Pammo ← Back to Legal Center

Effective 15 June 2026 · Updated 18 May 2026

PAMMO — DATA PROCESSING ADDENDUM (DPA) — SCHEDULE A

Version 1 — Publication-Ready Pending Final Review Last Updated: 2026-05-18 Effective Date: 15 June 2026

This Data Processing Addendum ("DPA") forms part of the Pammo Terms and Conditions of Service (Main) V1 (the "Terms") between the Pammo contracting entity (per Main T&C §0 — AEDOWON CO., LTD for Thai-Route Users or AEDOWON SINGAPORE PTE. LTD. (UEN 202612161D) for International-Route Users), together as "Pammo" or "Processor", and you (the "Customer", "Controller"). This DPA applies where you submit personal data of third parties as Input to the Service such that Pammo processes that personal data on your behalf.

This DPA is the "Schedule A — Data Processing Particulars" referenced from Main T&C §12.2A. It is fully drafted here and is not subject to a [TBD] placeholder.

This DPA satisfies:

PLAIN LANGUAGE: This DPA covers what happens when you upload customer audience lists, lead contact lists, photographs of title-deeds containing third-party names, or other third-party personal data into Pammo. You are the Controller of that data; Pammo processes it on your instructions as your Processor. This DPA sets out our processor obligations.


1. DEFINITIONS

Capitalized terms not defined here have the meaning given in the Terms or in the GDPR / Thailand PDPA / Singapore PDPA, as applicable.


2. SCOPE AND ROLES

2.1 Application. This DPA applies only where Customer uploads or otherwise submits Personal Data of third parties as Input, audience data, contact lists, lead lists, OCR-processed documents, or otherwise instructs Pammo to process such Personal Data in the course of providing the Service.

2.2 Controller / Processor Roles. For Customer Personal Data:

2.3 Other Personal Data. For account-level Personal Data of the Customer's own account holders (User identity, billing, authentication, security telemetry), Pammo acts as joint Controller with its affiliate per Pammo-Privacy-Notice-V1 §1. This DPA does not apply to that data.


3. SUBJECT-MATTER AND DURATION

3.1 Subject-matter. Processing by Pammo, as Processor, of Customer Personal Data for the purposes of providing the Service.

3.2 Duration. For the term of Customer's active subscription plus the retention periods set out in Pammo-Privacy-Notice-V1 §6 and §10 of this DPA.


4. NATURE AND PURPOSE OF PROCESSING

Pammo shall process Customer Personal Data for the following purposes only (the "Permitted Purposes"):

(a) hosting, storing, indexing, transmitting; (b) transforming via AI inference (text generation for listing descriptions and contract drafts; image processing for OCR; vector embedding for Property Matching; conversational responses for PANNORA Co-Pilot); (c) returning Outputs to Customer; (d) generating listing data, contract drafts, OCR-extracted fields, and Property Matching results for Customer's use; (e) (where instructed by Customer) onward transfer of contact / audience / lead data to advertising platforms (Meta, Google, TikTok, LINE) or to a third-party CRM via Customer-authorized integration; (f) fraud prevention, security, abuse detection on the Customer's account; (g) compliance with Pammo's legal obligations.

Any processing for other purposes requires Customer's separate documented instruction.


5. CATEGORIES OF DATA SUBJECTS AND PERSONAL DATA

5.1 Categories of Data Subjects. Customer's customers, prospective buyers or renters, property owners (where named in Customer-uploaded listings), property co-brokers, prospective tenants, leads, audience-list members, and other natural persons whose Personal Data Customer submits.

5.2 Categories of Personal Data.

5.3 Sensitive Personal Data. Customer should not submit sensitive Personal Data (Thailand PDPA §26 / Singapore PDPA Schedule 2 / GDPR Art 9 categories) unless Customer has obtained the explicit consent required by law and has documented that consent. Where submitted, the heightened obligations in §11 apply.

5.4 Real-estate-specific consideration. Property listings frequently embed natural-person identifiers (owner names, agent contacts, prior-tenant references). Customer represents and warrants that any such personal data is uploaded lawfully and that data-subject consent or other lawful basis exists.


6. PROCESSOR OBLIGATIONS (GDPR ART 28(3)(a)–(h) / THAILAND PDPA §40 / SG PDPA §24)

Pammo shall:

(a) process Customer Personal Data only on Customer's documented instructions — including with regard to international transfers — except where required to do so by applicable law, in which case Pammo will inform Customer of that legal requirement before processing (unless the law prohibits such notice);

(b) ensure that personnel authorized to process Customer Personal Data are bound by confidentiality undertakings (contractual or statutory) and have received appropriate data-protection training;

(c) implement appropriate technical and organizational measures consistent with Annex II (§11) to ensure a level of security appropriate to the risk;

(d) engage Sub-Processors only with Customer's prior general or specific authorization. Customer gives a general authorization for engagement of the Sub-Processors listed in our Sub-Processor List and for additional Sub-Processors subject to the 30-day prior-notice and right-of-objection mechanism in §7 below;

(e) assist Customer by appropriate technical and organizational measures, insofar as possible, in fulfilling Customer's obligation to respond to Data Subject requests (access, rectification, erasure, restriction, portability, objection);

(f) assist Customer in ensuring compliance with security, breach-notification, DPIA, and prior-consultation obligations under GDPR Arts 32–36 / Thailand PDPA §§37–39 / Singapore PDPA §§24, 26B–26D;

(g) at Customer's choice (and at end of Service), delete or return all Customer Personal Data after the end of provision of the Service, save where Singapore, EU, Thailand, or applicable law requires retention;

(h) make available to Customer all information necessary to demonstrate compliance with this DPA, and allow for and contribute to audits, including inspections, conducted by Customer or another auditor mandated by Customer — subject to §9 (audit) below.

Documented instructions are: (i) this DPA; (ii) the Terms; (iii) Customer's configuration of the Service through the Service interface (e.g., target advertising platforms selected, audience lists uploaded, OCR processing requested); and (iv) any additional written instructions agreed in writing between Customer and Pammo.


7. SUB-PROCESSORS

7.1 Authorized Sub-Processors. Authorized Sub-Processors are those listed in the current Sub-Processor List.

7.2 New Sub-Processors. Pammo provides at least 30 days' prior notice before engaging any new material Sub-Processor or replacing an existing material Sub-Processor with one in a different jurisdiction. Notice is given via:

7.3 Customer Objection. Customer may object to the engagement of a new Sub-Processor on reasonable grounds within the 30-day notice period. If Pammo cannot accommodate the objection, either party may terminate the affected portion of the Service with refund of unused prepaid fees per Main T&C §17 and §6.

7.4 Sub-Processor Obligations. Pammo enters into written agreements with each Sub-Processor that impose substantially the same data-protection obligations on the Sub-Processor as those imposed on Pammo under this DPA. Pammo remains fully liable to Customer for the performance of its Sub-Processors.


8. INTERNATIONAL TRANSFERS

8.1 Transfer Mechanisms. Where Customer Personal Data is transferred from the EEA, UK, Switzerland, Thailand, or Singapore to a third country, transfers are made on the following bases (in order of preference):

(a) Standard Contractual Clauses (SCCs) approved by the European Commission (Decision 2021/914) or by the Thailand PDPC, or Binding Corporate Rules approved by the competent supervisory authority; (b) Adequacy decision recognized by the Thailand PDPC or European Commission; (c) Contract necessity for performance of Customer's contract (Thailand PDPA §28 ¶2(3); GDPR Art 49(1)(b)); (d) Customer's explicit consent after being informed of the absence of adequate safeguards; (e) Compliance with legal obligation, public interest, vital interests, or legal claims.

8.2 EU SCCs Incorporation. Where required, the EU SCCs (Module 2: Controller-to-Processor) are deemed incorporated into this DPA between Customer and Pammo. The optional docking clause (Clause 7) is included, allowing additional parties to accede. Annex I (parties, description, supervisory authority), Annex II (TOMs — see §11 below), and Annex III (Sub-Processors — see Sub-Processor List) are completed as set out in the corresponding sections of this DPA.

8.3 UK Addendum. Where personal data is transferred from the United Kingdom, the UK International Data Transfer Addendum (issued by the UK Information Commissioner) is incorporated into this DPA, supplementing the EU SCCs.

8.4 Thailand PDPC SCCs. Where Thailand-PDPC-approved SCCs become available and applicable, those clauses are incorporated by this reference.

8.5 Singapore PDPC. Singapore PDPC's transfer-limitation obligation under Singapore PDPA §26 is satisfied by the SCC mechanism in §8.1(a) above and / or by Customer's consent / contractual-necessity bases.


9. AUDIT

9.1 Audit Frequency. No more than once per calendar year (or more frequently following a confirmed personal-data breach affecting Customer), Customer (or a mutually-acceptable auditor mandated by Customer) may audit Pammo's processing of Customer Personal Data.

9.2 Conditions. Audits are subject to:

9.3 Audit Substitution. Where Pammo obtains and maintains current SOC 2 Type II, ISO/IEC 27001, or equivalent independent assurance, Pammo may satisfy routine audit-information requests by providing the current report or certificate under NDA, subject to Customer's mandatory-law rights to inspect after a confirmed breach.


10. RETENTION AND DELETION

10.1 During the Service term. Customer Personal Data is retained for the periods set out in Pammo-Privacy-Notice-V1 §6 unless Customer instructs deletion earlier.

10.2 On termination. Customer may export Customer Personal Data per Main T&C §17.5 within the 30-day grace period; thereafter Pammo will delete (or, where infeasible, irreversibly anonymize) Customer Personal Data within the retention windows in the Privacy Notice §6, subject to legal hold, accounting-record retention (Thai Revenue Code §87/3, Thai Accounting Act B.E. 2543 §14, Singapore Companies Act §199, Singapore Income Tax Act §67 — minimum 5 years), and back-up-cycle exceptions.

10.3 Audit trail. Pammo maintains an audit trail of deletion / anonymization actions for at least the period required by applicable law.


11. SECURITY MEASURES (ANNEX II — TECHNICAL AND ORGANIZATIONAL MEASURES)

Pammo maintains the following technical and organizational measures (subject to ongoing improvement):

Control Area Baseline Measure
Encryption Personal Data encrypted at rest using AES-256 or equivalent managed-disk encryption; data in transit protected by TLS 1.2+ (TLS 1.3 preferred). Encryption keys managed via the cloud provider's HSM-backed key-management service.
Access control Role-based access control, least-privilege grants, named-user admin accounts, quarterly access review, immediate revocation on role change or termination.
Authentication Multi-factor authentication for all administrative, production, payment (Omise / Polar dashboards), payout (Currenxie / Wise / PayPal), and DPO tooling.
Logging Security-relevant admin events, authentication events, data exports, consent changes, payment webhook events, and DSR actions logged for at least twelve (12) months unless a longer retention period is required.
Backups Production data backed up periodically with restoration tested at least quarterly; backup deletion follows the retention schedule and legal-hold rules.
Business continuity Disaster-recovery target: RPO 24 hours / RTO 8 hours for core account, listing, and billing data, subject to third-party provider incidents outside Pammo's reasonable control.
Vendor risk Sub-Processors reviewed before onboarding and at least annually; material new Sub-Processors are subject to §7 notice and objection.
Incident response Written incident-response procedure, severity classification, breach assessment, and notification workflow aligned to SG PDPA §§26B–26D, TH PDPA §§37–39, GDPR Arts 33–34.
Training Mandatory annual data-protection training for personnel with access to Personal Data.
Physical security Hosting providers (Supabase, Vercel, Cloudflare) maintain SOC 2 / ISO 27001 / equivalent certifications for physical security at data-center facilities.
Pseudonymization / minimization Where technically feasible, fraud-detection signals are stored as hashes; access logs aggregate where individual-level data is not necessary. OCR-extracted document IDs are tokenized for downstream-system referencing.
Property-Data Scoping Property listings are treated as business content unless they embed identifiable personal data of named individuals; embedded personal data is segregated and subject to the same protections as core account data.
Creator KYC images Stored in Supabase encrypted storage with access restricted to the Pammo personnel performing KYC review; retained 24 months after Creator termination.

12. BREACH NOTIFICATION

12.1 Notification to Customer. Pammo will notify Customer of any Personal Data Breach affecting Customer Personal Data without undue delay after becoming aware, and in any event within the timeframes that allow Customer to comply with Customer's notification obligations to its own data subjects and supervisory authorities.

12.2 Content of notification. The notification will include, to the extent then known:

12.3 Pammo's own notification obligations. Pammo separately notifies regulators per Pammo-Privacy-Notice-V1 §9 (Thailand PDPC within 72 hours; Singapore PDPC within 3 calendar days; GDPR Arts 33–34 within 72 hours; UK ICO within 72 hours).


13. DATA SUBJECT REQUESTS

13.1 Assistance. Pammo shall, taking into account the nature of processing, assist Customer by appropriate technical and organizational measures, insofar as possible, to fulfill Customer's obligation to respond to Data Subject requests within statutory timelines.

13.2 Forwarding. If Pammo receives a Data Subject request relating to Customer Personal Data, Pammo will forward the request to Customer without undue delay and will not respond to the Data Subject directly unless authorized by Customer or required by law.


14. LIABILITY

14.1 Limitation. Each party's liability under this DPA is subject to the Limitation of Liability in Main T&C §15, and to the non-waivable carve-outs in §15.5 (including statutory data-protection damages under Thailand PDPA §77, Singapore PDPA §32, GDPR Art 82).

14.2 No additional limitation on Data Subject rights. Nothing in §14.1 limits or excludes Pammo's direct liability to Data Subjects under applicable data-protection law where such liability cannot be limited by contract.


15. ORDER OF PRECEDENCE

In case of conflict between this DPA and the Terms with respect to processor obligations under Thailand PDPA §40 / GDPR Art 28(3) / Singapore PDPA §24, this DPA controls. In case of conflict between this DPA and any SCCs incorporated under §8.2, the SCCs control.


16. TERM AND TERMINATION

This DPA continues for as long as Pammo processes Customer Personal Data, and terminates automatically on termination of the Terms, subject to §10 (retention and deletion).


17. THAILAND PDPA §40, SINGAPORE PDPC, AND UK / EU CONFORMANCE

17.1 Thailand PDPA §40. This DPA is intended to satisfy Thailand PDPA §40 written-contract requirements — including documented instructions, confidentiality, security, Sub-Processor control, data-subject assistance, deletion / return, and audit cooperation.

17.2 Singapore PDPC. This DPA is intended to operate as written data-processing terms for Singapore PDPA purposes (Protection Obligation §24, Transfer Limitation Obligation §26) and to be interpreted consistently with PDPC Singapore advisory guidance on accountability, transfer limitation, protection, retention limitation, breach notification, and DPO designation.

17.3 UK / EU. This DPA, together with the EU SCCs (Module 2) and UK Addendum incorporated under §8.2 / §8.3, is intended to operate as a valid Art 28 processor contract under GDPR / UK GDPR.


18. CONTACT

Pammo Data Protection Officer: dpo@pammo.co Privacy Inquiries: privacy@pammo.co Enterprise / DPA Inquiries: enterprise@pammo.co Singapore registered office: AEDOWON SINGAPORE PTE. LTD. (UEN 202612161D), 8 TEMASEK BOULEVARD, #17-02A, SUNTEC TOWER THREE, SINGAPORE 038988 Thailand registered office: AEDOWON CO., LTD, 250/207 SOI BUDDHAMONDON SAI 2 SOI 32, SALATHAMMASOP, TAWEWATTANA, BANGKOK 10170, THAILAND


END OF PAMMO DATA PROCESSING ADDENDUM — V1 — SCHEDULE A FULLY DRAFTED (PUBLICATION-READY PENDING FINAL REVIEW) Last Updated: 2026-05-18