Data Processing Addendum
OneSeller — operated by Raven AGI (UEN 53530733X) Effective 21 September 2026 · Version 1.1
1. Why this document exists
You use OneSeller to store personal data about your own customers — their names, phone numbers and delivery addresses. That data is yours, not ours, and we hold it on your behalf. That creates obligations we owe you, which this document sets out.
It also sets out one thing we ask of you in return: because we use data stored in OneSeller to develop artificial intelligence models (section 4A), you must have the consents that makes lawful.
This Addendum sets out those obligations. It forms part of the Terms of Service and applies automatically from the moment you create your first buyer record.
2. Who is what, under the PDPA
| Role | Meaning | |
|---|---|---|
| You | Organisation | You decide what customer data to collect and what to do with it. You are responsible for having a lawful basis, for notifying your customers, and for answering their requests. |
| Us | Data intermediary | We store and process that data solely on your instruction, to provide the service. We make no independent decisions about it. |
Under section 4(2) of the Personal Data Protection Act 2012, a data intermediary processing personal data on behalf of another organisation is bound by the Protection Obligation (section 24) and the Retention Limitation Obligation (section 25). We accept those obligations, and the commitments below go somewhat further.
3. What we process, and why
| Subject matter | Provision of the OneSeller service |
| Duration | While your account is open, plus the deletion periods in section 8 |
| Nature and purpose | Storage, retrieval, display, backup and export of buyer records, in order to produce invoices, delivery exports and reporting for you |
| Categories of data | Recipient name, phone number, postal code, street name, building, unit number, delivery instructions, purchase history, and payment proof files you upload |
| Categories of subject | Your customers |
| Special categories | None. OneSeller has no field for and no use for sensitive personal data. Do not put any into free-text fields. |
4. Our undertakings
We will:
- Process only on your instruction, and for model development as described in section 4A. Your use of the service is your instruction. We will not use your customers' data for our marketing, and will not sell or share it.
- Deliberately exclude identifying data from our own use. Where we analyse usage or develop models, we do so on aggregated or de-identified data from which identifying details have been purposely removed, so the result cannot be traced to you or to any individual customer of yours.
- Keep it secure — the measures in section 5.
- Restrict access to personnel who need it, each bound by confidentiality, and only through the controlled process in section 6.
- Use only the sub-processors listed in section 7, each bound by equivalent obligations, and give you notice before adding a new one.
- Help you meet your own obligations — access and correction requests, and breach handling — as set out in section 9.
- Tell you promptly if we become aware of a breach affecting your data (section 10).
- Return or delete it when your account ends (section 8).
4A. Model development, and what it requires of you
Raven AGI builds artificial intelligence systems, and data stored in OneSeller may be used to develop, train, test and improve machine learning models.
Our safeguards. Direct identifiers — names, phone numbers, addresses, email addresses and file attachments — are removed before data is used for this purpose, wherever that is practicable. Where they cannot be removed without destroying the usefulness of the data, that data is not used. We do not publish your data, sell it, expose it to other users, or build models designed to reproduce your business information.
Your warranty. You confirm that you have obtained any consent required under the PDPA for your customers' personal data to be processed in this way, or that another lawful basis applies. You are the organisation with the relationship to those individuals; we have none, and cannot obtain their consent on your behalf.
A practical note. Consent under the PDPA must be for a purpose the individual was told about. If you collected a customer's address in order to deliver a parcel, that consent does not automatically extend to model development. If you cannot cover this in your own customer notice, or you would rather not, opt your account out by writing to boss@r4v3nteam.com. Nothing in the service changes if you do.
Opt-out. One email, effective for your whole account, at any time, with no loss of functionality.
5. Security measures
- Encryption in transit (TLS 1.2+) and at rest.
- Tenant isolation enforced at the database level through row-level security, so a defect in application code cannot expose one account's data to another. This is backed by an automated test suite whose sole purpose is to attempt cross-account access and fail our build if it succeeds.
- Files in private storage, reachable only through short-lived signed links.
- No passwords in our systems; authentication is delegated to Google or Apple.
- Audit logging of data-affecting actions.
- Encrypted daily backups, held in a separate location from production, with restore tested.
- Least-privilege access to production, reviewed periodically.
- Dependency vulnerability scanning in our build pipeline.
We may update these measures, but will not materially reduce the level of protection.
6. Access by our staff
We do not browse your data. Support access to an account requires:
- an explicit action with a stated reason — it is never a side effect of being an administrator;
- automatic expiry, one hour by default;
- an immutable audit record of who, when, which account and why;
- visibility to you in your own account activity, so you can see it happened.
7. Sub-processors
| Provider | Role | Location |
|---|---|---|
| Supabase | Database, storage, authentication | Singapore |
| Vercel | Application hosting | Data at rest in Singapore |
| Sentry | Error diagnostics | European Union |
| [Email provider] | Service email | [Region] |
Each is engaged under terms imposing data protection obligations equivalent to these. We remain responsible to you for their performance.
We will give notice before a new sub-processor begins processing your data. If you object on reasonable data protection grounds, you may close your account and export your data.
8. Retention and deletion
- We keep your customers' data for as long as your account is open.
- You can delete any buyer record yourself at any time. Because deleting a customer entirely would destroy financial records you may be required to keep, deletion is implemented as anonymisation: name, phone number and address are irreversibly scrubbed, while the invoice and its totals survive for your accounting.
- When your account closes, all data — records and uploaded files alike — is permanently deleted after a 365-day grace period, or immediately if you ask us to delete it sooner.
- Backups age out on a rolling 30-day cycle.
- You can export everything at any time, in a standard format, without asking us.
9. Assisting you
- Access and correction requests. Your customers should come to you — you hold the relationship. The app lets you retrieve and correct any record yourself. If a request reaches us directly, we will not respond to it substantively; we will forward it to you.
- Complaints and regulator enquiries. We will give you reasonable assistance and the information you need to respond.
10. Data breaches
If we become aware of a breach of security affecting your data, we will:
- notify you without undue delay, and in any event within 72 hours of becoming aware;
- tell you what we know — what happened, what data and roughly how many individuals are affected, the likely consequences, and what we are doing about it;
- assist you in assessing whether the breach is notifiable to the PDPC and to affected individuals under the PDPA's mandatory breach notification regime, and in making those notifications;
- keep you updated as we learn more.
Assessment and notification to the PDPC in respect of your customers' data are your responsibility as the organisation. Ours is to give you everything you need to do it properly, and quickly enough that you can.
11. Cross-border transfers
Your customers' data is stored in Singapore. Where a sub-processor in section 7 processes personal data outside Singapore, we ensure it is subject to legally enforceable obligations providing a standard of protection comparable to the PDPA, as required by section 26 of the Act.
12. General
- This Addendum forms part of the Terms of Service; on data protection matters concerning your customers' data, this document prevails over any conflicting term.
- Governed by the laws of Singapore.
- We may update it, and will notify you of material changes. We will not reduce the protections below what is in force at the time you accept.
| Version | Date | Change |
|---|---|---|
| 1.1 | 21 September 2026 | The grace period after an account closes changed from 90 days to 365, and closing now offers immediate deletion instead of waiting. Nothing else changed. |
| 1.0 | 1 September 2026 | First published |
Raven AGI · UEN 53530733X · boss@r4v3nteam.com
