MassAdmin

Data Processing Addendum

Version MY-1.1. Last updated 11 October 2026. This addendum forms part of the Terms of Service and applies whenever MassAdmin processes personal data on Customer's behalf under the Personal Data Protection Act 2010 of Malaysia (the PDPA), as amended by the Personal Data Protection (Amendment) Act 2024.
1. Roles

Customer is the data controller of personal data of its employees, customers, vendors and signers stored in the workspace. MassAdmin (Epyphite Pte Ltd) is the data processor, processing that data only to provide the Service. As data processor we comply with the Security Principle (PDPA section 9), as section 5(1A) of the PDPA requires of a data processor.

2. Categories of personal data processed

On Customer's behalf, the Service processes:

  • HR: employee identification numbers, name, contact, salary, statutory contributions, payroll and tax records.

  • Accounting: customer/vendor names and contact, invoice line items, payment data.

  • Sign: signer names, emails, IPs and signature audit trail.

  • Account: administrator login credentials and access tokens for the Service.

3. Sub-processors

We engage the following sub-processors under written confidentiality terms:

  • Postgres-managed hosting provider (database, SG region).

  • MinIO / S3-compatible object storage (Sign documents, encrypted backups).

  • Stripe Payments Singapore Pte Ltd (billing only - no workspace data shared).

  • Peppol access point partner (when InvoiceNow e-invoicing is enabled - invoice payload only).

  • Transactional email provider (account confirmation, magic-link delivery).

We will provide 14 days' notice of any new sub-processor; you may terminate without penalty if you object before the change takes effect.

4. Security measures

We apply at minimum: TLS in transit; per-tenant database schema isolation; salted password hashing (PBKDF2); optional second-factor authentication; rate limiting on auth endpoints; encrypted-at-rest backups (AES-256, GPG symmetric); encrypted Data Protection key ring (X.509 cert); brute-force lockout on PIN attempts; audit logging of security-relevant actions. These are the practical steps we take under the Security Principle (PDPA section 9) to protect the personal data from loss, misuse, modification, unauthorised or accidental access or disclosure, alteration or destruction.

5. Data subject requests

Customer may exercise data-subject rights for its own users via the self-service page at /account/data (export and erasure). As data controller, Customer answers requests from its data subjects under the PDPA: access and correction (sections 30 to 35, within 21 days), withdrawal of consent (section 38), preventing processing likely to cause damage or distress (section 42), direct marketing (section 43) and data portability (section 43A). For requests received from Customer's data subjects directly, we will assist Customer in fulfilling them.

6. Breach notification

We will notify Customer of a personal data breach affecting the workspace promptly after we become aware of it, and in any case within 72 hours of confirmation, and give Customer all reasonable and necessary assistance to meet its own notification duties under section 12B of the PDPA (the Commissioner's Guideline on Data Breach Notification, paragraph 12.2). Our notice will give, as far as we know them at the time and otherwise in phases as soon as we learn them: the date and time the breach was detected; the type of personal data involved and the nature of the breach; how it was identified and its suspected cause; the number of affected data subjects and the estimated number of affected records; the system affected; the potential consequences; the chronology of events; the measures taken or proposed to address it and to mitigate its effects; and a contact for further information.

Notifying the Personal Data Protection Commissioner (as soon as practicable and within the 72 hours the Guideline sets, where the breach causes or is likely to cause significant harm) and the affected data subjects (without unnecessary delay and no later than 7 days after notifying the Commissioner) is Customer's duty as data controller; we do not make those notifications on Customer's behalf.

7. Return / deletion on termination

Within 30 days of termination, Customer may export workspace data; thereafter we hard-delete it per the configured retention period unless Customer requests retention in writing or statutory record-keeping requires it.

8. Cross-border transfers

Primary data residency is Singapore. Sub-processors that operate outside Singapore are bound by terms requiring a standard of protection comparable to the Singapore Personal Data Protection Act 2012. Using the Service therefore transfers the personal data Customer enters to Singapore, outside Malaysia.

Customer, as data controller, decides and records the basis for that transfer under section 129 of the PDPA and the Commissioner's Personal Data Protection Guideline No. 3/2025 on Cross Border Personal Data Transfer, and tells its data subjects about the transfer in its own personal data protection notice. We do not state that Singapore has been approved or found to have a law substantially similar to the PDPA: no list of approved places exists, and that finding, if Customer relies on section 129(2), is Customer's own.

For a transfer under section 129(3)(f), the following are contractual clauses binding us: (a) we apply the security measures in section 4 to provide a level of protection for the personal data at least equivalent to that afforded by the PDPA; (b) we process the personal data in compliance with the PDPA as it applies to a data processor, as if the processing took place in Malaysia; (c) we tell Customer without delay if we can no longer meet (a) or (b), and Customer may then suspend the transfer until we do, or terminate without penalty.

9. Data protection officer

Our data protection contact, including our data protection officer where one is appointed under section 12A of the PDPA, is reached at support@epyphite.com. Whether Customer must appoint its own data protection officer and notify the Commissioner of the appointment is for Customer to decide under section 12A and the Commissioner's guideline on the appointment of data protection officers.

10. Audits

Once per year, on reasonable notice, Customer may request a written summary of our security controls; on-site audits may be conducted under a separate NDA at Customer's expense.

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please retry or reload the page.