This Data Processing Agreement ("DPA") is entered into between Doha Dynamics ("Processor") and the healthcare institution using ShiftER ("Controller"). This DPA governs the processing of personal data in compliance with Qatar's Personal Data Protection Law (PDPL) and the EU General Data Protection Regulation (GDPR). Effective date: June 2025.
Controller: The healthcare institution that determines the purposes and means of processing personal data.
Processor: Doha Dynamics, which processes personal data on behalf of the Controller.
Personal Data: Any information relating to an identified or identifiable natural person, as defined by Qatar PDPL and GDPR.
Processing: Any operation performed on personal data, including collection, storage, organization, and deletion.
The subject matter of this DPA is the processing of healthcare staff scheduling data on behalf of the Controller using the ShiftER platform.
This DPA remains in effect for the duration of the service agreement between Controller and Processor.
The purpose of processing is to:
Types of personal data processed include:
Data subjects include clinical and administrative staff employed by the Controller organization, including physicians, nurses, technicians, and support personnel.
The Processor shall:
The Processor currently engages the following sub-processors:
The Controller will be notified of any changes to sub-processors at least 30 days in advance and may object to the appointment of new sub-processors.
The Processor implements the following security measures:
The Processor shall assist the Controller in fulfilling data subject requests for access, rectification, erasure, restriction of processing, data portability, and objection to processing. The Processor will respond to Controller requests within the timeframes required by applicable law.
All personal data remains within Qatar-hosted infrastructure. No international transfers of data will occur without the Controller's prior written consent and appropriate safeguards as required by Qatar PDPL and GDPR.
Upon termination of the service agreement, the Processor shall, at the Controller's choice, delete or return all personal data within 14 days. Deletion certificates will be provided upon request. Data required to be retained for legal compliance purposes will be securely isolated and deleted after the retention period expires.
Each party shall be liable for its respective obligations under this DPA. The Processor's liability is subject to the limitations set forth in the Terms of Service.
This DPA is governed by the laws of the State of Qatar.
For questions about this Data Processing Agreement, please contact us: