Data Processing Addendum.
Effective 15 August 2026 · Skewbird Technologies FZCO · United Arab Emirates
When we build or run software for you, your customers' personal data passes through it. This addendum sets out what we may do with that data, what we must do to protect it, and what we owe you if something goes wrong. It forms part of our Terms of Service.
01. Roles: You Are the Controller
For personal data you upload to, or process through, systems we build or host for you, you are the controller and Skewbird Technologies FZCO is the processor. You decide why and how that data is processed; we act on your instructions.
This is distinct from the personal data collected by the wisermonks.com website and your account there. That is handled by the platform operator as controller, and is covered by the Privacy Policy rather than by this addendum.
You warrant that you have a lawful basis under Federal Decree-Law No. 45 of 2021 (PDPL), and any other law that applies to you, for the data you put into our systems.
02. Scope of Processing
- Subject matter: Provision of the software, AI and ERP services described in your statement of work or subscription.
- Duration: For as long as the engagement runs, plus the retention period in section 08.
- Nature and purpose: Hosting, storage, transmission, computation, integration, backup, support and troubleshooting.
- Data subjects: Typically your staff, customers, suppliers and contacts, whoever your system is about.
- Categories of data: Identifiers, contact details, business and transaction records, usage data, and any other category your configuration introduces. Special-category data only where expressly agreed in writing.
03. Our Obligations
- Documented instructions: We process personal data only on your documented instructions, including for transfers, unless a law we are subject to requires otherwise, in which case we tell you first, where we lawfully can.
- No secondary use: We do not sell your data, use it for our own marketing, or use it to train general-purpose AI models. Where a feature would involve model training on your data, it is off unless you explicitly switch it on.
- Confidentiality: Our personnel are bound by confidentiality obligations and get access strictly on a need-to-know basis.
- Assistance: We assist you, so far as we reasonably can, with data subject requests, impact assessments and regulator enquiries.
04. Security Measures
- In transit and at rest: Encryption in transit using current TLS, and encryption at rest for stored data.
- Access control: Role-based access, least privilege, individual named accounts and multi-factor authentication for administrative access.
- Segregation: Customer environments are logically separated so one customer’s data is not reachable from another’s.
- Resilience: Backups per the Service Level Agreement, with restoration tested periodically.
- Change management: Reviewed changes, audit logging of administrative actions, and prompt patching of known vulnerabilities.
05. Sub-Processors
We use third parties to deliver the service: cloud hosting, AI model providers, email and messaging, and error monitoring. Each is bound by written terms no less protective than this addendum, and we remain responsible to you for what they do.
We maintain a current list of sub-processors, available on request from privacy@wisermonks.com. We give you at least 30 days’ notice before adding or replacing one; if you reasonably object on data protection grounds and we cannot offer an alternative, you may terminate the affected service without penalty.
06. International Transfers
Personal data may be processed outside the UAE where a sub-processor operates elsewhere. We transfer only where PDPL permits: an adequate jurisdiction, appropriate contractual safeguards, or your explicit instruction, and we will tell you the hosting region for your environment on request.
Where you require data residency in the UAE, say so before implementation. It is achievable for most workloads but constrains which services can be used, so it is a design decision rather than a switch.
07. Personal Data Breaches
We notify you without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting your data. The notification covers what we know: nature of the breach, categories and approximate numbers affected, likely consequences, and the measures taken or proposed.
We will not delay telling you in order to complete our investigation. As the controller, notifying the UAE Data Office and affected individuals where required is your decision and your obligation. We give you what you need to make it.
08. Return and Deletion
On termination you may export your data for 30 days, as set out in the Terms of Service. After that we delete it from live systems within 30 days, and it ages out of backups within a further 30 days on the rolling cycle.
Where a law requires us to keep something longer, we keep only that, only for as long as required, and it stays subject to this addendum.
09. Audit
On reasonable written notice, no more than once a year, you may request the information needed to demonstrate our compliance with this addendum. We will respond with our current security documentation and any third-party assessment we hold.
Where that is genuinely insufficient for your regulatory obligation, we will agree a proportionate audit. Scoped so it does not compromise other customers’ confidentiality or the security of the platform.
Who You Are Contracting With
Skewbird Technologies FZCO, AI Readiness, Software & ERP. This is the legal person you contract with, and that invoices you, for anything in this service line.
Dubai, United Arab Emirates
+971 55 545 9301 · legal@wisermonks.com
The wisermonks.com platform itself is operated by TheMonks India Pvt Ltd (India), which holds your account and is the controller of your account data. See our Privacy Policy.
Unresolved complaint? You may escalate to the UAE Ministry of Economy & Tourism: Consumer Protection Department on 600 522 225 or via moet.gov.ae.