Roles and instructions
The signed agreement must identify controller and processor roles for each dataset and limit processing to documented instructions.
Beta Preview: SolaBill is currently a beta software platform and is not independently accredited as a UAE Accredited Service Provider or Peppol Access Point. Regulated production exchange is not yet available.
Legal
The minimum framework that must be converted into a signed DPA before production customer data is processed.
Last updated 18 August 2026
The signed agreement must identify controller and processor roles for each dataset and limit processing to documented instructions.
The DPA must state data categories, subjects, purposes, locations, subprocessors, retention, deletion, security measures and international-transfer safeguards.
Access control, encryption, logging, vulnerability handling, backups, recovery and incident-notification duties must be measurable and evidenced.
The applicable Orchida entity, processing role, data location, retention and support obligations must be confirmed in writing. SolaBill will not invent or silently extend those terms.
This public page is a transparency framework, not a contract. Production use requires a signed customer-specific DPA reviewed by qualified counsel.