Legal

Legal/Privacy Policy/Data Processing Addendum

Data Processing Addendum

Last Updated: July 13, 2026

This Data Processing Addendum (“DPA”) will apply, if required by Data Protection Legislation and only to the extent that SigmaLayer Company Limited (the “Company”) processes Personal Data in the roles set out in Clause 2.1 below, in providing the relevant types of Service to the User through the Anvita Flow platform according to the Anvita Flow Terms of Service (available at Anvita Flow Terms of Service) (“Terms”).

The Company and the User agree as follows:

1. Definitions and interpretation

1.1 Definitions:

  • Business Purposes”: the provision by the Company of the relevant types of Service and any other purpose specifically identified in Annex A or Annex B (as applicable) of this DPA.
  • Controller”, “Processor”, “Data Subject” and “Processing, processes and process” (or their local law equivalents) have the meanings given to them in the Data Protection Legislation.
  • Data Protection Legislation”: in relation to a Party, means any applicable legislation and related guidelines and requirements relating to Personal Data in force from time to time, as applicable to such Party in the processing of Personal Data (including the privacy of electronic communications), including Hong Kong Personal Data (Privacy) Ordinance (Chapter 486 of the Laws of Hong Kong).
  • Personal Data”: any personal data processed by the Company as a result of, or in connection with, the Business Purposes.
  • Personal Data Breach”: a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data transmitted, stored or otherwise processed.
  • Standard Contractual Clauses” or “SCCs”: the standard contractual clauses for the transfer of Personal Data to third countries under applicable Data Protection Legislation.
  • Sub-Processor”: a Processor engaged by the Company for the processing of Personal Data on behalf of the Company for the Business Purposes.

1.2 Capitalised terms in this DPA shall have the meaning given to them in the Terms, unless defined herein.

1.3 Notwithstanding anything to the contrary, to the extent that any specific Data Protection Legislation applies, (a) any terms not defined in this DPA shall be interpreted in accordance with, and have the meanings given under, such applicable Data Protection Legislation, and (b) where any term is defined in this DPA but is also defined under such applicable Data Protection Legislation, the definition under the applicable Data Protection Legislation shall prevail to the extent of any inconsistency.

1.4 In the case of conflict or inconsistency between the provisions of this DPA and any executed SCCs, the provisions of the executed SCCs will prevail.

1.5 The Annexes form part of this DPA and will have effect as if set out in full in the body of this DPA. Any reference to this DPA includes the Annexes.

1.6 Unless otherwise specified, a reference to writing or written includes email.

1.7 A reference to a person shall include a reference to an individual, firm, company, corporation, partnership, unincorporated body of persons, government, state or agency of a state or any association, trust, joint venture or consortium (whether or not having separate legal personality).

2. Processing

2.1 This DPA will apply, if required by Data Protection Legislation and only to the extent that, in providing a specific type of Service to the User:

  • (a) the User is the Controller of Personal Data and the Company is a Processor with respect to the Personal Data described in Annex A; or
  • (b) each of the User and the Company acts as independent Controllers with respect to the Personal Data described in Annex B.

3. Company acting as a Controller

3.1 This Clause 3 applies where the Company processes Personal Data as an independent Controller.

3.2 Each Party shall comply with the obligations applicable to it under Data Protection Legislation in respect of its processing of Personal Data described in Annex B.

3.3 The User warrants and represents that it has provided all necessary notices to, and obtained all necessary consents from, the relevant Data Subjects for the Company to process the Personal Data in accordance with this DPA and the Terms.

4. Company acting as a Processor

4.1 This Clause 4 applies only to the extent that the Company processes Personal Data as a Processor of the User.

4.2 The User shall not require the Company to process Personal Data in a manner that would cause the Company to be in breach of any applicable Data Protection Legislation. If the Company reasonably believes that any instruction from the User infringes applicable Data Protection Legislation, the Company shall be entitled to suspend the relevant processing and promptly notify the User.

4.3 The Company agrees that it will:

  • (a) only process the Personal Data for the Business Purposes in accordance with the specifications set out in Annex A; and
  • (b) not retain the Personal Data for longer than is necessary for the Business Purposes, unless retention is required by Applicable Law or reasonably necessary for backup, security, dispute resolution, legal compliance or other legitimate business purposes, as permitted by Applicable Law.

4.4 To the extent required by applicable Data Protection Legislation, the Company will provide reasonable assistance to the User in responding to requests from Data Subjects and complying with the User's obligations under applicable Data Protection Legislation, taking into account the nature of the Company’s processing and the information available to the Company.

4.5 The User warrants and represents that: (a) it has a valid and sufficient legal basis under the Data Protection Legislation for each instruction it gives to the Company regarding the processing of Personal Data; (b) it has provided all necessary notices to, and obtained all necessary consents from, the relevant Data Subjects to permit the Company to process the Personal Data in accordance with this DPA and the Terms; (c) where any Inputs or other content submitted through the Service contains Personal Data of a more sensitive nature (including data relating to health, finances, communications, employment or account credentials), the User has assessed and ensured the lawfulness of providing such data through the Service; and (d) to the extent that any processing carried out by the Company on behalf of the User constitutes or involves a data matching procedure or automated decision making (in each case, as defined under Data Protection Legislation), the User has provided the necessary disclosure and obtained the prescribed consent of the relevant Data Subjects in accordance with the Data Protection Legislation to permit the Company to perform such matching procedure for the Business Purposes.

4.6 Security

  • (a) The Company shall implement reasonable technical, organisational and physical measures, in accordance with Data Protection Legislation, to protect against unauthorised or unlawful processing and against accidental loss, destruction, alteration, disclosure or damage of Personal Data.

4.7 Personal Data Breach

  • (a) If the Company becomes aware of a Personal Data Breach, it will, only to the extent required by applicable Data Protection Legislation:
    • (i) notify the User and provide such information regarding the Personal Data Breach as is reasonably available to the Company;
    • (ii) subject to Clause 4.7(b) below, take reasonable steps to investigate and to identify, prevent and mitigate the effects of the Personal Data Breach; and
    • (iii) obtain the User’s consent before informing any third party of any Personal Data Breach, except when required to do so by Applicable Law.
  • (b) The Company will cover reasonable expenses reasonably incurred in performing its obligations under Clause 4.7(b) unless the Personal Data Breach arose directly from the User’s specific instructions, negligence, wilful default or breach of the Terms, in which case the User will cover all reasonable expenses.

4.8 Sub-Processors

  • (a) The Company may engage Sub-Processors to process Personal Data in connection with the Business Purposes, provided that:
    • (i) the Company shall impose obligations on Sub‑Processors that are materially consistent with the obligations imposed on the Company under this DPA, to the extent applicable to the relevant types of Service performed by the relevant Sub‑Processor, and, where required by applicable Data Protection Legislation, implement such additional contractual measures in connection with the engagement of such Sub‑Processor; and
    • (ii) the Company maintains control over all Personal Data it entrusts to the Sub-Processor.
  • (b) The Sub-Processors as of the commencement of this DPA are set out in Annex A. Where required by applicable Data Protection Legislation, the Company will provide the User with reasonable advance notice of any material changes or additions to the Sub-Processors.

4.9 Data return and destruction

  • (a) On termination of the Terms for any reason or expiry of its term, the Company will delete or destroy or, if directed in writing by the User, return and not retain, Personal Data related to this DPA, unless otherwise required to be retained by the Company under Applicable Law or reasonably necessary for backup, security, dispute resolution, legal compliance or other legitimate business purposes, as permitted by Applicable Law.

5. Cross-border transfers of personal data

  • (a) The User acknowledges and agrees that, to the extent that any Personal Data is transferred to the Company in connection with the Service from any jurisdiction, the User shall be solely responsible for ensuring that such transfer complies with the requirements of applicable Data Protection Legislation, including obtaining all necessary consents, notifications and approvals required to permit: (i) the transfer of Personal Data to the Company; and (ii) the onward transfer or processing of Personal Data by the Company (including by any authorised subcontractor) in accordance with the Terms and this DPA.
  • (b) The User agrees that the Company and its Sub‑Processors may process Personal Data in Hong Kong or such other jurisdictions in which they operate. Where required by applicable Data Protection Legislation, the Company will implement appropriate safeguards as required by applicable Data Protection Legislation in connection with any cross-border transfer of Personal Data.

6. Term and termination

6.1 This DPA will remain in full force and effect so long as the Terms remains in effect (the “Term”).

6.2 Any provision of this DPA that expressly or by implication should come into or continue in force on or after termination or expiry of the Terms in order to protect Personal Data will remain in full force and effect.


Annex A

(Controller to Processor transfer)

1. Description of Processing

  • Subject matter
The processing of Personal Data by the Company in connection with the provision of the relevant types of Service to the User.
  • Duration
Not longer than is necessary for the relevant Business Purposes, unless retention is required by Applicable Law or reasonably necessary for backup, security, dispute resolution, legal compliance or other legitimate business purposes, as permitted by Applicable Law.
  • Nature and purpose
The Company processes Personal Data on behalf of the User as necessary to provide, operate, maintain and support the relevant types of Service and otherwise perform its obligations under the Terms in accordance with the User's instructions.
  • Categories of Personal Data
Any Personal Data contained in any Input submitted to, stored on, transmitted through, processed by or generated through the relevant types of Service by or on behalf of the User, including Inputs submitted by or on behalf of the User and Outputs generated through the relevant types of Service. The Personal Data may include sensitive Personal Data to the extent submitted by or on behalf of the User through the relevant types of Service.
  • Data Subjects
Individuals whose Personal Data is processed through the relevant types of Service by or on behalf of the User, including the User's personnel, customers, end users and other individuals.

Annex B

(Controller to Controller transfer)

1. Description of Processing

  • Subject matter
The processing of Personal Data by the Company in connection with the provision of the relevant types of Service to the User.
  • Duration
Not longer than is necessary for the relevant Business Purposes, unless retention is required by Applicable Law or reasonably necessary for backup, security, dispute resolution, legal compliance or other legitimate business purposes, as permitted by Applicable Law
  • Nature and purpose
The Company processes Personal Data as necessary to provide, operate, maintain and support the relevant types of Service and otherwise perform its obligations under the Terms.
  • Categories of Personal Data
Personal Data processed by the Company in its capacity as an independent controller in connection with the operation, administration, security, support and improvement of the Service, as described in the Company's Privacy Policy, including Personal Data contained in or relating to user account data, Service logs, security monitoring data, analytics data (if enabled) and customer support records.
  • Data Subjects
Individuals whose Personal Data is processed by the Company in connection with the provision, operation, administration, security and support of the Service, including the User's personnel, customers, end users and other individuals.