Data Processing Addendum
Effective 2026-08-10

Onedash processes personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles to the extent applicable. Where applicable to the relevant processing, Onedash also processes personal data in accordance with other applicable data protection and privacy laws, including the European Union General Data Protection Regulation, the United Kingdom General Data Protection Regulation, the Swiss Federal Act on Data Protection, the California Consumer Privacy Act, the Personal Information Protection and Electronic Documents Act of Canada, and Brazil's Lei Geral de Proteção de Dados.

To better protect individuals' personal data, these terms govern Onedash's and Customer's respective handling of personal data in connection with the Services. This Data Processing Addendum ("DPA") forms part of and supplements the Onedash Terms of Service ("Terms") and any applicable Order. This DPA applies where Onedash processes Customer Personal Data on behalf of Customer in connection with the Services. This DPA does not apply to personal information that Onedash processes as an independent Controller for its own legitimate business purposes, including account administration, billing, direct communications, security administration, and other processing described in the Onedash Privacy Policy.

This DPA also does not apply to data that remains exclusively on Customer's device or systems and is not transmitted to, stored by, or otherwise processed by Onedash. By using the Services and providing Customer Personal Data to Onedash for processing, Customer agrees to this DPA. No separate signature is required unless applicable law, an Order, or another agreement between the parties requires one. If Customer does not agree to this DPA, Customer must not provide Customer Personal Data to Onedash for processing and may discontinue use of the affected Services in accordance with the Terms. If there is a conflict between this DPA and the Terms concerning the processing of Customer Personal Data, this DPA will prevail to the extent of that conflict.

If an applicable Standard Contractual Clause, mandatory data transfer agreement, or other mandatory provision of Data Protection Law conflicts with this DPA, that mandatory provision will prevail to the extent of the conflict.

Definitions

It is important that the parties understand what data and whose data is protected under this DPA. Each party has respective obligations to protect personal data. The following definitions explain the scope of this DPA and the parties' respective commitments.

"Onedash", "we", "us", or "our" refers to the provider of the Onedash Services identified under the Terms.

"Customer", "you", or "your" refers to the individual, company, organisation, or other entity that has entered into the Terms or an applicable Order and uses the Services.

"Party" refers to Onedash or Customer depending on the context, and "Parties" means both.

"Authorised User" has the meaning given in the Terms.

"Customer Personal Data" means Personal Data that Onedash processes on behalf of Customer in connection with Customer's use of the Services. Customer Personal Data does not include personal information that Onedash processes as an independent Controller for its own purposes as described in the Privacy Policy.

"Data Subject" means an identified or identifiable natural person to whom Personal Data relates, or an equivalent term under applicable Data Protection Law.

"Personal Data" means information relating to an identified or identifiable natural person and includes "personal information", "personal data", and equivalent concepts under applicable Data Protection Law.

"Sensitive Personal Data" means Personal Data subject to enhanced protection under applicable Data Protection Law, including where applicable information concerning health, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data used for identification, sexual orientation, sex life, or criminal convictions and offences.

"Controller" means a person or entity that determines the purposes and means of Processing Personal Data and includes equivalent concepts such as a "business" where applicable.

"Processor" means a person or entity that Processes Personal Data on behalf of a Controller and includes equivalent concepts such as an "operator" or "service provider" where applicable.

"Subprocessor" means a third party engaged by Onedash to Process Customer Personal Data on behalf of Customer in connection with the Services.

"Personnel" means employees, contractors, and other individuals authorised to perform services on behalf of a Party.

"Processing", "Process", and "Processed" mean any operation or set of operations performed on Personal Data, whether or not by automated means, including collection, recording, organisation, structuring, storage, alteration, retrieval, consultation, use, disclosure, transmission, combination, restriction, erasure, or destruction.

"Security Incident" means a confirmed breach of security resulting in the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Customer Personal Data Processed by Onedash.

A Security Incident does not include unsuccessful attempts or activities that do not compromise the security of Customer Personal Data, such as unsuccessful login attempts, port scans, pings, denial-of-service attempts that do not result in unauthorised access, blocked malware, or other unsuccessful attacks.

"Data Subject Request" means a request by a Data Subject to exercise a right under applicable Data Protection Law in relation to Customer Personal Data.

"Data Protection Law" means all privacy and data protection laws that are applicable to a Party's Processing under this DPA, including where applicable:

  • (a) the Privacy Act 1988 (Cth) and the Australian Privacy Principles;
  • (b) regulation (EU) 2016/679 ("EU GDPR");
  • (c) the EU GDPR as incorporated into United Kingdom law and the Data Protection Act 2018 ("UK GDPR");
  • (d) the Swiss Federal Act on Data Protection ("Swiss FADP");
  • (e) the California Consumer Privacy Act, as amended ("CCPA");
  • (f) the Personal Information Protection and Electronic Documents Act of Canada ("PIPEDA");
  • (g) Brazil's Lei Geral de Proteção de Dados ("LGPD"); and
  • (h) any legislation replacing, amending, or supplementing those laws.

"EU Standard Contractual Clauses" or "EU SCCs" means the standard contractual clauses for the transfer of Personal Data to third countries adopted by the European Commission under Commission Implementing Decision (EU) 2021/914, as amended, replaced, or superseded from time to time.

"UK Addendum" means the United Kingdom International Data Transfer Addendum to the EU Standard Contractual Clauses issued by the United Kingdom Information Commissioner's Office, as revised or replaced from time to time.

"Training Datasets" has the meaning given in the Terms and means datasets created by Onedash using information that has been de-identified or aggregated so that it no longer identifies Customer or an individual in accordance with applicable law.

"Services" has the meaning given in the Terms.

Defined terms retain their meaning regardless of capitalisation unless the context requires otherwise.

1. Undertakings Regarding Customer Personal Data

1.1 Confidentiality and Compliance

Each Party agrees that Customer Personal Data will be treated as confidential information. Each Party will comply with Data Protection Law applicable to its Processing of Customer Personal Data. Customer acknowledges that Customer is ordinarily the Controller of Customer Personal Data and Onedash is ordinarily the Processor of that Customer Personal Data. Where Customer itself acts as a Processor for another Controller, Onedash will act as Customer's Subprocessor to the extent applicable. Customer retains control of Customer Personal Data and determines the purposes for which Customer Personal Data is Processed except where Onedash is required to Process the information independently under applicable law.

1.2 Customer Instructions

Onedash will Process Customer Personal Data only:

  • (a) to provide, operate, maintain, secure, and support the Services;
  • (b) in accordance with the Terms, this DPA, an applicable Order, and Customer's configuration of the Services;
  • (c) on Customer's documented instructions;
  • (d) to provide support or assistance requested by Customer;
  • (e) as necessary to comply with applicable law; and
  • (f) as otherwise expressly permitted under this DPA.

The Terms, this DPA, applicable Orders, Customer's use and configuration of the Services, and documented requests submitted by Customer constitute Customer's documented instructions to Onedash. Customer may provide additional written instructions provided those instructions are consistent with the Agreement, technically and commercially reasonable, and agreed by Onedash where they require a material change to the Services or Onedash's Processing. If Onedash believes that a Customer instruction infringes applicable Data Protection Law, Onedash may inform Customer and suspend the affected Processing until the parties resolve the issue. Nothing in this DPA requires Onedash to comply with an instruction that would cause Onedash to violate applicable law.

1.3 Access to Customer Personal Data

Onedash will ensure that access to Customer Personal Data is limited to Personnel and Subprocessors that require such access to perform Onedash's obligations, provide the Services, maintain security, or otherwise carry out Processing authorised under this DPA. Onedash will ensure that Personnel authorised to Process Customer Personal Data are subject to appropriate confidentiality obligations. Onedash may access Customer Personal Data where reasonably necessary to provide support, investigate technical issues, maintain or secure the Services, respond to Customer requests, or otherwise perform its obligations under the Agreement.

Where Customer requests support that requires access to Customer Personal Data, that request constitutes an instruction authorising Onedash to perform the Processing reasonably necessary to investigate, diagnose, and resolve the relevant issue.

1.4 Disclosure

Onedash will not disclose Customer Personal Data to a third party except:

  • (a) to an authorised Subprocessor;
  • (b) as instructed by Customer;
  • (c) where reasonably necessary to provide the Services;
  • (d) where required by applicable law, court order, or lawful governmental request; or
  • (e) as otherwise permitted by this DPA.

Where legally permitted, Onedash will use reasonable efforts to notify Customer before disclosing Customer Personal Data in response to a compulsory governmental or legal request.

1.5 Data Ownership

As between the Parties, Customer retains all rights Customer has in Customer Personal Data.

Nothing in this DPA transfers ownership of Customer Personal Data to Onedash.

1.6 De-Identified Data and Training Datasets

The Parties acknowledge that the Terms permit Onedash to create de-identified or aggregated information from Customer Data, including for the creation of Training Datasets. Subject to applicable Data Protection Law and Customer's applicable opt-out rights, Customer instructs Onedash to Process Customer Personal Data to the extent reasonably necessary to create de-identified or aggregated information for the purposes permitted by the Terms. Onedash will take reasonable measures designed to ensure that information treated as de-identified, anonymised, or aggregated under this Section cannot reasonably identify Customer or a Data Subject and satisfies applicable legal requirements for treatment as de-identified or anonymous information.

Onedash will not intentionally attempt to re-identify information that Onedash treats as de-identified for Training Dataset purposes except where necessary to test or verify the effectiveness of Onedash's de-identification measures and where permitted by applicable law. Once information has been de-identified or anonymised such that it no longer constitutes Personal Data under applicable Data Protection Law, that information is no longer Customer Personal Data for the purposes of this DPA. Onedash may use such de-identified information and Training Datasets in accordance with the Terms, including for lawful business purposes, research, analysis, development, evaluation, testing, security, improvement, training, and fine-tuning of artificial intelligence and machine-learning systems.

Customer may opt out of the use of Customer Data for the creation of future Training Datasets as provided in the Terms and Onedash AI Transparency Policy. An opt-out applies prospectively within a reasonable period after Onedash receives and verifies the request.

An opt-out does not require Onedash to:

  • (a) reverse completed artificial intelligence or machine-learning training;
  • (b) remove information from a dataset that has already been irreversibly de-identified or aggregated so that it no longer constitutes Personal Data; or
  • (c) reconstruct or alter a model where the influence of previously de-identified training information cannot reasonably be isolated.

Customer Personal Data subject to an applicable Business Associate Agreement will not be used for Training Datasets except where expressly permitted by that Business Associate Agreement or another written agreement that complies with applicable law. Customers with an applicable Business Associate Agreement are automatically excluded from the Training Dataset programme unless otherwise expressly agreed in writing.

1.7 Local Processing

Certain Onedash functionality may Process information entirely on Customer's device.

Where information remains exclusively on Customer's device and is not transmitted to Onedash or an Onedash Subprocessor, Onedash does not Process that information as a Processor and that information is outside the scope of this DPA. The fact that a feature is available through the Onedash Application does not by itself mean that data handled by that feature is transmitted to Onedash.

1.8 Return and Deletion

Upon expiration or termination of the Services, Onedash will delete or, where supported by the Services and requested by Customer, make available Customer Personal Data in accordance with the Terms and Onedash's standard retention and backup procedures. Customer is responsible for exporting Customer Personal Data that Customer wishes to retain before the applicable deletion or recovery period expires. Customer Personal Data associated with a recently cancelled Account may remain recoverable for the limited recovery period specified in the Terms where Onedash's systems support restoration. Residual copies may remain in backups, disaster recovery systems, security records, or other systems where immediate deletion is not technically practicable.

Any retained Customer Personal Data will remain subject to this DPA and will not be Processed for an unrelated purpose. Onedash may retain Customer Personal Data for longer where required by law or reasonably necessary to establish, exercise, or defend legal rights.

2. Undertakings Regarding Subprocessors

2.1 General Authorisation

Customer provides Onedash with general written authorisation to engage Subprocessors to Process Customer Personal Data for the purpose of providing, supporting, securing, and operating the Services. This authorisation constitutes Customer's prior written consent to Subprocessing where such consent is required under Data Protection Law.

2.2 Subprocessor Obligations

Before permitting a Subprocessor to Process Customer Personal Data, Onedash will enter into a written agreement with that Subprocessor that contains data protection obligations appropriate to the Processing and, where required by applicable law, obligations substantially equivalent to the relevant obligations imposed on Onedash under this DPA. Onedash will take reasonable steps to assess the privacy and security practices of its Subprocessors having regard to the nature of the Processing and the risks involved. Onedash will remain responsible for the performance of its Subprocessors to the extent required by applicable Data Protection Law.

2.3 Subprocessor List

Onedash will make a current list of material Subprocessors that Process Customer Personal Data available through the Onedash website or another location made available to Customer.

The list may identify, as applicable:

  • (a) the name of the Subprocessor;
  • (b) the service provided;
  • (c) the location or relevant processing region; and
  • (d) the nature of the Processing.

2.4 Changes to Subprocessors

Onedash may add, remove, or replace Subprocessors from time to time.

Where required under applicable Data Protection Law, Onedash will provide Customer with reasonable advance notice of a new Subprocessor that will Process Customer Personal Data. Where Onedash provides a Subprocessor notification subscription, Customer is responsible for subscribing to that notification mechanism and maintaining current contact details. For transfers governed by the EU SCCs using general Subprocessor authorisation, Onedash will provide at least 10 days' notice of an intended new or replacement Subprocessor before that Subprocessor begins Processing Customer Personal Data, unless a shorter period is reasonably necessary to address an urgent security, availability, or legal issue.

2.5 Objections

Customer may object to the appointment of a new Subprocessor on reasonable grounds relating specifically to the protection of Customer Personal Data. Customer must submit any objection promptly after receiving notice and provide reasonable details explaining the basis of the objection. Onedash will use reasonable efforts to work in good faith with Customer to address a valid objection. If the Parties cannot resolve the objection and Onedash cannot reasonably provide the affected Service without the Subprocessor, Customer may discontinue the affected portion of the Services in accordance with the Terms. An objection does not entitle Customer to a refund except where required by the Terms or applicable law.

3. Customer Undertakings and Onedash Assistance

3.1 Customer Authority

Customer warrants that it has all rights, permissions, consents, authorisations, and lawful bases necessary to provide Customer Personal Data to Onedash for Processing under the Agreement. Customer will not instruct Onedash to Process Customer Personal Data in violation of applicable Data Protection Law.

3.2 Customer Responsibilities

To the extent Customer acts as Controller, Customer is responsible for:

  • (a) determining the lawfulness of Customer's Processing;
  • (b) determining the purposes and means of Processing;
  • (c) providing all notices required to Data Subjects;
  • (d) obtaining and maintaining any consent or authorisation required by applicable law;
  • (e) responding to Data Subject Requests;
  • (f) maintaining appropriate records of Processing where required;
  • (g) performing any required privacy impact or data protection impact assessments;
  • (h) conducting any transfer impact, transfer risk, or equivalent assessments for which Customer is responsible as data exporter;
  • (i) implementing appropriate technical and organisational measures within Customer's own environment;
  • (j) ensuring that Customer's use of the Services complies with applicable Data Protection Law;
  • (k) determining whether Sensitive Personal Data may lawfully be submitted to the Services; and
  • (l) making notifications to regulators or Data Subjects where Customer is legally required to do so.

Where Customer acts as a Processor on behalf of another Controller, Customer warrants that its instructions to Onedash are authorised by the relevant Controller.

3.3 Data Subject Requests

If Onedash receives a Data Subject Request relating to Customer Personal Data and can reasonably identify Customer as the relevant Controller, Onedash will notify Customer unless applicable law prohibits Onedash from doing so. Onedash will not independently respond to a Data Subject Request concerning Customer Personal Data except:

  • (a) on Customer's documented instructions;
  • (b) where required by applicable law; or
  • (c) where the request relates to Personal Data for which Onedash acts independently as Controller.

Taking into account the nature of the Processing, Onedash will provide reasonable assistance to Customer through appropriate technical and organisational measures, insofar as reasonably and commercially practicable, to assist Customer in responding to Data Subject Requests.

3.4 Data Protection Assistance

Taking into account the nature of the Processing and the information available to Onedash, Onedash will provide reasonable assistance to Customer, where required by applicable Data Protection Law, in connection with:

  • (a) security of Processing;
  • (b) personal Data breach obligations;
  • (c) data protection impact assessments;
  • (d) prior consultation with supervisory authorities; and
  • (e) other Processor assistance obligations imposed by applicable Data Protection Law.

Customer acknowledges that Onedash's assistance obligations do not transfer Customer's Controller obligations to Onedash. Where Customer requests assistance that is materially beyond the ordinary functionality of the Services or Onedash's standard compliance processes, Onedash may charge Customer reasonable fees based on Onedash's then-current professional services rates, except where applicable law requires that assistance to be provided without charge.

3.5 Compliance Information

Onedash will make available to Customer information reasonably necessary to demonstrate Onedash's compliance with this DPA. Where available and appropriate, Onedash may satisfy this obligation by providing documentation, policies, security information, certifications, summaries of independent assessments, or similar materials.

Nothing in this DPA requires Onedash to disclose:

  • (a) source code;
  • (b) trade secrets;
  • (c) information relating to another customer;
  • (d) information that would create a material security risk;
  • (e) privileged legal material; or
  • (f) information that Onedash is prohibited from disclosing.

3.6 Audits

Where applicable Data Protection Law provides Customer with a right to audit Onedash's Processing, Customer may request an audit subject to this Section. Except where a regulator requires otherwise or there is reasonable evidence of material non-compliance, Customer may conduct no more than one audit in any 12-month period. Customer must provide reasonable advance written notice and the Parties will mutually agree upon the scope, timing, method, and duration of the audit.

Audits must:

  • (a) occur during normal business hours;
  • (b) avoid unreasonable disruption to Onedash's operations;
  • (c) be limited to systems, procedures, and records relevant to Customer Personal Data;
  • (d) comply with Onedash's reasonable security requirements;
  • (e) protect confidential information relating to Onedash and other customers; and
  • (f) where reasonably possible, rely first on documentation and remote evidence before requiring an on-site inspection.

Any third-party auditor must be independent, appropriately qualified, not a competitor of Onedash, and bound by confidentiality obligations acceptable to Onedash. Customer will bear its own audit costs and reimburse Onedash for reasonable time and resources incurred in supporting an audit at Onedash's then-current professional services rates, unless the audit identifies material non-compliance by Onedash with this DPA. Customer must promptly notify Onedash of any material non-compliance identified by an audit and provide Onedash a reasonable opportunity to address it.

4. Security Incident Management

4.1 Notification

When Onedash becomes aware of a Security Incident affecting Customer Personal Data, Onedash will notify Customer without undue delay where notification is required under applicable Data Protection Law. Notification of a Security Incident does not constitute an acknowledgement of fault or liability by Onedash.

4.2 Security Incident Information

To the extent information is reasonably available to Onedash, a Security Incident notification may include:

  • (a) a description of the nature of the Security Incident;
  • (b) the categories of Customer Personal Data affected;
  • (c) where reasonably possible, the approximate number or categories of affected Data Subjects or records;
  • (d) the name or contact details of a point of contact from whom further information may be obtained;
  • (e) a description of the likely consequences of the Security Incident, where reasonably known; and
  • (f) a description of measures taken or proposed to address or mitigate the Security Incident.

Where it is not reasonably possible to provide all relevant information at the same time, Onedash may provide the information in phases as it becomes available.

4.3 Cooperation

Onedash will take reasonable steps to investigate, contain, and mitigate a Security Incident affecting Customer Personal Data. Taking into account the nature of the Processing and information available to Onedash, Onedash will reasonably cooperate with Customer to enable Customer to meet applicable breach notification obligations. Customer remains responsible for determining whether Customer is required to notify a supervisory authority, regulator, Data Subject, or other person, except where applicable law independently places that obligation on Onedash.

4.4 Customer Incidents

Customer must promptly notify Onedash if Customer becomes aware of a security incident within Customer's systems, Account, devices, or credentials that may materially affect the security of the Services or Customer Personal Data Processed by Onedash. The Parties will reasonably cooperate where an incident involving both Parties requires coordinated investigation or response.

5. Security

5.1 Security Programme

Onedash will implement and maintain reasonable and appropriate technical and organisational measures designed to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access.

The measures will take into account:

  • (a) the nature of the Customer Personal Data;
  • (b) the scope, context, and purposes of Processing;
  • (c) the state of the art;
  • (d) implementation costs; and
  • (e) the risks to Data Subjects.

The technical and organisational measures applicable to the Services are described in Annex D.

5.2 Changes to Security Measures

Onedash may update its technical and organisational measures from time to time to reflect developments in technology, threats, the Services, and Onedash's security programme. Onedash will not materially reduce the overall level of protection for Customer Personal Data during an active Subscription Term without a legitimate security, technical, or legal reason.

5.3 Customer Security Responsibilities

Customer is responsible for configuring and using the Services appropriately and for implementing reasonable security measures for systems, devices, networks, accounts, and credentials under Customer's control. Customer is responsible for managing its Authorised Users, roles, access permissions, and authentication controls.

6. Liability and Indemnity

Each Party's liability to the other Party under or in connection with this DPA is subject to and limited by the limitations and exclusions of liability in the Terms. Nothing in this DPA increases Onedash's aggregate liability beyond the liability applicable under the Terms. The foregoing does not limit a right or liability to the extent that applicable Data Protection Law, the EU SCCs, the UK Addendum, or another mandatory transfer mechanism prohibits such limitation. Customer acknowledges that Onedash relies on Customer for instructions concerning the extent and purposes for which Onedash is entitled to Process Customer Personal Data. Onedash will not be liable for a claim arising from an act or omission performed in accordance with Customer's instructions to the extent the claim results from:

  • (a) customer's unlawful instruction;
  • (b) customer's failure to comply with Data Protection Law;
  • (c) customer's failure to obtain required rights, notices, permissions, or consents; or
  • (d) customer's Processing or use of the Services outside the scope permitted by the Agreement.

The indemnification provisions of the Terms apply to this DPA.

7. Duration and Termination

This DPA takes effect when Onedash first Processes Customer Personal Data on behalf of Customer and remains in effect for so long as Onedash Processes Customer Personal Data. Termination or expiration of the Terms will not discharge either Party from confidentiality or data protection obligations that by their nature continue while Customer Personal Data remains in that Party's possession or control. Sections concerning confidentiality, deletion, liability, international transfers, and other provisions intended by their nature to survive termination will remain effective to the extent necessary following termination.

8. International Data Transfers

8.1 Processing Locations

Onedash is based in Australia.

Customer acknowledges that Customer Personal Data may be Processed in Australia and in other countries in which Onedash's authorised Subprocessors operate. Onedash does not represent that all Customer Personal Data will remain exclusively within Australia unless Onedash expressly agrees to a specific data residency commitment in an Order or other written agreement. Onedash will ensure that international transfers of Customer Personal Data for which Onedash is responsible are made in accordance with applicable Data Protection Law.

8.2 Australian Cross-Border Disclosures

Where the Privacy Act 1988 (Cth) and Australian Privacy Principle 8 apply to an overseas disclosure by Onedash, Onedash will take such steps as are reasonable in the circumstances to ensure that the overseas recipient handles the relevant Personal Data consistently with applicable Australian Privacy Principle requirements, subject to any exception available under applicable law. Nothing in this DPA limits any accountability imposed on Onedash under the Privacy Act for an overseas disclosure.

8.3 European Economic Area Transfers

Where Customer transfers Customer Personal Data subject to the EU GDPR to Onedash in Australia and the transfer requires an appropriate safeguard under Chapter V of the EU GDPR, the EU SCCs are incorporated into this DPA as described in Annex B. Where Customer acts as Controller and Onedash acts as Processor, Module Two of the EU SCCs applies. Where Customer acts as Processor on behalf of another Controller and Onedash acts as Customer's Subprocessor, Module Three of the EU SCCs applies.

The EU SCCs apply only to transfers for which they are required under the EU GDPR.

8.4 United Kingdom Transfers

Where Customer transfers Customer Personal Data subject to the UK GDPR to Onedash and the transfer is a restricted transfer requiring appropriate safeguards, the UK Addendum applies together with the EU SCCs as described in Annex C. The Parties will reasonably cooperate in connection with a transfer risk assessment, data protection test, or equivalent assessment required by UK Data Protection Law. Customer, as data exporter, remains responsible for performing an assessment that applicable law places on Customer, with reasonable assistance from Onedash concerning matters within Onedash's knowledge.

8.5 Switzerland

Where Customer Personal Data subject to the Swiss FADP is transferred to Onedash and a contractual transfer safeguard is required, the EU SCCs will apply with the changes necessary for them to operate under the Swiss FADP. References to the EU GDPR or EU supervisory authorities will be interpreted to include corresponding provisions and authorities under Swiss law to the extent required. The competent Swiss supervisory authority is the Swiss Federal Data Protection and Information Commissioner where applicable.

8.6 Other Transfer Mechanisms

Where another lawful international transfer mechanism applies, the Parties may rely on that mechanism instead of the EU SCCs or UK Addendum to the extent permitted by applicable Data Protection Law.

9. General

9.1 Order of Precedence

In the event of a conflict concerning Customer Personal Data, the following order of precedence applies:

  • (a) a mandatory data transfer mechanism, including applicable EU SCCs or the UK Addendum;
  • (b) a Business Associate Agreement for matters within its scope;
  • (c) this DPA;
  • (d) an applicable Order; and
  • (e) the Terms.

9.2 Changes Required by Law

Onedash may update this DPA where reasonably necessary to reflect changes in Data Protection Law, regulatory requirements, transfer mechanisms, or the Services. Where a change materially affects Customer's rights or Onedash's obligations concerning Customer Personal Data, Onedash will provide reasonable notice where required by applicable law.

9.3 Governing Law

Except where an applicable mandatory transfer mechanism provides otherwise, this DPA is governed by the governing law and dispute resolution provisions of the Terms.

9.4 Contact

Questions concerning this DPA, Data Subject Requests directed to Onedash in its capacity as Processor, and notices concerning data protection may be submitted to:

Onedash
[email protected]
5 Beaumont Parade
West Footscray, Victoria 3012
Australia

Annex A. Jurisdiction-Specific Terms

The provisions of this Annex apply only to the extent Onedash Processes Customer Personal Data subject to the relevant Data Protection Law. If there is a conflict between this Annex and another provision of this DPA, this Annex prevails only to the extent necessary to comply with the applicable Data Protection Law.

Australia

Each Party will comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles to the extent applicable to that Party. Where Onedash Processes Personal Data on Customer's behalf, Onedash will use and disclose that Personal Data only as authorised under the Agreement, Customer's instructions, and applicable law. Where Onedash discloses Personal Data to an overseas Subprocessor and Australian Privacy Principle 8 applies, Onedash will take reasonable steps as required by applicable law regarding the overseas recipient's handling of that information. Nothing in this DPA limits a right of an individual or an obligation of a Party that cannot lawfully be excluded under the Privacy Act.

California

For Customer Personal Data governed by the CCPA:

  • (a) "Controller" includes "Business";
  • (b) "Processor" includes "Service Provider" or "Contractor";
  • (c) "Data Subject" includes "Consumer";
  • (d) "Personal Data" includes "Personal Information"; and
  • (e) "Process", "Processed", and "Processing" have the corresponding meanings under the CCPA.

Customer discloses Customer Personal Data to Onedash for the limited and specified business purposes of providing, operating, supporting, securing, maintaining, and improving the Services, performing the Agreement, responding to Customer instructions, and carrying out other Processing expressly permitted under this DPA.

Onedash will not:

  • (a) sell or share Customer Personal Data as those terms are defined by the CCPA;
  • (b) retain, use, or disclose Customer Personal Data for a purpose other than the specified business purposes or another purpose permitted under the CCPA;
  • (c) retain, use, or disclose Customer Personal Data outside the direct business relationship between Onedash and Customer except as permitted by the CCPA; or
  • (d) combine Customer Personal Data with Personal Information received from another person or collected from Onedash's own interaction with a Consumer except where the CCPA permits that combination.

Onedash will comply with applicable CCPA obligations imposed on Service Providers or Contractors. Customer may take reasonable and appropriate steps as permitted by the CCPA to help ensure that Onedash uses Customer Personal Data consistently with Customer's obligations under the CCPA. If Onedash determines that it can no longer meet an applicable CCPA obligation in relation to Customer Personal Data, Onedash will notify Customer as required by law. Onedash will permit Customer to take reasonable and appropriate steps required by the CCPA to stop and remediate unauthorised use of Customer Personal Data.

Nothing in this Section prevents Onedash from using information that has been de-identified so that it no longer constitutes Personal Information under the CCPA, provided Onedash complies with applicable restrictions on de-identified information, including restrictions on re-identification.

Canada

Where PIPEDA applies, each Party will comply with its respective obligations under PIPEDA. Onedash will implement reasonable security measures appropriate to the nature of Customer Personal Data. Where Onedash engages a Subprocessor to Process Customer Personal Data, Onedash will use contractual or other appropriate means designed to require a level of protection comparable to that required under applicable Canadian privacy law. Customer acknowledges that Personal Data Processed outside Canada may be subject to the lawful access requirements of the jurisdiction in which it is Processed.

Brazil

Where the LGPD applies, each Party is responsible for fulfilling its respective obligations under the LGPD. Customer will provide Processing instructions that enable Onedash to perform its obligations consistently with applicable LGPD requirements. Where a transfer of Personal Data governed by the LGPD to Onedash or an Onedash Subprocessor constitutes an international transfer requiring a transfer mechanism under Brazilian law, the Parties will use a transfer mechanism permitted by the LGPD and regulations of the Brazilian National Data Protection Authority. Where the standard contractual clauses approved under ANPD Resolution CD/ANPD No. 19/2024 are required, those clauses must be adopted in the official form required by the ANPD and without amendments prohibited by that regulation.

The Parties will execute or incorporate those clauses separately where necessary.

This Brazil Section does not purport to replace the official ANPD standard contractual clauses where those clauses are legally required.

Switzerland

Where the Swiss FADP applies, each Party will comply with its respective obligations under that law. Where the EU SCCs are used as a transfer safeguard for Swiss Personal Data, they apply with the adjustments described in Section 8.5 of this DPA.

United Kingdom

Where the UK GDPR applies, references in this DPA to obligations under the EU GDPR will be interpreted as corresponding obligations under the UK GDPR where appropriate. Restricted transfers from the United Kingdom will be governed by the transfer provisions in Section 8.4 and Annex C where applicable.

Annex B. Details of Processing and EU Standard Contractual Clauses

A. Parties

Data Exporter

The Customer identified in the applicable Account, Order, or Agreement.

Address
The address supplied by Customer to Onedash.

Contact
Customer's primary Account, privacy, or contractual contact as communicated to Onedash from time to time.

Role
Controller where Customer determines the purposes and means of Processing.
Processor where Customer Processes Personal Data on behalf of another Controller.

Data Importer

Onedash

Address
5 Beaumont Parade
West Footscray, Victoria 3012
Australia

Contact
[email protected]

Role
Processor or Subprocessor, as applicable.

B. Categories of Data Subjects

Customer Personal Data may concern:

  • (a) customer's Authorised Users;
  • (b) customer's employees, contractors, and personnel;
  • (c) customer's clients and customers;
  • (d) patients or healthcare service recipients where Customer is authorised to use applicable Services for that purpose;
  • (e) professional contacts;
  • (f) individuals whose information Customer enters into or stores through the Services;
  • (g) participants in communications, notes, recordings, or transcriptions Processed through applicable Services;
  • (h) users or contacts associated with Customer-controlled content; and
  • (i) other Data Subjects whose Personal Data Customer lawfully submits to the Services.

The exact categories of Data Subjects are determined by Customer's use of the Services.

C. Categories of Personal Data

Depending on Customer's use of the Services, Customer Personal Data may include:

  • (a) names and contact details;
  • (b) email addresses;
  • (c) organisation and employment information;
  • (d) professional information;
  • (e) identifiers;
  • (f) account and user information;
  • (g) device and technical information;
  • (h) IP addresses and security information;
  • (i) workspace information;
  • (j) settings and preferences;
  • (k) notes and text entered by Customer;
  • (l) files, documents, and media Customer elects to store or synchronise using applicable Services;
  • (m) audio, recording, or transcription content where Customer elects to use a feature that transmits such information to Onedash;
  • (n) support information;
  • (o) usage and activity information associated with Customer's use of applicable cloud Services; and
  • (p) any other Personal Data Customer elects to submit to a Service that Processes information through Onedash.

The Services may Process a broad range of Customer-controlled information. Onedash does not determine the content Customer chooses to submit and therefore cannot provide an exhaustive inventory of Customer Personal Data for every Customer. Information that remains exclusively on Customer's device and is not transmitted to Onedash is not included merely because it is handled by the Onedash Application.

D. Sensitive Personal Data

Customer may choose to submit information that qualifies as Sensitive Personal Data.

Depending on Customer's use, this may include:

  • (a) health information;
  • (b) racial or ethnic origin;
  • (c) religious or philosophical beliefs;
  • (d) political opinions;
  • (e) trade union membership;
  • (f) genetic information;
  • (g) biometric information;
  • (h) sexual orientation or sex life;
  • (i) criminal convictions or offences; or
  • (j) other information treated as sensitive under applicable law.

Customer is responsible for determining whether it has a lawful basis and appropriate safeguards for submitting Sensitive Personal Data. Protected Health Information governed by HIPAA may only be submitted where Customer has entered into an applicable Business Associate Agreement with Onedash and satisfies the requirements of that agreement.

E. Frequency

Customer Personal Data may be Processed on a continuous basis for the duration of Customer's use of applicable Services.

F. Nature of Processing

Processing may include:

  • (a) receipt;
  • (b) transmission;
  • (c) storage;
  • (d) organisation;
  • (e) retrieval;
  • (f) synchronisation;
  • (g) encryption and decryption;
  • (h) display;
  • (i) support access;
  • (j) security monitoring;
  • (k) backup and recovery;
  • (l) deletion;
  • (m) de-identification where authorised under this DPA; and
  • (n) other operations reasonably necessary to provide the Services.

G. Purposes

Customer Personal Data is Processed for the purpose of:

  • (a) providing the Services;
  • (b) operating Customer's Account and workspace;
  • (c) synchronising applicable data and preferences;
  • (d) storing information where Customer enables applicable cloud functionality;
  • (e) providing support;
  • (f) maintaining security and preventing abuse;
  • (g) troubleshooting;
  • (h) maintaining service reliability;
  • (i) complying with Customer's documented instructions;
  • (j) performing obligations under the Agreement;
  • (k) de-identifying information for purposes permitted under Section 1.6; and
  • (l) complying with applicable law.

H. Duration and Retention

Processing continues for the duration of the Agreement and for any limited period thereafter during which Onedash retains Customer Personal Data in accordance with the Terms, this DPA, backup procedures, or applicable legal requirements.

I. Subprocessors

The subject matter, nature, and duration of Processing performed by Subprocessors will be described in Onedash's then-current Subprocessor list.

J. EU SCC Selections

Where Module Two applies:

Customer is the data exporter and Controller.

Onedash is the data importer and Processor.

Where Module Three applies:

Customer is the data exporter and Processor.

Onedash is the data importer and Subprocessor.

For either applicable Module:

  • (a) clause 7, the optional docking clause, applies.
  • (b) clause 9 uses general written authorisation for Subprocessors.
  • (c) the notice period for Clause 9 is 10 days unless a shorter period is permitted under this DPA for an urgent reason and is lawful.
  • (d) the optional language in Clause 11 is not selected.
  • (e) for Clause 17, the governing law of the EU SCCs will be the law of Ireland.
  • (f) for Clause 18, the courts of Ireland will have jurisdiction as provided by the EU SCCs.
  • (g) annex I.A is completed using the Party information in this Annex.
  • (h) annex I.B is completed using the Processing information in this Annex.
  • (i) annex I.C will identify the supervisory authority determined in accordance with Clause 13 of the EU SCCs.
  • (j) annex II is completed by Annex D of this DPA.
  • (k) annex III consists of Onedash's then-current Subprocessor list.

Annex C. United Kingdom International Data Transfer Addendum

Where the UK Addendum applies, it forms part of this DPA.

Table 1

Exporter and key contact
As identified for the data exporter in Annex B.

Importer and key contact
Onedash, as identified in Annex B.

Table 2

The applicable EU SCCs are Module Two or Module Three as determined under Annex B.

The selections and optional provisions are those set out in Annex B.

Table 3

The Appendix Information required for the UK Addendum is contained in Annex B and Annex D of this DPA.

Table 4

The Importer may end the UK Addendum to the extent permitted by the section of the Approved Addendum addressing termination following changes to the Approved Addendum.

Mandatory Clauses

Part 2 Mandatory Clauses of the Approved Addendum, being the template Addendum B.1.0 issued by the United Kingdom Information Commissioner's Office and laid before Parliament in accordance with section 119A of the Data Protection Act 2018 on 2 February 2022, as revised under Section 18 of those Mandatory Clauses, are incorporated into this DPA. The UK Addendum applies only where required for a restricted transfer governed by UK Data Protection Law.

Annex D. Technical and Organisational Measures

The following describes the types of technical and organisational measures Onedash implements or may implement, as appropriate to the relevant Service, to protect Customer Personal Data. These measures describe Onedash's security programme and do not constitute a representation that every measure applies identically to every component or Service.

1. Access Control

Onedash uses access controls designed to limit access to Customer Personal Data to authorised Personnel and systems with a legitimate operational requirement.

Measures may include:

  • (a) role-based or least-privilege access controls;
  • (b) authentication requirements;
  • (c) multi-factor authentication for privileged or administrative access where appropriate;
  • (d) access review and revocation procedures;
  • (e) separation of administrative and ordinary user privileges; and
  • (f) restrictions on production-system access.

2. Authentication and Credentials

Onedash uses security measures designed to protect credentials and authentication information.

Depending on the relevant Service and platform, measures may include:

  • (a) secure password handling;
  • (b) multi-factor authentication;
  • (c) passkeys or other strong authentication mechanisms;
  • (d) operating-system credential stores for locally retained secrets where supported;
  • (e) protected service credentials; and
  • (f) credential revocation and rotation processes.

3. Encryption

Onedash uses encryption appropriate to the nature of the relevant data and system.

Measures may include:

  • (a) encryption of data in transit using industry-standard encrypted transport;
  • (b) encryption of stored Customer Personal Data where appropriate;
  • (c) encrypted local application databases where supported by the Application;
  • (d) application-layer or client-side encryption for applicable synchronised information;
  • (e) managed encryption keys and key-management systems;
  • (f) separation of encryption keys or key domains where appropriate; and
  • (g) secure management of application secrets and credentials.

Where Onedash manages encryption keys to support account recovery or operation of the Services, the use of managed keys does not constitute a representation that the relevant Service is zero-knowledge or that Onedash is technically incapable of recovering data unless Onedash expressly states otherwise for that Service.

4. Local-First Processing

Certain Onedash functionality is designed to Process information locally on Customer's device. Where applicable, local processing reduces the amount of information that must be transmitted to Onedash infrastructure. Data that remains entirely local and is never transmitted to Onedash does not become Customer Personal Data Processed by Onedash merely because the processing occurs within the Onedash Application.

5. Data Isolation

Onedash uses logical access controls and application architecture designed to prevent one Customer from accessing another Customer's Customer Personal Data. Where relevant to the Service, data, credentials, workspaces, and cryptographic material may be logically separated by Customer, Account, organisation, workspace, or other appropriate boundary.

6. Logging and Monitoring

Onedash may maintain security, administrative, and operational logging reasonably necessary to:

  • (a) detect suspicious activity;
  • (b) investigate incidents;
  • (c) maintain the Services;
  • (d) troubleshoot errors;
  • (e) enforce security controls; and
  • (f) maintain auditability.

Access to sensitive logs is restricted where appropriate.

7. Security Incident Response

Onedash maintains procedures designed to identify, investigate, contain, and respond to Security Incidents. Relevant Personnel may be assigned responsibilities for incident escalation, investigation, mitigation, recovery, and notification.

8. Secure Software Development

Onedash applies security practices to the development and maintenance of the Services appropriate to the nature of the system.

Measures may include:

  • (a) source control;
  • (b) code review;
  • (c) dependency management;
  • (d) software update processes;
  • (e) vulnerability remediation;
  • (f) validation of application releases;
  • (g) security testing where appropriate; and
  • (h) separation of development and production access where appropriate.

9. Malware and Threat Protection

Onedash uses technical and operational measures intended to reduce the risk of malicious code and unauthorised activity affecting systems that Process Customer Personal Data.

Measures vary according to the relevant system and infrastructure.

10. Availability, Backup and Recovery

Where applicable to cloud-hosted Customer Personal Data, Onedash uses measures designed to support availability and recovery from operational failures.

Measures may include:

  • (a) backup procedures;
  • (b) redundancy;
  • (c) recovery processes;
  • (d) infrastructure monitoring; and
  • (e) restoration procedures.

The existence of backups does not guarantee restoration of every item of Customer Personal Data and remains subject to the Terms.

11. Data Minimisation and Retention

Onedash seeks to limit the collection and retention of Customer Personal Data to information reasonably necessary for the relevant Processing purpose. Customer Personal Data is deleted or de-identified in accordance with the Agreement, applicable retention procedures, and legal obligations.

12. Personnel

Personnel with access to Customer Personal Data are subject to confidentiality obligations appropriate to their role. Onedash may provide Personnel with security and privacy guidance or training appropriate to their responsibilities.

13. Subprocessor Management

Onedash evaluates Subprocessors having regard to the nature of the Service and Processing and requires contractual privacy, confidentiality, and security obligations where appropriate and required by law.

14. Physical and Infrastructure Security

Where Onedash uses third-party infrastructure providers, physical data centre controls may be operated by those providers. Onedash selects infrastructure and service providers having regard to security, reliability, and applicable data protection requirements.

15. Device and Session Controls

Where supported by the Services, Onedash may provide controls relating to registered devices, session access, authentication factors, device revocation, or removal of locally stored workspace information. These controls supplement and do not replace Customer's responsibility to secure Customer-controlled devices and accounts.

16. Review

Onedash may review and update its technical and organisational measures in response to:

  • (a) changes to the Services;
  • (b) new threats or vulnerabilities;
  • (c) technological developments;
  • (d) changes in applicable law;
  • (e) security incidents; and
  • (f) operational requirements.

Onedash does not represent that any technical or organisational measure eliminates all security risk.