neobiz Back to home →

Legal

Country
IndonesiaWorldwide
Language
EnglishBahasa Indonesia
Terms of ServicePrivacy PolicyData Processing AgreementAcceptable Use PolicyAI TermsMessaging PolicySubprocessors

Neobiz Data Processing Agreement (DPA) — Global

Applies to: merchants registered outside Indonesia.

Drafted to GDPR standard by design. GDPR/UK GDPR is the strictest regime among the target markets, so a GDPR-grade DPA also satisfies Singapore/Malaysia/Thailand PDPA, the Philippines Data Privacy Act, Vietnam's PDPD, Japan's APPI and the Australian Privacy Act. The transfer exhibit (§12) and the US service-provider section (§13) form part of this document rather than separate annexes.

Version: global-2026-07-1 · Forms part of the Terms of Service.


1. Definitions

  • "Controller", "Processor", "Data Subject", "Personal Data", "Processing", "Personal Data Breach", "Supervisory Authority" — as defined in Data Protection Law.
  • "Data Protection Law" — all privacy and data protection laws applicable to the processing under this DPA, including the EU General Data Protection Regulation (2016/679) ("GDPR"), the UK GDPR and Data Protection Act 2018, and the equivalent laws of the markets in which you operate.
  • "Member Data" — Personal Data about your customers/members processed by Neobiz on your behalf, as defined in the Terms.
  • "Subprocessor" — a processor engaged by Neobiz to process Member Data.
  • "Standard Contractual Clauses" / "SCCs" — the clauses approved by the European Commission (Decision 2021/914) and, for the UK, the ICO's International Data Transfer Addendum ("UK Addendum").

2. Roles and scope

2.1 Allocation. For Member Data, you are the Controller and Neobiz is the Processor. For Account Data, Neobiz is the Controller (see the Privacy Policy).

2.2 Scope of processing. Neobiz processes Member Data only to provide, secure and support the Service, and only on your documented instructions. The Terms, this DPA, and your configuration and use of the Service constitute your complete documented instructions.

2.3 The consequence of the allocation. As Controller, you determine the purposes of processing, decide who is contacted and through which channel, and bear responsibility for the lawful basis for that processing. Neobiz does not review, verify or approve your lawful basis. Where you import contacts or send campaigns, you are making the controller's decision.

2.4 Details of processing. Set out in Annex A.

2.5 Unlawful instruction. Neobiz will inform you if, in its opinion, an instruction infringes Data Protection Law, and may suspend that instruction until it is confirmed or amended.

2.6 No independent-controller use. Neobiz does not use Member Data for its own purposes, does not sell or share it, and does not use it to train AI models except as expressly permitted by the AI Terms and any setting you enable.

3. Your obligations as Controller

3.1 You warrant that you have a valid lawful basis for all Member Data you provide or instruct us to process, and that you have given Data Subjects the notices required by Data Protection Law.

3.2 You are responsible for the accuracy, quality and legality of Member Data and the means by which you acquired it.

3.3 You will not provide special-category, criminal-offence, financial-account, government identifier or health data except where the Service is designed for it, you have a lawful basis, and applicable law permits. See the Messaging Policy for categories prohibited from Messaging Channels entirely.

3.4 You will implement appropriate security for your own access to the Service, including operator account hygiene and access reviews.

3.5 You will use the member-facing privacy notice base we make available, retaining its required core clauses, or an equivalent notice that meets Data Protection Law.

4. Neobiz's obligations as Processor

Neobiz will:

4.1 process Member Data only on your documented instructions (§2.2);

4.2 ensure personnel authorised to process Member Data are bound by confidentiality;

4.3 implement the technical and organisational measures in Annex B;

4.4 respect the conditions in §7 for engaging Subprocessors;

4.5 assist you, taking into account the nature of processing, in responding to Data Subject requests (§6);

4.6 assist you with data protection impact assessments and prior consultations, taking into account the information available to it;

4.7 notify you of a Personal Data Breach per §8;

4.8 at your choice, delete or return Member Data after termination per §9; and

4.9 make available information reasonably necessary to demonstrate compliance and allow for audits per §10.

5. Security

5.1 Neobiz maintains the measures described in Annex B, appropriate to the risk, and will not materially reduce the overall level of security during the term.

5.2 Data location. Member Data is hosted in the Azure Indonesia Central region. Managed-AI model calls may egress to the United States (Azure East US 2) under provider agreements including zero-retention and no-training terms; such egress is logged. See the subprocessor list.

6. Data Subject rights

6.1 The Service provides features enabling you to access, correct, export, restrict and delete Member Data. Where those features are insufficient, Neobiz will provide reasonable assistance.

6.2 If Neobiz receives a request directly from one of your members, it will (unless legally required otherwise) refer the person to you and notify you promptly.

6.3 Neobiz will assist with objections to automated decision-making and profiling to the extent the Service performs it. Where the AI assistant acts autonomously, see the AI Terms.

7. Subprocessors

7.1 You provide general written authorisation for Neobiz to engage the Subprocessors listed at ../subprocessors.md, which include hosting, email, WhatsApp/SMS BSPs, AI providers and payment processors.

7.2 Neobiz imposes data-protection obligations on each Subprocessor substantially as protective as this DPA, and remains fully liable for their performance.

7.3 Neobiz will give at least thirty (30) days' notice of intended additions or replacements (by updating the list and/or in-product notice). You may object on reasonable data-protection grounds within that period; if the parties cannot resolve the objection, you may terminate the affected part of the Service without penalty for the unused prepaid term.

8. Personal Data Breach

8.1 Neobiz will notify you without undue delay and in any event within 24 hours after becoming aware of a Personal Data Breach affecting Member Data.

8.2 The notice will include the information reasonably available to help you meet your notification obligations: the nature of the breach, categories and approximate number of Data Subjects and records affected, likely consequences, and measures taken or proposed.

8.3 Neobiz will take reasonable steps to mitigate and remediate, and will keep you informed.

8.4 Notification is not an acknowledgement of fault or liability.

9. Term, deletion and return

9.1 This DPA runs for as long as Neobiz processes Member Data.

9.2 On termination, Neobiz will make Member Data available for export for thirty (30) days, then delete it within the period in the retention schedule, subject to (a) routine backup cycles expiring on their normal schedule and (b) any legal-hold or retention required by law.

9.3 Liability. Liability under this DPA is subject to the limitations in Terms §12, including the carve-out preserving your indemnification obligations. Consistent with §2.3, Neobiz's role is limited to processing on your instructions; Controller obligations and the consequences of breaching them rest with you.

10. Audit

10.1 Neobiz will make available the information necessary to demonstrate compliance with this DPA.

10.2 Audits are satisfied in the first instance by Neobiz providing its current third-party audit reports, penetration-test summaries and completed security questionnaires.

10.3 Where that is demonstrably insufficient, you may conduct an audit no more than once per year (unless required by a Supervisory Authority or following a Personal Data Breach), on reasonable prior written notice, during business hours, subject to confidentiality, at your cost, and not requiring disclosure that would compromise other merchants' data or Neobiz's security.

11. International transfers

11.1 Neobiz may transfer Member Data internationally only where a valid transfer mechanism under Data Protection Law applies.

11.2 EEA transfers. Where Member Data is transferred from the EEA to a country without an adequacy decision, the SCCs are incorporated by reference and completed per §12.

11.3 UK transfers. The UK Addendum applies, completed per §12.

11.4 Other markets. For transfers subject to other Data Protection Law, the parties will implement the transfer mechanism that law requires.

12. Transfer exhibit — SCCs and UK Addendum

Dormant unless an EEA or UK transfer occurs. Included here rather than as a separate annex.

12.1 Module. Module Two (Controller to Processor) applies, with you as data exporter and Neobiz as data importer.

12.2 Completion. Clause 7 (docking) does not apply; Clause 9 — Option 2, general written authorisation, with the notice period in §7.3; Clause 11 — the optional independent dispute-resolution body does not apply; Clause 17 — governed by the law of Ireland; Clause 18 — forum the courts of Ireland.

12.3 Annexes. SCC Annex I (parties, description of transfer) is Annex A; Annex II (technical and organisational measures) is Annex B; Annex III (subprocessors) is ../subprocessors.md.

12.4 UK Addendum. Tables 1–4 are completed by reference to the same annexes; the ICO's Approved Addendum applies with Table 4 completed as "neither party" may terminate under Section 19.

12.5 Precedence. In case of conflict between the SCCs/UK Addendum and this DPA, the SCCs/UK Addendum prevail.

13. United States — service-provider terms

Applies where US state privacy law governs. GDPR vocabulary does not map exactly onto the US "service provider / processor" concepts, so this section states them expressly.

13.1 Neobiz acts as a service provider (or processor, as those terms are used under applicable US state privacy law) with respect to Member Data.

13.2 Neobiz will not: (a) sell or share Member Data; (b) retain, use or disclose it for any purpose other than performing the Service, or outside the direct business relationship; (c) combine it with personal information from another source, except as permitted to perform the Service; or (d) retain, use or disclose it outside your documented instructions.

13.3 Neobiz certifies that it understands and will comply with these restrictions.

13.4 Neobiz will provide the same level of privacy protection required of you, notify you if it can no longer meet these obligations, and — on notice — allow you to take reasonable steps to stop and remediate unauthorised use.

14. General

14.1 This DPA is governed by the governing law of the Terms unless Data Protection Law requires otherwise.

14.2 In case of conflict between this DPA and the Terms regarding the processing of Member Data, this DPA controls.

14.3 If a provision is held invalid, the remainder continues in effect.


Annex A — Details of processing

(Also serves as SCC Annex I.)

Item Detail
Subject matter Provision of the Neobiz platform to the Controller
Duration The term of the Terms, plus the deletion window in §9.2
Nature and purpose Hosting, storage, retrieval, organisation, transmission and deletion of Member Data to operate booking/scheduling, ordering, loyalty, CRM, messaging campaigns, payments and AI-assisted features
Categories of Data Subjects The Controller's customers and members; recipients the Controller elects to message
Categories of Personal Data Identifiers (name, phone, email); communication content and history; booking, order and transaction records; loyalty balances and activity; consent records and provenance; device/push tokens; other data the Controller elects to store in member profiles or notes
Special categories Not intended. The Controller must not supply special-category data except as permitted under §3.3
Frequency Continuous, for the duration of the Terms
Recipients The Subprocessors at ../subprocessors.md
Retention Per the retention schedule and §9.2

Annex B — Security measures

(Also serves as SCC Annex II.)

Area Measure
Tenant isolation Per-TenantId scoping enforced at the data layer; control-plane and tenant databases segregated
Encryption In transit (TLS); at rest Azure Premium SSD managed disks with platform-managed encryption at rest, with OS-level disk encryption additionally enabled on the database host
Access control Role-based access; least privilege; unique operator accounts; multi-factor authentication available to all operator accounts (authenticator app + recovery codes); not currently enforced
Audit logging Operator actions logged, including consent and acceptance events
Segregation of duties Production access restricted to authorised personnel
Resilience Backups per the schedule; restore procedures tested quarterly
Vulnerability management Dependency scanning on each build; security patches reviewed and applied weekly, with critical advisories expedited
Personnel Confidentiality obligations; security and data-protection awareness training delivered as part of the SecOps programme, on onboarding and periodically thereafter
Subprocessor management Contractual flow-down of these obligations; list maintained publicly
Incident response Documented process with the notification clock in §8.1

Contact for data-protection matters: hello@neobiz.id · PT Neobiz Global Technology.

© 2026 PT Neobiz Global Technology