Sandooqصندوق

Data Processing Addendum

Last updated: 4 August 2026

1. Purpose and status of this document

This Data Processing Addendum (“DPA”) summarizes how Xische FZ-LLC, trading as Sandooq (“Processor”, “we”), processes personal data on behalf of a business customer (“Controller”, “Customer”) using the Sandooq service (the “Service”).

This page is a plain-language summary for business customers evaluating Sandooq. A full, signable DPA is available on request for customers who require one, executed alongside the Terms of Service; in case of conflict, the executed DPA will prevail over this summary.

2. Roles of the parties

PartyRole
Customer (the business using Sandooq)Data Controller for its own staff and business data (e.g. driver names, expense records, uploaded receipts)
Sandooq / Xische FZ-LLCData Processor, acting only on the Customer's documented instructions to provide the Service
Simply put:Your business decides what data goes into Sandooq and why. We just process it to run the service for you. We don't use it for our own purposes.

3. Scope and nature of processing

  • Categories of data subjects: the Customer's staff/users (owners, admins, accountants, drivers/field staff) and, incidentally, any individuals named or shown in uploaded receipts.
  • Categories of personal data: names and email addresses, role assignments, company information, expense and cash-float records, uploaded receipts/documents, and usage/log data.
  • Nature and purpose of processing: storage, display, and processing of the above data solely to provide the petty-cash and expense-tracking Service (account authentication, recording transactions, generating exports, sending transactional emails, and related support).
  • Duration: for as long as the Customer maintains an active subscription, plus the post-termination retention period described in Section 9 below.

4. Sub-processors

We use the following sub-processors to provide the Service. Each is bound by a contract requiring data protection obligations no less protective than those in this DPA:

Sub-processorPurposeLocation / notes
SupabaseDatabase hosting, authentication infrastructurePostgres database; data region currently Mumbai (ap-south-1)
VercelApplication and website hosting / CDNGlobal edge network; no persistent storage of Customer Data
StripeSubscription billing and payment processingPCI-DSS certified; handles payment card data directly. Sandooq never receives or stores full card numbers
ResendTransactional email delivery (OTP codes, notices, exports)Processes recipient email address and message content

We will provide at least 30 days' prior notice before adding or replacing a sub-processor that handles Customer Data, and you may object by emailing support@sandooq.ae.

5. Security measures

Sandooq applies the following technical and organizational measures:

  • Encryption of data at rest using AES-256.
  • Encryption of data in transit using TLS.
  • Tenant isolation via database-level row-level security (RLS), so each Customer's data is logically separated from every other Customer's.
  • Role-based access control within each Customer's account (owner, admin, accountant, driver).
  • Restricted internal access to production data, limited to authorized personnel on a need-to-know basis.
  • No storage of payment card data. Subscription payments are processed entirely by Stripe.

We are working toward independent certifications such as SOC 2 and ISO 27001; we do not currently hold these certifications.

6. International data transfers

Processing Customer Data may involve transfers outside the UAE, including to India (Supabase's current hosting region), the United States, and/or the European Union, depending on the sub-processor. Where we transfer personal data across borders, we rely on appropriate contractual safeguards with our sub-processors, including standard contractual clauses where applicable.

7. Assistance with data subject requests

Where the Customer receives a request from one of its staff or another data subject to access, correct, delete, or export their personal data, we will provide reasonable assistance to help the Customer respond, including through in-Service export tools where available.

8. Personal data breach notification

If we become aware of a personal data breach affecting Customer Data, we will notify the Customer without undue delay and, where feasible, within 72 hours of becoming aware, and provide information reasonably available to us to help the Customer meet its own notification obligations.

9. Deletion or return of data on termination

On termination or expiry of the Customer's subscription, the Customer may export its Customer Data for 30 days. After that period, Customer Data will be deleted or anonymized from production systems within 30 days, except where retention is required by law (e.g. accounting/tax records) or remains in backups until rotated out.

10. Confidentiality

Personnel authorized to process Customer Data are bound by confidentiality obligations, whether contractual or statutory, and access is limited to what is necessary to provide the Service.

11. Audit

On reasonable prior notice, and no more than once in any 12-month period, we will make available information reasonably necessary to demonstrate compliance with this DPA, such as summaries of our security practices or any available third-party reports. We do not offer on-site audits.

12. Liability

Liability under this DPA is subject to the limitation of liability set out in our Terms of Service, unless a separately executed DPA states otherwise.

13. Contact

To request a signed copy of a full DPA, or with questions about this summary, contact: