Data Processing Addendum between Customer and BarmajTek
Data Controller
[Customer business name]
Represented by: [name]
Address: [address]
Email: [email]
Processor
BarmajTek
Trade name: BarmajTek
Represented by: BarmajTek
Email: info@barmajtek.com
1. Definitions
- Personal data
- Any data relating to an identified or identifiable natural person, processed by the processor on behalf of the controller.
- Controller
- The Customer, who determines the purposes and means of processing.
- Processor
- BarmajTek, which processes the data on behalf of and under the instructions of the controller.
- Sub-processor
- A third party engaged by the processor to carry out specific processing activities.
- Data subject
- The natural person to whom the personal data relates (patient/member/student/buyer).
2. Roles of the parties
The parties acknowledge that the controller determines the purposes and means of processing end users' personal data, and that the processor processes it solely on the controller's behalf under its documented instructions and this Addendum.
3. Scope and duration
The nature, purpose, and duration of processing, and the categories of data and data subjects, are detailed in Annex I. Processing continues for the term of the contract between the parties.
4. Processor obligations
- Process data only per the controller's documented instructions and the specified purpose.
- Not use the data for its own purposes or sell/share it for marketing.
- Ensure confidentiality of those who access the data and limit access to the minimum necessary.
- Apply the security measures set out in Annex II.
- Assist the controller in responding to data-subject requests and in impact assessments where needed.
- Notify the controller without undue delay of any confirmed data breach, within 72 hours at most of becoming aware.
- Delete or return the data per section 8 at the end of the service.
5. Controller instructions and compliance
The controller warrants that it has a legal basis to collect and transfer the data for processing and that it has obtained the necessary consents from data subjects. Its instructions must comply with the Law; if the processor considers an instruction to breach the Law, it will inform the controller.
6. Sub-processors
The controller authorises the processor to engage the sub-processors listed in Annex III, provided they are bound by data-protection obligations no less protective than those herein. The processor notifies the controller of any material change to the list and allows reasonable objection.
7. Data-subject rights
The processor assists the controller — by reasonable technical and organisational means — in responding to data-subject requests (access, rectification, erasure, objection). If the processor receives a request directly from a data subject, it refers it to the controller.
8. Deletion and return of data
At the end of the service, the processor enables the controller to export its data (Excel/CSV) and deletes or returns the data within 30 days of the request, unless the Law requires retention. Backups are deleted within the normal deletion cycle.
9. Audit
On reasonable request and at most once per year, the processor provides the controller with the information needed to demonstrate compliance, while protecting other customers' confidentiality and system security.
10. International transfers
Where data is processed or stored outside Jordan via sub-processors, the processor applies appropriate safeguards consistent with the Law.
11. Liability and governing law
The parties' liability is subject to the limits agreed in the main contract. This Addendum is governed by the laws of the Hashemite Kingdom of Jordan, and the courts of Amman have jurisdiction over any dispute.
Annex I — Details of processing
| Subject matter | Operating the BarmajTek platform to manage the controller's business. |
| Nature of processing | Storage, organisation, retrieval, display, backup, transmission (notifications). |
| Purpose | Providing management services (appointments, records, invoices, reminders) to the controller. |
| Duration | Term of the contract + deletion/return period (30 days). |
| Categories of data subjects | The controller's end users: [patients / members / students / buyers], and staff. |
| Categories of data | Name, phone, email, booking/membership data, billing data, and [sensitive data if any]. |
Annex II — Security measures
- Encryption of data in transit (TLS) and hashing of passwords.
- Per-customer data isolation (tenant isolation) and role-based access controls (RLS).
- Regular backups, security monitoring, and event logging.
- Least-privilege access reviews.
- Incident-response plan including 72-hour breach notification.
Annex III — Sub-processors
| Provider | Purpose |
|---|---|
| Cloud hosting provider [name] | Hosting, running the platform, and backups. |
| WhatsApp messaging provider [name] | Sending notifications, reminders, and codes. |
| CliQ payment channel / bank | Processing payments (subscriptions and invoices). |
| JoFotara / ISTD | Issuing official tax invoices. |
| Email/analytics provider [name] | Sending messages and measuring performance. |
[Customer business name]
Signature & date · Stamp
BarmajTek
Signature & date