This Data Processing Agreement (“DPA”) forms part of the agreement between the entity identified in the Subscription (“Customer”) and FinEase Pty Ltd (ABN 70 688 255 941) (“Processor”) for the processing of Personal Information in connection with the FinEase platform (“Service”).
1. Definitions
- “Personal Information” has the meaning given in the Privacy Act 1988 (Cth).
- “Processing” means any operation performed on Personal Information, including collection, storage, use, modification, disclosure, and deletion.
- “Data Subject” means the individual to whom the Personal Information relates (your customers experiencing financial hardship).
- “Sub-processor” means any third party engaged by us to process Personal Information on your behalf.
- “APPs” means the Australian Privacy Principles under Schedule 1 of the Privacy Act 1988 (Cth).
2. Scope and Roles
You are the entity that determines the purposes and means of processing Personal Information (“APP entity”). We process Personal Information solely on your behalf and in accordance with your instructions as set out in this DPA.
2.1 Categories of Data Subjects
- Your customers who have submitted or are subject to financial hardship applications;
- Your employees and authorised users of the Service.
2.2 Types of Personal Information
- Identity information (name, date of birth, contact details);
- Financial information (income, expenses, debts, bank statements, account details);
- Hardship application details (circumstances, supporting documents);
- Communication records (emails, notes, letters).
3. Our Obligations
We will:
- Process Personal Information only on your documented instructions, unless required by law;
- Ensure persons authorised to process Personal Information have committed to confidentiality obligations;
- Implement appropriate technical and organisational security measures;
- Not engage Sub-processors without your prior written consent;
- Assist you in responding to Data Subject access or correction requests (APP 12, APP 13);
- Assist you in meeting obligations related to Notifiable Data Breaches (Part IIIC);
- Delete or return all Personal Information upon termination, at your choice;
- Make available all information necessary to demonstrate compliance with this DPA.
4. Security Measures
We implement the following technical and organisational measures:
- Encryption in transit (TLS 1.2+) and at rest (AES-256);
- Role-based access control with least-privilege defaults;
- Multi-factor authentication;
- Comprehensive audit logging with 7-year retention;
- Session security controls including idle timeouts;
- Regular security assessments and dependency auditing;
- Australian data residency (Vultr, Sydney).
5. Sub-processors
We currently use the following sub-processors:
- Vultr (Sydney): Primary infrastructure hosting;
- Cloudflare: DDoS protection and WAF (no Customer Data stored);
- Transactional email provider: For system-generated emails (notifications, password resets).
We will notify you of any changes to Sub-processors at least 14 days before the change takes effect.
6. Data Breach Notification
In the event of a suspected or confirmed Notifiable Data Breach:
- We will notify you within 72 hours of becoming aware;
- We will provide details of the nature of the breach, categories of data affected, and steps taken;
- We will assist you in meeting your notification obligations under Part IIIC of the Privacy Act.
7. Data Retention and Deletion
Upon termination:
- Customer Data will be available for export for 30 days;
- After 30 days, all Customer Data will be permanently deleted from active systems;
- Audit logs required by law (NCC record-keeping obligations) will be retained for 7 years.
8. Audit Rights
You may request confirmation that we are processing Personal Information in accordance with this DPA. For Enterprise customers, we will facilitate a security audit no more than once per year with 30 days’ notice.
9. Contact
- Email: privacy@financialease.com.au