Nomos Pte. Ltd.
Data Processing Addendum
Last updated: 6 June 2026
This Data Processing Addendum describes how Nomos processes Customer Data on behalf of a customer acting as controller under Singapore’s PDPA.
1. Definitions
Terms such as \u201cCustomer Data\u201d, \u201cPersonal Data\u201d, \u201cProcess\u201d, \u201cSubprocessor\u201d, and \u201cData Breach\u201d have the meanings given by the PDPA and the applicable agreement.
2. Roles of the parties
The customer determines the purposes and means of processing. Nomos processes Customer Data only on documented instructions.
3. Scope, nature and purpose of processing
Processing supports governed extraction, classification, workflow routing, review, audit, and related service operations.
4. Nomos obligations
Nomos maintains confidentiality, security, access controls, deletion procedures, and personnel commitments appropriate to the processing.
5. Subprocessors
Nomos may use approved subprocessors for infrastructure, communications, analytics, and service delivery, subject to written obligations.
6. Cross-border transfers
Cross-border processing is subject to safeguards designed to maintain protection comparable to Singapore data protection requirements.
7. Notifiable Data Breach
Nomos will notify the customer without undue delay after confirming a Data Breach affecting Customer Data and will support investigation and response.
8. Use of AI systems
Customer Data is not used to train third-party foundation models. Human review and policy controls remain part of the governed workflow.
9. Return and deletion
At the customer\u2019s request or on termination, Nomos will return or delete Customer Data unless retention is required by law.
10. Audits
Nomos will make information reasonably necessary to demonstrate compliance available to the customer, subject to confidentiality and security limits.
11. Liability
Liability for processing activities follows the allocation in the applicable agreement and this Addendum.
12. Order of precedence
If this Addendum conflicts with another agreement, the order of precedence stated in the applicable contract applies.
Annex I — Description of processing
Processing covers business contact details, operational records, communications, and related metadata needed to provide the Services.
Annex II — Technical and organisational security measures
Measures include access control, least privilege, encryption in transit, logging, monitoring, secure development, and incident response.
Annex III — Approved Subprocessors
The current approved Subprocessor list is available from Nomos on request and may be updated with appropriate notice.