Data Processing Agreement

Last Updated: February 2026

1. Introduction

This Data Processing Agreement ("DPA") forms part of the Master Service Agreement or Terms of Service (the "Agreement") between InvestigatePro Pty Ltd ("Processor", "we", "us") and the customer entity identified in the Agreement ("Controller", "you", "Customer").

This DPA sets out the terms that apply when we process Personal Data on your behalf in connection with the InvestigatePro platform and services.

2. Definitions

"Applicable Data Protection Laws" means all data protection and privacy laws applicable to the processing of Personal Data, including GDPR (EU), Australian Privacy Act 1988, CCPA (California), and any other applicable privacy legislation.

"Data Subject" means an identified or identifiable natural person whose Personal Data is processed.

"Personal Data" means any information relating to a Data Subject that is processed by the Processor on behalf of the Controller in connection with the Services.

"Processing" means any operation performed on Personal Data, including collection, storage, use, disclosure, and deletion.

"Security Incident" means any accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data.

"Sub-processor" means any third party engaged by the Processor to process Personal Data on behalf of the Controller.

3. Scope and Roles

3.1 Data Processing Relationship

  • Controller: You determine the purposes and means of processing Personal Data
  • Processor: We process Personal Data only on your documented instructions

3.2 Categories of Data Subjects

Personal Data processed may relate to: your employees and contractors, witnesses to incidents, injured persons, investigation team members, and other individuals referenced in incident reports.

3.3 Types of Personal Data

  • Contact information (names, email addresses, phone numbers)
  • Employment information (job titles, departments, employee IDs)
  • Incident-related data (witness statements, injury details, photographs)
  • Investigation records (interview notes, analysis, recommendations)
  • System usage data (login times, actions taken)

4. Processor Obligations

4.1 Security Measures

We implement appropriate technical and organizational measures including:

Technical Controls

  • TLS 1.3 encryption for data in transit
  • AES-256 encryption for data at rest
  • Multi-factor authentication (MFA) capability
  • Role-based access control (RBAC)
  • Regular security testing and vulnerability assessments

Organizational Controls

  • Security awareness training for staff
  • Access reviews and audits
  • Incident response procedures
  • Business continuity planning

4.2 Data Subject Rights

We assist you in responding to Data Subject requests for:

  • Access to Personal Data (GDPR Article 15)
  • Rectification (GDPR Article 16)
  • Erasure / Right to be Forgotten (GDPR Article 17)
  • Data portability (GDPR Article 20)
  • Restriction of processing (GDPR Article 18)

4.3 Security Incidents

  • Notify you of any Security Incident without undue delay (within 72 hours)
  • Provide information necessary for breach notification obligations
  • Take reasonable steps to mitigate the effects

5. International Transfers

5.1 Data Location

Personal Data is primarily stored in Australia (primary data center) and United States (backup/disaster recovery).

5.2 Transfer Mechanisms

For transfers to countries without adequacy decisions, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission, plus additional safeguards including encryption and access controls.

6. Sub-processors

We use the following Sub-processors:

Sub-processor Purpose Location
Amazon Web Services Cloud hosting, storage Australia, US
Anthropic AI analysis (no PII sent) US
Stripe Payment processing US, EU
Resend Email delivery US

Questions About This DPA?

For enterprise customers requiring a signed DPA or with questions about our data processing practices:

Email: [email protected]

Enterprise customers on the Business tier receive a countersigned DPA as part of their onboarding.

Related Documents