Compliance · Version 1.0 · Effective October 1, 2026
Data Processing Agreement
This Data Processing Agreement (“DPA”) forms part of the Terms of Service (or any signed order or master agreement, the “Agreement”) between Guni Innovations Pte. Ltd. (trading as TamperCheck AI, “TamperCheck AI,” “we,” “us”) and the customer that uses our Services (“Customer,” “you”). It governs our processing of personal data contained in the documents you submit for analysis, and is referenced from our Privacy Policy.
How this DPA becomes binding. It applies automatically when you accept the Terms or use the Services to process personal data subject to Data Protection Laws. No signature is needed. If your procurement team needs a countersigned copy, email dpo@tampercheck.ai with your legal entity name, address, and signatory, and we will return an executed PDF with identical terms.
Who it is for. Organizations that submit documents containing personal data of other people (for example applicants, employees, or your customers). It does not cover account, billing, and website data for which we are an independent controller; those are described in the Privacy Policy.
1. Definitions
Capitalized terms not defined here have the meaning given in the Agreement. In this DPA:
- “Customer Personal Data” means personal data contained in documents, images, and related content that Customer or its users submit to the Services, and personal data in the analysis results we generate from them.
- “Data Protection Laws” means all laws applicable to the processing of Customer Personal Data, including the GDPR (Regulation (EU) 2016/679), the UK GDPR and UK Data Protection Act 2018, the Swiss Federal Act on Data Protection (“FADP”), the Singapore Personal Data Protection Act 2012 (“PDPA”), India's Digital Personal Data Protection Act, 2023 (“DPDPA”) and rules made under it, the California Consumer Privacy Act as amended by the CPRA (“CCPA”), and other US state privacy laws, each as amended.
- “Controller,” “Processor,” “Data Subject,” “Personal Data Breach,” “Processing” have the meanings in the GDPR. Where another Data Protection Law uses an equivalent term, it includes that term: “Data Fiduciary” and “Data Processor” (DPDPA), “organisation” and “data intermediary” (PDPA), and “business” and “service provider” (CCPA).
- “SCCs” means the standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914.
- “UK Addendum” means the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018, version B1.0.
- “Subprocessor” means a third party we engage that processes Customer Personal Data.
- “Restricted Transfer” means a transfer of Customer Personal Data that is subject to a transfer restriction under Data Protection Laws and requires a transfer mechanism such as the SCCs.
2. Scope and roles
- 1.Roles. For Customer Personal Data, Customer is the Controller (or Data Fiduciary, or organisation, or business) and TamperCheck AI is the Processor (or Data Processor, data intermediary, or service provider). Where Customer itself processes Customer Personal Data on behalf of its own customers, Customer is a Processor and TamperCheck AI is its Subprocessor, and this DPA applies on that basis.
- 2.Independent controller activities. We act as an independent controller for account, authentication, billing, security, support, and website analytics data, as described in Section 3 of our Privacy Policy. This DPA does not apply to that data.
- 3.Details of processing. The subject matter, duration, nature, purpose, data types, and Data Subject categories are in Annex I.
- 4.Duration. This DPA applies for as long as we process Customer Personal Data, including during any post-termination deletion period.
3. Customer instructions
- 1.We will process Customer Personal Data only on Customer's documented instructions. The Agreement, this DPA, and Customer's use and configuration of the dashboard and API are Customer's complete instructions at signature. Further instructions must be consistent with the Agreement and agreed in writing; we may charge reasonable fees for instructions that go beyond the standard Services.
- 2.We will tell Customer if we believe an instruction infringes Data Protection Laws, and may suspend the affected processing until Customer confirms or modifies the instruction.
- 3.We will not determine the purposes or means of processing Customer Personal Data; if we do so in breach of this DPA, we are a controller for that processing (GDPR Article 28(10)).
- 4.We will process Customer Personal Data to the extent required by law that applies to us, even without an instruction; where permitted we will notify Customer first.
4. Our obligations as processor
- 1.Purpose limitation. We process Customer Personal Data solely to provide the Services: receiving documents, running forensic and AI-assisted analysis, and returning results, together with reliability, security, and abuse prevention directly necessary to deliver them.
- 2.No model training. We do not use Customer Personal Data to train, fine-tune, or improve AI models, whether ours or third-party, and we do not permit Subprocessors to do so. We configure, and require by contract, our AI inference and OCR providers not to retain Customer Personal Data or use it for training beyond what is needed to process the request, subject to their published transient abuse-monitoring practices, which we will disclose on request.
- 3.No sale, no sharing, no combining. We do not sell or share (as defined in the CCPA) Customer Personal Data, do not retain, use, or disclose it outside the direct business relationship with Customer or for any purpose other than the business purposes in the Agreement, and do not combine it with personal data from other sources except as the CCPA permits for a service provider.
- 4.Confidentiality. We ensure everyone authorised to process Customer Personal Data is bound by written confidentiality obligations and receives access only on a need-to-know basis.
- 5.Compliance. We comply with the Data Protection Laws that apply to us as processor and will notify Customer without undue delay, and in any event within 5 business days, if we determine we can no longer meet our obligations under them. We provide the same level of privacy protection as the CCPA requires of businesses, and certify that we understand and will comply with the restrictions in this Section. Customer may then take reasonable and appropriate steps to stop and remediate unauthorised use of Customer Personal Data.
- 6.Records. We keep records of processing carried out on Customer's behalf as required by Article 30(2) GDPR and equivalent laws, and give them to a supervisory authority on request.
- 7.Data protection contact. Our Data Protection Officer is reachable at dpo@tampercheck.ai.
5. Security
- 1.We implement and maintain the technical and organisational measures in Annex II, appropriate to the risk and consistent with Article 32 GDPR, the “reasonable security arrangements” obligation of PDPA section 24, and the “reasonable security safeguards” obligation of DPDPA section 8(5).
- 2.We may update these measures from time to time, provided the update does not materially reduce the overall level of protection.
- 3.Customer is responsible for securing its own account credentials and API keys, and for configuring access to the dashboard appropriately for its users.
6. Subprocessors
- 1.General authorisation. Customer gives us general written authorisation to engage the Subprocessors listed in Annex III, and to engage new or replacement Subprocessors under this Section.
- 2.Notice of changes. We will give at least 30 days' notice of any addition or replacement of a Subprocessor by updating Annex III with a new version date and emailing the notification address of each Customer that has asked to be notified at dpo@tampercheck.ai (include the subject “Subprocessor notices”). Shorter notice may apply where a change is needed urgently to maintain security or availability, in which case we will notify as soon as practicable and Customer's right to object continues to apply afterwards.
- 3.Objection. Customer may object on reasonable data protection grounds within the notice period. We will work with Customer in good faith to resolve the objection, including by offering a commercially reasonable alternative. If we cannot resolve it, Customer may terminate the affected Services on written notice and receive a pro-rata refund of prepaid fees for the unused period, without penalty.
- 4.Flow-down and responsibility. We bind each Subprocessor by a written contract that imposes data protection obligations no less protective than this DPA in respect of Customer Personal Data, and we remain liable to Customer for each Subprocessor's performance of them. On request we will provide a copy of the relevant Subprocessor terms, with commercial information redacted.
7. International transfers
- 1.Processing locations. We are established in Singapore and process Customer Personal Data in Singapore and in the countries where our Subprocessors operate, as stated in Annex III. Customer authorises these transfers subject to this Section.
- 2.EEA transfers. Where a Restricted Transfer is made from the EEA to us, the SCCs apply, completed as set out in Annex IV: Module Two (controller to processor) where Customer is a controller, and Module Three (processor to processor) where Customer is a processor. The SCCs are incorporated into this DPA by reference, and Annex I of this DPA is Annexes I.A to I.C of the SCCs, and Annexes II and III of this DPA are Annexes II and III of the SCCs.
- 3.UK transfers. Where a Restricted Transfer is made from the UK, the SCCs apply as amended by the UK Addendum, completed as set out in Annex IV.
- 4.Swiss transfers. Where a Restricted Transfer is made from Switzerland, the SCCs apply with the adaptations in Annex IV.
- 5.Onward transfers to Subprocessors. We make onward transfers only to Subprocessors bound by terms that ensure an equivalent level of protection, including the SCCs (Module Three) or another valid transfer mechanism where required.
- 6.India. Where Customer is a Data Fiduciary subject to the DPDPA, transfers of Customer Personal Data outside India are made on the basis that section 16 of the DPDPA permits transfer to any country or territory except those the Central Government restricts by notification. We will not process Customer Personal Data in a country that is so restricted while the restriction applies to the transfer.
- 7.Singapore. Where Customer is an organisation subject to the PDPA, we, as a data intermediary, provide a standard of protection to Customer Personal Data transferred outside Singapore that is comparable to the protection under the PDPA, as required by the Personal Data Protection Regulations 2021.
- 8.Transfer assessment. Each party warrants that it has no reason to believe that the laws applicable to us prevent us from complying with the SCCs (Clause 14). On request we will give Customer the information reasonably needed for its transfer impact assessment, including the commitments in Section 14.
- 9.Alternative mechanism. If a transfer mechanism in this Section is invalidated or replaced, the parties will cooperate in good faith to put in place a valid alternative.
8. Data subject requests
- 1.If we receive a request directly from a Data Subject relating to Customer Personal Data (for example access, correction, erasure, restriction, portability, objection, or withdrawal of consent), we will not respond to it except to say that it has been referred to Customer, unless the law requires otherwise. We will forward the request to Customer without undue delay.
- 2.Taking into account the nature of the processing, we will assist Customer by appropriate technical and organisational measures, so far as possible, to respond to such requests. Customer can search and view their stored results from the dashboard and API; where Customer cannot self-serve a request, we will carry it out within 10 business days of Customer's written instruction.
- 3.Requests that concern data for which we are an independent controller should be made through our Data Subject Access Request form.
9. Assistance to Customer
Taking into account the nature of the processing and the information available to us, we will give Customer reasonable assistance with:
- security obligations (GDPR Article 32), and notification of Personal Data Breaches to authorities and Data Subjects (Articles 33 and 34; PDPA Part 6A; DPDPA section 8(6));
- data protection impact assessments and prior consultation with a supervisory authority (Articles 35 and 36), including information about our AI-assisted analysis, its inputs, outputs, and human-oversight design;
- deployer obligations under the EU AI Act, to the extent they relate to information about the Services that Customer needs to meet its own obligations; and
- responding to regulator enquiries about our processing on Customer's behalf.
We may charge reasonable fees for assistance that requires significant effort beyond the standard Services, after telling Customer in advance.
10. Personal data breach
- 1.We will notify Customer without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data. Notice goes to the security or account contact registered on Customer's account, and to any additional contact Customer gives us.
- 2.The notice will include, to the extent known: the nature of the breach, the categories and approximate number of Data Subjects and records affected, the likely consequences, and the measures taken or proposed to address it. Where all details are not available at once, we will provide them in phases without undue further delay.
- 3.We will take reasonable steps to contain and remediate the breach and to prevent recurrence, and will cooperate with Customer's reasonable requests relating to it.
- 4.Our notification is not an admission of fault or liability. Customer is responsible for deciding whether and how to notify regulators and Data Subjects, except where we are required by law to notify directly.
11. Deletion and return
- 1.During the term. Customer can view the jobs and their analysis results at any time from the dashboard or API. We do not retain the original submitted document after analysis completes, and the original is therefore not available for re-download. Deleted content is removed from live storage within 30 days and from backups within 90 days. On Customer's instruction (including under section 8(7) of the DPDPA), we will erase Customer Personal Data and require our Subprocessors to do so.
- 2.On termination. On termination or expiry of the Services, or on Customer's written request, we will delete all Customer Personal Data from live systems within 30 days and from backups within 90 days, unless applicable law requires us to keep it, in which case we keep it only for that purpose and continue to comply with this DPA and the SCCs for as long as we retain it. Before deletion, Customer may export its results through the dashboard or API. On request we will confirm deletion in writing.
- 3.Retained data. Job metadata (such as job ID, timestamps, verdict, risk score, and error codes) that does not contain document content may be kept for billing, audit, and abuse-prevention purposes as described in the Privacy Policy. Anything we keep under legal obligation stays subject to this DPA and is used only for that purpose.
- 4.Subprocessors are required to delete Customer Personal Data on the same basis, or on completion of the single request for which it was provided.
12. Audits and information
- 1.We will make available to Customer the information reasonably necessary to demonstrate our compliance with this DPA and Article 28 GDPR, including responses to security questionnaires, our current security documentation, and any available third-party audit reports or certifications.
- 2.If that information is not sufficient, or where a regulator requires it, Customer (or an independent auditor bound by confidentiality and not a competitor of ours) may audit our relevant processing: once per 12 months unless a Personal Data Breach or regulator request justifies more, on at least 30 days' written notice, during business hours, within a reasonable scope and duration, and without unreasonable disruption to our operations or to other customers. Customer bears its own audit costs and our reasonable costs of assisting beyond the first day.
- 3.Audits do not extend to other customers' data, to our intellectual property or detection logic beyond what the audit strictly requires, or to information we are obliged to keep confidential. Customer's audit rights under the SCCs are exercised as set out in this Section to the extent the SCCs permit, and nothing here limits the powers of a supervisory authority.
13. Customer responsibilities
- 1.Customer is responsible for having a lawful basis (and, where required, consent) to submit Customer Personal Data to the Services, for giving Data Subjects any notices the law requires, and for the accuracy and legality of the documents it submits.
- 2.The Services are not designed to require special categories of personal data, children's data, or government identifiers. Documents may nevertheless contain them incidentally; we do not create biometric templates (for example a payslip, bank statement, or ID card). Customer should not submit such data unless needed for its purpose, and confirms that its instructions and the safeguards in this DPA are adequate for it.
- 3.Analysis outputs are decision-support tools, not legal determinations. Customer is responsible for human review of any decision that significantly affects an individual, as described in Section 13 of the Privacy Policy, and for its own obligations as a deployer under any AI regulation.
- 4.Customer will not submit Customer Personal Data in breach of our Acceptable Use rules in the Terms, and will promptly notify us of any instruction or restriction (such as a localisation requirement) that affects our processing.
14. Government access requests
- 1.If we receive a legally binding request from a public authority for disclosure of Customer Personal Data, we will, where lawful, notify Customer promptly so it can seek protection, review the legality of the request and challenge it where there are reasonable grounds to do so, and disclose only the minimum amount permitted by a reasonable interpretation of the request.
- 2.We will not build backdoors into our systems, hand over encryption keys, or voluntarily provide Customer Personal Data to public authorities outside of legal process.
15. Liability and order of precedence
- 1.Each party's liability under this DPA is subject to the exclusions and limitations of liability in the Agreement, except that: (a) nothing limits either party's liability to Data Subjects, or its liability under Clause 12 of the SCCs, or any liability that cannot be limited by law; (b) the exclusion of “loss of data” in the Agreement does not apply to our breach of this DPA; and (c) our aggregate liability for all claims arising out of a breach of this DPA, including a Personal Data Breach caused by our failure to meet Annex II, will not exceed two times the amounts Customer paid for the Services in the twelve months before the first claim. This cap is separate from, and not in addition to, the general cap in the Agreement.
- 2.If there is a conflict, the order of precedence is: (1) the SCCs and the UK Addendum, where they apply; (2) this DPA; (3) the Agreement; (4) the Privacy Policy.
16. Term, changes, and governing law
- 1.This DPA takes effect on the earlier of the date Customer accepts the Terms and the date we first process Customer Personal Data, and ends when we have deleted all Customer Personal Data under Section 11.
- 2.We may update this DPA to reflect changes in law, regulator guidance, or our Services, including new SCC versions. We will post the new version here with a new version number and effective date and give Customers who requested notice at least 30 days' notice of any change that materially reduces Customer's protection. Archived versions are available on request. No update modifies the SCCs or the UK Addendum except to add or replace an approved version.
- 3.The SCCs and the UK Addendum are governed solely by Annex IV. The rest of this DPA is governed by the law that governs the Agreement (the laws of the Republic of Singapore unless a signed order says otherwise) and the courts specified in the Agreement have jurisdiction. Where Data Protection Laws mandate another law or forum, that law and forum apply to the extent mandated.
- 4.If any provision is held invalid, the rest of this DPA continues in force and the parties will replace the provision with a valid one that best achieves its purpose.
Annex I: Details of processing
A. Parties
| Data exporter (Customer) | Data importer (us) | |
|---|---|---|
| Name | The Customer entity identified on its account or signed order | Guni Innovations Pte. Ltd. (trading as TamperCheck AI), UEN 202302437E |
| Address | As stated on the Customer's account or signed order | 68 Circular Road #02-01, 049422, Singapore |
| Contact | Account owner or the contact Customer gives us for privacy and security notices | Data Protection Officer, dpo@tampercheck.ai |
| Role | Controller, or Processor acting for its own customers | Processor, or Subprocessor |
| Activities | Submitting documents for fraud and tampering analysis | Providing the Services described in the Agreement |
B. Description of processing and transfer
| Item | Description |
|---|---|
| Subject matter | Automated and AI-assisted forensic analysis of documents to detect tampering, forgery, and AI generation, and delivery of results. |
| Data subjects | Individuals who appear in the documents Customer submits, such as Customer's applicants, customers, employees, counterparties, or their referees and employers; and Customer's own users who upload or review documents. |
| Categories of personal data | Whatever the document contains. Typically: names, addresses, contact details, dates of birth, employment and income details (payslips), account and transaction data (bank statements), identity document numbers and images, signatures, photographs, and document metadata. Analysis results about the document (risk scores, verdicts, findings tied to document regions). |
| Sensitive data | Not intentionally requested. Documents may incidentally contain sensitive or special-category data (for example health information in a medical invoice, or government identifiers). Safeguards: encryption in transit and at rest, strict access control, purpose limitation, no model training, and short retention as in Annex II. |
| Frequency | Continuous, as and when Customer submits documents. |
| Nature of processing | Receiving, storing, transforming, extracting text and images from, analysing (including by OCR and AI inference), generating results from, transmitting, and deleting. |
| Purpose | To provide the Services to Customer under the Agreement and to carry out the instructions in Section 3. |
| Retention | The original submitted document is not retained: it is processed to produce the analysis and deleted once the analysis completes. Only the findings and processed results (verdict, risk score, findings, job metadata) are kept and made available to Customer through the dashboard, API, and logs, until Customer deletes them or the Agreement ends, and are then deleted in accordance with Section 11. We require AI inference and OCR Subprocessors not to retain or train on document content beyond what is needed to process the request, as described in Section 4.2. |
| Subprocessor transfers | To the Subprocessors in Annex III for the subject matter, nature, and duration stated there. |
C. Competent supervisory authority (SCC Clause 13)
Where Customer is established in an EU Member State, the supervisory authority of that Member State. Where Customer is not established in the EU but is subject to the GDPR under Article 3(2) and has appointed a representative, the authority of the Member State of its representative. Otherwise, the Irish Data Protection Commission. For UK transfers, the Information Commissioner's Office; for Swiss transfers, the Federal Data Protection and Information Commissioner.
Annex II: Technical and organisational measures
These measures apply to Customer Personal Data and are described at a level that does not weaken them. A more detailed security summary is available on request under NDA.
| Area | Measures |
|---|---|
| Encryption | TLS for data in transit. Encryption at rest for stored documents, databases, and backups. Application secrets stored in managed secret stores, not in code. |
| Access control | Role-based, least-privilege access to production systems; access reviewed regularly and removed on role change or exit. Multi-factor authentication for administrative access to cloud and infrastructure consoles. Customer-level logical separation: Customer content is accessible only to that Customer's organization. |
| Customer authentication | API keys stored only as hashes and not retrievable after creation; revocable at any time. Short-lived access tokens, session timeouts, and idle-timeout controls on the dashboard. Bot and abuse protection on public sign-up flows. |
| Document handling | Documents are processed in isolated, task-based compute and the original is deleted once analysis completes; only results are kept. Document content is not used for training, marketing, or any secondary purpose. Customer-initiated deletion removes stored results and any remaining artifacts. Staff access to document content is limited to what is needed to resolve an issue the Customer has raised, and is logged. |
| AI and OCR providers | Document content is sent to inference and OCR providers only to obtain the requested output, under contracts that prohibit training on it and restrict retention. Outputs are explainable and tied to document regions to support human review. |
| Logging and monitoring | Application and infrastructure logging, error monitoring, and alerting for anomalous access. We take measures designed to keep logs free of document content, and retain them only as long as needed for security and reliability. |
| Network and application security | Managed cloud networking with restricted ingress, rate limiting and throttling on the API, dependency and vulnerability management, and code review before release. |
| Resilience and recovery | Managed databases with automated backups, redundant task queues with retries, and documented restoration procedures. |
| Personnel | Written confidentiality obligations for staff and contractors and security and privacy awareness training. |
| Incident response | Documented incident response procedure with defined roles, triage, containment, and post-incident review; customer notification as in Section 10. |
| Vendor management | Security and privacy review of Subprocessors before engagement, written data protection terms, and periodic re-assessment. |
| Data minimisation and deletion | Collection limited to what the analysis needs; customer-initiated and account-closure deletion with documented backup expiry as in Section 11. |
Subprocessor assistance. When we use a Subprocessor, we require it to maintain measures that are no less protective than those above for the services it provides.
Annex III: Authorised Subprocessors
Version 1.0, effective October 1, 2026. We update this list under Section 6 before any change takes effect.
| Subprocessor | Service and data | Location |
|---|---|---|
| DigitalOcean, LLC | Object storage used to hold submitted documents and extraction artifacts only while analysis is in progress (document content). Originals are deleted on completion. | Singapore |
| Google LLC (Google Cloud) | Document AI OCR and document parsing; managed task queue for dispatching analysis jobs (document content, job references). | Singapore (asia-southeast1) |
| Amazon Web Services, Inc. | Serverless compute that runs analysis tasks (document content in transit and in transient storage). | Singapore (ap-southeast-1) |
| OpenRouter, Inc. (routing to Anthropic, PBC models) | AI inference for forensic analysis and findings (document content and extracted text/images in each request). No training on, and no retention beyond, processing of the request. | United States |
The following do not receive document content, but may process personal data of Customer's users (such as name and email) and are listed for completeness:
| Subprocessor | Service and data | Location |
|---|---|---|
| Stripe, Inc. / Stripe Payments Singapore Pte. Ltd. | Payment processing for wallet top-ups and invoices (billing contact details). | United States, Singapore |
| Resend, Inc. | Transactional email such as OTP, invoices, and job notifications (recipient email, message content). | United States |
| Functional Software, Inc. (Sentry) | Error monitoring (technical data; configured to exclude document content). | United States |
| Cloudflare, Inc. | Bot protection on sign-up and form pages (IP address, browser signals). | Global |
| Google LLC (Google Sign-In) | Optional OAuth sign-in (name, email, profile identifier). | United States |
Website analytics (such as Google Analytics, Google Tag Manager, and Microsoft Clarity) run only on our public website after cookie consent, concern website visitors rather than Customer Personal Data, and are covered by the Privacy Policy instead.
Annex IV: Transfer terms
EU Standard Contractual Clauses
| SCC provision | Selection |
|---|---|
| Modules | Module Two (controller to processor) and Module Three (processor to processor), as applicable under Section 7.2. |
| Clause 7 (docking) | Included. |
| Clause 9(a) (subprocessors) | Option 2, general written authorisation. Time period: at least 30 days before engaging a new or replacement Subprocessor, as in Section 6.2. |
| Clause 11(a) (redress) | The optional independent dispute resolution body wording is not included. |
| Clause 13 and Annex I.C | Supervisory authority as stated in Annex I.C. |
| Clause 17 (governing law) | Option 1: the law of Ireland. |
| Clause 18(b) (forum) | The courts of Ireland. |
| Annexes | Annex I.A, I.B, I.C: Annex I of this DPA. Annex II: Annex II of this DPA. Annex III: Annex III of this DPA. |
| Audit (Clause 8.9) and deletion (Clause 8.5) | Performed as described in Sections 12 and 11 of this DPA. |
UK Addendum
| Part | Selection |
|---|---|
| Table 1 (parties) | As in Annex I.A, including the importer's Singapore UEN 202302437E. Start date: the effective date of this DPA. |
| Table 2 (selected SCCs) | The Approved EU SCCs as selected above, including the Appendix Information. |
| Table 3 (appendix information) | Annexes I, II, and III of this DPA. |
| Table 4 (ending the Addendum when the Approved Addendum changes) | Neither party. |
| Mandatory Clauses | The Mandatory Clauses of the Approved Addendum, being the template Addendum B.1.0 issued by the ICO and laid before Parliament under section 119A of the Data Protection Act 2018 on 2 February 2022, as revised under Section 18 of those Mandatory Clauses. |
| Governing law and forum | England and Wales. |
Switzerland
- References to the GDPR are to the FADP, and references to Member State or EU law are to Swiss law.
- The competent supervisory authority is the Swiss Federal Data Protection and Information Commissioner.
- The law of Switzerland governs Clause 17 for transfers subject exclusively to the FADP, and the term "Member State" does not exclude data subjects in Switzerland from suing in Switzerland for their rights.
- Where a transfer is subject to both the GDPR and the FADP, the EU supervisory authority and the Swiss Commissioner act in parallel; the Swiss Commissioner is competent only for transfers governed exclusively by the FADP.
Executed by acceptance. By accepting the Terms or using the Services to process Customer Personal Data, Customer and Guni Innovations Pte. Ltd. agree to this DPA, including the SCCs and UK Addendum as completed in Annex IV, as of the effective date above. Questions or a countersigned copy: dpo@tampercheck.ai.
See also our Privacy Policy, Terms of Service, and Data Subject Access Request form.