Data Processing Agreement

Data Processing Agreement

Version 1.0, August 16, 2026

01

Parties and roles

This Data Processing Agreement (“DPA”) is between Komaa DigiTech, a company registered in the United Arab Emirates, operating the StandIn service (“Komaa”, “we”, “us”), and the customer that has accepted the StandIn Terms of Service (“you”). It forms part of the Terms of Service. For your account, billing, and usage data, Komaa acts as an independent data controller, and this DPA does not apply to that data (our Privacy Statement does). For personal data contained in the Microsoft Teams chat messages and real-time call media that StandIn relays between your Microsoft tenant and the AI agent you connect (“Tenant Relay Data”), you (or your organization) are the data controller and Komaa is your data processor. This DPA governs that processing.

02

Subject matter, duration, nature and purpose

Subject matter: the relay of Teams chat messages and real-time audio and video between your Microsoft tenant and your connected agent. Duration: for as long as you use StandIn under the Terms of Service, plus the deletion period in section 11. Nature: real-time transmission of call media through the StandIn media bridge without storage, and delivery of chat messages and inline attachments through the StandIn bot with a short-lived delivery record. Purpose: to let your AI agent take part in Teams calls and chats on your behalf, and for no other purpose. Komaa does not use Tenant Relay Data for analytics, advertising, profiling, or to train models.

03

Categories of data subjects and personal data

Data subjects: your users, employees, contractors, and guests who join Teams calls or send chat messages that involve your StandIn bot, and any other person whose data appears in those calls or messages. Personal data: display names and Teams user identifiers; the content of chat messages sent to your bot and the replies your agent sends back through it; inline attachments; and, in real time only, the voice, image (camera and screen share), and words of call participants. Special categories of data may be present in call or chat content only where your users choose to include them; you are responsible for that use. Komaa does not create voiceprints, transcripts, recordings, or biometric identifiers.

04

Processing on your instructions

Komaa will process Tenant Relay Data only on your documented instructions. Your instructions are: the Terms of Service, this DPA, and the configuration you set in the StandIn portal (which agent endpoint to relay to, which bot identity to use, and the features you enable). Komaa will inform you if, in its opinion, an instruction infringes applicable data protection law, and may then suspend that processing until the instruction is amended. If Komaa is required by law to process Tenant Relay Data otherwise, it will inform you before doing so unless the law prohibits that notice.

05

Confidentiality

Komaa ensures that the people it authorizes to process Tenant Relay Data are bound by written confidentiality obligations, are trained on their duties, and access that data only where strictly needed to operate, secure, or support the service. Access to production systems is limited to named engineers and is logged.

06

Security measures

Komaa implements and maintains the following technical and organizational measures. Encryption in transit: connections to StandIn use TLS 1.2 or higher; the link between StandIn and your agent is authenticated with a per-identity HMAC shared secret and uses TLS (wss/https) for deployed identities, while the Free Sandbox lets you choose a plaintext ws:// endpoint for evaluation at your own risk. Encryption at rest: databases and secrets are encrypted at rest on Microsoft Azure; bot credentials you provide are transmitted over TLS, stored server-side in the control plane, and never returned to the browser. Access control: least-privilege, managed-identity access to cloud resources, and named, logged administrative access. Network controls: private networking between the control plane and the media bridge, and default-deny policies inside the cluster. Logging and monitoring: operational logs and diagnostics are kept for up to 90 days and used to detect and respond to incidents. Data minimization and retention: real-time call media is relayed and never stored; chat delivery records are deleted about 24 hours after delivery to your agent by an hourly sweep, inline attachments expire after 15 minutes and are purged within the following hour, and conversation routing references (identifiers and service addresses, no content) are removed when the bot leaves a conversation and at the latest 180 days after the last activity; account data is deleted or anonymized within 90 days of account closure. Resilience: the service runs on managed Microsoft Azure infrastructure. Komaa may update these measures over time provided the overall level of protection is not reduced.

07

Sub-processors

You authorize Komaa to engage the following sub-processors for Tenant Relay Data: Microsoft (Azure hosting in the United States, West US 2, operational logging, and Microsoft Teams and Graph, which is also your own platform provider). The following sub-processors do not receive Tenant Relay Data but support the service you use with it: Paddle (payments, as Merchant of Record); Google (product analytics, and sign-in if you choose Google); GitHub (sign-in only, if you choose GitHub); and Cloudflare (web analytics). Komaa will give you at least 30 days’ notice, by email or in-product notice and by updating our Privacy Statement, before adding or replacing a sub-processor for Tenant Relay Data. If you object on reasonable data protection grounds and no resolution is found, you may terminate the affected service and receive a pro-rata refund of any prepaid fees for the remaining term. Komaa imposes data protection obligations on its sub-processors that are no less protective than this DPA and remains responsible for their performance. Your own AI agent and model providers are chosen and controlled by you and are not sub-processors of Komaa.

08

International transfers

StandIn runs in Microsoft Azure in the United States (West US 2). Tenant Relay Data transits, and chat delivery records are briefly held, in that region. Where the transfer of personal data from the European Economic Area, the United Kingdom, Switzerland, or another jurisdiction with transfer restrictions requires a safeguard, the parties rely on the European Commission’s Standard Contractual Clauses (module two, controller to processor) and, where applicable, the UK International Data Transfer Addendum, which are incorporated into this DPA by reference, together with the security measures in section 6. Where the UAE Personal Data Protection Law or another law requires a specific transfer mechanism, Komaa will cooperate with you to put it in place. Dedicated or in-region deployment is available as part of an Enterprise engagement.

09

Assistance with data-subject rights and compliance

Taking into account the nature of the processing, Komaa will assist you with appropriate technical and organizational measures to respond to requests from data subjects to exercise their rights (access, correction, deletion, restriction, portability, and objection). Because Tenant Relay Data is not stored beyond the short delivery window, such requests will normally be fulfilled by you within your own Microsoft tenant and your agent; where a request reaches Komaa directly, Komaa will refer it to you without undue delay and will not respond to it except on your instruction or as required by law. Komaa will also provide reasonable assistance, at your cost where the effort is material, with your data protection impact assessments and prior consultations with supervisory authorities, to the extent they relate to StandIn.

10

Personal data breach notification

Komaa will notify you without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting Tenant Relay Data. The notice will describe, so far as known, the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address it, and will be followed by updates as more information becomes available. Notice will be sent to the email address on your account. Komaa will cooperate with you and take reasonable steps to contain and remedy the breach.

11

Deletion and return at the end of the service

Real-time call media is never stored, so there is nothing to return. Chat delivery records and inline attachments are deleted automatically (about 24 hours after delivery, and 15 minutes plus the following hourly sweep, respectively), conversation routing references when the bot is removed and at the latest 180 days after the last activity, and in any case all of them within 90 days after the end of the service. Your bot configuration and account data are deleted or anonymized within 90 days after account closure, subject to any records Komaa is required to retain by law (such as billing records under UAE tax and accounting law), which remain protected under this DPA for as long as they are held. On request before deletion, Komaa will provide an export of the configuration data it holds for your account.

12

Audits and information

Komaa will make available to you the information reasonably necessary to demonstrate compliance with this DPA, including summaries of its security measures and, where available, third-party reports. Once in any twelve-month period, and additionally after a personal data breach affecting your data, you (or an independent auditor you appoint that is bound by confidentiality and is not a competitor of Komaa) may audit Komaa’s compliance with this DPA on at least 30 days’ written notice, during business hours, in a way that does not unreasonably disrupt the service or expose other customers’ data. Audits are at your cost, including Komaa’s reasonable time and expenses where the audit exceeds one business day. Where a supervisory authority requires an audit, the parties will cooperate in good faith.

13

Liability

Each party’s liability under or in connection with this DPA is subject to the disclaimers, exclusions, and limitation of liability in the StandIn Terms of Service, and any liability under this DPA counts towards, and does not add to, the aggregate cap set out there. Nothing in this DPA limits liability that cannot be limited under applicable law.

14

Governing law and jurisdiction

This DPA is governed by the laws of the United Arab Emirates, and the courts of Dubai have exclusive jurisdiction, without regard to conflict-of-laws rules, except that where the Standard Contractual Clauses apply, their own governing law and forum provisions govern the clauses themselves to the extent required.

15

Term, changes and precedence

This DPA applies for as long as Komaa processes Tenant Relay Data for you and until that data is deleted under section 11. Komaa may update this DPA from time to time; for material changes, Komaa will give at least 30 days’ notice as described in the Terms of Service and post the new version with a new version number and date. In case of conflict, this DPA prevails over the Terms of Service for the processing of Tenant Relay Data, and the Standard Contractual Clauses (where they apply) prevail over this DPA.

16

How to execute this agreement

This DPA, as published at standin.komaa.com/dpa, applies to all business customers by reference from the Terms of Service and the Privacy Statement, and no signature is required for it to take effect. If your organization needs a signed copy, download or print this page, complete your organization’s name, address, and authorized signatory, sign it, and send it to supportkomaa.com; Komaa will countersign and return it. Any change to the text requires Komaa’s written agreement.

17

Contact

Questions about this DPA and data protection requests: supportkomaa.com. Operated by Komaa DigiTech.