On this page
- 1. Scope and Incorporation
- 2. Definitions and Roles
- 3. Customer Instructions and Processing
- 4. Confidentiality and Customer Separation
- 5. Security
- 6. Subprocessors
- 7. Data Subject Requests
- 8. Personal Data Breaches
- 9. Compliance Assistance
- 10. International Transfers
- 11. Return and Deletion
- 12. Compliance Information and Audit
- 13. Liability and Order of Precedence
- 14. Duration and Termination
- Schedule 1 — Processing Details
- Schedule 2 — High-Level Security Measures
- Schedule 3 — Subprocessor Information
1. Scope and Incorporation
This Data Processing Addendum (DPA) forms part of the Antbuildz AI Terms of Service or other agreement between Antbuildz Pte. Ltd. (Antbuildz) and Customer for the Services (the Agreement). It applies when Antbuildz processes Customer Personal Data on Customer’s behalf.
Capitalised terms not defined here have the meanings in the Agreement. Applicable Data Protection Law means laws applicable to the processing, including the Singapore Personal Data Protection Act 2012 where relevant.
2. Definitions and Roles
Customer Personal Data means personal data contained in Customer Content that Antbuildz processes on Customer’s behalf. Controller includes an organisation that determines purposes and means; Processor includes a data intermediary that processes for another organisation. Subprocessor means a third party appointed by Antbuildz to process Customer Personal Data.
Customer acts as controller or responsible organisation and Antbuildz acts as processor or data intermediary, except where either party processes personal data for its own independent purposes. Customer is responsible for lawful instructions, notices, consents and legal bases.
3. Customer Instructions and Processing
Antbuildz will process Customer Personal Data only on documented instructions from Customer, including the Agreement, configured features, authorised user actions and written instructions consistent with the Services, unless law requires otherwise. Antbuildz will notify Customer if it believes an instruction infringes Applicable Data Protection Law and may suspend the affected processing while the parties address it.
Antbuildz will process Customer Personal Data for the nature, purposes, duration and categories described in Schedule 1 and as otherwise documented in an Order Form.
4. Confidentiality and Customer Separation
Antbuildz will ensure authorised personnel are bound by confidentiality duties and receive access only where reasonably required. Conversation access must be limited to customer-requested support or troubleshooting, security and abuse investigations, legal duties, platform protection or exceptional operational requirements.
Antbuildz will maintain appropriate logical separation and access controls for private Customer knowledge. It will not intentionally disclose it to unrelated Customers, train another Customer’s Agent with it, or use it to train shared Antbuildz models for unrelated Customers. These obligations permit necessary processing by contracted providers under this DPA; they do not assert that technical administrator access is impossible.
5. Security
Taking into account the nature of processing and reasonably available measures, Antbuildz will maintain commercially reasonable administrative, organisational and technical measures designed to protect Customer Personal Data. The current high-level measures are described in Schedule 2. Customer acknowledges that security responsibilities are shared and will secure its accounts, users, endpoints, integrations and instructions.
6. Subprocessors
Customer generally authorises necessary Subprocessors, including AI, cloud, database, hosting, communication, payment infrastructure, analytics, security and integration providers when processing Customer Personal Data. Antbuildz will impose written data-protection obligations materially consistent with this DPA and remains responsible for their performance as required by law and the Agreement.
A current description of material Subprocessors is available on reasonable written request to help@antbuildz.ai. Antbuildz will inform Customer of intended material additions or replacements in advance, allowing a reasonable opportunity to object on data-protection grounds. The parties will seek a reasonable alternative; if none is available, either may end the affected processing without restricting mandatory remedies. Where applicable law requires specific transfer terms or further authorisation, those must be put in place before the affected processing.
7. Data Subject Requests
Taking into account the nature of processing, Antbuildz will provide reasonable assistance for Customer to respond to requests by individuals to exercise applicable rights. If Antbuildz receives a request relating to Customer Personal Data, it will refer the requester to Customer and will not respond substantively unless authorised or legally required.
8. Personal Data Breaches
Antbuildz will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, including where it has credible grounds to believe a breach has occurred. It will not delay notice solely to complete its investigation. Notice will describe reasonably available information about the nature, likely effects and response, with further updates as information becomes available.
Antbuildz will take reasonable containment and remediation steps and assist Customer with required notifications. Customer determines its own regulator and individual notification duties; Antbuildz remains responsible for duties independently applicable to it. Notice is not an admission of liability.
9. Compliance Assistance
Taking into account the nature of processing and information available, Antbuildz will provide reasonable assistance with Customer’s security, breach, consultation and data-protection impact assessment obligations. Additional assistance beyond standard Service functionality may be subject to reasonable fees.
10. International Transfers
Antbuildz may process Customer Personal Data in countries where it or its Subprocessors operate. Antbuildz will use contractual or other legally recognised safeguards required by Applicable Data Protection Law. For transfers governed by the Singapore PDPA, Antbuildz will use measures intended to provide a standard of protection comparable to that under the PDPA.
11. Return and Deletion
At the end of processing, Antbuildz will, at Customer’s choice, return or delete Customer Personal Data within a reasonable period, except where law requires retention. Customer should request export before access ends; contact help@antbuildz.ai to arrange supported formats and timing. Backup copies may remain temporarily until deleted through protected lifecycle processes and must not be used for unrelated purposes.
Records Antbuildz lawfully keeps for its own billing, legal, security or dispute purposes are governed by the Privacy Policy, not an indefinite right to retain all Customer Content.
12. Compliance Information and Audit
Antbuildz will provide information reasonably needed to demonstrate compliance. Begin with available documentation, questionnaires or independent reports. If insufficient, Customer may request a proportionate audit on reasonable notice, during business hours, under confidentiality and safeguards for other Customers’ data. Ordinarily audits are limited to once annually, but that limit does not restrict mandatory rights, regulator requests or justified follow-up to a material breach. Reasonable costs may be agreed, except where law requires otherwise or an audit identifies Antbuildz’s material non-compliance.
13. Liability and Order of Precedence
Liability under this DPA is subject to the exclusions and limitations in the Agreement to the maximum extent permitted by law. If this DPA conflicts with the Agreement on processing Customer Personal Data, this DPA prevails. An Order Form may add processing details but does not reduce mandatory protections without express lawful agreement.
14. Duration and Termination
This DPA starts when Antbuildz first processes Customer Personal Data and continues until that processing ends. Confidentiality, security and deletion obligations continue for Customer Personal Data retained after termination.
Schedule 1 — Processing Details
Subject matter and duration
Provision of the subscribed Antbuildz AI services for the Agreement term and any limited period required for return, deletion, legal compliance or backup lifecycle processes.
Nature of processing
Collection, hosting, storage, organisation, retrieval, analysis, generation, transmission, display, support, deletion and other processing required to operate Antbuildz AI.
Purpose
Providing, securing, supporting and maintaining the subscribed AI Sales Agent, AI Webstore Suite, AI Agent Console, hosted webstore, integrations and related configured workflows.
Categories of data subjects
- Customer employees, representatives and authorised users;
- Customer prospects, customers, buyers, renters, suppliers and end users;
- website or webstore visitors; and
- business contacts and individuals whose data Customer lawfully provides.
Types of personal data
- names, emails, telephone numbers and company information;
- account, role and authentication-related information;
- conversation content, enquiry information and product interests;
- lead details, product requirements, quotations and bookings supplied by Customer;
- IP addresses, technical, device and usage information; and
- other personal data included in Customer Content at Customer’s direction.
The Services are not designed to require sensitive personal data. Customer must not submit such data unless necessary, lawful and expressly supported.
Schedule 2 — High-Level Security Measures
Measures maintained as appropriate to the Services may include:
- identity, authentication and access-control processes;
- role-based or need-to-know restrictions on data access;
- infrastructure and application security controls;
- logging and monitoring where appropriate;
- backup and recovery measures where applicable;
- vulnerability, change and incident-response processes;
- vendor and Subprocessor review;
- confidentiality requirements and personnel awareness; and
- processes for secure deletion or de-identification when no longer required.
These descriptions state control objectives and do not promise a particular certification, encryption standard, data location, backup frequency or service level unless separately confirmed in writing.
Schedule 3 — Subprocessor Information
Antbuildz may use providers in the following categories where required for the configured Services: cloud and hosting infrastructure; AI model and orchestration services; authentication and security; communications and support; payment processing; scheduling; and monitoring or analytics where enabled.
Antbuildz will make current provider-specific Subprocessor information and the applicable change-notification method available through this page, an account notice or on request. Customers may request current information through help@antbuildz.ai.
