Data Processing Addendum
Last updated: June 2026 · Forms part of the Terms of Service
1. Parties & Roles
This Data Processing Addendum ("DPA") is entered into between you ("Customer", the data controller / APP entity) and Registrum Pty Ltd (ABN 29 372 825 751) ("Registrum", the data processor / service provider). It is incorporated into and forms part of the Terms of Service.
For personal information that the Customer enters into the platform (including data about their own customers, suppliers, employees, contractors and contacts), the Customer is the APP entity under the Privacy Act 1988 (Cth). Registrum is the data processor acting on the Customer's documented instructions, which are set by the Customer's use of the platform's features.
2. Subject Matter, Duration & Nature
- Subject matter: processing of Customer Data required to provide the Registrum platform — cloud accounting, invoicing, payroll, jobs, inventory, document storage, bank feeds and the Reggie AI assistant.
- Duration: for the term of the Customer's subscription, plus the retention periods set out in the Privacy Policy and applicable Australian record-keeping laws.
- Nature of processing: hosting, structuring, indexing, searching, displaying, transmitting, backing up, exporting, deleting, and (where the Customer enables it) using AI providers to generate responses from Customer Data.
- Categories of data subjects: Customer's own personnel, customers, suppliers, contractors, employees and other contacts entered into the platform.
- Categories of personal data: identifiers (name, email, phone, ABN), financial data (invoices, expenses, payments, bank transactions), employment data (TFN, super fund, payslips, leave), and any data the Customer chooses to upload (documents, notes, photos).
3. Registrum's Obligations
Registrum will:
- Process Customer Data only to provide and improve the service, and only on the Customer's documented instructions (set by the Customer's use of the product).
- Apply the technical and organisational security measures listed in Annex A.
- Ensure all personnel with access to Customer Data are bound by confidentiality obligations.
- Engage only the subprocessors listed in Annex B, and impose data-protection obligations on them no less protective than this DPA.
- Assist the Customer, taking into account the nature of processing, in responding to data-subject requests (access, correction, deletion, portability) and in carrying out data-protection impact assessments where required.
- Notify the Customer of an eligible data breach as soon as practicable after confirming it, consistent with section 6.
- On termination, and at the Customer's choice, return or delete Customer Data subject to legal retention obligations.
4. Customer's Obligations
- Ensure that the personal information entered into the platform was collected lawfully and that any required notices or consents are in place (APP 3 and APP 5).
- Respond to data-subject requests as the primary APP entity / controller.
- Configure access controls inside the platform (roles, permissions, MFA, advisor invitations) appropriately.
- Keep your own copy or export of Customer Data — Registrum's backups are operational, not a substitute for the Customer's own backups.
- Not enter into the platform any special category data (e.g. health, biometric data) unless required for legitimate payroll/HR purposes and lawfully collected.
5. Subprocessors
The current subprocessors are listed in Annex B and in section 6 of the Privacy Policy. Registrum may add or replace subprocessors by updating the Privacy Policy and DPA at least 30 days before the new subprocessor begins processing Customer Data, except where a faster change is required for security or legal reasons. The Customer may object on reasonable grounds; if the parties cannot agree on a workaround, the Customer may terminate the affected service for the unused portion of any prepaid period.
6. Security & Breach Notification
Registrum maintains a security program designed to protect Customer Data against unauthorised access, loss, alteration or disclosure (see Annex A). If Registrum becomes aware of an unauthorised disclosure of, or access to, Customer Data:
- Registrum will carry out an assessment within 30 days, as required by Part IIIC of the Privacy Act 1988 (Cth).
- If the breach is likely to result in serious harm, Registrum will notify the Customer as soon as practicable with a description of the breach, the categories and approximate number of records affected, the likely consequences, and the steps Registrum has taken or proposes to take.
- The Customer, as the APP entity, is responsible for notifying affected individuals and the OAIC unless Registrum agrees in writing to do so on the Customer's behalf. If the Customer has obligations under any foreign privacy law, meeting those obligations remains the Customer's responsibility.
- Registrum will reasonably assist the Customer in meeting its notification obligations.
7. Cross-Border Transfers
Customer Data may be processed in Australia and the locations listed in Annex B. Where data is transferred outside Australia, Registrum relies on (a) the recipient country offering substantially similar protections to the Australian Privacy Principles (APP 8.2(a)), (b) the Customer's consent given through the use of the relevant integration (APP 8.2(b)), or (c) contractual safeguards such as Standard Contractual Clauses.
8. Audits
On reasonable written request, and no more than once in any 12-month period, Registrum will provide a written summary of its security controls and any current independent reports of its subprocessors that Registrum is permitted to share. On-site audits are not generally offered; where strictly required by law for a regulated customer, the parties will agree a reasonable scope, timing and cost-recovery in writing.
9. Liability
Each party's liability under this DPA is subject to the limitations of liability in the Terms of Service. Nothing in this DPA limits any non-excludable right of the Customer under the Australian Consumer Law or the Privacy Act 1988 (Cth).
10. Term & Termination
This DPA takes effect from the date the Customer first uses the platform and remains in force for the term of the Customer's subscription. On termination, Customer Data is handled as set out in the Privacy Policy and the Terms of Service.
Annex A — Security Measures
- TLS encryption for all data in transit; AES-256 (or equivalent) encryption for data at rest, as provided by the hosting subprocessor.
- Row-Level Security (RLS) policies enforce strict multi-tenancy — one organisation's data cannot be read or written by another.
- Multi-factor authentication (TOTP) available to all users; brute-force protection on sign-in (10 failed attempts trigger a 24-hour block).
- Role-based access control with capability-level granularity for advisors and team members.
- Audit logging of sensitive actions. Retention follows the statutory schedule: employee and payroll records 7 years (Fair Work Act 2009); tax records generally a minimum of 5 years (Taxation Administration Act 1953 s262A). The longer period governs payroll.
- Edge functions independently verify the caller's identity; client-supplied IDs are never trusted.
- Daily operational backups; quarterly restore drills with documented runbooks.
- Suppressed-emails and webhook delivery logging to detect deliverability and integration abuse.
- Vulnerability monitoring of dependencies; security patches applied promptly.
- Registrum does not claim to be "bank-grade", "military-grade", "ISO 27001 certified" or "SOC 2 certified". Such claims would be misleading under the Australian Consumer Law and would only be made if and when the underlying certification is held.
Annex B — Subprocessors
The current list of subprocessors and their processing locations is maintained in section 6 of the Privacy Policy. The list is updated whenever a subprocessor is added, removed, or its role changes.
Contact
For DPA-related enquiries, contact the Privacy Officer at support@registrum.com.au.