NefinityChat

Data Processing Addendum

Effective 30 September 2026

This Data Processing Addendum ("DPA") forms part of the Terms of Service between FUTURE CLOUD TECH ("Processor", "we") and the Customer ("Controller", "you"). It applies when we process personal data contained in Customer Data on your behalf.

1. Roles and instructions

You are the controller of personal data in your workspace; we are your processor. We process it only to provide the Service, according to your documented instructions — the Terms, this DPA and your use of the Service's settings — unless the law requires otherwise, in which case we will tell you if the law allows.

2. Details of processing

3. Our obligations

We will: make sure people authorised to process the data are bound by confidentiality; implement the security measures in section 6; assist you, taking into account the nature of the processing, with data subject requests, security, breach notifications and data protection impact assessments; and make available information reasonably needed to show compliance with this DPA.

4. Sub-processors

You authorise us to use the sub-processors listed in our Privacy Policy. We impose data protection obligations on them at least as protective as this DPA and remain responsible for their performance. We will give notice of new sub-processors by updating that list; you may object on reasonable data protection grounds, and if we cannot address the objection you may end the affected Service.

5. International transfers

Personal data may be processed in countries other than yours. Where the law requires it, we rely on appropriate safeguards for such transfers.

6. Security measures

Encryption in transit; hashed passwords and optional two-step verification for team members; limits on repeated sign-in attempts; logical separation between customers' workspaces, covered by automated tests; restricted, audited staff access, including logged sign-ins by platform administrators; automatic deletion according to your retention setting; and reliance on the certified security programmes of our infrastructure providers.

7. Personal data breaches

We will notify you without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting your data, with the information reasonably available (what happened, the data and people affected, likely consequences and the measures taken) so you can meet your own notification duties, including to the Personal Data Protection Commissioner of Malaysia. We will update you as more information becomes available and take reasonable steps to contain the breach.

8. Deletion and return

You can delete conversations at any time and set how long they are kept. When your account ends, we delete Customer Data within 90 days unless the law requires us to keep it; within 30 days of termination you may ask us to help you export it.

9. Audits

On reasonable written request, no more than once a year, we will answer security questionnaires and provide available documentation. Any on-site audit requires prior agreement on scope, timing and costs.

10. Precedence

If this DPA conflicts with the Terms regarding personal data, this DPA applies.

Contact: support@nefinitychat.com