This Data Processing Addendum ("DPA") forms part of, and is incorporated into, the Terms and Conditions ("Agreement") between Oppermind Pty Ltd (ABN 89 689 605 918) ("Oppermind", "Processor", "we", "us", or "our") and the individual or entity using the Oppermind platform ("Controller", "you", or "your"). This DPA sets out the terms governing Oppermind's processing of Personal Data on behalf of the Controller in connection with the Oppermind platform and services (the "Service").
Automatic Application: This DPA applies exclusively to users located in a jurisdiction whose applicable data protection law mandates a formal data processing agreement between a controller and processor — including the European Union, European Economic Area, United Kingdom, Switzerland, Brazil, and the State of California (United States). This DPA does not apply to users located in Australia or in any other jurisdiction whose applicable law does not mandate such an arrangement; those users are governed solely by the Terms and Conditions and Privacy Policy. This DPA does not create any additional rights, obligations, or causes of action for users to whom it does not apply, and nothing in this DPA shall be construed as extending its scope beyond the jurisdictions identified in this paragraph. By creating an account or using the Service from an applicable jurisdiction, you accept and agree to this DPA as a condition of use, as stated in our Privacy Policy (Section 6.5). If you do not accept this DPA, you may not use the Service.
Enterprise Customers: Organisations requiring a bespoke or negotiated DPA with custom terms, additional security requirements, or supplementary contractual arrangements may request a tailored agreement by contacting enquiry@oppermind.com with the subject line "Enterprise DPA Request".
In this DPA, unless the context otherwise requires, the following terms have the meanings set out below. Capitalised terms not defined in this DPA have the meanings given to them in the Agreement, the Privacy Policy, or the applicable Data Protection Law.
This DPA applies to the Processing of Personal Data by the Processor on behalf of the Controller in connection with the provision of the Service, as described in the Agreement and further specified in Annex I to this DPA, but only where the Controller is located in a jurisdiction whose applicable data protection law mandates a formal data processing agreement between a controller and processor. For the avoidance of doubt, this DPA does not apply to Controllers located in Australia or in any jurisdiction whose applicable law does not mandate such an arrangement, and shall not be interpreted as creating any contractual or statutory rights or obligations beyond those that would exist under the Agreement and Privacy Policy alone.
The parties acknowledge and agree that, with respect to the Processing of Personal Data under this DPA:
The Controller is responsible for:
This DPA shall remain in effect for the duration of the Agreement and shall automatically terminate upon the later of: (a) the termination or expiry of the Agreement; or (b) the completion of all Processing of Personal Data by the Processor on behalf of the Controller, including any post-termination Processing carried out in accordance with Section 12 of this DPA.
In the event of any conflict between this DPA and the Agreement, this DPA shall prevail to the extent of any inconsistency with respect to the Processing of Personal Data. In the event of any conflict between this DPA and the SCCs or UK Addendum, the SCCs or UK Addendum (as applicable) shall prevail to the extent of any inconsistency.
Article 28(3) GDPR Compliance: The obligations set out in this Section 3 give effect to the mandatory requirements of Article 28(3)(a) through (h) of the GDPR and corresponding provisions of the UK GDPR.
The Processor shall Process Personal Data only on the documented instructions of the Controller, unless required to do so by European Union or Member State law to which the Processor is subject, in which case the Processor shall inform the Controller of that legal requirement before Processing (unless such law prohibits such notification on important grounds of public interest). The Controller's documented instructions for Processing are set out in this DPA, the Agreement, and any additional written instructions provided by the Controller and acknowledged by the Processor. The Processor shall immediately inform the Controller if, in the Processor's opinion, an instruction from the Controller infringes Applicable Data Protection Law.
The Processor shall ensure that all persons authorised to Process Personal Data on behalf of the Controller have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. The Processor shall ensure that access to Personal Data is limited to those personnel who require access for the performance of the Service and that all such personnel have received appropriate training on data protection obligations.
The Processor shall implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as required by Article 32 of the GDPR. These measures are described in Annex II to this DPA and include, as appropriate:
The Processor shall regularly review and update these measures to address evolving threats and ensure continued appropriateness.
The Processor shall not engage another processor (Sub-processor) for the Processing of Personal Data on behalf of the Controller without the prior general written authorisation of the Controller, as set out in Section 5 of this DPA. Where a Sub-processor is engaged, the Processor shall impose on that Sub-processor, by way of a contract or other legal act under Union or Member State law, the same data protection obligations as set out in this DPA, in particular providing sufficient guarantees to implement appropriate technical and organisational measures in such a manner that the Processing will meet the requirements of the GDPR. Where the Sub-processor fails to fulfil its data protection obligations, the Processor shall remain fully liable to the Controller for the performance of that Sub-processor's obligations.
Taking into account the nature of the Processing, the Processor shall assist the Controller by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Controller's obligation to respond to requests for exercising the Data Subject's rights under Chapter III of the GDPR and Chapter 3 of the UK GDPR. This assistance is further described in Section 8 of this DPA.
The Processor shall assist the Controller in ensuring compliance with the obligations pursuant to Articles 32 to 36 of the GDPR (and corresponding provisions of the UK GDPR), taking into account the nature of Processing and the information available to the Processor. This includes assistance with:
At the choice of the Controller, the Processor shall delete or return all Personal Data to the Controller after the end of the provision of the Service, and delete existing copies unless European Union or Member State law requires storage of the Personal Data. The terms governing deletion and return are set out in Section 12 of this DPA.
The Processor shall make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 of the GDPR and shall allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller. The terms governing audits are set out in Section 10 of this DPA.
AI Platform Provisions: As the Service is an AI-powered platform, the following provisions apply specifically to the Processing of Personal Data in connection with AI features, including large language models, image and video generation, autonomous agents, and email AI integration. These provisions supplement (and do not limit) the Processor's general obligations in Section 3.
The Processor shall not use, and shall contractually ensure that its AI Model Provider Sub-processors do not use, Personal Data Processed on behalf of the Controller for the purpose of training, fine-tuning, improving, or developing any machine learning model, artificial intelligence system, or algorithm, except where:
For the avoidance of doubt, the Processing of Personal Data through AI models to generate responses and outputs for the Controller in the ordinary course of providing the Service (including ephemeral in-context processing that produces no persistent model weight changes) does not constitute "training" and is authorised by the Controller's use of the Service. Aggregated, anonymised, and de-identified data that no longer constitutes Personal Data under Applicable Data Protection Law (assessed in accordance with the EDPB's guidance on anonymisation techniques, including consideration of reasonably likely re-identification) is not subject to this restriction.
Where the Processing of Personal Data involves the use of AI systems within the scope of Regulation (EU) 2024/1689 (the "EU AI Act"), the Processor shall:
The Processor acknowledges that the Service provides AI-generated outputs that may be used by the Controller in decision-making processes. The Processor shall:
The Processor shall implement and maintain reasonable technical and organisational measures to protect against prompt injection attacks, adversarial inputs, jailbreak attempts, and other AI-specific security threats that could result in the unauthorised disclosure, modification, or Processing of Personal Data, including:
The Processor may update, change, or replace the AI models and AI Model Provider Sub-processors used to provide the Service from time to time. Where such a change materially affects the Processing of Personal Data (including changes to data retention practices, data access, or the jurisdictions in which Personal Data is Processed), the Processor shall notify the Controller in accordance with Section 5.3 of this DPA. Model updates that do not materially affect the Processing of Personal Data (such as performance improvements, bug fixes, or safety patches) do not require notification.
Where the Controller uses the email integration feature of the Service, the Processor shall:
Where the Controller uses the autonomous agent feature of the Service (including desktop agents, browser agents, or other automated interaction tools), the Processor shall:
In accordance with Article 5(1)(c) of the GDPR, the Processor shall apply the principle of data minimisation to AI Processing by:
The allocation of intellectual property rights in AI-generated outputs is governed by the Agreement (Terms and Conditions). This DPA does not confer any additional intellectual property rights on either party. For the avoidance of doubt, the Processor's obligation not to use Controller data for AI training (Section 3A.1) does not affect the intellectual property provisions of the Agreement.
The subject matter, duration, nature, purpose, types of Personal Data, and categories of Data Subjects are set out in full in Annex I to this DPA. A summary is provided below.
The Processing of Personal Data by the Processor in connection with the provision of the Oppermind AI workspace platform and related services to the Controller.
The Processing shall continue for the duration of the Agreement, plus any post-termination period necessary to complete deletion or return of Personal Data in accordance with Section 12.
The Processor Processes Personal Data for the purpose of providing, maintaining, securing, and supporting the Service as described in the Agreement, including:
The categories of Personal Data Processed include:
The Data Subjects whose Personal Data is Processed under this DPA include:
Trade Secret Protection: The identities of Oppermind's Sub-processors constitute proprietary trade secrets and confidential business information, as stated in our Terms and Conditions (Sections 6.4 and 6.5). Sub-processors are identified in this DPA by function and jurisdiction only.
The Controller hereby grants the Processor a general written authorisation to engage Sub-processors for the Processing of Personal Data in connection with the Service, subject to the requirements of this Section 5. This authorisation is given pursuant to Article 28(2) of the GDPR.
The Processor engages the following categories of Sub-processors as at the effective date of this DPA:
| Function | Processing Activity | Jurisdiction(s) |
|---|---|---|
| AI Model Providers | Processing of AI requests (prompts, queries, conversation context, and uploaded content) to generate AI responses | Australia; United States; may include additional jurisdictions |
| Cloud Infrastructure Provider | Hosting, storage, compute, and network infrastructure for the Service | Australia; United States; may include additional jurisdictions |
| Payment Processor | Processing of subscription payments, billing, and payment card data | United States; Ireland |
| Bot Detection & Abuse Prevention | Analysis of technical data for automated threat detection and abuse prevention | Australia; United States; may include additional jurisdictions |
The Processor shall notify the Controller of any intended changes concerning the addition or replacement of Sub-processors at least thirty (30) days before the new Sub-processor begins Processing Personal Data ("Notice Period"). Such notification shall be provided by updating this DPA and, where the Controller has provided an email address, by email notification to the Controller's registered email address. The Controller is responsible for regularly reviewing this DPA for updates.
The Controller may object to the appointment of a new Sub-processor by notifying the Processor in writing within the Notice Period, provided that such objection is based on reasonable grounds relating to data protection. If the Controller objects, the Processor shall use commercially reasonable efforts to:
If the Processor is unable to resolve the objection within a reasonable period (not exceeding thirty (30) days from receipt of the objection), either party may terminate the Agreement by providing written notice to the other party, without prejudice to any rights or obligations that accrued prior to termination. Where the Controller terminates the Agreement under this Section 5.4, the Controller shall be entitled to a pro-rata refund of any prepaid fees attributable to the period after the effective date of termination.
The Processor shall:
Where a Sub-processor is located in, or Processes Personal Data in, a jurisdiction that has not been recognised as providing an adequate level of data protection under Applicable Data Protection Law, the Processor shall ensure that appropriate safeguards are in place for the transfer, including the SCCs, the UK Addendum, or other transfer mechanisms recognised under Applicable Data Protection Law.
The Processor is established in Australia. As at the date of this DPA, Australia has not been granted an adequacy decision by the European Commission under Article 45 of the GDPR. Accordingly, transfers of Personal Data from the EEA, the United Kingdom, or Switzerland to the Processor are made subject to the appropriate safeguards set out in this Section 6.
For transfers of Personal Data from the EEA to Australia (and to any other jurisdiction without an adequacy decision), the parties agree that the Standard Contractual Clauses set out in the European Commission Implementing Decision (EU) 2021/914 of 4 June 2021 are incorporated into this DPA by reference and shall apply as follows:
For transfers of Personal Data from the United Kingdom, the UK Addendum (International Data Transfer Addendum to the EU Commission Standard Contractual Clauses), issued by the ICO under Section 119A(1) of the Data Protection Act 2018, is incorporated into this DPA by reference. The UK Addendum shall be completed as follows:
Where the UK Addendum conflicts with the SCCs, the UK Addendum shall prevail to the extent of the conflict, for transfers subject to the UK GDPR.
For transfers of Personal Data from Switzerland, the SCCs as set out in Section 6.2 shall apply with the following modifications: (a) references to "Regulation (EU) 2016/679" shall be interpreted as references to the Swiss Federal Act on Data Protection of 25 September 2020 (the "revised FADP", in force 1 September 2023); (b) references to the "EU", "Union", or "Member State" shall be interpreted as references to Switzerland, and Swiss Data Subjects shall not be excluded from the possibility of invoking rights under the SCCs by reason of Switzerland not being an EU Member State; (c) the competent supervisory authority shall be the Swiss Federal Data Protection and Information Commissioner (FDPIC); and (d) the governing law shall be the law of Switzerland.
In addition to the safeguards provided by the SCCs and UK Addendum, the Processor implements supplementary technical and organisational measures to protect Personal Data during International Data Transfers, including:
In accordance with the requirements established by the Court of Justice of the European Union in Case C-311/18 (Data Protection Commissioner v. Facebook Ireland and Maximillian Schrems, "Schrems II"), the Processor has conducted a Transfer Impact Assessment ("TIA") to evaluate whether the laws and practices of the jurisdictions to which Personal Data is transferred provide an essentially equivalent level of protection for Personal Data. The Processor shall:
The Processor is established in Australia and not in the European Union or the United Kingdom. Pursuant to Article 27 of the GDPR and Article 27 of the UK GDPR, the Processor shall appoint a representative in the European Union and a separate representative in the United Kingdom prior to actively offering the Service to Data Subjects in those jurisdictions. The Processor commits to appointing such representatives within ninety (90) days of the effective date of this DPA, or prior to the commencement of Processing of Personal Data of Data Subjects located in the EU or UK (whichever is earlier). Details of the appointed representative(s) will be published on the Processor's website, notified to the Controller, and included in updated versions of this DPA. Until such appointment, all enquiries from EU or UK Data Subjects, Controllers, or Supervisory Authorities may be directed to enquiry@oppermind.com, and the Processor shall respond to such enquiries as if a representative had been appointed.
Where the Processing of Personal Data is subject to data protection laws of additional jurisdictions beyond the GDPR, UK GDPR, and Swiss FADP, the following provisions apply:
The Processor shall, to the extent permitted by applicable law:
The Processor shall notify the Controller without undue delay, and in any event within forty-eight (48) hours, after becoming aware of a Personal Data Breach affecting Personal Data Processed on behalf of the Controller. This forty-eight (48) hour timeframe is intended to provide the Controller with sufficient time to assess the breach and, where required, notify the competent Supervisory Authority within the seventy-two (72) hour period prescribed by Article 33(1) of the GDPR.
The Processor's notification shall include, to the extent reasonably available at the time of notification:
Where it is not possible to provide all information at the time of the initial notification, the Processor shall provide the information in phases without undue further delay. The Processor shall cooperate with the Controller and take such commercially reasonable steps as are directed by the Controller to assist in the investigation, mitigation, and remediation of each Personal Data Breach.
The Processor shall maintain a record of all Personal Data Breaches, including the facts relating to the breach, its effects, and the remedial action taken. This record shall be made available to the Controller upon request.
The Processor's obligation to notify the Controller is not contingent on the Processor's assessment of the risk to Data Subjects. The Processor shall notify the Controller of all Personal Data Breaches, and the Controller shall be responsible for determining whether notification to the Supervisory Authority or Data Subjects is required.
The Processor shall not inform any third party of any Personal Data Breach without first obtaining the Controller's prior written consent, unless required to do so by applicable law or by a competent Supervisory Authority.
Where a Personal Data Breach constitutes, or is likely to constitute, an "eligible data breach" within the meaning of Part IIIC of the Privacy Act 1988 (Cth) (the "Notifiable Data Breaches scheme" or "NDB scheme"), the Processor shall, in addition to its obligations under Sections 7.1 to 7.6:
The Processor acknowledges that the forty-eight (48) hour notification obligation in Section 7.1 is designed to enable the Controller to meet its obligations under both the GDPR (Article 33(1), seventy-two (72) hours) and the NDB scheme, and that these obligations may run concurrently.
Taking into account the nature of the Processing, the Processor shall assist the Controller by appropriate technical and organisational measures, insofar as this is possible, in responding to requests from Data Subjects exercising their rights under Chapter III of the GDPR and Chapter 3 of the UK GDPR, including requests relating to:
If the Processor receives a request directly from a Data Subject regarding Personal Data Processed on behalf of the Controller, the Processor shall promptly redirect the Data Subject to the Controller and notify the Controller of the request. The Processor shall not respond to such request itself unless expressly authorised by the Controller in writing, except to inform the Data Subject that it is a processor and to redirect them to the Controller.
The Processor shall provide the Controller with such information and cooperation as the Controller may reasonably require to respond to Data Subject requests within the timeframes required by Applicable Data Protection Law. Where the Service provides functionality that enables the Controller to access, correct, or delete Personal Data directly, the Processor shall ensure that such functionality remains available to the Controller.
The Processor shall provide reasonable assistance with Data Subject requests at no additional charge. Where a request is manifestly unfounded, excessive, or requires disproportionate effort, the Processor reserves the right to charge a reasonable fee based on administrative costs, having informed the Controller in advance.
The Processor shall provide reasonable assistance to the Controller in carrying out Data Protection Impact Assessments ("DPIAs") under Article 35 of the GDPR and, where applicable, prior consultations with Supervisory Authorities under Article 36 of the GDPR, in each case to the extent that such assistance is required and relates to the Processing of Personal Data by the Processor on behalf of the Controller.
Such assistance shall include, upon the Controller's reasonable request, providing:
The Processor's obligation to assist with DPIAs is limited to information and measures within the Processor's possession or control. The Controller remains solely responsible for conducting the DPIA and for any decisions made as a result of the DPIA. The Processor shall not be required to disclose the identity of its Sub-processors, the specific AI models used, or any other information that constitutes proprietary trade secrets, but shall provide sufficient information about the nature and safeguards of Processing to enable the Controller to complete the DPIA.
The Processor shall make available to the Controller all information reasonably necessary to demonstrate compliance with the obligations laid down in Article 28 of the GDPR and this DPA. Such information shall be provided upon the Controller's reasonable written request.
The Processor shall satisfy its obligations under Article 28(3)(h) of the GDPR primarily through the provision of compliance documentation. Upon the Controller's reasonable written request (no more than once per twelve (12) month period), the Processor shall provide the Controller with one or more of the following:
Such documentation shall be provided subject to the Processor's confidentiality requirements (including the execution of a non-disclosure agreement if requested) and shall be treated as Confidential Information of the Processor. The Controller acknowledges that the provision of such documentation constitutes sufficient demonstration of compliance for the purposes of Article 28(3)(h) of the GDPR in the ordinary course.
Where the Controller can demonstrate, in writing, that the documentation provided under Section 10.2 is insufficient to verify compliance with this DPA, and that an on-site audit is strictly necessary (for example, following a confirmed Personal Data Breach directly affecting the Controller's data, or where required by a binding order of a competent Supervisory Authority specifically naming the Controller), the Processor shall allow for and contribute to an on-site audit, subject to all of the following conditions:
The Controller shall bear all costs and expenses of any audit conducted or requested by the Controller, including the reasonable costs incurred by the Processor in facilitating such audit. Where an audit reveals a material non-compliance by the Processor with this DPA, the Processor shall bear its own costs of remediation.
The total aggregate liability of each party under or in connection with this DPA (whether in contract, tort, negligence, breach of statutory duty, or otherwise) shall be subject to the limitations and exclusions of liability set out in Section 13 of the Agreement (Terms and Conditions). For the avoidance of doubt, the liability cap set out in Section 13.2 of the Agreement applies to claims arising under this DPA, and the aggregate liability of the Processor under both the Agreement and this DPA combined shall not exceed the cap set out in Section 13.2 of the Agreement.
Nothing in this Section 11 shall limit or exclude either party's liability for:
Where both parties are involved in the same Processing and are responsible for any damage caused by that Processing, each party shall be liable for the entire damage in accordance with Article 82(4) of the GDPR, subject to the right of contribution from the other party in respect of that party's share of responsibility for the damage.
Each party shall indemnify, defend, and hold harmless the other party from and against any claims, damages, losses, costs, and expenses (including reasonable legal fees) arising from the indemnifying party's breach of this DPA or Applicable Data Protection Law, subject to the limitations set out in this Section 11 and the Agreement.
Upon termination or expiry of the Agreement, the Processor shall, at the Controller's written election:
The Controller must make its election in writing within thirty (30) days of the termination or expiry of the Agreement. If the Controller does not make an election within this period, the Processor shall delete all Personal Data.
The Processor shall complete the deletion or return of Personal Data within ninety (90) days of the later of: (a) the effective date of termination or expiry of the Agreement; or (b) receipt of the Controller's written election. The Processor shall use commercially reasonable efforts to complete deletion or return as promptly as practicable.
The Processor may retain Personal Data (or specific categories of Personal Data) after termination to the extent required by applicable law, including European Union or Member State law, or the laws of the Commonwealth of Australia or the State of Western Australia. Where Personal Data is retained for legal compliance purposes, the Processor shall:
Notwithstanding the foregoing, the Processor may retain and use data that has been aggregated, anonymised, or de-identified such that it no longer constitutes Personal Data under Applicable Data Protection Law. Such data is not subject to the deletion or return obligations in this Section 12.
Personal Data contained in backup systems shall be deleted in accordance with the Processor's standard backup rotation schedule, and in any event within one hundred and eighty (180) days of the deletion of the corresponding production data, unless retention is required by applicable law.
This DPA shall be governed by and construed in accordance with the laws of the State of Western Australia and the Commonwealth of Australia, without regard to conflict of law principles, except to the extent that:
Subject to the jurisdiction provisions of the SCCs and UK Addendum (which shall apply to disputes arising under those instruments), the parties submit to the exclusive jurisdiction of the courts of Western Australia and the Federal Court of Australia (sitting in Perth) for the resolution of any dispute arising out of or in connection with this DPA. Nothing in this section limits the right of a Data Subject or Supervisory Authority to bring proceedings in the courts of any jurisdiction as permitted under Applicable Data Protection Law.
If any provision of this DPA is held to be invalid, illegal, or unenforceable, such provision shall be severed from this DPA and the remaining provisions shall continue in full force and effect. The parties shall negotiate in good faith to replace the invalid provision with a valid provision that achieves the same economic and legal effect to the greatest extent possible.
Oppermind reserves the right to update this DPA from time to time to reflect changes in Applicable Data Protection Law, regulatory guidance, or Oppermind's Processing activities. Material changes will be notified to the Controller via the email address associated with the Controller's account at least thirty (30) days before the changes take effect. If the Controller does not agree to a material change, the Controller may terminate the Agreement by providing written notice within the thirty (30) day notice period, and shall be entitled to a pro-rata refund of any prepaid fees attributable to the period after the effective date of termination. The Controller's continued use of the Service after the effective date of the updated DPA constitutes acceptance of the updated DPA. Non-material changes (such as formatting, typographical corrections, or clarifications that do not alter the substance of the Controller's or Processor's obligations) do not require advance notification but will be reflected in the "Last updated" date of this DPA.
This DPA, together with the Agreement (including the Privacy Policy) and the SCCs and UK Addendum incorporated herein, constitutes the entire agreement between the parties with respect to the Processing of Personal Data by the Processor on behalf of the Controller and supersedes all prior representations, understandings, and agreements relating to such Processing.
All notices under this DPA shall be sent in accordance with the notice provisions of the Agreement. Notices to the Processor shall be addressed to enquiry@oppermind.com. Notices to the Controller shall be sent to the email address associated with the Controller's account.
This DPA does not confer any rights on any person or party other than the parties to this DPA and their respective successors and permitted assigns, except to the extent that Data Subjects have rights under the SCCs, the UK Addendum, or Applicable Data Protection Law that cannot be excluded by contract.
The provisions of this DPA that by their nature should survive termination or expiry of the Agreement shall survive, including Sections 3A (AI-Specific Processing Obligations, to the extent relevant to post-termination Processing), 7 (Data Breach), 10 (Audit), 11 (Liability), 12 (Data Deletion and Return), and 13 (General Provisions).
The Processor acknowledges that, under Australian Privacy Principle 8 (APP 8) of the Privacy Act 1988 (Cth), an entity that discloses Personal Data to an overseas recipient is generally accountable for the acts and practices of that recipient, and that under section 16C of the Privacy Act 1988, the disclosing entity is taken to have breached the APPs if the overseas recipient acts in a manner that would constitute a breach, regardless of the contractual protections in place. The Processor shall:
The Processor shall use reasonable efforts to monitor changes to Applicable Data Protection Law, regulatory guidance, and enforcement action that may affect the Processing of Personal Data under this DPA. Where a change in law or regulation materially affects the Processor's obligations under this DPA, the Processor shall notify the Controller and, where necessary, propose amendments to this DPA to ensure continued compliance. The Processor shall cooperate with the Controller in implementing any changes required by new or amended Applicable Data Protection Law, including (without limitation) the anticipated reforms to the Privacy Act 1988 (Cth) as recommended by the Attorney-General's Department Privacy Act Review.
This Annex I forms part of the DPA and the SCCs (where applicable), and sets out the details of the Processing of Personal Data by the Processor on behalf of the Controller.
| Data Exporter (Controller) | The individual or entity that has entered into the Agreement and uses the Service. The data exporter's identity, contact details, and (where applicable) data protection officer details are as set out in the data exporter's account registration with the Service. |
|---|---|
| Data Importer (Processor) | Oppermind Pty Ltd (ABN 89 689 605 918), a company registered in Western Australia, Australia, operating from Perth, Western Australia. Contact: enquiry@oppermind.com. |
| Categories of Data Subjects |
|
|---|---|
| Categories of Personal Data |
|
| Sensitive Data | The Processor does not intentionally collect or Process special categories of data (Article 9 GDPR) or criminal conviction data (Article 10 GDPR). However, the Controller may submit content that includes such data. Where the Controller Processes special categories of data through the Service, the Controller is solely responsible for ensuring a lawful basis for such Processing, including obtaining explicit consent from Data Subjects where required. |
| Frequency of Transfer | Continuous, as initiated by the Controller's use of the Service. |
| Nature of Processing | Collection, storage, organisation, retrieval, consultation, use, disclosure by transmission to Sub-processors, alignment, combination, restriction, erasure, and destruction, as necessary to provide the Service. |
| Purpose of Transfer and Further Processing | Provision of the Oppermind AI workspace platform and related services, including: account management and authentication; AI request processing; content storage and retrieval; email integration services; autonomous agent operations; payment facilitation; security and content moderation; and service improvement using aggregated and de-identified data. |
| Retention Period | Personal Data is retained for the duration of the Agreement and thereafter in accordance with Section 12 of the DPA and the Processor's Privacy Policy (Section 7). |
The competent supervisory authority is determined in accordance with Section 6.2 (Clause 13(a)) of this DPA. Where the Controller is established in the EU, the competent authority is the supervisory authority of the Member State in which the Controller is established. Where the Controller is established in the UK, the competent authority is the Information Commissioner's Office (ICO).
This Annex II forms part of the DPA and the SCCs (where applicable), and describes the technical and organisational security measures implemented by the Processor pursuant to Article 32 of the GDPR. The specific details and configurations of these measures are proprietary and confidential.
| Measure | Description |
|---|---|
| Encryption in Transit | All data transmitted between users and the Service, and between the Service and Sub-processors, is encrypted using industry-standard TLS (Transport Layer Security) protocols. The Processor enforces a minimum of TLS 1.2 and supports TLS 1.3. HTTP Strict Transport Security (HSTS) headers are implemented to prevent protocol downgrade attacks. |
| Encryption at Rest | All Personal Data stored on the Processor's infrastructure and Sub-processor infrastructure is encrypted at rest using industry-standard encryption algorithms (AES-256 or equivalent). Database-level, storage-level, and backup encryption are implemented. Encryption keys are managed using dedicated key management services with appropriate access controls and key rotation policies. |
| Credential Encryption | User passwords are stored using one-way cryptographic hashing with salt. Email integration credentials and other sensitive credentials are stored using authenticated encryption. Encryption keys for credentials are stored separately from the encrypted data. |
| Measure | Description |
|---|---|
| Authentication | The Service implements secure authentication mechanisms for all user accounts, including password-based authentication with enforced complexity requirements and session management with token-based authentication. Session tokens have defined expiry periods and are invalidated upon logout. |
| Authorisation | Role-based access controls (RBAC) are implemented across the Service infrastructure. Access to Personal Data is restricted to authorised personnel on a need-to-know basis. Administrative access to production systems requires authenticated, audited access with appropriate privilege separation. |
| Infrastructure Access | Access to the Processor's cloud infrastructure is restricted to authorised personnel. Infrastructure access is managed through the cloud provider's identity and access management (IAM) systems. All administrative access is logged and auditable. |
| Logical Separation | User data is logically separated such that each user can access only their own data. Application-level access controls enforce data isolation between user accounts. |
| Measure | Description |
|---|---|
| Internal Identifiers | Where practicable, the Processor uses internal pseudonymous identifiers (such as system-generated user IDs) rather than directly identifying information for internal processing and analytics purposes. |
| De-identification | Data used for service improvement and analytics is aggregated and de-identified to the extent reasonably practicable, such that it cannot be attributed to a specific Data Subject without the use of additional information. |
| Measure | Description |
|---|---|
| Monitoring | The Processor implements monitoring and alerting systems to detect potential security incidents, including intrusion detection, anomaly detection, and automated threat analysis. Web Application Firewall (WAF) policies are implemented and actively maintained to detect and block malicious traffic and automated attacks. |
| Incident Response Plan | The Processor maintains a documented incident response plan that includes procedures for identification, containment, eradication, recovery, and post-incident analysis. The plan includes defined escalation procedures and communication protocols for notifying affected parties. |
| Logging & Audit Trail | Security-relevant events are logged, including authentication events, access to Personal Data, administrative actions, and system changes. Logs are retained for a period sufficient to support security investigations and are protected against unauthorised modification. |
| Vulnerability Management | The Processor conducts regular vulnerability assessments and applies security patches and updates in a timely manner. Dependencies are monitored for known vulnerabilities. |
| Measure | Description |
|---|---|
| Backup & Recovery | The Processor implements regular automated backups of Personal Data. Backups are encrypted and stored in a geographically separate location from production data. Backup restoration procedures are tested periodically. |
| Infrastructure Redundancy | The Service is hosted on cloud infrastructure with built-in redundancy and high availability capabilities. The Processor leverages the cloud provider's infrastructure resilience, including redundant power, cooling, and network connectivity. |
| Disaster Recovery | The Processor maintains disaster recovery capabilities appropriate to the scale and criticality of the Service. Recovery procedures are documented and periodically reviewed. |
| Measure | Description |
|---|---|
| Confidentiality Obligations | All personnel with access to Personal Data are bound by confidentiality obligations, whether by contract or statutory duty. Access to Personal Data is granted only to personnel whose role requires such access. |
| Training | Personnel with access to Personal Data receive training on data protection principles, security practices, and the Processor's obligations under Applicable Data Protection Law. Training is provided upon onboarding and refreshed periodically. |
| Acceptable Use | The Processor maintains internal policies governing the acceptable use of systems, data handling procedures, and security requirements for personnel. |
| Measure | Description |
|---|---|
| Selection & Assessment | Before engaging a Sub-processor, the Processor conducts due diligence to assess the Sub-processor's technical and organisational security measures, data protection practices, and compliance posture. Sub-processors are selected based on their ability to provide sufficient guarantees under Article 28(1) of the GDPR. |
| Contractual Safeguards | All Sub-processors are bound by written data processing agreements that impose obligations no less protective than those in this DPA, including obligations regarding security, confidentiality, data breach notification, and restrictions on Processing. |
| Ongoing Monitoring | The Processor periodically reviews the data protection and security practices of its Sub-processors. Where a Sub-processor is found to be non-compliant, the Processor takes appropriate remedial action, which may include termination of the Sub-processor relationship. |
| Measure | Description |
|---|---|
| Automated Content Safety | The Processor implements automated content safety and moderation systems to detect and prevent the generation or distribution of harmful, illegal, or prohibited content through the Service, in accordance with the Acceptable Use Policy set out in the Agreement. |
| Abuse Prevention | The Processor employs bot detection, rate limiting, and web application firewall technologies to detect and prevent automated abuse, credential stuffing, and other malicious activity. |
This Annex III forms part of the DPA and the SCCs (where applicable). In accordance with the trade secret protections set out in the Agreement (Sections 6.4 and 6.5), Sub-processors are listed by function and jurisdiction only.
| Function | Processing Activity | Jurisdiction(s) | Transfer Mechanism |
|---|---|---|---|
| AI Model Providers | Processing of AI requests (prompts, queries, conversation context, uploaded content) to generate AI responses and outputs | Australia; United States; may include additional jurisdictions | SCCs (Module Two); UK Addendum |
| Cloud Infrastructure Provider | Hosting, storage, compute, networking, and database infrastructure for the Service, including backup and disaster recovery | Australia; United States; may include additional jurisdictions | SCCs (Module Two); UK Addendum (for non-adequate jurisdictions) |
| Payment Processor | Processing of subscription payments, billing, invoicing, and payment card data (PCI-DSS compliant) | United States; Ireland | SCCs (Module Two); UK Addendum |
| Bot Detection & Abuse Prevention | Analysis of device and application data for automated threat detection, bot identification, and abuse prevention | Australia; United States; may include additional jurisdictions | SCCs (Module Two); UK Addendum |
The Controller has granted a general written authorisation for the engagement of the above Sub-processors in accordance with Section 5.1 of this DPA. Changes to this list will be notified to the Controller in accordance with Section 5.3.
This Annex IV incorporates by reference the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, as issued by the Information Commissioner under Section 119A(1) of the Data Protection Act 2018, Version B1.0, in force 21 March 2022 (the "UK Addendum"). The UK Addendum is available at ico.org.uk.
The tables of the UK Addendum are completed as follows:
| Table | Content |
|---|---|
| Table 1: Parties |
Start Date: The date on which the Controller creates an account with the Service, or the effective date of this DPA (22 May 2026), whichever is later. Exporter: The Controller (as identified in Annex I, Section A). Importer: Oppermind Pty Ltd (ABN 89 689 605 918), Perth, Western Australia, Australia. Contact: enquiry@oppermind.com. Key Contact (Importer): Data Protection Lead, enquiry@oppermind.com. |
| Table 2: Selected SCCs, Modules and Selected Clauses |
The Approved EU SCCs are the SCCs incorporated by reference in Section 6.2 of this DPA, being the Standard Contractual Clauses set out in the Annex to the European Commission Implementing Decision (EU) 2021/914. Module in operation: Module Two (Controller to Processor). Selected clauses and optional elements: As specified in Section 6.2 of this DPA (including Clause 7 docking clause, Clause 9(a) Option 2, Clause 17 Option 1 with the law of Ireland, and Clause 18(b) with the courts of Ireland). |
| Table 3: Appendix Information |
Annex 1A (List of Parties): As set out in Annex I, Section A of this DPA. Annex 1B (Description of Transfer): As set out in Annex I, Section B of this DPA. Annex II (Technical and Organisational Measures): As set out in Annex II of this DPA. Annex III (List of Sub-processors): As set out in Annex III of this DPA (Section 5.2). |
| Table 4: Ending this Addendum when the Approved Addendum Changes | Either party may end this UK Addendum as set out in Section 19 of the Mandatory Clauses of the UK Addendum. |
For transfers of Personal Data from the United Kingdom, the UK Addendum shall be read and interpreted in accordance with the UK GDPR and the Data Protection Act 2018. Where the UK Addendum conflicts with the SCCs, the UK Addendum shall prevail to the extent of the conflict.
For questions, requests, or notices relating to this Data Processing Addendum, please contact us:
For privacy-related enquiries, please refer to our Privacy Policy. For general terms of service, please refer to our Terms and Conditions.