Updated August 2026

Data Processing Agreement

DELVIFY LABS PTE LTD

DATA PROCESSING AGREEMENT

This Data Processing Agreement (“DPA“) forms part of the Delvify Material Management Platform Terms of Service (“Agreement“) between:

Delvify Labs Pte Ltd, a company incorporated in Singapore (“Delvify“, “Processor“, “we”, “us” or “our”);

and

the customer identified in the applicable Ordering Document (“Customer” or “Controller“).

Delvify and Customer are each a “Party” and together the “Parties“.

This DPA applies where and to the extent that Delvify processes Personal Data on behalf of Customer in connection with the Delvify Material Management Platform and related Services.


1. DEFINITIONS

Capitalised terms not defined in this DPA have the meanings given to them in the Agreement.

1.1 “Applicable Data Protection Law”

Means all applicable laws and regulations relating to the protection of Personal Data applicable to the processing under this DPA, including, where applicable:

  • the UK General Data Protection Regulation (“UK GDPR“);
  • the Data Protection Act 2018;
  • the EU General Data Protection Regulation (“EU GDPR“);
  • applicable national data-protection legislation implementing or supplementing the EU GDPR;
  • applicable Singapore data-protection law, including the Personal Data Protection Act 2012 (“Singapore PDPA“); and
  • any applicable legislation replacing, amending or supplementing the foregoing.

1.2 “Controller”

Means the entity that determines the purposes and means of the processing of Personal Data.

1.3 “Processor”

Means the entity that processes Personal Data on behalf of the Controller.

1.4 “Personal Data”

Means personal data, personal information or equivalent information protected under Applicable Data Protection Law.

1.5 “Processing”

Has the meaning given to it under Applicable Data Protection Law and includes collecting, recording, organising, storing, accessing, retrieving, using, transmitting, disclosing, altering, restricting and deleting Personal Data.

1.6 “Data Subject”

Means an identified or identifiable individual to whom Personal Data relates.

1.7 “Subprocessor”

Means any third party appointed by Delvify to process Personal Data on behalf of Customer in connection with the Services.

1.8 “Security Incident”

Means a breach of security resulting in accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data.


2. ROLE OF THE PARTIES

2.1 Controller and Processor

For Personal Data processed by Delvify on Customer’s behalf in connection with the Services:

  • Customer is the Controller; and
  • Delvify is the Processor.

Customer remains responsible for determining the purposes and lawful means of processing Customer Personal Data.

Delvify will process Customer Personal Data only in accordance with this DPA, the Agreement and Customer’s documented instructions.

2.2 Customer’s Responsibilities

Customer is responsible for:

  1. establishing a lawful basis for processing Personal Data;
  2. providing required privacy notices to Data Subjects;
  3. responding to Data Subject requests, except to the extent Delvify is required to assist;
  4. ensuring that Customer’s instructions to Delvify comply with Applicable Data Protection Law;
  5. ensuring that Customer has all necessary rights and permissions to provide Personal Data to Delvify; and
  6. determining the appropriate retention period for Customer Personal Data.

3. SUBJECT MATTER AND DURATION

3.1 Subject Matter

The subject matter of processing is the processing of Customer Personal Data as necessary to provide the Delvify Material Management Platform and related Services.

This may include:

  • storing Customer Personal Data;
  • retrieving Customer Personal Data;
  • displaying Customer Personal Data to authorised users;
  • organising Customer Personal Data;
  • transmitting Customer Personal Data;
  • providing technical support;
  • securing the Services;
  • maintaining and improving the technical operation of the Services; and
  • deleting Customer Personal Data.

3.2 Duration

Delvify will process Customer Personal Data for the duration of the applicable Subscription Term and thereafter only for:

  • the period necessary to provide data export or retrieval;
  • deletion or return of Personal Data;
  • compliance with legal obligations;
  • establishment, exercise or defence of legal claims; or
  • other purposes expressly permitted under this DPA.

4. NATURE AND PURPOSE OF PROCESSING

Delvify may process Customer Personal Data for the following purposes:

  • providing the Services;
  • authenticating and managing Authorized Users;
  • storing and retrieving Customer Data;
  • enabling Customer workflows;
  • providing customer support;
  • troubleshooting;
  • monitoring and securing the Services;
  • preventing fraud and abuse;
  • maintaining backups;
  • maintaining business continuity;
  • complying with legal obligations; and
  • performing other processing expressly instructed by Customer.

Delvify will not process Customer Personal Data for its own independent purposes except where:

  1. required by applicable law; or
  2. the Parties have separately agreed to such processing.

5. CATEGORIES OF DATA SUBJECTS

Customer Personal Data may concern:

  • Customer employees;
  • Customer contractors;
  • Customer representatives;
  • Authorized Users;
  • suppliers;
  • manufacturers;
  • vendors;
  • business contacts;
  • consultants;
  • other individuals whose Personal Data Customer elects to process through the Services.

Customer is responsible for determining which categories of Data Subjects are included in Customer Data.


6. CATEGORIES OF PERSONAL DATA

Depending on how Customer uses the Services, Customer Personal Data may include:

Identification information

  • name;
  • username;
  • employee or user ID;
  • job title;
  • department;
  • company or organisation name.

Contact information

  • business email address;
  • business telephone number;
  • business address;
  • other professional contact information.

Account information

  • account credentials;
  • authentication information;
  • user preferences;
  • account settings;
  • access permissions.

Delvify will not intentionally store passwords in readable form.

Business and professional information

  • employer;
  • job title;
  • role;
  • supplier or vendor relationships;
  • project responsibilities;
  • professional communications.

User activity information

  • login information;
  • access logs;
  • actions performed within the Platform;
  • timestamps;
  • IP addresses;
  • device and browser information where collected for security or technical purposes.

Customer-provided content

Customer may choose to upload or enter additional information into the Platform.

Customer is responsible for determining whether such information constitutes Personal Data and whether it is appropriate to process it through the Services.


7. SPECIAL CATEGORIES OF PERSONAL DATA

The Services are not intended to require the processing of special categories of Personal Data.

Customer must not intentionally upload special-category or sensitive Personal Data unless:

  1. the processing is necessary for Customer’s legitimate business use of the Services;
  2. Customer has established an appropriate lawful basis and condition for processing under Applicable Data Protection Law; and
  3. Customer has notified Delvify where additional technical or organisational measures are required.

Delvify may refuse or restrict processing where it reasonably determines that the requested processing presents a material security, legal or operational risk.


8. DOCUMENTED INSTRUCTIONS

Delvify will process Customer Personal Data only on Customer’s documented instructions.

Customer’s instructions are contained in:

  • this DPA;
  • the Agreement;
  • the applicable Ordering Document;
  • Customer’s use of the Services;
  • documented configuration instructions; and
  • subsequent written instructions provided by Customer.

Instructions may be provided electronically, including by email or through the Platform, where they can be retained as a record.

If Delvify believes an instruction violates Applicable Data Protection Law, Delvify will notify Customer where legally permitted.

If Delvify is required by applicable law to process Personal Data in a manner inconsistent with Customer’s instructions, Delvify will notify Customer before processing unless the law prohibits such notification.


9. CONFIDENTIALITY

Delvify will ensure that persons authorised to process Customer Personal Data:

  • are subject to confidentiality obligations; and
  • process Personal Data only as authorised.

Delvify will ensure that employees and contractors with access to Customer Personal Data are appropriately trained regarding their confidentiality and data-protection responsibilities.


10. SECURITY OF PROCESSING

Delvify will implement appropriate technical and organisational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.

Measures may include, as appropriate:

Access controls

  • role-based access controls;
  • least-privilege principles;
  • authentication controls;
  • access reviews;
  • administrative access restrictions.

Encryption

Appropriate encryption of Personal Data in transit and, where appropriate, at rest.

Infrastructure security

  • network security;
  • firewalls;
  • monitoring;
  • vulnerability management;
  • malware protection;
  • security logging.

Availability and resilience

  • backups;
  • disaster recovery measures;
  • business-continuity procedures;
  • service monitoring.

Security testing

Appropriate testing and assessment of technical and organisational security measures.

Personnel

Appropriate confidentiality obligations and security awareness measures for personnel with access to Personal Data.

Delvify may update its security measures from time to time provided that such changes do not materially reduce the overall level of protection.


11. SECURITY INCIDENTS

If Delvify becomes aware of a Security Incident affecting Customer Personal Data, Delvify will notify Customer without undue delay.

The notification will include, to the extent reasonably available:

  • the nature of the Security Incident;
  • the categories of Personal Data affected;
  • the categories or approximate number of Data Subjects affected;
  • the likely consequences;
  • measures taken or proposed to address the incident; and
  • a contact point for further information.

Delvify will:

  1. investigate the Security Incident;
  2. take reasonable steps to contain and remediate it;
  3. provide reasonably available information to Customer;
  4. cooperate with Customer’s reasonable investigation; and
  5. assist Customer with regulatory or Data Subject notifications where required by Applicable Data Protection Law.

Customer remains responsible for determining whether notification to a supervisory authority or Data Subjects is required.

Delvify will not make public statements about a Security Incident involving Customer Personal Data without consulting Customer where reasonably practicable, except where disclosure is legally required.


12. SUBPROCESSORS

12.1 Authorisation

Customer provides Delvify with general authorisation to appoint Subprocessors in accordance with this DPA.

Delvify will maintain a list of Subprocessors used to process Customer Personal Data.

The current list will be made available to Customer through Delvify’s designated Subprocessor information page or other reasonable means.

12.2 New Subprocessors

Delvify may appoint new Subprocessors where necessary to provide or improve the Services.

Where required by Applicable Data Protection Law, Delvify will provide Customer with advance notice of the appointment of a new Subprocessor.

Customer may object to a new Subprocessor on reasonable data-protection grounds.

If the Parties cannot resolve the objection within a reasonable period, either Party may terminate the affected Services in accordance with the Agreement.

12.3 Subprocessor Agreements

Delvify will enter into a written agreement with each Subprocessor requiring the Subprocessor to provide data-protection obligations materially equivalent to those applicable to Delvify under this DPA, to the extent applicable to the services performed by that Subprocessor.

Delvify remains responsible for the performance of its Subprocessors to the extent required by Applicable Data Protection Law.


13. INTERNATIONAL TRANSFERS

13.1 Singapore Processing

Customer acknowledges that Delvify Labs Pte Ltd is incorporated and operates in Singapore.

Where Customer is subject to the UK GDPR or EU GDPR, transfer of Customer Personal Data to Delvify in Singapore may constitute a restricted international transfer.

The Parties will implement an appropriate lawful transfer mechanism where required.

13.2 UK Transfers

For transfers restricted under UK data-protection law, the Parties may rely on:

  • an applicable adequacy regulation;
  • the UK International Data Transfer Agreement (“IDTA”);
  • the UK Addendum to the EU Standard Contractual Clauses; or
  • another lawful transfer mechanism recognised under applicable UK data-protection law.

The ICO states that the IDTA and UK Addendum are approved mechanisms for restricted transfers under the UK GDPR.

Where the IDTA or Addendum is required, the applicable instrument will be incorporated into or executed alongside this DPA.

13.3 EU Transfers

For transfers restricted under the EU GDPR, the Parties may use the EU Standard Contractual Clauses adopted by the European Commission.

The applicable SCC module will be selected according to the actual roles of the Parties and the transfer.

The EDPB confirms that the EU SCCs can provide appropriate safeguards for transfers to third countries.

13.4 Transfer Risk Assessments

Where required by Applicable Data Protection Law, the Parties will cooperate in carrying out appropriate transfer assessments.

Delvify will provide reasonably necessary information concerning the destination country, processing arrangements and security measures to enable Customer to conduct the assessment.

The ICO’s current guidance requires organisations relying on UK transfer safeguards to consider whether the transferred data receives an essentially equivalent level of protection, including through an appropriate transfer risk assessment where required.

13.5 Government Access Requests

Where legally permitted, Delvify will notify Customer if it receives a legally binding request from a public authority for access to Customer Personal Data.

Delvify will:

  • assess the legality of the request;
  • challenge unlawful or excessive requests where reasonably appropriate;
  • disclose only the minimum amount of Personal Data legally required; and
  • provide Customer with information concerning the request where legally permitted.

14. DATA SUBJECT RIGHTS

Taking into account the nature of the processing, Delvify will reasonably assist Customer in responding to requests from Data Subjects exercising their rights under Applicable Data Protection Law.

Such rights may include:

  • access;
  • rectification;
  • erasure;
  • restriction;
  • objection;
  • portability; and
  • other applicable rights.

Where Delvify receives a Data Subject request relating to Customer Personal Data, Delvify will not respond directly unless:

  1. Customer has authorised Delvify to do so; or
  2. Delvify is required to respond by law.

Where appropriate, Delvify will promptly refer the request to Customer.


15. ASSISTANCE WITH CUSTOMER’S COMPLIANCE OBLIGATIONS

Taking into account the nature of processing and information available to Delvify, Delvify will reasonably assist Customer with:

  • security obligations;
  • notification of Personal Data breaches;
  • Data Subject requests;
  • data-protection impact assessments;
  • consultations with supervisory authorities; and
  • other obligations required under applicable Article 32–36 provisions.

Where such assistance requires substantial additional work outside the ordinary operation of the Services, Delvify may charge reasonable fees where permitted under the Agreement.


16. DATA PROTECTION IMPACT ASSESSMENTS

Where Customer is required to conduct a Data Protection Impact Assessment (“DPIA”) concerning its use of the Services, Delvify will provide reasonable information and assistance concerning:

  • the Services;
  • processing operations;
  • security measures;
  • subprocessors;
  • data locations; and
  • other information reasonably available to Delvify.

Customer remains responsible for conducting and completing its DPIA.


17. AUDITS AND COMPLIANCE INFORMATION

Delvify will make available information reasonably necessary to demonstrate compliance with its obligations under this DPA.

Where reasonably necessary, Customer may conduct an audit of Delvify’s compliance with this DPA, subject to:

  • reasonable advance written notice;
  • normal business hours;
  • reasonable security requirements;
  • protection of other customers’ confidential information;
  • no unreasonable disruption to Delvify’s business; and
  • no access to systems or information unrelated to Customer Personal Data.

Customer will normally first review available:

  • security documentation;
  • independent audit reports;
  • certifications;
  • questionnaires; and
  • other compliance information

before requesting an on-site audit.

Audits may be conducted no more than once per year unless:

  • a Security Incident has occurred;
  • a supervisory authority requires an audit; or
  • Customer has reasonable grounds to suspect material non-compliance.

Customer bears its own audit costs.

If an audit identifies material non-compliance, Delvify will take reasonable steps to address the identified issue.


18. RETURN AND DELETION OF PERSONAL DATA

Upon termination or expiration of the Services, Delvify will, at Customer’s choice:

  • return Customer Personal Data; or
  • delete Customer Personal Data,

unless applicable law requires continued retention.

Customer may request an export of Customer Personal Data during the period specified in the Agreement.

Unless otherwise agreed, Customer should request export within 30 days following termination or expiration.

Following the applicable retrieval period, Delvify may delete Customer Personal Data.

Where Personal Data remains in backups, Delvify will securely isolate it and delete it in accordance with its ordinary backup-retention cycle.


19. LEGAL RETENTION

Delvify may retain Personal Data where required by applicable law.

Where retention is legally required:

  • Delvify will retain only the information required;
  • the information will remain subject to confidentiality and security obligations; and
  • Delvify will cease active processing except as required by law.

20. PROCESSING FOR DELVIFY’S OWN PURPOSES

Delvify may process certain information independently as a controller where necessary for:

  • account administration;
  • billing;
  • fraud prevention;
  • security;
  • legal compliance;
  • service administration;
  • direct business communications;
  • maintaining business records; and
  • establishing, exercising or defending legal claims.

Such processing is governed by Delvify’s applicable Privacy Policy rather than this DPA.

For clarity, Delvify’s use of the public Website and technologies such as Microsoft Clarity is not Customer’s processor relationship under this DPA unless expressly agreed otherwise.


21. AGGREGATED AND DE-IDENTIFIED INFORMATION

Nothing in this DPA prevents Delvify from creating and using aggregated or effectively de-identified information derived from use of the Services, provided that such information cannot reasonably be used to identify Customer, a Data Subject or an individual.

Delvify may use such information for:

  • analytics;
  • service improvement;
  • product development;
  • security;
  • benchmarking;
  • research; and
  • business planning.

Delvify will not use Customer Personal Data to train a general-purpose AI model unless expressly authorised by Customer in writing.


22. CUSTOMER INSTRUCTIONS AND CHANGES

Customer may provide additional written processing instructions where necessary.

If an instruction:

  • materially changes the nature of processing;
  • requires significant additional resources;
  • creates substantial security or legal risk; or
  • requires functionality not included in the Services,

the Parties will discuss the applicable changes and any associated fees before implementation.


23. DATA PROTECTION OFFICER / CONTACT

Privacy and data-protection enquiries concerning the Services may be directed to:

Delvify Labs Pte Ltd
Singapore

Email: privacy@delvify.ai

Where Delvify is legally required to appoint a Data Protection Officer or representative, applicable contact details will be provided to Customer.


24. LIABILITY

The liability provisions of the Agreement apply to this DPA unless the Parties expressly agree otherwise.

Nothing in this DPA limits liability that cannot legally be limited or excluded under Applicable Data Protection Law.


25. TERM AND TERMINATION

This DPA becomes effective when Customer first enters into the Agreement or otherwise begins using the Services.

It remains in effect for as long as Delvify processes Customer Personal Data.

Termination of the Agreement automatically terminates this DPA, except to the extent that Delvify continues to retain or process Personal Data as permitted or required under this DPA or applicable law.


26. ORDER OF PRECEDENCE

If there is a conflict between this DPA and the Agreement concerning the processing of Personal Data, this DPA controls.

If there is a conflict between this DPA and an applicable international transfer mechanism, the international transfer mechanism controls to the extent required by applicable law.


27. GOVERNING LAW

This DPA is governed by the governing-law provisions of the Agreement.

Unless otherwise stated in the Agreement, the governing law is the law of Singapore.


SCHEDULE 1

DETAILS OF PROCESSING

This Schedule forms part of the DPA.

A. Subject Matter

Processing of Customer Personal Data in connection with providing the Delvify Material Management Platform and related Services.

B. Duration

For the duration of the applicable Subscription Term and any applicable post-termination data-retrieval, deletion or legally required retention period.

C. Nature of Processing

Processing may include:

  • collection;
  • recording;
  • organisation;
  • structuring;
  • storage;
  • retrieval;
  • consultation;
  • use;
  • transmission;
  • disclosure to authorised recipients;
  • modification;
  • restriction;
  • deletion; and
  • destruction.

D. Purposes

  • providing the Platform;
  • account administration;
  • authentication;
  • customer support;
  • technical support;
  • security;
  • troubleshooting;
  • backups;
  • service continuity;
  • fraud prevention;
  • legal compliance; and
  • other documented Customer instructions.

E. Categories of Data Subjects

  • employees;
  • contractors;
  • Authorized Users;
  • customer representatives;
  • suppliers;
  • manufacturers;
  • vendors;
  • consultants;
  • business contacts; and
  • other individuals whose Personal Data Customer submits to the Platform.

F. Categories of Personal Data

  • names;
  • business email addresses;
  • business telephone numbers;
  • job titles;
  • departments;
  • company names;
  • user IDs;
  • authentication information;
  • account information;
  • access permissions;
  • user activity information;
  • IP addresses;
  • device/browser information;
  • project information;
  • supplier/vendor information; and
  • other Personal Data included in Customer Data.

G. Special Categories

The Services are not intended for special-category Personal Data.

If Customer requires such processing, the Parties will implement additional safeguards where appropriate.

H. Frequency

Processing may occur continuously throughout the Subscription Term as necessary to provide the Services.


SCHEDULE 2

TECHNICAL AND ORGANISATIONAL MEASURES

Delvify will maintain technical and organisational measures appropriate to the risks associated with the Services.

These may include:

1. Access management

  • unique user accounts;
  • role-based permissions;
  • least-privilege access;
  • administrative access restrictions;
  • authentication controls;
  • access logging.

2. Data protection

  • encryption in transit;
  • encryption at rest where appropriate;
  • controlled data access;
  • secure deletion procedures.

3. Infrastructure

  • secure cloud infrastructure;
  • network security controls;
  • monitoring;
  • vulnerability management;
  • malware protection.

4. Availability

  • backups;
  • disaster-recovery procedures;
  • business-continuity procedures;
  • service monitoring.

5. Incident response

  • security monitoring;
  • incident-response procedures;
  • breach investigation;
  • containment and remediation procedures.

6. Personnel

  • confidentiality obligations;
  • security awareness;
  • appropriate access authorisation;
  • access removal when personnel leave or change roles.

7. Testing

Delvify will periodically assess and, where appropriate, test the effectiveness of its security measures.


SCHEDULE 3

SUBPROCESSORS

Delvify may use third-party Subprocessors to provide infrastructure, hosting, communications, security, analytics, support and other Services.

The current Subprocessor List will be maintained by Delvify and made available to Customer.

The Subprocessor List should identify, at minimum:

SubprocessorServiceProcessing Location(s)Categories of Data
[Provider]Hosting/infrastructure[Location]Customer Data
[Provider]Database[Location]Customer Data
[Provider]Authentication[Location]Account information
[Provider]Customer support[Location]Support information
[Provider]Email/communications[Location]Contact information

Do not publish this schedule with invented providers. The actual vendors Delvify uses should be inserted before publication.


SCHEDULE 4

INTERNATIONAL TRANSFER MECHANISMS

Where required by Applicable Data Protection Law:

UK Customers

The Parties will use the applicable UK International Data Transfer Agreement or UK Addendum to the EU Standard Contractual Clauses, as appropriate.

The ICO confirms that these are the UK’s approved standard contractual mechanisms for restricted transfers.

EU Customers

The Parties will use the applicable EU Standard Contractual Clauses for restricted transfers where required.

The appropriate SCC module will be selected based on the Parties’ roles and transfer circumstances.

Singapore

Delvify’s principal contracting and operating entity is:

Delvify Labs Pte Ltd
Singapore

Where Customer Personal Data is transferred from the UK or EEA to Delvify in Singapore, the applicable international transfer mechanism will apply.


SCHEDULE 5

ORDER OF DOCUMENTS

The contractual relationship is intended to operate as follows:

1. Ordering Document
Commercial terms and subscription.

2. Application Terms of Service
General contractual terms governing use of the Delvify Platform.

3. Data Processing Agreement
Processing of Customer Personal Data.

4. Subprocessor List
Third parties processing Customer Personal Data.

5. Technical and Organisational Measures
Security measures applicable to the processing.

Where there is a conflict:

DPA controls over the Application Terms concerning Personal Data processing.


SIGNATURE / ACCEPTANCE

This DPA may be accepted:

  • by signature;
  • through an electronic contracting process;
  • by acceptance of the Application Terms incorporating this DPA; or
  • by another legally binding method agreed by the Parties.

DELVIFY LABS PTE LTD

Name: __________________________
Title: __________________________
Date: __________________________
Signature: ______________________

CUSTOMER

Legal Name: _____________________
Name: __________________________
Title: __________________________
Date: __________________________
Signature: ______________________

Delvify uses the power of AI to transform and improve how stakeholders in the fashion industry connect and collaborate.

join our Newsletter

Sign up for our newsletter to get free the latest updates, tips, inspirations, and more
Delvify – All Rights Reserved 2026