Data Processing Framework.
General public framework for B2B data-processing roles and responsibilities.
Framework Label
This page provides a general public framework describing how SHIFTFM approaches customer-data processing in standard service contexts. Where a signed order, enterprise agreement, or negotiated DPA applies, the relevant signed documents govern that relationship.
Roles of the Parties
Depending on the processing context, the customer may act as the controller or equivalent responsible party for the data it collects and enters into SHIFTFM, while SHIFTFM may act as a processor or service provider when processing such data to provide the service.
Where SHIFTFM determines purposes or means for its own business, security, support, or regulatory needs, SHIFTFM may act in a different role as permitted by applicable law.
Processing Scope and Instructions
Where SHIFTFM acts as a processor, it processes relevant Customer Data only to provide, secure, support, maintain, and improve the service, and in accordance with documented customer instructions reflected in the service configuration, order documents, support requests, or other agreed records.
Confidentiality
SHIFTFM limits access to Customer Data to personnel and authorized service providers who have a legitimate operational need and who are subject to appropriate confidentiality obligations.
Reasonable Security Measures
SHIFTFM applies reasonable technical and organizational measures proportionate to the nature of the service, the data involved, and the associated risks.
Service-Provider Categories
SHIFTFM may use specialized technical service providers for categories such as hosting, infrastructure, databases, backup, communications, data display, processing support, and related technical operations.
SHIFTFM may use technical service providers within categories such as hosting, infrastructure, databases, backup, communications, data display, processing support, and related technical operations needed to deliver the service.
Cross-Border Processing
Some technical components may require processing or storage through infrastructure outside the Kingdom of Saudi Arabia. In those cases, SHIFTFM manages that processing according to the legal requirements applicable to international transfer and cross-border processing in light of the data, the recipient, and the relevant legal basis.
Rights Requests Assistance
Where applicable and reasonably possible, SHIFTFM provides information or operational assistance needed for the customer to handle rights requests relating to Customer Data processed through the service.
Security Incident Cooperation
Where a security incident affecting Customer Data is identified, SHIFTFM works to assess, contain, investigate, and mitigate the incident, and cooperates with the customer regarding legally required or contractually agreed follow-up actions.
Return, Deletion, and Archival
Return, deletion, or archival of Customer Data is handled according to the agreed service documents, the nature of the environment, the service architecture, and applicable legal retention requirements.
Audit and Information Cooperation
Within reasonable operational and confidentiality limits, SHIFTFM may provide information reasonably needed to address customer diligence, security review, or contractual audit discussions.
Customer Responsibilities
The customer remains responsible for lawful collection of data, for ensuring that its instructions are lawful and appropriate, and for determining whether a more specific negotiated DPA is required for its use case.
Order of Precedence
If there is any conflict between this public framework and a signed order form, master agreement, or negotiated DPA, the signed commercial document or negotiated DPA controls to the extent of the conflict.