Mega Step
ServicesField ActionReportsProcessGuidesAboutAQL
EN
EN English DE Deutsch FR Français ES Español AR العربية
Book a call
Data Processing Agreement

Data processing, safeguards, storage and deletion.

This Data Processing Agreement (DPA) explains how Mega Step (HK) Ltd. processes, safeguards, stores and deletes personal data on behalf of a customer in connection with quality control, factory inspection and related reporting services.

Last updated: 11 July 2026

Mega Step provides these Data Processing terms in English only. Any translation, browser translation or informal explanation is for convenience only; the English version is the controlling version.

This DPA forms part of the service agreement where Mega Step processes personal data on the customer's documented instructions and the parties have not signed a separate DPA. The customer is the Controller and Mega Step is the Processor for that processing. A separately executed DPA prevails if it expressly conflicts with this page.

1. Inspection data covered by these terms

In connection with quality control, factory inspection, pre-shipment inspection, during-production inspection, container loading supervision, audit, sample verification and related services, Mega Step (HK) Ltd. collects, processes and stores inspection data. This may include inspection reports, photographs, videos, test results, checklists, AQL sampling details, measurements, defect notes, product documents and related service documentation.

2. Purpose of processing

Inspection data is processed only for performing the agreed service, documenting the results, delivering reports, supporting customer review, enabling supplier follow-up, maintaining service traceability and fulfilling Mega Step's contractual and legal obligations.

3. Roles, instructions and legal basis

The customer determines the purposes and legal basis of the processing and is responsible for the lawfulness, accuracy and transparency of personal data supplied to Mega Step. Mega Step processes that data only on documented instructions contained in the service order, agreed scope, this DPA and related written directions, unless applicable law requires otherwise. If Mega Step believes an instruction infringes applicable data protection law, it will inform the customer unless prohibited by law.

4. Storage location

Inspection data for online reports may be stored in Cloudflare R2 Object Storage and related Cloudflare services used for report delivery, security and lifecycle management. Access is limited to the service workflow and authorized operational users or systems.

Mega Step uses Cloudflare subject to the applicable Cloudflare terms and privacy documentation, including Cloudflare's Terms of Use, Privacy Policy, Service-Specific Terms and Workers AI data usage documentation, where relevant.

5. AI-assisted processing

Where agreed or operationally required, Mega Step may use approved AI services and internal agent workflows, which may include Ollama Cloud, Cloudflare Workers AI, Codex-assisted workflows and self-hosted Hermes or similar internal agent systems, for limited processing such as translation, summarization, formatting, structured extraction, draft report preparation or internal quality review. AI-assisted processing is a support tool and material output remains subject to human review.

Mega Step minimises personal data submitted to AI services and does not intentionally use customer data, inspection records, report content or supplier data to train AI models. Ollama's Privacy Policy and Cloudflare's Workers AI data usage documentation describe their current treatment of customer content. The customer may request that hosted AI services not be used for specified data, subject to Mega Step confirming service feasibility, timing and cost.

6. Podio workflow storage

Mega Step may store service workflow records in Podio / Progress systems, including bookings, customer and supplier contact details, service status, report workflow information, task notes, invoice references and follow-up records. Podio is used as a structured business workflow system and is operated subject to Progress / Podio's Privacy Policy, ShareFile and Podio End User Agreement, Podio service description and related data protection and security documentation.

7. Confidentiality and security

Mega Step ensures that personnel authorized to process customer personal data are subject to confidentiality obligations and receive appropriate instructions. Mega Step maintains technical and organisational measures proportionate to the risk, including role-based access, least-privilege permissions, account security, encryption in transit where supported, secure remote access, data minimisation, backup and recovery controls where applicable, incident handling and secure deletion procedures.

8. Sub-processors

The customer gives general authorization for Mega Step to use sub-processors necessary to deliver the service. Current categories include Cloudflare for website, security, serverless processing and storage; Podio / Progress for workflow records; Qarma for inspection reporting where ordered; Microsoft for business email and productivity services; and approved AI providers, which may include Ollama Cloud and Cloudflare Workers AI. Internal agent names or interfaces are not separate sub-processors unless an external provider receives personal data through them.

Mega Step will require sub-processors to protect personal data under written terms appropriate to their service and remains responsible for its processor obligations to the extent required by applicable law. Mega Step will provide at least thirty (30) days' notice of a material new sub-processor where reasonably practicable. A customer may object during that period on reasonable data-protection grounds; the parties will work in good faith on a practical alternative, which may affect service availability or cost.

9. Personal data breach

Mega Step will notify the customer without undue delay and, where reasonably practicable, within forty-eight (48) hours after becoming aware of a personal data breach affecting customer personal data. Mega Step will provide available information reasonably needed for the customer's assessment and legally required notifications and will take reasonable steps to contain, investigate and remediate the incident. This timeframe is a notification objective and does not create an admission of fault or liability.

10. Data subject requests, DPIAs and regulator enquiries

Taking account of the nature of the processing and information available, Mega Step will provide reasonable assistance with data subject requests, security assessments, data protection impact assessments, prior consultations and regulator enquiries relating to Mega Step's processing. If Mega Step receives a request directly, it will forward it to the customer and will not respond substantively unless instructed or legally required. Additional work beyond the ordinary service may be charged at agreed rates where permitted by law.

11. Automatic deletion after report handover

After handover of the final inspection report to the client, inspection data stored specifically for online report delivery is automatically and permanently deleted after a maximum period of one hundred eighty (180) days through configured lifecycle rules, unless a longer retention period applies under section 12.

12. Return, deletion and longer retention

At the end of the service, Mega Step will return or delete customer personal data on written request, subject to the online-report lifecycle above and unless applicable law requires retention. Mega Step may retain data longer where statutory or regulatory obligations apply, the customer has agreed to extended storage, retention is necessary for legal claims, or the record is a necessary business workflow, accounting, contract or compliance record. Retained data remains protected and is deleted when the reason for retention ends.

13. Early deletion requests

The client may request earlier deletion of inspection data, provided that the request does not conflict with legal, accounting, contractual, dispute-handling or compliance obligations of Mega Step.

14. Audit information

On reasonable written request, Mega Step will provide information necessary to demonstrate compliance with this DPA. Where that information is insufficient and applicable law requires an audit, the customer may arrange a proportionate audit by an independent, confidentiality-bound auditor no more than once per year, unless a breach or regulator requires otherwise. Audits must avoid disruption, protect other customers' information and be at the customer's cost unless the audit identifies a material breach by Mega Step.

15. International transfers

Personal data may be processed in Hong Kong, Mainland China and jurisdictions used by approved service providers. Where a transfer mechanism is legally required, the parties will use an appropriate mechanism, which may include the European Commission's 2021 SCCs in the applicable module, the Hong Kong PCPD Recommended Model Contractual Clauses, or another lawful safeguard. These mechanisms apply only when validly executed or incorporated; this website statement does not itself execute SCCs or RMCs.

16. Processing details

  • Subject matter: personal data processed to plan, perform, document, report and administer the ordered inspection, audit, sample, sourcing, laboratory or follow-up service.
  • Duration: the service term plus the retention periods in this DPA or required by law.
  • Nature and purpose: collection, access, organization, review, communication, storage, report creation, delivery, support, deletion and related quality-control administration.
  • Data subjects: customer representatives, supplier and factory contacts, factory personnel incidentally recorded in evidence, inspectors, logistics or laboratory contacts and other persons identified in service materials.
  • Data types: business contact details, signatures, communications, booking and access data, photographs or videos, inspection notes, report content, order references and related operational records. Special-category data is not intentionally requested.

17. Report links and access

Online report links are intended for the client and authorized recipients. Clients should avoid forwarding report links to unauthorized parties. Mega Step may disable access, rotate links or delete report materials where required for security, confidentiality, legal compliance or lifecycle deletion.

18. Liability and governing law

Liability under this DPA is subject to the limitations and exclusions in the applicable service agreement to the extent permitted by law. These data processing terms are governed by the laws of Hong Kong Special Administrative Region. Any dispute arising out of or in connection with these terms shall be subject to the dispute clause in the service agreement or, if none applies, the exclusive jurisdiction of the courts of Hong Kong.

19. Contact

DPA requests, sub-processor enquiries, security notices and data protection requests should be sent to privacy@megastephk.com.

Mega Step (HK) Ltd.

Independent quality control, inspections, audits and digital reporting for consumer product supply chains in Asia.

Contact
Inspection request
Company
About Guides AQL
Legal
Terms Privacy Data Processing Digital Services Act