Loading...
Last updated: March 2026
This Data Processing Agreement (DPA) forms part of the agreement between Digital ITS ("Processor") and the subscribing organization ("Controller") for the use of the Sentinel platform. This DPA applies to Enterprise, Campaign, and Strategic tier subscriptions.
"Personal Data" means any information relating to an identified or identifiable natural person. "Processing" means any operation performed on Personal Data, including collection, storage, use, disclosure, and deletion. "Sub-processor" means any third party engaged by the Processor to process Personal Data on behalf of the Controller.
The Processor shall process Personal Data only on documented instructions from the Controller, as necessary to provide the Sentinel platform services. Processing activities include media monitoring, narrative analysis, sentiment analysis, and reporting across Arabic, English, and French language media.
The Processor shall: (a) process Personal Data only on documented instructions from the Controller; (b) ensure personnel are bound by confidentiality obligations; (c) implement appropriate technical and organizational security measures; (d) assist the Controller in responding to data subject requests; (e) delete or return all Personal Data upon termination of services.
The Processor implements industry-standard security measures including: encryption in transit (TLS 1.2+) and at rest (AES-256), role-based access controls, multi-tenant data isolation, regular security audits, automated backup procedures, and incident response protocols.
The Processor may engage sub-processors to assist in providing services. The Controller will be notified of any new sub-processors at least 30 days before engagement. Current sub-processors include cloud infrastructure providers, AI model providers (Anthropic, OpenAI as fallback), and communication service providers (email, SMS).
Personal Data is primarily stored on self-hosted infrastructure. Any international data transfers will be conducted in compliance with applicable data protection laws, with appropriate safeguards in place including standard contractual clauses where required.
In the event of a Personal Data breach, the Processor shall notify the Controller without undue delay and no later than 72 hours after becoming aware of the breach. Notification shall include the nature of the breach, categories of data affected, estimated number of data subjects, and measures taken to address the breach.
The Controller has the right to audit the Processor's compliance with this DPA. The Processor shall provide reasonable access to relevant documentation, systems, and personnel upon reasonable notice. Audits shall be conducted during normal business hours and no more than once per calendar year.
Upon termination of services, the Processor shall delete all Personal Data within 30 days unless retention is required by applicable law. The Controller may request data export in a standard format prior to deletion.
Each party's liability under this DPA is subject to the limitations set forth in the main service agreement. The Processor shall indemnify the Controller for any losses arising from the Processor's breach of this DPA or applicable data protection laws.
This DPA is governed by the laws of the Republic of Lebanon. Any disputes shall be subject to the exclusive jurisdiction of the courts of Beirut, Lebanon.
For questions about this Data Processing Agreement, contact us at [email protected] or at our office: Santa Maria Plaza Center, 3rd Floor, Hadath, Lebanon.