EngageX processes personal data on behalf of our customers (the Data Controllers) to deliver the platform. A small number of third-party providers — our sub-processors — receive that data to help us deliver specific parts of the service. This page lists every one of them. If you need a copy of our Data Processing Addendum or want to ask questions before signing it, this is the reference.
Every sub-processor relationship is governed by a Data Processing Agreement meeting Article 28 GDPR, DIFC Data Protection Law 2020, and UAE PDPL obligations. Cross-border transfers are covered by Standard Contractual Clauses, explicit data-subject consent, or both. Transfer Impact Assessments are on file for every non-adequate-country transfer.
cross_border_transfer) · TIA on fileWhen you connect your Salesforce, HubSpot, Pipedrive, Zoho or Dynamics instance to EngageX, data flows from our platform to your CRM — not through us to a third party. Your CRM vendor is your direct processor, not ours. Their DPA is with you, not with EngageX. We never store CRM credentials in plaintext; OAuth tokens are encrypted with per-tenant keys.
When we add, remove or materially change a sub-processor, we update this page and notify affected customers via the email address on file at least 30 days before the new sub-processor starts receiving data. You have the right to object during that window.
Our Data Processing Addendum incorporates DIFC, UAE PDPL and EU GDPR obligations into a single document. Email legal@engagex.io or request it via the form below — we'll send a countersigned copy within 3 business days.
Get in touch with our team and discover how EngageX connects visitors, exhibitors, and organisers with real purpose.