Data Processing Addendum
Version 2.0, effective 27 July 2026. This Data Processing Addendum (DPA) forms part of our Terms of Service and applies whenever 6 Seven Labs Pte Ltd processes personal data on behalf of a client in delivering the Service.
1. How this addendum applies
This Data Processing Addendum (DPA) forms part of our Terms of Service and applies whenever 6 Seven Labs Pte Ltd processes personal data on behalf of a client in delivering the Service. It takes effect for a client when the client accepts the Terms or continues to use the Service after this DPA is published. No signature is required. Clients whose procurement process requires a countersigned copy may request one; we countersign this published text as it stands, with client-specific particulars recorded in the Order Form.
2. Roles and the law
The client decides the purposes for which prospect and contact data is processed and is the organisation responsible for it under Singapore's Personal Data Protection Act 2012 (PDPA). We process that data on the client's behalf and documented instructions as a data intermediary. Some duties apply to us directly under the Act, including the obligations to protect personal data in our possession, not to retain it longer than needed, and to notify the client without undue delay if we become aware of a data breach affecting it. Data about the client's own account, users, and billing is processed for our own purposes and is covered by our Privacy Policy rather than this DPA.
3. The data we process for you
Processing under this DPA typically covers: prospect and contact records the client uploads or connects (names, business phone numbers, business email addresses, company details); call recordings and transcripts generated when the Service places or receives calls for the client; and related call outcomes and notes. The Service is not designed for special categories of sensitive data (for example medical details, financial account numbers, or government identifiers), and the client agrees not to submit them.
4. How we process it
We process client personal data only to deliver, secure, and support the Service, and only on the client's documented instructions, which are given through the Terms, the Order Form, and the client's configuration of the Service. We will inform the client if a legal requirement prevents us from following an instruction, and, unless legally prohibited, we will notify the client before complying with a demand from an authority to disclose client personal data. We may produce aggregated or de-identified statistics that no longer identify any individual; these fall outside this DPA. The client warrants that it has the legal right to have the data processed as instructed.
5. Confidentiality
Everyone we authorise to process client personal data is bound by confidentiality obligations.
6. Security
We protect client personal data with measures including: encryption in transit and at rest; separation of each client's data by workspace; invite-only portal access with one-time login codes; two-factor authentication on administrative accounts; and access for our personnel limited to what their role requires. We may update these measures as the Service evolves, provided the overall level of protection is not materially reduced.
7. Sub-processors
The client authorises us to use sub-processors in these categories: cloud infrastructure and hosting; AI voice processing; telecommunications carriage; database and application platforms; payment processing (Stripe); email delivery; and support tooling. Our cloud layer runs on AWS. A current named list is available on written request to loading…. We will give at least 14 days' notice by email or through the portal before a new or replacement sub-processor processes client personal data. A client may object within the notice period on reasonable data protection grounds; if we cannot resolve the objection, the client may cancel the affected Service as set out in the Terms. We remain responsible for our sub-processors and impose data protection obligations on them consistent with this DPA.
8. Where data is processed
Client personal data is processed in Singapore and the United States. Where personal data is transferred outside Singapore, we take the steps required under the PDPA to ensure it receives a standard of protection comparable to the PDPA, including legally enforceable contract terms with the receiving party.
9. Requests from individuals
If an individual contacts us directly about personal data we process for a client, we will refer them to the client and will not respond on the client's behalf except as the client instructs or the law requires. Opt-out requests made during calls are recorded and applied to the client's suppression list as part of the Service. We provide reasonable assistance with access, correction, and similar requests, primarily through the portal's self-service tools for searching, exporting, and managing records.
10. Data breaches
If we become aware of a breach of security leading to loss or unauthorised access, use, or disclosure of client personal data, we will notify the affected client without undue delay, and in any event within 72 hours of confirming the breach, with the information then available; further details may follow in phases as we learn more. We will take reasonable steps to contain and remediate the breach and will give the client reasonable assistance with its own assessment and notification duties under the PDPA.
11. Retention, export, and deletion
Call recordings are retained on a 12-month rolling basis during an active subscription; a different period can be configured for a client in the Order Form or portal settings. Other call data is retained for the life of the subscription. When a subscription ends, the client has 30 days to export its data through the portal, after which we delete client personal data from our systems, except where the law requires us to retain specific records (for example financial records) or where data persists for a limited period in encrypted backups that expire on their own schedule and are not restored except for disaster recovery. On written request we will confirm deletion once it is complete.
12. Audit and information
Once in any 12-month period, on written request, we will provide the information reasonably needed to demonstrate compliance with this DPA, including summaries of third-party certifications and reports covering the infrastructure used to deliver the Service, where available. If a client has a genuine, documented reason, for example a data breach affecting its data or an inquiry from a regulator, we will additionally support a remote review scoped to that reason and to the client's own data, on at least 30 days' notice, at the client's cost, once per triggering event. Reviews must respect the isolation of other clients' data.
13. General
This DPA is governed by the same law as the Terms and does not increase either party's total liability beyond the limitations in the Terms; nothing in this DPA limits a responsibility that cannot lawfully be limited. If this DPA conflicts with the Terms on the processing of client personal data, this DPA prevails. It applies for as long as we process client personal data for the client and until deletion completes under section 11. Notices to clients are sent to the account contacts on file; notices to us go to loading…. Updates to this DPA follow the change and notice mechanism in the Terms, and an update will not materially reduce the protection applying to personal data already entrusted to us unless required by law or agreed with the client. Responsibilities for calling compliance, including Singapore's Do Not Call provisions, are allocated in the Terms. If client personal data becomes subject to the EU or UK GDPR, the parties will, on written request, put in place the applicable standard contractual clauses to supplement this DPA.