Neobiz Data Processing Agreement (DPA) — Global
Applies to: merchants registered outside Indonesia.
Drafted to GDPR standard by design. GDPR/UK GDPR is the strictest regime among the target markets, so a GDPR-grade DPA also satisfies Singapore/Malaysia/Thailand PDPA, the Philippines Data Privacy Act, Vietnam's PDPD, Japan's APPI and the Australian Privacy Act. The transfer exhibit (§12) and the US service-provider section (§13) form part of this document rather than separate annexes.
Version: global-2026-07-1 · Forms part of the
Terms of Service.
1. Definitions
- "Controller", "Processor", "Data Subject", "Personal Data", "Processing", "Personal Data Breach", "Supervisory Authority" — as defined in Data Protection Law.
- "Data Protection Law" — all privacy and data protection laws applicable to the processing under this DPA, including the EU General Data Protection Regulation (2016/679) ("GDPR"), the UK GDPR and Data Protection Act 2018, and the equivalent laws of the markets in which you operate.
- "Member Data" — Personal Data about your customers/members processed by Neobiz on your behalf, as defined in the Terms.
- "Subprocessor" — a processor engaged by Neobiz to process Member Data.
- "Standard Contractual Clauses" / "SCCs" — the clauses approved by the European Commission (Decision 2021/914) and, for the UK, the ICO's International Data Transfer Addendum ("UK Addendum").
2. Roles and scope
2.1 Allocation. For Member Data, you are the Controller and Neobiz is the Processor. For Account Data, Neobiz is the Controller (see the Privacy Policy).
2.2 Scope of processing. Neobiz processes Member Data only to provide, secure and support the Service, and only on your documented instructions. The Terms, this DPA, and your configuration and use of the Service constitute your complete documented instructions.
2.3 The consequence of the allocation. As Controller, you determine the purposes of processing, decide who is contacted and through which channel, and bear responsibility for the lawful basis for that processing. Neobiz does not review, verify or approve your lawful basis. Where you import contacts or send campaigns, you are making the controller's decision.
2.4 Details of processing. Set out in Annex A.
2.5 Unlawful instruction. Neobiz will inform you if, in its opinion, an instruction infringes Data Protection Law, and may suspend that instruction until it is confirmed or amended.
2.6 No independent-controller use. Neobiz does not use Member Data for its own purposes, does not sell or share it, and does not use it to train AI models except as expressly permitted by the AI Terms and any setting you enable.
3. Your obligations as Controller
3.1 You warrant that you have a valid lawful basis for all Member Data you provide or instruct us to process, and that you have given Data Subjects the notices required by Data Protection Law.
3.2 You are responsible for the accuracy, quality and legality of Member Data and the means by which you acquired it.
3.3 You will not provide special-category, criminal-offence, financial-account, government identifier or health data except where the Service is designed for it, you have a lawful basis, and applicable law permits. See the Messaging Policy for categories prohibited from Messaging Channels entirely.
3.4 You will implement appropriate security for your own access to the Service, including operator account hygiene and access reviews.
3.5 You will use the member-facing privacy notice base we make available, retaining its required core clauses, or an equivalent notice that meets Data Protection Law.
4. Neobiz's obligations as Processor
Neobiz will:
4.1 process Member Data only on your documented instructions (§2.2);
4.2 ensure personnel authorised to process Member Data are bound by confidentiality;
4.3 implement the technical and organisational measures in Annex B;
4.4 respect the conditions in §7 for engaging Subprocessors;
4.5 assist you, taking into account the nature of processing, in responding to Data Subject requests (§6);
4.6 assist you with data protection impact assessments and prior consultations, taking into account the information available to it;
4.7 notify you of a Personal Data Breach per §8;
4.8 at your choice, delete or return Member Data after termination per §9; and
4.9 make available information reasonably necessary to demonstrate compliance and allow for audits per §10.
5. Security
5.1 Neobiz maintains the measures described in Annex B, appropriate to the risk, and will not materially reduce the overall level of security during the term.
5.2 Data location. Member Data is hosted in the Azure Indonesia Central region. Managed-AI model calls may egress to the United States (Azure East US 2) under provider agreements including zero-retention and no-training terms; such egress is logged. See the subprocessor list.
6. Data Subject rights
6.1 The Service provides features enabling you to access, correct, export, restrict and delete Member Data. Where those features are insufficient, Neobiz will provide reasonable assistance.
6.2 If Neobiz receives a request directly from one of your members, it will (unless legally required otherwise) refer the person to you and notify you promptly.
6.3 Neobiz will assist with objections to automated decision-making and profiling to the extent the Service performs it. Where the AI assistant acts autonomously, see the AI Terms.
7. Subprocessors
7.1 You provide general written authorisation for Neobiz to engage the Subprocessors listed
at ../subprocessors.md, which include hosting, email, WhatsApp/SMS
BSPs, AI providers and payment processors.
7.2 Neobiz imposes data-protection obligations on each Subprocessor substantially as protective as this DPA, and remains fully liable for their performance.
7.3 Neobiz will give at least thirty (30) days' notice of intended additions or replacements (by updating the list and/or in-product notice). You may object on reasonable data-protection grounds within that period; if the parties cannot resolve the objection, you may terminate the affected part of the Service without penalty for the unused prepaid term.
8. Personal Data Breach
8.1 Neobiz will notify you without undue delay and in any event within 24 hours after becoming aware of a Personal Data Breach affecting Member Data.
8.2 The notice will include the information reasonably available to help you meet your notification obligations: the nature of the breach, categories and approximate number of Data Subjects and records affected, likely consequences, and measures taken or proposed.
8.3 Neobiz will take reasonable steps to mitigate and remediate, and will keep you informed.
8.4 Notification is not an acknowledgement of fault or liability.
9. Term, deletion and return
9.1 This DPA runs for as long as Neobiz processes Member Data.
9.2 On termination, Neobiz will make Member Data available for export for thirty (30) days, then delete it within the period in the retention schedule, subject to (a) routine backup cycles expiring on their normal schedule and (b) any legal-hold or retention required by law.
9.3 Liability. Liability under this DPA is subject to the limitations in Terms §12, including the carve-out preserving your indemnification obligations. Consistent with §2.3, Neobiz's role is limited to processing on your instructions; Controller obligations and the consequences of breaching them rest with you.
10. Audit
10.1 Neobiz will make available the information necessary to demonstrate compliance with this DPA.
10.2 Audits are satisfied in the first instance by Neobiz providing its current third-party audit reports, penetration-test summaries and completed security questionnaires.
10.3 Where that is demonstrably insufficient, you may conduct an audit no more than once per year (unless required by a Supervisory Authority or following a Personal Data Breach), on reasonable prior written notice, during business hours, subject to confidentiality, at your cost, and not requiring disclosure that would compromise other merchants' data or Neobiz's security.
11. International transfers
11.1 Neobiz may transfer Member Data internationally only where a valid transfer mechanism under Data Protection Law applies.
11.2 EEA transfers. Where Member Data is transferred from the EEA to a country without an adequacy decision, the SCCs are incorporated by reference and completed per §12.
11.3 UK transfers. The UK Addendum applies, completed per §12.
11.4 Other markets. For transfers subject to other Data Protection Law, the parties will implement the transfer mechanism that law requires.
12. Transfer exhibit — SCCs and UK Addendum
Dormant unless an EEA or UK transfer occurs. Included here rather than as a separate annex.
12.1 Module. Module Two (Controller to Processor) applies, with you as data exporter and Neobiz as data importer.
12.2 Completion. Clause 7 (docking) does not apply; Clause 9 — Option 2, general written authorisation, with the notice period in §7.3; Clause 11 — the optional independent dispute-resolution body does not apply; Clause 17 — governed by the law of Ireland; Clause 18 — forum the courts of Ireland.
12.3 Annexes. SCC Annex I (parties, description of transfer) is
Annex A; Annex II (technical and organisational measures) is
Annex B; Annex III (subprocessors) is
../subprocessors.md.
12.4 UK Addendum. Tables 1–4 are completed by reference to the same annexes; the ICO's Approved Addendum applies with Table 4 completed as "neither party" may terminate under Section 19.
12.5 Precedence. In case of conflict between the SCCs/UK Addendum and this DPA, the SCCs/UK Addendum prevail.
13. United States — service-provider terms
Applies where US state privacy law governs. GDPR vocabulary does not map exactly onto the US "service provider / processor" concepts, so this section states them expressly.
13.1 Neobiz acts as a service provider (or processor, as those terms are used under applicable US state privacy law) with respect to Member Data.
13.2 Neobiz will not: (a) sell or share Member Data; (b) retain, use or disclose it for any purpose other than performing the Service, or outside the direct business relationship; (c) combine it with personal information from another source, except as permitted to perform the Service; or (d) retain, use or disclose it outside your documented instructions.
13.3 Neobiz certifies that it understands and will comply with these restrictions.
13.4 Neobiz will provide the same level of privacy protection required of you, notify you if it can no longer meet these obligations, and — on notice — allow you to take reasonable steps to stop and remediate unauthorised use.
14. General
14.1 This DPA is governed by the governing law of the Terms unless Data Protection Law requires otherwise.
14.2 In case of conflict between this DPA and the Terms regarding the processing of Member Data, this DPA controls.
14.3 If a provision is held invalid, the remainder continues in effect.
Annex A — Details of processing
(Also serves as SCC Annex I.)
| Item | Detail |
|---|---|
| Subject matter | Provision of the Neobiz platform to the Controller |
| Duration | The term of the Terms, plus the deletion window in §9.2 |
| Nature and purpose | Hosting, storage, retrieval, organisation, transmission and deletion of Member Data to operate booking/scheduling, ordering, loyalty, CRM, messaging campaigns, payments and AI-assisted features |
| Categories of Data Subjects | The Controller's customers and members; recipients the Controller elects to message |
| Categories of Personal Data | Identifiers (name, phone, email); communication content and history; booking, order and transaction records; loyalty balances and activity; consent records and provenance; device/push tokens; other data the Controller elects to store in member profiles or notes |
| Special categories | Not intended. The Controller must not supply special-category data except as permitted under §3.3 |
| Frequency | Continuous, for the duration of the Terms |
| Recipients | The Subprocessors at ../subprocessors.md |
| Retention | Per the retention schedule and §9.2 |
Annex B — Security measures
(Also serves as SCC Annex II.)
| Area | Measure |
|---|---|
| Tenant isolation | Per-TenantId scoping enforced at the data layer; control-plane and tenant databases segregated |
| Encryption | In transit (TLS); at rest Azure Premium SSD managed disks with platform-managed encryption at rest, with OS-level disk encryption additionally enabled on the database host |
| Access control | Role-based access; least privilege; unique operator accounts; multi-factor authentication available to all operator accounts (authenticator app + recovery codes); not currently enforced |
| Audit logging | Operator actions logged, including consent and acceptance events |
| Segregation of duties | Production access restricted to authorised personnel |
| Resilience | Backups per the schedule; restore procedures tested quarterly |
| Vulnerability management | Dependency scanning on each build; security patches reviewed and applied weekly, with critical advisories expedited |
| Personnel | Confidentiality obligations; security and data-protection awareness training delivered as part of the SecOps programme, on onboarding and periodically thereafter |
| Subprocessor management | Contractual flow-down of these obligations; list maintained publicly |
| Incident response | Documented process with the notification clock in §8.1 |
Contact for data-protection matters: hello@neobiz.id · PT Neobiz Global Technology.
