Data Processing Agreement

Last Updated: September 2026

This Data Processing Agreement forms part of the Agreement between Customer and Teralo Pty Ltd (ABN 98 634 996 115). It sets out Teralo's obligations when it handles Personal Information on Customer's behalf. Capitalised terms not defined here have the meaning given in the Master Terms.

1. Roles

For Customer Material, Customer is the controller and Teralo is the processor. Customer decides why and how Personal Information within Customer Material is handled. Teralo handles it on Customer's documented instructions and does not use it for its own purposes.

For information about Customer's own account holders, and about visitors to teralo.co, Teralo is the controller. That handling is described in the Privacy Policy and is outside this Agreement.

Customer warrants that it has collected the Personal Information in Customer Material lawfully, has given the notices and obtained the Consents that Privacy Laws require, and is entitled to have Teralo process it.

2. Scope of Processing

Subject matter: provision of the Teralo construction project management platform.

Duration: the Term, plus the 90-day export window under clause 7.2 of the Master Terms.

Nature and purpose: hosting, storing, transmitting, indexing, generating derived records from and otherwise processing Customer Material in order to provide the Products and Services.

Categories of data subject: Customer's Personnel and Authorised Users, and the workers, subcontractors, suppliers, consultants, site visitors and client representatives whose records Customer or its Authorised Users enter into the platform.

Categories of Personal Information: names, contact details, employment and role information, licences, competencies and induction records, site attendance records, photographs, correspondence, and where Customer enables it, biometric templates for kiosk face sign-in. Incident and injury records may contain health information.

Customer is responsible for deciding what it puts into the platform, and for whether that is proportionate to its purpose.

3. Teralo's Obligations

Teralo must:

  • Process Personal Information only on Customer's documented instructions, which the Agreement constitutes, unless Law requires otherwise, in which case Teralo will inform Customer before processing unless that Law prohibits it
  • Not sell Personal Information, and not use it for its own marketing
  • Ensure personnel authorised to process Personal Information are bound by confidentiality obligations
  • Implement and maintain the technical and organisational measures described in clause 4
  • Assist Customer, to the extent reasonable and at Customer's cost where the assistance is substantial, with data subject requests, privacy impact assessments and regulator engagement
  • Make available the information reasonably necessary to demonstrate compliance with this Agreement

4. Security Measures

Teralo maintains the controls described on the Security page. That page is written to be accurate as configured rather than aspirational, and it states plainly where a control is not in place.

The measures include encryption in transit using TLS 1.2 or above, encryption at rest by the platforms holding the data, role-based access control enforced on the server, multi-factor authentication available to all users and mandatory for Teralo staff with administrative access, automated penetration testing, and continuous monitoring.

Teralo will not materially reduce the overall level of security during the Term.

5. Sub-processors

Customer gives Teralo general authorisation to engage sub-processors.

Every sub-processor is named, with its purpose, the categories of data it receives and its processing location, on the Sub-processor list. That page carries the date the list last changed.

Notification. Teralo will update that page before a new sub-processor begins processing Customer Material, and will notify Customer.

Objection. Customer may object to a new sub-processor on reasonable data protection grounds within 30 days of notification. The parties will work in good faith to find an alternative. Where none is reasonably available, Customer may terminate the affected part of the Products and Services without penalty for the remainder of the Term, and Teralo will refund pre-paid fees for the unused portion.

Flow-down. Teralo imposes on each sub-processor data protection obligations no less protective than those in this Agreement, and remains liable to Customer for a sub-processor's performance as if it were Teralo's own.

6. International Transfers

Where Customer Material rests, and what leaves that region, are described in the Privacy Policy. The description distinguishes between a location that is contractually committed and one that reflects a provider's placement decision, and Customer should read it before relying on either.

Where Personal Information is transferred outside Australia, Teralo takes reasonable steps to ensure the recipient handles it in a manner consistent with the Australian Privacy Principles, as APP 8 requires.

7. Data Incidents

Teralo will notify Customer in writing without undue delay, and in any event within 48 hours, of becoming aware of a Data Incident affecting Customer Material.

The notification will describe the nature of the incident, the categories and approximate volume of Personal Information involved, the likely consequences, and the measures taken or proposed. Where the full picture is not available within 48 hours, Teralo will provide what it has and the remainder as it becomes known, rather than delaying the initial notification.

Teralo will cooperate with Customer in assessing whether the incident is an Eligible Data Breach under the Privacy Act, and neither party's obligation to cooperate delays a notification that Law requires it to make.

8. Data Subject Requests

Where Teralo receives a request from an individual relating to Customer Material, Teralo will not respond to it directly except to acknowledge it and to direct the individual to Customer. Teralo will inform Customer of the request without undue delay and will assist Customer in responding.

9. Return and Deletion

Customer may export Customer Material at any time during the Term, and for 90 days after expiry or termination, under clause 7 of the Master Terms.

After that period, Teralo will delete Customer Material from its production systems. Copies held in backups are deleted on the ordinary backup rotation, and remain subject to this Agreement until they are.

Where Customer purchases a long-term archive under clause 7.3 of the Master Terms, the archived material remains subject to this Agreement for the duration of the archive.

10. Audit

Teralo will respond to a reasonable written information request from Customer about its compliance with this Agreement, including by providing its most recent penetration testing report under a non-disclosure agreement and by completing Customer's security questionnaire.

Where Customer reasonably requires an on-site or third-party audit, the parties will agree its scope, timing and cost in advance. An audit may be conducted no more than once in any 12-month period unless a Data Incident or a regulator requires otherwise.

11. Precedence

Where this Agreement is inconsistent with the Master Terms or a Schedule in respect of the handling of Personal Information, this Agreement prevails. In all other respects the order of precedence in clause 1 of the Master Terms applies.

Contact

For questions about this Data Processing Agreement, or to raise a sub-processor objection, please contact us at support@teralo.co.