Data Processing Addendum
Last updated: 24 June 2026
This Addendum applies where Pointgate Systems Sdn Bhd processes personal data on behalf of a café (the "Customer") using SmartID Café, in line with Malaysia's PDPA 2010.
Roles
The Customer is the data controller for its diners' and staff's personal data; Pointgate acts as the data processor, processing data only on the Customer's documented instructions.
Scope of processing
We process order, menu, account and contact data solely to provide the service — for the duration of the agreement.
Sub-processors
We use vetted sub-processors (hosting, email, payments) under contracts that impose equivalent data-protection obligations.
Security
We apply appropriate technical and organisational measures, including access controls, encryption in transit, and regular backups.
Data subject requests & breaches
We assist the Customer in responding to data-subject requests and will notify the Customer without undue delay of any personal-data breach affecting their data.
Return & deletion
On termination, we return or delete Customer personal data on request, subject to any legal retention requirements.
Contact
Data protection enquiries: support@smartid.my.
This is a general template provided for convenience and is not legal advice. Final wording should be reviewed by a qualified adviser before launch.