Data Processing Agreement

Last updated: 18 December 2025

This Data Processing Agreement ("DPA") forms part of the Terms of Service between:

Customer ("Controller"): The entity that has agreed to the Vyklow Terms of Service

Vyklow Analytics Pty Ltd ("Processor"): ABN 22 688 212 795

Collectively referred to as the "Parties".

1. Definitions

"Agreement" means the Terms of Service or other agreement governing the provision of the Products.

"Controller" means the entity that determines the purposes and means of Processing Personal Data.

"Data Protection Laws" means all applicable laws relating to data protection, including GDPR, UK GDPR, Australian Privacy Act, and any other applicable privacy legislation.

"Data Subject" means an identified or identifiable natural person whose Personal Data is Processed.

"GDPR" means Regulation (EU) 2016/679 (General Data Protection Regulation).

"Personal Data" means any information relating to a Data Subject that is Processed by Processor on behalf of Controller through the Products.

"Personal Data Breach" means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data.

"Processing" means any operation performed on Personal Data (and "Process" has a corresponding meaning).

"Sub-processor" means any third party engaged by Processor to Process Personal Data on behalf of Controller.

2. Scope and Relationship

2.1 Roles

The Parties acknowledge that Controller is the data controller of the Personal Data, and Processor processes Personal Data on behalf of Controller as a data processor.

2.2 Application

This DPA applies to all Processing of Personal Data by Processor in connection with the Products.

2.3 Conflict

In case of conflict between this DPA and the Agreement, this DPA shall prevail with respect to data protection matters.

3. Details of Processing

The details of Processing are set out in Annex I and include the subject matter and duration of Processing, nature and purpose of Processing, types of Personal Data, and categories of Data Subjects.

4. Controller Obligations

Controller shall:

  • Ensure it has a lawful basis for Processing and that all necessary consents have been obtained
  • Provide Processing instructions that comply with Data Protection Laws
  • Ensure the accuracy and quality of Personal Data provided to Processor
  • Respond to Data Subject requests with assistance from Processor where required
  • Comply with all Data Protection Laws in its use of the Products

5. Processor Obligations

5.1 Processing Instructions

Processor shall Process Personal Data only on documented instructions from Controller, unless required by law, and inform Controller if any instruction infringes Data Protection Laws.

5.2 Confidentiality

Processor shall ensure all personnel processing Personal Data are bound by confidentiality obligations, and not disclose Personal Data to third parties except as permitted by this DPA or required by law.

5.3 Security

Processor shall implement appropriate technical and organisational measures to protect Personal Data, as described in Annex II.

5.4 Sub-processing

Processor shall maintain a list of Sub-processors in Annex III. Controller authorises Processor to use the Sub-processors listed in Annex III. Processor shall notify Controller of intended changes to Sub-processors at least 30 days in advance. Controller may object to a new Sub-processor within 15 days; if the Parties cannot resolve the matter, Controller may terminate the affected Products. Processor shall ensure Sub-processors are bound by equivalent data protection obligations and remains liable for their acts and omissions.

5.5 Data Subject Rights

Processor shall assist Controller in responding to Data Subject requests including access, rectification, erasure, portability, restriction, and objection. Processor shall respond to such requests within 10 business days.

5.6 Personal Data Breach

In the event of a Personal Data Breach, Processor shall:

  • Notify Controller without undue delay and within 72 hours
  • Provide sufficient information to enable Controller to meet its notification obligations
  • Cooperate in investigating and mitigating the breach
  • Document the breach, its effects, and remedial actions

5.7 Audit Rights

Processor shall make available information necessary to demonstrate compliance with this DPA and allow for audits. Controller shall provide 30 days written notice for audits, which shall be conducted during normal business hours at Controller's cost.

6. International Data Transfers

Processor shall not transfer Personal Data outside Australia, the EEA, or the UK unless:

  • The transfer is to a country with an adequacy decision
  • Appropriate safeguards are in place (such as Standard Contractual Clauses)
  • An exception under Data Protection Laws applies

For transfers from the EEA, the EU Standard Contractual Clauses (Module Two: Controller to Processor) are incorporated by reference. For transfers from the UK, the UK International Data Transfer Addendum is incorporated by reference.

7. Data Return and Deletion

Controller may export Personal Data at any time through the Products' export functionality. Upon termination of the Agreement, Processor shall, at Controller's choice, return all Personal Data in a standard format or delete all Personal Data. Processor shall complete return or deletion within 30 days of termination and provide written certification of deletion upon request. Processor may retain Personal Data to the extent required by applicable law.

8. Term and Termination

This DPA shall remain in effect for the duration of the Agreement. Provisions that by their nature should survive termination shall survive, including confidentiality, liability, and data deletion obligations.

9. Liability

Each Party's liability under this DPA is subject to the limitations set out in the Agreement. Each Party shall indemnify the other against claims arising from its breach of this DPA or Data Protection Laws.

10. General

This DPA may only be amended in writing agreed by both Parties. This DPA is governed by the laws stated in the Agreement (Western Australia, Australia). This DPA, together with its Annexes, constitutes the entire agreement between the Parties regarding data protection.

Annex I: Details of Processing

1. Subject Matter

Processing of Personal Data necessary to provide Vyklow Products as described in the Agreement, including AI governance monitoring, analytics, and related services.

2. Duration

For the term of the Agreement plus 30 days for data deletion.

3. Nature and Purpose of Processing

Purpose Processing Activities
Service provision Storing, processing, and displaying monitoring data; generating reports and alerts
Support Accessing data to resolve support requests and troubleshoot issues
Security Logging, monitoring for threats, access control
Improvement Aggregated, anonymised analytics to improve Products

4. Types of Personal Data

Contact information (name, email), account credentials, company information, user identifiers, AI tool usage data (URLs, timestamps, redacted prompts), device and browser information, and audit logs.

5. Categories of Data Subjects

Controller's employees, Controller's authorised users, and Controller's administrators.

6. Special Categories of Data

The Products are not intended to process special categories of data (racial origin, health data, political opinions, religious beliefs, etc.). If Controller uploads such data, Controller accepts full responsibility for ensuring lawful processing.

Annex II: Technical and Organisational Measures

Processor implements the following security measures:

1. Access Control

  • Multi-factor authentication for administrative access
  • Role-based access controls
  • Principle of least privilege
  • Regular access reviews
  • Automatic session timeout

2. Encryption

  • TLS 1.2+ for data in transit
  • AES-256 encryption for data at rest
  • Encrypted backups
  • Secure key management procedures

3. Network Security

  • Firewalls and intrusion detection
  • Network segmentation
  • DDoS protection
  • Regular vulnerability scanning

4. Physical Security

Data hosted on Google Cloud Platform infrastructure with ISO 27001, SOC 2, and other certifications. Google data centres provide 24/7 security, biometric access controls, and environmental controls.

5. Operational Security

  • Change management procedures
  • Security incident response plan
  • Regular security training for staff
  • Confidentiality agreements for personnel with data access

6. Data Recovery

  • Automated daily backups
  • Geographically distributed backup storage
  • Regular backup testing
  • Documented recovery procedures

7. Monitoring and Logging

  • Security event logging
  • Automated alerting for anomalies
  • Regular log review

Annex III: Approved Sub-processors

Sub-processor Purpose Location Website
Google Cloud Cloud infrastructure and hosting EU cloud.google.com
Paddle Payment processing UK / US paddle.com
Mailjet Transactional email delivery EU mailjet.com
Userback Bug reporting and feedback Australia userback.io

Sub-processor notification: Controller will be notified of changes to this list at the email address associated with their account at least 30 days before any new Sub-processor begins Processing.

Contact

For questions about this DPA:

Vyklow Analytics Pty Ltd
ABN: 22 688 212 795
Email: privacy@vyklow.com
Website: www.vyklow.com

Document version: 1.0