Legal
Data Processing Addendum
The terms on which the operator processes personal data on behalf of a customer organisation: roles, instructions, security, subprocessors, transfers, assistance and deletion.
Version 1.0.0 · Effective
Draft — not yet reviewed by counsel
This text has not been reviewed by a qualified legal practitioner and is published for review rather than as an executed instrument. The review state is recorded in mybase/docs/legal/README.md.
Operator details outstanding
The operating entity name, registered address, governing-law jurisdiction and privacy contact have not been configured for this deployment. Each appears below as a marked placeholder rather than a guess.
1. Parties and roles
This addendum forms part of the agreement between [PENDING — operator to supply] of [PENDING — operator to supply] ("Processor") and the customer organisation that licenses the platform ("Controller").
For personal data of the Controller’s members, staff and contacts processed through the platform, the Controller is the controller and the Processor is the processor. The Processor processes that data only on the Controller’s documented instructions, of which the agreement and the use of the platform’s features are the primary instruction.
2. Subject matter, duration, nature and purpose
| Item | Detail |
|---|---|
| Subject matter | Provision of the community platform to the Controller. |
| Duration | The term of the agreement, plus the deletion period in §9. |
| Nature and purpose | Hosting, storage, retrieval, display, transmission, backup, and — where enabled by the Controller — AI-assisted retrieval and generation. |
| Categories of data subject | The Controller’s community members, administrators, staff, event attendees and invitees. |
| Categories of personal data | Identity and contact data, authentication data, profile data, user-generated content including private messages, learning and gamification records, event and ticketing records, payment records, and technical data such as IP address and user agent. |
| Special categories | Not requested by the platform. The Controller must not configure fields, and should not encourage content, that solicit special-category data unless it has established a lawful basis and told the Processor. |
3. Processor obligations
- Process personal data only on the Controller’s documented instructions, including as to international transfers, unless required otherwise by law — in which case the Processor will inform the Controller unless that law forbids it.
- Ensure personnel authorised to process the data are bound by confidentiality.
- Not sell the data, and not use it for the Processor’s own purposes.
- Inform the Controller if, in the Processor’s opinion, an instruction infringes applicable data-protection law.
4. Security measures
The Processor implements appropriate technical and organisational measures, which currently include:
- Database-per-tenant isolation: each Controller’s data resides in its own dedicated Postgres database with its own credentials, rather than in shared tables partitioned by an identifier.
- Row-level security policies enforced in the database, covering member-scoped access to community data.
- Encryption in transit (TLS) for all connections, and encryption at rest for databases, backups and object storage as provided by the hosting subprocessor.
- Credential hygiene: passwords stored only as hashes; service credentials held server-side and never exposed to browsers.
- Automated backups of the tenant database, retained per the hosting subprocessor’s schedule.
- Access to production systems limited to personnel who need it.
Measures are reviewed as the platform changes; the Processor may substitute a measure with one providing an equivalent or higher level of protection.
5. Subprocessors
The Controller grants general authorisation for the Processor to engage the subprocessors published at /legal/subprocessors. That page is the authoritative list and is not restated here, so that there is only one list to keep current.
The Processor imposes data-protection obligations on each subprocessor no less protective than those in this addendum, and remains liable for their performance. The Processor will give the Controller notice before a new subprocessor begins processing the Controller’s data, and the Controller may object on reasonable data-protection grounds; where an objection cannot be resolved, the Controller may terminate the affected part of the service.
The AI subprocessors are engaged only where the Controller enables the assistant. Leaving it disabled means no assistant transfer occurs for that Controller.
6. Location and international transfers
Tenant databases are provisioned in AWS ap-southeast-2 (Sydney) by default; an alternative region may be agreed before the tenant database is created. Subprocessors listed at /legal/subprocessors operate their own infrastructure and may process data in other jurisdictions.
Where a transfer is made from a jurisdiction that restricts international transfer, the parties rely on the transfer mechanism required by that jurisdiction, including the applicable standard contractual clauses, which are incorporated by reference on execution of this addendum.
7. Personal data breach
The Processor will notify the Controller without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting the Controller’s data, and will provide the information reasonably available to allow the Controller to meet its own notification obligations, together with the remediation taken.
8. Assistance, audit and data subject requests
The platform’s administrative features allow the Controller to locate, correct, export and delete member data itself. Where a request cannot be satisfied through the product, the Processor will assist the Controller in responding to data subject requests and in carrying out data protection impact assessments and prior consultations, taking into account the nature of the processing.
The Processor will make available the information necessary to demonstrate compliance with this addendum and will allow for and contribute to audits, including inspections, conducted by the Controller or an auditor it mandates, on reasonable notice, no more than once in any twelve-month period unless a breach or a regulator requires otherwise, and subject to confidentiality.
9. Return and deletion
On termination, and at the Controller’s election, the Processor will return or delete the Controller’s personal data. Unless the Controller instructs otherwise, the tenant database is deleted within 30 days of termination. Backups containing the data age out on their normal cycle and are not selectively edited; they remain subject to this addendum until they expire.
10. Contact
Data protection contact: [PENDING — operator to supply]. Governing law follows the agreement and, absent a stated choice, the laws of [PENDING — operator to supply].