Last updated: August 23, 2026
Evnao (“Processor”) will process “Customer Data” on behalf of Customer (“Controller”). Each party will comply with applicable data protection laws (e.g. Jordan PDPL, GDPR, CCPA). The Processor will process Customer Data solely to perform the Services described in the Terms of Service. Categories of data include Customer account data and end-user support content; categories of data subjects include the Customer's employees and customers.
The Controller authorizes the Processor to process data as necessary to provide the Service. The Processor will follow written instructions from the Controller (e.g. configurations set in the admin panel). If a law requires the Processor to use data beyond these instructions, the Processor will notify the Controller unless legally barred.
Upon termination or expiration, Processor will delete or return all Customer Data as instructed by Controller, within 30 days. If law requires retention (e.g. accounting regulations), Processor will isolate such data until that law's requirements are satisfied.
Controller instructs Processor to transfer data as needed for the Services. Where a restricted international transfer requires a lawful transfer mechanism, Evnao will use an applicable mechanism, which may include the European Commission Standard Contractual Clauses and, where applicable, the UK International Data Transfer Addendum. The specific mechanism used will depend on the jurisdictions involved and the requirements of applicable law.
For personal data subject to the Jordan Personal Data Protection Law, transfers outside Jordan will be made in accordance with applicable requirements, including any adequacy determinations, appropriate safeguards, or regulatory approvals required under Jordanian law. Controller acknowledges that certain subprocessors may process data outside Jordan in order to deliver the Service, and authorizes such transfers subject to the safeguards described in this DPA.
If Controller's Customer Data includes California personal information, the parties agree that Processor is a “service provider” under CCPA. Processor will not sell or share Personal Information, will use it only for Business Purposes, and will comply with applicable requirements for handling Consumer requests.
Controller may audit Processor's compliance once per year, subject to confidentiality, by providing reasonable notice. Where available, Processor may provide a relevant third-party audit or assessment report to demonstrate compliance in lieu of an on-site audit. Each party's liability is governed by the Terms of Service.
By using Evnao, Controller acknowledges this DPA and authorizes Evnao to engage subprocessors under these terms.