Legal
Data Processing Agreement
This Data Processing Agreement ("DPA") forms part of the Terms of Service between AssetStack Pty Ltd ("Processor") and the Customer ("Controller"). It sets out the terms governing the processing of Personal Information (as defined in the Privacy Act 1988 (Cth)) by the Processor on behalf of the Controller.
1. Definitions
- "APPs" means the Australian Privacy Principles set out in Schedule 1 of the Privacy Act 1988 (Cth).
- "Personal Information" has the meaning given in the Privacy Act 1988 (Cth).
- "Processing" means any operation performed on Personal Information, including collection, recording, organisation, storage, adaptation, alteration, retrieval, consultation, use, disclosure, dissemination, alignment, combination, restriction, erasure or destruction.
- "Sub-processor" means any third party engaged by the Processor to process Personal Information on behalf of the Controller.
2. Roles and Responsibilities
- The Controller is the organisation that determines the purposes and means of Processing Personal Information.
- The Processor processes Personal Information only on documented instructions from the Controller, including as set out in the Terms of Service and this DPA.
- Both parties agree to comply with their respective obligations under the Privacy Act 1988 (Cth) and the APPs.
3. Processor Obligations
The Processor agrees to:
- process Personal Information solely for the purposes of providing the Services and as otherwise instructed by the Controller
- ensure that persons authorised to process Personal Information are bound by confidentiality obligations
- implement and maintain appropriate technical and organisational measures to protect Personal Information against unauthorised access, alteration, disclosure or destruction
- not engage Sub-processors without the Controller's prior written consent (which may be given generally via the Terms of Service or specifically)
- assist the Controller in responding to requests from individuals exercising their rights under the Privacy Act 1988 (Cth)
- notify the Controller without undue delay upon becoming aware of any actual or suspected data breach affecting Personal Information
- make available to the Controller information necessary to demonstrate compliance with this DPA
4. Sub-processors
The Controller authorises the Processor to engage the following categories of Sub-processors:
- cloud infrastructure and hosting providers
- payment processing services
- analytics and monitoring services
- customer support and communication platforms
A current list of Sub-processors is available upon request. The Processor will notify the Controller of any intended changes to Sub-processors and provide the opportunity to object.
All Sub-processors are contractually bound to process Personal Information only in accordance with the Processor's instructions and to maintain security measures at least equivalent to those maintained by the Processor.
5. Security Measures
The Processor implements the security measures described in its Security documentation, including:
- encryption of Personal Information in transit and at rest
- role-based access controls and multi-factor authentication
- per-tenant data isolation
- regular security monitoring, vulnerability assessment and penetration testing
- documented incident response procedures
6. Data Breach Notification
In the event of a data breach involving Personal Information, the Processor will:
- notify the Controller without undue delay and in any event within 24 hours of becoming aware of the breach
- provide details of the nature of the breach, the categories and approximate number of individuals affected, and the likely consequences
- cooperate with the Controller in taking remedial action and, where required, notifying affected individuals and the Office of the Australian Information Commissioner (OAIC)
7. Data Subject Rights
The Processor will assist the Controller in responding to requests from individuals to:
- access their Personal Information
- correct inaccurate or out-of-date Personal Information
- make a complaint about the handling of their Personal Information
The Processor will not respond directly to such requests unless expressly authorised by the Controller.
8. Data Return and Deletion
Upon termination or expiry of the Services, the Processor will:
- return all Personal Information to the Controller in a standard format (e.g., CSV, Excel) within 30 days, or sooner if requested
- delete or de-identify all remaining copies of Personal Information within 90 days, except where retention is required by law
- provide written certification of deletion upon request
9. Audit and Inspection
The Controller has the right to audit the Processor's compliance with this DPA, including:
- reviewing the Processor's security documentation and certifications
- requesting evidence of Sub-processor agreements
- conducting on-site inspections (with reasonable notice, not more than once per year)
The Processor will cooperate fully with such audits and provide access to relevant personnel and records.
10. Limitation of Liability
Each party's liability under this DPA is subject to the limitations set out in the Terms of Service. Nothing in this DPA excludes or limits liability that cannot be excluded or limited under applicable law.
11. Term and Termination
This DPA commences on the date the Controller first uses the Services and continues until all Personal Information has been returned or deleted in accordance with Clause 8.
12. Governing Law
This DPA is governed by the laws of Australia. The parties submit to the exclusive jurisdiction of the courts of New South Wales.
13. Contact
For questions about this DPA or data processing matters:
Email: [email protected]
