Data Processing Agreement — Australia
The terms under which Cerrax handles your customers' personal information on your instructions.
This agreement forms part of the Terms of Service and applies whenever Cerrax handles personal information on your behalf. It uses the meanings given in the Privacy Act 1988 (Cth) and the Australian Privacy Principles (the "APPs"). It applies whether or not your business is itself covered by the Privacy Act. Where this agreement and the Terms conflict on data protection, this agreement governs.
1. Which of us is which
You collect your customers’ personal information and remain responsible for it: you decide why and how it is handled. We handle it on your behalf, as your service provider: we act on your instructions and use it for our own purposes only in the ways section 3 lists (for those uses alone we are responsible in our own right), and you keep effective control of it. For your own account information — your name, your login, your business’s settings and billing — we are responsible in our own right, and our Privacy Policy covers that.
One exception, which is your customer's choice, not yours. When your customer sends a video or photographs of their home, they may tick a separate box allowing Cerrax to keep them to train software that recognises furniture and rooms. For that use alone, Cerrax handles that information in its own right, not on your behalf, on the customer's consent, and our Privacy Policy (§3) covers it: identifying details are blurred before it is ever used for training, nothing uses it today, and the customer can withdraw at any time, after which the video and photographs are deleted under the ordinary ninety-day rule. Everything else in this agreement applies to them as it does to the rest of your customers’ information.
2. What we handle, and for how long
- Purpose: running your removals business on Cerrax — receiving and organising your enquiries, keeping your customer records (contacts), pricing, quoting and following up quotes, booking and running jobs, and sending the messages you set up — on your instructions.
- What we do with it: collecting, storing, organising, reading (including with AI, to suggest details for a person at your business to confirm), pricing, sending messages on your behalf, de-identifying (section 9), exporting and deleting.
- Duration: for as long as your account is open, and afterwards only as section 8 allows.
- Kinds of personal information: names, addresses, contact details, move dates, and details of the property and its contents that you or your customer enter; where your crew use Cerrax on the day of the move, photographs of the property, its access and any damage found, together with the name and drawn signature of whoever signs the inventory off; and, where you invite it and your customer chooses to send one, a video of their home. Where you use them: your contacts (names, email addresses, phone numbers, company, preferred language, addresses used, the choices they gave you about your messages and when, where they came from, and your notes); enquiries, including the text of enquiry emails sent to your Cerrax lead address; the messages you send through Cerrax and whether they were delivered; follow-up tasks and their notes; whether a payment has been made (never card details); and reviews and ratings your customers give you.
- People it is about: people who enquire with you (whether or not they become customers); your customers; the people at the properties you move between; other people you keep as contacts; people named in notes, messages, photographs or video; and your staff and crew in their working role.
We do not ask for and do not want sensitive information. Please do not enter health, biometric or similar information into free-text fields. If it arrives anyway — in an enquiry or a note — we hold it only as part of that record, never use it for pricing or learning, and keep it out of section 9.
A signature captured against an inventory is held as evidence that your customer agreed what was moved and in what condition. Nothing measures, compares or matches it, and it is never used to identify anyone — so we do not treat it as biometric information. Collecting signatures is optional: if you would rather your crew did not, simply do not use it.
3. We act on your instructions
We handle your customers’ personal information only on your instructions — which include your use of the product and this agreement — unless the law requires otherwise, in which case we will tell you first unless the law forbids that. If we think an instruction would breach the Privacy Act, we will tell you promptly and may pause carrying it out until you confirm or change it. We will not use or disclose the information for any purpose of our own, sell it, or use it for direct marketing — except the de-identified use in section 9.
Our own uses, and only these: the de-identification in section 9; keeping descriptions of a job's items and rooms, with any email address, phone number or postcode removed, for 30 days to improve how Cerrax recognises items (we keep no other text sent to our AI sub-processor); keeping the service secure and preventing abuse; and meeting our own legal obligations.
Your instructions include these, when you use the features concerned: receiving emails sent to your Cerrax lead address and reading them — using our AI sub-processor where an email has no labelled layout — to suggest details you confirm; keeping contact records and the choices your customers make about your messages; and sending the messages you switch on, in your name, identifying you and with your postal address, honouring every request to stop at once and for all of those messages from you to that person. We keep a record of each choice and each stop, and a scrambled record of a stop for as long as it must be honoured.
Also on your instructions, when you use the features concerned: sending your customers the messages about a job that you set up (by WhatsApp where you have connected it, otherwise by email), including a review request and the private rating and comment a customer may give you; creating links you choose to share — a job sheet for your crew, or evidence (the customer's name, photographs, video and signatures, never their contact details) for your insurer, broker or claims handler; publishing your jobs to calendar subscriptions you create; and keeping follow-up tasks and their notes.
4. Confidentiality
Everyone we allow to access your customers’ personal information is bound by a written duty of confidentiality that continues after they leave, and only sees what their role requires. Access inside the product is governed by roles and individual permissions, checked on the server for every request.
5. Security
We take reasonable steps to protect the information from misuse, interference and loss, and from unauthorised access, modification or disclosure — the standard APP 11 sets — described in our security overview: encryption in transit and at rest, role-based access control, an audit trail of consequential actions, point-in-time recovery and separate daily backups. That page states plainly what we do not yet have.
We will not materially reduce the overall level of security described there while this agreement lasts.
6. Sub-processors
You authorise us to use sub-processors. The current list is in section 8 of our Privacy Policy and is kept current there. We bind each of them by written contract to obligations no less protective than these, and we remain fully responsible to you for their performance. We will email your account owner at least 30 days before a new sub-processor starts handling your customers’ personal information (sooner only in an emergency, such as a provider failing, and then we tell you as soon as we can). You may object within that time on reasonable data protection grounds; if we cannot resolve it, you may end the affected service or your subscription and we will refund any fees paid in advance for the unused period. Services you connect yourself under your own account with them — your own Stripe, WhatsApp Business or Xero account — act on your instruction under your agreement with them, and are not our sub-processors.
If you subscribe your own calendar to your Cerrax calendar link, your calendar provider fetches your jobs under your own agreement with it; it is not our sub-processor.
7. Helping you meet your own obligations
Taking into account the nature of our work, we will help you respond to requests from your customers to access or correct their information (APPs 12 and 13), and with your security and breach duties. If one of your customers contacts us directly about information we hold for you, we will refer them to you rather than answer for you.
If we suspect a data breach affecting information we hold for you, we will tell you without undue delay, and in any event within 48 hours — and in any case in time for the assessment the Notifiable Data Breaches scheme requires within 30 days — with what we know and what we are doing about it. We will work with you on the assessment. Where it is an eligible data breach, we agree with you which of us notifies the Office of the Australian Information Commissioner and the people affected, so that they are told once and promptly; unless we agree otherwise, you notify and we give you everything you need.
You can find, export, correct and delete a contact or a job yourself in the product; for anything the product cannot do, we will act within 10 working days of your written instruction.
8. Deletion and return
Your instruction on how long we keep it. Unless you tell us otherwise, you instruct us to keep each job record — the quote, its booking and outcome, the crew's sheets and the photographs attached to them — for six years after the move (or after the quote, if the job did not go ahead), or for longer while a claim or dispute about that job is open, and then to delete it. A video, and any photographs your customer sends with it, are deleted 90 days after the job's last date unless your customer has separately agreed to their longer use. You can change this instruction by telling us.
At the end of the agreement you can export your data for 30 days. We then delete your customers’ personal information within 90 days, and it leaves our backups as they expire (within 98 days), except where the law requires us to keep it or you ask us to keep specific records, such as evidence in an open claim. Committed pricing records are never silently altered — personal identifiers within them are removed, which is how deletion is honoured without falsifying a record of what was quoted. Section 9 records are not your customers’ personal information and are not affected.
Unless you tell us otherwise, you also instruct us to delete: an enquiry that was never priced or sent, 12 months after its last activity; a quote that was sent but never accepted, 24 months after it was sent; and a contact record 12 months after the last job record linked to it is deleted (or 12 months after it was made, if it was never linked to a job). A record of a person's consent is kept while their contact record is kept and for six years after; a scrambled record of a request to stop messages is kept for as long as it must be honoured.
Two records keep their own periods: email delivery records (recipient, subject and whether it was delivered), 90 days; and the audit trail of actions in your account, up to six years after your account closes, with a customer's details removed when that customer is erased.
9. De-identified job data
(a) You instruct us to make de-identified records from the jobs we hold for you. (b) A de-identified record holds only the shape and economics of a job — volume, a distance band, access features, crew, vans, hours, price and cost, whether the quote was won and why not, the month of the move, and an area no finer than the first two digits of a postcode — and never a name, contact detail, full address or postcode, map position, free text, photograph, video, signature, your business's identity, or any reference that links it back to the job. (c) We treat a record as de-identified only when no one could reasonably identify a person from it, taking account of other information we or you hold. Data that can be linked back — for example by a job reference, or while we still hold the original job — is not de-identified and stays under this agreement until the original is deleted. (d) We will not try to re-identify anyone from these records, and require anyone we share them with to make the same commitment. (e) Once a record meets this standard it is not your customers’ personal information; it is ours, and we may keep and use it to improve and provide Cerrax, including after the underlying records are deleted and after this agreement ends. (f) We never show another business, or anyone else, your individual prices or anything that identifies your business.
10. Learning across firms
We use de-identified records under section 9, and statistics made from them, from across all firms using Cerrax, in every country, to improve the pricing engine for everyone, including you. This is stated here rather than assumed, because it is how the product gets better and we would rather you knew than found out.
11. Your numbers stay yours
Your rates, your margins, your customers and your prices are never visible to another firm, and never shown to the people you are quoting. The learning in section 10 runs on aggregated, de-identified signal — not on access to any one firm’s data by anybody else.
12. Audit
We will make available the information you reasonably need to show we are meeting these obligations — first by written answers and our security documentation — and will allow and contribute to a reasonable assessment by you or an independent assessor you appoint where those are not enough or a regulator requires it: at your cost, on 30 days' notice, under confidentiality, without access to other businesses' data, and no more than once a year unless a regulator or a breach requires otherwise.
13. Information held overseas
We hold your customers’ personal information outside Australia — in the United Kingdom, in London — and you authorise that. Some sub-processors handle it in the United States — AI processing by Anthropic and website hosting by Vercel, as our Privacy Policy (§9) sets out — and providers that operate globally (Cloudflare, Meta, Xero and Google) may handle it in other countries where they operate. Because you keep effective control of the information and we handle it only for you, giving it to us is, in the ordinary case, your use of it rather than a disclosure. If in any case it is a disclosure to an overseas recipient, we agree to handle it in a way that does not breach the Australian Privacy Principles (APPs 1 to 13, other than those that only you can meet), so that you have taken the reasonable steps APP 8.1 requires, and we will impose the same obligation on any sub-processor overseas. Where your data is stored on any given day is a question you can ask us at any time, and we will answer it for the day you ask.
Liability. Section 11 of the Terms of Service (limitation of liability) applies to this agreement.
14. Contact
Data protection questions, access and correction requests, and breach notifications: hello@cerrax.io.
15. Privacy Act terms, in one place
For your own records, this agreement gives you the contractual steps the Privacy Act expects of a business using a service provider, including one overseas: handling only for your purpose and on your instructions (sections 2 and 3); confidentiality (section 4); security under APP 11 (section 5); sub-processors bound by written contract (section 6); help with access and correction requests and with the Notifiable Data Breaches scheme (section 7); deletion or return at the end (section 8); de-identified data (section 9); information and assessments to show compliance (section 12); and a binding commitment to the APPs for information held overseas (section 13). If the Privacy Act requires a term this agreement does not contain, that term is treated as included, to the extent the law requires it.