Data Processing Addendum
DPA for organisation customers where GigBlend processes personal data on their behalf.
Last updated: 21 August 2026
This Data Processing Addendum (“DPA”) forms part of the agreement between Nikah AI Ltd (“Processor”) and the organisation customer (“Controller”) when the Platform processes personal data on the Controller’s documented instructions in connection with organisation accounts.
If you are an individual consumer, the Privacy Notice applies and this DPA is not required.
1. Roles Controller determines purposes and means of processing personal data of its users/employees submitted to the Platform. Processor provides the Platform and processes such data only on documented instructions, unless required by law.
2. Details of processing - **Subject matter:** hosting and operation of marketplace accounts, orders, messaging and related support for the Controller’s authorised users - **Duration:** term of the agreement + retention in Privacy Notice - **Nature:** storage, transmission, display, deletion, security logging, AI fulfilment when ordered - **Purpose:** provide Platform services - **Types of data:** identity, contact, account, order and content data as submitted - **Data subjects:** Controller’s staff and end users authorised by Controller
3. Processor obligations Processor shall: process only on instructions; ensure confidentiality; implement appropriate technical and organisational measures; not engage sub-processors without meeting clause 4; assist with data subject requests and DPIAs reasonably; delete or return data on termination subject to legal retention; make available information to demonstrate compliance.
4. Sub-processors Controller authorises Processor’s current sub-processors listed on the Subprocessors page. Processor will give notice of material changes where required and remain responsible for sub-processors.
5. International transfers Processor shall ensure lawful transfer mechanisms for restricted transfers.
6. Security incidents Processor will notify Controller without undue delay after becoming aware of a personal data breach affecting Controller data, with information reasonably available.
7. Audits Upon reasonable notice, Processor will provide security summaries or reports. On-site audits are limited to once per year unless a breach or regulator requires otherwise.
8. Liability Liability follows the main agreement, subject to mandatory data-protection law.
Questions?
Privacy: privacy@gig-blend.com · Legal: legal@gig-blend.com · See also Contact & company information.