Data Processing Agreement
RR Sols Pty Ltd t/a WattleAddr · ABN 56 672 722 486 · Last updated 4 September 2026
This Data Processing Agreement (DPA) forms part of the agreement between the Customer and RR Sols Pty Ltd (ABN 56 672 722 486) t/a WattleAddr and governs our handling of personal information on the Customer's behalf. It applies to every workspace from the moment it is created, with no signature needed. All processing occurs within Australia.
1. Scope and roles
This DPA applies where WattleAddr ("WattleAddr", "we") processes personal information on behalf of the Customer ("you") in providing the Service. In respect of End User Data submitted to the Service, you decide why it is collected and how it is used; we handle it only to provide the Service on your instructions. Australian law does not distinguish "controllers" from "processors": each of us holds the data and each is directly responsible for its own obligations under the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs) and the Notifiable Data Breaches scheme. We use the words "process" and "on your behalf" for readers familiar with overseas terminology only.
Where there is any conflict between this DPA and the Terms of Service on the subject of personal-information processing, this DPA prevails.
2. Definitions
- "Personal Information" has the meaning in the Privacy Act 1988 (Cth).
- "End User Data" means Personal Information contained in the address queries and related data you submit to the Service (for example, an individual's address).
- "Process" / "Processing" means any operation performed on Personal Information.
- "Sub-processor" means a third party engaged by WattleAddr that handles Personal Information on our behalf, whether End User Data or your account information. Annex C says which each one sees.
- "APPs" means the Australian Privacy Principles.
3. Processing details
We Process End User Data only to provide, secure, support and maintain the Service, in accordance with your documented instructions (including your configuration of the Service, such as retention and privacy-mode settings) and this DPA. If we believe an instruction breaches the Privacy Act or other law, we will inform you. The subject matter, duration, nature, purpose, categories of data and categories of individuals are set out in Annex A.
4. Your obligations
- You must have a lawful basis to collect End User Data and to submit it to the Service, and to authorise the Processing described in this DPA.
- You must comply with the APPs (or other applicable privacy law) in your own handling of End User Data, including providing any required notices to, and obtaining any required consents from, individuals.
- You are responsible for the accuracy of the instructions you give and the configuration you choose (including retention and query-hashing options).
5. Our obligations
- We will Process End User Data only on your instructions and for the purposes of providing the Service, and will not use it for our own purposes or disclose it except as permitted by this DPA or required by law.
- We will ensure personnel authorised to Process End User Data are subject to confidentiality obligations.
- We will implement and maintain the technical and organisational security measures described in Annex B (APP 11).
- We will assist you, taking into account the nature of the Processing, to respond to individuals exercising their rights (including access and correction) and to meet your obligations regarding security and data-breach notification.
6. Data residency
All End User Data is stored and Processed within Australia (primary infrastructure in Sydney, a standby in Melbourne, backups held in Australia). We do not transfer or disclose End User Data to any overseas recipient, and address queries are not routed outside Australia.
7. Sub-processors
You authorise us to engage the Sub-processors listed in Annex C, each of which handles data in Australia and is bound by obligations no less protective than those in this DPA. Annex C says what each one sees; only our hosting provider handles End User Data. Annex C also records one narrow exception outside the address request path: the developer console's card-payment form loads our payment processor's card-capture script from a globally operated content delivery network, which receives your IP address and browser type only, never End User Data.
We will give you at least 30 days' notice by email before adding or replacing a Sub-processor. You may object within 14 days on reasonable data-protection grounds; if we cannot address your objection, you may terminate the affected Service and we will refund any prepaid fees for the unused part of your period.
Geoscape Australia is the source of the underlying G-NAF address dataset and is not a Sub-processor. We do not send your queries or End User Data to Geoscape. Our database runs on WattleDB, another product of RR Sols Pty Ltd; it is the same legal entity and not a Sub-processor, and it is disclosed so you can assess it.
8. Data breach notification
If we become aware of unauthorised access to, disclosure of, or loss of End User Data, we will tell you as soon as practicable and no later than 5 business days after becoming aware, by email to your workspace's billing contact (or through the Shopify app for Shopify merchants), and then keep you informed as our assessment progresses. We will provide the information reasonably available to help you assess the breach and meet your obligations under the Notifiable Data Breaches scheme (Part IIIC of the Privacy Act), and take reasonable steps to contain and remediate it. Where the breach is likely to result in serious harm and both of us hold the affected information, we will agree with you which party notifies the Commissioner and affected individuals, so that a single notification satisfies both parties under section 26WB of the Privacy Act.
9. Individual requests
If we receive a request from an individual relating to End User Data (for example, for access, correction or deletion), we will, to the extent legally permitted, refer the request to you and assist you to respond, rather than responding directly.
10. Retention, return and deletion
We retain End User Data in the search log for the retention period you configure, after which query and matched-address text is automatically purged. When you delete a workspace, its search-log text is deleted at that moment. On termination of the Service, or on your written request, we delete or de-identify any remaining End User Data from live systems within 30 days. Database backups are taken daily and kept for 7 days, so a copy can remain in a backup for up to 7 days after deletion; backups are restored only to recover the Service. Records we must keep by law (tax invoices, adjustment notes and refund records, five years) and aggregated usage counts that are not Personal Information are retained.
11. Audit and information
On reasonable written request (and no more than once per year unless required by a regulator or following a data breach), we will provide information reasonably necessary to demonstrate our compliance with this DPA: written answers, a completed security questionnaire, and a screen-shared walkthrough of the relevant controls. We do not offer on-site inspection or access to systems shared with other customers. Enterprise & Government customers may agree additional arrangements in an Order Form.
12. Liability and term
Each party's liability under this DPA is subject to the limitations and exclusions in the Terms of Service. This DPA is incorporated into the Terms of Service and takes effect when you create a workspace or, for Enterprise & Government customers, on the date of your Order Form, and continues while we Process End User Data on your behalf. Provisions that by their nature should survive termination will do so.
13. Governing law
This DPA is governed by the laws of New South Wales, Australia, consistent with the Terms of Service.
14. Annex A: Details of Processing
| Item | Detail |
|---|---|
| Subject matter | Provision of Australian address autocomplete, verification and geocoding |
| Duration | For the term of the Service and the configured retention period |
| Nature and purpose | Matching, verifying and returning address results; metering; security and support |
| Categories of individuals | The Customer's End Users who enter addresses into the Customer's applications |
| Categories of Personal Information | Address text and matched addresses (which may include an individual’s address), API usage metadata and IP address |
| Sensitive information | Not intended to be Processed |
15. Annex B: Security measures
- Encryption of data in transit (TLS) and Australian-hosted infrastructure with access controls.
- Hashing of passwords and API keys; keys shown once and stored only as prefix and hash.
- Least-privilege access, authentication, and logging and monitoring of access.
- Configurable search-log retention, automatically purged once the window passes, to minimise Personal Information held.
- Optional per-workspace search-log privacy: store queries as a salted keyed hash (HMAC; pseudonymisation, as we hold the key) or store no query or matched-address text at all, applicable to existing log data on request.
- Regular review of controls, backups held in Australia, and a written data-breach response procedure.
16. Annex C: Approved Sub-processors
| Sub-processor | Purpose and what it sees | Location |
|---|---|---|
| Binary Lane Pty Ltd | Cloud hosting and infrastructure for the API, console and website; Sydney primary and Melbourne standby | Australia (Sydney and Melbourne) |
| Pinch Payments | Processing customer payments of WattleAddr invoices (one-off card payments). No end-user address data. | Australia (Sydney); in-browser card-capture script served from a global CDN |
| VentraIP Australia Pty Ltd | Outbound email: invoices, account and service notices, contact-form messages. Sees account-holder name, email address and invoice content. No end-user address data. | Australia |
17. Contact
For DPA and privacy matters, contact privacy@wattleaddr.com.au.
This document is part of the agreement between you and RR Sols Pty Ltd. It is not advice about your own legal position; get your own advice if you need it. Questions: legal@wattleaddr.com.au.