Last updated 24 Sep 2026
Data Processing Agreement
This agreement forms part of the Terms of Service. It covers the personal data of your customers that you store in Lunas, and what we, as your data intermediary under Singapore's PDPA, commit to doing with it.
1.Roles
- You (the business with the account) are the organisation responsible for your customers' personal data under the PDPA.
- We ([Company name], UEN [UEN]) process it on your behalf and for your purposes only: a data intermediary.
- For data about you and your staff as users of Lunas, we are the responsible organisation; see the Privacy Policy.
2.What we process
| Individuals | Your customers (and anyone you record as a contact for them) |
| Data | Names, phone numbers, email and postal addresses, notes you write, orders, items, invoices, receipts, payments and payment references, pay-link activity (opened, terms accepted) |
| Purpose | Providing the service: records, invoices and receipts, PayNow QR codes, pay links, emails and reminders you ask for, exports |
| Duration | While your account is open, then deletion as in section 9 |
3.Only on your instructions
We process your customers' data only to provide the service as you use and configure it, or where the law requires (in which case we'll tell you first unless the law forbids it). We never use it for our own purposes, never sell it, and never use it to market to your customers.
4.Security measures
These are in place today:
- Separation: every record carries your business's id, and the database enforces it (row-level security), so no other business can read or change your data, even through a bug in the app. This is covered by automated tests.
- Least privilege: the app connects with a restricted database role that has no administrator rights.
- Integrity: issued invoices and recorded payments can't be edited or deleted, only voided with a reason; changes are written to an audit log.
- Location: data is stored in Singapore (database in ap-southeast-1, app in Singapore).
- Encryption in transit: HTTPS only, with strict transport security.
- Access: verified email sign-in, hashed passwords, rate-limited sign-in; pay links use long random codes stored only as hashes, expire and can be revoked.
- Devices: the installable app doesn't keep business data on the device.
[Before launch: confirm encryption at rest and backup/restore settings on the database plan, and list them here.]
5.People and confidentiality
Only people who need to (to run and support the service) can access your data, and they are bound to keep it confidential. We access your account's data only to fix a problem you reported, or where the law requires.
6.Sub-processors
We use these providers, each under a contract with data protection terms. We'll tell you by email at least 14 days before adding or replacing one, so you can object.
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database and file storage | Singapore |
| Vercel | Application hosting | Singapore |
| Resend | Sending invoice, receipt and reminder emails | [Confirm before launch] |
| Stripe | Our subscription billing (your account details only, not your customers') | Global |
7.Data breaches
If we believe a data breach has affected your customers' data, we'll tell you without undue delay, and in any case within 48 hours of becoming aware of it, with what we know and what we're doing about it. That lets you meet your own PDPA duties (assessing the breach and, where it's notifiable, telling the PDPC within 3 days and the affected people). We'll help with that assessment and notification.
8.Requests from individuals
If one of your customers asks us to see, correct or delete their data, we'll pass the request to you and help you respond: you can edit records in the app and export them at any time.
9.Return and deletion
You can export all your data as CSV at any time. When you close your account, we delete your customers' data within 30 days, except where the law requires us to keep something (and then only for as long as it requires).
10.Information and audits
We'll answer reasonable questions about how we protect your data, and provide information you need to show your own PDPA compliance. Contact hey@bindery.run.