Data Processing Agreement v2.0

Doughboy Platform · operated by Cameron James Moir · ABN 52 721 553 987 · Effective 26 June 2026

Plain-English summary. This Data Processing Agreement ("DPA") governs how Doughboy, as your processor, handles personal data on behalf of your organisation, the controller. It is written to satisfy Article 28 of the EU GDPR and the UK GDPR, incorporates the European Commission's Standard Contractual Clauses and the UK Addendum for international transfers, and forms part of your Doughboy subscription agreement. By subscribing to or using Doughboy on behalf of an organisation, that organisation accepts this DPA. For a counter-signed copy for your records, email doughboy@streamables.live. (This DPA governs the data your organisation controls; the separate Privacy Policy covers data for which Doughboy is itself the controller.)

1. Definitions

2. Roles, scope and duration

For the Personal Data covered by this DPA, the Controller is the controller and the Processor is the processor. The Processor Processes Personal Data only to provide the Doughboy platform and related services to the Controller. The subject matter, duration, nature and purpose of the Processing, the types of Personal Data, and the categories of Data Subjects are set out in Annex I. This DPA applies for as long as the Processor Processes Personal Data on the Controller's behalf.

3. Processing on documented instructions (Art 28(3)(a))

The Processor will Process Personal Data only on the Controller's documented instructions - including with regard to international transfers - unless required to do otherwise by law, in which case the Processor will inform the Controller before Processing (unless that law prohibits it on important grounds of public interest). This DPA, together with the Controller's use of the platform's features and any written instructions, constitutes the Controller's complete instructions. The Processor will inform the Controller if, in its opinion, an instruction infringes Applicable Data Protection Law.

4. Confidentiality (Art 28(3)(b))

The Processor ensures that persons authorised to Process the Personal Data are bound by confidentiality obligations and Process the data only as necessary to provide the services.

5. Security (Art 28(3)(c), Art 32)

The Processor implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as described in Annex II, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of Processing.

6. Sub-processors (Art 28(2), (4))

The Controller gives the Processor general written authorisation to engage the Sub-processors listed in Annex III. The Processor will: (a) impose data protection obligations on each Sub-processor that are no less protective than those in this DPA, in particular providing sufficient guarantees to implement appropriate technical and organisational measures; and (b) remain fully liable to the Controller for each Sub-processor's performance. The Processor will give the Controller at least 14 days' notice of any intended addition or replacement of a Sub-processor (by updating Annex III and emailing the Controller's account address). The Controller may reasonably object within that period; if the parties cannot resolve the objection, the Controller may terminate the subscription with respect to the affected services.

7. Assistance with Data Subject rights (Art 28(3)(e))

Taking into account the nature of the Processing, the Processor will assist the Controller by appropriate technical and organisational measures, insofar as possible, to respond to requests from Data Subjects exercising their rights (access, rectification, erasure, restriction, portability, objection, and rights relating to automated decision-making). Where a Data Subject contacts the Processor directly, the Processor will, without undue delay, inform the Controller and not respond to the request itself except on the Controller's instruction or as legally required.

8. Assistance with security, breaches and impact assessments (Art 28(3)(f))

The Processor will assist the Controller in ensuring compliance with its obligations under Articles 32 to 36 of the EU GDPR (and equivalents), taking into account the nature of Processing and the information available to the Processor - including security of Processing, Personal Data Breach notification, data protection impact assessments, and prior consultation with a Supervisory Authority.

9. Personal Data Breach notification (Art 33(2))

The Processor will notify the Controller without undue delay after becoming aware of a Personal Data Breach affecting the Controller's Personal Data, and will provide the Controller with information reasonably required to meet the Controller's own notification obligations to Supervisory Authorities and Data Subjects. The Processor's internal breach-response procedure targets supervisory-authority notification within 72 hours where the Processor is itself the controller.

10. International transfers

The Controller authorises the Processor to transfer Personal Data to the Sub-processors in Annex III, including outside the EEA, the UK, Switzerland or Australia. For any Restricted Transfer, the parties agree to the following safeguards under Chapter V of the EU GDPR (and equivalents):

Where there is any conflict between the SCCs and the rest of this DPA on a transfer matter, the SCCs prevail.

11. Return or deletion of data (Art 28(3)(g))

On termination of the services, and at the Controller's choice, the Processor will delete or return all Personal Data and delete existing copies, unless Applicable Data Protection Law requires continued storage. The Controller may export its operational data at any time through the platform. Absent a contrary instruction, the Processor will delete Personal Data on the schedule in the Privacy Policy (live data promptly; routine encrypted backups overwritten on the standard cycle).

12. Audits and information (Art 28(3)(h))

The Processor will make available to the Controller all information reasonably necessary to demonstrate compliance with this DPA, and will allow for and contribute to audits, including inspections, conducted by the Controller or an auditor it mandates. To minimise disruption, the Processor may satisfy an audit request by providing relevant documentation and its Sub-processors' third-party certifications (e.g. SOC 2, ISO 27001); on-site inspections are on reasonable prior notice, no more than once per year (or following a Personal Data Breach), and subject to confidentiality.

13. Controller's obligations

The Controller warrants that it has a lawful basis to provide the Personal Data to the Processor and to instruct the Processing; that it has given any notices and obtained any consents required of a controller (including informing its staff that their name, email and role are stored in Doughboy); and that its instructions will comply with Applicable Data Protection Law. The Controller is responsible for the accuracy of the data it enters.

14. Liability

Each party's liability under or in connection with this DPA is subject to the exclusions and limitations of liability in the main agreement between the parties (the Master Customer Agreement / Terms of Use). Nothing in this DPA limits any liability that cannot be limited under Applicable Data Protection Law.

15. Order of precedence

In the event of conflict: (1) the SCCs prevail on matters of Restricted Transfers; (2) this DPA prevails over the main agreement on matters of data protection; (3) the main agreement governs all other matters.

16. Governing law and forum

This DPA is governed by the laws of Queensland, Australia, and the parties submit to the courts of Queensland, except that, for the SCCs, the governing law and forum are as stated in Annex I (an EU/EEA Member State law where required for the SCCs to be effective).

17. Contact

Annex I — Description of the Processing

A. Parties

Data exporter / Controller: the subscribing organisation (the customer), as identified in its Doughboy account and subscription. Data importer / Processor: Cameron James Moir (Streamables.live), ABN 52 721 553 987.

B. Description of transfer

C. Competent Supervisory Authority

For SCC purposes, the competent Supervisory Authority is that of the EEA Member State in which the Controller (data exporter) is established or, where the Controller is not EEA-established, the authority of the Member State of its EU representative or affected Data Subjects, as determined under Clause 13 of the SCCs. For UK transfers, the UK Information Commissioner's Office.

Annex II — Technical and organisational security measures

Annex III — Authorised Sub-processors

Sub-processorServiceLocationTransfer basis
Supabase, Inc. (on AWS)Database, authentication, file storageTokyo, JapanAdequacy (Japan)
Vercel, Inc.Hosting, serverless functions, edge deliveryUSA / global edge; functions in TokyoSCCs + DPF
Stripe, Inc.Payment processing, subscription billingUnited StatesSCCs + DPF
Namecheap, Inc. (PrivateEmail)Transactional email deliveryUnited StatesSCCs