Legal
Data Processing Agreement
How we handle personal information on behalf of our clients.
Last updated: 2 August 2026
01What this agreement covers
This Data Processing Agreement ("DPA") applies where Azoria (ABN 31 573 683 285) handles personal information on your behalf in the course of providing a service to you. It forms part of our Terms of Service and applies automatically to every client whose service involves us handling personal information – you do not need to sign a separate copy, though we will sign one on request.
It covers services including website hosting, Azoria Leads (our enquiry system), email handling, AI agent services, and business automation. It does not cover information we collect for our own purposes as a business – billing you, corresponding with you, meeting our own records obligations. Our Privacy Policy covers that.
Where a signed agreement between us says something different about a matter in this DPA, the signed agreement takes precedence for that matter.
02Who is responsible for what
You decide what personal information is collected through your services, why it is collected, how long it is kept, and who it is disclosed to. You are the entity accountable to the individuals concerned, and you are responsible for having a privacy policy and collection notices that accurately describe what happens to their information.
We hold and handle that information to operate the service for you. We do not decide what it is used for. Where we suggest wording for your privacy policy or your contact forms, we do so as a convenience – the obligation to have accurate notices remains yours, and you should have them reviewed.
Australian privacy law does not divide parties into 'controllers' and 'processors' the way some overseas regimes do. This agreement uses plain terms deliberately. If you need a GDPR-form DPA because you handle information about people in the EU or UK, tell us and we will put one in place instead of this one.
03We handle it only for you
We handle personal information you entrust to us only to provide and support the service, to keep it secure and available, and where we are required to by law. We handle it on your instructions, and the agreement between us constitutes those instructions unless you give us others in writing.
We do not use it for our own purposes. Specifically: we do not sell it, we do not disclose it to anyone except the sub-processors listed in section 06 or where the law compels us, we do not use it to market to the individuals concerned, and we do not use one client's information for the benefit of another client or to build our own datasets or products.
If we are ever compelled by law to disclose your information, we will tell you before we do so unless we are legally prohibited from telling you, in which case we will tell you as soon as we are permitted.
04AI agents and what you put into them
Where we run AI agents or automation for you, personal information in those workflows is handled under the same restrictions as everything else in this agreement. It is used to perform the task you have configured, and for nothing else. The agents themselves run on our own servers in Australia.
We do not use your information, your customers' information, or your business content to train, fine-tune, or evaluate any machine learning model of our own.
Language model requests are the exception to staying on our infrastructure. They are routed through OpenRouter to whichever model provider is configured for your agent, which means the content of a prompt leaves our servers and may be handled overseas. Each model's data-handling terms – how long a provider retains a request, and whether it may train on it – are set by that provider and published in OpenRouter's model registry at openrouter.ai/models. We select models with data policies appropriate to the workflow and will tell you which ones your agent uses, but we do not control those providers' terms and we cannot vary them.
This is why what goes into an agent matters. You decide what your agent is given and what your customers can put into it. You are responsible for that content, and we are not responsible for the consequences of sensitive information being fed into a model – by you, by your staff, or by your customers through an interface you have deployed.
Do not put information into an AI workflow that would cause serious harm if it were retained or disclosed – health records, financial account details, government identifiers, credentials, or anything you hold under a confidentiality obligation to someone else – unless we have specifically designed the workflow for it and agreed that in writing. If you need a workflow that handles that kind of information, tell us before it goes live and we will build it differently, using models and routing chosen for it.
Automated output can be confidently wrong. Where an agent drafts something that reaches your customers or is filed in your systems, reviewing that output is your responsibility, as set out in our Terms of Service.
05Security and our people
We take reasonable technical and organisational steps to protect personal information from misuse, interference, loss, and unauthorised access, modification, or disclosure. These include encryption in transit, access controls and separate credentials per system, restricting production access to those who need it, keeping systems patched, and taking routine backups.
Access to your information is limited to the people who need it to deliver or support your service. They are bound by confidentiality obligations that survive the end of their engagement with us.
No security measure is absolute, and we do not represent that our services cannot be compromised. What we commit to is proportionate care and honest, prompt notification when something goes wrong.
06Sub-processors and where your data is held
We use third-party providers to deliver our services – infrastructure, content delivery, payment processing, and similar. They are listed, with what each one does and the country it operates from, on our Sub-processors page at azoria.com.au/subprocessors. That page is the current list, and we maintain it as the single source of truth rather than restating it in each client's documents.
Some of those providers are located outside Australia. Azoria Leads is hosted on infrastructure in Singapore, behind a content delivery network operated from the United States. AI agents run on our own servers in Australia, but the model requests they make are routed overseas as described in section 04. cPanel hosting and our email are provided from Australia. Engaging a service that involves an overseas provider means personal information in it is handled overseas, and your own privacy policy needs to say so – we provide standard wording for this that names the countries.
We require sub-processors to protect information to a standard consistent with this agreement, and we remain responsible to you for what they do with it. We will give you reasonable notice before adding a sub-processor that handles personal information in a materially new way, and if you reasonably object, we will work with you on an alternative or you may terminate the affected service without penalty.
07If there is a data breach
If we become aware of unauthorised access to, disclosure of, or loss of personal information we hold for you, we will notify you without undue delay and in any event within 48 hours of becoming aware of it. We will tell you what we know, what information is affected, what we are doing about it, and what we recommend you do.
Under the Notifiable Data Breaches scheme, where a breach is likely to result in serious harm, the obligation to assess it and notify affected individuals and the Office of the Australian Information Commissioner generally sits with you, as the entity accountable to those individuals. We will give you the information and assistance you reasonably need to meet that obligation and to make that assessment within the statutory timeframe.
We will not notify affected individuals on your behalf unless you ask us to in writing, so that you keep control of what your customers are told.
08Requests from individuals
If an individual asks us directly for access to their information, or to correct or delete it, we will not act on it ourselves. We will refer them to you and let you know, because you are the one who decides. The exception is the deletion link in the enquiry receipt email, which you have already authorised by using Azoria Leads: an enquirer who clicks it deletes their own enquiry, and the enquiry is removed from your inbox as a result.
Where you need to respond to an access, correction, or deletion request, we will give you the information we hold and carry out deletions you direct, at no charge, within a reasonable time.
09Getting your data back, and deletion
Your data is yours. At any time during your service you can ask us for an export of the personal information we hold for you in a common machine-readable format, and we will provide it within a reasonable time.
When a service ends, we will return or delete the personal information we hold for it, at your election, within 30 days of the service ending – except where we are required to retain it by law. Tell us which you want before the service ends; if you tell us nothing, we will retain it for 30 days and then delete it.
Where a service is terminated for non-payment, the 30-day suspension period described in our Payment Terms is that window. The data is retained throughout it, you can ask for an export at any point during it, and it is deleted on termination rather than 30 days afterwards.
Backups are deleted on their normal rotation rather than individually edited. Information in a backup remains subject to this agreement until that rotation removes it, and we will not restore deleted information from a backup except to recover the service as a whole.
10Checking that we are doing this
You may ask us, once in any twelve-month period, for information reasonably necessary to confirm we are meeting our obligations under this agreement, and we will respond within a reasonable time. Where you are subject to a regulatory requirement to audit your providers, we will co-operate with a reasonable audit scope agreed between us in advance.
We will not disclose another client's information, our credentials, or security details in a way that would itself create a risk.
11Term, changes, and contact
This agreement applies for as long as we hold personal information for you, and the obligations that protect that information survive the end of your service until the information is returned or deleted.
We may update this agreement. Where a change materially reduces the protections it gives you, we will notify active clients before it takes effect, and the current version will always be published on this page. This agreement is governed by the laws of Western Australia.
Questions, requests, and breach notifications can be sent to [email protected].