Skip to content
Settlers

Data processing agreement

When we build or run agent workflows for you, we process personal data held in your systems on your behalf. This agreement sets out how. It forms part of every engagement, and we countersign a copy on request.

Last updated 17 September 2026 · Rizq Management Software Ltd, Abu Dhabi Global Market (ADGM), Abu Dhabi, United Arab Emirates

1. How this agreement applies

This data processing agreement (“DPA”) is between Rizq Management Software Ltd, a company registered in Abu Dhabi Global Market (ADGM), Abu Dhabi, United Arab Emirates, trading as Settlers (“Settlers”, “we”), and the client named in the master services agreement or statement of work that refers to it (the “Agreement” and the “Client”). It is incorporated into the Agreement and applies whenever Settlers processes Client Personal Data in providing the services.

If this DPA conflicts with the Agreement on the protection of personal data, this DPA prevails. Where the parties have signed the standard contractual clauses or another transfer instrument, that instrument prevails over both. To request a countersigned copy, write to hello@settlers.tech.

2. Definitions

  • Data Protection Law — all laws on the processing of personal data that apply to a party in connection with the Agreement, including the ADGM Data Protection Regulations 2021, the EU General Data Protection Regulation 2016/679 (“GDPR”), the UK GDPR and the UK Data Protection Act 2018, as applicable.
  • Client Personal Data — personal data that Settlers processes on the Client’s behalf in providing the services.
  • Client Environment — the Client’s own cloud accounts, private networks, servers and business systems (such as its CRM, ERP, messaging and email systems) in which the workflows run.
  • Sub-processor — a third party engaged by Settlers that processes Client Personal Data.
  • Personal Data Breach, controller, processor, data subject and processing have the meanings given in Data Protection Law.

3. Roles

The Client is the controller of Client Personal Data and Settlers is its processor. Where the Client is itself a processor for another controller, Settlers is its sub-processor, and the Client confirms that its controller has authorised Settlers’ engagement on these terms.

The Client is responsible for the lawfulness of the processing it instructs, including having a legal basis for it, giving data subjects the information the law requires, and ensuring that the data it makes available to the workflows may be used for that purpose.

4. Instructions

Settlers processes Client Personal Data only on the Client’s documented instructions. The Agreement, each statement of work, the workflow specifications and approval rules agreed between the parties, and this DPA are the Client’s complete instructions at the time of signing; later instructions must be given in writing. Settlers will promptly tell the Client if, in its opinion, an instruction infringes Data Protection Law, and may suspend the affected processing until the instruction is confirmed or changed.

Settlers will not sell Client Personal Data, will not use it for its own purposes, and will not use it — or allow any Sub-processor to use it — to train, fine-tune or otherwise improve any artificial intelligence model.

5. How the workflows are deployed

Because the services consist of building software that runs inside the Client’s own systems, most processing takes place in the Client Environment, not in infrastructure controlled by Settlers. In particular:

  • Credentials. Workflows access Client systems only with credentials issued by the Client, scoped to the permissions the workflow needs. The Client may revoke them at any time.
  • Run log. The record of each run — its input, the actions taken and the person who approved them — is kept in the Client Environment, under the Client’s control and retention rules.
  • Human approval. Actions the parties designate as consequential are held for approval by a person the Client appoints and are not executed until approved.
  • Model inference. For each deployment the Client chooses, in the statement of work, one of two options:
    1. Hosted inference — language model requests are sent to Anthropic’s API under zero-data-retention terms, so that prompts and outputs are not stored by Anthropic beyond what is needed to return a response, and are not used for training; or
    2. Local inference — models run entirely on machines in the Client Environment, and no Client Personal Data is sent to any model provider.

Settlers personnel may access Client Personal Data during design, testing, deployment and support, but only to the extent needed for that work, and only through access the Client grants.

6. Confidentiality

Settlers ensures that everyone it authorises to process Client Personal Data is bound by an appropriate obligation of confidentiality and processes it only as needed to provide the services.

7. Security

Settlers implements the technical and organisational measures in Annex 2, taking into account the state of the art, the cost of implementation, and the nature, scope, context and purposes of the processing and the risks to data subjects. Settlers may update those measures, provided the overall level of protection is not reduced. Security of the Client Environment itself remains the Client’s responsibility.

8. Sub-processors

The Client gives general authorisation for Settlers to engage the Sub-processors listed in Annex 3. Settlers will give the Client at least thirty days’ written notice before adding or replacing a Sub-processor. The Client may object on reasonable data protection grounds within that period; the parties will then discuss the objection in good faith, and if they cannot resolve it, the Client may terminate the affected services without penalty.

Settlers imposes on each Sub-processor data protection obligations that are no less protective than those in this DPA, and remains responsible to the Client for its Sub-processors’ performance.

9. International transfers

Settlers will not transfer Client Personal Data out of the jurisdiction in which the Client holds it except as needed to provide the services and in compliance with Data Protection Law. Where a transfer requires a transfer mechanism, the parties rely on an adequacy decision where one exists, or on the European Commission’s standard contractual clauses (Module Two or Three, as applicable), the UK International Data Transfer Addendum, or the standard clauses recognised under the ADGM Data Protection Regulations 2021, which the parties will execute on request. Where the Client selects local inference, no transfer to a model provider takes place.

10. Assisting the Client

Taking into account the nature of the processing, Settlers will promptly forward to the Client any request it receives from a data subject about Client Personal Data, will not respond to it except on the Client’s instructions, and will provide reasonable assistance so that the Client can meet its obligations to respond to data subject requests, carry out data protection impact assessments and consult supervisory authorities.

11. Personal data breaches

Settlers will notify the Client without undue delay, and in any event within forty-eight hours, after becoming aware of a Personal Data Breach affecting Client Personal Data. The notice will describe, as far as then known, the nature of the breach, the categories and approximate number of data subjects and records concerned, its likely consequences, and the measures taken or proposed. Settlers will update the Client as more information becomes available, take reasonable steps to contain and remedy the breach, and cooperate with the Client’s own notifications. Notification is not an acknowledgement of fault.

12. Return and deletion

When the services end, Settlers will, at the Client’s choice, return or delete all Client Personal Data in its possession — including copies in development and test environments — and revoke its own access to the Client Environment, unless the law requires it to keep the data. Data retained under such a requirement stays protected by this DPA. Data in the Client Environment, including the run log, remains with the Client.

13. Audits

Settlers will make available the information reasonably necessary to demonstrate compliance with this DPA, including answers to security questionnaires. Where that information is not sufficient, the Client, or an independent auditor bound by confidentiality, may audit Settlers’ compliance no more than once a year, on at least thirty days’ notice, during business hours and without unreasonably disrupting its operations, unless a supervisory authority requires otherwise or a Personal Data Breach has occurred. Each party bears its own costs of an audit.

14. Liability and term

Each party’s liability under this DPA is subject to the limitations and exclusions in the Agreement, except where Data Protection Law does not permit them. This DPA lasts for as long as Settlers processes Client Personal Data, and the obligations that by their nature should survive, including sections 6, 11, 12 and 13, survive its end. It is governed by the law and jurisdiction that govern the Agreement.

Annex 1 — Details of the processing

  • Subject matter and purpose — designing, building, testing, deploying, operating and supporting automated workflows that read, extract, validate, transform and write business information in the Client’s systems, as described in the statement of work.
  • Nature of the processing — access, retrieval, structuring, analysis, classification and extraction by language models, comparison with the Client’s records, creation and updating of records, routing for human approval, logging and deletion.
  • Duration — the term of the Agreement and the period until deletion or return under section 12.
  • Categories of data subjects — the Client’s customers, prospects, suppliers, business partners and their contacts, and the Client’s own personnel who use or approve the workflows.
  • Categories of personal data — identification and contact details; job titles and company affiliations; account, customer and supplier identifiers; order, quote, booking, shipment, invoice and payment status information; the content of messages, emails, attachments and voice notes submitted to the workflows; and approval records.
  • Special categories — none are intended. If a workflow must process special categories of personal data or data about criminal convictions, the parties will record this and the additional safeguards in the statement of work before processing begins.

Annex 2 — Security measures

  • Workflows are deployed in the Client Environment — the Client’s private cloud or on-premise servers — rather than in shared infrastructure operated by Settlers.
  • Access to Client systems only through Client-issued credentials with least-privilege scopes; credentials stored in a secrets manager, never in source code.
  • Encryption of data in transit between components and to any model provider; encryption at rest as provided by the Client Environment.
  • Typed schema validation of model outputs before any write, and deterministic rules — not model judgement — for consequential decisions.
  • Human approval gates on actions the parties designate as consequential.
  • Hard limits on spend, retries and write volume, which halt the workflow and alert a person when crossed.
  • An end-to-end run log of input, action and approver for each run, kept in the Client Environment.
  • Hosted inference only through endpoints with zero data retention and no training on inputs or outputs; local inference available where the Client requires that no data leave its environment.
  • Access by Settlers personnel limited to named individuals working on the engagement, removed when their work ends; confidentiality obligations for all personnel.
  • Separation of development and test data from production, and use of synthetic or minimised data for development where practicable.
  • Deletion of Settlers-held copies of Client Personal Data at the end of the engagement.

Annex 3 — Sub-processors

Settlers engages the following Sub-processor for Client Personal Data:

  • Anthropic, PBC (United States) — large language model inference through the Anthropic API under zero-data-retention terms. Used only for deployments where the Client selects hosted inference; not used where the Client selects local inference.

Services that host the Client Environment itself — such as the Client’s own cloud provider — are engaged by the Client and are not Settlers’ Sub-processors. See also our privacy policy for data we handle as a controller, such as contact requests.