Formal DPA governing processor/controller roles, technical safeguards, sub-processor authorizations, and breach notification obligations for UMMIGO ERP enterprise tenants.
This Data Processing Agreement ("DPA") governs the processing of personal and enterprise business data between:
This DPA applies to all personal data processed through the UMMIGO ERP SaaS platform on behalf of the enterprise client.
UMMIGO ERP as Data Processor commits to the following obligations:
As the Data Controller, the enterprise tenant accepts responsibility for:
UMMIGO ERP implements the following verified technical safeguards:
UMMIGO ERP currently engages the following approved sub-processors under binding data processing agreements:
| Sub-Processor | Service | Data Location |
|---|---|---|
| Amazon Web Services (AWS) | Database & Cloud Compute Hosting | Asia Pacific / EU Regions |
| SendGrid | Transactional Email Delivery | USA (GDPR/SCC Covered) |
| Twilio | SMS OTP & Alert Notifications | USA (GDPR/SCC Covered) |
Sub-processor updates are communicated via email notice 14 days in advance. Controllers may object to new sub-processors in writing within this window.
In the event of a confirmed personal data breach, UMMIGO ERP will notify the enterprise Controller within 72 hours via registered email and Admin Console alert. Notification will include: nature of breach, categories of data affected, estimated data subject count, and immediate containment measures taken.
This DPA is governed by the laws of Pakistan and shall be interpreted in accordance with applicable international data protection standards. Disputes are subject to arbitration in Lahore, Pakistan.
UMMIGO ERP Operations & Legal Governance Team
Email: legal@ummigoerp.com | Phone: +92 321 8272999
Corporate Address: UMMIGO Tower, Tech District, Lahore / Karachi, Pakistan