Roles and instructions
The customer determines the purposes and means of processing customer-controlled personal data and is responsible for its lawful basis, notices, instructions and data-subject relationships. Webz Fusion processes that data only on documented instructions needed to provide the agreed service, unless law requires otherwise.
Each party remains responsible for obligations that apply to it in its actual role. Webz Fusion may act separately as an organization or controller for account, billing, security and legal-administration records described in the Privacy Policy.
Processing details
The accepted service document should identify the subject matter, duration, nature, purpose, personal-data categories and data-subject groups. The customer must not provide categories outside that description without written agreement.
The customer warrants that its instructions are lawful and will promptly notify Webz Fusion of restrictions, sensitive data, retention rules or high-risk processing.
Confidentiality and security
Personnel authorised to process customer data are subject to appropriate confidentiality duties. Webz Fusion maintains reasonable administrative, technical and organizational safeguards proportionate to the service and risk.
Security is a shared responsibility. The customer must configure its accounts, permissions, devices, applications and integrations appropriately and must not weaken agreed controls.
Subprocessors
The customer authorises use of subprocessors reasonably required for hosting, cloud, communications, security, payments, support and agreed AI or integration services. Webz Fusion remains responsible for imposing appropriate data-protection obligations on subprocessors for the relevant processing.
Material subprocessor arrangements may be identified in the service documents or made available on reasonable request. The parties will work in good faith on a substantiated objection, which may require an alternative service, changed scope or termination of the affected feature.
International transfers
Where customer data is transferred outside Singapore, the parties will use contractual or other safeguards required to provide a standard of protection comparable to the PDPA where applicable.
The customer is responsible for identifying additional transfer rules arising from its location, users or industry before ordering the service. Additional measures may require separate scope and fees.
Requests and assistance
Taking account of the processing and information available, Webz Fusion will provide reasonable assistance with access, correction, deletion, restriction, breach and regulatory requests that relate to customer-controlled data.
The customer remains responsible for responding to individuals and authorities. Assistance beyond normal service operation may be chargeable where the request is extensive or caused by the customer’s configuration or breach.
Security incidents
Webz Fusion will notify the customer without undue delay after becoming aware of a confirmed breach of customer-controlled personal data where notification is required by the applicable intermediary or processor obligation.
The notice will include available information reasonably needed for assessment. Notification does not constitute an admission of fault, and the customer remains responsible for its notification decisions unless law assigns that duty differently.
Return, deletion and retention
At the end of the affected service, customer data is returned or deleted according to the service capability, documented request and applicable lifecycle, unless law or legitimate security and dispute needs require retention.
Backups and logs may age out through standard retention cycles rather than immediate deletion. Retained data remains protected and is not used for a new purpose.
Audit information and priority
Webz Fusion will make available information reasonably necessary to demonstrate the obligations incorporated by this addendum, subject to confidentiality, security, proportionality and protection of other customers. Independent reports or questionnaires may be used instead of intrusive inspection.
The accepted service document defines liability, fees, governing law and document priority. If this addendum conflicts on data-processing obligations, this addendum controls for that subject to mandatory law.