Draft — pending legal review. This text is a working draft and is not yet in force.
Data Processing Agreement
How we process personal data in your workspace on your behalf.
Last updated October 4, 2026
This document is available in English, Bahasa Melayu and Chinese. The English version is the most accurate version and prevails if there is any inconsistency.
1. Scope
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Webbalances Solution (003096168-D) ("Processor") and the Customer ("Controller"). It applies to personal data that we process on the Customer's behalf in its MetriCRM workspace ("Customer Personal Data"). Terms such as data controller, data processor, personal data and processing have the meanings in the Personal Data Protection Act 2010 ("PDPA").
2. Roles
The Customer is the data controller of Customer Personal Data and decides why and how it is processed. We are the data processor and process it only on the Customer's behalf.
3. Details of processing
- Subject matter and duration: providing MetriCRM for the term of the subscription and the 30-day export period after it.
- Nature and purpose: hosting, storing, organising, retrieving, transmitting and analysing data as needed to provide the features the Customer uses.
- Data subjects: the Customer's users, and its customers, contacts, prospects, email recipients and other people whose data the Customer stores.
- Types of data: identity and contact details, organisation details, communications such as emails and notes, case and service history, and other data the Customer chooses to store. The Customer should store sensitive personal data only when necessary and lawful.
4. Customer responsibilities
The Customer is responsible for having a lawful basis for the processing, giving the notices and obtaining the consents the PDPA requires (including for direct marketing and email broadcasts), the accuracy of the data, and configuring its workspace (users, roles, retention and AI settings) to suit its needs.
5. Our obligations
We will:
- process Customer Personal Data only on the Customer's documented instructions, which are given through these Terms and through its use and configuration of MetriCRM, and tell the Customer if we believe an instruction breaks the law;
- ensure that our personnel with access are bound by confidentiality and only access data when needed to provide or support the service;
- comply with the Security Principle that applies to data processors under the PDPA;
- not sell Customer Personal Data or use it for our own purposes, including AI model training.
6. Security measures
We maintain technical and organisational measures appropriate to the risk, including:
- a separate database for each workspace, so customer data is never stored together;
- encryption in transit (TLS) and at rest, with additional encryption for secrets such as mailbox passwords and API keys;
- role-based access, two-factor authentication and configurable session and password policies;
- audit logs of administrative actions and access to sensitive data;
- encrypted backups, monitoring, and vulnerability management;
- AI redaction policies that the Customer can configure.
7. Sub-processors
The Customer authorises us to use the sub-processors below. We impose data protection terms on each sub-processor that are no less protective than this DPA and remain responsible for their performance. We will give at least 30 days' notice before adding or replacing a sub-processor. If the Customer objects on reasonable data protection grounds and we cannot resolve the objection, the Customer may terminate the affected service and receive a refund of prepaid fees for the unused period.
- Neon (database hosting) — Singapore.
- Vercel (application hosting and encrypted file storage) — Singapore, with a global edge network for delivery.
- Stripe (payments and invoicing) — billing data only.
- Inngest (background job scheduling) — job metadata, not message content.
- AI providers the Customer enables: Anthropic, OpenAI and Google — only content sent to AI features.
8. International transfers
Customer Personal Data is stored in Singapore. Where a sub-processor processes it outside Malaysia, we ensure the transfer meets section 129 of the PDPA, for example through contractual safeguards that require protection equivalent to the PDPA.
9. Assistance
Taking into account the nature of the processing, we help the Customer to respond to data subject requests (access, correction, limiting processing and data portability) mainly through export, edit and delete features in MetriCRM, and to meet its obligations on security, breach notification and data protection impact assessments. If we receive a request directly from a data subject, we will pass it to the Customer and not respond ourselves unless the Customer instructs us to.
10. Personal data breaches
We will notify the Customer without undue delay, and in any case within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data. We will describe the nature of the breach, the data and people likely affected, its likely consequences and the steps we have taken, and keep the Customer updated. This helps the Customer meet its 72-hour obligation to notify the Personal Data Protection Commissioner.
11. Audits
We will make available the information needed to show our compliance with this DPA, including answers to reasonable security questionnaires and summaries of independent assessments when available. If that is not enough, the Customer may carry out an audit once a year, with at least 30 days' notice, during business hours, at its own cost, and under confidentiality.
12. Return and deletion
During the subscription and for 30 days after it ends, the Customer can export its data. After that period we delete Customer Personal Data from production systems, and backups are overwritten in the normal backup cycle, unless the law requires us to keep it.
13. Liability and precedence
Each party's liability under this DPA is subject to the limitations in the Terms of Service. If this DPA conflicts with the Terms on the processing of personal data, this DPA prevails.