Data Processing Agreement

Data Processing Agreement

The processor terms that apply when Difinity processes personal data on your behalf.

Version: 1.0 | Effective Date: 2 September 2026 | Last Updated: 2 September 2026

This Data Processing Agreement ("DPA") forms part of the agreement under which Difinity Pty Ltd (ABN 82 686 692 759) provides the Services to the Customer.

1. Parties and legal identity

1.1 Parties

This DPA is between the customer identified in the applicable order form or enterprise agreement ("Customer") and Difinity Pty Ltd (ABN 82 686 692 759), with its registered office stated as Sydney, NSW, Australia ("Difinity").

1.2 Notices

Notices to Difinity under this DPA must be sent to privacy@difinity.ai, with a copy to legal@difinity.ai. Customer notices must be sent to the contact in the applicable order form or enterprise agreement.

2. Incorporation, scope and precedence

2.1 Incorporation

This DPA applies when the Customer uses the Services to process Customer Personal Data and is incorporated into the applicable order form, enterprise agreement or the Terms of Service.

2.2 Precedence

If this DPA conflicts with another part of the agreement on personal data processing, this DPA prevails. Applicable Standard Contractual Clauses or another binding transfer instrument prevail for a Restricted Transfer to the extent of any conflict.

2.3 Related documents

The Privacy Policy describes processing for which Difinity acts as a controller. The current list of Services Sub-processors is published at /sub-processors.

3. Roles by activity

3.1 Customer role

The Customer is a controller of Customer Personal Data. If the Customer processes Customer Personal Data for another controller, the Customer is a processor and appoints Difinity as its sub-processor.

3.2 Difinity role

Difinity is a processor or sub-processor when it processes Customer Personal Data to provide the Services on the Customer's documented instructions.

3.3 Separate controller purposes

Difinity acts as a separate controller for its own corporate account administration, security, billing, legal compliance, support relationship and website operations. Those activities are outside this DPA and are described in the Privacy Policy.

4. Definitions

4.1 Applicable Data Protection Law

"Applicable Data Protection Law" means privacy and data protection law that applies to the processing under this DPA, including the EU GDPR, UK GDPR and Australian Privacy Act 1988 (Cth), where applicable.

4.2 Customer Personal Data

"Customer Personal Data" means personal data or personal information contained in Customer Data that Difinity processes as a processor or sub-processor under the agreement.

4.3 Instructions

"Instructions" means the Customer's documented directions in the agreement, use-case and policy configuration, authorised API requests, connected-system configuration, support requests and other written directions consistent with the agreement.

4.4 Security Incident

"Security Incident" means an accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data in Difinity's or a Sub-processor's custody. It excludes unsuccessful attempts that do not compromise Customer Personal Data.

4.5 Services

"Services" means the contracted Difinity.ai services, including Hub, the Platform API, Flow, the chat and agent workspace at chat.difinity.ai, and the tool gateway, as specified in the order form or enterprise agreement. The tool gateway is not reachable from the internet.

4.6 Sub-processor and Restricted Transfer

"Sub-processor" means a third party appointed by Difinity to process Customer Personal Data for the Services. "Restricted Transfer" means a transfer of Customer Personal Data that requires a recognised transfer mechanism under Applicable Data Protection Law.

5. Subject matter, duration, nature and purpose

5.1 Processing details

The subject matter, duration, nature, purpose, data categories and data subjects are set out in Annex 1.

5.2 Duration

This DPA applies for as long as Difinity processes Customer Personal Data under the agreement, including the return, deletion and legally required retention period described in clause 17 and Annex 1.

6. Documented instructions

6.1 Instruction limit

Difinity will process Customer Personal Data only on documented Instructions, including transfers, unless applicable law requires otherwise. If law requires processing outside the Instructions, Difinity will notify the Customer before processing unless the law prohibits notice. Enabling a provider's models for a use case in Hub is a documented Instruction to use that provider for the applicable model calls.

6.2 Unlawful instruction

Difinity will inform the Customer if, in its reasonable opinion, an Instruction infringes Applicable Data Protection Law. Difinity may suspend the affected processing while the parties resolve the issue.

6.3 Model training and benchmarks

Difinity will not use Customer Personal Data or Customer Content to train a general model or create an unrelated benchmark without the Customer's express written agreement.

6.4 Credentials

Provider keys and connector credentials are write-only through customer-facing interfaces. No endpoint available through customer-facing interfaces returns a stored credential.

7. Customer responsibilities

7.1 Lawful processing

The Customer is responsible for its lawful basis, required notices, data accuracy, and the legality of its Instructions and use of the Services.

7.2 Connected systems

The Customer must have authority to connect each provider, system and MCP server, grant each scope, and instruct actions using the relevant person or organisation credential.

7.3 Configuration

The Customer must configure use cases, policies, permissions, data handling and approval requirements appropriate to its activities. Difinity's controls do not replace the Customer's assessment of law, risk or required human oversight.

7.4 Sensitive data

The Customer must not submit special-category, sensitive, children's, health, biometric, criminal, regulated financial or similarly restricted data unless the applicable order form or enterprise agreement expressly permits that data and states the required safeguards.

8. Confidentiality and authorised personnel

8.1 Confidentiality

Difinity will limit access to Customer Personal Data to personnel who need it to perform the Services and who are bound by confidentiality duties. Difinity will maintain access-control and personnel offboarding processes appropriate to those duties.

8.2 Staff support access

Authorised Difinity staff can read one organisation's data at a time, can add a person where the Customer's only administrator has lost access, remove people and appoint operators, and can look up which organisations an email address belongs to. Each staff action opens an organisation scope that names the staff member, so a change is recorded as done by that staff member. Access requires both a directory role and membership of an operator allowlist; the allowlist cannot be edited through the product, and an empty allowlist permits nobody. Staff do not sign in as or impersonate one of an organisation's people. An access log for this staff access is not yet implemented.

8.3 Customer notice item

The Customer acknowledges the staff access described in clause 8.2 as a current operational limitation. Difinity will notify the Customer of a material change to that access model through the agreement contact.

9. Security measures

9.1 Measures

Difinity will implement and maintain the technical and organisational measures in Annex 2, taking into account the nature, scope, context and purpose of processing and the risks to individuals.

9.2 No material reduction

Difinity may update the measures in Annex 2 if the update does not materially reduce the overall security of the Services.

9.3 Shared responsibility

The Customer remains responsible for its accounts, endpoint security, permissions, connected-system configuration and review of actions performed under its Instructions.

10. Sub-processors

10.1 General authorisation

The Customer gives general written authorisation for Difinity to appoint the Sub-processors listed in Annex 3 and at /sub-processors.

10.2 Changes and notice

Difinity will give at least 30 days' advance notice of a new or replacement Sub-processor that will process Customer Personal Data. Notice will be sent by email to the organisation's administrators and published at /sub-processors.

10.3 Objection

The Customer may object during the notice period on reasonable data protection grounds. The parties will work in good faith on a commercially reasonable alternative. If no alternative is available, the Customer may terminate the affected Service without penalty.

10.4 Flow-down and responsibility

Difinity will bind each Sub-processor by written data protection obligations that provide no less protection than the relevant obligations in this DPA. Difinity remains responsible for its Sub-processors to the extent required by Applicable Data Protection Law.

Where a Sub-processor listed in Annex 3 publishes no processor terms, Annex 3 says so, and the flow-down in this clause does not apply to that Sub-processor. Difinity uses such a Sub-processor for Difinity-funded model calls only where the Customer has enabled that provider's models for a use case in Hub, which is the Customer's documented instruction to use it.

11. Customer-appointed third parties

11.1 Customer provider relationships

When the Customer supplies its own model-provider key or directly appoints a connected system, connector destination or MCP server, that provider or destination is the Customer's own third-party relationship and is not appointed by Difinity as a Sub-processor for that interaction.

11.2 Customer instructions

The Customer instructs Difinity to disclose Customer Personal Data to a customer-appointed third party only as required by the configured request or action. Difinity remains responsible for the security controls it applies before that disclosure.

11.3 Credential boundary

An agent cannot hold a credential or reach a system directly. Every action is proposed to the tool gateway, which decides, holds the credential and acts.

12. International transfers

12.1 Agreed hosting region

Difinity offers hosting in AWS regions in Australia (Sydney), European Union (Frankfurt) and United States. The region for an organisation is agreed in the order form.

12.2 Restricted Transfers

The parties will not make a Restricted Transfer unless an adequacy decision, the applicable Standard Contractual Clauses, the UK International Data Transfer Agreement or Addendum, or another legally recognised safeguard applies.

12.3 Assessments and supplementary measures

Each party will provide reasonably requested information for a transfer impact or risk assessment. Difinity will implement supplementary measures identified as necessary and technically applicable to its processing.

12.4 Modules

For transfers subject to the EU Standard Contractual Clauses, Module 2 applies when the Customer is a controller and Module 3 applies when the Customer is a processor, unless the parties document another applicable module. Annex 4 gives the jurisdiction-specific structure and completion requirements.

13. Data-subject requests

13.1 Forwarding requests

Difinity will promptly notify the Customer if it receives a request from an individual concerning Customer Personal Data. Difinity will not respond except on the Customer's documented Instructions or as required by law.

13.2 Assistance

Taking into account the nature of processing, Difinity will provide reasonable technical and organisational assistance for access, correction, deletion, restriction, portability, objection and other applicable rights.

13.3 Identity and records

The Customer is responsible for verifying the requester and deciding how to respond. Difinity may request information reasonably required to identify the relevant Customer Personal Data and preserve security.

14. Security incidents

14.1 Notice

Difinity will notify the Customer without undue delay after becoming aware of a Security Incident affecting Customer Personal Data.

14.2 Contents and updates

The notice will describe, as information becomes available, the nature of the incident, affected data and individuals, likely consequences, mitigation and a contact point. Difinity will provide material updates and reasonable cooperation with the Customer's investigation and notification duties.

14.3 Mitigation

Difinity will take reasonable steps to contain, investigate and mitigate the Security Incident. Notice is not an admission of fault or liability.

15. DPIAs and regulator consultation

15.1 Assistance

Taking into account the nature of processing and information available to Difinity, Difinity will provide reasonable assistance with data protection impact assessments and prior consultation required under Applicable Data Protection Law.

15.2 Customer decisions

The Customer remains responsible for deciding whether an assessment or consultation is required and for documenting its lawful basis, risks and safeguards.

16. Audit and compliance information

16.1 Information

Difinity will make available information reasonably necessary to demonstrate compliance with this DPA, including relevant security descriptions, questionnaire responses and available independent reports.

16.2 Audit

If that information is insufficient, the Customer or an independent auditor bound by confidentiality may conduct a proportionate audit at reasonable intervals and on reasonable notice. An audit must avoid exposing another customer's data, credentials, confidential information or security vulnerabilities.

16.3 Findings

Difinity will address a substantiated material non-conformity within a reasonable period agreed by the parties. Difinity does not claim a certification or regulatory determination that it has not independently obtained.

16.4 Compliance evidence boundary

Governed run records can contribute operational evidence to wider EU AI Act, ISO/IEC 42001, risk and audit processes. Difinity does not determine that an organisation or AI system is compliant, and it does not provide ISO/IEC 42001 certification.

17. Return, export, deletion and retention

17.1 End of Services

The Customer may request an export of Customer Personal Data during the 30 days after termination. Difinity will delete Customer Personal Data within 90 days after that export period ends, except for the run trail and data subject to a legal hold or other mandatory law.

17.2 Current operational periods

Chat attachments are kept for 28 days. Parked agent runs and database backups are kept for 7 days.

17.3 Transcript and trail

The transcript retention period is a rolling 12-month window during the Subscription Term, with a 90-day export window after termination before deletion. The run-trail retention period follows the same rule: a rolling 12-month window during the Subscription Term, with a 90-day export window after termination before deletion.

17.4 Archive and erasure

The Services expose conversation archive, not conversation deletion. Transcript erasure follows the process in clause 17.1. When erasure of personal data in the append-only run trail is required, Difinity destroys the separate redaction map so that the retained trail is no longer attributable through that map. The anonymised run trail is retained for 12 months on a rolling basis during the Subscription Term, with a 90-day export window after termination before deletion.

17.5 Backups and legal holds

Deleted data may remain in a backup until that backup ages out within a further 7 days. Difinity may retain data subject to a legal hold or other mandatory law only for the required period and will restrict it to that purpose.

17.6 Credentials

Difinity destroys a connector credential when it is revoked. On valid termination instructions, Difinity will revoke or destroy other stored provider credentials within its control. No endpoint available through customer-facing interfaces returns a stored value.

18. Government and law-enforcement demands

18.1 Review and notice

If Difinity receives a binding government or law-enforcement demand for Customer Personal Data, it will review the demand and notify the Customer before disclosure unless prohibited by law.

18.2 Minimum disclosure

Difinity will disclose only the minimum data legally required and will challenge an overbroad or unlawful demand where reasonable grounds and lawful means exist.

19. Records and regulatory cooperation

19.1 Processing records

Difinity will maintain records of processing required of a processor under Applicable Data Protection Law and provide information reasonably required for the Customer's corresponding records.

19.2 Regulator cooperation

Difinity will cooperate with a competent regulator as required by law and will provide the Customer reasonable assistance with a regulator inquiry concerning processing under this DPA.

19.3 Contacts

The privacy contact for this DPA is privacy@difinity.ai. Any representative or data-protection-officer details required by applicable law will be stated in the Privacy Policy.

20. Liability and indemnity

20.1 Agreement terms

Liability and indemnity arising under this DPA are governed by the limitations, exclusions and indemnities in the Terms of Service, applicable order form or enterprise agreement.

20.2 Mandatory rights

Nothing in this DPA limits a data subject's rights, a regulator's powers, liability under binding Standard Contractual Clauses, or rights and liabilities that cannot lawfully be limited or excluded.

21. Term, survival and changes

21.1 Term and survival

This DPA begins when it becomes binding under clause 22 and continues while Difinity processes Customer Personal Data. Confidentiality, return, deletion, retained-data protection, audit and transfer obligations survive for as long as relevant Customer Personal Data remains.

21.2 Changes

Difinity may update this DPA to reflect law, regulator guidance, Services or security changes. Difinity will give advance notice of a material change and will not materially reduce the protection of Customer Personal Data during a current order term without the Customer's agreement or a legal requirement.

22. Execution

22.1 Binding effect

This DPA becomes binding when it is incorporated into an executed order form or enterprise agreement, or otherwise signed by authorised representatives of both parties. Publication at /dpa alone does not create an agreement.

22.2 Counterparts and electronic signature

The parties may execute this DPA in counterparts and by electronic signature where permitted by law. Each counterpart forms one instrument with the others.

Annex 1. Processing details

A1.1 Subject matter and duration

Difinity processes Customer Personal Data to provide the contracted Services for the period described in clauses 5 and 17.

A1.2 Nature and purpose

Processing may include collection, transmission, storage, organisation, retrieval, detection and replacement of personal information, model inference, response delivery, agent and tool execution, approval handling, evidence recording, metering, billing, support, return and deletion.

A1.3 Data subjects

Data subjects may include Customer administrators, personnel, contractors and application end users; people identified in prompts, files, transcripts, model outputs, tool arguments, tool results and connected systems; and Customer contacts.

A1.4 Data categories

Customer Personal Data may include identifiers and contact details; account, authentication and session data; prompts, responses and transcripts; attachments and extracted content; agent, use-case and policy configuration; tool arguments and results; connected-system records; credential references; approvals; a redaction map; run-trail evidence; support records; and usage, invoice and billing data.

A1.5 Sensitive data

Sensitive or special-category data is not approved by default. The Customer may provide it only where the order form or enterprise agreement expressly identifies the data, purpose, lawful basis and safeguards.

A1.6 Frequency

Processing occurs when the Customer, its authorised people or its applications use or administer the Services, and during scheduled storage, backup, billing, support and deletion operations.

A1.7 Hosting and retention

The organisation's AWS hosting region is Australia (Sydney), European Union (Frankfurt) or United States, as agreed in the order form. Authentication data is processed in the same region as the organisation's hosting region: Australia (Sydney), European Union (Frankfurt) or United States.

Attachments are retained for 28 days, parked agent runs for 7 days and database backups for 7 days. Transcript retention is a rolling 12-month window during the Subscription Term, with a 90-day export window after termination before deletion, and run-trail retention follows the same rule.

After termination, an export is available on request for 30 days. Customer Personal Data is deleted within 90 days after that period, and backups age out within a further 7 days, subject to the run-trail treatment and legal-hold exception in clause 17.

A1.8 Return and export

Return and export use formats and methods supported by the Services or otherwise reasonably agreed in writing. Individual attached files can be downloaded by their owner, one file at a time.

Annex 2. Technical and organisational measures

A2.1 Organisation isolation and staff access

Platform data is separated by organisation through row-level security. Authorised Difinity staff can read one organisation's data at a time, can add a person where the Customer's only administrator has lost access, remove people and appoint operators, and can look up which organisations an email address belongs to. Each staff action opens an organisation scope that names the staff member, so a change is recorded as done by that staff member. Access requires both a directory role and membership of an operator allowlist; the allowlist cannot be edited through the product, and an empty allowlist permits nobody. Staff do not sign in as or impersonate one of an organisation's people. An access log for this staff access is not yet implemented.

A2.2 Storage protection

Platform data is stored in Aurora PostgreSQL 16.14 in private subnets and encrypted at rest with an AWS KMS key managed by Difinity. Database connections require SSL. Backups and point-in-time recovery are kept for 7 days.

A2.3 Credential protection

Provider keys and connector credentials are stored through AWS Secrets Manager and remain write-only through customer-facing interfaces. No endpoint available through customer-facing interfaces returns a stored credential.

A2.4 Tool boundary

An agent holds no credential and cannot reach a system itself. Every action is proposed to the tool gateway, which decides, holds the credential and acts. The tool gateway is unreachable from the internet.

A2.5 Personal-information boundary

The model works on replaced text. Real values are restored only in the last step before an action leaves through the tool gateway. An action waiting for approval shows the restored form, which is the form approved and executed.

A tool result is checked before the model reads it. A result that cannot be checked is withheld, and a failed check refuses the request.

The run trail records the kind of value replaced and never the original value.

A2.6 Action authority and evidence

An agent's authority is the intersection of the approved version's bindings, the caller's entitlements and the use case's permissions.

The run trail is append-only evidence. It is separate from the Configuration Log and the transcript.

A2.7 File and temporary-state controls

A chat attachment is limited to 25 MB and kept for 28 days. A parked agent run is kept for 7 days.

A2.8 Review and change control

Difinity reviews material changes to these measures against the no-material-reduction obligation in clause 9.2. Security measures supplied by a Sub-processor remain subject to the applicable vendor agreement and Difinity's Sub-processor review.

Annex 3. Services Sub-processors

A3.1 Conditions

The list below sets out the Services Sub-processors authorised under clause 10. Model providers are conditional Sub-processors only when Difinity funds the model call. If the Customer supplies its own provider key, the provider is the Customer's own provider relationship for that call.

Amazon Web Services Australia Pty Ltd

  • Service and purpose: AWS, including Aurora, S3, Secrets Manager and Bedrock: hosting, storage, secret storage and Difinity-hosted model processing
  • Customer personal data: Service data, stored content, credentials and model inputs and outputs as applicable
  • Data subjects: Customer administrators, authorised people, application end users and people represented in Customer content
  • Processing location: Australia (Sydney), European Union (Frankfurt) or United States, according to the order form
  • Transfer mechanism: EU Standard Contractual Clauses adopted in June 2021, UK Addendum and Swiss addendum, as applicable
  • Appointment date: Before 2 September 2026
  • Privacy, security and processor terms: AWS DPA; AWS sub-processors; Bedrock privacy
  • Customer notice: privacy@difinity.ai

Supabase Pte. Ltd.

  • Service and purpose: Supabase: authentication and session services
  • Customer personal data: Account identifiers, authentication data, session data and minimal profile claims
  • Data subjects: Customer administrators and authorised people
  • Processing location: in the same region as the organisation's hosting region: Australia (Sydney), European Union (Frankfurt) or United States
  • Transfer mechanism: EU Standard Contractual Clauses Module 2 or 3, UK Addendum and Swiss addendum, as applicable
  • Appointment date: Before 2 September 2026
  • Privacy, security and processor terms: Supabase DPA; Supabase sub-processors; Supabase security
  • Customer notice: privacy@difinity.ai

Stripe Payments Australia Pty Ltd

  • Service and purpose: Stripe and Stripe affiliates under Stripe's Data Processing Agreement: billing and monthly invoicing
  • Customer personal data: Customer contact, billing, invoice and payment-related data
  • Data subjects: Customer billing contacts and authorised administrators
  • Processing location: Multiple locations; Stripe does not publish one fixed processing region for the Services
  • Transfer mechanism: EEA Standard Contractual Clauses Modules 1 and 2 and UK International Data Transfer Addendum, as applicable
  • Appointment date: Before 2 September 2026
  • Privacy, security and processor terms: Stripe DPA; Stripe service providers; Stripe security
  • Customer notice: privacy@difinity.ai

OpenAI OpCo, LLC

  • Service and purpose: OpenAI: conditional model inference for Difinity-funded calls
  • Customer personal data: Model input, output and technical request metadata
  • Data subjects: People represented in model input or output
  • Processing location: Vendor-selected locations unless data residency is configured; available residency regions include Australia, the United States and Europe, while system data may be processed elsewhere
  • Transfer mechanism: EU Standard Contractual Clauses for EEA and Swiss data and the UK Addendum for UK data; APP 8 reasonable steps apply to Difinity's disclosures from Australia
  • Appointment date: Before 2 September 2026
  • Privacy, security and processor terms: OpenAI DPA; OpenAI sub-processors; OpenAI API data controls
  • Customer notice: privacy@difinity.ai

Anthropic, PBC

  • Service and purpose: Anthropic: conditional model inference for Difinity-funded calls
  • Customer personal data: Model input, output and technical request metadata
  • Data subjects: People represented in model input or output
  • Processing location: No single default processing country or region is stated in Anthropic's published commercial terms
  • Transfer mechanism: EU Standard Contractual Clauses Module 2 or 3, UK Addendum and Swiss addendum, as applicable
  • Appointment date: Before 2 September 2026
  • Privacy, security and processor terms: Anthropic DPA; Anthropic sub-processors; Anthropic retention
  • Customer notice: privacy@difinity.ai

Google Australia Pty Ltd

  • Service and purpose: Google: conditional model inference for Difinity-funded calls
  • Customer personal data: Model input, output and technical request metadata
  • Data subjects: People represented in model input or output
  • Processing location: No fixed default region for the Gemini Developer API; data may be processed in countries where Google or its agents maintain facilities unless a region-pinned service is used
  • Transfer mechanism: EU Standard Contractual Clauses for controller-to-processor or processor-to-processor transfers and the EU-US Data Privacy Framework, as applicable
  • Appointment date: Before 2 September 2026
  • Privacy, security and processor terms: Google processor terms; Google sub-processors; Gemini API data controls
  • Customer notice: privacy@difinity.ai

Hangzhou DeepSeek Artificial Intelligence Co., Ltd.

  • Service and purpose: DeepSeek: conditional model inference for Difinity-funded calls
  • Customer personal data: Model input, output and technical request metadata
  • Data subjects: People represented in model input or output
  • Processing location: People's Republic of China
  • Transfer mechanism: No named transfer mechanism is published; DeepSeek states only that it will use appropriate safeguards where required
  • Appointment date: Before 2 September 2026
  • Privacy, security and processor terms: DeepSeek Privacy Policy; DeepSeek Open Platform Terms. DeepSeek publishes no DPA and no API no-training commitment. Enabled only by the Customer's own model selection in Hub; excluded from the clause 10.4 flow-down.
  • Customer notice: privacy@difinity.ai

SpaceXAI (formerly xAI), as named in its Data Processing Addendum effective 24 August 2026

  • Service and purpose: xAI (Grok): conditional model inference for Difinity-funded calls
  • Customer personal data: Model input, output and technical request metadata
  • Data subjects: People represented in model input or output
  • Processing location: United States and other countries
  • Transfer mechanism: EU Standard Contractual Clauses and UK Addendum under the SpaceXAI DPA; APP 8 reasonable steps apply to Difinity's disclosures from Australia
  • Appointment date: Before 2 September 2026
  • Privacy, security and processor terms: SpaceXAI DPA; xAI API security
  • Customer notice: privacy@difinity.ai

A3.2 Current list

The public version of this list and change notices are available at /sub-processors.

Annex 4. International transfer mechanisms

A4.1 European Economic Area

Where EU GDPR applies to a Restricted Transfer, the parties incorporate the European Commission Standard Contractual Clauses adopted by Implementing Decision (EU) 2021/914. Module 2 applies to controller-to-processor transfers and Module 3 applies to processor-to-processor transfers, as applicable. The order form or transfer schedule must complete the parties, competent authority, governing law, processing details, security measures and Sub-processor information.

A4.2 United Kingdom

Where UK GDPR applies to a Restricted Transfer, the parties will complete the UK International Data Transfer Agreement or UK Addendum to the EU Standard Contractual Clauses, as applicable, together with the required transfer risk assessment.

A4.3 Australia

Where the Australian Privacy Act applies, the parties will address APP 8 and section 16C through the location disclosures, contractual controls and due diligence in this DPA and the applicable order form.

A4.4 Other jurisdictions

For another jurisdiction, the parties will complete any mandatory local controller-processor terms or transfer instrument in the order form or a written addendum. Neither party may treat this Annex as replacing a mandatory local instrument.