Data Processing Agreement

Last Updated: December 16, 2025

This Data Processing Agreement (“DPA”) forms part of the Terms of Service (the “Terms”) between Indexync Pte. Ltd. (“Indexync”, “Processor”, “we”, “us”) and the user of the Service (“User”, “Controller”, “you”) and takes effect automatically on the date you accept the Terms.

This DPA applies only to the extent Indexync processes Personal Data on behalf of the User in the course of providing the Service. It does not apply to Indexync’s processing as a controller for account, billing, support and Service usage data, which is described in the Privacy Policy.

1. Definitions

“Applicable Data Protection Laws” means all data protection and privacy laws applicable to the processing of Personal Data under this DPA, including the Personal Data Protection Act 2012 of Singapore (“PDPA”).

“Controller” means the entity which determines the purposes and means of the Processing of Personal Data, and includes any equivalent concept under Applicable Data Protection Laws (such as an “organisation”).

“Data Subject” means an identified or identifiable natural person to whom Personal Data relates, and includes any equivalent concept under Applicable Data Protection Laws (such as an “individual”).

“Personal Data” means any information relating to an identified or identifiable individual, as defined under Applicable Data Protection Laws.

“Personal Data Breach” means any breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data, or any equivalent event defined under Applicable Data Protection Laws.

“Processing” means any operation or set of operations performed on Personal Data, whether by automated means or otherwise, including the collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, disclosure, transmission, dissemination, alignment, combination, restriction, erasure, or destruction of such data.

“Processor” means the entity which Processes Personal Data on behalf of a Controller and not for its own purposes, and includes any equivalent concept under Applicable Data Protection Laws (such as a “data intermediary”).

Other capitalized terms not defined therein shall have the meanings given in the Terms.

In the event of any inconsistency between the definitions in this DPA and Applicable Data Protection Laws, the definitions under Applicable Data Protection Laws shall prevail to the extent required to comply with such laws.

2. Roles of the Parties

The User acts as the Controller of Personal Data contained in Merchant Data.

Indexync acts as a Processor (or “data intermediary” under the PDPA), processing Personal Data solely on behalf of and on the instructions of the User.

Indexync processes Personal Data only:

  • to provide, operate, and improve the Service;
  • in accordance with the Terms, this DPA, and the User’s configuration and use of the Service; and
  • as required by applicable law.

3. Description of Processing

Categories of Data Subjects. May include the User’s customers and prospective customers, end users, employees, and authorised representatives.

Types of Personal Data. May include names, contact details, shipping information, order details, transaction metadata, product information, and other data synced from connected platforms as determined by the User. The Service is not intended to process special categories of data or children’s data.

Purpose of Processing. To provide ecommerce operations tools, including syncing products, inventory, and orders across connected platforms, analytics, troubleshooting, security, and support.

Duration of Processing. For the duration of the User’s use of the Service, plus any retention period described in the Terms or Privacy Policy, or required by law.

4. Processor Obligations

Indexync shall:

Instructions. Process Personal Data only on documented instructions from the User, as set out in the Terms, this DPA and the configurations the User applies within the Service, unless required to do otherwise by applicable law.

Confidentiality. Ensure that persons authorised to process Personal Data are bound by appropriate confidentiality obligations.

Security Measures. Implement reasonable administrative and technical measures designed to protect Personal Data against unauthorised or unlawful processing and against accidental loss, destruction, or damage, taking into account:

  • the nature of the processing;
  • the risks involved; and
  • the information available to Indexync.

Data Minimisation. Limit processing to what is reasonably necessary to provide the Service.

5. User Obligations

The User is responsible for:

  • the lawfulness of Personal Data and the purposes, means, and instructions for processing;
  • providing legally sufficient privacy notices to, and obtaining any required consents from, Data Subjects;
  • configuring and using the Service in compliance with applicable laws and platform rules; and
  • not directing Indexync to process special categories of data or children’s data.

6. Sub-processors

The User authorises Indexync to engage sub-processors to assist in providing the Service, including cloud hosting providers, analytics providers, and customer support tools.

Indexync shall:

  • remain responsible for the performance of its sub-processors in accordance with this DPA; and
  • ensure sub-processors are subject to data protection obligations no less protective than those set out herein.

A list of sub-processors may be made available on Indexync’s website or upon reasonable request and Indexync may update such list of sub-processors from time to time. Continued use of the Service after an update constitutes acceptance of the change.

7. Data Subject Rights

Taking into account the nature of the processing, Indexync shall provide reasonable assistance to the User, at the User’s cost where permitted by law or contract, to enable the User to respond to requests from Data Subjects exercising rights under Applicable Data Protection Laws.

Where Indexync receives a request directly from a Data Subject relating to Merchant Data, Indexync shall, where legally permitted, redirect the request to the User.

8. Personal Data Breach

Indexync shall notify the User without undue delay after becoming aware of a Personal Data Breach affecting Personal Data processed on the User’s behalf.

Such notification shall include, to the extent reasonably available to Indexync:

  • a description of the nature of the breach;
  • the categories of data affected; and
  • steps taken or proposed to mitigate the breach.

9. International Data Transfers

The User acknowledges that Personal Data may be processed in countries outside the User’s jurisdiction, including where Indexync or its sub-processors operate.

Where required under Applicable Data Protection Laws, Indexync shall take steps designed to ensure a comparable standard of protection for such cross-border transfers.

10. Deletion or Return of Data

Upon termination or expiry of the Terms, Indexync shall, within a reasonable period:

  • delete or anonymise Personal Data contained in Merchant Data; or
  • retain such data where required by law or for legitimate purposes described in the Privacy Policy.

Residual copies in backups may be retained for a limited period in accordance with Indexync’s backup and retention practices. Indexync may retain and use aggregated or de-identified data that does not identify the User or Data Subjects.

11. Audits and Compliance

Indexync shall make available information reasonably necessary to demonstrate compliance with this DPA.

Any audit rights shall be limited to:

  • documentation reviews; or
  • third-party certifications or reports where available,

and shall not permit on-site audits unless required by Applicable Data Protection Laws.

12. Limitation of Liability

Liability arising out of or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Terms, to the extent permitted by law.

Any assistance, cooperation, audits, responses to subject requests, or bespoke measures requested by the User and not generally available to all users of the Service may be chargeable on a time-and-materials basis at Indexync’s then-current rates.

13. Precedence

In the event of any conflict between this DPA and the Terms, this DPA shall prevail solely with respect to the processing of Personal Data on the User’s behalf; otherwise, the Terms prevail.

14. Miscellaneous

This DPA shall automatically terminate when Indexync no longer processes Personal Data on the User’s behalf.

Indexync may update this DPA from time to time in accordance with the Terms’ change mechanism. Continued use of the Service after the effective date of an update constitutes acceptance.

15. Governing Law and Dispute Resolution

This DPA is governed by and construed in accordance with the laws specified in the Terms.

Any dispute, claim or controversy arising out of or in connection with this DPA shall be resolved in accordance with the dispute resolution provisions set out in the Terms, which are hereby incorporated by reference and apply to this DPA as if fully set out herein.

16. Contact

Questions regarding this DPA may be directed to: hello@indexync.com