Data Processing Agreement
Version: 1.0 · Effective date: 29 July 2026
This DPA forms part of the OpsFlow Terms of Service. It is designed to be given to your NDIS auditor, your board, or your privacy officer as evidence of how participant information is handled in OpsFlow. You do not need to sign it separately — it applies automatically when you accept the Terms. If your organisation requires a signed copy, email hello@opsflow.net.au and we will provide one.
1. Parties and roles
1.1 This DPA is between James Stephen Maximos (ABN 16 961 953 494) trading as OpsFlow (we, us) and the Customer (you).
1.2 Your role. You determine what Personal Information is collected in the platform, from whom, for what purpose, who within your organisation may access it, and how long it is kept. Under the Privacy Act 1988 (Cth) you are the APP entity accountable to the individuals concerned.
1.3 Our role. We hold and handle that Personal Information solely on your behalf and on your documented instructions, in order to provide the platform. We do not determine the purposes for which it is used.
1.4 Your instructions. Your instructions to us are: (a) these Terms and this DPA; (b) the configuration choices you make in the platform; and (c) any additional written instruction we agree to in writing.
1.5 If we consider an instruction would cause us to breach a law, we will tell you promptly and are not obliged to follow it.
2. Scope of processing
| Item | Detail |
|---|---|
| Subject matter | Provision of the OpsFlow platform |
| Duration | For the term of your subscription, plus the retention periods in clause 10 |
| Nature and purpose | Hosting, storage, retrieval, structuring, transmission, backup, display, deletion and support of Customer Data, and delivery of communications you initiate |
| Categories of individuals | NDIS participants; family members, guardians and nominees; support workers and other staff; referrers and referral sources; contractors; your customers’ contacts |
| Categories of Personal Information | Identity and contact details; NDIS numbers and plan details; health information (sensitive information) including diagnoses, support needs, behaviour support and incident material; worker screening clearances, qualifications and expiry dates; employment details; documents and signed agreements; SMS and email content; call metadata and call recordings; system audit records |
| Sensitive information | Yes — the platform is expected to hold health information within the meaning of s 6FA of the Privacy Act |
3. Our obligations
We will:
(a) handle Customer Data only for the purposes of providing the platform and only in accordance with your instructions; (b) handle Customer Data in a manner consistent with the Australian Privacy Principles; (c) implement and maintain the security measures in Schedule A; (d) ensure our personnel who access Customer Data are subject to confidentiality obligations and are trained appropriately; (e) limit access to Customer Data to personnel who need it to perform their role, and log that access; (f) assist you, at your cost where the assistance is substantial, to respond to requests from individuals for access to or correction of their information; (g) assist you to meet your obligations under the Notifiable Data Breaches scheme; (h) notify you of a data breach in accordance with clause 8; and (i) return or delete Customer Data in accordance with clause 10.
We will not:
- sell, rent or trade Customer Data;
- use Customer Data for advertising or marketing;
- use Customer Data to train any artificial intelligence or machine learning model;
- disclose Customer Data to any third party except as permitted in clause 6 or required by law; or
- use Customer Data to develop products for third parties.
4. Aggregated and de-identified data
4.1 We may generate aggregated statistics about platform usage across all customers (for example, total referrals processed, median response time, feature adoption).
4.2 Aggregated data:
- must not identify you, any individual, or permit re-identification;
- must not be derived from the content of health information, documents, call recordings, SMS content or email content; and
- is limited to structural and operational metadata (counts, timings, statuses, feature usage).
5. Your obligations
You must:
(a) ensure you have a lawful basis to collect the Personal Information you put into the platform, and that you have given the notices required by APP 5; (b) obtain consent where required, including for the collection of sensitive information and health information (APP 3.3), and for the recording of calls; (c) configure roles, permissions, recording settings and retention appropriately for your organisation; (d) keep your user list current and remove departed staff promptly; (e) not put Personal Information into the platform that you have no lawful reason to hold; and (f) meet your own obligations under the Privacy Act 1988 (Cth), applicable State and Territory health records legislation, the NDIS Practice Standards, and the NDIS Code of Conduct.
6. Sub-processors
6.1 You authorise us to engage sub-processors to provide the platform.
6.2 The current list of sub-processors, including what each handles and where it processes data, is at opsflow.net.au/subprocessors and is reproduced in Schedule B.
6.3 We will: (a) impose data protection obligations on each sub-processor that are substantially equivalent to those in this DPA; and (b) remain responsible to you for the acts and omissions of our sub-processors as if they were our own.
6.4 Notice of change. We will give you at least 30 days’ notice before adding or replacing a sub-processor that handles Customer Data. You may subscribe to change notices at privacy@opsflow.net.au.
6.5 Objection. If you reasonably object to a new sub-processor on data protection grounds, tell us within the notice period. We will work with you in good faith to find an alternative. If we cannot, you may terminate the affected part of the service, or the subscription, without penalty and receive a pro-rata refund of prepaid Fees.
7. Cross-border disclosure ⚠️
7.1 The core platform is hosted in Australia. The database, file storage, documents and application backend are hosted in AWS Sydney (ap-southeast-2). Voice calls and call recordings are handled in Twilio’s Australian region (AU1, Sydney).
7.2 Some processing occurs outside Australia. Specifically:
| Service | What leaves Australia | Where |
|---|---|---|
| Resend | Email content and recipient addresses for messages sent from the platform | United States |
| Twilio (Messaging) | SMS message content and recipient numbers | Outside Australia — see 7.3 |
| Stripe | Billing contact and payment data (not participant data) | Outside Australia |
| Vercel | Web request metadata (IP address, user agent, URL paths) | Global edge network |
| Sentry (if enabled) | Error diagnostics, with payloads scrubbed before transmission | Outside Australia |
| Apple / Google push | Content-free push notifications — no personal information in the payload | Outside Australia |
7.3 ⚠️ SMS content does not stay in Australia. Twilio’s Australian region supports voice, but message content is processed through infrastructure outside Australia. If Australian-only processing of message content is a requirement for your organisation, do not enable SMS features. We will tell you if this position changes.
7.4 Before disclosing Personal Information to an overseas recipient we take such steps as are reasonable in the circumstances to ensure the recipient does not breach the APPs, consistent with APP 8. We remain accountable under section 16C of the Privacy Act for the handling of that information by overseas recipients.
7.5 We will not add a new offshore sub-processor that handles participant health information, message content or documents without giving notice under clause 6.4.
8. Data breach notification
8.1 If we become aware of unauthorised access to, unauthorised disclosure of, or loss of Customer Data, we will: (a) notify you without undue delay, and in any event within 48 hours of becoming aware; (b) provide the information reasonably available to us, including what happened, when, what data and how many individuals are affected, what we are doing, and what we recommend you do; (c) provide updates as the investigation progresses; (d) take reasonable steps to contain the breach and mitigate harm; and (e) not make any public statement identifying you without consulting you first, unless required by law.
8.2 You lead notification to individuals where the affected information is Customer Data, because you are the entity with the relationship to those individuals and the obligation under the NDB scheme. We will give you the information and assistance you reasonably need.
8.3 Where we are independently required to notify the OAIC, we will do so, and will consult you beforehand where practicable.
8.4 We maintain a written Data Breach Response Plan, reviewed at least annually.
9. Audit and assurance
9.1 On written request (no more than once in any 12 months, unless following a data breach affecting your data), we will provide: (a) a written response to a reasonable security questionnaire; (b) a copy of our then-current security overview; and (c) confirmation of our sub-processor list and data locations.
9.2 We do not currently hold ISO 27001 certification or a SOC 2 report. We will tell you plainly what we do and do not have rather than imply certifications we do not hold. Our current security posture is described in Schedule A.
9.3 On-site audits are not included as standard. If your NDIS audit requires one, contact us and we will negotiate reasonable terms in good faith.
10. Return and deletion of data
10.1 During the subscription, you may obtain a complete export of Customer Data at any time and at no charge — either through the export features in the platform, or by asking us in writing, in which case we will provide a full export (including uploaded documents and call recordings) in a commonly usable format within 10 business days.
10.2 On termination, we retain Customer Data for a Retrieval Period of 90 days so you can export it.
10.3 After the Retrieval Period, we delete Customer Data from active systems within 30 days, and it is purged from backups as they rotate (currently a 7 day backup retention window).
10.4 We may retain Customer Data beyond those periods only where required by law, and only for as long as required, and it remains protected by this DPA while retained.
10.5 On written request, we will confirm deletion has occurred.
10.6 ⚠️ This clause does not discharge your own retention obligations. NDIS providers must generally keep participant records for at least 7 years, and records relating to a child until they turn 25. Export before you terminate.
11. General
11.1 This DPA is governed by the same law as the Terms of Service.
11.2 If there is an inconsistency between this DPA and the Terms of Service in relation to the handling of Personal Information, this DPA prevails.
11.3 We may update this DPA in accordance with clause 21 of the Terms of Service. We will not make a change that materially reduces the protections in this DPA without giving you the right to terminate without penalty.
Schedule A — Security measures
This schedule describes our security measures as at 29 July 2026. It is written to be accurate rather than impressive. Measures may improve over time; we will not reduce them materially without notice.
A.1 Hosting and data location
- Database, authentication, file storage and backend functions: Supabase on AWS Sydney (ap-southeast-2), Australia
- Voice and call recordings: Twilio AU1 (Sydney), Australia
- Web application delivery: Vercel global edge network
- Offshore processing is limited to the services identified in clause 7.2
A.2 Access control
- Row-level security enforced in the database, scoping every record to the owning provider tenant
- Role-based permissions within each provider account, configured by the provider
- Passwords stored hashed; we cannot read them
- Multi-factor authentication available
- Passwordless, scoped, time-limited links for external participants such as support workers, granting access only to the specific records required
- Least-privilege administrative access for our personnel; production access limited to those who require it
- Support access to Customer Data is logged
A.3 Encryption
- TLS in transit for all connections to the platform and to sub-processors
- Encryption at rest for the database, file storage and backups (AWS-managed)
A.4 Application security
- Server-side authorisation on all privileged operations; the client is not trusted to enforce permissions
- Signature verification on inbound webhooks from third parties, failing closed
- Server-side audit logging of significant actions
- Immutable attestation ledger available for records where the provider enables it
- Automated test suite run before deployment
- Dependency and configuration drift checks between source control and production
A.5 Backups and recovery
- Automated daily database backups, retained 7 days
- Point-in-time recovery: Not enabled (available as a paid upgrade)
- Documented and tested procedure to rebuild the entire production environment from source control
- File storage backed up as part of the platform backup regime
A.6 Monitoring
- Application error monitoring and alerting
- Automated operational sweeps detecting stuck or anomalous records
- Scheduled job monitoring with alerting on failure
A.7 Personnel
- All personnel and contractors bound by written confidentiality obligations
- Access removed promptly on departure
- Background checks: not currently applicable — no personnel other than the principal have production access
A.8 Known limitations (stated honestly)
| Item | Status |
|---|---|
| ISO 27001 / SOC 2 | Not held |
| Independent penetration test | Not yet completed |
| Independent tenant-isolation review | Not yet completed |
| Cyber liability insurance | Not yet in place |
| Professional indemnity insurance | Not yet in place |
| 24/7 support | Not provided — see Schedule 1 of the Terms |
Schedule B — Sub-processors
Current as at 29 July 2026. The authoritative list is at opsflow.net.au/subprocessors.
| Sub-processor | Service provided | Data handled | Location |
|---|---|---|---|
| Supabase Inc. (on AWS) | Database, auth, storage, edge functions | All Customer Data | Australia — AWS Sydney |
| Vercel Inc. | Web application hosting | Request metadata (IP, user agent, paths) | Global edge |
| Twilio Inc. (Voice) | Voice calling, call recording | Call metadata, call recordings | Australia — AU1 Sydney |
| Twilio Inc. (Messaging) | SMS send and receive | SMS content, phone numbers | Outside Australia |
| Resend | Transactional and notification email | Email content, recipient addresses | United States |
| Stripe, Inc. | Payments and subscription billing | Billing contact, payment data. No participant data | Outside Australia |
| Annature Pty Ltd | Electronic signature | Documents sent for signature, signer details | Australia |
| Functional Software, Inc. (Sentry) | Error monitoring (optional, DSN-gated) | Scrubbed error diagnostics | Outside Australia |
| Apple Inc. (APNs) | iOS push notifications | Content-free notification triggers | Outside Australia |
| Google LLC (FCM) | Android push notifications | Content-free notification triggers | Outside Australia |
| Microsoft Corporation | Where you connect a mailbox/calendar | Email and calendar data via Microsoft Graph, at your direction | Your tenant’s region |
| Google LLC (Workspace) | Where you connect a mailbox/calendar | Email and calendar data, at your direction | Your tenant’s region |
⚠️ The last two are connections you choose to make. When you connect your own mailbox, data flows between OpsFlow and your own Microsoft or Google tenant under your agreement with that provider.