Data Processing Addendum

Version 2026-09 · Incorporated into the Terms of Service for every workspace

Draft template — not yet reviewed by counsel. Written to be usable under the Australian Privacy Act and, where a customer requires it, GDPR/UK GDPR Article 28. Highlighted items are placeholders. Not legal advice.

1. Roles

For personal data contained in Customer Data, the customer is the controller (or APP entity) and [Operator legal name] is the processor, acting only on the customer's documented instructions, which are: to host, store, display, export and delete Customer Data as directed through the Service. For account data (your users' work emails and sign-in events) we are an independent controller as described in the Privacy Policy.

2. Nature of the data

The Service is designed to hold organisational information — capabilities, systems, data standards, processes, projects, business-case economics. It does not require personal data beyond your users' work email addresses, and our onboarding guidance instructs customers not to enter personal information into the model. Special-category data must not be uploaded.

3. Our obligations

4. Subprocessors

We use the following subprocessors. We will notify workspace administrators at least 30 days before adding one; you may object on reasonable data-protection grounds, and if we cannot resolve the objection you may terminate with a pro-rata refund.

SubprocessorPurposeLocationSafeguard
Cloudflare, Inc.Hosting (Pages Functions), database (D1), edge network, bot protection (Turnstile)Global edge; data at rest in Cloudflare's network [state region if pinned]Cloudflare DPA and SCCs
Stripe, Inc. / Stripe Payments AustraliaSubscription billing, invoices, card processing (card data never touches our systems)US / AUStripe DPA, PCI DSS Level 1
Clerk, Inc. (once enabled)Identity: sign-up, sign-in, MFA, SSOUSClerk DPA and SCCs

No other third party receives Customer Data. Optional AI endpoints are configured by you and are your own subprocessors, not ours.

5. Technical and organisational measures

6. International transfers

Where Customer Data is transferred outside your jurisdiction (for example to Cloudflare's global network or a US-based subprocessor), the transfer is covered by the subprocessor's standard contractual clauses or an equivalent safeguard, and by this Addendum. Customers requiring in-country residency should use the region-pinned hosted option or the offline edition.

7. Term

This Addendum applies for as long as we process Customer Data on your behalf and survives termination until deletion is complete. Contact for data-protection matters: [privacy contact email].