This Data Processing Addendum (“Addendum”) forms part of the agreement between Wondertree Studios Pty Ltd (ACN 699 886 498, ABN 82 699 886 498) of Level 10, 387 George Street, Sydney NSW 2000, Australia (“Wondertree”, “we”, “us”, “our”) and the organisation subscribing to OneForce Care (“Customer”, “you”, “your”), and applies whenever we handle personal information contained in Customer Data on your behalf.
Our Privacy Policy explains our handling of personal information. This Addendum sets out the contractual terms that apply when we handle personal information contained in Customer Data on your behalf.
1. How this Addendum works
1.1 This Addendum applies automatically to every subscription to OneForce Care. You do not need a separately signed document for the published Addendum to form part of the Agreement. A request for an executed counterpart or customer paper is subject to our legal and commercial review and does not bind us unless both parties agree to it in writing.
1.2 This Addendum forms part of the Terms of Service (the “Terms”). Capitalised terms not defined here have the meaning given in the Terms.
1.3 If there is a conflict between this Addendum and the rest of the Agreement in relation to our handling of personal information contained in Customer Data, this Addendum prevails, including over the Early Access Terms. Our data-protection commitments do not weaken because your account is in early access.
1.4 Changes to this Addendum are handled under the change provisions in the Terms.
2. Definitions
- “APPs” means the Australian Privacy Principles in Schedule 1 to the Privacy Act.
- “Customer Personal Information” means personal information contained in Customer Data that we handle on your behalf, including Participant Data and Worker Data.
- “Eligible Data Breach” has the meaning given in Part IIIC of the Privacy Act.
- “Personal information”, “sensitive information” and “health information” have the meanings given in the Privacy Act.
- “Privacy Act” means the Privacy Act 1988 (Cth).
- “Security Incident” means unauthorised access to, unauthorised disclosure of, or loss of Customer Personal Information held by us or a Subprocessor.
- “Subprocessor” means a service provider we engage that handles Customer Personal Information in helping us deliver the Service.
3. Roles and scope of processing
3.1 As between the parties, you decide what Customer Personal Information is recorded and how it is used. You are responsible for your authority, consents, collection notices, permissions and retention decisions.
3.2 We handle Customer Personal Information on your instructions to provide, support and secure the Service, subject to clause 4.3.
3.3 Annex A describes the subject matter, duration, nature and purpose of our processing, the types of personal information involved, and the categories of individuals it concerns.
3.4 We are independently responsible for information we collect for our own purposes, such as account and billing contacts. Where the Privacy Act applies, we are responsible for that handling under the Act. Our Privacy Policy, rather than this Addendum, governs it.
4. Our processing instructions
4.1 Documented instructions. We will handle Customer Personal Information only on your documented instructions. Your instructions are:
- (a) your use of the features of the Service and the configuration choices you make in it;
- (b) this Addendum and the Terms;
- (c) any written instruction you give us, including a support request asking us to act on a record; and
- (d) anything else we agree in writing.
4.2 When we will tell you an instruction is a problem. If we reasonably believe an instruction would breach applicable Australian law or the agreed privacy standards in this Addendum, we may pause or refuse it and tell you why unless doing so is prohibited or would compromise security.
4.3 The limited exceptions. We may handle Customer Personal Information outside your instructions only where:
- (a) it is necessary to secure, maintain, troubleshoot or operate the Service, including investigating misuse and preventing fraud;
- (b) it is required by Australian law, in which case we will tell you before we act unless the law prohibits us from doing so; or
- (c) it has been genuinely de-identified or aggregated so that no individual, and no Provider, can reasonably be identified, in which case it is no longer personal information.
4.4 Restricted uses. We will not sell Customer Personal Information, use it for advertising, use it to create or benchmark an unrelated commercial data product for other customers, or disclose it to a third party other than as this Addendum permits.
4.5 Government and law-enforcement requests. We respond to a valid request from a regulator, court or law-enforcement body as required by law. Where lawful and appropriate, we may notify you before disclosing Customer Personal Information.
5. Your obligations
5.1 You warrant that you have the authority, lawful basis and consents needed for us to handle the Customer Personal Information you put into the Service, including sensitive and health information.
5.2 You are responsible for the accuracy and relevance of what you record, the permissions you configure, deactivating access when someone leaves, and the lawful use of any feature that collects attendance, activity or work-related location information.
5.3 You must not put into the Service categories of information the Service is not designed to hold, and you must not enter a real person’s identifying details purely for testing or demonstration. Our Acceptable Use Policy sets this out in full.
6. Confidentiality and our personnel
6.1 We restrict access to Customer Personal Information to authorised personnel who require it to provide, support, secure or operate the Service.
6.2 Authorised personnel are subject to confidentiality and security obligations appropriate to their role and access.
7. Security measures
7.1 We will implement and maintain technical and organisational measures appropriate to the sensitivity of Customer Personal Information, designed to protect it from misuse, interference, loss, and unauthorised access, modification or disclosure, consistent with APP 11. Annex B summarises the control categories, and our Security page provides a public overview.
7.2 We may change individual security measures as technology, threats and the Service change, provided the overall safeguards remain appropriate to the information and risk.
7.3 We may provide standard security and privacy information on request. Bespoke questionnaires, meetings, evidence collection or substantial work require separate agreement and may be subject to a fee.
8. Data breach notification and assistance
8.1 We maintain processes to identify, assess, contain and respond to suspected Security Incidents.
8.2 We will notify you without undue delay after confirming a Security Incident affecting your Customer Personal Information. Information may be provided in stages as the investigation develops.
8.3 To the extent reasonably available, we will provide information about the nature and effect of the incident and the steps being taken in response.
8.4 We will provide reasonable assistance with your applicable data-breach obligations. Assistance is subject to law and to the security, confidentiality and rights of other customers and third parties.
8.5 We will make notifications required of us by applicable law. Where lawful and practicable, we will coordinate with you before communicating directly with individuals about Customer Personal Information handled on your behalf.
8.6 A notification under this clause is not an admission of fault or liability.
9. Subprocessors
9.1 Your general authorisation. You authorise us to engage Subprocessors to help deliver the Service. Annex C lists the categories we use. Further information may be provided on request, subject to confidentiality, security and third-party restrictions.
9.2 Flow-down. We require Subprocessors to protect Customer Personal Information through terms appropriate to the service, information and risk involved.
9.3 Our responsibility. Using a Subprocessor does not relieve us of our obligations under this Addendum. Our responsibility remains subject to the allocation of responsibility, exclusions and limits in the Agreement and applicable law.
9.4 Material changes. Where reasonably practicable, we will give advance notice of a new Subprocessor category that materially changes the purpose or data categories described in this Addendum. Routine changes within an existing category do not require separate notice. Urgent security, legal or continuity changes may be notified after implementation.
9.5 You may raise a reasonable objection to a notified change that creates a material data-protection risk. We will consider the objection and any available alternative. If the risk cannot reasonably be resolved, either party may terminate the affected part of the subscription, with any prepaid Fees for the unused terminated period refunded.
10. Data location
10.1 Primary storage of Customer Personal Information as part of the Service is located in Australia.
10.2 A material change to the Australian primary-storage commitment is handled under clause 9.
11. Assistance with individual rights and regulatory obligations
11.1 The Service gives you direct control of many records, so most access and correction requests can be handled through your account.
11.2 If an individual contacts us about a record you control, we may refer the request to you and will not alter or disclose the record unless authorised or required by law.
11.3 Where you cannot action a request through the Service, we will provide reasonable assistance with an access, correction, regulatory enquiry or complaint concerning information handled on your behalf. Substantial or custom work may be charged at a fee agreed before work begins, unless applicable law requires otherwise.
11.4 Any privacy impact or risk assessment remains your responsibility. We may provide standard information under clause 7.3.
12. Audit and information rights
12.1 On written request, we may provide standard information reasonably available to support your assessment of our compliance with this Addendum. We may withhold information that would compromise security, legal privilege, confidentiality or third-party rights.
12.2 Any audit must be required by law or agreed in writing. It must be proportionate, confidential, non-disruptive and limited to Customer Personal Information handled on your behalf. Source code, penetration testing, other customers’ information, privileged material and third-party confidential information are excluded unless disclosure is legally required.
12.3 Unless law requires otherwise or the audit establishes our material breach, you are responsible for the audit and our reasonable support costs.
12.4 We will cooperate with a regulator as required by law.
13. Return and deletion of Customer Data
13.1 While you are a customer. You can use the self-service exports in Section 11 of the Terms at no additional charge. If those tools do not cover a reasonable exit export, we will use commercially reasonable efforts to provide one standard assisted export in the formats we ordinarily support within 30 Business Days, subject to identity, authority, security and technical checks. Custom formats, transformations, repeated requests and substantial engineering work may be charged as set out in the Terms.
13.2 On termination. We will make Customer Data available for export for 30 days after termination or expiry. After that period we will delete or de-identify it, except where we are required to retain something to meet our own legal obligations. Any retained Customer Data remains protected under this Addendum for as long as we hold it.
13.3 Backups. Deleted Customer Data may remain temporarily in backups until those backups expire. If restored for recovery, security or legal purposes, the deletion instruction will be reapplied where reasonably practicable.
13.4 Your record-keeping is not ours. You must determine and meet the retention schedule that applies to your records using your own copies. Export before the exit window closes.
14. Liability, term and general
14.1 This Addendum takes effect when your subscription starts and continues for as long as we hold Customer Personal Information on your behalf. Clauses 6, 8, 12, 13 and this clause 14 survive termination for as long as they are capable of applying.
14.2 Each party’s liability under this Addendum is subject to the limitations and exclusions in Section 18 of the Terms.
14.3 This Addendum is governed by the laws of New South Wales, Australia, and disputes about it follow Section 21 of the Terms.
14.4 Nothing in this Addendum limits either party’s obligations under the Privacy Act or any other law, or an individual’s rights under them.
Annex A: Details of processing
Subject matter. Our provision of the OneForce Care platform and Worker App to you.
Duration. For the term of your subscription, plus the export and deletion periods in clause 13.
Nature and purpose of processing. Collection, recording, organisation, storage, retrieval, use, transmission, backup and deletion of Customer Personal Information to provide, support and secure the Service and the functions selected by you.
Types of personal information. Identity, contact, account, participant, worker, representative, operational, financial, technical and support information entered or generated through the Service, including government-related identifiers and work-related location information where recorded.
Sensitive information. Customer Personal Information may include health information and other sensitive information within the meaning of the Privacy Act.
Categories of individuals. Participants, workers, Provider personnel, representatives, contacts and other people recorded in Customer Data.
Annex B: Security measures
We maintain controls in the following areas:
- access control and authentication;
- encryption and logging;
- backup, recovery and continuity;
- personnel and service-provider controls; and
- incident response.
We may change individual measures as technology, threats and the Service change, subject to clause 7.2. Public descriptions do not include configurations, procedures or evidence that could compromise security or third-party confidentiality.
Annex C: Subprocessor categories
Subprocessors may be engaged for infrastructure and security, operational Service functions, support and administration. A Provider may also select an integration, including Xero.
Clause 10 describes the primary-storage commitment. Further information may be requested from hello@oneforce.com.au, subject to confidentiality, security and third-party restrictions.
Contact
Questions about this Addendum, or requests for additional assurance material or a separate counterpart, can be sent to hello@oneforce.com.au, or by post to Wondertree Studios Pty Ltd, Level 10, 387 George Street, Sydney NSW 2000, Australia. Clauses 1, 7 and 12 explain how those requests are handled.