Data Processing Agreement
Last updated: 25 June 2026
[REVIEW: …] require sign-off from an Australian tech/privacy lawyer before being relied on commercially.This DPA forms part of the Terms of Service between the customer ("Controller") and Apex Workforce Development Pty Ltd ("Processor"). It applies whenever Apex processes personal information about the Controller's workers, candidates or representatives on the Controller's behalf.
1. Roles
The Controller determines the purposes and means of processing employee personal information. Apex acts as Processor (or Service Provider under equivalent regimes), processing only on documented instructions from the Controller (those instructions being: the Terms, this DPA, and the Controller's use of the platform).
2. Subject matter and duration
Processing is for the term of the subscription plus the deletion window in the Terms.
3. Nature and purpose
Hosting, processing, displaying and routing employee records, compliance evidence, hours and training data necessary to operate the platform and route training enquiries.
4. Categories of data subjects and personal data
- Data subjects: Controller's employees, contractors, candidates and authorised representatives.
- Personal data: identification, contact, employment, licence/ticket, VOC, qualifications, hours, induction acknowledgements; limited sensitive information (e.g. fitness-for-work) only as uploaded by the Controller.
5. Apex's obligations
- Process only on Controller's documented instructions.
- Ensure personnel are bound by confidentiality.
- Implement appropriate technical and organisational security measures (see schedule below).
- Assist the Controller with data subject requests where reasonably required.
- Notify the Controller of a personal data breach without undue delay and within 72 hours of becoming aware.
- On termination, return or delete personal data within 30 days, except where retention is required by law.
6. Subprocessors
The Controller authorises Apex to engage subprocessors listed at /subprocessors. We will give 30 days' notice of new subprocessors. The Controller may object on reasonable grounds; if we cannot accommodate the objection, the Controller may terminate the affected portion of the service. Apex remains liable for subprocessor performance.
7. Cross-border transfers
Primary storage is Australia. Some subprocessors process limited data overseas. Apex takes reasonable steps to ensure protections consistent with the Australian Privacy Principles (APP 8).
8. RTO partner sharing
When the Controller submits a training enquiry through the platform, the Controller instructs Apex to share the minimum necessary fields with matched RTO partners. RTO partners then act as independent controllers in respect of that enquiry under their own privacy policies.
9. Audit
Apex will respond to reasonable written information requests regarding compliance with this DPA. On-site audits are available on Enterprise plans on reasonable notice and at the Controller's cost.
10. Liability
Each party's liability under this DPA is subject to the limitations of liability in the Terms.
Schedule A — Security measures
- TLS 1.2+ in transit; AES-256 at rest.
- Row-level security tenant isolation in the database.
- Short-lived signed URLs for file access.
- Hashed passwords (bcrypt) with HIBP breach screening.
- Role-based access control with least-privilege admin access.
- Append-only audit logs of administrative actions.
- Daily backups, 30-day retention, point-in-time recovery.
- Documented incident response plan and breach notification process.
See also: Help · Status · Terms · Privacy · Acceptable Use · Cookies · DPA · Employee Privacy Notice · Refunds · Subprocessors · RTO Partner Agreement