This Data Processing Addendum (“DPA”) forms part of the Terms of Service between you (“Customer”) and ECONNECION SDN. BHD. (Registration No. 202401005594) (“Processor”, “we”) and applies where we process personal data on your behalf as part of the Service.
For Customer Data (the contacts and business data you capture), the Customer is the controller and eConnection is the processor. Each party will comply with applicable data-protection law, including the Malaysian PDPA 2010 and, where applicable to the Customer, other relevant laws.
“Applicable Data Protection Law”, “personal data”, “processing”, “controller”, “processor” and “data subject” have the meanings given in the Applicable Data Protection Law. “Customer Personal Data” means personal data within Customer Data that we process on the Customer’s behalf.
We will process Customer Personal Data only: (a) to provide the Service; (b) in accordance with the Customer’s documented instructions (including as set out in the Terms and Annex A); and (c) as required by law (in which case we will inform the Customer unless prohibited). The Customer is responsible for the accuracy and legality of Customer Personal Data and for having the right to provide it to us.
The Customer authorises us to engage third-party sub-processors to support the Service (for example hosting, email delivery, messaging and payment providers). Our current list of sub-processors is available on request. We impose data-protection obligations on our sub-processors that are consistent with this DPA, and we remain responsible for their performance. We will give reasonable notice of any intended addition or replacement of a sub-processor so the Customer may object on reasonable data-protection grounds.
Taking into account the nature of the processing, we will assist the Customer with appropriate measures to respond to requests from data subjects to exercise their rights. If we receive such a request directly relating to Customer Personal Data, we will refer the data subject to the Customer.
We will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and will provide information reasonably available to help the Customer meet its notification obligations.
We may transfer and process Customer Personal Data in countries other than the Customer’s, including through our sub-processors, subject to appropriate safeguards consistent with Applicable Data Protection Law.
We will make available information reasonably necessary to demonstrate compliance with this DPA and, on reasonable prior notice and subject to confidentiality, allow for audits by the Customer or an appointed auditor, limited in scope and frequency to what is required by Applicable Data Protection Law.
On termination of the Service, we will delete or return Customer Personal Data in accordance with the Terms and our Privacy Policy, save to the extent we are required to retain it by law. Residual copies in routine backups are deleted in the ordinary course.
Each party’s liability under this DPA is subject to the limitations of liability in the Terms. If there is a conflict between this DPA and the Terms in respect of data protection, this DPA prevails. This DPA is governed by the laws of Malaysia.
Subject matter: provision of the eCSyn Service. Duration: for the term of the Service. Nature & purpose: hosting, storage and processing of Customer Data to deliver capture, CRM, calendar, pipeline, forecasting and team features. Types of personal data: names, contact details, company/role, notes, appointment and deal data, and account/usage data. Categories of data subjects: the Customer’s users, contacts, leads and business connections.
Encryption of data in transit; access controls and authentication; role-based access within Workspaces; reputable cloud hosting; logical separation of customer data; monitoring and logging; and periodic review of security practices. We also apply regular software updates and patching, restrict administrative access on a need-to-know basis, store credentials using industry-standard hashing or encryption, and maintain incident-response procedures for suspected security events.