Data Processing Addendum

Last updated: 24 June 2026

This Addendum applies where Pointgate Systems Sdn Bhd processes personal data on behalf of a café (the "Customer") using SmartID Café, in line with Malaysia's PDPA 2010.

Roles

The Customer is the data controller for its diners' and staff's personal data; Pointgate acts as the data processor, processing data only on the Customer's documented instructions.

Scope of processing

We process order, menu, account and contact data solely to provide the service — for the duration of the agreement.

Sub-processors

We use vetted sub-processors (hosting, email, payments) under contracts that impose equivalent data-protection obligations.

Security

We apply appropriate technical and organisational measures, including access controls, encryption in transit, and regular backups.

Data subject requests & breaches

We assist the Customer in responding to data-subject requests and will notify the Customer without undue delay of any personal-data breach affecting their data.

Return & deletion

On termination, we return or delete Customer personal data on request, subject to any legal retention requirements.

Contact

Data protection enquiries: support@smartid.my.

This is a general template provided for convenience and is not legal advice. Final wording should be reviewed by a qualified adviser before launch.