Ozibus
  • Home
  • About Us
  • Contact Us
  • Products
    • Broadcast
    • Chat
    • Scheduling
  • Services
    • Emailing
    • Newsletter Subscriptions
    • OTP
    • SMS
  • Pricing
  • Documentation
Sign In Get Started
  • Home
  • About Us
  • Contact Us
  • Products
    • Broadcast
    • Chat
    • Scheduling
  • Services
    • Emailing
    • Newsletter Subscriptions
    • OTP
    • SMS
  • Pricing
  • Documentation
  • Product Guide
Get Started Sign In
Home Legal Centre Data Processing Addendum
Privacy & data ยท Document 04

Data Processing Addendum (DPA)

Customer and Ozibus responsibilities for processing Customer Data, security, subprocessors, incidents and international transfers.

All policies
Versionv1 Updated23 August 2026 EntityOZIBUS PTY LTD ABN29 680 267 083
Legal library
01 Privacy 02 Terms of Service 03 Acceptable Use 04 Data Processing Addendum 05 Hosting & Subprocessors 06 Cookies & Tracking 07 Security Disclosure 08 Service Level & Support 09 Health & Sensitive Data 10 Messaging Compliance 11 Billing & Account Balance 12 API & Developer Terms 13 APP 5 Notices 14 Publication & Governance

This document forms part of the Ozibus Public Website Legal Centre. It should be read together with other policies that apply to the services and channels you use.

This Data Processing Addendum forms part of the agreement between OZIBUS PTY LTD (ABN 29 680 267 083) ("Ozibus") and the customer that uses Ozibus to process personal information ("Customer"). It applies to Customer Data that constitutes personal information or personal data under applicable privacy or data-protection law.

4.1 Roles and scope

For Customer Data, Customer generally determines the purposes for which the information is collected and used, and Ozibus processes that information to provide, secure and support the Services. Where a law uses the concepts "controller" and "processor", Customer will generally be the controller and Ozibus the processor for Customer Data, except where Ozibus independently determines a purpose permitted by law, such as security, fraud prevention, billing, legal compliance or service integrity.

4.2 Customer instructions

Ozibus will process Customer Data on Customer's documented instructions as expressed in the Agreement, Customer's configuration and use of the Services, support requests, and other written instructions that are consistent with the Services and applicable law. Ozibus may refuse an instruction that it reasonably believes is unlawful, technically unsafe or outside the agreed Services and will explain the reason where legally permitted.

4.3 Customer responsibilities

  • ensure Customer Data was lawfully collected and may lawfully be provided to Ozibus;
  • provide all required privacy notices and obtain consent or other authority required for SMS, email, WhatsApp Business messaging, marketing, scheduling, tracking or other processing;
  • configure the Services appropriately for the sensitivity of the information involved;
  • protect Customer credentials, API keys and endpoints; and
  • avoid submitting restricted or regulated data unless the applicable Ozibus service, the relevant third-party channel rules and written terms permit it.

4.4 Confidentiality and personnel

Ozibus will limit access to Customer Data to personnel and authorised contractors who require access for legitimate service, support, security or compliance purposes and who are subject to appropriate confidentiality obligations.

4.5 Security measures

Ozibus will maintain technical and organisational measures designed to protect Customer Data against unauthorised access, use, alteration, disclosure, loss or destruction, taking into account the nature of the data, available technology, implementation cost and relevant risks. The measures may include access controls, authentication, encryption in transit, encryption at rest for designated systems, secrets management, logging, rate limiting, backups, vulnerability management, monitoring, secure development practices and incident response.

Customer acknowledges that ordinary SMS delivery traverses telecommunications networks and is not represented by Ozibus as end-to-end encrypted.

For WhatsApp Business messaging, channel encryption and security features are provided and controlled by WhatsApp/Meta. Once message content or metadata is made available to Ozibus, Customer or another authorised integration endpoint, that subsequent processing is governed by the security controls applicable to that environment and should not be described as remaining end-to-end encrypted merely because WhatsApp was used as the transport channel.

4.6 Subprocessors

Customer gives Ozibus general authorisation to use subprocessors to provide the Services. Ozibus will impose data-protection and confidentiality obligations on material subprocessors appropriate to the services they perform. Ozibus will maintain a public or customer-accessible list of material subprocessors and their principal processing locations. Where reasonably practicable, Ozibus will give advance notice of a material new subprocessor. A Customer with a reasonable data-protection objection should notify Ozibus promptly so the parties can discuss an appropriate solution.

Where SMS or WhatsApp Business messaging is enabled, Customer authorises the disclosures and processing reasonably necessary to route communications through Twilio, telecommunications carriers and, for WhatsApp, Meta/WhatsApp infrastructure. Ozibus currently uses Twilio as an underlying provider for both SMS and WhatsApp Business messaging. Those providers may also process information under their own applicable terms, policies and data-processing documentation.

Where Ozibus email delivery is enabled, Customer authorises the processing reasonably necessary through Ozibus's Namecheap-hosted private email infrastructure and recipient email systems. Namecheap and other email infrastructure providers may process information under their applicable terms, privacy documentation and technical requirements.

Customer acknowledges that enabling a third-party messaging channel does not make Ozibus responsible for the independent operation, policy enforcement, service availability or processing practices of that third-party platform beyond Ozibus's own contractual and legal obligations.

4.7 Overseas processing

Ozibus is an Australian company. Its primary hosting infrastructure is currently located in Phoenix, Arizona, United States. Customer Data may therefore be stored or processed in the United States and may also transit or be processed in other countries by Twilio, Namecheap-hosted email infrastructure, Stripe, telecommunications carriers, Meta/WhatsApp, recipient networks or other providers required to deliver the Services. Ozibus will take reasonable steps required by applicable Australian privacy law in relation to overseas disclosures and will maintain appropriate contractual, security and due-diligence controls for material providers.

4.8 Assistance with individual rights

Taking into account the nature of the processing, Ozibus will provide reasonable assistance to Customer with requests relating to access, correction, deletion or other individual rights where the relevant information is Customer Data and Customer cannot reasonably fulfil the request using the Services. Ozibus may refer a requester to the relevant Customer where Customer controls the information.

4.9 Data incidents and breach notification

Ozibus will maintain a process for identifying, containing, assessing and responding to confirmed security incidents involving Customer Data. Ozibus will notify affected Customers without undue delay after becoming aware of a confirmed incident affecting their Customer Data where notification is required by law or the Agreement, and will provide information reasonably available to assist Customer with its assessment and notification obligations. Notification does not constitute an admission of fault or liability.

4.10 Regulatory and assessment assistance

Where reasonably required by applicable law and proportionate to the Services, Ozibus will provide information reasonably necessary to assist Customer with privacy impact assessments, regulator enquiries or consultations relating to Ozibus processing. Additional work beyond standard documentation and support may be chargeable if agreed in advance.

4.11 Government and legal requests

Ozibus may disclose information where required by valid legal process or applicable law. Where legally permitted and reasonably practicable, Ozibus will direct a request for Customer Data to Customer or notify Customer before disclosure. Ozibus will not voluntarily provide Customer Data to a government authority for unrelated purposes.

4.12 Return and deletion

During the applicable service term, Customer may use available export functionality to retrieve Customer Data. After termination, Ozibus may delete or de-identify Customer Data in accordance with its retention schedule, subject to backups, legal holds, security requirements and records Ozibus must retain by law. Where required by a written enterprise agreement, Ozibus will provide reasonable return or deletion assistance.

4.13 Audit information

Ozibus will make available reasonable information about its privacy and security controls to demonstrate compliance with this DPA. Where additional audit rights are legally required and cannot reasonably be satisfied through existing documentation, the parties will agree a proportionate audit process that protects other customers, security information and confidential information. Customer will bear its own audit costs unless otherwise required by law or agreed in writing.

4.14 Health and sensitive information

Health information, biometric information and other sensitive information may be subject to additional restrictions. Customer must not use Ozibus for such information unless it is legally permitted and the applicable Ozibus service and contract allow it. The Ozibus Health & Sensitive Data Addendum applies where incorporated into the Customer's agreement.

4.15 International privacy regimes

If Customer is subject to privacy laws outside Australia, the parties will cooperate in good faith to implement any additional mandatory contractual mechanism required for the relevant transfer or processing. This DPA does not, by itself, represent that Ozibus is certified under or automatically subject to every overseas privacy framework.

4.16 Order of precedence and term

If this DPA conflicts with the general Terms of Service on the handling of Customer Data, this DPA prevails to the extent of the conflict. It remains effective for as long as Ozibus processes Customer Data on Customer's behalf, including any lawful retention period after termination.

Schedule 1 - Processing details

ItemDescription
Subject matterBusiness communications, SMS, email, WhatsApp Business messaging, scheduling, webchat, broadcasting, verification, analytics, APIs, webhooks and related customer-configured services.
DurationFor the applicable service term and post-termination retention period.
Nature of processingCollection, storage, transmission, retrieval, organisation, delivery, logging, support, security monitoring, deletion and other processing necessary to provide the Services.
People concernedCustomer users, employees, clients, contacts, recipients, website/chat visitors, booking participants and other people whose information Customer submits.
Data typesNames, contact details, telephone numbers, WhatsApp identifiers and business-account metadata, account identifiers, message content and attachments, chat transcripts, bookings, consent/opt-out records, message/template/status metadata, device/IP data, delivery metadata, API/webhook logs and other Customer-submitted information.
Sensitive dataOnly where lawfully authorised and permitted by the relevant Ozibus service and agreement.

Schedule 2 - Baseline security controls

  • role-based and least-privilege access controls;
  • multi-factor authentication for privileged access where supported;
  • secure handling and rotation of secrets and API credentials;
  • TLS or equivalent encrypted transport for supported network connections;
  • security logging and monitoring appropriate to the service;
  • rate limiting, abuse controls and anomaly detection where appropriate;
  • patching and vulnerability remediation based on risk;
  • backup and recovery procedures;
  • incident-response procedures; and
  • vendor and subprocessor due diligence proportionate to risk.
Previous Acceptable Use Next Hosting & Subprocessors
On this page
4.1 Roles and scope 4.2 Customer instructions 4.3 Customer responsibilities 4.4 Confidentiality and personnel 4.5 Security measures 4.6 Subprocessors 4.7 Overseas processing 4.8 Assistance with individual rights 4.9 Data incidents and breach notification 4.10 Regulatory and assessment assistance 4.11 Government and legal requests 4.12 Return and deletion 4.13 Audit information 4.14 Health and sensitive information 4.15 International privacy regimes 4.16 Order of precedence and term Schedule 1 - Processing details Schedule 2 - Baseline security controls
Questions?Contact Ozibus
Ozibus suite

Customer operations, connected from first ping to booked outcome.

Book a Demo View Pricing
Messaging SMS, email, WhatsApp
Serve Chat, tickets, AI assist
Schedule Bookings, reminders, queues
O Ozibus

One client-facing operations suite for messaging, scheduling, live chat, verification, customer data, and service workflows.

API ready Client facing Ops aligned

Suite

  • Ozibus App
  • Customer Chat
  • Scheduling
  • Broadcast
  • Contacts & Audiences

Channels

  • SMS
  • Email Delivery
  • Verify & OTP
  • WhatsApp
  • All Services

Resources

  • Documentation
  • API Reference
  • Guides
  • Product Guide
  • System Status

Company

  • Pricing
  • About Us
  • Book a Demo
  • Contact Us
  • Sign In

Legal

  • Legal Centre
  • Privacy Policy
  • Terms of Service
  • Acceptable Use
  • Data Processing Addendum

© 2026 Ozibus. All rights reserved. Legal Centre · Privacy Policy · Terms of Service · Powered by Ikemba Tech