Data Processing Agreement
BEKIRIM DATA PROCESSING AGREEMENT (DPA)
Last Updated: August 2026
Website: https://bekirim.com
INTRODUCTION
This Data Processing Agreement ("DPA") establishes the terms and conditions under which Bekirim ("Data Controller") processes personal data collected through the Bekirim platform ("Service").
This DPA applies to all users, including Customers and Drivers, and defines how personal data is collected, processed, stored, and protected in compliance with Brunei's Personal Data Protection Act (BDPA).
Governing Law: This DPA is governed by the Personal Data Protection Act (BDPA) of Brunei Darussalam and applicable Brunei law.
---
SECTION 1: DEFINITIONS AND ROLES
1.1 DEFINITIONS
- "Personal Data" means any information relating to an identified or identifiable natural person
- "Data Controller" means Bekirim, which determines the purposes and means of processing personal data
- "Data Processor" means third parties (Supabase, Lovable, Google Maps) who process personal data on behalf of Bekirim
- "Processing" means any operation performed on personal data (collection, storage, use, transmission, etc.)
- "Data Subject" means the individual to whom personal data relates
- "Data Breach" means unauthorized or accidental access, disclosure, or loss of personal data
1.2 PARTIES
- Data Controller: Bekirim
- Data Subjects: Customers, Drivers, and other users of the platform
- Data Processors:
* Supabase (database and storage)
* Lovable (platform infrastructure)
* Google Maps (location and routing services)
---
SECTION 2: SCOPE AND PRINCIPLES
2.1 SCOPE
This DPA covers:
- Personal data collected through the Bekirim app and website
- Processing of personal data by Bekirim and its processors
- Storage and security of personal data
- Compliance with BDPA requirements
- User rights regarding their data
2.2 PRINCIPLES OF DATA PROCESSING
Bekirim processes personal data in accordance with these principles:
LAWFULNESS
- Personal data is processed only for lawful purposes
- Processing has a legitimate legal basis
- Users are informed of data processing practices
FAIRNESS
- Data collection methods are transparent
- Users understand why their data is collected
- No deceptive or unfair practices
TRANSPARENCY
- Users are provided with clear information about processing
- Privacy Policy explains collection and use of data
- Users can access and control their personal data
DATA MINIMIZATION
- Only necessary personal data is collected
- Excessive or irrelevant data is not collected
- Collection is proportionate to purposes
PURPOSE LIMITATION
- Personal data is used only for stated purposes
- Data is not repurposed without user consent
- Secondary uses are clearly disclosed
ACCURACY
- Personal data is kept accurate and up-to-date
- Inaccurate data is corrected promptly
- Users can request corrections
STORAGE LIMITATION
- Personal data is retained only as long as necessary
- Data is securely deleted when no longer needed
- Retention schedules are documented
INTEGRITY AND CONFIDENTIALITY
- Personal data is protected against unauthorized access
- Security measures are implemented and maintained
- Data is kept confidential
ACCOUNTABILITY
- Bekirim maintains records of processing activities
- Compliance is documented and verifiable
- Responsibility for data protection is clear
---
SECTION 3: PERSONAL DATA COLLECTION
3.1 TYPES OF PERSONAL DATA COLLECTED
CUSTOMER DATA
- Full name, email, phone number
- Residential address and delivery addresses
- Payment information (bank details, transaction history)
- Location data (delivery location, GPS coordinates during delivery)
- Device information (device type, IP address)
- Usage data (orders, preferences, interaction history)
- Communications (messages to/from Drivers)
DRIVER DATA
- Full name, email, phone number, home address
- Driver's license number and expiry date
- Vehicle information (make, model, registration number, insurance details)
- Bank account information (for payment withdrawal)
- Location data (real-time GPS, route information)
- Insurance provider and policy details
- Device information (device type, IP address)
- Usage data (deliveries completed, ratings, earnings)
- Background check results
- Communications (messages to/from Customers)
3.2 LEGAL BASIS FOR PROCESSING
DATA COLLECTION IS BASED ON:
- Performance of the delivery service contract
- Compliance with legal obligations (payment verification, identity verification)
- Protection of legitimate interests (fraud prevention, safety, platform security)
- User consent for certain processing activities (marketing communications, analytics)
- Vital interests (safety and emergency response)
3.3 CONSENT
For certain processing activities, Bekirim obtains explicit user consent:
- Location tracking (Drivers)
- Marketing communications
- Use of analytics and cookies
- Sharing data with third-party processors
Users can withdraw consent at any time through account settings.
---
SECTION 4: PROCESSING ACTIVITIES
4.1 PROCESSING PURPOSES
Personal data is processed for:
CORE SERVICE DELIVERY
- Creating and maintaining user accounts
- Facilitating deliveries
- Processing payments and Digital Wallet transactions
- Providing customer support
- Communicating with users about orders
IDENTITY AND ELIGIBILITY VERIFICATION
- Verifying user age and identity
- Verifying Driver license and insurance
- Confirming eligibility for service
PAYMENT PROCESSING
- Processing manual bank transfers
- Verifying payment transactions
- Managing Digital Wallet accounts
- Processing refunds and withdrawals
SAFETY AND SECURITY
- Detecting and preventing fraud
- Monitoring for suspicious activity
- Ensuring compliance with policies
- Protecting platform security
- Verifying delivery completion
OPTIMIZATION AND IMPROVEMENT
- Analyzing user behavior and trends
- Improving app features and performance
- Debugging technical issues
- Conducting research and analytics
LEGAL AND REGULATORY COMPLIANCE
- Complying with Brunei law
- Meeting regulatory requirements
- Handling legal disputes
- Maintaining audit trails
DISPUTE RESOLUTION
- Investigating complaints and disputes
- Reviewing evidence and communications
- Processing refund requests
- Resolving payment disputes
4.2 AUTOMATED PROCESSING
Bekirim uses automated processing for:
- Fraud detection and prevention
- Driver rating and qualification assessment
- Delivery route optimization
- Payment verification
- Duplicate account detection
For sensitive decisions (e.g., driver approval), human review is involved.
---
SECTION 5: DATA RETENTION
5.1 RETENTION SCHEDULE
ACTIVE ACCOUNT DATA
- Retained while account is active
- Deleted within 3 months of account closure
POST-ACCOUNT CLOSURE
- Retained for 3 years after closure for legal compliance and dispute resolution
- Then permanently deleted
PAYMENT RECORDS
- Retained for 3 years (tax and audit purposes)
- Longer if required by Brunei tax law
DELIVERY RECORDS
- Retained for 1 year (dispute resolution)
- Deleted after 1 year if no disputes
LOCATION DATA
- Retained during active delivery
- Deleted within 90 days after delivery completion
- Longer if disputes are pending
COMMUNICATIONS/SUPPORT RECORDS
- Retained for 1 year after resolution
- Longer if disputes are unresolved
FRAUD/SECURITY RECORDS
- Retained for 2 years (investigation and prevention purposes)
5.2 LEGAL HOLDS
Data subject to legal holds or disputes is retained until the matter is resolved.
5.3 SECURE DELETION
When data is deleted:
- Deleted from primary storage systems
- Deleted from backup systems within 90 days
- Deletion is permanent and irreversible
- Deletion certificates are maintained
---
SECTION 6: DATA PROCESSORS AND THIRD PARTIES
6.1 AUTHORIZED DATA PROCESSORS
SUPABASE (Database Provider)
- Role: Stores and manages all personal data
- Processing: Data storage, encryption, access management
- Location: International (servers outside Brunei)
- Agreement: Supabase is contractually bound to process data according to this DPA
- Security: Implements encryption at rest and in transit
LOVABLE (Platform Infrastructure)
- Role: Hosts and operates the Bekirim platform
- Processing: App hosting, user authentication, access logs
- Location: Cloud infrastructure
- Agreement: Lovable processes data only as instructed
- Security: Implements platform-level security measures
GOOGLE MAPS (Location Services)
- Role: Provides mapping, routing, and location services
- Processing: Receives location data and delivery addresses
- Location: Google's data centers
- Agreement: Limited to routing purposes only
- Data Retention: Google does not retain location data long-term
PAYMENT VERIFICATION
- Role: Manual verification of bank transfers by Bekirim Admin staff
- Processing: Access to bank transfer information for verification
- Security: Admin staff bound by confidentiality agreements
- Access: Limited to staff with verification responsibilities
6.2 PROCESSOR AGREEMENTS
Data processors are bound by:
- Written data processing agreements
- Confidentiality obligations
- Security requirements
- Data protection standards
- Audit and compliance requirements
- Data subject rights enforcement
6.3 SUBPROCESSORS
Processors may use subprocessors (e.g., cloud infrastructure providers) with:
- Prior notification to Bekirim
- Contractual data protection obligations
- Equivalent security standards
- Subject to this DPA terms
6.4 INTERNATIONAL DATA TRANSFERS
Personal data is transferred internationally to:
- Supabase servers (location varies)
- Google servers (global infrastructure)
- Lovable infrastructure (cloud-based)
By using Bekirim, users consent to international data transfers.
---
SECTION 7: DATA SUBJECT RIGHTS
7.1 RIGHT TO ACCESS
Data subjects have the right to:
- Request access to their personal data
- Receive information about data processing
- Obtain a copy of their data
- No charge for reasonable requests
- Response within 30 days
7.2 RIGHT TO CORRECTION
Data subjects have the right to:
- Request correction of inaccurate data
- Update personal information through account
- Request changes through support team
- No unreasonable delay in correction
7.3 RIGHT TO DELETION
Data subjects have the right to:
- Request deletion of personal data
- Erasure of data from all systems
- Exceptions for legal compliance or contract fulfillment
- Response within 30 days
- Note: Some data retained for legal reasons
7.4 RIGHT TO RESTRICT PROCESSING
Data subjects have the right to:
- Limit processing of their data
- Request suspension of certain processing
- Maintain access while processing is restricted
- Used pending correction or disputes
7.5 RIGHT TO DATA PORTABILITY
Data subjects have the right to:
- Receive personal data in structured format
- Transfer data to another service
- Commonly used formats (CSV, JSON)
- Response within 30 days
7.6 RIGHT TO WITHDRAW CONSENT
Data subjects have the right to:
- Withdraw consent for processing anytime
- Opt out of marketing communications
- Disable location tracking (if feature allows)
- Effect through account settings or support
7.7 EXERCISING RIGHTS
To exercise data subject rights:
Email: [INSERT CONTACT EMAIL]
Include:
- Full name and account email
- Specific right being exercised
- Supporting documentation
- Any relevant dates or transaction IDs
Response: Within 30 days, Bekirim will:
- Confirm receipt of request
- Process the request
- Provide response with data or confirmation
- Explain any delays or refusals
---
SECTION 8: DATA SECURITY
8.1 SECURITY MEASURES
ENCRYPTION
- Data encrypted in transit (HTTPS/TLS)
- Data encrypted at rest in Supabase
- Encryption keys managed securely
- Industry-standard encryption algorithms
ACCESS CONTROL
- Role-based access management
- Admin staff have limited access to necessary data only
- Multi-factor authentication for admin accounts
- Access logs maintained for accountability
STORAGE SECURITY
- Secure storage in Supabase data centers
- Regular security updates and patches
- Firewalls and intrusion detection systems
- Regular security audits
BACKUP AND RECOVERY
- Regular encrypted backups maintained
- Backup data stored securely
- Recovery procedures tested regularly
- Backup retention per retention schedule
MONITORING
- Continuous security monitoring
- Automated threat detection
- Incident response procedures
- Security event logging
EMPLOYEE TRAINING
- Staff trained on data protection
- Confidentiality agreements with employees
- Regular security awareness training
- Compliance procedures documented
8.2 SECURITY RESPONSIBILITIES
BEKIRIM RESPONSIBILITIES
- Implements and maintains security measures
- Conducts regular security assessments
- Updates security practices
- Responds to security incidents
- Ensures processor compliance
PROCESSOR RESPONSIBILITIES
- Implements agreed security measures
- Reports security incidents
- Maintains security certifications
- Provides audit evidence
- Cooperates with security assessments
USER RESPONSIBILITIES
- Keep login credentials confidential
- Do not share account information
- Report suspicious activity immediately
- Maintain device security
- Update passwords regularly
8.3 SECURITY INCIDENT RESPONSE
DATA BREACH PROCEDURE
1. Incident is discovered or reported
2. Immediate investigation begins
3. Affected systems isolated if necessary
4. Evidence preserved for analysis
5. Data Subjects notified within reasonable time
6. Regulatory authorities notified if required
7. Remedial action implemented
8. Post-incident review conducted
NOTIFICATION
- Affected users notified of breaches affecting their data
- Notification includes:
* Nature of breach
* Data affected
* Potential impact
* Protective measures taken
* Contact for questions
- Notification sent via email or in-app notification
---
SECTION 9: DATA PROTECTION BY DESIGN AND DEFAULT
9.1 IMPLEMENTATION
Bekirim implements data protection principles in:
- App design and development
- Feature planning and rollout
- Infrastructure decisions
- Third-party vendor selection
- Policy and procedure development
9.2 PRIVACY BY DEFAULT
- Minimum necessary data is collected
- Shortest necessary retention periods
- Users control sharing of their data
- Privacy settings favor user preferences
- Opt-in for non-essential processing
---
SECTION 10: DATA IMPACT ASSESSMENTS
10.1 IMPACT ASSESSMENTS
Bekirim conducts Data Protection Impact Assessments (DPIA) for:
- New features that process personal data
- Significant changes to processing
- High-risk processing activities
- Automated decision-making systems
10.2 ASSESSMENT CONTENTS
Assessments include:
- Description of processing
- Purpose and legal basis
- Data types and categories
- Risk analysis
- Mitigation measures
- Risk ratings
---
SECTION 11: COMPLIANCE AND ACCOUNTABILITY
11.1 COMPLIANCE DOCUMENTATION
Bekirim maintains:
- Records of all processing activities
- Data protection policies
- Staff training records
- Security audit reports
- Incident logs
- Data subject request records
- Processor agreements
- DPA update history
11.2 AUDIT AND MONITORING
- Regular internal audits of data protection compliance
- Processor compliance monitoring
- User rights requests tracked
- Processing activities reviewed periodically
- Compliance issues documented and addressed
11.3 REGULATORY COOPERATION
Bekirim cooperates with:
- Brunei Personal Data Protection Authority
- Government agencies as required
- Law enforcement with proper legal authority
- Regulatory investigations and audits
---
SECTION 12: CHANGES TO THIS AGREEMENT
12.1 MODIFICATIONS
Bekirim may modify this DPA:
- To comply with new laws or regulations
- To improve data protection practices
- To reflect changes in operations
- To address security developments
12.2 NOTIFICATION
- Significant changes notified to users
- Changes effective upon notice
- Users may object to material adverse changes
- Continued use constitutes acceptance
---
SECTION 13: CONTACT INFORMATION
For data protection inquiries or to exercise data subject rights:
Email: [INSERT CONTACT EMAIL]
Website: https://bekirim.com
Address: [INSERT BEKIRIM BUSINESS ADDRESS]
Data Protection Officer: [INSERT NAME/TITLE IF APPLICABLE]
Response target: 30 days for most inquiries
---
SECTION 14: ACKNOWLEDGMENT
By using Bekirim, you acknowledge:
- You have read and understand this DPA
- You understand how your personal data is processed
- You understand your rights regarding your data
- You consent to processing as described
- You can withdraw consent or exercise rights anytime
---
END OF DATA PROCESSING AGREEMENT