PostMyDoc Business – Data Processing Agreement
and structured to satisfy Article 28 of the EU General Data Protection Regulation (GDPR)
1. Parties
This Data Processing Agreement (Agreement or DPA) is made between:
1.1 PostMyDoc Digital Mailing Service Pty Ltd ACN 697 539 512, trading as PostMyDoc, ABN 18 697 539 512, of 82 Onkaparinga Valley Road, Woodside, South Australia 5244 (PostMyDoc, we, us or the Processor); and
1.2 the business customer identified in the PostMyDoc Business account application and approved by PostMyDoc (Customer, you or the Controller),
1.3 each a party and together the parties.
2. Background
2.1 PostMyDoc operates a digital-to-physical mail service: a Customer uploads a document, PostMyDoc prints it and posts it to the nominated recipient through Australia Post, and the uploaded document is then permanently deleted in accordance with the Burn After Reading Policy (the Services).
2.2 This Agreement governs PostMyDoc’s processing of Personal Data on the Customer’s behalf through the PostMyDoc Business Portal in connection with the Services. It forms part of, and is supplemental to, the PostMyDoc Business Terms of Service between the parties (the Principal Agreement).
2.3 The parties acknowledge that, in performing the Services, PostMyDoc processes Personal Data for which the Customer is responsible as Controller, and that this Agreement is required by Article 28(3) of the GDPR (where it applies) and supports the parties’ obligations under the Privacy Act 1988 (Cth).
3. Definitions and interpretation
3.1 In this Agreement, unless the context requires otherwise:
“APPs” means the Australian Privacy Principles set out in Schedule 1 to the Privacy Act.
“Australian Privacy Law” means the Privacy Act, the APPs, the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act, and any related binding code, guideline or determination of the OAIC, each as amended from time to time.
“Authorised Users” means the natural persons whom the Customer permits to access and use the Business Portal under the Customer’s Business account, comprising the Primary Contact and any additional business users the Customer adds. Each Authorised User acts for and on behalf of the Customer, and the access available to an Authorised User is determined by the role the Customer assigns (by default, a business user other than the Primary Contact can see only their own orders).
“Burn After Reading Policy” means PostMyDoc’s operating commitment that uploaded documents are encrypted in transit, printed once for dispatch, and permanently deleted within 24 hours of dispatch.
“Controller” means the entity that, alone or jointly, determines the purposes and means of the Processing of Personal Data; for the Customer Personal Data this is the Customer. “Controller” includes an “APP entity” that determines those matters for the purposes of Australian Privacy Law.
“Customer Personal Data” means any Personal Data that PostMyDoc Processes on behalf of the Customer under or in connection with the Services and the Business Portal, as described in Annex 1. It does not include data that PostMyDoc Processes as a Controller in its own right (see clause 4.4).
“Data Protection Laws” means all laws applicable to the Processing of Customer Personal Data under this Agreement, including Australian Privacy Law and, where applicable to a party in respect of the relevant Processing, the GDPR and the UK GDPR.
“Data Subject” means an identified or identifiable individual to whom Personal Data relates.
“Eligible Data Breach” means an “eligible data breach” as defined in Part IIIC of the Privacy Act.
“GDPR” means Regulation (EU) 2016/679 (the EU General Data Protection Regulation); and UK GDPR means the GDPR as it forms part of the law of the United Kingdom by virtue of the European Union (Withdrawal) Act 2018, together with the Data Protection Act 2018 (UK).
“Notifiable Data Breaches scheme” means or NDB scheme, the scheme established under Part IIIC of the Privacy Act.
“OAIC” means the Office of the Australian Information Commissioner, including the Australian Information Commissioner and the Privacy Commissioner.
“Personal Data” means information relating to a Data Subject that is protected as “personal data” under the GDPR or the UK GDPR, or as “personal information” under the Privacy Act. References to “Personal Data” include “personal information” and the two terms are used interchangeably in this Agreement.
“Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data, including any event that is or may be an Eligible Data Breach.
“Primary Contact” means the Authorised User the Customer nominates as the administrator of its Business account (shown in the Portal as the Account Admin). The Primary Contact is authorised to act for the Customer in relation to the account — including to accept this Agreement and the related PostMyDoc Business legal documents on the Customer’s behalf, to add and remove other Authorised Users and set their access, and to give account-level and written instructions to PostMyDoc — and has visibility of all orders within the Customer’s account.
“Privacy Act” means the Privacy Act 1988 (Cth).
“Processing” means any operation performed on Personal Data, whether or not by automated means, including collection, recording, storage, use, transmission, printing, disclosure, erasure and destruction (and Process and Processed have corresponding meanings).
“Processor” means the entity that Processes Personal Data on behalf of the Controller; for the Customer Personal Data this is PostMyDoc.
“Sensitive Information” means “sensitive information” as defined in the Privacy Act (which includes health information), and “special categories of personal data” within the meaning of Article 9 of the GDPR, together with personal data relating to criminal convictions and offences.
“Standard Contractual Clauses” means or SCCs, the standard contractual clauses for the transfer of personal data to third countries set out in Commission Implementing Decision (EU) 2021/914 of 4 June 2021, as amended or replaced from time to time.
“Sub-processor” means any third party engaged by PostMyDoc (or by a Sub-processor) to Process Customer Personal Data in connection with the Services.
“Supervisory Authority” means the OAIC and, where the GDPR or UK GDPR applies, any competent supervisory authority responsible for monitoring the application of those laws.
“Technical and Organisational Measures” means or TOMs, the measures described in Annex 2.
“UK Addendum” means the International Data Transfer Addendum to the EU Standard Contractual Clauses issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018 (UK), and IDTA means the UK International Data Transfer Agreement.
3.2 Interpretation: (a) headings are for convenience only and do not affect interpretation; (b) the singular includes the plural and vice versa; (c) a reference to legislation includes any subordinate legislation and any amendment, consolidation or replacement of it; (d) “including” and similar expressions are not words of limitation; and (e) where a term is defined in the Data Protection Laws but not in this Agreement, it has the meaning given in those laws.
3.3 If there is any inconsistency between the documents forming the arrangement between the parties, the order of precedence in clause 19.2 applies.
4. Status and roles of the parties
4.1 In respect of the Customer Personal Data, the Customer is the Controller and PostMyDoc is the Processor.
4.2 The Customer warrants that it has a lawful basis to Process, and to authorise PostMyDoc to Process, the Customer Personal Data for the purposes described in Annex 1, including where the documents it submits contain Personal Data of recipients or of third parties, and including any Sensitive Information.
4.3 The Customer is responsible for the accuracy, quality and lawfulness of the Customer Personal Data and of the instructions it gives to PostMyDoc, and for providing all notices to, and obtaining all consents from, Data Subjects required under the Data Protection Laws for the Processing contemplated by this Agreement.
4.4 PostMyDoc as an independent Controller. Separately from its role as Processor, PostMyDoc acts as a Controller for limited purposes of its own, including operating, securing and improving the Services, account administration, billing and the keeping of financial records, fraud prevention and meeting its own legal obligations. That Processing is governed by PostMyDoc’s own privacy policy and not by this Agreement. This Agreement governs only PostMyDoc’s Processing of Customer Personal Data as Processor.
4.5 Nothing in this Agreement makes the parties joint controllers.
5. Scope of this Agreement
5.1 In scope. This Agreement applies to PostMyDoc’s Processing of Customer Personal Data through the PostMyDoc Business Portal, including:
(a) the Business account application and account approval workflow;
(b) all customer-facing surfaces of the business dashboard (at postmydoc.au/business-dashboard/ and its sub-paths), including order creation, recipient entry, address-book and saved-recipient features, team and invitation management, account management, and billing (invoices and statements);
(c) the B2B order pipeline — documents uploaded for printing and dispatch, and their associated recipient and dispatch data — and the deletion of those documents under the Burn After Reading Policy;
(d) the business-context transactional email surfaces (order confirmation, dispatch, delivery, first-deletion, weekly digest, and account/approval emails); and
(e) the business account metadata described in Annex 1.
5.2 Out of scope. This Agreement does not apply to, and the Customer Personal Data does not include, Personal Data processed in connection with:
(a) browsing of the consumer (B2C) PostMyDoc website, which is governed by the consumer Privacy Policy;
(b) the consumer PostMyDoc mobile application, which is governed by its own privacy policy and the relevant app-store terms; or
(c) the Chatway chat widget, which operates only on consumer surfaces and is disabled across the business dashboard, and which is governed by the consumer Privacy Policy.
5.3 Pre-sale browsing of PostMyDoc’s marketing pages by a prospective Customer is evaluative and is governed by the consumer Privacy Policy until a Business account is approved and the Services commence.
6. Compliance with Data Protection Laws
6.1 Each party will comply with the Data Protection Laws that apply to it in respect of the Processing under this Agreement.
6.2 PostMyDoc will Process the Customer Personal Data in a manner that enables the Customer to comply with its own obligations under the Data Protection Laws, and will not, by act or omission, cause the Customer to be in breach of those laws.
6.3 Where the GDPR or UK GDPR applies to a Customer in respect of the relevant Processing (for example, where the Customer is established in the EEA or the United Kingdom, or otherwise falls within the territorial scope of those laws), this Agreement is the parties’ agreement for the purposes of Article 28(3) of the GDPR and the equivalent provision of the UK GDPR, and clauses 7 to 16 are to be read as giving effect to each of the requirements of Article 28(3).
6.4 Australian Privacy Law applies to the Processing under this Agreement regardless of whether the GDPR or UK GDPR also applies.
7. Processing of Personal Data
7.1 Documented instructions. PostMyDoc will Process the Customer Personal Data only on the Customer’s documented instructions, including in relation to any transfer of Personal Data outside Australia, unless required to Process the data by a law to which PostMyDoc is subject. The Customer’s documented instructions are constituted by this Agreement, the Principal Agreement, the configuration and orders the Customer (and its Authorised Users) submit through the Business Portal, and any further written instructions the parties agree.
7.2 Required by law. If a law requires PostMyDoc to Process the Customer Personal Data otherwise than on the Customer’s instructions, PostMyDoc will, to the extent permitted by that law, inform the Customer of the legal requirement before Processing.
7.3 Unlawful instructions. PostMyDoc will inform the Customer without undue delay if, in its opinion, an instruction infringes the Data Protection Laws, and may suspend performance of the affected instruction (without liability) until the Customer confirms or amends it. PostMyDoc is not obliged to provide legal advice on the Customer’s instructions.
7.4 How instructions are given. Routine, order-level instructions are given by the Customer’s Authorised Users through the Business Portal, within the access each has been granted. Account-level instructions, and any other instruction given in writing, are given by the Primary Contact for and on behalf of the Customer, to PostMyDoc’s privacy contact at privacy@postmydoc.au. The Customer is responsible for the authority and conduct of its Authorised Users (including the Primary Contact), for ensuring that only its Authorised Users issue instructions, and for the access it grants to each within its account.
8. Confidentiality
8.1 PostMyDoc will treat the Customer Personal Data as confidential and will not disclose it except as permitted by this Agreement or required by law.
8.2 PostMyDoc will ensure that each person it authorises to Process the Customer Personal Data (including any personnel and contractors) is subject to a binding obligation of confidentiality — whether by written agreement, a professional duty of confidence, or a duty implied at law — and is made aware of the confidential nature of the data.
8.3 PostMyDoc will ensure that access to the Customer Personal Data is limited to those persons who need access to perform the Services, and will take reasonable steps to ensure the reliability of any such person.
9. Security of processing
9.1 PostMyDoc will implement and maintain the Technical and Organisational Measures described in Annex 2, which are designed to ensure a level of security appropriate to the risk, having regard to the state of the art, the costs of implementation, and the nature, scope, context and purposes of the Processing, as well as the risk of varying likelihood and severity to the rights and freedoms of Data Subjects.
9.2 In implementing those measures, PostMyDoc will take account of the matters in Article 32 of the GDPR (including, as appropriate, pseudonymisation and encryption, confidentiality, integrity, availability and resilience, the ability to restore availability and access after an incident, and a process for regularly testing and evaluating the measures) and of the requirement in APP 11 of the Privacy Act to take reasonable steps — including reasonable technical and organisational measures — to protect Personal Data from misuse, interference and loss, and from unauthorised access, modification or disclosure.
9.3 PostMyDoc may update the TOMs from time to time provided that the updated measures do not materially reduce the overall level of protection of the Customer Personal Data.
9.4 Document deletion. As a security and data-minimisation measure, PostMyDoc operates the Burn After Reading Policy: uploaded documents are encrypted in transit, retained only as long as needed to print and dispatch them. An automated, scheduled server-side task runs hourly and removes any uploaded document file that is more than 24 hours old; because dispatch occurs within 24 hours of upload under PostMyDoc’s operating commitment, document content is deleted within 24 hours of dispatch and never later. Deletion removes the file from the live file system (it is not a cryptographic erasure), and a deletion record is generated for each dispatched document. The Customer acknowledges that, because documents are deleted on this basis, PostMyDoc cannot re-send or recover a document after deletion and the Customer must resubmit it if required.
10. Sub-processing
10.1 General authorisation. The Customer gives PostMyDoc a general authorisation to engage the Sub-processors listed in Annex 3, and to engage further Sub-processors in accordance with this clause 10.
10.2 Notice and objection. PostMyDoc will inform the Customer of any intended addition or replacement of a Sub-processor at least fourteen (14) days before that Sub-processor begins Processing Customer Personal Data, giving the Customer the opportunity to object. If the Customer objects on reasonable data-protection grounds within that period, the parties will work in good faith to resolve the objection; if it cannot be resolved, the Customer may terminate the affected Services on written notice, as its sole remedy.
10.3 Flow-down. PostMyDoc will enter into a written contract with each Sub-processor that imposes data-protection obligations that are no less protective than those in this Agreement, in particular as regards security and the requirements of Article 28(3) of the GDPR where it applies.
10.4 Liability. PostMyDoc remains fully liable to the Customer for the performance of each Sub-processor’s obligations to the same extent as if PostMyDoc had performed them itself, and remains accountable for the acts and practices of any overseas Sub-processor in the manner contemplated by APP 8 and section 16C of the Privacy Act (see clause 16).
10.5 An up-to-date list of Sub-processors is maintained in Annex 3 and is available to the Customer on request.
11. Assistance with Data Subject requests
11.1 Taking into account the nature of the Processing, PostMyDoc will assist the Customer by appropriate technical and organisational measures, insofar as possible, to respond to requests from Data Subjects to exercise their rights under the Data Protection Laws — including rights of access and correction under APP 12 and APP 13, and the rights of access, rectification, erasure, restriction, portability and objection under the GDPR and UK GDPR where they apply.
11.2 If PostMyDoc receives a request from a Data Subject relating to the Customer Personal Data, it will not respond to the request itself (except to confirm that the request has been referred to the Customer, or as required by law), and will refer the request to the Customer without undue delay.
11.3 The Customer acknowledges that, because documents are deleted under the Burn After Reading Policy, the data available for PostMyDoc to assist with a Data Subject request is generally limited to account, order and dispatch metadata — including recipient details and the document filename and content hash retained in the dispatch and deletion records — and not the content of dispatched documents. That metadata is retained until deleted in accordance with clause 14.
11.4 PostMyDoc may charge a reasonable fee for assistance that is unusual in nature or that requires material effort beyond standard support, having first notified the Customer of the basis for the charge.
12. Assistance with security, impact assessments and consultation
12.1 Taking into account the nature of the Processing and the information available to it, PostMyDoc will provide reasonable assistance to the Customer with:
(a) ensuring compliance with the security obligations in clause 9 (and Article 32 of the GDPR / APP 11);
(b) carrying out data protection impact assessments under Article 35 of the GDPR, and privacy impact assessments under Australian Privacy Law, where required; and
(c) any prior consultation with a Supervisory Authority under Article 36 of the GDPR.
12.2 Clause 11.4 (reasonable fees for unusual or burdensome assistance) applies to assistance under this clause 12.
13. Personal Data Breach and eligible data breach notification
13.1 Notice to the Customer. PostMyDoc will notify the Customer without undue delay, and in any event no later than 48 hours, after becoming aware of a Personal Data Breach affecting the Customer Personal Data. PostMyDoc will not delay that notification in order to complete its investigation; an initial notification with the information then available is acceptable, with further information provided in phases as it becomes available. This notification is given to enable the Customer, as Controller, to meet its own obligations within the time required by the Data Protection Laws — including any obligation to notify as soon as practicable under the Notifiable Data Breaches scheme, and to notify within 72 hours under Article 33 of the GDPR where it applies. It does not transfer those obligations to PostMyDoc, and does not itself constitute a notification by PostMyDoc under those laws.
13.2 Each notification will, to the extent known, describe:
(a) the nature of the Personal Data Breach, including the categories and approximate number of Data Subjects and records concerned;
(b) the likely consequences of the breach;
(c) the measures taken or proposed to address the breach and to mitigate its possible adverse effects; and
(d) a contact point at PostMyDoc from whom further information may be obtained.
13.3 Assistance and containment. PostMyDoc will take reasonable steps to contain and remediate the breach, will reasonably cooperate with the Customer, and will assist the Customer in meeting any obligation it has to notify a Supervisory Authority (including, under the GDPR, within 72 hours under Article 33) and affected Data Subjects.
13.4 Notifiable Data Breaches scheme — coordination. The parties acknowledge that both of them may “hold” the same Customer Personal Data for the purposes of the NDB scheme. Where there are reasonable grounds to suspect that an Eligible Data Breach may have occurred, PostMyDoc will assist the Customer with its assessment within the period contemplated by Part IIIC of the Privacy Act (generally 30 days). Unless the parties agree otherwise in writing, the Customer will, as Controller, be the entity that makes any required notification to the OAIC and to affected individuals, and PostMyDoc will not make a separate notification in respect of the same breach except where the parties agree or where PostMyDoc is independently required by law to do so; this reflects the single-notification approach permitted under the NDB scheme where more than one entity holds the affected information.
13.5 Nothing in this clause is an admission of fault or liability by either party in respect of a Personal Data Breach.
14. Retention, return and deletion of Personal Data
14.1 During the Services. Document content is deleted continuously under the Burn After Reading Policy (clause 9.4), independently of termination. A document deletion certificate is generated for each dispatched document (for a batch order, one certificate per recipient), recording the deletion of that document’s content.
14.2 On termination. On expiry or termination of the Principal Agreement, PostMyDoc will, at the Customer’s election, either return the remaining Customer Personal Data to the Customer in a commonly used format, or delete it, and will delete existing copies, within ninety (90) days of the later of termination and the Customer’s election, except to the extent clause 14.4 applies. If the Customer does not make an election within 30 days of termination, PostMyDoc may delete the data.
14.3 Back-ups. The hosting platform takes full-volume back-ups of the entire account and cannot be configured to exclude particular directories, so where an uploaded document is captured in a back-up before its primary copy is deleted, that back-up copy is retained until the back-up ages out of the provider’s retention window, which is up to approximately 30 days. Such back-up copies remain subject to the confidentiality and security obligations of this Agreement until they age out. This is the only circumstance in which a copy persists beyond the 24-hour Burn After Reading window, and then only transiently.
14.4 Retention required by law. PostMyDoc may retain Customer Personal Data to the extent, and for as long as, required by a law to which it is subject — for example, financial and transaction records that must be kept under Australian taxation law — in which case PostMyDoc will retain the data only for that purpose, will keep it secure and confidential, and will Process it only as required by that law.
14.5 On request, PostMyDoc will provide the Customer with written confirmation that it has complied with this clause 14.
14.6 Retention limits and no mandated content retention. PostMyDoc is not a carrier or carriage service provider and is not subject to the mandatory telecommunications data-retention scheme under the Telecommunications (Interception and Access) Act 1979 (Cth); no law requires PostMyDoc to retain the content of Customer documents. Consistent with APP 11.2, document content is retained only as long as needed to print and dispatch it and is then permanently deleted under the Burn After Reading Policy (clause 9.4). That deletion occurs automatically and in the ordinary course of business; it is not undertaken in response to, or in order to frustrate, any actual or anticipated investigation or proceeding. PostMyDoc retains only the account, order and dispatch metadata needed to provide the Services and to meet its own legal obligations (including the financial-record retention in clause 14.4). The Customer remains responsible for retaining its own copies of documents and any records it is required by law to keep; deletion under the Burn After Reading Policy affects only the transient copy PostMyDoc holds for printing and dispatch, not the Customer’s own records.
14.7 Law-enforcement and government access. PostMyDoc can disclose only Customer Personal Data that it holds at the time of a request; because document content is deleted under the Burn After Reading Policy, it is generally not available to be produced after dispatch. PostMyDoc will not disclose Customer Personal Data to a law-enforcement or government authority except where required by a valid and binding legal compulsion, or as otherwise permitted by this Agreement. Where it is legally able to do so, PostMyDoc will inform the Customer of the request without undue delay so that the Customer may seek to limit or challenge it. If PostMyDoc receives a valid legal preservation or production order in respect of Customer Personal Data it then holds (for example, document content still within the pre-deletion window), it will comply with its obligations under that order; nothing in the Burn After Reading Policy requires or permits PostMyDoc to destroy data that it is under a current legal obligation to preserve.
15. Records and audit
15.1 PostMyDoc will maintain records of its Processing of Customer Personal Data sufficient to demonstrate compliance with this Agreement, and will make available to the Customer the information reasonably necessary to demonstrate compliance with the obligations in Article 28 of the GDPR (where it applies) and this Agreement.
15.2 Audits. PostMyDoc will allow for and contribute to audits, including inspections, conducted by the Customer or an independent auditor mandated by the Customer (and who is not a competitor of PostMyDoc and is bound by confidentiality), subject to the following: audits may be conducted once in any 12-month period (and additionally following a Personal Data Breach affecting the Customer Personal Data), on at least 30 days’ written notice, during business hours, in a manner that does not unreasonably disrupt PostMyDoc’s operations, and limited to systems, records and personnel relevant to the Processing of the Customer Personal Data.
15.3 Third-party reports. PostMyDoc may satisfy an audit request by providing relevant current third-party audit reports, certifications or attestations held by it or its Sub-processors (for example, ISO/IEC 27001 certification or SOC 2 reports of a Sub-processor), where these reasonably address the scope of the Customer’s audit.
15.4 Each party bears its own costs of an audit, except that the Customer will reimburse PostMyDoc’s reasonable costs for assistance that exceeds PostMyDoc’s reasonable internal effort. Audit findings are the confidential information of both parties.
16. International data transfers
16.1 Where the data is held. The primary hosting and storage of Customer Personal Data is in Australia (see Annex 3). Certain Sub-processors Process limited categories of Customer Personal Data outside Australia, as identified in Annex 3.
16.2 APP 8 — cross-border disclosure. Where PostMyDoc discloses Customer Personal Data to an overseas recipient (including an overseas Sub-processor), PostMyDoc will take such steps as are reasonable in the circumstances to ensure that the recipient does not breach the APPs in relation to the data, consistently with APP 8.1, and acknowledges the accountability provision in section 16C of the Privacy Act. The contractual measures in clause 10.3 and the relevant Sub-processor contracts are intended to satisfy this obligation.
16.3 GDPR / UK GDPR transfers. Where the GDPR or UK GDPR applies to a Customer and that law requires a transfer mechanism for the transfer of Customer Personal Data to PostMyDoc in Australia (a country that is not, at the date of this Agreement, the subject of an EU or UK adequacy decision), the cross-border transfer terms in Annex 4 apply and the relevant Standard Contractual Clauses (and, for transfers from the United Kingdom, the UK Addendum or IDTA) are incorporated into this Agreement on the basis set out in that Annex.
16.4 Onward transfers. Where PostMyDoc, as importer, makes an onward transfer of Customer Personal Data that is subject to the GDPR or UK GDPR to a Sub-processor located outside Australia, PostMyDoc will ensure that an appropriate transfer mechanism under Chapter V of the GDPR (or the UK equivalent) is in place for that onward transfer.
16.5 If a transfer mechanism on which the parties rely is invalidated or materially changed, the parties will cooperate in good faith to put in place an alternative lawful mechanism without undue delay.
17. Liability and indemnity
17.1 Subject to clause 17.3, each party’s liability arising out of or in connection with this Agreement is subject to, and counts towards, the limitations and exclusions of liability in the Principal Agreement.
17.2 The parties acknowledge that, under Article 82 of the GDPR (where it applies), a Controller and a Processor may be jointly and severally liable to a Data Subject for the entire damage caused by Processing that infringes the GDPR. As between the parties, each party will be responsible for, and will indemnify the other against, losses to the extent caused by that first party’s breach of this Agreement or of the Data Protection Laws, in the proportion for which it is responsible.
17.3 Nothing in this Agreement limits or excludes a liability that cannot lawfully be limited or excluded, including certain liabilities under the Data Protection Laws or the Australian Consumer Law.
18. Term and termination
18.1 This Agreement takes effect on the date the Customer accepts it (or, if later, the date the Customer’s Business account is approved) and continues for as long as PostMyDoc Processes Customer Personal Data under the Principal Agreement.
18.2 Clauses that by their nature should survive termination — including clauses 8 (confidentiality), 14 (retention, return and deletion), 15 (records and audit, in respect of the period before termination), 16 (transfers, for retained data), 17 (liability) and 19 (general) — survive termination of this Agreement.
19. General
19.1 Acceptance and updates. The Customer accepts this Agreement through its Primary Contact, by the required acceptance step at the Business account application (and, where applicable, on re-acceptance prompted by a material update). By completing that step, the person doing so confirms that they are the Customer’s Primary Contact and are authorised to accept this Agreement for and on behalf of the Customer. A per-account acceptance record — including a timestamp and the version of each accepted document — is created and retained. PostMyDoc may update this Agreement where reasonably necessary (including to reflect changes in law, the Services or Sub-processors); for a material change PostMyDoc will give reasonable notice and, where required, seek the Customer’s re-acceptance, and will not reduce the overall level of protection of the Customer Personal Data.
19.2 Order of precedence. If there is an inconsistency, the following order of precedence applies (highest first): (a) the Standard Contractual Clauses and UK Addendum incorporated under Annex 4, to the extent they apply to a GDPR/UK GDPR transfer; (b) this Agreement; and (c) the Principal Agreement and any other related document. The PostMyDoc Business Privacy Policy and Refund Policy are read consistently with this Agreement.
19.3 Governing law and jurisdiction. This Agreement is governed by the laws of South Australia and the Commonwealth of Australia, and the parties submit to the non-exclusive jurisdiction of the courts of South Australia, except that, where the Standard Contractual Clauses apply to a transfer, the governing law and forum for those clauses are as stated in Annex 4.
19.4 Notices. Notices to PostMyDoc under this Agreement must be sent to privacy@postmydoc.au. Notices to the Customer may be sent to the Primary Contact email recorded for the Business account.
19.5 Variation and waiver. Except as provided in clause 19.1, a variation of this Agreement must be in writing. A failure to exercise, or delay in exercising, a right does not operate as a waiver.
19.6 Severance. If a provision of this Agreement is or becomes invalid or unenforceable, it is to be read down or severed to the minimum extent necessary, without affecting the remaining provisions.
19.7 Assignment. Neither party may assign or novate this Agreement without the other’s consent, except that PostMyDoc may assign it to a related body corporate or in connection with a transfer of its business, on notice to the Customer.
19.8 Entire agreement. This Agreement, together with the documents it refers to, is the entire agreement between the parties about its subject matter and supersedes prior arrangements about that subject matter.
19.9 Counterparts. This Agreement may be executed (where it is executed rather than accepted online) in counterparts, including by electronic signature.
20. Execution
Where this Agreement is accepted online, clause 19.1 governs and no signature is required. The signature blocks below are provided for use where the parties choose to execute this Agreement.
Signed for and on behalf of the Processor — PostMyDoc Digital Mailing Service Pty Ltd (trading as PostMyDoc):
| Authorised signatory Signature | Name |
| Title | Date |
Signed for and on behalf of the Customer:
| Authorised signatory Signature | Name |
| Title | Date |
Annex 1 — Description of the Processing
This Annex describes the Processing of Customer Personal Data under this Agreement. Where the GDPR applies, it serves as the description required by Article 28(3) and (for any incorporated Standard Contractual Clauses) Annex I to those clauses.
| Item | Description |
| Parties | Data exporter / Controller: the Customer (the approved PostMyDoc Business account holder identified in the account record). Data importer / Processor: PostMyDoc Digital Mailing Service Pty Ltd trading as PostMyDoc, Australia. |
| Subject matter | PostMyDoc’s provision of the digital-to-physical mail Services to the Customer through the Business Portal: receiving uploaded documents, printing them, dispatching them via Australia Post, and providing the associated account, order, billing and notification functions. |
| Duration | For the term of the Principal Agreement and until return or deletion of the Customer Personal Data under clause 14. Document content is retained only until permanent deletion within 24 hours of dispatch (Burn After Reading Policy). |
| Nature of the Processing | Collection, recording, storage, organisation, transmission, printing, disclosure to Australia Post for dispatch, use for account administration, billing and notifications, and erasure / permanent deletion. |
| Purpose of the Processing | To perform the Services on the Customer’s documented instructions — print and post the Customer’s documents to nominated recipients — and to operate the related Business Portal functions (account and team management, order history, billing, and transactional notifications). |
| Frequency | Continuous / on an ongoing basis for the duration of the Services, driven by the orders and activity of the Customer’s Authorised Users. |
Categories of Data Subjects
| Category | Examples |
| The Customer’s Authorised Users | The Primary Contact and other linked business users and invitees — typically the Customer’s staff. |
| Recipients of mailed documents | The named addressees to whom documents are dispatched. |
| Individuals appearing within documents | Any individuals whose Personal Data appears in the content of an uploaded document (the Customer determines this and PostMyDoc does not control or inspect it). |
Categories of Personal Data
| Category | Detail |
| Account and identity data | Business name, ABN, industry; Primary Contact name, email and phone; applicant name and email; names and emails of linked users and invited users; user role (Primary Contact / business user); internal account notes. |
| Authentication and security data | Hashed account passwords; login-attempt metadata processed for brute-force protection (including IP address, timestamp and attempted username); tokenised invitation and password-reset links. |
| Order, recipient and dispatch data | Recipient names and delivery addresses (address lines, suburb/city, state, postcode, country); partial address data entered through address autocomplete; destination zone; postage service; tracking numbers and delivery status; dispatch date; and order references such as purchase-order number, cost centre and sender label. |
| Document content | The content of the uploaded documents (PDFs), which is determined by the Customer and may contain Personal Data of any kind. Documents are deleted within 24 hours of dispatch. |
| Billing and transaction data | Order and pricing data, invoices and statements, payment status, and payment-transaction metadata. Card/payment-instrument data is collected and processed directly by the payment Sub-processor (Stripe); PostMyDoc does not store full card numbers. |
| Usage and analytics data | Page-view and usage metadata and related identifiers (including IP address) processed for site analytics. |
Annex 2 — Technical and Organisational Measures
These are the measures PostMyDoc maintains under clause 9. Where the GDPR applies, this Annex serves as the description of measures under Article 28(3) and Article 32, and as Annex II to any incorporated Standard Contractual Clauses. Items marked for confirmation are operational facts to be verified and finalised before execution.
| Measure | Description |
| Data minimisation and deletion | Uploaded document content is retained only as long as needed to print and dispatch. An automated, scheduled server-side task runs hourly and removes any uploaded document file more than 24 hours old; because dispatch occurs within 24 hours of upload, document content is deleted within 24 hours of dispatch and never later (Burn After Reading Policy). The task runs on the server’s own scheduler, independently of site traffic, and deletion removes the file from the live file system. Only the account, order and dispatch fields needed to provide the Services are collected; document filenames and content hashes retained in the dispatch and deletion records are kept until deleted under clause 14. |
| Encryption in transit | All connections to the Business Portal and PostMyDoc’s service endpoints are served over HTTPS/TLS; documents are encrypted in transit. |
| Encryption at rest | Uploaded document content is encrypted at rest using authenticated application-level encryption (libsodium), so the stored bytes are ciphertext; a document is decrypted only transiently in memory at the point it is retrieved for dispatch, and a plaintext copy is never written back to disk. This is layered with strong data minimisation: under the Burn After Reading Policy the document content is permanently deleted within 24 hours of dispatch and does not persist. Connections are encrypted in transit (TLS), and access to stored data is role-restricted. |
| Access control | Role-based access: a dedicated business-user role; row-level visibility so the nominated Primary Contact sees the account’s orders while other users see only their own; a fail-secure default (own-records-only) until a Primary Contact is set; privileged administrative access is restricted to authorised PostMyDoc personnel; unauthorised access to a record returns an opaque “not found” response rather than revealing its existence. |
| Authentication | Account passwords are stored only as salted hashes; a minimum password length is enforced on invitation and reset; a branded login and a tokenised password-reset flow are used. |
| Multi-factor authentication | Multi-factor authentication is enforced for administrative and operator access to the platform, and for the third-party administrative consoles used to operate it (hosting, payments and connected services). |
| Secure document download | Documents and billing artefacts are served only through gated, authenticated download paths tied to the requesting user’s permissions; direct unauthenticated file access is not permitted. |
| Brute-force / abuse protection | Login-attempt rate limiting with lockout, and cloud-assisted IP-reputation checks via the login-security plugin’s cloud service, to protect against credential-stuffing and brute-force attacks. |
| Input validation | Uploads are restricted by file-type (content/“magic-byte”) checks and a size cap; key request values are validated against strict allow-lists; errors are returned generically without exposing internal detail. |
| Privacy-by-design in notifications | Transactional email subject lines deliberately omit recipient location detail; an anonymous-sender option is available so the sender identity can be withheld on dispatch where chosen. |
| Hosting and platform | Hosting is provided in Australia (Sydney) by the hosting provider (Netregistry Pty Ltd t/a Webcentral) on a managed platform with current server software and PHP, in a data centre that holds ISO/IEC 27001 certification. The provider operates a web application firewall and malware scanning, applies platform security patching, takes twice-daily back-ups with restore-to-last-known-good recovery, and monitors for suspected security incidents. Time-based tasks run on a server-level scheduler (server-side cron); WordPress’s traffic-triggered scheduler is disabled so that scheduled tasks, including document deletion, execute reliably on schedule rather than depending on site visits. |
| Back-up and recovery | The hosting provider (Netregistry Pty Ltd t/a Webcentral) takes automated twice-daily full-volume back-ups of the entire account, retained for up to approximately 30 days, with restore-to-last-known-good recovery that has been tested. |
| Logging and monitoring | The hosting provider’s Trust and Safety team monitors for suspected security incidents and notifies of suspected breaches. At the application level, PostMyDoc logs document-deletion events, payment and Stripe-webhook processing (including signature and payload failures), and authentication failures and lockouts, in on-server logs retained for approximately 30 days. |
| Incident response | A process to detect, contain, assess and notify Personal Data Breaches in accordance with clause 13, including assistance with NDB-scheme assessment and notification. |
| Personnel and confidentiality | Personnel and any contractors with access to Customer Personal Data are bound by confidentiality obligations and are granted access on a least-privilege, need-to-know basis. Privileged administrative access is restricted to authorised PostMyDoc personnel. |
| Sub-processor assurance | Engagement of Sub-processors that maintain recognised security practices and, where applicable, certifications (see Annex 3); contractual flow-down of data-protection obligations under clause 10.3. |
Annex 3 — Approved Sub-processors
The Sub-processors PostMyDoc engages to Process Customer Personal Data for the Business Portal, authorised under clause 10. Where the GDPR applies, this Annex serves as the Sub-processor list and as Annex III to any incorporated Standard Contractual Clauses.
| Sub-processor | Service provided | Data Processed | Location |
| Netregistry Pty Ltd t/a Webcentral | Website and database hosting, file storage, and outbound transactional email (SMTP) infrastructure. | All Customer Personal Data stored on the platform, and email content and metadata. | Australia (Sydney) |
| Stripe (Stripe Payments Australia Pty Ltd, merchant of record, with Stripe, Inc. as the United States processing entity) | Payment processing for orders, invoices and statements. | Payment-instrument and transaction data, and related billing identifiers. (PostMyDoc does not store full card numbers.) | Australia and United States |
| Australia Post | Printing-to-post dispatch and parcel tracking. | Recipient names and delivery addresses; tracking and delivery-status data. | Australia |
| Google Maps Platform (Google LLC) | Address autocomplete during recipient entry. | Partial address data entered during address look-up. | United States and other locations |
| Google Analytics (GA4) (Google LLC) | Site analytics for the Business Portal (logged-out portal visitors only; authenticated business users are excluded from analytics). | Usage and page-view metadata and related identifiers (including IP address). | United States and other locations |
| Google Fonts (Google LLC) | Delivery of web fonts used to render Business Portal pages. | The visitor’s IP address and User-Agent, sent to Google’s font service when a portal page loads its fonts. | United States and other locations |
| Google Tag Manager (Google LLC) | Tag-management container that loads and manages measurement tags on the Business Portal. | Page-interaction and device metadata and related identifiers (including IP address) passed to tags loaded through the container. | United States and other locations |
| Cloudflare, Inc. | Cloudflare Turnstile bot/abuse protection (a CAPTCHA challenge) on the Business Account Application form. If an edge proxy or web application firewall is later enabled, Cloudflare would also proxy Business Portal traffic and terminate TLS at its edge, so request data would transit Cloudflare in the course of delivery; document content would not be cached or stored by Cloudflare. | For Turnstile: the applicant’s IP address and CAPTCHA challenge-interaction data. (If an edge proxy is later enabled: connection and request metadata, source IP addresses, and request content in transit.) | United States (with Australian points of presence) |
| Limit Login Attempts Reloaded (LLAR) cloud, provided by Atlantic Silicon Inc. | Login-security firewall. LLAR’s cloud service checks login attempts against a shared, crowdsourced IP-reputation blocklist and the site contributes login-attempt IP telemetry to that shared database. Business-user logins flow through this path. | On every login attempt: the client IP address(es), the attempted login identifier (username or email) and the authentication gateway. On a successful login, additionally the user ID, WordPress roles, full User-Agent and referring path. The data is sent un-pseudonymised (the plugin’s GDPR option masks only the local log, not the cloud payload). | United States |
The contracting entities named above are confirmed against the live configuration: the Stripe account is Australian-domiciled, so Stripe Payments Australia Pty Ltd is the merchant of record and Stripe, Inc. is the United States processing entity. The Webcentral hosting entity is Netregistry Pty Ltd t/a Webcentral. Registered addresses are completed in the SCC Annex III appendix if and when an EEA or UK Customer is onboarded, rather than in this Australian-baseline list. Cloudflare publishes its own data processing addendum incorporating the Standard Contractual Clauses; that addendum is to be accepted/incorporated for the transfer to Cloudflare (currently engaged via Turnstile on the application form). LLAR’s cloud service is in use, so Atlantic Silicon Inc. (3999 Commons Dr. W Unit N, Destin, Florida 32541, United States; support@limitloginattempts.com) is an overseas Sub-processor receiving login-attempt data, covered by the transfer terms in clause 16; if LLAR is switched to local-only operation, no login data leaves the server and it is removed from this list (moving to the excluded items below).
Annex 4 — Cross-border transfer mechanism (GDPR / UK GDPR)
This Annex applies only where the GDPR or UK GDPR applies to a Customer and a transfer mechanism is required for the transfer of Customer Personal Data to PostMyDoc in Australia (clause 16.3). Australia is not, at the date of this Agreement, the subject of an EU or UK adequacy decision.
A4.1 EU Standard Contractual Clauses. For transfers subject to the GDPR, the parties incorporate the Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914), and agree that:
(a) Module Two (Controller to Processor) applies, with the Customer as data exporter and PostMyDoc as data importer;
(b) the optional docking clause (Clause 7) [●];
(c) for Clause 9 (use of sub-processors), Option 2 (general written authorisation) applies, with the notice period in clause 10.2 of this Agreement (14 days);
(d) for Clause 11 (redress), the optional independent-dispute-resolution wording [●];
(e) for Clause 17 (governing law), the SCCs are governed by the law of [●];
(f) for Clause 18 (forum and jurisdiction), disputes will be resolved before the courts of [●]; and
(g) Annexes 1, 2 and 3 of this Agreement populate, respectively, Annex I (description of the transfer), Annex II (technical and organisational measures) and Annex III (list of sub-processors) of the SCC Appendix; the competent supervisory authority is identified in accordance with Clause 13 based on the data exporter’s establishment.
A4.2 UK transfers. For transfers subject to the UK GDPR, the parties incorporate the EU SCCs as modified and completed by the UK Addendum (or, alternatively, the IDTA), with the tables of the UK Addendum completed by reference to this Agreement and its Annexes, and Part 1 details [●].
A4.3 Transfer impact. The parties will, where required, conduct and document a transfer impact assessment, taking into account the circumstances of the transfer, the destination (Australia) and the supplementary measures in Annex 2. PostMyDoc will assist the Customer with that assessment on reasonable request.
A4.4 Precedence. To the extent of any conflict between the incorporated SCCs (or UK Addendum/IDTA) and the rest of this Agreement in respect of a transfer to which they apply, the incorporated clauses prevail, consistently with clause 19.2.
End of Data Processing Agreement — PostMyDoc Business