on:

(a) the Customer's own lawful basis for the transfer under the applicable GCC data-protection law (UAE Federal Decree-Law No. 45 of 2021, KSA PDPL 2021 as amended 2023, Bahrain PDPL 2018, Qatar Law No. 13 of 2016, Oman Royal Decree 6/2022, Kuwait DPPR 2021);

(b) the Standard Contractual Clauses (SCC) module 2 (Controller → Processor) as annexed to the DPA;

(c) additional technical measures set out in §4 below.

The Customer, as Controller, is responsible for informing its own data subjects of the international transfer where local law requires it.

4. Technical and organisational safeguards

Encryption in transit: TLS 1.3 with modern cipher suites for all traffic between the client, the Service, and the backend provider.

Encryption at rest: AES-256 for the primary database, object storage, and backups.

Key management: envelope encryption; per-tenant data-encryption keys wrapped by a KMS master key that never leaves the KMS boundary.

Access control: least-privilege IAM, mandatory MFA for Provider personnel, and full audit logging of any administrative access.

Backups: encrypted, retained 30 days in the same EU region; deleted on Customer termination per the DPA §10.

Sub-processors: listed and version-controlled at /subprocessors; the Customer is notified in advance of any new sub-processor with a 30-day objection window.

5. Government access requests

The Provider will not disclose Personal Data to any government authority except where legally compelled.

If the Provider receives a backed by verifiable evidence request from a public authority (including any EU, GCC, US or UK authority), it will: (i) promptly notify the Customer unless prohibited by law, (ii) challenge overbroad or unlawful requests, (iii) disclose only the minimum data strictly required, and (iv) publish annual aggregate statistics of such requests.

6. In-region roadmap

The Provider is monitoring the availability of a fully-managed, feature-parity hosting region inside the GCC (target regions under evaluation: AWS Bahrain, AWS UAE, and G42/Core42 in Abu Dhabi).

When the backend provider makes an eligible region generally available with parity for the managed database, storage, and edge functions the Service depends on, the Provider will offer a migration path to Enterprise Customers at no additional cost.

Until then, the EU-Frankfurt posture and safeguards described in §§2–4 apply.

7. Customer choice

By signing the Order Form referencing this Addendum, the Customer expressly acknowledges and consents to processing of Personal Data in the European Union, subject to the safeguards in §§3–5.

This consent may be withdrawn on 30 days' written notice, in which case the Provider will assist the Customer in migrating or deleting Personal Data in accordance with the DPA §10.

8. Precedence

In case of conflict between this Addendum and the DPA, this Addendum prevails for matters of hosting region and transfer mechanism only. All other DPA provisions remain in full force.

9. Contact

For residency, transfer and audit questions: legal@garaagrisafe.com

For security incident notification: security@garaassets.com (24 × 7)

legal@garaagrisafe.com · GARAAGRISAFE Ltd.