M
Mango DMA
Back to site

Data Processing Agreement

Version: 1.0  |  Effective: March 2026  |  Operator: Mango Technologies Ltd (DIFC-Incorporated)


1. Definitions

1.1 Applicable Laws

1.2 Parties

1.3 Processing Terms

1.4 Service-Specific Terms


2. Scope and Roles

2.1 Applicability

This DPA applies to all Processing of Personal Data that occurs in connection with the provision of Mango DMA services to the Controller. This DPA is incorporated by reference into the Service Agreement and shall form an integral part thereof. In the event of any conflict between this DPA and the Service Agreement, the provisions of this DPA shall prevail with respect to the Processing of Personal Data.

2.2 Controller Responsibilities

The Controller shall:

2.3 Processor Responsibilities

Mango shall:

2.4 Limitations on Processing

Mango shall not Process Personal Data for any purpose other than to provide Mango DMA services as documented in the Service Agreement and pursuant to the Controller's documented instructions. Mango shall not combine Personal Data received from different Controllers unless expressly authorized in writing. Mango shall not use Personal Data for building or improving machine learning models, competitive intelligence, or secondary purposes without explicit prior written consent from the Controller.


3. Processor Obligations

3.1 Processing Instructions

Mango shall not commence Processing of Personal Data until it has received written instructions from the Controller specifying the identity and role of the Controller; the categories of Personal Data to be Processed; the nature and purpose of Processing; the type and duration of Processing; the categories of Data Subjects; any technical and organisational security requirements; and whether Mango is authorized to engage Sub-processors.

3.2 Confidentiality

Mango shall ensure that all natural persons who are authorized to Process Personal Data on Mango's behalf are placed under a legally binding confidentiality obligation that survives the termination of their engagement, are trained on the requirements of DIFC DPL, GDPR, and UAE PDPL on an ongoing basis, and have access to Personal Data only to the extent necessary to perform their assigned functions.

3.3 Security Obligations

Mango shall maintain and implement comprehensive Technical and Organisational Measures as detailed in Annex B, including:

3.4 Sub-processor Authorization and Management

The Controller grants Mango general authorization to engage Sub-processors, provided that Mango provides the Controller with a list of all Sub-processors prior to their engagement and at least 30 days prior to any change; the Controller has the right to object to the engagement of a new Sub-processor on reasonable grounds; and Mango remains fully liable to the Controller for any failure by a Sub-processor to fulfill its data protection obligations.

3.5 Data Subject Rights Assistance

Mango shall assist the Controller to facilitate Data Subject rights including:


4. Security Measures

4.1 Encryption

4.2 Access Controls

4.3 Audit Logging and Monitoring

4.4 Data Isolation and Multi-tenancy


5. Sub-processors

The Controller authorizes Mango to engage the following Sub-processors:

Sub-processorRoleLocationData CategoriesProcessing Activity
Google Cloud Platform (Vertex AI)AI Service ProviderUSA / GlobalBrand config, content, user promptsAI model inference, generative content
Google Cloud Platform (Cloud SQL, GCS, Secret Manager)Infrastructure Providerme-central1 (UAE)All Personal DataStorage, encryption, secret management
fal.aiImage GenerationUSABrand config, content briefsFLUX.2 image generation, LoRA training
IdeogramText Image GenerationUSABrand config, social captionsIdeogram V3 text-heavy image synthesis
Perplexity AIIntelligence PlatformUSAResearch keywords, brand topicsAudience research, trend detection
StripePayment ProcessingUSABilling name, email, Stripe customer IDPayment authorization, subscription billing
Meta Platforms (Instagram/Facebook)Social PublishingUSAContent, engagement metricsSocial media posting, analytics retrieval
LinkedIn (Microsoft)Social PublishingUSAContent, engagement metricsLinkedIn posting, analytics retrieval
TikTok (ByteDance)Social PublishingUSA (Project Texas)Content, engagement metricsTikTok posting, analytics retrieval
YouTube (Google)Video PublishingUSAContent, engagement metricsYouTube Shorts publishing, analytics retrieval

Mango shall notify the Controller of any addition, removal, or significant change to Sub-processors at least 30 days in advance. The Controller may object within 15 days of notice on reasonable data protection grounds.


6. International Data Transfers

6.1 Transfer Mechanisms

For transfers outside the EEA or the United Arab Emirates, Mango applies the following mechanisms in order of precedence:

6.2 Schrems II Compliance

Mango acknowledges the CJEU decision in Schrems II (Case C-311/18) and conducts Transfer Impact Assessments for US transfers, implements binding contractual clauses limiting government access, and maintains TIA documentation available upon Controller request.


7. Data Subject Rights


8. Personal Data Breach Notification

Mango shall notify the Controller of a Personal Data Breach without undue delay and no later than 72 hours from discovery (GDPR Article 33, DIFC DPL Article 25). Notification shall include:

The Controller remains responsible for notifying Data Subjects and supervisory authorities. Mango shall cooperate and provide reasonable assistance.


9. Audit Rights

The Controller, or an independent auditor acting on the Controller's behalf, has the right to audit Mango's compliance with this DPA upon 30 days' written notice. One comprehensive audit is permitted per calendar year at no additional charge. Audit reports shall be kept confidential.


10. Term, Termination, and Data Return

This DPA commences on the Effective Date and continues for the duration of the Service Agreement. Upon termination or expiration:

Permitted Retention After Termination (maximum 7 years): legal compliance obligations, anonymized audit logs, tax and accounting records (7 years per UAE tax law), and data necessary to defend legal claims.

Retention Period: 5 years for active subscriber data (matching platform Terms of Service), extended to 7 years where required by applicable law, tax regulation, or legal hold.


11. Governing Law and Dispute Resolution

11.1 Governing Law

11.2 Dispute Resolution


Annex A: Description of Processing

CategoryData TypesSourceProcessing PurposeRetentionLegal Basis
Business IdentityBusiness name, email, company name, role, phoneController input, OAuth SSOService delivery, authentication, account managementSubscription + 7 yearsService contract, legitimate interest
Brand ConfigurationBrand name, voice, tone, target audience, colors, logo, brand bible (JSON)Controller upload, dashboardContent generation, brand consistency, strategySubscription + 7 yearsService contract
AI-Generated ContentSocial captions, blog drafts, email campaigns, image prompts, video scriptsGenerated by Gemini agentsContent delivery, analytics, quality reviewSubscription + 30 days archiveService contract
Social Engagement DataPost IDs, likes, comments, shares, impressions, reach, engagement rateMeta, LinkedIn, TikTok APIsPerformance analytics, trend detection, audience insightsSubscription + 90 daysService contract, legitimate interest
OAuth TokensInstagram, Facebook, LinkedIn, TikTok, YouTube tokensOAuth authorization flowAPI authentication, social platform integrationSubscription duration; refreshed on useService contract, controller authorization
Billing InformationStripe customer ID, subscription plan, billing emailStripe OAuth / webhookPayment processing, subscription managementSubscription + 7 yearsService contract, tax obligation
Usage AnalyticsFeature usage, API requests, login timestampsApplication loggingPerformance monitoring, product improvementSubscription + 1 yearLegitimate interest
Security & AuditIP addresses, user agents, login timestamps, audit trailAudit logging systemSecurity monitoring, incident response, compliance7 yearsLegal obligation, legitimate interest

Annex B: Technical and Organisational Measures (TOMs)

No.MeasureCategoryImplementation Details
1Encryption in TransitTechnicalTLS 1.2+ for all network communications. HTTPS mandatory for all user-facing interfaces. Annual certificate rotation.
2Encryption at RestTechnicalAES-256-GCM for database fields containing Personal Data. Fernet encryption for OAuth tokens with key rotation every 90 days.
3Key ManagementTechnicalPBKDF2-HMAC-SHA256 key derivation from secrets in GCP Secret Manager (me-central1, UAE). Key rotation every 12 months minimum.
4Access Control – AuthNTechnicalMFA mandatory for all user and admin access. JWT bearer tokens rotated every 24 hours. OAuth 2.0 with PKCE for third-party integrations.
5Access Control – AuthZTechnicalRBAC enforced at application layer. PostgreSQL row-level security (RLS) for tenant isolation. Least privilege principle. Weekly access reviews.
6Audit LoggingTechnicalAll data access logged with timestamp, user ID, IP, operation type, affected fields, result. Logs immutable and separated from production. 7-year retention.
7Vulnerability ManagementTechnicalAnnual external penetration testing. Quarterly automated vulnerability scanning (OWASP Top 10). Monthly dependency scanning. High/critical remediation within 30 days.
8Data IsolationTechnicalPostgreSQL RLS for tenant isolation. Separate GCS paths per tenant for media. Quarterly penetration testing to verify isolation.
9Incident ResponseOrganisationalDocumented plan with defined roles, escalation, forensic protocols. Semi-annual training. Annual simulated breach exercises.
10Backup & DRTechnicalDaily automated PostgreSQL backups. GCS replication. Encrypted backups. Recovery tested quarterly (RTO: 2h, RPO: 1h).
11Third-Party RiskOrganisationalDue diligence of Sub-processors before engagement. Annual security assessments. Contractual SLAs requiring compliance.
12Data Subject RightsOrganisationalDocumented procedures for access, rectification, erasure, portability, restriction. Acknowledge within 5 days, respond within 30 days.
13Personnel TrainingOrganisationalAnnual data protection training. Signed confidentiality agreements. Disciplinary procedures. Background checks for sensitive access.
14Privacy by DesignOrganisationalPIAs for new features. Data minimization. Pseudonymization where feasible. Privacy controls for Controllers.
15MonitoringOrganisationalReal-time SIEM monitoring via Cloud Logging. Monthly security reviews. Quarterly TOM effectiveness reviews.
16Business ContinuityOrganisationalRedundant systems across GCP availability zones (me-central1). Automated failover. Annual BCP testing.

Annex C: EU Standard Contractual Clauses

Incorporation by Reference – Module 2 (Controller to Processor)

This Annex incorporates by reference the EU Standard Contractual Clauses for data transfers from controllers in the EU/EEA to processors located outside the EU/EEA, as approved by the European Commission under Commission Implementing Decision (EU) 2021/914 of 4 June 2021, available at: https://eur-lex.europa.eu/eli/dec_impl/2021/914/oj

The parties incorporate Clauses 1-7 of the EU SCCs (Module 2) with the following supplementary terms: the Processor shall process Personal Data only to the extent necessary to provide Mango DMA services; Sub-processors require prior written authorization with 30 days' advance notice of changes; upon termination, the Processor shall return or delete all Personal Data at the Controller's election.

Schrems II Supplementary Measures: The Processor warrants that US government access to Personal Data shall be limited to legally authorized requests; the Processor shall seek to narrow the scope of any government access request; and the Processor shall maintain and produce Transfer Impact Assessment documentation demonstrating compliance with Schrems II principles.


Signature Block

To execute this DPA, please contact hello@mangosuite.com to receive a countersigned copy. By continuing to use Mango DMA services under the Service Agreement, the Controller agrees to be bound by the terms of this DPA.

CONTROLLER

By: _______________________________
Name (Print): _______________________________
Title: _______________________________
Company: _______________________________
Date: _______________________________
PROCESSOR: Mango Technologies Ltd

By: _______________________________
Name (Print): _______________________________
Title: _______________________________
Date: _______________________________

DIFC, Dubai, United Arab Emirates
hello@mangosuite.com

Data Processing Agreement v1.0 · March 2026 · Mango Technologies Ltd · mangosuite.com