Sateek
The realityThe productPricing
Try the demoGet startedLog in

MASTER TERMS OF SERVICE & DATA PROCESSING AGREEMENT

Sateek Master Terms of Service and Data Processing Agreement

Version 1.0 — Consolidated Master Agreement — Effective September 22, 2026

Parties

This Master Terms of Service and Data Processing Agreement (this “Agreement”) is made and entered into by and between:

(1) SATEEK TECHNOLOGIES LIMITED, a corporation incorporated under the Canada Business Corporations Act (“Sateek,” “the Company,” “we,” “us,” or “our”); and

(2) the business or other legal entity subscribing to or using the Services, as identified during account registration (the “Customer,” “you,” or “your”),

each individually a “Party” and together the “Parties.” The individual completing registration or accepting this Agreement on the Customer's behalf represents and warrants that they have authority to bind the Customer.

Recitals

WHEREAS Sateek has developed and operates a software-as-a-service bookkeeping and fleet-management platform designed for trucking and logistics companies operating in the United Arab Emirates (the “Services”);

WHEREAS the Customer wishes to subscribe to and use the Services for its business operations, and Sateek is willing to provide the Services, subject to the terms and conditions of this Agreement;

WHEREAS in the course of providing the Services, Sateek will process personal data submitted by or on behalf of the Customer, including personal data of the Customer's own personnel and of the Customer's employees and drivers, and the Parties wish to set out their respective rights, obligations, and responsibilities with respect to that data;

NOW, THEREFORE, in consideration of the mutual covenants set out in this Agreement, the sufficiency of which is acknowledged, the Parties agree as follows.

Structure of This Agreement

This Agreement consists of the following Parts, each of which forms an integral part of, and is incorporated by reference into, this Agreement as a whole:

  • Part A — Terms of Service, which governs the Customer's subscription to and use of the Services;
  • Schedule 1 — Privacy Policy, which describes how Sateek collects, uses, discloses, retains, and protects personal information in connection with the Services; and
  • Schedule 2 — Data Processing Addendum, which governs Sateek's processing of personal data on the Customer's instructions.

References in any Part or Schedule to “this Agreement” refer to this Agreement as a whole, including all Parts and Schedules, unless the context requires otherwise. In the event of a conflict between Part A and a Schedule specifically with respect to the processing of personal data, the applicable Schedule controls, as further stated in Schedule 2.

PART A — TERMS OF SERVICE

1. Introduction, Contracting Parties, and Authority to Bind

These Terms of Service form Part A of the Agreement between Sateek Technologies Limited, a corporation incorporated under the Canada Business Corporations Act ("Sateek", "we", "us", or "our"), and the business or other legal entity identified during account registration as subscribing to or using the Sateek service ("Customer", "you", or "your").

Sateek provides a software-as-a-service bookkeeping and fleet-management platform (the "Services") designed for trucking and logistics companies operating in the United Arab Emirates.

This Agreement becomes binding on the earlier of the Customer's acceptance during account setup or its first use of the Services. The individual accepting this Agreement on behalf of a company represents and warrants that they have the authority to bind that company to its terms; Sateek is entitled to rely on that representation.

The Customer must be a business or other legal entity legally authorized to engage in commercial trucking, logistics, or related operations in its jurisdiction. The Services are offered for business use only. Individuals under the age of 18 may not be Authorized Users.

2. Definitions

  • "Authorized User" means an individual the Customer permits to access the Services under its account, including any Owner, Administrator, Dispatcher, or Accountant role.
  • "Customer Data" means all data, records, and content submitted to the Services by or on behalf of the Customer, including operational, financial, employee, and driver records.
  • "Personal Data" means information relating to an identified or identifiable individual contained within Customer Data, including data about the Customer's employees and drivers who are not themselves Authorized Users.
  • "Subscription" means the paid plan under which the Customer accesses the Services.
  • "Services" means the Sateek software platform, including all features, updates, and support Sateek makes available under this Agreement.
  • "Applicable Law" means the laws of Canada and the applicable province, together with any laws of the United Arab Emirates that apply to the Customer's use of the Services or to Personal Data of individuals located in the UAE.

3. Account Registration, Credentials, and Eligibility

The Customer must provide accurate, current information when registering for the Services and must promptly update that information if it changes. The Customer is responsible for all activity that occurs under its account, including activity by any Authorized User it invites.

The Customer is responsible for maintaining the confidentiality of its Authorized Users' login credentials and for any activity conducted using those credentials, whether or not authorized. The Customer must notify Sateek promptly upon becoming aware of any unauthorized access to or use of its account. Sharing a single Authorized User's credentials among multiple individuals is not permitted; each individual with access must have their own account.

The Customer represents that it has the authority to bind the organization it registers on behalf of, and that it will only invite individuals it is authorized to grant access to the Services.

4. Organization Access and Permissions

Sateek provides role-based access controls, including Owner, Administrator, Dispatcher, and Accountant roles (and any other roles Sateek makes generally available). The Customer is solely responsible for assigning roles to its Authorized Users and for the consequences of those assignments, including the level of access each role grants to Customer Data, financial records, and Personal Data. A decision by the Customer to grant an Authorized User access to sensitive financial or payroll information is the Customer's decision alone; Sateek implements the access-control mechanisms described in this Agreement and the Data Processing Addendum but does not review or approve the Customer's internal role assignments.

The Customer is responsible for the conduct of its Authorized Users in using the Services, including any misuse of an account by an employee or other individual to whom the Customer granted access.

5. Services and Permitted Use

The Services allow the Customer to record and organize bookkeeping entries, track expenses, maintain vehicle and driver records, manage customer ledgers and invoices, and generate reports, including reports relevant to UAE Value Added Tax ("VAT").

The features, functionality, and support levels of the Services may change over time as described in Section 11 (Service Availability, Changes, and Discontinuation). Sateek does not guarantee any specific level of customer support response time unless separately agreed in writing.

The Services do not constitute accounting, auditing, legal, tax, or payroll advice, and do not independently verify the accuracy of information entered by Authorized Users. Section 12 (Financial and Bookkeeping Responsibility) governs this point in detail and should be read carefully.

The Customer agrees not to use the Services to store or process data unrelated to its trucking and logistics operations, or in a manner that violates Applicable Law, infringes any third party's rights, or attempts to circumvent the Services' access controls.

6. Acceptable Use

In addition to the restrictions elsewhere in this Agreement, the Customer and its Authorized Users must not:

  • attempt to gain unauthorized access to any part of the Services, other customers' data, or Sateek's systems;
  • introduce malware, viruses, or other harmful code into the Services;
  • probe, scan, or attempt to exploit vulnerabilities in the Services, or interfere with their normal operation;
  • reverse engineer, decompile, or disassemble the Services, except to the extent Applicable Law expressly permits;
  • scrape, systematically extract, or use automated means to access the Services beyond normal use, or circumvent any rate limits, usage limits, or account restrictions;
  • share Authorized User credentials in a manner inconsistent with Section 3;
  • upload unlawful, fraudulent, or maliciously false content, including fabricated financial or trip records intended to misrepresent the Customer's business to a third party (such as a lender, auditor, or tax authority);
  • upload content that violates another person's privacy or intellectual property rights, content unrelated to the Customer's trucking or logistics operations, or content containing information about children;
  • impersonate another person or entity, or misrepresent an affiliation with any person or entity;
  • interfere with or disrupt Sateek's infrastructure or the ability of other customers to use the Services; or
  • resell, sublicense, or provide access to the Services to any third party without Sateek's prior written consent, other than granting access to the Customer's own Authorized Users as contemplated by this Agreement.

Where the Customer or an Authorized User violates this Section, Sateek may, at its discretion and in proportion to the violation, issue a warning, restrict or remove content, suspend the account temporarily, suspend or terminate the account immediately (see Section 13), and/or report the conduct to law enforcement or regulators where Sateek is legally required or reasonably believes it appropriate to do so.

7. Subscription and Billing

  • Subscription fee: AED 399 per month per organization, inclusive of applicable UAE VAT unless otherwise stated at checkout.
  • Billing cycle: charged monthly in advance via the Customer's payment method on file, processed through Sateek's payment processor (Stripe). The Subscription renews automatically each billing period unless cancelled in accordance with Section 13.
  • Price changes: Sateek may change Subscription pricing on at least 30 days' prospective notice to the Customer. A price change takes effect at the Customer's next renewal following the notice period and does not apply retroactively.
  • Promotional or founding pricing, if offered, is subject to the specific conditions stated at the time it was offered and is not guaranteed to continue indefinitely unless those conditions say otherwise.
  • Failed payments: Sateek will attempt to notify the Customer and may restrict access to the Services (see Section 13) if payment is not resolved within the notice period stated at checkout or in a separate billing policy.
  • Chargebacks: initiating a chargeback or payment reversal without first attempting to resolve a billing dispute with Sateek may result in immediate suspension of the account pending resolution.
  • Billing errors: if Sateek undercharges or overcharges the Customer due to an error, Sateek will correct the error going forward and, for an overcharge, refund or credit the difference for the affected period.
  • Cancellation: the Customer may cancel at any time; cancellation takes effect at the end of the then-current billing period, and the Customer retains access to the Services through the end of that period. Cancellation does not entitle the Customer to a refund for the remainder of a partially used billing period unless Section 7's refund terms say otherwise.
  • Refunds: Subscription fees are non-refundable, including for a partial billing period. Cancellation stops future charges but does not refund any amount already paid for the current period; the Customer retains access through the end of that period as stated above.

8. Customer Data, Feedback, and Aggregated Data

As between the parties, the Customer retains all rights in Customer Data. The Customer grants Sateek the limited rights necessary to host, store, process, transmit, display, and otherwise use Customer Data solely to provide, secure, maintain, and support the Services in accordance with this Agreement, the Data Processing Addendum, and Applicable Law.

Sateek may use Customer Data in aggregated and de-identified form (such that it does not identify the Customer or any individual) to analyze, maintain, and improve the Services, including for internal analytics and benchmarking. Sateek will not sell or disclose Customer Data, in identifiable form, to third parties for their own marketing purposes.

If the Customer submits feedback, suggestions, or ideas about the Services, Sateek may use that feedback without restriction or obligation to the Customer, and the Customer assigns to Sateek any rights it may have in that feedback.

Sateek will not use the Customer's name, trademarks, or logo in public marketing materials without the Customer's prior written authorization.

The Customer is solely responsible for the accuracy, lawfulness, and completeness of all data it or its Authorized Users submit to the Services, including any Personal Data of employees or drivers entered into the platform. The Customer represents that it has the necessary rights and, where required by Applicable Law, the consents necessary to submit that Personal Data to Sateek for processing.

9. Confidentiality and Security

Sateek will implement and maintain administrative, technical, and organizational measures designed to protect Customer Data, as further described in the Data Processing Addendum. As of the Effective Date, Sateek's founder is the only individual with administrative or infrastructure-level access to Customer Data. The founder does not routinely access individual customer organizations' data through the application. Any infrastructure-level access is limited to operating, securing, maintaining, troubleshooting, or supporting the Services. Before Sateek grants any additional employee, contractor, or other individual access to Customer Data or the underlying infrastructure, Sateek will adopt and apply a written access policy governing authorization, scope, logging, review, and revocation.

Sateek will notify the Customer of a confirmed security incident affecting Customer Data without undue delay, in accordance with the incident-response terms of the Data Processing Addendum.

10. Third-Party Services

Sateek relies on third-party service providers to deliver the Services, including cloud hosting and database infrastructure (Supabase), payment processing (Stripe), and email delivery. A current list of subprocessors is maintained in the Data Processing Addendum and, where applicable, at a URL Sateek will designate. If a third-party provider that the Services depend on becomes unavailable or discontinues its service, Sateek will use commercially reasonable efforts to find a suitable replacement but is not liable for any resulting service interruption beyond its reasonable control (see Section 15).

11. Service Availability, Changes, and Discontinuation

Sateek will use commercially reasonable efforts to maintain the availability of the Services but does not guarantee uninterrupted, error-free, or any specific level of uptime unless separately agreed in writing. Sateek may perform scheduled or emergency maintenance, during which the Services may be temporarily unavailable.

Sateek may add, modify, redesign, or discontinue features of the Services from time to time. Sateek will provide reasonable advance notice of a change that materially reduces the core functionality the Customer relies on, except where immediate action is required for security, legal, or safety reasons. Sateek may discontinue the Services entirely on reasonable advance notice, in which case the Customer's data-export rights under Section 13 apply.

12. Financial and Bookkeeping Responsibility

The Services are software tools for recording, organizing, and reporting information entered by Authorized Users. They are not a substitute for a professional accountant, auditor, tax advisor, or payroll administrator, and Sateek does not provide accounting, tax, financial, payroll, or legal advice. This section states, specifically, how responsibility is divided between Sateek and the Customer for the categories of risk inherent in bookkeeping software.

12.1 Data Entered by the Customer or Its Authorized Users

Sateek calculates, organizes, and displays results based on the data an Authorized User enters. If an Authorized User enters incorrect, incomplete, or mistaken information — for example, an expense or trip amount entered as AED 10,000 instead of AED 1,000 — any resulting inaccuracy in a dashboard, report, ledger, or calculation is a consequence of the data entered, not a defect in the Services. The Customer is responsible for reviewing entries and outputs for accuracy and for correcting mistaken entries.

12.2 Reliance on Reports, Including VAT Reports

Reports generated by the Services, including VAT-related reports, are informational tools intended to help the Customer organize its records. They are not a certified or independently verified tax filing product, and the Customer remains solely responsible for verifying the accuracy of any report before relying on it for a tax filing, financial statement, loan application, or other purpose, and for engaging a qualified tax professional as it considers appropriate.

12.3 Payroll Information

Where an Authorized User enters payroll-related information (such as salary, allowances, deductions, or banking details) into the Services, Sateek processes and calculates payroll amounts based on that entered information. Sateek is not responsible for a payment made, over- or under-paid, or misdirected as a result of incorrect information entered by an Authorized User. The Customer is responsible for reviewing payroll calculations before confirming or acting on them.

12.4 Access Granted by the Customer to Its Own Personnel

The Customer decides which of its own Authorized Users may view or edit financial, payroll, or other sensitive company information, through the role-based permissions described in Section 4. Sateek is not responsible for a Customer's decision to grant a given Authorized User a level of access it later considers to have been inappropriate, or for that Authorized User's misuse of access the Customer granted them.

12.5 Calculation Errors Attributable to the Services

Sections 12.1 through 12.4 address inaccuracy caused by information the Customer or its Authorized Users entered, or by access the Customer granted. Where a calculation error is instead attributable to a defect in the Services themselves, Sateek will investigate and correct the confirmed defect promptly upon being notified of it. Sateek's financial responsibility for losses arising from a defect in the Services is subject to the limitation of liability in Section 15; it is neither unlimited nor excluded.

13. Suspension, Termination, and Data After Termination

Sateek may suspend or terminate the Customer's access to the Services if the Customer materially breaches this Agreement (including the Acceptable Use provisions in Section 6), fails to pay outstanding Subscription fees after notice, or if suspension is necessary to protect the security or integrity of the Services or other customers' data. Sateek may suspend an account immediately, without prior notice, where necessary to address a security threat, suspected fraud, or a legal requirement.

The Customer may cancel at any time in accordance with Section 7. Upon cancellation or termination for any reason, the Customer may request export of its Customer Data during the 90-day period following the effective date of cancellation or termination. Following that 90-day period, Sateek will delete Customer Data from its active systems, subject to: (a) information Sateek must retain to comply with legal, tax, or accounting obligations; (b) unresolved billing disputes or outstanding amounts owed; (c) information subject to a legal hold; and (d) copies retained in routine backups until those backups are rotated out in the ordinary course, in accordance with the retention schedule in the Data Processing Addendum. Outstanding fees remain payable notwithstanding termination.

Sections 8 (Customer Data, Feedback, and Aggregated Data, as to the license already granted), 12 (Financial and Bookkeeping Responsibility), 14 (Disclaimers), 15 (Liability), 16 (Indemnification), and 18 (Legal Mechanics) survive termination of this Agreement.

14. Disclaimers

Except as expressly stated in this Agreement, the Services are provided "as is" and "as available," without warranties of any kind, whether express, implied, or statutory, including any implied warranty of merchantability, fitness for a particular purpose, or non-infringement, to the maximum extent Applicable Law permits.

Nothing in this Agreement is intended to, and does not, constitute accounting, tax, legal, financial, or payroll advice. The Customer should consult qualified professionals for such advice.

15. Limitation of Liability

EXCEPT FOR THE CARVE-OUTS LISTED BELOW, SATEEK'S TOTAL LIABILITY ARISING OUT OF OR RELATING TO THIS AGREEMENT, HOWEVER THE CLAIM ARISES, WILL NOT EXCEED THE TOTAL SUBSCRIPTION FEES PAID BY THE CUSTOMER TO SATEEK IN THE 12 MONTHS PRECEDING THE EVENT GIVING RISE TO THE CLAIM. NEITHER PARTY WILL BE LIABLE FOR INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, OR FOR LOSS OF PROFITS, REVENUE, OR DATA, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.

The following are not subject to the cap in this Section: (a) the Customer's payment obligations under Section 7; (b) either party's indemnification obligations under Section 16; (c) either party's breach of its confidentiality obligations under Section 9; and (d) either party's gross negligence or willful misconduct. Nothing in this Section excludes, limits, or waives a right, remedy, liability, or statutory obligation to the extent that Applicable Law does not permit it to be excluded, limited, or waived.

16. Indemnification

The Customer will indemnify, defend, and hold harmless Sateek from and against any third-party claim, and resulting liabilities, damages, and reasonable expenses (including legal fees), arising from or relating to: (a) Customer Data, including its accuracy, legality, and the Customer's right to submit it to the Services; (b) content uploaded by the Customer or its Authorized Users, including under the Acceptable Use provisions of Section 6; (c) the Customer's or an Authorized User's breach of this Agreement; or (d) the Customer's use of the Services in violation of Applicable Law.

Sateek will indemnify, defend, and hold harmless the Customer from and against any third-party claim, and resulting liabilities, damages, and reasonable expenses (including legal fees), alleging that the Services, as provided by Sateek and used in accordance with this Agreement, infringe that third party's intellectual property rights, excluding any claim arising from Customer Data, the Customer's modifications, or use of the Services in combination with anything not provided by Sateek.

Each party's indemnification obligations under this Section are subject to the indemnified party promptly notifying the indemnifying party of the claim, giving the indemnifying party control of the defense and settlement, and providing reasonable cooperation, at the indemnifying party's expense.

17. Changes to This Agreement

Sateek may amend this Agreement from time to time. Sateek will provide notice of a material change at least 30 days before it takes effect, by email to the account owner or through an in-app notice. Continued use of the Services after the effective date of a change constitutes acceptance of the amended Agreement. If the Customer does not agree to a material change, its sole remedy is to cancel the Subscription under Section 7 before the change takes effect.

18. Legal Mechanics

18.1 Governing Law and Disputes

This Agreement is governed by the laws of the Province of Ontario and the federal laws of Canada applicable therein, without regard to conflict-of-laws principles.

Before commencing a claim, the parties will attempt in good faith to resolve any dispute arising out of or relating to this Agreement through informal negotiation between senior representatives of each party for at least 30 days following written notice of the dispute. If the dispute is not resolved within that period, either party may commence proceedings, and each party irrevocably submits to the exclusive jurisdiction of the courts located in Ontario, Canada.

18.2 Notices

Notices to the Customer may be given by email to the account owner's address on file or by in-app notice. Notices to Sateek must be given to info@sateek.ca.

18.3 Severability

If any provision of this Agreement is found unenforceable, that provision will be limited or eliminated to the minimum extent necessary, and the remaining provisions will remain in full force and effect.

18.4 Waiver

Sateek's failure to enforce any provision of this Agreement is not a waiver of its right to do so later.

18.5 Assignment

The Customer may not assign this Agreement without Sateek's prior written consent. Sateek may assign this Agreement in connection with a merger, acquisition, corporate reorganization, or sale of substantially all of its assets, provided the assignee agrees to be bound by this Agreement.

18.6 Force Majeure

Neither party is liable for a failure or delay in performance caused by circumstances beyond its reasonable control, including natural disasters, war, government action, internet or infrastructure failures, or failures of third-party providers described in Section 10.

18.7 Entire Agreement

This Agreement, together with the Privacy Policy and the Data Processing Addendum, constitutes the entire agreement between the parties regarding the Services and supersedes any prior agreements or understandings on that subject.

SCHEDULE 1 — PRIVACY POLICY

1. Who We Are

This Privacy Policy is issued by Sateek Technologies Limited, a corporation incorporated under the Canada Business Corporations Act ("Sateek", "we", "us", or "our"). It explains how we collect, use, disclose, retain, and protect personal information in connection with the Sateek platform.

Privacy contact: info@sateek.ca.

This Policy covers two distinct groups of individuals: (a) Sateek account users — owners, managers, dispatchers, and accountants who register for or receive an invitation to a Sateek account; and (b) operational employees and drivers — individuals whose information is entered into Sateek by a trucking-company customer, who do not themselves hold a Sateek login.

2. Information We Collect

We collect the categories of information described in the data inventory below, confirmed against the live database schema and storage configuration.

Data groupExamplesCurrently confirmed as stored?
AuthenticationEmail, account timestamps, authentication metadataYes
ProfilesName, phone, avatar URL, language, timezoneYes
Organization accessMemberships, roles, permission flagsYes
EmployeesName, employee ID, position, phone, hire dateYes
PayrollSalary, IBAN/payment details, advances, reimbursementsYes
ComplianceDriving licence number/expiry, visa and MOHRE expiryYes
Company recordsLegal name, address, TRN, phone, email, bank detailsYes
Company assetsLogo, stamp, invoice-related assetsYes
BillingStripe customer and subscription informationYes
Technical / session dataIP address, device info, and approximate location derived from IP, recorded per login sessionYes

3. How We Use Information

  • To create and administer accounts and enforce role-based permissions.
  • To provide the Services: bookkeeping, expense tracking, vehicle and driver records, customer ledgers, VAT-related reports, and other platform functionality.
  • To secure the platform, including tenant isolation between customer organizations, fraud prevention, and abuse detection.
  • To provide customer support and troubleshoot issues, including limited internal staff access as described in Section 8.
  • To process billing through our payment processor.
  • To comply with legal obligations and respond to lawful requests.

4. Customer-Submitted Employee and Driver Information

Trucking-company customers enter operational records about their own employees and drivers into Sateek, including identity, position, payroll, and compliance information (see the data inventory above). Sateek processes this information to provide the Services requested by the customer that submitted it. Sateek's relationship to this information, and the customer's own obligations to the individuals it concerns, are addressed in the Data Processing Addendum.

If you are an employee or driver whose information has been entered into Sateek by your employer and you have questions about that information, please contact your employer in the first instance, as they control what is submitted. You may also contact us using the details in Section 13.

5. Legal Grounds and Consent

For Sateek account users (owners, managers, dispatchers, accountants), Sateek processes account information to establish and administer the business relationship, authenticate users, provide and secure the Services, process billing, provide support, and comply with legal obligations. Where consent is required under PIPEDA or other Applicable Law, Sateek seeks or relies on consent appropriate to the circumstances. Where the UAE Personal Data Protection Law applies, Sateek processes Personal Data on a lawful basis available for the relevant processing activity, including contract-related or other grounds permitted by that law.

For employee and driver information entered by a Customer: this information is processed on the Customer's instructions to provide the Services, consistent with the Data Processing Addendum. As the employer, the Customer is responsible for any notice or consent it must obtain from its own employees and drivers under applicable law, including the PDPL's employment-relationship provisions, which recognize employment, social security, and social protection obligations as an independent basis for processing employee data. Sateek does not independently solicit or manage consent from these individuals.

6. Service Providers and Disclosures

We share information with service providers who help us deliver the Services, under contractual obligations to protect it. Categories currently in use:

  • Cloud hosting and database infrastructure — Supabase.
  • Payment processing — Stripe.
  • Transactional email delivery — Resend (invitation emails); some system emails, such as account authentication and password-reset emails, are sent through Supabase's built-in authentication email system rather than Resend.

7. International Data Transfers

Sateek is a Canadian company serving customers based in the United Arab Emirates. Based on verified infrastructure configuration, the Supabase project underlying the Services is hosted in the ap-south-1 region (Mumbai, India). Personal information submitted by UAE-based Customers may therefore be transmitted to and stored on infrastructure in India and administered by Sateek from Canada. Stripe, Resend, and other subprocessors may process information in additional jurisdictions as described in Sateek's current subprocessor disclosures and the applicable provider arrangements. Sateek does not state a processing location as verified unless Sateek has confirmed that location for the relevant service.

8. Security Safeguards

We implement technical and organizational measures designed to protect the confidentiality, integrity, and availability of information in the Services, including:

  • Tenant isolation enforced at the database level, so that one customer organization's data is not accessible to another — verified through direct testing of database access rules, server-side functions, and file storage.
  • Private, access-controlled file storage for uploaded documents and receipts, scoped per organization.
  • As of the Effective Date, Sateek's founder is the only individual with administrative or infrastructure-level access to Customer Data; no separate employee, contractor, or support team has such access. The founder does not routinely access individual Customer organizations' data through the application. As administrator of the underlying Supabase project, the founder has broader technical access through the infrastructure dashboard when necessary to operate, secure, maintain, troubleshoot, or support the Services. Before any additional individual is granted such access, Sateek will adopt and apply a written access policy covering authorization, scope, logging, review, and revocation.

9. Retention and Deletion

While an account is active, we retain Customer Data and Personal Data to provide the Services. Following cancellation or termination of a Customer's account, we retain Customer Data for 90 days to allow the Customer to export it, after which we delete it from our active systems, subject to: (a) information we must retain to meet legal, tax, or accounting obligations; (b) unresolved billing disputes or amounts owed; (c) information subject to a legal hold; and (d) copies retained in routine backups until those backups are rotated out in the ordinary course. As of the Effective Date, Sateek's primary Supabase project uses daily database backups with a seven-day backup retention period under its current Supabase Pro configuration.

10. Privacy Rights and Requests

Individuals may request access to, correction of, or (subject to legal and contractual limits) deletion of their personal information by contacting us using the details in Section 13. We will take reasonable steps to verify the identity of the requester before responding.

11. Cookies and Technical Data

Sateek does not embed a dedicated third-party analytics, tracking, or session-replay tool (such as Google Analytics, PostHog, or Hotjar) in the Services. Lovable, the platform used to build and host the Services, provides Sateek as the operator with aggregate, platform-level usage metrics (such as overall active-user counts), and does not give Sateek visibility into an individual data subject's specific activity beyond what is already recorded in the Services' own session log described in the data inventory (Section 2).

12. Children's Privacy

The Services are directed at business use by trucking and logistics companies and are not directed at, or intended for use by, children.

13. Changes and Contact

We may update this Policy from time to time. We will indicate the effective date of the current version and provide notice of material changes where required.

Contact: info@sateek.ca.

SCHEDULE 2 — DATA PROCESSING ADDENDUM

1. Scope and Relationship

This Data Processing Addendum ("DPA") is entered into between Sateek Technologies Limited, a corporation incorporated under the Canada Business Corporations Act ("Sateek"), and the Customer under the Terms of Service, and governs Sateek's processing of personal data submitted by the Customer to the Services.

2. Processing Instructions

Sateek will process personal data only in accordance with the Customer's documented instructions, which consist of this DPA, the Terms of Service, and the Customer's use of the Services' documented features. Changes to these instructions must be agreed in writing (including by email).

3. Categories of Personal Data

  • Account information: name, email, phone, role/permissions.
  • Employee identity information: name, employee ID, position, phone, hire date.
  • Payroll information: salary, IBAN/payment details, advances, reimbursements.
  • Driver compliance information: driving licence number/expiry, visa and MOHRE expiry.
  • Company and billing information: legal name, address, TRN, bank details, Stripe billing data.
  • Session/technical information: IP address and device information recorded per login session.

4. Categories of Data Subjects

Account users (owners, administrators, dispatchers, accountants), employees, drivers, and any other individuals whose personal data the Customer submits to the Services.

5. Processing Purposes

Service delivery, account management, record organization and reporting, security, customer support, and other purposes documented in the Terms of Service and this DPA.

6. Confidentiality

Sateek requires personnel authorized to access Customer Data to protect its confidentiality and to access it only for approved purposes consistent with this DPA.

7. Security Measures

Sateek has directly tested and confirmed the following technical measures as of the Effective Date:

  • Tenant (organization) isolation is enforced at the database level: authenticated users of one organization cannot read or write another organization's trips, invoices, customers, vehicles, employees, or expenses, whether attempted through direct record-ID manipulation, forged organization identifiers in requests, or normal search/filter/dropdown paths.
  • File storage (receipts and similar uploads) is private and folder-scoped per organization; cross-organization file access was tested and blocked.
  • Authorization testing included the payroll-confirmation function. A cross-organization write issue identified during testing was remediated and successfully retested before the Effective Date.
  • Financial and VAT calculation functions were tested against known datasets, and defects identified during testing were corrected and retested before the Effective Date.
  • The monthly analytics report generator was also tested for customer-specific output isolation; an identified customer-profile display defect was corrected before the Effective Date.

8. Internal Staff Access Policy

As of this draft, Sateek has one individual: its founder. There is no separate staff, contractor, or team with access to Customer Data, and no in-app administrative role is currently assigned to anyone other than the founder.

  • Application-level access: the founder does not routinely access individual customer organizations' data through the application. The application's own access controls (tenant isolation, described in Section 7) apply to any account Sateek operates within the product.
  • Infrastructure-level access: as the owner and administrator of the underlying Supabase project, the founder has technical access to the underlying database and infrastructure through the Supabase dashboard, separate from and broader than any in-app role. This is a function of operating the infrastructure the Services run on, not a customer-facing access grant, but the Customer should understand it exists.
  • Access by anyone other than the founder: none currently exists. Before Sateek gives any additional individual (employee, contractor, or otherwise) access to Customer Data or the underlying infrastructure, Sateek will adopt and follow a written access policy covering the basis for granting access, the scope of records reachable, logging, revocation on role change or departure, and periodic review.

9. Subprocessors

Current subprocessors include Supabase (cloud hosting and database infrastructure, ap-south-1 / Mumbai region — verified), Stripe (payment processing), and Resend (transactional email for invitations). Sateek will notify the Customer of a new subprocessor with material access to Customer Data with reasonable advance notice.

10. International Transfers

Processing occurs across at least three jurisdictions: Sateek is incorporated and administered in Canada; the Customer and relevant Data Subjects are primarily located in the United Arab Emirates; and Sateek's primary Supabase infrastructure is hosted in the ap-south-1 / Mumbai, India region, verified against the live project. Stripe, Resend, and other approved subprocessors may process Personal Data in additional jurisdictions as described in Sateek's current subprocessor disclosures and the applicable provider arrangements. Sateek will not represent a particular processing location as verified unless it has confirmed that location for the relevant service.

11. Security Incidents

Sateek will notify the Customer immediately upon becoming aware of a confirmed Personal Data security breach affecting Customer Data and will provide information reasonably available to Sateek to assist the Customer with its regulatory obligations. Where Sateek acts as a Processor, this notification is intended to support the Customer's obligations as Controller, including any applicable notification obligation to the UAE Data Office. Sateek may provide an earlier preliminary notice where appropriate and will update the Customer as material information becomes available.

12. Data Subject Requests

Sateek will provide reasonable assistance to the Customer in responding to requests from individuals to access, correct, delete, restrict, or otherwise exercise rights concerning their Personal Data, to the extent supported by Sateek's systems and required by Applicable Law. The Customer remains responsible for determining and meeting any statutory response deadline that applies to it as Controller.

13. Retention and Deletion

Following termination of the Customer's account, Sateek retains Customer Data for 90 days to allow the Customer to export it, after which Sateek deletes it from active systems, subject to: (a) information Sateek must retain to meet legal, tax, or accounting obligations; (b) unresolved billing disputes or amounts owed; (c) information subject to a legal hold; and (d) copies retained in routine backups until those backups are rotated out in the ordinary course. As of the Effective Date, Sateek's primary Supabase project is on the Supabase Pro plan and uses the provider's daily database backup capability with a seven-day backup retention period. This describes the current backup configuration and may change if Sateek adopts an equivalent or stronger backup and recovery arrangement.

14. Audits and Compliance Evidence

Sateek will make available, on reasonable request and subject to confidentiality and cost limitations, information reasonably necessary to demonstrate compliance with this DPA.

15. Term and Liability

This DPA remains in effect for as long as Sateek processes personal data on the Customer's behalf under the Terms of Service. In the event of a conflict between this DPA and the Terms of Service regarding the processing of personal data, this DPA controls. Liability arising under or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service, which apply to this DPA as though fully set out in it.

Acceptance

By checking the box or clicking “I Agree” (or an equivalent affirmative mechanism) presented during account registration, or by accessing or using the Services, the individual so acting represents that they have read, understood, and agree, on behalf of the Customer, to be bound by this Agreement in its entirety, including Part A, Schedule 1, and Schedule 2, as they may be amended from time to time in accordance with Part A, Section 17 (Changes to This Agreement).

This Agreement constitutes the entire agreement between the Parties regarding the Services and supersedes any prior agreements or understandings between them on that subject.

Sateek

The financial operating system for UAE trucking.

info@sateek.ca+1 (647) 460 6796
Terms of ServicePrivacy PolicyData Processing Addendum
© 2026 Sateek Technologies limited.