Version 2026-09 · Incorporated into the Terms of Service for every workspace
Draft template — not yet reviewed by counsel. Written to be usable under the Australian Privacy Act and, where a customer requires it, GDPR/UK GDPR Article 28. Highlighted items are placeholders. Not legal advice.
1. Roles
For personal data contained in Customer Data, the customer is the controller (or APP entity) and [Operator legal name] is the processor, acting only on the customer's documented instructions, which are: to host, store, display, export and delete Customer Data as directed through the Service. For account data (your users' work emails and sign-in events) we are an independent controller as described in the Privacy Policy.
2. Nature of the data
The Service is designed to hold organisational information — capabilities, systems, data standards, processes, projects, business-case economics. It does not require personal data beyond your users' work email addresses, and our onboarding guidance instructs customers not to enter personal information into the model. Special-category data must not be uploaded.
3. Our obligations
Process Customer Data only to provide the Service and on your instructions; never sell it, never use it for advertising, never use it to train models.
Ensure staff with access are bound by confidentiality and limited to what is necessary.
Implement the technical and organisational measures in §5.
Assist you with data-subject requests, security questionnaires and impact assessments, within reason.
Notify you of a personal-data breach affecting your workspace without undue delay (target [72] hours of confirmation) with the information you need to meet your own notification duties.
Delete or return Customer Data at the end of the Service (export is self-serve at any time; deletion completes [60] days after termination), and delete subprocessor copies on the same schedule.
Make available the information necessary to demonstrate compliance and, subject to reasonable notice and confidentiality, allow audits by you or an independent auditor not more than once a year unless required by a regulator or following a breach.
4. Subprocessors
We use the following subprocessors. We will notify workspace administrators at least 30 days before adding one; you may object on reasonable data-protection grounds, and if we cannot resolve the objection you may terminate with a pro-rata refund.
Global edge; data at rest in Cloudflare's network [state region if pinned]
Cloudflare DPA and SCCs
Stripe, Inc. / Stripe Payments Australia
Subscription billing, invoices, card processing (card data never touches our systems)
US / AU
Stripe DPA, PCI DSS Level 1
Clerk, Inc. (once enabled)
Identity: sign-up, sign-in, MFA, SSO
US
Clerk DPA and SCCs
No other third party receives Customer Data. Optional AI endpoints are configured by you and are your own subprocessors, not ours.
5. Technical and organisational measures
Tenant isolation: every record is scoped to a workspace; the workspace identifier is derived only from the signed server-side session, never from the client.
Encryption: TLS 1.2+ in transit; platform-managed encryption at rest.
Access control: role-based roles within a workspace (admin / editor / viewer); administrative access to infrastructure limited to named operator staff with MFA.
Session security: HMAC-signed HttpOnly Secure SameSite cookies with expiry; origin checks on all state-changing requests.
Abuse controls: rate limiting, disposable-domain blocking and an optional bot challenge on sign-up.
Logging: an append-only per-workspace audit trail (exportable); infrastructure logs held by Cloudflare.
Backup and recovery: database point-in-time recovery plus periodic exports; per-workspace version history (last 20 model versions); documented restore procedure with stated RPO/RTO.
Secure development: parameterised database access, content-security policy and security headers, dependency-light code base, changes reviewed and validated before deployment.
Certification status: none held yet; controls are documented toward SOC 2 / ISO 27001. We will not represent a certification we do not hold.
6. International transfers
Where Customer Data is transferred outside your jurisdiction (for example to Cloudflare's global network or a US-based subprocessor), the transfer is covered by the subprocessor's standard contractual clauses or an equivalent safeguard, and by this Addendum. Customers requiring in-country residency should use the region-pinned hosted option or the offline edition.
7. Term
This Addendum applies for as long as we process Customer Data on your behalf and survives termination until deletion is complete. Contact for data-protection matters: [privacy contact email].