OntraqOntraq

Data Processing Agreement

Last updated: 19 July 2026

1. Purpose and scope

This Data Processing Agreement (DPA) supplements the Terms of Service between you (the Customer, acting as the data controller) and The Trustee for Shineex Family Trust (ABN 53 103 510 319) (Ontraq, acting as the data processor). It governs how Ontraq processes Personal Information about individuals on the Customer's behalf in the course of providing the Service.

This DPA applies to all Personal Information processed by Ontraq on the Customer's instructions, regardless of whether a signed copy is executed. By using the Service, the Customer accepts the obligations and rights set out in this DPA.

2. Definitions

  • Customer Personal Information — Personal Information about individuals other than the Customer's own account holders that the Customer submits to or processes through the Service. This includes cleaner names, contact details, GPS coordinates, work history, photos taken on jobs, and step-count data.
  • Personal Information — as defined in the Privacy Act 1988 (Cth): information or an opinion about an identified or reasonably identifiable individual.
  • Personal Information Breach — unauthorised access to, or disclosure or loss of, Customer Personal Information held by Ontraq.
  • Sub-processor — any third party engaged by Ontraq to process Customer Personal Information on Ontraq's behalf.
  • APPs — the Australian Privacy Principles set out in Schedule 1 of the Privacy Act 1988 (Cth).
  • NDB Scheme — the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act 1988 (Cth).

3. Roles of the parties

For Customer Personal Information, the parties acknowledge:

  • the Customer is the data controller — the Customer decides what Customer Personal Information is collected through the Service, the purposes of collection, and to whom it is disclosed within the Customer's organisation;
  • Ontraq is the data processor processes Customer Personal Information solely on the Customer's documented instructions (the Customer's use of the Service constituting such instructions), to provide the Service and comply with applicable law.

For Personal Information about the Customer's own account holders (administrators, billing contacts, contractor profile data), Ontraq acts as data controller under our Privacy Policy.

4. Subject matter, nature, and purpose of processing

Subject matter: provision of the Ontraq cleaning operations platform.

Duration: for the term of the Customer's Subscription, plus any post-termination retention period set out in clause 11.

Nature of processing: hosting, storage, transmission, computation, display, and deletion of Customer Personal Information as part of the Service's features (job scheduling, GPS clock-in tracking, payroll computation, invoice generation, push notification delivery, etc.).

Purpose of processing: to enable the Customer to manage its cleaning operations, including team scheduling, attendance verification, billing, and payroll.

5. Types of Personal Information and data subjects

The categories of data subjects and Personal Information processed by Ontraq on the Customer's behalf may include:

Data subjectsPersonal Information
CleanersName, email, phone, role, clean-type qualifications, hourly rate, GPS coordinates at clock-in/out, geofence arrival/departure timestamps, step counts during shifts, photos taken on jobs, pay records, payslip history.
Subcontractor org adminsName, email, phone, role, organisation affiliation, login history.
ClientsClient name, site address, invoice history.
End recipients of emailsEmail address, opening / delivery metadata via Resend.

6. Processor obligations

Ontraq will:

  • Process only on documented instructions.Process Customer Personal Information only as needed to provide the Service, comply with applicable law, or as the Customer otherwise directs in writing. If Ontraq believes an instruction infringes applicable law, Ontraq will inform the Customer.
  • Confidentiality. Ensure that personnel authorised to process Customer Personal Information are bound by a duty of confidentiality.
  • Security. Implement and maintain the technical and organisational measures set out in Schedule A.
  • Assistance. Provide reasonable assistance to the Customer in responding to data subject requests (access, correction, deletion, portability), conducting privacy impact assessments, and consulting with the OAIC, taking into account the nature of the processing and the information available to Ontraq.
  • Sub-processors. Engage Sub-processors only on the terms of clause 7.
  • Breach notification. Notify the Customer without undue delay (and in any event within 72 hours) of becoming aware of a Personal Information Breach affecting Customer Personal Information, with sufficient detail to enable the Customer to meet any obligations under the NDB Scheme.
  • Return or deletion. On termination of the Subscription or on the Customer's written request, return or delete Customer Personal Information per clause 11.
  • Audit. Make available to the Customer information reasonably necessary to demonstrate compliance with this DPA, on the terms of clause 9.

7. Sub-processors

The Customer grants Ontraq general authorisation to engage Sub-processors to assist in providing the Service. The current list of authorised Sub-processors is set out in Schedule B (and also published at /legal/subprocessors).

Ontraq will:

  • impose data-protection obligations on each Sub-processor that are no less protective than those in this DPA;
  • give the Customer at least 30 days' notice of any intended addition or replacement of a Sub-processor (published at the URL above and, where the Sub-processor change is material, by email to billing contacts);
  • remain responsible for the acts and omissions of its Sub-processors as if they were its own.

Customer's right to object. If the Customer objects in writing within 30 days of notice of a new Sub-processor on reasonable data-protection grounds, the parties will work in good faith to resolve. If unresolvable, the Customer may terminate the Subscription with pro-rata refund of pre-paid fees attributable to the period after termination.

8. International transfers (APP 8)

Some Sub-processors are located outside Australia, primarily in the United States. Where Ontraq discloses Customer Personal Information to an overseas recipient, Ontraq takes reasonable steps to ensure that the recipient does not breach the APPs in relation to that information, including by:

  • contracting on terms that require the recipient to handle Personal Information in a manner consistent with the APPs;
  • selecting Sub-processors whose published security and privacy practices materially align with the APPs;
  • limiting transfers to those necessary to provide the Service.

9. Audit rights

Subject to the Customer's confidentiality obligations, Ontraq will provide on reasonable request:

  • copies of its current security and privacy policies;
  • responses to a reasonable security questionnaire (no more than annually unless triggered by a Personal Information Breach);
  • once available, copies of independent third-party security audit reports (e.g. SOC 2 Type II or ISO 27001).

Ontraq is working towards obtaining a SOC 2 Type II attestation and aims to publish it within the first 12 months following public launch. Until then, the security commitments in Schedule A apply.

10. Liability

Each party's liability under this DPA is subject to the limitation-of-liability provisions in the Terms of Service. Nothing in this DPA expands liability beyond what those Terms provide.

11. Return and deletion

The Customer may export Customer Personal Information at any time during the term via the Service's export features. On termination of the Subscription:

  • Customer Personal Information will be deleted from active systems within 30 days, except where retention is required by law (notably tax invoices and payment records retained 5 years per ATO requirements);
  • Encrypted database backups are taken daily and retained in line with our hosting provider's backup schedule, after which backup data expires automatically. Uploaded photos are stored redundantly by our storage provider but are not part of database backups.

Detailed retention and deletion mechanics are described in our Account & Data Deletion page.

12. Term

This DPA takes effect on the earlier of the Customer's first use of the Service or the Customer's acceptance of the Terms of Service, and continues for as long as Ontraq processes Customer Personal Information on the Customer's behalf.

13. Governing law

This DPA is governed by the laws of Queensland, Australia, consistent with the Terms of Service.


Schedule A — Technical and organisational security measures

Ontraq implements the following measures, which it may update from time to time to reflect evolving security best practice. Updates will not materially reduce protections.

  • Encryption in transit. All communications between client applications and Ontraq services use TLS 1.2 or higher.
  • Encryption at rest. Customer Personal Information is encrypted at rest using AES-256 (provided by the hosting infrastructure).
  • Access controls. Production database access is restricted to authorised personnel via least-privilege role-based access control. Multi-factor authentication is required for all administrative access.
  • Authentication. Customer accounts use bcrypt-hashed passwords; sessions are JWT-based with short expiry and rotation.
  • Network controls. Production infrastructure is hosted on managed cloud services with vendor-grade firewalling and DDoS protections.
  • Logging and monitoring. Authentication events and significant administrative actions are logged; logs are retained 90 days. Errors are monitored via Sentry (web application only).
  • Vulnerability management. Dependencies are monitored for known vulnerabilities; security patches are applied per vendor severity guidance.
  • Backup and recovery. Encrypted database backups are taken daily and retained in line with our hosting provider's backup schedule. Uploaded photos are stored redundantly by our storage provider but are not part of database backups. Restoration procedures are documented.
  • Personnel. Personnel with access to Customer Personal Information are bound by confidentiality obligations and receive security awareness orientation.
  • Incident response. A documented incident-response process governs detection, assessment, notification, and post-incident review.

Schedule B — Authorised Sub-processors (as at last updated date)

The current Sub-processor list is also published at /legal/subprocessors.

Sub-processorFunctionLocation
Supabase Inc.Database, auth, file storageSingapore (on AWS)
Stripe Inc.Payments / subscription billingUnited States
Resend Inc.Transactional email deliveryUnited States
Vercel Inc.Web application hostingUnited States / global edge
Expo Inc.Mobile push notifications and build infrastructureUnited States
Google LLCPush notification delivery (Firebase Cloud Messaging, Android)United States
Functional Software Inc. (Sentry)Web error monitoringUnited States