Legal
Data Processing Agreement
Processor terms that apply when VaultLabs handles personal data on behalf of a business customer, including security measures, sub-processors, and UAE PDPL commitments.
Last updated: 2026-08-06 · Version 2.0 · Effective 2026-01-01
When this agreement applies
For ordinary retail purchases we act as a data controller and our Privacy Policy governs. This Data Processing Agreement applies where a business customer — for example a laboratory, university, hospital procurement team, or distributor — provides us with personal data belonging to its own staff, researchers, or end recipients so that we can fulfil orders, arrange delivery, or issue documentation. In that arrangement the business customer is the controller and we act as processor for that data. This agreement forms part of our Terms and Conditions and takes effect without separate signature when a business account is approved, unless we have signed a separate written agreement, in which case that agreement prevails.
Roles and instructions
We process personal data only on documented instructions from the controller, which include the order, delivery, and documentation instructions given through your account, by email, or through the wholesale portal. We will tell you if we believe an instruction breaches applicable data protection law. We do not use controller personal data for our own marketing, do not sell it, and do not combine it with data from other customers.
Subject matter, duration, and categories of data
Subject matter: fulfilment of research supply orders and related documentation. Duration: for as long as the business relationship continues, plus the retention periods below. Categories of data subject: the controller's employees, researchers, procurement contacts, and nominated delivery recipients. Categories of personal data: name, business email, business telephone, job role, delivery address, order and invoice history, and verification documents where the controller supplies them. We do not require special categories of personal data, and you should not send them to us; if they are supplied in error we will delete them on request.
Security measures
We maintain technical and organisational measures appropriate to the risk, and review them as our systems change. Measures currently in place include the following.
- Encryption in transit using HTTPS across the site, the account area, and the partner and wholesale portals.
- Authentication session cookies issued as HttpOnly, Secure in production, and SameSite-restricted, with server-side session validation.
- Role-based access control for staff, with the admin area gated behind a separate authenticated session.
- Segregation of retail, wholesale, and fulfilment-partner data paths, so a partner account cannot read retail customer records.
- Managed hosting and platform patching through our infrastructure provider, with access to production restricted to authorised personnel.
- Audit logging of administrative actions, retained so that account and order changes can be traced.
- Data minimisation at collection — we ask only for the fields needed to verify, fulfil, and document an order.
Confidentiality of personnel
Personnel authorised to process controller personal data are bound by confidentiality obligations, receive access only to the extent needed for their role, and have that access removed when their role changes or ends.
Sub-processors
You give general authorisation for us to appoint the sub-processors listed below, each engaged under terms that impose data protection obligations equivalent to those in this agreement. We remain liable to you for their performance. If we intend to add or replace a sub-processor for controller personal data we will give reasonable notice so you can object on legitimate data protection grounds; if we cannot resolve the objection, either party may terminate the affected service without penalty.
- Hosting and platform: Vercel.
- Transactional email: Resend.
- Payment processing: Ziina, Apple Pay, Stripe, Tamara — these providers act as independent controllers for payment data under their own terms, and we do not receive or store full card numbers.
- Delivery: Licensed UAE last-mile courier partners. Courier name and tracking reference are provided on dispatch confirmation when assigned.
- Analytics: Google Analytics / Google Ads, loaded only where the individual has consented to optional cookies.
International transfers
Some sub-processors operate infrastructure outside the UAE. Where controller personal data is transferred outside the UAE we rely on the transfer conditions permitted by UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data, including transfers to jurisdictions recognised as providing adequate protection and, where that is not available, appropriate contractual safeguards with the recipient.
Assistance with data subject rights
Taking into account the nature of the processing, we will assist you with requests from data subjects to access, correct, delete, restrict, or object to processing, and with data portability requests, so far as the data is within our systems. If a data subject contacts us directly about data we process for you, we will not respond substantively on your behalf; we will redirect them to you and notify you without undue delay.
Personal data breach
We will notify you without undue delay after becoming aware of a personal data breach affecting controller personal data, with the information reasonably available to us at the time, including the nature of the breach, the categories and approximate number of records affected, the likely consequences, and the measures taken or proposed. We will provide further detail as our investigation progresses and will cooperate with any notification you must make to the UAE Data Office or to affected individuals.
Audits and information
We will make available the information reasonably necessary to demonstrate compliance with this agreement, and will respond to a reasonable written security questionnaire no more than once in any twelve-month period. Where a controller has a documented regulatory requirement for an on-site or third-party audit, we will discuss scope, timing, and cost in good faith, with reasonable notice and subject to confidentiality, so that other customers' data is not exposed.
Retention, return, and deletion
We retain order and invoice records for 7 years to meet UAE commercial and tax record-keeping obligations, verification documents for 7 years, and support correspondence for 3 years. On termination, and at your choice, we will return or delete controller personal data that is not subject to a legal retention obligation, within a reasonable period of your written request. Data retained under a legal obligation remains protected by this agreement until deletion.
Liability and precedence
Liability under this agreement is subject to the limits set out in our Terms and Conditions. Where this agreement conflicts with the Terms and Conditions in relation to the processing of controller personal data, this agreement prevails for that subject matter only. Nothing in this agreement limits either party's obligations directly imposed by UAE data protection law.
Contact
Data protection enquiries, sub-processor objections, audit requests, and deletion instructions: support@vaultlabs.shop.
Version
Policy version 2.0 · Last updated 2026-08-06.
These pages provide the current commercial policies of VaultLabs.shop and are not a substitute for independent legal advice.