Legal agreement

Data Processing Agreement

Standard terms governing how eMaaree processes personal data on behalf of business customers using the platform.

Published version

Effective August 29, 2026

Request an executable copy if your organization requires signatures or additional local terms.

This page is the standard public DPA, not a representation of regulatory certification. Contract-specific terms must be confirmed through an authorized agreement with eMaaree.

1. Scope and application

This Data Processing Agreement (“DPA”) applies when eMaaree processes personal data on behalf of a business customer in connection with the eMaaree services. It supplements the Terms of Service, subscription agreement, order form, or other written agreement between the customer and eMaaree (the “Agreement”).

The customer acts as controller or business responsible for the personal data it places in eMaaree. eMaaree acts as processor or service provider for that data, except where eMaaree independently determines a purpose and means of processing as described in the Privacy Policy.

2. Processing details

Processing continues for the term of the Agreement and any limited period needed to return, secure, or delete data in accordance with the Agreement and applicable law.

  • Subject matter: providing, securing, supporting, maintaining, and improving the contracted eMaaree services.
  • Nature of processing: collection, organization, storage, retrieval, transmission, calculation, reporting, synchronization, export, restriction, and deletion.
  • Purposes: operating retail, wholesale, inventory, customer, supplier, employee, payroll, cash, accounting, reporting, and related customer-configured workflows.
  • Data subjects may include customers, suppliers, employees, contractors, users, business contacts, and people represented in transaction records.
  • Data may include identity and contact details, employment records, transaction data, account balances, payment references, device information, and other information submitted by the customer.

3. Customer instructions

eMaaree will process customer personal data only on documented instructions from the customer, including instructions expressed through configuration and use of the services, unless applicable law requires otherwise. If legally permitted, eMaaree will inform the customer before processing required by law.

The customer is responsible for ensuring its instructions and use of eMaaree comply with applicable law, and that it has an appropriate legal basis to collect and provide the personal data.

4. Confidentiality and personnel

eMaaree will ensure that people authorized to process customer personal data are subject to appropriate confidentiality obligations and receive access only where needed for their responsibilities.

Support access to a customer workspace must be limited to legitimate support, security, maintenance, or legal needs and may be recorded where supported by the service.

5. Security measures

eMaaree will maintain reasonable technical and organizational measures appropriate to the nature of the service and the risks presented by processing. Measures may evolve as the platform, threats, and available safeguards change.

  • Authentication, session protection, multi-factor authentication capabilities, and secure credential handling.
  • Role-based permissions and server-side authorization controls.
  • Logical separation of customer workspaces and scoped access to business records.
  • Audit logging and approval controls for supported sensitive actions.
  • Protected transport, production configuration, monitoring, maintenance, and incident handling.
  • Safeguards for supported offline workflows, synchronization, exports, and document verification.

6. Subprocessors

The customer authorizes eMaaree to use subprocessors to provide infrastructure, communications, payments, document generation, monitoring, support, and other necessary service functions. eMaaree remains responsible for requiring subprocessors to protect customer personal data consistently with their assigned processing.

Information about material subprocessors may be requested through support@emaaree.com. Where required by an applicable agreement or law, eMaaree will provide reasonable notice of material changes and a process for the customer to raise a substantiated data-protection objection.

7. Data-subject requests

The customer is responsible for responding to requests from people exercising privacy rights relating to customer-controlled data. Taking into account the nature of processing, eMaaree will provide reasonable assistance through available product controls or support where the customer cannot complete a valid request independently.

If eMaaree receives a request relating to customer-controlled data, eMaaree may direct the requester to the customer unless law prevents it.

8. Personal-data incidents

eMaaree will notify the customer without undue delay after confirming a personal-data breach affecting customer personal data where notification is required. Notice will include available information reasonably needed for the customer to understand the nature and likely consequences of the event and the measures taken or proposed.

Notification does not constitute an admission of fault or liability. The customer remains responsible for its own regulatory and data-subject notifications unless applicable law provides otherwise.

9. Compliance assistance

Considering the nature of processing and information available to eMaaree, eMaaree will provide reasonable assistance with security assessments, data-protection impact assessments, regulator consultations, and evidence of compliance where legally required and relevant to the services.

The parties will agree in advance on the scope, timing, confidentiality, and reasonable costs of assistance that goes beyond standard product functionality or documentation.

10. Return and deletion

During the subscription, the customer may use supported export and deletion tools. Following termination, eMaaree will delete or return customer personal data in accordance with the Agreement, product capabilities, retention schedules, backup cycles, and applicable legal obligations.

eMaaree may retain information where required by law or where it has been irreversibly de-identified. Retained personal data remains protected by this DPA for as long as it is held.

11. International transfers

eMaaree may process data in countries where eMaaree or its subprocessors operate. Where applicable law requires a transfer mechanism or additional safeguards, the parties will cooperate to implement an appropriate mechanism through the Agreement, an addendum, or another legally recognized arrangement.

12. Information and audits

eMaaree will make reasonably necessary information available to demonstrate compliance with this DPA. Where that information is insufficient and applicable law requires an audit, the customer may request a proportionate audit subject to advance notice, confidentiality, security restrictions, avoidance of disruption, and reasonable cost allocation.

Audits must not expose information belonging to another customer, compromise platform security, or require disclosure of information protected by law or third-party confidentiality duties.

13. Precedence and liability

If this DPA conflicts with the Agreement on the processing of customer personal data, this DPA controls to the extent of that conflict. All other contractual limitations, exclusions, governing-law provisions, and dispute terms in the Agreement continue to apply unless prohibited by applicable law.

14. Execution and contact

This published DPA describes eMaaree’s standard processing terms. It becomes contractually binding when incorporated into an executed order form or agreement, accepted through an authorized eMaaree contracting process, or otherwise agreed in writing by both parties.

To request an executable copy, discuss local requirements, or ask a data-protection question, contact support@emaaree.com.

Need to execute this DPA?

Send your business name, authorized contact, and any required local addendum.

Contact legal