PostMyDoc Business – Data Processing Agreement
This Data Processing Agreement governs PostMyDoc’s processing of Customer Personal Data on behalf of Business customers and is structured to satisfy Article 28 of the EU General Data Protection Regulation (GDPR) where it applies.
1. Parties
This Data Processing Agreement (Agreement or DPA) is made between:
1.1 PostMyDoc Digital Mailing Service Pty Ltd ACN 697 539 512, trading as PostMyDoc, ABN 18 697 539 512, of 82 Onkaparinga Valley Road, Woodside, South Australia 5244 (PostMyDoc, we, us or the Processor); and
1.2 the business customer identified in the PostMyDoc Business account application and approved by PostMyDoc (Customer, you or the Controller),
1.3 each a party and together the parties.
2. Background
2.1 PostMyDoc operates a digital-to-physical mail service. A Customer submits one or more PDF Files and delivery instructions through the Business Portal or another ordering channel accepted by PostMyDoc. PostMyDoc prepares and prints the PDF File Content, places it into one or more Envelopes and dispatches each Envelope to the nominated recipient through Australia Post. PDF File Content is then deleted in accordance with the Burn After Reading Policy and the lifecycle applicable to each custody channel (the Services).
2.2 This Agreement governs PostMyDoc’s Processing of Personal Data on the Customer’s behalf in connection with the Services and a Business account, regardless of whether the relevant business order or instruction is submitted through the Business Portal, by email, by telephone or through another ordering channel accepted by PostMyDoc. It forms part of, and is supplemental to, the PostMyDoc Business Terms of Service between the parties (the Principal Agreement).
2.3 The parties acknowledge that, in performing the Services, PostMyDoc processes Personal Data for which the Customer is responsible as Controller, and that this Agreement is required by Article 28(3) of the GDPR (where it applies) and supports the parties’ obligations under the Privacy Act 1988 (Cth).
3. Definitions and interpretation
3.1 In this Agreement, unless the context requires otherwise:
“APPs” means the Australian Privacy Principles set out in Schedule 1 to the Privacy Act.
“Australian Privacy Law” means the Privacy Act, the APPs, the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act, and any related binding code, guideline or determination of the OAIC, each as amended from time to time.
“Authorised Users” means the natural persons whom the Customer permits to access and use the Business Portal under the Customer’s Business account, comprising the Primary Contact and any additional business users the Customer adds. Each Authorised User acts for and on behalf of the Customer, and the access available to an Authorised User is determined by the role the Customer assigns (by default, a business user other than the Primary Contact can see only their own orders).
“Burn After Reading Policy” means PostMyDoc’s operating commitment under which PDF File Content is retained only for the period applicable to each custody channel and is deleted or securely destroyed in accordance with this Agreement. This includes the automated purge of stored server-side PDF Files, deletion of each Print-Agent Copy at the end of its single print attempt, deletion of Local Operational Copies and customer-initiated email copies, and secure destruction of returned physical mail, subject to the lifecycle applying to each custody channel. The automated purge operates independently of whether the relevant Envelope has been dispatched.
“Business Order” means an order treated by PostMyDoc as an order of the Customer under its approved Business account, regardless of whether it is submitted through the Business Portal, by email, by telephone or through another ordering channel accepted by PostMyDoc.
“Controller” means the entity that, alone or jointly, determines the purposes and means of the Processing of Personal Data; for the Customer Personal Data this is the Customer. “Controller” includes an “APP entity” that determines those matters for the purposes of Australian Privacy Law.
“Customer Personal Data” means any Personal Data that PostMyDoc Processes on behalf of the Customer under or in connection with the Services and the Business Portal, as described in Annex 1. It does not include data that PostMyDoc Processes as a Controller in its own right (see clause 4.4).
“Data Protection Laws” means all laws applicable to the Processing of Customer Personal Data under this Agreement, including Australian Privacy Law and, where applicable to a party in respect of the relevant Processing, the GDPR and the UK GDPR.
“Data Subject” means an identified or identifiable individual to whom Personal Data relates.
“Eligible Data Breach” means an “eligible data breach” as defined in Part IIIC of the Privacy Act.
“Envelope” means the individual physical mailing unit prepared for dispatch under a Business Order. An Envelope may contain one or more document files, and an order may contain one or more Envelopes, including multiple Envelopes addressed to the same recipient.
“GDPR” means Regulation (EU) 2016/679 (the EU General Data Protection Regulation); and UK GDPR means the GDPR as it forms part of the law of the United Kingdom by virtue of the European Union (Withdrawal) Act 2018, together with the Data Protection Act 2018 (UK).
“Local Operational Copy” means a temporary copy of PDF File Content downloaded or created on an access-controlled local device by, or at the direction of, authorised PostMyDoc personnel where reasonably necessary to prepare, print, dispatch or complete manual or exceptional fulfilment of a Business Order. It does not include a Print-Agent Copy.
“Notifiable Data Breaches scheme” or “NDB scheme” means the scheme established under Part IIIC of the Privacy Act.
“OAIC” means the Office of the Australian Information Commissioner, including the Australian Information Commissioner and the Privacy Commissioner.
“PDF File” means a document file in Portable Document Format submitted by or on behalf of the Customer to PostMyDoc for processing as part of a Business Order, whether submitted through the Business Portal, by email or through another ordering channel accepted by PostMyDoc. “PDF File Content” means the content contained in a PDF File.
“Personal Data” means information relating to a Data Subject that is protected as “personal data” under the GDPR or the UK GDPR, or as “personal information” under the Privacy Act. References to “Personal Data” include “personal information” and the two terms are used interchangeably in this Agreement.
“Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data, including any event that is or may be an Eligible Data Breach.
“Primary Contact” means the Authorised User the Customer nominates as the administrator of its Business account (shown in the Portal as the Account Admin). The Primary Contact is authorised to act for the Customer in relation to the account — including to accept this Agreement and the related PostMyDoc Business legal documents on the Customer’s behalf, to add and remove other Authorised Users and set their access, and to give account-level and written instructions to PostMyDoc — and has visibility of all orders within the Customer’s account.
“Print-Agent Copy” means a temporary decrypted copy of a PDF File created automatically within the restricted working directory of PostMyDoc’s on-premises print agent solely to submit the PDF File Content to the local print system for a single print attempt. A Print-Agent Copy does not include a Local Operational Copy.
“Privacy Act” means the Privacy Act 1988 (Cth).
“Processing” means any operation performed on Personal Data, whether or not by automated means, including collection, recording, storage, use, transmission, printing, disclosure, erasure and destruction (and Process and Processed have corresponding meanings).
“Processor” means the entity that Processes Personal Data on behalf of the Controller; for the Customer Personal Data this is PostMyDoc.
“Sensitive Information” means “sensitive information” as defined in the Privacy Act (which includes health information), and “special categories of personal data” within the meaning of Article 9 of the GDPR, together with personal data relating to criminal convictions and offences.
“Standard Contractual Clauses” or “SCCs” means the standard contractual clauses adopted by the European Commission under Article 46(2)(c) or Article 46(2)(d) of the GDPR, as amended, replaced or superseded from time to time.
“Sub-processor” means any third party engaged by PostMyDoc (or by a Sub-processor) to Process Customer Personal Data in connection with the Services.
“Supervisory Authority” means the OAIC and, where the GDPR or UK GDPR applies, any competent supervisory authority responsible for monitoring the application of those laws.
“Technical and Organisational Measures” or “TOMs” means the measures described in Annex 2.
“UK Addendum” means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the United Kingdom Information Commissioner under section 119A of the Data Protection Act 2018 (UK), as amended, replaced or superseded from time to time.
“UK IDTA” or “IDTA” means the International Data Transfer Agreement issued by the United Kingdom Information Commissioner under section 119A of the Data Protection Act 2018 (UK), as amended, replaced or superseded from time to time.
3.2 Interpretation: (a) headings are for convenience only and do not affect interpretation; (b) the singular includes the plural and vice versa; (c) a reference to legislation includes any subordinate legislation and any amendment, consolidation or replacement of it; (d) “including” and similar expressions are not words of limitation; and (e) where a term is defined in the Data Protection Laws but not in this Agreement, it has the meaning given in those laws.
3.3 If there is any inconsistency between the documents forming the arrangement between the parties, the order of precedence in clause 19.2 applies.
4. Status and roles of the parties
4.1 In respect of the Customer Personal Data, the Customer is the Controller and PostMyDoc is the Processor.
4.2 The Customer warrants that it has a lawful basis to Process, and to authorise PostMyDoc to Process, the Customer Personal Data for the purposes described in Annex 1, including where the documents it submits contain Personal Data of recipients or of third parties, and including any Sensitive Information.
4.3 The Customer is responsible for the accuracy, quality and lawfulness of the Customer Personal Data and of the instructions it gives to PostMyDoc, and for providing all notices to, and obtaining all consents from, Data Subjects required under the Data Protection Laws for the Processing contemplated by this Agreement.
4.4 PostMyDoc as an independent Controller. Separately from its role as Processor, PostMyDoc acts as a Controller for limited purposes of its own, including operating, securing and improving the Services, account administration, billing and the keeping of financial records, fraud prevention and meeting its own legal obligations. That Processing is governed by PostMyDoc’s own privacy policy and not by this Agreement. This Agreement governs only PostMyDoc’s Processing of Customer Personal Data as Processor.
4.5 Nothing in this Agreement makes the parties joint controllers.
5. Scope of this Agreement
5.1 In scope. This Agreement applies to PostMyDoc’s Processing of Customer Personal Data in connection with the Customer’s Business account and Business Orders, including:
(a) the Business account application and account approval workflow;
(b) all customer-facing surfaces of the Business Portal, including order creation, recipient entry, address-book and saved-recipient features, team and invitation management, account management, billing, invoices and statements;
(c) Business Orders submitted through the Business Portal, by email, by telephone or through another ordering channel accepted by PostMyDoc;
(d) the B2B order pipeline, including receiving PDF Files and delivery instructions, preparing Envelopes, automatically transferring and decrypting PDF File Content for the on-premises print agent, creating a temporary Print-Agent Copy for a single print attempt, creating a Local Operational Copy where reasonably necessary for manual or exceptional fulfilment, printing PDF File Content, dispatching Envelopes through Australia Post, processing associated recipient and dispatch data, and deleting PDF File Content under the Burn After Reading Policy;
(e) processing associated recipient, order, dispatch, tracking, return, reposting and deletion data;
(f) holding, reposting and securely destroying returned physical mail in accordance with clause 14;
(g) the business-context transactional email surfaces, including order confirmation, dispatch, delivery, first-deletion, weekly digest and account or approval emails; and
(h) the Business account metadata described in Annex 1.
5.2 Out of scope. This Agreement does not apply to, and Customer Personal Data does not include, Personal Data Processed in connection with:
(a) an order placed by a person or entity that does not hold an approved Business account, even if that order is submitted by telephone or email, unless PostMyDoc expressly agrees in writing to treat it as a Business Order;
(b) browsing of the consumer PostMyDoc website, which is governed by the consumer Privacy Policy;
(c) the consumer PostMyDoc mobile application, which is governed by its own privacy policy and the relevant app-store terms; or
(d) the Chatway chat widget, which operates only on consumer surfaces and is disabled across the Business Portal, and which is governed by the consumer Privacy Policy.
5.3 Pre-sale browsing of PostMyDoc’s marketing pages by a prospective Customer is evaluative and is governed by the consumer Privacy Policy until a Business account is approved and the Services commence.
6. Compliance with Data Protection Laws
6.1 Each party will comply with the Data Protection Laws that apply to it in respect of the Processing under this Agreement.
6.2 PostMyDoc will Process the Customer Personal Data in a manner that enables the Customer to comply with its own obligations under the Data Protection Laws, and will not, by act or omission, cause the Customer to be in breach of those laws.
6.3 GDPR and UK GDPR processor terms. Where the GDPR or UK GDPR applies to a Customer in respect of the relevant Processing, including where the Customer is established in the EEA or the United Kingdom or otherwise falls within the territorial scope of those laws, this Agreement is the parties’ agreement for the purposes of Article 28(3) of the GDPR and the equivalent provision of the UK GDPR. Clauses 7 to 16 are to be read as giving effect to the applicable requirements of Article 28(3). For the avoidance of doubt, this Agreement does not itself incorporate or constitute the Standard Contractual Clauses, the UK Addendum, the IDTA or any other transfer mechanism required under Chapter V of the GDPR or the equivalent provisions of the UK GDPR.
6.4 Australian Privacy Law applies to the Processing under this Agreement regardless of whether the GDPR or UK GDPR also applies.
7. Processing of Personal Data
7.1 Documented instructions. PostMyDoc will Process the Customer Personal Data only on the Customer’s documented instructions, including in relation to any transfer of Personal Data outside Australia, unless required to Process the data by a law to which PostMyDoc is subject. The Customer’s documented instructions are constituted by this Agreement, the Principal Agreement, the configuration and Business Orders submitted by the Customer or its Authorised Users through the Business Portal, instructions submitted through another ordering channel accepted by PostMyDoc, and any further written instructions the parties agree. PostMyDoc may make and use a temporary Local Operational Copy where reasonably necessary to carry out those instructions and fulfil the relevant Business Order.
7.2 Required by law. If a law requires PostMyDoc to Process the Customer Personal Data otherwise than on the Customer’s instructions, PostMyDoc will, to the extent permitted by that law, inform the Customer of the legal requirement before Processing.
7.3 Unlawful instructions. PostMyDoc will inform the Customer without undue delay if, in its opinion, an instruction infringes the Data Protection Laws, and may suspend performance of the affected instruction (without liability) until the Customer confirms or amends it. PostMyDoc is not obliged to provide legal advice on the Customer’s instructions.
7.4 How instructions are given. Routine, order-level instructions may be given by the Customer’s Authorised Users through the Business Portal or through another ordering channel accepted by PostMyDoc, within the authority and access each Authorised User has been granted. Account-level instructions and other written instructions are given by the Primary Contact for and on behalf of the Customer to PostMyDoc’s privacy contact at privacy@postmydoc.au. The Customer is responsible for the authority and conduct of its Authorised Users, including the Primary Contact, for ensuring that only authorised persons issue instructions, and for the access and authority it grants to each person within its account.
8. Confidentiality
8.1 PostMyDoc will treat the Customer Personal Data as confidential and will not disclose it except as permitted by this Agreement or required by law.
8.2 PostMyDoc will ensure that each person it authorises to Process the Customer Personal Data (including any personnel and contractors) is subject to a binding obligation of confidentiality — whether by written agreement, a professional duty of confidence, or a duty implied at law — and is made aware of the confidential nature of the data.
8.3 PostMyDoc will ensure that access to the Customer Personal Data is limited to those persons who need access to perform the Services, and will take reasonable steps to ensure the reliability of any such person.
9. Security of processing
9.1 PostMyDoc will implement and maintain the Technical and Organisational Measures described in Annex 2, which are designed to ensure a level of security appropriate to the risk, having regard to the state of the art, the costs of implementation, and the nature, scope, context and purposes of the Processing, as well as the risk of varying likelihood and severity to the rights and freedoms of Data Subjects.
9.2 In implementing those measures, PostMyDoc will take account of the matters in Article 32 of the GDPR (including, as appropriate, pseudonymisation and encryption, confidentiality, integrity, availability and resilience, the ability to restore availability and access after an incident, and a process for regularly testing and evaluating the measures) and of the requirement in APP 11 of the Privacy Act to take reasonable steps — including reasonable technical and organisational measures — to protect Personal Data from misuse, interference and loss, and from unauthorised access, modification or disclosure.
9.3 PostMyDoc may update the TOMs from time to time provided that the updated measures do not materially reduce the overall level of protection of the Customer Personal Data.
9.4 PDF File handling and deletion.
(a) As security and data-minimisation measures, PostMyDoc operates the Burn After Reading Policy. PDF Files stored on PostMyDoc’s live server are encrypted in transit and at rest and retained temporarily for printing and dispatch.
(b) An automated, scheduled server-side purge process runs hourly and removes each stored PDF File from live server storage when that file becomes more than 24 hours old. The purge timetable is measured from the age of the PDF File in live server storage and does not depend on whether the associated Envelope has been dispatched.
(c) A PDF File may be deleted before or after the associated Envelope is dispatched, while the associated Business Order is awaiting payment settlement or another pre-dispatch step, after the associated Business Order or Envelope is cancelled, or where the associated Envelope is never dispatched.
(d) For automated printing, PostMyDoc’s on-premises print agent retrieves the relevant PDF File Content from the server over an encrypted HTTPS connection, decrypts it for printing and writes a Print-Agent Copy to a restricted working directory.
(e) The working directory used by the print agent is accessible only to the operating-system account under which the print agent runs, and each Print-Agent Copy is readable and writable only by that account.
(f) The print agent submits the Print-Agent Copy to the local print system solely for one print attempt and deletes the Print-Agent Copy at the end of that attempt, whether the attempt succeeds or fails.
(g) The print agent does not retain a Print-Agent Copy between print attempts. A later print attempt requires the print agent to retrieve the PDF File Content again while it remains available, or requires an authorised Local Operational Copy or resubmission by the Customer.
(h) Where a stored server-side PDF File has been deleted before fulfilment is complete, an authorised Local Operational Copy may be retained only as long as reasonably necessary to fulfil the Business Order.
(i) Access to a Local Operational Copy is limited to authorised personnel who require access to prepare, print or dispatch the relevant Envelope, and the copy must not be used for another purpose.
(j) Each Local Operational Copy is deleted promptly after dispatch is confirmed or, if fulfilment does not proceed, promptly after cancellation or closure of the Business Order.
(k) Business Portal administrative and transactional notifications do not include PDF Files as email attachments.
(l) Deletion by the automated purge removes the stored PDF File from the live file system and is not cryptographic erasure. Back-up copies are handled separately under clause 14.7.
(m) When the automated purge deletes a PDF File from live server storage, PostMyDoc’s system records the deletion event for the relevant PDF File and associated Envelope. That deletion record is created when the purge occurs, whether or not the Envelope has been dispatched. Dispatch information, if any, is recorded separately.
(n) After a PDF File has been deleted from live server storage, PostMyDoc cannot recover or re-send that file from the live system. After every active operational copy has been deleted, PostMyDoc cannot recover or re-send the PDF File Content. If the PDF File is required again, the Customer must submit it again through an available intake channel.
10. Sub-processing
10.1 General authorisation. The Customer gives PostMyDoc general written authorisation to engage the Sub-processors identified in Part A of Annex 3 and to engage additional or replacement Sub-processors in accordance with this clause 10. The Customer acknowledges that PostMyDoc may also disclose Customer Personal Data to independent recipients identified in Part B of Annex 3 where reasonably necessary to carry out the Customer’s documented instructions, provide the Services or comply with law. A recipient’s inclusion in Part B does not make that recipient a Sub-processor.
10.2 Notice and objection. PostMyDoc will inform the Customer of any intended addition or replacement of a Sub-processor at least fourteen (14) days before that Sub-processor begins Processing Customer Personal Data, giving the Customer the opportunity to object. If the Customer objects on reasonable data-protection grounds within that period, the parties will work in good faith to resolve the objection; if it cannot be resolved, the Customer may terminate the affected Services on written notice, as its sole remedy.
10.3 Sub-processor protections.
(a) Before engaging a Sub-processor, PostMyDoc will take reasonable steps, proportionate to the nature and privacy risk of the Processing, to assess the Sub-processor’s privacy and security practices and the terms available for the service.
(b) Where reasonably available, PostMyDoc will enter into a written contract with the Sub-processor that imposes obligations concerning:
(i) confidentiality and permitted use;
(ii) information security;
(iii) notification and management of Personal Data Breaches;
(iv) engagement of further Sub-processors;
(v) return, deletion and retention of Customer Personal Data;
(vi) assistance with Data Subject requests and regulatory obligations; and
(vii) international transfers.
10.3(c) If a supplier or other recipient that Processes Customer Personal Data in connection with the Services does not provide or accept suitable contractual data-protection terms, PostMyDoc may engage or continue to engage that supplier or make or continue the relevant disclosure only after:
(i) documenting the absence or limitation of contractual protection;
(ii) assessing the categories and sensitivity of the Customer Personal Data involved, the purpose and frequency of the Processing, the location of the recipient, retention practices, onward disclosures, reasonably available security information and the consequences of unauthorised access, use or disclosure;
(iii) considering whether the same function can reasonably be obtained through a provider offering stronger contractual protection or through a local or reduced-data mode;
(iv) implementing reasonable supplementary technical and organisational measures within PostMyDoc’s control;
(v) accurately identifying the supplier or recipient, its role or unresolved status, the relevant Processing, locations and material residual limitations in the applicable Part of Annex 3;
(vi) accurately disclosing in Annex 2 any material residual limitation affecting the Technical and Organisational Measures; and
(vii) recording the basis on which PostMyDoc considers continued use reasonable in the circumstances.
(d) PostMyDoc will periodically review each engagement under clause 10.3(c), and will also review it following:
(i) a material change to the data transmitted, service operation, recipient, location, retention practice or supplier terms;
(ii) a Personal Data Breach or material security concern involving the Sub-processor;
(iii) evidence that the Sub-processor’s published description does not accurately describe the Processing; or
(iv) the availability of a reasonably practicable alternative providing materially stronger privacy protection.
(e) PostMyDoc will not describe a supplier’s published privacy or security statement as a contractual obligation unless it forms part of an enforceable agreement applying to the relevant Processing.
(f) The absence of suitable supplier terms, or the disclosure of a material residual limitation in Annex 2 or Annex 3, does not reduce PostMyDoc’s responsibility under clause 10.4 or its obligations to the Customer under this Agreement or applicable Data Protection Laws.
10.4 Responsibility.
(a) PostMyDoc remains responsible to the Customer for the performance of each Sub-processor’s obligations to the extent required by the Data Protection Laws.
(b) PostMyDoc remains accountable for the acts or practices of an overseas recipient to the extent provided by APP 8 and section 16C of the Privacy Act.
(c) A limitation in PostMyDoc’s agreement with a Sub-processor, or disclosure of a Sub-processor limitation in Annex 2 or Annex 3, does not:
(i) reduce any obligation PostMyDoc owes to the Customer under this Agreement or applicable Data Protection Laws;
(ii) transfer PostMyDoc’s responsibility to the Customer;
(iii) constitute a warranty that the Sub-processor complies with the APPs; or
(iv) establish that PostMyDoc has satisfied APP 8.1 in every circumstance.
10.5 An up-to-date list of authorised Sub-processors is maintained in Part A of Annex 3 and is available to the Customer on request.
10.6 Independent recipients and permitted disclosures.
(a) PostMyDoc may disclose Customer Personal Data to an independent recipient identified in Part B of Annex 3 only:
(i) on the Customer’s documented instructions;
(ii) where reasonably necessary to perform the Services requested by the Customer, including physical dispatch, delivery, tracking, return and reposting;
(iii) where required by applicable law or valid and binding legal compulsion; or
(iv) where another permitted basis is expressly stated in this Agreement.
(b) An independent recipient determines the purposes and means of its own Processing to the extent required to perform its independent function and does not Process Customer Personal Data solely on PostMyDoc’s behalf.
(c) Before making a disclosure under this clause, PostMyDoc will:
(i) limit the Customer Personal Data disclosed to what is reasonably necessary for the relevant function;
(ii) take reasonable steps to assess the recipient, the nature and sensitivity of the data, the purpose of the disclosure, available privacy and security information, known locations, retention practices and the likely consequences of unauthorised access, use or disclosure;
(iii) apply reasonable technical and organisational safeguards within PostMyDoc’s control;
(iv) seek appropriate contractual or other protections where reasonably available and appropriate to the recipient’s role; and
(v) accurately describe in Part B of Annex 3 the recipient, the purpose of the disclosure, the categories of Customer Personal Data disclosed, the recipient’s role and the known location of the Processing.
(d) PostMyDoc remains responsible for its own decision to disclose Customer Personal Data and for complying with this Agreement and applicable Data Protection Laws in making that disclosure. PostMyDoc does not warrant that an independent recipient will comply with obligations that apply to PostMyDoc as Processor and that are not applicable to the recipient in its own capacity.
(e) Clauses 10.2 to 10.4 do not apply to an independent recipient merely because it is listed in Part B of Annex 3. This does not limit PostMyDoc’s responsibility under APP 8 or section 16C of the Privacy Act where those provisions apply.
(f) If an entity performs more than one function, its role will be assessed separately for each function. The same entity may therefore appear in more than one Part of Annex 3 where it acts in different capacities for different Processing activities.
10.7 Suppliers with material residual limitations or status requiring confirmation.
(a) Part C of Annex 3 identifies:
(i) a supplier that Processes Customer Personal Data in connection with the Services but does not provide or accept suitable contractual data-protection terms for the relevant Processing;
(ii) a supplier whose role as Sub-processor, independent recipient or separate Controller cannot be finally classified without further operational or contractual confirmation;
(iii) a proposed or conditional supplier function that has not yet been activated; or
(iv) another engagement for which a material residual privacy, security, retention, location or contractual limitation must be disclosed.
(b) Inclusion in Part C does not, by itself:
(i) authorise PostMyDoc to commence a proposed or conditional Processing activity;
(ii) constitute the Customer’s general authorisation under clause 10.1;
(iii) establish that the supplier is a Sub-processor, independent recipient or Controller;
(iv) establish that the supplier is contractually bound to comply with the APPs or the obligations in this Agreement; or
(v) establish that PostMyDoc has complied with APP 8.1 or another applicable transfer requirement.
(c) PostMyDoc may use a supplier described in Part C for an existing Processing activity only where PostMyDoc has completed and documented the assessment and safeguards required by clause 10.3(c), and the entry in Part C accurately states:
(i) the supplier and service;
(ii) the Processing activity and categories of Customer Personal Data involved;
(iii) the known Processing locations;
(iv) the supplier’s current role or the reason that role remains unresolved;
(v) the relevant contractual, privacy, security, retention or transfer limitation;
(vi) the supplementary measures applied by PostMyDoc;
(vii) any restrictions placed on the engagement; and
(viii) whether the Processing activity is active, inactive, proposed or conditional.
(d) Before activating a proposed or conditional Processing activity in Part C, PostMyDoc will:
(i) complete the assessment required by clause 10.3(c);
(ii) determine and record the supplier’s role for that activity;
(iii) obtain any Customer authorisation or give any notice required by this clause 10;
(iv) put in place any transfer mechanism required by clause 16;
(v) update Parts A, B or C of Annex 3, as appropriate;
(vi) update Annex 2 if the activity materially changes the Technical and Organisational Measures or creates a material residual limitation; and
(vii) ensure that activation does not materially reduce the overall level of protection of Customer Personal Data.
(e) PostMyDoc will review each active Part C engagement periodically and on the occurrence of an event described in clause 10.3(d). If the engagement can be finally classified, PostMyDoc will move it to Part A or Part B, as appropriate, and make any related amendments required by this Agreement.
(f) PostMyDoc remains responsible for its obligations under this Agreement and applicable Data Protection Laws despite an entry in Part C.
For clarity, a person is not a Sub-processor merely because it receives Customer Personal Data in order to perform a regulated carriage, postal, banking or payment service in its own capacity and determines the operational means by which that service is performed.
Despite the remainder of this clause, where Annex 3 identifies a Sub-processor as being in wind-down and records that suitable contractual data-protection terms have not been verified, PostMyDoc may continue the engagement only for the shortest period reasonably necessary to discontinue or replace the service, provided that PostMyDoc:
(a) does not materially expand the categories, sensitivity, purpose or frequency of Customer Personal Data disclosed during that period;
(b) implements reasonable data-minimisation and supplementary security measures within its control;
(c) records and investigates material inconsistencies in the supplier information available to it;
(d) uses reasonable endeavours to obtain or verify the relevant contractual terms and processing chain;
(e) ceases disclosure by the announced withdrawal date or earlier where a reasonably practicable alternative becomes available; and
(f) updates Annex 3 promptly after cloud transmission has ceased.
11. Assistance with Data Subject requests
11.1 Taking into account the nature of the Processing, PostMyDoc will assist the Customer by appropriate technical and organisational measures, insofar as possible, to respond to requests from Data Subjects to exercise their rights under the Data Protection Laws — including rights of access and correction under APP 12 and APP 13, and the rights of access, rectification, erasure, restriction, portability and objection under the GDPR and UK GDPR where they apply.
11.2 If PostMyDoc receives a request from a Data Subject relating to the Customer Personal Data, it will not respond to the request itself (except to confirm that the request has been referred to the Customer, or as required by law), and will refer the request to the Customer without undue delay.
11.3 The Customer acknowledges that, because PDF files are deleted from live server storage under the Burn After Reading Policy, the data available for PostMyDoc to assist with a Data Subject request is generally limited to account, order and dispatch metadata, together with any document filename, content hash and deletion-event information retained in the applicable records. The content of a PDF file may cease to be available before dispatch, after dispatch, or where dispatch never occurs. The remaining metadata is retained until deleted in accordance with clause 14.
11.4 PostMyDoc may charge a reasonable fee for assistance that is unusual in nature or that requires material effort beyond standard support, having first notified the Customer of the basis for the charge.
12. Assistance with security, impact assessments and consultation
12.1 Taking into account the nature of the Processing and the information available to it, PostMyDoc will provide reasonable assistance to the Customer with:
(a) ensuring compliance with the security obligations in clause 9 (and Article 32 of the GDPR / APP 11);
(b) carrying out data protection impact assessments under Article 35 of the GDPR, and privacy impact assessments under Australian Privacy Law, where required; and
(c) any prior consultation with a Supervisory Authority under Article 36 of the GDPR.
12.2 Clause 11.4 (reasonable fees for unusual or burdensome assistance) applies to assistance under this clause 12.
13. Personal Data Breach and eligible data breach notification
13.1 Notice to the Customer. PostMyDoc will notify the Customer without undue delay, and in any event no later than 48 hours, after becoming aware of a Personal Data Breach affecting the Customer Personal Data. PostMyDoc will not delay that notification in order to complete its investigation; an initial notification with the information then available is acceptable, with further information provided in phases as it becomes available. This notification is given to enable the Customer, as Controller, to meet its own obligations within the time required by the Data Protection Laws — including any obligation to notify as soon as practicable under the Notifiable Data Breaches scheme, and to notify within 72 hours under Article 33 of the GDPR where it applies. It does not transfer those obligations to PostMyDoc, and does not itself constitute a notification by PostMyDoc under those laws.
13.2 Each notification will, to the extent known, describe:
(a) the nature of the Personal Data Breach, including the categories and approximate number of Data Subjects and records concerned;
(b) the likely consequences of the breach;
(c) the measures taken or proposed to address the breach and to mitigate its possible adverse effects; and
(d) a contact point at PostMyDoc from whom further information may be obtained.
13.3 Assistance and containment. PostMyDoc will take reasonable steps to contain and remediate the breach, will reasonably cooperate with the Customer, and will assist the Customer in meeting any obligation it has to notify a Supervisory Authority (including, under the GDPR, within 72 hours under Article 33) and affected Data Subjects.
13.4 Notifiable Data Breaches scheme — coordination. The parties acknowledge that both of them may “hold” the same Customer Personal Data for the purposes of the NDB scheme. Where there are reasonable grounds to suspect that an Eligible Data Breach may have occurred, PostMyDoc will assist the Customer with its assessment within the period contemplated by Part IIIC of the Privacy Act (generally 30 days). Unless the parties agree otherwise in writing, the Customer will, as Controller, be the entity that makes any required notification to the OAIC and to affected individuals, and PostMyDoc will not make a separate notification in respect of the same breach except where the parties agree or where PostMyDoc is independently required by law to do so; this reflects the single-notification approach permitted under the NDB scheme where more than one entity holds the affected information.
13.5 Nothing in this clause is an admission of fault or liability by either party in respect of a Personal Data Breach.
14. Retention, return and deletion of Personal Data
14.1 Deletion records and document-deletion certificates.
(a) Deletion of PDF files from live server storage occurs continuously under the Burn After Reading Policy and independently of expiry or termination of the Principal Agreement.
(b) PostMyDoc’s system records a deletion event when the automated purge process deletes an uploaded PDF file from live server storage. The deletion record is generated by the purge event and does not depend on whether the associated Envelope has been dispatched.
(c) Subject to paragraph (d), the Customer is entitled to one document-deletion certificate for each Envelope where:
(i) one or more PDF files associated with that Envelope entered PostMyDoc’s live server storage;
(ii) the automated purge process deleted the stored server-side content of those PDF files; and
(iii) PostMyDoc’s system created the records required to generate the certificate.
(d) The entitlement applies per Envelope, regardless of:
(i) the number of PDF files included in that Envelope;
(ii) the number of Envelopes included in the Business Order;
(iii) whether multiple Envelopes are addressed to the same recipient; or
(iv) whether the Envelope was dispatched.
(e) A Business Order or Envelope submitted or administered manually, including by telephone or email, does not produce a document-deletion certificate where the relevant PDF files never entered PostMyDoc’s live server storage. In that case, there is no automated server-side purge event or corresponding system record from which a certificate can be generated. An email request does not create certificate eligibility where the requirements in paragraph (c) were not met.
(f) Where both deletion and dispatch have been recorded for an eligible Envelope, the Customer may obtain the certificate through the Business Portal or through the link in the applicable deletion notification.
(g) If a certificate cannot be obtained through the self-service channels described in paragraph (f), including because dispatch has not occurred or has not been recorded, the Customer may request the existing certificate from PostMyDoc by email. The delivery method does not affect eligibility and cannot create eligibility where none exists.
(h) A certificate may be generated and issued for an eligible Envelope that was not dispatched, including where the Business Order was cancelled or refunded after the automated purge process deleted the relevant PDF files from live server storage. The certificate may record no dispatch date. Where dispatch occurs after deletion, the certificate will record the events in their actual chronological sequence.
(i) A document-deletion certificate records only the automated purge process’s deletion of the relevant PDF files from live server storage. It does not certify or record:
(i) deletion of a Print-Agent Copy;
(ii) deletion of a Local Operational Copy;
(iii) deletion of a customer-initiated email copy or attachment;
(iv) deletion of any other manually held copy;
(v) rotation or deletion of a back-up copy;
(vi) destruction of returned physical mail; or
(vii) manual deletion of a PDF file by the Customer or PostMyDoc.
(j) PostMyDoc may retain the certificate and the limited system records reasonably required to create, provide and verify it, including the Envelope identifier, filename, content hash and relevant event dates, until those records are deleted in accordance with this clause 14.
14.2 On termination. On expiry or termination of the Principal Agreement, PostMyDoc will, at the Customer’s election, return the remaining Customer Personal Data to the Customer in a commonly used format or delete it, and will delete existing copies, within ninety (90) days after expiry or termination of the Principal Agreement.
14.3 Customer election not made. If the Customer does not make an election within 30 days after expiry or termination of the Principal Agreement, PostMyDoc will delete the Customer Personal Data in accordance with this clause 14.
14.4 Data subject to deletion. Subject to clauses 14.5 to 14.11, PostMyDoc will delete within the period in clause 14.2:
(a) recipient names, delivery addresses, recipient history, order history and dispatch history;
(b) Business account, Authorised User and identity records;
(c) Ordinary internal account, operational and support notes;
(d) Account access records and account credentials; and
(e) other Customer Personal Data that PostMyDoc no longer needs to provide the Services or comply with a legal obligation.
14.5 PDF File Content retention and deletion.
Subject to clauses 14.6 to 14.8:
(a) PDF Files stored on PostMyDoc’s live server are retained temporarily for printing and dispatch and are deleted by the automated purge process described in clause 9.4;
(b) the deletion timetable for each PDF File in live server storage is measured from the age of that file in live server storage and is not conditional on dispatch;
(c) a PDF File may be deleted:
(i) before the associated Envelope is dispatched;
(ii) after the associated Envelope is dispatched;
(iii) while the associated Business Order is awaiting payment settlement or another pre-dispatch step;
(iv) after the associated Business Order or Envelope is cancelled; or
(v) where the associated Envelope is never dispatched;
(d) each Print-Agent Copy is retained only for the duration of a single print attempt and is deleted at the end of that attempt, whether the attempt succeeds or fails;
(e) a Local Operational Copy may be retained only as long as reasonably necessary to prepare, print, dispatch or otherwise complete manual or exceptional fulfilment of the relevant Business Order, including where the server-side PDF File has been purged while payment settlement or another fulfilment step remains pending;
(f) a Local Operational Copy will be deleted promptly after dispatch is confirmed or, if the Envelope is not dispatched, promptly after cancellation or closure of the relevant Business Order;
(g) where the Customer voluntarily submits a PDF File to PostMyDoc by email, PostMyDoc may retain the email and attachment only as long as reasonably necessary to receive, verify, prepare, fulfil and administer the Business Order, after which the PDF File attachment and any operational email copy containing it will be deleted from PostMyDoc’s active email systems;
(h) PostMyDoc will not send PDF Files as attachments to its administrative or transactional email notifications for Business Orders;
(i) deletion from live server storage or another active system removes the relevant file or copy from that system and is not cryptographic erasure;
(j) PostMyDoc does not retain PDF File Content as part of its ordinary business records.
(k) PostMyDoc will not retain PDF File Content merely because it retains financial, tax, invoice, payment, reconciliation, transaction, order or dispatch records;
(l) deletion from active systems does not require selective deletion from back-ups where selective deletion is not technically available. Back-up copies remain protected and rotate out in accordance with clause 14.7; and
(m) nothing in this clause requires or permits PostMyDoc to delete Customer Personal Data that it is under a current legal obligation to preserve or produce.
14.6 Returned physical mail. If an Envelope is returned to PostMyDoc as undeliverable:
(a) PostMyDoc will hold the returned physical mail securely, with access limited to authorised personnel, for five business days after PostMyDoc receives it;
(b) during that period, PostMyDoc may repost the Envelope on the Customer’s documented request and subject to the Principal Agreement;
(c) if the Envelope is not reposted during that period, PostMyDoc will securely destroy the returned physical mail after the five-business-day period ends; and
(d) PostMyDoc may retain the returned physical mail for longer only where required by law or a valid and binding legal preservation requirement.
14.7 Back-ups. The hosting platform takes full-volume back-ups of the entire account and cannot be configured to exclude particular directories or selectively delete individual document files. If document content is captured in a back-up before its active server-side copy is deleted, the back-up copy may remain until the relevant back-up rotates out, being up to approximately 30 days. A back-up copy remains subject to the confidentiality and security obligations in this Agreement, is not used in ordinary operations, is restored only where reasonably necessary for disaster recovery or system restoration, and will be deleted when the relevant back-up ages out.
14.8 Retention required by law. PostMyDoc may retain Customer Personal Data after the period in clause 14.2 only to the extent, and for as long as, reasonably necessary:
(a) to comply with a law to which PostMyDoc is subject, including Australian tax, accounting and record-keeping obligations;
(b) to establish, exercise or defend legal claims;
(c) to investigate, prevent or respond to fraud, a security incident, misuse or unlawful activity; or
(d) to comply with a request from a regulator, court, tribunal, law-enforcement agency or other authority with lawful power to make the request.
Where PostMyDoc retains Customer Personal Data under this clause, it will document the applicable retention basis and period, or the event by which the continuing need for retention will be reviewed. PostMyDoc will securely delete or irreversibly anonymise the data when the applicable retention period expires or the relevant retention purpose ends, unless continued retention is required or permitted under this clause.
14.9 Financial and transaction records. Where PostMyDoc retains financial, tax, invoice, payment, reconciliation or transaction records after closure of a Business account:
(a) PostMyDoc will retain only the minimum Customer Personal Data reasonably necessary for the applicable retention purpose;
(b) where practicable, PostMyDoc will use an anonymised account reference or other limited identifier;
(c) PostMyDoc will not retain recipient names, delivery addresses, recipient history, order history, dispatch history, active account access, account credentials or uploaded document content merely because a financial or tax record is retained; and
(d) ordinary internal account, operational and support notes will not be retained merely because financial, tax or transaction records are retained.
14.10 Authentication and security logs. Authentication and security logs are retained for approximately 30 days, unless a longer period is reasonably necessary for a documented investigation or response relating to a security incident, fraud, misuse or unlawful activity. Records retained for longer are access-restricted, reviewed periodically and deleted when the applicable purpose ends.
14.11 Protection of retained data. Customer Personal Data retained after expiry or termination under clauses 14.8 to 14.10:
(a) will be access-restricted and kept secure and confidential;
(b) will be Processed only for the applicable retention purpose; and
(c) will be securely deleted or irreversibly anonymised once the applicable retention purpose ends.
14.12 Confirmation of compliance. On request, PostMyDoc will provide the Customer with written confirmation that it has complied with this clause 14.
14.13 Limitations on disclosure.
(a) PostMyDoc can disclose only Customer Personal Data that it holds at the time of a request.
(b) Because PDF files are removed from live server storage under the age-based automated purge process, their content may cease to be available before dispatch, after dispatch, or where dispatch never occurs.
(c) PostMyDoc will not disclose Customer Personal Data to a law-enforcement or government authority except where required by a valid and binding legal compulsion, or as otherwise permitted by this Agreement.
(d) Where legally permitted, PostMyDoc will inform the Customer of the request without undue delay so the Customer may seek to limit or challenge it.
14.14 Law-enforcement access. If PostMyDoc receives a valid legal preservation or production order concerning Customer Personal Data it then holds, including document content still within the pre-deletion period, PostMyDoc will comply with that order. Nothing in the Burn After Reading Policy requires or permits PostMyDoc to destroy data that it is under a current legal obligation to preserve.
15. Records and audit
15.1 PostMyDoc will maintain records of its Processing of Customer Personal Data sufficient to demonstrate compliance with this Agreement, and will make available to the Customer the information reasonably necessary to demonstrate compliance with the obligations in Article 28 of the GDPR (where it applies) and this Agreement.
15.2 Audits. PostMyDoc will allow for and contribute to audits, including inspections, conducted by the Customer or an independent auditor mandated by the Customer (and who is not a competitor of PostMyDoc and is bound by confidentiality), subject to the following: audits may be conducted once in any 12-month period (and additionally following a Personal Data Breach affecting the Customer Personal Data), on at least 30 days’ written notice, during business hours, in a manner that does not unreasonably disrupt PostMyDoc’s operations, and limited to systems, records and personnel relevant to the Processing of the Customer Personal Data.
15.3 Third-party reports. PostMyDoc may satisfy an audit request by providing relevant current third-party audit reports, certifications or attestations held by it or its Sub-processors (for example, ISO/IEC 27001 certification or SOC 2 reports of a Sub-processor), where these reasonably address the scope of the Customer’s audit.
15.4 Each party bears its own costs of an audit, except that the Customer will reimburse PostMyDoc’s reasonable costs for assistance that exceeds PostMyDoc’s reasonable internal effort. Audit findings are the confidential information of both parties.
16. International data transfers
16.1 Where the data is held. The primary hosting and storage of Customer Personal Data is in Australia. Certain Sub-processors and independent recipients Process or receive limited categories of Customer Personal Data outside Australia, as identified in Parts A and B of Annex 3. Part C of Annex 3 identifies active, inactive, proposed or conditional engagements that have material residual limitations or require further role, contractual, operational or transfer assessment.
16.2 APP 8 cross-border disclosure. (a) Before disclosing Customer Personal Data to an overseas recipient, PostMyDoc will take such steps as are reasonable in the circumstances to seek to ensure that the recipient does not breach the APPs, other than APP 1, in relation to that information, consistently with APP 8.1. (b) The reasonable steps taken by PostMyDoc may include, according to the circumstances: (i) seeking enforceable contractual privacy and security obligations; (ii) reviewing the recipient’s available privacy, security, retention and incident-response information; (iii) identifying the data transmitted, Processing purpose, recipient and known locations; (iv) limiting the data transmitted to what is reasonably necessary for the relevant function; (v) applying technical and organisational safeguards within PostMyDoc’s control; (vi) seeking deletion where it is available and reasonably appropriate; (vii) assessing available alternative suppliers or service configurations; and (viii) documenting and periodically reviewing any residual risk. (c) Where an overseas recipient does not provide or accept suitable contractual data-protection terms, PostMyDoc will not state that contractual measures protect that disclosure. PostMyDoc will document the contractual limitation, apply the process in clause 10.3(c), and accurately describe the material residual limitation in Annex 3. (d) The measures described in this clause are intended to support PostMyDoc’s compliance with APP 8.1. They do not constitute a representation that an overseas recipient is bound by the APPs or that any particular measure will, by itself, satisfy APP 8.1. (e) Subject to any applicable statutory exception, PostMyDoc acknowledges the accountability provision in section 16C of the Privacy Act.
16.3 Transfers subject to the GDPR or UK GDPR. Where:
(a) the GDPR or UK GDPR applies to the relevant Processing;
(b) a transfer of Customer Personal Data to PostMyDoc in Australia constitutes a restricted transfer requiring an international data-transfer mechanism under Chapter V of the GDPR or the equivalent provisions of the UK GDPR; and
(c) no applicable adequacy decision or other lawful transfer mechanism is available,
the parties will, before the restricted transfer begins, enter into and complete the Standard Contractual Clauses, the UK Addendum, the IDTA or another lawful transfer mechanism applicable to that transfer.
PostMyDoc will provide reasonable information and assistance required to complete the applicable transfer mechanism and any transfer impact assessment required by the Data Protection Laws. The Customer must not submit Customer Personal Data to PostMyDoc as part of a restricted transfer until the required transfer mechanism has taken effect. Each party will comply with the obligations that apply to it under that mechanism.
16.4 Onward transfers subject to the GDPR or UK GDPR. Where Customer Personal Data is subject to the GDPR or UK GDPR and PostMyDoc transfers that data to a Sub-processor in a country for which no applicable adequacy decision exists, PostMyDoc will ensure, before the transfer begins, that:
(a) the transfer is made under a lawful transfer mechanism in accordance with Chapter V of the GDPR or the equivalent provisions of the UK GDPR;
(b) the Sub-processor is bound by the data-protection obligations required by clause 10.3; and
(c) any supplementary measures reasonably required by the applicable Data Protection Laws are implemented.
A transfer mechanism entered into between the Customer and PostMyDoc under clause 16.3 does not, by itself, govern an onward transfer by PostMyDoc to a Sub-processor.
16.5 If a transfer mechanism on which the parties rely is invalidated or materially changed, the parties will cooperate in good faith to put in place an alternative lawful mechanism without undue delay.
17. Liability and indemnity
17.1 Subject to clause 17.3, each party’s liability arising out of or in connection with this Agreement is subject to, and counts towards, the limitations and exclusions of liability in the Principal Agreement.
17.2 The parties acknowledge that, under Article 82 of the GDPR (where it applies), a Controller and a Processor may be jointly and severally liable to a Data Subject for the entire damage caused by Processing that infringes the GDPR. As between the parties, each party will be responsible for, and will indemnify the other against, losses to the extent caused by that first party’s breach of this Agreement or of the Data Protection Laws, in the proportion for which it is responsible.
17.3 Nothing in this Agreement limits or excludes a liability that cannot lawfully be limited or excluded, including certain liabilities under the Data Protection Laws or the Australian Consumer Law.
18. Term and termination
18.1 This Agreement takes effect on the date the Customer accepts it (or, if later, the date the Customer’s Business account is approved) and continues for as long as PostMyDoc Processes Customer Personal Data under the Principal Agreement.
18.2 Clauses that by their nature should survive termination — including clauses 8 (confidentiality), 14 (retention, return and deletion), 15 (records and audit, in respect of the period before termination), 16 (transfers, for retained data), 17 (liability) and 19 (general) — survive termination of this Agreement.
19. General
19.1 Acceptance and updates. The Customer accepts this Agreement through its Primary Contact by completing the required acceptance step during the Business account application and, where applicable, any later re-acceptance step. By completing that step, the person doing so confirms that they are the Customer’s Primary Contact and are authorised to accept this Agreement for and on behalf of the Customer. PostMyDoc will retain a per-account acceptance record that includes the date and time of acceptance and the version of each accepted document.
PostMyDoc may update this Agreement where reasonably necessary to reflect changes in applicable law, the Services, Processing activities, security measures, suppliers or Sub-processors.
An update that does not materially disadvantage the Customer or materially reduce the overall level of protection of Customer Personal Data may take effect on publication or on a later date stated in the updated Agreement.
Subject to clause 10.2, if an update materially disadvantages the Customer or materially reduces the overall level of protection of Customer Personal Data, PostMyDoc will ordinarily give the Primary Contact at least 14 days’ written notice before it takes effect. During that period, the Customer may stop using the affected Services and close its Business account before the update takes effect.
PostMyDoc may make an update on shorter notice, or with immediate effect, where reasonably necessary to comply with applicable law or a binding direction, respond to a Personal Data Breach or material security risk, prevent fraud or unlawful Processing, or address an urgent supplier or operational change necessary to protect Customer Personal Data or continue the Services. Where practicable, PostMyDoc will notify the Primary Contact before the update takes effect and otherwise will notify the Primary Contact as soon as reasonably practicable afterwards.
Where appropriate, PostMyDoc may require the Customer to accept the updated Agreement before continuing to use the affected Services. Acceptance does not remove or reduce any obligation imposed on PostMyDoc by applicable Data Protection Laws, clause 10.2 or an applicable international data-transfer mechanism.
19.2 Order of precedence. If there is any inconsistency between the documents forming the arrangement between the parties, the following order of precedence applies:
(a) any Standard Contractual Clauses, UK Addendum, IDTA or other mandatory international data-transfer mechanism separately entered into between the parties under clause 16.3, but only to the extent of the relevant transfer and inconsistency;
(b) this Agreement; and
(c) the Principal Agreement and any other related document. The PostMyDoc Business Privacy Policy, the PostMyDoc Business Terms of Service and the PostMyDoc Business Refund Policy are read consistently with this Agreement.
19.3 Governing law and jurisdiction. This Agreement is governed by the laws of South Australia and the Commonwealth of Australia, and the parties submit to the non-exclusive jurisdiction of the courts of South Australia.
Despite the preceding paragraph, if the parties separately enter into Standard Contractual Clauses, a UK Addendum, an IDTA or another mandatory international data-transfer mechanism under clause 16.3, that mechanism is governed by the law and jurisdiction specified in it to the extent required for its validity and operation.
19.4 Notices. Notices to PostMyDoc under this Agreement must be sent to privacy@postmydoc.au. Notices to the Customer may be sent to the Primary Contact email recorded for the Business account.
19.5 Variation and waiver. Except as provided in clause 19.1, a variation of this Agreement must be in writing. A failure to exercise, or delay in exercising, a right does not operate as a waiver.
19.6 Severance. If a provision of this Agreement is or becomes invalid or unenforceable, it is to be read down or severed to the minimum extent necessary, without affecting the remaining provisions.
19.7 Assignment. Neither party may assign or novate this Agreement without the other’s consent, except that PostMyDoc may assign it to a related body corporate or in connection with a transfer of its business, on notice to the Customer.
19.8 Entire agreement. This Agreement, together with the documents it refers to, is the entire agreement between the parties about its subject matter and supersedes prior arrangements about that subject matter.
19.9 Counterparts. This Agreement may be executed (where it is executed rather than accepted online) in counterparts, including by electronic signature.
20. Execution
Where this Agreement is accepted online, clause 19.1 governs and no signature is required. The signature blocks below are provided for use where the parties choose to execute this Agreement.
Signed for and on behalf of the Processor — PostMyDoc Digital Mailing Service Pty Ltd (trading as PostMyDoc):
| Authorised signatory Signature | Name |
| Title | Date |
Signed for and on behalf of the Customer:
| Authorised signatory Signature | Name |
| Title | Date |
Annex 1 — Description of the Processing
This Annex describes the Processing of Customer Personal Data under this Agreement. Where the GDPR applies, it serves as the description required by Article 28(3) and (for any Standard Contractual Clauses the parties enter into under clause 16.3) Annex I to those clauses.
| Item | Description |
| Parties | Data exporter / Controller: the Customer (the approved PostMyDoc Business account holder identified in the account record). Data importer / Processor: PostMyDoc Digital Mailing Service Pty Ltd trading as PostMyDoc, Australia. |
| Subject matter | PostMyDoc’s provision of the digital-to-physical mail Services to the Customer in connection with the Customer’s Business account, regardless of whether a Business Order is submitted through the Business Portal, by email, by telephone or through another ordering channel accepted by PostMyDoc. The Services include receiving document content and delivery instructions, preparing and printing Envelopes, dispatching them through Australia Post, handling returned physical mail, and providing associated account, order, billing, notification, tracking, deletion and certificate functions. |
| Duration | For the term of the Principal Agreement and until return or deletion of Customer Personal Data under clause 14. Each copy of PDF File Content is retained only for the period applicable to its custody channel: stored server-side PDF Files are handled by the automated purge; each Print-Agent Copy is retained only for one print attempt and deleted at the end of that attempt whether it succeeds or fails; Local Operational Copies are deleted promptly after dispatch confirmation or cancellation; customer-initiated email copies are deleted from active email systems after fulfilment and administration of the relevant Business Order; returned physical mail is held for five business days after receipt and then securely destroyed if not reposted; and back-up copies rotate out within up to approximately 30 days. |
| Nature of the Processing | Collection, recording, storage, organisation, encrypted transmission, automated retrieval and decryption by the on-premises print agent, creation and deletion of a temporary Print-Agent Copy for a single print attempt, temporary local copying for manual or exceptional fulfilment, printing, disclosure to Australia Post for dispatch, handling and reposting of returned physical mail, use for Business account administration, billing and notifications, generation of envelope-level deletion certificates, deletion from active systems, and secure destruction of returned physical mail. |
| Purpose of the Processing | To perform the Services on the Customer’s documented instructions, including receiving Business Orders through approved channels, preparing, printing and posting the Customer’s documents to nominated recipients, completing fulfilment where server-side files have already been purged, administering returns and reposting, and operating related Business account, billing, notification, tracking, deletion and certificate functions. |
| Frequency | Continuous / on an ongoing basis for the duration of the Services, driven by the orders and activity of the Customer’s Authorised Users. |
Categories of Data Subjects
| Category | Examples |
| The Customer’s Authorised Users | The Primary Contact and other linked business users and invitees — typically the Customer’s staff. |
| Recipients of mailed documents | The named addressees to whom documents are dispatched. |
| Individuals appearing within documents | Any individuals whose Personal Data appears in the content of an uploaded document (the Customer determines this and PostMyDoc does not control or inspect it). |
Categories of Personal Data
| Category | Detail |
| Account and identity data | Business name; Australian Business Number where applicable; official company, business or tax registration identifiers for an approved foreign applicant; jurisdiction of formation; industry or sector; information reasonably required to verify the applicant’s legal identity, registration status, business activities, ownership and authority; Primary Contact name, email and phone number; applicant name and email; names and emails of linked users and invited users; user role, including Primary Contact or business user; and internal application and account notes. |
| Authentication and security data | Hashed account passwords; login-attempt metadata processed for brute-force protection (including IP address, timestamp and attempted username); tokenised invitation and password-reset links. |
| Order, recipient and dispatch data | Recipient names and delivery addresses (address lines, suburb/city, state, postcode, country); partial address data entered through address autocomplete; destination zone; postage service; tracking numbers and delivery status; dispatch date; and order references such as purchase-order number, cost centre and sender label. |
| PDF File Content | The content of PDF Files submitted by or on behalf of the Customer, which is determined by the Customer and may contain Personal Data of any kind. PDF Files stored on the live server are deleted by the automated purge described in clause 9.4. Temporary Local Operational Copies, customer-initiated email copies and back-up copies are handled under their respective lifecycles in clause 14. |
| Billing and transaction data | Order and pricing data, invoices and statements, payment status, and payment-transaction metadata. Card/payment-instrument data is collected and processed directly by the payment Sub-processor (Stripe); PostMyDoc does not store full card numbers. |
| Usage and analytics data | Page-view and usage metadata and related identifiers (including IP address) processed for site analytics. |
| Operational custody and return data | Local device access and deletion records relating to temporary Local Operational Copies; customer-initiated order emails and their document attachments; returned-mail receipt, hold, reposting and destruction records; and envelope-level certificate data, including submission, deletion and dispatch dates where applicable. |
Annex 2 — Technical and Organisational Measures
These are the measures PostMyDoc maintains under clause 9. Where the GDPR applies, this Annex serves as the description of measures under Article 28(3) and Article 32, and as Annex II to any Standard Contractual Clauses the parties enter into under clause 16.3. Items marked for confirmation are operational facts to be verified and finalised before execution.
| Measure | Description |
| Data minimisation and deletion | PDF File Content is retained only as long as needed to prepare, print and dispatch the relevant Envelope. An automated, scheduled server-side task runs hourly and removes any stored PDF File more than 24 hours old. The task runs on the server’s own scheduler, independently of site traffic, and deletion removes the PDF File from the live file system. Temporary Local Operational Copies, customer-initiated email copies and back-up copies are handled under their respective lifecycles in clauses 9.4 and 14. Only the account, order and dispatch fields needed to provide the Services are collected. PDF filenames and content hashes retained in dispatch and deletion records are kept until deleted under clause 14. |
| Encryption in transit | All connections to the Business Portal and PostMyDoc’s service endpoints are served over HTTPS/TLS; documents are encrypted in transit. |
| Encryption at rest | Uploaded PDF File Content is encrypted at rest using authenticated application-level encryption (libsodium), so the stored bytes are ciphertext. A PDF File is decrypted only transiently in memory when retrieved for printing or dispatch, and a plaintext copy is not written back to disk. This protection is combined with data minimisation. The automated purge process removes each uploaded PDF File from live server storage when the file becomes more than 24 hours old, whether or not the associated Envelope has been dispatched. Connections are encrypted in transit using TLS, and access to stored data is restricted by role. |
| Access control | Role-based access: a dedicated business-user role; row-level visibility so the nominated Primary Contact sees the account’s orders while other users see only their own; a fail-secure default (own-records-only) until a Primary Contact is set; privileged administrative access is restricted to authorised PostMyDoc personnel; unauthorised access to a record returns an opaque “not found” response rather than revealing its existence. |
| Authentication | Account passwords are stored only as salted hashes; a minimum password length is enforced on invitation and reset; a branded login and a tokenised password-reset flow are used. |
| Multi-factor authentication | Multi-factor authentication is enforced for administrative and operator access to the platform, and for the third-party administrative consoles used to operate it (hosting, payments and connected services). |
| Security notifications | A request to change an Authorised User’s sign-in email address sends the confirmation request to the new address and a change alert to the current address at the time of the request; once the change is completed, a completion alert is sent to the former address. When second-step verification is enabled, disabled or reset by the Primary Contact, a backup code is used, an authenticator application is removed, backup codes are regenerated, or a passkey is added or removed, a security notice is sent to the affected Authorised User’s sign-in address. Those second-factor notices are not copied to the Primary Contact. |
| Secure document download | Documents and billing artefacts are served only through gated, authenticated download paths tied to the requesting user’s permissions; direct unauthenticated file access is not permitted. |
| Brute-force / abuse protection | Login-attempt rate limiting with lockout, and cloud-assisted IP-reputation checks via the login-security plugin’s cloud service, to protect against credential-stuffing and brute-force attacks. |
| Input validation | Uploads are restricted by file-type (content/“magic-byte”) checks and a size cap; key request values are validated against strict allow-lists; errors are returned generically without exposing internal detail. |
| Privacy-by-design in notifications | Transactional email subject lines deliberately omit recipient location detail; an anonymous-sender option is available so the sender identity can be withheld on dispatch where chosen. |
| Hosting and platform | Hosting is provided in Australia (Sydney) by Netregistry Pty Ltd trading as Webcentral on a managed platform. Based on the provider information available to PostMyDoc, the provider operates platform security controls that include a web application firewall, malware scanning, platform security patching, full-volume back-ups, recovery functions and monitoring for suspected security incidents. PostMyDoc has reviewed an ISO/IEC 27001:2022 certificate naming Netregistry Pty Ltd and Terrific.com.au Pty Ltd. The stated certification scope is information security for internet domain name registration services. It does not state that PostMyDoc’s managed hosting service or the relevant data centre is within the certification scope. PostMyDoc therefore does not represent that the hosting service, hosting environment, relevant data centre or PostMyDoc itself is ISO/IEC 27001 certified. Time-based tasks run on a server-level scheduler. WordPress’s traffic-triggered scheduler is disabled so scheduled tasks, including document deletion, execute on schedule rather than depending on site visits. The hosting provider takes twice-daily full-volume back-ups with restore-to-last-known-good recovery, subject to the limitations described in the “Back-up and recovery” and “Full-volume back-up limitation” measures. |
| Back-up and recovery | The hosting provider (Netregistry Pty Ltd trading as Webcentral) takes automated twice-daily full-volume back-ups of the entire account, retained for up to approximately 30 days, with restore-to-last-known-good recovery that has been tested. Back-ups are intended for restoration following accidental or malicious deletion, corruption, damage or another recovery event and are not used in ordinary operations. PostMyDoc has not verified that access to back-ups is individually logged or restricted by a contractual control specific to Customer Personal Data. PostMyDoc therefore does not represent those controls as confirmed Technical and Organisational Measures. If a back-up is restored, PDF files that had already reached the deletion threshold under the Burn After Reading Policy will be removed again from live server storage by the automated purge process or an equivalent deletion process. |
| Logging and monitoring | The hosting provider’s Trust and Safety team monitors for suspected security incidents and notifies of suspected breaches. At the application level, PostMyDoc logs document-deletion events, payment and Stripe-webhook processing (including signature and payload failures), and authentication failures and lockouts, in on-server logs retained for approximately 30 days. |
| Incident response | A process to detect, contain, assess and notify Personal Data Breaches in accordance with clause 13, including assistance with NDB-scheme assessment and notification. |
| Personnel and confidentiality | Personnel and any contractors with access to Customer Personal Data are bound by confidentiality obligations and are granted access on a least-privilege, need-to-know basis. Privileged administrative access is restricted to authorised PostMyDoc personnel. |
| Sub-processor and recipient assurance | PostMyDoc assesses suppliers and other recipients having regard to their role, the nature and privacy risk of the relevant Processing, the categories and sensitivity of Customer Personal Data involved, known Processing locations, retention practices, available privacy and security information, onward disclosures and the consequences of unauthorised access, use or disclosure. For Sub-processors in Part A of Annex 3, PostMyDoc seeks written contractual data-protection obligations in accordance with clause 10.3. For independent recipients in Part B, PostMyDoc limits disclosures to what is reasonably necessary and applies the safeguards in clause 10.6. Where suitable contractual terms are unavailable, a role remains unresolved, or an activity is proposed or conditional, PostMyDoc applies clauses 10.3(c) and 10.7, records the material residual limitations in Part C, implements reasonable supplementary measures within its control and periodically reviews the engagement. Disclosure of a limitation does not reduce PostMyDoc’s obligations or responsibility under this Agreement or applicable Data Protection Laws. |
| Full-volume back-up limitation | The hosting provider takes full-volume back-ups of the entire hosting account and cannot be configured to exclude particular directories or selectively delete individual PDF Files. If PDF File Content is captured before its active server-side copy is deleted, the protected back-up copy may remain until the relevant back-up rotates out, for up to approximately 30 days. Back-up copies remain protected by the confidentiality, access-control and security measures in this Agreement; are not used in ordinary operations to retrieve, view, re-send or otherwise use individual documents as part of the Services; and are restored or accessed only where reasonably necessary for disaster recovery, system restoration or, in exceptional circumstances, investigation, containment or remediation of a security incident. PostMyDoc does not represent that deletion from live server storage selectively deletes an existing back-up copy or constitutes cryptographic erasure. Webcentral has not provided a data processing agreement or equivalent binding data-protection terms applying to the service. PostMyDoc therefore relies on the supplementary measures and restrictions described in Annex 3, periodically reviews the engagement and remains responsible for its obligations under this Agreement and applicable Data Protection Laws. PostMyDoc does not describe the full-volume back-ups as encrypted at rest. Although uploaded PDF file content is encrypted by PostMyDoc at the application level, a full-environment back-up may also capture cryptographic material within the same recoverable environment. The main deletion protection for a back-up copy is the bounded rotation period rather than selective deletion or separation of that cryptographic material. |
| Local operational copies | Separate from automated Print-Agent Copies, authorised PostMyDoc personnel may create a temporary Local Operational Copy where reasonably necessary for manual or exceptional preparation, printing, dispatch or fulfilment of a Business Order. The copy is held on an access-controlled local device, access is restricted to personnel who require it for fulfilment, it is not used for another purpose, and it is deleted promptly after dispatch confirmation or, where fulfilment does not proceed, after cancellation or closure of the Business Order. |
| Automated on-premises printing | For each automated print attempt, the on-premises print agent retrieves the relevant PDF File Content from PostMyDoc’s server over HTTPS and creates a temporary decrypted Print-Agent Copy solely within its restricted working directory. The working directory is created with operating-system permissions equivalent to mode 0700, and the Print-Agent Copy is created with permissions equivalent to mode 0600. The print agent submits the copy to the local CUPS print system and deletes it at the end of the print attempt whether the attempt succeeds or fails. The copy is not retained between print attempts. |
| Email controls | Business Portal administrative and transactional notifications do not include customer document files as attachments. Where a Customer chooses to submit document content by email, access to the email and attachment is restricted to authorised personnel and the attachment and operational email copy are deleted from active email systems after fulfilment and administration of the relevant Business Order, subject to ordinary protected back-up rotation. |
| Returned physical mail | Returned Envelopes are stored securely with access limited to authorised personnel, held for five business days after receipt to permit reposting on the Customer’s request, and securely destroyed after that period if not reposted, unless continued retention is required by law. |
Annex 3: Processing Providers and Independent Recipients
This Annex identifies:
(a) in Part A, the Sub-processors authorised under clause 10.1;
(b) in Part B, independent recipients to whom PostMyDoc may disclose Customer Personal Data under clause 10.6; and
(c) in Part C, suppliers or Processing activities with material residual limitations, unresolved status, or proposed or conditional operation under clause 10.7.
Classification is activity-specific. An entity may appear in more than one Part where it performs different functions in different capacities.
Where the GDPR applies, Part A is the Sub-processor list for Article 28 purposes and Annex III to any Standard Contractual Clauses entered into under clause 16.3. Parts B and C do not form part of that Sub-processor authorisation merely because they appear in this Annex.
PART A: AUTHORISED SUB-PROCESSORS
Netregistry Pty Ltd trading as Webcentral
Service provided: Website and database hosting, live file storage, full-volume back-ups and outbound transactional email infrastructure.
Customer Personal Data Processed: Customer Personal Data stored on or transmitted through the hosted platform, including PDF File Content, account and identity data, authentication and security data, recipient, order and dispatch data, billing metadata, logs, and email content and metadata.
Location: Australia (Sydney).
Status and limitations: Active Sub-processor. Webcentral provides the primary Australian hosting environment. Its back-up system takes full-volume back-ups and cannot selectively exclude directories or delete individual PDF Files. A PDF File captured before deletion from live server storage may remain in a protected back-up for up to approximately 30 days. The back-up is not used for ordinary operations and is accessed only for the restricted purposes described in clauses 14.7 and Annex 2.
Stripe group entities, including Stripe Payments Australia Pty Ltd, Stripe Payments Europe, Limited, Stripe Technology Company, Limited and Stripe, LLC
Service provided: Payment processing for Business Orders, invoices and statements, including checkout security, fraud prevention and related payment administration.
Customer Personal Data Processed: Payment-instrument and transaction data, billing identifiers, checkout-session data, device and browser data, IP address, cookies or similar identifiers, payment status and related fraud-prevention information. PostMyDoc does not store full card numbers.
Location: Australia, Ireland, the United States and other locations in which Stripe group entities and approved service providers Process payment, merchant-support, security or operational data under Stripe’s applicable terms.
Status and limitations: Active Sub-processor to the extent Stripe Processes Customer Personal Data on PostMyDoc’s behalf to provide payment services. Stripe or a Stripe group entity may act as an independent Controller for fraud prevention, security, legal compliance or another purpose determined by Stripe. Any such separate Processing is outside PostMyDoc’s instructions as Processor and is governed by Stripe’s applicable terms and privacy notice.
Google Maps Platform, provided by Google LLC
Service provided: Address autocomplete during recipient entry.
Customer Personal Data Processed: Partial address data entered during address lookup, IP address, device and request metadata, and related technical identifiers.
Location: United States and other locations in which Google and its service providers Process the data.
Status and limitations: Active Sub-processor for address-autocomplete functionality to the extent Google Processes the submitted data on PostMyDoc’s behalf. The Customer should avoid entering unnecessary Personal Data into the address-lookup field.
Google Analytics 4, provided by Google LLC
Service provided: Business Portal usage analytics.
Customer Personal Data Processed: Usage and page-view metadata, IP address, device and browser data, and related online identifiers for Portal visitors, including authenticated Authorised Users.
Location: United States and other locations in which Google and its service providers Process the data.
Status and limitations: Active Sub-processor to the extent Google Processes analytics data on PostMyDoc’s behalf. Google may separately Process limited data for its own security, measurement-system administration or legal compliance purposes under its applicable terms. PostMyDoc will not configure analytics to collect PDF File Content or intentionally send recipient names, delivery addresses or document content through analytics events.
Google Fonts, provided by Google LLC
Service provided: Delivery of web fonts used to render Business Portal pages.
Customer Personal Data Processed: IP address, User-Agent and technical request metadata transmitted when a Portal page retrieves a font.
Location: United States and other locations in which Google and its service providers Process the data.
Status and limitations: Active provider receiving limited network and device information. No PDF File Content, recipient details or order content is intentionally disclosed through this function.
Google Tag Manager, provided by Google LLC
Service provided: Tag-management container used to load and manage approved measurement tags on the Business Portal.
Customer Personal Data Processed: Page-interaction data, device and browser metadata, IP address and related identifiers passed to approved tags loaded through the container.
Location: United States and other locations in which Google and its service providers Process the data.
Status and limitations: Active Sub-processor for tag-management functions. Google Tag Manager must not be configured to transmit PDF File Content, recipient names, delivery addresses or document content. Each tag loaded through the container must be separately assessed and included in this Annex where it Processes Customer Personal Data.
Cloudflare, Inc.
Service provided: Cloudflare Turnstile bot and abuse protection on the Business account application form.
Customer Personal Data Processed: Applicant IP address, CAPTCHA interaction data, device and browser information, and related security identifiers.
Location: United States, with Australian points of presence, and other locations used by Cloudflare and its service providers.
Status and limitations: Active Sub-processor for Turnstile only. Cloudflare’s data processing addendum and applicable transfer provisions must apply to this activity. The separate edge-proxy or web application firewall function described in Part C is not authorised by this Part A entry.
PART B: INDEPENDENT RECIPIENTS AND PERMITTED DISCLOSURES
Australia Post
Function: Physical carriage, dispatch, delivery, tracking, return and reposting of Envelopes.
Customer Personal Data disclosed: Recipient name and delivery address, postage and service details, tracking identifier, delivery and return status, and any Personal Data visible on or necessarily contained in the physical Envelope and its contents.
Location: Australia and, for international mail, the destination country and transit locations used for postal delivery.
Role: Independent recipient and postal carrier. Australia Post determines aspects of the means and purposes of postal carriage, delivery, tracking, return and compliance with postal laws and its own legal obligations. It does not act solely on PostMyDoc’s instructions as a Sub-processor when carrying out those independent postal functions.
Operational qualification: PostMyDoc prepares and prints each Envelope before handing it to Australia Post. Where Australia Post makes a recipient signatory’s name available through its ordinary tracking service, PostMyDoc may be able to view that name. PostMyDoc does not receive or access the signature image and has no Australia Post application programming interface access. Customers may see only that the item was signed for or another delivery status made available through the PostMyDoc service.
Safeguards and limitations: PostMyDoc limits disclosure to the information reasonably necessary for the selected postal service. Once an Envelope is handed to Australia Post, Australia Post’s handling is subject to its postal functions, legal obligations and applicable terms. PostMyDoc remains responsible for its own preparation and disclosure of the Customer Personal Data but does not control the physical postal network.
Courts, tribunals, regulators, law-enforcement agencies and other public authorities
Function: Receipt of Customer Personal Data where PostMyDoc is required by a valid and binding legal compulsion, or is otherwise authorised by this Agreement and applicable law, to preserve, produce or disclose the data.
Customer Personal Data disclosed: Only the Customer Personal Data that PostMyDoc holds at the relevant time and is legally required or permitted to disclose.
Location: The jurisdiction of the requesting authority.
Role: Independent recipient acting under statutory or judicial authority.
Safeguards and limitations: PostMyDoc will assess the validity and scope of the request, limit disclosure to what is required, and notify the Customer without undue delay where legally permitted. The Burn After Reading Policy does not require or permit PostMyDoc to destroy data subject to a current legal preservation or production obligation.
Professional advisers
Function: Legal, accounting, insurance, audit, security or other professional assistance connected with the Services, compliance, a dispute, a security incident or the establishment, exercise or defence of legal claims.
Customer Personal Data disclosed: The minimum Customer Personal Data reasonably necessary for the relevant advice or professional function.
Location: Primarily Australia, unless the Customer is informed otherwise or the disclosure is otherwise permitted under this Agreement.
Role: Independent recipient subject to professional, contractual or legal confidentiality obligations.
Safeguards and limitations: Disclosure is limited to what is reasonably necessary for the relevant purpose and is subject to applicable confidentiality and professional obligations.
PART C: MATERIAL RESIDUAL LIMITATIONS, UNRESOLVED STATUS AND CONDITIONAL PROCESSING
Cloudflare, Inc.: potential edge proxy or web application firewall
Service or proposed function: If separately enabled in future, Cloudflare would proxy Business Portal traffic, terminate TLS at its edge and provide edge-network or web application firewall services.
Processing status: Inactive and conditional. This function is not authorised or activated by Cloudflare’s current use for Turnstile.
Customer Personal Data potentially Processed: Source IP address, connection and request metadata, device and browser information, authentication and account request data, and request content in transit. Depending on the final configuration, request content could include Personal Data submitted through the Business Portal. PDF File Content must not be cached or intentionally retained by Cloudflare.
Location: United States, Australian points of presence and other locations used by Cloudflare and its service providers.
Current role: Not finally classified for this proposed function. If activated, Cloudflare is expected to act as a Sub-processor for the edge-delivery and security function, subject to confirmation against the final configuration and applicable contractual terms.
Material residual limitation: The edge function would place Cloudflare in the transmission path for Business Portal traffic and may expose request content to overseas Processing. The precise data fields, edge locations, caching rules, log retention, security configuration and contractual coverage must be confirmed before activation.
Required supplementary measures and restrictions: Before activation, PostMyDoc must:
(a) complete the assessment required by clauses 10.3(c), 10.7 and 16;
(b) confirm and document Cloudflare’s role and contracting entity;
(c) ensure the applicable data processing addendum and transfer terms are in force;
(d) configure the service to disable caching and storage of PDF File Content;
(e) apply suitable TLS, access-control, firewall, logging, retention and deletion settings;
(f) determine whether PDF upload routes or other sensitive endpoints should bypass the edge;
(g) update Annex 2 and move the activity to Part A if it is authorised and activated; and
(h) give the Customer any notice required by clause 10.2 before Processing begins.
Netregistry Pty Ltd trading as Webcentral: full-volume back-up and contractual-protection limitations
Service: Full-volume back-up, disaster-recovery and hosting infrastructure.
Processing status: Active. Webcentral’s principal hosting functions are authorised in Part A.
Customer Personal Data Processed: Customer Personal Data stored within or captured by the hosting environment and its full-volume back-ups, potentially including PDF File Content that remained in live server storage when a back-up was taken.
Location: Australia (Sydney).
Current role: Sub-processor, as stated in Part A.
Material residual limitations: The hosting platform cannot exclude particular directories from full-volume back-ups or selectively delete an individual PDF File from an existing back-up. A PDF File captured before deletion from live server storage may therefore remain until the relevant back-up rotates out, for up to approximately 30 days. This prevents PostMyDoc from guaranteeing immediate deletion of each back-up copy when the corresponding active file is deleted.
Webcentral has confirmed that no data processing agreement or equivalent binding data-protection terms apply to the service. PostMyDoc therefore does not represent that Webcentral is contractually bound to comply with the APPs, this Agreement or obligations equivalent to those imposed on PostMyDoc. Webcentral necessarily retains infrastructure-level access required to provide hosting, back-up, maintenance, security, incident-response and recovery functions.
Supplementary measures and restrictions: PostMyDoc:
(a) keeps primary hosting and storage in Australia;
(b) encrypts PDF File Content in transit and at rest while held in live server storage;
(c) limits PDF File Content in live server storage through the automated age-based purge;
(d) restricts PostMyDoc personnel access to authorised persons with a need to know;
(e) does not use back-up copies in ordinary operations to retrieve, view, re-send or otherwise use individual documents as part of the Services;
(f) permits PostMyDoc access to back-up material only where reasonably necessary for disaster recovery, system restoration or, in exceptional circumstances, investigation, containment or remediation of a security incident;
(g) acknowledges that authorised Webcentral personnel may retain infrastructure-level access where reasonably necessary to provide hosting, back-up, maintenance, security, incident-response or recovery functions;
(h) requires back-up copies to remain protected and to rotate out under the hosting platform’s ordinary back-up cycle, which may take up to approximately 30 days;
(i) does not claim that deletion from live server storage deletes an existing back-up copy or constitutes cryptographic erasure;
(j) periodically reviews the engagement and the availability of suitable contractual protections or reasonably practicable alternative Australian hosting arrangements; and
(k) will update Annex 2 and Annex 3 if Webcentral’s terms, Processing, locations, retention practices, access arrangements or security measures materially change.
Residual risk: In the absence of binding data-protection terms, PostMyDoc cannot contractually require Webcentral to comply with processor obligations equivalent to those in this Agreement or provide the Customer with direct contractual enforcement against Webcentral. PostMyDoc remains responsible to the Customer under clauses 10.4 and 17 and remains accountable under applicable Data Protection Laws despite this limitation.
Atlantic Silicon Inc., provider of Limit Login Attempts Reloaded cloud services: wind-down
Sub-processor: Atlantic Silicon Inc., provider of Limit Login Attempts Reloaded cloud services
Infrastructure provider identified by the supplier: Amazon Web Services, at 410 Terry Avenue North, Seattle, Washington 98109-5210, United States
Status: Wind-down. Atlantic Silicon Inc. notified PostMyDoc in writing on 31 August 2026 that its cloud service is being discontinued within the following 90 days. PostMyDoc will cease transmission of Customer Personal Data to that cloud service no later than the date on which the supplier withdraws the service and will remove this entry after confirming that cloud transmission has ceased.
Service provided: Login-security firewall, shared IP-reputation checking and two-factor verification functions. The service checks login attempts against cloud-hosted reputation information and receives login and verification telemetry from the Business Portal.
Customer Personal Data processed:
(a) for login-protection events: username, or an unmasked email address where used as the login identifier; all detected user IP addresses, including proxy and forwarding addresses; and the login gateway of the site where the attempt occurred;
(b) for two-factor verification: login URL, masked email address, user group or role, all detected user IP addresses and user ID;
(c) for successful logins: the login-protection data described above, together with login URL, masked email address, user group or role, user ID and full User-Agent information;
(d) location information derived internally by the supplier from the transmitted IP address using a commercial DB2Location database; and
(e) LLAR plugin settings.
The supplier states that it does not collect passwords or other site content.
Retention reported by the supplier:
(a) login-protection data is retained for three months;
(b) two-factor verification data is deleted when the verification session ends or, if the session does not conclude normally, within 30 minutes; and
(c) successful-login data is retained for one year.
Processing locations: United States.
Onward processing: Atlantic Silicon Inc. states that the LLAR cloud service is hosted on Amazon Web Services infrastructure in the United States and that AWS acts as an infrastructure sub-processor. The same written response also states that no sub-processors are involved. PostMyDoc has requested clarification and does not treat either statement as resolving the inconsistency until the supplier confirms the processing chain in writing.
Transfer safeguards and contractual status: Atlantic Silicon Inc. states that transfers from the United Kingdom are covered by the European Commission’s 2021 Standard Contractual Clauses and the United Kingdom International Data Transfer Addendum, and that its AWS arrangements are governed by the AWS Data Processing Addendum and AWS UK GDPR Addendum. The supplier did not provide PostMyDoc with a copy of, or link to, an agreement binding Atlantic Silicon Inc. to PostMyDoc, and did not identify Australian-specific contractual safeguards. PostMyDoc does not represent that these supplier-reported arrangements satisfy APP 8.1 or are enforceable by PostMyDoc.
Certifications: Atlantic Silicon Inc. states that neither it nor the LLAR application holds ISO/IEC 27001 or SOC 2 certification. The supplier reports that the underlying AWS infrastructure holds ISO/IEC 27001 and SOC 2 assurance. Those certifications apply to AWS and not to Atlantic Silicon Inc. or the LLAR application.
Material residual limitations: Until cloud transmission ceases, PostMyDoc has not verified suitable contractual data-protection terms covering Atlantic Silicon Inc., the complete processing chain, Australian Privacy Law, incident notification, deletion, onward processing or APP-equivalent handling. The supplier’s written response contains inconsistent statements concerning its processor identity and AWS’s sub-processor status.
Supplementary measures and exit controls: Pending withdrawal, PostMyDoc will minimise the login data transmitted where technically practicable, restrict use of the cloud service to the minimum period required for an orderly exit, investigate local-only operation or a replacement service, and verify that cloud transmission has ceased when the supplier withdraws the service.
End of Data Processing Agreement — PostMyDoc Business