PocketBay Data Processing Addendum and Subprocessor Notice PocketBay Technologies Limited | pocketbay.com Last Updated / 最后更新: 2026-07-08 Effective Date / 生效日期: 2026-07-08 Public URL / 建议公开地址: /legal/dpa Contact / 联系方式: support@pocketbay.com
Implementation Note
This document is for enterprise customers, developers processing end-user data, privacy compliance, subprocessor disclosure and data-processing role descriptions.
Scope and Roles
This Data Processing Addendum and Subprocessor Notice applies where PocketBay processes Customer Personal Data on behalf of a customer and supplements the Terms. If you use PocketBay only as an individual user, this document may not apply; if you use PocketBay as an enterprise, team, developer or controller to process end-user, customer, employee or other personal data, this document may serve as the basis for the parties' data-processing arrangement unless the parties sign a separate DPA.
Generally, you are the controller/business for Customer Personal Data and PocketBay is the processor/service provider. For PocketBay's own account, billing, security, support, marketing and platform operations data, PocketBay generally acts as an independent controller and the Privacy Policy applies.
If applicable law requires more specific data-processing terms, standard contractual clauses, cross-border transfer mechanisms, audit rights, industry compliance commitments or customer-specific security annexes, you should sign a separate written agreement with PocketBay.
Processing Instructions, Purposes and Data Types
PocketBay will process Customer Personal Data according to the Terms, product configuration, your instructions, documentation, orders, support requests and applicable law. Processing purposes include providing, maintaining, protecting, supporting, troubleshooting, backing up, restoring, billing, optimizing, complying with law and improving the Service.
Customer Personal Data may include end-user data, account information, project data, logs, IP addresses, device information, configurations, communications, support information, application data, database content, uploaded files, AI diagnostic context and other personal data you submit or process through the Service. Data subjects may include your users, customers, employees, contractors, administrators, developers and other individuals.
You are responsible for ensuring processing instructions are lawful, transparent and clear, and that you have all notices, consents, contracts, legitimate interests, authorizations or other legal bases required to process Customer Personal Data.
Security Measures and Confidentiality
PocketBay will implement reasonable technical and organizational measures to protect Customer Personal Data, including appropriate access controls, permission management, transmission protection, logging, isolation, monitoring, vulnerability remediation, confidentiality obligations for personnel/contractors and security incident response. Specific measures may change with technology, risk, service types and upstream services.
PocketBay does not by default commit to any specific certification or regulatory framework, such as HIPAA, PCI DSS, SOC 2, ISO 27001, GDPR, CCPA, PDPA, financial, healthcare or government compliance, unless PocketBay expressly confirms in writing. You must not process data requiring specific certification or special regulation without written consent.
You are responsible for configuring reasonable security settings, access permissions, secrets, backups, log redaction, application security, database security, end-user notices and compliance measures.
Subprocessors, Third-Party Services and Cross-Border Transfers
You authorize PocketBay to use subprocessors and third-party service providers to provide the Service, including cloud infrastructure, storage, databases, CDNs, domains, certificates, payments, KYC/KYB, email, SMS, identity, AI models, monitoring, logging, analytics, security, support, tax and legal providers. PocketBay will require subprocessors to undertake confidentiality and data-protection obligations appropriate to their processing activities.
PocketBay may update the subprocessor list, service regions, data-transfer paths and upstream services. If you have a reasonable data-protection objection to a new subprocessor, send it to support@pocketbay.com within a reasonable period after notice or publication; PocketBay may explain, provide alternatives, restrict functionality or allow you to stop the relevant service.
The Service may involve cross-border transfers. You are responsible for determining whether cross-border transfers are lawful and obtaining necessary consents, assessments, contracts, filings or other mechanisms. PocketBay may process or store data according to actual service architecture and upstream arrangements.
Data Subject Requests, Deletion and Audit
If PocketBay receives a data-subject request, regulatory request or complaint relating to your Customer Personal Data, PocketBay may refer it to you and provide reasonable assistance. You are responsible for responding to data-subject requests unless applicable law requires PocketBay to respond directly.
Upon service termination, project deletion or your reasonable request, PocketBay will delete, anonymize, export or retain Customer Personal Data according to service functionality, system cycles, backup cycles, legal, billing, security, dispute and compliance needs. PocketBay does not guarantee immediate deletion from all backups or logs.
Subject to reasonable request, applicable law and confidentiality restrictions, PocketBay may provide security descriptions, policy summaries, third-party audit materials or reasonable questionnaire responses. Any onsite audit, penetration test, log export, source-code review or customer-specific audit requires prior written approval and must not jeopardize PocketBay, other users or upstream-service security.