At a glance
Summary
Business Account
Controls the purpose and authority for Customer Data entered into Crewzon.
Crewzon
Processes Customer Data for the agreed service and lawful instructions; cross-business reuse is prohibited.
Subprocessors
Authorised processing, advance material-change notices and an objection process.
Overview
This Data Processing Addendum (**DPA**) forms part of the Crewzon Terms of Service between NOT ANOTHER APP BUILDER PTY. LTD. (ACN 699 954 071, ABN 92 699 954 071) trading as Crewzon and the Business Account.
It applies to Crewzon's processing of Customer Data for the Business Account. It is designed for Australian business customers. A signed customer agreement may add requirements for another jurisdiction.
1. Definitions and roles
Terms defined in the Terms of Service have the same meaning here.
- **Data Protection Law** means privacy, data-protection and data-breach law
applicable to the relevant processing, including the Privacy Act 1988 (Cth) where it applies.
- **Security Incident** means unauthorised access to, disclosure of, loss,
alteration or destruction of Customer Data handled by Crewzon or its Subprocessors for the Services. It excludes unsuccessful attempts that do not compromise Customer Data and incidents caused solely within the Business Account's systems or accounts unless Crewzon contributed to them.
- **Subprocessor** means a third party engaged by Crewzon to process Customer
Data for the Services.
The Business Account ordinarily determines the work purposes and instructions for its Customer Data. Crewzon supplies the processing service. Controller and processor terminology is descriptive; it does not import GDPR requirements into Australian law or displace either party's own applicable obligations. Crewzon cannot rely solely on the business's employee-records exemption.
Crewzon separately determines the handling of its own account, billing, security, support, product-analytics and business-administration information as described in the Privacy Policy.
2. Scope and processing instructions
The subject matter is the Customer Data submitted to or generated through the Services. Processing continues for the subscription and any lawful retention period. The nature and purposes are hosting, storage, retrieval, transmission, organisation, support, security, deletion and other operations needed to provide the configured Services. Data subjects may include the Business Account's workers, contractors, customers, site contacts, suppliers and other people recorded in its workspace.
Crewzon will process Customer Data only:
- to provide, secure, maintain and support the Services;
- on documented instructions expressed through the agreement, the Business
Account's configuration and lawful directions from authorised users;
- to prevent or investigate fraud, misuse or a Security Incident; or
- as required by law.
Crewzon will notify the Business Account if it reasonably believes an instruction infringes applicable Data Protection Law and may suspend that instruction while the parties resolve it. If law requires processing beyond an instruction, Crewzon will notify the Business Account before processing unless the law prohibits notice.
Crewzon will not sell Customer Data, pool it across businesses, use it for advertising or benchmarking, or train models on it. De-identification does not authorise those uses. Business-specific reporting remains governed by lawful instructions; minimised operational telemetry is described separately in the Privacy Policy.
3. Business Account obligations
The Business Account must:
- have a lawful basis, authority and any required consent for Customer Data;
- give required privacy, workplace-surveillance and collection notices;
- ensure its instructions and use of Crewzon comply with law;
- minimise Customer Data and avoid sensitive information unless necessary and
lawful;
- authorise users, configure roles and promptly revoke unnecessary access;
- handle requests and decisions for Customer Data it controls; and
- provide Crewzon with information reasonably needed to meet an instruction or
legal obligation.
Sensitive-information instructions require a documented necessary purpose and consent that covers Crewzon's processing, or a documented exception applicable to that processing. Crewzon must assess its own legal basis and take proportionate steps where information is excessive, withdrawn or supplied unlawfully. General acceptance of this DPA does not constitute an individual's sensitive-data consent.
4. Confidentiality and personnel
Crewzon will treat Customer Data as confidential and limit access to personnel, contractors and Subprocessors with a legitimate need. People authorised by Crewzon to process Customer Data must be bound by confidentiality obligations and receive appropriate security and privacy direction.
5. Security
Crewzon will maintain technical and organisational measures appropriate to the risk, taking account of the nature of Customer Data, available technology, implementation cost and likely consequences of misuse, interference, loss or unauthorised access, modification or disclosure.
Measures include appropriate encryption in transit and at rest, with business-scoped application encryption for protected fields/files as described in the Security statement, role and tenant access controls, secure authentication, logging and monitoring, backup and recovery processes, secure development practices and personnel access controls. Current and configuration-dependent measures are described in Security and Authentication. Crewzon may evolve the measures provided it does not materially reduce the overall protection of Customer Data during the service, including free access, without a valid legal, security or technical reason and appropriate mitigation.
6. Security incidents and data breaches
Crewzon will notify the affected Business Account without undue delay after becoming aware of a Security Incident, or reasonable grounds to suspect one, materially affecting its Customer Data. This includes incidents at a Subprocessor. Crewzon will not wait for final confirmation or completion of its investigation. Unsuccessful attacks with no reasonable indication of compromise need not be reported individually.
Initial notice will identify what is known, uncertainties, affected data and systems where known, immediate protective steps and a contact. Crewzon will provide staged material updates and a closure summary, preserve proportionate evidence and coordinate with the business on containment and required notices. No party must await the other's approval to satisfy a legal notification duty. Notice is not an admission of fault.
Where the NDB scheme applies, assessment begins on awareness of reasonable grounds for suspicion and proceeds reasonably and expeditiously, with all reasonable steps taken to finish within 30 calendar days. Required OAIC and individual notices follow as soon as practicable when the legal threshold is met. This statutory assessment period does not postpone the customer notice required above. Crewzon seeks prompt incident escalation from Subprocessors.
7. Individual rights and regulatory assistance
Taking account of the nature of processing and available functionality, Crewzon will provide reasonable assistance where the Business Account cannot reasonably respond itself to a request for access, correction, deletion or another applicable privacy right. Crewzon may refer a requester to the Business Account where it controls the relevant Customer Data.
Crewzon will provide reasonable information and cooperation for a privacy impact assessment, regulator enquiry or consultation concerning the Services where required by Data Protection Law and not reasonably available to the Business Account. Additional work outside standard functionality may be subject to agreed reasonable fees unless caused by Crewzon's breach. This does not authorise charges prohibited by law or make a statutory right conditional on a subscription payment or purchase of assistance.
8. Subprocessors
The Business Account authorises only the providers identified as authorised subprocessors in the edition supplied with its agreement, for the stated processing. Providers marked Planned in the register are not authorised to receive Customer Data through those planned services. User-selected services acting for their own purposes are identified separately; mixed roles are assessed by processing activity.
Crewzon will impose appropriate confidentiality, security, incident assistance, return/deletion and processing restrictions on its Subprocessors and remains responsible for their performance of Crewzon's contracted processing obligations.
For a material addition or replacement, Crewzon will ordinarily give at least 30 days' direct notice before processing starts, stating identity, purpose, data and likely countries. The business may object on documented privacy or security grounds within 14 days. Crewzon will consider an alternative or other reasonable solution before disputed processing begins. If none is feasible, the business may terminate the affected service and receive a proportionate refund of unused prepaid fees. Urgent changes necessary for security or law may proceed with prompt notice, reasons and the same objection/remedy process.
9. Overseas processing
Customer Data may be processed in Australia and in the likely locations listed for each Subprocessor. Where Australian Privacy Principle 8 applies, Crewzon will take reasonable steps in the circumstances before an overseas disclosure to require appropriate handling unless an exception applies. Crewzon remains accountable for an overseas recipient where section 16C of the Privacy Act 1988 (Cth) applies.
10. Government and third-party requests
Unless prohibited by law or an immediate security risk, Crewzon will notify the Business Account of a legally binding government or third-party demand directed to Crewzon for its Customer Data. Crewzon will disclose only what it reasonably believes is legally required and may challenge an overbroad demand where there are reasonable grounds and it is proportionate to do so.
11. Return, export and deletion
During the subscription, the Business Account may use available exports. The Terms and deletion notice provide the exit request period, available formats and assistance terms. Available exports do not necessarily include the whole workspace. Crewzon identifies included and excluded records in an export manifest; contact accounts@crewzon.com about records unavailable through self-service exports. Crewzon will not withhold a statutory privacy right merely because subscription charges are disputed.
After termination or a valid instruction, Crewzon will return requested available data and dispose of unneeded Customer Data under the retention schedule, using deletion or legally sufficient de-identification as appropriate. This does not permit cross-business reuse. An instruction to delete operational data is not satisfied merely by retaining an anonymised business copy. Exceptions apply only to information Crewzon must or may lawfully retain for tax, accounting, security, fraud, dispute, legal-hold or similar purposes. Residual backup copies may remain until ordinary rotation and remain protected and unavailable for routine use. The record-class periods and purposes are described in the Data Retention Schedule. Closure and archive states are distinct from completed deletion. Restricted compliance evidence and records under a valid hold may remain after operational deletion. Restored copies must be reconciled against current deletion and hold information before service resumes; unverifiable recovery remains isolated. These measures do not erase copies already exported to the Business Account or its recipients. Further detail is in Account Deletion and Data Retention.
12. Information and audits
On reasonable written request, Crewzon will provide information reasonably necessary to demonstrate compliance with this DPA, including available security documentation or independent assurance when it exists.
If that information is insufficient for a legally required assessment, the Business Account may request a further review no more than once in 12 months, unless a Security Incident or regulator reasonably requires more. A review must be scoped in advance, occur during business hours, avoid access to another customer's data and Crewzon's penetration pathways or secrets, minimise disruption, and be subject to confidentiality. The Business Account bears its cost unless the review identifies a material Crewzon breach.
13. Liability and priority
Liability arising under this DPA shares the single aggregate cap in section 21 of the Terms of Service, including its exceptions; this DPA does not create a separate or higher cap unless a signed agreement expressly states otherwise. If this DPA conflicts with the Terms, this DPA prevails only for processing of Customer Data. A signed agreement prevails only to the extent it expressly changes this DPA.