Home Privacy Terms Sub-processors DPA Cookies Trust Center
Legal

Data Processing Addendum

Last Updated: 7 August 2026  ·  Version: 1.0

Contents

  1. Scope and Definitions
  2. Roles of the Parties
  3. Instructions and Purpose Limitation
  4. Sub-processor Authorisation
  5. Data Security Obligations
  6. Confidentiality
  7. Assistance with Data Subject Rights
  8. Audit Rights
  9. Breach Notification
  10. Return or Deletion of Data
  11. Governing Law
  12. Nature and Purpose of Processing
  13. Liability
  14. Order of Precedence

1. Scope and Definitions

This Data Processing Addendum ("DPA") forms part of the agreement between Axiom Advisory Global ("Processor," "we," "us," or "our") and the Customer ("Controller," "you," or "your") governing the Customer's use of our products and services (the "Services"). This DPA applies to the extent we process personal data on your behalf in the course of providing the Services.

Terms such as "personal data," "processing," "controller," "processor," "sub-processor," and "data subject" have the meanings given to them under the GDPR and equivalent applicable data protection law. "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data processed under this DPA.

2. Roles of the Parties

The parties agree that, with respect to personal data submitted by you or your personnel to the Services ("Customer Data"), you are the data controller and we are the data processor. We will process Customer Data only in accordance with your documented instructions, including as set out in your account configuration and use of the Services, unless required to do otherwise by applicable law.

With respect to Account Data we collect directly to administer your account and our relationship with you, we act as an independent data controller, as described in our Privacy Policy.

3. Instructions and Purpose Limitation

We will process Customer Data solely for the purpose of providing the Services, and will not use Customer Data for any other purpose, including our own marketing, profiling, or benchmarking, without your prior written consent. If we believe an instruction from you infringes applicable data protection law, we will notify you promptly.

4. Sub-processor Authorisation

You provide general authorisation for us to engage sub-processors to assist in providing the Services, subject to the notice and objection process described in our Sub-processors page. We remain responsible for the acts and omissions of our sub-processors to the same extent we would be liable if performing their services directly, and we impose data protection terms on each sub-processor that are no less protective than those in this DPA.

5. Data Security Obligations

We implement and maintain industry-standard technical and organisational measures designed to protect Customer Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access, including encryption of data in transit and at rest, access controls, authentication mechanisms, rate limiting, continuous audit logging, and regular internal security reviews. Further detail is available in our Trust Center.

6. Confidentiality

We ensure that personnel authorised to process Customer Data are subject to a binding duty of confidentiality, whether contractual or statutory, and that access to Customer Data is limited to personnel who require it to perform their duties in connection with the Services.

7. Assistance with Data Subject Rights

Taking into account the nature of the processing, we will provide reasonable assistance to you, at your cost where the assistance requires material effort, in responding to requests from data subjects to exercise their rights under applicable data protection law, and in connection with your obligations relating to data protection impact assessments and consultations with supervisory authorities, to the extent such information is not otherwise available to you through the Services.

8. Audit Rights

Upon reasonable prior written notice, and no more than once per 12-month period unless required following a Personal Data Breach or by a supervisory authority, you may request information reasonably necessary to demonstrate our compliance with this DPA, which we will provide in the form of relevant security documentation, summaries, or a mutually agreed audit conducted during business hours in a manner that does not unreasonably disrupt our operations or compromise the confidentiality or security of other customers' data.

9. Breach Notification

We will notify you without undue delay, and in any event within 24 hours of becoming aware, of any confirmed Personal Data Breach affecting Customer Data, and will provide information reasonably available to us regarding the nature of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address it, to support your own notification obligations under applicable law.

10. Return or Deletion of Data

Upon termination or expiry of the agreement between us, and upon your written request, we will make Customer Data available for export for a limited period, after which we will delete Customer Data from our active systems in accordance with the retention periods described in our Privacy Policy, except to the extent applicable law requires continued retention.

11. Governing Law

This DPA is governed by the laws of New South Wales, Australia, and is subject to the governing law and dispute resolution provisions of the underlying agreement between the parties, except where the GDPR or another applicable data protection law requires specific standard contractual clauses to govern international transfers, in which case those clauses apply to the extent of the transfer.

12. Nature and Purpose of Processing

The subject matter of processing under this DPA is Customer Data submitted to the Services. The duration of processing corresponds to the term of the underlying agreement between the parties, plus any post-termination retention period described in our Privacy Policy. The nature and purpose of processing is to provide, secure, and support the Services, including document capture, data extraction, storage, and reporting functionality. The categories of data subjects typically include the Customer's employees, contractors, and other personnel whose information appears in records submitted to the Services. The categories of personal data typically processed are described in our Privacy Policy.

13. Liability

Each party's liability arising out of or in connection with this DPA, including liability for breach of applicable data protection law, is subject to the limitation of liability provisions set out in the underlying agreement between the parties, except to the extent applicable law prohibits such limitation.

14. Order of Precedence

In the event of a conflict between this DPA and the underlying agreement between the parties, this DPA governs with respect to the processing of personal data. Where a standard contractual clause or equivalent transfer mechanism mandated by applicable law applies, that mechanism governs to the extent of any inconsistency with this DPA.