Data Processing Agreement
The promise we make to every business about its visitors' and team's data. You accept it when you create an account, and we will sign a copy on request.
Version 2026-10-02 · Last updated 2 October 2026
This agreement is published in English. If it is translated into any other language, the English version governs.
1. Who and what this covers
- "turnda", "we": SKANDAN PTE. LTD. (UEN 202621966R), 60 Paya Lebar Road, #06-28 Paya Lebar Square, Singapore 409051.
- "You", "the business": the business that holds a turnda account.
- This agreement covers the personal data of your visitors and of your own team that we handle for you when we provide turnda ("Business Personal Data"). It forms part of the Terms of Service. You accept it when you create your account, and we record the version and date you accepted. If you need a copy signed by both of us, write to legal@turnda.com and we will sign this same text.
- It does not cover data turnda is itself in charge of (owner sign-in, billing, security, our website); our Privacy Policy covers that.
- If this agreement and the Terms disagree about personal data, this agreement wins. If the standard contractual clauses in Annex 4 apply and disagree with this agreement, the clauses win.
2. Roles
- You are in charge of Business Personal Data (the controller, or in Singapore the organisation responsible). You decide what is collected, why, and how long it is kept.
- We act only on your instructions (the processor, or in Singapore a data intermediary). Your instructions are: this agreement, the Terms, and the settings you choose in turnda. If we think an instruction breaks the law, we will tell you, and we may decline to follow it.
- You are responsible for having a legal basis for what you collect, giving your visitors the notice your law requires (turnda lets you add your own short notice to each branch's visitor pages), and the content you and your team type into turnda, including notes and flags.
3. What we process (details in Annex 1)
- Purpose: to run your queues, bookings, lobby screens, messages, reports and the rest of the service, and to fix problems you report.
- Whose data: your visitors, and your own owners, managers and staff.
- What data: the visitor fields you switch on (name, one contact — a WhatsApp number or an email, never both — party size, service, vehicle, a note), queue and booking records, notes and flags your staff add, ratings and comments, WhatsApp messages, and your team's names, usernames, sign-in emails and roles.
- Sensitive data. turnda does not ask for health, religious, financial or identity-document data. A note or flag can hold such data only if your team types it in. You must have a legal basis to do so. We treat notes and flags as sensitive: staff-only, never on a public screen, left out of exports, and deleted outright when your visitor-data window ends.
- How long: for as long as you have an account, and then as set out in section 11.
4. Confidentiality
Only the people who run turnda (today its founder) can access Business Personal Data, and only to provide, support or secure the service, or when the law requires it. They are bound to keep it confidential.
5. Security
We keep the measures in Annex 2 in place, and we may improve them. We will not reduce the overall protection they give during your subscription.
6. Retention you control
You set how long visitor details are kept: any value from 24 hours to 1 year, 48 hours by default, counted from the end of each visit (for a booking, from the booked time). The database refuses a value outside that range. When the window ends, the visitor's name and contact are erased, and notes, flags, comments and WhatsApp reply-window records are deleted; anonymous counts remain for your reports. The other fixed periods are listed in Annex 1.
7. Sub-processors
- You give us general permission to use the sub-processors listed at turnda.com/sub-processors (Annex 3 summarises them).
- Before we add or replace one, we update that page and email you at least 14 days ahead. If you object on reasonable data-protection grounds, tell us within those 14 days; if we cannot meet your objection, you may close your account before the change, and we will refund the unused part of the month already paid for.
- Every sub-processor is bound by written terms that protect the data at least as well as this agreement. We remain responsible to you for what they do.
8. Helping you with people's requests
- turnda gives you the tools to answer requests yourself: an owner can find everything held about one visitor (including their WhatsApp messages) and erase it in one step, and can export the setup and reports. Every request handled this way is logged for your records, identifying the person only by a one-way fingerprint.
- If a request about your data reaches us directly, we pass it to you within 5 working days and do not answer it ourselves unless you ask us to or the law requires it.
- If you need our help beyond the tools, we give it at no charge for reasonable requests.
Limits we tell you about now:
- Opt-out records survive erasure. If a visitor replied STOP or unsubscribed, a one-way fingerprint of their number or address is kept so we keep honouring it.
- Backups are not reached by an erasure straight away. See section 11.
- A support-report screenshot cannot be searched for one person. Screenshots you attach to a support report are deleted after 30 days; an erasure does not reach them sooner.
9. If personal data is breached
- We will tell you without undue delay, and within 48 hours of becoming aware, of any breach of security that leads to Business Personal Data being lost, destroyed, changed, disclosed or accessed without permission.
- We will tell you what happened, what data and how many people may be affected, the likely consequences, what we have done and will do, and who to contact. If we do not know everything at first, we tell you what we know and follow up.
- We will take reasonable steps to contain it and help you meet your own duties (for example to notify a regulator or the people affected). You decide whether to notify them; we will not notify your visitors or a regulator about your data in your name unless you ask us to or the law requires us to.
10. Assessments, records and audits
- We will give you the information you reasonably need for a data-protection impact assessment or a regulator's enquiry about our processing.
- Audits. Because turnda is run by a very small team, we meet audit requests in writing: we answer your reasonable written questions about our processing and security within 30 days, once a year (or more often after a breach or if a regulator asks). If the law gives you a right to inspect that written answers cannot satisfy, we will agree a remote review with you, at your cost, with 30 days' notice.
- We keep records of our processing as the law requires.
11. When your account ends
- Before you leave, you can export your setup and download your reports at any time. Individual visit records are not kept long enough to export, by design.
- If you close the account, it can be reversed for 7 days; then Business Personal Data is deleted, and so are the sign-in records of your owners, managers and staff at our sign-in provider (a person who also belongs to another business on turnda keeps theirs until that business is deleted too).
- If the account lapses (the trial ends without a card, or the subscription ends), it is kept for 90 days so you can return, then deleted. An account that never added a card is deleted 90 days after it was created.
- You can ask us to delete sooner.
- Backups: we back up nightly and keep 14 daily and 8 weekly copies, so deleted data can remain in a backup for about 8 weeks. Backups are private and used only to recover from a disaster. If we restore one, we re-apply every erasure and deletion made since that backup before the service is used again. Because backups are nightly, up to 24 hours of data could be lost in a disaster.
- What we keep after deletion: the items listed in section 8.3 of our Privacy Policy — none of them contains your visitors' names or contact details, except one-way fingerprints in opt-out records.
12. International transfers
- Business Personal Data is stored in Frankfurt, in the European Union. Some sub-processors handle it in other countries (Annex 3). turnda itself is a Singapore company.
- Wherever data leaves the country it came from, we make sure it is protected to a standard comparable to the law it came from: through our sub-processors' written terms (including approved standard clauses where required), and through Annex 4 for transfers from you to us.
13. Liability
Each party's liability under this agreement is subject to the limits in the Terms of Service, including the separate, higher limit for our breach of this agreement (Terms section 13.4).
14. Term, law and changes
- This agreement lasts as long as we process Business Personal Data for you.
- It is governed by Singapore law, except where Annex 4 says the standard contractual clauses are governed by another law.
- We may change it with at least 30 days' notice by email and in the app, unless the law requires a change sooner. A change will not reduce the protection of Business Personal Data.
Annex 1 — Details of the processing
| Subject matter | Providing turnda: queues, bookings, lobby screens, visitor messages, reports, support |
|---|---|
| Nature | Collecting, storing, organising, displaying, sending, erasing |
| People | Your visitors; your owners, managers and staff |
| Visitor data | As switched on by you: name (or WhatsApp profile name when joining by WhatsApp); one contact (WhatsApp number or email); party size; service; vehicle; visitor's note; queue and booking times and outcome; staff notes and flags; rating and comment; WhatsApp messages in both directions; a one-time code fingerprint for a few minutes if you require email confirmation; network address in an abuse counter for at most 15 minutes |
| Team data | Name, sign-in email, optional recovery email, username, PIN fingerprint, role, locations, device names, sign-in sessions, team chat messages, notifications |
| Sensitive data | Only if your team types it into a note or flag |
| Visitor details kept | You choose 24 hours to 1 year after the visit; 48 hours by default |
| WhatsApp message contents | 30 days |
| Team chat | 7 days |
| Notifications | Support replies at least 30 days, payments at least 90 days, others on your visitor window |
| Support screenshots and technical details | 30 days; the report itself 1 year after its last message |
| Security log of changes | 1 year |
| Review-request marker | A one-way fingerprint, up to 365 days |
| Opt-out records | Kept (one-way fingerprint only) |
| Backups | About 8 weeks |
Annex 2 — Security measures
- Separation of businesses by the database itself (row-level security forced on every business table, with a database role that cannot bypass it), and an automated check that refuses any new business table without it.
- Encryption in transit everywhere (HTTPS with strict transport security). Stored data is encrypted by our database provider.
- No passwords. Sign-in by email link or Google; staff PINs and recovery codes stored only as one-way fingerprints; sign-in sessions expire.
- Least data. Every visitor field is off unless you switch it on; one contact per visit; notes and flags staff-only and never sent to a public screen; a numbers-only lobby screen is never sent names.
- Automatic deletion on the clocks in Annex 1, run every few minutes.
- Security log of every change made in an account, recording the event, not the personal data.
- Scrubbed logs and error reports: contact details and keys removed before anything is written; the error monitor's personal-data collection is switched off.
- Abuse protection: limits on sign-in attempts, code guessing and request floods.
- Backups nightly to private storage that the software checks is private before writing.
- Card data never touches turnda; it goes straight to Stripe.
- Access to production limited to the people who run turnda, with keys held outside the code.
- What we do not have: SOC 2 or ISO 27001 certification, or an outside security test.
Annex 3 — Sub-processors (summary)
The current list, with what each handles and where, is at turnda.com/sub-processors. On 2 October 2026 it is: Supabase (database, sign-in, files, backups — Frankfurt); Fly.io (runs the application — Frankfurt, with connections accepted at the nearest location); Upstash (job queue and abuse counters — Frankfurt, Germany); Stripe (payments); Meta (WhatsApp); Resend (email — sending from Ireland); Cloudflare (domain names and incoming mail); Sentry (error reports — Germany); Google (sign-in with Google, and our support mailbox).
Annex 4 — Transfers from you to us
turnda is in Singapore and stores data in the European Union. Where the law that applies to you requires an approved mechanism for sending personal data to turnda, the following are incorporated into this agreement by reference and apply automatically, with you as the exporter and turnda as the importer:
| Your data comes from | Mechanism | Choices |
|---|---|---|
| European Economic Area or Switzerland | The EU standard contractual clauses (Commission Implementing Decision (EU) 2021/914) | Module 2 (controller to processor); where you are yourself a processor, Module 3. Clause 7 (docking) applies. Clause 9: option 2, general authorisation, with the notice in section 7 above. Clause 11: the optional wording does not apply. Clause 13: the supervisory authority of the EU country where you are established. Clauses 17 and 18: the law and courts of Ireland. Annexes I–III are filled by Annexes 1–3 of this agreement. For Switzerland, references to the GDPR are read as the Swiss Federal Act on Data Protection, and the Swiss regulator is competent. |
| United Kingdom | The UK International Data Transfer Addendum to the EU clauses, issued by the Information Commissioner | The tables are filled from this agreement; either party may end the addendum as its section 19 allows. |
| Brazil | The standard contractual clauses of Brazil's data protection authority (Resolution CD/ANPD No. 19/2024) | Incorporated in full, unchanged, as that resolution requires. |
| Saudi Arabia | The standard contractual clauses issued by the Saudi Data and AI Authority under the Personal Data Protection Law | Controller-to-processor clauses, incorporated by reference. |
| Anywhere else | This agreement, as a binding contract giving protection comparable to your law | — |
If a mechanism above is replaced by an updated version, the updated version applies from the date it becomes mandatory.
Also see our Terms of Service, Privacy Policy and sub-processor list.