Data Processing Addendum
Last updated 13 August 2026
This Data Processing Addendum ("DPA") forms part of the agreement between an Operator and Al Wafaa Group ("Stay71 Manage", "Processor") for use of Stay71 Manage (the "Service"). It applies whenever an Operator enters personal data belonging to its own tenants or staff into the Service. It is written with the United Arab Emirates' Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data ("PDPL") in mind.
1. Roles
For personal data an Operator enters into the Service about its tenants and staff, the Operator is the data controller: it decides what data to collect, why, and for how long, and is responsible for having a lawful basis to process it. Stay71 Manage is the data processor: we process that data only to provide the Service, on the Operator's instructions as given through use of the Service and this DPA.
2. Subject matter and duration
The subject matter of processing is the provision of property, tenancy, and financial record-keeping functionality described in our Terms of Service. Processing continues for as long as the Operator's subscription is active, and thereafter only as needed to comply with Section 7 (data return and deletion) or applicable law.
3. Categories of data subjects
- Tenants and prospective tenants (bookings) of the Operator;
- Staff of the Operator who use the Service;
- Referrers, guarantors, or other individuals an Operator chooses to record in connection with a tenancy.
4. Categories of personal data
- Identity data: full name, nationality, Emirates ID or passport number, phone number, email;
- Tenancy data: room and building assignment, rent, deposit, move-in/move-out dates, visa expiry, employer;
- Financial data: rent charges, payments, cheque details, bank transaction references;
- Documents: identity, contract, or other files an Operator's staff choose to upload;
- Staff account data: name, email, phone, role.
No special category or sensitive personal data is intentionally collected beyond the above.
5. Processor obligations
We agree to:
- Process personal data only on the Operator's documented instructions, as given through configuration and use of the Service, unless required otherwise by law;
- Ensure personnel authorised to process the data are bound by confidentiality obligations;
- Implement appropriate technical and organisational security measures, including per-organisation database access controls, role-based permissions, and encryption in transit and at rest;
- Not engage a new sub-processor without giving the Operator a reasonable opportunity to object, except for the infrastructure sub-processors named in Section 6, which are necessary to operate the Service at all;
- Assist the Operator, on request and to a reasonable extent, in responding to data subject requests (access, correction, deletion) that the Operator receives regarding data held in the Service;
- Notify the Operator without undue delay after becoming aware of a personal data breach affecting the Operator's data, with the information reasonably available at the time;
- Make available to the Operator the information reasonably necessary to demonstrate compliance with this DPA.
6. Sub-processors
We currently use the following sub-processors to provide the Service:
- Supabase — database hosting, authentication, and file storage.
- Vercel — application hosting.
If we introduce optional features that require a new category of sub-processor — for example a WhatsApp Business API or email delivery provider — we will update this list before that sub-processor begins processing data on an Operator's behalf.
7. Data return and deletion
On termination of an Operator's subscription, we will make the Operator's data available for export for a reasonable period. After that period, data is deleted or retained only to the extent required by applicable law or for legitimate audit purposes, consistent with our Privacy Policy.
8. Liability
Each party is responsible for its own compliance with the PDPL and other applicable data protection law in its respective role. Nothing in this DPA overrides the limitation of liability set out in our Terms of Service, except to the extent such a limitation cannot lawfully apply to data protection obligations.
9. Contact
Data protection queries relating to this DPA can be sent to hello@stay71.com.