Data Processing Addendum (DPA)
Effective: 18 April 2026
Last updated: 18 April 2026
This Data Processing Addendum ("DPA") forms part of the agreement between LYT BROX PTE LTD (UEN: 202538612N), 60 Paya Lebar Road, #06-28 Paya Lebar Square, Singapore 409051 ("Processor") and the subscribing client ("Controller"). Capitalised terms follow the Singapore PDPA and EU GDPR usage where applicable.
1. Subject Matter and Duration
The Processor processes personal data solely to provide the contracted services as described in the Terms of Service and any applicable service agreement. This DPA remains in effect for the duration of the Agreement and continues until all personal data has been deleted or returned.
2. Nature and Purpose of Processing
- AI-powered business operations: lead management, customer communication automation, quotation and invoice generation
- Message processing and routing via WhatsApp Business API and email
- Data storage, retrieval, and analytics
- Hosting and technical infrastructure for the Service
3. Types of Data and Data Subjects
- Data types: Contact details (names, emails, phone numbers, addresses), business data (price lists, quotations, invoices), communications (messages, emails), technical data (IP addresses, device information)
- Data subjects: Controller's employees and authorised users, Controller's customers and business contacts, prospective leads and enquirers
4. Processor Obligations
- Process personal data only on documented instructions from the Controller, unless required by applicable law.
- Ensure that persons authorised to process personal data are subject to confidentiality obligations.
- Implement appropriate technical and organisational security measures, including encryption in transit and at rest, row-level security, role-based access controls, and audit logging.
- Assist the Controller in responding to data subject rights requests (access, correction, deletion, portability) within reasonable timeframes.
- Notify the Controller without undue delay (and in any case within 48 hours) upon becoming aware of a personal data breach.
- Assist the Controller with Data Protection Impact Assessments and regulatory consultations as reasonably required.
- Delete or return all personal data within 30 days of termination of the Agreement, unless retention is required by applicable law. Provide confirmation of deletion upon request.
5. Sub-processors
The Controller authorises the Processor to engage the following sub-processors. The Processor will maintain this list, notify the Controller of material changes, and ensure each sub-processor is bound by data protection obligations no less protective than this DPA.
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase Inc. | Database, authentication, storage, edge functions | United States |
| OpenAI, L.L.C. | AI processing (classification, generation, analysis) | United States |
| Resend Inc. | Transactional email delivery | United States |
| Google LLC (Gemini) | AI image generation and analysis | United States |
| Meta Platforms Inc. | WhatsApp Business API (message delivery) | United States |
| Stripe Inc. | Payment processing | United States |
| Vercel Inc. | Application hosting and CDN | United States |
The Controller may object to a new sub-processor by notifying the Processor in writing within 14 days of receiving notice of the change. If the objection cannot be resolved, the Controller may terminate the Agreement.
6. International Transfers
Personal data may be transferred to and processed in countries outside Singapore, including the United States. The Processor ensures appropriate safeguards are in place for such transfers, including contractual data protection clauses with sub-processors that meet the requirements of the PDPA and, where applicable, EU Standard Contractual Clauses (SCCs) under the GDPR.
7. Audit Rights
Upon reasonable written notice (no less than 30 days), the Processor will provide the Controller with information necessary to demonstrate compliance with this DPA. The Controller may conduct or commission an audit no more than once per year, at the Controller's expense, during normal business hours, and with reasonable scope limitations to protect other clients' confidentiality.
8. Liability
Each party's liability under this DPA is subject to the limitations of liability set out in the Terms of Service. This DPA does not limit either party's liability for breaches of data protection law to the extent such limitation is prohibited by applicable law.
9. Contact
LYT BROX PTE LTD
UEN: 202538612N
60 Paya Lebar Road, #06-28 Paya Lebar Square, Singapore 409051
Email: sales@lytbrox.com