WeCom DATA PROCESSING AGREEMENT

This data processing agreement is between Tencent International Service Pte. Ltd., an entity incorporated in Singapore and Tencent International Service Europe B.V., an entity incorporated in the Netherlands, as the processors (each a “Data Processor”), and the relevant entity that has entered into the Service Agreement (as defined below) (the “Data Controller” or “Company User”) and incorporates the terms and conditions set out in the Schedules attached hereto (the “Agreement”).

In respect of this Agreement, if the Company User is a registered entity in the EEA, UK or Switzerland, references to “Data Processor” shall be read as a reference to Tencent International Service Europe B.V., and if the Company User is a registered entity outside of the EEA, UK and Switzerland, references to “Data Processor” shall be read as a reference to Tencent International Service Pte. Ltd.

Data Controller has appointed Data Processor to provide services to the Data Controller as set out in the WeCom Service Agreement (the “Service Agreement”) entered into between Data Processor and Data Controller on or around the date of this Agreement, and the parties acknowledge that, for purposes of Applicable Data Protection Laws, Data Controller is the “controller,” “business” or any other similar term and Data Processor is the “service provider,” “processor,” “contractor” or similar term, each as provided for under the Applicable Data Protection Laws. As a result of its providing such services to the Data Controller, Data Processor will store and Process certain Personal Data of the Data Controller, in each case as described in further detail in Schedule 2 (Description of Transfers).

The Agreement is being put in place to ensure Data Processor Processes Data Controller’s Personal Data on the Data Controller’s instructions and in compliance with Applicable Data Protection Laws.

The parties to this Agreement hereby agree to be bound by the terms and conditions in the attached Schedules, as applicable, with effect from the date the Company User is deemed to have agreed to the terms of the Service Agreement (in accordance with the terms of such agreement) (the “Effective Date”).

This Agreement may be executed in any number of counterparts, each of which is an original and all of which evidence the same agreement between the parties.

Please note that this Data Processing Agreement only applies to Personal Data for which the Data Processor is the processor as described in the Privacy Policy located here. For Personal Data processed where the Data Processor is the controller, please review the relevant parts of the Privacy Policy.

 

SCHEDULE 1STANDARD TERMS FOR PROCESSING AGREEMENT BACKGROUND

Data Controller wishes to appoint Data Processor to Process Personal Data, as further described in Schedule 2 (Description of Transfers).

The Agreement is being put in place to ensure Data Processor Processes Data Controller’s Personal Data on Data Controller’s instructions and in compliance with the Applicable Data Protection Laws (as defined below).

 

1. Definitions

For the purposes of this Agreement, the following expressions bear the following meanings, unless the context otherwise requires:

Applicable Data Protection Laws” means (a) the General Data Protection Regulation 2016/679 (the “GDPR”); (b) the Privacy and Electronic Communications Directive 2002/58/EC; (c) the UK Data Protection Act 2018 (“DPA”), the UK Data (Use and Access) Act 2025 (“DUA Act”), the UK General Data Protection Regulation, as defined by the DUA Act as amended by the Data Protection, Privacy and Electronic Communications (Amendments etc.) (EU Exit) Regulations 2019 and the DUA Act (together with the DPA and the DUA Act, the “UK GDPR”), and the Privacy and Electronic Communications Regulations 2003; (d) the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA”), the Colorado Privacy Act (“CPA”), the Connecticut Data Privacy Act (“CTDPA”), the Delaware Personal Data Privacy Act ("DPDPA"), the Florida Digital Bill of Rights (“FDBR”), , the Indiana Consumer Data Protection Act (“INCDPA”), the Iowa Consumer Data Protection Act (“ICDPA”), the Maryland Online Data Privacy Act ("MODPA"), the Minnesota Consumer Data Privacy Act ("MNCDPA"), the Montana Consumer Data Privacy Act (“MCDPA”), the Nebraska Data Privacy Act ("NEDPA"), the New Hampshire Data Privacy Act ("NHDPA"), the New Jersey Data Privacy Act ("NJDPA"), the Oregon Consumer Privacy Act (“OCPA”), the Tennessee Information Protection Act (“TIPA”), the Texas Data Privacy and Security Act (“TDPSA”), the Utah Consumer Privacy Act (“UCPA”), and the Virginia Consumer Data Protection Act (“VCDPA”); (collectively, “Applicable US Data Protection Laws”); and (e) any relevant law, statute, declaration, decree, directive, legislative enactment, order, ordinance, regulation, rule or other binding instrument which implements any of the above, or which otherwise relates to data protection, privacy or the use of personal data, in each case, as applicable and in force from time to time, and as amended, consolidated, re-enacted or replaced from time to time;

Controller to Processor Clauses” means (i) in respect of transfers of Personal Data subject to the GDPR, the standard contractual clauses for the transfer of Personal Data to third countries set out in Commission Decision 2021/914 of 4 June 2021, specifically including Module 2 (Controller to Processor); and (ii) in respect of transfers of Personal Data subject to the UK GDPR, the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses (version B.1.0) issued by the UK Information Commissioner, in each case as amended, updated or replaced from time to time;

Business”, “Data Controller”, “Data Processor”, “Data Subject”, “Selling”, “Service Provider” and “Sharing” shall have the meaning given to these term or equivalent concepts in the relevant Applicable Data Protection Laws;

Data Privacy Framework” means, as relevant, (i) the EU-US Data Privacy Framework as administered by the US Department of Commerce and approved by the European Commission as ensuring an adequate level of protection for Personal Data for the purposes of Article 45 GDPR; (ii) the UK Extension to the EU-US Data Privacy Framework approved by the competent authority of the United Kingdom as ensuring an adequate level of protection for Personal Data for the purposes of Article 45 UK GDPR; and (iii) the Swiss-US Data Privacy Framework as administered by the US Department of Commerce and approved by the Swiss Federal Administration as ensuring an adequate level of protection for Personal Data for the purposes of applicable Swiss data protection laws, in each case as in force, amended, consolidated, re-enacted or replaced from time to time;

Lawful Export Measure” means a method allowing for the lawful transfer of Personal Data from a data exporter to a data importer, as may be stipulated by Applicable Data Protection Laws or a Regulator from time to time, which may include (depending upon the applicable laws) model transfer terms prescribed by Applicable Data Protection Laws; or prior registration, licensing or permission from a Regulator;

Personal Data” shall have the meaning given to “personal data” and “personal information” and other similar terms in the relevant Applicable Data Protection Laws;

Process”, “Processed” or “Processing” shall have the meaning given to this term or equivalent concept in the relevant Applicable Data Protection Laws;

Processor to Controller Clauses” means, as relevant, (i) in respect of transfers of Personal Data subject to the GDPR, the standard contractual clauses for the transfer of Personal Data to third countries set out in Commission Decision 2021/914 of 4 June 2021, specifically including Module 4 (Processor to Controller); (ii) in respect of transfers of Personal Data subject to the UK GDPR, the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses (version B.1.0) issued by the UK Information Commissioner, and (iii) in respect of transfers of Personal Data outside any jurisdiction that require such transfer to be effected by a Lawful Export Measure, the lawful form of contract for the transfer of Personal Data to Third Countries from data processors to data controllers approved by the relevant competent authority of such jurisdiction, in each case as in force, amended, updated or replaced from time to time;

Processor to Processor Clauses” means, as relevant, (i) in respect of transfers of Personal Data subject to the GDPR, the standard contractual clauses for the transfer of Personal Data to third countries set out in Commission Decision 2021/914 of 4 June 2021, specifically including Module 3 (Processor to Processor); (ii) in respect of transfers of Personal Data subject to the UK GDPR, the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses (version B.1.0) issued by the UK Information Commissioner, in each case as amended, updated or replaced from time to time;

Regulator” means (a) a data protection supervisory authority which has jurisdiction over a Data Controller’s Processing of Personal Data; and (b) in the PRC, the competent central governmental authorities and respective local counterparts, which include but not limited to the Cyberspace Administration of China (“CAC”) in the PRC; and

Third Country” means (i) in relation to Personal Data transfers subject to the GDPR, any country or territory outside of the scope of the data protection laws of the European Economic Area (“EEA”), excluding countries or territories approved as providing adequate protection for Personal Data by the European Commission from time to time; (ii) in relation to Personal Data transfers subject to the UK GDPR, any country or territory outside of the scope of the data protection laws of the UK, excluding countries or territories approved as providing adequate protection for Personal Data by the relevant competent authority of the UK from time to time; and (iii) in relation to Personal Data transfers from any other jurisdiction, any country or territory other than those approved as providing adequate protection for Personal Data by the relevant competent authority of such jurisdiction from time to time.

 

2. Conditions of Processing

This Agreement governs the terms under which Data Processor is required to Process Personal Data on behalf of the Data Controller.

 

3. Data Processor’s Obligations

3.1 Data Processor shall only Process Personal Data on behalf of the Data Controller and in accordance with, and for the limited and specific purposes set out in the documented instructions received from the Data Controller unless  required to Process such Personal Data by applicable law to which the Data Processor is subject; in each case, the Data Processor shall inform the Data Controller of that legal requirement before Processing without undue delay, unless that law prohibits such information on important grounds of public interest. To the extent required by Applicable US Data Protection Laws, Data Processor shall provide the same level of privacy protection as is required by such laws.

3.2 To the extent required by Applicable US Data Protection Laws, Data Processor shall notify Data Controller if Data Processor makes a determination that it can no longer meet its obligations under Applicable US Data Protection and Data Controller  may take reasonable and appropriate steps to help ensure that Data Processor uses the Personal Data in a manner consistent with the Data Controller’s obligations under Applicable US Data Protection Laws and to the extent Data Controller reasonably believes Data Processor is using Personal Data in violation of Applicable US Data Protection Laws, stop and remediate any unauthorized use of the Personal Data.

3.3 Data Processor shall implement appropriate technical and organisational measures designated to provide a level of security appropriate to the risk, taking into account the state-of-the-art, the costs of implementation and the nature, scope, context and purpose of the Processing as set out in Schedule 3, or otherwise agreed and documented between the Data Controller and Data Processor from time to time. The allocation as set out in Schedule 3 establishes the responsibilities between the parties to this Agreement to implement such measures.

3.4 Data Processor shall, without undue delay, notify the Data Controller about any breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, the Personal Data belonging to the Data Controller (with further information about the breach provided in phases as more details become available).

3.5 To the extent required by Applicable Data Protection Laws, Data Processor shall:

(i)​ upon reasonable written request from Data Controller, provided that Data Controller gives at least one (1) month's prior written notice of any such request, from time to time (but no more than once annually), provide Data Controller with such documentation in its possession as is reasonably necessary to demonstrate compliance with the obligations laid down in this Agreement, in a manner mutually agreed by the parties; and

(ii)​ in a manner mutually agreed by the parties, either arrange for a qualified and independent auditor to conduct an assessment of Data Processor’s policies and technical and organizational measures in support of its obligations under Applicable Data Protection Laws and this Agreement, or allow, and cooperate with, reasonable assessments by Data Controller, or Data Controller’s designated auditor, of Data Processor’s compliance with its obligations under Applicable Data Protection Laws and this Agreement.

3.6 Where:

(ii)​ a Data Subject exercises his or her rights under the Applicable Data Protection Law in respect of Personal Data Processed by Data Processor on behalf of Data Controller, including Data Subjects exercising rights under Applicable Data Protection Laws (such as rights to rectification, erasure, blocking, access their personal data, objection, restriction of processing, data portability and the right not to be subject to automated decision-making);

(ii)​ Data Controller is required to deal or comply with any assessment, enquiry, notice or investigation by the Regulator; or

(iii)​ Data Controller is required under the Applicable Data Protection Laws to carry out a mandatory data protection impact assessment or consult with the Regulator prior to Processing Personal Data entrusted to the Data Processor under this Agreement,

then Data Processor will provide reasonable assistance to the Data Controller to enable that Data Controller to comply with obligations which arise as a result thereof.

3.7 When the Data Processor Processes Personal Data in the United States, the Data Processor is prohibited from:

(i)​ Selling the Personal Data;

(ii)​ Sharing the Personal Data for cross-context behavioural advertising purposes;

(iii)​  retaining, using, or disclosing the Personal Data for any purpose other than for the specific purpose of performing the services that are to be provided to Data Controller;

(iv)​ retaining, using or disclosing the Personal Data outside of the direct business relationship between the Data Processor and Data Controller; or

(v)​ combining the Personal Data received from Data Controller with any Personal Data that may be collected from Data Processor’s separate interactions with the individual(s) (if applicable) to whom the Personal Data relates to or from any other sources, provided that the Data Processor may combine the Personal Data from other sources if such combination is necessary to perform the business purposes set forth by this Agreement.

3.8 To the extent required by Applicable US Data Protection Laws and to the extent Data Processor receives de-identified data (as such term is defined under Applicable Data Protection Laws) from Data Controller, Data Processor shall:

(i)  take reasonable measures to ensure that the data cannot be associated with an identified or identifiable individual;

 (ii)  publicly commit to maintain and use the data only in a de-identified fashion; and (iii) not attempt to re-identify the data.

3.9 To the extent the Data Processor Processes Personal Data in a Third Country other than in the United States pursuant to the Data Privacy Framework, and it is acting as data importer, the Data Processor shall:

(i)  in respect of the Processing of Personal Data in a Third Country that is not subject to the GDPR or UK GDPR, and to the extent required by Applicable Data Protection Laws, ensure such transfer is carried out using a Lawful Export Measure. To the extent such Lawful Export Measure requires (a) a contract imposing appropriate safeguards on the transfer and processing of such Personal Data (which is not otherwise satisfied by this Agreement); (b) a description of the Processing of Personal Data contemplated under this Agreement; and (c) a description of technical and organisational measures to be implemented by the data importer, the parties agree that the Controller to Processor Clauses, the description of processing activities set out in Schedule 2 (Description of Transfers) and the description of technical and organisational measures set out in Schedule 3 (Technical and Organisation Security Measures), shall apply mutatis mutandis for the benefit of such transfer, and in relation to any onward transfer of the Personal Data to another person, the other person shall comply with the same importer obligations, mutatis mutandis;

(ii)   in respect of the Processing of Personal Data in a Third Country that is subject to the GDPR or UK GDPR, comply with the data importer’s obligations set out in the Controller to Processor Clauses, which are hereby incorporated into and form part of this Agreement; the Data Controller will comply with the data exporter’s obligations in such Controller to Processor Clauses; and:

(iii)​ for the purposes of Annex I or Part 1 (as relevant) of such Controller to Processor Clauses, the Parties and Processing details set out in Schedule 2 (Description of Transfers) shall apply, and the Start Date is the Effective Date, and the signature(s) (in any form) given in connection with the execution of this Agreement by a party and the date(s) of such signature(s) shall apply as the dated signature required from that party;

(iv)​ if applicable, for the purposes of Part 1 of such Controller to Processor Clauses, the relevant Addendum EU SCCs (as such term is defined in the applicable Controller to Processor Clauses) are the standard contractual clauses for the transfer of Personal Data to third countries set out in Commission Decision 2021/914 of 4 June 2021 (Module 2), as incorporated into this Agreement by virtue of this Clause 3.10;

(v)​ for the purposes of Annex II or Part 1 (as relevant) of such Controller to Processor Clauses, the technical and organisational security measures set out in Schedule 3(Technical and Organisation Security Measures) shall apply; and

(vi)​ if applicable, for the purposes of: (i) Clause 9 of such Controller to Processor Clauses, Option 2 (“General written authorization”) is deemed to be selected and the notice period specified in Clause 6.2 shall apply; (ii) Clause 11(a) of such Controller to Processor Clauses, the optional wording in relation to independent dispute resolution is deemed to be omitted; (iii) Clause 13 and Annex I.C, the competent supervisory authority shall be the Dutch Supervisory Authority; (iv) Clause 17, Option 2 is deemed to be selected and the governing law shall be the laws of the Netherlands; (v) Clause 18, the competent courts shall be the competent courts of the Netherlands; (vi) Part 1 of such Controller to Processor Clauses, the Data Processor, as Importer may terminate the Controller to Processor Clauses pursuant to Section 19 of such Controller to Processor Clauses; and

3.10 To the extent Data Controller Processes Personal Data in a Third Country, and is acting as data importer, and Data Processor is acting as data exporter, Data Processor shall:

(i)​ in respect of the Processing of Personal Data in a Third Country that is not subject to the GDPR or UK GDPR, and to the extent required by Applicable Data Protection Laws, comply with the data exporter’s obligations required by the Lawful Export Measure adopted; Data Controller will comply with the data importer’s obligations required by the Lawful Export Measure adopted. To the extent such Lawful Export Measure requires (a) a contract imposing appropriate safeguards on the transfer and processing of such Personal Data (which is not otherwise satisfied by this Agreement); and (b) a description of the Processing of Personal Data contemplated under this Agreement, the Parties agree that the Processor to Controller Clauses and the description of processing activities set out in Schedule 2 (Description of Transfers), shall apply mutatis mutandis for the benefit of such transfer;

(ii)​ in respect of the Processing of Personal Data in a Third Country that is subject to the GDPR or UK GDPR, comply with the data exporter’s obligations set out in the Processor to Controller Clauses, which are hereby incorporated into and form part of this Agreement; Data Controller will comply with the data importer’s obligations in such Processor to Controller Clauses; and:

(iii)​ for the purposes of Annex I or Part 1 (as relevant) of such Processor to Controller Clauses, the Parties and Processing details set out in Schedule 2  (Description of Transfers) shall apply, and the Start Date is the Effective Date, and the signature(s) (in any form) given in connection with the execution of this Agreement by a Party and the date(s) of such signature(s) shall apply as the dated signature required from that Party;

(iv)​ if applicable, for the purposes of Part 1 of such Processor to Controller Clauses, the relevant Addendum EU SCCs (as such term is defined in the applicable Processor to Controller Clauses) are the standard contractual clauses for the transfer of Personal Data to third countries set out in Commission Decision 2021/914 of 4 June 2021 (Module 4) as incorporated into this Agreement by virtue of this sub-Clause (ii)(B); and

(v)​ if applicable, for the purposes of: (i) Clause 17, the governing law shall be the law of the Netherlands; (ii) Clause 18, the competent courts shall be the competent courts of the Netherlands; (iii) Part 1 of such Processor to Controller Clauses, Data Processor as Exporter may terminate the Processor to Controller Clauses pursuant to Section 19 of such Processor to Controller Clauses.

3.11 The Data Controller acknowledges and agrees that Data Processor may appoint an affiliate or a third-party subcontractor to Process the Data Controller’s Personal Data in a Third Country, in which case, the Data Processor shall execute the Processor to Processor Clauses with any relevant subcontractor (including affiliates) it appoints on behalf of the Data Controller.

 

4. Data Controller’s Obligations

4.1 Data Controller warrants that: (i) the legislation applicable to it does not prevent Data Processor from fulfilling the instructions received from the Data Controller and performing Data Processor’s obligations under this Agreement; and (ii) it has complied, and continues to comply, with the Applicable Data Protection Laws, in particular, that it has obtained any necessary consents or given any necessary notices, and otherwise has a legitimate ground to disclose the data to Data Processor and enable the Processing of the Personal Data by the Data Processor, as set out in this Agreement.

4.2 Where Data Controller acts as the data importer, it shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account the state of the art, the costs of implementation and the nature, scope, context and purpose of the Processing as otherwise agreed and documented between Data Controller and Data Processor from time to time.

4.3 Data Controller agrees that it will indemnify and hold harmless Data Processor on demand from and against all claims, liabilities, costs, expenses, loss or damage (including consequential losses, loss of profit and loss of reputation, and all interest, penalties and legal and other professional costs and expenses) incurred by Data Processor arising directly or indirectly from a breach of Applicable Data Protection Laws or this Agreement.

 

5. Changes in Applicable Data Protection Laws

The parties agree to negotiate in good faith modifications to this Agreement if changes are required for Data Processor to continue to process the Personal Data, as contemplated by this Agreement in compliance with the Applicable Data Protection Laws, or to address the legal interpretation of the Applicable Data Protection Laws, including: (i) to comply with the GDPR or any national legislation implementing it, or the UK General Data Protection Regulation or the DPA, and any guidance on the interpretation of any of their respective provisions; (ii) if the Controller to Processor Clauses or the Processor to Processor Clauses, or any other mechanisms or findings of adequacy, are invalidated or amended; (iii) if changes to the membership status of a country in the European Union or the EEA require such modification.

 

6. Sub-Contracting

6.1 The Data Controller hereby grants the Data Processor general written authorisation to engage, and consents to the use of the subcontractor(s) set out in Schedule 4 (Authorised Subcontractors), for the purposes further described in Schedule 4 (Authorised Subcontractors), and subject to this Clause 6.  The Data Processor may also maintain an online list of subcontractor(s) in its Privacy Policy, available at https://work.weixin.qq.com/nl/data_agreement (“Online List”). The Data Controller authorises the Data Processor to engage, and consents to the use of, the subcontractors included in the Online List and any subsequent updates to it. In case of conflict between the Online List and Schedule 4, the most recent one shall prevail.

6.2 If Data Processor appoints a new subcontractor or intends to make any changes concerning the addition or replacement of the subcontractors set out in Schedule 4 (Authorised Subcontractors), it shall provide the Data Controller with twenty (20) business days’ prior written notice, during which the Data Controller can object against the appointment or replacement. If the Data Processor updates the Online List of subcontractors, the Data Controller shall have twenty (20) days from the date of the update to object to the appointment or replacement of any subcontractor. If the Data Controller does not object within the applicable notice period, the Data Processor may proceed with the appointment or replacement of the subcontractor.

6.3 The Data Processor shall ensure it has a written agreement in place with all subcontractors which contains obligations on the subcontractor that are no less onerous on the relevant subcontractor than the obligations on Data Processor under this Agreement. 

 

7. Confidentiality

7.1 Each party (the “Recipient”) undertakes to the other party (the “Discloser”) to:

(i)​ hold all Personal Data of the Discloser which it obtains in relation to this Agreement, in strict confidence; and

(ii)​ ensure that employees, agents, officers, consultants, sub-processors, subcontractors, and advisers authorised to Process the Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

7.2 The obligation in Clause 7.1 will not apply to a disclosure of Personal Data that is:

(i)​ required by any law or regulation of any country with jurisdiction over the affairs of any Data Processor; and

(ii)​ required by any order of any court of competent jurisdiction.

7.3 The obligation in Clause 7.1 shall apply to the provision of any document or information that states a party’s approach to security by Data Processor to Data Controller.

 

8. Termination

Termination of this Agreement shall be governed by the Service Agreement.

 

9. Consequences of Termination

Upon termination of this Agreement in accordance with Clause 8 (Termination), Data Processor shall, following the completion of services relating to the Processing, destroy all Personal Data Processed on behalf of the Data Controller, including all copies thereof, and shall cease all Processing of Personal Data on its behalf, unless such destruction is prohibited by applicable law. Where destruction is technically infeasible, Data Controller authorises Data Processor to, and Data Processor shall, anonymise all such Personal Data.

 

10. Law and Jurisdiction

This Agreement and any dispute or claim (including non-contractual disputes or claims) arising out of or in connection with it or its subject matter or formation shall be governed by and construed in all respects in accordance with the governing law of the Service Agreement.

Any dispute shall be referred to, and finally resolved by, the dispute resolution process and forum specified in the Service Agreement.

 

SCHEDULE 2DESCRIPTION OF TRANSFERS

1. LIST OF PARTIES

Data exporter(s) – Data Controller: Identity and contact details of the data exporter(s) and, where applicable, of its/their data protection officer and/or representative in the European Union

-Name: The Company User

-Address: See details in Service Agreement

-Contact person’s name, position and contact details: See details in Service Agreement

-Activities relevant to the data transferred under these Clauses: To obtain services as detailed in the Service Agreement.

-Role (controller/processor): Controller

 

Data importer(s) – Data Processor (as relevant depending on where Company User is established):

If the Company User is a registered entity in the EEA, UK or Switzerland.

If the Company User is a registered entity outside of the EEA, UK and Switzerland.

-Name: Tencent International Service Europe B.V.

-Address: Buitenveldertselaan 1-5, 1082 VA, Amsterdam, the Netherlands

-Contact person’s name, position and contact details:  Data Protection Officer; WeCom_DP@tencent.com

-Activities relevant to the data transferred under these Clauses: To provide services as detailed in the Service Agreement.

-Role (controller/processor): Processor

-Name: Tencent International Service Pte. Ltd.

-Address: 10 Anson Road, #21-07 International Plaza, Singapore

-Contact person’s name, position and contact details:  Data Protection Officer; WeCom_DP@tencent.com

-Activities relevant to the data transferred under these Clauses: To provide services as detailed in the Service Agreement.

-Role (controller/processor): Processor

 

2. PROCESSING DETAILS / DESCRIPTION OF TRANSFER

Categories of data subjects whose personal data is processed / transferred

Users of the Services detailed in the Service Agreement.

Categories of personal data processed / transferred

Personal Data transmitted by the users of the WeCom platform (for example, by setting up a Company User or Individual User account, by video or audio transmission, or by sharing information on WeCom). These include but are not limited to:

-Company registration data;

-Address book data;

-Chat data;

-Backend management statistics data;

-Voice and video call functions data, and live broadcast data;

-Schedule and calendar data;

-Favourites data (where users choose to mark items as favourites);

-Email communication data and announcements data;

-Meetings data;

-Human resources assistant data;

-Documents data;

-Contact data, and customer group chat data;

-Data related to specific functions and features available on WeCom (e.g. WeDrive, Mini Programs, Moments, body temperature (where available), forms, approval, inspection report, company forum, succession upon resignation, customer acquisition assistant, group chat assistant, classwork, extra-curricular activities, school dashboard, dining reservations, conference room, industry news, device inspection, door access);

-WeChat/Weixin workspace data, and Weixin customer service plugin data;

-Wireless connectivity and printing data; and

-Data security data.

Sensitive data processed / transferred (if applicable) and applied restrictions or safeguards that fully take into consideration the nature of the data and the risks involved, such as, for instance, strict purpose limitation, access restrictions (including access only for staff having followed specialised training), keeping a record of access to the data, restrictions for onward transfers or additional security measures.

N/A

The frequency of the transfer (e.g. whether the data is transferred on a one-off or continuous basis)

Continuous

Nature of the processing

The collection, storage, duplication, deletion, and disclosure of Personal Data pursuant to providing services to Company User pursuant to the Services Agreement.

Purpose(s) of the data processing / data transfer and further processing

To provide services to Company User as detailed in the Service Agreement.

Please refer to the Categories of Data section above

Duration of the processing / the period for which the personal data will be retained, or, if that is not possible, the criteria used to determine that period

For the duration of the Service Agreement.

For processing by / transfers to (sub-)processors, also specify subject matter, nature and duration of the processing

See Schedule 4 and Online List.

3. COMPETENT SUPERVISORY AUTHORITY

Dutch Supervisory Authority

 

SCHEDULE 3TECHNICAL AND ORGANISATION SECURITY MEASURESData Processor

Description of the technical and organisational measures implemented by the data importer(s) (including any relevant certifications) to ensure an appropriate level of security, taking into account the nature, scope, context and purpose of the processing, and the risks for the rights and freedoms of natural persons.

1. Data security. Implement:

(i)​ the encryption of Personal Data;

(ii)​ the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services;

(iii)​ the ability to restore the availability and access to Personal Data in a timely manner in the event of a physical or technical incident;

(iv)​ a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing;

(v)​ standards for data categorisation and classification;

(vi)​ a set of authentication and access control capabilities at the physical, network, system and application levels; and

(vii)​ a mechanism for detecting abnormal behaviour.

2. Network security. Implement stringent rules on internal network isolation to achieve access control and border protection for internal networks (including office networks, development networks, testing networks and production networks) by way of physical and logical isolation.

3. Physical and environmental security. Stringent infrastructure and environment access controls for data access based on relevant security requirements. An access control matrix to be established to ensure effective management and control of access and operations personnel and to prevent unauthorized access and illegal access.

4. Incident management. Operate active and real-time service monitoring, combined with a rapid response and handling mechanism, that enables prompt detection and handling of security incidents.

5. Training and awareness. Promotion of privacy and security awareness among personnel, staff, employees, or other individuals involved in the access, collection, use, modification, alteration, deletion, or disclosure of personal data, including via training sessions on personal data protection, and the notification of personal data protection policies, practices, and measures.

6. User and access management. Assign user responsibilities in order to prevent access, use, modification, deletion or disclosure of personal data without authorization or unlawfully, including where actions are carried out beyond the scope of assigned duties and responsibilities as well as unauthorized or unlawful duplication of personal data and theft of devices used for storing or processing personal data.

For transfers to (sub-)processors, also describe the specific technical and organisational measures to be taken by the (sub-)processor to be able to provide assistance to the controller and, for transfers from a processor to a sub-processor, to the data exporter

For any transfers of Personal Data to sub-processors within the same corporate group as the Data Processor, the Data Processor will ensure that such sub-processors implement technical and organisational measures that are substantially equivalent to those maintained by the Data Processor, as described herein.

The Data Processor will update the Data Controller with details of the measures implemented by any other third parties upon its written request and as part of the onboarding process of third parties sub-processor.

 

SCHEDULE 4AUTHORISED SUBCONTRACTORS

Subcontractors

Services provided

Description of Processing

Contact Details

Tencent Cloud International Pte. Ltd.

Provider of Cloud service

Providing cloud storage service in accordance with WeCom’s Privacy Policy

Address : 10 Anson Road, #21-07, International Plaza, Singapore 079903

Contact : same as Data Processor

Shenzhen Tencent Computer Systems Company Limited

Provider of operation service, interrelated functions and Tencent Meeting Service

Providing operation service, interrelated functions and Tencent Meeting Service in accordance with WeCom’s Privacy Policy

Address : 35/F., Tencent Building, Kejizhongyi Avenue, Maling Community, Yuehai Street, Nanshan District, Shenzhen, People’s Republic of China

Contact : same as Data Processor

Tencent Cloud Hong Kong Limited

Provider of VooV Meeting Service

Providing VooV Meeting Service in accordance with WeCom’s Privacy Policy

Address : 29/F., Three Pacific Place No. 1 Queen's Road East Wanchai Hong Kong

Contact : same as Data Processor

ACEVILLE PTE LIMITED

Provider of VooV Meeting Service

Providing VooV Meeting Service in accordance with WeCom’s Privacy Policy

Address : 79 ROBINSON ROAD, #07-01, CAPITASKY, SINGAPORE 068897

Contact : same as Data Processor