Updated August 2026
This Data Processing Agreement (“DPA“) forms part of the Delvify Material Management Platform Terms of Service (“Agreement“) between:
Delvify Labs Pte Ltd, a company incorporated in Singapore (“Delvify“, “Processor“, “we”, “us” or “our”);
and
the customer identified in the applicable Ordering Document (“Customer” or “Controller“).
Delvify and Customer are each a “Party” and together the “Parties“.
This DPA applies where and to the extent that Delvify processes Personal Data on behalf of Customer in connection with the Delvify Material Management Platform and related Services.
Capitalised terms not defined in this DPA have the meanings given to them in the Agreement.
Means all applicable laws and regulations relating to the protection of Personal Data applicable to the processing under this DPA, including, where applicable:
Means the entity that determines the purposes and means of the processing of Personal Data.
Means the entity that processes Personal Data on behalf of the Controller.
Means personal data, personal information or equivalent information protected under Applicable Data Protection Law.
Has the meaning given to it under Applicable Data Protection Law and includes collecting, recording, organising, storing, accessing, retrieving, using, transmitting, disclosing, altering, restricting and deleting Personal Data.
Means an identified or identifiable individual to whom Personal Data relates.
Means any third party appointed by Delvify to process Personal Data on behalf of Customer in connection with the Services.
Means a breach of security resulting in accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data.
For Personal Data processed by Delvify on Customer’s behalf in connection with the Services:
Customer remains responsible for determining the purposes and lawful means of processing Customer Personal Data.
Delvify will process Customer Personal Data only in accordance with this DPA, the Agreement and Customer’s documented instructions.
Customer is responsible for:
The subject matter of processing is the processing of Customer Personal Data as necessary to provide the Delvify Material Management Platform and related Services.
This may include:
Delvify will process Customer Personal Data for the duration of the applicable Subscription Term and thereafter only for:
Delvify may process Customer Personal Data for the following purposes:
Delvify will not process Customer Personal Data for its own independent purposes except where:
Customer Personal Data may concern:
Customer is responsible for determining which categories of Data Subjects are included in Customer Data.
Depending on how Customer uses the Services, Customer Personal Data may include:
Delvify will not intentionally store passwords in readable form.
Customer may choose to upload or enter additional information into the Platform.
Customer is responsible for determining whether such information constitutes Personal Data and whether it is appropriate to process it through the Services.
The Services are not intended to require the processing of special categories of Personal Data.
Customer must not intentionally upload special-category or sensitive Personal Data unless:
Delvify may refuse or restrict processing where it reasonably determines that the requested processing presents a material security, legal or operational risk.
Delvify will process Customer Personal Data only on Customer’s documented instructions.
Customer’s instructions are contained in:
Instructions may be provided electronically, including by email or through the Platform, where they can be retained as a record.
If Delvify believes an instruction violates Applicable Data Protection Law, Delvify will notify Customer where legally permitted.
If Delvify is required by applicable law to process Personal Data in a manner inconsistent with Customer’s instructions, Delvify will notify Customer before processing unless the law prohibits such notification.
Delvify will ensure that persons authorised to process Customer Personal Data:
Delvify will ensure that employees and contractors with access to Customer Personal Data are appropriately trained regarding their confidentiality and data-protection responsibilities.
Delvify will implement appropriate technical and organisational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access.
Measures may include, as appropriate:
Appropriate encryption of Personal Data in transit and, where appropriate, at rest.
Appropriate testing and assessment of technical and organisational security measures.
Appropriate confidentiality obligations and security awareness measures for personnel with access to Personal Data.
Delvify may update its security measures from time to time provided that such changes do not materially reduce the overall level of protection.
If Delvify becomes aware of a Security Incident affecting Customer Personal Data, Delvify will notify Customer without undue delay.
The notification will include, to the extent reasonably available:
Delvify will:
Customer remains responsible for determining whether notification to a supervisory authority or Data Subjects is required.
Delvify will not make public statements about a Security Incident involving Customer Personal Data without consulting Customer where reasonably practicable, except where disclosure is legally required.
Customer provides Delvify with general authorisation to appoint Subprocessors in accordance with this DPA.
Delvify will maintain a list of Subprocessors used to process Customer Personal Data.
The current list will be made available to Customer through Delvify’s designated Subprocessor information page or other reasonable means.
Delvify may appoint new Subprocessors where necessary to provide or improve the Services.
Where required by Applicable Data Protection Law, Delvify will provide Customer with advance notice of the appointment of a new Subprocessor.
Customer may object to a new Subprocessor on reasonable data-protection grounds.
If the Parties cannot resolve the objection within a reasonable period, either Party may terminate the affected Services in accordance with the Agreement.
Delvify will enter into a written agreement with each Subprocessor requiring the Subprocessor to provide data-protection obligations materially equivalent to those applicable to Delvify under this DPA, to the extent applicable to the services performed by that Subprocessor.
Delvify remains responsible for the performance of its Subprocessors to the extent required by Applicable Data Protection Law.
Customer acknowledges that Delvify Labs Pte Ltd is incorporated and operates in Singapore.
Where Customer is subject to the UK GDPR or EU GDPR, transfer of Customer Personal Data to Delvify in Singapore may constitute a restricted international transfer.
The Parties will implement an appropriate lawful transfer mechanism where required.
For transfers restricted under UK data-protection law, the Parties may rely on:
The ICO states that the IDTA and UK Addendum are approved mechanisms for restricted transfers under the UK GDPR.
Where the IDTA or Addendum is required, the applicable instrument will be incorporated into or executed alongside this DPA.
For transfers restricted under the EU GDPR, the Parties may use the EU Standard Contractual Clauses adopted by the European Commission.
The applicable SCC module will be selected according to the actual roles of the Parties and the transfer.
The EDPB confirms that the EU SCCs can provide appropriate safeguards for transfers to third countries.
Where required by Applicable Data Protection Law, the Parties will cooperate in carrying out appropriate transfer assessments.
Delvify will provide reasonably necessary information concerning the destination country, processing arrangements and security measures to enable Customer to conduct the assessment.
The ICO’s current guidance requires organisations relying on UK transfer safeguards to consider whether the transferred data receives an essentially equivalent level of protection, including through an appropriate transfer risk assessment where required.
Where legally permitted, Delvify will notify Customer if it receives a legally binding request from a public authority for access to Customer Personal Data.
Delvify will:
Taking into account the nature of the processing, Delvify will reasonably assist Customer in responding to requests from Data Subjects exercising their rights under Applicable Data Protection Law.
Such rights may include:
Where Delvify receives a Data Subject request relating to Customer Personal Data, Delvify will not respond directly unless:
Where appropriate, Delvify will promptly refer the request to Customer.
Taking into account the nature of processing and information available to Delvify, Delvify will reasonably assist Customer with:
Where such assistance requires substantial additional work outside the ordinary operation of the Services, Delvify may charge reasonable fees where permitted under the Agreement.
Where Customer is required to conduct a Data Protection Impact Assessment (“DPIA”) concerning its use of the Services, Delvify will provide reasonable information and assistance concerning:
Customer remains responsible for conducting and completing its DPIA.
Delvify will make available information reasonably necessary to demonstrate compliance with its obligations under this DPA.
Where reasonably necessary, Customer may conduct an audit of Delvify’s compliance with this DPA, subject to:
Customer will normally first review available:
before requesting an on-site audit.
Audits may be conducted no more than once per year unless:
Customer bears its own audit costs.
If an audit identifies material non-compliance, Delvify will take reasonable steps to address the identified issue.
Upon termination or expiration of the Services, Delvify will, at Customer’s choice:
unless applicable law requires continued retention.
Customer may request an export of Customer Personal Data during the period specified in the Agreement.
Unless otherwise agreed, Customer should request export within 30 days following termination or expiration.
Following the applicable retrieval period, Delvify may delete Customer Personal Data.
Where Personal Data remains in backups, Delvify will securely isolate it and delete it in accordance with its ordinary backup-retention cycle.
Delvify may retain Personal Data where required by applicable law.
Where retention is legally required:
Delvify may process certain information independently as a controller where necessary for:
Such processing is governed by Delvify’s applicable Privacy Policy rather than this DPA.
For clarity, Delvify’s use of the public Website and technologies such as Microsoft Clarity is not Customer’s processor relationship under this DPA unless expressly agreed otherwise.
Nothing in this DPA prevents Delvify from creating and using aggregated or effectively de-identified information derived from use of the Services, provided that such information cannot reasonably be used to identify Customer, a Data Subject or an individual.
Delvify may use such information for:
Delvify will not use Customer Personal Data to train a general-purpose AI model unless expressly authorised by Customer in writing.
Customer may provide additional written processing instructions where necessary.
If an instruction:
the Parties will discuss the applicable changes and any associated fees before implementation.
Privacy and data-protection enquiries concerning the Services may be directed to:
Delvify Labs Pte Ltd
Singapore
Email: privacy@delvify.ai
Where Delvify is legally required to appoint a Data Protection Officer or representative, applicable contact details will be provided to Customer.
The liability provisions of the Agreement apply to this DPA unless the Parties expressly agree otherwise.
Nothing in this DPA limits liability that cannot legally be limited or excluded under Applicable Data Protection Law.
This DPA becomes effective when Customer first enters into the Agreement or otherwise begins using the Services.
It remains in effect for as long as Delvify processes Customer Personal Data.
Termination of the Agreement automatically terminates this DPA, except to the extent that Delvify continues to retain or process Personal Data as permitted or required under this DPA or applicable law.
If there is a conflict between this DPA and the Agreement concerning the processing of Personal Data, this DPA controls.
If there is a conflict between this DPA and an applicable international transfer mechanism, the international transfer mechanism controls to the extent required by applicable law.
This DPA is governed by the governing-law provisions of the Agreement.
Unless otherwise stated in the Agreement, the governing law is the law of Singapore.
This Schedule forms part of the DPA.
Processing of Customer Personal Data in connection with providing the Delvify Material Management Platform and related Services.
For the duration of the applicable Subscription Term and any applicable post-termination data-retrieval, deletion or legally required retention period.
Processing may include:
The Services are not intended for special-category Personal Data.
If Customer requires such processing, the Parties will implement additional safeguards where appropriate.
Processing may occur continuously throughout the Subscription Term as necessary to provide the Services.
Delvify will maintain technical and organisational measures appropriate to the risks associated with the Services.
These may include:
Delvify will periodically assess and, where appropriate, test the effectiveness of its security measures.
Delvify may use third-party Subprocessors to provide infrastructure, hosting, communications, security, analytics, support and other Services.
The current Subprocessor List will be maintained by Delvify and made available to Customer.
The Subprocessor List should identify, at minimum:
| Subprocessor | Service | Processing Location(s) | Categories of Data |
|---|---|---|---|
| [Provider] | Hosting/infrastructure | [Location] | Customer Data |
| [Provider] | Database | [Location] | Customer Data |
| [Provider] | Authentication | [Location] | Account information |
| [Provider] | Customer support | [Location] | Support information |
| [Provider] | Email/communications | [Location] | Contact information |
Do not publish this schedule with invented providers. The actual vendors Delvify uses should be inserted before publication.
Where required by Applicable Data Protection Law:
The Parties will use the applicable UK International Data Transfer Agreement or UK Addendum to the EU Standard Contractual Clauses, as appropriate.
The ICO confirms that these are the UK’s approved standard contractual mechanisms for restricted transfers.
The Parties will use the applicable EU Standard Contractual Clauses for restricted transfers where required.
The appropriate SCC module will be selected based on the Parties’ roles and transfer circumstances.
Delvify’s principal contracting and operating entity is:
Delvify Labs Pte Ltd
Singapore
Where Customer Personal Data is transferred from the UK or EEA to Delvify in Singapore, the applicable international transfer mechanism will apply.
The contractual relationship is intended to operate as follows:
1. Ordering Document
Commercial terms and subscription.
2. Application Terms of Service
General contractual terms governing use of the Delvify Platform.
3. Data Processing Agreement
Processing of Customer Personal Data.
4. Subprocessor List
Third parties processing Customer Personal Data.
5. Technical and Organisational Measures
Security measures applicable to the processing.
Where there is a conflict:
DPA controls over the Application Terms concerning Personal Data processing.
This DPA may be accepted:
DELVIFY LABS PTE LTD
Name: __________________________
Title: __________________________
Date: __________________________
Signature: ______________________
CUSTOMER
Legal Name: _____________________
Name: __________________________
Title: __________________________
Date: __________________________
Signature: ______________________