Legal
Data Processing Addendum (DPA)
Last updated on Aug 2026
This data processing addendum ("DPA") shall govern the Processing of Licensee Personal Data in connection with the Software licensed under the Enterprise Software Licence Agreement ("Licence Agreement") entered into between you (the "Licensee") and ZIIKR Pte. Ltd., a company incorporated in Singapore with a registered office at #01-08, 2 Science Park Drive, Singapore 118222 (the "Licensor").
In consideration of the mutual obligations set out in this DPA, the Parties agree that the provisions set out in this DPA are supplemental to the relevant Licence Agreement and shall form part of the Licence Agreement. In the event of any conflict or inconsistency between the provisions of this DPA and the provisions of the Licence Agreement in connection with the Processing of Licensee Personal Data, the provisions of this DPA shall take precedence.
Except where the context requires otherwise, references in this DPA to the Licence Agreement are to the Licence Agreement as amended by, and including, this DPA.
1. Definitions and Interpretation
In this DPA, the following terms shall have the meanings set out below and cognate terms shall be construed accordingly:
Applicable Data Protection Laws means all applicable laws relating to the protection of Personal Data, as amended, updated or replaced from time to time, which apply to the Licensor or Licensee in connection with the Processing of Licensee Personal Data governed by this DPA, including but not limited to: (a) Regulation (EU) 2016/679 of the European Parliament and of the Council (the “GDPR”); (b) the UK version of the GDPR as incorporated into UK law (the “UK GDPR”) and the Data Protection Act 2018; (c) the Personal Data Protection Act 2012 of Singapore (“PDPA”); and (d) any other applicable data protection or privacy laws, regulations, or binding requirements in the relevant jurisdiction.
"Controller", "Data Subject", "Personal Data", "Personal Data Breach", "Process", "Processor" and "Special Categories of Personal Data" have the meanings described in the Applicable Data Protection Laws and cognate terms shall be construed accordingly;
Authorised Licensees has the meaning given to that term in the Licence Agreement;
Licensee Data has the meaning given to that term in the Licence Agreement;
Licensee Personal Data means Personal Data contained in the Licensee Data and Processed by the Licensor under this DPA;
Licensor Privacy Notice means the Licensor's privacy notice found at https://notewise.dev/privacy-policy;
Party means a party to this DPA; and
Software has the meaning given to that term in the Licence Agreement.
2. Compliance
Each Party shall comply with Applicable Data Protection Laws when Processing Licensee Personal Data in connection with this DPA.
The Licensee shall:
ensure that all Licensee Personal Data has been collected and provided to the Licensor in compliance with Applicable Data Protection Laws and, where required by the Applicable Data Protection Laws, shall obtain Data Subjects’ consent prior to providing their Personal Data to the Licensor;
notify Data Subjects that their Personal Data may be provided to the Licensor;
ensure that all Licensee Personal Data is accurate, and where appropriate kept up to date; and
notify the Licensor if it becomes aware that any Licensee Personal Data is inaccurate.
If, during the term of this DPA, Applicable Data Protection Laws change in a manner that requires changes to this DPA in order for the Processing of Licensee Personal Data to remain compliant, the Licensor may make such amendments to this DPA as it reasonably considers necessary to address that change. Any such amendment will be published at https://www.notewise.dev/data-processing-addendum and will take effect from the date stated in the updated DPA or as otherwise required by Applicable Data Protection Laws. Where required by Applicable Data Protection Laws, the Licensor will provide additional notice of material changes.
This DPA shall terminate upon expiration or termination of the Licence Agreement.
Where the Licensee Personal Data is provided to the Licensor by an Authorised Licensee or generated as a result of an Authorised Licensee's use of the Software, the Licensee shall procure that the relevant Authorised Licensee shall agree to, and comply with, the provisions set out in this DPA and that:
references in the provisions of this DPA to "Party" or "Parties" shall be deemed to include "the relevant Authorised Licensee" as appropriate; and
references in the provisions of this DPA to "the Licensee" shall be replaced with "the relevant Authorised Licensee".
3. Obligations when Processing Licensee Personal Data as a Controller
The Parties acknowledge and agree that the Licensor shall in certain circumstances Process Licensee Personal Data as an independent Controller, and the circumstances under which it Processes Licensee Personal Data as an independent Controller are set out in the Licensor Privacy Notice.
To the extent that the Licensor is acting as an independent Controller of Licensee Personal Data under this DPA:
the Licensee agrees to bring the Licensor Privacy Notice to the attention of Data Subjects whose Personal Data may be Processed by the Licensor in connection with this DPA;
each Party shall, at the other Party's sole expense, provide the other Party with such co-operation as reasonably requested to assist the other Party’s compliance with its obligations under Applicable Data Protection Laws in relation to the Licensee Personal Data; and
the Licensor shall notify the Licensee upon becoming aware of any Personal Data Breach affecting the Licensee Personal Data.
4. Obligations when Processing Licensee Personal Data as a Processor
Except to the extent that the Licensor Processes Licensee Personal Data as an independent Controller pursuant to Clause 3, the Parties acknowledge and agree that the Licensor will Process Licensee Personal Data as a Processor on behalf of the Licensee. The details of this Processing activity are set out in Appendix 1 (Data Processing Details).
To the extent that the Licensor is acting as a Processor of Licensee Personal Data under this DPA, the Licensor shall:
process Licensee Personal Data on the documented instructions of the Licensee, in order to supply its services and the Software, and as otherwise necessary to perform its obligations under the Licence Agreement unless required to do otherwise by applicable law, in which case the Licensor, if permitted by such law, shall inform the Licensee of that legal requirement before such Processing;
ensure that persons authorised to process the Licensee Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality;
implement and maintain appropriate technical and organisational measures to protect against unauthorised or unlawful Processing of the Licensee Personal Data and against accidental loss or destruction of, or damage to, the Licensee Personal Data, appropriate to the harm that might result and the nature of the Licensee Personal Data to be protected, having regard to the state of technological development and the cost of implementing any measures;
be generally authorised by the Licensee to engage another Processor to Process the Licensee Personal Data ("Subprocessor"), provided that the Licensor maintains a list of such Subprocessors (which can be found below in Appendix 2) and subject to (i) the Licensor ensuring that the Subprocessor enters into binding contractual obligations which are substantially similar to those set out in Clause 4.2 of this DPA and (ii) the Licensor remaining fully liable to the Licensee for the performance by such Subprocessor of such obligations. The Licensor will provide notice of the addition or replacement of Subprocessors at least fourteen (14) calendar days in advance of the change becoming effective, during which period the Licensee may raise a reasonable objection to the proposed Subprocessor on legitimate data protection grounds. If such an objection is raised within this fourteen (14)-day notice period, the Parties shall discuss in good faith a reasonable resolution to the objection;
taking into account the nature of the Processing, assist the Licensee by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Licensee's obligation to respond to requests from Data Subjects to exercise their rights laid down in Applicable Data Protection Laws in relation to the Licensee Personal Data;
notify the Licensee without undue delay of any Personal Data Breach in relation to the Licensee Personal Data upon becoming aware of the same, and provide all information reasonably required by the Licensee to comply with its obligations under Applicable Data Protection Laws in relation to such Personal Data Breach, and assist the Licensee with its obligations pursuant to Applicable Data Protection Laws in relation to data protection impact assessments and prior consultations with relevant data protection authorities (and with any similar obligations under other Applicable Data Protection Laws) taking into account the nature of the Processing and information available to the Licensor;
not transfer the Licensee Personal Data outside of the EU, UK or a jurisdiction in respect of which there has been a finding of adequacy by the European Commission pursuant to Article 45 of the GDPR or by the Secretary of State pursuant to Article 45 of the UK GDPR (as applicable) (Relevant Jurisdictions) unless it ensures that any such transfer of Licensee Personal Data outside the Relevant Jurisdictions is subject to appropriate safeguards as recognised by Applicable Data Protection Laws;
not transfer Licensee Personal Data to a country or territory unless the transfer is permitted under Applicable Data Protection Laws and, where required, is subject to an applicable adequacy decision, legally recognised transfer mechanism, contractual safeguards, or other appropriate safeguards;
where Licensee Personal Data subject to the GDPR is transferred to a country or recipient that is not covered by an applicable adequacy decision and the transfer requires appropriate safeguards under Chapter V of the GDPR, the Parties will rely on the applicable Standard Contractual Clauses adopted by the European Commission, including the applicable module based on the Parties’ roles, together with any supplementary measures required by Applicable Data Protection Laws;
where Licensee Personal Data subject to the UK GDPR is transferred in circumstances constituting a restricted transfer, the Parties will rely on an appropriate transfer mechanism recognised under the UK GDPR, which may include the UK International Data Transfer Agreement or the UK International Data Transfer Addendum to the European Commission Standard Contractual Clauses, as applicable; and
where Licensee Personal Data is transferred outside Singapore, the Licensor will take appropriate steps as required under the PDPA to ensure that the transferred Personal Data receives a standard of protection comparable to that provided under the PDPA.
upon the termination or expiry of the relevant Licence Agreement and at the Licensee's option, either return or delete all copies of the Licensee Personal Data Processed by the Licensor, unless applicable law requires the continued storage of such Licensee Personal Data;
make available to the Licensee on request all information necessary to demonstrate compliance with Article 28 of the UK GDPR and GDPR (and with any similar requirements under other Applicable Data Protection Laws) in relation to its Processing of Licensee Personal Data and shall, no more than once per calendar year, during the Licensor's normal business hours and subject to reasonable prior written notice and upon agreeing appropriate confidentiality provisions, allow for and contribute to audits, including inspections, by the Licensee or an auditor mandated by the Licensee.
5. General Terms
Except as expressly provided in this DPA, including in relation to amendments required as a result of changes to Applicable Data Protection Laws, no variation of this DPA will be effective unless agreed in writing by the Parties.
APPENDIX 1 – DATA PROCESSING DETAILS
This Appendix 1 forms part of the DPA and describes the Processing of Licensee Personal Data that the Licensor will perform on behalf of Licensee.
A. Subject matter and duration of the Processing of the Personal Data:
The subject matter of the Processing of the Licensee Personal Data is set out in the Licence Agreement.
The duration of the Processing of the Licensee Personal Data is for the term of the Licence Agreement.
B. The nature and purpose of the Processing of the Personal Data:
The nature and purpose of the Processing of Licensee Personal Data is to provide, administer, secure, support, and maintain the Software and related services provided to the Licensee, including organization and administrator account management, eligibility and domain verification, licence allocation and activation, device and licence management, billing and transaction administration, customer support, troubleshooting, service analytics, security, fraud prevention, and compliance with applicable legal obligations.
C. The type of Personal Data:
The Licensee Personal Data Processed may include some or all of the following:
(i) personal identifiers and contact information, including names and email addresses;
(ii) organization or educational institution information, including organization name, email domain, country or region, address, and relevant administrator or representative information;
(iii) administrator and account-management information, including configured access or licence policies;
(iv) licence activation and usage information, including device identifiers, licence assignments, activation events, quotas, and related service usage information;
(v) billing, invoice, and transaction information relating to the Licensee's purchase and management of licences, excluding full payment card details where those details are processed directly by third-party payment processors;
(vi) diagnostic and technical information voluntarily provided or generated for troubleshooting, customer support, security, or service reliability purposes; and
(vii) communications and other information voluntarily provided by the Licensee or an Authorised Licensee to the Licensor in connection with administration, support, or use of the Software.
For clarity, the ordinary Processing covered by this DPA does not include the content of end-user notes stored locally on an Authorised Licensee's device, except where such content is expressly provided to the Licensor by the Licensee or Authorised Licensee for support or another separately agreed purpose
D. Special Categories of Personal Data:
The Software does not require or intend for the Licensee to provide Special Categories of Personal Data to the Licensor as part of the ordinary services covered by this DPA. The Licensee shall not intentionally provide Special Categories of Personal Data to the Licensor unless such Processing has been separately agreed in writing and is carried out in accordance with Applicable Data Protection Laws.
E. The categories of Data Subject to whom the Licensee Personal Data relates:
The categories of Data Subject may include the Licensee's and Authorised Licensees' users of the Software, administrators, authorized representatives, billing or procurement contacts, and other individuals whose Personal Data is provided to the Licensor in connection with the Licence Agreement.
F. The obligations and rights of the Licensee:
The obligations and rights of the Licensee are set out in the Licence Agreement.
APPENDIX 2 – SUBPROCESSORS
The Licensor uses the following Subprocessors:
Amazon Web Services
Cloudflare
Google
RevenueCat
SendGrid
Stripe


