Data Processing Agreement
Standardise Pte. Ltd. (UEN 202630608Z) · Last updated: 5 August 2026
1. This DPA
This Data Processing Agreement (“DPA”) forms part of, and is incorporated into, the Standardise Terms of Service (the “Terms”) between Standardise Pte. Ltd. (UEN 202630608Z) (“Standardise”, “we”, “us”) and you. It applies automatically – no separate signature is required. Capitalised and defined terms used but not defined in this DPA have the meanings given in the Terms.
2. Data processing roles
Where we process personal data in connection with the Service, the parties’ roles are as follows.
- (a)Personal data in Customer Data: as between the parties, you are the party responsible for that personal data under applicable data protection laws and we are a data intermediary, processing that personal data on your behalf. We process it only on your documented instructions: the Terms, your Orders and your use and configuration of the Service constitute those instructions. The remainder of this DPA applies to this processing.
- (b)Your personal data: for personal data relating to you and your Authorised Users’ accounts and use of the Service (such as names, business contact details, login records and usage data), we process such personal data in accordance with our Privacy Policy.
3. Details of processing
- (a)Nature and purpose: hosting and processing Customer Data to provide the Service, including generating Output, providing support and maintaining security.
- (b)Duration: the Term, plus the deletion period in this DPA.
- (c)Individuals concerned: your personnel and Authorised Users, and individuals appearing in the documents you upload, such as clients, counterparties, witnesses and deponents.
- (d)Categories of data: any personal data contained in those documents, which may include financial, health or other sensitive information typical of legal proceedings.
4. Personnel
The Service is designed so that Customer Data is processed automatically, without routine human review of its content. Where access to Customer Data by our personnel is exceptionally required, for example, to resolve a technical issue at your request, to maintain security, or where required by law, we limit that access to personnel or service providers who need it for the purposes in clause 3.2 of the Terms, and ensure they are bound by confidentiality obligations.
5. Security
We maintain appropriate technical and organisational measures designed to protect Customer Data against unauthorised access, loss and disclosure, including encryption in transit and at rest, and access controls.
6. Sub-processors
You authorise us to use the following sub-processors to process personal data in Customer Data, each bound by written data protection obligations no less protective than this DPA:
- (a)Microsoft (cloud hosting and storage); and
- (b)Amazon Web Services (AI processing).
We will give you at least 30 days’ notice before adding or replacing a sub-processor. If you object on reasonable data protection grounds and we cannot resolve the objection, you may terminate the affected subscription.
7. Requests from individuals
If an individual contacts us directly with an access, correction or other request concerning personal data in Customer Data, we will redirect them to you and, taking into account the nature of the processing, provide reasonable assistance to help you respond.
8. Data breaches
We will notify you of a data breach affecting Customer Data without undue delay and, in any event, within 72 hours of becoming aware of it where feasible. The notice will describe the nature of the breach, the data affected and the measures taken or proposed, and we will cooperate reasonably with your own notification obligations under applicable data protection laws.
9. Transfers
You acknowledge that personal data in Customer Data may be transferred to us in Singapore, and may be processed by our sub-processors in the locations in which they provide their services, in order to provide the Service for the purposes set out in this DPA. Where personal data in Customer Data is transferred to a recipient outside Singapore (or outside any other jurisdiction whose data protection laws apply to that data), we will ensure that the recipient is bound by legally enforceable obligations to provide a standard of protection comparable to that under the data protection laws applicable to such data, including standard contractual clauses or other appropriate contractual safeguards.
10. Deletion
Customer Data and Output are not retained by us following termination of the Terms and will be deleted from our systems. You are responsible for downloading anything you need before termination takes effect.
11. Liability, precedence and survival
Liability arising under this DPA is subject to the Terms. On matters of data protection, this DPA prevails over the Terms. This DPA lasts for as long as we process personal data in Customer Data and survives termination of the Terms until deletion of Customer Data is complete.