Last updated 5 September 2026. This page is provided for information and is a summary of the position, not the executed instrument. Where you hold a signed licence agreement, order form or data processing addendum with BizfyLabs FZC LLC, that executed document governs and prevails over this page. Nothing here is legal advice; please take your own advice on how it applies to you.
1.Purpose, and how this addendum fits the agreement
This page describes the data protection position between you and BizfyLabs FZC LLC ("BizfyLabs") when you licence DocxIntel. It is written to answer the questions a data protection officer, a CISO and a procurement lawyer ask in that order, and to be honest about which of them actually apply to an on-premise product.
Where a data processing addendum is executed between us, it forms part of your licence agreement and applies to the extent BizfyLabs processes personal data on your behalf. It does not widen the scope of that processing, and it does not create a processor relationship where none exists.
This addendum is intended to work under the UAE Personal Data Protection Law and, where the customer or the processing falls within its scope, under the EU and UK General Data Protection Regulation. Where the two regimes use different language for the same idea, the stricter obligation applies.
The most important clause is clause 3. If you read only one, read that one.
2.Definitions
- Controller
- The party that determines the purposes and means of processing personal data. In a self-hosted DocxIntel deployment, that is you.
- Processor
- A party that processes personal data on behalf of, and on the documented instructions of, a controller. BizfyLabs is a processor only for the limited services described in clause 3.
- Personal Data
- Any information relating to an identified or identifiable natural person, including personal data contained inside documents you process and the contact data of your personnel.
- Customer Personal Data
- Personal data contained in the documents, extracted fields, indexes and outputs held inside your deployment. In a self-hosted deployment this never reaches BizfyLabs.
- Sub-processor
- A third party engaged by BizfyLabs to carry out part of a processing activity for which BizfyLabs acts as processor.
- Personal Data Breach
- A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data.
- Deployment
- One installed instance of the DocxIntel software in an environment operated by you or, in the managed single-tenant model, operated by BizfyLabs for you alone.
- Support Data
- Ticket contents, environment details, logs, configuration extracts and sample documents that you choose to send BizfyLabs to investigate an issue.
3.Roles: why a self-hosted deployment changes the answer
DocxIntel is licensed software installed inside your infrastructure. The models that analyse, identify, classify, map, modify and answer questions about documents ship inside the deployment bundle and run on your hardware. There is no external inference call, no phone-home telemetry and no cloud fallback.
The consequence is that for Customer Personal Data you are the controller and BizfyLabs is normally not a processor at all. This is not a drafting position — it is a statement of fact about data flow. A processor relationship requires the processor to process personal data on the controller's behalf. BizfyLabs cannot process what it never receives.
- You decide which documents enter the deployment, why, and how long the outputs are kept.
- Documents are read from your storage and results are written back to your storage. Nothing transits BizfyLabs infrastructure.
- Model weights, keys, access logs and audit trails sit inside your environment under your administration.
- An air-gapped deployment behaves identically to a connected one, so there is no fallback path that would send content to us.
- BizfyLabs holds no copy of your documents, no derived index and no dataset built from your content, and therefore cannot disclose, lose or be compelled to produce them.
There are three, and only three, situations in which BizfyLabs does process personal data in connection with DocxIntel. Each is narrow, and each is deliberately identified so that your records of processing can be accurate.
- Managed single-tenant deployment — BizfyLabs acts as processor
- Where you buy the managed single-tenant deployment model, BizfyLabs operates a dedicated environment for you alone. Personal data inside that environment is processed on your instructions and this addendum applies in full.
- Support and diagnostics — BizfyLabs acts as processor for what you send
- Where you choose to attach a log extract, configuration file or sample document to a support ticket, or grant time-boxed remote access to your environment, BizfyLabs processes any personal data in that material on your instructions and for the sole purpose of resolving the issue. You control whether to send it, and we ask you to redact or synthesise personal data first.
- Website, sales and marketing data — BizfyLabs acts as controller
- For enquiry, correspondence, contract and marketing data about your personnel, BizfyLabs determines the purposes and is the controller. That processing is described in the privacy policy at docxintel.com/privacy-policy, not in this addendum.
Getting this distinction right matters to you as well as to us. Recording BizfyLabs as a processor of your document content in a self-hosted deployment would misstate your own record of processing activities and would imply a transfer that does not happen.
4.Scope and duration of processing
Where BizfyLabs acts as processor, processing lasts only as long as needed for the service that gave rise to it, and no longer than the term of the relevant agreement or statement of work.
- Managed single-tenant: for the term of the managed service, ending with the deletion or handover step agreed at the end of that term.
- Support and diagnostics: for the life of the individual ticket, ending when the ticket is closed or sooner on your request.
- Remote access sessions: for the duration of the session only, time-boxed, credentialed by you and revocable by you at any time.
- Proof of Value: for the period of the engagement stated in the statement of work, after which the evaluation environment is decommissioned.
Where BizfyLabs acts as processor for no part of a deployment — the ordinary air-gapped or private cloud case — the duration of processing by BizfyLabs is nil, and the retention decisions are entirely yours.
5.Subject matter, nature and purpose of processing
The subject matter is the provision of the licensed software and, where purchased, the managed and support services connected with it. The nature and purpose of any processing by BizfyLabs as processor is limited to what those services require.
- Hosting, operating, monitoring, patching and backing up a dedicated environment, in the managed single-tenant model only.
- Reproducing, diagnosing and resolving a defect from material you choose to provide.
- Configuring field schemas, taxonomies and pipelines during an implementation or Proof of Value, on your instructions.
- Storing material you send us securely for as long as the ticket or engagement requires, and then deleting it.
BizfyLabs does not use any personal data it processes as a processor for its own purposes. In particular, it does not use Customer Personal Data or Support Data to train, fine-tune, evaluate or benchmark models, and does not aggregate it into any product dataset.
6.Categories of data subjects and personal data
The categories below are indicative, because in a self-hosted deployment only you know what is in your documents. They are provided so that a record of processing can be completed accurately for the narrow cases where BizfyLabs is a processor.
- Data subjects
- Your customers, policyholders, patients, claimants, applicants, counterparties and their representatives, where their data appears in documents; and your own employees, contractors and administrators who use or operate the deployment.
- Categories of personal data in documents
- Identification and contact details, identity and residency document numbers, financial and account details, employment details, claim and case details, signatures and handwriting, and other content specific to your document types. Documents may contain special categories of data, such as health data, where your use case involves them.
- Categories of personal data in support material
- Whatever appears in the log excerpt, configuration file or sample document you choose to send, plus the contact details of the person raising the ticket.
- Special categories and sensitive data
- Where your documents contain health, biometric or other sensitive data, the self-hosted architecture is designed so that this data never leaves your control environment. If a support case would require you to send us sensitive data, tell us and we will find a way to diagnose the issue without it.
7.Processor obligations
Where BizfyLabs acts as processor, it will:
- Process personal data only on your documented instructions and only for the purposes set out in this addendum, the agreement or the applicable statement of work.
- Not process personal data for its own purposes, and not disclose it to a third party except as permitted by this addendum or required by law.
- Implement and maintain appropriate technical and organisational measures, as described in the clause on security measures.
- Ensure that personnel with access are bound by confidentiality obligations and are trained on their responsibilities.
- Engage sub-processors only in accordance with the clause on sub-processors, and remain responsible for their performance.
- Assist you, taking account of the nature of the processing and the information available, with data subject requests, data protection impact assessments and consultations with a supervisory authority.
- Notify you without undue delay after becoming aware of a personal data breach affecting personal data it processes for you.
- Delete or return personal data at the end of the processing, subject to any legal retention obligation.
- Make available the information reasonably necessary to demonstrate compliance with these obligations, and allow audits on the terms set out below.
- Tell you if, in its opinion, an instruction infringes applicable data protection law, and pause the affected processing pending resolution.
8.Instructions and confidentiality of personnel
Your instructions are given through the agreement, this addendum, the applicable statement of work and the tickets and change requests you raise through the agreed channels. BizfyLabs will not act on an instruction from anyone other than an authorised contact you have nominated.
- Access is granted on a least-privilege, need-to-know basis and reviewed periodically.
- Personnel with access are subject to written confidentiality obligations that survive the end of their engagement.
- Personnel are background-screened to the extent permitted by applicable law before being granted access to a customer environment.
- Administrative access to a managed environment is logged, and remote access to your own environment happens only through credentials you issue and can revoke.
- Access rights are removed promptly when a role changes or an engagement ends.
If BizfyLabs receives a legally binding request from a public authority for personal data it processes for you, it will notify you unless prohibited by law, will challenge a request that appears unlawful or overbroad, and will disclose only the minimum required.
9.Security measures
The security measures that protect your document content in a self-hosted deployment are, by design, your own: your network segregation, your identity provider, your key management, your logging and your backups. The software is built to fit inside that control environment rather than to sit beside it.
- Product controls available to you: role-based access control, integration with your identity provider, encryption of data at rest and in transit using keys you hold, immutable audit logging of who processed which document, and configurable retention and deletion.
- Deployment integrity: signed container images and model artefacts with published digests, dependency manifests and a software bill of materials, so you can verify what you are installing.
- No egress by design: no outbound telemetry requirement, so the deployment can run behind a default-deny egress policy or fully air-gapped.
- Measures for data BizfyLabs holds: encryption in transit and at rest, multi-factor authentication, least-privilege access, hardened endpoints, centralised logging, vulnerability management and a documented incident response process.
- Managed single-tenant: dedicated infrastructure per customer with no shared processing plane, segregated credentials and customer-specific keys.
BizfyLabs does not hold a SOC 2 attestation or an ISO/IEC 27001 certificate and will not claim one. Controls are designed and documented against recognised frameworks so that they map cleanly onto your own certification and audit programme, and the security architecture is described at docxintel.com/security.
10.Sub-processors and changes to them
In an ordinary self-hosted deployment there are no sub-processors, because there is no processing by BizfyLabs to sub-contract. Sub-processors are relevant only to the managed single-tenant model and to the support and business systems that hold Support Data and correspondence.
- You give general authorisation for BizfyLabs to engage sub-processors for the services described in this addendum.
- Each sub-processor is engaged under a written contract imposing data protection obligations no less protective than those in this addendum.
- The current sub-processor list for a given service is available on request and is provided as part of the signed addendum where you require it.
- BizfyLabs will give you at least 30 days' written notice before adding or replacing a sub-processor for a service you receive.
- You may object on reasonable data protection grounds within that notice period. If the objection cannot be resolved, you may terminate the affected service and receive a refund of prepaid fees for the unused period.
- BizfyLabs remains liable to you for the acts and omissions of its sub-processors as if they were its own.
11.Data subject requests
As controller, you handle requests from data subjects to exercise their rights. In a self-hosted deployment you are also the only party able to handle them: BizfyLabs has no access to your documents, cannot search them and cannot identify a data subject inside them.
- The software gives you the tooling to locate, export, correct and delete records, with field-level traceability back to the source page and coordinates, which is what makes an access or erasure request answerable.
- Where BizfyLabs receives a request that relates to your data, it will not respond directly. It will inform the individual to contact you and, where it can identify you, will forward the request.
- Where BizfyLabs acts as processor, it will assist you in responding, taking account of the nature of the processing and the information available to it.
- Assistance with an unusually burdensome request may be chargeable at the rates in your order form, and BizfyLabs will tell you before incurring the cost.
12.Personal data breach notification
A breach inside your own environment is yours to detect and report, because that is where your document content lives. The software supports that work with audit logging and access records; the notification obligation to a supervisory authority and to data subjects sits with you as controller.
- Where BizfyLabs becomes aware of a personal data breach affecting personal data it processes for you, it will notify you without undue delay and in any event within 48 hours of becoming aware.
- The notification will describe the nature of the breach, the categories and approximate volume of data and data subjects affected, the likely consequences and the measures taken or proposed, to the extent known.
- Where information is not available at the outset, it will be provided in phases as the investigation progresses.
- BizfyLabs will cooperate with you and take the reasonable steps you direct to help investigate, contain and remediate the breach.
- BizfyLabs will not notify a supervisory authority or a data subject about a breach affecting your personal data on your behalf without your instruction, unless it is separately required by law to do so.
A security defect in the software itself is handled as a product security matter: BizfyLabs will issue an advisory and a fix to affected customers, whether or not any personal data was involved.
13.Audits and information rights
You are entitled to satisfy yourself that BizfyLabs meets its obligations. Because the architecture keeps document content inside your own perimeter, most of what an auditor wants to see is already in your possession and does not require our cooperation.
- BizfyLabs will provide the information reasonably necessary to demonstrate compliance with this addendum, including its security documentation, architecture descriptions, sub-processor list and completed security questionnaires.
- Where BizfyLabs acts as processor, you or an independent auditor bound by confidentiality may audit the relevant controls once in any 12-month period, on at least 30 days' written notice, during business hours and without unreasonable disruption.
- Additional audits are permitted where required by a supervisory authority or following a confirmed personal data breach affecting your data.
- Audit scope is limited to the systems and processes used for the services you receive. It does not extend to other customers' data, to shared corporate systems beyond that scope, or to source code or model weights.
- Deployment bundles ship with digests and a software bill of materials so that your own assurance team can verify the artefacts independently.
14.International transfers
In a self-hosted deployment there is no international transfer of Customer Personal Data, because the data does not leave the infrastructure you chose, in the country you chose. This is usually the shortest answer in a data residency review, and it is the reason the architecture exists.
Where BizfyLabs does process personal data as processor, and that processing involves a transfer out of the UAE, BizfyLabs applies the cross-border transfer conditions of the UAE Personal Data Protection Law and its implementing decisions. Where the GDPR applies, BizfyLabs relies on an adequacy decision where one exists and otherwise on standard contractual clauses with a transfer risk assessment and supplementary measures.
For a managed single-tenant deployment, the hosting region is fixed in the order form and BizfyLabs will not move the environment to another region without your prior written agreement.
15.Deletion and return of data
At the end of processing, and at any time on your written request, BizfyLabs will delete or return the personal data it processes for you, at your option, and delete existing copies unless applicable law requires it to keep them.
- Support material is deleted when the ticket is closed, and sooner if you ask.
- A managed single-tenant environment is exported to you in the agreed format and then securely decommissioned, with written confirmation of deletion.
- Backups are purged in accordance with the documented backup cycle, and the deletion certificate records when the last copy expires.
- Where BizfyLabs must retain data to comply with a legal obligation, it will retain only what the obligation requires, isolate it, protect it and delete it once the obligation ends.
For a self-hosted deployment, termination has no data consequences at our end because we hold nothing. Your documents, extracted fields and outputs remain in your storage, in open formats, readable without the software. What must be removed on termination is the software and the deployment bundle, including the model weights, as set out in the terms and conditions.
16.Liability
Liability under this addendum is subject to the limitations and exclusions in the licence agreement or order form, which apply to claims under this addendum as if they were claims under that agreement. Where the agreement is silent, the terms and conditions at docxintel.com/terms-conditions apply.
Each party remains responsible for its own compliance obligations in its own role. As controller you are responsible for the lawfulness of the processing you instruct, for the lawful basis on which documents are processed, for transparency to data subjects and for your own security controls. BizfyLabs is responsible for meeting the processor obligations in this addendum for the services in which it acts as processor.
Nothing in this addendum limits a data subject's rights under applicable data protection law, or a supervisory authority's powers.
17.Getting a signable addendum
A signable data processing addendum, with the annexes completed for your deployment model, hosting region and service scope, is available on request. Ask for it through the contact page at https://bizfylabs.com/contact-us and it will be issued as part of the contract pack.
- Annex 1 records the subject matter, duration, nature and purpose of processing, the categories of data subjects and personal data, and the roles of each party.
- Annex 2 records the technical and organisational security measures applicable to the services you buy.
- Annex 3 records the authorised sub-processors, if any, for the services you buy.
- Standard contractual clauses and a transfer risk assessment are attached where a transfer subject to the GDPR is in scope.
- Where your legal team prefers to work from your own template, send it over and we will review it against the architecture rather than insist on ours.
Where a deployment is fully self-hosted and BizfyLabs receives no personal data at all, we will say so in writing rather than sign a document that implies otherwise. Several customers have found that statement more useful in a regulatory conversation than a processor addendum would have been.
18.Governing law and jurisdiction
This addendum is governed by the laws of the United Arab Emirates, and the courts of Dubai have exclusive jurisdiction over any dispute or claim arising out of or in connection with it, including non-contractual disputes.
Where your executed agreement specifies a different governing law or dispute resolution mechanism for the relationship as a whole, that choice applies to this addendum as well, and any standard contractual clauses incorporated into it are governed as those clauses require.