Data Processing Addendum
Last updated: 20 July 2026
Because Residion runs on the Customer's own infrastructure, Ednatronics does not Process Customer Data in the ordinary course. This DPA therefore applies to the narrow, defined situations in which Ednatronics does Process Personal Data on the Customer's behalf, principally Customer-authorised support access and the optional metadata-only Cloud Console, and describes the safeguards that apply when it does.
1Definitions
Capitalised terms not defined here have the meaning given in the Agreement or the PDPA.
- Controller / Data User
- The party that determines the purposes and means of Processing Personal Data. The Customer is the Controller / data user.
- Processor / Data Processor
- A party that Processes Personal Data on behalf of the Controller. Ednatronics is a Processor only to the limited extent described in Section 2.
- Personal Data
- Personal data (as defined in the PDPA) within Customer Data that Ednatronics Processes on the Customer's behalf under the Agreement.
- Customer Data
- Content the Customer or its users process using Residion, as defined in the Terms & Conditions.
- Processing
- Any operation performed on Personal Data, such as access, storage, use, disclosure, or erasure.
- Data Subject
- The individual to whom Personal Data relates.
- Subprocessor
- A third party engaged by Ednatronics to Process Personal Data on the Customer's behalf.
- Cloud Console
- The optional, metadata-only cloud control plane of Residion, designed to contain no Customer Data.
2Roles & scope
- The Customer is the Controller (data user) of Personal Data within Customer Data and is responsible for the lawfulness of its collection and use. Ednatronics acts as a Processor only where, and to the extent that, it Processes such Personal Data on the Customer's behalf.
- On-premise operation. Residion runs inside the Customer's own environment. In normal operation, Customer Data, including any Personal Data it contains, is Processed only within that environment and is not accessed by Ednatronics. Where Ednatronics does not access Personal Data, it does not Process it and this DPA imposes no Processing obligations in respect of it.
- When Ednatronics does Process Personal Data. Ednatronics may Process Personal Data on the Customer's behalf only in the following situations:
- Customer-authorised support and diagnostics, where the Customer asks Ednatronics to help with support, troubleshooting, or professional services and grants access that exposes Personal Data, such access occurs only under the Customer's authorisation and control; and
- the optional Cloud Console, which is designed to receive only management Metadata bound to a closed schema and to contain no Customer Data. To the limited extent any Personal Data were nonetheless present in that Metadata, this DPA applies to it.
- The subject matter, duration, nature, purpose, types of Personal Data, and categories of Data Subjects for such Processing are set out in Annex 1.
3Processing on instructions
- Ednatronics shall Process Personal Data only on the Customer's documented instructions, which comprise this DPA, the Agreement, the Customer's configuration of Residion, and specific support requests, unless required to act otherwise by applicable law (in which case Ednatronics will inform the Customer where legally permitted).
- Ednatronics shall inform the Customer if, in its opinion, an instruction infringes applicable data protection law.
4Confidentiality
Ednatronics shall ensure that personnel authorised to Process Personal Data are bound by appropriate confidentiality obligations and access it only as needed to perform under the Agreement.
5Security
Ednatronics shall implement appropriate technical and organisational measures to protect Personal Data it Processes against loss and unauthorised or unlawful Processing, having regard to the state of the art, the costs of implementation, and the nature and risk of the Processing. A description of these measures is set out in Annex 2. Because the Appliance runs in the Customer's environment, the Customer is responsible for the security measures of that environment.
6Subprocessors
- The Customer authorises Ednatronics to engage the Subprocessors listed in Annex 3, and other Subprocessors that Ednatronics may appoint subject to this Section.
- Ednatronics shall impose data protection obligations on each Subprocessor that are no less protective than those in this DPA, and remains responsible for its Subprocessors' performance.
- Ednatronics shall give the Customer reasonable notice of any intended addition or replacement of a Subprocessor that would Process Personal Data, giving the Customer the opportunity to object on reasonable data protection grounds.
7Data subject requests
Because Personal Data within Customer Data resides in the Customer's own environment, the Customer is ordinarily able to respond to Data Subject requests (such as access, correction, or erasure) directly using Residion's features. Taking into account the nature of the Processing, Ednatronics shall provide reasonable assistance to the Customer in responding to such requests to the extent the Customer cannot do so itself and the request relates to Personal Data Ednatronics Processes on the Customer's behalf. If Ednatronics receives a request directly from a Data Subject relating to the Customer's Personal Data, it shall refer the Data Subject to the Customer.
8Personal data breach
Ednatronics shall notify the Customer without undue delay after becoming aware of a Personal Data breach affecting Personal Data that Ednatronics Processes on the Customer's behalf, and shall provide information reasonably available to it to assist the Customer in meeting any breach obligations. A breach occurring within the Customer's own environment, which Ednatronics does not operate or access, is the Customer's responsibility to detect and handle.
9Return & deletion
On expiry or termination of the Agreement, and at the Customer's choice, Ednatronics shall delete or return Personal Data it Processes on the Customer's behalf, and delete existing copies, unless retention is required by applicable law. Customer Data held within the Customer's own environment remains with the Customer and under the Customer's control; its retention and deletion there are the Customer's responsibility.
10Audits
Ednatronics shall make available to the Customer information reasonably necessary to demonstrate compliance with this DPA and shall allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates, on reasonable prior notice, during business hours, no more than once per year (except where required by a supervisory authority or following a Personal Data breach), and subject to confidentiality obligations.
11International transfers
Ednatronics does not transfer Customer Data as part of providing Residion, since that data remains in the Customer's environment. Where Ednatronics Processes Personal Data on the Customer's behalf (see Section 2) and this would involve a transfer outside Malaysia (for example, via a Subprocessor) Ednatronics shall ensure a standard of protection comparable to that required under the PDPA and put appropriate safeguards in place.
12Liability & precedence
- Each party's liability under or in connection with this DPA is subject to the limitations and exclusions of liability in the Agreement.
- This DPA forms part of the Agreement. In the event of a conflict between this DPA and the rest of the Agreement on the subject of data protection, this DPA prevails. In all other respects the Agreement remains in full force.
A1Annex 1: Details of processing
- Subject matter
- Provision of Residion and related support, to the limited extent it involves Personal Data within Customer Data (Section 2).
- Duration
- For the term of the Agreement, plus any period required to complete return or deletion.
- Nature & purpose
- Customer-authorised support, troubleshooting, diagnostics, and professional services; and operation of the optional metadata-only Cloud Console. Ednatronics does not Process Customer Data in normal operation.
- Types of Personal Data
- Determined by the Customer through what it processes with Residion and what it exposes during a support request. Ednatronics does not require or seek any particular category, including sensitive personal data.
- Categories of Data Subjects
- Determined by the Customer: for example, the Customer's employees, customers, or other individuals whose information appears in Customer Data.
A2Annex 2: Security measures
Ednatronics maintains technical and organisational measures appropriate to its role. Because the Appliance runs in the Customer's environment, many controls are provided as product capabilities that the Customer operates; the measures below apply to Processing Ednatronics performs.
- role-based access control and least-privilege access to any systems Ednatronics operates;
- encryption in transit for management channels, and a closed metadata schema across the sovereignty boundary;
- access to Customer environments only on Customer authorisation, scoped and time-limited;
- confidentiality obligations and security awareness for personnel;
- audit logging of administrative actions on systems Ednatronics operates;
- vendor and supply-chain review of components; and
- as product capabilities the Customer configures: RBAC on every surface, PII redaction, grounding enforcement, and an exportable audit trail.
A3Annex 3: Subprocessors
Ednatronics does not use Subprocessors to Process Customer Data in normal operation, because that data stays in the Customer's environment. The following Subprocessors may Process limited Personal Data that Ednatronics collects or holds in connection with providing Residion:
- Cloud hosting provider
- Hosts our public websites and the optional metadata-only Cloud Console. May process limited technical data (e.g. server-log IP addresses) and Cloud Console Metadata, which is designed to contain no Customer Data.
- Form delivery provider
- Receives enquiry and briefing form submissions from our public website and emails them to us. Does not Process Customer Data.
- Business communication provider
- Email and communication tooling used to correspond with the Customer, which may contain business contact details.
This list reflects Ednatronics' current Subprocessors and may be updated in accordance with Section 6. The specific providers in use will be identified to the Customer on request.
Ednatronics Sdn. Bhd. (Company No. 202001004495 (1360815-T))Unit 2-1, Level 2, The Podium, Tower 3, UOA Business Park,
No 1, Jalan Pengaturcara U1/51a, Seksyen U1, 40150 Shah Alam, Selangor, Malaysia
Email: hello@residion.io ↑ Back to top