Data Processing Addendum
Version 1.0 · Effective 19 August 2026
This Data Processing Addendum (DPA) forms part of the SimpleDiagrams Cloud Terms between McQuillen Interactive Pty. Ltd. (Processor, we, or us) and the Customer organisation that accepted those Terms (Controller or Customer). It applies only to Customer Personal Data that we process on Customer's behalf in SimpleDiagrams Cloud Customer Content. It does not apply to the separately sold SimpleDiagrams Desktop product.
1. Definitions
Applicable Data Protection Law means privacy and data-protection law applicable to processing under this DPA, including where applicable the Australian Privacy Act 1988 (Cth) and Australian Privacy Principles, EU Regulation 2016/679 (GDPR), UK GDPR and Data Protection Act 2018, and the California Consumer Privacy Act as amended (CCPA).
Customer Personal Data means personal data or personal information contained in Customer Content that we process for Customer. Data Subject, Controller, Processor, processing, and Supervisory Authority have the meanings in Applicable Data Protection Law. Security Incident means a confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Customer Personal Data. Sub-processor means a third party appointed by us to process Customer Personal Data.
2. Scope, roles, and instructions
Customer is Controller and we are Processor for Customer Personal Data. Each party will comply with its obligations under Applicable Data Protection Law. Customer determines the lawfulness, purpose, data subjects, content, memberships, visibility, integrations, and retention choices available through supported Service controls, subject to the standard periods in this DPA and the Privacy Policy. Customer represents that it has a lawful basis, has given required notices, and may instruct us to process the data.
We will process Customer Personal Data only to provide, secure, support, and maintain the Service; comply with Customer's documented configuration and requests; and comply with law. The Terms, this DPA, Customer's use of supported controls, and written support instructions are Customer's documented instructions. If we believe an instruction violates Applicable Data Protection Law, we will notify Customer unless prohibited and may suspend the affected processing while the parties resolve it.
This DPA does not govern account contact, billing, legal-acceptance, security, fraud, and service-administration data that we process for our own legitimate purposes as a separate controller or APP entity. That processing is described in the Privacy Policy.
3. Processor obligations
We will:
- process Customer Personal Data only on documented instructions unless law requires otherwise;
- ensure personnel with access are authorised, need access, and owe confidentiality duties;
- maintain the technical and organisational measures in Annex 2;
- not sell Customer Personal Data or use it for cross-context behavioural advertising;
- not use Customer Personal Data to train a general-purpose artificial intelligence model;
- provide reasonable information needed to demonstrate compliance with this DPA; and
- inform Customer if we can no longer meet a material legal obligation under this DPA.
4. Security incidents
We will notify Customer without undue delay after becoming aware of a Security Incident affecting Customer Personal Data. As information becomes reasonably available, notice will describe the nature of the incident, affected data and data subjects, likely consequences, mitigation, and a contact for follow-up. We may provide information in phases and will take reasonable steps to contain, investigate, and remediate. We will promptly assess suspected incidents. The definition of Security Incident does not postpone a notification or other action required earlier by Applicable Data Protection Law.
Notification is not an admission of fault. Customer is responsible for notices to its data subjects, regulators, and other parties, and we will provide reasonable assistance considering the nature of processing and information available to us. Unsuccessful attacks, routine scans, blocked login attempts, and events that do not compromise Customer Personal Data are not Security Incidents under this DPA.
5. Data-subject and compliance assistance
Taking account of the nature of processing, we will provide reasonable assistance so Customer can respond to Data Subject requests for access, correction, deletion, restriction, objection, or portability. If we receive a request concerning Customer Personal Data, we will direct the requester to Customer unless law requires us to act. Customer should first use available account, visibility, and deletion controls.
We will provide reasonable assistance with Customer's data-protection impact assessments, prior consultations, breach obligations, and security reviews where required by law and relevant to our processing. Material bespoke work may be charged at agreed rates where law permits and the need did not result from our breach.
6. Sub-processors
Customer gives general written authorisation for the Sub-processors on the current Sub-processor List. We will impose written data-protection obligations appropriate to their processing and remain responsible for their performance to the extent required by Applicable Data Protection Law.
We will post an updated list and, for a new Sub-processor that will materially process Customer Personal Data, give affected account owners at least 30 days' notice before use where practicable. Where the EU SCCs or other binding transfer terms require advance notice, their notice requirements apply without this practicability qualification. Customer may object during the notice period on reasonable documented data-protection grounds. The parties will work in good faith on a reasonable alternative. If none is commercially reasonable, Customer may terminate the affected Service and receive a pro-rata refund for the unused prepaid period.
7. International transfers
Customer authorises processing in the locations in the Sub-processor List. For a restricted transfer of Customer Personal Data from the EEA to a country without an adequacy decision, the European Commission standard contractual clauses adopted by Implementing Decision (EU) 2021/914 (EU SCCs) are incorporated by reference as follows: Module Two (Controller to Processor) applies; Customer is data exporter; we are data importer; Clause 7 docking applies; Option 2 and the 30-day notice period apply in Clause 9; the optional wording in Clause 11 does not apply; Ireland is the governing Member State and Irish courts have jurisdiction under Clauses 17 and 18; and Annexes 1 and 2 of this DPA complete the corresponding SCC annexes.
For a restricted transfer from the United Kingdom, the then-current UK International Data Transfer Addendum to the EU SCCs issued by the Information Commissioner's Office is incorporated, with the information in this DPA completing its tables. The parties will cooperate in implementing a replacement lawful mechanism if required. Where APP 8 applies, we will take reasonable steps to ensure an overseas recipient handles personal information consistently with the Australian Privacy Principles.
8. CCPA terms
To the extent CCPA applies to Customer Personal Data, we act as a service provider and contractor. We will:
- not sell or share Customer Personal Data;
- not retain, use, or disclose it outside the direct business relationship or for a purpose other than the business purposes in this DPA;
- not combine it with personal information received from another person except as CCPA permits;
- provide the same level of privacy protection required by CCPA; and
- allow Customer to take reasonable and appropriate steps to help ensure compliant use and to stop and remediate unauthorised use.
9. Return and deletion
During paid or lapsed organisation access, Customer may use supported exports where available. Subscription cancellation alone is not a deletion instruction while the organisation remains in the limited lapsed period described in the Terms. For a planned Service Closure, we will make supported export available until the notified closure date unless doing so would create a security, legal, or material harm risk. On a verified written deletion instruction, deliberate organisation closure, expiry of that lapsed period, or termination that closes the organisation, we will delete or return Customer Personal Data as described in the Privacy Policy, unless law requires retention. Data retained for legal reasons remains protected and is not processed for another purpose. Deletion from active systems occurs within 30 days; residual encrypted backups expire within 90 days under the backup rotation and remain isolated from ordinary use.
10. Audit
On reasonable request no more than once annually, we will provide information reasonably necessary to demonstrate compliance, such as current security descriptions, provider materials, policies, and responses to a proportionate questionnaire. If that is insufficient or a Security Incident or regulator requires more, Customer may arrange an independent audit with at least 30 days' notice, during business hours, under confidentiality, without access to another customer's data or unreasonable disruption. Customer bears audit costs unless the audit identifies our material breach.
11. Liability, conflict, and term
Liability under this DPA is included within the liability framework in the Terms, except where Applicable Data Protection Law prohibits that limitation. If this DPA conflicts with the Terms on processing Customer Personal Data, this DPA prevails; the EU SCCs or mandatory law prevail over both for their scope. This DPA lasts while we process Customer Personal Data. Confidentiality, deletion, audit, transfer, and liability provisions survive as necessary.
Annex 1 — Details of processing
| Parties | Customer named in the account or order is Controller/data exporter. McQuillen Interactive Pty. Ltd., Victoria, Australia, is Processor/data importer. |
|---|---|
| Subject matter | Provision of the SimpleDiagrams hosted live-diagram service. |
| Duration | The agreement term, any limited lapsed export/resubscription period, and the deletion and backup periods described in Section 9 and the Privacy Policy. |
| Nature and purpose | Receiving, storing, organising, validating, retrieving, rendering, transmitting, exporting, securing, backing up, and deleting Customer Content as instructed. |
| Data subjects | People identified in Customer Content, which may include Customer users, employees, contractors, students, clients, and viewers. Platform account and visitor data processed for our own purposes remains outside this DPA as described in Section 2. |
| Personal data | Personal data Customer chooses to submit in diagram labels, configuration, external references, current state values, timestamps, or other supported Customer Content. This may include names, work contact details, or identifiers where Customer includes them in that content. Account contact, billing, legal-acceptance, security, fraud, and service-administration data processed for our own purposes is excluded as described in Section 2. |
| Sensitive data | None intended or permitted without a separate written agreement. The AUP prohibits special-category and similarly sensitive data. |
| Frequency | Continuous or intermittent according to Customer's use, including periodic viewer polling and state updates. |
| Retention | As configured by Customer where controls exist, otherwise for the agreement, limited lapsed, deletion, and backup periods described in Section 9 and the Privacy Policy. |
Annex 2 — Technical and organisational measures
-
Hosting: managed Google Cloud infrastructure with the primary application, database, and Customer Content storage configured for
australia-southeast1in Sydney, Australia. Google may provide support and resilience from other locations under its terms. - Encryption: TLS for production network traffic and provider-managed encryption at rest.
- Identity: individual accounts, strong password hashing, mandatory email verification, session security, and role-based organisation access.
- Isolation: organisation ownership on resources, central authorisation services, server-side permission checks, and cross-tenant tests.
- Credentials: environment and secret-manager separation, scoped credentials where supported, and no card data in the application.
- Application security: CSRF protection, secure cookies, payload bounds, revision checks, usage and rate enforcement, signed Stripe webhooks, and dependency vulnerability review.
- Operations: restricted production access, structured logging that excludes secrets and full state payloads, error monitoring when enabled, backups, deployment checks, and incident response.
- Lifecycle: code review, automated tests, migration checks, pinned dependencies, non-root containers, and documented deletion and provider review procedures.
Measures evolve with risk and the Service. We may replace a measure with one that provides materially equivalent or stronger protection without amending this DPA.
Annex 3 — Contacts
Controller contact: the organisation owner or contact in Customer's account.
Processor contact: McQuillen Interactive Pty. Ltd. · ABN 49 600 623 069 · 7/3 Bolinda Street, Bentleigh, Victoria 3204, Australia · support@simplediagrams.com.