03LEGAL
Data Processing Agreement
Last updated · 20 August 2026
This agreement applies between you (the “Controller”) and Onecheckout Limited (the “Processor”) whenever we process personal data on your behalf. It forms part of our Terms of Service.
1. Subject matter and duration
Subject matter: processing of order and courier remittance data to produce COD reconciliation reports. Duration: for as long as your account is active, plus the retention periods set out in clause 8.
2. Nature and purpose of processing
Ingesting files you supply, normalising and matching records, computing discrepancies, generating reports, and storing those reports for your access. No other processing is carried out.
3. Categories of data subjects
- Your end customers (the recipients of COD orders).
- Your own personnel who hold CODAudit accounts.
4. Categories of personal data
- End customers: name, phone number, delivery address, order identifiers, AWB number, COD amount, delivery and remittance status.
- Your personnel: name, work email, role, company.
No special categories of personal data are required or knowingly processed.
5. Processor obligations
- Process personal data only on your documented instructions and for the purpose above.
- Impose confidentiality obligations on all personnel with access.
- Implement the technical and organisational measures in clause 7.
- Assist you with data subject requests, DPIAs and regulator enquiries.
- Not transfer data outside the agreed region except under clause 9.
6. Sub-processors
You authorise the following sub-processors:
- Vercel Inc. — application hosting and file storage — European Union (Frankfurt)
- Stripe — payment processing
- Resend — transactional email
- Cloudflare, Inc. — DNS, email routing and cookieless web analytics (aggregate data retained 6 months)
- Lovable AI Gateway — AI inference for the support assistant chat, currently routed to Google Gemini models; used only for chat text and never for uploaded files
We remain liable for their performance and will give at least 30 days’ notice before appointing a replacement, which you may object to on reasonable data protection grounds.
7. Security measures
- Encryption in transit (TLS 1.2+) and at rest.
- Role-based least-privilege access, multi-factor authentication, access logging.
- Segregation of customer data and environment separation.
- Documented change management, backup and restore procedures.
- Personnel security screening and periodic security training.
8. Breach notification
We will notify you without undue delay and in any case within 72 hours of becoming aware of a personal data breach affecting your data, with the nature of the breach, categories and approximate volume of records, likely consequences and remedial measures taken.
9. International transfers
Where personal data is transferred outside the country of origin, the transfer is made under contractual safeguards equivalent to the EU Standard Contractual Clauses and the transfer conditions of the UAE PDPL.
10. Audit rights
On no less than 30 days’ written notice, and no more than once in any 12-month period (unless required by a regulator), you may request evidence of compliance — including our security documentation and available third-party assessments — or conduct an audit at your cost, subject to confidentiality and minimal disruption to our operations.
11. Return and deletion
On termination, or on your earlier written request, we delete uploaded files and generated reports within 30 days and confirm deletion in writing, except where retention is required by law. Exports can be requested before deletion.
12. Support access controls
Processor personnel access to Controller data is tiered and technically enforced. Tier 1 is a read-only diagnostic view containing processing metadata (formats, encodings, mappings, row counts, skip reasons, errors, delivery logs) in which data-subject identifiers — name, phone, email and address — are masked before transmission to the support operator. Tier 2 (read-only entry into the Controller’s account) and Tier 3 (changes on the Controller’s behalf) require the Controller’s explicit, revocable in-product consent, expire automatically after 24 hours, and are unavailable without a live grant.
All access at every tier is recorded in an append-only audit log capturing the operator identity, the account, the tier, the action, the session identifier, the timestamp and, for changes, the previous and new values. The Controller can read the log entries relating to its own account at any time in the product.
13. Contact
Processor: Onecheckout Limited, No. 5, 17/F, Strand, Bonham Strand, Sheung Wan, Hong Kong (Reg. No. 77305897). Data protection contact: privacy@codaudit.com. Governing law: Hong Kong SAR.