ALGOZ OPSBY ALGOZ
ALGOZ OPS
Download PDF

Data Processing Agreement

Last updated 25 July 2026

This Data Processing Agreement (“DPA”) forms part of the Terms and Conditions between the Customer (controller) and ALGOZ FZ-LLC (processor) for the ALGOZ OPS platform. It reflects Article 28 of the EU GDPR and the equivalent UK GDPR, and applies where Algoz processes personal data on the Customer’s behalf.

1. Roles and scope

The Customer is the controller and Algoz is the processor of the personal data the Customer processes through the platform (the “Customer Personal Data”). Algoz processes Customer Personal Data only to provide the platform and only on the Customer’s documented instructions, including as set out in the Terms, this DPA, and the Customer’s use of the platform’s features.

2. Processor obligations

3. Confidentiality and security

Algoz keeps Customer Personal Data confidential and applies the measures described in Annex II and in the Security Overview.

4. Personal data breach

Algoz will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, with the information reasonably available to help the Customer meet its own notification duties.

5. Sub-processors

The Customer authorises Algoz to engage the sub-processors listed in Annex III. Algoz imposes data protection terms on each sub-processor no less protective than this DPA and remains responsible for their performance. Algoz will inform the Customer of intended changes to sub-processors and give the Customer a reasonable opportunity to object on reasonable data protection grounds.

6. International transfers

Where Algoz transfers Customer Personal Data outside the EEA or the UK, it relies on an appropriate transfer mechanism, such as the Standard Contractual Clauses and the UK Addendum, which are incorporated by reference where required.

7. Data subject requests

Taking into account the nature of the processing, Algoz will assist the Customer by appropriate measures to fulfil the Customer’s obligation to respond to requests to exercise data subject rights. If Algoz receives a request directly, it will advise the individual to contact the Customer and, unless legally required, will not respond itself except to confirm the request has been forwarded.

8. Return and deletion

On termination or on the Customer’s written request, Algoz will delete or return Customer Personal Data within the timelines on the Data Deletion page, and delete existing copies unless law requires storage.

9. Audits

Algoz will make available information reasonably necessary to demonstrate compliance with this DPA and, on reasonable prior notice and subject to confidentiality, allow the Customer or an independent auditor to verify compliance no more than once a year, or following a breach.

10. Liability and precedence

Liability under this DPA is subject to the limitations in the Terms. If there is a conflict on data protection matters, this DPA prevails over the Terms.

Annex I: Details of processing

ItemDetail
Subject matterProvision of the ALGOZ OPS security operations platform.
DurationThe term of the Customer’s subscription and any deletion or return period.
Nature and purposeHosting, storage, transmission and display of operational data to coordinate close protection and security operations.
Categories of data subjectsThe Customer’s operatives, directors and staff, and the principals and contacts the Customer protects or records.
Categories of personal dataIdentity and contact details, role and rank, profile photos, live and historical location, principal profiles, operational content, media and files, device and technical data, and communications metadata.
Special category dataNot required by the platform. The Customer must not enter special category data unless it has a lawful basis and has configured appropriate controls.

Annex II: Technical and organisational measures

See the Security Overview for the full description. In summary: encryption in transit (HTTPS/TLS) and at rest; identity based authentication with role based access control and per company isolation enforced by server side security rules and signed claims; least privilege administration; audit logging; secure hosting on Google Cloud and Firebase; backups with point in time recovery; security headers and content security policy; and monitoring with a defined incident response process.

Annex III: Sub-processors

Sub-processorPurposeLocation
Google LLC / Google Cloud EMEA (Firebase, Google Cloud Platform)Authentication, database, file storage, serverless functions and hostingEuropean Union and global Google Cloud regions
Mapbox, Inc.Map tiles and geocoding for the live map and toolsUnited States
Telegram (Customer’s own bot)Delivery of operational alerts to the Customer’s chosen recipientsGlobal
Hostinger International Ltd.Hosting of the marketing site and supporting automationEuropean Union
Paddle.com Market Ltd.Subscription billing and payment processing, where enabledUnited Kingdom / European Union

This list may be updated as the platform evolves. The current list is available at any time at operations.algozgroup.com/dpa or on request at ops@algozgroup.com.

ALGOZ FZ-LLC. Registered office: [Registered office address, RAKEZ, Ras Al Khaimah, United Arab Emirates , to confirm]. Trade licence 47023214. VAT/TRN 105119056700001.
Contact for privacy, data protection and deletion requests: ops@algozgroup.com. © 2026 ALGOZ FZ-LLC. All rights reserved.