Data Processing Agreement

Last updated: July 2026

1. Parties

This Data Processing Agreement (“DPA”) is entered into between the Customer (“Data Controller”) and Agentrion Pte. Ltd. (“Data Processor”), and supplements the Master Service Agreement between the parties.

2. Definitions

  • “Personal Data” has the meaning given in the Singapore Personal Data Protection Act 2012 (PDPA) and, where applicable, the EU General Data Protection Regulation (GDPR).
  • “Processing” means any operation performed on Personal Data, including collection, use, storage, disclosure, and deletion.
  • “Sub-processor” means any third party engaged by Agentrion to process Personal Data on behalf of the Customer.

3. Scope of Processing

Agentrion processes Personal Data solely for the purpose of providing the contracted services (AI orchestration, system integration, workflow automation). Categories of data subjects may include Customer employees, Customer’s end-users, and business contacts. Data types processed include identifiers, contact details, usage logs, and business data as defined in the service order.

4. Obligations of the Processor

  • Process Personal Data only on documented instructions from the Controller
  • Ensure personnel authorised to process data are bound by confidentiality obligations
  • Implement appropriate technical and organisational measures (see Security Policy)
  • Assist the Controller in responding to data subject access requests within the timeframes required by the PDPA (30 days) and GDPR (1 month)
  • Notify the Controller without undue delay (and within 72 hours) upon becoming aware of a data breach
  • Delete or return all Personal Data upon termination of services, unless retention is required by law

5. Sub-processors

Agentrion maintains a list of approved sub-processors, available at legal@agentrion.ai upon request. The Controller will be notified at least 30 days in advance of any new sub-processor engagement. Sub-processors are contractually bound to equivalent data protection obligations.

Current Sub-processors

A detailed list of current sub-processors is available upon request by contacting legal@agentrion.ai.

6. International Data Transfers

Where Personal Data is transferred outside of Singapore, Agentrion ensures adequate protection through:

  • ASEAN Model Contractual Clauses for cross-border data flows within ASEAN
  • EU Standard Contractual Clauses (SCCs) for transfers involving EEA data subjects
  • Binding Corporate Rules where applicable
  • Transfer Impact Assessments conducted prior to any new cross-border arrangement

7. Data Retention & Deletion

Personal Data is retained only for the duration of the service agreement plus a maximum of 90 days for backup rotation. Upon contract termination, Customer may request data export (in standard formats: JSON, CSV, or Parquet) within 30 days. After this period, all data is securely deleted using NIST 800-88 compliant methods.

8. Audit Rights

The Controller may audit Agentrion’s compliance with this DPA once per calendar year with 30 days’ written notice. Agentrion will provide access to relevant documentation, certifications (SOC 2, ISO 27001), and facilities. Where on-site audits are impractical, Agentrion will make available its most recent third-party audit reports.

9. Liability

Liability under this DPA is subject to the limitations set forth in the Master Service Agreement. Both parties agree to indemnify each other against losses arising from a breach of this DPA to the extent caused by the indemnifying party’s negligence or wilful misconduct.

10. Governing Law & Jurisdiction

This DPA is governed by the laws of the Republic of Singapore. Any disputes shall be resolved in accordance with the dispute resolution mechanism set out in the Master Service Agreement, with the courts of Singapore having exclusive jurisdiction.

11. Contact

For DPA-related inquiries or to request a signed copy, contact our Data Protection Officer:

Data Protection Officer

Agentrion Pte. Ltd.

Email: dpo@agentrion.ai

Singapore