1. Introduction
This Data Processing Agreement (“DPA”) forms part of the agreement between the customer (“Customer”, “Controller” or “you”) and AI Solution Technologies Pty Ltd (“AI Solution Technologies”, “Processor”, “we”, “us” or “our”) for the provision of services (the “Principal Agreement”). It applies where we process Personal Data on the Customer’s behalf in connection with the services. Where there is any conflict between this DPA and the Principal Agreement in relation to data protection, this DPA prevails.
2. Definitions
In this DPA, “Data Protection Laws” means all applicable laws relating to the processing of Personal Data, including the Privacy Act 1988 (Cth) and the Australian Privacy Principles, and, where applicable, the EU General Data Protection Regulation (“GDPR”) and UK GDPR. “Personal Data”, “Controller”, “Processor”, “Data Subject”, “process/processing” and “Sub-processor” have the meanings given in the applicable Data Protection Laws. Terms not defined here have the meaning given in the Principal Agreement.
3. Roles of the parties
The parties acknowledge that, in respect of the processing of Personal Data under the Principal Agreement, the Customer is the Controller and we are the Processor. Each party will comply with its obligations under the Data Protection Laws.
4. Scope and instructions
We will process Personal Data only on the documented instructions of the Customer, including as set out in this DPA and the Principal Agreement, unless required to do otherwise by law (in which case we will, where permitted, inform the Customer of that legal requirement before processing). The subject matter, duration, nature and purpose of the processing, the types of Personal Data and the categories of Data Subjects are described in Annex A.
5. Our obligations as Processor
We will:
- process Personal Data only for the purposes of providing the services and in accordance with the Customer’s instructions;
- ensure that persons authorised to process Personal Data are bound by appropriate confidentiality obligations;
- implement and maintain appropriate technical and organisational security measures as described in Annex B;
- assist the Customer, taking into account the nature of the processing, in responding to Data Subject requests and in meeting the Customer’s obligations regarding security, breach notification, data protection impact assessments and prior consultation;
- make available information reasonably necessary to demonstrate compliance with this DPA; and
- at the Customer’s choice, delete or return Personal Data at the end of the services, as described in clause 11.
6. Confidentiality
We will keep Personal Data confidential and will not disclose it except as permitted under this DPA or the Principal Agreement, or as required by law. We limit access to Personal Data to personnel who need it to perform the services.
7. Security
Taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of processing, as well as the risk to Data Subjects, we implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as further described in Annex B. Our information security management is aligned with ISO/IEC 27001 and ISO/IEC 42001.
8. Sub-processors
The Customer provides general authorisation for us to engage Sub-processors to support the services, including reputable cloud and technology providers such as Microsoft Azure and Amazon Web Services. We will impose data protection obligations on each Sub-processor that are no less protective than those in this DPA and remain responsible for their performance. We will inform the Customer of intended changes to Sub-processors and give the Customer the opportunity to object on reasonable data protection grounds.
9. Data Subject rights
Taking into account the nature of the processing, we will assist the Customer by appropriate technical and organisational measures, insofar as possible, to fulfil the Customer’s obligation to respond to requests by Data Subjects to exercise their rights. If we receive a request from a Data Subject directly, we will, where legally permitted, promptly notify the Customer and not respond except on the Customer’s instructions.
10. Data breach notification
We will notify the Customer without undue delay after becoming aware of a Personal Data breach affecting the Customer’s Personal Data, and will provide the Customer with information reasonably available to us to assist the Customer in meeting any obligations to notify supervisory authorities, the Office of the Australian Information Commissioner (under the Notifiable Data Breaches scheme) and/or affected individuals.
11. Return and deletion
On termination or expiry of the services, or on the Customer’s earlier written request, we will (at the Customer’s choice) delete or return all Personal Data and delete existing copies, unless retention is required by law. Where deletion is not immediately practicable (for example, data held in backups), we will securely isolate the Personal Data and protect it from further processing until deletion is possible.
12. International transfers
We may transfer and process Personal Data in locations outside Australia, and outside the EEA or the UK where the GDPR or UK GDPR applies, including in the United States, the United Arab Emirates and the Kingdom of Saudi Arabia. Where required by Data Protection Laws, we will implement an appropriate transfer mechanism, such as the European Commission’s Standard Contractual Clauses (and the UK Addendum where applicable), and will take reasonable steps to ensure overseas recipients handle the Personal Data consistently with the Australian Privacy Principles.
13. Audits
We will make available to the Customer information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor mandated by the Customer, subject to reasonable notice, confidentiality obligations, and no more than once per year (except where required following a Personal Data breach or by a regulator). The Customer bears its own costs of any audit.
14. Liability
Each party’s liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Principal Agreement. Nothing in this DPA limits any liability that cannot be limited under applicable law.
15. Governing law
This DPA is governed by the same law as the Principal Agreement or, where none is specified, the laws of New South Wales, Australia.
16. Effect
This DPA is effective from 1 January 2026 or the commencement date of the Principal Agreement, whichever is later, and continues for as long as we process Personal Data on the Customer’s behalf.
Annex A Details of processing
Item
Description
Subject matter
Provision of data engineering, analytics, business intelligence, artificial intelligence, cloud and related professional services under the Principal Agreement.
Duration
For the term of the Principal Agreement and any period during which we process Personal Data on the Customer’s behalf.
Nature and purpose
Collection, storage, structuring, analysis, hosting, transmission and other processing necessary to deliver the services.
Types of Personal Data
As determined by the Customer, which may include identity and contact details, employment and business data, and other data contained in the Customer’s systems and datasets. Special category data only where expressly agreed.
Categories of Data Subjects
As determined by the Customer, which may include the Customer’s employees, contractors, customers, suppliers and other individuals whose data is contained in the Customer’s systems.
Annex B Technical and organisational measures
We maintain technical and organisational measures appropriate to the risk, which include:
- access controls, including role-based access, least-privilege principles and multi-factor authentication;
- encryption of Personal Data in transit and, where appropriate, at rest;
- network security controls, including firewalls, monitoring and vulnerability management;
- secure development practices and change management;
- logical and, where applicable, physical separation of Customer environments;
- backup, business continuity and disaster recovery arrangements;
- personnel confidentiality obligations and security awareness training;
- vendor and Sub-processor risk management;
- logging, monitoring and incident response processes; and
- an information security governance framework aligned with ISO/IEC 27001 and ISO/IEC 42001.
Contact Us
For questions about this DPA or our data processing practices, please contact us using the details below.
AI Solution Technologies Pty Ltd
Attention: Privacy Officer
33 East Street, Granville, Sydney, NSW 2142, Australia
Email: info@aisolutiontechnologies.com
Phone: +61 466 558 862
Web: aisolutiontechnologies.com
