This Data Processing Agreement (“DPA”) is entered into between:
Data Controller: The entity subscribing to the LuxGov Platform (“Controller”, “Client”, or “Tenant”)
Data Processor: Luxemss Resources, SSM Registration No. 202603121194 (PG0587419-T), with its principal office at No 46, Jalan Bidara 3, Saujana Utama 3, 47000 Sungai Buloh, Selangor, Malaysia (admin@luxgov.net) (“Processor” or “LuxGov”)
This DPA supplements and forms part of the LuxGov Terms of Service (“Agreement”) and is effective from the date the Controller first accesses the Platform.
“Applicable Data Protection Law” means all laws and regulations relating to the processing and protection of Personal Data that apply to the processing of Personal Data under this DPA, including PDPA 2010 (Malaysia), PDPA 2012 (Singapore), Privacy Act 1988 (Australia), UK GDPR and DPA 2018 (United Kingdom), and CCPA/CPRA (United States — California).
“Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data transmitted, stored, or otherwise processed by the Processor.
“Data Subject” means an identified or identifiable natural person whose Personal Data is processed under this DPA.
“Personal Data” means any information relating to a Data Subject that is processed by the Processor on behalf of the Controller in connection with the Platform.
“Processing” means any operation or set of operations performed on Personal Data, including collection, recording, organisation, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination, alignment, combination, restriction, erasure, or destruction.
“Sub-processor” means any third party engaged by the Processor to process Personal Data on behalf of the Controller.
“Standard Contractual Clauses” or “SCCs” means the standard contractual clauses for the transfer of personal data to processors established in third countries, as adopted by the relevant supervisory authority.
3.1. Scope. This DPA applies to the processing of Personal Data by the Processor on behalf of the Controller in connection with the provision of the LuxGov Platform services.
3.2. Duration. This DPA shall remain in effect for as long as the Processor processes Personal Data on behalf of the Controller, and shall automatically terminate upon the later of: (a) termination of the Agreement; or (b) the Processor ceasing all processing of the Controller’s Personal Data, including deletion in accordance with Section 13.
4.1. Subject Matter. The processing of building compliance documents, engineering drawings, professional certificates, project data, and associated personal data for the purpose of providing automated compliance auditing services.
4.2. Nature of Processing. The Processor performs the following processing activities:
4.3. Purpose. The Processor processes Personal Data solely for the purpose of providing the Platform services as described in the Agreement. The Processor shall not process Personal Data for any other purpose unless instructed in writing by the Controller.
Personal Data processed under this DPA may relate to the following categories of Data Subjects:
The following categories of Personal Data may be processed:
7.1. Processing Instructions. The Processor shall process Personal Data only on documented instructions from the Controller, unless required to do so by applicable law. The Agreement and this DPA constitute the Controller’s complete initial instructions. Any additional instructions must be agreed in writing.
7.2. Confidentiality. The Processor shall ensure that all personnel authorised to process Personal Data have committed themselves to confidentiality obligations or are under an appropriate statutory obligation of confidentiality.
7.3. Security Measures. The Processor shall implement and maintain the technical and organisational security measures described in Annex B to protect Personal Data against Data Breaches. The Processor shall regularly test, assess, and evaluate the effectiveness of these measures.
7.4. Sub-processing. The Processor shall not engage another processor (Sub-processor) without prior written authorisation from the Controller, subject to Section 10.
7.5. Assistance with Data Subject Rights. The Processor shall assist the Controller, by appropriate technical and organisational measures, in fulfilling the Controller’s obligation to respond to requests from Data Subjects exercising their rights under Applicable Data Protection Law.
7.6. Assistance with Compliance. The Processor shall assist the Controller in ensuring compliance with the obligations regarding security of processing, notification of Data Breaches, data protection impact assessments, and prior consultation with supervisory authorities.
7.7. Demonstrating Compliance. The Processor shall make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in this DPA, and shall allow for and contribute to audits and inspections conducted by the Controller or a mandated auditor, subject to Section 11.
8.1. The Controller warrants that it has a lawful basis to provide Personal Data to the Processor for processing in accordance with this DPA.
8.2. The Controller is responsible for ensuring that appropriate consents or authorisations have been obtained from Data Subjects whose personal data is uploaded to the Platform, particularly where documents contain the personal data of third parties (e.g., professional engineers, certifiers).
8.3. The Controller shall provide processing instructions that comply with Applicable Data Protection Law.
8.4. The Controller shall notify the Processor promptly of any Data Subject rights requests that require the Processor’s assistance.
9.1. The Processor implements and maintains the technical and organisational measures detailed in Annex B, including but not limited to:
| Category | Measure |
|---|---|
| Tenant Isolation | PostgreSQL Row Level Security (RLS) enforcing per-tenant data boundaries at the database layer |
| Encryption at Rest | AES-256-GCM encryption for tenant state files; Azure Storage Service Encryption for all blob storage |
| Encryption in Transit | TLS 1.2+ for all data transmissions between clients, the Platform, and third-party services |
| Secret Management | Azure Key Vault for all credentials, API keys, encryption keys, and connection strings — zero hardcoded secrets |
| Access Control | Role-based access control (RBAC) across defined tenant and platform roles, fail-closed enforcement at startup |
| Authentication | Microsoft Entra ID (Azure AD) with JWT token validation, JWKS key verification, and session management |
| Audit Logging | SHA-256 hash-chained tamper-evident audit trail; WORM immutability on published audit outputs |
| Immutability | SOFT WORM for UK/SG/MY (allows deletion after retention); HARD LOCK for AU/US (deletion prohibited before expiry) |
| Rate Limiting | Per-tenant, per-plan rate limits preventing abuse and denial-of-service |
| Network Security | Azure App Service with managed identity; no public database endpoint; firewall rules for administrative access |
9.2. The Processor shall not materially reduce the overall level of security without prior written notice to the Controller.
10.1. The Controller provides general written authorisation for the Processor to engage the Sub-processors listed in Annex C.
10.2. The Processor shall:
10.3. The Controller may object to a new Sub-processor on reasonable grounds within fifteen (15) days of receiving notice. If the objection is not resolved, the Controller may terminate the affected services without penalty.
11.1. The Processor shall make available to the Controller all information reasonably necessary to demonstrate compliance with this DPA.
11.2. The Controller (or its mandated independent auditor) may conduct an audit of the Processor’s data processing activities and security measures:
11.3. Audits shall be conducted during normal business hours, shall not unreasonably interfere with the Processor’s operations, and shall be subject to reasonable confidentiality obligations.
11.4. The Processor may satisfy audit requests by providing written responses to the Controller's specific audit questions, security architecture documentation, and evidence of implemented technical and organisational measures as described in Annex B.
11.5. The Controller shall bear its own costs for audits, except where an audit reveals material non-compliance by the Processor.
The Processor shall notify the Controller of a Data Breach without undue delay and in no event later than seventy-two (72) hours after becoming aware of the breach.
12.2. The notification shall include, to the extent available:
12.3. Where it is not possible to provide all information simultaneously, the Processor shall provide information in phases without undue further delay.
12.4. The Processor shall cooperate with the Controller and take reasonable steps to assist in the investigation, mitigation, and remediation of the Data Breach.
12.5. Notification of a Data Breach shall not be construed as an acknowledgement of fault or liability.
13.1. Upon termination of the Agreement, or upon the Controller’s written request, the Processor shall, at the Controller’s election:
13.2. The Controller shall make its election within thirty (30) days of termination. If no election is made, the Processor shall delete all Personal Data.
Where Applicable Data Protection Law or regulatory requirements mandate retention of certain data (e.g., WORM-protected audit logs in AU/US jurisdictions with retention periods up to 7 years), the Processor shall: isolate such data from active processing; apply appropriate security measures for the duration of retention; delete such data promptly upon expiry of the applicable retention period; and provide the Controller with written confirmation of the specific data retained and the applicable retention period.
13.4. The Processor shall provide written confirmation of data deletion within thirty (30) days of completing the deletion process.
14.1. The Processor stores Personal Data in the Azure region corresponding to the Controller’s Jurisdiction, as specified in the Privacy Policy.
14.2. Where Personal Data is transferred to a country outside the Controller’s Jurisdiction, the Processor shall ensure that appropriate safeguards are in place:
| Transfer | Safeguard |
|---|---|
| AI processing via US-based AI service provider | Sub-processor DPA + Standard Contractual Clauses (where required) |
| Payment processing via Stripe (US-based) | Stripe DPA + Standard Contractual Clauses |
| Azure infrastructure management (cross-region telemetry) | Microsoft DPA + Standard Contractual Clauses |
14.3. For UK Tenants: The International Data Transfer Agreement (IDTA) or UK Addendum to the EU SCCs is incorporated by reference where Personal Data is transferred outside the UK.
14.4. For Australian Tenants: The Processor ensures that overseas recipients of Personal Data are bound by obligations substantially similar to the Australian Privacy Principles, in compliance with APP 8.
14.5. For Malaysian Tenants: Cross-border transfers comply with Section 129 of the PDPA 2010, ensuring that Personal Data is transferred only to jurisdictions with adequate levels of protection or with the Data Subject’s consent.
14.6. For Singaporean Tenants: Cross-border transfers comply with the PDPA 2012 Transfer Limitation Obligation (Section 26), ensuring that recipients provide a standard of protection comparable to the PDPA.
15.1. The liability of each party under this DPA is subject to the limitations and exclusions of liability set out in the Agreement (Terms of Service, Section 12).
15.2. Nothing in this DPA limits or excludes liability for: (a) Data Breaches caused by wilful default or gross negligence; (b) any liability that cannot be limited by Applicable Data Protection Law.
16.1. This DPA shall be governed by and construed in accordance with the governing law of the Agreement (Malaysia, subject to jurisdiction-specific provisions as set out in the Terms of Service, Section 19).
16.2. Any dispute arising out of this DPA shall be resolved in accordance with the dispute resolution provisions of the Agreement (mediation, then AIAC arbitration).
| Field | Description |
|---|---|
| Subject matter | Processing of building compliance data and associated personal data for the purpose of providing automated compliance auditing services |
| Duration | For the term of the subscription Agreement plus any post-termination retention period |
| Nature of processing | Collection, storage, classification, AI-assisted analysis, scoring, report generation, archival, and deletion |
| Purpose | Providing the LuxGov compliance intelligence platform services: automated audit of building documents against jurisdiction-specific building codes |
| Categories of Data Subjects | Tenant employees, professional engineers, architects, building certifiers, inspectors, project stakeholders |
| Categories of Personal Data | Names, professional titles, registration numbers, email addresses, organisational roles, professional opinions, authentication tokens, session data, IP addresses, usage timestamps |
| Controller | The subscribing Tenant organisation |
| Processor | Luxemss Resources (LuxGov) |
| Sensitive data | Not ordinarily processed. If compliance documents contain health and safety incident data or similar sensitive categories, the Controller must notify the Processor |
| Measure | Detail |
|---|---|
| Authentication | Microsoft Entra ID (Azure AD) with OAuth 2.0 / OpenID Connect; JWT token validation with JWKS key verification |
| Role-based access | Defined roles across platform and tenant scopes |
| Permission granularity | Dot-notation permissions enforced at middleware layer |
| Fail-closed enforcement | Platform refuses to start if role configuration is missing, malformed, or empty |
| Session management | Token expiry timers with 5-minute warning; automatic logout on expiry |
| Multi-tenant isolation | Tenant identity derived exclusively from cryptographic JWT claims, never from request parameters |
| Measure | Detail |
|---|---|
| In transit | TLS 1.2+ mandatory for all client-server and server-to-server communications |
| At rest (state files) | AES-256-GCM with keys managed in Azure Key Vault |
| At rest (blob storage) | Azure Storage Service Encryption (SSE) with Microsoft-managed keys |
| Secret management | All credentials, API keys, and encryption keys stored in Azure Key Vault (kv-luxgov-core); zero hardcoded secrets in codebase |
| Key rotation | Supported via Key Vault secret versioning |
| Measure | Detail |
|---|---|
| Database isolation | PostgreSQL Row Level Security (RLS) policies enforce tenant-scoped queries; application sets SET LOCAL app.current_tenant per connection |
| Storage isolation | Per-tenant namespaced containers within jurisdiction-specific Azure Blob Storage accounts |
| Network isolation | Azure App Service with managed identity; PostgreSQL accessible only via Azure private networking and explicit firewall rules |
| Measure | Detail |
|---|---|
| Audit logging | All platform events recorded with SHA-256 hash chaining (tamper-evident) |
| WORM immutability | Published audit outputs written to WORM-protected storage: SOFT WORM for UK/SG/MY; HARD LOCK for AU/US |
| Change tracking | Git-based version control for all platform code; CI/CD pipeline with automated testing |
| Measure | Detail |
|---|---|
| Compute | Azure App Service with 2 Gunicorn workers × 4 threads = 8 concurrent requests |
| Deployment | Automated CI/CD pipeline with health check retry loops (10 × 30 seconds), rollback capability |
| Monitoring | Microsoft Application Insights for performance monitoring and error diagnostics |
| Backup | Azure-managed PostgreSQL backups; blob storage geo-redundancy per Azure region policy |
| Measure | Detail |
|---|---|
| Breach detection | Application-level logging; Azure security alerts |
| Notification timeline | 72-hour notification to affected Controller |
| Response | Documented incident response procedure; designated DPO contact |
| Sub-processor | Processing Activity | Data Categories | Location |
|---|---|---|---|
| Microsoft Corporation (Azure) | Cloud infrastructure: compute (App Service), database (PostgreSQL Flexible Server), storage (Blob Storage), identity (Entra ID), key management (Key Vault), monitoring (Application Insights) | All categories of Personal Data and Tenant Data | Per-jurisdiction Azure regions (see Privacy Policy Section 7) |
| Anthropic PBC (Claude API) | AI-powered compliance analysis: document classification, natural language processing, compliance scoring. Anthropic’s API Terms of Service prohibit using API inputs for model training. | Building compliance document content (may contain personal data of engineers, certifiers, project stakeholders) | United States |
| Stripe Inc. | Payment processing: subscription billing, invoice generation, payment card processing. LuxGov does not receive or store payment card details. | Billing data: customer name, email, subscription plan, payment history | United States |
Current as of: 5 June 2026
The Processor will notify the Controller at least thirty (30) days before adding or replacing any Sub-processor.
This DPA is executed by the authorised representatives of each party.
Name
Title
Organisation
Date
Signature
Name
Title
Organisation: Luxemss Resources
Date
Signature