Business legal
Data Processing Agreement
These standard terms apply where Kattegat processes personal data on a business customer's documented instructions as a processor. Each party remains responsible for processing for which it acts as controller.
Version 1.0 · 30 July 2026
1. Scope and applicable law
This Data Processing Agreement forms part of the applicable agreement between the customer and Hidden Diversion Recreational Services, operating as Kattegat. It applies to processor activities described in the customer's order form or service agreement.
Applicable data-protection law includes UAE Federal Decree-Law No. 45 of 2021 Regarding the Protection of Personal Data and other binding privacy law applicable to the processing. Statutory definitions of controller, processor, personal data, processing, data subject, and personal-data breach apply.
2. Instructions and responsibilities
Kattegat processes customer personal data only to provide the contracted services and on documented lawful instructions, including approved transfers, unless law requires otherwise. Kattegat will notify the customer if an instruction appears unlawful and may suspend the affected processing while it is resolved.
The customer is responsible for its notices, lawful basis, instructions, and the accuracy and legality of data supplied to Kattegat.
3. Confidentiality and security
Authorised personnel are subject to confidentiality duties. Kattegat maintains proportionate safeguards including access controls, least privilege, encrypted transport, credential protection, logging, vulnerability management, backup and recovery controls, and incident response.
4. Sub-processors
The customer generally authorises sub-processors needed to provide the service. Kattegat will impose materially equivalent protection obligations, remain responsible as required by law, and provide reasonable notice of material additions or replacements. Current provider categories may include database and authentication, media hosting, payments, caching, email or push delivery, and monitoring.
5. Assistance and incidents
Considering the nature of processing, Kattegat will reasonably assist with data-subject requests, impact assessments, regulator enquiries, compliance evidence, and security obligations.
Kattegat will notify the customer without undue delay after becoming aware of a confirmed personal-data breach affecting customer personal data, provide available information needed for lawful notifications, and take reasonable containment, investigation, and mitigation steps.
6. International transfers
Kattegat will transfer customer personal data across borders only with a mechanism or safeguard permitted by applicable law. The parties will execute reasonable supplementary terms required for a lawful transfer.
7. Return, deletion, and audits
At termination or written request, Kattegat will return or delete customer personal data within a reasonable period unless law requires retention. Protected backups remain isolated from ordinary use and expire under the normal backup schedule. Statutory financial, fraud, safety, and dispute records may be retained only for lawful purposes.
Kattegat will provide relevant compliance evidence on reasonable request. If that evidence is insufficient, a customer may request a proportionate, confidential, non-disruptive audit subject to reasonable notice and security controls.
8. Contracting and contact
Processing details, data categories, retention, security schedules, sub-processors, liability, and signatures may be completed in a customer order form or signed DPA. Governing law and dispute resolution follow the main agreement.
To request a signed DPA or current processing schedule, email seller@kattegat.app.
Kattegat in your pocket
Find the right connection wherever the work happens.
Discover services, review sellers, and continue the conversation from the Kattegat app — buyer and seller on one account.
- Discover
- Review
- Chat

