This Data Processing Agreement (“Agreement”) forms part of the contractual relationship between Rolling Arrays Technologies (“RATech”, “Data Processor”) and the Customer (“Data Controller”) and governs the processing of Personal Data in connection with the services provided by RATech.
This Agreement is entered into in accordance with applicable data protection laws, including the Personal Data Protection Act 2012 (Singapore), GDPR, and other relevant regulations.
1. DEFINITIONS
Unless otherwise defined in this Agreement, capitalised terms shall have the meanings assigned to them under:
- RATech Privacy Policy / Data Protection Notice
- RATech Terms and Conditions
- Applicable data protection laws
Personal Data, Processing, Controller, and Processor shall have the meanings given under applicable data protection laws.
2. ROLES OF THE PARTIES
- The Customer acts as the Data Controller.
- RATech acts as the Data Processor, processing Personal Data solely on behalf of and under the instructions of the Customer.
3. SCOPE AND PURPOSE OF PROCESSING
RATech shall process Personal Data only to the extent necessary to:
- Provide HR Technology platforms, SAP SuccessFactors services, AI-driven solutions, analytics, integrations, and add-on products
- Perform contractual obligations
- Provide support, maintenance, and service improvements
- Comply with legal and regulatory requirements
Processing shall be carried out strictly in accordance with the Customer’s documented instructions unless otherwise required by law.
4. CATEGORIES OF PERSONAL DATA AND DATA
SUBJECTS
Rolling Arrays Technologies uses cookies and similar technologies to:
May include, but are not limited to:
- Names, job titles, business contact details
- HR, payroll, recruitment, and employee-related data (where applicable)
- User credentials and system identifiers
- Technical data such as IP address, device, and usage logs
4.2 Categories of Data Subjects
- Customer employees
- Contractors
- Job applicants
- Authorized users of RATech platforms
5. CONFIDENTIALITY
RATech shall ensure that:
- All personnel processing Personal Data are bound by confidentiality obligations
- Personal Data is accessed strictly on a need-to-know basis
6. DATA SECURITY MEASURES
RATech implements appropriate technical and organisational measures, including:
- Secure cloud infrastructure
- Encryption and access controls
- Role-based access management
- Regular security reviews and audits
These measures are designed to protect Personal Data against unauthorised access, loss, alteration, or disclosure.
7. SUB-PROCESSORS
RATech may engage third-party sub-processors (e.g., hosting, analytics, CRM providers) to support service delivery.
RATech ensures that:
- Sub-processors are contractually bound by equivalent data protection obligations
- Customer data remains protected at all times
8. DATA SUBJECT RIGHTS
RATech shall reasonably assist the Customer in fulfilling requests relating to:
- Access
- Rectification
- Erasure
- Restriction or objection to processing
- Data portability (where applicable)
9. PERSONAL DATA BREACH
In the event of a Personal Data breach:
- RATech shall notify the Customer without undue delay
- Provide reasonable assistance to support regulatory notifications and mitigation actions
10. DATA RETENTION AND DELETION
Personal Data shall be:
- Retained only for as long as required for contractual or legal purposes
- Securely deleted or anonymised upon termination of services, unless retention is
required by law
11. CROSS-BORDER DATA TRANSFERS
Where Personal Data is transferred outside Singapore or the EU:
- RATech ensures adequate protection through contractual safeguards
- Transfers are compliant with applicable data protection laws
12. AUDIT AND COMPLIANCE
Upon reasonable notice, RATech shall:
- Make available information necessary to demonstrate compliance
- Cooperate with audits conducted by the Customer or regulators, subject to confidentiality and security requirements
13. LIABILITY
Liability under this Agreement shall be subject to the limitation of liability provisions set out in RATech’s Terms and Conditions.
14. GOVERNING LAW
This Agreement shall be governed by and construed in accordance with the laws of Singapore, unless otherwise required by applicable data protection law.
15. CONTACT DETAILS – DATA PROTECTION OFFICER
Data Protection Officer
Name: Sunesh Rodrigo
Company: Rolling Arrays Technologies
Address: 9 Straits View, Marina One West Tower, #05-07, Singapore 018937
Email: sunesh_r@rollingarrays.tech