Effective Date: August 11, 2026
Last Updated: August 11, 2026
This Data Processing Addendum (“DPA”) forms part of the agreement between Northline Systems FZ-LLC, trading as Cevimo (“Cevimo,” “Processor,” “Service Provider,” “we,” “us,” or “our”), and the business or legal entity using the Cevimo System (“Client,” “Controller,” “Business,” “you,” or “your”).
This DPA applies where Cevimo Processes Personal Data on your behalf in connection with the Cevimo System.
This DPA supplements and forms part of our Terms and Conditions, Privacy Policy, and any other written agreement governing your use of the Cevimo System.
Where there is a conflict between this DPA and our Terms and Conditions regarding the Processing of Client Personal Data, this DPA will prevail to the extent of that conflict.
1. Definitions
For purposes of this DPA:
Applicable Data Protection Law means all privacy, data protection, and data security laws applicable to the Processing covered by this DPA, including, where applicable:
- UAE Federal Decree-Law No. 45 of 2021 Regarding the Protection of Personal Data
- Regulation (EU) 2016/679 (“GDPR”)
- The United Kingdom GDPR (“UK GDPR”)
- The UK Data Protection Act 2018
- The California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA/CPRA”)
- Applicable US state comprehensive privacy laws
- Other applicable privacy and data protection legislation
Client Personal Data means Personal Data Processed by Cevimo on behalf of the Client through the Cevimo System.
Controller means the person or organization that determines the purposes and means of Processing Personal Data.
Data Subject means an identified or identifiable individual to whom Personal Data relates.
Personal Data means any information relating to an identified or identifiable individual and includes “personal information,” “personal data,” and equivalent terms under Applicable Data Protection Law.
Personal Data Breach means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data.
Process, Processed, or Processing means any operation performed on Personal Data, including collection, recording, organization, storage, use, transmission, disclosure, retrieval, modification, deletion, or destruction.
Processor means a person or organization that Processes Personal Data on behalf of a Controller.
Services or Cevimo System means the subscription-based system provided by Cevimo, including the Client Website, lead management functionality, communications tools, business phone functionality, missed-call text back, automated follow-up, review functionality, local SEO functionality, integrations, automations, and related features.
Subprocessor means a third party appointed by Cevimo to Process Client Personal Data on behalf of the Client.
2. Roles of the Parties
For Client Personal Data Processed through the Cevimo System:
The Client generally acts as the Controller or Business.
Cevimo generally acts as the Processor, Service Provider, or Contractor.
The Client determines the purposes for which its customers, leads, prospects, and other Data Subjects are contacted and how their Personal Data is used.
Cevimo Processes that Personal Data on the Client's behalf for the purpose of providing and operating the Cevimo System.
Nothing in this DPA prevents either party from acting as an independent Controller for Personal Data it Processes independently for its own legitimate purposes.
For example, Cevimo acts as an independent Controller for information relating to its own Clients, billing contacts, prospective Clients, website visitors, and Account administration as described in our Privacy Policy.
3. Client Instructions
Cevimo will Process Client Personal Data only:
- On the Client's documented instructions
- As necessary to provide the Cevimo System
- As configured or initiated by the Client through the System
- As required to maintain, secure, troubleshoot, and support the System
- As required by Applicable Data Protection Law
- As otherwise agreed between the parties in writing
The Client's documented instructions include:
- These Terms and this DPA
- The Client's use and configuration of the Cevimo System
- Features activated by the Client
- Automations configured for the Client
- Communications initiated or authorized by the Client
- Integrations authorized by the Client
- Written instructions provided to Cevimo through Account settings, onboarding, support, or other agreed channels
If Cevimo reasonably believes that an instruction violates Applicable Data Protection Law, we may inform the Client and suspend the affected Processing until the matter is resolved.
4. Purpose of Processing
Cevimo may Process Client Personal Data only for the specific purposes necessary to provide the Cevimo System.
These purposes may include:
- Receiving and storing website enquiries
- Capturing leads
- Creating and maintaining contact records
- Organizing Client leads and customers
- Displaying communications in the all-in-one inbox
- Routing enquiries to the Client
- Sending authorized SMS messages
- Sending authorized emails
- Supporting telephone communications
- Operating missed-call text-back functionality
- Operating automated lead follow-up
- Sending appointment or booking communications
- Sending review requests
- Managing customer communication history
- Maintaining communication preferences and opt-out status
- Operating Client websites
- Providing technical infrastructure
- Maintaining Client Accounts
- Providing support and troubleshooting
- Maintaining security
- Preventing fraud and abuse
- Backing up and restoring data
- Maintaining integrations authorized by the Client
- Performing functionality otherwise requested by the Client through the Cevimo System
Cevimo will not Process Client Personal Data for unrelated advertising or marketing purposes on behalf of another company.
5. Client Responsibilities
The Client is responsible for ensuring that its collection and use of Client Personal Data complies with Applicable Data Protection Law.
The Client represents and warrants that it has all necessary rights, lawful bases, notices, permissions, and consents required to provide Client Personal Data to Cevimo and instruct Cevimo to Process it.
The Client is responsible for:
- Providing required privacy notices to its customers and leads
- Establishing an appropriate lawful basis for Processing
- Obtaining consent where required
- Maintaining evidence of consent where required
- Ensuring forms and lead collection methods comply with applicable law
- Determining which individuals may be contacted
- Complying with applicable electronic marketing and telecommunications laws
- Honoring unsubscribe and opt-out requests
- Keeping Client Personal Data reasonably accurate
- Determining appropriate retention periods
- Responding to Data Subject requests
- Ensuring authorized users access Personal Data appropriately
- Avoiding the collection of unnecessary Personal Data
The Client must not instruct Cevimo to Process Personal Data in a manner that would knowingly violate Applicable Data Protection Law.
6. Processing Restrictions
Cevimo will not:
- Sell Client Personal Data
- Share Client Personal Data for cross-context behavioral advertising
- Use Client Personal Data to advertise unrelated third-party products or services
- Use one Client's customer or lead database for another Client
- Disclose Client Personal Data except as permitted by this DPA
- Retain, use, or disclose Client Personal Data outside the direct business relationship with the Client except where permitted or required by Applicable Data Protection Law
- Use Client Personal Data for purposes materially unrelated to providing, maintaining, protecting, or improving the Services as permitted by applicable law
Where the CCPA/CPRA applies, Cevimo acts as a Service Provider or Contractor and agrees to the applicable restrictions imposed on such parties.
Cevimo will provide the same level of privacy protection for Client Personal Data as required of a Service Provider or Contractor under applicable provisions of the CCPA/CPRA.
Cevimo certifies that it understands and will comply with the restrictions applicable to its Processing of Client Personal Data.
7. Confidentiality
Cevimo will ensure that personnel authorized to Process Client Personal Data are subject to appropriate confidentiality obligations.
Access to Client Personal Data will be limited to personnel, contractors, and Subprocessors that require access to perform legitimate functions related to the Cevimo System.
Cevimo will take reasonable steps to ensure authorized personnel understand their obligations regarding confidentiality, privacy, and security.
8. Security Measures
Cevimo will implement and maintain reasonable technical and organizational measures appropriate to the nature of the Personal Data, the nature of the Processing, and the risks involved.
These measures may include, as appropriate:
- Access controls
- Role-based permissions
- Authentication controls
- Password protection
- Multi-factor authentication where supported
- Encryption of data in transit
- Encryption or equivalent safeguards for stored information where appropriate and supported
- Secure infrastructure
- Logging and monitoring
- Backup and recovery procedures
- Security incident procedures
- Restriction of employee and contractor access
- Confidentiality obligations
- Subprocessor due diligence
- Secure configuration practices
- Software and infrastructure updates
- Measures designed to prevent unauthorized access
- Measures designed to maintain availability and resilience
Additional information regarding Cevimo's security measures is set out in Appendix 2.
No information system can be guaranteed to be completely secure, but Cevimo will maintain measures reasonably appropriate to the Processing carried out on behalf of the Client.
9. Personal Data Breaches
If Cevimo becomes aware of a confirmed Personal Data Breach affecting Client Personal Data, Cevimo will notify the affected Client without undue delay.
Where reasonably available, the notification will include information concerning:
- The nature of the Personal Data Breach
- The categories of affected Data Subjects
- The categories of affected Personal Data
- The approximate number of affected records or individuals, where known
- Known or reasonably anticipated consequences
- Measures taken or proposed to contain or mitigate the incident
- Contact information for further communication
Cevimo may provide information in stages where complete information is not immediately available.
Cevimo will take reasonable steps to investigate, contain, remediate, and mitigate a confirmed Personal Data Breach.
Notification under this section does not constitute an admission of fault or liability by Cevimo.
The Client remains responsible for determining whether the incident requires notification to Data Subjects, regulators, authorities, or other parties unless Applicable Data Protection Law places that obligation directly on Cevimo.
10. Subprocessors
10.1 General Authorization
The Client provides Cevimo with general written authorization to appoint Subprocessors where reasonably necessary to provide the Cevimo System.
Cevimo will ensure that each Subprocessor that Processes Client Personal Data is subject to contractual obligations requiring an appropriate level of privacy, confidentiality, and security protection.
Cevimo remains responsible for its obligations under this DPA when Processing is carried out by a Subprocessor appointed by Cevimo, subject to the liability provisions of the Agreement.
10.2 Current Core Subprocessor
The Cevimo System uses the following core platform provider:
HighLevel LLC / HighLevel, Inc.
Purpose: CRM and platform infrastructure, contact and lead management, automations,
communications functionality, website and funnel functionality, client portal/application functionality,
and related infrastructure.
Primary Processing Location: United States and other locations used by HighLevel and its authorized subprocessors.
Additional technical providers may be used where necessary to operate specific Cevimo functionality.
Providers that independently Process information relating to Cevimo's own billing, corporate administration, or direct relationship with the Client are not necessarily Subprocessors of Client Personal Data for purposes of this DPA.
Client-authorized third-party integrations may also Process Personal Data according to their own contractual relationship with the Client.
10.3 Changes to Subprocessors
Cevimo may add or replace Subprocessors.
Where required by Applicable Data Protection Law, Cevimo will provide reasonable advance notice of a new Subprocessor that will materially Process Client Personal Data.
Unless a shorter period is reasonably necessary because of security, operational, or legal requirements, Cevimo will aim to provide approximately 30 days' notice of material Subprocessor changes.
The Client may object to a new Subprocessor on reasonable and documented data protection grounds.
The parties will work in good faith to resolve the objection.
If no reasonable alternative is available, Cevimo may discontinue the affected feature or the Client may terminate the affected Services in accordance with the Agreement.
11. Data Subject Requests
Taking into account the nature of the Processing, Cevimo will provide reasonable assistance to enable the Client to respond to requests from Data Subjects where required by Applicable Data Protection Law.
Such requests may include:
- Access
- Correction
- Deletion
- Restriction
- Objection
- Portability
- Withdrawal of consent
- Other rights granted by applicable law
Where Cevimo receives a request directly from a Data Subject relating to Client Personal Data, Cevimo will normally instruct the Data Subject to contact the Client or forward the request to the Client.
Cevimo will not independently respond to the substantive request unless:
- The Client instructs Cevimo to do so
- Applicable Data Protection Law requires Cevimo to respond directly
- Cevimo acts as an independent Controller for the relevant Personal Data
12. Regulatory and Compliance Assistance
Taking into account the nature of the Processing and information reasonably available to Cevimo, Cevimo will provide reasonable assistance to the Client with its obligations concerning:
- Data protection impact assessments
- Security of Processing
- Personal Data Breach assessments
- Regulatory consultations
- Data Subject rights
- International transfer assessments
- Other compliance obligations directly relating to Cevimo's Processing
The Client remains responsible for determining whether a data protection impact assessment, transfer assessment, regulatory consultation, or other compliance procedure is legally required.
Cevimo may charge reasonable fees for assistance that is unusually extensive, repetitive, or outside the normal operation of the Services, provided such charges are agreed or communicated in advance.
13. Audits and Compliance Information
Cevimo will make available information reasonably necessary to demonstrate compliance with this DPA where required by Applicable Data Protection Law.
The Client should first use available documentation, policies, security information, compliance information, or written questionnaires to assess Cevimo's compliance.
Where Applicable Data Protection Law requires an additional audit, the Client may request one subject to the following conditions:
- Reasonable prior written notice
- No more than once in any 12-month period unless required because of a confirmed Personal Data Breach, regulator request, or reasonable evidence of material non-compliance
- Conduct during normal business hours
- No unreasonable disruption to Cevimo or other Clients
- Appropriate confidentiality obligations
- No access to information concerning other Clients
- No access that could compromise system security
- The Client bears its own audit costs
Cevimo may satisfy an audit request by providing a relevant third-party audit report, certification, security assessment, or equivalent documentation where reasonably sufficient.
14. Data Return and Deletion
Cevimo will Process Client Personal Data for the duration of the Client's active Subscription and for as long as reasonably necessary to provide the Services.
Upon termination of the Services, and subject to the Client's instructions, Cevimo will delete or return Client Personal Data as required by Applicable Data Protection Law unless continued retention is legally required.
Deletion from active systems may occur progressively according to normal technical deletion procedures.
Residual copies may remain temporarily within backups, disaster recovery systems, logs, or secure archives until deleted through normal retention cycles.
Any Personal Data retained because of a legal obligation will remain protected under this DPA and will not be actively Processed for unrelated purposes.
The Client is responsible for exporting any data available for export before access to the Cevimo System ends.
15. International Data Transfers
The Client acknowledges that Cevimo is established in the United Arab Emirates and that Cevimo and its authorized Subprocessors may Process Client Personal Data in multiple countries.
Depending on the technology used, this may include Processing in:
- The United Arab Emirates
- The United States
- The European Economic Area
- The United Kingdom
- Other countries in which an authorized Subprocessor lawfully operates
Where Applicable Data Protection Law requires safeguards for an international transfer, the parties will use an appropriate transfer mechanism.
This may include:
- An adequacy decision
- Standard Contractual Clauses
- The UK International Data Transfer Agreement
- The UK International Data Transfer Addendum
- Contractual safeguards
- Other legally permitted transfer mechanisms
16. European Economic Area Transfers
Where Client Personal Data subject to the GDPR is transferred to Cevimo in a country not covered by an applicable adequacy decision and the 2021 European Commission Standard Contractual Clauses are legally available for that transfer, the parties agree that the European Commission Standard Contractual Clauses adopted under Commission Implementing Decision (EU) 2021/914 (“EU SCCs”) apply.
For a transfer from a Client acting as Controller to Cevimo acting as Processor:
Module 2 — Controller to Processor applies.
For purposes of the EU SCCs:
- The Client is the data exporter
- Cevimo is the data importer
- The parties' identities and contact information are those contained in the Agreement and this DPA
- The description of Processing is set out in Appendix 1
- The technical and organizational measures are set out in Appendix 2
- The Subprocessor information is set out in Section 10 and may be updated in accordance with this DPA
- The Client provides general authorization for Subprocessors subject to the notice mechanism in Section 10
- The optional docking clause applies
- For Clause 17 of the SCCs, where a Member State law must be selected, the parties select the laws of Ireland
- For Clause 18, the parties select the courts of Ireland
- The competent supervisory authority will be determined in accordance with Clause 13 of the EU SCCs
If the EU SCCs conflict with another provision of this DPA regarding an international transfer governed by the EU SCCs, the EU SCCs will prevail to the extent of the conflict.
The parties will cooperate in good faith regarding any transfer impact assessment or supplementary measure reasonably required by Applicable Data Protection Law.
17. United Kingdom Transfers
Where Client Personal Data subject to UK Data Protection Law is transferred to a country that requires an appropriate international transfer safeguard, the parties agree to use an appropriate mechanism recognized under UK law.
Where appropriate, the parties agree that the International Data Transfer Addendum to the European Commission Standard Contractual Clauses issued by the UK Information Commissioner's Office (“UK Addendum”) applies to the EU SCCs incorporated under Section 16.
For purposes of the UK Addendum:
- The parties are the Client and Cevimo
- The relevant transfer information is contained in this DPA and its Appendices
- The EU SCCs are the SCCs identified in Section 16
- The relevant Module is Module 2 where the Client is Controller and Cevimo is Processor
- The technical and organizational measures are described in Appendix 2
- Either party may end the UK Addendum where permitted by the mandatory provisions of the applicable UK Addendum
Where another UK-approved transfer mechanism is more appropriate, the parties may agree to use that mechanism instead.
18. United States Privacy Laws
Where Client Personal Data is subject to an applicable US state privacy law and the Client acts as a Business or Controller while Cevimo acts as a Service Provider, Contractor, or Processor, Cevimo agrees that it will:
- Process Client Personal Data only for the specific purposes described in this DPA
- Not sell Client Personal Data
- Not share Client Personal Data for cross-context behavioral advertising
- Not retain, use, or disclose Client Personal Data outside the direct business relationship except as permitted by applicable law
- Not retain, use, or disclose Client Personal Data for unrelated commercial purposes except as legally permitted
- Provide an appropriate level of privacy protection
- Assist the Client with eligible consumer rights requests where reasonably required
- Notify the Client if Cevimo determines that it can no longer meet applicable legal obligations
- Permit the Client to take reasonable and appropriate steps required by applicable law to help ensure that Client Personal Data is Processed consistently with the Client's obligations
- Cooperate in taking reasonable steps to stop and remediate unauthorized Processing where required
Where legally permitted, Cevimo may Process Client Personal Data internally to maintain or improve the quality, security, functionality, or reliability of the Services, provided such Processing does not involve using one Client's Personal Data to provide unrelated marketing or services on behalf of another Client.
19. UAE Data Protection
Where the UAE Personal Data Protection Law applies to the Processing under this DPA, the parties will comply with their respective obligations under applicable UAE data protection legislation.
Cevimo will Process Client Personal Data according to the Client's instructions except where Processing is otherwise required or permitted by applicable law.
Cevimo will maintain appropriate security and confidentiality measures and will cooperate with the Client regarding applicable Data Subject rights, security incidents, and lawful cross-border transfer requirements.
20. Sensitive Personal Data
The Cevimo System is not designed for the routine Processing of highly sensitive or special-category Personal Data.
The Client should not intentionally upload sensitive Personal Data unless:
- It is reasonably necessary for the Client's legitimate business purpose
- The Client has an appropriate lawful basis
- Applicable legal requirements are satisfied
- The Cevimo System is suitable for the intended Processing
Sensitive Personal Data may include, depending on applicable law:
- Health or medical information
- Biometric information
- Genetic information
- Racial or ethnic origin
- Religious or philosophical beliefs
- Sexual orientation
- Political opinions
- Precise geolocation
- Government identification information
- Highly sensitive financial information
Cevimo does not undertake to provide sector-specific regulated infrastructure, such as a HIPAA-compliant healthcare system, unless expressly agreed in writing.
21. Client-Authorized Integrations
The Client may choose to connect the Cevimo System with third-party applications or services.
Where a third-party integration is activated by or at the direction of the Client, the Client authorizes the transfer of Personal Data reasonably necessary for the integration to function.
Depending on the circumstances, the third-party provider may act as:
- The Client's processor
- Cevimo's Subprocessor
- An independent Controller
- Another legally defined role
Cevimo is not responsible for the independent privacy practices of third-party services selected or independently controlled by the Client.
The Client should review the privacy and data protection terms of third-party integrations before enabling them.
22. Government and Law Enforcement Requests
If Cevimo receives a legally binding request from a public authority for Client Personal Data, Cevimo will, to the extent legally permitted:
- Review the validity of the request
- Limit disclosure to information legally required
- Notify the Client where legally permitted
- Challenge or seek clarification regarding requests that appear unlawful or excessive where reasonably appropriate
Nothing in this DPA requires Cevimo to violate applicable law.
23. Liability
Each party's liability arising out of or relating to this DPA is subject to the limitations and exclusions of liability contained in the Cevimo Terms and Conditions or other applicable agreement between the parties.
Nothing in this DPA limits liability to the extent such liability cannot legally be limited under Applicable Data Protection Law.
24. Term and Termination
This DPA becomes effective when the Client becomes bound by the Agreement and Cevimo begins Processing Client Personal Data on the Client's behalf.
This DPA remains in effect for as long as Cevimo Processes Client Personal Data on behalf of the Client.
Obligations relating to confidentiality, security, deletion, international transfers, and protection of retained Client Personal Data survive termination for as long as Cevimo retains such Personal Data.
25. Changes to This DPA
Cevimo may update this DPA where reasonably necessary to reflect:
- Changes to Applicable Data Protection Law
- Regulatory requirements
- Changes to the Cevimo System
- Changes to Subprocessors
- International transfer requirements
- Security or compliance improvements
Where a material change affects the protection of Client Personal Data, Cevimo will provide reasonable notice where required by Applicable Data Protection Law.
An updated DPA will become effective on the date specified in the updated version.
26. Governing Terms
Except where an applicable international data transfer mechanism requires otherwise, this DPA is governed by the governing-law and dispute-resolution provisions contained in the Cevimo Terms and Conditions.
Where the EU SCCs, UK Addendum, or another mandatory privacy mechanism applies and conflicts with those governing-law provisions, the mandatory requirements of the applicable transfer mechanism prevail solely with respect to the relevant Processing or transfer.
27. Electronic Acceptance
This DPA may be accepted electronically.
By entering into the Cevimo Terms and Conditions, creating or using a Cevimo Account, starting a Subscription, checking an applicable acceptance box, or otherwise using the Cevimo System to Process Client Personal Data, the Client agrees to this DPA where applicable.
No separate physical signature is required unless applicable law or a separate agreement requires one.
28. Contact
For questions concerning this DPA or Cevimo's Processing of Client Personal Data, contact:
Northline Systems FZ-LLC
Trading as Cevimo
VAT: 104663755700003
License Number: 47013647
Address:
DCW2023
Compass Building
Al Shohada Road
Al Hamra Industrial Zone-FZ
Ras Al Khaimah
United Arab Emirates
Email: [email protected]
For data protection matters, please include “Data Protection” in the email subject line.
Appendix 1 — Details of Processing
A. Subject Matter
Processing of Client Personal Data as necessary to provide, maintain, secure, and support the Cevimo System.
B. Duration
For the duration of the Client's Subscription and for any limited period afterwards during which Cevimo retains Client Personal Data in accordance with the Agreement, this DPA, legal obligations, and normal backup or deletion procedures.
C. Nature of Processing
Processing may include:
- Collection
- Receipt
- Recording
- Organization
- Structuring
- Storage
- Retrieval
- Consultation
- Display
- Transmission
- Communication
- Updating
- Automation
- Matching within the Client's Account
- Restriction
- Export
- Backup
- Deletion
D. Purposes of Processing
The purposes include:
- Operating Client websites
- Capturing website enquiries
- Creating lead and customer records
- Organizing Client contacts
- Managing communications
- Operating the all-in-one inbox
- Sending authorized SMS and email communications
- Supporting business telephone functionality
- Operating missed-call text back
- Operating automated lead follow-up
- Managing appointments and enquiries
- Sending customer review requests
- Storing communication history
- Supporting Client users
- Providing integrations
- Providing technical support
- Maintaining system security
- Preventing abuse
- Providing backup and recovery
- Maintaining and improving the functionality, security, and reliability of the Services as legally permitted
E. Categories of Data Subjects
Client Personal Data may relate to:
- Client customers
- Prospective customers
- Leads
- Website visitors
- People submitting enquiry forms
- People calling or messaging the Client
- People booking appointments
- Former customers
- Client employees
- Client contractors
- Client authorized users
- Other individuals whose Personal Data the Client lawfully Processes through the Cevimo System
F. Categories of Personal Data
Depending on how the Client uses Cevimo, Personal Data may include:
- Name
- Email address
- Telephone number
- Postal or service address
- Business information
- Enquiry details
- Service requested
- Lead source
- Form submissions
- Messages
- SMS content
- Email content
- Call information and metadata
- Appointment information
- Booking information
- Communication history
- Review-request information
- Customer status
- Lead status
- Notes entered by the Client
- Communication preferences
- Opt-in and opt-out information
- Consent records where stored
- IP address
- Device or browser information
- Website activity
- Custom fields configured by the Client
- Other Personal Data submitted by the Data Subject or Client through the System
G. Special Categories of Personal Data
Cevimo does not require Clients to submit special-category or highly sensitive Personal Data as part of the ordinary operation of the Cevimo System.
Clients should avoid Processing such data unless legally permitted and reasonably necessary.
H. Frequency of Processing
Processing may occur continuously for the duration of the Client's active use of the Cevimo System.
Appendix 2 — Technical and Organizational Measures
Cevimo maintains technical and organizational measures designed to provide an appropriate level of security based on the nature and risks of the Processing.
These measures may include:
A. Access Control
- Access restricted according to business need
- User authentication
- Role-based access where supported
- Administrative access restrictions
- Procedures for removing access where no longer required
- Multi-factor authentication where available and appropriate
B. Confidentiality
- Confidentiality obligations for relevant personnel
- Restricted internal access to Client Personal Data
- Security and privacy expectations for personnel and contractors
C. Data Transmission
- Encryption in transit using industry-standard encrypted communications where supported
- Secure connections to technical infrastructure
- Appropriate safeguards for integrations and APIs
D. Infrastructure Security
- Use of reputable infrastructure and platform providers
- Technical monitoring where appropriate
- Security updates and maintenance
- Logical separation of Client Accounts where supported by underlying infrastructure
- Measures intended to reduce unauthorized system access
E. Availability and Recovery
- Backup procedures where supported by relevant infrastructure
- Disaster recovery measures appropriate to the Services
- Measures intended to restore access following operational incidents
- Use of infrastructure designed for reasonable availability and resilience
F. Security Incident Management
- Processes for evaluating suspected security incidents
- Escalation procedures
- Incident containment and remediation
- Client notification procedures for qualifying Personal Data Breaches
G. Subprocessor Management
- Review of relevant Subprocessors
- Contractual privacy and confidentiality requirements
- Appropriate data protection terms
- Ongoing management of material Subprocessor relationships
H. Data Minimization and Retention
- Processing limited to purposes connected with providing the Services
- Access restricted according to legitimate need
- Deletion and retention procedures
- Measures designed to avoid unnecessary retention
I. Account Security
- Password and authentication controls
- Account access management
- Logging or activity records where supported
- Procedures for investigating suspected unauthorized Account access
Appendix 3 — International Transfer Information
Where the EU SCCs apply:
Data Exporter:
The Client identified in the applicable Cevimo Account, Subscription, order, or agreement.
Role: Controller
Data Importer:
Northline Systems FZ-LLC, trading as Cevimo
Role: Processor
Address:
DCW2023
Compass Building
Al Shohada Road
Al Hamra Industrial Zone-FZ
Ras Al Khaimah
United Arab Emirates
Email: [email protected]
Relevant SCC Module:
Module 2 — Controller to Processor
Categories of Data Subjects:
As described in Appendix 1.
Categories of Personal Data:
As described in Appendix 1.
Sensitive Data:
Not ordinarily intended to be Processed. Where submitted by the Client,
Processing is subject to the Client's compliance obligations and any appropriate additional safeguards.
Frequency:
Continuous or as required during the Client's Subscription.
Nature and Purpose:
As described in Appendix 1.
Retention:
For the duration described in Appendix 1 and Section 14.
Technical and Organizational Measures:
As described in Appendix 2.
Subprocessors:
As described in Section 10 and any subsequent notice provided in accordance with this DPA.
Competent Supervisory Authority:
Determined according to Clause 13 of the applicable EU SCCs.
SCC Governing Law:
Ireland, where the SCCs require selection of an EU Member State law.
SCC Courts:
Ireland, where required under the applicable SCCs.
Acceptance
By entering into the Cevimo Terms and Conditions or otherwise using the Cevimo System to Process Client Personal Data, the Client confirms that:
- It has read and understood this DPA
- It authorizes Cevimo to Process Client Personal Data as described
- It provides general authorization for the Subprocessors described in this DPA
- It has the legal right to provide Client Personal Data to Cevimo
- It is responsible for the lawful collection and use of its customer and lead data
- It accepts the international transfer provisions applicable to its use of Cevimo
- It agrees that this DPA forms part of its agreement with Cevimo
By continuing to use the Cevimo System, the Client agrees to this Data Processing Addendum.




