Oppermind Back

Data Processing Addendum

Last updated: 22 May 2026  |  Effective: 22 May 2026  |  Version 1.0

This Data Processing Addendum ("DPA") forms part of, and is incorporated into, the Terms and Conditions ("Agreement") between Oppermind Pty Ltd (ABN 89 689 605 918) ("Oppermind", "Processor", "we", "us", or "our") and the individual or entity using the Oppermind platform ("Controller", "you", or "your"). This DPA sets out the terms governing Oppermind's processing of Personal Data on behalf of the Controller in connection with the Oppermind platform and services (the "Service").

Automatic Application: This DPA applies exclusively to users located in a jurisdiction whose applicable data protection law mandates a formal data processing agreement between a controller and processor — including the European Union, European Economic Area, United Kingdom, Switzerland, Brazil, and the State of California (United States). This DPA does not apply to users located in Australia or in any other jurisdiction whose applicable law does not mandate such an arrangement; those users are governed solely by the Terms and Conditions and Privacy Policy. This DPA does not create any additional rights, obligations, or causes of action for users to whom it does not apply, and nothing in this DPA shall be construed as extending its scope beyond the jurisdictions identified in this paragraph. By creating an account or using the Service from an applicable jurisdiction, you accept and agree to this DPA as a condition of use, as stated in our Privacy Policy (Section 6.5). If you do not accept this DPA, you may not use the Service.

Enterprise Customers: Organisations requiring a bespoke or negotiated DPA with custom terms, additional security requirements, or supplementary contractual arrangements may request a tailored agreement by contacting enquiry@oppermind.com with the subject line "Enterprise DPA Request".

1. Definitions

1.1 Interpretation

In this DPA, unless the context otherwise requires, the following terms have the meanings set out below. Capitalised terms not defined in this DPA have the meanings given to them in the Agreement, the Privacy Policy, or the applicable Data Protection Law.

1.2 Defined Terms

  • "Applicable Data Protection Law" means all laws and regulations relating to the processing and protection of Personal Data that apply to the processing of Personal Data under this DPA, including: (a) the General Data Protection Regulation (EU) 2016/679 ("GDPR"); (b) the United Kingdom General Data Protection Regulation as incorporated into UK law by the European Union (Withdrawal) Act 2018 and the Data Protection Act 2018 ("UK GDPR"); (c) the Privacy Act 1988 (Cth) and the Australian Privacy Principles; (d) the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act of 2020 ("CCPA/CPRA"); and (e) any other applicable data protection or privacy legislation, in each case as amended, supplemented, or replaced from time to time.
  • "Controller" means the natural or legal person which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. For the purposes of this DPA, the Controller is the individual or entity that has entered into the Agreement and uses the Service.
  • "Data Subject" means an identified or identifiable natural person to whom Personal Data relates.
  • "EEA" means the European Economic Area (the EU Member States plus Iceland, Liechtenstein, and Norway).
  • "International Data Transfer" means a transfer of Personal Data from the EEA, the United Kingdom, or Switzerland to a country that has not been recognised by the relevant authority as providing an adequate level of data protection.
  • "Personal Data" means any information relating to an identified or identifiable natural person that is processed by the Processor on behalf of the Controller in connection with the Service, as further described in Annex I.
  • "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data transmitted, stored, or otherwise processed by the Processor.
  • "Processing" (and "Process") means any operation or set of operations performed on Personal Data, whether or not by automated means, including collection, recording, organisation, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination, alignment, combination, restriction, erasure, or destruction.
  • "Processor" means a natural or legal person which Processes Personal Data on behalf of the Controller. For the purposes of this DPA, the Processor is Oppermind Pty Ltd.
  • "SCCs" means the Standard Contractual Clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679, as set out in the Annex to the European Commission Implementing Decision (EU) 2021/914 of 4 June 2021, as may be amended, supplemented, or replaced from time to time.
  • "Sub-processor" means any third party engaged by the Processor to Process Personal Data on behalf of the Controller in connection with the Service.
  • "Supervisory Authority" means an independent public authority established by a Member State of the EU pursuant to Article 51 GDPR, or the Information Commissioner's Office ("ICO") in the United Kingdom, or any other competent data protection authority with jurisdiction.
  • "UK Addendum" means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, as issued by the Information Commissioner under Section 119A(1) of the Data Protection Act 2018, Version B1.0, in force 21 March 2022, as may be amended from time to time.

2. Scope & Application

2.1 Scope of Processing

This DPA applies to the Processing of Personal Data by the Processor on behalf of the Controller in connection with the provision of the Service, as described in the Agreement and further specified in Annex I to this DPA, but only where the Controller is located in a jurisdiction whose applicable data protection law mandates a formal data processing agreement between a controller and processor. For the avoidance of doubt, this DPA does not apply to Controllers located in Australia or in any jurisdiction whose applicable law does not mandate such an arrangement, and shall not be interpreted as creating any contractual or statutory rights or obligations beyond those that would exist under the Agreement and Privacy Policy alone.

2.2 Roles of the Parties

The parties acknowledge and agree that, with respect to the Processing of Personal Data under this DPA:

  • The Controller determines the purposes and means of the Processing of Personal Data by using the Service and directing the Processing through the Controller's use of the Service's features and functionality;
  • The Processor Processes Personal Data on behalf of the Controller solely in accordance with the Controller's documented instructions, which consist of: (a) the terms of the Agreement; (b) the terms of this DPA; (c) the Controller's configuration and use of the Service; and (d) any other written instructions agreed by the parties, provided that such additional instructions are consistent with the terms of the Agreement and are technically feasible.

2.3 Controller Responsibilities

The Controller is responsible for:

  • Ensuring that it has a lawful basis for the Processing of Personal Data, including any necessary consents, authorisations, or legal bases required under Applicable Data Protection Law;
  • Ensuring that all necessary privacy notices have been provided to Data Subjects and that all necessary consents have been obtained;
  • Determining the purposes and means of Processing, and ensuring that the Processor's Processing on its behalf is lawful;
  • Complying with all Applicable Data Protection Law in its capacity as Controller;
  • Ensuring that its instructions to the Processor comply with Applicable Data Protection Law.

2.4 Duration

This DPA shall remain in effect for the duration of the Agreement and shall automatically terminate upon the later of: (a) the termination or expiry of the Agreement; or (b) the completion of all Processing of Personal Data by the Processor on behalf of the Controller, including any post-termination Processing carried out in accordance with Section 12 of this DPA.

2.5 Precedence

In the event of any conflict between this DPA and the Agreement, this DPA shall prevail to the extent of any inconsistency with respect to the Processing of Personal Data. In the event of any conflict between this DPA and the SCCs or UK Addendum, the SCCs or UK Addendum (as applicable) shall prevail to the extent of any inconsistency.

3. Processor Obligations

Article 28(3) GDPR Compliance: The obligations set out in this Section 3 give effect to the mandatory requirements of Article 28(3)(a) through (h) of the GDPR and corresponding provisions of the UK GDPR.

3.1 Processing on Instructions (Art. 28(3)(a))

The Processor shall Process Personal Data only on the documented instructions of the Controller, unless required to do so by European Union or Member State law to which the Processor is subject, in which case the Processor shall inform the Controller of that legal requirement before Processing (unless such law prohibits such notification on important grounds of public interest). The Controller's documented instructions for Processing are set out in this DPA, the Agreement, and any additional written instructions provided by the Controller and acknowledged by the Processor. The Processor shall immediately inform the Controller if, in the Processor's opinion, an instruction from the Controller infringes Applicable Data Protection Law.

3.2 Confidentiality (Art. 28(3)(b))

The Processor shall ensure that all persons authorised to Process Personal Data on behalf of the Controller have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. The Processor shall ensure that access to Personal Data is limited to those personnel who require access for the performance of the Service and that all such personnel have received appropriate training on data protection obligations.

3.3 Security Measures (Art. 28(3)(c))

The Processor shall implement and maintain appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as required by Article 32 of the GDPR. These measures are described in Annex II to this DPA and include, as appropriate:

  • The pseudonymisation and encryption of Personal Data;
  • The ability to ensure the ongoing confidentiality, integrity, availability, and resilience of processing systems and services;
  • The ability to restore the availability and access to Personal Data in a timely manner in the event of a physical or technical incident;
  • A process for regularly testing, assessing, and evaluating the effectiveness of technical and organisational measures for ensuring the security of Processing.

The Processor shall regularly review and update these measures to address evolving threats and ensure continued appropriateness.

3.4 Sub-processors (Art. 28(3)(d))

The Processor shall not engage another processor (Sub-processor) for the Processing of Personal Data on behalf of the Controller without the prior general written authorisation of the Controller, as set out in Section 5 of this DPA. Where a Sub-processor is engaged, the Processor shall impose on that Sub-processor, by way of a contract or other legal act under Union or Member State law, the same data protection obligations as set out in this DPA, in particular providing sufficient guarantees to implement appropriate technical and organisational measures in such a manner that the Processing will meet the requirements of the GDPR. Where the Sub-processor fails to fulfil its data protection obligations, the Processor shall remain fully liable to the Controller for the performance of that Sub-processor's obligations.

3.5 Data Subject Rights Assistance (Art. 28(3)(e))

Taking into account the nature of the Processing, the Processor shall assist the Controller by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Controller's obligation to respond to requests for exercising the Data Subject's rights under Chapter III of the GDPR and Chapter 3 of the UK GDPR. This assistance is further described in Section 8 of this DPA.

3.6 Security, Breach Notification, DPIAs & Prior Consultation Assistance (Art. 28(3)(f))

The Processor shall assist the Controller in ensuring compliance with the obligations pursuant to Articles 32 to 36 of the GDPR (and corresponding provisions of the UK GDPR), taking into account the nature of Processing and the information available to the Processor. This includes assistance with:

  • Security of Processing (Article 32);
  • Notification of a Personal Data Breach to the Supervisory Authority (Article 33);
  • Communication of a Personal Data Breach to the Data Subject (Article 34);
  • Data Protection Impact Assessments (Article 35), as further described in Section 9;
  • Prior consultation with the Supervisory Authority (Article 36).

3.7 Deletion or Return of Data (Art. 28(3)(g))

At the choice of the Controller, the Processor shall delete or return all Personal Data to the Controller after the end of the provision of the Service, and delete existing copies unless European Union or Member State law requires storage of the Personal Data. The terms governing deletion and return are set out in Section 12 of this DPA.

3.8 Audit & Compliance Demonstration (Art. 28(3)(h))

The Processor shall make available to the Controller all information necessary to demonstrate compliance with the obligations laid down in Article 28 of the GDPR and shall allow for and contribute to audits, including inspections, conducted by the Controller or another auditor mandated by the Controller. The terms governing audits are set out in Section 10 of this DPA.

3A. AI-Specific Processing Obligations

AI Platform Provisions: As the Service is an AI-powered platform, the following provisions apply specifically to the Processing of Personal Data in connection with AI features, including large language models, image and video generation, autonomous agents, and email AI integration. These provisions supplement (and do not limit) the Processor's general obligations in Section 3.

3A.1 No Training on Controller Data

The Processor shall not use, and shall contractually ensure that its AI Model Provider Sub-processors do not use, Personal Data Processed on behalf of the Controller for the purpose of training, fine-tuning, improving, or developing any machine learning model, artificial intelligence system, or algorithm, except where:

  • The Controller has provided prior, specific, informed, and documented consent for such use; and
  • Such use is limited to the specific purpose consented to by the Controller.

For the avoidance of doubt, the Processing of Personal Data through AI models to generate responses and outputs for the Controller in the ordinary course of providing the Service (including ephemeral in-context processing that produces no persistent model weight changes) does not constitute "training" and is authorised by the Controller's use of the Service. Aggregated, anonymised, and de-identified data that no longer constitutes Personal Data under Applicable Data Protection Law (assessed in accordance with the EDPB's guidance on anonymisation techniques, including consideration of reasonably likely re-identification) is not subject to this restriction.

3A.2 EU AI Act Compliance

Where the Processing of Personal Data involves the use of AI systems within the scope of Regulation (EU) 2024/1689 (the "EU AI Act"), the Processor shall:

  • Comply with the transparency obligations set out in Article 50 of the EU AI Act, including ensuring that AI-generated content is clearly identifiable as such where required by the EU AI Act;
  • Maintain documentation regarding the AI systems used in the Processing, to the extent required by the EU AI Act and to the extent such documentation does not constitute proprietary trade secrets;
  • Cooperate with the Controller in relation to any obligations the Controller may have under the EU AI Act in its capacity as a "deployer" of AI systems;
  • Implement appropriate measures to monitor the AI systems for risks to health, safety, and fundamental rights, as required by the EU AI Act;
  • Promptly notify the Controller where an AI system used in the Service is classified as "high-risk" under the EU AI Act, and provide the Controller with such information as is reasonably necessary for the Controller to fulfil its obligations as a deployer.

3A.3 Automated Decision-Making

The Processor acknowledges that the Service provides AI-generated outputs that may be used by the Controller in decision-making processes. The Processor shall:

  • Ensure that the Service does not make solely automated decisions with legal or similarly significant effects on Data Subjects, within the meaning of Article 22 of the GDPR, without the Controller's express configuration and the Controller's assumption of responsibility for ensuring a lawful basis for such Processing;
  • Provide the Controller with meaningful information about the logic involved, the significance, and the envisaged consequences of any automated Processing carried out by the Service, sufficient to enable the Controller to fulfil its obligations under Article 22(3) of the GDPR. The Processor may withhold specific proprietary implementation details (such as model weights, training data composition, and source code) but shall not withhold information to the extent that doing so would prevent the Controller from providing Data Subjects with meaningful information about the automated Processing;
  • Support the Controller in implementing meaningful human oversight of automated decision-making processes where required by Applicable Data Protection Law or the EU AI Act.

3A.4 Prompt Injection & Output Integrity

The Processor shall implement and maintain reasonable technical and organisational measures to protect against prompt injection attacks, adversarial inputs, jailbreak attempts, and other AI-specific security threats that could result in the unauthorised disclosure, modification, or Processing of Personal Data, including:

  • Input validation and sanitisation mechanisms applied to user prompts and uploaded content;
  • Output filtering to prevent inadvertent disclosure of Personal Data from AI model responses;
  • Content safety and moderation systems to prevent the generation of harmful, illegal, or prohibited content;
  • Regular testing and assessment of AI-specific security measures, including adversarial testing where appropriate.

3A.5 Model Updates & Versioning

The Processor may update, change, or replace the AI models and AI Model Provider Sub-processors used to provide the Service from time to time. Where such a change materially affects the Processing of Personal Data (including changes to data retention practices, data access, or the jurisdictions in which Personal Data is Processed), the Processor shall notify the Controller in accordance with Section 5.3 of this DPA. Model updates that do not materially affect the Processing of Personal Data (such as performance improvements, bug fixes, or safety patches) do not require notification.

3A.6 Email Integration Processing

Where the Controller uses the email integration feature of the Service, the Processor shall:

  • Process email data (including email content, headers, attachments, and encrypted credentials) solely for the purpose of providing the email integration functionality as directed by the Controller;
  • Store email credentials using authenticated encryption with keys stored separately from the encrypted credentials, in accordance with industry best practices;
  • Not access, read, analyse, or Process email content except as necessary to carry out the Controller's instructions through the Service;
  • Delete email credentials promptly upon the Controller's disconnection of the email integration feature or termination of the Agreement;
  • Not disclose, transfer, or make available the content of any email to any third party other than the AI Model Provider Sub-processors engaged for the purpose of generating the Controller's requested AI response, and only to the extent necessary for that purpose;
  • Comply with all applicable provisions of the Telecommunications (Interception and Access) Act 1979 (Cth) ("TIA Act") in relation to stored communications, and ensure that access to stored email communications is undertaken only with the knowledge or implied consent of the intended recipient (being the Controller), in accordance with section 108 of the TIA Act.

3A.7 Autonomous Agent Processing

Where the Controller uses the autonomous agent feature of the Service (including desktop agents, browser agents, or other automated interaction tools), the Processor shall:

  • Process agent data (including screen data, file operations data, and system interaction data) solely in accordance with the Controller's instructions and configuration of the agent;
  • Implement access controls to ensure that agent operations are limited to the scope authorised by the Controller;
  • Not retain screen captures, file contents, or system interaction data beyond the period necessary to complete the Controller's requested operation, unless otherwise directed by the Controller or required for security and audit purposes;
  • Apply the same security, confidentiality, and data protection obligations to agent data as to all other Personal Data under this DPA.

3A.8 AI Data Minimisation

In accordance with Article 5(1)(c) of the GDPR, the Processor shall apply the principle of data minimisation to AI Processing by:

  • Limiting the Personal Data included in prompts, queries, and context sent to AI Model Provider Sub-processors to that which is reasonably necessary for the performance of the requested operation;
  • Implementing technical measures to reduce unnecessary transmission or retention of Personal Data in AI processing pipelines, including context window management and token optimisation;
  • Encouraging, through documentation and product design, the use of de-identified or pseudonymised data where the full fidelity of Personal Data is not required for the AI operation.

3A.9 Intellectual Property in AI Outputs

The allocation of intellectual property rights in AI-generated outputs is governed by the Agreement (Terms and Conditions). This DPA does not confer any additional intellectual property rights on either party. For the avoidance of doubt, the Processor's obligation not to use Controller data for AI training (Section 3A.1) does not affect the intellectual property provisions of the Agreement.

4. Details of Processing

The subject matter, duration, nature, purpose, types of Personal Data, and categories of Data Subjects are set out in full in Annex I to this DPA. A summary is provided below.

4.1 Subject Matter

The Processing of Personal Data by the Processor in connection with the provision of the Oppermind AI workspace platform and related services to the Controller.

4.2 Duration of Processing

The Processing shall continue for the duration of the Agreement, plus any post-termination period necessary to complete deletion or return of Personal Data in accordance with Section 12.

4.3 Nature and Purpose of Processing

The Processor Processes Personal Data for the purpose of providing, maintaining, securing, and supporting the Service as described in the Agreement, including:

  • Account management and authentication;
  • Processing of AI requests (prompts, queries, and related data) through Oppermind's AI infrastructure;
  • Storage and retrieval of user content (conversations, documents, files, media);
  • Email integration services (access, composition, and transmission of emails on behalf of the Controller);
  • Autonomous agent operations (device interactions, file operations, system interactions as directed by the Controller);
  • Payment processing facilitation (via Sub-processor);
  • Security, content moderation, and abuse prevention;
  • Service improvement using aggregated and de-identified data.

4.4 Types of Personal Data

The categories of Personal Data Processed include:

  • Account data (name, email address, hashed password);
  • AI conversation data (prompts, queries, responses, conversation history);
  • User-uploaded content (documents, images, files, and associated metadata);
  • Email data (email content, headers, attachments, and encrypted credentials, where the Controller uses the email integration feature);
  • Autonomous agent data (file operations data, screen data, and system interaction data, where the Controller uses the agent feature);
  • AI-generated outputs (text, images, video, code);
  • Payment identifiers (subscription IDs, billing status; full payment card data is processed exclusively by the payment Sub-processor);
  • Technical and device data (IP address, browser type, operating system, session identifiers, device identifiers);
  • Security and audit data (authentication logs, access logs, content moderation records).

4.5 Categories of Data Subjects

The Data Subjects whose Personal Data is Processed under this DPA include:

  • Users of the Service (registered account holders);
  • Individuals whose Personal Data is contained within content uploaded, submitted, or processed by the Controller through the Service (including, where applicable, email correspondents, document subjects, and other third parties whose data appears in Controller content).

5. Sub-processors

Trade Secret Protection: The identities of Oppermind's Sub-processors constitute proprietary trade secrets and confidential business information, as stated in our Terms and Conditions (Sections 6.4 and 6.5). Sub-processors are identified in this DPA by function and jurisdiction only.

5.1 General Written Authorisation

The Controller hereby grants the Processor a general written authorisation to engage Sub-processors for the Processing of Personal Data in connection with the Service, subject to the requirements of this Section 5. This authorisation is given pursuant to Article 28(2) of the GDPR.

5.2 Current Sub-processors

The Processor engages the following categories of Sub-processors as at the effective date of this DPA:

Function Processing Activity Jurisdiction(s)
AI Model Providers Processing of AI requests (prompts, queries, conversation context, and uploaded content) to generate AI responses Australia; United States; may include additional jurisdictions
Cloud Infrastructure Provider Hosting, storage, compute, and network infrastructure for the Service Australia; United States; may include additional jurisdictions
Payment Processor Processing of subscription payments, billing, and payment card data United States; Ireland
Bot Detection & Abuse Prevention Analysis of technical data for automated threat detection and abuse prevention Australia; United States; may include additional jurisdictions

5.3 Notification of New Sub-processors

The Processor shall notify the Controller of any intended changes concerning the addition or replacement of Sub-processors at least thirty (30) days before the new Sub-processor begins Processing Personal Data ("Notice Period"). Such notification shall be provided by updating this DPA and, where the Controller has provided an email address, by email notification to the Controller's registered email address. The Controller is responsible for regularly reviewing this DPA for updates.

5.4 Right to Object

The Controller may object to the appointment of a new Sub-processor by notifying the Processor in writing within the Notice Period, provided that such objection is based on reasonable grounds relating to data protection. If the Controller objects, the Processor shall use commercially reasonable efforts to:

  • Make available to the Controller a modification to the Service that avoids the Processing of Personal Data by the objected-to Sub-processor, without unreasonably burdening the Controller; or
  • Take other reasonable steps to address the Controller's objection.

If the Processor is unable to resolve the objection within a reasonable period (not exceeding thirty (30) days from receipt of the objection), either party may terminate the Agreement by providing written notice to the other party, without prejudice to any rights or obligations that accrued prior to termination. Where the Controller terminates the Agreement under this Section 5.4, the Controller shall be entitled to a pro-rata refund of any prepaid fees attributable to the period after the effective date of termination.

5.5 Sub-processor Obligations

The Processor shall:

  • Enter into a written agreement with each Sub-processor that imposes data protection obligations no less protective than those set out in this DPA, as required by Article 28(4) of the GDPR;
  • Carry out appropriate due diligence on each Sub-processor prior to engagement, assessing the Sub-processor's ability to provide sufficient guarantees regarding the implementation of appropriate technical and organisational measures;
  • Remain fully liable to the Controller for the acts and omissions of its Sub-processors with respect to the Processing of Personal Data.

5.6 Onward Transfers

Where a Sub-processor is located in, or Processes Personal Data in, a jurisdiction that has not been recognised as providing an adequate level of data protection under Applicable Data Protection Law, the Processor shall ensure that appropriate safeguards are in place for the transfer, including the SCCs, the UK Addendum, or other transfer mechanisms recognised under Applicable Data Protection Law.

6. International Data Transfers

6.1 Transfer Mechanism

The Processor is established in Australia. As at the date of this DPA, Australia has not been granted an adequacy decision by the European Commission under Article 45 of the GDPR. Accordingly, transfers of Personal Data from the EEA, the United Kingdom, or Switzerland to the Processor are made subject to the appropriate safeguards set out in this Section 6.

6.2 Standard Contractual Clauses (EU/EEA Transfers)

For transfers of Personal Data from the EEA to Australia (and to any other jurisdiction without an adequacy decision), the parties agree that the Standard Contractual Clauses set out in the European Commission Implementing Decision (EU) 2021/914 of 4 June 2021 are incorporated into this DPA by reference and shall apply as follows:

  • Module Two (Controller to Processor) applies where the Controller transfers Personal Data to the Processor for Processing on the Controller's behalf;
  • The data exporter is the Controller; the data importer is the Processor;
  • Clause 7 — The optional docking clause is included, permitting additional parties to accede to the SCCs;
  • Clause 9(a) — Option 2 (General written authorisation) applies. The Processor shall inform the Controller of any intended changes to the list of Sub-processors with a minimum notice period of thirty (30) days, as set out in Section 5.3 of this DPA;
  • Clause 11 — The optional language regarding independent dispute resolution bodies is not included;
  • Clause 13(a) — The competent supervisory authority shall be the supervisory authority of the EU Member State in which the data exporter (Controller) is established. Where the Controller is not established in the EU, the competent supervisory authority shall be the supervisory authority of the EU Member State in which the Controller's EU representative is appointed, or, in the absence of a representative, the supervisory authority of the Member State in which the Data Subjects whose Personal Data is transferred are located;
  • Clause 17 — Option 1 (Governing law of an EU Member State) applies. The SCCs shall be governed by the law of the Republic of Ireland;
  • Clause 18(b) — Disputes shall be resolved before the courts of the Republic of Ireland;
  • Annex I — The details of the transfer are as set out in Annex I to this DPA;
  • Annex II — The technical and organisational measures are as set out in Annex II to this DPA;
  • Annex III — The list of Sub-processors is as set out in Section 5.2 of this DPA.

6.3 UK International Data Transfer Addendum

For transfers of Personal Data from the United Kingdom, the UK Addendum (International Data Transfer Addendum to the EU Commission Standard Contractual Clauses), issued by the ICO under Section 119A(1) of the Data Protection Act 2018, is incorporated into this DPA by reference. The UK Addendum shall be completed as follows:

  • Table 1: The parties and their details are as set out in Annex I to this DPA;
  • Table 2: The Approved EU SCCs referenced are those set out in Section 6.2 of this DPA, including the selected modules, clauses, and optional elements;
  • Table 3: The Annex information is as set out in Annexes I and II to this DPA, and the Sub-processor list is as set out in Section 5.2;
  • Table 4: Either party may end the UK Addendum in accordance with its terms.

Where the UK Addendum conflicts with the SCCs, the UK Addendum shall prevail to the extent of the conflict, for transfers subject to the UK GDPR.

6.4 Swiss Data Transfers

For transfers of Personal Data from Switzerland, the SCCs as set out in Section 6.2 shall apply with the following modifications: (a) references to "Regulation (EU) 2016/679" shall be interpreted as references to the Swiss Federal Act on Data Protection of 25 September 2020 (the "revised FADP", in force 1 September 2023); (b) references to the "EU", "Union", or "Member State" shall be interpreted as references to Switzerland, and Swiss Data Subjects shall not be excluded from the possibility of invoking rights under the SCCs by reason of Switzerland not being an EU Member State; (c) the competent supervisory authority shall be the Swiss Federal Data Protection and Information Commissioner (FDPIC); and (d) the governing law shall be the law of Switzerland.

6.5 Supplementary Measures

In addition to the safeguards provided by the SCCs and UK Addendum, the Processor implements supplementary technical and organisational measures to protect Personal Data during International Data Transfers, including:

  • Encryption of Personal Data in transit using industry-standard TLS protocols;
  • Encryption of Personal Data at rest;
  • Access controls limiting access to Personal Data to authorised personnel on a need-to-know basis;
  • Contractual obligations on all Sub-processors to maintain equivalent security measures;
  • Regular assessment of the legal framework of the countries to which Personal Data is transferred to evaluate whether any circumstances may affect the protections provided by the transfer mechanism.

6.6 Transfer Impact Assessment

In accordance with the requirements established by the Court of Justice of the European Union in Case C-311/18 (Data Protection Commissioner v. Facebook Ireland and Maximillian Schrems, "Schrems II"), the Processor has conducted a Transfer Impact Assessment ("TIA") to evaluate whether the laws and practices of the jurisdictions to which Personal Data is transferred provide an essentially equivalent level of protection for Personal Data. The Processor shall:

  • Make the findings and conclusions of the TIA available to the Controller upon reasonable written request, subject to redaction of proprietary or trade-secret information;
  • Re-assess the TIA periodically, and in any event when there is a material change in the laws, practices, or surveillance framework of a jurisdiction to which Personal Data is transferred;
  • Implement additional supplementary measures where the TIA identifies that the existing transfer safeguards may not be sufficient to ensure an essentially equivalent level of protection;
  • Suspend the transfer of Personal Data to a jurisdiction where the Processor determines that the laws or practices of that jurisdiction prevent compliance with the SCCs or UK Addendum in a manner that materially affects the guarantees provided thereunder, and promptly notify the Controller of any such suspension.

6.7 EU & UK Representative

The Processor is established in Australia and not in the European Union or the United Kingdom. Pursuant to Article 27 of the GDPR and Article 27 of the UK GDPR, the Processor shall appoint a representative in the European Union and a separate representative in the United Kingdom prior to actively offering the Service to Data Subjects in those jurisdictions. The Processor commits to appointing such representatives within ninety (90) days of the effective date of this DPA, or prior to the commencement of Processing of Personal Data of Data Subjects located in the EU or UK (whichever is earlier). Details of the appointed representative(s) will be published on the Processor's website, notified to the Controller, and included in updated versions of this DPA. Until such appointment, all enquiries from EU or UK Data Subjects, Controllers, or Supervisory Authorities may be directed to enquiry@oppermind.com, and the Processor shall respond to such enquiries as if a representative had been appointed.

6.8 Additional Jurisdiction Provisions

Where the Processing of Personal Data is subject to data protection laws of additional jurisdictions beyond the GDPR, UK GDPR, and Swiss FADP, the following provisions apply:

  • Brazil — Lei Geral de Proteção de Dados (LGPD): Where Personal Data of Data Subjects located in Brazil is Processed, the Processor shall comply with the applicable provisions of the LGPD (Lei nº 13.709/2018), including the data processing principles, Data Subject rights, and international transfer requirements set out therein. The SCCs shall serve as the primary transfer mechanism, supplemented by any additional measures required by the Autoridade Nacional de Proteção de Dados (ANPD).
  • United States — California (CCPA/CPRA): To the extent that the Processing involves "personal information" of California "consumers" (as defined in the CCPA/CPRA), the Processor acts as a "service provider" within the meaning of Cal. Civ. Code §1798.140(ag) and shall: (a) Process personal information only for the business purposes specified in this DPA and the Agreement; (b) not sell or share (as those terms are defined in the CCPA/CPRA) personal information received from the Controller; (c) not retain, use, or disclose personal information outside of the direct business relationship with the Controller; (d) not combine personal information received from the Controller with personal information received from other sources, except as permitted by the CCPA/CPRA; (e) comply with all applicable provisions of the CCPA/CPRA, including certification to the Controller that it understands these restrictions and will comply with them; (f) grant the Controller the right to take reasonable and appropriate steps to help ensure that the Processor uses personal information in a manner consistent with the Controller's obligations under the CCPA/CPRA; and (g) notify the Controller if the Processor makes a determination that it can no longer meet its obligations under the CCPA/CPRA.

6.9 Government Access Requests

The Processor shall, to the extent permitted by applicable law:

  • Promptly notify the Controller if it receives a legally binding request from a law enforcement authority or government body for access to Personal Data Processed under this DPA, unless such notification is prohibited by law;
  • Refer the requesting authority to the Controller where possible;
  • Challenge any request for access to Personal Data that the Processor reasonably considers to be unlawful, and shall not disclose Personal Data in response to such request unless compelled by applicable law;
  • Provide the minimum amount of Personal Data necessary to satisfy any disclosure obligation.

7. Personal Data Breach Notification

7.1 Notification Obligation

The Processor shall notify the Controller without undue delay, and in any event within forty-eight (48) hours, after becoming aware of a Personal Data Breach affecting Personal Data Processed on behalf of the Controller. This forty-eight (48) hour timeframe is intended to provide the Controller with sufficient time to assess the breach and, where required, notify the competent Supervisory Authority within the seventy-two (72) hour period prescribed by Article 33(1) of the GDPR.

7.2 Content of Notification

The Processor's notification shall include, to the extent reasonably available at the time of notification:

  • A description of the nature of the Personal Data Breach, including, where possible, the categories and approximate number of Data Subjects concerned and the categories and approximate number of Personal Data records concerned;
  • The name and contact details of the Processor's point of contact from whom further information may be obtained;
  • A description of the likely consequences of the Personal Data Breach;
  • A description of the measures taken or proposed to be taken by the Processor to address the Personal Data Breach, including, where appropriate, measures to mitigate its possible adverse effects.

7.3 Ongoing Cooperation

Where it is not possible to provide all information at the time of the initial notification, the Processor shall provide the information in phases without undue further delay. The Processor shall cooperate with the Controller and take such commercially reasonable steps as are directed by the Controller to assist in the investigation, mitigation, and remediation of each Personal Data Breach.

7.4 Record of Breaches

The Processor shall maintain a record of all Personal Data Breaches, including the facts relating to the breach, its effects, and the remedial action taken. This record shall be made available to the Controller upon request.

7.5 No Assessment by Processor

The Processor's obligation to notify the Controller is not contingent on the Processor's assessment of the risk to Data Subjects. The Processor shall notify the Controller of all Personal Data Breaches, and the Controller shall be responsible for determining whether notification to the Supervisory Authority or Data Subjects is required.

7.6 Communications

The Processor shall not inform any third party of any Personal Data Breach without first obtaining the Controller's prior written consent, unless required to do so by applicable law or by a competent Supervisory Authority.

7.7 Australian Notifiable Data Breaches Scheme

Where a Personal Data Breach constitutes, or is likely to constitute, an "eligible data breach" within the meaning of Part IIIC of the Privacy Act 1988 (Cth) (the "Notifiable Data Breaches scheme" or "NDB scheme"), the Processor shall, in addition to its obligations under Sections 7.1 to 7.6:

  • Cooperate with the Controller in conducting the assessment required under section 26WH of the Privacy Act 1988 to determine whether there are reasonable grounds to believe that the breach is an eligible data breach likely to result in serious harm to any individual;
  • Complete such assessment within the timeframe required by the Privacy Act 1988 (currently thirty (30) days from the date the Processor becomes aware of the breach);
  • Provide the Controller with all information reasonably necessary to prepare the statement required under section 26WK of the Privacy Act 1988 for notification to the Office of the Australian Information Commissioner (OAIC), including the kinds of information concerned and recommendations about the steps individuals should take in response to the breach;
  • Assist the Controller in taking reasonable remedial action to prevent or reduce the risk of serious harm to affected individuals, in accordance with section 26WF of the Privacy Act 1988.

The Processor acknowledges that the forty-eight (48) hour notification obligation in Section 7.1 is designed to enable the Controller to meet its obligations under both the GDPR (Article 33(1), seventy-two (72) hours) and the NDB scheme, and that these obligations may run concurrently.

8. Data Subject Rights

8.1 Assistance with Data Subject Requests

Taking into account the nature of the Processing, the Processor shall assist the Controller by appropriate technical and organisational measures, insofar as this is possible, in responding to requests from Data Subjects exercising their rights under Chapter III of the GDPR and Chapter 3 of the UK GDPR, including requests relating to:

  • Right of access (Article 15 GDPR);
  • Right to rectification (Article 16 GDPR);
  • Right to erasure (Article 17 GDPR);
  • Right to restriction of processing (Article 18 GDPR);
  • Notification obligation regarding rectification, erasure, or restriction (Article 19 GDPR);
  • Right to data portability (Article 20 GDPR);
  • Right to object (Article 21 GDPR);
  • Rights related to automated individual decision-making and profiling (Article 22 GDPR).

8.2 Direct Requests to Processor

If the Processor receives a request directly from a Data Subject regarding Personal Data Processed on behalf of the Controller, the Processor shall promptly redirect the Data Subject to the Controller and notify the Controller of the request. The Processor shall not respond to such request itself unless expressly authorised by the Controller in writing, except to inform the Data Subject that it is a processor and to redirect them to the Controller.

8.3 Cooperation

The Processor shall provide the Controller with such information and cooperation as the Controller may reasonably require to respond to Data Subject requests within the timeframes required by Applicable Data Protection Law. Where the Service provides functionality that enables the Controller to access, correct, or delete Personal Data directly, the Processor shall ensure that such functionality remains available to the Controller.

8.4 Costs

The Processor shall provide reasonable assistance with Data Subject requests at no additional charge. Where a request is manifestly unfounded, excessive, or requires disproportionate effort, the Processor reserves the right to charge a reasonable fee based on administrative costs, having informed the Controller in advance.

9. Data Protection Impact Assessments

9.1 DPIA Assistance

The Processor shall provide reasonable assistance to the Controller in carrying out Data Protection Impact Assessments ("DPIAs") under Article 35 of the GDPR and, where applicable, prior consultations with Supervisory Authorities under Article 36 of the GDPR, in each case to the extent that such assistance is required and relates to the Processing of Personal Data by the Processor on behalf of the Controller.

9.2 Information Provision

Such assistance shall include, upon the Controller's reasonable request, providing:

  • A description of the Processing operations carried out by the Processor on behalf of the Controller;
  • Information regarding the technical and organisational measures implemented by the Processor (as set out in Annex II);
  • Information regarding the Sub-processors engaged by the Processor (as set out in Section 5.2);
  • Any other information reasonably required by the Controller to conduct the DPIA, to the extent such information is available to the Processor and does not constitute Oppermind's proprietary trade secrets or Confidential Information (as defined in the Agreement).

9.3 Limitations

The Processor's obligation to assist with DPIAs is limited to information and measures within the Processor's possession or control. The Controller remains solely responsible for conducting the DPIA and for any decisions made as a result of the DPIA. The Processor shall not be required to disclose the identity of its Sub-processors, the specific AI models used, or any other information that constitutes proprietary trade secrets, but shall provide sufficient information about the nature and safeguards of Processing to enable the Controller to complete the DPIA.

10. Audit & Compliance

10.1 Information Access

The Processor shall make available to the Controller all information reasonably necessary to demonstrate compliance with the obligations laid down in Article 28 of the GDPR and this DPA. Such information shall be provided upon the Controller's reasonable written request.

10.2 Documentation-Based Compliance Verification (Primary Mechanism)

The Processor shall satisfy its obligations under Article 28(3)(h) of the GDPR primarily through the provision of compliance documentation. Upon the Controller's reasonable written request (no more than once per twelve (12) month period), the Processor shall provide the Controller with one or more of the following:

  • Relevant third-party certifications, audit reports, or attestations held by the Processor's infrastructure and cloud Sub-processors (such as SOC 2 Type II, ISO 27001, or equivalent) that are applicable to the infrastructure on which Personal Data is Processed;
  • The Processor's own internal security and data protection documentation, to the extent such documentation can be provided without disclosing proprietary trade secrets;
  • Completed data protection compliance questionnaires or similar documentation;
  • Written responses to the Controller's reasonable, specific compliance enquiries.

Such documentation shall be provided subject to the Processor's confidentiality requirements (including the execution of a non-disclosure agreement if requested) and shall be treated as Confidential Information of the Processor. The Controller acknowledges that the provision of such documentation constitutes sufficient demonstration of compliance for the purposes of Article 28(3)(h) of the GDPR in the ordinary course.

10.3 On-Site Audit (Exceptional Circumstances Only)

Where the Controller can demonstrate, in writing, that the documentation provided under Section 10.2 is insufficient to verify compliance with this DPA, and that an on-site audit is strictly necessary (for example, following a confirmed Personal Data Breach directly affecting the Controller's data, or where required by a binding order of a competent Supervisory Authority specifically naming the Controller), the Processor shall allow for and contribute to an on-site audit, subject to all of the following conditions:

  • The Controller shall provide the Processor with at least forty-five (45) days' prior written notice, including a detailed written explanation of why the documentation provided under Section 10.2 is insufficient;
  • The Processor shall have the right to propose alternative measures to address the Controller's concerns before agreeing to an on-site audit, and the Controller shall consider such alternatives in good faith;
  • Audits shall be conducted during normal business hours and shall not unreasonably disrupt the Processor's operations;
  • The Controller or its auditor shall execute a non-disclosure agreement on terms satisfactory to the Processor before any audit commences;
  • Audits shall be strictly limited in scope to verifying the Processor's compliance with this DPA with respect to the Controller's Personal Data, and shall not extend to the Processor's proprietary trade secrets, including the identity of Sub-processors, AI models, algorithms, source code, or technology infrastructure;
  • The Controller shall not conduct more than one (1) on-site audit per twelve (12) month period;
  • Third-party auditors must be from a reputable, independent audit firm, must not be a competitor of the Processor, and must be approved by the Processor in advance (such approval not to be unreasonably withheld);
  • The scope, timing, and duration of the audit shall be agreed in advance between the parties.

10.4 Audit Costs

The Controller shall bear all costs and expenses of any audit conducted or requested by the Controller, including the reasonable costs incurred by the Processor in facilitating such audit. Where an audit reveals a material non-compliance by the Processor with this DPA, the Processor shall bear its own costs of remediation.

11. Liability

11.1 Liability Cap

The total aggregate liability of each party under or in connection with this DPA (whether in contract, tort, negligence, breach of statutory duty, or otherwise) shall be subject to the limitations and exclusions of liability set out in Section 13 of the Agreement (Terms and Conditions). For the avoidance of doubt, the liability cap set out in Section 13.2 of the Agreement applies to claims arising under this DPA, and the aggregate liability of the Processor under both the Agreement and this DPA combined shall not exceed the cap set out in Section 13.2 of the Agreement.

11.2 Exclusions

Nothing in this Section 11 shall limit or exclude either party's liability for:

  • Liability that cannot be excluded or limited under Applicable Data Protection Law, including liability under Article 82 of the GDPR;
  • Fines, penalties, or administrative sanctions imposed by a Supervisory Authority directly on the liable party;
  • Liability arising from fraud, wilful misconduct, or gross negligence;
  • Liability that cannot be excluded or limited under the Australian Consumer Law (Schedule 2 of the Competition and Consumer Act 2010 (Cth)).

11.3 Apportionment

Where both parties are involved in the same Processing and are responsible for any damage caused by that Processing, each party shall be liable for the entire damage in accordance with Article 82(4) of the GDPR, subject to the right of contribution from the other party in respect of that party's share of responsibility for the damage.

11.4 Indemnification

Each party shall indemnify, defend, and hold harmless the other party from and against any claims, damages, losses, costs, and expenses (including reasonable legal fees) arising from the indemnifying party's breach of this DPA or Applicable Data Protection Law, subject to the limitations set out in this Section 11 and the Agreement.

12. Data Deletion & Return

12.1 Post-Termination Obligations

Upon termination or expiry of the Agreement, the Processor shall, at the Controller's written election:

  • Return: Return all Personal Data to the Controller in a structured, commonly used, and machine-readable format, where technically feasible; or
  • Delete: Delete all Personal Data and all existing copies, and certify such deletion to the Controller in writing.

The Controller must make its election in writing within thirty (30) days of the termination or expiry of the Agreement. If the Controller does not make an election within this period, the Processor shall delete all Personal Data.

12.2 Deletion Timeline

The Processor shall complete the deletion or return of Personal Data within ninety (90) days of the later of: (a) the effective date of termination or expiry of the Agreement; or (b) receipt of the Controller's written election. The Processor shall use commercially reasonable efforts to complete deletion or return as promptly as practicable.

12.3 Exceptions to Deletion

The Processor may retain Personal Data (or specific categories of Personal Data) after termination to the extent required by applicable law, including European Union or Member State law, or the laws of the Commonwealth of Australia or the State of Western Australia. Where Personal Data is retained for legal compliance purposes, the Processor shall:

  • Limit the Processing of such retained Personal Data to the purposes for which retention is required by law;
  • Implement appropriate technical and organisational measures to protect such retained Personal Data;
  • Delete such retained Personal Data as soon as the legal retention obligation expires.

12.4 Aggregated and De-identified Data

Notwithstanding the foregoing, the Processor may retain and use data that has been aggregated, anonymised, or de-identified such that it no longer constitutes Personal Data under Applicable Data Protection Law. Such data is not subject to the deletion or return obligations in this Section 12.

12.5 Backup Copies

Personal Data contained in backup systems shall be deleted in accordance with the Processor's standard backup rotation schedule, and in any event within one hundred and eighty (180) days of the deletion of the corresponding production data, unless retention is required by applicable law.

13. General Provisions

13.1 Governing Law

This DPA shall be governed by and construed in accordance with the laws of the State of Western Australia and the Commonwealth of Australia, without regard to conflict of law principles, except to the extent that:

  • The GDPR or UK GDPR mandates the application of a different governing law with respect to certain matters (in which case that mandatory law shall apply to the relevant matter);
  • The SCCs are governed by the law of the Republic of Ireland (as specified in Section 6.2);
  • The UK Addendum is governed by the laws of England and Wales.

13.2 Jurisdiction

Subject to the jurisdiction provisions of the SCCs and UK Addendum (which shall apply to disputes arising under those instruments), the parties submit to the exclusive jurisdiction of the courts of Western Australia and the Federal Court of Australia (sitting in Perth) for the resolution of any dispute arising out of or in connection with this DPA. Nothing in this section limits the right of a Data Subject or Supervisory Authority to bring proceedings in the courts of any jurisdiction as permitted under Applicable Data Protection Law.

13.3 Severability

If any provision of this DPA is held to be invalid, illegal, or unenforceable, such provision shall be severed from this DPA and the remaining provisions shall continue in full force and effect. The parties shall negotiate in good faith to replace the invalid provision with a valid provision that achieves the same economic and legal effect to the greatest extent possible.

13.4 Amendments

Oppermind reserves the right to update this DPA from time to time to reflect changes in Applicable Data Protection Law, regulatory guidance, or Oppermind's Processing activities. Material changes will be notified to the Controller via the email address associated with the Controller's account at least thirty (30) days before the changes take effect. If the Controller does not agree to a material change, the Controller may terminate the Agreement by providing written notice within the thirty (30) day notice period, and shall be entitled to a pro-rata refund of any prepaid fees attributable to the period after the effective date of termination. The Controller's continued use of the Service after the effective date of the updated DPA constitutes acceptance of the updated DPA. Non-material changes (such as formatting, typographical corrections, or clarifications that do not alter the substance of the Controller's or Processor's obligations) do not require advance notification but will be reflected in the "Last updated" date of this DPA.

13.5 Entire Agreement

This DPA, together with the Agreement (including the Privacy Policy) and the SCCs and UK Addendum incorporated herein, constitutes the entire agreement between the parties with respect to the Processing of Personal Data by the Processor on behalf of the Controller and supersedes all prior representations, understandings, and agreements relating to such Processing.

13.6 Notices

All notices under this DPA shall be sent in accordance with the notice provisions of the Agreement. Notices to the Processor shall be addressed to enquiry@oppermind.com. Notices to the Controller shall be sent to the email address associated with the Controller's account.

13.7 No Third-Party Beneficiaries

This DPA does not confer any rights on any person or party other than the parties to this DPA and their respective successors and permitted assigns, except to the extent that Data Subjects have rights under the SCCs, the UK Addendum, or Applicable Data Protection Law that cannot be excluded by contract.

13.8 Survival

The provisions of this DPA that by their nature should survive termination or expiry of the Agreement shall survive, including Sections 3A (AI-Specific Processing Obligations, to the extent relevant to post-termination Processing), 7 (Data Breach), 10 (Audit), 11 (Liability), 12 (Data Deletion and Return), and 13 (General Provisions).

13.9 Australian Privacy Principles — Cross-Border Disclosure (APP 8)

The Processor acknowledges that, under Australian Privacy Principle 8 (APP 8) of the Privacy Act 1988 (Cth), an entity that discloses Personal Data to an overseas recipient is generally accountable for the acts and practices of that recipient, and that under section 16C of the Privacy Act 1988, the disclosing entity is taken to have breached the APPs if the overseas recipient acts in a manner that would constitute a breach, regardless of the contractual protections in place. The Processor shall:

  • Ensure that all Sub-processors located outside Australia that receive Personal Data of Australian Data Subjects are bound by enforceable contractual obligations that are substantially similar to the Australian Privacy Principles;
  • Take reasonable steps to ensure that such Sub-processors do not act in a manner that would constitute a breach of the Australian Privacy Principles in relation to the Personal Data;
  • Implement appropriate technical and organisational safeguards consistent with Australian Privacy Principle 11 (APP 11) — security of personal information — to protect Personal Data from misuse, interference, loss, and from unauthorised access, modification, or disclosure;
  • Cooperate with the Controller in responding to any enquiry, complaint, or investigation by the Office of the Australian Information Commissioner (OAIC) or a recognised external dispute resolution scheme in relation to Personal Data Processed under this DPA.

13.10 Future Law & Regulatory Change

The Processor shall use reasonable efforts to monitor changes to Applicable Data Protection Law, regulatory guidance, and enforcement action that may affect the Processing of Personal Data under this DPA. Where a change in law or regulation materially affects the Processor's obligations under this DPA, the Processor shall notify the Controller and, where necessary, propose amendments to this DPA to ensure continued compliance. The Processor shall cooperate with the Controller in implementing any changes required by new or amended Applicable Data Protection Law, including (without limitation) the anticipated reforms to the Privacy Act 1988 (Cth) as recommended by the Attorney-General's Department Privacy Act Review.


Annex I: Details of Processing

This Annex I forms part of the DPA and the SCCs (where applicable), and sets out the details of the Processing of Personal Data by the Processor on behalf of the Controller.

A. List of Parties

Data Exporter (Controller) The individual or entity that has entered into the Agreement and uses the Service. The data exporter's identity, contact details, and (where applicable) data protection officer details are as set out in the data exporter's account registration with the Service.
Data Importer (Processor) Oppermind Pty Ltd (ABN 89 689 605 918), a company registered in Western Australia, Australia, operating from Perth, Western Australia. Contact: enquiry@oppermind.com.

B. Description of Transfer

Categories of Data Subjects
  • Users of the Service (registered account holders)
  • Third parties whose Personal Data is contained within content uploaded, submitted, or processed by the Controller through the Service (e.g., email correspondents, document subjects, contacts referenced in user content)
Categories of Personal Data
  • Account data: name, email address, hashed password
  • AI interaction data: prompts, queries, responses, conversation history
  • User content: documents, images, files, media, and associated metadata
  • Email data: email content, headers, attachments, encrypted credentials (where email integration is used)
  • Agent data: file operations data, screen data, system interaction data (where agent feature is used)
  • AI-generated outputs: text, images, video, code
  • Payment identifiers: subscription IDs, billing status
  • Technical data: IP address, browser type, operating system, session identifiers, device identifiers
  • Security data: authentication logs, access logs, content moderation records
Sensitive Data The Processor does not intentionally collect or Process special categories of data (Article 9 GDPR) or criminal conviction data (Article 10 GDPR). However, the Controller may submit content that includes such data. Where the Controller Processes special categories of data through the Service, the Controller is solely responsible for ensuring a lawful basis for such Processing, including obtaining explicit consent from Data Subjects where required.
Frequency of Transfer Continuous, as initiated by the Controller's use of the Service.
Nature of Processing Collection, storage, organisation, retrieval, consultation, use, disclosure by transmission to Sub-processors, alignment, combination, restriction, erasure, and destruction, as necessary to provide the Service.
Purpose of Transfer and Further Processing Provision of the Oppermind AI workspace platform and related services, including: account management and authentication; AI request processing; content storage and retrieval; email integration services; autonomous agent operations; payment facilitation; security and content moderation; and service improvement using aggregated and de-identified data.
Retention Period Personal Data is retained for the duration of the Agreement and thereafter in accordance with Section 12 of the DPA and the Processor's Privacy Policy (Section 7).

C. Competent Supervisory Authority

The competent supervisory authority is determined in accordance with Section 6.2 (Clause 13(a)) of this DPA. Where the Controller is established in the EU, the competent authority is the supervisory authority of the Member State in which the Controller is established. Where the Controller is established in the UK, the competent authority is the Information Commissioner's Office (ICO).


Annex II: Technical & Organisational Measures

This Annex II forms part of the DPA and the SCCs (where applicable), and describes the technical and organisational security measures implemented by the Processor pursuant to Article 32 of the GDPR. The specific details and configurations of these measures are proprietary and confidential.

1. Encryption

Measure Description
Encryption in Transit All data transmitted between users and the Service, and between the Service and Sub-processors, is encrypted using industry-standard TLS (Transport Layer Security) protocols. The Processor enforces a minimum of TLS 1.2 and supports TLS 1.3. HTTP Strict Transport Security (HSTS) headers are implemented to prevent protocol downgrade attacks.
Encryption at Rest All Personal Data stored on the Processor's infrastructure and Sub-processor infrastructure is encrypted at rest using industry-standard encryption algorithms (AES-256 or equivalent). Database-level, storage-level, and backup encryption are implemented. Encryption keys are managed using dedicated key management services with appropriate access controls and key rotation policies.
Credential Encryption User passwords are stored using one-way cryptographic hashing with salt. Email integration credentials and other sensitive credentials are stored using authenticated encryption. Encryption keys for credentials are stored separately from the encrypted data.

2. Access Controls

Measure Description
Authentication The Service implements secure authentication mechanisms for all user accounts, including password-based authentication with enforced complexity requirements and session management with token-based authentication. Session tokens have defined expiry periods and are invalidated upon logout.
Authorisation Role-based access controls (RBAC) are implemented across the Service infrastructure. Access to Personal Data is restricted to authorised personnel on a need-to-know basis. Administrative access to production systems requires authenticated, audited access with appropriate privilege separation.
Infrastructure Access Access to the Processor's cloud infrastructure is restricted to authorised personnel. Infrastructure access is managed through the cloud provider's identity and access management (IAM) systems. All administrative access is logged and auditable.
Logical Separation User data is logically separated such that each user can access only their own data. Application-level access controls enforce data isolation between user accounts.

3. Pseudonymisation

Measure Description
Internal Identifiers Where practicable, the Processor uses internal pseudonymous identifiers (such as system-generated user IDs) rather than directly identifying information for internal processing and analytics purposes.
De-identification Data used for service improvement and analytics is aggregated and de-identified to the extent reasonably practicable, such that it cannot be attributed to a specific Data Subject without the use of additional information.

4. Incident Detection & Response

Measure Description
Monitoring The Processor implements monitoring and alerting systems to detect potential security incidents, including intrusion detection, anomaly detection, and automated threat analysis. Web Application Firewall (WAF) policies are implemented and actively maintained to detect and block malicious traffic and automated attacks.
Incident Response Plan The Processor maintains a documented incident response plan that includes procedures for identification, containment, eradication, recovery, and post-incident analysis. The plan includes defined escalation procedures and communication protocols for notifying affected parties.
Logging & Audit Trail Security-relevant events are logged, including authentication events, access to Personal Data, administrative actions, and system changes. Logs are retained for a period sufficient to support security investigations and are protected against unauthorised modification.
Vulnerability Management The Processor conducts regular vulnerability assessments and applies security patches and updates in a timely manner. Dependencies are monitored for known vulnerabilities.

5. Business Continuity & Availability

Measure Description
Backup & Recovery The Processor implements regular automated backups of Personal Data. Backups are encrypted and stored in a geographically separate location from production data. Backup restoration procedures are tested periodically.
Infrastructure Redundancy The Service is hosted on cloud infrastructure with built-in redundancy and high availability capabilities. The Processor leverages the cloud provider's infrastructure resilience, including redundant power, cooling, and network connectivity.
Disaster Recovery The Processor maintains disaster recovery capabilities appropriate to the scale and criticality of the Service. Recovery procedures are documented and periodically reviewed.

6. Staff & Organisational Measures

Measure Description
Confidentiality Obligations All personnel with access to Personal Data are bound by confidentiality obligations, whether by contract or statutory duty. Access to Personal Data is granted only to personnel whose role requires such access.
Training Personnel with access to Personal Data receive training on data protection principles, security practices, and the Processor's obligations under Applicable Data Protection Law. Training is provided upon onboarding and refreshed periodically.
Acceptable Use The Processor maintains internal policies governing the acceptable use of systems, data handling procedures, and security requirements for personnel.

7. Sub-processor Due Diligence

Measure Description
Selection & Assessment Before engaging a Sub-processor, the Processor conducts due diligence to assess the Sub-processor's technical and organisational security measures, data protection practices, and compliance posture. Sub-processors are selected based on their ability to provide sufficient guarantees under Article 28(1) of the GDPR.
Contractual Safeguards All Sub-processors are bound by written data processing agreements that impose obligations no less protective than those in this DPA, including obligations regarding security, confidentiality, data breach notification, and restrictions on Processing.
Ongoing Monitoring The Processor periodically reviews the data protection and security practices of its Sub-processors. Where a Sub-processor is found to be non-compliant, the Processor takes appropriate remedial action, which may include termination of the Sub-processor relationship.

8. Content Safety & Moderation

Measure Description
Automated Content Safety The Processor implements automated content safety and moderation systems to detect and prevent the generation or distribution of harmful, illegal, or prohibited content through the Service, in accordance with the Acceptable Use Policy set out in the Agreement.
Abuse Prevention The Processor employs bot detection, rate limiting, and web application firewall technologies to detect and prevent automated abuse, credential stuffing, and other malicious activity.

Annex III: Sub-processor List

This Annex III forms part of the DPA and the SCCs (where applicable). In accordance with the trade secret protections set out in the Agreement (Sections 6.4 and 6.5), Sub-processors are listed by function and jurisdiction only.

Function Processing Activity Jurisdiction(s) Transfer Mechanism
AI Model Providers Processing of AI requests (prompts, queries, conversation context, uploaded content) to generate AI responses and outputs Australia; United States; may include additional jurisdictions SCCs (Module Two); UK Addendum
Cloud Infrastructure Provider Hosting, storage, compute, networking, and database infrastructure for the Service, including backup and disaster recovery Australia; United States; may include additional jurisdictions SCCs (Module Two); UK Addendum (for non-adequate jurisdictions)
Payment Processor Processing of subscription payments, billing, invoicing, and payment card data (PCI-DSS compliant) United States; Ireland SCCs (Module Two); UK Addendum
Bot Detection & Abuse Prevention Analysis of device and application data for automated threat detection, bot identification, and abuse prevention Australia; United States; may include additional jurisdictions SCCs (Module Two); UK Addendum

The Controller has granted a general written authorisation for the engagement of the above Sub-processors in accordance with Section 5.1 of this DPA. Changes to this list will be notified to the Controller in accordance with Section 5.3.


Annex IV: UK International Data Transfer Addendum

This Annex IV incorporates by reference the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, as issued by the Information Commissioner under Section 119A(1) of the Data Protection Act 2018, Version B1.0, in force 21 March 2022 (the "UK Addendum"). The UK Addendum is available at ico.org.uk.

Mandatory Clauses of the UK Addendum

The tables of the UK Addendum are completed as follows:

Table Content
Table 1: Parties Start Date: The date on which the Controller creates an account with the Service, or the effective date of this DPA (22 May 2026), whichever is later.
Exporter: The Controller (as identified in Annex I, Section A).
Importer: Oppermind Pty Ltd (ABN 89 689 605 918), Perth, Western Australia, Australia. Contact: enquiry@oppermind.com.
Key Contact (Importer): Data Protection Lead, enquiry@oppermind.com.
Table 2: Selected SCCs, Modules and Selected Clauses The Approved EU SCCs are the SCCs incorporated by reference in Section 6.2 of this DPA, being the Standard Contractual Clauses set out in the Annex to the European Commission Implementing Decision (EU) 2021/914.

Module in operation: Module Two (Controller to Processor).
Selected clauses and optional elements: As specified in Section 6.2 of this DPA (including Clause 7 docking clause, Clause 9(a) Option 2, Clause 17 Option 1 with the law of Ireland, and Clause 18(b) with the courts of Ireland).
Table 3: Appendix Information Annex 1A (List of Parties): As set out in Annex I, Section A of this DPA.
Annex 1B (Description of Transfer): As set out in Annex I, Section B of this DPA.
Annex II (Technical and Organisational Measures): As set out in Annex II of this DPA.
Annex III (List of Sub-processors): As set out in Annex III of this DPA (Section 5.2).
Table 4: Ending this Addendum when the Approved Addendum Changes Either party may end this UK Addendum as set out in Section 19 of the Mandatory Clauses of the UK Addendum.

For transfers of Personal Data from the United Kingdom, the UK Addendum shall be read and interpreted in accordance with the UK GDPR and the Data Protection Act 2018. Where the UK Addendum conflicts with the SCCs, the UK Addendum shall prevail to the extent of the conflict.


Contact

For questions, requests, or notices relating to this Data Processing Addendum, please contact us:

  • Email: enquiry@oppermind.com
  • Subject Line: "DPA Enquiry" (for general enquiries) or "Enterprise DPA Request" (for bespoke agreements)
  • Entity: Oppermind Pty Ltd (ABN 89 689 605 918)
  • Location: Perth, Western Australia, Australia

For privacy-related enquiries, please refer to our Privacy Policy. For general terms of service, please refer to our Terms and Conditions.

© 2026 Oppermind Pty Ltd. All rights reserved.
Terms Privacy AUP DPA Cookies Refunds Accessibility Children's Privacy Withdraw consent