Data Processing Agreement
Last updated: 2026-08-13
1. Parties and subject matter
This is a data processing agreement between the merchant (the "controller") and Murtadha Abdulrahim Al-Haddad Trading Establishment (the "processor"). It is incorporated into the Barqia Terms of Service and accepted when they are; no separate signature is required. Subject matter: Barqia's processing of the personal data of the merchant's end-customers, to the extent needed to provide the platform. Duration: the term of the merchant's subscription. Data about the merchant's own account is data for which we are the controller; it is governed by the Privacy Policy rather than by this agreement. Nature and purpose: enabling messaging between the merchant and its customers over WhatsApp, and the inbox, campaigns, automation, reminders, support tickets and satisfaction measurement that go with it. Categories of data: mobile numbers, WhatsApp profile names, message content and attachments, order and cart data received from a connected store, and any custom fields the merchant defines. Categories of data subjects: the merchant's existing and prospective customers, and anyone who messages its number.
2. Processing on the controller's instructions
We process personal data only on your documented instructions. Your configuration of the platform — lists, campaigns, automation rules, permissions — is that instruction. We do not use your customers' data for our own purposes, to enrich another merchant's data, to train AI models, or to sell. If we consider an instruction of yours to breach the PDPL, we will tell you.
3. Confidentiality
Everyone on our side with access to your customers' data is bound by confidentiality, and access is limited to those who need it to do their job. That obligation survives the end of their employment.
4. Security measures
The measures in force today — verifiable in the product, not merely described: • Encryption of traffic in transit, and encryption of access tokens and sensitive data at rest. • Separation of every account's data from every other: each record is owned by its account, and every query on the read paths a merchant reaches is constrained to it — in application code, not by a database-level constraint. • Three independent scopes on employee permissions: which numbers, restriction to assigned conversations, and the team — and above them, masking a customer's number from a given employee. • An audit log of mutations made through the API (AuditLog), and a log of opening a customer's conversation or their phonebook card (ViewLog). Both are partial rather than exhaustive: real-time inbox operations are not written to the audit log, and other screens display an identified customer's data without being recorded. We are extending them, and we do not offer them as a complete record of everyone who looked. • Verification of every inbound message from Meta by matching the phone-number identifier against the one registered to the account, and Meta's signature where one is configured. We may update these measures provided the level of protection is not reduced. We do not include regular off-site backups on a guaranteed schedule among them: the platform supports them and monitors their state, but their regularity is an open item on our side and we will not commit to it contractually until it is settled.
5. Sub-processors
You authorise us to engage sub-processors to deliver the service. The complete, current list is published in the "Sharing & sub-processors" section of the Privacy Policy at barqia.net/privacy, stating what each one processes and when. We bind every sub-processor to protection obligations no lower than our own to you, and we remain responsible to you for their performance. We notify merchants before adding a new sub-processor, by updating the published list and by an email to the address on the account; you may object within thirty days of the notice, and you may terminate without penalty if the objection cannot be resolved.
6. Cross-border transfer
Our infrastructure and our sub-processors are outside the Kingdom today. The full detail — where the data sits, the legal basis for the transfer, the safeguards in place, and which of them are not yet complete — is in the "Cross-border transfer & safeguards" section of the Privacy Policy, which forms part of this agreement. We may not transfer data to a new recipient outside the Kingdom without notifying you under clause 5.
7. Breach notification
On a breach affecting personal data we process on your behalf, we notify you without undue delay and within 48 hours of becoming aware of it at the latest, with what we know of its nature, the categories affected, the likely impact and the steps we have taken, and we assist you in meeting the notification duty that falls on you as controller.
8. Assisting with data-subject requests
The platform lets you export and erase a customer's data yourself without waiting on us, and provides a public deletion path at barqia.net/data-deletion. If one of your customers sends a request directly to us, we refer it to you and do not answer it on your behalf except on your instruction. We also assist you, to a reasonable extent and with the information available to us, on data protection impact assessments and on any enquiry from the Saudi Data & AI Authority.
9. Deletion or return on termination
You may export your data at any time during the subscription and for thirty days after it ends. After that period we delete or anonymise your end-customers' data on your request. Closing the account from your profile page triggers deletion immediately: conversations, messages, contacts, orders, tickets, media files on disk, and the raw inbound payloads. The steps run in sequence and any step that fails is logged for manual completion, so one failure cannot strand the rest. There is no automatic deletion on expiry alone without a request from you — we say so plainly, because an expired account may be resumed and erasing its data over a late payment is not recoverable. Excepted is what the law requires us to keep and what the Privacy Policy states is retained in the data subject's own interest — such as opt-out lists, since erasing one would put a person who asked not to be messaged back on the sending list.
10. Audit and information rights
We provide the information needed to demonstrate our compliance with this agreement, answer one written security questionnaire per year, and answer an additional one after any breach that affects you. This agreement does not include a right to inspect our premises or systems on site. For anything about this agreement, or to request a countersigned copy: support@barqia.net.
Measurement choices
You can review or withdraw your choice at any time — it does not affect your use of the platform.