Skip to content
Residion
Pricing Contact Docs Request a briefingBriefing
Legal

Data Processing Addendum

Last updated: 20 July 2026

This Data Processing Addendum ("DPA") forms part of the agreement between the customer ("Customer") and Ednatronics Sdn. Bhd. (Company No. 202001004495 (1360815-T)) ("Ednatronics") for the provision of Residion (the Terms & Conditions and any Order, together the "Agreement"). It applies where Ednatronics Processes Personal Data on the Customer's behalf and is made in accordance with the Personal Data Protection Act 2010 of Malaysia (the "PDPA") and other applicable data protection law.

Because Residion runs on the Customer's own infrastructure, Ednatronics does not Process Customer Data in the ordinary course. This DPA therefore applies to the narrow, defined situations in which Ednatronics does Process Personal Data on the Customer's behalf, principally Customer-authorised support access and the optional metadata-only Cloud Console, and describes the safeguards that apply when it does.

Contents

  1. Definitions
  2. Roles & scope
  3. Processing on instructions
  4. Confidentiality
  5. Security
  6. Subprocessors
  7. Data subject requests
  8. Personal data breach
  9. Return & deletion
  10. Audits
  11. International transfers
  12. Liability & precedence
  13. Annex 1: Details of processing
  14. Annex 2: Security measures
  15. Annex 3: Subprocessors

1Definitions

Capitalised terms not defined here have the meaning given in the Agreement or the PDPA.

Controller / Data User
The party that determines the purposes and means of Processing Personal Data. The Customer is the Controller / data user.
Processor / Data Processor
A party that Processes Personal Data on behalf of the Controller. Ednatronics is a Processor only to the limited extent described in Section 2.
Personal Data
Personal data (as defined in the PDPA) within Customer Data that Ednatronics Processes on the Customer's behalf under the Agreement.
Customer Data
Content the Customer or its users process using Residion, as defined in the Terms & Conditions.
Processing
Any operation performed on Personal Data, such as access, storage, use, disclosure, or erasure.
Data Subject
The individual to whom Personal Data relates.
Subprocessor
A third party engaged by Ednatronics to Process Personal Data on the Customer's behalf.
Cloud Console
The optional, metadata-only cloud control plane of Residion, designed to contain no Customer Data.

2Roles & scope

  1. The Customer is the Controller (data user) of Personal Data within Customer Data and is responsible for the lawfulness of its collection and use. Ednatronics acts as a Processor only where, and to the extent that, it Processes such Personal Data on the Customer's behalf.
  2. On-premise operation. Residion runs inside the Customer's own environment. In normal operation, Customer Data, including any Personal Data it contains, is Processed only within that environment and is not accessed by Ednatronics. Where Ednatronics does not access Personal Data, it does not Process it and this DPA imposes no Processing obligations in respect of it.
  3. When Ednatronics does Process Personal Data. Ednatronics may Process Personal Data on the Customer's behalf only in the following situations:
    • Customer-authorised support and diagnostics, where the Customer asks Ednatronics to help with support, troubleshooting, or professional services and grants access that exposes Personal Data, such access occurs only under the Customer's authorisation and control; and
    • the optional Cloud Console, which is designed to receive only management Metadata bound to a closed schema and to contain no Customer Data. To the limited extent any Personal Data were nonetheless present in that Metadata, this DPA applies to it.
  4. The subject matter, duration, nature, purpose, types of Personal Data, and categories of Data Subjects for such Processing are set out in Annex 1.

3Processing on instructions

  1. Ednatronics shall Process Personal Data only on the Customer's documented instructions, which comprise this DPA, the Agreement, the Customer's configuration of Residion, and specific support requests, unless required to act otherwise by applicable law (in which case Ednatronics will inform the Customer where legally permitted).
  2. Ednatronics shall inform the Customer if, in its opinion, an instruction infringes applicable data protection law.

4Confidentiality

Ednatronics shall ensure that personnel authorised to Process Personal Data are bound by appropriate confidentiality obligations and access it only as needed to perform under the Agreement.

5Security

Ednatronics shall implement appropriate technical and organisational measures to protect Personal Data it Processes against loss and unauthorised or unlawful Processing, having regard to the state of the art, the costs of implementation, and the nature and risk of the Processing. A description of these measures is set out in Annex 2. Because the Appliance runs in the Customer's environment, the Customer is responsible for the security measures of that environment.

6Subprocessors

  1. The Customer authorises Ednatronics to engage the Subprocessors listed in Annex 3, and other Subprocessors that Ednatronics may appoint subject to this Section.
  2. Ednatronics shall impose data protection obligations on each Subprocessor that are no less protective than those in this DPA, and remains responsible for its Subprocessors' performance.
  3. Ednatronics shall give the Customer reasonable notice of any intended addition or replacement of a Subprocessor that would Process Personal Data, giving the Customer the opportunity to object on reasonable data protection grounds.

7Data subject requests

Because Personal Data within Customer Data resides in the Customer's own environment, the Customer is ordinarily able to respond to Data Subject requests (such as access, correction, or erasure) directly using Residion's features. Taking into account the nature of the Processing, Ednatronics shall provide reasonable assistance to the Customer in responding to such requests to the extent the Customer cannot do so itself and the request relates to Personal Data Ednatronics Processes on the Customer's behalf. If Ednatronics receives a request directly from a Data Subject relating to the Customer's Personal Data, it shall refer the Data Subject to the Customer.

8Personal data breach

Ednatronics shall notify the Customer without undue delay after becoming aware of a Personal Data breach affecting Personal Data that Ednatronics Processes on the Customer's behalf, and shall provide information reasonably available to it to assist the Customer in meeting any breach obligations. A breach occurring within the Customer's own environment, which Ednatronics does not operate or access, is the Customer's responsibility to detect and handle.

9Return & deletion

On expiry or termination of the Agreement, and at the Customer's choice, Ednatronics shall delete or return Personal Data it Processes on the Customer's behalf, and delete existing copies, unless retention is required by applicable law. Customer Data held within the Customer's own environment remains with the Customer and under the Customer's control; its retention and deletion there are the Customer's responsibility.

10Audits

Ednatronics shall make available to the Customer information reasonably necessary to demonstrate compliance with this DPA and shall allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates, on reasonable prior notice, during business hours, no more than once per year (except where required by a supervisory authority or following a Personal Data breach), and subject to confidentiality obligations.

11International transfers

Ednatronics does not transfer Customer Data as part of providing Residion, since that data remains in the Customer's environment. Where Ednatronics Processes Personal Data on the Customer's behalf (see Section 2) and this would involve a transfer outside Malaysia (for example, via a Subprocessor) Ednatronics shall ensure a standard of protection comparable to that required under the PDPA and put appropriate safeguards in place.

12Liability & precedence

  1. Each party's liability under or in connection with this DPA is subject to the limitations and exclusions of liability in the Agreement.
  2. This DPA forms part of the Agreement. In the event of a conflict between this DPA and the rest of the Agreement on the subject of data protection, this DPA prevails. In all other respects the Agreement remains in full force.

A1Annex 1: Details of processing

Subject matter
Provision of Residion and related support, to the limited extent it involves Personal Data within Customer Data (Section 2).
Duration
For the term of the Agreement, plus any period required to complete return or deletion.
Nature & purpose
Customer-authorised support, troubleshooting, diagnostics, and professional services; and operation of the optional metadata-only Cloud Console. Ednatronics does not Process Customer Data in normal operation.
Types of Personal Data
Determined by the Customer through what it processes with Residion and what it exposes during a support request. Ednatronics does not require or seek any particular category, including sensitive personal data.
Categories of Data Subjects
Determined by the Customer: for example, the Customer's employees, customers, or other individuals whose information appears in Customer Data.

A2Annex 2: Security measures

Ednatronics maintains technical and organisational measures appropriate to its role. Because the Appliance runs in the Customer's environment, many controls are provided as product capabilities that the Customer operates; the measures below apply to Processing Ednatronics performs.

  • role-based access control and least-privilege access to any systems Ednatronics operates;
  • encryption in transit for management channels, and a closed metadata schema across the sovereignty boundary;
  • access to Customer environments only on Customer authorisation, scoped and time-limited;
  • confidentiality obligations and security awareness for personnel;
  • audit logging of administrative actions on systems Ednatronics operates;
  • vendor and supply-chain review of components; and
  • as product capabilities the Customer configures: RBAC on every surface, PII redaction, grounding enforcement, and an exportable audit trail.

A3Annex 3: Subprocessors

Ednatronics does not use Subprocessors to Process Customer Data in normal operation, because that data stays in the Customer's environment. The following Subprocessors may Process limited Personal Data that Ednatronics collects or holds in connection with providing Residion:

Cloud hosting provider
Hosts our public websites and the optional metadata-only Cloud Console. May process limited technical data (e.g. server-log IP addresses) and Cloud Console Metadata, which is designed to contain no Customer Data.
Form delivery provider
Receives enquiry and briefing form submissions from our public website and emails them to us. Does not Process Customer Data.
Business communication provider
Email and communication tooling used to correspond with the Customer, which may contain business contact details.

This list reflects Ednatronics' current Subprocessors and may be updated in accordance with Section 6. The specific providers in use will be identified to the Customer on request.

Ednatronics Sdn. Bhd. (Company No. 202001004495 (1360815-T))
Unit 2-1, Level 2, The Podium, Tower 3, UOA Business Park,
No 1, Jalan Pengaturcara U1/51a, Seksyen U1, 40150 Shah Alam, Selangor, Malaysia
Email: hello@residion.io
↑ Back to top
© 2026 Ednatronics Sdn. Bhd. Home Pricing Contact Terms Privacy Cookies residion.io