1 Parties and roles
This Data Processing Agreement ("DPA") is entered into between SKILLQ PTE. LTD., a company registered in Singapore (company registration number / UEN 202420247R), with registered office at 68 Circular Road #02-01, Singapore 049422 ("Processor", "Tailo"), and the customer organisation accepting this DPA ("Controller", "you").
You are the data controller; Tailo acts as data processor, processing personal data only on your documented instructions.
Acceptance occurs when an authorised representative of the Controller indicates agreement — including via the on-site checkbox presented during pilot onboarding — or otherwise signs this DPA. The individual accepting confirms they are authorised to bind the Controller.
2 Scope and purpose of processing
- Subject matter: processing of pseudonymized customer data to generate next-best-offer recommendations, holdout designs, and uplift analysis as part of a Tailo pilot.
- Duration: the pilot term, plus a wind-down period not exceeding 30 days, after which data is deleted (Section 9).
- Nature and purpose: modelling, scoring, and measurement to produce the pilot deliverables. Processing is limited to this purpose.
- No secondary use: Tailo will not sell the data, share it with third parties except permitted sub-processors (Section 7), or use it to train or improve models served to other customers, without the Controller's explicit prior written consent.
3 Categories of data and data subjects
- Data subjects: the Controller's customers.
- Categories of data: pseudonymized identifiers (hashed customer IDs), transaction history, campaign engagement history, and product / offer attributes.
Excluded data — what you must not send. Direct identifiers including names, email addresses, phone numbers, postal addresses, payment details, or any special-category data (Article 9 GDPR). The Controller is responsible for pseudonymizing data before transfer and warrants that submitted data contains no direct identifiers.
4 Controller obligations
- You determine the purposes and means of processing and confirm you have a lawful basis for the processing instructed.
- You are responsible for the lawfulness of the data you provide, including ensuring it is pseudonymized and free of direct identifiers before transfer.
- You will issue instructions only through lawful means.
5 Processor obligations
- Tailo processes personal data only on the Controller's documented instructions, including this DPA, unless required otherwise by law — in which case it will inform the Controller unless legally prohibited.
- Tailo ensures persons authorised to process the data are bound by confidentiality.
- Tailo will assist the Controller, taking into account the nature of processing, with: responding to data subject rights requests; data protection impact assessments; and security and breach obligations under Articles 32–36 GDPR.
- Tailo will make available information necessary to demonstrate compliance and allow for and contribute to audits, subject to reasonable confidentiality and security arrangements.
6 Security measures
Tailo implements appropriate technical and organisational measures, including:
- Encrypted transfer over an access-controlled channel — your approved secure channel, or a link Tailo provisions.
- Access restricted to named, least-privilege users, with access expiry tied to the pilot.
- Logging of transfers and access.
- Pseudonymized data only; no direct identifiers processed.
- No use of email attachments for data exchange.
A current description of measures is available on request.
7 Sub-processors
- The Controller provides general authorisation for Tailo to engage sub-processors to support processing. A current list of sub-processors is available on request from hello@tailoai.com.
- Tailo imposes data protection obligations on sub-processors no less protective than those in this DPA, and remains liable for their performance.
- Tailo will give the Controller reasonable notice of intended changes to sub-processors and an opportunity to object on reasonable data-protection grounds.
8 International transfers
Tailo operates globally and processes data in and from multiple regions, including via its operations in Singapore. Where personal data is transferred across borders, Tailo applies an appropriate lawful transfer mechanism for the regions involved, together with supplementary technical and organisational measures (such as pseudonymization) where required:
- From the EEA: the European Commission's Standard Contractual Clauses (Module Two, controller-to-processor), incorporated by reference.
- From the United Kingdom: the SCCs as supplemented by the UK International Data Transfer Addendum.
- From Switzerland: the SCCs with Swiss-specific amendments recognised by the FDPIC.
- From other jurisdictions: the transfer safeguard required by applicable local law (for example, recognised standard clauses, adequacy, or consent where permitted).
Because the Controller sends pseudonymized data only, the personal-data risk associated with any transfer is materially reduced. The specific clauses applicable to your engagement are available on request.
9 Retention and deletion
- On completion of the pilot, Tailo deletes the Controller's personal data and any derived working copies within 30 days, and confirms deletion in writing on request.
- If the Controller proceeds to a paid engagement, retention is governed by that engagement's terms and the Controller's instructions.
- Tailo will not retain data beyond the period necessary for the agreed purpose.
10 Personal data breach
Tailo will notify the Controller without undue delay after becoming aware of a personal data breach affecting the Controller's data, providing information reasonably available to assist the Controller in meeting its own notification obligations.
11 Liability, term, and governing law
- This DPA takes effect on acceptance and remains in force for the duration of processing.
- Liability is subject to the limitations set out in the applicable pilot or service agreement between the parties.
- This DPA is governed by the laws of Singapore, and the parties submit to the exclusive jurisdiction of the courts of Singapore, without prejudice to any mandatory data-protection rights or remedies available to data subjects under applicable law.
12 Contact
Data protection enquiries and requests: hello@tailoai.com.
Tailo has not appointed a dedicated Data Protection Officer; data protection matters are handled by the team reachable at the address above.
Acceptance
By accepting this agreement — including by ticking the acceptance checkbox during pilot onboarding — you confirm you are authorised to bind your organisation to these terms. Tailo may update this DPA; material changes affecting an active pilot will be notified to the Controller.
DPA version 1.0 · SKILLQ PTE. LTD. (UEN 202420247R) · 68 Circular Road #02-01, Singapore 049422