DRAF / DRAFT — Dokumen ini masih dalam semakan undang-undang dan belum berkuat kuasa. This document is under legal review and is not yet in effect; items marked ⚠ are still to be settled.
Rebana

Rebana — Data Processing Addendum

Canang Technologies Sdn Bhd · Registration No. ⚠ [No. Pendaftaran SSM]
Status: DRAFT for legal review — not yet in use, not legal advice.
Last updated: ⚠ [date]


This Data Processing Addendum ("DPA") forms part of the Master Customer Agreement between Canang Technologies Sdn Bhd ("Canang") and the Customer named in the Order (the "Agreement"). Capitalised terms not defined here have the meaning given in the Agreement.

1. Roles and scope

1.1 Roles. For Customer Personal Data, the Customer is the data user (controller) and Canang is the data processor, processing solely on the Customer's behalf. "Customer Personal Data" means personal data, as defined in the PDPA, contained in Customer Data — including data about the Customer's residents, ratepayers, licensees, traders, tenants, complainants, visitors, staff and contractors.

1.2 Where the PDPA does not apply to the Customer. The PDPA does not apply to the Federal Government or State Governments (PDPA s.3(1)), and some public bodies may fall outside it. Canang will nonetheless process Customer Personal Data to the standard this DPA sets, whether or not the PDPA binds the Customer, and will also comply with the Customer's written data-handling and security directives notified to Canang (see 5.1).

1.3 Details of processing. The subject matter, nature, purpose, duration, data categories and data subjects are in Schedule 1.

1.4 Precedence. If this DPA conflicts with the rest of the Agreement on the processing of Customer Personal Data, this DPA prevails.

2. Canang's processing obligations

2.1 Instructions only. Canang processes Customer Personal Data only to provide the Services and as the Customer instructs in writing — through the Agreement, this DPA, the Order, and the configuration the Customer's administrators set in the Rebana applications ("Documented Instructions"). If Canang believes an instruction breaks the law, or the law requires Canang to process data otherwise, it will tell the Customer first unless the law forbids that.

2.2 What Canang will not do. Canang will not:

(a) sell, rent or trade Customer Personal Data; (b) use it for its own purposes, including marketing, profiling or benchmarking; (c) use Customer Data to train, fine-tune or evaluate any artificial-intelligence or machine-learning model, other than a model deployed for and used only by that Customer at the Customer's written request; (d) combine it with data from any other customer or source, except as the Customer instructs; or (e) disclose it to anyone except as this DPA allows.

2.3 Aggregated statistics. Canang may produce statistics across customers (for example, programme indices) only from data that has been aggregated and anonymised so that neither an individual nor the Customer can be identified, and only with the Customer's prior written consent to that use.

2.4 Personnel. Canang allows access only to personnel who need it to provide the Services, who are bound by confidentiality, and who have been trained on this DPA. Where the Customer requires it, those personnel will sign the Customer's declaration under the Official Secrets Act 1972 and undergo any vetting the Customer's security policy requires.

2.5 Records. Canang keeps a record of the processing it carries out for the Customer and makes it available on request.

3. Deployment models

The Order states which model applies to each Rebana node.

3.1 Canang-hosted node. Canang operates the node on infrastructure it contracts for, in the hosting region stated in the Order. Canang is responsible for the security of the infrastructure, operating system, database, backups and disaster recovery.

3.2 On-premise node. The node runs in the Customer's data centre or the Customer's chosen cloud. The Customer controls physical and network access and is responsible for the infrastructure it operates. Canang accesses the node only as the Customer authorises — for installation, upgrades and support — through the channel the Customer approves, and every Canang session is logged. Outside those sessions Canang has no access to Customer Personal Data on an on-premise node.

3.3 Entitlement file. Each node is licensed by a signed entitlement file verified on the node itself. The file carries the licensee code, plan, features and validity period, and no personal data. Verification needs no connection to Canang ("no phone-home").

4. Sub-processors

4.1 Authorisation. The Customer authorises the sub-processors listed in Schedule 2 for each node. Canang will impose on each sub-processor written data-protection obligations no less protective than this DPA, and remains liable for their acts and omissions.

4.2 AI services. Rebana's AI features (for example Rebana Insight, Rebana CRM and citizen assistance) use a language model. The Order states, per node, which model runs and where: a model hosted on the node or the Customer's premises (no data leaves), or an external model provider (which is then a sub-processor listed in Schedule 2). The Customer may require local-only AI, and Canang will not switch a node to an external model provider without the Customer's written approval.

4.3 Changes. Canang will give at least 30 days' written notice before adding or replacing a sub-processor with access to Customer Personal Data. The Customer may object on reasonable data-protection grounds within that period. The parties will then work in good faith to resolve the objection; if they cannot, the Customer may terminate the affected Services without penalty and receive a refund of prepaid fees for the unused period.

5. Security

5.1 Measures. Canang maintains the technical and organisational measures in Schedule 3 and complies with the Security Principle of the PDPA (s.9), which now binds data processors directly. Canang will also follow the Customer's own information-security directives notified in writing (for example, the Customer's ICT security policy and applicable public-sector security frameworks), provided they are reasonable and consistent with the Services; any material cost of complying with new directives is agreed through a change to the Order.

5.2 Audit trail. The Rebana applications keep an audit trail of record changes, and records are not permanently deleted in normal operation. Canang will not disable or alter the audit trail except on the Customer's written instruction.

5.3 No weakening. Canang may update its security measures but will not materially reduce the overall protection of Customer Personal Data.

6. Personal data breaches

6.1 Notice to the Customer. Canang will notify the Customer without undue delay and in any event within 24 hours of becoming aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data ("Personal Data Breach"). The short window is deliberate: it leaves the Customer time to meet its own notification duties to the Personal Data Protection Commissioner and affected individuals, and to any other authority.

6.2 Content. The notice will describe, as far as then known: what happened; the categories and approximate number of individuals and records affected; the likely consequences; the measures taken or proposed; and a contact person. Canang will supplement it as more becomes known.

6.3 Assistance. Canang will investigate, contain and remediate the breach, preserve evidence, and help the Customer notify the Commissioner, affected individuals and, where relevant, the National Cyber Security Agency (NACSA) or other authority. Canang will not notify any authority or individual about Customer Personal Data on the Customer's behalf unless the Customer instructs it or the law requires it.

6.4 No admission. Notifying a breach is not an admission of fault.

7. Assistance with the Customer's obligations

7.1 Data subject requests. If Canang receives a request from an individual about Customer Personal Data (access, correction, withdrawal of consent, portability), it will forward it to the Customer within 3 working days and will not respond to it itself except to tell the individual it has been passed on. The Rebana applications let the Customer's administrators search, export and correct records; where they cannot meet a request themselves, Canang will help.

7.2 Assessments and regulators. Canang will give reasonable help with data-protection impact assessments, security reviews, and any enquiry by the Personal Data Protection Commissioner or other authority about the processing.

7.3 Cost. Assistance within the ordinary support scope of the Order is included. Assistance beyond it is charged at the rates in the Order, agreed in advance — except where the need arises from Canang's own breach.

8. Audit

8.1 Customer audit. Once every 12 months, and additionally after any Personal Data Breach, the Customer (or an auditor it appoints under confidentiality) may audit Canang's compliance with this DPA, on 20 working days' notice, during business hours, with a scope agreed in advance. Canang may first offer recent independent certifications or audit reports; if they answer the Customer's questions, the audit may be narrowed accordingly.

8.2 Government audit. Nothing in this DPA limits the access to records to which the National Audit Department (Jabatan Audit Negara), the Customer's internal audit unit or another authority with statutory audit powers over the Customer is entitled. Canang will cooperate with such an audit.

8.3 Cost. Each party bears its own cost of an audit, unless the audit reveals a material breach by Canang, in which case Canang bears the reasonable cost.

9. Location and transfers

9.1 Default location. Customer Personal Data on a Canang-hosted node is stored and processed in Malaysia ⚠, unless the Order states another region.

9.2 Transfers. Canang will not transfer Customer Personal Data outside Malaysia, or allow a sub-processor to, except (a) as listed in Schedule 2 and approved in the Order, and (b) in compliance with PDPA s.129. Remote support from outside Malaysia is a transfer and needs the same approval.

9.3 Classified information. Information classified under the Official Secrets Act 1972 will not leave Malaysia, and will be processed only on the nodes and by the personnel the Customer approves.

10. Return and deletion — Data Handback

10.1 Export at any time. During the term the Customer may export its data from the applications in standard formats.

10.2 Data Handback on exit. On expiry or termination of the Agreement, or on the Customer's request, Canang will deliver a complete export of Customer Data within 10 working days, in open, documented formats — a PostgreSQL database dump, CSV or JSON for tabular data, and the stored documents and files in their original formats — free of charge ⚠, together with a data dictionary. For 6 months after expiry Canang will keep the node available to the Customer read-only, so records remain accessible while the Customer migrates.

10.3 Lapse of the entitlement does not lock data. An expired entitlement file disables application features after its grace period; it must never prevent the Customer from reading or exporting its data, or Canang from performing the Data Handback.

10.4 Deletion. After the read-only period, or earlier if the Customer instructs, Canang will delete Customer Personal Data from Canang-hosted nodes, and from backups as they rotate out within ⚠ [35] days, and certify deletion in writing. Canang may keep data only where the law requires, and then only for as long as it requires, still protected by this DPA. On an on-premise node the data is already in the Customer's custody; Canang will delete any copy it holds (for example support extracts).

11. Liability

Each party's liability under this DPA is subject to the limitations in the Agreement, except as the Agreement itself excludes from those limitations.

12. Term

This DPA applies for as long as Canang processes Customer Personal Data, including during the Data Handback period.


Schedule 1 — Description of processing

Item Detail
Data user The Customer named in the Order (a local authority, public agency, statutory body, university or other organisation).
Data processor Canang Technologies Sdn Bhd.
Subject matter Provision of the Rebana applications and related services (activation, migration, training, support) listed in the Order.
Nature Hosting (Canang-hosted nodes), storage, backup, retrieval, structuring, transmission, display and deletion; data migration from the Customer's legacy systems; support access; generation of AI answers from Customer Data where AI features are enabled.
Purpose To run the Customer's own processes — licensing, rentals, bookings, collections, complaints, HR and payroll, assets, procurement, audit, analytics — as configured by the Customer.
Data subjects Depending on modules subscribed: residents and ratepayers; property owners; licence holders and applicants; traders and tenants; complainants and service users; visitors and ticket buyers; vendors and contractors; the Customer's employees, pensioners and their dependants; the Customer's officers using the applications.
Categories of personal data Identification (name, MyKad/passport number, date of birth); contact details; addresses and property or lot references; business registration details; application, licence, tenancy, bill, payment, compound and arrears records; complaint content, photos and locations; employment, salary, statutory-contribution and bank details (HR/payroll); vehicle plates and images (parking/enforcement); CCTV-derived counts (Pulse, which does not identify individuals ⚠); user accounts, roles and audit logs.
Sensitive personal data Only where the Customer's modules require it — for example health information in HR leave or medical claims, or OKU status for concessions. Processed only for that purpose, access-restricted by role and logged.
Duration The term of the Agreement plus the Data Handback period (§10).
Retention inside the applications Set by the Customer's own retention rules (for example, under the National Archives Act 2003 and the Customer's record-management policy). Canang does not delete Customer records on its own initiative.

Schedule 2 — Authorised sub-processors (per node)

⚠ To be completed per Order. Template:

Sub-processor Service Data location Applies to
⚠ [Hosting provider] Infrastructure for Canang-hosted nodes ⚠ [Malaysia — region] Canang-hosted nodes only
⚠ [Object-storage / backup provider, if separate] Encrypted backups ⚠ [Malaysia] Canang-hosted nodes only
⚠ [E-mail / SMS gateway] Notifications to users ⚠ Nodes with notifications enabled
⚠ [Payment gateway / collection hub] Payment processing ⚠ Where the Customer uses online payment (often contracted by the Customer directly — then not a Canang sub-processor)
⚠ [WhatsApp Business Platform — Meta] Messaging channel (Rebana CRM) Outside Malaysia Only if the Customer enables the WhatsApp channel
⚠ [External language-model provider, e.g. Azure OpenAI] AI answers ⚠ Only if the Customer approves an external model (§4.2); none where local AI is chosen

Schedule 3 — Technical and organisational measures

  1. Access control. Single sign-on and role-based access in every application; access to records limited by the Customer's organisational scope (for example, per department); administrator actions logged.
  2. Authentication. Signed, short-lived tokens between applications; service-to-service calls authenticated; credentials never stored in plain text.
  3. Encryption. TLS for data in transit; encryption at rest for Canang-hosted databases and backups ⚠ [confirm].
  4. Audit trail. Record-level audit of creation and change; no hard deletion of records in normal operation.
  5. Separation. One node, one database per Customer; no Customer's data shares a database with another's.
  6. Backups and recovery. Regular database backups and point-in-time recovery for Canang-hosted nodes; restore tested ⚠ [frequency]; stated recovery objectives in the Order.
  7. Change management. Versioned releases; database changes applied by migration scripts; upgrades scheduled with the Customer.
  8. Vulnerability management. Dependency updates, security patches within ⚠ [days] for critical issues, and penetration testing ⚠ [frequency / by whom].
  9. Personnel. Confidentiality undertakings; data-protection training; least-privilege support access that is revoked when no longer needed; Official Secrets Act declarations where the Customer requires them.
  10. Support access to production data only on a support ticket, time-limited, logged, and — for on-premise nodes — only through the channel the Customer authorises.
  11. Incident response. A documented procedure meeting the 24-hour notice in §6.
  12. Bug reports. The in-app "Lapor Isu" widget files issue reports to Canang. Reports are Customer Data under this DPA; officers are asked not to attach personal data unless needed to reproduce the fault ⚠.