Data processing
How data is handled when Eightech delivers services, and how to request a data processing agreement.
Last updated: 26 August 2026
About this page
This page explains how Eightech approaches data protection in client engagements, and how to request a data processing agreement (DPA).
This page is informational. It is not itself a data processing agreement and does not create binding obligations. Where a DPA is required, it is executed as a separate document alongside the services agreement.
Controller and processor roles
Which role each party holds depends on the engagement:
- For personal data a client holds and asks us to process as part of delivering a service, the client is the controller and Eightech acts as processor, acting on the client's documented instructions.
- For data we process for our own purposes — our business contacts, our own staff, this website's enquiry correspondence — Eightech is the controller.
- Some engagements involve both. Roles are set out in the agreement rather than assumed.
Confidentiality
Our people are bound by confidentiality obligations covering client information. Confidentiality agreements can be signed before commercial discussions go into detail, and are routine on our engagements.
Subprocessors
Where an engagement requires us to involve a third party in processing client data, that is agreed with the client as part of the engagement rather than decided unilaterally. The applicable list, and the process for notifying changes to it, form part of the DPA for that engagement.
For this website specifically, the providers involved are listed in the privacy policy.
Information security
Technical and organisational measures are described on the security page. Measures specific to an engagement — including any client-mandated controls — are agreed in the contract.
Data subject requests
Where Eightech acts as processor, requests from data subjects are referred to the client as controller, and we assist the client in responding as the agreement requires.
Where Eightech is the controller, requests are handled as described in the privacy policy.
Return and deletion of data
At the end of an engagement, client data is returned or deleted according to the terms of the agreement, subject to any retention we are legally required to observe. The handling of data at termination is agreed in writing rather than left to a default.
International transfers
Eightech operates between Morocco and the United Arab Emirates and delivers to clients in multiple jurisdictions, so engagements can involve cross-border processing.
Where a transfer is subject to the EU or UK GDPR, an appropriate safeguard such as standard contractual clauses is put in place. Where a client requires data to remain in a specific region, that is agreed before the engagement starts.
Requesting a DPA
If your procurement or legal team needs a data processing agreement, or a completed security or data-protection questionnaire, contact us and tell us what you need.
Tell us what you need.
Managed IT, a dedicated team, or a product build. We reply within one business day, in English, Arabic, or French.
contact@eightech.com · Dubai, United Arab Emirates
