Điều Khoản Khách Hàng

Data Processing Addendum

Cập nhật lần cuối: July 31, 2026

This Data Processing Addendum ("DPA") forms part of the agreement between the Acua entity identified in the applicable Order Form or other written agreement ("Acua") and the customer identified there ("Customer") for the Acua platform and related services (the "Agreement"). Depending on where the services are sold or delivered, Acua may be Acua (Thailand) Co., Ltd., Acua Co., Ltd. in Japan, or Acua Vietnam Co., Ltd. It reflects and supplements the data protection terms of the Master Service Agreement, including Section A.7 (Data Protection).

No separate signature is required for this DPA to apply; it applies automatically whenever Acua processes personal data on behalf of Customer as a data processor. The parties may additionally execute this DPA or a customer-specific data processing agreement where required.

This DPA is provided in English, and the English version prevails over any translation.

1. Definitions

"Thailand PDPA" means the Personal Data Protection Act B.E. 2562 (2019) of Thailand and its implementing regulations. "Japan APPI" means Japan's Act on the Protection of Personal Information and applicable Personal Information Protection Commission rules. "Vietnam PDPL" means Vietnam's Law No. 91/2025/QH15 on Personal Data Protection, Decree No. 356/2025/ND-CP, and applicable implementing rules. "Data Protection Law" means those laws and any other data protection law applicable to processing under the Agreement, including the EU/UK GDPR where applicable.
"Customer Data" means data provided by or for Customer to Acua in connection with the services, as defined in the Agreement. "Customer Personal Data" means personal data contained in Customer Data that Acua processes on behalf of Customer.
"Affiliate" means an entity that controls, is controlled by, or is under common control with Acua. "Subprocessor" means an Affiliate or third party engaged by Acua to process Customer Personal Data on Acua's behalf. Terms such as "controller", "processor", "data subject", "personal data", and "processing" have the meanings given under applicable Data Protection Law.

2. Roles of the Parties

For Customer Personal Data uploaded, entered, or transmitted through the services for Customer's business operations (including invoices, receipts, supplier records, customer records, employee records, and transaction data), Customer is the data controller and Acua is the data processor.
Acua acts as an independent data controller for personal data of Customer's representatives that Acua collects for its own contracting, billing, account management, customer relationship, and internal compliance purposes; such processing is described in the Acua Privacy Policy.
Customer is responsible for ensuring that it has all necessary legal bases, consents, and notices under Data Protection Law to provide Customer Personal Data to Acua and to permit the processing described in the Agreement and this DPA.

3. Processing Instructions

Acua processes Customer Personal Data only on documented instructions from Customer, including the Agreement, this DPA, Customer's configuration and use of the services, and other written instructions agreed by the parties.
Acua will inform Customer if, in its opinion, an instruction infringes applicable Data Protection Law, unless prohibited from doing so by law.
Acua does not sell Customer Personal Data and does not use Customer Data to train general-purpose AI models, except with Customer's prior written consent or where the data has been aggregated or anonymized so that it does not identify Customer, any authorized user, or any data subject and cannot reasonably be re-identified.

4. Details of Processing

Subject matter and duration: the provision of the Acua platform and related services for the term of the Agreement, plus the post-termination retention period described in Section 10.
Nature and purpose: hosting, storage, digitization and data extraction, workflow processing, display, transmission, export, backup, and related operations necessary to provide the services described in the Agreement.
Categories of data subjects: Customer's personnel and authorized users; personnel of Customer's suppliers, vendors, and business partners; and other individuals whose personal data is contained in documents or records submitted to the services.
Categories of personal data: business contact details (name, title, email, phone), organizational information, invoice and payment-related information (including bank account details of payees), employment-related information contained in expense and reimbursement records, and other personal data contained in Customer Data. The services are not designed for special category (sensitive) personal data, and Customer agrees not to submit it except where strictly necessary and lawful.

5. Confidentiality

Acua ensures that personnel authorized to process Customer Personal Data are bound by confidentiality obligations, and limits access to personnel who need it to provide the services.

6. Security Measures

Acua implements and maintains appropriate technical and organizational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, including: role- and permission-based access control with least-privilege defaults and tenant isolation; encryption of data in transit (TLS 1.2 or higher) and at rest; authenticated AES-256-GCM encryption for sensitive integration credentials, with secrets held in managed secret storage; controlled network ingress with no direct public access to primary data stores; centralized logging, monitoring, and audit trails; secure development practices with peer review and automated testing; and automated daily backups with point-in-time recovery.
Details of Acua's operational practices for availability, backup, disaster recovery, and support are published in the Acua Service Policy.

7. Personal Data Breach Notification

As Customer's data processor, Acua will notify Customer of any confirmed personal data breach affecting Customer Personal Data without undue delay after becoming aware of it and, as a contractual maximum, within 72 hours. This processor-to-controller notice does not replace Customer's own assessment or notification obligations as data controller.
The notification will describe, to the extent then known: the nature of the breach; the categories and approximate number of data subjects and records affected; the likely consequences; and the measures taken or proposed to address the breach and mitigate its effects. Customer is responsible for determining whether notice to the Thailand Personal Data Protection Committee, Japan Personal Information Protection Commission, the competent Vietnamese personal-data-protection authority, affected data subjects, or another authority is required. Acua will provide reasonable cooperation and information to support those obligations.

8. Subprocessors

Customer provides a general authorization for Acua to engage Subprocessors, including Acua Affiliates that provide product development, engineering, local service delivery, support, and administration, and third-party cloud infrastructure, document processing, analytics, and support providers. The current list of material Subprocessors and their processing regions is published on the Acua Subprocessors page.
Acua will notify Customer of any new material Subprocessor at least 30 days before the change. If Customer objects in writing within 15 days of the notice on reasonable data protection grounds, the parties will negotiate in good faith; if no resolution is reached within 30 days, Customer may terminate the affected services with a pro-rata refund of prepaid fees, as set out in the Agreement.
Acua imposes data protection obligations on each Subprocessor that are substantially equivalent to those in this DPA and remains responsible for its Subprocessors' processing of Customer Personal Data.

9. Data Subject Requests and Assistance

The services provide functionality that enables Customer to access, correct, export, and delete Customer Personal Data. Taking into account the nature of the processing, Acua will provide reasonable assistance to Customer in fulfilling its obligations to respond to data subject requests under Data Protection Law.
If Acua receives a request directly from a data subject relating to Customer Personal Data, Acua will, to the extent legally permitted, forward the request to Customer and will not respond except to direct the data subject to Customer.
Acua will provide reasonable assistance to Customer with data protection impact assessments and consultations with supervisory authorities, to the extent required under Data Protection Law and related to the services.

10. Return and Deletion of Customer Personal Data

During the term and for 30 days after termination, Customer may request an export of Customer Data in a commonly used format (such as CSV, JSON, or Excel).
After termination, cancellation, or expiration of the subscription, Acua retains Customer Data for 90 days for export, reinstatement, billing, and compliance purposes, after which Customer Data in the active production environment is deleted or anonymized, unless retention is required by applicable law. Customer may request early deletion, which Acua will fulfil within 30 days of confirmation where practicable. Data in backups is removed in accordance with the normal backup retention cycle.
Upon reasonable request, Acua will confirm the status of the deletion process.

11. Cross-Border Transfers

Acua may process and store Customer Personal Data in Thailand and permit role-based access from Japan and Vietnam through Acua Affiliates. Acua Vietnam principally provides product development and engineering support and may also support local customer delivery. Third-party Subprocessors may process data in the regions published on the Acua Subprocessors page. Remote access from another country is treated as a cross-border transfer where required by Data Protection Law.
Acua implements the safeguards required by the law of the transfer origin: Thailand PDPA sections 28 and 29 and applicable PDPC notifications; Japan APPI requirements for foreign third-party provision and service-provider supervision; and Vietnam PDPL requirements, including transfer-impact documentation and regulatory filings where required. Safeguards may include intra-group and vendor data-processing and transfer terms, ASEAN Model Contractual Clauses or equivalent binding arrangements, transfer-risk review, data minimization, encryption, logging, and access controls.

12. Audit and Information

Upon Customer's reasonable written request, Acua will make available information reasonably necessary to demonstrate compliance with this DPA, including summaries of relevant security documentation and third-party assessments where available.
Where the information provided is not reasonably sufficient, Customer may conduct (directly or through an independent auditor bound by confidentiality) an audit of Acua's processing of Customer Personal Data, no more than once per 12-month period, on at least 30 days' written notice, during business hours, without disruption to Acua's operations, at Customer's cost, and subject to reasonable confidentiality and security requirements. Audits do not extend to other customers' data or to Subprocessor facilities operated by hyperscale cloud providers, for which provider attestations are relied upon.

13. Liability, Term, and Governing Law

The liability of each party under this DPA is subject to the limitations and exclusions of liability set out in the Agreement.
This DPA applies for as long as Acua processes Customer Personal Data on behalf of Customer.
This DPA is governed by the law governing the Agreement. In the event of a conflict between this DPA and the Agreement with respect to the processing of Customer Personal Data, this DPA prevails to the extent of the conflict.