This document is published in English. The English text is the governing version.
The terms on which we process personal data on your behalf, with the processing annexes.
1. Introduction
This Data Processing Agreement (“DPA”) forms part of the agreement between the customer (“Customer”, “Controller” or “you”) and AI Solution Technologies Pty Ltd (“AI Solution Technologies”, “Processor”, “we”, “us” or “our”) for the provision of the Hivenox platform (the “Principal Agreement”). It applies where we process Personal Data contained in Customer Data on the Customer’s behalf. Where there is any conflict between this DPA and the Principal Agreement regarding data protection, this DPA prevails.
2. Definitions
“Data Protection Laws” means all applicable laws relating to the processing of Personal Data, including the Privacy Act 1988 (Cth) and the Australian Privacy Principles, and, where applicable, the EU GDPR and UK GDPR. “Personal Data”, “Controller”, “Processor”, “Data Subject”, “process/processing” and “Sub-processor” have the meanings given in the applicable Data Protection Laws. “Customer Data” has the meaning given in the Principal Agreement. Other terms have the meaning given in the Principal Agreement.
3. Roles of the parties
The Customer is the Controller (or processor acting on behalf of a third-party controller) of Personal Data in Customer Data, and we are the Processor. Each party will comply with its obligations under the Data Protection Laws. The Customer is responsible for the accuracy, quality and legality of Customer Data and for having a lawful basis to provide it to us for processing.
4. Scope and instructions
We process Personal Data only on the Customer’s documented instructions — including as set out in this DPA, the Principal Agreement, and the Customer’s configuration and use of the Service — unless required otherwise by law (in which case, where permitted, we will inform the Customer first). The subject matter, duration, nature and purpose of processing, types of Personal Data and categories of Data Subjects are described in Annex A.
5. Our obligations as Processor
We will:
- process Personal Data only to provide and support the Service and as instructed;
- ensure personnel authorised to process Personal Data are bound by confidentiality;
- implement and maintain the security measures described in Annex B;
- assist the Customer, taking into account the nature of processing, in responding to Data Subject requests and in meeting obligations regarding security, breach notification, data protection impact assessments and prior consultation;
- make available information reasonably necessary to demonstrate compliance; and
- at the Customer’s choice, delete or return Personal Data at the end of the Service, as described in clause 11.
6. Confidentiality
We keep Personal Data confidential and disclose it only as permitted under this DPA or the Principal Agreement, or as required by law. Access is limited to personnel and Sub-processors who need it to provide the Service.
7. Security
Taking into account the state of the art, costs of implementation, and the nature, scope, context and purposes of processing, as well as the risk to Data Subjects, we implement appropriate technical and organisational measures (Annex B) to ensure a level of security appropriate to the risk. Our information security and AI governance are aligned with ISO/IEC 27001 and ISO/IEC 42001.
8. Sub-processors
The Customer provides general authorisation for us to engage Sub-processors to provide the Service, including the categories listed in Annex C. We impose data protection obligations on each Sub-processor that are no less protective than those in this DPA and remain responsible for their performance. We will maintain an up-to-date list of Sub-processors and give the Customer reasonable notice of intended additions or replacements, and the Customer may object on reasonable data protection grounds.
9. Data Subject rights
Taking into account the nature of the processing, we will assist the Customer by appropriate technical and organisational measures, insofar as possible, to respond to Data Subject requests. The Service provides self-service tools that enable the Customer to access, correct, export and delete Personal Data. If we receive a request directly from a Data Subject, we will, where legally permitted, promptly direct them to the Customer and not respond except on the Customer’s instructions.
10. Data breach notification
We will notify the Customer without undue delay after becoming aware of a Personal Data breach affecting the Customer’s Personal Data, and will provide information reasonably available to assist the Customer in meeting its obligations to notify supervisory authorities, the OAIC (under the Notifiable Data Breaches scheme) and/or affected individuals.
11. Return and deletion
On termination or expiry, or on the Customer’s earlier written request, we will (at the Customer’s choice) delete or return Personal Data and delete existing copies, unless retention is required by law. The Service provides export functionality for a limited period after termination, after which Personal Data may be deleted. Where deletion is not immediately practicable (for example, in backups), we securely isolate the data and protect it from further processing until deletion.
12. International transfers
We may process Personal Data in locations outside Australia, and outside the EEA or UK where the GDPR or UK GDPR applies, including in the United States, the United Arab Emirates and the Kingdom of Saudi Arabia. Where required by Data Protection Laws, we implement an appropriate transfer mechanism, such as the European Commission’s Standard Contractual Clauses (with the UK Addendum where applicable), and take reasonable steps to ensure overseas recipients handle Personal Data consistently with the Australian Privacy Principles. Where offered, the Customer may select a preferred hosting region.
13. Audits
We will make available information reasonably necessary to demonstrate compliance and will contribute to audits conducted by the Customer or its mandated auditor, subject to reasonable notice, confidentiality, and no more than once per year (except following a Personal Data breach or where required by a regulator). We may satisfy audit requests by providing current certifications and third-party audit reports. The Customer bears its own audit costs.
14. Liability
Each party’s liability under this DPA is subject to the limitations and exclusions in the Principal Agreement. Nothing in this DPA limits liability that cannot be limited under applicable law.
15. Governing law
This DPA is governed by the same law as the Principal Agreement or, where none is specified, the laws of New South Wales, Australia.
16. Effect
This DPA is effective from 1 January 2026 or the commencement date of the Principal Agreement, whichever is later, and continues for as long as we process Personal Data on the Customer’s behalf.
Annex A — Details of processing
| Item | Description |
|---|---|
| Subject matter | Provision of the Hivenox SaaS platform, including ERP, CRM, HRMS, finance, service desk, operations, analytics and AI agent modules. |
| Duration | For the term of the Principal Agreement and any period during which we process Personal Data on the Customer’s behalf. |
| Nature and purpose | Hosting, storage, collection, structuring, analysis, transmission, display and other processing necessary to provide, secure, support and improve the Service, including AI-assisted features configured by the Customer. |
| Types of Personal Data | As determined by the Customer through its use of the Service, which may include identity and contact details, employment and HR data, customer and prospect records, financial and transaction data, communications, and usage data. Special category data only where the Customer chooses to input it. |
| Categories of Data Subjects | As determined by the Customer, which may include the Customer’s employees, contractors, job applicants, customers, prospects, suppliers and other individuals whose data the Customer processes in the Service. |
Annex B — Technical and organisational measures
We maintain technical and organisational measures appropriate to the risk, which include:
- access controls, including role-based access, least-privilege principles and multi-factor authentication;
- encryption of Personal Data in transit and at rest;
- network security, including firewalls, segmentation, monitoring and vulnerability management;
- secure software development lifecycle and change management;
- logical separation of Customer environments in a multi-tenant architecture;
- backup, business continuity and disaster recovery arrangements;
- personnel confidentiality obligations and security awareness training;
- vendor and Sub-processor risk management;
- logging, monitoring, alerting and incident response; and
- information security and AI governance aligned with ISO/IEC 27001 and ISO/IEC 42001.
Annex C — Categories of Sub-processors
We engage Sub-processors in the following categories to provide the Service. A current list of specific Sub-processors is made available to Customers on request or through the Service.
| Category | Purpose |
|---|---|
| Cloud infrastructure and hosting | Hosting, storage, compute and networking for the Service (e.g. Microsoft Azure, Amazon Web Services). |
| AI model and processing providers | Providing generative and analytical AI capabilities used by AI features. |
| Communications and email delivery | Sending transactional and notification messages. |
| Analytics and monitoring | Product analytics, performance monitoring and error reporting. |
| Payment processing | Processing subscription payments (card data handled by the processor, not stored by us). |
| Customer support tooling | Managing and responding to support requests. |
Contact Us
For questions about this DPA or our data processing practices, please contact us using the details below.
Hivenox — operated by AI Solution Technologies Pty Ltd
- Registered officeSuite 6, 191 Church Street
Parramatta, Sydney NSW 2150 - Privacy Officerinfo@hivenox.com
- Phone+61 466 558 962
- Webhivenox.com