Privacy & data

Data Processing Agreement - Australia

Australia-focused data processing terms for Induct For Work customers.

Data Processing Agreement / DPA

This Data Processing Agreement (“DPA”) is entered into between Induct For Work Pty Ltd (ACN 164 860 986, ABN 49 164 860 986) of 1/1142 North Road, Oakleigh South VIC 3167, Australia (“Induct For Work”) and the customer entity that has entered into or accepted an agreement for the use of the Induct For Work Services (“Customer”).

Induct For Work and Customer are each a “Party” and together the “Parties”. This DPA forms part of and is subject to the master subscription agreement, terms of use, order form or other written or electronic agreement between Induct For Work and Customer governing Customer’s use of the Services (“Main Agreement”).

01

Definitions

1.1 Applicable Privacy Laws

“Applicable Privacy Laws” means the privacy and data-protection laws applicable to the handling of Customer Personal Information in connection with the Services including where applicable the Privacy Act 1988 (Cth), the Australian Privacy Principles (“APPs”), applicable State or Territory privacy legislation and other Australian laws regulating the handling, security or disclosure of personal or sensitive information.

1.2 Customer Personal Information

“Customer Personal Information” means personal information as defined under Applicable Privacy Laws that is provided to, uploaded to, collected through or otherwise processed by Induct For Work on behalf of Customer in connection with the Services.

1.3 Personal Information

“Personal Information” has the meaning given under the Privacy Act 1988 (Cth) where that Act applies.

1.4 Sensitive Information

“Sensitive Information” has the meaning given under the Privacy Act 1988 (Cth) and may include health information and other information classified as sensitive under Applicable Privacy Laws.

1.5 Services

“Services” means the cloud-based online induction, training, learning, compliance, workforce management, contractor management, visitor management and related services provided by Induct For Work under the Main Agreement.

1.6 Subprocessor

“Subprocessor” means a third party engaged by Induct For Work to process Customer Personal Information as reasonably necessary to provide, maintain, secure or support the Services.

02

Scope and Application

2.1 Application

This DPA applies whenever Induct For Work processes Customer Personal Information on behalf of Customer in connection with the Services.

2.2 Relationship of the Parties

Customer determines the purposes for which Customer Personal Information is collected and used through the Services. Induct For Work processes Customer Personal Information for the purpose of providing, maintaining, securing and supporting the Services and otherwise in accordance with the Main Agreement and this DPA.

2.3 Duration

This DPA remains in effect for as long as Induct For Work processes or retains Customer Personal Information in connection with the Services. Suspension, overdue payment, cancellation, expiry or termination of Customer’s account does not affect the application of this DPA while Induct For Work continues to retain or process Customer Personal Information. Commercial rights arising from overdue payment, suspension or termination remain governed by the Main Agreement.

03

Customer Instructions

3.1 Instructions

Induct For Work will process Customer Personal Information as reasonably necessary to provide the Services, operate Customer’s account, implement Customer’s configuration and workflows, provide technical or administrative support, maintain service availability and security, comply with lawful obligations and perform other processing authorised under the Main Agreement.

3.2 Platform Use as Instructions

Customer’s use and configuration of the Services, submission of Customer Personal Information, creation of forms or workflows and acceptance of the Main Agreement and this DPA constitute Customer’s instructions to Induct For Work.

3.3 Additional Instructions

Where Customer requests processing or services outside the ordinary scope of the Services, Induct For Work may require additional fees, terms, technical work or a separate written agreement before implementing the request.

3.4 Unlawful Instructions

If Induct For Work reasonably believes that an instruction issued by Customer would require Induct For Work to breach Applicable Privacy Laws or another legal obligation, Induct For Work may notify Customer, decline to implement the instruction or suspend implementation until the issue is resolved. Induct For Work is not required to carry out any instruction that would cause it to breach applicable law.

04

Obligations of Induct For Work

4.1 Compliance

Induct For Work will comply with the obligations that apply directly to it under Applicable Privacy Laws when handling Customer Personal Information.

4.2 Confidentiality

Induct For Work will take reasonable steps to ensure that personnel authorised to access Customer Personal Information are subject to appropriate confidentiality obligations. Access will be limited to personnel who reasonably require access in connection with the Services, support, security, maintenance or legal obligations.

4.3 Security Measures

Induct For Work will implement and maintain reasonable technical and organisational measures designed to protect Customer Personal Information against unauthorised access, unauthorised disclosure, misuse, interference, loss, alteration and destruction.

  • user access controls;
  • role-based permissions;
  • authentication controls;
  • encryption in transit and at rest;
  • network and infrastructure security controls;
  • logging and monitoring;
  • backup and recovery procedures;
  • secure software-development practices;
  • vulnerability management and security testing;
  • incident-response procedures; and
  • measures designed to maintain the confidentiality, integrity and availability of the Services.

Induct For Work may update its security measures from time to time as technology, risks and the Services evolve provided that the overall level of protection is not materially reduced.

05

Subprocessors

5.1 General Authorisation

Customer authorises Induct For Work to engage Subprocessors where reasonably necessary to provide, maintain, secure or support the Services.

5.2 Contractual Protection

Induct For Work will take reasonable steps to ensure that Subprocessors that process Customer Personal Information are subject to appropriate contractual obligations relating to privacy, confidentiality and security.

5.3 Responsibility

Induct For Work remains responsible for the performance of its Subprocessors to the extent required by Applicable Privacy Laws and subject to the limitations of liability contained in the Main Agreement.

5.4 Changes to Subprocessors

Induct For Work may appoint, remove or replace Subprocessors from time to time. Where reasonably required by Applicable Privacy Laws or an applicable contractual commitment, Induct For Work may provide Customer with information regarding material Subprocessors that process Customer Personal Information.

5.5 Customer Concerns

Where Customer raises a reasonable privacy or security concern regarding a Subprocessor, Induct For Work may consider the concern in good faith. A concern or objection does not provide Customer with any right to inspect, audit or obtain direct access to Induct For Work or the relevant Subprocessor unless such right has been expressly agreed under a separate Service Level Agreement or other written agreement signed by Induct For Work.

06

Customer Responsibilities

6.1 Lawful Collection and Use

Customer is responsible for ensuring that it has lawful authority to collect and use Customer Personal Information, appropriate privacy notices are provided, any required consents or authorisations are obtained, Customer’s use of the Services complies with Applicable Privacy Laws and Customer’s instructions to Induct For Work are lawful.

6.2 Data Accuracy and Minimisation

Customer is responsible for the accuracy, quality and relevance of Customer Personal Information, ensuring that information submitted to the Services is reasonably necessary for Customer’s purposes and avoiding the collection of unnecessary Personal Information.

6.3 User Access

Customer is responsible for creating and managing authorised user accounts, allocating user permissions, removing access when it is no longer required, protecting account credentials and maintaining appropriate internal access policies.

6.4 Sensitive Information

Customer acknowledges that depending on its configuration and use of the Services, Customer Personal Information may include Sensitive Information including health information. Customer determines whether Sensitive Information is collected through the Services and is responsible for ensuring that any such collection, use and disclosure is lawful.

07

Overseas Processing and Disclosure

7.1 Locations

Customer acknowledges that Customer Personal Information may be processed or stored in Australia or in other locations used by Induct For Work or its authorised Subprocessors.

7.2 Overseas Disclosures

Where Customer Personal Information is disclosed to an overseas recipient and Applicable Privacy Laws impose requirements on that disclosure, Induct For Work will take reasonable steps to address those requirements. Such steps may include contractual privacy obligations, confidentiality requirements, security requirements, restrictions on permitted processing, appropriate technical safeguards and other measures reasonably appropriate to the circumstances.

7.3 Information Requests

Upon reasonable written request, Induct For Work may provide Customer with available information about material locations in which Customer Personal Information is processed where that information is reasonably necessary for Customer to satisfy its obligations under Applicable Privacy Laws. Customised reports, assessments or questionnaires requiring substantial work may be subject to reasonable additional charges and may also be restricted by Customer’s subscription level under Section 10.

08

Data Breaches

8.1 Notification

Where Induct For Work becomes aware of an eligible or suspected data breach involving Customer Personal Information that requires Customer involvement under Applicable Privacy Laws, Induct For Work will notify Customer without undue delay.

8.2 Information Provided

To the extent information is reasonably available, notification may include the nature of the incident, categories of information affected, approximate number of persons or records affected, known or likely consequences, measures taken or proposed to contain the incident and measures taken or proposed to reduce potential harm. Information may be provided progressively where the investigation is continuing.

8.3 Cooperation

Induct For Work will provide reasonable cooperation to Customer where required for Customer to assess or respond to an incident affecting Customer Personal Information.

8.4 No Admission

Notification of an actual or suspected data breach does not constitute an acknowledgement of fault, wrongdoing or liability by Induct For Work.

09

Privacy Requests

9.1 Requests Received by Induct For Work

Where Induct For Work receives a request from an individual concerning Customer Personal Information that is primarily controlled by Customer, Induct For Work may direct the individual to Customer, notify Customer of the request or take another reasonable step appropriate to the circumstances.

9.2 Assistance

Where Customer cannot reasonably respond to a privacy request through the functionality available within the Services, Induct For Work may provide reasonable assistance. Where assistance requires more than minimal administrative or technical effort, Induct For Work may charge its then-current professional services or account-management rates where permitted by law.

10

Audit and Compliance Information

10.1 Compliance Information

Customers subscribed to an Ultra Plus annual subscription or any successor annual subscription plan expressly designated by Induct For Work as including equivalent compliance-support benefits may request reasonable non-public compliance information relating to the privacy and security of Customer Personal Information.

Subject to availability, confidentiality requirements, security considerations and reasonable scope, such information may include selected security documentation, privacy and security questionnaires, selected policies, available certifications, available independent reports or other compliance information that Induct For Work considers appropriate. Induct For Work determines the format, level of detail and method by which such information is provided.

Customers who do not hold an eligible subscription are not entitled to customised compliance documentation, completed security questionnaires, internal policies, non-public reports or other non-public compliance information unless Induct For Work expressly agrees otherwise in writing.

All customers may access Induct For Work’s publicly available privacy, data-security, Terms and legal information through the Induct For Work Legal Centre.

Nothing in this clause requires Induct For Work to disclose confidential, security-sensitive, commercially sensitive or legally privileged information or information concerning another customer. Nothing in this clause restricts information that Induct For Work is legally required to provide.

10.2 No General Customer Audit Right

Except where expressly agreed under a separate Service Level Agreement or other written agreement signed by Induct For Work, Customer has no contractual right to conduct, commission or require an audit, inspection, penetration test, vulnerability assessment or physical or remote inspection of Induct For Work’s systems, infrastructure, premises, personnel, records or security controls. An Ultra Plus annual subscription does not itself create any audit right.

10.3 SLA Audit Rights

Where Customer has been expressly granted audit rights under a separate Service Level Agreement or other written agreement signed by Induct For Work, any audit must be conducted strictly in accordance with that agreement including any agreed scope, notice requirements, frequency limitations, confidentiality obligations, security restrictions, access restrictions and cost provisions. Induct For Work may refuse activity outside the expressly agreed scope or activity that could reasonably compromise the confidentiality, security, availability or integrity of the Services or information relating to another customer.

10.4 Regulators

Nothing in this DPA prevents Induct For Work from complying with a lawful investigation, information request, direction or inspection from an Australian regulator, court, government authority or other body where Induct For Work is legally required to comply.

11

Return and Deletion of Data

11.1 Customer Responsibility

Customer is responsible for exporting or downloading any Customer Personal Information it wishes to retain before authorised access to the Services ends. Induct For Work will provide Customer with the export or download functionality ordinarily available through the Services while Customer continues to have authorised access to the account. Customer should complete any required export before cancelling its account or allowing its subscription to expire.

11.2 Following Termination

Following termination, cancellation or expiry of the Main Agreement, Induct For Work may delete, destroy or irreversibly anonymise Customer Personal Information in accordance with the Main Agreement and Induct For Work’s ordinary retention and deletion procedures. Customer acknowledges that active account information may be deleted within the timeframes specified in the Main Agreement including, where applicable, within approximately 24–48 hours after authorised account access ends. Different retention periods may apply to backups, archives, disaster-recovery systems and information that Induct For Work is required or permitted by law to retain. Customer Personal Information retained after termination will continue to be protected under this DPA until it is deleted, anonymised or otherwise no longer constitutes Customer Personal Information.

11.3 Backups

Customer Personal Information may remain within routine backups, archives or disaster-recovery systems for a limited period after deletion from active systems. While such information remains retained, Induct For Work will continue to protect it in accordance with this DPA.

11.4 Confirmation

Where reasonably required under Applicable Privacy Laws, Customer may request written confirmation that Customer Personal Information has been deleted or anonymised. Induct For Work is not required to provide forensic verification, infrastructure access, backup-system access or system-level inspection rights unless expressly agreed under a separate Service Level Agreement.

12

Records and Compliance Assistance

12.1 Records

Induct For Work will maintain such records relating to its handling of Customer Personal Information as may be reasonably required under Applicable Privacy Laws.

12.2 Compliance Assistance

Taking into account the nature of the Services and information available to Induct For Work, Induct For Work may provide reasonable assistance to Customer regarding privacy compliance, security incidents, privacy impact assessments, regulatory enquiries and information reasonably necessary to demonstrate Induct For Work’s compliance with obligations directly applicable to it. Access to non-public compliance information under this clause is subject to Section 10.1. Customers who are not subscribed to an eligible annual subscription should use publicly available information within the Induct For Work Legal Centre as their primary privacy and security information resource. Assistance requiring substantial time, specialist resources, customised responses or additional documentation may be subject to reasonable additional charges where permitted by law.

13

Liability and Indemnity

13.1 Limitations of Liability

The limitations, exclusions, disclaimers, remedies and aggregate liability cap contained in the Main Agreement apply to this DPA and to all claims arising out of or relating to Customer Personal Information to the maximum extent permitted by law. For clarity, liability arising under this DPA does not create a separate liability cap and is aggregated with liability arising under the Main Agreement for the purpose of calculating the maximum liability of Induct For Work. Nothing in this DPA excludes or limits liability that cannot lawfully be excluded or limited.

13.2 Responsibility

Each Party is responsible for loss or damage arising from its own failure to comply with this DPA or Applicable Privacy Laws that apply directly to that Party.

13.3 Indemnities

Any indemnity obligations arising in relation to this DPA are subject to and governed by the indemnity provisions contained in the Main Agreement.

14

Priority

14.1 Order of Precedence

If there is an inconsistency between this DPA and the Main Agreement, this DPA prevails only to the extent of the inconsistency and only in relation to the handling and protection of Customer Personal Information. The Main Agreement prevails in relation to fees, account access, suspension, cancellation, deletion timing, intellectual property, indemnities, limitation of liability and other commercial matters unless this DPA expressly states otherwise.

15

Amendments

15.1 Legal or Service Changes

Induct For Work may update this DPA where reasonably necessary to reflect changes to Applicable Privacy Laws, regulatory guidance, changes to the Services, security practices, Subprocessors, infrastructure or Induct For Work’s privacy and data-handling practices. Updates will take effect in accordance with the amendment provisions contained in the Main Agreement.

16

Term and Termination

16.1 Term

This DPA commences when Customer first accepts or becomes bound by the Main Agreement. It continues for as long as Induct For Work processes or retains Customer Personal Information in connection with the Services.

16.2 Effect of Termination

Termination, cancellation, expiry or suspension of the Main Agreement does not terminate provisions of this DPA that must continue while Induct For Work retains Customer Personal Information. Clauses concerning confidentiality, security, data breaches, deletion, liability and other provisions that by their nature are intended to continue will survive termination.

17

Governing Law and Jurisdiction

This DPA is governed by the laws of Victoria, Australia. The parties submit to the non-exclusive jurisdiction of the courts of Victoria and the Federal Court of Australia and any courts entitled to hear appeals from those courts.

18

Execution and Acceptance

This DPA forms part of the Main Agreement and may be accepted through the Main Agreement, through an online process or by Customer execution of this DPA. Electronic acceptance has the same effect as written execution to the extent permitted by applicable law.

S1

Schedule 1 - Details of Processing

Subject Matter

Processing of Customer Personal Information as reasonably necessary to provide, maintain, secure and support the INDUCT FOR WORK Services.

Duration

For the duration of the Main Agreement and any subsequent period during which Induct For Work legitimately retains or processes Customer Personal Information.

Nature and Purpose

Processing may include collection, hosting, storage, organisation, retrieval, transmission, display, reporting, backup, analysis, support, deletion and other processing reasonably necessary to provide the Services. The Services may include online inductions, online training, assessments and quizzes, learning management, contractor management, workforce management, visitor management, site-access management, electronic forms, electronic signatures, incident reporting, hazard reporting, safety communications and related administration and reporting.

Categories of Individuals

Customer Personal Information may relate to employees, contractors, subcontractors, labour-hire workers, volunteers, visitors, suppliers, administrators, supervisors, trainees and other persons authorised or required by Customer to interact with the Services.

Types of Personal Information

Customer Personal Information may include names, usernames, identification numbers, signatures, email addresses, telephone numbers, addresses, employment information, position and role information, department information, supervisor information, site and location information, induction records, training records, course enrolments, completion records, quiz and assessment results, acknowledgements, licences, permits, qualifications, site-entry and exit records, timestamps, IP addresses, device information, browser information, technical logs, incident information, hazard information and other information submitted or configured by Customer through the Services.

Sensitive Information

Depending on Customer’s configuration and use of the Services, Customer Personal Information may include health information or other Sensitive Information. Customer determines whether such information is collected and is responsible for ensuring that it has lawful authority to collect, use and disclose that information.

S2

Schedule 2 - Technical and Organisational Security Measures

Induct For Work maintains reasonable technical and organisational security measures appropriate to the nature of the Services and the risks associated with Customer Personal Information. Measures may include access controls, role-based permissions, authentication controls, encryption, network security, infrastructure security, system logging, security monitoring, backup procedures, recovery procedures, secure software-development practices, vulnerability management, security testing, incident-response procedures, confidentiality obligations, administrative access controls and business-continuity and disaster-recovery measures.

Security measures may evolve over time as technologies, threats and the Services change provided that Induct For Work does not materially reduce the overall level of protection afforded to Customer Personal Information. Information contained within this Schedule does not give Customer any right to inspect, test or obtain access to Induct For Work systems or security controls.

S3

Schedule 3 - Subprocessors

Induct For Work may maintain a list of material Subprocessors used in connection with the Services. The list may include Subprocessor name, service provided, nature of processing and primary processing location where appropriate. The Subprocessor list may be maintained separately from this DPA and updated from time to time without requiring this DPA to be re-executed. The inclusion of a Subprocessor in such a list does not create a direct contractual relationship between Customer and the Subprocessor.