Parties and Purpose
Parties
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Klicktify Sdn Bhd (Company Registration No. 202601000123 (1456789-X)) ("Klicktify", "Processor") and each Merchant café operator that creates a Klicktify account ("Merchant", "Controller"). The Controller is the party that determines the purposes and means of processing personal data of its Members. The Processor is the party that processes that personal data on the Controller's instructions.
Purpose
This DPA sets out the obligations of each party with respect to the processing of Member personal data under Malaysia's Personal Data Protection Act 2010 (Act 709) ("PDPA"), including: the Processor acting only on documented instructions from the Controller; the Controller's obligations as an independent data controller; security obligations; sub-processor management; data subject rights assistance; breach notification; and return and deletion upon termination.
Precedence
In the event of a conflict between this DPA and the Terms of Service (/legal/terms), this DPA prevails with respect to personal data processing matters.
Roles of the Parties
Controller — Merchant
The Merchant acts as the data controller for all personal data relating to its Members processed through the Klicktify platform. This means the Merchant:
- Determines the purposes for which Members' personal data is collected and used.
- Determines the means of processing — what data is collected, how points are awarded, what rewards are offered.
- Bears primary responsibility for the lawfulness of the processing, including establishing a valid lawful basis (typically Member consent or contract performance) for each processing activity.
- Must issue its own privacy notice to Members describing its loyalty programme and how it uses their personal data.
- Is responsible for responding to data subject rights requests from its own Members, though Klicktify will assist as described in Section 7.
Processor — Klicktify
Klicktify processes Member personal data solely as a data processor acting on the Controller's instructions. Klicktify:
- Processes Member data only to the extent necessary to provide the loyalty platform service.
- Will not use Member data for any purpose other than providing the contracted service without the Controller's prior written authorisation.
- Will not transfer Member data to any third party except as authorised by the Controller or required by law.
- Will assist the Controller in fulfilling its obligations under the PDPA, as described in this DPA.
Scope of Processing
Subject Matter and Nature
The processing concerns personal data of Members who join the Merchant's loyalty programme, processed through Klicktify's QR check-in, points engine, tier management, and reward redemption system. The processing is carried out by automated means.
Categories of Personal Data
- Name — provided by the Member at registration.
- Email address — provided by the Member.
- Phone number — primary account identifier used for check-in.
- Birthday (optional) — provided by the Member to access birthday rewards.
- Points balance and tier status — calculated by the points engine.
- Check-in records — timestamped QR scans at the Merchant's venue.
- Reward redemption history — records of rewards claimed and redeemed.
- Device and technical data — IP address, browser type, device identifiers.
Purposes of Processing
Klicktify processes the above data solely for the following purposes on the Controller's behalf:
- Creating and maintaining the Member's loyalty account with the Controller.
- Authenticating the Member at check-in.
- Recording and calculating points based on the Controller's points rules.
- Managing tier progression.
- Processing reward redemptions.
- Sending transactional notifications (points earned, reward claimed).
- Providing the Controller with an analytics dashboard showing aggregate Member data.
- Security monitoring and fraud prevention.
Processing Instructions
Instructions
The Controller provides its processing instructions to Klicktify through: (a) the account registration and profile configuration settings it selects on the platform; (b) the points rules, tier thresholds, and reward catalogue it defines; and (c) any ad hoc written instructions communicated to dpo@klicktify.com. Klicktify will process Member data only in accordance with the Controller's instructions. If Klicktify believes an instruction violates the PDPA or other applicable law, it will notify the Controller immediately.
Sub-Processors
Authorised Sub-Processors
The Controller authorises Klicktify to engage the following sub-processors to process Member personal data:
| Sub-Processor | Service Provided | Data Processed | Location |
|---|---|---|---|
| Neon / Lakebase Postgres | Database hosting | All Member and Merchant data | Southeast Asia |
| Stripe | Payment processing (subscription billing) | Merchant billing data only (card tokens, billing email) | United States / Singapore |
| Resend (or equivalent) | Transactional email delivery | Member email addresses and message content | United States |
Sub-Processor Obligations
Klicktify ensures that each sub-processor is contractually bound to process personal data only on Klicktify's instructions and to implement appropriate technical and organisational security measures. The sub-processors are required to maintain at least an equivalent level of data protection as required by the PDPA.
New Sub-Processors
Klicktify will provide at least 30 days' written notice before engaging any new sub-processor. If the Controller has a reasonable objection to a new sub-processor, it may terminate its account in accordance with the cancellation provisions in the Terms of Service.
Security Obligations
Processor's Security Measures
Klicktify implements and maintains the following security measures:
- Encryption in transit: TLS 1.2+ for all data transmitted.
- Encryption at rest: AES-256 for database storage.
- Password hashing: bcrypt with cost factor ≥ 12.
- Access controls: IP allow-listing, least-privilege database roles.
- Tenant isolation: row-level security policies ensuring each Merchant's Member data is isolated from other Merchants' data.
- Separated authentication sessions: Merchant (NextAuth) and Member (member-auth) sessions are fully separated.
- Audit logging: access and activity logs maintained for security monitoring.
Controller's Security Obligations
The Controller is responsible for: (a) maintaining the security of its own Klicktify account credentials; (b) restricting access to its Klicktify dashboard to authorised staff only; (c) ensuring that its own systems and devices are not compromised; and (d) promptly reporting any suspected security incident to security@klicktify.com.
Data Subject Rights Assistance
Controller's Primary Obligation
As the data controller, the Merchant is primarily responsible for responding to data subject rights requests from its Members under the PDPA (access, correction, withdrawal of consent, limit processing). Klicktify will assist the Controller in fulfilling these obligations as described below.
Processor's Assistance
- Access requests: the Controller can access a Member's data through the Klicktify dashboard. For data not visible in the dashboard, the Controller may contact dpo@klicktify.com.
- Correction requests: Members can update most of their own profile data through the platform. For data that cannot be self-corrected, the Controller may contact dpo@klicktify.com.
- Deletion requests: when a Member requests deletion of their data, Klicktify will delete the Member's account data from its platform within 30 days, subject to any overriding legal retention obligations (e.g., billing records). The Controller is responsible for ensuring its own records comply with retention obligations.
- Withdrawal of consent: Members can withdraw consent through their account settings or by contacting the Merchant directly. Klicktify will process withdrawal notifications and update the Member's consent record accordingly.
Time for Assistance
Klicktify will use reasonable efforts to provide assistance within 14 business days of receiving a written request from the Controller. Complex requests may take longer.
Audit Rights
Controller's Right to Audit
The Controller may request an audit of Klicktify's data protection practices once per calendar year, at the Controller's expense, with reasonable advance written notice (at least 30 days) and during business hours. The audit will be conducted by an independent, mutually agreed-upon auditor under appropriate confidentiality obligations. Klicktify will provide reasonable cooperation and access to relevant records and personnel.
Alternative to Audit
Klicktify may provide the Controller with copies of its security certifications, audit reports, or a written summary of its security practices in lieu of an on-site audit, at Klicktify's discretion.
Breach Notification
Notification to Controller
Klicktify will notify the Controller without undue delay upon becoming aware of a personal data breach affecting the Controller's Member data. The notification will include: (a) a description of the nature of the breach; (b) the categories and approximate number of data subjects affected; (c) the likely consequences; and (d) the measures taken or proposed to address the breach.
Controller's Obligation to Notify Members
The Controller is responsible for assessing whether a breach notification to affected Members is required and for communicating with Members in accordance with its own PDPA obligations. Klicktify will provide the Controller with all information reasonably necessary to make this assessment.
Return and Deletion on Termination
Return of Data
Upon termination of the Controller's Klicktify account, the Controller may request a full export of its Member data in a commonly used, machine-readable format (CSV) within 30 days of the termination request. After the 30-day export window, data will be deleted in accordance with Klicktify's retention policy.
Deletion of Data
Following the export window (if any), Klicktify will delete all Member personal data associated with the Controller's account within 90 days, subject to any overriding legal, accounting, or regulatory retention obligations (e.g., billing records retained for 7 years under Malaysian tax law). Deleted data will be removed from all active systems and backups in accordance with Klicktify's data destruction policy.
Surviving Provisions
The provisions of this DPA relating to confidentiality, security obligations, audit rights, breach notification, and data subject assistance survive the termination of the Terms of Service and the Controller's account.
International Transfers
Transfers Within the Platform
Member personal data is primarily stored on Neon (Lakebase Postgres) with servers in Southeast Asia. Certain sub-processors (e.g., Stripe, email delivery providers) may process data in the United States or other jurisdictions. All international transfers are covered by standard contractual clauses or equivalent data protection commitments with the relevant sub-processor.
Governing Law
Jurisdiction
This DPA is governed by the laws of Malaysia. Any dispute arising from this DPA shall be subject to the dispute resolution provisions in the Terms of Service at /legal/terms.