Data Processing Agreement
Version 1.5 · Effective 2026-09-14 · Forms part of the Terms of Service.
Version 1.5 withdraws part of what version 1.4 stated. Storage is unchanged and confirmed: your content is stored in the Singapore region (ap-southeast-1) and our application runs there. But we no longer state that ALL PROCESSING happens in Singapore, because it does not — extracting data from an uploaded identity document involves sending that document's content to a third-party AI service outside Singapore. We are confirming which provider, its retention and model-training terms, and where it processes, and we will state the position fully once we have. We are withdrawing the claim now rather than waiting, because leaving an incorrect guarantee published while we work out the correct wording would be the worse of the two.
1. Roles of the parties
Your organization is the organisation with control over the personal data uploaded to the platform. Straits Compliance processes that personal data solely on your behalf and on your documented instructions.
2. Scope of processing
Categories of data subjects: directors, shareholders, registrable controllers, nominees, authorised representatives and connected natural persons. Categories of data: identity document data, addresses, dates of birth, nationality, screening results and case decision records.
3. Processing instructions
We process personal data only to provide document extraction, screening, risk scoring, audit stamping and record retention. We do not sell personal data, and we do not use customer content to train general-purpose models.
4. Security measures
Encryption in transit (TLS 1.2+) and at rest (AES-256), tenant-level row isolation enforced in the database, least-privilege access, immutable audit logging of case events and Maker/Checker segregation enforced at database level.
5. Sub-processors
Infrastructure, screening data providers and document-processing services engaged as sub-processors are bound by equivalent obligations.
What this means today. We do not currently operate a channel that can notify you of anything — there is no outbound email or messaging capability in the product, and an in-app notice reaches only people who sign in. We therefore do not promise advance notice of a change to our sub-processors, because we could not keep that promise. Nor do we yet publish a consolidated list of our sub-processors — that is a gap, and naming it is more useful to you than a commitment to notify you of changes to a list you cannot read. Ask us and we will tell you who they are — support@straitscompliance.sg. We will publish the list, and state a notification commitment, once there is a channel that can honour one. Our hosting platform is named in section 7.2, because stating where your data is processed requires naming who processes it.
6. Breach notification
We notify you without undue delay of any data breach affecting personal data we process on your behalf, with sufficient information for you to meet your own notification duties. As a data intermediary under section 26C(3) of the Personal Data Protection Act 2012, notifying you is our obligation. Assessing whether a breach is a notifiable data breach, and notifying the Personal Data Protection Commission within 3 calendar days of that assessment under section 26D(1), remain yours as the responsible organisation.
What this means today. We do not currently operate an automated breach detection, assessment or notification mechanism. Notification under this section is performed manually on becoming aware of a breach. A fuller mechanism — recorded breach assessment, tracked notification deadlines and evidenced delivery — is under active development, and this paragraph will be removed in a further version of this document when it ships.
7. PDPA, residency and retention
7.1 PDPA data intermediary designation
Straits Compliance acts as a data intermediary under the Personal Data Protection Act 2012 (Singapore), processing personal data on your behalf under contract. Your organization remains the responsible organisation for consent, notification, accuracy, access and correction obligations. We comply with the protection and retention limitation obligations applicable to data intermediaries and will assist you in responding to access or correction requests.
7.2 Data residency
Storage. Uploaded documents, extracted personal data, screening results, audit stamps and backups are stored in the Singapore region (ap-southeast-1), and the application that serves the product executes in that region on our hosting platform, Vercel. Our DNS provider operates in DNS-only mode and is not in the request path, so it sees no customer content.
Processing. We are withdrawing the statement that all processing takes place in Singapore, because it is not correct as published. Extracting data from an uploaded identity document involves sending the content of that document to a third-party AI service, which is not located in Singapore. The specific provider, its data-handling terms — including retention, and whether content is used for model training — and the location at which it processes are being confirmed. Until that confirmation is complete we make no statement about where document extraction is processed, rather than one we cannot stand behind.
We do not transfer customer content out of Singapore for our own purposes, and we will not do so on your account without your prior written instruction. Where a screening provider you enable operates outside Singapore, only the minimum query terms necessary for that search are transmitted, and the provider you have enabled is named in your own screening configuration in the product.
Why this section has changed three times. Version 1.3 withdrew a residency guarantee that had never been verified. Version 1.4 restated it once the hosting region was confirmed. Version 1.5 withdraws the processing half again, because confirming where our own code runs did not establish where content is processed — our code sends document content elsewhere. We would rather publish this sequence than leave a guarantee standing that we know to be wrong.
7.3 Five-year retention lifecycle
In line with the record-keeping requirement in §6.55 of the ACRA Guidelines for Registered Corporate Service Providers, CDD records, supporting documents, screening evidence and Annex C audit stamps are retained for a minimum of five years from the later of the end of the business relationship or the completion of the transaction. During that period audit records are immutable and cannot be deleted through the application.
What this means today. The expiry date is computed for each case and surfaced to your officers for action; a case whose retention period has lapsed is listed as outstanding until somebody deals with it. Disposal is not automatic. Nothing in the product destroys records when the period expires — an officer reviews the case and acts, and a decision to refuse an early disposal request is itself recorded. A previous version of this document said records “are securely destroyed” after expiry, which described an outcome the product does not produce on its own. We retain records for at least the period above; we do not represent that they are deleted the moment it ends.
🔒 Encrypted in transit and at rest · Stored in Singapore (ap-southeast-1) · See §7.2 on processing