Legal
Data Processing Addendum
How we handle personal data on a customer's behalf, and the common case where we handle none of it.
Effective 23 August 2026
1. Scope and incorporation
This Addendum forms part of the licence agreement (the "Agreement") between Webint Expert Pte Ltd, registered as WEBINT EXPERT PTE LTD ("we", "Processor") and the customer ("you", "Controller"). It applies where, and only where, we process personal data on your behalf in connection with a WebINT product. Capitalised terms not defined here have the meaning given in the Agreement.
2. When we are not a processor
Read this section before the rest. In air-gapped and on-premises deployments the software runs entirely inside your infrastructure, under your keys and your administrative control. We have no access to the data in it and no technical means of obtaining access. In those deployments we are not a processor of that data and this Addendum has no subject matter in respect of it. You are the sole controller and, as between us, solely responsible for the lawfulness of the processing.
We become a processor only where you engage us for a service that requires it, for example a hosted or managed deployment, or a support engagement in which you deliberately give us access to an environment containing personal data. Sections 3 onwards apply to those cases.
3. Details of processing
| Item | Detail |
|---|---|
| Subject matter | Provision of the WebINT products and related support services |
| Duration | The term of the Agreement, plus any deletion period in section 10 |
| Nature and purpose | Hosting, storage, retrieval, structuring, analysis, and deletion, as instructed by you |
| Types of personal data | Determined by you. May include identifiers, contact details, online identifiers, location data, financial data, and content of communications |
| Categories of data subject | Determined by you. May include persons of investigative interest, associated persons, and your own personnel |
| Special category data | May be present depending on your use. You are responsible for establishing a lawful basis and any additional condition required |
4. Roles and your responsibilities
You are the controller and we are the processor. You warrant that you have a lawful basis and, where the processing concerns investigative or law enforcement activity, a valid legal authority for the processing you instruct, and that your instructions do not require us to breach applicable law. You are responsible for notices to data subjects and for any assessment your law requires before processing begins.
5. Our obligations
- We process personal data only on your documented instructions, including for transfers, unless required otherwise by law. If we believe an instruction breaches applicable data protection law we will tell you.
- We will not sell personal data, and will not use it for our own purposes, for profiling, or to train or fine-tune any machine learning model.
- Personnel with access are bound by confidentiality obligations that survive their engagement.
- Access is limited to those who need it to deliver the service, on a least-privilege basis.
6. Security
We implement appropriate technical and organisational measures having regard to the state of the art, the cost of implementation, and the risk to data subjects. These include encryption in transit and at rest, role-based access control, tamper-evident audit logging, segregation of environments, and periodic review. Measures may be updated provided the level of protection is not reduced. Our current security posture is summarised on our security page, including an honest statement of the certifications we do and do not hold.
7. Sub-processors
You give general authorisation for us to engage sub-processors. We impose data protection obligations on each of them no less protective than those in this Addendum, and we remain fully liable to you for their performance. We will maintain a current list of sub-processors and give you at least 30 days' notice before adding or replacing one. If you reasonably object on data protection grounds within that period, we will work with you in good faith on an alternative; if none is available you may terminate the affected service without penalty.
8. Data subject requests and assistance
Taking into account the nature of the processing, we will assist you by appropriate technical and organisational measures in responding to data subject requests. If a request reaches us directly we will not respond to it on the merits, and will refer it to you promptly unless legally required to act. We will also provide reasonable assistance with impact assessments, prior consultations with a supervisory authority, and security obligations.
9. Personal data breach
We will notify you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting personal data we process for you. The notification will describe the nature of the breach, the likely consequences, the measures taken or proposed, and a contact point, to the extent known at the time, with further information following as it becomes available. We will not delay initial notification in order to complete an investigation.
10. Deletion and return
On expiry or termination of the Agreement, and at your election, we will return or delete the personal data we process for you and delete existing copies, within 60 days, unless law requires continued storage. On request we will certify deletion in writing.
11. International transfers
We will not transfer personal data out of the jurisdiction you nominate without your instruction. Where a transfer occurs, we will put in place a lawful transfer mechanism recognised under the applicable law, and, where required by the Singapore Personal Data Protection Act 2012 (PDPA), ensure the recipient is bound to a comparable standard of protection.
12. Audit
We will make available the information reasonably necessary to demonstrate compliance with this Addendum, and will allow for and contribute to audits, including inspections, conducted by you or an independent auditor you appoint. Audits are on reasonable notice, no more than once in any 12-month period unless a breach has occurred or a supervisory authority requires otherwise, during business hours, subject to confidentiality, and conducted so as not to disrupt our operations or the security of other customers.
13. Liability and conflict
Liability under this Addendum is subject to the limitations and exclusions in the Agreement. If there is a conflict between this Addendum and the Agreement on the processing of personal data, this Addendum prevails.
14. Contact
Notices under this Addendum go through our contact form, or to the
account contact named in the Agreement.
WEBINT EXPERT PTE LTD