Data Processing Agreement
Last updated 20 August 2026
This Data Processing Agreement (DPA) forms part of the Agreement between Compozer Pty Ltd (Compozer, we, us or our) and the customer that has entered into it (Customer, you), and is binding on both parties as part of the Agreement.
It sets out how Compozer handles Customer Personal Data in the role of Processor or Service Provider for the Customer, and applies wherever Compozer Processes Customer Personal Data on the Customer's behalf under the Agreement.
The Customer enters into this DPA for itself and for every Authorised Affiliate it permits to use the Service, either by accepting the Agreement or, where the parties choose, by signing this DPA.
This DPA is otherwise subject to the Agreement, except that, to the extent of any inconsistency between this DPA and the rest of the Agreement about the handling of Customer Personal Data, this DPA prevails.
Our contact for privacy and security matters under this DPA is privacy@compozer.com.
1. Definitions and interpretation
1.1 In this DPA, the following definitions apply.
| Affiliate | means an entity that directly or indirectly controls a party, is controlled by it, or is under common control with it. |
| Agreement | means Compozer's terms of service or other agreement between Compozer and the Customer that governs the Customer's access to and use of the Service. |
| Applicable Privacy Laws | means every privacy or data protection law that governs the Processing of Personal Data under the Agreement, which, where they apply, include the European Privacy Laws, the CCPA, and the Privacy Act 1988 (Cth) (as amended, and including the Australian Privacy Principles in Schedule 1 to that Act). |
| Authorised Affiliate | means an Affiliate of the Customer that the Customer permits to use the Service under the Agreement. |
| Authorised Person | means a person that Compozer permits to Process Customer Personal Data, including Compozer's personnel, agents, and Subprocessors. |
| CCPA | means the California Consumer Privacy Act of 2018, Cal. Civ. Code § 1798.100 et seq., as amended (including by the California Privacy Rights Act of 2020) and its implementing regulations. |
| Customer Content | means all content and information that the Customer, its Users, or its Authorised Affiliates put into the Service, together with any content and information the Service otherwise captures or generates for the Customer through their use of it. |
| Customer Personal Data | means the Personal Data within Customer Content that Compozer Processes on the Customer's behalf in providing the Service, as further described in Annex 1.B. |
| EEA | means the European Economic Area: the member states of the European Union together with Norway, Iceland, and Liechtenstein. |
| European Privacy Laws | means, each as amended or replaced over time: (i) the EU GDPR (Regulation (EU) 2016/679); (ii) the UK GDPR, being the EU GDPR as assimilated into United Kingdom law by section 3 of the European Union (Withdrawal) Act 2018; and (iii) the Swiss Federal Act on Data Protection (the Swiss FADP). |
| Personal Data | has the meaning given in Applicable Privacy Laws, and in any case covers information that identifies, or can be used to identify, an individual. |
| Personal Data Breach | means a personal data breach, as defined in Article 4(12) of the EU GDPR, that affects Customer Personal Data. |
| Restricted Transfer | means a transfer of Customer Personal Data to a destination that the relevant authority has not recognised as offering adequate protection: under the EU GDPR, a transfer leaving the EEA without a European Commission adequacy decision; under the UK GDPR, a transfer leaving the United Kingdom without United Kingdom adequacy regulations; and under the Swiss FADP, a transfer to a country the Swiss Federal Data Protection and Information Commissioner has not listed as adequate. |
| SCCs | means the standard contractual clauses approved by European Commission Implementing Decision (EU) 2021/914 of 4 June 2021, as amended or replaced over time. |
| Security Policy | means the Compozer security policy published at compozer.com/trust/security, which forms part of this DPA. |
| Service | means the products and services that Compozer provides to the Customer under the Agreement. |
| Special Category Data | means the special categories of personal data described in Article 9(1) of the EU GDPR. |
| Subprocessor | means a Processor that Compozer engages to Process Customer Personal Data on Compozer's behalf in providing the Service. |
| Subprocessor List | means the list of Subprocessors published at compozer.com/trust/subprocessors, which forms part of this DPA. |
| UK Addendum | means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses (version B1.0) issued by the United Kingdom Information Commissioner under section 119A of the Data Protection Act 2018, as amended or replaced over time. |
| User | means an individual that the Customer or an Authorised Affiliate authorises to use the Service. |
1.2 In this DPA, the terms Controller, Processor, Data Subject, and Processing (with Process) carry the meanings Applicable Privacy Laws give them, falling back to the EU GDPR and UK GDPR where those laws are silent; Business and Service Provider carry their CCPA meanings. A capitalised term this DPA leaves undefined takes its meaning from the Agreement.
2. Application of this DPA
2.1 This DPA applies to Compozer's Processing of Customer Personal Data for every Customer, wherever the Customer and the relevant Data Subjects are located. It is intended to satisfy the requirements that each applicable law places on that Processing, including the processor requirements of Article 28 of the EU GDPR and the UK GDPR, the Swiss FADP, the CCPA, and the Privacy Act 1988 (Cth) (including the Australian Privacy Principles). The core obligations in this DPA - including as to permitted use, confidentiality, security, Subprocessing, assistance with Data Subject requests and impact assessments, breach notification, and return and deletion - apply to all Customer Personal Data under Applicable Privacy Laws.
Terms specific to a particular law
2.2 The provisions of this DPA that are specific to a particular law apply only to Customer Personal Data that is protected by that law, and do not otherwise limit this DPA. The SCCs and the UK and Swiss transfer terms apply only to a Restricted Transfer of Customer Personal Data protected by the European Privacy Laws, and section 2.3 applies only to Customer Personal Data protected by the Privacy Act 1988 (Cth). Where a law does not apply to a Customer, the terms specific to that law do not apply to that Customer.
Australian Privacy Act
2.3 Where the Privacy Act 1988 (Cth) applies to Customer Personal Data, Compozer will handle it consistently with the Australian Privacy Principles and in a way that supports the Customer's compliance with that Act. Compozer's security, confidentiality, and Subprocessing commitments under this DPA support the Customer where Customer Personal Data is disclosed to, or handled by, Compozer or its Subprocessors, including where that involves the disclosure of personal information outside Australia, and Compozer will assist the Customer with its data breach notification obligations under that Act as set out in section 3.14.
3. Processing of Customer Personal Data
Roles
3.1 The Customer acts as the Controller or Business for Customer Personal Data, and Compozer acts only as the Customer's Processor or Service Provider in Processing it. If the Customer is itself a Processor for another Controller, Compozer is a Subprocessor, and owes its duties under this DPA to the Customer. Each party keeps to its own obligations under Applicable Privacy Laws.
Permitted use of Customer Personal Data
3.2 Compozer will Process Customer Personal Data only:
- (a) to provide, maintain, and secure the Service;
- (b) to meet its obligations under the Agreement and this DPA; and
- (c) in line with the Customer's documented instructions given through the Agreement, this DPA, or the Service (the Permitted Purpose).
3.3 Beyond the Permitted Purpose, Compozer will not keep, use, disclose, or otherwise handle Customer Personal Data for any end of its own or anyone else's, unless a law binding on Compozer requires it. If Compozer notices that an instruction from the Customer would breach Applicable Privacy Laws, it will say so, but it has no duty to police the Customer's compliance.
3.4 For Customer Personal Data covered by the CCPA or another United States state privacy law, Compozer will not sell it, share it, use it for targeted advertising, or combine it with data from other sources, except as the Agreement and Applicable Privacy Laws allow. The parties treat the Customer's supply of Customer Personal Data to Compozer as something other than a sale, given for no consideration. Compozer confirms that it understands these United States state privacy restrictions and will comply with them.
Cross-border transfers
3.5 Where providing the Service involves moving Customer Personal Data across a border, Compozer first puts in place the safeguards that Applicable Privacy Laws require for that transfer, so that the data continues to be protected to the standard those laws demand.
Standard contractual clauses
3.6 Where a transfer of Customer Personal Data from the Customer to Compozer is a Restricted Transfer, the SCCs are incorporated into and form part of this DPA, with the Customer as data exporter and Compozer as data importer, completed as follows:
- (a) Module Two (controller to processor) applies where the Customer is a Controller, and Module Three (processor to processor) applies where the Customer is a Processor, and the other Modules do not apply;
- (b) in Clause 7, the docking clause applies, so that an Authorised Affiliate may accede;
- (c) in Clause 9, Option 2 (general written authorisation) applies, with the notice period in section 3.11;
- (d) in Clause 11, the optional language does not apply;
- (e) in Clause 17, Option 1 applies and the SCCs are governed by the law of Ireland;
- (f) in Clause 18(b), disputes are resolved before the courts of Ireland;
- (g) the SCC Annexes draw their content from the Annexes to this DPA; and
- (h) where the SCCs conflict with another part of the Agreement, the SCCs govern on the point of conflict.
UK transfers
3.7 For Customer Personal Data that the UK GDPR protects, the SCCs referred to in the section above apply as changed by the UK Addendum, incorporated here by reference. Its Part 1 Tables 1 to 3 take their content from this DPA's Annexes, Table 4 selects 'importer', and the law and courts of England and Wales govern those transfers.
Swiss transfers
3.8 For Customer Personal Data that the Swiss FADP protects, the SCCs apply with these adjustments: read references to the EU GDPR as references to the Swiss FADP; read references to the EU, the Union, or a member state as references to Switzerland; treat the Swiss Federal Data Protection and Information Commissioner as the supervising authority, with the competent Swiss courts as the forum; and apply Swiss law to the SCCs.
Confidentiality of Processing
3.9 Compozer will ensure that each Authorised Person is bound by a duty of confidentiality, whether by contract or by law, and handles Customer Personal Data only as the Permitted Purpose requires.
Security
3.10 Compozer keeps in place suitable technical and organisational measures to guard Customer Personal Data against loss, misuse, and unauthorised access, alteration, or disclosure, as set out in Annex 2 and the Security Policy. Compozer may update those measures from time to time by updating the Security Policy, provided the updates do not materially reduce the overall level of security. The Customer is responsible for deciding whether the Service's security is appropriate for the risk presented by the Customer Personal Data it chooses to Process through the Service.
Subprocessing
3.11 The Customer authorises Compozer to engage Subprocessors to Process Customer Personal Data for the Permitted Purpose, on the following terms.
- (a) Compozer keeps its Subprocessors listed on the Subprocessor List, and adds an intended new or replacement Subprocessor there at least 30 days before it starts work on Customer Personal Data. Compozer will notify the Customer's nominated account owner in writing when the list changes, which gives the Customer time to raise a reasonable data protection objection by writing to privacy@compozer.com within 10 days of the notice. Compozer will then either keep providing the Service without the Subprocessor the Customer objected to, or, where it needs that Subprocessor and cannot settle the objection, let the Customer end the subscription for the affected part of the Service from the point that Subprocessor starts Processing Customer Personal Data.
- (b) Every Subprocessor Compozer engages is placed under data protection obligations that meet the standard Article 28(4) of the EU GDPR sets where it applies, and Compozer stays responsible to the Customer for how its Subprocessors handle Customer Personal Data. On request, Compozer will share what it can about a Subprocessor agreement; where confidentiality limits disclosure, Clause 9(c) of the SCCs governs and Compozer gives, in confidence, the information it reasonably can.
Assisting with Data Subject requests
3.12 Compozer will give the Customer reasonable and timely help in answering a Data Subject who seeks to exercise rights under Applicable Privacy Laws (for instance, to access, correct, erase, or port their data, or to object to its use), and in dealing with a related complaint or enquiry about Compozer's Processing of Customer Personal Data, whoever raises it, unless Applicable Privacy Laws forbid it. If such a request or complaint reaches Compozer first, Compozer passes it to the Customer promptly, with the details.
Data protection impact assessments
3.13 Compozer will give the Customer the reasonable and timely assistance the Customer needs to carry out data protection impact assessments and, where required, to consult its supervisory authority, taking into account the nature of the Processing and the information available to Compozer.
Personal Data Breach
3.14 On becoming aware of a Personal Data Breach, Compozer will notify the Customer without undue delay, and will give the Customer the timely information and cooperation the Customer reasonably needs to meet its own breach-reporting obligations within the timeframes Applicable Privacy Laws require. Compozer will take reasonable steps to contain the Personal Data Breach and limit its impact, and will keep the Customer informed of material developments. A notification under this section is not an admission of fault or liability. The Customer will not issue any public notice that identifies Compozer in connection with a Personal Data Breach without Compozer's prior agreement, unless a law requires it, in which case the Customer will give Compozer reasonable prior notice.
Return and deletion
3.15 The Service lets the Customer delete its Customer Personal Data at any time, including by deleting its account. Cancelling the Customer's subscription for the Service does not by itself require Compozer to delete Customer Personal Data; the Customer's account and its Customer Personal Data remain available to the Customer until the Customer deletes them, deletes its account, or the Agreement ends. Once the Agreement ends, Compozer will destroy the Customer Personal Data it holds, apart from anything it needs to keep to finish the Permitted Purpose or to meet a law that binds it, and except that copies of Customer Personal Data held in Compozer's routine, secured backups are overwritten or deleted in the ordinary course of Compozer's backup cycle, within a rolling period of up to 12 months, and remain protected under this DPA until they are. Compozer will go on protecting any retained Customer Personal Data under this DPA for as long as it holds it. Where the SCCs apply, Compozer will give the certification of deletion they describe if the Customer asks for one.
Audits and security reviews
3.16 Compozer will make available the information reasonably needed to demonstrate its compliance with this DPA. The security review in this section is the agreed way for the Customer to meet its audit and inspection rights, including any right under Clause 8.9 of the SCCs. On reasonable written notice, and no more than once in any 12-month period, Compozer will respond to reasonable written information security and due diligence questionnaires sent to privacy@compozer.com, and will give further information about its information security programme as reasonably needed to confirm its compliance. Compozer need not disclose anything that would expose another customer's data, give direct access to its systems, or breach a confidentiality, trade secret, or other legal obligation, and the Customer will bear Compozer's reasonable costs where a response requires material effort.
4. General
Term
4.1 This DPA takes effect when the Agreement does, or when the Customer first accepts it, whichever is earlier, and continues for as long as Compozer Processes Customer Personal Data. Sections that by their nature should survive termination, including section 3.15, survive it.
Liability
4.2 Each party's liability arising out of or related to this DPA, whether in contract, tort, or under any other theory of liability, is subject to the exclusions and limitations of liability set out in the Agreement, and any reference in the Agreement to the liability of a party means the aggregate liability of that party under the Agreement and this DPA together.
Order of precedence
4.3 This DPA forms part of, and is otherwise subject to, the Agreement. However, to the extent of any inconsistency between this DPA and the rest of the Agreement about the handling of Customer Personal Data, this DPA prevails; and where the SCCs apply and conflict with this DPA or the rest of the Agreement, the SCCs prevail on the point of conflict. This section does not displace section 4.2, under which liability under this DPA remains subject to the limitations in the Agreement.
Governing law
4.4 Except where the SCCs, the UK Addendum, or the Swiss adjustments require a different governing law or forum for a particular transfer, this DPA is governed by the law that governs the Agreement, and the parties submit to the courts identified in the Agreement.
Changes to this DPA
4.5 Compozer may update this DPA from time to time to reflect changes in Applicable Privacy Laws, the SCCs, or its practices, provided the update does not materially reduce the protections given to Customer Personal Data. Compozer will make the current version available at compozer.com/trust/dpa and, where a change is material, will take reasonable steps to notify the Customer in writing.
Annex 1 - Details of Processing
Annex 1.A - List of parties
Data exporter
The Customer, identified by the name, address, and contact details recorded in the Agreement or in the Customer's account. Transfer activity: use of the Service. Role: Controller, or Processor where the Customer acts for another Controller.
Data importer
Compozer Pty Ltd (ABN 24 631 334 944).
Contact: privacy@compozer.com.
Transfer activity: operating the Service, a cloud-based eLearning authoring platform. Role: Processor, or Subprocessor where the Customer acts for another Controller.
Annex 1.B - Description of Processing
Categories of Data Subjects
The Customer's and its Authorised Affiliates' employees, contractors, and Users; learners, trainees, or other end users who access or interact with Customer Content, including where the Customer makes Customer Content available through the Service or an integration; and other individuals whose personal data the Customer or its Users include in Customer Content.
Categories of Personal Data
Name; contact information such as email, phone number, or address; usage and analytics data such as device information or IP address; authentication identifiers (account and user IDs); and any personal data a Customer includes within Customer Content (for example, names or images used in course material).
Special Category Data
Compozer does not seek out or knowingly Process Special Category Data. If the Customer or its Users place Special Category Data into Customer Content, the Customer alone decides on and controls that, and Compozer handles it under the terms of this DPA.
Frequency of Processing and transfer. Continuous, for as long as needed to provide the Service.
Nature and purpose of Processing
Operating the Service by Processing Customer Personal Data for the Permitted Purpose, which covers collecting, recording, retrieving, storing, structuring, encrypting, restricting, deleting, and destroying it.
Retention
Customer Personal Data is retained for as long as needed for the Permitted Purpose or required by a law that applies to Compozer, subject to section 3.15.
Annex 1.C - Competent supervisory authority
The competent supervisory authority follows Clause 13 of the SCCs: where the Customer is established in an EEA member state, that state's authority; where the Customer is not established in the EEA but has an Article 27 representative, the authority of the representative's member state; and otherwise, the authority of a member state where the affected Data Subjects are located. For UK-protected transfers, it is the Information Commissioner's Office.
Annex 2 - Technical and organisational measures
The technical and organisational measures Compozer maintains are described in the Security Policy, which forms part of this DPA. They include: hosting on Amazon Web Services with production data and application compute located in Australia; encryption of data in transit (TLS 1.2 or higher) and at rest (AES-256); role-based access control and logical tenant isolation between customer accounts; restriction of production infrastructure access to authorised personnel on a need-to-know basis; storage of application secrets in a dedicated secrets management service; monitoring and logging across infrastructure; automated, managed database backups; and confidentiality obligations for personnel with access to Customer Content.
Annex 3 - List of Subprocessors
Compozer's current Subprocessors are set out on the Subprocessor List, which forms part of this DPA and is published at compozer.com/trust/subprocessors.