Data processing addendum
How we handle personal information our customers store in our products.
Version 1.0 · Last updated · Zhon1 Tech Pty Ltd
This Data Processing Addendum ("DPA") forms part of the Customer Agreement between Zhon1 Tech Pty Ltd (ACN 700 514 478) ("Zhon1", "we") and the Customer. It applies when Customer Data includes personal information (as defined in the Privacy Act 1988 (Cth)) about the Customer's own customers, staff or contacts ("Customer Personal Information").
1. Roles
The Customer decides what Customer Personal Information is collected and why. Zhon1 handles it only as the Customer's service provider, to provide the Service.
2. What we will do
2.1 Use only on your instructions. We will handle Customer Personal Information only to provide, secure, support and maintain the Service, or as required by law.
2.2 No other use. We will not sell it, use it for our own marketing, or use it to contact your customers.
2.3 Security. We will protect it with reasonable technical and organisational measures, including encryption in transit and at rest, per-customer data isolation (row-level security), least-privilege access, and audit logging.
2.4 Staff. Only people who need access to do their job will have it, and they are bound by confidentiality.
2.5 Sub-processors. We use the sub-processors listed in section 5. We will give the Account Owner at least 30 days' notice by email before adding or replacing a sub-processor that will handle Customer Personal Information. If you reasonably object, you may end your subscription and receive a pro-rata refund of fees for the unused part of the Subscription Period.
2.6 Overseas. Customer Personal Information is stored in Sydney, Australia. Some sub-processors may access or process it overseas as listed in section 5. We will take reasonable steps so they handle it consistently with the Australian Privacy Principles.
2.7 Data breaches. If we become aware of unauthorised access to, or loss of, Customer Personal Information, we will notify the Account Owner without undue delay and within 72 hours, with the information reasonably available, so you can assess the breach under the Notifiable Data Breaches scheme. We will help you investigate and respond.
2.8 Requests from individuals. If an individual asks us to access or correct their information held in your account, we will refer them to you and help you respond.
2.9 End of service. When your subscription ends, we will make Customer Data available for export for 60 days and then delete it from our active systems, unless the law requires us to keep it.
3. What you will do
The Customer is responsible for collecting Customer Personal Information lawfully, giving the individuals any required privacy notices, and not entering sensitive information (such as health information) into the Service.
4. Audit
On reasonable request (no more than once a year), we will answer written security questionnaires about how we protect Customer Personal Information.
5. Sub-processors
| Sub-processor | Purpose | Location of processing |
|---|---|---|
| Supabase Inc. | Database, authentication, file storage | Stored in Sydney, Australia (AWS ap-southeast-2); support access from the United States and other countries |
| Vercel Inc. | Application hosting and server functions | United States and other countries |
| Stripe (Stripe Payments Australia Pty Ltd and affiliates) | Billing (Customer and User billing details only, not your customers' data) | Australia, United States and other countries |
We will update this list (and notify you under clause 2.5) before any new sub-processor handles Customer Personal Information.