Legal

Data Processing Agreement

This Data Processing Agreement (“DPA”) forms part of the Terms of Service between KSKILL INTEGRA SDN BHD (“Processor”) and the business customer (“Controller”) that subscribes to the KSKILL Integra Training Centre platform (the “Service”). B2B customers may print, sign, and countersign this page as a standalone contract.

Last updated: 15 August 2026

1. Definitions

  • Personal Data, Processing, Data Subject, Controller, and Processor have the meanings given in the Malaysia Personal Data Protection Act 2010 (“PDPA”) and, where applicable, the EU General Data Protection Regulation (“GDPR”).
  • Sub-processor means a third party engaged by Processor to Process Personal Data on Controller’s behalf.
  • Standard Contractual Clauses means the European Commission’s SCCs (Decision 2021/914), attached by reference for restricted transfers.

2. Subject matter and duration

Subject matter. Processor operates the Service on behalf of Controller and Processes Personal Data as needed to deliver it.

Duration. This DPA is effective from the date Controller first accesses the Service and continues for as long as Processor Processes Personal Data on Controller’s behalf.

3. Nature and purpose of Processing

Hosting, storing, transmitting, indexing, backing up, and displaying Personal Data so that Controller and its authorised users can administer training, deliver courses and assessments, communicate, issue certificates, and produce compliance reports.

4. Categories of Data Subjects

  • Controller’s administrators, instructors, and staff.
  • Learners and prospective learners.
  • External reviewers, examiners, and moderators.
  • Business contacts of Controller (e.g., partners, employers).

5. Categories of Personal Data

  • Identity — name, email, workspace role, locale, time zone.
  • Credential — MFA state, session identifiers. Password material is held by the identity provider, not in the application database.
  • Learning activity — enrolments, progress, lesson completions, assessment attempts and scores, uploaded assignments, issued certificates, awarded skills.
  • Communication — messages, discussion posts, help tickets, notifications.
  • Billing (where applicable) — organisation name, tax identifier, transaction references. Full card and bank details are held by the payment provider only.
  • Technical — IP address, user agent, audit-log entries with actor and resource identifiers.

Processor does not intentionally Process special-category data. If Controller uploads or asks its learners to upload special-category data (e.g., health data as part of a medical training programme), Controller is responsible for the lawful basis and any additional safeguards required.

6. Processor obligations

Processor will:

  • Process Personal Data only on documented instructions from Controller (the Terms and reasonable configuration through the Service qualify as documented instructions);
  • ensure that persons authorised to Process Personal Data are subject to written confidentiality obligations;
  • implement and maintain the technical and organisational measures in Section 9;
  • assist Controller in responding to Data Subject requests under Section 10;
  • assist Controller with data protection impact assessments and consultations with regulators where required;
  • on termination, delete or return Personal Data as instructed by Controller, subject to legal retention windows;
  • make available all information necessary to demonstrate compliance and permit audits as described in Section 11.

7. Controller obligations

Controller will:

  • establish the lawful basis for the Processing it directs;
  • issue notices and, where required, obtain consents from Data Subjects;
  • maintain accurate account and user data;
  • not upload content that infringes third-party rights or breaches applicable law.

8. Sub-processors

Controller authorises Processor to engage the following Sub-processors:

  • Cloudflare, Inc. — content delivery, DDoS mitigation, Zero Trust access.
  • Keycloak — identity and access management (may be self-hosted by Processor or, on request, deployed inside Controller infrastructure).
  • MinIO / S3-compatible object storage — file storage. Storage can be pinned to a Controller-owned bucket.
  • Payment providers — currently Billplz Sdn Bhd for Malaysian FPX and e-wallet payments; others may be added on notice.
  • AI providers — Anthropic PBC, OpenAI OpCo LLC, Google LLC (Gemini), DeepSeek Ltd, or a Controller-supplied self-hosted model. Each Controller selects the provider used inside its own workspace.
  • Resend, Inc. — outbound transactional email delivery.
  • LiveKit, Inc. — real-time video routing for live classes.

Processor will notify Controller at least 30 days before a new Sub-processor takes on regulated Processing. Controller may object on reasonable data-protection grounds within that window; if the parties cannot agree on a workaround, Controller may terminate the affected Service without penalty.

9. Security measures

Processor implements at minimum:

  • Encryption — TLS 1.3 in transit, encryption at rest at the database and storage layers, application-level encryption for secrets.
  • Tenant isolation — PostgreSQL row-level security (RLS) as the primary boundary; application code fails closed when the tenant claim is missing.
  • Access control — role-based capabilities, MFA available on every account, mandatory MFA for admin roles.
  • Audit — tamper-evident append-only audit log for admin and privileged actions.
  • Vulnerability management — dependency scanning on every build, coordinated disclosure programme, annual penetration test.
  • Backup and recovery — daily database backups with point-in-time recovery, offsite replication.
  • Physical security — data centres operated by Sub-processors under SOC 2 / ISO 27001.

10. Data Subject requests

Processor will forward any Data Subject request it receives to Controller within 5 business days and will assist Controller in responding using the export, edit, and delete tools built into the Service. Processor may charge only for assistance that goes beyond the tools already provided.

11. Audit rights

Processor will make available its most recent security summary and, on 30 days written notice, permit Controller (or an independent auditor bound by confidentiality obligations) to audit the Service during business hours at Controller’s cost, no more than once every 12 months, unless a regulator requires more frequent access.

12. International transfers

Where Personal Data is transferred outside Malaysia or (for EU Data Subjects) outside the EEA, the parties incorporate the Standard Contractual Clauses (Module 2, Controller-to-Processor), including the transfer impact assessment obligations. Cloudflare edge caching may briefly Process request metadata globally; content itself remains in the region configured for Controller.

13. Breach notification

Processor will notify Controller without undue delay and in any event within 72 hours of becoming aware of a Personal Data breach affecting Controller’s data. The notification will describe the nature of the breach, the categories and approximate number of Data Subjects and records affected, the likely consequences, and the measures taken or proposed.

14. Return and deletion on termination

On termination Processor will make Controller Personal Data available for export in a machine-readable format for 30 days, then delete it, except where retention is required by law (e.g., financial records for 7 years under Malaysian tax law). Backups age out under Processor’s standard rotation, no later than 90 days.

15. Liability

Each party’s liability under this DPA is subject to the limitations in the Terms of Service. Nothing in this DPA excludes liability that cannot be excluded under applicable law.

16. Order of precedence

In case of conflict between this DPA, the Terms of Service, and any signed order form, the order of precedence is: signed order form, this DPA, Terms of Service.

17. Governing law

This DPA is governed by the laws of Malaysia, without prejudice to mandatory data-protection law that applies to a given Processing activity.


Signature

Two-way signatures are accepted electronically. To countersign this DPA, print, sign, and return to [email protected] — a countersigned copy will be returned within 5 business days.

Processor

KSKILL INTEGRA SDN BHD

Name / title

Date

Controller

________________________

Name / title

Date

Data Processing Agreement — KSKILL Integra Training Centre