This Data Processing Agreement ("DPA") forms part of the Terms of Service between:
Customer ("Controller"): The entity that has agreed to the Vyklow Terms of Service
Vyklow Analytics Pty Ltd ("Processor"): ABN 22 688 212 795
Collectively referred to as the "Parties".
"Agreement" means the Terms of Service or other agreement governing the provision of the Products.
"Controller" means the entity that determines the purposes and means of Processing Personal Data.
"Data Protection Laws" means all applicable laws relating to data protection, including GDPR, UK GDPR, Australian Privacy Act, and any other applicable privacy legislation.
"Data Subject" means an identified or identifiable natural person whose Personal Data is Processed.
"GDPR" means Regulation (EU) 2016/679 (General Data Protection Regulation).
"Personal Data" means any information relating to a Data Subject that is Processed by Processor on behalf of Controller through the Products.
"Personal Data Breach" means a breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Data.
"Processing" means any operation performed on Personal Data (and "Process" has a corresponding meaning).
"Sub-processor" means any third party engaged by Processor to Process Personal Data on behalf of Controller.
The Parties acknowledge that Controller is the data controller of the Personal Data, and Processor processes Personal Data on behalf of Controller as a data processor.
This DPA applies to all Processing of Personal Data by Processor in connection with the Products.
In case of conflict between this DPA and the Agreement, this DPA shall prevail with respect to data protection matters.
The details of Processing are set out in Annex I and include the subject matter and duration of Processing, nature and purpose of Processing, types of Personal Data, and categories of Data Subjects.
Controller shall:
Processor shall Process Personal Data only on documented instructions from Controller, unless required by law, and inform Controller if any instruction infringes Data Protection Laws.
Processor shall ensure all personnel processing Personal Data are bound by confidentiality obligations, and not disclose Personal Data to third parties except as permitted by this DPA or required by law.
Processor shall implement appropriate technical and organisational measures to protect Personal Data, as described in Annex II.
Processor shall maintain a list of Sub-processors in Annex III. Controller authorises Processor to use the Sub-processors listed in Annex III. Processor shall notify Controller of intended changes to Sub-processors at least 30 days in advance. Controller may object to a new Sub-processor within 15 days; if the Parties cannot resolve the matter, Controller may terminate the affected Products. Processor shall ensure Sub-processors are bound by equivalent data protection obligations and remains liable for their acts and omissions.
Processor shall assist Controller in responding to Data Subject requests including access, rectification, erasure, portability, restriction, and objection. Processor shall respond to such requests within 10 business days.
In the event of a Personal Data Breach, Processor shall:
Processor shall make available information necessary to demonstrate compliance with this DPA and allow for audits. Controller shall provide 30 days written notice for audits, which shall be conducted during normal business hours at Controller's cost.
Processor shall not transfer Personal Data outside Australia, the EEA, or the UK unless:
For transfers from the EEA, the EU Standard Contractual Clauses (Module Two: Controller to Processor) are incorporated by reference. For transfers from the UK, the UK International Data Transfer Addendum is incorporated by reference.
Controller may export Personal Data at any time through the Products' export functionality. Upon termination of the Agreement, Processor shall, at Controller's choice, return all Personal Data in a standard format or delete all Personal Data. Processor shall complete return or deletion within 30 days of termination and provide written certification of deletion upon request. Processor may retain Personal Data to the extent required by applicable law.
This DPA shall remain in effect for the duration of the Agreement. Provisions that by their nature should survive termination shall survive, including confidentiality, liability, and data deletion obligations.
Each Party's liability under this DPA is subject to the limitations set out in the Agreement. Each Party shall indemnify the other against claims arising from its breach of this DPA or Data Protection Laws.
This DPA may only be amended in writing agreed by both Parties. This DPA is governed by the laws stated in the Agreement (Western Australia, Australia). This DPA, together with its Annexes, constitutes the entire agreement between the Parties regarding data protection.
Processing of Personal Data necessary to provide Vyklow Products as described in the Agreement, including AI governance monitoring, analytics, and related services.
For the term of the Agreement plus 30 days for data deletion.
| Purpose | Processing Activities |
|---|---|
| Service provision | Storing, processing, and displaying monitoring data; generating reports and alerts |
| Support | Accessing data to resolve support requests and troubleshoot issues |
| Security | Logging, monitoring for threats, access control |
| Improvement | Aggregated, anonymised analytics to improve Products |
Contact information (name, email), account credentials, company information, user identifiers, AI tool usage data (URLs, timestamps, redacted prompts), device and browser information, and audit logs.
Controller's employees, Controller's authorised users, and Controller's administrators.
The Products are not intended to process special categories of data (racial origin, health data, political opinions, religious beliefs, etc.). If Controller uploads such data, Controller accepts full responsibility for ensuring lawful processing.
Processor implements the following security measures:
Data hosted on Google Cloud Platform infrastructure with ISO 27001, SOC 2, and other certifications. Google data centres provide 24/7 security, biometric access controls, and environmental controls.
| Sub-processor | Purpose | Location | Website |
|---|---|---|---|
| Google Cloud | Cloud infrastructure and hosting | EU | cloud.google.com |
| Paddle | Payment processing | UK / US | paddle.com |
| Mailjet | Transactional email delivery | EU | mailjet.com |
| Userback | Bug reporting and feedback | Australia | userback.io |
Sub-processor notification: Controller will be notified of changes to this list at the email address associated with their account at least 30 days before any new Sub-processor begins Processing.
For questions about this DPA:
Vyklow Analytics Pty Ltd
ABN: 22 688 212 795
Email: privacy@vyklow.com
Website: www.vyklow.com
Document version: 1.0