Data Processing Agreement (DPA)

Last Updated: 04 September 2026

Effective Date: 04 September 2026

This Data Processing Agreement (“DPA”) forms part of the agreement governing the Customer’s use of the services provided by RunCloud Sdn Bhd (“RunCloud”, “we”, “us” or “our”), including RunCloud’s Terms of Service, any applicable order form, enterprise agreement, statement of work or other written agreement between RunCloud and the Customer (collectively, the “Agreement”).

This DPA governs the Processing of Personal Data in connection with the Services as described below.

By entering into the Agreement or using the Services, the Customer enters into this DPA on behalf of itself and, where applicable, its Authorized Affiliates.

If there is any conflict between this DPA and the Agreement concerning the Processing of Personal Data, this DPA shall prevail to the extent of that conflict.

1. Definitions

For purposes of this DPA:

“Applicable Data Protection Laws” means all laws and regulations relating to privacy, data protection or the Processing of Personal Data applicable to the Processing under the Agreement, including, where applicable:

  1. the Malaysian Personal Data Protection Act 2010 [Act 709], as amended, together with applicable regulations, standards, circulars and guidelines (“Malaysia PDPA”);
  2. Regulation (EU) 2016/679 (“GDPR”);
  3. the GDPR as it forms part of United Kingdom law (“UK GDPR”) and the UK Data Protection Act 2018; and
  4. the California Consumer Privacy Act, as amended (“CCPA”).

“Authorized Affiliate” means an Affiliate of Customer that is permitted to use or receive the benefit of the Services under the Agreement.

“Controller” means the person or entity that determines the purposes and means of Processing Personal Data, including a “data controller”, “controller” or “business” as those terms are defined under Applicable Data Protection Laws.

“Customer” means the person or legal entity that has entered into the Agreement with RunCloud.

“Customer Personal Data” means Personal Data Processed by RunCloud on behalf of Customer in connection with providing the Services.

Customer Personal Data does not include Personal Data for which RunCloud determines the purposes and means of Processing as a Controller.

“Data Subject” means an identified or identifiable individual to whom Personal Data relates, including a “consumer” under applicable privacy laws.

“Personal Data” means any information relating to an identified or identifiable individual and includes “personal data”, “personal information” or an equivalent term under Applicable Data Protection Laws.

“Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Customer Personal Data.

“Process”, “Processing” and “Processed” have the meanings given under Applicable Data Protection Laws.

“Processor” means a person or entity that Processes Personal Data on behalf of a Controller, including a “data processor”, “processor”, “service provider” or “contractor”, where applicable.

“Services” has the meaning given in the Agreement.

“Subprocessor” means a third party engaged by RunCloud to Process Customer Personal Data on behalf of Customer in connection with the Services.

Capitalized terms not defined in this DPA shall have the meanings given in the Agreement.

2. Scope

This DPA forms part of the Agreement and governs the Processing of Personal Data in connection with the Services.

Capitalized terms not defined in this DPA shall have the meanings given in the Agreement. “Services” has the meaning given in the Agreement.

3. Data Processing Roles and Details

3.1 RunCloud as Processor. Where RunCloud Processes Customer Personal Data on behalf of Customer in connection with the Services, Customer acts as the Controller, Business or equivalent role under Applicable Data Protection Laws, and RunCloud acts as the Processor, Service Provider, Contractor or equivalent role, as applicable.

3.2 RunCloud as Controller. RunCloud acts as a Controller where it determines the purposes and means of Processing Personal Data for its own business purposes in connection with the Services.

Such Processing is governed by Applicable Data Protection Laws and RunCloud’s Privacy Policy.

3.3 Nature, Purpose and Subject Matter of Processing. The Processing relates to the provision of the Services to Customer under the Agreement.

RunCloud Processes Customer Personal Data for the limited purposes of providing, operating, maintaining, securing and supporting the Services, and otherwise in accordance with Customer’s documented instructions and Applicable Data Protection Laws.

3.4 Categories of Data Subjects. Customer Personal Data may relate to Customer’s personnel, customers, end users, website or application users, and other individuals whose Personal Data is Processed through the Services.

3.5 Categories of Customer Personal Data. Customer Personal Data may include identification, contact, account, authentication, technical, usage, log, system, application and other Personal Data submitted, stored, transmitted or otherwise Processed through the Services.

3.6 Sensitive Personal Data. Customer Personal Data may include sensitive, special-category or other regulated Personal Data where such information is Processed through the Services.

Such Personal Data remains subject to this DPA and Applicable Data Protection Laws.

3.7 Duration of Processing. RunCloud Processes Customer Personal Data for the duration of the applicable Services and thereafter only as necessary to return or delete Customer Personal Data, complete ordinary backup or disaster-recovery retention cycles, or comply with applicable legal requirements.

4. Customer Responsibilities

Customer shall:

  1. comply with its obligations under Applicable Data Protection Laws;
  2. ensure that its instructions to RunCloud comply with Applicable Data Protection Laws;
  3. have all rights, permissions, notices, consents and lawful bases necessary for RunCloud to Process Customer Personal Data as contemplated by the Agreement and this DPA;
  4. determine whether the Services are appropriate for the nature and sensitivity of the Personal Data Customer intends to Process;
  5. configure and use the Services in a manner consistent with Applicable Data Protection Laws; and
  6. remain responsible for the accuracy, quality, legality and means by which Customer Personal Data is acquired.

Customer is responsible for determining whether any additional regulatory, industry-specific or contractual requirements apply to Customer’s use of the Services.

5. Processing Instructions

5.1 Documented Instructions. RunCloud shall Process Customer Personal Data only:

  1. to provide, maintain, secure and support the Services;
  2. in accordance with the Agreement and this DPA;
  3. in accordance with Customer’s documented instructions; or
  4. where required by applicable law.

The Agreement, this DPA, Customer’s configuration and use of the Services, and documented support or technical instructions submitted by authorized Customer personnel constitute Customer’s documented instructions to RunCloud.

5.2 Required Processing. Where RunCloud is required by law to Process Customer Personal Data other than in accordance with Customer’s instructions, RunCloud shall notify Customer of that legal requirement before Processing unless prohibited from doing so by law.

5.3 Unlawful Instructions. RunCloud shall immediately inform Customer if, in RunCloud’s reasonable opinion, an instruction infringes Applicable Data Protection Laws.

RunCloud may suspend performance of the affected instruction until the parties have resolved the matter.

6. Confidentiality

RunCloud shall ensure that personnel authorized to Process Customer Personal Data:

  1. are subject to appropriate contractual or statutory confidentiality obligations;
  2. receive access to Customer Personal Data only where reasonably necessary to perform their responsibilities; and
  3. receive appropriate information security and privacy awareness training relevant to their responsibilities.

Confidentiality obligations shall survive termination of the individual’s employment or engagement where appropriate.

7. Security of Processing

7.1 Security Measures. RunCloud shall implement and maintain appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access.

Such measures shall take into account:

  1. the state of the art;
  2. implementation costs;
  3. the nature, scope, context and purposes of Processing; and
  4. the risks to the rights and freedoms of individuals.

RunCloud’s technical and organizational measures are described in Annex A (Technical and Organizational Measures).

7.2 Security Program. RunCloud shall maintain an information security management and risk-management program appropriate to the nature of the Services and Customer Personal Data Processed.

7.3 Changes to Security Measures. RunCloud may update its technical and organizational measures from time to time provided that such changes do not materially reduce the overall level of protection provided to Customer Personal Data.

7.4 Customer Responsibilities. Customer acknowledges that security of Customer’s own servers, cloud provider accounts, applications, operating systems, credentials and configurations may involve responsibilities shared between Customer, RunCloud and Customer’s selected infrastructure or cloud providers.

Nothing in this DPA transfers to RunCloud security responsibilities that remain under Customer’s control under the Agreement.

8. Personal Data Breaches

8.1 Notification. RunCloud shall notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data.

8.2 Information. To the extent reasonably available, RunCloud’s notification or subsequent updates shall include sufficient information to enable Customer to understand the nature and impact of the Personal Data Breach, including its general characteristics, the categories of Personal Data and Data Subjects involved, the likely consequences, and the measures taken or proposed to address or mitigate the breach, together with an appropriate point of contact for further information.

Information may be provided in stages where not all details are available at the time of the initial notification.

8.3 Assistance. RunCloud shall provide reasonable assistance to Customer in fulfilling Customer’s applicable Personal Data Breach notification obligations, taking into account the nature of the Processing and information available to RunCloud.

8.4 No Admission. RunCloud’s notification of a Personal Data Breach shall not constitute an admission of fault, liability or violation of Applicable Data Protection Laws.

9. Subprocessors

9.1 General Authorization. Customer generally authorizes RunCloud to engage Subprocessors to Process Customer Personal Data as necessary to provide the Services, subject to the requirements of this DPA.

9.2 Subprocessor Obligations. Before permitting a Subprocessor to Process Customer Personal Data, RunCloud shall enter into a written agreement requiring the Subprocessor to provide data protection obligations that are no less protective in substance than those applicable to RunCloud under this DPA, to the extent relevant to the services performed by that Subprocessor.

RunCloud shall remain responsible for the performance of its Subprocessors to the extent required by Applicable Data Protection Laws.

9.3 Subprocessor List. RunCloud shall maintain an up-to-date list of Subprocessors that Process Customer Personal Data in connection with the Services.

The list shall include, where applicable, the name of the Subprocessor, the purpose of the Processing and the country or region where the Processing takes place.

The current list shall be made available to Customer upon request through RunCloud’s customer support.

9.4 New or Replacement Subprocessors. RunCloud may appoint new Subprocessors or replace existing Subprocessors.

RunCloud shall provide Customer with at least fourteen (14) days’ prior notice before a new or replacement Subprocessor begins Processing Customer Personal Data.

Notice may be provided by email, through the Services, or through another reasonable notification method.

9.5 Objections. Customer may object to a new or replacement Subprocessor by notifying RunCloud in writing within fourteen (14) days after receiving notice.

The objection must be based on reasonable data protection grounds relating to Customer Personal Data.

RunCloud and Customer shall work in good faith to address the objection.

If RunCloud does not replace the relevant Subprocessor, either party may terminate the affected Services upon written notice.

10. Data Subject Requests

Taking into account the nature of the Processing, RunCloud shall provide reasonable assistance to Customer through appropriate technical and organizational measures to enable Customer to respond to requests from Data Subjects exercising their rights under Applicable Data Protection Laws.

If RunCloud receives a request directly from a Data Subject concerning Customer Personal Data, RunCloud shall, unless prohibited by law, promptly notify Customer and may direct the Data Subject to Customer.

RunCloud shall not independently respond to such request except on Customer’s documented instructions or as required by law.

11. Regulatory Assistance and Data Protection Impact Assessments

11.1 Assistance. Taking into account the nature of the Processing and the information available to RunCloud, RunCloud shall provide reasonable assistance to Customer in ensuring compliance with Customer’s obligations under Applicable Data Protection Laws relating to security of Processing, Personal Data Breach notifications, data protection impact assessments and prior consultations with competent Supervisory Authorities, to the extent such obligations relate to RunCloud’s Processing of Customer Personal Data.

The assistance relating to security and Personal Data Breaches is further described in Sections 7 and 8.

11.2 Costs of Assistance. RunCloud may charge reasonable fees for assistance that requires material time or resources beyond the ordinary provision of the Services, unless the assistance is required due to RunCloud’s breach of this DPA.

12. Compliance Information and Audits

12.1 Compliance Information. RunCloud shall make available to Customer information reasonably necessary to demonstrate RunCloud’s compliance with this DPA.

In the first instance, RunCloud may provide relevant security certifications, independent assurance reports or summaries, compliance documentation, security information or responses to a reasonable security questionnaire.

Customer shall take such information into account when determining whether an additional audit is reasonably necessary.

12.2 Additional Audit. Customer may request an audit where reasonably necessary to verify RunCloud’s compliance with this DPA, taking into account the information provided under Section 12.1.

RunCloud shall allow for and contribute to a reasonable audit conducted by Customer or an independent auditor appointed by Customer, subject to the conditions in this Section.

12.3 Audit Conditions. Any audit shall:

  1. be conducted on at least thirty (30) days’ prior written notice, specifying the proposed scope, timing and expected duration. The parties shall reasonably coordinate the scope, timing and duration of the audit. A shorter notice period may apply where reasonably necessary following a Personal Data Breach materially affecting Customer Personal Data or where required by a competent Supervisory Authority;
  2. be limited to matters reasonably relevant to RunCloud’s compliance with this DPA and its Processing of Customer Personal Data;
  3. not occur more than once in any twelve (12)-month period, unless there are reasonable indications of material non-compliance, a Personal Data Breach materially affecting Customer Personal Data, or an additional audit is required by Applicable Data Protection Laws or a competent Supervisory Authority;
  4. be conducted at Customer’s own cost, including the costs of any auditor appointed by Customer;
  5. be conducted during normal business hours and in a manner that does not unreasonably interfere with RunCloud’s normal business operations;
  6. where conducted by a third-party auditor, be carried out by an independent and appropriately qualified auditor that is subject to appropriate confidentiality obligations. RunCloud may reasonably object to an auditor where there is a material conflict of interest, competitive relationship or security concern, in which case Customer shall appoint another suitable auditor; and
  7. not permit access to another customer’s Personal Data or to information that is not reasonably relevant to RunCloud’s compliance with this DPA.

12.4 Confidential and Third-Party Information. RunCloud may redact or withhold information that relates to other customers, third parties, trade secrets or other confidential information that is not reasonably relevant to the audit.

Any such redaction or withholding shall not prevent Customer from reasonably assessing RunCloud’s compliance with its obligations under this DPA.

12.5 Supervisory Authorities. RunCloud and Customer shall make information relating to an audit, including relevant audit results, available to a competent Supervisory Authority where required by Applicable Data Protection Laws.

13. Return and Deletion of Customer Personal Data

Upon termination or expiry of the applicable Services, RunCloud shall, at Customer’s choice, delete or return Customer Personal Data in accordance with the Agreement and Customer’s instructions.

RunCloud may retain residual copies of Customer Personal Data in its internal backup or disaster recovery systems until such copies are deleted through RunCloud’s ordinary retention cycles, or where retention is required by applicable law.

Any retained Customer Personal Data shall remain protected under this DPA and shall not be actively Processed except as required by law or as necessary to maintain the security and integrity of RunCloud’s backup and disaster recovery systems.

14. International Transfers

14.1 General. RunCloud may Process Customer Personal Data in countries outside the country in which Customer or the relevant Data Subjects are located, subject to Applicable Data Protection Laws.

14.2 European Economic Area Transfers. Where Customer Personal Data subject to the GDPR is transferred from the European Economic Area (“EEA”) to RunCloud in Malaysia or another country not covered by an applicable adequacy decision, the EU Standard Contractual Clauses shall apply, unless another lawful transfer mechanism is available.

The applicable terms are set out in Annex B (International Data Transfer Terms).

14.3 United Kingdom Transfers. Where Customer Personal Data subject to the UK GDPR is transferred to Malaysia or another country requiring an appropriate transfer safeguard, the EU Standard Contractual Clauses, as supplemented by the UK International Data Transfer Addendum, shall apply, unless another lawful transfer mechanism is available.

The applicable terms are set out in Annex B.

14.4 Transfers from Malaysia. Where Customer Personal Data is transferred from Malaysia to another country, RunCloud shall comply with the applicable cross-border transfer requirements under the Malaysia PDPA.

15. Government and Law-Enforcement Requests

Where RunCloud receives a legally binding request from a public authority for disclosure of Customer Personal Data, RunCloud shall, unless prohibited by law:

  1. review the request to determine whether it is valid and legally binding;
  2. disclose only the Customer Personal Data reasonably required by the request;
  3. notify Customer where legally permitted; and
  4. where appropriate, challenge or seek clarification of requests that RunCloud reasonably considers unlawful, excessive or inconsistent with applicable legal requirements.

Nothing in this Section requires RunCloud to undertake litigation or incur unreasonable expense.

16. California Privacy Laws

To the extent the CCPA applies to Customer Personal Data Processed by RunCloud on behalf of Customer:

  1. RunCloud shall act as Customer’s service provider or contractor, as applicable, under the CCPA;
  2. Customer discloses Customer Personal Data to RunCloud only for the limited and specified purposes described in Section 3 (Data Processing Roles and Details);
  3. RunCloud shall not sell or share Customer Personal Data as those terms are defined under the CCPA, and shall not retain, use or disclose Customer Personal Data for cross-context behavioral advertising;
  4. RunCloud shall not retain, use or disclose Customer Personal Data outside the direct business relationship between RunCloud and Customer except as permitted by the CCPA;
  5. RunCloud shall not retain, use or disclose Customer Personal Data for purposes other than those described in Section 3 (Data Processing Roles and Details), except as otherwise permitted by the CCPA;
  6. RunCloud shall not combine Customer Personal Data received from or on behalf of Customer with personal information received from another person or entity, or collected from RunCloud’s own interaction with the relevant consumer, except as expressly permitted by the CCPA and applicable regulations;
  7. RunCloud shall comply with the applicable requirements of the CCPA and its implementing regulations in its capacity as a service provider or contractor, including providing the level of privacy protection required under the CCPA;
  8. RunCloud shall notify Customer if RunCloud determines that it can no longer meet its applicable obligations under the CCPA in relation to Customer Personal Data; and
  9. Customer may take reasonable and appropriate steps to verify RunCloud’s compliance with this Section and, where necessary, stop and remediate any unauthorized use of Customer Personal Data as permitted by the CCPA.

17. Liability

The liability of each party arising out of or relating to this DPA shall be subject to the limitations and exclusions of liability contained in the Agreement, except to the extent such limitation or exclusion is prohibited by Applicable Data Protection Laws or by the EU SCCs or UK Addendum.

Nothing in the Agreement or this DPA limits any rights of Data Subjects that cannot lawfully be limited by contract.

18. Order of Precedence

In the event of a conflict:

  1. the applicable EU SCCs or UK Addendum shall prevail to the extent of the conflict where the relevant Processing is governed by those instruments;
  2. this DPA shall prevail over the Agreement to the extent of the conflict regarding the Processing of Customer Personal Data; and
  3. the Agreement shall otherwise remain in full force and effect.

19. Duration and Termination

This DPA becomes effective when the Agreement becomes effective or when RunCloud first Processes Customer Personal Data on behalf of Customer, whichever occurs first.

This DPA remains in effect for so long as RunCloud Processes Customer Personal Data.

Any provision that by its nature should survive termination, including confidentiality, deletion, international transfer protections and accrued liability, shall survive termination for as long as relevant Customer Personal Data remains in RunCloud’s possession or control.

Annex A — Technical and Organizational Measures

RunCloud implements and maintains the following technical and organizational measures to protect Personal Data Processed in connection with the Services.

The measures are applied as appropriate to the relevant systems, Processing activities and risks.

1. Technical Measures

No.MeasureRunCloud Implementation / Description
1Access ControlRunCloud implements access controls to ensure that only authorized personnel can access systems and Personal Data based on their roles and responsibilities.
2Least PrivilegeRunCloud grants employees and administrators only the permissions necessary to perform their assigned duties.
3Authentication and Multi-Factor AuthenticationRunCloud implements strong authentication mechanisms and multi-factor authentication for privileged or administrative access where applicable.
4Network SecurityRunCloud uses firewalls, network controls and restricted access mechanisms to protect infrastructure from unauthorized access.
5Database SecurityRunCloud restricts access to databases, which can only be accessed through an internal network.
6Encryption in TransitRunCloud uses appropriate encryption mechanisms, such as TLS/HTTPS, to protect Personal Data during transmission.
7Encryption at RestRunCloud applies appropriate encryption and hashing mechanisms to protect Personal Data stored within its infrastructure, where applicable.
8Logging and MonitoringRunCloud maintains appropriate system, security and administrative logs and monitors relevant events to identify potential unauthorized or malicious activity.
9Log RetentionRunCloud applies defined retention and deletion controls to logs containing Personal Data and retains them only for legitimate operational, security or compliance purposes.
10Backup and RecoveryRunCloud maintains appropriate backup and recovery mechanisms to support the availability and restoration of systems and data following failures or incidents.
11Secure DeletionRunCloud implements procedures and technical controls for the secure deletion or removal of Personal Data when it is no longer required, subject to contractual and legal requirements.
12Vulnerability and Patch ManagementRunCloud maintains processes for identifying, assessing and addressing vulnerabilities and applying security updates to relevant systems.
13Secure ConfigurationRunCloud applies security-hardening and secure-configuration practices, including disabling unnecessary services, ports and access mechanisms where appropriate.
14Malware and Intrusion ProtectionRunCloud implements appropriate security controls to detect, prevent and respond to malware, intrusion attempts and other malicious activities.
15Environment SegregationRunCloud maintains appropriate separation between production, development, testing and other environments where required to reduce unauthorized access or data exposure.
16Data MinimisationRunCloud designs and configures systems to Process only Personal Data necessary for the relevant purpose.
17Availability and ResilienceRunCloud implements appropriate technical measures, including server redundancy where applicable, to maintain the availability, reliability and resilience of the Services.
18Security TestingRunCloud performs appropriate security assessments, vulnerability testing and other technical checks to identify and address security weaknesses.

2. Organizational Measures

No.MeasureRunCloud Implementation / Description
19Information Security PolicyRunCloud maintains documented information security policies and procedures governing the protection of information and Personal Data.
20Data Protection PolicyRunCloud maintains policies addressing the appropriate collection, Processing, storage, disclosure and protection of Personal Data.
21Confidentiality ObligationsRunCloud requires personnel to comply with appropriate confidentiality obligations.
22Security and Privacy TrainingRunCloud provides relevant personnel with appropriate information security, privacy and data protection training.
23Onboarding and OffboardingRunCloud maintains processes to provision and revoke access when personnel join or leave the organization.
24Periodic Access ReviewsRunCloud periodically reviews access rights and privileges to ensure that they remain appropriate and necessary.
25Incident ResponseRunCloud maintains documented procedures for detecting, assessing, responding to and recovering from information security incidents.
26Personal Data Breach ManagementRunCloud maintains procedures for identifying, investigating and documenting Personal Data Breaches and, where applicable, notifying relevant parties.
27Business Continuity and Disaster RecoveryRunCloud maintains business continuity and disaster recovery arrangements designed to support continued operation or timely restoration of critical Services.
28Risk ManagementRunCloud periodically assesses information security and data protection risks and implements appropriate mitigation measures.
29Vendor and Subprocessor ManagementRunCloud assesses and manages relevant third-party providers and Subprocessors that may Process or have access to Personal Data.
30Data Processing AgreementsRunCloud maintains appropriate contractual arrangements with customers, processors and Subprocessors where required by Applicable Data Protection Laws.
31Data Retention and DeletionRunCloud maintains appropriate retention and deletion procedures designed to ensure that Personal Data is not retained longer than necessary, subject to contractual and legal requirements.
32Privacy by Design and by DefaultRunCloud incorporates privacy and data protection considerations into the design and configuration of the Services and applies privacy-protective settings by default where appropriate.
33Change ManagementRunCloud maintains change-management processes to assess and control changes that may affect security, availability or the Processing of Personal Data.
34Internal Audit and Compliance ReviewRunCloud conducts appropriate internal reviews or audits to assess compliance with applicable security, privacy and data protection requirements.

Annex B — International Data Transfer Terms

1. Application

1.1 European Economic Area Transfers. Where Section 14.2 of the DPA applies, the Standard Contractual Clauses adopted by the European Commission under Commission Implementing Decision (EU) 2021/914 (“EU SCCs”) are incorporated into this DPA and shall apply to the relevant transfer of Customer Personal Data.

1.2 United Kingdom Transfers. Where Section 14.3 of the DPA applies, the EU SCCs shall apply together with the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner (“UK Addendum”).

1.3 Alternative Transfer Mechanisms. The EU SCCs or UK Addendum shall apply only to the extent required by Applicable Data Protection Laws and where the relevant transfer is not otherwise covered by an applicable adequacy decision, adequacy regulation or other lawful transfer mechanism.

2. EU Standard Contractual Clauses

2.1 Applicable Modules.

  1. Module Two (Controller to Processor) applies where Customer acts as a Controller and RunCloud acts as a Processor.
  2. Module Three (Processor to Processor) applies where Customer acts as a Processor and RunCloud acts as a Subprocessor.

2.2 SCC Elections. For purposes of the EU SCCs:

  1. Clause 7 (Docking Clause) shall not apply.
  2. For Clause 9(a), Option 2 — General Written Authorization shall apply.
  3. The period for prior notice of a new or replacement Subprocessor under Clause 9(a) shall be fourteen (14) days, consistent with Section 9 of the DPA.
  4. The optional language in Clause 11 shall not apply.
  5. For Clause 17, the EU SCCs shall be governed by the laws of Ireland.
  6. For Clause 18, disputes arising from the EU SCCs shall be resolved before the competent courts of Ireland.

3. Annex I.A to the EU SCCs — List of Parties

3.1 Data Exporter.

Name: Customer or the applicable Authorized Affiliate.

Address: As stated in the Agreement, applicable order form or Customer account.

Contact details: As stated in the Agreement, applicable order form or Customer account.

Activities relevant to the transfer: Customer’s use of the Services under the Agreement.

Role: Controller where Module Two applies, or Processor where Module Three applies.

3.2 Data Importer.

Name: RunCloud Sdn Bhd

Company Registration No.: 201701034105 (1248276-T)

Country: Malaysia

Contact details: As stated in the Agreement or RunCloud’s applicable legal or privacy documentation.

Activities relevant to the transfer: Provision of the Services to Customer under the Agreement.

Role: Processor where Module Two applies, or Subprocessor where Module Three applies.

4. Annex I.B to the EU SCCs — Description of Transfer

For purposes of Annex I.B of the EU SCCs:

  1. Nature, purpose and subject matter of Processing: As described in Section 3.3 of the DPA.
  2. Categories of Data Subjects: As described in Section 3.4 of the DPA.
  3. Categories of Customer Personal Data: As described in Section 3.5 of the DPA.
  4. Sensitive Personal Data: As described in Section 3.6 of the DPA.
  5. Frequency of transfer: Customer Personal Data may be transferred on a continuous or as-needed basis for the duration of the applicable Services.
  6. Duration of Processing and retention: As described in Section 3.7 and Section 13 of the DPA.
  7. Purpose of transfer: To enable RunCloud to provide, operate, maintain, secure and support the Services in accordance with the Agreement, the DPA and Customer’s documented instructions.

Where sensitive, special-category or other regulated Personal Data is transferred, such Personal Data shall be subject to the applicable technical and organizational measures in Annex A and the confidentiality and access-control requirements of the DPA.

5. Annex I.C to the EU SCCs — Competent Supervisory Authority

The competent Supervisory Authority shall be determined in accordance with Clause 13 of the applicable EU SCC Module.

6. Annex II to the EU SCCs — Technical and Organizational Measures

The technical and organizational measures applicable to the relevant transfer are set out in Annex A (Technical and Organizational Measures).

Annex A forms the information required for Annex II of the EU SCCs.

7. Subprocessors

For purposes of Clause 9(a) of the EU SCCs, RunCloud’s appointment of Subprocessors shall be governed by Section 9 of the DPA.

The current list shall be made available to Customer upon request through RunCloud’s customer support.

8. UK International Data Transfer Addendum

8.1 Application. Where Section 14.3 of the DPA applies, the UK Addendum shall supplement the applicable EU SCCs identified in this Annex B.

8.2 Table 1 — Parties and Start Date.

  1. Start Date: The date on which the relevant restricted transfer begins.
  2. Exporter: Customer or the applicable Authorized Affiliate.
  3. Importer: RunCloud Sdn Bhd.

The parties’ details are those set out in Section 3 of this Annex B and the applicable Agreement.

8.3 Table 2 — Selected SCCs, Modules and Clauses. For purposes of Table 2 of the UK Addendum:

  1. The Approved EU SCCs are the EU SCCs identified in Section 1.1 of this Annex B.
  2. Module Two applies where Customer acts as a Controller and RunCloud acts as a Processor.
  3. Module Three applies where Customer acts as a Processor and RunCloud acts as a Subprocessor.
  4. Clause 7 does not apply.
  5. Clause 9(a), Option 2 — General Written Authorization applies.
  6. The notice period under Clause 9(a) is fourteen (14) days.
  7. The optional language in Clause 11 does not apply.

8.4 Table 3 — Appendix Information.

  1. Annex 1A — List of Parties: Section 3 of this Annex B.
  2. Annex 1B — Description of Transfer: Section 4 of this Annex B.
  3. Annex II — Technical and Organizational Measures: Annex A of the DPA.
  4. Annex III — Subprocessors: Section 9 of the DPA and Section 7 of this Annex B, to the extent applicable.

8.5 Table 4 — Ending the Addendum if the Approved Addendum Changes. For purposes of Table 4 of the UK Addendum, the Importer may exercise the termination right provided under the UK Addendum where the conditions for exercising that right are satisfied.

8.6 Mandatory Clauses. Part 2: Mandatory Clauses of the Approved Addendum, being the template Addendum B.1.0 issued by the ICO and laid before Parliament in accordance with section 119A of the Data Protection Act 2018 on 2 February 2022, as revised under Section 18 of those Mandatory Clauses.

9. Transfer Assessments

Where required for a transfer governed by the EU SCCs or UK Addendum, the parties shall comply with the applicable transfer assessment requirements.

RunCloud shall provide Customer with information reasonably available to RunCloud that is reasonably necessary to assist Customer with an applicable transfer assessment.

For clarity, RunCloud is not responsible for conducting Customer’s transfer assessment or determining the lawfulness of Customer’s transfer.

10. Execution and Conflict

By entering into the Agreement, the parties agree to be bound by the applicable EU SCCs and UK Addendum to the extent those instruments apply.

Nothing in this Annex B modifies the EU SCCs or UK Addendum in a manner prohibited by those instruments.

In the event of a conflict, the applicable EU SCCs or UK Addendum shall prevail to the extent of the conflict.