Version: 2026-07-10
Effective Date: This Agreement is effective from the date you first access the platform.
This Data Processing Agreement forms part of the Terms of Service between Risk 2 Solution Pty Ltd (ABN 91 128 669 554) of PO Box 1009, Cleveland QLD 4163, Australia (Processor) and the client identified in the applicable Terms of Service or Order Form (Controller).
In this Data Processing Agreement:
Controller means the Client who determines the purposes and means of processing Personal Data.
Personal Data means any information relating to an identified or identifiable natural person processed through the Service.
Processing means any operation performed on Personal Data, including collection, storage, use, disclosure, or deletion.
Processor means Risk 2 Solution Pty Ltd, which processes Personal Data on behalf of the Controller.
Service means the Presilience360 service provided by the Processor under the Terms of Service.
Sub-processor means any third party engaged by the Processor to process Personal Data on behalf of the Processor in connection with the Service.
Terms of Service means the agreement governing the Controller’s use of the Service, including any applicable Order Form.
This Data Processing Agreement (DPA) governs the processing of Personal Data by the Processor on behalf of the Controller in connection with the Service.
The subject matter, nature, and purpose of the Processing are the provision of the Service under the Terms of Service. The duration of the Processing is the term of the Terms of Service, unless otherwise required by applicable law or this DPA.
The Processor shall process Personal Data only in accordance with the documented instructions of the Controller, as set out in the Terms of Service, this DPA, and any applicable Order Form, unless otherwise required by applicable law.
If the Processor is required by applicable law to process Personal Data other than in accordance with the Controller’s instructions, the Processor shall, to the extent permitted by law, notify the Controller before carrying out that Processing.
Each party shall comply with all applicable data protection laws, including the Privacy Act 1988 (Cth) and the Australian Privacy Principles, in connection with its respective obligations under this DPA.
The Controller is responsible for:
(a) ensuring that its instructions to the Processor are lawful;
(b) ensuring that it has provided all notices and obtained all consents, permissions, and other lawful bases required for the collection, use, disclosure, and Processing of Personal Data in connection with the Service;
(c) the accuracy, quality, and legality of the Personal Data and the means by which the Controller acquired the Personal Data; and
(d) ensuring that its use of the Service complies with applicable law.
If the Processor reasonably believes that an instruction from the Controller infringes applicable law, the Processor may suspend the affected Processing and notify the Controller.
The Processor shall implement and maintain appropriate technical and organisational measures to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access.
These measures include, at a minimum:
(a) encryption of data in transit using TLS 1.2 or higher;
(b) encryption of data at rest;
(c) access controls and authentication requirements;
(d) regular security testing;
(e) physical security controls at data centres; and
(f) appropriate confidentiality obligations and access restrictions for personnel authorised to process Personal Data.
The Processor may update or modify its security measures from time to time, provided that the overall level of protection for Personal Data is not materially reduced.
The Processor shall notify the Controller without undue delay after becoming aware of a confirmed Personal Data breach affecting Personal Data processed under the Service, and where reasonably practicable within 72 hours of becoming aware of the breach.
Such notification shall include, to the extent known at the time:
(a) the nature of the breach;
(b) the categories and approximate number of affected individuals or records;
(c) the likely consequences of the breach; and
(d) the measures taken or proposed to address the breach.
The Controller acknowledges that initial notifications may be based on incomplete information, and the Processor may provide further information in phases as it becomes available.
Each party shall reasonably co-operate with the other in relation to the investigation, mitigation, and remediation of a Personal Data breach affecting Personal Data processed under the Service.
The Controller authorises the Processor to engage the following Sub-processors:
Supabase Inc. — Purpose: Database hosting and authentication services. Location: Sydney, Australia (AWS ap-southeast-2).
Anthropic PBC — Purpose: AI-powered document processing and field extraction. Location: United States.
Stripe Inc. — Purpose: Payment processing. Location: United States.
Google LLC — Purpose: Location data enrichment via Places API. Location: United States.
The Processor may update its Sub-processors from time to time. The Processor shall notify the Controller of any intended addition or replacement of a Sub-processor that will process Personal Data.
The Controller may object to a proposed Sub-processor only on reasonable written grounds relating to data protection or information security, by giving written notice to the Processor within 14 days after receiving notice of the proposed change.
The parties shall work in good faith to resolve any such objection. If the parties cannot resolve the objection within a reasonable period, the Processor may, at its option:
(a) provide the affected functionality without using the proposed Sub-processor;
(b) take commercially reasonable steps to address the Controller’s objection; or
(c) if the objection cannot reasonably be resolved, permit the Controller to terminate the affected part of the Service in accordance with the Terms of Service.
The Processor shall ensure that each Sub-processor engaged to process Personal Data is bound by written obligations that are no less protective of Personal Data than the obligations imposed on the Processor under this DPA, to the extent applicable to the services performed by that Sub-processor.
The Processor shall, taking into account the nature of the Processing and the functionality of the Service, provide reasonable assistance to the Controller in fulfilling the Controller’s obligations to respond to requests from data subjects exercising their rights under applicable data protection laws, including rights of access, rectification, erasure, and portability.
Where such assistance requires material additional work outside the standard functionality of the Service, the Processor may charge the Controller its reasonable costs, provided those costs are disclosed in advance.
The Controller acknowledges and agrees that, in connection with the provision of the Service, Personal Data may be transferred to or accessed from countries outside Australia, including the countries in which the authorised Sub-processors listed in this DPA operate.
Where Personal Data is transferred to a country outside Australia, the Processor shall ensure that such transfers are made in compliance with the Privacy Act 1988 (Cth) and that appropriate safeguards are in place, including written contractual protections with the relevant receiving party.
The Processor shall take reasonable steps to ensure that any overseas recipient engaged by the Processor to process Personal Data:
(a) is subject to confidentiality obligations;
(b) implements appropriate technical and organisational security measures;
(c) processes Personal Data only for the permitted purposes; and
(d) provides notification of security incidents affecting Personal Data, where applicable.
Upon termination of the Service, or upon written request from the Controller where consistent with the functionality of the Service and the Terms of Service, the Processor shall, within 30 days, delete or return the Personal Data to the Controller, unless retention is required by applicable law.
The Processor may retain archived or back-up copies of Personal Data to the extent such copies are maintained pursuant to the Processor’s standard backup or business continuity processes, provided that such retained copies remain protected in accordance with this DPA and are deleted or overwritten in the ordinary course.
Where the Processor returns Personal Data, it may do so in a standard format made available through the Service or otherwise reasonably determined by the Processor.
Nothing in this clause requires the Processor to delete or return Personal Data that the Processor is required to retain by applicable law, or to retain for the establishment, exercise, or defence of legal claims, internal compliance purposes, or security logging, in each case only for so long as required for those purposes.
The Controller may, upon reasonable written notice of no less than 30 days and no more than once in any 12 month period, request information reasonably necessary to demonstrate the Processor’s compliance with this DPA.
The Processor may satisfy this obligation by providing available third-party audit reports, certifications, security summaries, or responses to reasonable written questionnaires, where those materials reasonably address the Controller’s request.
If, acting reasonably, the Controller still requires a further audit after reviewing the materials provided, the Controller may conduct or commission a further audit of the Processor’s relevant data processing activities, subject to the following conditions:
(a) the audit must be conducted during normal business hours and in a manner that minimises disruption to the Processor’s business;
(b) the scope of the audit must be reasonable and limited to matters relevant to the Processor’s compliance with this DPA;
(c) any third-party auditor must be independent, suitably qualified, and bound by written confidentiality obligations acceptable to the Processor;
(d) the Controller must bear its own costs of the audit and reimburse the Processor for its reasonable internal costs incurred in supporting the audit, except where the audit identifies a material breach of this DPA by the Processor;
(e) the audit must not unreasonably compromise the security, confidentiality, or integrity of the Processor’s systems, and must not provide access to other customers’ data, source code, or information that would create a security risk or breach confidentiality obligations owed to third parties; and
(f) if the Processor has experienced a recent security incident, is subject to a regulator investigation, or is already supporting another customer audit, the Processor may propose an alternative reasonable time or method for the audit.
Nothing in this clause limits the Controller’s rights where disclosure or access is required by a regulator with lawful authority.
Each party’s liability under this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service.
To the extent of any inconsistency between this DPA and the Terms of Service in relation to the subject matter of data protection and Processing of Personal Data, this DPA prevails.
This DPA shall remain in force for the duration of the Terms of Service and shall automatically terminate upon termination of the Terms of Service.
Termination of this DPA does not relieve either party of obligations that are intended to survive termination, including obligations relating to confidentiality, liability, deletion or return of Personal Data, and any accrued rights or remedies.
This DPA is governed by the laws of Queensland, Australia.
For any data protection enquiries, please contact:
Risk 2 Solution Pty Ltd Data Protection Officer PO Box 1009, Cleveland QLD 4163, Australia Phone: 1300 560 295 Email: info@risk2solution.com