Legal & Compliance

Data Processing Addendum

Baseline processor terms for enterprise services; contact us for an execution copy and schedules.

Effective and last updated: July 13, 2026

This public policy is a baseline. A signed order form, enterprise agreement, or data-processing agreement may contain additional terms and prevails to the extent of a conflict.

Parties, roles, and scope

This Addendum applies when HEOSSI processes personal data on behalf of a customer under an agreement that incorporates it. The customer is the controller or processor, as applicable, and HEOSSI is its processor or subprocessor. Processing is limited to providing, securing, supporting, and maintaining the contracted services for the agreement term.

The subject matter is customer-provided or service-generated personal data. Data subjects may include the customer's users, personnel, clients, suppliers, and other persons whose data the customer submits. Categories depend on the service and may include identifiers, business contact information, account data, content, device data, and logs. Customers must not submit special-category, biometric, health, payment-card, criminal-offence, or government-identifier data unless expressly agreed in writing.

Instructions and confidentiality

HEOSSI will process personal data only on documented customer instructions, including instructions in the agreement and ordinary use of the service, unless law requires otherwise. Authorised personnel are bound by confidentiality duties. HEOSSI will notify the customer if an instruction appears to violate applicable data-protection law, unless prohibited by law.

Security and incidents

HEOSSI will maintain risk-appropriate technical and organisational measures covering access control, authentication, encryption where appropriate, logging, vulnerability management, backup, resilience, personnel security, and incident response. No security measure is absolute.

After becoming aware of a confirmed personal-data breach affecting customer data, HEOSSI will notify the customer without undue delay, provide reasonably available information needed for the customer's legal assessment and notifications, mitigate the incident, and preserve relevant evidence. Notification is not an admission of fault.

Subprocessors

The customer gives general authorisation for the subprocessors disclosed on our Subprocessors page. HEOSSI will impose materially equivalent data-protection obligations and remains responsible for their performance to the extent required by the agreement and law. Customers may object on reasonable data-protection grounds to a new subprocessor after receiving notice; the parties will seek a commercially reasonable alternative.

International transfers

HEOSSI will use a lawful transfer mechanism where required, including contractual protection providing a standard comparable to Singapore's PDPA and, when applicable, the EU Standard Contractual Clauses or UK transfer addendum. The parties will complete required transfer schedules in the signed version of this Addendum.

Assistance, audits, deletion

Taking account of the nature of processing, HEOSSI will reasonably assist with data-subject requests, impact assessments, regulator consultations, and compliance information. Subject to confidentiality and security controls, HEOSSI will provide independent reports or documentation and permit an audit where legally required and other evidence is insufficient; the customer bears reasonable costs unless material non-compliance is found.

At the end of services, HEOSSI will delete or return customer personal data on request, subject to backup cycles, legal retention duties, and data retained securely to establish or defend legal claims.

Mandatory terms

If the customer is itself a processor, these obligations extend for the benefit of the relevant controller. Nothing in this Addendum reduces either party's independent legal duties. Liability is governed by the underlying agreement except where applicable law prohibits that allocation.