Service Level Agreement

11. Data Protection and Privacy

11.1 Compliance with Data Protection Laws

(a) Each party shall comply with the Personal Data Protection Act 2010 of Malaysia, as amended, and other data-protection laws applicable to that party in connection with BlockchainCert.

(b) To the extent the Subscriber determines the purposes and means of processing Subscriber Personal Data, the Subscriber acts as data controller and the Service Provider acts as data processor.

(c) The Subscriber is responsible for appropriate privacy notices, consents or other lawful bases, data accuracy, and instructions for collecting, issuing, publishing, verifying, retaining, transferring, and otherwise processing Subscriber Personal Data and Credential content.

(d) The Service Provider acts as an independent data controller for personal data processed for its own lawful purposes, including account administration, KYB, billing, security, fraud prevention and legal compliance.

11.2 Data Hosting, Residency and Cross-Border Transfers

(a) Subscriber Personal Data may be hosted or processed in the locations used by the Service Provider and its approved providers, subject to the Subscription Agreement and applicable cross-border transfer requirements.

(b) The Service Provider shall effect cross-border transfers in accordance with applicable law and shall provide reasonable information needed for the Subscriber to assess those transfers.

(c) Any specific data-residency or localisation requirement must be expressly agreed in the Subscription Agreement or an applicable Statement of Work.

11.3 Sub-Processors

(a) The Service Provider may use Sub-Processors to host, secure, maintain, support, or deliver BlockchainCert. The Service Provider shall provide reasonable information about material Sub-Processors and reasonable notice of a material change where required by the Subscription Agreement or applicable law.

(b) The Service Provider shall impose confidentiality, data-protection, and security obligations on each material Sub-Processor that are appropriate to the processing performed and shall remain responsible for its obligations under this SLA.

(c) Upon written request, the Service Provider shall provide reasonable information regarding material Sub-Processors, subject to confidentiality and security limitations.

11.4 Data Subject Rights

Taking into account the nature of processing and information available, the Service Provider shall reasonably assist the Subscriber with data-subject requests, data-protection impact assessments, regulatory enquiries, and security-incident obligations. The Subscriber remains primarily responsible for responding as controller.

11.5 Data Return and Deletion

(a) Upon expiry or termination, the Service Provider shall, on the Subscriber’s written request, return or delete Subscriber Personal Data held in Service Provider-controlled off-chain systems within a reasonable period, unless retention is required or permitted by law, the Subscription Agreement, security requirements, or ordinary backup cycles.

(b) The Service Provider is not required to delete a record that is immutably recorded on the MasChain Network or that it is legally required or permitted to retain.

(c) The Subscriber shall not knowingly submit direct personal data for on-chain recording unless expressly agreed, lawful, and technically supported. BlockchainCert is intended to anchor a cryptographic hash, reference, or minimised metadata; the Subscriber must review Credential content and metadata before issuance.