Data Processing Agreement
Effective date: · Version 1.0
1. Parties and acceptance
This Data Processing Agreement (“Agreement”) is published by SaaS Global Pte Ltd (UEN 202322132C), a company incorporated in Singapore (“we”, “us”, “SaaS Global”), and applies to all customers who engage SaaS Global Pte Ltd for services under any of its brands, including the DCRM brand and the Practice Growth Studio (PGS) brand. By engaging us, the customer (referred to as the Data Controller) agrees to the terms of this Agreement.
| Data Intermediary (Processor) | Data Controller (Organisation) |
|---|---|
| SaaS Global Pte Ltd UEN 202322132C 2 Venture Drive #19-18 Vision Exchange, Singapore 608526 Brands operated: DCRM and Practice Growth Studio DPO email: eric@dcrm.io | The customer as identified in the applicable service agreement or order form. Referred to as “the Customer” or “the Data Controller”. |
Together, we are referred to as “the Parties”.
2. Purpose
This Agreement sets out the terms on which SaaS Global Pte Ltd processes personal data on behalf of its customers in connection with the delivery of CRM, automation, SMS and communications, AI features, website design and development, digital marketing, and related services (the “Services”) across its DCRM and Practice Growth Studio brands.
This Agreement is designed to ensure compliance with Singapore’s Personal Data Protection Act 2012 in a practical and proportionate manner.
3. Legal framework
This Agreement is governed by the Personal Data Protection Act 2012 (PDPA) of Singapore. The PDPA regulates the collection, use, disclosure, and care of personal data by organisations in Singapore.
The Personal Data Protection Commission (PDPC) is the regulator responsible for administering and enforcing the PDPA. Customers who are located in Australia should note that, where SaaS Global Pte Ltd processes the personal data of Australian individuals on their behalf, SaaS Global Pte Ltd will take reasonable steps to ensure that processing is consistent with the Australian Privacy Principles under the Privacy Act 1988 (Cth) as required by the Customer’s own obligations.
Note for Australian customers. Where your customers or end users are Australian individuals, you (as the Data Controller) remain primarily responsible for ensuring a lawful basis for collection and compliance with the Privacy Act 1988 (Cth). SaaS Global Pte Ltd will support that compliance as a Data Intermediary under this Agreement.
4. Definitions
- PDPA means the Personal Data Protection Act 2012 (Singapore).
- PDPC means the Personal Data Protection Commission of Singapore.
- Personal Data has the meaning given in the PDPA: data, whether true or not, about an individual who can be identified from that data or from that data and other information to which the organisation has or is likely to have access.
- Data Breach means any unauthorised access to, collection, use, disclosure, copying, modification, disposal, or loss of Personal Data.
- Data Intermediary means an organisation that processes Personal Data on behalf of and for the purposes of another organisation, in accordance with the PDPA.
- Services means the services provided by SaaS Global Pte Ltd to the Customer under any applicable service agreement or order form, including under the DCRM and Practice Growth Studio brands.
- Sub-processor means any third-party platform or service provider engaged by SaaS Global Pte Ltd that processes Personal Data in connection with the Services.
- AI Provider means any third-party artificial intelligence or machine learning service used in connection with the Services, including OpenAI and any underlying model providers integrated through Go High Level (GHL).
5. Roles of the Parties
SaaS Global Pte Ltd acts as a Data Intermediary under the PDPA. It processes Personal Data on behalf of the Customer, and only in accordance with the Customer’s instructions and the terms of this Agreement.
The Customer is the Data Controller (referred to as the “Organisation” under the PDPA). The Customer is responsible for:
- ensuring it has a lawful basis to collect and process the Personal Data it provides to SaaS Global Pte Ltd;
- obtaining any necessary consents from individuals whose data is processed through the Services;
- ensuring its own compliance with all applicable data protection laws, including the PDPA and any relevant laws in the Customer’s jurisdiction; and
- providing accurate and lawful instructions to SaaS Global Pte Ltd regarding the processing of Personal Data.
As a Data Intermediary, SaaS Global Pte Ltd is not liable under the PDPA for the Customer’s failure to obtain proper consent or establish a lawful basis for processing.
6. Permitted use of Personal Data
SaaS Global Pte Ltd will:
- only process Personal Data for the purpose of delivering the Services to the Customer;
- not use Personal Data for any purpose beyond the scope of the Services without the Customer’s prior written consent;
- not disclose Personal Data to third parties except where required to deliver the Services (for example, passing contact data to a communications carrier for SMS delivery), where required by law, or with the Customer’s prior written consent;
- process Personal Data in accordance with the Customer’s instructions as communicated through use of the Services or in writing; and
- not use Personal Data, materials provided by the Customer, or any data flowing through the Services to train, fine-tune, or evaluate any artificial intelligence or machine learning model for general use or for any purpose outside the delivery of the Services to the Customer.
Where Personal Data is disclosed to a Sub-processor for service delivery, SaaS Global Pte Ltd will use reasonable commercial efforts to ensure that Sub-processor handles the data consistently with this Agreement and the PDPA.
7. Customer obligations and AI training prohibition
The Customer must not use any of SaaS Global’s confidential information, platform configuration, Snapshots, automation structures, campaign logic, prompt sets, workflows, scripts, dashboards, training materials, or any other materials or methodologies provided by SaaS Global Pte Ltd to train, fine-tune, or evaluate any artificial intelligence or machine learning model, or to build any competing product, service, methodology, or platform.
8. AI processing
The DCRM platform incorporates artificial intelligence and machine learning features, including Voice AI, Conversation AI, AI Automation Workflows, call summarisation, transcription, lead scoring, and automated response suggestions. The Practice Growth Studio brand uses generative AI tools during the production of content and campaigns. These features process Personal Data through one or more AI Providers.
8.1 Data flows to AI Providers
When the Customer or its end users invoke AI features, Personal Data forming the input to those features (including contact information, conversation transcripts, voice recordings, and contextual data) is transmitted to the relevant AI Provider for processing. SaaS Global Pte Ltd is not the originator of AI Provider terms of service or model behaviour.
8.2 AI Provider terms
SaaS Global Pte Ltd uses AI Providers that, to the best of its knowledge at the date of this Agreement, do not retain Customer Personal Data for the purpose of training their general AI models, where the relevant AI Provider offers that posture. Where an AI Provider changes its data handling terms in a manner that materially affects this Agreement, SaaS Global Pte Ltd will notify the Customer in writing as soon as reasonably practicable.
8.3 No general training use
SaaS Global Pte Ltd does not use Customer Personal Data to train general AI models for the benefit of other customers, nor does it permit such use by any Sub-processor where SaaS Global Pte Ltd has a contractual ability to prevent it.
8.4 Output review and Customer responsibility
The Customer acknowledges that AI outputs are probabilistic and may be inaccurate, incomplete, or unsuitable for a given purpose (“hallucination”). The Customer is solely responsible for reviewing, approving, and validating any AI output before publication, distribution, or operational use. AI outputs are not, and must not be represented as, professional advice of any kind.
Important. Customers are strictly prohibited from deploying AI-generated content, automated voice interactions, or AI-driven responses in a live environment with the Customer’s end users without prior human review and approval. SaaS Global Pte Ltd is not liable for any error, regulatory non-compliance, or reputational harm arising from unreviewed AI outputs.
9. Retention and deletion
SaaS Global Pte Ltd will retain Personal Data only for as long as it is reasonably necessary to deliver the Services or as required by law. When an account is inactive for 12 or more consecutive months, SaaS Global Pte Ltd reserves the right to delete the account and all associated data after reasonable notice to the Customer.
When Personal Data is no longer needed, SaaS Global Pte Ltd will take reasonable steps to delete or anonymise it from active systems. Backups held within third-party platforms will be deleted in accordance with those platforms’ standard retention policies.
10. Data security
SaaS Global Pte Ltd implements security arrangements that are reasonable and appropriate for a small business processing the relevant type of Personal Data. These include:
- restricting access to Personal Data to authorised personnel only;
- using secure passwords and, where available, two-factor authentication;
- relying on reputable, industry-standard third-party infrastructure that maintains its own security controls;
- applying confidentiality obligations to personnel with access to Personal Data; and
- promptly notifying the Customer in the event of a confirmed Data Breach.
SaaS Global Pte Ltd does not warrant enterprise-grade security infrastructure but will take reasonable steps to protect Personal Data commensurate with the nature of the data and the risk involved.
11. Data Breach notification
Under the PDPA’s mandatory data breach notification obligations, if SaaS Global Pte Ltd becomes aware of a Data Breach that is likely to result in significant harm to affected individuals, it will:
- notify the Customer as soon as practicable, and in any event within 72 hours of becoming aware of the breach or of assessing that the breach is notifiable;
- provide reasonable details of the breach, including the nature of the data affected and the steps being taken to contain it;
- cooperate with the Customer to investigate and respond to the breach; and
- assist the Customer in meeting any notification obligations to the PDPC, the Office of the Australian Information Commissioner, or affected individuals where applicable.
The Customer, as Data Controller, retains primary responsibility for determining whether a Data Breach requires notification to a regulator or to affected individuals under applicable law.
Enquiries regarding data breaches should be directed to the SaaS Global Pte Ltd Data Protection Officer at eric@dcrm.io.
12. Cross-border data transfers and Sub-processors
SaaS Global Pte Ltd uses cloud-based infrastructure and Sub-processors located outside Singapore, including in the United States. Under section 26 of the PDPA, SaaS Global Pte Ltd will take reasonable steps to ensure that any overseas recipient of Personal Data provides a standard of protection comparable to that under the PDPA.
By engaging SaaS Global Pte Ltd, the Customer acknowledges and consents to cross-border transfers to the extent necessary for delivery of the Services.
| Sub-processor | Purpose | Location |
|---|---|---|
| Go High Level (GHL) | Underlying CRM and automation infrastructure on which the DCRM platform is built | USA |
| Google (Workspace, Analytics, Ads) | Email, document storage, website analytics, advertising campaign management | USA / Global |
| Meta (Facebook, Instagram) | Paid advertising, audience management | USA |
| OpenAI | AI-assisted content, conversation AI, and automation features | USA |
| Telecommunications carriers (including LeadConnector and Twilio) | SMS, MMS, and voice delivery for DCRM communications | Various |
| WordPress / WP Engine | Website hosting and content management for Practice Growth Studio | USA / Global |
| Stripe | Payment processing | USA / Global |
A full and current list of Sub-processors is available on request at eric@dcrm.io.
13. Return or destruction of data
Upon termination of the Services or written request by the Customer, SaaS Global Pte Ltd will take reasonable steps to return or securely delete the Customer’s Personal Data from its active systems within 30 days, unless retention is required by law.
Backups held within third-party platforms will be deleted in accordance with those platforms’ standard data retention schedules. The Customer is responsible for exporting any data it requires before termination of its account.
14. Audit and evidence
On reasonable written notice and no more than once in any 12-month period (except where a Data Breach has occurred or is reasonably suspected), the Customer may request:
- a written summary of SaaS Global’s information security practices, the categories of Personal Data processed on the Customer’s behalf, the Sub-processors involved, and any third-party certifications held;
- copies of relevant policies and procedures; and
- reasonable additional information necessary to verify SaaS Global’s compliance with this Agreement.
SaaS Global Pte Ltd will respond within a reasonable time, having regard to the proportionate nature of this Agreement and the small-business context. The Parties agree that audit assistance which involves disproportionate cost or that would compromise the confidentiality of other customers’ data may be limited or substituted with equivalent assurances.
SaaS Global Pte Ltd may rely on access logs, system metadata, communications records, platform telemetry, and other reasonable forms of evidence to investigate any suspected breach of this Agreement, including misuse of materials, unauthorised retention of Personal Data, unauthorised AI training activity, or anti-cloning breaches relating to Snapshots, automations, or campaign structures. On reasonable notice, the Customer must assist with any such investigation and, where breach is found, must certify the return, deletion, or destruction of affected materials.
15. Term and termination
15.1 Term
This Agreement applies for the duration of any active service engagement between SaaS Global Pte Ltd and the Customer, commencing on the date the Customer engages SaaS Global Pte Ltd for Services.
15.2 Termination for cause
Either party may terminate this Agreement by written notice if the other party commits a material breach that is not remedied within 30 calendar days of written notice specifying the breach.
15.3 Effect of termination
On termination, SaaS Global Pte Ltd will cease processing Personal Data and comply with clause 13. Provisions that by their nature survive termination, including confidentiality, audit and evidence rights, AI training prohibition, and liability, will continue to apply.
16. Liability
Each party is responsible for its own acts and omissions in relation to Personal Data. As a Data Intermediary under the PDPA, SaaS Global Pte Ltd’s obligations run to the Customer as Data Controller, not directly to individual data subjects.
SaaS Global Pte Ltd’s liability under this Agreement is limited to direct losses caused by its failure to comply with this Agreement or the PDPA, and is capped at the total fees paid by the Customer to SaaS Global Pte Ltd in the 12 months preceding the relevant event.
SaaS Global Pte Ltd is not liable for any loss caused by the Customer’s failure to obtain lawful consent for processing, the acts of Sub-processors or AI Providers operating within their own platforms, or events outside SaaS Global Pte Ltd’s reasonable control.
Nothing in this clause limits or excludes any right that cannot lawfully be limited or excluded under the Singapore Consumer Protection (Fair Trading) Act or, where the Customer is an Australian resident or business, the Australian Consumer Law.
17. Governing law, dispute resolution, and injunctive relief
This Agreement is governed by the laws of Singapore. The Parties submit to the non-exclusive jurisdiction of the courts of Singapore for any dispute arising from this Agreement.
The Parties will attempt to resolve any dispute in good faith through direct negotiation before initiating formal proceedings. If a dispute is not resolved within 20 business days of written notice, either party may refer the matter to mediation or commence proceedings in a court of competent jurisdiction.
Nothing in this clause prevents either party from seeking urgent injunctive, interlocutory, or other equitable relief from a court of competent jurisdiction at any time, in particular to protect Personal Data, confidential information, intellectual property rights, or to prevent unauthorised disclosure, retention, or use of materials, Snapshots, or platform configuration.
SaaS Global Pte Ltd acknowledges the role of the PDPC in receiving and investigating personal data protection complaints. Customers and individuals who are unsatisfied with how a data protection matter is handled may contact the PDPC at www.pdpc.gov.sg or, for Australian individuals, the Office of the Australian Information Commissioner at www.oaic.gov.au.
18. Data Protection Officer and contact
In accordance with the PDPA, SaaS Global Pte Ltd has appointed a Data Protection Officer (DPO). All data protection enquiries, access requests, and complaints should be directed to the DPO:
Data Protection Officer, SaaS Global Pte Ltd (UEN 202322132C)
2 Venture Drive #19-18 Vision Exchange, Singapore 608526
Email: eric@dcrm.io
This Agreement may be updated from time to time. Material updates will be notified to active customers with 30 days notice. Continued use of the Services after the notice period constitutes acceptance of the updated terms.
© SaaS Global Pte Ltd. All rights reserved. UEN 202322132C. Trading as DCRM and Practice Growth Studio.