Data Processing Addendum
Last updated 8 October 2026
This addendum forms part of the Terms of Service between the customer and Tyrian Ventures Pte. Ltd., 10 Anson Road, #13-09 International Plaza, Singapore 079903 ("FastKPIs", "we"). It applies when we process personal data about the customer's staff on the customer's behalf.
1. Roles
The customer decides which staff to add and what to ask them, and is the controller (or organisation) for that personal data. FastKPIs processes it only to provide the service, as the customer's processor (a data intermediary under Singapore's PDPA).
2. Instructions
We process customer personal data only on the customer's documented instructions, which are the Terms, this addendum and the customer's use of the service, unless the law requires otherwise.
3. Data and purpose
- People: the customer's staff and reviewers.
- Data: names, email addresses, job titles, review answers, ratings, comments, scores, reviewers' notes and results.
- Purpose: creating, sending, completing, scoring and keeping records of performance reviews.
- Duration: while the customer uses FastKPIs, and until deletion under section 9.
4. Confidentiality
Anyone at FastKPIs who can access customer personal data is bound by confidentiality, and access is limited to what their role requires.
5. Security
We maintain the technical and organisational measures described on our security page, including organisation-level data separation enforced by the database, hashed private links, encryption in transit, and restricted access.
6. Subprocessors
The customer authorises the subprocessors listed on our subprocessors page. We update that page before adding or replacing a subprocessor that handles customer personal data, and impose data protection terms on each one at least as protective as these.
7. Helping with requests
We help the customer respond to staff requests to access, correct or delete their data, and with data protection assessments where reasonably needed. If a staff member contacts us directly, we pass the request to the customer.
8. Data breaches
If we become aware of a breach affecting customer personal data, we notify the customer without undue delay (aiming for within 72 hours), with the information available, and help the customer meet its own notification duties.
9. Deletion
When the customer asks, or the account closes, we delete customer personal data within 30 days, except where the law requires us to keep it (for example, payment records).
10. International transfers
Customer data is stored in Singapore. Where a subprocessor processes it elsewhere, we make sure it is protected to a standard comparable to the PDPA, using contractual safeguards where required.
11. Information
We make available the information reasonably needed to show we meet this addendum, for example by answering a security questionnaire.