This Data Processing Addendum ("DPA") forms part of the Terms of Service between Capital Placement Ltd trading as Reena ("Processor" or "Reena") and the Customer identified in the Order Form ("Controller" or "Customer").
1. Definitions and Interpretation
The terms "Personal Data", "Controller", "Processor", "Processing", "Special Category Data", and "Personal Data Breach" shall have the meanings given in Applicable Data Protection Law.
"Applicable Data Protection Law" means all laws and regulations relating to the processing of Personal Data applicable to a Party's performance under this DPA, including where applicable:
- The UK GDPR and UK Data Protection Act 2018
- The EU GDPR (Regulation 2016/679)
- The Personal Data Protection Act 2012 of Singapore
- The Personal Data Protection Act, No. 9 of 2022 of Sri Lanka, as amended by the Personal Data Protection (Amendment) Act, No. 22 of 2025
- The Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data of the United Arab Emirates
- Any other applicable national data protection laws
Where specific jurisdictional variations or clarifications apply, these are set out in Schedule 4 (Jurisdiction-Specific Terms).
"Customer Personal Data" means Personal Data that Customer uploads to or collects through the Services, including Candidate Data.
All other capitalised terms not defined herein shall have the meanings given in the Principal Agreement.
2. Scope and Roles
The Parties acknowledge that with regard to the Processing of Customer Personal Data, Customer is the Controller and Reena is the Processor.
Customer shall:
- Ensure that its instructions for the Processing of Customer Personal Data comply with Applicable Data Protection Law
- Ensure it has all necessary lawful bases and has obtained all consents and authorisations necessary for the Processing of Customer Personal Data
- Ensure the accuracy of all Customer Personal Data and any Processing instructions
- Be solely responsible for determining the lawfulness of Processing including for Special Category Data
- Inform Reena if Processing instructions infringe Applicable Data Protection Law
3. Processing Obligations
Reena shall Process Customer Personal Data only on Customer's documented instructions as set out in this DPA, the Principal Agreement, via the Services' features, or as otherwise agreed in writing, unless required by law to Process Customer Personal Data otherwise, in which case Reena shall inform Customer unless legally prohibited.
Reena shall:
- Ensure that personnel Processing Customer Personal Data are subject to appropriate confidentiality obligations
- Ensure personnel receive appropriate training on data protection
- Process Customer Personal Data only as necessary to provide the Services
- Not sell Customer Personal Data or Process it for Reena's own purposes or any purposes other than providing the Services
4. Security Measures
Reena shall implement and maintain appropriate technical and organisational measures to protect Customer Personal Data against unauthorised access, use, disclosure, alteration, or destruction.
Reena maintains ISO/IEC 27001:2022 certification for its information security management system and shall maintain such certification or equivalent industry standard throughout the term of the Principal Agreement.
Reena reserves the right to update or modify its security measures from time to time provided that such updates do not materially decrease the overall protection of Customer Personal Data, and will maintain industry‑standard security practices appropriate to the nature of the Services.
5. Sub‑processors
Customer generally authorises Reena to engage Sub‑processors to Process Customer Personal Data, subject to appropriate safeguards. The Sub‑processors currently engaged by Reena are listed in Schedule 3, and Customer consents to the use of these Sub‑processors.
Reena shall:
- Enter into written agreements with Sub‑processors imposing data protection obligations materially similar to those in this DPA
- Ensure all critical Sub‑processors maintain appropriate certifications (SOC 2, ISO 27001, or equivalent) and demonstrate GDPR compliance
- Apply ISO 27001 standards for Sub‑processor selection, monitoring, and management
- Perform appropriate due diligence before engaging any Sub‑processor including security assessment and certification verification
- Remain fully liable for Sub‑processors' performance
Changes to Sub‑processors
Changes to Sub‑processors may be made by Reena providing Customer reasonable advance notice, typically fourteen days, via email to Customer's administrators or through the Services.
- For immaterial changes such as corporate rebranding or intra‑group reorganisations, updates may be made with shorter notice
- Emergency replacements necessary for security, legal compliance, or service continuity may be made immediately with subsequent notice
Customer may object to material Sub‑processor changes on reasonable data protection grounds within seven days of notice. If Reena cannot reasonably accommodate the objection, Customer may terminate the affected Services as its sole remedy with a pro‑rata refund for any prepaid fees.
6. Data Subject Rights
Where technically feasible and commercially reasonable, Reena shall assist Customer in responding to Data Subject requests through the Services' built‑in features and standard export functionality.
Where Reena receives a request directly from a Data Subject, it shall promptly forward it to Customer unless legally prohibited.
Additional assistance beyond standard features may be subject to Reena's professional services rates.
Reena shall provide Customer the ability to export Customer Personal Data in a structured, commonly used, and machine‑readable format via the Services' standard export features.
7. Security Incidents and Breaches
Reena shall notify Customer without undue delay and in any event within seventy‑two hours after becoming aware of a Personal Data Breach affecting Customer Personal Data.
Such notification shall include available information about:
- The nature, scope, and potential impact of the breach
Reena shall:
- Cooperate with Customer and take reasonable commercial steps to assist in the investigation, mitigation, and remediation of any Personal Data Breach
- Maintain records of all Security Incidents and provide reports to Customer upon reasonable request
8. Compliance Assistance
Upon Customer's reasonable request and where technically feasible, Reena shall provide assistance with data protection impact assessments and supervisory authority consultations through:
- Providing relevant security documentation
- Completing reasonable questionnaires with limited frequency
- Making available information about the Services' data protection features
Such assistance shall be provided at Reena's then‑current professional services rates unless included in Customer's subscription plan.
9. International Data Transfers
Customer acknowledges that Reena may Process Customer Personal Data in the following locations:
- United Arab Emirates
- United Kingdom
- European Union (including the Netherlands)
- United States, for certain AI processing operations, email delivery and error monitoring
- Sri Lanka, for SMS notifications to candidates and for support provided by Reena personnel
and in any other location notified to Customer under Section 5 (Changes to Sub‑processors).
Primary hosting region. Unless agreed otherwise with Customer, Customer Personal Data is stored in Microsoft Azure in the UAE, primarily in the UAE North (Dubai) region, and is mainly processed there. AI processing takes place mainly in the UAE, the United Kingdom and the European Union, with some AI services hosted in the United States. Outside the primary hosting region, Customer Personal Data is processed only by the Sub-processors listed in Schedule 3 and by Reena personnel providing support and maintenance.
For customers requiring data residency in Saudi Arabia, dedicated infrastructure is available subject to enterprise agreements.
Safeguards for International Transfers
Where Customer Personal Data is transferred internationally, appropriate safeguards apply:
For UK and EEA originating data:
- UK International Data Transfer Agreement (UK IDTA) or UK Addendum to EU SCCs for UK data
- EU Standard Contractual Clauses Module 2 for EEA data
- Incorporated herein by reference where applicable
For all international transfers:
- Encryption in transit using TLS 1.2 or higher and at rest using AES‑256
- Access controls and authentication measures
- Security measures as described in Schedule 2
- Compliance with applicable local data protection laws
Reena has conducted transfer risk assessments and implemented appropriate supplementary measures. Customer acknowledges these assessments and agrees that the safeguards are appropriate for their data transfers.
Enterprise customers may request specific data residency arrangements subject to additional fees and technical feasibility.
10. Audit Rights
Customer may verify Reena's compliance with this DPA through reviewing Reena's ISO 27001 certificate, which demonstrates comprehensive security controls and regular independent auditing. Reena will provide its current ISO 27001 certificate upon reasonable request and may also provide executive summaries of recent penetration testing or other security assessments where available.
Additional Assurance
For customers requiring additional assurance, Reena will complete reasonable security questionnaires, limited to once per year unless following a Security Incident. Responses may reference existing documentation where appropriate to avoid duplicative efforts.
Enterprise Audit Provisions
Enterprise customers with specific contractual audit provisions may arrange additional review procedures as agreed in their Order Form. Any such reviews shall be subject to:
- Reasonable advance notice
- Execution of Reena's confidentiality agreement
- Reasonable cost reimbursement for extensive time requirements
- Shall not unreasonably interfere with Reena's operations or compromise the security or confidentiality of other customers' data
Cloud Infrastructure
Customer acknowledges that as Reena utilises managed cloud infrastructure from Azure and Google Cloud, physical data centre inspections are neither applicable nor necessary. The cloud providers' certifications including SOC 2, ISO 27001, and other industry standards provide appropriate infrastructure assurance, and Reena's ISO 27001 certification covers the application layer controls.
11. Data Return and Deletion
Customer may export Customer Personal Data at any time during the term via the Services' export features.
Following termination of the Principal Agreement:
- Reena shall provide a sixty‑day period for Customer to export Customer Personal Data
- After such period, Reena shall delete Customer Personal Data from active systems within 30 days, and from backups on their standard rotation schedule within 90 days
- Reena may retain Customer Personal Data as required by law, subject to continuing confidentiality
- Upon request, Reena shall provide written certification of deletion
Retention During the Term
Customer determines how long Customer Personal Data is kept. On Customer's written request, Reena shall set up an automatic deletion period for candidate data in Customer's account. When that period ends, Reena shall delete the relevant Customer Personal Data from active systems within 30 days, and from backups on their standard rotation schedule within 90 days. Customer may also delete individual records at any time. Copies that Customer's users download or export from the Services are outside Reena's control and are Customer's responsibility.
12. Special Category Data
Where Customer uploads Special Category Data as defined in UK GDPR Article 9, Customer warrants that:
- It has a valid lawful basis under Article 6 and meets a condition under Article 9 of UK GDPR
- Such Processing is necessary for employment law purposes, equality monitoring, or other permitted purposes under Applicable Data Protection Law
- It has implemented appropriate safeguards
For Special Category Data, Reena implements enhanced access controls and audit logging.
Customer acknowledges that Special Category Data is logically segregated within the multi‑tenant database architecture.
13. Liability
The liability provisions of the Principal Agreement apply to this DPA.
Each Party's liability for data protection breaches shall be subject to the limitations set forth in the Principal Agreement.
Reena maintains appropriate measures to address potential security incidents, including incident response procedures and financial provisions for breach‑related obligations.
14. Term and Updates
This DPA shall remain in effect for the duration of the Principal Agreement. Obligations relating to security, confidentiality, and data deletion shall survive termination.
In case of conflict between this DPA and the Principal Agreement regarding data protection matters, this DPA prevails.
Updates to this DPA
Reena may update this DPA from time to time to reflect:
- Changes in Applicable Data Protection Law
- Security improvements
- Operational requirements
For active customers:
- Material changes that reduce Customer's rights or protections will require consent or will take effect at the next renewal
- Updates required by law may take effect immediately with notice
- Non‑material updates such as clarifications or enhanced protections may be made with reasonable notice
The current version will be available on Reena's website or upon request.
15. Governing Law
This DPA is governed by the laws of England and Wales.
If any provision is invalid, the remainder continues in effect.
16. AI Processing
Where Customer uses Reena's AI‑powered features (including but not limited to AI‑assisted interview analysis, scoring, or candidate evaluation), the following terms apply in addition to the general processing terms above:
Roles and Responsibilities
Customer is the data controller and retains full decision‑making authority regarding candidate selection, hiring decisions, and employment actions. Reena provides AI tools to assist Customer's personnel but does not make decisions on Customer's behalf.
AI Sub-processors
Customer acknowledges that AI processing may involve sending Customer Personal Data to specialised AI sub‑processors identified in Schedule 3, including:
- Microsoft Azure AI (processing in UAE, UK, European Union and US regions)
- OpenAI
- Anthropic
- AssemblyAI (speech-to-text for AI interviews)
Such sub-processors may process data outside the UK/EEA. Such transfers are protected by appropriate safeguards as set out in Section 9 of this DPA.
Customer Responsibilities for AI Processing
Customer is responsible for:
- Ensuring compliance with GDPR Article 22 requirements regarding automated decision‑making
- Configuring appropriate human review and validation of all AI outputs before making decisions that produce legal or similarly significant effects
- Obtaining all necessary consents from data subjects for AI processing of their personal data
- Ensuring that AI‑assisted processes do not result in unlawful discrimination
- Informing data subjects that AI technology is being used and their right to object under applicable data protection law
Limitations
Reena does not make hiring, employment, or other decisions on behalf of Customer. AI outputs may contain errors or bias, and Reena does not warrant that AI outputs are accurate, complete, or non‑discriminatory. Customer acknowledges these limitations and agrees to implement appropriate safeguards.
Schedule 1: Details of Processing
Subject Matter: Processing of Customer Personal Data in connection with Reena's provision of recruitment, HR technology and workforce management services.
Duration: For the term of the Principal Agreement plus any retention period.
Nature and Purpose: Reena Processes Customer Personal Data to provide the Services, including:
- Applicant tracking and recruitment management
- AI‑assisted interview analysis and scoring
- HR information system functions
- Performance management
- Leave and attendance management
- Onboarding and offboarding processes
- Reporting and analytics
- Integration with Customer's other systems
Categories of Data Subjects:
- Job applicants and candidates
- Customer's employees and contractors
- Customer's hiring managers and HR personnel
- Referees and emergency contacts
- Other individuals whose data Customer uploads to the Services
Categories of Personal Data:
- Identification data including name, email, phone, and address
- Professional data including CV, work history, and qualifications
- Interview data including recordings, transcripts, and assessments
- Employment data including contracts, compensation, and performance
- System data including user accounts, access logs, and communications
- Special Category Data only where Customer determines necessary for employment law compliance, equality monitoring, or other lawful purposes
Frequency of Transfer: Continuous, as necessary to provide the Services.
Schedule 2: Technical and Organisational Measures
Reena implements comprehensive security measures aligned with ISO/IEC 27001:2022.
Technical Measures
Reena implements:
- Encryption of Customer Personal Data in transit using TLS 1.2 or higher and at rest using AES‑256
- Multi‑factor authentication for administrator accounts
- Logical segregation of Customer data in multi‑tenant architecture
- Web application firewall and DDoS protection
- Vulnerability scanning and patch management
- Security logging and monitoring with automated alerting
- Backup and disaster recovery procedures with defined RTOs and RPOs
- Annual independent penetration testing
Organisational Measures
Reena maintains:
- Information security policies and procedures
- Security awareness training for all personnel
- Access control on least‑privilege and need‑to‑know basis
- Confidentiality agreements with all personnel
- Vendor security assessment programme
- Incident response procedures
- Change management controls
- Regular security reviews and updates
Physical Security
Data centres maintain:
- 24/7 security with biometric access controls and CCTV
- Environmental controls including fire suppression, climate control, and power redundancy
- Secure disposal of hardware and media
Compliance
Reena:
- Maintains ISO/IEC 27001:2022 certification
- Conducts regular internal and external audits
- Applies privacy by design and by default principles
- Conducts Data Protection Impact Assessments where appropriate
Schedule 3: Sub‑processors
Critical Sub‑processors listed below maintain appropriate certifications (SOC 2 Type II, ISO 27001, or equivalent) and demonstrate GDPR compliance:
Cloud Infrastructure
Microsoft Azure: Cloud infrastructure and AI services, processing in UAE, UK, European Union (including the Netherlands), Saudi Arabia and US. Certifications: ISO 27001, SOC 2, CSA STAR.
Google Cloud Platform: Cloud infrastructure and regional storage, processing in UK and Saudi Arabia. Certifications: ISO 27001, SOC 2, CSA STAR.
AI/ML Processing
Microsoft Azure AI: AI/ML processing services, processing in UAE, UK, European Union and US regions. Certifications: ISO 27001, SOC 2 (via Azure).
OpenAI: AI/ML processing for interview analysis, processing in US, UK and European Union. Certifications: SOC 2 Type II.
Anthropic: AI/ML processing for interview analysis, processing in US, UK and European Union. Certifications: SOC 2 Type II.
AssemblyAI: Speech-to-text for AI interviews, processing in the United States and the European Union. Each request is routed to the nearest available AssemblyAI region. AssemblyAI does not use Reena's data to train its models. Reena sets AssemblyAI to delete audio and transcripts after 30 days, which allows Reena to check transcription quality. Certifications: SOC 2 Type II, ISO 27001.
Communication Services
SendGrid: Email delivery services, processing in EU and US. Certifications: ISO 27001, SOC 2.
Azure Communication Services: Communication services, processing in UK and UAE. Certifications: ISO 27001, SOC 2 (via Azure).
Monitoring
Sentry: Error monitoring services, processing in US. Certifications: SOC 2 Type II, ISO 27001.
Add-on Services
The Sub-processors below are used only for Customers who enable the relevant add-on. They do not process the data of Customers who do not use that add-on. By enabling an add-on, Customer authorises Reena to use the Sub-processor listed for it.
text.lk: SMS notifications to candidates, such as interview reminders, processing in Sri Lanka. Used only for Customers who enable SMS notifications. text.lk receives the candidate's mobile number and a short message with their first name, the role, Customer's company name and a link to the AI interview. No CVs or other application data are shared. text.lk provides its service on its published terms, which include its GDPR statement (https://text.lk/gdpr/). Customer acknowledges that the requirement in Section 5 for written agreements with obligations materially similar to this DPA applies to text.lk only to the extent its published terms allow.
Testlify: Skills assessments, hosted in the European Union (Ireland). Used only for Customers who enable the Testlify assessment module. Testlify's own sub-processors may process data in other countries, as set out in its data processing agreement: https://testlify.com/data-processing-agreement/
Notes
- Specific services may be processed in specific regions based on Customer configuration
- This list is subject to updates per Section 5 of this DPA
- Reena ensures all Sub‑processors meet appropriate compliance standards before engagement
- Schedule 3, as published at https://reenahr.com/legal/dpa, is the current list of Sub-processors.
- Where a Sub-processor uses its own suppliers, those suppliers may process data in other countries under that Sub-processor's terms.
Appendix: International Data Transfer Mechanisms
For UK/EEA Data Transfers
Where required, the following standard contractual clauses apply and are incorporated by reference:
- UK International Data Transfer Agreement (IDTA) available at ico.org.uk
- EU Standard Contractual Clauses Module 2 available at ec.europa.eu
For Other Regions
This DPA, combined with the security measures in Schedule 2 and contractual commitments herein, constitutes appropriate safeguards for international data transfers under applicable laws. Reena commits to compliance with local data protection requirements in all jurisdictions where it processes Customer Personal Data.
For Specific Jurisdictions
Where Personal Data is subject to the laws of Singapore, Sri Lanka, United Arab Emirates, or other jurisdictions with specific data protection requirements, the additional terms and clarifications set out in Schedule 4 (Jurisdiction-Specific Terms) shall apply.
In the event of any conflict between the main DPA and Schedule 4, Schedule 4 shall prevail to the extent necessary to comply with the applicable jurisdiction's requirements.
Schedule 4: Jurisdiction-Specific Terms
This Schedule 4 forms part of the Data Processing Addendum dated 4 September 2025 between Capital Placement Ltd trading as Reena ("Processor" or "Reena") and Customer ("Controller" or "Customer").
Purpose: This Schedule sets out jurisdiction-specific variations and clarifications to the DPA to ensure compliance with applicable data protection laws in the jurisdictions where Customer operates or where Customer Personal Data is processed.
Application: The provisions in this Schedule apply in addition to the main DPA. Where there is any conflict between this Schedule and the main DPA, this Schedule shall prevail to the extent necessary to comply with the applicable jurisdiction's data protection law.
1. SINGAPORE
1.1 Applicable Law
The definition of "Applicable Data Protection Law" includes the Personal Data Protection Act 2012 (No. 26 of 2012) of Singapore ("Singapore PDPA") and all regulations, codes and guidelines issued thereunder, including the Personal Data Protection Regulations 2021.
1.2 Definitions
For the purposes of processing Personal Data subject to the Singapore PDPA:
(a) The definition of "Personal Data" includes "personal data" as defined in Section 2(1) of the Singapore PDPA, meaning data, whether true or not, about an individual who can be identified from that data, or from that data and other information to which the organisation has or is likely to have access.
(b) The definition of "Processing" includes "collect", "use" and "disclose" as defined in the Singapore PDPA.
(c) The definition of "Controller" shall be read as "organisation" as defined in the Singapore PDPA.
(d) The definition of "Processor" shall be read as "data intermediary" as defined in Section 2(1) of the Singapore PDPA.
(e) The definition of "Data Subject" shall be read as "individual" as defined in the Singapore PDPA.
1.3 Regulatory Authority
The regulatory authority for Singapore is the Personal Data Protection Commission ("PDPC").
1.4 Specific Obligations
(a) Purpose Limitation: Customer acknowledges that under the Singapore PDPA, organisations may only collect, use or disclose Personal Data for purposes that a reasonable person would consider appropriate in the circumstances, and must notify individuals of such purposes.
(b) Consent: Where Customer relies on consent as the basis for Processing, Customer warrants it has obtained valid consent in accordance with the Singapore PDPA, including deemed consent where applicable.
(c) Notification of Data Breaches: In addition to Section 7 of the DPA, where Reena has reason to believe that a data breach affecting Singapore Personal Data has occurred, Reena shall notify Customer without undue delay so that Customer can assess whether the breach is notifiable. A breach is notifiable if it results in, or is likely to result in, significant harm to affected individuals, or if it is of a significant scale (500 or more individuals). Customer is responsible for notifying the PDPC no later than 3 calendar days after assessing that a breach is notifiable, and for notifying affected individuals where required.
(d) Cross-Border Transfers: Customer acknowledges that Reena may process Singapore Personal Data in the locations listed in Section 9 of the DPA. Customer confirms that such transfers are permitted under Section 26 of the Singapore PDPA on the basis that:
- Reena is bound by legally enforceable obligations to provide a standard of protection comparable to the Singapore PDPA through this DPA and applicable Standard Contractual Clauses; and
- Customer has taken appropriate steps to ensure ongoing compliance.
(e) Retention Limitation: Customer is responsible for determining retention periods for Singapore Personal Data. Reena shall cease to retain Singapore Personal Data, or remove the means by which the data can be associated with particular individuals, as soon as it is reasonable to assume that retention no longer serves the purpose for which it was collected and is no longer necessary for legal or business purposes, in accordance with Section 11 of the DPA.
1.5 Data Subject Rights
Where Customer Personal Data is subject to the Singapore PDPA:
(a) Customer acknowledges that individuals have the right to request access to and correction of their Personal Data under Sections 21 and 22 of the Singapore PDPA.
(b) Reena shall assist Customer in responding to such requests in accordance with Section 6 of the DPA.
(c) Customer may charge a reasonable fee for access requests in accordance with Section 21(4) of the Singapore PDPA, where permitted.
1.6 Do Not Call Registry
Where Customer uses the Communication Module for SMS or telephone communications to Singapore phone numbers, Customer is solely responsible for compliance with the Do Not Call Registry provisions of the Singapore PDPA (Part 9) and ensuring that individuals have provided clear and unambiguous consent to receive such communications.
2. SRI LANKA
2.1 Applicable Law
The definition of "Applicable Data Protection Law" includes the Personal Data Protection Act, No. 9 of 2022 of Sri Lanka, as amended by the Personal Data Protection (Amendment) Act, No. 22 of 2025 (together, the "Sri Lanka PDPA"). It also includes the regulations, rules and directives made under it. Each Party shall have regard to guidelines and codes of practice issued by the Authority.
2.2 Commencement
Provisions of the Sri Lanka PDPA come into operation on the dates appointed by Order published in the Gazette. The commitments Reena gives in this Section apply from the date this Schedule takes effect. Where a commitment in this Section is to comply with a provision of the Sri Lanka PDPA, or with regulations, rules or directives made under it, that commitment applies from the date the provision comes into operation.
2.3 Definitions
Terms used in this Section, including "personal data", "special categories of personal data", "controller", "processor", "data subject", "personal data breach" and "third country", have the meanings given in section 56 of the Sri Lanka PDPA. References in this DPA to Special Category Data include special categories of personal data under the Sri Lanka PDPA.
2.4 Regulatory Authority
The regulatory authority for Sri Lanka is the Data Protection Authority of Sri Lanka (the "Authority"), established under Part V of the Sri Lanka PDPA.
2.5 Data Protection Officer
(a) Section 20 of the Sri Lanka PDPA requires controllers and processors to designate or appoint a Data Protection Officer in the circumstances set out in that section and in regulations made under it. Customer is responsible for deciding whether it must appoint one and for doing so.
(b) Reena has appointed a Data Protection Officer:
- Name: Niranjan Thampu
- Contact: dpo@reenahr.com
Reena shall publish these contact details and communicate them to the Authority, as required by section 20(4).
2.6 Lawful Processing
Customer, as controller, is responsible for ensuring that each processing activity is lawful under section 5 of the Sri Lanka PDPA and the Schedules referred to in it, including any additional conditions that apply to special categories of personal data. Customer shall document the basis it relies on.
2.7 Customer's Obligations as Controller
Customer is responsible for:
(a) collecting personal data only for specified, explicit and legitimate purposes, and limiting it to what is necessary for those purposes (sections 6 and 7);
(b) keeping personal data accurate and setting retention periods (sections 8 and 9);
(c) giving data subjects the information required by section 11, including that Reena processes their data on Customer's behalf and the locations where it is processed; and
(d) maintaining its own Data Protection Management Programme under section 12.
2.8 Reena's Obligations as Processor
(a) Instructions: Reena shall process Sri Lankan personal data only on Customer's documented instructions, as set out in Section 3 of this DPA, and shall meet its obligations as a processor under section 22 of the Sri Lanka PDPA.
(b) Security: Reena's measures in Schedule 2 are designed to meet the integrity and confidentiality requirements of section 10 of the Sri Lanka PDPA.
(c) Records: Reena shall keep records of the processing it carries out on Customer's behalf. It shall give Customer the information Customer reasonably needs for its Data Protection Management Programme under section 12.
(d) Impact assessments: AI-assisted screening, scoring and interviews may amount to a systematic and extensive evaluation of personal data, including profiling. Customer is responsible for:
- deciding whether its use of these features requires a personal data protection impact assessment under section 24;
- carrying out any such assessment before processing begins; and
- taking any further steps required by section 25.
Reena shall assist in accordance with Section 8 of this DPA.
2.9 Personal Data Breach
(a) Reena shall notify Customer without undue delay, and in any event within forty-eight hours, after becoming aware of a Personal Data Breach affecting Sri Lankan personal data. Reena becomes aware of a Personal Data Breach when it has a reasonable degree of certainty that a security incident has led to Sri Lankan personal data being compromised.
(b) The notice shall include the information then available to Reena that Customer reasonably needs to notify the Authority. Where not all of that information is available, Reena shall provide it in stages, without further undue delay.
(c) Customer, as controller, is responsible for notifying the Authority under section 23 of the Sri Lanka PDPA and the rules made under it, and for notifying affected data subjects where those rules require it.
(d) Notification of a Personal Data Breach by Reena is not an admission of fault or liability.
2.10 Processing Outside Sri Lanka
(a) Hosting: For Customers in Sri Lanka, Customer Personal Data is stored in Microsoft Azure in the UAE, primarily in the UAE North (Dubai) region, and is mainly processed there. Some processing, including AI processing, email delivery, SMS notifications and support, takes place in the other locations listed in Section 9 of this DPA, through the Sub-processors listed in Schedule 3 and Reena personnel.
(b) Section 26: Reena shall process Sri Lankan personal data outside Sri Lanka only in accordance with section 26 of the Sri Lanka PDPA, as replaced by the Personal Data Protection (Amendment) Act, No. 22 of 2025. This includes complying with Part I, Part II and sections 20 to 25, to the extent they apply to Reena as processor, and adopting the instruments specified by directive of the Authority.
(c) Instruments: Until a directive of the Authority specifying instruments is in force, processing outside Sri Lanka is carried out under this DPA, including the safeguards in Section 9 and the measures in Schedule 2. When such a directive comes into force, Reena shall adopt the instruments it specifies. The Parties shall sign any documents reasonably required for that purpose.
(d) Transfer impact assessment: Reena has assessed the laws and practices of the countries where it and its Sub-processors process Sri Lankan personal data, and the safeguards in place. Reena shall review that assessment when it adds a new country or when relevant laws change. Reena shall give Customer a summary of the assessment on reasonable written request, no more than once a year.
(e) Requests from public authorities: If Reena receives a legally binding request from a public authority in any country to disclose Sri Lankan personal data, Reena shall, unless the law prohibits it:
- promptly notify Customer of the request;
- review whether the request is lawful, and challenge it where, after careful assessment, Reena concludes there are reasonable grounds to do so;
- disclose only the minimum personal data needed to comply; and
- keep a record of such requests, and give Customer a summary of them on reasonable written request.
If the law prohibits Reena from notifying Customer, Reena shall use reasonable efforts to obtain a waiver of that prohibition.
2.11 Data Subject Rights
Once Part II of the Sri Lanka PDPA is in operation, data subjects have the rights it sets out. These include access (section 13), withdrawal of consent and objection (section 14), rectification or completion (section 15), erasure (section 16) and rights relating to automated individual decision-making (section 18). Data subjects may also appeal to the Authority (section 19). Reena shall forward requests it receives and assist Customer in accordance with Section 6 of this DPA. Customer is responsible for responding within the time limits set by the Sri Lanka PDPA.
2.12 Automated Decision-Making
Where Customer uses Reena's AI features for Sri Lankan personal data, Customer must comply with section 18 of the Sri Lanka PDPA on decisions based solely on automated processing, including profiling. Customer must ensure meaningful human review of all AI-assisted decisions, as required by Reena's Acceptable Use Policy. Reena's AI features are designed to support human decision-makers and do not make decisions on Customer's behalf.
3. UNITED ARAB EMIRATES
3.1 Applicable Law
The definition of "Applicable Data Protection Law" includes:
(a) Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data ("UAE Data Protection Law")
(b) All regulations, resolutions and decisions issued by the UAE Data Office pursuant to the UAE Data Protection Law
(c) For entities operating in the Dubai International Financial Centre (DIFC), the DIFC Data Protection Law (DIFC Law No. 5 of 2020)
(d) For entities operating in the Abu Dhabi Global Market (ADGM), the ADGM Data Protection Regulations 2021
3.2 Definitions
For the purposes of processing Personal Data subject to UAE data protection law:
(a) The definition of "Personal Data" includes "personal data" as defined in Article 1 of the UAE Data Protection Law, meaning any data that leads to the identification of an individual or makes their identification possible by any means.
(b) The definition of "Sensitive Personal Data" or "Special Category Data" includes "sensitive personal data" as defined in Article 1, meaning:
- Data relating to race, ethnic origin, political opinions, or religious or philosophical beliefs
- Biometric data, genetic data, or health data
- Data relating to criminal convictions or offences
- Financial data
- Location data
- Data of minors
- Any other category prescribed by the Executive Regulations
(c) The definition of "Controller" shall be read as "data controller" as defined in the UAE Data Protection Law.
(d) The definition of "Processor" shall be read as "data processor" as defined in the UAE Data Protection Law.
3.3 Regulatory Authority
The regulatory authority is the UAE Data Office, referred to in the UAE Data Protection Law as the Bureau.
3.4 Data Processing in the UAE
Customer acknowledges that:
(a) Reena processes Customer Personal Data using Microsoft Azure UAE North (Dubai) and Azure UAE Central (Abu Dhabi) data centres
(b) For certain AI processing operations, data may be processed in other locations as set out in Section 9 of the DPA
3.5 Specific Obligations
(a) Lawful Basis: Customer acknowledges that under the UAE Data Protection Law, processing requires the data subject's consent unless one of the cases in Article 4 applies. The UAE Data Protection Law does not include a general legitimate interests basis.
(b) Purpose Limitation: Processing must be for specified, declared and legitimate purposes in accordance with Article 5 of the UAE Data Protection Law.
(c) Data Minimisation and Accuracy: Customer is responsible for ensuring Personal Data is adequate, relevant, limited to what is necessary, accurate and kept up to date, in accordance with Article 5.
(d) Transparency: Customer must provide data subjects with clear information about processing activities as required by Article 13 of the UAE Data Protection Law.
(e) Security: Reena's security measures in Schedule 2 are designed to comply with Article 20 of the UAE Data Protection Law, which requires appropriate technical and organisational measures to protect Personal Data.
(f) Data Breach Notification: In addition to Section 7 of the DPA, where a Personal Data breach affecting UAE Personal Data occurs:
- Reena shall notify Customer without undue delay and in any event within 72 hours
- Customer is responsible for notifying the UAE Data Office under Article 9, within the period and in the manner set by the Executive Regulations
- Customer is responsible for notifying affected data subjects where Article 9 requires it
3.6 Cross-Border Data Transfers
(a) Customer acknowledges that Reena may transfer Personal Data outside the UAE to the other locations listed in Section 9 of this DPA. These include the United Kingdom, the European Union, the United States (for certain AI processing, email delivery and error monitoring) and Sri Lanka (for SMS notifications and support).
(b) Under the UAE Data Protection Law, Personal Data may be transferred outside the UAE to a country with an adequate level of protection approved by the UAE Data Office (Article 22), or on one of the grounds set out in Article 23. The Executive Regulations, once issued, may set further controls on such transfers.
(c) Reena shall carry out transfers outside the UAE in accordance with Articles 22 and 23, and protects transferred Personal Data through this DPA, the measures in Schedule 2 and the data protection terms in Reena's written agreements with its Sub-processors.
(d) The Executive Regulations may specify additional requirements for cross-border transfers, which Customer and Reena agree to comply with.
3.7 Data Subject Rights
Where Customer Personal Data is subject to UAE data protection law, data subjects have the following rights under Chapter 3 of the UAE Data Protection Law:
(a) Right to obtain information (Article 13)
(b) Right to data portability (Article 14)
(c) Right to correction or erasure (Article 15)
(d) Right to restriction of processing (Article 16)
(e) Right to stop processing, including for direct marketing (Article 17)
(f) Right to object to decisions based on automated processing, including profiling (Article 18)
Reena shall assist Customer in responding to such requests in accordance with Section 6 of the DPA. Customer must respond within the timeframes set by the UAE Data Protection Law and its Executive Regulations.
3.8 Automated Decision-Making
Where Customer uses automated decision-making (including profiling) for UAE Personal Data, Customer must comply with Article 18 of the UAE Data Protection Law, including:
(a) Informing data subjects about the automated processing
(b) Providing data subjects with the right to human intervention
(c) Allowing data subjects to express their point of view and contest the decision
(d) Implementing suitable measures to safeguard data subject rights
3.9 Free Zones
(a) For Customers operating in DIFC or ADGM, the relevant free zone data protection laws shall apply in addition to (for DIFC) or instead of (for ADGM) the UAE Federal data protection law.
(b) Customer is responsible for determining which laws apply to their operations and ensuring compliance with the applicable regime.
(c) Reena shall cooperate with Customer to meet the requirements of the applicable free zone data protection laws.
4. GENERAL PROVISIONS
4.1 Hierarchy
In the event of any conflict or inconsistency between:
(a) This Schedule 4 and the main DPA, this Schedule 4 shall prevail to the extent necessary to comply with the specific jurisdiction's data protection law
(b) The requirements of different jurisdictions in this Schedule, each shall apply to the Personal Data subject to that jurisdiction's law
4.2 Multiple Jurisdictions
Where Customer Personal Data is subject to the laws of multiple jurisdictions:
(a) Customer and Reena shall comply with all applicable requirements
(b) Where requirements conflict, the Parties shall cooperate in good faith to determine an appropriate approach that satisfies the most protective requirements
(c) Customer may configure the Services to meet specific jurisdictional requirements where technically feasible
4.3 Updates
(a) Reena may update this Schedule 4 to reflect:
- Changes in applicable data protection laws
- Guidance or decisions from regulatory authorities
- Additional jurisdictions as Reena expands its service offerings
- Technical or operational changes to the Services
(b) Material updates that reduce Customer's rights or protections will be subject to the update provisions in Section 14 of the DPA.
(c) Non-material updates (including addition of new jurisdictions or clarifications) may be made with reasonable notice and will be posted on Reena's website.
4.4 Customer Responsibilities
Customer acknowledges and agrees that:
(a) Customer is responsible for determining which jurisdictions' data protection laws apply to its use of the Services
(b) Customer must configure the Services appropriately to meet jurisdiction-specific requirements (e.g., data residency preferences)
(c) Customer must ensure it has appropriate lawful bases for processing under all applicable laws
(d) Customer must provide appropriate privacy notices to data subjects in accordance with applicable laws
(e) Customer must implement jurisdiction-specific requirements that are within Customer's control (e.g., responding to data subject rights within prescribed timeframes)
4.5 Reena's Commitments
Reena commits to:
(a) Processing Customer Personal Data in accordance with this DPA and applicable data protection laws
(b) Maintaining security measures appropriate to the risks and in compliance with applicable requirements
(c) Assisting Customer in meeting its compliance obligations as set out in the DPA
(d) Providing Customer with information necessary to demonstrate compliance
(e) Monitoring changes to data protection laws in jurisdictions where Reena processes data and updating this Schedule 4 accordingly
4.6 Regulatory Inquiries
Where Reena receives an inquiry, investigation or enforcement action from a regulatory authority in any jurisdiction:
(a) Reena shall promptly notify Customer if the inquiry relates to Customer Personal Data
(b) Reena shall cooperate with Customer in responding to the inquiry
(c) Customer shall be responsible for responding to inquiries directed to Customer as the data controller
(d) Each Party shall bear its own costs unless otherwise agreed or required by law
4.7 Additional Jurisdictions
For jurisdictions not specifically addressed in this Schedule 4:
(a) The main DPA provisions shall apply
(b) "Applicable Data Protection Law" includes all applicable data protection laws in such jurisdictions
(c) Parties shall cooperate to implement any additional measures required by such laws
(d) Customer may request Reena to add specific jurisdiction provisions to this Schedule, subject to technical feasibility and commercial agreement
5. DEFINITIONS FOR THIS SCHEDULE
For the purposes of this Schedule 4, unless otherwise specified:
"DPA" means the Data Processing Addendum dated 4 September 2025 between Reena and Customer.
"Regulatory Authority" means the supervisory authority, data protection authority, commission or other government body responsible for enforcement of data protection law in the relevant jurisdiction.
"Data Residency" means the practice of storing and processing data within the geographical boundaries of a specific country or region.
"Standard Contractual Clauses" means the contractual clauses approved by relevant authorities for the transfer of personal data to countries that do not provide adequate protection, including:
- EU Standard Contractual Clauses (for EU/EEA transfers)
- UK International Data Transfer Agreement (UK IDTA) or UK Addendum to EU SCCs (for UK transfers)
- Any equivalent transfer mechanisms approved by other jurisdictions
"Data Localisation Requirement" means a legal requirement to store or process personal data within a specific jurisdiction.
EXECUTION
BY EXECUTING THE PRINCIPAL AGREEMENT OR ANY ORDER FORM THAT REFERENCES THIS DPA, THE PARTIES AGREE TO BE BOUND BY THIS DATA PROCESSING ADDENDUM AND ALL SCHEDULES HERETO.