Data Processing Addendum
How we handle personal information in your data on your behalf. It forms part of our Terms of Service, or of any other agreement you have with us for the service. Last updated 30 September 2026.
Draft under review. It describes how we work today and may be reworded before it's final.
1. Scope and roles
This addendum is between Emitt [legal entity and ABN to be confirmed] ("we") and the customer ("you"). It applies to personal information contained in your data that we handle to provide the service ("customer personal information").
You decide what data goes into the service and why. We handle customer personal information only on your behalf, as your service provider. Terms not defined here have the meaning given in our Terms of Service or your agreement with us.
2. Processing on your instructions
We process customer personal information only to provide, secure and support the service, as set out in the agreement, and on your other documented instructions. If we're required by law to process it otherwise, we'll tell you first unless the law prevents it. If we think an instruction breaks the law, we'll tell you.
3. What we process
| People concerned | Your users; and people named in the records you upload, such as account contacts on bills and supplier contacts. |
| Kinds of information | Names, work email addresses, roles and sign-in identifiers of users; contact names, addresses and account numbers that appear in uploaded records; audit records of who changed what and when. |
| Purpose | Providing the service: storing records and evidence, calculating emissions, producing reports, and keeping an audit trail. |
| Duration | The term of the agreement, then until deleted under clause 10. |
The service is not designed for sensitive information (as the Privacy Act defines it), such as health information. Please don't upload it.
4. Our people
Only people who need access to provide the service can access customer personal information, and they are bound by confidentiality obligations.
5. Security measures
We maintain technical and organisational measures appropriate to the risk, including:
- Hosting on Microsoft Azure, with the database, uploaded files and backups stored in the Australia East region.
- Encryption in transit (TLS) and at rest.
- Every query scoped to the signed-in user's organisation, with database row-level security and automated tests of that separation.
- Sign-in through Microsoft Entra ID; invite-only access controlled by your administrators; admin and member roles.
- Secrets held in Azure Key Vault, not in application code.
- An audit log of changes to your data, and application monitoring and alerting through Azure Monitor.
- Automated database backups with point-in-time restore, and versioned file storage that keeps deleted files recoverable for 30 days.
We may update these measures, but won't reduce the overall level of protection during your subscription. More detail is on our security page.
6. Subprocessors
- You authorise us to use the subprocessors listed on our subprocessors page.
- We'll give at least 30 days' notice before adding or replacing a subprocessor that handles customer personal information, by updating that page and emailing customers who have asked to be notified.
- You may object on reasonable data protection grounds within that period. We'll work with you in good faith to resolve it; if we can't, you may end the affected part of the service and receive a refund of prepaid fees for it.
- We impose data protection obligations on each subprocessor that are no less protective than this addendum, and remain responsible for their performance.
7. Where data is processed
Your data is stored in Australia. Some subprocessors process limited information outside Australia, as the subprocessors page shows for each one. Where we disclose customer personal information overseas, we take reasonable steps to ensure the recipient handles it consistently with the Australian Privacy Principles.
8. Helping you with requests
If someone asks us to access, correct or delete personal information in your data, we'll pass the request to you rather than answer it ourselves, unless the law requires otherwise. We'll give you reasonable help to respond to such requests and to meet your own privacy obligations, including privacy impact assessments.
9. Data breaches
If we become aware of unauthorised access to, disclosure of, or loss of customer personal information, we'll tell you without undue delay, and in any case within 72 hours. We'll give you the information you reasonably need to assess the breach, including under the Notifiable Data Breaches scheme; take reasonable steps to contain it; and keep you updated.
10. Return and deletion
When the agreement ends, you can export your data for 30 days. We then delete customer personal information from the service within a further 30 days. Copies in database backups are overwritten as the backups expire, within 14 days after that; deleted files are purged from storage 30 days after deletion. We'll confirm deletion in writing if you ask. We keep information only where the law requires, and protect it while we do.
11. Information and audits
We'll give you the information reasonably needed to show that we meet this addendum, including completed security questionnaires and, when available, our SOC 2 report under confidentiality. If that isn't enough, or a regulator requires it, you may audit our compliance once a year, with at least 30 days' notice, at your cost, during business hours, and without access to other customers' data.
12. General
If this addendum conflicts with the Terms of Service or your agreement with us, this addendum wins for customer personal information. Questions go to [email protected].