Back to Home

Data Processing Addendum (DPA)

Effective: 18 April 2026

Last updated: 18 April 2026

This Data Processing Addendum ("DPA") forms part of the agreement between LYT BROX PTE LTD (UEN: 202538612N), 60 Paya Lebar Road, #06-28 Paya Lebar Square, Singapore 409051 ("Processor") and the subscribing client ("Controller"). Capitalised terms follow the Singapore PDPA and EU GDPR usage where applicable.

1. Subject Matter and Duration

The Processor processes personal data solely to provide the contracted services as described in the Terms of Service and any applicable service agreement. This DPA remains in effect for the duration of the Agreement and continues until all personal data has been deleted or returned.

2. Nature and Purpose of Processing

  • AI-powered business operations: lead management, customer communication automation, quotation and invoice generation
  • Message processing and routing via WhatsApp Business API and email
  • Data storage, retrieval, and analytics
  • Hosting and technical infrastructure for the Service

3. Types of Data and Data Subjects

  • Data types: Contact details (names, emails, phone numbers, addresses), business data (price lists, quotations, invoices), communications (messages, emails), technical data (IP addresses, device information)
  • Data subjects: Controller's employees and authorised users, Controller's customers and business contacts, prospective leads and enquirers

4. Processor Obligations

  • Process personal data only on documented instructions from the Controller, unless required by applicable law.
  • Ensure that persons authorised to process personal data are subject to confidentiality obligations.
  • Implement appropriate technical and organisational security measures, including encryption in transit and at rest, row-level security, role-based access controls, and audit logging.
  • Assist the Controller in responding to data subject rights requests (access, correction, deletion, portability) within reasonable timeframes.
  • Notify the Controller without undue delay (and in any case within 48 hours) upon becoming aware of a personal data breach.
  • Assist the Controller with Data Protection Impact Assessments and regulatory consultations as reasonably required.
  • Delete or return all personal data within 30 days of termination of the Agreement, unless retention is required by applicable law. Provide confirmation of deletion upon request.

5. Sub-processors

The Controller authorises the Processor to engage the following sub-processors. The Processor will maintain this list, notify the Controller of material changes, and ensure each sub-processor is bound by data protection obligations no less protective than this DPA.

Sub-processorPurposeLocation
Supabase Inc.Database, authentication, storage, edge functionsUnited States
OpenAI, L.L.C.AI processing (classification, generation, analysis)United States
Resend Inc.Transactional email deliveryUnited States
Google LLC (Gemini)AI image generation and analysisUnited States
Meta Platforms Inc.WhatsApp Business API (message delivery)United States
Stripe Inc.Payment processingUnited States
Vercel Inc.Application hosting and CDNUnited States

The Controller may object to a new sub-processor by notifying the Processor in writing within 14 days of receiving notice of the change. If the objection cannot be resolved, the Controller may terminate the Agreement.

6. International Transfers

Personal data may be transferred to and processed in countries outside Singapore, including the United States. The Processor ensures appropriate safeguards are in place for such transfers, including contractual data protection clauses with sub-processors that meet the requirements of the PDPA and, where applicable, EU Standard Contractual Clauses (SCCs) under the GDPR.

7. Audit Rights

Upon reasonable written notice (no less than 30 days), the Processor will provide the Controller with information necessary to demonstrate compliance with this DPA. The Controller may conduct or commission an audit no more than once per year, at the Controller's expense, during normal business hours, and with reasonable scope limitations to protect other clients' confidentiality.

8. Liability

Each party's liability under this DPA is subject to the limitations of liability set out in the Terms of Service. This DPA does not limit either party's liability for breaches of data protection law to the extent such limitation is prohibited by applicable law.

9. Contact

LYT BROX PTE LTD

UEN: 202538612N

60 Paya Lebar Road, #06-28 Paya Lebar Square, Singapore 409051

Email: sales@lytbrox.com