Lvl 4, 11 York Street
Sydney NSW 2000 Australia
+61 (0) 2 9099 5700
Sydney NSW 2000 Australia
+61 (0) 2 9099 5700
hello@apollosecure.com
Effective date: 30 June 2026
1.1. This Data Processing Agreement forms part of the agreement between Apollo Secure Pty Ltd (ACN 663 095 065) located at Level 4, 11 York Street Sydney NSW 2000 (Apollo, our, us, we) and the customer identified in that agreement (Customer, you).
1.2. This Data Processing Agreement applies where we process Customer Personal Information in providing the Services.
1.3. Our general privacy practices are described in our Privacy Policy available at apollosecure.com/privacy-policy.
1.4. If there is any inconsistency between this Data Processing Agreement and our Privacy Policy concerning Customer Personal Information, this Data Processing Agreement prevails.
2.1. In this Data Processing Agreement:
a) Applicable Privacy Law means the Privacy Act 1988 (Cth), the Australian Privacy Principles and any other Australian privacy law that applies to either party
b) Customer Personal Information means Personal Information submitted to, stored in or generated through the Services by or on behalf of the Customer
c) Data Breach means actual or reasonably suspected unauthorised access to, disclosure of or loss of Customer Personal Information that is likely to materially affect its confidentiality, integrity or availability
d) Personal Information, Sensitive Information and related terms have the meanings given under Applicable Privacy Law
e) Trust Centre means our trust centre available at trust.apollosecure.com.
3.1. We process Customer Personal Information to host, provide, secure, maintain and support the Services.
3.2. We process Customer Personal Information for the term of the agreement and any applicable retention period.
3.3. We only process Customer Personal Information as reasonably required to:
a) provide the Services
b) comply with the agreement
c) follow your documented instructions
d) comply with applicable law.
3.4. Customer Personal Information may relate to your personnel, contractors, customers, suppliers, students and other individuals whose information you choose to process through the Services.
3.5. Processing may include collection, storage, organisation, access, retrieval, transmission, backup, support and deletion.
3.6. The countries in which Customer Personal Information may be stored or processed are identified in our Privacy Policy and Trust Centre.
4.1. You must:
a) comply with Applicable Privacy Law
b) have the right to provide Customer Personal Information to us
c) provide any required privacy notices and obtain any required consents
d) ensure your instructions to us are lawful
e) only submit Personal Information reasonably required for your use of the Services
f) appropriately manage your users, permissions and access to the Services.
5.1. We will:
a) process Customer Personal Information only to provide the Services, follow your documented instructions or comply with applicable law
b) ensure personnel with access to Customer Personal Information are subject to appropriate confidentiality obligations
c) limit access to personnel who reasonably require it
d) not sell Customer Personal Information or use it for advertising
e) not use Customer Personal Information to train general-purpose artificial intelligence models without your written agreement
f) notify you if we reasonably believe an instruction breaches Applicable Privacy Law.
6.1. We will maintain reasonable technical and organisational measures designed to protect Customer Personal Information from misuse, interference, loss and unauthorised access, modification or disclosure.
6.2. Details of our current security controls and assurance information are available through the Trust Centre.
6.3. We will not materially reduce the overall level of security applying to the Services during the term of the agreement.
6.4. We may update our technical and organisational measures from time to time, provided that we do not materially reduce the overall level of security applying to the Services.
7.1. We may engage subprocessors to assist us in providing the Services.
7.2. We will:
a) maintain a list of subprocessors that process Customer Personal Information, through the Trust Centre and update that list within a reasonable time after any material change
b) require subprocessors to comply with written privacy, confidentiality and security obligations appropriate to the services they provide
c) remain responsible for our subprocessors’ performance of those obligations.
7.3. Where a subprocessor processes Customer Personal Information outside Australia, we will take reasonable steps to ensure it is subject to privacy and security obligations appropriate to the nature of the information and the processing activities.
8.1. We will notify you without undue delay and, where practicable, within 72 hours after becoming aware of a Data Breach affecting Customer Personal Information.
8.2. We will promptly investigate, contain and mitigate the Data Breach and take reasonable steps to remediate its cause and effects.
8.3. We will preserve relevant records and provide available information when available about:
a) the nature of the Data Breach
b) the information and individuals potentially affected
c) the likely consequences
d) the investigation, containment and remediation measures.
8.4. We will provide reasonable assistance and timely updates to help you assess and comply with your obligations under the Notifiable Data Breaches scheme and Applicable Privacy Law.
8.5. Unless required by law, we will not notify affected individuals or regulators on your behalf without your approval.
9.1. We will provide reasonable assistance to help you respond to:
a) requests to access or correct Personal Information
b) privacy complaints
c) regulator enquiries
d) lawful requests to delete Customer Personal Information.
9.2. You remain responsible for determining and communicating the appropriate response to any affected individuals.
10.1. During the term of the agreement, you may access and, where available, export Customer Personal Information from the Services.
10.2. Following termination of the agreement, we will securely delete or de-identify Customer Personal Information when it is no longer reasonably required to provide the Services, comply with applicable law or resolve outstanding legal or security matters.
10.3. Customer Personal Information retained in backups will remain protected, will not be actively processed except for recovery, security or legal purposes and will be deleted in accordance with our standard backup lifecycle.
11.1. You may review our available security, compliance, control and subprocessor information through the Trust Centre.
11.2. We will maintain appropriate records relating to our processing of Customer Personal Information and provide information reasonably required to help you demonstrate compliance with Applicable Privacy Law, where that information is not available through the Trust Centre.
11.3. Any further audit must be reasonably necessary due to:
a) a material Data Breach
b) a regulatory requirement
c) a substantiated compliance concern.
11.4. Any audit will be subject to appropriate confidentiality, security, scope, timing and cost arrangements.
12.1. This Data Processing Agreement continues for as long as we hold Customer Personal Information.
12.2. Except as expressly varied by this Data Processing Agreement from time to time as published on our website, the agreement between the parties remains unchanged.