Data Processing Agreement (Waqi)
Last updated: 13 August 2026 · Draft pending legal counsel review — not yet a signed or signable agreement.
This Data Processing Agreement (“DPA”) describes how Bilazann (“Waqi”, “we”, “Processor”) handles personal data on behalf of a customer (“you”, “Controller”) when you use Waqi to connect an AI client to your business tools. It supplements our Terms of Use and Privacy Policy, and is written to satisfy UAE PDPL (Federal Decree-Law No. 45 of 2021) Article 8 and UK/EU GDPR Article 28.
1. Roles
You are the Controller of any personal data (about your own customers, employees, or others) that passes through a tool Waqi connects to on your behalf. We are the Processor, acting only on your documented instructions — which, for Waqi, means the tool calls your connected AI client makes through your Waqi link. We do not decide what data is processed or why; you do, by choosing which tools to connect and what your AI client asks of them.
2. Subject matter, nature, and duration
Subject matter: detection and redaction of sensitive/personal data in responses from tools you connect to Waqi (e.g. Stripe), before those responses reach your AI client.
Nature: automated scanning of API responses for defined categories of sensitive data (see the Waqi product page), in-memory redaction, and logging of redacted metadata only.
Duration: for as long as your Waqi account is active and a given connector remains connected. Processing of a specific tool call is momentary — see Section 5.
3. Categories of data and data subjects
Data subjects: your customers, employees, or other individuals whose personal data appears in responses from the tools you connect (e.g. a Stripe charge's customer email or name).
Categories of data: whatever categories the connected tool's API can return that fall into Waqi's detection scope — card and bank details, government IDs, email addresses, phone numbers, names in API-labelled fields, IP addresses, and API secrets. The current, exact scope (including documented gaps) is maintained at /waqi and in the product's own source, not frozen into this document, since detection coverage is expected to expand over time.
4. Processor obligations
- Process personal data only on your documented instructions (i.e. only what your connected AI client requests via your Waqi link), unless required otherwise by UAE, UK, or EU law.
- Ensure anyone processing data under our direction is bound by confidentiality.
- Implement appropriate technical and organisational security measures — see Section 5.
- Not engage a sub-processor without informing you in advance (see our published sub-processor list); we will notify active customers before adding or replacing one.
- Assist you in responding to data subject rights requests concerning data processed through Waqi, to the extent we are able given we do not retain the underlying data (Section 5).
- Notify you without undue delay if we become aware of a personal data breach affecting data processed through Waqi.
- Delete or return connector credentials and account data on termination, and confirm deletion on request (see Privacy Policy, Retention).
- Make available the information necessary to demonstrate compliance with this DPA, and allow for audits by you or an auditor you mandate, on reasonable notice.
5. How this is actually enforced, not just promised
Waqi does not store the personal data returned by a connected tool. A response is held in memory only for the duration of a single request, scanned for sensitive categories, redacted, and only the redacted result — plus metadata about what was caught — is written anywhere persistent. The full technical explanation, written to be checked against the actual source code rather than taken on trust, is at waqi.bilazann.com/security. This is why several obligations elsewhere in this DPA (return of data on termination, assistance with access requests to the underlying data) are structurally limited — there is very little of your data for us to return or search, because we don't keep it.
6. International transfers
Our sub-processors (see Privacy Policy) may process data outside the UAE. Where personal data leaves the UAE, we rely on PDPL's transfer provisions and contractual safeguards with each provider; where it involves EU/UK personal data, we rely on Standard Contractual Clauses or an equivalent adequacy mechanism with each sub-processor, to the extent applicable.
7. Liability and precedence
Liability for processing under this DPA is governed by the Terms of Use. If this DPA conflicts with the Terms on data protection matters specifically, this DPA controls.
Status of this document
This is a working draft, published so prospective customers can review our approach before it has been through formal legal counsel review. If you need a countersigned DPA for your own compliance requirements, contact info@bilazann.com.