Data Processing Agreement — Singapore
The terms under which Cerrax processes your customers' personal data as your data intermediary.
This agreement forms part of the Terms of Service and applies whenever Cerrax processes personal data on your behalf. It uses the meanings given in the Personal Data Protection Act 2012 (the "PDPA") and the Personal Data Protection Regulations 2021. It is the written contract under which we act as your data intermediary, and the legally enforceable obligations on which you transfer personal data to us outside Singapore. Where this agreement and the Terms conflict on data protection, this agreement governs.
1. Which of us is which
You are the organisation responsible for your customers’ personal data. We are your data intermediary for it: we process it on your behalf, on your instructions, and use it for our own purposes only in the ways section 3 lists. That covers personal data about your customers, the people who enquire with you, your other contacts, and your staff and crew in their working role. For your own account data — your name, your login, your firm’s settings and billing — we are an organisation in our own right, and our Privacy Policy covers that.
One exception, which is your customer's choice, not yours. When your customer sends a video or photographs of their home, they may tick a separate box allowing Cerrax to keep them to train software that recognises furniture and rooms. For that use alone, Cerrax is not your data intermediary: it is an organisation responsible for that data in its own right, on the customer's consent, and our Privacy Policy (§3) covers it: identifying details are blurred before it is ever used for training, nothing uses it today, and the customer can withdraw at any time, after which the video and photographs are deleted under the ordinary ninety-day rule. Everything else in this agreement applies to them as it does to the rest of your customers’ data.
2. What we process, and for how long
- Purpose: running your removals business on Cerrax — receiving and organising your enquiries, keeping your customer records (contacts), pricing, quoting and following up quotes, booking and running jobs, and sending the messages you set up — on your instructions.
- What we do with it: collecting, storing, organising, reading (including with AI, to suggest details for a person at your firm to confirm), pricing, sending messages on your behalf, de-identifying (section 9), exporting and deleting.
- Duration: for as long as your account is open, and afterwards only as section 8 allows.
- Type of personal data: names, addresses, contact details, move dates, and details of the property and its contents that you or your customer enter; where your crew use Cerrax on the day of the move, photographs of the property, its access and any damage found, together with the name and drawn signature of whoever signs the inventory off; and, where you invite it and your customer chooses to send one, a video of their home. Where you use them: your contacts (names, email addresses, phone numbers, company, preferred language, addresses used, the choices they gave you about your messages and when, where they came from, and your notes); enquiries, including the text of enquiry emails sent to your Cerrax lead address; the messages you send through Cerrax and whether they were delivered; follow-up tasks and their notes; whether a payment has been made (never card details); and reviews and ratings your customers give you.
- People it is about: people who enquire with you (whether or not they become customers); your customers; the people at the properties you move between; other people you keep as contacts; people named in notes, messages, photographs or video; and your staff and crew in their working role.
We do not ask for and do not want NRIC numbers or other national identification numbers, or health, financial-account or similar sensitive information. Please do not enter them into free-text fields. If it arrives anyway — in an enquiry or a note — we hold it only as part of that record, never use it for pricing or learning, and keep it out of section 9.
A signature captured against an inventory is held as evidence that your customer agreed what was moved and in what condition. Nothing measures, compares or matches it, and nothing recognises a face in a photograph or video (where faces are blurred, software finds them only to blur them and keeps no measurement of them) — so it is never used to identify anyone. Collecting signatures is optional: if you would rather your crew did not, simply do not use it.
Your part. You are responsible for having your customers’ consent, or another basis the PDPA allows, to collect their personal data and to have it processed by us as described here — including in the United Kingdom — and for telling them the purposes for which it is used.
3. We act on your instructions
We process your customers’ personal data only on your documented instructions — which include your use of the product and this agreement — unless the law requires otherwise, in which case we will tell you first unless the law forbids that. If we think an instruction breaches the PDPA, we will tell you promptly and may pause carrying it out until you confirm or change it. We do not sell your customers’ personal data, and we do not use or disclose it for any purpose other than the one in section 2 — except the de-identified use in section 9.
Our own uses, and only these: the de-identification in section 9; keeping descriptions of a job's items and rooms, with any email address, phone number or postal code removed, for 30 days to improve how Cerrax recognises items (we keep no other text sent to our AI sub-processor); keeping the service secure and preventing abuse; and meeting our own legal obligations.
Your instructions include these, when you use the features concerned: receiving emails sent to your Cerrax lead address and reading them — using our AI sub-processor where an email has no labelled layout — to suggest details you confirm; keeping contact records and the choices your customers make about your messages; and sending the messages you switch on, in your name, identifying you and with your postal address, honouring every request to stop at once and for all of those messages from you to that person. We keep a record of each choice and each stop, and a scrambled record of a stop for as long as it must be honoured.
Also on your instructions, when you use the features concerned: sending your customers the messages about a job that you set up (by WhatsApp where you have connected it, otherwise by email), including a review request and the private rating and comment a customer may give you; creating links you choose to share — a job sheet for your crew, or evidence (the customer's name, photographs, video and signatures, never their contact details) for your insurer, broker or claims handler; publishing your jobs to calendar subscriptions you create; and keeping follow-up tasks and their notes.
4. Confidentiality
Everyone we allow to access your customers’ personal data is bound by a written duty of confidentiality that continues after they leave, and only sees what their role requires. Access inside the product is governed by roles and individual permissions, checked on the server for every request.
5. Security
We make reasonable security arrangements to protect the personal data in our possession or under our control against unauthorised access, collection, use, disclosure, copying, modification or disposal, and against the loss of any storage medium on which it is held. They are described in our security overview — encryption in transit and at rest, role-based access control, an audit trail of consequential actions, point-in-time recovery and separate daily backups. That page states plainly what we do not yet have.
We will not materially reduce the overall level of security described there while this agreement lasts.
6. Sub-processors
You authorise us to use sub-processors. The current list is in section 8 of our Privacy Policy and is kept current there. We bind each of them by written contract to obligations no less protective than these, and we remain fully responsible to you for their performance. We will email your account owner at least 30 days before a new sub-processor starts handling your customers’ personal data (sooner only in an emergency, such as a provider failing, and then we tell you as soon as we can). You may object within that time on reasonable data protection grounds; if we cannot resolve it, you may end the affected service or your subscription and we will refund any fees paid in advance for the unused period. Services you connect yourself under your own account with them — your own Stripe, WhatsApp Business or Xero account — act on your instruction under your agreement with them, and are not our sub-processors.
If you subscribe your own calendar to your Cerrax calendar link, your calendar provider fetches your jobs under your own agreement with it; it is not our sub-processor.
7. Helping you meet your own obligations
Taking into account the nature of the processing, we will help you respond to requests from individuals — for access, correction, or withdrawal of consent — and with your security and breach-notification duties. If an individual contacts us directly about data we hold for you, we will refer them to you rather than answer for you. If we have reason to believe a data breach has occurred affecting your customers’ data, we will tell you without undue delay, and in any event within 48 hours, with the information you need to assess it and, if it is notifiable, to notify the Personal Data Protection Commission within your 3 calendar days and the people affected.
You can find, export, correct and delete a contact or a job yourself in the product; for anything the product cannot do, we will act within 10 working days of your written instruction.
8. Deletion and return
Your instruction on how long we keep it. Unless you tell us otherwise, you instruct us to keep each job record — the quote, its booking and outcome, the crew's sheets and the photographs attached to them — for six years after the move (or after the quote, if the job did not go ahead), or for longer while a claim or dispute about that job is open, and then to delete it. A video, and any photographs your customer sends with it, are deleted 90 days after the job's last date unless your customer has separately agreed to their longer use. You can change this instruction by telling us.
Beyond that, we keep your customers’ personal data only for as long as it serves the purpose in section 2 or a legal or business purpose, and then cease to retain it or remove the means by which it can be associated with anyone. At the end of the agreement you can export your data for 30 days. We then delete your customers’ personal data within 90 days, and it leaves our backups as they expire (within 98 days), except where the law requires us to keep it or you ask us to keep specific records, such as evidence in an open claim. Committed pricing records are never silently altered — personal identifiers within them are removed, which is how deletion is honoured without falsifying a record of what was quoted. Section 9 records are not your customers’ personal data and are not affected.
Unless you tell us otherwise, you also instruct us to delete: an enquiry that was never priced or sent, 12 months after its last activity; a quote that was sent but never accepted, 24 months after it was sent; and a contact record 12 months after the last job record linked to it is deleted (or 12 months after it was made, if it was never linked to a job). A record of a person's consent is kept while their contact record is kept and for six years after; a scrambled record of a request to stop messages is kept for as long as it must be honoured.
Two records keep their own periods: email delivery records (recipient, subject and whether it was delivered), 90 days; and the audit trail of actions in your account, up to six years after your account closes, with a customer's details removed when that customer is erased.
9. De-identified job data
(a) You instruct us to make de-identified records from the jobs we hold for you. (b) A de-identified record holds only the shape and economics of a job — volume, a distance band, access features, crew, vans, hours, price and cost, whether the quote was won and why not, the month of the move, and an area no finer than the first two digits of a postal code — and never a name, contact detail, full address or postal code, map position, free text, photograph, video, signature, your firm's identity, or any reference that links it back to the job. (c) We treat a record as de-identified only when no one could reasonably identify a person from it, taking account of other information we or you hold. Data that can be linked back — for example by a job reference, or while we still hold the original job — is not de-identified and stays under this agreement until the original is deleted. (d) We will not try to re-identify anyone from these records, and require anyone we share them with to make the same commitment. (e) Once a record meets this standard it is not your customers’ personal data; it is ours, and we may keep and use it to improve and provide Cerrax, including after the underlying records are deleted and after this agreement ends. (f) We never show another firm, or anyone else, your individual prices or anything that identifies your firm.
10. Learning across firms
We use de-identified records under section 9, and statistics made from them, from across all firms using Cerrax, in every country, to improve the pricing engine for everyone, including you. This is stated here rather than assumed, because it is how the product gets better and we would rather you knew than found out.
11. Your numbers stay yours
Your rates, your margins, your customers and your prices are never visible to another firm, and never shown to the people you are quoting. The learning in section 10 runs on aggregated, de-identified signal — not on access to any one firm’s data by anybody else.
12. Audit
We will make available the information you reasonably need to show we are meeting these obligations — first by written answers and our security documentation — and will allow and contribute to a reasonable assessment by you or an independent assessor you appoint where those are not enough or a regulator requires it: at your cost, on 30 days' notice, under confidentiality, without access to other firms' data, and no more than once a year unless a regulator or a breach requires otherwise.
13. Transfers outside Singapore
We hold your customers’ personal data in the United Kingdom, in London, and you authorise that. The sub-processors named in section 8 of our Privacy Policy may also process it in the United States — the AI provider is the main case today — and, for mapping and for delivering the pages your customers open, on those providers’ global networks; you authorise transfers there. Wherever it is processed, we will protect the personal data transferred to a standard at least comparable to the protection under the PDPA, and this obligation is legally enforceable against us by you. We are also bound in the United Kingdom by the UK GDPR and the Data Protection Act 2018, and we bind each sub-processor outside Singapore by written contract to a comparable standard. Where your data is stored on any given day is a question you can ask us at any time, and we will answer it for the day you ask.
Liability. Section 11 of the Terms of Service (limitation of liability) applies to this agreement.
14. Contact
Data protection questions, individuals’ requests and breach notifications: hello@cerrax.io.
15. PDPA terms, in one place
For your own records, this agreement gives you the terms the PDPA expects of a contract with a data intermediary and of a transfer outside Singapore: the purpose, the type of personal data and the duration (section 2); processing only on your behalf and instructions (section 3); confidentiality (section 4); the Protection Obligation — reasonable security arrangements (section 5); sub-processors bound by written contract (section 6); breach notification to you without undue delay, and help with individuals’ requests (section 7); the Retention Limitation Obligation, and deletion or return at the end (section 8); de-identified data (section 9); information and assessments to show compliance (section 12); and a comparable standard of protection for data transferred out of Singapore, with the countries it goes to (section 13). If the PDPA requires a term this agreement does not contain, that term is treated as included, to the extent the law requires it.