Data Processing Addendum
Last updated: 28 August 2026
This Data Processing Addendum ("DPA") forms part of the Terms of Service between TKH Global Group, Singapore ("appsg.ai", "Processor", "we") and the Customer ("Controller", "you"). It governs appsg.ai's processing of personal data on the Customer's behalf under Singapore's Personal Data Protection Act 2012 ("PDPA"). Where there is any conflict on the subject of data protection, this DPA prevails.
1. Roles and scope
For personal data of the Customer's end-customers and contacts that is processed through the Service ("Customer Personal Data"), the Customer is the data controller and appsg.ai is the data processor. appsg.ai processes Customer Personal Data only on the documented instructions of the Customer, which include these Terms, the configuration of the Customer's workspace and agents, and any further written instructions the Customer gives. appsg.ai will inform the Customer if, in its opinion, an instruction infringes the PDPA.
The Customer, as controller, is responsible for the accuracy, quality and legality of Customer Personal Data and for having a valid basis (including any consent and notification required under the PDPA) for the collection and processing carried out through the Service.
2. Nature and purpose of processing
- Subject matter: provision of the appsg.ai AI-agent platform.
- Duration: for the term of the Customer's subscription, plus any period required for return or deletion.
- Nature and purpose: hosting, routing and storing messages; generating AI responses; maintaining conversation context and knowledge bases; producing the Customer's analytics; and supporting the Service.
- Types of data: end-customer identifiers (name, phone number, messaging IDs, email), the content of conversations, and any personal data contained in knowledge-base material the Customer uploads.
- Categories of data subjects: the Customer's end-customers, prospects, contacts and other individuals who interact with the Customer's agents.
3. Confidentiality
appsg.ai will treat Customer Personal Data as confidential and ensure that personnel authorised to process it are bound by appropriate confidentiality obligations and access it only on a need-to-know basis under least-privilege controls.
4. Security measures
appsg.ai will implement and maintain administrative, technical and physical security measures appropriate to the risk, including: encryption of data in transit (TLS); hashed credentials; tenant isolation; role-based access control and session hardening; audit logging; least-privilege access to production systems; and regular review of these measures. The Customer is responsible for securing its own credentials, access management and channel configuration.
5. Sub-processors
The Customer authorises appsg.ai to engage the sub-processors below to process Customer Personal Data. appsg.ai remains responsible for its sub-processors' performance of their data-protection obligations and imposes on them terms consistent with this DPA.
| Sub-processor | Purpose | Location |
|---|---|---|
| Anthropic (Claude) | AI inference — generating agent responses | United States |
| OpenAI | AI inference — generating agent responses | United States |
| Google (Gemini) | AI inference — generating agent responses | United States |
| Stripe | Payment processing and card storage | United States / Singapore |
| Meta Platforms (WhatsApp) | Message delivery over WhatsApp | United States / global |
| Telegram | Message delivery over Telegram | Global |
| Email provider | Transactional and channel email delivery | Singapore |
appsg.ai will give the Customer prior notice of any intended addition or replacement of a sub-processor so the Customer has an opportunity to object on reasonable data-protection grounds. Under the AI providers' API terms, Customer Personal Data submitted through the API is not used to train the providers' models.
6. International transfers
The Customer acknowledges and instructs that, to generate agent responses and deliver the Service, Customer Personal Data is transferred to and processed by sub-processors located outside Singapore, including in the United States (notably the AI inference providers). appsg.ai will take steps reasonably required under the PDPA to ensure that a recipient outside Singapore is bound to provide a standard of protection comparable to the PDPA, including through contractual commitments with its sub-processors.
7. Assistance with data-subject requests
Taking into account the nature of the processing, appsg.ai will provide reasonable assistance to enable the Customer to respond to requests from individuals to access, correct or withdraw consent in respect of their personal data, and to meet the Customer's other obligations under the PDPA. Where appsg.ai receives such a request directly, it will (unless legally prohibited) refer the individual to the Customer and notify the Customer without undue delay.
8. Personal data breach notification
appsg.ai will notify the Customer without undue delay after becoming aware of a data breach affecting Customer Personal Data, and will provide information reasonably available to help the Customer assess the breach and meet its own notification obligations to the PDPC and affected individuals under the PDPA. appsg.ai will take reasonable steps to contain and remediate the breach.
9. Return and deletion on termination
On termination or expiry of the subscription, and at the Customer's choice, appsg.ai will return or delete Customer Personal Data within a reasonable period, and delete existing copies except to the extent retention is required by law. Details of data handling on cancellation are also described in the Refund & Cancellation Policy.
10. Audit and records
appsg.ai will make available to the Customer information reasonably necessary to demonstrate compliance with this DPA and will maintain records of its processing of Customer Personal Data as required by the PDPA.
11. Contact
Data-protection matters under this DPA may be directed to our Data Protection Officer at dpo@appsg.ai. Our general privacy practices are described in the Privacy Policy.
Questions about any of this? Talk to us. To ask for a copy of your data, a correction or an erasure, use the data rights request form.