Data Processing Agreement

Effective date: 30 June 2026

1. Application

1.1. This Data Processing Agreement forms part of the agreement between Apollo Secure Pty Ltd (ACN/Company Number 663 095 065) located at Level 4, 11 York Street Sydney NSW 2000 (Apollo, our, us, we) and the customer identified in that agreement (Customer, you).

1.2. This Data Processing Agreement applies where we process Customer Personal Information in providing the Services.

1.3. Our general privacy practices are described in our Privacy Policy available at apollosecure.com/privacy-policy.

1.4. If there is any inconsistency between this Data Processing Agreement and our Privacy Policy concerning Customer Personal Information, this Data Processing Agreement prevails.

2. Definitions

2.1. In this Data Processing Agreement:

a) Applicable Privacy Law means the Privacy Act 1988 (Cth), the Australian Privacy Principles and any other Australian privacy law that applies to either party

b) Customer Personal Information means Personal Information submitted to, stored in or generated through the Services by or on behalf of the Customer

c) Data Breach means unauthorised access to, disclosure of or loss of Customer Personal Information

d) Personal Information, Sensitive Information and related terms have the meanings given under Applicable Privacy Law

e) Trust Centre means our trust centre available at trust.apollosecure.com.

3. Processing Details

3.1. We process Customer Personal Information to host, provide, secure, maintain and support the Services.

3.2. We process Customer Personal Information for the term of the agreement and any applicable retention period.

3.3. We only process Customer Personal Information as reasonably required to:

a) provide the Services

b) comply with the agreement

c) follow your documented instructions

d) comply with applicable law.

3.4. Customer Personal Information may relate to your personnel, contractors, customers, suppliers, students and other individuals whose information you choose to process through the Services.

3.5. Processing may include collection, storage, organisation, access, retrieval, transmission, backup, support and deletion.

4. Customer Responsibilities

4.1. You must:

a) comply with Applicable Privacy Law

b) have the right to provide Customer Personal Information to us

c) provide any required privacy notices and obtain any required consents

d) ensure your instructions to us are lawful

e) only submit Personal Information reasonably required for your use of the Services

f) appropriately manage your users, permissions and access to the Services.

5. Our Obligations

5.1. We will:

a) process Customer Personal Information only to provide the Services, follow your documented instructions or comply with applicable law

b) ensure personnel with access to Customer Personal Information are subject to appropriate confidentiality obligations

c) limit access to personnel who reasonably require it

d) not sell Customer Personal Information or use it for advertising

e) not use Customer Personal Information to train general-purpose artificial intelligence models without your written agreement

f) notify you if we reasonably believe an instruction breaches Applicable Privacy Law.

6. Security

6.1. We will maintain reasonable technical and organisational measures designed to protect Customer Personal Information from misuse, interference, loss and unauthorised access, modification or disclosure.

6.2. Details of our current security controls and assurance information are available through the Trust Centre.

6.3. We will not materially reduce the overall level of security applying to the Services during the term of the agreement.

7. Subprocessors

7.1. We may engage subprocessors to assist us in providing the Services.

7.2. We will:

a) maintain a current list of subprocessors that process Customer Personal Information through the Trust Centre

b) require subprocessors to comply with appropriate privacy, confidentiality and security obligations

c) remain responsible for our subprocessors’ performance of those obligations

d) provide reasonable notice of any material new subprocessor that will process Customer Personal Information.

7.3. You may raise a reasonable privacy or security objection to a new subprocessor.

7.4. We will work with you in good faith to resolve any reasonable objection.

8. Data Breaches

8.1. We will notify you without undue delay and, where practicable, within 72 hours after becoming aware of a Data Breach affecting Customer Personal Information.

8.2. We will provide available information about:

a) the nature of the Data Breach

b) the information and individuals potentially affected

c) the likely consequences

d) containment and remediation measures.

8.3. We will provide reasonable assistance with your investigation, assessment and notification obligations.

8.4. Unless required by law, we will not notify affected individuals or regulators on your behalf without your approval.

9. Assistance and Requests

9.1. We will provide reasonable assistance to help you respond to:

a) requests to access or correct Personal Information

b) privacy complaints

c) regulator enquiries

d) lawful requests to delete Customer Personal Information.

9.2. You remain responsible for determining and communicating the appropriate response.

10. Return and Deletion

10.1. During the term of the agreement, you may access and export Customer Personal Information using the functionality available within the Services.

10.2. Following termination of the agreement, we will delete or de-identify Customer Personal Information in accordance with our standard retention and backup processes, unless retention is required by law.

10.3. Customer Personal Information retained in backups will remain protected and will not be actively processed except for recovery, security or legal purposes.

11. Information and Assurance

11.1. You may review our available security, compliance, control and subprocessor information through the Trust Centre.

11.2. We will respond to reasonable additional requests where the relevant information is not available through the Trust Centre.

11.3. Any further audit must be reasonably necessary due to:

a) a material Data Breach

b) a regulatory requirement

c) a substantiated compliance concern.

11.4. Any audit will be subject to appropriate confidentiality, security, scope, timing and cost arrangements.

12. General

12.1. This Data Processing Agreement continues for as long as we hold Customer Personal Information.

12.2. Except as expressly varied by this Data Processing Agreement, the agreement between the parties remains unchanged.