This document forms part of the Ozibus Public Website Legal Centre. It should be read together with other policies that apply to the services and channels you use.
This Data Processing Addendum forms part of the agreement between OZIBUS PTY LTD (ABN 29 680 267 083) ("Ozibus") and the customer that uses Ozibus to process personal information ("Customer"). It applies to Customer Data that constitutes personal information or personal data under applicable privacy or data-protection law.
4.1 Roles and scope
For Customer Data, Customer generally determines the purposes for which the information is collected and used, and Ozibus processes that information to provide, secure and support the Services. Where a law uses the concepts "controller" and "processor", Customer will generally be the controller and Ozibus the processor for Customer Data, except where Ozibus independently determines a purpose permitted by law, such as security, fraud prevention, billing, legal compliance or service integrity.
4.2 Customer instructions
Ozibus will process Customer Data on Customer's documented instructions as expressed in the Agreement, Customer's configuration and use of the Services, support requests, and other written instructions that are consistent with the Services and applicable law. Ozibus may refuse an instruction that it reasonably believes is unlawful, technically unsafe or outside the agreed Services and will explain the reason where legally permitted.
4.3 Customer responsibilities
- ensure Customer Data was lawfully collected and may lawfully be provided to Ozibus;
- provide all required privacy notices and obtain consent or other authority required for SMS, email, WhatsApp Business messaging, marketing, scheduling, tracking or other processing;
- configure the Services appropriately for the sensitivity of the information involved;
- protect Customer credentials, API keys and endpoints; and
- avoid submitting restricted or regulated data unless the applicable Ozibus service, the relevant third-party channel rules and written terms permit it.
4.4 Confidentiality and personnel
Ozibus will limit access to Customer Data to personnel and authorised contractors who require access for legitimate service, support, security or compliance purposes and who are subject to appropriate confidentiality obligations.
4.5 Security measures
Ozibus will maintain technical and organisational measures designed to protect Customer Data against unauthorised access, use, alteration, disclosure, loss or destruction, taking into account the nature of the data, available technology, implementation cost and relevant risks. The measures may include access controls, authentication, encryption in transit, encryption at rest for designated systems, secrets management, logging, rate limiting, backups, vulnerability management, monitoring, secure development practices and incident response.
Customer acknowledges that ordinary SMS delivery traverses telecommunications networks and is not represented by Ozibus as end-to-end encrypted.
For WhatsApp Business messaging, channel encryption and security features are provided and controlled by WhatsApp/Meta. Once message content or metadata is made available to Ozibus, Customer or another authorised integration endpoint, that subsequent processing is governed by the security controls applicable to that environment and should not be described as remaining end-to-end encrypted merely because WhatsApp was used as the transport channel.
4.6 Subprocessors
Customer gives Ozibus general authorisation to use subprocessors to provide the Services. Ozibus will impose data-protection and confidentiality obligations on material subprocessors appropriate to the services they perform. Ozibus will maintain a public or customer-accessible list of material subprocessors and their principal processing locations. Where reasonably practicable, Ozibus will give advance notice of a material new subprocessor. A Customer with a reasonable data-protection objection should notify Ozibus promptly so the parties can discuss an appropriate solution.
Where SMS or WhatsApp Business messaging is enabled, Customer authorises the disclosures and processing reasonably necessary to route communications through Twilio, telecommunications carriers and, for WhatsApp, Meta/WhatsApp infrastructure. Ozibus currently uses Twilio as an underlying provider for both SMS and WhatsApp Business messaging. Those providers may also process information under their own applicable terms, policies and data-processing documentation.
Where Ozibus email delivery is enabled, Customer authorises the processing reasonably necessary through Ozibus's Namecheap-hosted private email infrastructure and recipient email systems. Namecheap and other email infrastructure providers may process information under their applicable terms, privacy documentation and technical requirements.
Customer acknowledges that enabling a third-party messaging channel does not make Ozibus responsible for the independent operation, policy enforcement, service availability or processing practices of that third-party platform beyond Ozibus's own contractual and legal obligations.
4.7 Overseas processing
Ozibus is an Australian company. Its primary hosting infrastructure is currently located in Phoenix, Arizona, United States. Customer Data may therefore be stored or processed in the United States and may also transit or be processed in other countries by Twilio, Namecheap-hosted email infrastructure, Stripe, telecommunications carriers, Meta/WhatsApp, recipient networks or other providers required to deliver the Services. Ozibus will take reasonable steps required by applicable Australian privacy law in relation to overseas disclosures and will maintain appropriate contractual, security and due-diligence controls for material providers.
4.8 Assistance with individual rights
Taking into account the nature of the processing, Ozibus will provide reasonable assistance to Customer with requests relating to access, correction, deletion or other individual rights where the relevant information is Customer Data and Customer cannot reasonably fulfil the request using the Services. Ozibus may refer a requester to the relevant Customer where Customer controls the information.
4.9 Data incidents and breach notification
Ozibus will maintain a process for identifying, containing, assessing and responding to confirmed security incidents involving Customer Data. Ozibus will notify affected Customers without undue delay after becoming aware of a confirmed incident affecting their Customer Data where notification is required by law or the Agreement, and will provide information reasonably available to assist Customer with its assessment and notification obligations. Notification does not constitute an admission of fault or liability.
4.10 Regulatory and assessment assistance
Where reasonably required by applicable law and proportionate to the Services, Ozibus will provide information reasonably necessary to assist Customer with privacy impact assessments, regulator enquiries or consultations relating to Ozibus processing. Additional work beyond standard documentation and support may be chargeable if agreed in advance.
4.11 Government and legal requests
Ozibus may disclose information where required by valid legal process or applicable law. Where legally permitted and reasonably practicable, Ozibus will direct a request for Customer Data to Customer or notify Customer before disclosure. Ozibus will not voluntarily provide Customer Data to a government authority for unrelated purposes.
4.12 Return and deletion
During the applicable service term, Customer may use available export functionality to retrieve Customer Data. After termination, Ozibus may delete or de-identify Customer Data in accordance with its retention schedule, subject to backups, legal holds, security requirements and records Ozibus must retain by law. Where required by a written enterprise agreement, Ozibus will provide reasonable return or deletion assistance.
4.13 Audit information
Ozibus will make available reasonable information about its privacy and security controls to demonstrate compliance with this DPA. Where additional audit rights are legally required and cannot reasonably be satisfied through existing documentation, the parties will agree a proportionate audit process that protects other customers, security information and confidential information. Customer will bear its own audit costs unless otherwise required by law or agreed in writing.
4.14 Health and sensitive information
Health information, biometric information and other sensitive information may be subject to additional restrictions. Customer must not use Ozibus for such information unless it is legally permitted and the applicable Ozibus service and contract allow it. The Ozibus Health & Sensitive Data Addendum applies where incorporated into the Customer's agreement.
4.15 International privacy regimes
If Customer is subject to privacy laws outside Australia, the parties will cooperate in good faith to implement any additional mandatory contractual mechanism required for the relevant transfer or processing. This DPA does not, by itself, represent that Ozibus is certified under or automatically subject to every overseas privacy framework.
4.16 Order of precedence and term
If this DPA conflicts with the general Terms of Service on the handling of Customer Data, this DPA prevails to the extent of the conflict. It remains effective for as long as Ozibus processes Customer Data on Customer's behalf, including any lawful retention period after termination.
Schedule 1 - Processing details
| Item | Description |
|---|---|
| Subject matter | Business communications, SMS, email, WhatsApp Business messaging, scheduling, webchat, broadcasting, verification, analytics, APIs, webhooks and related customer-configured services. |
| Duration | For the applicable service term and post-termination retention period. |
| Nature of processing | Collection, storage, transmission, retrieval, organisation, delivery, logging, support, security monitoring, deletion and other processing necessary to provide the Services. |
| People concerned | Customer users, employees, clients, contacts, recipients, website/chat visitors, booking participants and other people whose information Customer submits. |
| Data types | Names, contact details, telephone numbers, WhatsApp identifiers and business-account metadata, account identifiers, message content and attachments, chat transcripts, bookings, consent/opt-out records, message/template/status metadata, device/IP data, delivery metadata, API/webhook logs and other Customer-submitted information. |
| Sensitive data | Only where lawfully authorised and permitted by the relevant Ozibus service and agreement. |
Schedule 2 - Baseline security controls
- role-based and least-privilege access controls;
- multi-factor authentication for privileged access where supported;
- secure handling and rotation of secrets and API credentials;
- TLS or equivalent encrypted transport for supported network connections;
- security logging and monitoring appropriate to the service;
- rate limiting, abuse controls and anomaly detection where appropriate;
- patching and vulnerability remediation based on risk;
- backup and recovery procedures;
- incident-response procedures; and
- vendor and subprocessor due diligence proportionate to risk.