How TrancheMate processes personal information on behalf of subscriber Firms
Last updated: 10 June 2026 · Effective: 10 June 2026
This Data Processing Agreement ("DPA") is entered into between TrancheMate (ABN 74 421 798 989) ("TrancheMate", "Processor") and the subscribing professional services firm ("Firm", "Controller") that has accepted the Terms of Service. This DPA forms part of and is incorporated into the Terms of Service. It governs the processing of personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
This DPA is not legal advice. It is a disclosure document explaining how TrancheMate handles personal information on your Firm's behalf. If your Firm has specific legal requirements — for example, under a professional indemnity insurance policy, an engagement contract with a large client, or a specific regulatory requirement — you should seek independent legal advice from a qualified Australian solicitor.
In this DPA, unless the context otherwise requires:
TrancheMate processes Firm Data on behalf of the Firm for the purpose of delivering the Services. The processing activities are:
| Module | Data processed | Purpose |
|---|---|---|
| AML/CTF Program Builder | Firm details, compliance officer name, business structure, designated services | Generate and store the Firm's AML/CTF Program document |
| Client CDD Hub | Client names, dates of birth, addresses, photo identity documents, entity structures, beneficial ownership information, PEP declarations, source of funds declarations | Facilitate AML/CTF customer due diligence on behalf of the Firm; store immutable CDD records |
| Compliance Calendar | Compliance officer name, obligation dates, reminder preferences | Track and remind the Firm of AML/CTF compliance obligations |
| SMR & Transaction Log | Client references, transaction descriptions, AUSTRAC reference numbers, staff names | Maintain an immutable SMR/TTR audit log on behalf of the Firm |
| Audit Export | All of the above | Compile a compliance evidence package for AUSTRAC audits or insurance renewals |
Personal information processed under this DPA relates to:
TrancheMate processes Firm Data only on the documented instructions of the Firm, as reflected in the Firm's use of the platform features. The Firm's act of initiating a processing activity (for example, sending a CDD intake form to a client) constitutes an instruction for that processing.
TrancheMate will notify the Firm if it believes any instruction would cause TrancheMate to breach the Privacy Act or any other applicable Australian law.
In processing Firm Data, TrancheMate will:
Process Firm Data only on the Firm's documented instructions and only for the purposes described in this DPA and the Terms of Service, unless required to do so by applicable Australian law (in which case TrancheMate will notify the Firm of that legal requirement before processing, unless the law prohibits such notification).
Ensure that staff who access Firm Data are bound by confidentiality obligations and are provided access only to the Firm Data necessary to perform their role.
Implement and maintain the technical and organisational security measures described in section 6 of this DPA, and in TrancheMate's Privacy Policy (section 7).
Only engage sub-processors as set out in section 5 of this DPA, and ensure each sub-processor is bound by obligations equivalent to those in this DPA with respect to the protection of Firm Data.
Assist the Firm in meeting its obligations to individuals under the Privacy Act, including access, correction, and complaint handling, as described in section 8 of this DPA.
Notify the Firm without undue delay upon becoming aware of a security incident affecting Firm Data, as described in section 7 of this DPA.
On termination of the subscription, handle Firm Data as set out in section 10 of this DPA.
Provide the Firm with information reasonably necessary to demonstrate TrancheMate's compliance with this DPA, subject to reasonable conditions described in section 11.
The Firm, as Controller of Firm Data, is responsible for:
TrancheMate uses the following sub-processors to deliver the Services. All sub-processors handling Firm Data operate infrastructure located in Australia (ap-southeast-2 Sydney region) or are engaged solely for payment processing, where Australian residency requirements do not apply to card data.
| Sub-processor | Role | Data involved | Location |
|---|---|---|---|
| Akamai Technologies | Hosting infrastructure, file storage | All Firm Data, including uploaded identity documents | Sydney, Australia (ap-southeast-2). ISO 27001:2022 and SOC 2 Type II certified. |
| Stripe Inc. | Payment processing | Subscription billing data only. Card numbers are handled exclusively by Stripe and never pass through TrancheMate's systems. | PCI DSS Level 1 certified. See Stripe's Privacy Policy. |
| SMTP email delivery provider | Transactional email delivery | Recipient email address, name, and email content (compliance reminders, CDD intake links, account notifications) | Subject to provider's terms. No Firm CDD records, identity documents, or SMR data are transmitted via email. |
TrancheMate will provide at least 30 days' notice before adding or replacing a sub-processor. Notice will be provided by updating this DPA and emailing active Firm principals. If the Firm reasonably objects to a new sub-processor on privacy grounds, it may terminate its subscription in accordance with the Terms of Service within the 30-day notice period and receive a pro-rata refund.
TrancheMate implements and maintains the following technical and organisational measures to protect Firm Data:
The Firm is responsible for the security of its user accounts, including the strength of passwords chosen by its staff and the prompt removal of access for departing employees.
TrancheMate will notify the Firm without undue delay — and in any event within 72 hours of TrancheMate becoming aware of a security incident involving Firm Data — where that incident is likely to constitute an Eligible Data Breach under the NDB Scheme. Notification will be provided to the email address of the Firm's principal on record.
The notification will include, to the extent then known:
Where full information is not available within 72 hours, TrancheMate will provide an initial notification with available information and supplement it as further details are confirmed.
Under the Privacy Act 1988 (Cth) NDB Scheme (Part IIIC), where an Eligible Data Breach occurs:
TrancheMate will cooperate in good faith with the Firm's reasonable requests for information, assistance, and access in responding to a data security incident. TrancheMate will take reasonable steps to contain the incident and prevent further unauthorised access or disclosure.
TrancheMate will, taking into account the nature of the processing, assist the Firm in responding to requests from individuals exercising their rights under the Privacy Act, including:
All Firm Data — including CDD records, client identity documents, AML/CTF program content, SMR/TTR records, and account information — is stored exclusively on infrastructure located in Sydney, Australia (Akamai ap-southeast-2). No Firm Data is transferred to, processed in, or stored in overseas systems.
Australian data residency is a material compliance consideration for professional services firms subject to the Privacy Act and the AML/CTF Act. TrancheMate treats it as a non-negotiable architectural constraint.
TrancheMate will not transfer Firm Data outside of Australia without the Firm's prior written consent, except where required to do so by an Australian court order or regulatory requirement, in which case TrancheMate will notify the Firm before transferring (unless prohibited by law).
This commitment is consistent with APP 8 (cross-border disclosure of personal information), which requires entities to take reasonable steps to ensure overseas recipients handle personal information consistently with the Australian Privacy Principles. By keeping all data in Australia, this obligation does not arise in ordinary operations.
The Firm may export its compliance data at any time using the Audit Export module, which generates a complete compliance archive in PDF and CSV formats.
Following cancellation or expiry of the subscription:
On request, TrancheMate will provide written confirmation that Firm Data has been deleted from active systems following account closure.
The Firm may, upon reasonable written notice (no less than 30 days) and no more than once per calendar year, request documentation from TrancheMate demonstrating compliance with this DPA. TrancheMate will respond to such requests by providing:
Physical or remote access to TrancheMate's systems is not included in these audit rights. TrancheMate may decline requests that it considers unreasonable or that would compromise the security of other Firms' data. All audit correspondence should be directed to [email protected].
This DPA is effective from the date the Firm accepts the Terms of Service and remains in force for the duration of the Firm's subscription.
This DPA terminates automatically upon expiry or termination of the subscription. Termination of this DPA does not affect any accrued rights or obligations, and clauses that by their nature survive termination (including data retention obligations under clause 10 and confidentiality obligations) will continue to apply.
Either party may terminate the subscription in accordance with the Terms of Service. The Firm's right to a pro-rata refund on early termination is set out in the Terms of Service.
TrancheMate's liability under this DPA is subject to the limitations set out in the Terms of Service (Limitation of Liability).
Each party is responsible for its own obligations under the Privacy Act. The Firm indemnifies TrancheMate against any liability arising from the Firm's failure to comply with its Controller obligations, including failure to provide adequate collection notices to its clients or failure to maintain lawful basis for the collection of client personal information.
Nothing in this DPA limits either party's liability for fraud, wilful misconduct, or any liability that cannot be excluded or limited by applicable Australian law.
This DPA is governed by the laws of New South Wales, Australia. The parties submit to the non-exclusive jurisdiction of the courts of New South Wales and the federal courts of Australia.
This DPA is to be read in conjunction with the Privacy Act 1988 (Cth). In the event of any inconsistency between this DPA and the Privacy Act, the Privacy Act prevails.
TrancheMate may update this DPA from time to time to reflect changes in processing activities, sub-processors, applicable law, or regulatory guidance.
For material changes, TrancheMate will:
For sub-processor changes specifically, the 30-day notice and objection rights described in section 5.1 apply.
Continued use of TrancheMate after the effective date of a revised DPA constitutes acceptance of the updated terms.
For questions about this DPA, data processing activities, access requests, breach reporting, or audit enquiries:
TrancheMate
ABN 74 421 798 989
Email: [email protected]
Subject line: "Data Processing Enquiry"
This agreement is governed by the laws of New South Wales, Australia and the Privacy Act 1988 (Cth). It is not subject to the EU General Data Protection Regulation (GDPR) — TrancheMate operates exclusively under Australian law.