Suiviro Legal
Data Processing Agreement
Last updated: 7 July 2026
This Data Processing Agreement (“DPA”) governs how Suiviro processes personal information on behalf of its customers. This DPA forms part of the Suiviro Terms of Service and, where the Customer or its end-users are located in the European Economic Area, the United Kingdom, Switzerland or California, incorporates the additional processor / service-provider terms in Sections 12 and 12A–12C.
1. Roles
For customer information stored within Suiviro:
Customer - the Customer is the Data Controller. The Customer determines what information is collected, which customers are entered, and how information is used.
Suiviro - Suiviro acts as the Data Processor. Suiviro processes information solely to provide the Services.
2. Customer Data
Customer Data may include names, phone numbers, email addresses, addresses, job history, notes, uploaded photos, communications, and files and attachments. Customer Data remains the property of the Customer.
3. Data Ownership
Customers retain ownership of client records, job records, staff records, communications, uploaded files, photos and notes. Suiviro acquires no ownership rights over Customer Data.
4. Processing Activities
Suiviro may process Customer Data to:
- Store information
- Display information
- Synchronise integrations
- Send notifications
- Generate reports
- Provide customer support
- Maintain security
Processing is limited to providing the Services.
5. Security Measures
- HTTPS encryption
- Access controls
- Role-based permissions
- Audit logging
- Secure hosting
- Backup procedures
6. Subprocessors
Suiviro engages third-party service providers ("subprocessors") to help deliver the Services. Current subprocessors include Supabase (managed Postgres, authentication and file storage), Cloudflare (edge hosting and CDN), Lovable (platform hosting and deployment), Paddle (Merchant-of-Record billing and tax), ClickSend (SMS delivery), Microsoft 365 (transactional email and optional Outlook calendar / mail integration) and Google (optional Google Calendar and Google sign-in). An up-to-date list, with the categories of data processed and the region in which each subprocessor operates, is published in the Privacy Policy. Suiviro will update the published list when subprocessors change. Customers may request advance notification of new subprocessors by emailing privacy@suiviro.com, and may object on reasonable grounds. Where an objection cannot be resolved, the Customer's sole remedy is to terminate the affected Services.
7. Data Retention
Customer Data is retained while accounts remain active, for backup purposes, and to comply with legal obligations. Customers may request deletion of their data subject to legal and operational requirements.
8. Data Export
Customers may request export of their data. Where technically feasible, Suiviro will provide data in a commonly used electronic format such as CSV, PDF or JSON depending on the information requested.
9. Data Deletion
Upon account termination, customers may request deletion of Customer Data. Deletion requests may be subject to backup retention periods, legal obligations and security requirements.
10. Data Breach Response
If Suiviro becomes aware of a material security incident affecting Customer Data, Suiviro will investigate the incident, take reasonable containment measures, notify affected customers where appropriate, and restore services where possible.
11. Customer Responsibilities
- Obtaining required consents
- Complying with privacy laws
- Managing user access
- Maintaining accurate records
- Reviewing permissions
12. International Processing and Transfer Safeguards
Customer Data is primarily stored in Australia (Supabase, ap-southeast-2). Certain subprocessors may process Customer Data in other jurisdictions, including the European Economic Area, the United Kingdom, Switzerland, the United States and New Zealand.
Where Customer Data relating to individuals in the EEA, the UK or Switzerland is transferred to a country outside those regions that has not been recognised by the European Commission, the UK Government or the Swiss Federal Data Protection and Information Commissioner as offering an adequate level of protection, Suiviro relies on the following transfer safeguards, in each case supplemented by the technical and organisational measures described in Section 5 and by the outcome of a transfer impact assessment:
- EEA transfers — the European Commission's Standard Contractual Clauses of 4 June 2021 (Commission Implementing Decision (EU) 2021/914), Module Two (Controller-to-Processor) where the Customer is a controller and Suiviro acts as processor, and Module Three (Processor-to-Processor) where the Customer is itself a processor. Clause 7 (docking) is included; Clause 9(a) uses Option 2 (general written authorisation) with a minimum 30-day notice period; Clause 11 does not include the optional independent dispute-resolution body; Clause 17 Option 1 applies with Irish law as governing law; Clause 18 designates the courts of Ireland as the forum. Annex I identifies the parties and describes the transfer; Annex II incorporates the security measures in Section 5; Annex III lists the subprocessors published under Section 6.
- UK transfers — the SCCs as varied by the UK International Data Transfer Addendum issued by the Information Commissioner under section 119A of the Data Protection Act 2018 (version B1.0, 21 March 2022). Tables 1–3 are completed by reference to this DPA and Annexes I–III; Table 4 permits the importer to end the Addendum where the ICO issues a revised approved version.
- Swiss transfers — the SCCs adapted for the Swiss Federal Act on Data Protection (revFADP), read so that references to the GDPR include the revFADP, the competent supervisory authority is the Swiss FDPIC, and Swiss law governs the transfer.
For Australian Privacy Principle 8 purposes, Suiviro takes reasonable steps to ensure overseas recipients of personal information handle that information consistently with the Australian Privacy Principles, including through the contractual terms in this DPA and in its subprocessor agreements.
12A. Article 28(3) GDPR / UK GDPR Processor Terms
Where Suiviro processes personal data of individuals located in the EEA, the UK or Switzerland on behalf of a Customer, this DPA together with the Terms of Service constitutes the written contract required by Article 28(3) of the GDPR and the equivalent UK GDPR provision. Suiviro will:
- (a) Documented instructions. Process Customer Data only on the Customer's documented instructions — including instructions expressed through configuration of, and use of, the Services — unless required to do so by EU, EEA-Member-State, UK or Swiss law to which Suiviro is subject, in which case Suiviro will inform the Customer of that legal requirement before processing (unless the law prohibits such notice).
- (b) Confidentiality. Ensure that personnel authorised to process Customer Data are subject to an enforceable duty of confidentiality.
- (c) Article 32 security. Implement the technical and organisational measures described in Section 5 to meet the requirements of Article 32.
- (d) Sub-processor authorisation. Engage sub-processors only under the general written authorisation in Section 6, on written terms materially no less protective than this DPA, and notify the Customer of intended additions or replacements at least 30 days in advance so the Customer may object on reasonable data-protection grounds; where an objection cannot be resolved, the Customer's sole remedy is to terminate the affected Services under Section 6.
- (e) Data-subject assistance. Taking into account the nature of the processing and the information available, assist the Customer by appropriate technical and organisational measures, insofar as possible, to respond to requests from data subjects exercising their rights under Chapter III of the GDPR.
- (f) Article 32–36 assistance. Assist the Customer, taking into account the nature of the processing and the information available, in ensuring compliance with the security (Art. 32), personal-data-breach (Arts. 33–34), data-protection-impact-assessment (Art. 35) and prior-consultation (Art. 36) obligations.
- (g) Breach notification. Notify the Customer without undue delay, and in any event within 72 hours after Suiviro becomes aware, of a personal data breach affecting Customer Data, providing at least the information required by Article 33(3) as it becomes available.
- (h) Deletion or return. On termination or expiry of the Services, delete or (at the Customer's choice, expressed in writing before the end of the retention window in Section 9) return Customer Data, and delete existing copies, unless EU, EEA-Member-State, UK or Swiss law requires further storage — in which case Suiviro will continue to protect the Customer Data in accordance with this DPA.
- (i) Audit rights. Make available to the Customer the information reasonably necessary to demonstrate compliance with the obligations in Article 28 and, on reasonable prior written notice and no more than once per year (or more frequently where required by a supervisory authority or following a personal data breach), allow for and contribute to audits — including inspections — conducted by the Customer or an independent auditor mandated by the Customer, subject to reasonable confidentiality undertakings and to protection of the security and confidentiality of Suiviro's other customers.
- (j) Compliance flag. Immediately inform the Customer if, in Suiviro's opinion, an instruction infringes the GDPR, the UK GDPR or the revFADP.
12B. California Service-Provider Terms (CCPA / CPRA)
Where the Customer is a "business" and Suiviro processes personal information of California consumers on the Customer's behalf, Suiviro acts as a service provider as defined in California Civil Code §1798.140(ag). Suiviro will:
- Process the personal information only for the business purposes specified in this DPA and the Terms of Service, and only as reasonably necessary and proportionate to provide the Services.
- Not sell or share the personal information within the meaning of §1798.140(ad) and §1798.140(ah), and not use the personal information for cross-context behavioural advertising.
- Not retain, use or disclose the personal information for any purpose other than for the business purposes specified above, including any commercial purpose, or outside the direct business relationship with the Customer, except as permitted by §1798.140(ag)(1) and the CPRA regulations.
- Not combine the personal information with personal information Suiviro receives from, or on behalf of, another person, or that Suiviro collects from its own interaction with the consumer, except as permitted under 11 CCR §7050(b).
- Comply with applicable obligations under the CCPA / CPRA, and provide the Customer with the same level of privacy protection as required by that legislation.
- Notify the Customer if Suiviro determines it can no longer meet its obligations under the CCPA / CPRA, and allow the Customer to take reasonable and appropriate steps to stop and remediate unauthorised use of personal information.
- Grant the Customer the right, on reasonable written notice, to take reasonable and appropriate steps to ensure that Suiviro uses the personal information transferred to it in a manner consistent with the Customer's obligations under the CCPA / CPRA.
- Engage sub-contractors that receive personal information only under a written contract that binds them to the same restrictions as this Section 12B, consistent with §1798.140(ag)(1)(D).
Suiviro certifies that it understands the restrictions in this Section 12B and will comply with them.
12C. Swiss FADP and Additional Jurisdictions
Where personal data relates to Swiss data subjects, Suiviro will process that data in accordance with the revised Swiss Federal Act on Data Protection (revFADP) in force from 1 September 2023, giving effect to the additional requirements applicable to Swiss transfers as described in Section 12. For personal information originating in other jurisdictions with mandatory processor terms (for example, Quebec's Law 25 or Brazil's LGPD), the substantive obligations in this DPA are read to include the additional local requirements to the extent legally required.
13. Return of Data
Upon termination of services, customers may request a reasonable opportunity to retrieve their data before deletion.
14. Governing Law
This DPA is governed by the laws of Western Australia and the Commonwealth of Australia.
15. Contact
Data protection enquiries: Privacy Officer, privacy@suiviro.com. Security incidents: security@suiviro.com. Processor: Suiviro Pty Ltd (ACN 699 266 987, ABN 30 699 266 987), Australia.
Questions about this document? Email admin@suiviro.com.