1.DEFINITIONS:
For the purposes of this DPA, the following terms shall have the meanings set out below. Terms not defined herein shall have the meanings given in the Agreement or applicable Data Protection Laws.
"Data Protection Laws" means all applicable legislation regarding privacy and the protection of Personal Data, including: (a) the Personal Data Protection Act 2012 (No. 26 of 2012) of Singapore and any regulations, guidelines, advisory guidelines and codes of practice issued thereunder by the Personal Data Protection Commission, including the Personal Data Protection Regulations 2021 (collectively, the “PDPA”), (b) any other applicable data protection or privacy legislation in the Asia-Pacific region including but not limited to Australia’s Privacy Act 1988 (Cth) and Japan’s Act on the Protection of Personal Information (APPI), (c) the retained EU law version of the General Data Protection Regulation ((EU) 2016/679) as incorporated by section 3 of the European Union (Withdrawal) Act 2018 and Data Protection Act 2018 (together, the “UK GDPR”) and Privacy and Electronic Communications Regulations 2003 (SI 2003/2426) (where the Agreement is governed by English law), (d) applicable U.S. state privacy laws (where the Agreement is governed by New York law) including the California Consumer Privacy Act (“CCPA”) as amended by the California Privacy Rights Act (“CPRA”), and (e) any substantially similar U.S. state privacy legislation, together with any successor or replacement legislation and any equivalent legislation in any jurisdiction in which the Services are provided. The term “organisation” and “data intermediary” shall have the same meanings as in the PDPA. The terms “controller”, “data processor”, “process”, “processing”, “personal data breach” and “data subject” shall have the meanings given to them in the UK GDPR. The terms “business”, “business purpose”, “consumer” and “service provider” shall have the same meaning as in the CCPA.
“Data Security Policy” means Fifth Dimension's Information Security Policy at https://www.fifthdimensionai.com/en-gb/trust-center updated from time to time on reasonable notice to the Customer.
"Sub-processor" means any third party engaged by Fifth Dimension to process Personal Data on behalf of the Customer.
“Sub-processor List” is the list of Fifth Dimension’s Sub-processors at https://www.fifthdimensionai.com/en-gb/trust-center (as may be updated in accordance with Section 5.11 of this DPA).
"International Data Transfer Agreement" or "IDTA" means the standard international data transfer agreement issued by the UK Information Commissioner's Office under Section 119A(1) of the Data Protection Act 2018.
“Personal Data” or “Personal Information” means any information that identifies, relates to, describes, is capable of being associated with, or could reasonably be linked, directly or indirectly, to or with an identified or identifiable natural person which is processed by Fifth Dimension on behalf of Customer under this DPA and the Agreement.
“Sensitive Data” means Personal Data that requires unique treatment under Data Protection Laws, such as “special categories of data”, “sensitive data” or other materially similar terms, which may include any of the following types of Personal Data: (a) social security number, tax file number, passport number, driver’s license number, or similar identifier (or any portion thereof); (b) financial or credit information, credit or debit card number; (c) information revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data or biometric data for the purpose of uniquely identifying a natural person, data concerning a person’s health, sex life or sexual orientation, or data relating to criminal convictions and offences; (d) precise geolocation data; (e) Personal Data relating to children; and/or (f) account passwords in unhashed form, excluding authentication credentials necessary for the provision of the Services.
"Standard Contractual Clauses” or “SCCs" means the standard data protection clauses adopted by the European Commission on 4 June 2021 under Article 46(2)(c) of the General Data Protection Regulation ((EU) 2016/679) and approved for use in England and Wales under The Data Protection, Privacy and Electronic Communications (Amendments etc) (EU Exit) Regulations 2019.
"UK Addendum to the SCCs" means the addendum to the SCCs, as amended, approved for use in England and Wales by the UK Information Commissioner's Office pursuant to The Data Protection, Privacy and Electronic Communications (Amendments etc) (EU Exit) Regulations 2019.
"UK Standard Contractual Clauses" means such standard data protection clauses as are adopted from time to time by the UK Information Commissioner's Office in accordance with Article 46(2) of the UK GDPR; including, the International Data Transfer Agreement and UK Addendum to the SCCs.
2.SCOPE
2.1.Application: This DPA sets out the data protection terms required under the applicable Data Protection Laws for arrangements between an organisation (or controller or business) and a data intermediary (or processor or service provider) and applies to Fifth Dimension and the Customer because:
(a)the Customer has engaged Fifth Dimension to provide the Software and Services to it by accepting the terms of the Agreement; and
(b)the Services provided by Fifth Dimension pursuant to that Agreement require Fifth Dimension to act as a data intermediary under the PDPA (where the Agreement is governed by the laws of Singapore), and may also require it to act as a data processor under the UK GDPR (where the Agreement is governed by English law) and/or a service provider or contractor under the CCPA/CPRA (where the Agreement is governed by New York law), in each case in relation to any Personal Data that the Customer provides to Fifth Dimension in order for it to provide Customer with the Services.
2.2.Roles: Where the Agreement is governed by the laws of Singapore, the Customer is the organisation under the PDPA and Fifth Dimension is the data intermediary processing Personal Data on behalf of the Customer. Where the Agreement is governed by English law, the Customer is the data controller under the UK GDPR and Fifth Dimension is the data processor. Where the Agreement is governed by New York law, the Customer is the business and Fifth Dimension is the service provider under the CCPA/CPRA. In each case, the Customer remains responsible for Personal Data and Fifth Dimension processes it only in accordance with the Customer’s instructions. The only exception to this is with respect to any of Customer's employee data that Fifth Dimension processes solely to administer the Agreement such as the name and contact details of Customer's billing contact person. In that limited situation, Fifth Dimension acts as an independent organisation, controller or business (as applicable) of such data and processes it in accordance with its Privacy Notice. The Parties acknowledge and agree that, by executing this DPA, the Customer enters into the DPA on behalf of itself and, as applicable, each of its Group Companies that uses the Services under the Agreement. Each such Group Company shall be bound by Customer’s obligations under this DPA to the extent Fifth Dimension processes Personal Data on its behalf and such Group Companies shall be deemed an organisation, controller or business (as applicable) for that Personal Data. All access to and use of the Services by any Group Company must comply with the Agreement and this DPA, and any breach by a Group Company shall be deemed a breach by Customer and the Customer is solely responsible for the compliance of this DPA by any Group Company.
3.DETAILS OF THE PROCESSING
3.1.Nature and Purpose of Processing. Fifth Dimension processes Personal Data solely for the following purposes:
(a)providing, operating, maintaining, securing, and supporting the Services to Customer;
(b)performing the Agreement;
(c)acting upon Customer’s instructions, where such instructions are consistent with the terms of the Agreement;
(d)sharing Personal Data with sub-processors in accordance with Customer’s instructions, the terms of this DPA and/or pursuant to Customer’s use of the Services (e.g., integrations between the Services and any Third Party Applications, as configured or requested by the Customer to facilitate the sharing of Personal Data between the Services and such Third Party Applications);
(e)rendering Personal Data to be de-identified/anonymized information;
(f)as required under the laws applicable to processor, and/or as required by a court of competent jurisdiction or other competent governmental or semi-governmental authority, provided that processor shall inform Customer of the legal requirement before Processing, unless such law or order prohibits disclosing such information;
(g)all tasks related to any of the above.
3.2.Duration of Processing:
(a)Processor will process the Personal Data for the duration of the Agreement. Customer retains the ability to rectify, erase or restrict Fifth Dimension's processing of personal data via the functionalities of the Services or by written instruction to Fifth Dimension.
(b)The exception to this is if the law requires Fifth Dimension to retain a copy of any such Personal Data (and this DPA will continue to apply to that retained data).
(c)Following termination of the Agreement, Fifth Dimension will irretrievably destroy any Personal Data held on the Customer's behalf within 30 days of termination of the Agreement for any reason. If Customer wants to retain a copy of Customer's Personal Data it is the Customer’s responsibility to export it from the Software prior to the end of this time period.
3.3.Type of Personal Data: Other than the following categories of Personal Data below which Fifth Dimension processes in order to provide the Services to the Customer, the categories of Personal Data being processed by Fifth Dimension on the Customer’s behalf to provide its Services under the Agreement is solely determined by the Customer:
3.4.Sensitive Data: The parties agree that the Services are not intended for processing Sensitive Data. Customer shall not upload or otherwise provide Sensitive Data to the Services without Fifth Dimension’s prior written consent and the Parties’ execution of any additional terms reasonably required by Fifth Dimension.
3.5.Categories of Data Subjects: The Categories of data subjects relating to the Personal Data that will be processed by processor are dependent on the Customer, and may include, but are not limited to, any of the following categories:
3.6.Frequency of Processing: Personal Data is processed by Fifth Dimension on a continuous and ongoing basis for as long as Customer or its users maintain active use of the Services and as otherwise required to fulfil the purposes described above.
4.CUSTOMER RESPONSIBILITIES
4.1.Lawful basis: Customer retains control of the Personal Data and remains responsible for its obligations under the applicable Data Protection Laws, whether as an organisation under the PDPA, a data controller under the UK GDPR, or a business under the CCPA/CPRA (as applicable). Customer is responsible for (a) ensuring that the collection, use and disclosure of Personal Data to Fifth Dimension and the instructions it issues for processing are lawful and consistent with the Agreement and this DPA; (b) where the PDPA applies, ensuring that a valid legal basis exists for the collection, use and disclosure of Personal Data (including consent under Section 13 of the PDPA, deemed consent under Section 15 or 15A, or the legitimate interests exception under the First Schedule to the PDPA, as applicable), and where required, conducting a risk assessment in respect of the legitimate interests exception; (c) where the UK GDPR applies, determining and documenting the appropriate legal basis (e.g., consent, contract necessity, legitimate interests, or other applicable ground) for the processing of Personal Data; (d) ensuring that all required notifications of purpose have been provided to individuals in accordance with the PDPA (including Sections 20 and 20A) and, where applicable, data subjects or consumers under the UK GDPR or CCPA/CPRA; and (e) where consent is relied upon under the PDPA, ensuring that consent has been validly obtained and that individuals have been informed of the purposes for which their Personal Data will be collected, used and disclosed. Customer also represents and warrants that it has obtained all necessary rights and authority to provide the Personal Data to Fifth Dimension and to authorize Fifth Dimension to process that Personal Data for the limited and specific purposes described in this DPA. Where the Agreement is governed by the laws of Singapore, Customer acknowledges that Personal Data will by default be hosted in the UK in accordance with Section 6.1, and Customer is responsible for ensuring that individuals have been informed, as part of its notification of purpose under the PDPA, that their Personal Data will be transferred to and processed in the UK.
5.FIFTH DIMENSION’S OBLIGATIONS
5.1.Compliance with Law: Fifth Dimension will at all times comply with Fifth Dimension's obligations under the Data Protection Laws when processing any Customer Personal Data on Customer's behalf. Processor shall inform Customer without undue delay if, in processor’s reasonable opinion, an instruction for the Processing of Personal Data given by Customer infringes applicable Data Protection Laws, unless processor is prohibited from notifying Customer under applicable Data Protection Laws. It is hereby clarified that processor has no obligation to assess whether instructions by Customer infringe any Data Protection Laws. The parties will act in good faith to agree an amendment to this DPA (such agreement not to be unreasonably withheld or delayed) should an amendment be required by any law or to reflect any change to this relationship.
5.2.CCPA Standard of Care; No Sale or Sharing of Personal Information (applicable where the Agreement is governed by New York law): Processor certifies that it understands the rules, requirements and definitions of the CCPA/CPRA and agrees to refrain from selling or sharing (as such terms are defined in the CCPA/CPRA) any Personal Information processed hereunder, without Customer’s prior written consent or instruction, nor take any action that would cause any transfer of Personal Information to or from processor under the Agreement or this DPA to qualify as “selling” and/or “sharing” such Personal Information under the CCPA. Processor acknowledges that Customer discloses Personal Information to processor only for the limited and specified purposes set out in this DPA and the Agreement. Processor shall process all Personal Information only (a) for such limited and specific purpose(s), and (b) in compliance with applicable sections of the CCPA. Processor shall not (i) retain, use, or disclose Personal Information outside the direct business relationship of the Parties, as described in the Agreement, or for any business or commercial purpose other than for the specific business purpose of performing the Services or as otherwise permitted by the CCPA, the Agreement and/or this DPA; nor (ii) combine, by way of logical separation, personal information that processor processes on behalf of other parties with Personal Information of Customer, unless expressly permitted under the CCPA, its implementing regulations, the Agreement and/or this DPA between the Parties. Processor further acknowledges that Customer has the right, upon notice, to take reasonable and appropriate steps designed to stop and remediate any unauthorized use of Personal Information by processor. Processor shall notify Customer if processor makes a determination that it can no longer meet its obligations under the CCPA.
5.3.Acting on Customer instructions: Fifth Dimension will only process Customer Personal Data in accordance with the Customer’s documented instructions set out in this DPA and the Agreement. Where Fifth Dimension acts as a data intermediary under the PDPA, it shall: (i) comply with the protection obligation under Section 24 of the PDPA and the retention limitation obligation under Section 25 of the PDPA in respect of Customer Personal Data as if it were an organisation to which those obligations apply; (ii) process Customer Personal Data only for the purposes for which the Customer disclosed or is deemed to have disclosed the Personal Data; (iii) not retain Customer Personal Data for longer than is necessary for such purposes, and shall return or destroy such data in accordance with this DPA; and (iv) implement reasonable security arrangements to protect Customer Personal Data from unauthorised access, collection, use, disclosure, copying, modification, disposal or similar risks in accordance with Section 24 of the PDPA. Fifth Dimension will not process the Customer’s Personal Data for any other purposes or transfer it to any third parties, unless permitted by the Agreement or DPA. If Fifth Dimension is required to process Customer Personal Data for another reason (such as to comply with a law), unless it is prohibited from doing so, Fifth Dimension will advise Customer of that legal requirement in advance of any processing.
5.4.Commitment to confidentiality: Fifth Dimension will maintain confidentiality of Customer's Personal Data in accordance with the confidentiality provisions of the Agreement. Specifically, Fifth Dimension will ensure that any persons authorised to process Customer's Personal Data have agreed in writing to confidentiality terms which are no worse than what Fifth Dimension requires for its own personal data or are under a similar statutory obligation to keep Customer's Personal Data confidential.
5.5.Responding to Individual Rights Requests:
(a)Taking into account the nature of processing, Fifth Dimension will assist the Customer, at Customer’s cost, to respond to requests from individuals (including data subjects, consumers or other individuals as applicable under the relevant Data Protection Laws) when exercising their rights, including access and correction requests under Sections 21 and 22 of the PDPA, subject access rights and rights to rectification or erasure under the UK GDPR, and equivalent rights under other applicable Data Protection Laws.
(b)If Fifth Dimension receives direct requests from data subjects, it shall promptly forward the request to the Customer and will not respond directly unless legally required to do so save that it may acknowledge receipt and advise the data subject of the fact that their request has been forwarded to the Customer.
5.6.Assisting Impact Assessments and Regulatory Requests: Fifth Dimension will provide reasonable assistance to the Customer with respect to any data protection impact assessment and communications with data privacy authorities (such as the Information Commissioner’s Office or the Singapore Personal Data Protection Commission) as is required under any Data Protection Laws, in each case solely in relation to Fifth Dimension’s processing of Customer's Personal Data, taking into account the nature and scope of such Personal Data.
5.7.Information and Audit Requests: If Customer requests assistance in ensuring its compliance with its obligations under the Data Protection Laws, Fifth Dimension will make available all information reasonably necessary to demonstrate its compliance with this DPA to the Customer, including allowing for and contributing to audits by Customer's mandated auditor, provided that (i) such audit is at Customer's expense and no more than once in any twelve-month period (except where required by a relevant regulatory authority or in respect of a Personal Data breach); (ii) reasonable advance written notice is given to Fifth Dimension; (iii) such audit shall not materially interfere with Fifth Dimension's day to day business operations; and, (iv) Customer shall comply with Fifth Dimension's reasonable confidentiality, security, and health and safety requirements. Customer also agrees that the first step in relation to any required audit under this clause or information request by the relevant regulatory authority, shall be for Fifth Dimension to provide Customer with a report verifying its compliance with its obligations under this DPA. Customer agrees that it shall only request a further audit if it shows reasonable grounds for believing the report to be insufficient. If any audit or other inspection by or on behalf of the Customer demonstrates any material non-compliance by Fifth Dimension of its obligations pursuant to these Terms, Fifth Dimension shall, without prejudice to any other rights and remedies the Customer may have: (a) remedy the cause of such non-compliance as soon as reasonably practicable; and, (b) promptly refund the Customer its reasonable costs and expenses relating to such audit or inspection.
5.8.Notification of Breaches: In the event of any personal data breach related to the Personal Data, Fifth Dimension will notify Customer without undue delay or as required by the applicable Data Protection Laws. Where the PDPA applies, Fifth Dimension will notify Customer as soon as practicable after it has credible grounds to believe that a notifiable data breach (as defined under Section 26A of the PDPA) has occurred, and in any event no later than three (3) calendar days after Fifth Dimension has made an assessment that the breach is a notifiable data breach, so as to enable Customer to comply with its notification obligations to the PDPC and affected individuals under Sections 26C and 26D of the PDPA. The notice will include, where available, information about the nature of the breach and categories of data affected, the approximate number of data subjects and records affected, likely consequences, measures taken or proposed, and contact details for further information. Fifth Dimension will assist Customer in the notification of such breach to the relevant data privacy authority and data subject as required by law.
5.9.Staff Controls: Fifth Dimension will ensure (via contractual obligations, internal policies and training) that Fifth Dimension's staff are both authorised and have the necessary skills to process Customer's Personal Data in accordance with Fifth Dimension's obligations under this DPA. Fifth Dimension will also limit Fifth Dimension's personnel's access to Customer's Personal Data to a need-to-know basis.
5.10.Security Controls:
(a)Fifth Dimension maintains administrative, technical, and physical safeguards designed to protect Personal Data against unauthorized access, use, disclosure, alteration, or destruction. These safeguards include, at a minimum, the technical and organizational measures set out in its Data Security Policy. Customer confirms Customer has reviewed these measures and agrees that they are appropriate and proportionate, taking into account current industry practice for data security, implementation costs, the nature of Customer's Personal Data processed, scope, and context of Fifth Dimension's processing.
(b)Fifth Dimension reviews and updates Fifth Dimension's data security controls and may accordingly update the Data Security Policy from time to time without notice to Customer, so long as any such changes do not cause there to be a reduction to these security levels.
5.11.Sub-processing: Customer agrees that Fifth Dimension may engage Sub-processors set out in Fifth Dimension's Sub-processor List to process Customer's Personal Data. In all cases:
(a)each Sub-processor will be bound by written terms no less protective than those imposed on Fifth Dimension under this DPA;
(b)Fifth Dimension will remain liable to Customer for any acts or omissions of any Sub-processors Fifth Dimension appoints to process Customer's Personal Data;
(c)Fifth Dimension may change or replace Fifth Dimension's Sub-processors from time to time provided that it notifies the Customer in writing at least 30 days before a new sub-processor is appointed. Fifth Dimension will not disclose any Customer Personal Data to the proposed Sub-processor prior to the end of this notification period and may only do so at the end of that period if it has not received a written objection from the Customer by that time.
(d)Customer may reasonably object in writing to the proposed new Sub-processor during this notification period. If Fifth Dimension receives such an objection, Fifth Dimension agrees it will not disclose any Customer Personal Data to the proposed Sub-processor. If the parties cannot reach agreement on an alternative solution within 30 days, and Fifth Dimension cannot continue to provide the Services without engaging the proposed Sub-processor, either party may terminate the affected Order Form.
(e)The sub-processing will end in accordance with section 3.2 above, or earlier if the services of the relevant Sub-processor are no longer required by Fifth Dimension in order to provide Customer with the Services.
6.INTERNATIONAL TRANSFERS
6.1.Other than any relevant Sub-processors listed on Fifth Dimension’s Sub-processor List (as updated in accordance with this DPA), Fifth Dimension will not transfer, access or process Customer’s Personal Data outside of the UK or EEA without Customer’s prior written consent, except where such transfer is to a Sub-processor listed on the Sub-processor List. By default, all Customer Personal Data will be hosted and processed in the UK or EEA regardless of which Fifth Dimension contracting entity is party to the Agreement. Customer may request that its Personal Data be hosted in Singapore or another jurisdiction by specifying this in the “Special Conditions” section of the applicable Order Form, subject to availability and any additional terms or Fees notified by Fifth Dimension. Where the Agreement is governed by the laws of Singapore, Customer acknowledges and agrees that the hosting of Personal Data in the UK constitutes a transfer of Personal Data outside of Singapore for the purposes of Section 26 of the PDPA. Fifth Dimension warrants that it will comply with the transfer limitation obligation under Section 26 of the PDPA in respect of such transfer by ensuring that: (i) the Personal Data transferred to the UK is subject to legally enforceable obligations providing a standard of protection that is at least comparable to the protection under the PDPA, as required by Section 26(1)(b) read with the Second Schedule of the PDPA, including by virtue of the obligations imposed on Fifth Dimension under this DPA and the data protection standards maintained by Fifth Dimension under the UK GDPR; and (ii) any onward transfer of Personal Data from the UK to a country outside the UK or EEA satisfies the requirements of the UK GDPR (including the use of UK Standard Contractual Clauses where required) and, where the PDPA applies, continues to provide a standard of protection that is at least comparable to the protection under the PDPA. Where applicable, Fifth Dimension will also ensure compliance with any other cross-border data transfer requirements under applicable Data Protection Laws in the Asia-Pacific region, including the APEC Cross-Border Privacy Rules (CBPR) system where relevant. Where Customer consents to or instructs such transfer of Personal Data to a country that the UK Secretary of State or the European Commission has not determined has an adequate level of protection, and no other framework has been approved as adequate for the transfer (such as the UK-US Data Bridge Framework) for which the Sub-processor is registered, Fifth Dimension confirms it has entered into UK Standard Contractual Clauses with such Sub-processors. Where relevant, Fifth Dimension is the "Data Exporter" and each relevant Sub-processor is the "Data Importer" of such Personal Data.
6.2.For any restricted transfers of Personal Data between Fifth Dimension and the Customer, parties confirm that such transfers will be made pursuant to an International Data Transfer Agreement as follows:
(a)for the purposes of the IDTA, Fifth Dimension is the “Data Importer” and Customer is the “Data Exporter” of the Personal Data. The required details for these tables are set out in Customer's signed Order Form and Section 2 and Section 3 of this DPA;
(b)for the purposes of Table 2 of the IDTA:
(i) the governing law shall be English law, and disputes shall be resolved in the Courts of London, England;
(ii) in relation to the processing of the Personal Data, the Data Exporter is the Customer and Fifth Dimension and Fifth Dimension's Sub-processors are the Data Importer (and any onward transfers to Fifth Dimension's Sub-processors will be made strictly in accordance with the requirements of this DPA);
(iii) the ‘Linked Agreement’ is this DPA and shall remain in place for the duration of the Agreement; and,
(iv) the details of the ‘Transferred Data’ are set out in Section 3 of this DPA and with respect to any specific onward processing by Fifth Dimension's relevant Sub-processors in Sub-processors List; and,
(c)for the purposes of Table 4, the details of the ‘Security Requirements’ are set out in clause 5.10 of this DPA and Fifth Dimension's Data Security Policy;
(d)the Part 4 ‘Mandatory Clauses’ of IDTA apply;
(e)for the avoidance of doubt where this DPA specifies any further audit and Sub-processor requirements, such requirements also apply in relation to the IDTA;
(f)the parties acknowledge that a transfer risk assessment has been conducted; and
(g)by signing the Order Form both parties confirm their agreement to this IDTA.
7.GOVERNANCE
7.1.Order of precedence: In the event of any inconsistency among the following documents, the order of precedence shall be (1) the Order Form, (2) this DPA, (3) the Master Services Agreement, and (4) the Policies referenced herein and therein. For the avoidance of doubt, where any of the UK Standard Contractual Clauses are incorporated under Section 6 (International Transfers), those instruments shall prevail solely with respect to the cross-border transfer of Personal Data to the extent of any direct conflict with this DPA.
7.2.Variations required by applicable law: Each Party may with at least forty-five (45) calendar days prior written notice to the other Party, request in writing any variations to this DPA if they are required as a result of any change in applicable Data Protection Laws to allow Processing of Customer Personal Data to be made (or continue to be made) without breach of such Data Protection Laws. Pursuant to such notice the Parties shall use commercially reasonable efforts to accommodate such required modification and negotiate in good faith with a view to agreeing and implementing those or alternative variations designed to address the requirements under applicable Data Protection Law as identified in Customer’s or processor’s notice as soon as is reasonably practicable.
Last updated: 12 August 2026