Logo
Logo
Pricing

Data Processing Addendum

Last updated:

This Data Processing Addendum ("DPA") forms part of the OhhWells Terms of Service between OhhWells Pte. Ltd. ("OhhWells", the "Processor") and the customer that accepts the Terms ("Customer", the "Controller"). It applies whenever OhhWells processes personal data of the Customer's site visitors, leads, bookers or buyers ("Customer Data") on the Customer's behalf.

3.1 Roles

Customer is the controller (PDPA: organisation) of Customer Data and determines why and how it is processed. OhhWells is the processor (PDPA: data intermediary) and processes Customer Data only to provide the Services and on Customer's documented instructions, which include the Terms, the Customer's use of the product's settings, and any written instructions. OhhWells will tell Customer if it believes an instruction breaks the law.

3.2 Details of processing

  • Subject matter: hosting the Customer's website; storing and forwarding form submissions, bookings and lead-capture data; displaying and managing the Customer's storefront up to checkout.
  • Duration: the life of the Customer's account plus the 30-day export window.
  • Nature and purpose: storage, transmission, display, notification and backup.
  • Data subjects: the Customer's website visitors, leads, customers and bookers.
  • Types of data: name, email, phone, messages, booking details, order and shipping details, and any other fields the Customer adds to a form. Payment card data is processed by Stripe under the Customer's own Stripe account and never touches OhhWells systems.

3.3 OhhWells' obligations

OhhWells will:

  • keep Customer Data confidential and ensure its staff and contractors are bound by confidentiality;
  • implement the security measures in Section 3.6;
  • help Customer respond to data-subject requests (access, correction, deletion, portability) relating to Customer Data, by providing tools in the product or assistance on request;
  • notify Customer without undue delay, and in any case within 72 hours, after becoming aware of a personal-data breach affecting Customer Data, and provide what is known about its nature, scope and remediation;
  • help Customer with data-protection impact assessments and regulator consultations where reasonably needed;
  • delete or return Customer Data within 90 days of account termination (subject to the 30-day export window in the Terms), unless the law requires retention;
  • make available the information reasonably needed to show compliance with this DPA, and allow one audit per year on 30 days' notice, at Customer's cost, by Customer or an independent auditor bound by confidentiality.

3.4 Subprocessors

The following subprocessors may process Customer Data, and Customer authorises their use:

SubprocessorPurposeLocation
Vercel Inc.Hosting and content delivery for Customer sites and form and booking submissionsUnited States (global edge)
Sanity.io ASContent storage for site copy and assetsUnited States / EU
Resend, Inc.Transactional email — form and booking notifications sent to CustomerUnited States
Scroll horizontally to see the full table →

Other vendors named in the OhhWells Privacy Policy (Stripe, Anthropic, Loops, PostHog, Google, Meta, Slack, Zapier) process data about OhhWells' own users, billing and marketing site — not Customer Data — and are therefore not subprocessors under this DPA.

OhhWells will give at least 30 days' notice by email before adding or replacing a subprocessor that processes Customer Data. Customer may object on reasonable data-protection grounds within that period; if the parties cannot resolve the objection, Customer may terminate the affected Services. OhhWells remains responsible for its subprocessors.

3.5 International transfers

Where Customer Data is transferred out of the country in which it was collected, OhhWells will ensure a standard of protection comparable to the PDPA's Transfer Limitation Obligation. For personal data subject to EU or UK law, the parties incorporate the EU Standard Contractual Clauses (Module 2, controller-to-processor) and the UK International Data Transfer Addendum, with Customer as data exporter and OhhWells as data importer, and Singapore law and courts for the optional clauses.

3.6 Security measures

  • Encryption in transit (TLS 1.2+) and at rest at hosting and database providers.
  • Role-based access with least privilege; multi-factor authentication for OhhWells staff on production systems.
  • Logical separation of each Customer's data.
  • Automated backups and tested restore procedures.
  • Vendor due diligence and written data-processing terms with every subprocessor.
  • Incident-response procedure with defined roles and the 72-hour notification commitment above.

3.7 Customer's obligations

Customer is responsible for: having a lawful basis to collect Customer Data; publishing a privacy notice on its site; obtaining any required consents (including cookie consent for tools the Customer adds); keeping its login credentials secure; and configuring forms so that it does not collect more data, or more sensitive data, than it needs.

3.8 General

This DPA prevails over the Terms in case of conflict about personal data. Liability under this DPA is subject to the limits in the Terms. This DPA is governed by Singapore law. Either party may request a countersigned copy at support@ohhwells.com.