Skip to main content

Legal

Data Processing Addendum

Draft β€” pending legal review

This document is a working draft prepared as a starting point, not a lawyer-reviewed or binding agreement. It does not yet govern any account or subscription. Bracketed items (like our registered entity name and ABN) are placeholders pending company registration. Draft dated draft, not yet published.

This Data Processing Addendum ("DPA") forms part of the Terms of Service between [Eidon Pty Ltd, ACN/ABN pending] ("Processor", "we") and the Customer ("Controller", "you"), and applies to the extent we process personal data contained within your Customer Data on your behalf. It is written to reflect the roles set out under the GDPR and the Privacy Act 1988 (Cth).

1. Roles

You are the controller of any personal data within your Customer Data; we are a processor acting only on your documented instructions, given through your configuration and use of the Service, and as set out in this DPA.

2. Subject matter and duration

We process personal data within Customer Data for the duration of your subscription (including any cancellation grace period), for the purpose of providing, securing and supporting the Service, and for no other purpose.

3. Nature and categories of data

The nature of processing is storage, retrieval, transmission and display of whatever records you choose to create within your workspace (for example: architecture entities, service design artifacts, engagement and stakeholder records, diagrams). The categories of data subject and personal data involved depend entirely on what you and your users choose to enter β€” typically your own personnel, stakeholders and business contacts, limited to what a Customer chooses to record (for example, a name or role attached to an engagement or stakeholder plan).

4. Sub-processors

We use a limited set of sub-processors, published and kept current on our security page. As of this draft: Stripe (payment processing only, not Customer Data). We do not use a bundled email sub-processor β€” outbound email runs through SMTP credentials you configure yourself, at your own instruction. If you enable an optional integration (Jira, Azure DevOps, Confluence, an SSO/OIDC provider, or AI-assisted drafting), the destination or AI provider you configure becomes a processor you instruct directly, not an Eidon sub-processor, since we do not choose that destination for you. We will give reasonable notice of any new sub-processor added to the Service itself and an opportunity to object on reasonable grounds.

5. Security measures

We maintain the technical and organisational measures described on our security page, including workspace-level data isolation, encryption of secrets at rest, role-based access control, and an audit trail of changes to governed artifacts.

6. Data subject requests

Where we receive a request from a data subject relating to personal data within your Customer Data, we will promptly forward it to you and, at your written request, provide reasonable assistance to help you respond, using the export and account-management tools already available in the product where possible.

7. Personal data breach

We will notify you without undue delay after becoming aware of a personal data breach affecting your Customer Data, and provide information reasonably available to us to help you meet your own notification obligations.

8. International transfers

Where personal data within Customer Data is transferred outside the region it was collected in (for example, via a sub-processor listed in section 4), we will apply an appropriate transfer mechanism β€” such as GDPR standard contractual clauses β€” as applicable, once our hosting arrangements are finalised.

9. Deletion or return of data

On termination of your subscription and after the cancellation grace period described in our Terms of Service, we will delete Customer Data, except to the extent we are required by law to retain it. You may export your data at any time before that point using the product's own export tools.

10. Audit

On reasonable written request, no more than once per year, we will make available information reasonably necessary to demonstrate compliance with this DPA, such as summaries of relevant security documentation.

11. Contact

Questions about this DPA can be sent to [privacy@eidon.example.com].