Contents

  1. Definitions
  2. Scope and nature of processing
  3. TrancheMate's obligations as Processor
  4. Firm's obligations as Controller
  5. Sub-processors
  6. Security measures
  7. Data breach notification
  8. Assistance with individual rights
  9. Australian data residency
  10. Return and deletion of data
  11. Audit and inspection rights
  12. Duration and termination
  13. Liability and indemnification
  14. Governing law
  15. Updates to this agreement

This Data Processing Agreement ("DPA") is entered into between TrancheMate (ABN 74 421 798 989) ("TrancheMate", "Processor") and the subscribing professional services firm ("Firm", "Controller") that has accepted the Terms of Service. This DPA forms part of and is incorporated into the Terms of Service. It governs the processing of personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

This DPA is not legal advice. It is a disclosure document explaining how TrancheMate handles personal information on your Firm's behalf. If your Firm has specific legal requirements — for example, under a professional indemnity insurance policy, an engagement contract with a large client, or a specific regulatory requirement — you should seek independent legal advice from a qualified Australian solicitor.

1. Definitions

In this DPA, unless the context otherwise requires:

2. Scope and nature of processing

2.1 Processing activities

TrancheMate processes Firm Data on behalf of the Firm for the purpose of delivering the Services. The processing activities are:

Module Data processed Purpose
AML/CTF Program Builder Firm details, compliance officer name, business structure, designated services Generate and store the Firm's AML/CTF Program document
Client CDD Hub Client names, dates of birth, addresses, photo identity documents, entity structures, beneficial ownership information, PEP declarations, source of funds declarations Facilitate AML/CTF customer due diligence on behalf of the Firm; store immutable CDD records
Compliance Calendar Compliance officer name, obligation dates, reminder preferences Track and remind the Firm of AML/CTF compliance obligations
SMR & Transaction Log Client references, transaction descriptions, AUSTRAC reference numbers, staff names Maintain an immutable SMR/TTR audit log on behalf of the Firm
Audit Export All of the above Compile a compliance evidence package for AUSTRAC audits or insurance renewals

2.2 Categories of data subjects

Personal information processed under this DPA relates to:

2.3 Controller instructions

TrancheMate processes Firm Data only on the documented instructions of the Firm, as reflected in the Firm's use of the platform features. The Firm's act of initiating a processing activity (for example, sending a CDD intake form to a client) constitutes an instruction for that processing.

TrancheMate will notify the Firm if it believes any instruction would cause TrancheMate to breach the Privacy Act or any other applicable Australian law.

3. TrancheMate's obligations as Processor

In processing Firm Data, TrancheMate will:

3.1 Process only on instructions

Process Firm Data only on the Firm's documented instructions and only for the purposes described in this DPA and the Terms of Service, unless required to do so by applicable Australian law (in which case TrancheMate will notify the Firm of that legal requirement before processing, unless the law prohibits such notification).

3.2 Confidentiality

Ensure that staff who access Firm Data are bound by confidentiality obligations and are provided access only to the Firm Data necessary to perform their role.

3.3 Security

Implement and maintain the technical and organisational security measures described in section 6 of this DPA, and in TrancheMate's Privacy Policy (section 7).

3.4 Sub-processors

Only engage sub-processors as set out in section 5 of this DPA, and ensure each sub-processor is bound by obligations equivalent to those in this DPA with respect to the protection of Firm Data.

3.5 Assistance with individual rights

Assist the Firm in meeting its obligations to individuals under the Privacy Act, including access, correction, and complaint handling, as described in section 8 of this DPA.

3.6 Breach notification

Notify the Firm without undue delay upon becoming aware of a security incident affecting Firm Data, as described in section 7 of this DPA.

3.7 Deletion or return on termination

On termination of the subscription, handle Firm Data as set out in section 10 of this DPA.

3.8 Audit assistance

Provide the Firm with information reasonably necessary to demonstrate TrancheMate's compliance with this DPA, subject to reasonable conditions described in section 11.

4. Firm's obligations as Controller

The Firm, as Controller of Firm Data, is responsible for:

5. Sub-processors

TrancheMate uses the following sub-processors to deliver the Services. All sub-processors handling Firm Data operate infrastructure located in Australia (ap-southeast-2 Sydney region) or are engaged solely for payment processing, where Australian residency requirements do not apply to card data.

Sub-processor Role Data involved Location
Akamai Technologies Hosting infrastructure, file storage All Firm Data, including uploaded identity documents Sydney, Australia (ap-southeast-2). ISO 27001:2022 and SOC 2 Type II certified.
Stripe Inc. Payment processing Subscription billing data only. Card numbers are handled exclusively by Stripe and never pass through TrancheMate's systems. PCI DSS Level 1 certified. See Stripe's Privacy Policy.
SMTP email delivery provider Transactional email delivery Recipient email address, name, and email content (compliance reminders, CDD intake links, account notifications) Subject to provider's terms. No Firm CDD records, identity documents, or SMR data are transmitted via email.

5.1 Changes to sub-processors

TrancheMate will provide at least 30 days' notice before adding or replacing a sub-processor. Notice will be provided by updating this DPA and emailing active Firm principals. If the Firm reasonably objects to a new sub-processor on privacy grounds, it may terminate its subscription in accordance with the Terms of Service within the 30-day notice period and receive a pro-rata refund.

6. Security measures

TrancheMate implements and maintains the following technical and organisational measures to protect Firm Data:

6.1 Technical measures

6.2 Organisational measures

6.3 Firm responsibility

The Firm is responsible for the security of its user accounts, including the strength of passwords chosen by its staff and the prompt removal of access for departing employees.

7. Data breach notification

7.1 Notification to the Firm

TrancheMate will notify the Firm without undue delay — and in any event within 72 hours of TrancheMate becoming aware of a security incident involving Firm Data — where that incident is likely to constitute an Eligible Data Breach under the NDB Scheme. Notification will be provided to the email address of the Firm's principal on record.

The notification will include, to the extent then known:

Where full information is not available within 72 hours, TrancheMate will provide an initial notification with available information and supplement it as further details are confirmed.

7.2 NDB Scheme obligations

Under the Privacy Act 1988 (Cth) NDB Scheme (Part IIIC), where an Eligible Data Breach occurs:

7.3 Incident response cooperation

TrancheMate will cooperate in good faith with the Firm's reasonable requests for information, assistance, and access in responding to a data security incident. TrancheMate will take reasonable steps to contain the incident and prevent further unauthorised access or disclosure.

8. Assistance with individual rights

TrancheMate will, taking into account the nature of the processing, assist the Firm in responding to requests from individuals exercising their rights under the Privacy Act, including:

9. Australian data residency

All Firm Data — including CDD records, client identity documents, AML/CTF program content, SMR/TTR records, and account information — is stored exclusively on infrastructure located in Sydney, Australia (Akamai ap-southeast-2). No Firm Data is transferred to, processed in, or stored in overseas systems.

Australian data residency is a material compliance consideration for professional services firms subject to the Privacy Act and the AML/CTF Act. TrancheMate treats it as a non-negotiable architectural constraint.

TrancheMate will not transfer Firm Data outside of Australia without the Firm's prior written consent, except where required to do so by an Australian court order or regulatory requirement, in which case TrancheMate will notify the Firm before transferring (unless prohibited by law).

This commitment is consistent with APP 8 (cross-border disclosure of personal information), which requires entities to take reasonable steps to ensure overseas recipients handle personal information consistently with the Australian Privacy Principles. By keeping all data in Australia, this obligation does not arise in ordinary operations.

10. Return and deletion of data

10.1 During the subscription

The Firm may export its compliance data at any time using the Audit Export module, which generates a complete compliance archive in PDF and CSV formats.

10.2 On subscription cancellation or expiry

Following cancellation or expiry of the subscription:

10.3 Deletion confirmation

On request, TrancheMate will provide written confirmation that Firm Data has been deleted from active systems following account closure.

11. Audit and inspection rights

The Firm may, upon reasonable written notice (no less than 30 days) and no more than once per calendar year, request documentation from TrancheMate demonstrating compliance with this DPA. TrancheMate will respond to such requests by providing:

Physical or remote access to TrancheMate's systems is not included in these audit rights. TrancheMate may decline requests that it considers unreasonable or that would compromise the security of other Firms' data. All audit correspondence should be directed to [email protected].

12. Duration and termination

This DPA is effective from the date the Firm accepts the Terms of Service and remains in force for the duration of the Firm's subscription.

This DPA terminates automatically upon expiry or termination of the subscription. Termination of this DPA does not affect any accrued rights or obligations, and clauses that by their nature survive termination (including data retention obligations under clause 10 and confidentiality obligations) will continue to apply.

Either party may terminate the subscription in accordance with the Terms of Service. The Firm's right to a pro-rata refund on early termination is set out in the Terms of Service.

13. Liability and indemnification

TrancheMate's liability under this DPA is subject to the limitations set out in the Terms of Service (Limitation of Liability).

Each party is responsible for its own obligations under the Privacy Act. The Firm indemnifies TrancheMate against any liability arising from the Firm's failure to comply with its Controller obligations, including failure to provide adequate collection notices to its clients or failure to maintain lawful basis for the collection of client personal information.

Nothing in this DPA limits either party's liability for fraud, wilful misconduct, or any liability that cannot be excluded or limited by applicable Australian law.

14. Governing law

This DPA is governed by the laws of New South Wales, Australia. The parties submit to the non-exclusive jurisdiction of the courts of New South Wales and the federal courts of Australia.

This DPA is to be read in conjunction with the Privacy Act 1988 (Cth). In the event of any inconsistency between this DPA and the Privacy Act, the Privacy Act prevails.

15. Updates to this agreement

TrancheMate may update this DPA from time to time to reflect changes in processing activities, sub-processors, applicable law, or regulatory guidance.

For material changes, TrancheMate will:

For sub-processor changes specifically, the 30-day notice and objection rights described in section 5.1 apply.

Continued use of TrancheMate after the effective date of a revised DPA constitutes acceptance of the updated terms.

Data processing enquiries

For questions about this DPA, data processing activities, access requests, breach reporting, or audit enquiries:

TrancheMate
ABN 74 421 798 989
Email: [email protected]
Subject line: "Data Processing Enquiry"

This agreement is governed by the laws of New South Wales, Australia and the Privacy Act 1988 (Cth). It is not subject to the EU General Data Protection Regulation (GDPR) — TrancheMate operates exclusively under Australian law.