Draft — pre-launch. These legal documents are under revision and are not yet in force. Hail Pilot is a pre-launch service; the legal entity responsible for it will be identified here, with its registered name, before the Service accepts customer sign-ups. No account may be opened, and no data processing agreement executed, in reliance on this draft.

Data Processing Agreement

Version: 2026-10-05.v4. Effective date: 5 October 2026. Operator: ABSOLUTE SERVICES (UEN 53464936W), a sole proprietorship registered in Singapore and owned by LEE KOK WAN. "Hail Pilot" is the name of the product and service operated by ABSOLUTE SERVICES ("Hail Pilot", "we", "us"). Registered address: 60 Paya Lebar Road, #06-28, Paya Lebar Square, Singapore 409051.

This Data Processing Agreement ("DPA") is part of the Terms of Service between Hail Pilot and the Merchant ("you"). It is the written contract under which we process Buyer Data on your behalf, as the Personal Data Protection Act 2012 (Singapore) ("PDPA") requires of a data intermediary, and it contains the terms the Personal Data Protection Act 2010 (Malaysia) ("MY PDPA") requires a data controller to impose on a data processor. You accept it when you accept the Terms; we record the accepted version and provide it to you on request. Capitalised terms have the meanings given in the Terms.

1. Roles

1.1 For Buyer Data that we process to provide the Service to you, you are the organisation responsible (PDPA) and the data controller (MY PDPA), and we are your Data Intermediary (PDPA) and Data Processor (MY PDPA). We process that Buyer Data only on your behalf and for your purposes.

1.2 For Network Signals we act as an organisation in our own right, as clause 8 of the Terms and section 6 of the Privacy Policy describe. Clause 11 of this DPA sets out how that processing relates to this DPA.

1.3 For personal data of your Merchant Users we are the responsible organisation, and the Privacy Policy applies instead of this DPA.

2. Details of processing

The subject matter, duration, nature, purposes, categories of Buyers and categories of Buyer Data are set out in Annex 1.

3. Your instructions

3.1 Your instructions are: the Terms and this DPA; the settings you choose (including any Auto-Send setting you enable under clause 9 of the Terms) and the actions your Merchant Users take in the Service; the Connectors you authorise; and any written instruction you give us that is consistent with the Terms. An instruction that would require a change to the Service, or work beyond what the Service provides, takes effect only when we agree to it in writing, and we may charge for it. We process Buyer Data only on those instructions, unless the law requires otherwise, in which case we tell you before processing unless the law prohibits it.

3.1A Your instructions include that we use Buyer Data to improve the AI Features for your workspace, as described in sections 4.3 and 4.3A of the AI Transparency Notice. We do not use Buyer Data to improve the Service for any other Merchant, and we keep what is learnt from it separate from other Merchants' data.

3.2 If we believe an instruction breaches the PDPA, MY PDPA or Platform Terms, we tell you and may suspend the instruction until it is resolved.

3.3 You are responsible for the lawfulness of the Buyer Data you give us and of your instructions, including the notices, consents and other lawful bases the Terms require you to have, and for your own obligations to Buyers, Platforms and regulators. You tell us at sign-up, and keep current in your account, the country in which you are established, because the clocks and language requirements that apply to you depend on it.

4. Our obligations

4.1 Confidentiality. We limit access to Buyer Data to personnel and Sub-processors who need it to provide the Service and who are bound by written confidentiality obligations.

4.2 Security. We protect Buyer Data with the technical and organisational measures in Annex 2 and the Security Statement, which are designed to meet the protection obligation under PDPA section 24 and the security principle under MY PDPA section 9 as it applies to data processors. We will not materially reduce the overall level of protection during the term.

4.3 Retention. We keep Buyer Data only for the periods and triggers in the Retention Schedule. At the end of a period we keep the records and replace the personal details in them with keyed tokens and mask free text, as Retention Schedule 1.3 describes; the result is pseudonymised Buyer Data, which we keep processing under this Agreement on your instructions and protect as Buyer Data. Irreversible anonymisation counts as ceasing to retain; tokenisation does not. On your written instruction, or a Buyer request you pass to us, we delete Buyer Data (clause 7.2 and the Data Deletion page).

4.4 Data protection officer. We have designated a data protection officer, reachable at business@hailpilot.com. That officer is not yet proficient in Bahasa Malaysia. Before we process Buyer Data for a Merchant established in Malaysia we designate a data protection officer who is proficient in Bahasa Malaysia and English, register the appointment where MY PDPA requires, and give you the details you need for your own notification to the Commissioner.

4.5 Records. We keep a record of the categories of processing we carry out for you, of Sub-processors, and of transfers, and we make it available to you on request.

5. Sub-processors

5.1 You authorise us to engage the Sub-processors named in the Sub-processor List, for the purposes and in the countries stated there.

5.2 Notice of changes to Sub-processors, your right to object and your remedy are set out in the Sub-processor List.

5.3 We bind each Sub-processor by written terms that impose protection comparable to this DPA, and we remain responsible to you for its processing.

6. Transfers

6.1 Our production systems are in Singapore and are operated by us. Sub-processors process Buyer Data in the countries named in the Sub-processor List. You authorise these transfers.

6.2 Before we transfer Buyer Data to a Sub-processor outside Singapore, we ensure that the Sub-processor is bound by legally enforceable obligations to protect the data to a standard comparable to the PDPA, and we record the countries to which the data is transferred.

6.3 Malaysia. Where you are established in Malaysia, you are the party that must satisfy the MY PDPA conditions for transferring Buyer Data outside Malaysia. To support you we: (a) maintain a register of recipients with the fields in Annex 3 and provide it on request; (b) provide, on request, a transfer impact assessment for Singapore and for each Sub-processor country, kept current for no longer than three years; and (c) on request, enter into the transfer clauses in Annex 3 with you.

7. Assistance with Buyers' requests

7.1 If a Buyer contacts us about their personal data, we forward the request to you within the period stated in the Privacy Policy and do not respond in your place unless you instruct us to or the law requires it.

7.2 We give you the assistance reasonably needed to answer access, correction, withdrawal, portability and direct-marketing-objection requests from Buyers within the time the law gives you, including by locating, exporting, correcting and deleting the Buyer Data concerned. This assistance is free for reasonable volumes; where requests are excessive or repetitive we may charge a reasonable fee after telling you the estimate.

7.3 Where a request concerns Network Signals, we handle it under clause 11.

8. Security Incidents

8.1 "Security Incident" has the meaning given in the Terms: it covers Merchant Data (including Buyer Data) and personal data of Merchant Users.

8.2 We notify you of a Security Incident affecting your Merchant Data or your Merchant Users' personal data without undue delay and in any event within 48 hours after we confirm that it has occurred. We confirm an incident when, after initial triage, we have reasonable evidence that it occurred; we do not delay confirmation to extend this period, and where confirmation is not possible within five days of first detection we tell you what we know. Where you are established in Malaysia, we notify you within 24 hours after we become aware of a suspected Security Incident, and update you as we confirm it, because the period MY PDPA gives you runs from the incident, not from our notice.

8.3 Our notice states, as far as then known: what happened and when; the categories and approximate number of Buyers and records affected; the likely consequences; the measures we have taken or propose; and a contact for further information. We update the notice as we learn more.

8.4 You should assess whether the incident is notifiable within 30 calendar days of our notice, and we assist you with that assessment. Where it is notifiable, the PDPA requires you to notify the Personal Data Protection Commission within three calendar days after assessing that it is notifiable (an incident affecting 500 or more individuals is treated as being of significant scale), and in notifying affected Buyers where the law requires. We give you the information, logs and draft language reasonably needed, and we do not notify Buyers or regulators on your behalf unless you instruct us or the law requires.

8.5 We keep a record of Security Incidents and provide it to you on request.

9. Audit and assurance

9.1 On written request, no more than once in any 12-month period, we provide: a completed security questionnaire; the current Security Statement; summaries of any third-party assessment we hold; and the records in clauses 4.5 and 8.5.

9.2 Where a Security Incident has affected your Buyer Data, or a regulator or Platform requires it of you, you or an independent auditor bound by confidentiality may audit our processing of your Buyer Data on 30 days' notice, during business hours, without disrupting the Service. You bear the cost of an audit unless it finds a material non-conformity with this DPA, in which case we bear our own costs of it. Where a Platform's terms oblige you to obtain our cooperation within a shorter period, we cooperate within that period once you tell us of it.

9.3 We correct any non-conformity an audit identifies within a reasonable time.

10. Return and deletion

10.1 During the term and for the export window stated in the Retention Schedule, you may ask us for a copy of your Buyer Data in a common machine-readable format; we provide it within the time stated there.

10.2 After the export period we do not delete Buyer Data, except WhatsApp and Instagram messages and media, which we delete then (Retention Schedule 2.10). We disconnect Connectors and replace the personal details in Buyer Data with keyed tokens, with free text masked, in accordance with Part 4 of the Retention Schedule, and you instruct us to keep the tokenised data for analysis and for Network Signals (clause 11). The tokenised data is pseudonymised personal data, not anonymous data, and we keep protecting it under this Agreement. Backups holding earlier forms of it expire within the backup period stated there. During the term, on your written instruction, we delete a Buyer's data as the Data Deletion page describes. We confirm on request what was done.

10.3 We may retain Buyer Data where the law requires us to, and only for as long as it requires.

11. Network Signals

11.1 Network Signals derived from your Buyer Data are processed by us as an organisation in our own right under the legitimate interests exception in the First Schedule to the PDPA, with the safeguards in clause 8 of the Terms. They are pseudonymised personal data; they are not anonymous data and we do not describe them as such.

11.2 Network Signals survive termination, are not returned or deleted under clause 10, and are retained indefinitely. They are not deleted or nullified on request from a Buyer or from you.

11.3 You will make the Notice to Buyers available to your Buyers where your own privacy notice refers to us, so that the reliance on the legitimate interests exception is made known to them.

12. Liability

The limitations and exclusions of liability in the Terms apply to this DPA, including the data-breach cap in clause 19.2 of the Terms and the items clause 19.4 leaves uncapped.

13. Term and precedence

This DPA lasts as long as we process Buyer Data for you. The order of precedence in clause 25.4 of the Terms applies: this DPA prevails over the Terms for the processing of Buyer Data, and the Platform & Card-Network Compliance Addendum prevails over this DPA for data obtained from a Platform to the extent it is more protective of that data.

14. Governing law

This DPA is governed by the laws of Singapore, and the courts of Singapore have exclusive jurisdiction, as clause 25 of the Terms provides.

Annex 1 — Details of processing

Subject matter: Buyer Data that you connect, upload or generate in the Service. Duration: the term of the Terms plus the export and deletion periods in the Retention Schedule. Nature: collection through Connectors and uploads; storage; encryption; indexing; analysis by AI Features; drafting; assembly of evidence files; transmission to your Platform, payment-processor, carrier and messaging accounts on your instruction; derivation of pseudonymised Network Signals under clause 11; deletion. Purposes: organising evidence for refunds, returns, disputes and chargebacks; drafting communications for your review; detecting abuse patterns within your data; producing summaries and risk signals for your human review; improving the AI Features for your workspace only; storing, backing up and securing your data. Categories of Buyers: your customers; persons identified in evidence files; carriers' delivery personnel named in delivery records. Categories of Buyer Data: identifiers (name, email, telephone, Platform account identifiers); addresses; order, delivery, payment-status and dispute records (the card network and the result codes of address and card-verification checks only; never full card numbers, card security codes or magnetic-stripe data); messages between you and Buyers; evidence files including photographs, screenshots and delivery records and any personal data they show; AI Output derived from the above. Sensitive personal data is not required and must not be uploaded unless strictly necessary for a specific dispute.

Annex 2 — Technical and organisational measures

The measures in the Security Statement, which include: encryption of data in transit and at rest; hashed storage of credentials; server-side session management with secure cookies; protection against request forgery; separation of each Merchant's data with application-level controls; access and audit logging; malware scanning of uploaded files; encrypted storage of connector secrets with key versioning; automated screening of inputs to AI Features; regular encrypted backups to two providers on the cadence stated in the Security Statement; and confidentiality obligations on personnel and Sub-processors.

Annex 3 — Transfer support for Merchants in Malaysia

Register fields per recipient: name of the recipient; company registration number where available; data protection officer or privacy contact; country of processing; categories of personal data transferred; purposes of the transfer. Transfer clauses: on request we enter into the ASEAN Model Contractual Clauses or the standard contractual clauses recognised by the Malaysian cross-border transfer guideline, with a rider confirming that the recipient's obligations are equivalent to those under MY PDPA, included in this DPA by reference. Transfer impact assessment: provided on request for Singapore and for each Sub-processor country, kept current as clause 6.3(b) states.

Data Processing Agreement | Hail Pilot