This document is the Data Processing Agreement (“DPA”) of PinChat (PinChat Inc.), prepared pursuant to Article 28 of the EU General Data Protection Regulation (“GDPR”). It is a legally binding agreement between PinChat (PinChat Inc.) and You, the User of the PinChat.me Software Solution.
It is recommended that You read this document carefully, together with our:
Note
Version: 1.0
Last updated: 10 May 2023
Effective date: 10 May 2023
This Annex 2: Details of Processing forms part of the DPA.
The Company has taken appropriate measures to prevent unauthorized access to the System, network, applications, and eventually Personal Data such as:
The Company shall use appropriate encryption technologies to protect Personal Data and where applicable for data in transit (for all communications, between end-users and server) and for data at rest.
The Company shall have in place an appropriate Record of Processing Operations, an Asset Handling Procedure, and an Acceptable Use Policy all of which ensure that all information, including Personal Data, is classified in accordance with its criticality and sensitivity to unauthorized access, disclosure, or modification.
The Company has taken reasonable measures to ensure that its employees and contractors, which have access to Personal Data are aware of and adhere to the security and privacy policies and procedures.
The measures include:
The Company is committed to ensuring that correct and secure facilities for the Processing of Personal Data by:
The Company has implemented a Firewall Protection, and an Intrusion Detection System and is regularly monitoring the Network Activity.
The Company performs software development and relevant support processes according to adopted secure system engineering principles such as:
The Company performs regular assessments of supplier services and acknowledges the responsibility to inform the Data Controller of any changes to the provision of Services pursuant to the Main Agreement.
The Company ensures a consistent approach to the management of privacy and security incidents, including communication on security breaches and weaknesses via:
The Company performs periodic assessments of risks to Personal Data and reviews the effectiveness of the implemented security policies and procedures.
Read this Annex 4 in conjunction with Clause 5 and other applicable provisions of the DPA.
Sub-Processor | Purpose | Location |
---|---|---|
Google | Social Login & App & Push Notification | USA |
Facebook | Social Login & Webhook Integration | USA |
Apple | Social Login & App | USA |
MetaMask | Social Login | USA |
WalletConnect | Social Login | USA |
MailChimp | Mail Server | USA |
Twilio | Short Message Service | USA |
Amazon Web Service | Hosting & Infrastructure | Japan |
PayPal | Payment Integration | USA |
Stripe | Payment Integration | Irene |
LINE | Payment Integration | Japan |
TapPay | Payment Gateway | Taiwan |
Instagram | Webhook Integration | USA |
WhatsApp | Webhook Integration | USA |
GoSquared | Statistics | UK |