PARROTSIGHT

Data Processing Agreement

Last updated: 12 August 2025

This Data Processing Agreement ("the DPA") forms part of the Terms of Service and applies where PARROTSIGHT processes personal data on behalf of a customer in its capacity as a data processor under the Personal Data Protection Act 2010 (Act 709) or other applicable data protection law. This page summarises the key processing commitments; the executed agreement, where applicable, governs the relationship in full.

Processor Obligations

PARROTSIGHT processes personal data only on the documented instructions of the customer, including with respect to transfers, retention and the categories of processing necessary to deliver the Services. We do not process customer data for our own purposes and we do not use customer data to train models.

We will ensure that personnel authorised to process customer data are subject to confidentiality obligations, and we will implement and maintain technical and organisational measures appropriate to the risk of the processing, including encryption, access controls and security monitoring.

Sub-processors

The customer provides general authorisation for PARROTSIGHT to engage sub-processors in the provision of the Services. A list of current sub-processors is maintained and made available to the customer, and we will notify the customer of intended additions or replacements.

Where we engage a sub-processor, we will impose contractual obligations that are no less protective than those set out in this DPA, and we will remain fully liable to the customer for the acts and omissions of our sub-processors.

Data Residency and Location

Customer data is processed in Malaysia or Singapore, depending on the region selected by the customer. Regional pinning ensures that customer data, including inference payloads, does not leave the selected region except where strictly necessary to route traffic or to address a support request authorised by the customer.

Where a customer requires processing to remain in a specific jurisdiction for regulatory reasons, the customer should select the appropriate region in the console, and we will maintain that choice for the duration of the service term.

Incident Notification

PARROTSIGHT will notify the customer of any confirmed security incident involving customer data without undue delay and in any event within seventy-two hours of becoming aware of the incident. Notifications will include a description of the incident, the categories and approximate volume of data affected, and the measures taken or proposed to mitigate the impact.

We will cooperate with the customer to help meet its own notification obligations to supervisory authorities and affected data subjects, and will provide reasonably requested information to the extent available.

Deletion and Return of Data

Upon termination of the Services, customer data will be deleted from live systems in accordance with the customer's retention setting or, at the customer's election and where technically feasible, returned to the customer in a standard format before deletion.

Where deletion cannot be completed immediately due to backup rotation or legal hold, we will isolate the data from further processing and delete it as soon as operationally possible, and we will certify deletion upon the customer's reasonable request.

Audit Rights and Compliance

PARROTSIGHT will make available to the customer, upon reasonable request and no more than once per calendar year, information sufficient to demonstrate compliance with this DPA, together with summaries of relevant independent security assessments and certifications.

Where further assurance is required, the customer or an independent auditor subject to confidentiality obligations may, at the customer's expense and with reasonable notice, conduct an audit of our processing environment. Any such audit will be limited in scope, will not disrupt operations and will not compromise the confidentiality of other customers.