For the Personal Data covered by this DPA, the Controller is the controller and the Processor is the processor. The Processor Processes Personal Data only to provide the Doughboy platform and related services to the Controller. The subject matter, duration, nature and purpose of the Processing, the types of Personal Data, and the categories of Data Subjects are set out in Annex I. This DPA applies for as long as the Processor Processes Personal Data on the Controller's behalf.
The Processor will Process Personal Data only on the Controller's documented instructions - including with regard to international transfers - unless required to do otherwise by law, in which case the Processor will inform the Controller before Processing (unless that law prohibits it on important grounds of public interest). This DPA, together with the Controller's use of the platform's features and any written instructions, constitutes the Controller's complete instructions. The Processor will inform the Controller if, in its opinion, an instruction infringes Applicable Data Protection Law.
The Processor ensures that persons authorised to Process the Personal Data are bound by confidentiality obligations and Process the data only as necessary to provide the services.
The Processor implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as described in Annex II, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of Processing.
The Controller gives the Processor general written authorisation to engage the Sub-processors listed in Annex III. The Processor will: (a) impose data protection obligations on each Sub-processor that are no less protective than those in this DPA, in particular providing sufficient guarantees to implement appropriate technical and organisational measures; and (b) remain fully liable to the Controller for each Sub-processor's performance. The Processor will give the Controller at least 14 days' notice of any intended addition or replacement of a Sub-processor (by updating Annex III and emailing the Controller's account address). The Controller may reasonably object within that period; if the parties cannot resolve the objection, the Controller may terminate the subscription with respect to the affected services.
Taking into account the nature of the Processing, the Processor will assist the Controller by appropriate technical and organisational measures, insofar as possible, to respond to requests from Data Subjects exercising their rights (access, rectification, erasure, restriction, portability, objection, and rights relating to automated decision-making). Where a Data Subject contacts the Processor directly, the Processor will, without undue delay, inform the Controller and not respond to the request itself except on the Controller's instruction or as legally required.
The Processor will assist the Controller in ensuring compliance with its obligations under Articles 32 to 36 of the EU GDPR (and equivalents), taking into account the nature of Processing and the information available to the Processor - including security of Processing, Personal Data Breach notification, data protection impact assessments, and prior consultation with a Supervisory Authority.
The Processor will notify the Controller without undue delay after becoming aware of a Personal Data Breach affecting the Controller's Personal Data, and will provide the Controller with information reasonably required to meet the Controller's own notification obligations to Supervisory Authorities and Data Subjects. The Processor's internal breach-response procedure targets supervisory-authority notification within 72 hours where the Processor is itself the controller.
The Controller authorises the Processor to transfer Personal Data to the Sub-processors in Annex III, including outside the EEA, the UK, Switzerland or Australia. For any Restricted Transfer, the parties agree to the following safeguards under Chapter V of the EU GDPR (and equivalents):
Where there is any conflict between the SCCs and the rest of this DPA on a transfer matter, the SCCs prevail.
On termination of the services, and at the Controller's choice, the Processor will delete or return all Personal Data and delete existing copies, unless Applicable Data Protection Law requires continued storage. The Controller may export its operational data at any time through the platform. Absent a contrary instruction, the Processor will delete Personal Data on the schedule in the Privacy Policy (live data promptly; routine encrypted backups overwritten on the standard cycle).
The Processor will make available to the Controller all information reasonably necessary to demonstrate compliance with this DPA, and will allow for and contribute to audits, including inspections, conducted by the Controller or an auditor it mandates. To minimise disruption, the Processor may satisfy an audit request by providing relevant documentation and its Sub-processors' third-party certifications (e.g. SOC 2, ISO 27001); on-site inspections are on reasonable prior notice, no more than once per year (or following a Personal Data Breach), and subject to confidentiality.
The Controller warrants that it has a lawful basis to provide the Personal Data to the Processor and to instruct the Processing; that it has given any notices and obtained any consents required of a controller (including informing its staff that their name, email and role are stored in Doughboy); and that its instructions will comply with Applicable Data Protection Law. The Controller is responsible for the accuracy of the data it enters.
Each party's liability under or in connection with this DPA is subject to the exclusions and limitations of liability in the main agreement between the parties (the Master Customer Agreement / Terms of Use). Nothing in this DPA limits any liability that cannot be limited under Applicable Data Protection Law.
In the event of conflict: (1) the SCCs prevail on matters of Restricted Transfers; (2) this DPA prevails over the main agreement on matters of data protection; (3) the main agreement governs all other matters.
This DPA is governed by the laws of Queensland, Australia, and the parties submit to the courts of Queensland, except that, for the SCCs, the governing law and forum are as stated in Annex I (an EU/EEA Member State law where required for the SCCs to be effective).
Data exporter / Controller: the subscribing organisation (the customer), as identified in its Doughboy account and subscription. Data importer / Processor: Cameron James Moir (Streamables.live), ABN 52 721 553 987.
For SCC purposes, the competent Supervisory Authority is that of the EEA Member State in which the Controller (data exporter) is established or, where the Controller is not EEA-established, the authority of the Member State of its EU representative or affected Data Subjects, as determined under Clause 13 of the SCCs. For UK transfers, the UK Information Commissioner's Office.
| Sub-processor | Service | Location | Transfer basis |
|---|---|---|---|
| Supabase, Inc. (on AWS) | Database, authentication, file storage | Tokyo, Japan | Adequacy (Japan) |
| Vercel, Inc. | Hosting, serverless functions, edge delivery | USA / global edge; functions in Tokyo | SCCs + DPF |
| Stripe, Inc. | Payment processing, subscription billing | United States | SCCs + DPF |
| Namecheap, Inc. (PrivateEmail) | Transactional email delivery | United States | SCCs |