Legal
Data Processing Terms (shops)
Last updated: 21 July 2026 · Version: 1.1
Audience: shop owners using TempahHQ. This is a product draft of processing terms for early access. Replace with counsel-approved DPA language before enterprise or regulated deployments.
These Data Processing Terms (“DPT”) form part of the Terms of Service when you use TempahHQ to process end-customer personal data.
Scope note: These DPT cover personal data of end customers processed on behalf of shops (bookings, pay-to-confirm, payment links, reminders). The platform activation fee (one-time RM50 paid by the shop to TempahHQ) is a separate B2B transaction between TempahHQ and the shop. Payment metadata for that fee is processed under the Privacy Policy and Terms §6.2—not as Customer personal data under this DPT.
1. Definitions
| Term | Meaning |
|---|---|
| Shop / you | The tenant business that creates an account and collects booking data from customers |
| TempahHQ / we | The platform operator |
| Customer personal data | Personal data of end customers (name, phone, email, booking and payment metadata, notification content) processed via the Service |
| Service | TempahHQ multi-tenant booking and payments software |
Plain-language roles: Data roles.
2. Roles
- For Customer personal data, you determine the purposes of processing (appointments, your business operations). You act as the business / data user responsible toward your customers under applicable law.
- TempahHQ processes Customer personal data on your documented instructions as embodied in the Service features (book, pay, confirm, remind, admin) and these Terms—i.e. as a service provider / processor for that data.
- For your staff accounts and platform telemetry, TempahHQ may act as an independent controller/operator as described in the Privacy Policy.
3. Nature and purpose of processing
| Item | Detail |
|---|---|
| Subject matter | Appointment booking, pay-to-confirm, payment links, admin calendar/ledger, transactional notifications |
| Duration | For the term of your use of the Service plus retention needed for security, disputes, and law |
| Types of data | Identity and contact (name, phone, email); booking details; payment status and gateway references; message logs |
| Data subjects | Your end customers and, where applicable, your staff whose names appear on bookings |
4. Shop instructions and obligations
You instruct us to process Customer personal data only to:
- Provide and support the Service
- Maintain security, prevent abuse, and ensure tenant isolation
- Comply with law
You must:
- Provide any notices and obtain any consents required for your use of customer data (especially marketing outside our transactional messages)
- Not configure the Service to process special categories of data unless we have agreed in writing (TempahHQ is not an EMR or clinical system)
- Use strong credentials and protect Billplz secrets
- Handle customer rights requests promptly; we will assist as described below
5. TempahHQ obligations
We will:
- Process Customer personal data only per these instructions, unless law requires otherwise (we will notify you if legally allowed)
- Ensure staff/contractors with access are bound by confidentiality
- Implement appropriate technical and organisational security measures for a multi-tenant booking SaaS
- Not sell Customer personal data
- Assist you with reasonable requests related to data subject rights, security incidents, and information needed for your compliance, taking into account the nature of processing
- Delete or return Customer personal data after account closure upon request, subject to legal retention and backup cycles
6. Sub-processors
You authorise us to use sub-processors to deliver the Service. The current list is published at Sub-processors.
We remain responsible for sub-processor performance under these DPT. We will post material changes to the sub-processor list on that page; continued use of the Service after an update constitutes acceptance of the updated list for early access. (Enterprise customers may negotiate advance notice separately.)
7. International transfers
Sub-processors may process data outside Malaysia. We use providers and contractual measures appropriate to the risk. See the sub-processors page for locations when known.
8. Security incidents
If we become aware of a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Customer personal data we process, we will notify you without undue delay and provide information reasonably available to help you meet your own notification duties.
Report suspected incidents to hello@tempahhq.com.
9. Audits
During early access, formal on-site audits are not offered by default. Upon reasonable written request we will provide security documentation summaries appropriate to partner readiness. Expanded audit rights may be agreed in a separate enterprise agreement.
10. Order of precedence
If these DPT conflict with the Terms regarding processing of Customer personal data, these DPT control for that subject. The Privacy Policy describes notices to individuals; it does not reduce your obligations to your customers.
11. Contact
Product drafts for early access — not a substitute for legal advice.