MyGatePass Data Processing Agreement
Version 1.0 · In force from 09/09/2026
Contents
- 1. How this DPA applies
- 2. Definitions
- 3. Roles, scope and law
- 4. Instructions and purpose limitation
- 5. MyGatePass's obligations
- 6. Security and Personal Data Breach
- 7. Subprocessors
- 8. Data residency and international transfers
- 9. Data Subject rights, assistance and audit
- 10. Retention, return and deletion
- 11. Term, liability and general
- Annex A: Details of the Processing
- Annex B: Technical and organisational measures
- Annex C: Default retention periods
- Annex D: Contacts
- Schedule 1: School Module (Pick-up and Dismissal)
- Annex F: Transfer clauses (EU and UK)
- Annex E: Execution (optional)
1. How this DPA applies
1.1 Parties. This DPA is between:
| Processor | MyGatePass FZ-LLC, a free-zone limited liability company incorporated in the Dubai Development Authority, United Arab Emirates ("MyGatePass") |
|---|---|
| Controller | the legal entity that accepted the Terms and Conditions or is named as the customer in a Service Agreement or order form ("Customer"), together with its Affiliates that use the Services under the same account |
1.2 Formation. The Terms and Conditions incorporate this DPA by reference, as does any Service Agreement that refers to it. This DPA applies from the moment the Customer accepts those terms, and the Customer's continued use of the Services constitutes acceptance of the version of this DPA then in force.
1.3 Precedence. Where this DPA conflicts with any other part of the agreement between the Parties, this DPA prevails in relation to the Processing of Customer Personal Data, save that clauses 11.4 (liability) and 11.5 (governing law) give effect to the corresponding provisions of that agreement. Where the Parties have signed a separate negotiated data processing agreement, that agreement prevails over this one.
1.4 Amendment. MyGatePass may amend this DPA to (a) reflect a change in Applicable Data Protection Law or in regulator guidance, (b) update Annex B, Annex C, Annex D or the Subprocessor List, or (c) add a Schedule for a new module. Any other amendment applies to the Customer only from its next renewal.
MyGatePass will publish the amended version at the URL above with a new version number, and will notify the Customer's Notice Contact of every amendment, at least 30 days before it takes effect.
Where an amendment reduces the protections in this DPA, or changes the categories of Customer Personal Data, the residency position in clause 8.1, or the retention position in Annex C, the Customer may, within 30 days of the later of the notice and the date the change takes effect, terminate the Services affected by the change or, where the change concerns clause 6 or clause 8, the Services in whole. MyGatePass will refund fees paid in advance for the terminated part pro rata. This paragraph prevails over any provision of the agreement between the Parties on termination for convenience or refunds.
Continued use of the Services after an amendment takes effect, and after the objection period has expired, constitutes acceptance of it.
1.5 Versions and record of acceptance. MyGatePass maintains a dated archive of every published version of this DPA at mygatepass.com/dpa-versions, records on the Customer's account the version accepted and the date of acceptance, and will on request provide the Customer with a copy of the version applicable to it together with the record of its acceptance.
1.6 Existing Customers. A Customer that accepted the Terms and Conditions before the version date of this DPA becomes bound by it on the later of 30 days after MyGatePass notifies its Notice Contact and the version date. The objection right in clause 1.4 applies to that notification.
1.7 Interpretation. References to a clause, Annex or Schedule are to this DPA unless stated otherwise. Headings do not affect interpretation. "Including" is not limiting.
2. Definitions
| Term | Meaning |
|---|---|
| Affiliate | an entity that controls, is controlled by, or is under common control with a Party |
| Applicable Data Protection Law | (a) UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data and any regulations made under it, being the law applicable to MyGatePass; and (b) any data protection law applicable to the Customer's Processing, including the EU GDPR, the UK GDPR and the UK Data Protection Act 2018 to the extent they apply to the Customer by law. Where limb (b) applies, clause 3.9 applies |
| Customer Personal Data | Personal Data that MyGatePass Processes on behalf of the Customer in connection with the Services, being the categories described in Annex A and in any applicable Schedule, together with any further category the Customer instructs under clause 4.2 |
| Data Subject, Personal Data, Personal Data Breach, Processing | as defined in Applicable Data Protection Law; where the limbs differ, the definition giving the Data Subject greater protection applies |
| Notice Contact | the Customer's designated administrator, and the administrative email address, held on the Customer's MyGatePass account. The Customer is responsible for keeping these current, and may add a dedicated data protection contact, security incident contact and safety or safeguarding contact in its account settings, which MyGatePass will use in preference to the administrative address where they are set |
| Regulator | the UAE Data Office established under UAE Federal Decree-Law No. 44 of 2021, and any other authority with competence over either Party's Processing |
| Version date | the date stated at the head of this DPA |
| Sensitive Personal Data | data falling within "Sensitive Personal Data" in Article 1 of UAE Federal Decree-Law No. 45 of 2021, and any "special category" data within Article 9 EU or UK GDPR |
| Services | the MyGatePass platform modules the Customer has subscribed to, as recorded on its account. Module-specific terms are in the Schedules and apply only to the modules the Customer uses |
| Subprocessor | any processor engaged by MyGatePass to Process Customer Personal Data |
| Subprocessor List | the list published at mygatepass.com/subprocessors, as updated under clause 7 |
3. Roles, scope and law
3.1 In relation to Customer Personal Data, the Customer is the controller and MyGatePass is the processor.
3.2 Annex A describes the subject matter, duration, nature and purpose of the Processing, the categories of Data Subject and of Personal Data, and the obligations and rights of the Customer. Each Schedule adds the detail specific to a module.
3.3 The Customer determines the lawful basis. The Customer is responsible for establishing and documenting a lawful basis for each element of the Processing, for issuing the privacy information required to Data Subjects, for any signage or notices its own law requires, and for any consent it relies on. MyGatePass does not obtain consent from Data Subjects for the Customer's Processing, and no provision of the agreement between the Parties is to be read as MyGatePass doing so.
3.4 The Customer's own compliance. The Customer warrants that it has the authority to instruct the Processing, that it will not instruct MyGatePass to Process Personal Data unlawfully, and that it will not upload or enter categories of Personal Data materially beyond those described in Annex A and the applicable Schedules without instructing MyGatePass under clause 4.2.
3.5 Where MyGatePass acts as controller. MyGatePass acts as controller in its own right, and not as processor, in respect of: (a) support correspondence with the Customer's personnel; (b) MyGatePass's own staff account, authentication and audit records, excluding records of MyGatePass's access to the Customer's tenant written to the Customer's audit trail, which are Customer Personal Data; (c) security and platform telemetry that does not identify a Data Subject of the Customer; (d) billing and account administration; and (e) the MyGatePass Visitor App account of an individual who installs that application, together with any Visitor Record that individual elects to keep under clause 3.10. MyGatePass Processes that data under its own privacy notice and remains bound by clause 5.2 in respect of any Customer Personal Data it contains.
3.6 Data of children. Where the Services are used in a setting involving children, MyGatePass acknowledges that the Processing concerns the Personal Data of children and that this raises the standard of care expected of it.
3.7 Free-text fields. The Services include free-text fields whose content is determined entirely by the Customer's personnel. Depending on what is entered, those fields may contain Sensitive Personal Data. The Customer is responsible for what its personnel enter into them and for any additional basis its own law requires for that content. MyGatePass applies the protections in Annex B to those fields but cannot control their content.
3.8 Cooperation with a Regulator. MyGatePass will cooperate, on request, with any Regulator in the performance of that Regulator's tasks in relation to the Processing, and will inform the Customer of any such request concerning Customer Personal Data unless legally prohibited from doing so.
3.9 Where GDPR or UK GDPR applies to the Customer. Where the Customer is subject to the EU GDPR or the UK GDPR, this DPA is intended to satisfy Article 28(3) of that instrument, and clauses 4 to 11 are to be read as giving effect to it. MyGatePass applies the measures in Annex B and clauses 4 to 11 of this DPA to all Customers, irrespective of whether the EU or UK GDPR applies to them.
3.10 The Visitor Record, disclosed. The MyGatePass Visitor App keeps, for each individual who uses it, a record of that individual's own visits (a "Visitor Record"), so that the individual can see their own history. It is a feature of the Visitor App and is created when the individual uses the Services to enter a site. MyGatePass writes it as a separate record, held in a separate store, as controller in its own right, and not as part of the Customer's tenant. MyGatePass states this in the DPA so that the Customer knows of the arrangement before accepting it, rather than discovering it later.
The following apply to every Visitor Record, and MyGatePass will not reduce them other than in accordance with clause 1.4:
- Contents. A Visitor Record contains only the site visited, the date and time of the visit, and the individual's own MyGatePass account identity. It contains no field originating in the Customer's record, and in particular no host, no stated purpose of visit, no permit or contractor detail, no vehicle plate or plate read, no access or release decision, no restriction or welfare flag, and no free-text content.
- No linkage. A Visitor Record carries no identifier that links it to the Customer's tenant record, and the Customer's record cannot be derived or reconstructed from it.
- Transparency and right to object. The individual is told, in the Visitor App and in MyGatePass's privacy notice, that the record exists, what it contains and the purposes for which MyGatePass uses it. Where MyGatePass uses Visitor Records to produce irreversibly anonymised and aggregated statistics, the individual may require MyGatePass to stop that use at any time by notifying it, and MyGatePass will stop and confirm within 30 days. Exercising that right does not require the individual to delete their profile, their record, or anything else, and does not affect their use of the Services or the Customer's own record.
- Adults only. A Visitor Record exists only for an account holder who has reached the age of majority, MyGatePass accounts being for adults.
- Deletion. The individual may delete their MyGatePass profile at any time in the application, which deletes their Visitor Record with it. Deletion of a Visitor Record has no effect on the Customer's own record, and deletion of the Customer's record has no effect on a Visitor Record.
- No effect on the Customer's record. The existence of a Visitor Record neither adds to nor subtracts from what MyGatePass Processes on the Customer's behalf, and it is not a disclosure of Customer Personal Data to any third party.
- Retention. As stated in Annex C Part 2, independently of any period the Customer sets under clause 10.1.
- The Customer's own record is unaffected. Where the Customer has enabled the School Module, the Customer's own record of every release, including the rule that produced it, any staff override and the operator's identity, is created and retained in the Customer's tenant as a complete and auditable trail, in accordance with Schedule 1 and Annex C. The Customer is its controller. Nothing in this clause changes, limits, shortens or deletes that record, and no individual right in respect of a Visitor Record operates against it.
- No commercial use of School Module data, ever. MyGatePass will not use any Customer Personal Data connected with the School Module, and will not use the Personal Data of any student, parent, guardian or other collecting adult, to produce statistics or insights or for any other commercial purpose, whether that data sits in the Customer's record or in a Visitor Record. This prohibition is absolute, is not capable of variation by the addendum described in clause 5.2, is not limited in time, and survives termination.
MyGatePass Processes a Visitor Record under its own privacy notice and for its own purposes, which may include the production of irreversibly anonymised and aggregated statistics. Clause 5.2 continues to apply in full to Customer Personal Data, and nothing in this clause permits MyGatePass to use, copy or derive from the Customer's record.
4. Instructions and purpose limitation
4.1 Purpose limitation. MyGatePass will Process Customer Personal Data only to provide the Services, as instructed under clause 4.2, as permitted by clause 3.5, to produce irreversibly anonymised data as described in clause 5.2, and as required or permitted by clauses 8.6, 8.7 and 10.2.
4.2 Instructions. MyGatePass Processes Customer Personal Data only on the Customer's documented instructions. The Customer's initial instructions are: the Terms and Conditions or Service Agreement; this DPA and its Annexes and applicable Schedules; and the configuration of the Customer's MyGatePass account, including the modules and features enabled for it at its request, and the permissions it grants its own users. Retention periods are set by MyGatePass and are stated in Annex C, and the categories of Personal Data Processed follow from the modules enabled, as described in Annex A and the applicable Schedules. Further instructions must be given in writing to the contact in Annex D.
4.3 Where MyGatePass is required by law to Process Customer Personal Data otherwise than on the Customer's instructions, including to transfer it, it will inform the Customer of that requirement before Processing, unless the law prohibits that on important grounds of public interest.
4.4 Unlawful instructions. If MyGatePass considers that an instruction infringes Applicable Data Protection Law, it will immediately inform the Customer. It may suspend performance of that instruction only after informing the Customer and only for so long as reasonably necessary to resolve the point. Where a Schedule applicable to the Customer identifies a function as safety-critical, that Schedule's provision applies instead of this clause.
5. MyGatePass's obligations
MyGatePass performs the obligations in this clause 5 as processor, in satisfaction of the processor obligations of UAE Federal Decree-Law No. 45 of 2021 and, where it applies to the Customer, Article 28 EU or UK GDPR.
5.1 Confidentiality of personnel. MyGatePass will ensure that every person authorised to Process Customer Personal Data is subject to a duty of confidence, has completed training appropriate to the role, and has been screened before an account is issued.
5.2 No secondary use. MyGatePass will not:
- use Customer Personal Data, including in de-identified, pseudonymised or redacted form, to train, fine-tune or improve any machine-learning model, or permit any third party to do so. This prohibition is absolute. It is not subject to the addendum described at the end of this clause, is not limited in time, and survives termination;
- use Customer Personal Data for market research, marketing, resale, or disclosure to any third party except as this DPA permits;
- combine Customer Personal Data with the data of any other customer, or with data from any other source, in any form from which the Customer or a Data Subject can be identified; or
- disclose to any third party any statistic or insight derived from Customer Personal Data from which the Customer or a Data Subject can be identified.
Permitted. Nothing in this clause prevents MyGatePass from using irreversibly anonymised and aggregated data for platform performance analysis, capacity planning, abuse and fraud detection, reliability engineering, security improvement, and improvement of the Services. That means data from which neither the Customer nor any Data Subject can be identified, whether alone or with other information reasonably available. Anonymisation for this purpose is not a secondary use of Personal Data, and the resulting data is not Customer Personal Data.
Models. The machine-learning prohibition in this clause applies to Customer Personal Data in any form, including de-identified, pseudonymised and redacted forms, and is absolute. It does not prevent MyGatePass from developing statistical or machine-learning models on irreversibly anonymised and aggregated data of the kind described in the preceding paragraph, which is not Personal Data. Where MyGatePass does so it will not attempt, and will not permit any third party to attempt, to re-identify the Customer or any Data Subject from such data or from any model derived from it, and will not publish or supply any output that identifies the Customer or a Data Subject or that describes an individual site.
Addendum. The second, third and fourth prohibitions in this clause apply except to the extent the Customer expressly agrees otherwise in a separate written addendum signed by both Parties, which will state the data included, the purposes permitted, the safeguards and thresholds applied, and its term. The machine-learning prohibition in the first bullet is not capable of being varied by such an addendum. MyGatePass will not offer or enter into such an addendum with a Customer that has enabled the School Module. Absent a signed addendum, this clause applies in full, and acceptance of the Terms and Conditions or of this DPA is not agreement to any such addendum.
Flow-down. MyGatePass will impose the prohibitions in this clause on each Subprocessor by written agreement to the extent it is able to do so, and will not engage a Subprocessor whose terms permit the use of Customer Personal Data to train, fine-tune or improve a machine-learning model. Where a Subprocessor receives only a device token, or a message payload containing no identifier of a Data Subject, MyGatePass relies on the minimisation stated for that Subprocessor on the Subprocessor List.
The prohibitions in this clause are not limited in time and survive termination.
5.3 AI tooling, disclosed. MyGatePass uses third-party AI services for internal operational tooling only. MyGatePass does not submit Customer Personal Data to any AI service, save as described in this clause. The one adjacent flow, disclosed rather than left to be discovered: text originating in a support ticket may be submitted for triage and summarisation after identifying information has been removed by an automated redaction step. MyGatePass describes that step rather than warranting a particular implementation, and will treat any submission of Customer Personal Data to an AI service as a Personal Data Breach under clause 6. On written request to the contact in Annex D, MyGatePass will disable that step in respect of tickets raised by the Customer's personnel. On the basis described above the AI providers are not Subprocessors and do not receive Customer Personal Data. If that basis ceases to hold, MyGatePass will add them to the Subprocessor List under clause 7.2.
5.4 No biometric processing without consent. MyGatePass represents and warrants that the Services perform no facial recognition, biometric identification, biometric categorisation, occupant or in-cabin imaging, gait analysis or emotion inference. Where a module performs automated number-plate recognition, that recognition is designed to identify a vehicle rather than a person. MyGatePass will not introduce any such capability without the Customer's prior written consent. Breach of this clause is a material breach.
5.5 Personnel and access. MyGatePass:
- will grant access to Customer Personal Data only to authorised personnel whose normal place of work is the United Arab Emirates, and will not grant standing, temporary or just-in-time access to production systems or to Customer Personal Data to any person whose normal place of work is outside the United Arab Emirates without first giving the Customer's Notice Contact at least 30 days' written notice stating the change and the reason for it. The Customer may object within that period on reasonable data-protection grounds, and clause 7.3 applies to that objection as if it were an objection to a Subprocessor. Occasional access by an authorised person while travelling does not breach this clause, provided the access is from a managed device with multi-factor authentication and is logged;
- will not export, copy or replicate Customer Personal Data to any environment or endpoint outside the United Arab Emirates, other than to a Subprocessor on the Subprocessor List for the purpose stated there;
- will not knowingly use Customer Personal Data in any non-production, development, test or training environment, and will use synthetic or irreversibly anonymised data for those purposes. Where Customer Personal Data is required to reproduce a defect, MyGatePass will obtain the Customer's prior written consent, minimise the data used, and delete it on closure of the defect;
- will grant access on a just-in-time basis against a stated business justification, time-bound and automatically revoked, subject to multi-factor authentication, requiring a compliant managed device, and recorded in the Customer's own audit trail; and
- will, where the Customer requests it, obtain the Customer's consent by email to its Notice Contact before each elevation of MyGatePass access to the Customer's tenant, and will make a tenant setting for this available as described in Annex B. That requirement does not apply where access is necessary to respond to an incident affecting the availability, integrity or security of the Services, or to a safety or safeguarding incident; in those cases MyGatePass may access the tenant immediately and will notify the Customer of the access, and the reason for it, within one business day.
5.6 Minimisation at integration interfaces. Where the Services synchronise data from a Customer system, MyGatePass will synchronise only the fields in the field mapping displayed in the Customer's account for that integration. Enabling the integration constitutes the Customer's approval of that mapping. MyGatePass will not add a field to a default mapping, and will not collect categories of Personal Data beyond those described in Annex A and the applicable Schedules, without notice under clause 1.4 or the Customer's written instruction.
5.7 Records. MyGatePass will maintain a record of its Processing of Customer Personal Data containing the information required by Article 30(2) EU and UK GDPR and by the corresponding record-keeping provision of UAE Federal Decree-Law No. 45 of 2021, and will provide it within 15 business days of a written request.
5.8 Data protection contact. MyGatePass's Data Protection Contact, who is responsible for data protection matters and is the point of contact for the Customer and for any Regulator, is named in Annex D. MyGatePass will notify the Customer if the holder of that role changes. Stated so the Customer need not ask: MyGatePass has appointed a Data Protection Contact rather than a Data Protection Officer within the meaning of Article 37 EU and UK GDPR, on the basis of its assessment of the scale and nature of its Processing. It will appoint a Data Protection Officer if that assessment changes, and will notify Customers if it does.
6. Security and Personal Data Breach
6.1 Security measures. MyGatePass will implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including as appropriate pseudonymisation and encryption, measures to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems, the ability to restore availability and access in a timely manner, and a process for regularly testing, assessing and evaluating the effectiveness of those measures, being the testing and assurance activities described in Annex B.
6.2 The measures in place are described in Annex B. Annex B separates measures MyGatePass has verified from measures it operates as configured but has not yet evidenced, and from gaps. It states the position accurately, including where a control is not in place. The Customer acknowledges that it has reviewed Annex B, including the gaps identified in it, and has assessed those measures against its own risk before accepting the Services. Nothing in this clause relieves MyGatePass of clause 6.1.
6.3 MyGatePass will not reduce the overall level of protection described in Annex B other than in accordance with clause 1.4, and will publish an updated Annex B before any change that would materially affect it.
6.4 Standard of care. MyGatePass holds ISO/IEC 27001:2022 certification. Certification is not a warranty that every control described in Annex B is independently evidenced, and Annex B identifies which are not. Any designation of ISO/IEC 27001 as a standard of care elsewhere in the agreement between the Parties does not limit clause 6.1.
6.5 Breach notification. MyGatePass will notify the Customer of a Personal Data Breach affecting Customer Personal Data without undue delay after becoming aware of it, and in any event within 72 hours. "Without undue delay" is the operative obligation; the 72-hour period is an outer limit, not a permitted period of delay. MyGatePass will in any event notify in sufficient time for the Customer to meet its own obligations, noting that UAE Federal Decree-Law No. 45 of 2021 requires a controller to notify the Regulator immediately on becoming aware, and that Article 33 EU and UK GDPR gives a controller 72 hours from its own awareness.
6.6 Awareness means the point at which MyGatePass has a reasonable degree of certainty that a security incident involving Customer Personal Data has occurred. It is not conditional on MyGatePass having completed its investigation or classified the incident, and MyGatePass will investigate promptly on becoming aware of facts suggesting a Personal Data Breach may have occurred.
6.7 Where MyGatePass holds enough information to be useful before it has a complete picture, it will make an initial notification promptly rather than waiting, so that the Customer can begin its own assessment.
6.8 The notification will include, to the extent known: the nature of the breach; the categories and approximate number of Data Subjects and records affected; whether Sensitive Personal Data or the data of children is involved; the likely consequences; the measures taken or proposed; and a point of contact. Information not available at the time will be provided as it becomes available and without a further request.
6.9 Assistance. MyGatePass will assist the Customer in meeting its own obligations in respect of the breach, including by providing the information the Customer reasonably requires for its notification to a Regulator or to Data Subjects, taking reasonable measures to contain and mitigate the breach, preserving evidence to the extent the relevant records are within the retention periods in Annex C and using the monitoring described in Annex B, providing a written post-incident report with root cause and corrective actions to the extent those records allow, and taking part in a joint review if the Customer requests one.
6.10 MyGatePass will not notify a Regulator or any Data Subject about a Personal Data Breach affecting Customer Personal Data without the Customer's instruction, that being the Customer's decision, save where MyGatePass is required to notify in its own capacity as controller under clause 3.5, in which case it will inform the Customer before doing so and will not disclose Customer Personal Data beyond what is legally required.
7. Subprocessors
7.1 Authorisation. The Customer gives general written authorisation for MyGatePass to engage the Subprocessors on the Subprocessor List. That list identifies each Subprocessor, the country in which it Processes Customer Personal Data, the Processing it performs, and the categories of data it receives.
7.2 Notice of change. MyGatePass will publish any addition or replacement to the Subprocessor List and will notify the Customer's Notice Contact by email at least 30 days before the new Subprocessor begins Processing Customer Personal Data. The notice will state the Subprocessor's identity, the country in which it will Process Customer Personal Data, the Processing it will perform, the categories of Customer Personal Data it will receive, and the transfer basis relied on.
MyGatePass will give the same notice before (a) a change in the country in which an existing Subprocessor Processes Customer Personal Data, whether or not the Subprocessor is replaced, and (b) any change to the description of the Processing, the categories of data received, or the minimisation applied to any Subprocessor on the List.
7.3 Right to object. The Customer may object within that period on reasonable data-protection grounds, stating them. Where an objection is not resolved, the Customer may terminate the affected Services, without penalty, and MyGatePass will refund fees paid in advance for the terminated part pro rata. This clause prevails over any provision of the agreement between the Parties on termination for convenience or refunds.
7.4 Flow-down. MyGatePass will impose on each Subprocessor, by written agreement, data-protection obligations no less protective than those in this DPA, including clause 5.2, and will provide on request a copy of or extract from the relevant data-protection terms, subject to the confidentiality obligations owed to the Subprocessor and to redaction of commercial terms. Where a Subprocessor engages a further processor to Process Customer Personal Data, the flow-down in this clause requires equivalent terms and clause 7.5 applies to that further processor as if it were a Subprocessor. The Subprocessor List identifies the Subprocessors engaged by MyGatePass.
7.5 Liability for Subprocessors. MyGatePass remains fully liable to the Customer for the acts and omissions of each Subprocessor as if they were its own.
8. Data residency and international transfers
8.1 Residency. MyGatePass will configure the Services so that Customer Personal Data is stored at rest in Microsoft Azure UAE North, with backup replication to Microsoft Azure UAE Central, and so that the compute that Processes Customer Personal Data and the log workspace holding its telemetry are provisioned in those regions. Both are in the United Arab Emirates.
MyGatePass does not operate parallel production estates in other geographies. Any requirement for residency in another region is scoped, agreed and priced separately, and until it is, this clause states the position.
8.2 MyGatePass will not relocate any of the foregoing outside the United Arab Emirates without first giving the Customer's Notice Contact at least 30 days' written notice stating the change and the reason for it. The Customer may object within that period on reasonable data-protection grounds, and clause 7.3 applies to that objection as if it were an objection to a Subprocessor. This clause prevails over any provision of the agreement between the Parties permitting MyGatePass to host or Process data on a cloud-agnostic basis or in any other region.
8.3 Platform layer, stated so the Customer is not misled. Certain Microsoft Azure services involve global control-plane, routing and service-management processing that Microsoft operates outside a single region. MyGatePass cannot promise more on that point than Microsoft does in the Microsoft Products and Services Data Protection Addendum and its published data-location commitments, which apply to that platform layer. Clause 8.1 concerns Customer Personal Data content.
8.4 Supporting services outside the UAE. Certain services on the Subprocessor List operate outside the United Arab Emirates. The Subprocessor List states, for each, the country in which it Processes Customer Personal Data, the data it receives, and the minimisation applied. The Customer authorises those transfers on the terms stated there, and clause 7.2 requires notice before any of those terms changes. No authorisation is given for any country not identified on the Subprocessor List or notified under clause 7.2 and not objected to.
8.5 Transfer basis. MyGatePass relies on Article 23 of UAE Federal Decree-Law No. 45 of 2021, which permits a transfer in the absence of an adequate level of protection where it is supported by a contract obliging the recipient to comply with that law, and supports each transfer with contractual data-protection clauses with the Subprocessor concerned. Stated rather than glossed, and as at the version date of this DPA: MyGatePass is not aware of an adequacy determination by the UAE Data Office under Article 22 covering those destinations, and the executive regulations under that law have not been issued. MyGatePass will keep the position under review and will put a different or additional instrument in place if one becomes required. This clause records MyGatePass's understanding and is not legal advice to the Customer.
Where Applicable Data Protection Law requires the Data Subject's consent or another condition to be satisfied for a transfer of the kind described in clause 8.4, the Customer is responsible for satisfying it, and clause 3.3 applies.
Where the Customer is subject to the EU or UK GDPR, the transfer clauses in Annex F are incorporated into this DPA and take effect on acceptance. No separate signature is required. The transfer risk assessment required by those clauses is the Customer's, as data exporter. MyGatePass will provide, on request, the information the Customer reasonably requires for that assessment, including on the law of the United Arab Emirates and on the position on government access described in clause 8.6.
8.6 Government and authority access. MyGatePass is established in the United Arab Emirates and UAE authorities may compel disclosure under UAE law. No provision of this DPA overrides that. MyGatePass will not disclose Customer Personal Data to any authority voluntarily, save as permitted by clause 8.7. On receiving a request it will require the request to be in writing, legally valid and from an authority with jurisdiction; will review it with external counsel; will disclose only the minimum required; and will inform the Customer so that the Customer may respond or challenge, unless legally prohibited, in which case it will use reasonable efforts to have the prohibition lifted.
8.7 Threat to life or safety. Where there is a genuine and imminent threat to the life or safety of a person, MyGatePass may disclose the minimum necessary Customer Personal Data to the appropriate authority, or to the Customer's designated safety or safeguarding contact where one is set in the Customer's account and otherwise to its Notice Contact, without waiting for the process in clause 8.6. It will record the disclosure and inform the Customer as soon as practicable.
9. Data Subject rights, assistance and audit
9.1 MyGatePass will refer any request it receives from a Data Subject in respect of Customer Personal Data to the Customer within 3 business days and will not respond to it substantively itself, except to acknowledge receipt and identify the Customer as responsible.
9.2 MyGatePass will assist the Customer in responding to requests for access, rectification, erasure, restriction, portability and objection, and in relation to rights concerning automated decision-making, including by providing the technical means to locate, extract, correct, restrict and delete the relevant Personal Data.
9.2A Automated decisions. Where an automated rule determines an access, entry or release outcome, MyGatePass versions the rule set, retains each version for as long as any decision record made under it, and will on request provide an extract of the decision record identifying the rule that produced a given outcome and the rule-set version in force. MyGatePass will not introduce artificial intelligence or machine learning into any such decision without the Customer's prior written consent and a prior assessment shared with the Customer, and will retain the deterministic and fail-closed operation of those decisions, and any human verification and override step, as design invariants.
9.3 MyGatePass will assist the Customer with data protection impact assessments and with any prior consultation with a Regulator in relation to the Services, and will provide the information about the Processing the Customer needs for that purpose.
9.4 Charges for assistance. MyGatePass will provide reasonable assistance under clauses 6.9, 9.2, 9.2A, 9.3, 9.5, 9.6, 9.8 and 10, and will make available the information in clause 5.7, at no additional charge, within the timescales the Customer reasonably requires to meet its own statutory deadlines. Where a single request, or a series of related requests, requires effort materially beyond that, for example a large-scale regulatory investigation, litigation support, or a bespoke extraction, MyGatePass may charge at its standard professional-services rates, agreed in advance in writing. No charge applies where the assistance is required as a result of MyGatePass's breach of this DPA.
9.5 Information rights. MyGatePass will make available the information reasonably necessary to demonstrate compliance with this DPA, including its ISO/IEC 27001 certificate, scope statement and Statement of Applicability, its policy index, its configuration evidence pack, and its vulnerability summary with severity counts and remediation status. MyGatePass produces the evidence pack and the vulnerability summary in the same form for all Customers and makes its then-current versions available; it does not prepare a bespoke pack per Customer.
9.6 Audit. The Customer, or an auditor it appoints who is not a competitor of MyGatePass and who is subject to confidentiality obligations, may audit MyGatePass's compliance with this DPA once in any twelve-month period on at least 30 days' written notice, and additionally following a Personal Data Breach affecting its Customer Personal Data or where a Regulator requires it. Audits will be conducted during business hours, will not unreasonably disrupt MyGatePass's operations, and will not extend to any other customer's data. MyGatePass may satisfy a request under this clause by providing its then-current ISO/IEC 27001 certificate, scope statement and Statement of Applicability, its configuration evidence pack, its completed information security questionnaire, and written answers to the Customer's questions. Where those are insufficient, the Customer may conduct an auditor-led audit, and MyGatePass may recover its reasonable costs for any such audit exceeding two working days.
9.7 Security testing. The Customer may test the security of the Services once in any twelve-month period, at its own cost, subject to a written scope agreed in advance and to testing being conducted against the test environment MyGatePass makes available for that purpose unless the Parties agree otherwise. Clause 9.4 does not apply to this clause.
9.8 MyGatePass will provide named-individual access lists on request and will review entitlements at least quarterly.
10. Retention, return and deletion
10.1 Retention. The retention periods for Customer Personal Data are set out in Annex C and are set by MyGatePass. MyGatePass configures and enforces them by automated deletion, with deletions logged, so that no category of Customer Personal Data is retained without a limit. Retention is not currently configurable by the Customer, and Annex C states the periods that apply rather than a set of options. Where the Customer requires a shorter period, Annex C sets out how to request it. MyGatePass will not lengthen a period in Annex C other than in accordance with clause 1.4.
10.2 MyGatePass will not retain Customer Personal Data longer than the applicable period, except where retention is required by law, in which case it will inform the Customer of the requirement and of the period.
10.3 Immutable stores. Where a record cannot be deleted because it sits in an append-only or immutable store, MyGatePass will say so in response to any deletion instruction and will delete it when that store's retention expires. Annex C states the retention of each such store.
10.4 On termination or expiry, MyGatePass will return or delete Customer Personal Data as follows. The Customer may elect return or deletion by written notice to the contact in Annex D before the end of the export window. Absent an election, MyGatePass will delete.
- a read-only export window of 30 days, which opens automatically on the effective date of termination or expiry and requires no request, with MyGatePass-assisted export in a machine-readable format at no additional charge;
- deletion from production systems within 30 days of the end of that window;
- deletion of residual copies from encrypted immutable backups as the backup rotation expires, being within 90 days on the point-in-time restore tier and within 90 days on the long-term retention tier. Copies within an immutable set cannot be selectively erased before their retention expires, and MyGatePass states this rather than promising otherwise;
- a certificate of deletion confirming deletion from production systems and the date on which the last residual backup copy is scheduled to expire. MyGatePass does not certify the destruction of individual copies within an immutable backup set, which it cannot do.
10.5 MyGatePass will continue to protect Customer Personal Data in accordance with this DPA for as long as it holds it, including during any wind-down period.
11. Term, liability and general
11.1 Term. This DPA takes effect on the earlier of the effective date of the agreement between the Parties and the date on which MyGatePass first Processes Customer Personal Data, applies to all such Processing including during implementation and onboarding, and continues for as long as MyGatePass Processes Customer Personal Data.
11.2 Affiliates. Where an Affiliate of the Customer uses the Services under the Customer's account, the Customer contracts on that Affiliate's behalf and is responsible for its compliance with this DPA.
11.3 No third-party rights. This DPA confers no rights on any person who is not a Party, save that a Data Subject retains any right conferred directly by Applicable Data Protection Law and any third-party beneficiary right conferred by the transfer clauses in Annex F where those apply.
11.4 Liability. Liability under this DPA is governed by the limitation of liability provisions of the Terms and Conditions or Service Agreement that incorporates it.
11.5 Governing law. This DPA is governed by the laws of the United Arab Emirates and the courts of Dubai have exclusive jurisdiction, as provided in the agreement between the Parties, save where that agreement specifies a different governing law and forum, in which case those apply, and save that where the transfer clauses in Annex F apply, the governing law and forum stated in Annex F apply to those clauses.
11.6 Severability. If any provision of this DPA is invalid or unenforceable, the remainder continues in effect.
11.7 Notices. Notices and instructions under this DPA are given to MyGatePass at the contact in Annex D, and to the Customer at its Notice Contact, in writing. A notice from MyGatePass by email is deemed received on the day it is sent to the address then held on the Customer's account, unless MyGatePass receives a delivery-failure message; MyGatePass will in addition post the notice in the Customer's account. A notice to MyGatePass is effective on receipt.
Annex A: Details of the Processing
Subject matter. Provision of the MyGatePass Services the Customer has subscribed to.
Duration. The term of the agreement between the Parties, plus the wind-down periods in clause 10.4.
Nature and purpose. Managing and recording the entry, presence and exit of people and vehicles at the Customer's sites; verifying identity and authorisation; issuing and checking passes and permits; notifying the Customer's personnel and the individuals concerned; recording events and decisions for audit; and reporting to the Customer. Module-specific purposes are in the Schedules.
Categories of Data Subject. Visitors; contractors and their personnel; the Customer's own staff and authorised users; vehicle keepers and drivers; and MyGatePass personnel whose identities and actions appear in the Customer's audit trail. Each Schedule may add further categories.
Categories of Personal Data. This list is exhaustive for the core Services. A category not listed here or in an applicable Schedule is Processed only if the Customer instructs it in writing under clause 4.2, in which case this Annex is treated as amended accordingly.
| Category | Detail |
|---|---|
| Visitor and contractor records | name, contact identifiers, employer, host, purpose of visit, identity-document reference where that feature is enabled for the Customer, entry and exit times |
| Permit and contractor-management records | permit details, scope of work, validity period, approvals, associated personnel and their competencies where the Customer records them |
| Vehicle data | number plate; plate-to-person association; where a module uses automated number-plate recognition, plate reads with confidence scores and vehicle still images |
| Access and gate events | event, time, gate, outcome, the rule or permission relied on, and any staff override with the operator's identity |
| Customer staff and user records | identity, role, permissions, and actions in the audit trail |
| Free-text fields | notes and restrictions entered by the Customer's personnel (see clause 3.7) |
| Audit records | before-and-after state for every modification, actor and timestamp |
| Identity verification attributes | where verification through a national or third-party digital identity service is enabled for the Customer, including UAE PASS, the identity attributes that service returns when the individual authenticates, being name, a verification reference and the confirmation that verification succeeded. No credential, password or authentication secret is received or stored. The identity service is not a Subprocessor: it returns attributes at the individual's own authentication rather than Processing Customer Personal Data on MyGatePass's behalf, and it is recorded on the Subprocessor List for transparency |
| Technical data | IP address, device identifier, session and timestamp metadata; device push tokens where notifications are enabled; and, where an optional location feature is enabled for the Customer, only the geofence-crossing event and not location history |
Sensitive Personal Data. No health, racial origin, political or philosophical opinion, religious belief, criminal-record or biometric data is collected as such by the core Services. Free-text fields are the exception (see clause 3.7). The Parties do not purport to determine the classification of any particular content, which is a matter of law. MyGatePass treats free-text restriction and welfare fields as the most sensitive class in the Services: separately permissioned, encrypted at the application layer, individually audited, excluded from lower-privilege exports, and excluded from any AI tooling path within the Services. These measures are described in Annex B section B2 and are subject to the qualification stated there. MyGatePass cannot prevent the Customer's personnel from including such content in a support ticket; clause 5.3 applies to that content.
Recipients. As set out in the Subprocessor List.
Obligations and rights of the Customer
The Customer:
- determines the purposes and means of the Processing and the lawful basis for each element, and satisfies itself that the retention periods in Annex C are appropriate for its own purposes;
- issues the privacy information required to Data Subjects, and provides any signage its own law requires where a module captures images or plates;
- reviews the field mapping shown in its account before enabling an integration with its own systems, that mapping being the minimisation control for that interface;
- decides, and instructs MyGatePass on, which modules and features are enabled for its deployment, including any feature that captures images, plates or location;
- administers its own users' permissions within the Services;
- keeps its Notice Contact and the contacts in its account current; and
- has the rights set out in clauses 1.4, 7.3, 9 and 10, and the right to give and withdraw instructions under clause 4.2.
Annex B: Technical and organisational measures
This Annex states the position at the version date of this DPA. It separates measures MyGatePass has verified from measures it operates as configured but has not yet evidenced, and from gaps. It prevails to the extent of any inconsistency with another description of MyGatePass's security posture, but does not reduce any measure MyGatePass has separately represented in writing.
B1: Verified
Checked by MyGatePass against the running environment on the dates stated. MyGatePass re-verifies this section at least annually and republishes this Annex under clause 1.4 with updated dates.
| Area | Measure | Basis |
|---|---|---|
| Data residency | Customer Personal Data stores in Azure UAE North with backup replication to Azure UAE Central. No production data store outside the United Arab Emirates | Subscription enumerated 29 August 2026 |
| Certification | ISO/IEC 27001:2022 certification held | Certificate available |
| Monitoring, as it actually is | Microsoft Defender for Cloud for posture and workload threat detection, and Azure Application Insights for application monitoring, with alerting to an on-call engineer | Verified 21 August 2026 |
| Log retention | Platform and telemetry log retention of 90 days | Verified 21 August 2026 |
| Availability design | Zone-redundant deployment within Azure UAE North; geo-redundant backup to Azure UAE Central | Resource configuration |
B2: Operated as configured, evidence not yet produced
These are the measures MyGatePass operates. It has not yet produced configuration exports evidencing each, and states that rather than presenting them as verified. MyGatePass will produce a configuration evidence pack covering this section on the Customer's request. Nothing in this section is warranted as independently evidenced.
| Area | Measures |
|---|---|
| Encryption | TLS 1.2/1.3 in transit including integration channels, with certificate pinning in the gate application; AES-256 at rest; application-layer encryption additionally on free-text restriction and welfare fields, contact identifiers and vehicle plates; keys held in Azure Key Vault with rotation, soft-delete and purge protection, and not in source or images |
| Network | Data stores behind private endpoints with public network access disabled; Azure web application firewall with the OWASP Core Rule Set; DDoS protection; default-deny firewalling; all Customer-side traffic outbound-initiated, so no inbound path into the Customer's network is opened |
| Access control | Role-based and attribute-based access control; free-text restriction and welfare fields behind a separately granted permission not included in any general operational role; multi-factor authentication on privileged accounts; conditional access through Microsoft Entra ID; database access brokered through a bastion path with session logging and break-glass accounts under controlled custody; no standing MyGatePass access to tenant data; just-in-time, justified, time-bound and revocable elevation, logged to the Customer's audit trail; quarterly entitlement review |
| Tenant isolation | Tenant scope enforced in the data-access layer and independently by database row-level security; per-tenant storage partitioning; automated isolation tests in the build pipeline |
| Audit | Audit store configured as append-only with an immutability policy and legal-hold capability; tenant administrators can search and export their own tenant's records in product |
| Backup | Encrypted immutable retention-locked backups; point-in-time restore; long-term retention tier per Annex C |
| Development | Documented secure development lifecycle; static analysis, secret scanning and dependency scanning in the merge path; dynamic scanning; purpose-written tests for tenant isolation, object-level authorisation and the fail-closed default of any automated access decision; a documented incident response plan including a personal-data-breach sub-process |
| People | Screening before an account is issued; confidentiality agreements; annual security and privacy training; revocation of access on exit |
| Retention enforcement | Automated tenant-level retention jobs that delete rather than archive, enforcing the periods in Annex C, with deletions written to a deletion log |
| Testing and assurance | Static analysis, secret scanning and dependency scanning in the merge path; dynamic scanning; automated tenant-isolation and object-level-authorisation tests in the build pipeline; continuous posture assessment through Microsoft Defender for Cloud; quarterly entitlement review; annual re-verification of section B1. No independent penetration test and no recorded restore test (see B3) |
| Access consent setting | A tenant setting requiring the Customer's prior consent for each elevation of MyGatePass access, as referred to in clause 5.5. Where the setting is not yet available in product, MyGatePass performs the equivalent by email to the Customer's Notice Contact |
| Fallback procedures | Where the Customer uses a module with a documented operational fallback, including the manual dismissal fallback under Schedule 1, MyGatePass makes that procedure available to the Customer to adopt and maintain |
| Recovery targets | Design targets of RTO 4 hours and RPO 15 minutes, not yet validated through a recorded restore test |
B3: Not in place
Stated rather than omitted, because these bear on the obligations in this DPA.
| Gap | Position |
|---|---|
| No security information and event management system, no centralised security event collection, and no operating detection rules | What operates is Defender for Cloud and Application Insights with on-call escalation. Domain-specific abuse detections described in solution design documents are design intent and are not operating controls |
| No network intrusion detection or prevention appliance | Cloud-native network threat detection operates instead. In a platform-as-a-service estate with no MyGatePass-owned network fabric there is no tap point for an appliance |
| No 24×7 staffed security operations centre and no managed detection and response provider | Automated detection and alerting run continuously and an engineer is reachable at all times by on-call escalation. There is no dedicated staffed security operations function |
| Business continuity and disaster recovery plans are not documented and no restore test has been recorded | The technical recovery capability exists: point-in-time restore, geo-redundant backup and infrastructure-as-code redeployment. The written plan, the named owner and a recorded restore test do not |
| No independent penetration test has been completed | The Customer is invited to test the Services under clause 9.7. MyGatePass does not commit to a date; where a Customer requires an independent test, MyGatePass will scope, schedule and price it |
| No cyber-liability insurance in force | MyGatePass does not currently hold cyber-liability insurance. Its current position is stated in its information security questionnaire, available on request |
| Encryption keys are platform-managed | Microsoft therefore has the technical capability to access key material, inherent to this cloud model. Customer-managed keys under the Customer's control would remove this and are not implemented today |
Further assurance and certification matters, being single sign-on, SOC 2, ISO/IEC 27701 and an external digital-forensics retainer, are addressed in MyGatePass's completed information security questionnaire, available on request.
Annex C: Default retention periods
The periods below are set by MyGatePass and are stated here so that the Customer knows exactly how long each category is held. None of them is currently configurable by the Customer. MyGatePass enforces them by automated deletion, with deletions logged, and will not lengthen any of them other than in accordance with clause 1.4.
Part 1: Customer Personal Data
Every period in this Part is set by MyGatePass and applies automatically. MyGatePass configures and enforces them by automated deletion, with deletions logged. Retention is not currently configurable by the Customer, and this Part states the periods that run rather than a menu of options. MyGatePass will not lengthen a period in this Part other than in accordance with clause 1.4, which requires 30 days' notice and gives the Customer a right to object.
| Category | Period | Note |
|---|---|---|
| Visitor and contractor records | 12 months | |
| Permit records | validity period plus 12 months | |
| Vehicle images captured by number-plate recognition | 30 days | The shortest of any class. A gate image is the most intrusive artefact the Services create and its operational value expires almost immediately: it exists to resolve a disputed or failed read, not to build a record |
| Plate reads and confidence scores | 30 days, or as part of an access event record where one was created | |
| Plate-to-person associations | duration of the association plus 30 days | |
| Access and gate event records | current calendar year plus 12 months | |
| Customer staff and user records | duration of the individual's authorisation plus 12 months | |
| Identity verification attributes | as part of the visitor or staff record they verify | No credential or authentication secret is retained |
| Free-text restriction and welfare fields | duration of the underlying relationship | The Customer should review these at least annually and remove those no longer required. A restriction that is no longer valid is itself a harm. MyGatePass cannot make that judgement for the Customer, and does not delete them automatically while the relationship continues |
| Geofence-crossing events, where enabled | 30 days | No location history is retained |
| Device push tokens | on uninstall or account closure, and in any event 180 days after last use | |
| Technical data (IP address, device identifier, session metadata) | 90 days | |
| Platform and telemetry logs containing Customer Personal Data | 90 days | The verified current configuration. MyGatePass does not commit to a longer period |
| In-product audit records, including before-and-after state | matching the event records they describe | Held in an append-only store: a record cannot be deleted before this period expires, and clause 10.3 applies |
| Deletion logs | 12 months | Retained to evidence that deletion occurred |
| Backups (point-in-time restore tier) | up to 90 days | |
| Backups (long-term retention tier) | up to 90 days | Configured so that no residual copy containing Customer Personal Data persists beyond 90 days. This bounds the residual window in clause 10.4 |
Where the Customer requires a shorter period than one stated above, it may request it in writing to the contact in Annex D. MyGatePass will confirm within 15 business days whether it can be applied to that Customer's tenant and, where it cannot, will say so plainly rather than leaving the request open.
Module-specific defaults are in the applicable Schedule and prevail over this Part for that module.
Part 2: Data MyGatePass holds as controller under clauses 3.5 and 3.10
Stated for transparency. Clause 10.1 does not apply to this Part.
| Category | Period |
|---|---|
| Visitor App account | until the individual closes the account, and in any event 12 months after last use |
| Visitor Records under clause 3.10 | until the individual deletes the record or closes the account, and in any event 24 months after the visit recorded |
| Support correspondence | 12 months |
| MyGatePass staff account, authentication and audit records | duration of employment or engagement plus 12 months |
| Security and platform telemetry not identifying a Data Subject of the Customer | 90 days |
| Billing and account administration records | as required by UAE tax and company law |
Annex D: Contacts
MyGatePass
| Role | Contact |
|---|---|
| Data Protection Contact | Adil Bouhouch, dpo@mygatepass.com |
| Notices under this DPA | legal@mygatepass.com |
| Security incidents | security@mygatepass.com |
| Subprocessor List | mygatepass.com/subprocessors |
Customer. MyGatePass gives notice to the Customer's Notice Contact as defined in clause 2, being the designated administrator and the administrative email address on the Customer's account. The Customer may add a dedicated data protection contact, a security incident contact, and a safety or safeguarding contact in its account settings, and MyGatePass will use those in preference to the administrative address where they are set. Keeping them current is the Customer's responsibility under Annex A.
Schedule 1: School Module (Pick-up and Dismissal)
This Schedule applies only where the Customer has enabled the School Module. It supplements the DPA; where it conflicts with the DPA, this Schedule prevails for that module.
S1.1 Additional purpose. Verifying the authority of an adult to collect a named student; evaluating an automated release decision; queueing and displaying call-forward instructions; notifying gate staff and guardians; recording the release event, its outcome, the rule that produced it and any staff override; and enforcing collection restrictions.
S1.2 Additional categories of Data Subject. Students; parents, guardians and other authorised collecting adults.
S1.3 Additional categories of Personal Data.
| Category | Detail |
|---|---|
| Student identity and school data | name, year group, class, timetable, location within site; date of birth or age band where the Customer's student information system supplies it; and photograph where that feature is enabled for the Customer |
| Guardian records | name, contact identifiers, relationship to student, authorisation to collect, notification preferences, collection history |
| Release and dismissal records | event, time, outcome, the rule that fired, the rule-set version, staff override and operator identity |
| Safeguarding data | collection restrictions, welfare flags, and free-text safeguarding notes (clause 3.7 applies) |
Sensitive Personal Data. Free-text safeguarding notes and collection restrictions may contain health, disability, religious, family, court-order or allegation information and may therefore constitute Sensitive Personal Data. The Customer is responsible for what its staff enter and for any additional basis its own law requires.
S1.4 Safety-critical functions. Notwithstanding clause 4.4, MyGatePass may not suspend any function on which the safe release of a student depends unless performance would be manifestly unlawful; in that case it will inform the Customer immediately, propose the least disruptive lawful alternative, and support the manual fallback under S1.6.
S1.5 The automated release decision. Clause 9.2A applies to the release decision, so the rule set is versioned and a decision can be replayed against the rules in force at the time. In addition, and specific to students: MyGatePass will retain the requirement for human verification at the gate and the staff override as design invariants, and will not remove either without the Customer's prior written consent.
S1.6 Availability at the point of release. The safe release of a student must not depend on the Services being available. MyGatePass makes a documented manual dismissal fallback procedure available to the Customer at onboarding and on request. The Customer is responsible for adopting and maintaining it, and will not rely on the Services as its only means of releasing a student. No sign-off is required for this DPA to take effect, and MyGatePass's obligations under it do not depend on the Customer adopting the procedure.
MyGatePass will not schedule planned maintenance during the Customer's own configured Dismissal Windows, and for maintenance affecting shared infrastructure will schedule outside all configured Dismissal Windows where practicable. The exception is a security update that cannot safely be deferred, in which case MyGatePass will give as much notice as the circumstances allow. MyGatePass will make an on-call contact reachable during each Dismissal Window and will notify the Customer of any unplanned unavailability affecting one as soon as it becomes aware of it. "Dismissal Window" means each period configured in the Services for the Customer's tenant during which students are released at a gate.
S1.7 Safeguarding incidents. Any incident with a child-safeguarding dimension will be escalated to MyGatePass's highest incident severity level, as defined in its incident response plan, and routed to the Customer's designated safeguarding contact where one is set in the Customer's account, and otherwise to its Notice Contact, as a safeguarding incident and not only as a technical one.
S1.8 Additional retention. Set by MyGatePass, on the same basis as Annex C, and prevailing over Annex C Part 1 for this module.
| Category | Period |
|---|---|
| Student identity and school data, including any photograph | duration of enrolment plus 12 months |
| Guardian records | duration of authorisation plus 12 months |
| Plate-to-guardian associations | enrolment plus 30 days |
| Release and dismissal event records | current academic year plus 12 months |
| Release rule-set versions | as long as any decision record made under that version |
| Safeguarding flags and notes | duration of enrolment. The Customer should review these at least annually and remove those no longer required, which MyGatePass cannot judge on its behalf |
Annex F: Transfer clauses (EU and UK)
This Annex applies only where the Customer is subject to the EU GDPR or the UK GDPR. It takes effect on acceptance of this DPA. No separate signature is required, and MyGatePass will execute a counterpart under Annex E on request.
F1: EU Standard Contractual Clauses
Where the Customer is subject to the EU GDPR, the Standard Contractual Clauses annexed to Commission Implementing Decision (EU) 2021/914, Module Two (controller to processor), are incorporated into and form part of this DPA, with the following elections:
| Provision | Election |
|---|---|
| Clause 7 (docking clause) | omitted |
| Clause 9(a) (subprocessors) | Option 2: general written authorisation. The notice period is 30 days, as provided in clause 7.2 of this DPA |
| Clause 11(a) (independent dispute resolution) | the optional wording is omitted |
| Clause 13 / Annex I.C (supervisory authority) | the supervisory authority of the Customer's place of establishment, or where the Customer is not established in the EU, the supervisory authority of the Member State in which its EU representative is established |
| Clause 17 (governing law) | Option 1: the law of Ireland |
| Clause 18(b) (forum) | the courts of Ireland |
| Annex I.A (parties) | the Parties identified in clause 1.1 and Annex D of this DPA. The Customer is the data exporter and controller; MyGatePass is the data importer and processor |
| Annex I.B (description of transfer) | the details in Annex A and any applicable Schedule of this DPA. Frequency: continuous. Duration: as clause 11.1 |
| Annex II (technical and organisational measures) | Annex B of this DPA |
| Annex III (subprocessors) | the Subprocessor List |
F2: UK Addendum
Where the Customer is subject to the UK GDPR, the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, version B1.0, issued by the Information Commissioner, is incorporated into and forms part of this DPA and applies to the clauses in F1, with the following completions:
| Table | Completion |
|---|---|
| Table 1 (parties) | as F1 Annex I.A. Key contact: as Annex D of this DPA |
| Table 2 (selected SCCs) | the clauses in F1, Module Two, with the elections stated there |
| Table 3 (appendix information) | Annex I.A, I.B, II and III as stated in F1 |
| Table 4 (ending the Addendum) | neither Party may end the Addendum as set out in Section 19 |
| Start date | the date the Customer accepts this DPA |
F3: Alternative instrument
Where the Customer prefers the UK International Data Transfer Agreement in place of F1 and F2, MyGatePass will execute it on request, completed consistently with this DPA.
F4: Transfer risk assessment
The assessment required by Clause 14 of the clauses in F1, and by the corresponding provision of the Addendum in F2, is the Customer's, as data exporter. MyGatePass will provide, on request, the information the Customer reasonably requires for it, including on the law of the United Arab Emirates, on the position on government access described in clause 8.6, and on the technical and organisational measures in Annex B.
Annex E: Execution (optional)
No signature is required for this DPA to take effect. This Annex is provided only where a Customer requires a signed counterpart. Signing does not vary the terms.
| Customer | MyGatePass | |
|---|---|---|
| Entity | MyGatePass FZ-LLC | |
| Name | ||
| Title | ||
| Signature | ||
| Date |
DPA version accepted: 1.0