DRAFT — NOT LEGAL ADVICE. Prepared as a starting draft; not reviewed by a lawyer. A data processing addendum carries real legal weight — have a qualified Australian legal practitioner review and adapt it before use.
[TO CONFIRM: …]items need your input (seedocs/legal/README.md).
Data Processing Addendum — Grace
This Data Processing Addendum ("DPA") forms part of the Terms of Service between [TO CONFIRM: full legal entity name] ("Egan Services", "we") and the customer ("Customer", "you") for the Grace Service. It governs our handling of personal information contained in Customer Data that we process on your behalf and on your instructions to provide the Service.
Australian privacy law does not use the EU "controller/processor" split, but this DPA adopts a similar structure: you determine what personal information goes into your workspace and why; we handle it only to run the Service for you. Where you or your end-customers are subject to the GDPR or other laws, [TO CONFIRM: consider whether GDPR standard contractual clauses / a separate GDPR addendum are needed].
1. Scope and roles
- Subject matter: our processing of personal information within Customer Data to provide the Service.
- Duration: for the term of the Terms of Service, plus any post-termination export/deletion window.
- Nature and purpose: hosting, storage, computation, transmission, access control, backup, security and support — solely to provide, secure and support the Service.
- Types of personal information: as determined by you; typically the identity and contact details of your staff, contractors and business contacts, and whatever you record in your compliance registers.
- Categories of individuals: your Users, personnel, contractors, and contacts you include.
2. Our obligations
We will:
- Process on instructions. Process personal information in Customer Data only to provide the Service and in accordance with your documented instructions (these Terms and your use of the Service), except where law requires otherwise (in which case we will tell you, unless prohibited).
- No independent use. Not use Customer Data for our own purposes, and not sell it or use it for advertising.
- Confidentiality. Ensure personnel authorised to process Customer Data are bound by confidentiality.
- Security. Implement and maintain reasonable technical and organisational security measures
appropriate to the risk, consistent with APP 11 and summarised in
security-statement.md. - Assist you. Provide reasonable assistance for you to meet your obligations, including responding to individuals' access/correction requests and to data-breach and regulatory obligations, taking into account the nature of the processing and the information available to us.
- Data breaches. Notify you without undue delay after becoming aware of a data breach affecting Customer Data, with the information reasonably available, and cooperate with your response and any obligations under the Notifiable Data Breaches scheme.
- Deletion/return. On termination, make Customer Data available for export and then delete it in accordance with the Terms, unless retention is required by law.
- Records and information. Make available information reasonably necessary to demonstrate compliance with this DPA. [TO CONFIRM: audit rights — scope, frequency, cost — negotiate with your solicitor.]
3. Sub-processors
You authorise us to engage sub-processors to help provide the Service. The current sub-processors, their
purposes and locations, are listed in sub-processors.md. We remain responsible for their performance of
the obligations in this DPA, impose data-protection terms on them consistent with this DPA, and will give
you a reasonable way to learn of changes (and, where you have a paid Plan, [TO CONFIRM: notice period and
any right to object] before a new sub-processor starts processing Customer Data).
4. Overseas / cross-border processing (APP 8)
Some sub-processors are located outside Australia (for example, authentication in the United States;
see sub-processors.md). Where personal information in Customer Data is processed overseas, we take
reasonable steps to ensure the recipient handles it consistently with the APPs. You are responsible for
determining that such cross-border processing is permitted for your own use case and for making any
disclosures required to the individuals concerned.
5. Your obligations
You warrant that: you have the right to provide the Customer Data to us for processing under this DPA; you have made any notifications and obtained any consents required from individuals; your instructions comply with applicable law; and your use of the Service will not cause us to breach applicable privacy law.
6. Precedence
If there is a conflict between this DPA and the Terms of Service on the handling of personal information in Customer Data, this DPA prevails to the extent of the conflict.