Data Processing Agreement

BEKIRIM DATA PROCESSING AGREEMENT (DPA) Last Updated: August 2026 Website: https://bekirim.com INTRODUCTION This Data Processing Agreement ("DPA") establishes the terms and conditions under which Bekirim ("Data Controller") processes personal data collected through the Bekirim platform ("Service"). This DPA applies to all users, including Customers and Drivers, and defines how personal data is collected, processed, stored, and protected in compliance with Brunei's Personal Data Protection Act (BDPA). Governing Law: This DPA is governed by the Personal Data Protection Act (BDPA) of Brunei Darussalam and applicable Brunei law. --- SECTION 1: DEFINITIONS AND ROLES 1.1 DEFINITIONS - "Personal Data" means any information relating to an identified or identifiable natural person - "Data Controller" means Bekirim, which determines the purposes and means of processing personal data - "Data Processor" means third parties (Supabase, Lovable, Google Maps) who process personal data on behalf of Bekirim - "Processing" means any operation performed on personal data (collection, storage, use, transmission, etc.) - "Data Subject" means the individual to whom personal data relates - "Data Breach" means unauthorized or accidental access, disclosure, or loss of personal data 1.2 PARTIES - Data Controller: Bekirim - Data Subjects: Customers, Drivers, and other users of the platform - Data Processors: * Supabase (database and storage) * Lovable (platform infrastructure) * Google Maps (location and routing services) --- SECTION 2: SCOPE AND PRINCIPLES 2.1 SCOPE This DPA covers: - Personal data collected through the Bekirim app and website - Processing of personal data by Bekirim and its processors - Storage and security of personal data - Compliance with BDPA requirements - User rights regarding their data 2.2 PRINCIPLES OF DATA PROCESSING Bekirim processes personal data in accordance with these principles: LAWFULNESS - Personal data is processed only for lawful purposes - Processing has a legitimate legal basis - Users are informed of data processing practices FAIRNESS - Data collection methods are transparent - Users understand why their data is collected - No deceptive or unfair practices TRANSPARENCY - Users are provided with clear information about processing - Privacy Policy explains collection and use of data - Users can access and control their personal data DATA MINIMIZATION - Only necessary personal data is collected - Excessive or irrelevant data is not collected - Collection is proportionate to purposes PURPOSE LIMITATION - Personal data is used only for stated purposes - Data is not repurposed without user consent - Secondary uses are clearly disclosed ACCURACY - Personal data is kept accurate and up-to-date - Inaccurate data is corrected promptly - Users can request corrections STORAGE LIMITATION - Personal data is retained only as long as necessary - Data is securely deleted when no longer needed - Retention schedules are documented INTEGRITY AND CONFIDENTIALITY - Personal data is protected against unauthorized access - Security measures are implemented and maintained - Data is kept confidential ACCOUNTABILITY - Bekirim maintains records of processing activities - Compliance is documented and verifiable - Responsibility for data protection is clear --- SECTION 3: PERSONAL DATA COLLECTION 3.1 TYPES OF PERSONAL DATA COLLECTED CUSTOMER DATA - Full name, email, phone number - Residential address and delivery addresses - Payment information (bank details, transaction history) - Location data (delivery location, GPS coordinates during delivery) - Device information (device type, IP address) - Usage data (orders, preferences, interaction history) - Communications (messages to/from Drivers) DRIVER DATA - Full name, email, phone number, home address - Driver's license number and expiry date - Vehicle information (make, model, registration number, insurance details) - Bank account information (for payment withdrawal) - Location data (real-time GPS, route information) - Insurance provider and policy details - Device information (device type, IP address) - Usage data (deliveries completed, ratings, earnings) - Background check results - Communications (messages to/from Customers) 3.2 LEGAL BASIS FOR PROCESSING DATA COLLECTION IS BASED ON: - Performance of the delivery service contract - Compliance with legal obligations (payment verification, identity verification) - Protection of legitimate interests (fraud prevention, safety, platform security) - User consent for certain processing activities (marketing communications, analytics) - Vital interests (safety and emergency response) 3.3 CONSENT For certain processing activities, Bekirim obtains explicit user consent: - Location tracking (Drivers) - Marketing communications - Use of analytics and cookies - Sharing data with third-party processors Users can withdraw consent at any time through account settings. --- SECTION 4: PROCESSING ACTIVITIES 4.1 PROCESSING PURPOSES Personal data is processed for: CORE SERVICE DELIVERY - Creating and maintaining user accounts - Facilitating deliveries - Processing payments and Digital Wallet transactions - Providing customer support - Communicating with users about orders IDENTITY AND ELIGIBILITY VERIFICATION - Verifying user age and identity - Verifying Driver license and insurance - Confirming eligibility for service PAYMENT PROCESSING - Processing manual bank transfers - Verifying payment transactions - Managing Digital Wallet accounts - Processing refunds and withdrawals SAFETY AND SECURITY - Detecting and preventing fraud - Monitoring for suspicious activity - Ensuring compliance with policies - Protecting platform security - Verifying delivery completion OPTIMIZATION AND IMPROVEMENT - Analyzing user behavior and trends - Improving app features and performance - Debugging technical issues - Conducting research and analytics LEGAL AND REGULATORY COMPLIANCE - Complying with Brunei law - Meeting regulatory requirements - Handling legal disputes - Maintaining audit trails DISPUTE RESOLUTION - Investigating complaints and disputes - Reviewing evidence and communications - Processing refund requests - Resolving payment disputes 4.2 AUTOMATED PROCESSING Bekirim uses automated processing for: - Fraud detection and prevention - Driver rating and qualification assessment - Delivery route optimization - Payment verification - Duplicate account detection For sensitive decisions (e.g., driver approval), human review is involved. --- SECTION 5: DATA RETENTION 5.1 RETENTION SCHEDULE ACTIVE ACCOUNT DATA - Retained while account is active - Deleted within 3 months of account closure POST-ACCOUNT CLOSURE - Retained for 3 years after closure for legal compliance and dispute resolution - Then permanently deleted PAYMENT RECORDS - Retained for 3 years (tax and audit purposes) - Longer if required by Brunei tax law DELIVERY RECORDS - Retained for 1 year (dispute resolution) - Deleted after 1 year if no disputes LOCATION DATA - Retained during active delivery - Deleted within 90 days after delivery completion - Longer if disputes are pending COMMUNICATIONS/SUPPORT RECORDS - Retained for 1 year after resolution - Longer if disputes are unresolved FRAUD/SECURITY RECORDS - Retained for 2 years (investigation and prevention purposes) 5.2 LEGAL HOLDS Data subject to legal holds or disputes is retained until the matter is resolved. 5.3 SECURE DELETION When data is deleted: - Deleted from primary storage systems - Deleted from backup systems within 90 days - Deletion is permanent and irreversible - Deletion certificates are maintained --- SECTION 6: DATA PROCESSORS AND THIRD PARTIES 6.1 AUTHORIZED DATA PROCESSORS SUPABASE (Database Provider) - Role: Stores and manages all personal data - Processing: Data storage, encryption, access management - Location: International (servers outside Brunei) - Agreement: Supabase is contractually bound to process data according to this DPA - Security: Implements encryption at rest and in transit LOVABLE (Platform Infrastructure) - Role: Hosts and operates the Bekirim platform - Processing: App hosting, user authentication, access logs - Location: Cloud infrastructure - Agreement: Lovable processes data only as instructed - Security: Implements platform-level security measures GOOGLE MAPS (Location Services) - Role: Provides mapping, routing, and location services - Processing: Receives location data and delivery addresses - Location: Google's data centers - Agreement: Limited to routing purposes only - Data Retention: Google does not retain location data long-term PAYMENT VERIFICATION - Role: Manual verification of bank transfers by Bekirim Admin staff - Processing: Access to bank transfer information for verification - Security: Admin staff bound by confidentiality agreements - Access: Limited to staff with verification responsibilities 6.2 PROCESSOR AGREEMENTS Data processors are bound by: - Written data processing agreements - Confidentiality obligations - Security requirements - Data protection standards - Audit and compliance requirements - Data subject rights enforcement 6.3 SUBPROCESSORS Processors may use subprocessors (e.g., cloud infrastructure providers) with: - Prior notification to Bekirim - Contractual data protection obligations - Equivalent security standards - Subject to this DPA terms 6.4 INTERNATIONAL DATA TRANSFERS Personal data is transferred internationally to: - Supabase servers (location varies) - Google servers (global infrastructure) - Lovable infrastructure (cloud-based) By using Bekirim, users consent to international data transfers. --- SECTION 7: DATA SUBJECT RIGHTS 7.1 RIGHT TO ACCESS Data subjects have the right to: - Request access to their personal data - Receive information about data processing - Obtain a copy of their data - No charge for reasonable requests - Response within 30 days 7.2 RIGHT TO CORRECTION Data subjects have the right to: - Request correction of inaccurate data - Update personal information through account - Request changes through support team - No unreasonable delay in correction 7.3 RIGHT TO DELETION Data subjects have the right to: - Request deletion of personal data - Erasure of data from all systems - Exceptions for legal compliance or contract fulfillment - Response within 30 days - Note: Some data retained for legal reasons 7.4 RIGHT TO RESTRICT PROCESSING Data subjects have the right to: - Limit processing of their data - Request suspension of certain processing - Maintain access while processing is restricted - Used pending correction or disputes 7.5 RIGHT TO DATA PORTABILITY Data subjects have the right to: - Receive personal data in structured format - Transfer data to another service - Commonly used formats (CSV, JSON) - Response within 30 days 7.6 RIGHT TO WITHDRAW CONSENT Data subjects have the right to: - Withdraw consent for processing anytime - Opt out of marketing communications - Disable location tracking (if feature allows) - Effect through account settings or support 7.7 EXERCISING RIGHTS To exercise data subject rights: Email: [INSERT CONTACT EMAIL] Include: - Full name and account email - Specific right being exercised - Supporting documentation - Any relevant dates or transaction IDs Response: Within 30 days, Bekirim will: - Confirm receipt of request - Process the request - Provide response with data or confirmation - Explain any delays or refusals --- SECTION 8: DATA SECURITY 8.1 SECURITY MEASURES ENCRYPTION - Data encrypted in transit (HTTPS/TLS) - Data encrypted at rest in Supabase - Encryption keys managed securely - Industry-standard encryption algorithms ACCESS CONTROL - Role-based access management - Admin staff have limited access to necessary data only - Multi-factor authentication for admin accounts - Access logs maintained for accountability STORAGE SECURITY - Secure storage in Supabase data centers - Regular security updates and patches - Firewalls and intrusion detection systems - Regular security audits BACKUP AND RECOVERY - Regular encrypted backups maintained - Backup data stored securely - Recovery procedures tested regularly - Backup retention per retention schedule MONITORING - Continuous security monitoring - Automated threat detection - Incident response procedures - Security event logging EMPLOYEE TRAINING - Staff trained on data protection - Confidentiality agreements with employees - Regular security awareness training - Compliance procedures documented 8.2 SECURITY RESPONSIBILITIES BEKIRIM RESPONSIBILITIES - Implements and maintains security measures - Conducts regular security assessments - Updates security practices - Responds to security incidents - Ensures processor compliance PROCESSOR RESPONSIBILITIES - Implements agreed security measures - Reports security incidents - Maintains security certifications - Provides audit evidence - Cooperates with security assessments USER RESPONSIBILITIES - Keep login credentials confidential - Do not share account information - Report suspicious activity immediately - Maintain device security - Update passwords regularly 8.3 SECURITY INCIDENT RESPONSE DATA BREACH PROCEDURE 1. Incident is discovered or reported 2. Immediate investigation begins 3. Affected systems isolated if necessary 4. Evidence preserved for analysis 5. Data Subjects notified within reasonable time 6. Regulatory authorities notified if required 7. Remedial action implemented 8. Post-incident review conducted NOTIFICATION - Affected users notified of breaches affecting their data - Notification includes: * Nature of breach * Data affected * Potential impact * Protective measures taken * Contact for questions - Notification sent via email or in-app notification --- SECTION 9: DATA PROTECTION BY DESIGN AND DEFAULT 9.1 IMPLEMENTATION Bekirim implements data protection principles in: - App design and development - Feature planning and rollout - Infrastructure decisions - Third-party vendor selection - Policy and procedure development 9.2 PRIVACY BY DEFAULT - Minimum necessary data is collected - Shortest necessary retention periods - Users control sharing of their data - Privacy settings favor user preferences - Opt-in for non-essential processing --- SECTION 10: DATA IMPACT ASSESSMENTS 10.1 IMPACT ASSESSMENTS Bekirim conducts Data Protection Impact Assessments (DPIA) for: - New features that process personal data - Significant changes to processing - High-risk processing activities - Automated decision-making systems 10.2 ASSESSMENT CONTENTS Assessments include: - Description of processing - Purpose and legal basis - Data types and categories - Risk analysis - Mitigation measures - Risk ratings --- SECTION 11: COMPLIANCE AND ACCOUNTABILITY 11.1 COMPLIANCE DOCUMENTATION Bekirim maintains: - Records of all processing activities - Data protection policies - Staff training records - Security audit reports - Incident logs - Data subject request records - Processor agreements - DPA update history 11.2 AUDIT AND MONITORING - Regular internal audits of data protection compliance - Processor compliance monitoring - User rights requests tracked - Processing activities reviewed periodically - Compliance issues documented and addressed 11.3 REGULATORY COOPERATION Bekirim cooperates with: - Brunei Personal Data Protection Authority - Government agencies as required - Law enforcement with proper legal authority - Regulatory investigations and audits --- SECTION 12: CHANGES TO THIS AGREEMENT 12.1 MODIFICATIONS Bekirim may modify this DPA: - To comply with new laws or regulations - To improve data protection practices - To reflect changes in operations - To address security developments 12.2 NOTIFICATION - Significant changes notified to users - Changes effective upon notice - Users may object to material adverse changes - Continued use constitutes acceptance --- SECTION 13: CONTACT INFORMATION For data protection inquiries or to exercise data subject rights: Email: [INSERT CONTACT EMAIL] Website: https://bekirim.com Address: [INSERT BEKIRIM BUSINESS ADDRESS] Data Protection Officer: [INSERT NAME/TITLE IF APPLICABLE] Response target: 30 days for most inquiries --- SECTION 14: ACKNOWLEDGMENT By using Bekirim, you acknowledge: - You have read and understand this DPA - You understand how your personal data is processed - You understand your rights regarding your data - You consent to processing as described - You can withdraw consent or exercise rights anytime --- END OF DATA PROCESSING AGREEMENT