Legal
General Terms & Conditions
Ryse Cloud Pte. Ltd. (UEN: 202611557W)
Version 1.0, Effective 01 May 2026
These General Terms & Conditions are the commercial contractual terms that apply to a signed Order Form between Ryse Cloud Pte. Ltd. (“Ryse”) and the Customer. They govern the Customer's receipt of the Services under the Agreement.
1. Definitions and Interpretation
1.1 Definitions. In the Agreement, unless the context requires otherwise:
- "Affiliate" means, with respect to a party, any entity that directly or indirectly controls, is controlled by, or is under common control with that party, where "control" means ownership of more than 50% of the voting securities or equity interests of an entity, or the power to direct its management and policies.
- "Agreement" means, collectively, the Order Form, these General Terms and Conditions, the Ryse Privacy Policy, and the Schedules, each as amended in accordance with clause 16.7.
- "Commencement Date" means the date specified as such in the Order Form or, if none is specified, the date on which the Platform is made generally available to the public on behalf of the Customer.
- "Confidential Information" means any information disclosed by or on behalf of one party (the "Disclosing Party") to the other (the "Receiving Party"), whether before or after the Effective Date, that is marked as confidential or that a reasonable person would understand to be confidential, including the terms of the Agreement, business and financial information, Customer Data, and the Platform and its underlying technology.
- "Customer" means the legal entity identified as the Customer in the Order Form.
- "Customer Data" means all data, content, and materials submitted by or on behalf of the Customer to the Platform, including end-purchaser data, brand assets, and transaction records.
- "DPA" means the Data Processing Agreement at Schedule B.
- "Effective Date" means the later of the two dates set out in the signature block of the Order Form.
- "Fees" means the Transaction Fee and any other amounts payable by the Customer as set out in the Order Form.
- "Gross Transaction Value" or "GTV" means, for any period, the aggregate gross amount paid by end purchasers for Products sold by or on behalf of the Customer (whether through the Customer's storefront or otherwise) on the Platform during that period, before deduction of any Fees, but excluding refunds processed, chargebacks to purchasers, and applicable taxes collected on behalf of a taxing authority (if and where applicable).
- "Initial Term" means the period specified as such in the Order Form.
- "Order Form" means the Ryse Order Form executed by the parties that references and incorporates these General Terms & Conditions.
- "Personal Data" means the personal data collected, processed, stored, or otherwise used as defined in the DPA.
- "Platform" means the Ryse digital commerce software, white-label storefront, dashboards, and APIs, together with any and all related services made available by Ryse and updated from time to time.
- "Privacy Policy" means the Ryse Privacy Policy in effect as amended from time to time and published at www.rysecloud.com/privacy.
- "Product" means any digital or physical item created, sold, fulfilled, redeemed, made available or otherwise transacted through the Platform, including gift vouchers, gift cards, packages, prepaid or stored-value products, and physical goods and merchandise.
- "Properties" means the hotel(s), hospitality property/properties, or Customer's facilities listed in the Order Form for which the Services are provided.
- "Renewal Term" has the meaning given in clause 6.2.
- "Schedules" means Schedule A (Description of Services) and Schedule B (Data Processing Agreement), together with any other schedule added from time-to-time.
- "Services" means the services described in Schedule A and the Order Form, provided through the Platform.
- "Transaction Fee" means the Transaction Fee Rate applied to GTV, as set out in the Order Form.
1.2 Interpretation: (a) Clause and Schedule headings are for convenience only and do not affect interpretation; (b) references to a "party" are to Ryse or the Customer, and to the "parties" are to both; (c) "Including" and "in particular" are without limitation; (d) references to writing include email; and (e) references to a statute or regulation are to that statute or regulation as amended or re-enacted from time to time.
2. Structure of the Agreement and Order of Precedence
2.1 The Agreement comprises the Order Form, these General Terms & Conditions, the Privacy Policy, and the Schedules, which are to be read together as a single agreement. 2.2 If there is any conflict or inconsistency between the documents making up the Agreement, the following order of precedence applies (highest first): (a) the Order Form; (b) these General Terms & Conditions; (c) the Schedules, except that the DPA (Schedule B) prevails over all other documents in respect of the processing of Personal Data; and (d) the Privacy Policy. 2.3 The Agreement constitutes the entire commercial agreement between the parties for the supply of the Services and supersedes any prior or contemporaneous understanding on that subject matter. The Ryse website / platform Terms of Use continue to govern general access to the Platform but do not override the Agreement; in the event of any conflict between those Terms of Use and the Agreement in respect of the Customer's receipt of the Services, the Agreement prevails.
3. The Services
3.1 Ryse will provide the Services described in Schedule A and the Order Form to the Customer for the Properties, with reasonable skill and care. 3.2 Ryse will use commercially reasonable efforts to make the Platform available, except for planned maintenance (for which Ryse will give reasonable notice where practicable) and emergency maintenance. 3.3 Ryse may improve, update, or modify the Platform from time to time, provided that no such change will materially reduce the core functionality of the Services during the then-current Term. 3.4 Services not expressly listed in Schedule A or the Order Form (including the items listed as out of scope in Schedule A) are not included and may be provided only under a separate written agreement and at additional cost.
3A. Role of Ryse; Agency
3A.1 The Customer is the principal and the legal seller of all Products offered through its storefront on the Platform. Ryse does not take title to, own, purchase, or resell any Product, and is not a party to the contract of sale between the Customer and any end purchaser. 3A.2 Ryse acts solely as a disclosed agent of the Customer for the limited purposes of (a) collecting payment from end purchasers on the Customer's behalf in accordance with clause 5A, and (b) facilitating the creation, marketing, and redemption tracking of Products through the Platform. Except as expressly stated in this clause, the parties remain independent contractors, and nothing in the Agreement makes Ryse a general agent of the Customer or gives Ryse authority to bind the Customer to any obligation beyond what is expressly set out in the Agreement. 3A.3 Ryse is an intermediary that operates the Platform on behalf of Customer. Ryse does not act as principal, reseller, or merchant of record in respect of any Product, and nothing in the Agreement shall be read as Ryse selling, reselling, or otherwise dealing in Products in its own name, whether through the Customer's white-label storefront or any other channel through which Products are made available under this Agreement. Ryse may, at its discretion, make Products available for sale through additional channels beyond the Customer's white-label storefront or API, including third-parties or other channels, or any marketplace whether operated by Ryse or otherwise (each, an "Additional Channel"). Ryse acts solely as Customer's agent and intermediary in respect of any such sale, and Customer remains the seller of record for all Products sold through an Additional Channel. Customer may opt out of participation in any existing or future Additional Channel, in whole or by specifying the particular Additional Channel(s) from which Customer elects to withdraw, by giving Ryse written notice, with such withdrawal taking effect no later than 30 days after Ryse's receipt of any such written notice. Opting out does not affect Products already sold through an Additional Channel prior to the opt-out taking effect.
4. Customer Obligations
4.1 The Customer will: (a) provide accurate and complete information reasonably required by Ryse to provide the Services; (b) keep account credentials confidential and be responsible for activity under its account; (c) use commercial reasonable measures to protect such credentials and avoid any unauthorised use and/or access, and to promptly notify Ryse at hello@rysecloud.com of any suspected unauthorised use and/or access; and (d) ensure that its use of the Platform and any Products complies with any applicable laws. 4.2 The Customer will not use the Platform to create or sell Products for services that are fraudulent, misleading, not legitimately offered by the relevant Property, or otherwise not generally permitted by law in either the Customer's home market or markets in which the Products are made available for sale. The Customer shall be solely responsible for such compliance and shall indemnify and hold harmless Ryse against any liability arising from a breach of this clause. 4.3 The Customer is responsible for the accuracy of its brand assets, product listings, pricing (including any applicable taxes), and its ability to deliver and fulfil the underlying goods, services, or experiences represented by its Products.
5. Fees, GTV and Payment
5.1 In consideration for the Services, the Customer will pay the Fees set out in the Order Form. The Transaction Fee is calculated by applying the Transaction Fee Rate to GTV for each relevant billing period. 5.2 Unless the Order Form states otherwise, Ryse will deduct or invoice the Transaction Fee and any other applicable fees determined by the value or number of transactions against GTV processed through the Platform for each relevant billing period, together with any taxes pursuant to clause 5.4. 5.3 Any fixed Fees (such as a custom domain fee) are payable in advance for the relevant period. Unless the Order Form states otherwise, any and all invoiced amounts are payable within 30 days of the invoice date. Ryse may at its sole discretion charge interest on overdue amounts at 1.5% per month or the maximum permitted by law, whichever is lower. 5.4 All Fees are exclusive of sales tax(es) and/or other applicable taxes, which the Customer will pay in addition where chargeable. 5.5 Fees are as stated in the Order Form. Ryse may revise the Fees for a Renewal Term by giving the Customer at least 30 days' written notice before the end of the then-current Term.
5A. Payment Collection
5A.1 Ryse will collect payment from end purchasers for Products sold through the Customer's storefront or otherwise transacted through the Platform, acting as the Customer's payment collection agent. Amounts collected are held for the account of the Customer until Product redemption or expiry, less the Transaction Fee and any other Fees or charges together with applicable taxes due under the Order Form. 5A.2 Amounts collected under clause 5A.1 become payable to the Customer only upon redemption or expiry of the relevant Product. Ryse will remit the net amount due to the Customer, to the Customer's nominated bank account (as advised from time-to-time), within 7 days following the end of the month in which redemption or expiry took place – unless an alternative payment schedule is specified in the Order Form or thereafter agreed in writing between the parties. 5A.3 Payment by an end purchaser to Ryse for a Product discharges that purchaser's payment obligation to the Customer for that purchase, to the extent of the amount paid.
5B. Taxes on Product Sales
5B.1 The Customer is solely responsible for determining the taxes (including VAT, GST, sales or use tax, and/or any other taxes) applicable to its Products, for ensuring such taxes are correctly charged to end purchasers, and for remitting such taxes to the relevant tax authority, except to the extent Ryse is required by applicable law to collect and remit such taxes under clause 5B.2. 5B.2 Where applicable law requires Ryse, as operator of the Platform, to collect and remit tax on sales of Products on the Customer's behalf (for example, under a marketplace facilitator or equivalent statute), Ryse will do so, and the Customer will provide the tax determination information Ryse reasonably requests for that purpose. Should Ryse be required to pay any taxes on behalf of the Customer, Ryse shall be entitled to claw back such payment from the Customer. Ryse's compliance with such a requirement does not make Ryse the seller of the underlying Product, the merchant of record, or a party to the sale contract. 5B.3 Ryse is not the merchant of record for any Product sale. Ryse's own GST, VAT, and/or sales tax obligations are limited to any applicable taxes properly chargeable on its own Fees under clause 5 or any other charges payable by the Customer.
5C. Invoicing and Receipts
5C.1 Receipts issued to end purchasers for Product sales will identify the Customer, by its legal entity name and where applicable its tax registration number, as the seller, and will state that the sale was facilitated by Ryse acting as the Customer's agent. 5C.2 The Customer will keep its legal entity and tax registration details with Ryse current and accurate for this purpose.
6. Term and Termination
6.1 The Agreement takes effect on the Effective Date. The Initial Term commences on the Commencement Date and continues for the Initial Term, unless terminated earlier in accordance with this clause 6. 6.1A If the Commencement Date has not occurred within 90 days of the Effective Date, either party may terminate the Agreement by written notice with immediate effect. On such termination, neither party will have any liability to the other except in respect of obligations accrued before termination. 6.2 After the Initial Term, the Agreement automatically renews for successive 12-month periods (each a "Renewal Term", and together with the Initial Term, the "Term") unless either party gives written notice of non-renewal at least 30 days before the end of the then-current Term, consistent with the Order Form. 6.3 Either party may terminate the Agreement on written notice if the other party: (a) commits a material breach that is not remedied within 30 days of written notice requiring it to do so; or (b) becomes insolvent, enters liquidation or judicial management, or is unable to pay its debts as they fall due. 6.4 Ryse may terminate the Agreement for convenience on 60 days' written notice. The Customer may terminate for convenience with effect from the end of the then-current Term in accordance with clause 6.2. 6.4A Should the Customer fail to log in to the Platform or process any Product transaction(s) for a consecutive period of 90 days ("Inactivity"), Ryse may issue a written notice of Inactivity to the Customer. If the Customer does not resume use of the Platform within 14 days of issuance of such notice, Ryse may terminate this Agreement and suspend the Customer's access to the Platform without further notice. Upon termination under this clause, Ryse shall provide the Customer a period of 30 days to retrieve its data before any deletion, and this clause shall not affect either party's obligations in respect of Products issued prior to termination, obligations pursuant to clause 6.5, or the survival of any other clauses as specified in clause 6.6. 6.5 On termination or expiry of the Agreement: (a) the Customer's right to use the Platform ceases; (b) the Customer will pay all Fees accrued up to the effective date of termination; and (c) each party will, on request, return or destroy the other's Confidential Information, subject to legal retention requirements. 6.6 Termination does not affect any rights or liabilities accrued before the effective date of termination. Clauses that by their nature should survive (including clauses 1, 5 (for accrued amounts), 7, 8, 9, 11, 12, 13, and 17) survive termination.
7. Intellectual Property and Brand Licence
7.1 All intellectual property rights in the Platform (including its software, design, trademarks, and Ryse-created content) are and remain the exclusive property of Ryse. The Agreement grants the Customer no ownership interest in the Platform. 7.2 The Customer grants Ryse a limited, non-exclusive, royalty-free licence to use the Customer's brand assets (logos, images, and copy) to operate the Customer's gifting storefront and provide the Services, and to identify the Customer in Ryse's marketing and promotional materials. The Customer's branding is used on its storefront because the Customer, not Ryse, is the seller of the Products offered there. Neither this licence nor its use should be construed as Ryse selling Products in its own name. The Customer may withdraw consent to marketing use by Ryse at any time by written notice, and Ryse shall cease such use within 30 days. 7.3 As between the parties, the Customer owns all Customer Data. The Customer grants Ryse a non-exclusive licence to host, process, and use Customer Data as necessary to provide the Services and as set out in the DPA, and to create and use aggregated, anonymised data that does not identify the Customer, any Property, or end-purchasers for research, benchmarking, and market studies.
8. Confidentiality
8.1 The Receiving Party will keep the Disclosing Party's Confidential Information confidential, use it only to perform or receive the Services, and disclose it only to its personnel, advisers, consultants, and/or contractors who need to know it and are bound by equivalent obligations. 8.2 Clause 8.1 does not apply to information that is or becomes public other than through breach, is independently developed, is lawfully received from a third party, or is required to be disclosed by law or a regulator (in which case the relevant party will give reasonable notice where lawfully permitted to do so).
9. Data Protection
9.1 Where Ryse processes Personal Data on behalf of the Customer in connection with the Services, the parties will comply with the DPA at Schedule B and applicable data protection laws, including the Singapore Personal Data Protection Act 2012.
10. Third-Party Integrations
10.1 The Platform may integrate with or link to third-party services. The Customer's use of any third-party service is subject to that third party's terms, and any applicable fees, charges, and/or taxes. 10.2 Ryse does not warrant that integrations with third-party systems will operate as intended and/or remain available, and Ryse is not liable for any resulting interruption to, or discontinuation of, any such integration.
11. Warranties
11.1 Each party warrants that it has the authority to enter into the Agreement and that doing so does not breach any other agreement binding on it. 11.2 Ryse warrants that it will provide the Services with reasonable skill and care. Except as expressly stated in the Agreement, and to the fullest extent permitted by law, the Platform and Services are provided "as is", and Ryse disclaims all other warranties, express or implied, including implied warranties of merchantability, fitness for a particular purpose, and non-infringement, and does not warrant that the Platform will be uninterrupted or error-free.
12. Limitation of Liability
12.1 Nothing in the Agreement limits or excludes either party's liability for death or personal injury caused by negligence, fraud or fraudulent misrepresentation, or any liability that cannot be limited or excluded under applicable law. 12.2 Subject to clause 12.1, neither party is liable for any indirect, incidental, special, consequential, or punitive loss, or for loss of profits, revenue, data, or goodwill, whether in contract, tort, or otherwise. 12.3 Subject to clauses 12.1, 12.2, and 12.4, each party's total aggregate liability arising out of or in connection with the Agreement will not exceed the greater of (a) the total Fees paid or payable by the Customer in the 12 months preceding the event giving rise to the claim, and (b) SGD10,000. 12.4 The cap in clause 12.3 does not apply to: (a) Ryse's obligation to remit amounts collected and held for the Customer's account under clause 5A or Schedule A - A.5; (b) either party's payment obligations under the Agreement; or (c) the Customer's indemnification obligations under clause 13.
13. Indemnification
13.1 The Customer will indemnify and hold harmless Ryse and its officers, directors, employees, agents, and contractors from and against any claims, liabilities, damages, losses, and reasonable expenses (including reasonable legal fees) arising out of: (a) the Customer's breach of the Agreement; (b) the goods, services, or experiences underlying the Customer's Products; or (c) any third-party claim relating to Customer Data, the Customer's use of the Platform, or end-user data or end-user's use of the Platform, except to the extent caused by Ryse's breach or negligence.
14. Suspension
14.1 Ryse may suspend the Customer's access to the Platform, in whole or in part: (a) on written notice, if the Customer fails to pay any undisputed Fees when due and does not remedy the failure within 14 days of that notice; (b) immediately and without prior notice, where suspension is reasonably necessary to address a material security risk, or actual or suspected unlawful or unauthorised activity; or (c) immediately and without prior notice, where required by applicable law or a regulator. 14.2 Where Ryse suspends without prior notice under clause 14.1(b) or (c), it will notify the Customer as soon as reasonably practicable, including (where lawfully permitted) the reason for the suspension. 14.3 Ryse will limit any suspension to the scope and duration reasonably necessary and will restore access once the cause of the suspension is resolved or, in the case of clause 14.1(a), once the overdue amounts are paid. 14.4 Suspension does not relieve the Customer of any obligation that accrues during the Term, including the obligation to pay Fees, and does not limit any other right or remedy available to Ryse, including termination under clause 6.
15. Force Majeure
15.1 Neither party is liable for any delay or failure to perform (other than a payment obligation) caused by an event beyond its reasonable control, provided it takes reasonable steps to mitigate. If the event continues for more than 90 days, either party may terminate the affected Services on written notice.
16. General
16.1 Assignment. Neither party may assign or transfer this Agreement without the other's prior written consent, not to be unreasonably withheld, except that either party may assign this Agreement upon written notice to the other party, (a) to an Affiliate, or (b) in connection with a merger, acquisition, or sale of all or substantially all of the assets of that party or of the business or division to which this Agreement relates, provided always that the assignee assumes all of the assigning party's obligations under this Agreement. 16.2 Notices. Notices must be in writing and sent to the contact details in the Order Form (and, for Ryse, to hello@rysecloud.com). Notices are deemed received on delivery, or on the next business day if sent by email. 16.3 Relationship. Except for the limited agency described in clause 3A, the parties are independent contractors. Nothing in the Agreement creates a partnership or employment relationship between the parties. 16.4 No third-party rights. A person who is not a party to the Agreement has no rights under the Contracts (Rights of Third Parties) Act 2001 of Singapore to enforce any term. 16.5 Waiver. A failure or delay in exercising a right is not a waiver of it. 16.6 Severance. If any provision is held invalid or unenforceable, the remaining provisions continue in full force, and the invalid provision will be modified to the minimum extent necessary to make it enforceable. 16.7 Variation. Any variation to the Order Form must be in writing and signed by (or on behalf of) both parties. Ryse may revise these General Terms & Conditions and/or the Privacy Policy at any time by posting a revised version or by notifying the Customer in writing. The revised terms take effect on the date of posting or, if Ryse notifies the Customer by email, on the date stated in that notice. The Customer's continued use of the Services after the effective date of a revision constitutes acceptance of it. Notwithstanding the foregoing, no revision that is materially adverse to the Customer will take effect in respect of the then-current Term without at least 30 days' prior notice to the Customer. 16.8 Entire agreement. The Agreement is the entire agreement between the parties for the Services and supersedes all prior representations and agreements on that subject matter.
17. Governing Law and Dispute Resolution
17.1 The Agreement is governed by the laws of the Republic of Singapore, without regard to conflict of law principles. 17.2 Any dispute arising out of or in connection with the Agreement, including any question regarding its existence, validity, or termination, will be referred to and finally resolved by arbitration in Singapore administered by the Singapore International Arbitration Centre ("SIAC") in accordance with the SIAC Rules in force, as amended from time to time. The tribunal will consist of one arbitrator, and the language of the arbitration will be English.
For any questions about the Agreement, contact hello@rysecloud.com.
Schedule A
Description of Services
A.1 Core Platform
• Product creation, management, and redemption tools • Inventory management • Automated Product delivery by email to end purchasers • Automated approval workflow engine • Expiry date management (where applicable) and redemption tracking • Multi-currency and multi-language support (as available at the relevant time) • Shipping & Fulfilment management • Promotions and discount codes • Secure checkout & payment processing
A.2 White-Label Storefront
• Branded gifting storefront configured with the Customer's logo, colours, and imagery • Custom domain or subdomain setup (Customer to provide domain access where applicable), subject to applicable Fees • Web and mobile-responsive design • Product listing and display
A.3 Reporting and Analytics
• Real-time sales and GTV dashboard • Product issuance, redemption, and expiry reports • Revenue and transaction history export (CSV) • Monthly performance reports
A.4 Onboarding and Support
Standard onboarding (included at no additional charge): • Account activation and standard Platform configuration using Ryse's self-serve setup tools • One remote onboarding training session • Email support during Ryse business hours (Singapore time) • Access to Ryse's knowledge base and help documentation Premium Setup (optional service, available at the fee stated in the Order Form) Ryse performs the account configuration on the Customer's behalf, including storefront branding setup, product and pricing configuration, domain configuration, and pre-launch review. Premium Setup excludes items listed in A.6.
A.5 Expired Product Remittance
When a Product reaches its expiry date without being redeemed, Ryse will remit to the Customer the percentage of its Residual Value specified in the Order Form (the Customer Rebate), in the next scheduled remittance cycle following expiry, subject to applicable law. "Residual Value" means the unredeemed value of a Product as at its expiry date.
A.6 Out of Scope
The following are not included in the Services without a separate written agreement and applicable fees: custom software development, on-site training, account configuration beyond standard onboarding (unless Premium Setup is selected in the Order Form), integration work beyond Schedule A, multi-language content translation, and any services not expressly listed in this Schedule A.
Schedule B
Data Processing Agreement
This Schedule B forms part of the Agreement between Ryse and the Customer and governs the processing of Personal Data by Ryse on behalf of the Customer in connection with the Services.
DPA.1 Definitions
Terms not defined in this Schedule B have the meanings given to them in clause 1.1 of the General Terms & Conditions. In this Schedule B:
- "Applicable Data Protection Law" means, as relevant to a party or the processing in question: (a) the Singapore Personal Data Protection Act 2012 ("PDPA") and any regulations or guidelines issued thereunder; (b) the EU General Data Protection Regulation (2016/679) ("GDPR"), where the processing involves Personal Data of individuals in the European Economic Area ("EEA"); (c) the UK General Data Protection Regulation and the Data Protection Act 2018 ("UK GDPR"), where the processing involves Personal Data of individuals in the United Kingdom; and (d) any other data protection or privacy law applicable to either party in connection with the Services.
- "Controller" means the Customer, as the party that determines the purposes and means of processing Personal Data. This term is used for convenience and alignment with GDPR terminology; see DPA.12.2 for its application under the PDPA.
- "Data Subject" means an identified or identifiable natural person whose Personal Data is processed under this Schedule B, primarily end purchasers.
- "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data.
- "Processing" (and "Process", "Processed", "Processes") means any operation or set of operations performed on Personal Data, whether or not by automated means, including collection, recording, storage, adaptation, retrieval, use, disclosure, combination, restriction, erasure, or destruction.
- "Processor" means Ryse, as the party that processes Personal Data on behalf of the Controller. This term is used for convenience and alignment with GDPR terminology; see DPA.12.2 for its application under the PDPA.
- "Sub-processor" means any third-party processor engaged by Ryse to process Personal Data on behalf of the Customer in connection with the Services.
- "Supervisory Authority" means a public authority responsible for monitoring the application of Applicable Data Protection Law, including the Personal Data Protection Commission (Singapore), national data protection authorities within the EEA, and the Information Commissioner's Office (UK).
DPA.2 Scope and Duration
DPA.2.1 This Schedule B applies to all processing of Personal Data carried out by Ryse in the course of providing the Services to the Customer. DPA.2.2 The subject matter, nature, purpose, and duration of the processing, the types of Personal Data processed, and the categories of Data Subjects are set out in Annex A. DPA.2.3 This Schedule B remains in force for as long as Ryse processes Personal Data on behalf of the Customer and terminates automatically upon expiry or termination of the Agreement, subject to the data deletion and return obligations in DPA.10.
DPA.3 Processor Obligations
Ryse agrees, as Processor, to the following: DPA.3.1 Instructions. Ryse will process Personal Data only on the documented instructions of the Customer, including as set out in the Agreement and this Schedule B, unless required to do so by applicable law. Where Ryse is required by law to process Personal Data other than in accordance with the Customer's instructions, Ryse will inform the Customer of that requirement before processing, unless prohibited by law. DPA.3.2 Notification of unlawful instructions. Ryse will promptly inform the Customer if, in its reasonable opinion, an instruction given by the Customer infringes Applicable Data Protection Law. DPA.3.3 Confidentiality. Ryse will ensure that all personnel authorised to process Personal Data are subject to binding obligations of confidentiality with respect to that data, whether by contract or statutory duty. DPA.3.4 Security. Ryse will implement and maintain appropriate technical and organisational measures to protect Personal Data against unauthorised or unlawful processing and against accidental loss, destruction, damage, alteration, or disclosure, as further described in Annex B. DPA.3.5 Sub-processors. Ryse may engage Sub-processors to process Personal Data in accordance with the general authorisation and notice provisions set out in DPA.6. DPA.3.6 Assistance — data subject rights. Ryse will assist the Customer, by appropriate technical and organisational measures and to the extent reasonably practicable, in fulfilling the Customer's obligations to respond to requests from Data Subjects exercising their rights under Applicable Data Protection Law (including rights of access, rectification, erasure, restriction, portability, and objection). DPA.3.7 Assistance — other obligations. Ryse will assist the Customer in ensuring compliance with obligations relating to: (a) security of processing; (b) notification of Personal Data Breaches to Supervisory Authorities and Data Subjects; (c) data protection impact assessments; and (d) prior consultation with Supervisory Authorities, having regard to the nature of the processing and the information available to Ryse. DPA.3.8 Deletion and return. Upon termination or expiry of the Agreement, Ryse will, at the Customer's election and subject to DPA.10, delete or return all Personal Data processed on behalf of the Customer. DPA.3.9 Audit. Ryse will make available to the Customer information reasonably necessary to demonstrate compliance with this Schedule B and will permit and contribute to audits conducted by the Customer or an auditor mandated by the Customer, in accordance with DPA.11.
DPA.4 Customer Obligations
DPA.4.1 The Customer, as Controller, represents and warrants that: (a) it has a lawful basis under Applicable Data Protection Law for collecting and transferring Personal Data to Ryse for processing; (b) its instructions to Ryse regarding the processing of Personal Data comply with Applicable Data Protection Law; (c) it has provided appropriate privacy notices to Data Subjects at the point of data collection, including in relation to the processing activities described in Annex A; and (d) it will comply with its own obligations under Applicable Data Protection Law in connection with the Services. DPA.4.2 The Customer is responsible for the accuracy, quality, and legality of Personal Data it provides to Ryse, and for the means by which it acquired that data.
DPA.5 Security
DPA.5.1 Ryse will implement and maintain the technical and organisational security measures described in Annex B, taking into account: (a) the state of the art; (b) the costs of implementation; (c) the nature, scope, context, and purposes of processing; and (d) the risks to the rights and freedoms of Data Subjects. DPA.5.2 Ryse will review and update its security measures from time-to-time to reflect developments in technology and the evolving risk landscape. DPA.5.3 The Customer acknowledges that the security measures in Annex B represent an appropriate level of security for the nature of the Personal Data processed under this Schedule B and accepts responsibility for evaluating whether those measures are sufficient for its compliance obligations.
DPA.6 Sub-processors
DPA.6.1 General authorisation. The Customer grants Ryse a general authorisation to engage Sub-processors, subject to the requirements of this DPA.6. DPA.6.2 Current Sub-processors. The Sub-processors engaged by Ryse as at the date of the Agreement are listed in Annex C. Ryse will update Annex C to reflect any changes to its Sub-processor arrangements. DPA.6.3 Notice of changes. Ryse will maintain an up-to-date list of Sub-processors at rysecloud.com/subprocessors, which the Customer may consult at any time. Ryse is not required to provide additional notice of changes to that list. DPA.6.4 Sub-processor obligations. Ryse will impose data protection obligations on each Sub-processor that are no less protective than those in this Schedule B. Ryse remains responsible to the Customer for the acts and omissions of its Sub-processors, subject to the limitation of liability in clause 12 of the General Terms & Conditions.
DPA.7 International Data Transfers
DPA.7.1 Ryse will not transfer Personal Data outside Singapore, the EEA, or the UK (as applicable) unless appropriate safeguards are in place in accordance with Applicable Data Protection Law. DPA.7.2 GDPR transfers. Where Personal Data of EEA Data Subjects is transferred to a country outside the EEA that has not been recognised by the European Commission as providing an adequate level of data protection, Ryse will rely on one of the following mechanisms: (a) Standard Contractual Clauses adopted by the European Commission; or (b) another transfer mechanism permitted under GDPR Chapter V. DPA.7.3 UK transfers. Where Personal Data of UK Data Subjects is transferred outside the UK, Ryse will rely on the International Data Transfer Agreement ("IDTA") or another transfer mechanism approved under UK data protection law. DPA.7.4 PDPA transfers. Where Personal Data of Singapore Data Subjects is transferred outside Singapore, Ryse will comply with the cross-border transfer obligations under the PDPA, including by ensuring the recipient provides a comparable standard of protection.
DPA.8 Personal Data Breach Notification
DPA.8.1 Ryse will notify the Customer without undue delay, and in any event within seventy-two (72) hours of becoming aware of a Personal Data Breach affecting Personal Data processed under this Schedule B, in accordance with clause 16.2 of the General Terms & Conditions. DPA.8.2 The notification will include, to the extent then known: (a) the nature of the breach, including categories and approximate volume of Personal Data and Data Subjects affected; (b) the name and contact details of Ryse's data protection contact; (c) the likely consequences of the breach; and (d) the measures taken or proposed to address the breach and mitigate its effects. DPA.8.3 Where all required information is not available at the time of initial notification, Ryse will provide it in phases as it becomes available. DPA.8.4 Ryse's notification of a breach does not constitute an admission of fault or liability. DPA.8.5 The Customer is solely responsible for determining whether it is required to notify the relevant Supervisory Authority or affected Data Subjects, and for making any such notification.
DPA.9 Data Subject Rights
DPA.9.1 Ryse will, upon receiving a data subject rights request that appears to relate to Personal Data processed on behalf of the Customer, promptly forward that request to the Customer without responding directly to the Data Subject (unless instructed otherwise by the Customer or required to do so by law). DPA.9.2 Ryse will provide the Customer with reasonable assistance to enable the Customer to respond to data subject rights requests within the timeframes required by Applicable Data Protection Law, including by providing relevant data extracts or deletion confirmations at the Customer's request.
DPA.10 Deletion and Return of Personal Data
DPA.10.1 Upon termination or expiry of the Agreement, Ryse will, at the Customer's written election within thirty (30) days of termination: (a) return Personal Data to the Customer in a commonly used machine-readable format; or (b) securely delete or destroy all copies of Personal Data in Ryse's possession or control. DPA.10.2 Where the Customer does not make an election within thirty (30) days of termination, Ryse may securely delete all Personal Data. DPA.10.3 Ryse may retain Personal Data beyond the period above only to the extent and for as long as required by applicable law. DPA.10.4 On request, Ryse will provide the Customer with a written confirmation of deletion, identifying any Personal Data retained under DPA.10.3 and the applicable legal basis and expected retention period.
DPA.11 Audit Rights
DPA.11.1 Ryse will, on reasonable written notice (no less than thirty (30) days in ordinary circumstances), make available the information and access reasonably necessary for the Customer to verify Ryse's compliance with this Schedule B. DPA.11.2 The Customer may conduct an audit no more than once per calendar year, except where the Customer has reasonable cause to believe a breach of this Schedule B has occurred or is occurring. DPA.11.3 Audits will be conducted at the Customer's expense, during normal business hours, and in a manner that does not unreasonably disrupt Ryse's operations. The auditor must be subject to confidentiality obligations no less restrictive than those in clause 8 of the General Terms & Conditions. DPA.11.4 The parties may agree that Ryse's compliance may be demonstrated by providing a current third-party audit report or certification (such as ISO 27001 or SOC 2) in lieu of a direct audit, where Ryse reasonably determines a direct audit would pose an unacceptable security or operational risk.
DPA.12 Singapore PDPA Provisions
DPA.12.1 To the extent that Personal Data of individuals in Singapore is processed under this Schedule B, the parties acknowledge and agree that: (a) Ryse acts as an organisation that processes personal data on behalf of the Customer for purposes authorised by the Customer; (b) the Customer, as the party responsible for the personal data, must ensure that the purposes for which Ryse processes such data are authorised under the PDPA; (c) Ryse will implement reasonable security arrangements to protect personal data in accordance with the PDPA; and (d) Ryse will comply with the mandatory data breach notification requirements under the PDPA, including notifying the Personal Data Protection Commission where a notifiable data breach occurs. DPA.12.2 References in this Schedule B to "Controller" and "Processor" are used for convenience and alignment with GDPR terminology. Under the PDPA, the Customer retains responsibility as the organisation accountable for the personal data.
DPA.13 Liability
DPA.13.1 Each party's liability under this Schedule B is subject to the limitations set out in clause 12 of the General Terms & Conditions, except to the extent that such limitations are not permitted under Applicable Data Protection Law. DPA.13.2 Where both parties are liable to a Data Subject or a Supervisory Authority in respect of the same processing activity, liability will be apportioned between the parties in accordance with their respective responsibility for the damage caused.
DPA.14 Amendments
Notwithstanding clause 16.7 of the General Terms & Conditions, Ryse may update this Schedule B, without notice, to the extent necessary to comply with a binding change in Applicable Data Protection Law, a decision of a Supervisory Authority, or a replacement of a data transfer mechanism referenced in DPA.7 (such as new Standard Contractual Clauses). All other changes to this Schedule B are subject to clause 16.7 of the General Terms & Conditions.
Annex A — Details of Processing
- Subject matter
- Processing of Personal Data in connection with the Customer's digital gifting programme hosted on the Platform
- Duration
- For the Term and as set out in DPA.10
- Nature of processing
- Collection, storage, retrieval, display, transmission, deletion
- Purpose of processing
- Enabling the Customer to manage Products; processing end purchaser orders; facilitating issuance, delivery, and redemption of Products; order management and reporting
- Types of personal data
- End purchaser names; email addresses; delivery addresses (where applicable); order and transaction data; payment confirmation references; communication preferences
- Categories of data subjects
- End purchasers who purchase or receive Products through the Customer's storefront
- Special category data
- None anticipated. The Customer must notify Ryse immediately if it intends to process special category data through the Platform
Annex B — Technical and Organisational Measures
Ryse implements, at minimum, the following technical and organisational measures to protect Personal Data:
Access controls
• Role-based access controls limiting data access to personnel with a need to know • Multi-factor authentication for administrative access to production systems • Regular review and revocation of access rights upon role change or departure
Encryption
• Encryption of Personal Data in transit using TLS 1.2 or higher • Encryption of Personal Data at rest using industry-standard encryption
Network security
• Firewalls and intrusion detection/prevention systems • Regular vulnerability scanning and penetration testing • Segregation of production and non-production environments
Incident management
• Documented incident response and breach notification procedures • Logging and monitoring of access to systems processing Personal Data • Regular review of security logs
Organisational measures
• Data protection training for personnel with access to Personal Data • Confidentiality obligations for all personnel • Documented policies for data handling, retention, and disposal • Vendor due diligence process for Sub-processors
Business continuity
• Regular backups of data with tested restoration procedures • Business continuity and disaster recovery plans
Ryse will update these measures as appropriate to reflect changes in technology, risk, and regulatory requirements. A more detailed description of security measures is available to Customers on request.
Annex C — Approved Sub-processors
The current list of Sub-processors engaged by Ryse is maintained at rysecloud.com/subprocessors and forms part of this Schedule B. Ryse will update that page in accordance with clause DPA.6.3.