SkyLightNazmIQ
Guides Live Example Pricing Telegram Log in Start Free

Data Processing Agreement

Last updated: June 2026

This document is provided for transparency. SkyLight is a limited liability company established under Law No. 72 of 2017 (Investment Law) and its Executive Regulations, Arab Republic of Egypt. Buyer support: contact@nazmiq.com · +20 101 992 8994.

Version 1.3 · Effective 29 August 2026 · Applies to all customers of NazmIQ

This Data Processing Agreement ("DPA") forms part of the Terms of Service between SkyLight (LLC, Arab Republic of Egypt), operator of NazmIQ ("we", "us"), and the customer ("you"). It governs our processing of personal data contained in the documents and data you submit to the Service.

1. Roles

Your documents. You are the controller and we are the processor. We process the personal data in your uploaded quotations only on your documented instructions — which are these Terms, this DPA, and your use of the Service's features.

Your account. For your own users' account details — name, email, company, role, country, usage counts, plan — we are the controller, processing them to provide, secure, support and bill for the Service.

Third parties in your documents. Supplier quotations routinely contain personal data of people who are not our customers: the names, job titles, direct telephone numbers, email addresses and signatures of supplier representatives. You confirm you have a lawful basis for submitting that data to us.

2. What we will never do with your data

We do not use personal data extracted from your documents for any purpose of our own. Specifically, we do not use supplier contact details for marketing or lead generation, we do not build a supplier directory or price index from your documents, and we do not train or fine-tune any model on your data. This obligation survives termination of your account.

Nor do our AI sub-processors train on it. Under Google Cloud's enterprise terms, customer prompts and responses are not used to train or fine-tune foundation models. We want to be precise about what that does not mean: Google's standard terms permit prompts and responses to be retained for up to 30 days for automated abuse monitoring — safety screening, held separately from any training pipeline. We have not purchased a zero-retention exception, so we do not claim one. That 30-day safety window is the honest position, and we would rather state it than have a reviewer discover it.

3. Confidentiality and access

Access to production systems is limited to personnel who need it to operate or support the Service, who are bound by confidentiality obligations. SkyLight personnel are located in Egypt; that access is itself an international transfer and is covered by section 8.

4. Security

All data is encrypted in transit using TLS, and at rest by Google Cloud's default encryption. Database security rules deny all direct client access, so every read and write passes through our application server, which enforces per-account scoping. Uploaded documents are stored under a per-account key and every access path resolves your identity server-side.

Model inference on our primary path authenticates using the application's own Google Cloud service identity rather than a stored API key, so there is no long-lived credential to leak or rotate, and every call is recorded in Google Cloud audit logs.

Our operational telemetry is content-free by design: it records counts, statuses, durations and timestamps, and contains no supplier names, prices, item descriptions or file names.

We do not currently hold a SOC 2 or ISO 27001 report. Where a sub-processor holds one, it is identified below.

5. Sub-processors

You authorise the sub-processors below. We impose data-protection obligations on each of them and remain responsible to you for their performance. We will give you at least 30 days' notice before adding or replacing a sub-processor, by email to the account owner and by updating this page. If you object on reasonable data-protection grounds and we cannot resolve it, you may terminate the affected part of the Service and receive a pro-rata refund of prepaid fees.

Sub-processorPurposeLocation
Google Cloud / Google LLC Hosting, storage, database, authentication, logging United States (us-central1)
Google LLC — Vertex AI Primary document reading and comparison Google's global endpoint — see section 7
OpenRouter, Inc. Inference gateway — fallback only, used when the primary path is unavailable United States

Where the fallback path is used, we constrain routing per request rather than leaving it to the gateway. The second tier is the same Google model reached through OpenRouter. The third tier is restricted to two named United States operators (Phala and CoreWeave) and is sent with zero data retention asserted (zdr: true) and data_collection: deny, with provider fallback disabled — so a request cannot silently move to an operator we have not named, or to one that would retain it. It fails instead. Our OpenRouter account is additionally configured to permit only zero-retention providers, so the guarantee holds at both the account and the request level. No provider in any tier is hosted in China.

Currency reference rates are fetched from public exchange-rate services. Those receive a currency code and none of your data.

6. Payments — Paddle

Paddle acts as Merchant of Record for all purchases. Your payment contract is with Paddle, which acts as an independent controller for billing, tax and chargeback data under its own privacy notice. We never receive or store your card details.

7. Where your data is processed

At rest: documents, account data and generated reports are stored in Google Cloud's us-central1 region (Iowa, United States). Our application servers run in the same region.

Model inference: our primary model is served through Google's global endpoint, which may process a request in any Google Cloud region. We therefore do not represent that inference occurs in any particular country. If your organisation requires region-pinned processing, contact us — it is achievable with an alternative model and we will tell you honestly what it costs in accuracy.

8. International transfers

You to us. SkyLight is established in Egypt, which is not the subject of an adequacy decision under the EU or UK GDPR. Where you are established in the EEA or the United Kingdom, transfers of your data to us are governed by the EU Standard Contractual Clauses (Commission Decision 2021/914), Module Two (controller to processor), and for the UK by the International Data Transfer Addendum. Access by our personnel in Egypt is a transfer and is covered by the same clauses — remote access is a transfer even though no copy is made in Egypt.

Us to Google. Google LLC participates in the EU-U.S. Data Privacy Framework and its UK extension, so transfers to Google are covered by the adequacy decision, with the Standard Contractual Clauses in the Google Cloud Data Processing Addendum as a secondary mechanism should the framework be disturbed.

Egypt. Egyptian Law No. 151 of 2020 treats storing personal data on servers outside Egypt as a cross-border transfer, and its Executive Regulations — issued in November 2025 by Decision No. 81 of 2025 — require a licence from the Personal Data Protection Centre for such transfers, with a transitional period running to October 2026. We are working through that licensing requirement. In the interim, transfers rest on the derogations available under the law, including that the transfer is necessary to perform the contract with you.

To execute the SCCs with us, email privacy@nazmiq.com.

9. Optional Telegram integration

The Telegram integration is off unless you turn it on, and the Service is fully usable without it.

Telegram is not a sub-processor. If you enable it, you are instructing us to send data to a service you have separately chosen and contracted with, and Telegram receives it as an independent controller under its own terms. We have no contract with Telegram, cannot impose obligations on it, and cannot delete data once it has been received.

What passes through Telegram: the quotation documents you send to the bot, the completed comparison workbook the bot returns, and messages naming your projects. Assume that any personal data on a submitted quotation passes through in the same way. Messages exchanged with a bot are not end-to-end encrypted — Telegram's end-to-end encryption applies only to Secret Chats, which the Bot API does not use.

Do not enable the integration for data you are unwilling to place on a consumer messaging service. Accepting Telegram's own terms settles your relationship with Telegram; it does not by itself discharge your obligations to the people whose data appears in those documents. You may unlink at any time, which stops further transmission but has no effect on data already sent.

10. Retention and deletion

Generated comparison reports are deleted automatically 30 days after they are created. Each report carries an expiry that the database enforces itself, so the deletion does not depend on us remembering to run anything. Reports generated before 18 August 2026 pre-dated this mechanism and carried no expiry; they have been deleted.

Documents you upload remain available to you until you delete them, and are deleted within 90 days of your account closing. Backups are overwritten on a rolling basis and deletion completes there within the same 90 days.

Account and billing records are retained for as long as your account is open, and financial records for 5 years as required by law.

Service records — when a comparison ran, how long it took, how many files it read, whether it succeeded, and which account it belonged to — are kept for as long as your account is open, and are not covered by the 30-day expiry above. They tell us how the Service is performing and how usage changes over time, which a 30-day window cannot show. These records contain no supplier names, no prices, no item descriptions and no file names; they are counts, timestamps and status codes, stored separately from the reports themselves.

You can delete uploaded documents yourself at any time in the Service. The deletion obligations here do not extend to data held by Telegram (section 9).

11. Data subject requests

We will not respond directly to a request from an individual about data in your documents, other than to direct them to you. We will assist you in responding, including through the export and deletion functions in the Service.

12. Personal data breach

We will notify you without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting your data, describing what happened, the categories and approximate number of records affected, the likely consequences and the measures taken. We will notify the Egyptian Personal Data Protection Centre where and as required by Egyptian Law No. 151 of 2020 and its implementing regulations.

13. Audit

We will provide the information reasonably necessary to demonstrate compliance with this DPA, and will respond to a security questionnaire once in any 12-month period.

14. Contact and regulatory point

SkyLight is established in Egypt and has no establishment or representative in the European Union or the United Kingdom. Data subjects and supervisory authorities may contact us directly at privacy@nazmiq.com, and we will respond to supervisory authority enquiries without undue delay. Where we become required to appoint a representative under Article 27 GDPR or UK GDPR, we will do so and publish the details on this page.

We have not appointed a Data Protection Officer under Article 37 GDPR, and the address above is a privacy contact rather than a DPO. Egyptian Law No. 151 of 2020 and its 2025 Executive Regulations do require a registered data protection officer, with a transitional period to October 2026; we are acting to meet that requirement and will publish the appointment here. We would rather tell you where we are than claim an appointment we have not made.

15. Liability and precedence

Liability under this DPA is subject to the limitations in our Terms of Service. Nothing here limits liability that cannot be limited under applicable data protection law, including liability to data subjects under Article 82 GDPR. In the event of conflict, this DPA prevails over the Terms of Service in respect of personal data, and the Standard Contractual Clauses prevail over this DPA.

Questions about this DPA, or to request signed Standard Contractual Clauses: privacy@nazmiq.com

Terms of Service· Privacy Policy· Refund Policy · DPA· Pricing
© 2026 SkyLight · contact@nazmiq.com · +20 101 992 8994