1. Purpose and status
This Data Processing Addendum ("DPA") describes how Omakase Software Sdn Bhd — or, where your organisation has signed an order form or agreement with another DonorCARE group company, that company (in either case "DonorCARE", "Processor") processes personal data of an Organisation's donors and beneficiaries ("Donor Data") on behalf of the Organisation ("Data User", "Controller") when the Organisation uses the DonorCARE platform. It forms part of, and is incorporated into, our Subscription Terms and supplements our Privacy Policy.
2. Processing on documented instructions
DonorCARE processes Donor Data only on the Organisation's documented instructions, which consist of: the Subscription Terms, this DPA, the Organisation's configuration choices within the dashboard (enabling recurring donations, MyInvois submission, email campaigns, and similar features), and any further written instruction the Organisation gives us. We will notify the Organisation if we believe an instruction breaches the PDPA or another applicable law, and we will not act on an instruction we reasonably believe to be unlawful.
3. Scope, duration, and categories of data
Duration. Processing continues for as long as the Organisation's account is active, and for the period described in the "Data export and effect of termination" section of the Subscription Terms afterward.
Categories of data subjects. Donors, ceremony or ritual registrants, and other individuals the Organisation records in connection with a donation or campaign.
Categories of Donor Data. Name, contact details (email, phone, address), identification type and number (NRIC, passport, or business registration number) where supplied for receipt purposes, donation amount, date, and payment method, campaign or ceremony/ritual registration details, and communication preferences.
Nature and purpose of processing. Storage, donation processing, receipt generation, MyInvois e-invoice submission where enabled, email delivery where the Organisation uses the platform's campaign tools, and analytics reporting back to the Organisation.
4. Security
We apply the technical and organisational measures described on our Security & Compliance page, including encryption in transit and at rest, organisation-scoped access control, and audit logging of mutating actions, having regard to the nature of the Donor Data and the harm that might result from unauthorised access, alteration, disclosure, or loss.
5. Subprocessor use
We engage subprocessors to provide infrastructure and services necessary to operate the platform. The current list, with each subprocessor's purpose, is published on our Subprocessors page rather than duplicated here, so it stays current. We impose data- protection obligations on each subprocessor materially equivalent to those in this DPA, and remain responsible to the Organisation for a subprocessor's performance. We will update the Subprocessors page when we add or remove a subprocessor; the page itself is the notice mechanism, and we encourage an Organisation to check it periodically rather than expect an individual notification for every change.
6. Assisting with data-subject requests
Where a donor exercises a right under the PDPA directly against an Organisation (access, correction, or withdrawal of consent), we will provide reasonable technical assistance — including data export tools and, where necessary, direct support — to help the Organisation respond within the PDPA's timelines, including the 21-day response window for access and correction requests.
7. Breach notification
If we become aware of a security incident that results in the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Donor Data, we will notify the affected Organisation without undue delay and, in any event, within 72 hours of becoming aware of the incident, with the information we have available at that time. We will cooperate with the Organisation's own investigation and, where the Organisation is required to notify affected donors or a regulator, provide the information reasonably necessary for it to do so.
8. Return or deletion on termination
On termination of the Organisation's account, we handle Donor Data as described in the "Data export and effect of termination" section of the Subscription Terms: export access for 30 days, then deletion from active systems, subject to the statutory retention period for donation and receipt records under the Income Tax Act 1967 (seven years), which we retain regardless of a deletion request unless the Organisation accepts responsibility in writing for the resulting compliance gap.
9. Audit and inspection
On reasonable written request, no more than once per year absent a specific security concern, we will provide the Organisation with information reasonably necessary to demonstrate compliance with this DPA, such as our current Security & Compliance page and Subprocessors list. Given the number of Organisations on a shared platform, we do not offer on-site audits; where an Organisation's own regulatory obligations require a more formal assessment, contact us to discuss what we can support.
10. Contact us
Questions about this Data Processing Addendum can be sent to [email protected].

