Data Processing Agreement (Standard)

Standard DPA for Maelstrom AI B2B customers (Controllers): covers support data processed through our support platform, and records that downpipes is no-custody with no sub-processor for customer data

Legal Template

Data Processing Agreement (Standard)

Between: [CONTROLLER NAME] (“Controller”) And: Maelstrom AI Pty Ltd ATF Maelstrom AI Holding Trust (“Processor”)

Effective Date: [DATE] Version: 2.5 (updates Version 2.0, which legal counsel reviewed on 2026-09-04)


Scope of this Agreement. Maelstrom AI runs one ISMS over its downpipes platform and its internal support platform.

  • downpipes, no-custody backup and disaster recovery for the Cloudflare data layer.
  • Our support platform, Maelstrom’s internal support system.

This Agreement governs Maelstrom AI’s processing of personal data as a Processor for support data the Controller sends through our support platform, in connection with the Controller’s use of downpipes. It does not apply to the Controller’s own infrastructure data run through downpipes itself. For that system, Maelstrom supplies software that runs in the Controller’s own account. Maelstrom has no access to that data and is not a processor of it. Maelstrom engages no sub-processor for downpipes customer data (see Section 4.5).


Recitals

WHEREAS, the Controller uses downpipes, a no-custody product that runs in the Controller’s own Cloudflare account;

WHEREAS, the Controller may from time to time send Maelstrom support data, including diagnostic bundles and attachments, through our support platform, for the purpose of diagnosing and resolving issues;

WHEREAS, the parties wish to enter into a data processing relationship compliant with applicable privacy laws including the General Data Protection Regulation (EU) 2016/679 (“GDPR”), the Australian Privacy Act 1988, and other applicable data protection laws;

WHEREAS, this Agreement sets forth the terms under which the Processor will process support data on behalf of the Controller, and records the Processor’s position that it is not a processor of the Controller’s data run through downpipes itself;

NOW, THEREFORE, in consideration of the mutual covenants contained herein, the parties agree as follows:


1. Definitions

1.1 Key Terms

For purposes of this Agreement:

(a) “Controller” means the entity that determines the purposes and means of processing personal data, as identified in the signature block above.

(b) “Processor” means Maelstrom AI Pty Ltd ATF Maelstrom AI Holding Trust, which processes personal data on behalf of the Controller.

(c) “Personal Data” means any information relating to an identified or identifiable natural person as defined under applicable Data Protection Laws.

(d) “Data Protection Laws” means all applicable laws and regulations relating to privacy and data protection, including but not limited to:

  • GDPR (General Data Protection Regulation (EU) 2016/679)
  • UK GDPR and Data Protection Act 2018
  • Australian Privacy Act 1988
  • California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA)
  • Canadian Personal Information Protection and Electronic Documents Act (PIPEDA)
  • Any successor or replacement legislation

(e) “Data Subject” means an identified or identifiable natural person whose personal data is processed under this Agreement.

(f) “Sub-Processor” means any third party engaged by the Processor to process personal data on behalf of the Controller.

(g) “Processing” has the meaning given in applicable Data Protection Laws and includes collection, storage, use, disclosure, and deletion of personal data.

(h) “Services” means downpipes as used by the Controller, and the support service described in Section 2.

(i) “Service Agreement” means the master services agreement or terms of service between the parties governing the provision of Services.

1.2 Interpretation

References to GDPR articles apply equally to equivalent provisions in other Data Protection Laws. Capitalised terms not defined herein have the meanings assigned in the Service Agreement.


2. Processing Details

2.1 Subject Matter of Processing

The Processor processes personal data included in support conversations, attachments, and support bundles that the Controller or the Controller’s personnel send to the Processor’s support platform, in connection with the Controller’s use of downpipes.

For the Controller’s own infrastructure data run through downpipes itself, the Processor has no access to that data and is not a processor of it (see Section 2.6). This Agreement does not govern that data.

2.2 Duration of Processing

This Agreement commences on the Effective Date. It continues until termination of the Service Agreement or earlier termination of this Agreement in accordance with Section 10.

2.3 Nature and Purpose of Processing

The Processor processes personal data for the following purposes only:

(a) Support Service Provision: Receiving, triaging, and answering support requests submitted through the support platform. This includes diagnosing issues from attachments and support bundles the Controller chooses to send

(b) Anti-Fraud and Security: Detection and prevention of abuse of the support portal, including rate limiting

(c) Service Provision: Technical operation and maintenance of the support portal, including ticket tracking and service-level management

(d) Legal Compliance: Compliance with applicable laws and legal obligations

2.4 Categories of Personal Data

The Processor processes the following personal data through the support platform:

Data CategoryData ElementsRetention PeriodPurpose
Contact DataName, email address365 days after ticket closeSupport correspondence
Message ContentSupport conversation content, operator notes365 days after ticket closeDiagnosing and resolving the reported issue
AttachmentsAttachments sent with a support message365 days after ticket closeDiagnosing the reported issue
Support BundlesSupport bundles uploaded, including through a one-time upload link30 days after upload, or on ticket close, whichever is soonerDiagnosing the reported issue
Entitlement DataEntitlement record at the time of the ticket365 days after ticket closeConfirming support eligibility
Technical MetadataCaller IP address, operator email address (technical log records)90 days, then deleted automaticallySecurity monitoring, service diagnostics
Export SnapshotsA daily export of ticket records (contact data, message content, entitlement data), held in a separate storage bucket30 days, then deleted automaticallyRecovery after data loss
Backup CopiesEncrypted backup copies of stored messages, attachments and support bundles, made by Maelstrom’s own downpipes deployment in the Processor’s Cloudflare accountUntil the Processor prunes its backups. The deletion periods in the rows above do not apply to these copiesRecovery after data loss

The Processor does not apply masking or redaction to support data: message content and attachments are held as submitted. Retained data may therefore include any personal data the Controller chooses to include in a support conversation, attachment, or bundle. The Controller should avoid including personal data beyond what is necessary to diagnose the issue.

2.5 Categories of Data Subjects

Individuals whose personal data may appear in support data sent to the support platform, including:

  • The Controller’s personnel who submit support requests
  • Any individual whose personal data the Controller’s personnel include in a message, attachment, or support bundle, for example because it appears in the Controller’s own logs or configuration

2.6 downpipes: No Access, Not a Processor

For downpipes, the Processor supplies software that runs in the Controller’s own Cloudflare account, under the Controller’s own keys. The Processor has no access to the data the Controller runs through this product and is not a processor of it. See Section 4.5 for the corresponding sub-processor position.

2.7 Controller and Processor Obligations

The parties acknowledge and agree that:

(a) Controller Obligations:

  • Determines purposes and means of processing personal data
  • Ensures lawful basis for processing under Data Protection Laws
  • Provides privacy notices to data subjects regarding support-data processing
  • Responds to data subject requests (with Processor assistance as provided in Section 6)
  • Ensures compliance with Data Protection Laws for its processing activities

(b) Processor Obligations:

  • Processes personal data only on documented instructions from Controller (Section 3)
  • Implements appropriate technical and organisational security measures (Section 5)
  • Assists Controller with data subject rights requests (Section 6)
  • Notifies Controller of personal data breaches (Section 5.5)
  • Deletes or returns personal data upon termination (Section 10.3)

3. Processor Obligations

3.1 Processing Instructions

(a) The Processor shall process personal data only on documented instructions from the Controller, unless required to process by applicable law (in which case the Processor shall inform the Controller of such legal requirement before processing, unless prohibited by law).

(b) The Controller’s instructions are set forth in:

  • This Agreement (Section 2.3 - Nature and Purpose of Processing)
  • The Service Agreement
  • Additional written instructions provided by Controller through the support platform or other written channels

(c) If the Processor believes an instruction violates Data Protection Laws, it shall immediately inform the Controller. In that case, the Processor may suspend processing until the instruction is confirmed or modified.

3.2 Confidentiality

(a) The Processor shall ensure that all personnel authorised to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.

(b) Every person with access to personal data is bound by a confidentiality obligation, by contract or by law.

3.3 Prohibited Processing

The Processor shall NOT:

  • Process personal data for purposes other than those specified in Section 2.3
  • Disclose personal data to third parties except as authorised by this Agreement (Section 4)
  • Transfer personal data outside the territory specified in Section 7 without appropriate safeguards
  • Retain personal data beyond the retention periods specified in Section 2.4 and Section 10.3
  • Use personal data for Processor’s own purposes or to provide services to other clients

3.4 Data Protection Laws Compliance

The Processor shall:

  • Maintain familiarity with applicable Data Protection Laws
  • Implement measures to ensure compliance with Data Protection Laws
  • Notify Controller promptly of any changes in Data Protection Laws that may affect processing
  • Cooperate with Controller to ensure compliance with Data Protection Laws

3.5 Records of Processing Activities

The Processor shall maintain records of processing activities as required by GDPR Article 30(2) and equivalent provisions in other Data Protection Laws, including:

  • Name and contact details of Processor and Controller
  • Categories of processing activities
  • Categories of personal data subjects and personal data
  • Categories of recipients of personal data
  • International data transfers and safeguards
  • Retention periods
  • Security measures

4. Sub-Processors

4.1 General Authorisation

(a) The Controller provides general authorisation for the Processor to engage Sub-Processors, subject to the requirements of this Section 4.

(b) The Processor shall impose on Sub-Processors the same data protection obligations as set out in this Agreement, through a written contract.

(c) The Processor remains fully liable to the Controller for the performance of any Sub-Processor’s obligations.

4.2 Current Sub-Processors

The Processor’s current Sub-Processors for the support data that is the subject of this Agreement are those listed in Section 2 of the Sub-Processors page. Section 4.4 refers to the same list.

4.3 Sub-Processor Changes

(a) The Processor shall provide the Controller with at least 30 days’ prior written notice of any intended changes concerning the addition or replacement of Sub-Processors.

(b) Notice shall be provided via email to Controller’s designated contact and/or through the support platform.

(c) The Controller may object to a new or replacement Sub-Processor on reasonable grounds relating to data protection within 14 days of receiving notice.

(d) If the Controller objects and the parties cannot resolve the objection within a reasonable time:

  • The Controller may terminate the affected Services without penalty
  • The Processor may choose not to engage the Sub-Processor
  • The parties may negotiate alternative arrangements

4.4 Sub-Processor List

An up-to-date list of Sub-Processors is available at the Sub-Processors page.

4.5 downpipes: No Sub-Processor for Customer Data

Section 2 of the Sub-Processors page lists the Sub-Processors engaged for support-platform data, which is the subject of this Agreement. Section 1 of that page covers Maelstrom’s own website and the downpipes vendor surfaces, which hold no support data. Maelstrom AI also operates downpipes, no-custody backup and disaster recovery for the Cloudflare data layer. It does not add a Sub-Processor to this Agreement for the Controller’s own infrastructure data, because:

(a) No-custody architecture. The downpipes engine and console are deployed and run in the customer’s own Cloudflare account, under the customer’s own keys. Backup archives are sealed under customer-held keys using post-quantum hybrid encryption and written via a 3-2-1 fan-out to customer-controlled destinations. Through the product itself, Maelstrom holds no customer keys, data or Cloudflare tokens.

(b) No customer data processed by Maelstrom through the product. Neither Maelstrom nor anyone on its behalf ever receives or processes customer data through the downpipes product itself. For this reason, there is no processing through the product for which Maelstrom would engage a Sub-Processor. The Cloudflare services hosting the engine, console and customer-controlled destinations are contracted under the customer’s own Cloudflare account: they are the customer’s infrastructure, not a Maelstrom Sub-Processor. Support data that a Controller’s personnel choose to send Maelstrom, for example a diagnostic bundle sent for troubleshooting, is different: it is the subject of this Agreement, described in Section 2 above.

(c) Vendor-operated surfaces are content-free. Maelstrom operates only the control-plane (mints licence tokens and receives a content-free advisory beacon from engines whose operator turns it on; holds no customer keys, backup data or Cloudflare tokens; fail-open, never gates backup or restore) and a static, signature-pinned update channel (pull-only, no phone-home). Neither carries customer data, so neither introduces a Sub-Processor for customer data.


5. Security Measures

5.1 Security Obligations

The Processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, taking into account:

  • The state of the art
  • The costs of implementation
  • The nature, scope, context, and purposes of processing
  • The risk of varying likelihood and severity for the rights and freedoms of data subjects

5.2 Technical Security Measures

The Processor implements the following technical measures:

(a) Encryption:

  • TLS 1.2 or higher for web and API traffic (HTTPS). HTTP requests are redirected to HTTPS, and HSTS is set
  • Encryption at rest, provided by Cloudflare’s managed storage services

(b) Access Controls:

  • Access to the systems that hold support data is limited to a single operator, the ISMS Owner
  • An allowlist of these identities controls the operator role on the support platform
  • Cloudflare Access gates the support portal’s administrative surface
  • Multi-factor authentication (MFA) required for production system access
  • Authenticated service-to-service access for machine-to-machine support routes
  • Principle of least privilege enforced

(c) Data Minimisation:

  • Support data is retained only for the periods set out in Section 2.4, which include the Backup Copies row
  • The Processor does not apply masking or redaction to support data (see Section 2.4); the Controller controls what it sends

(d) Network Security:

  • DDoS protection (Cloudflare)
  • Cloudflare’s managed Web Application Firewall (WAF) rules
  • Rate limits per source IP address and per ticket reference, each with a global limit

(e) Monitoring and Logging:

  • Technical log records (caller IP, operator email), per Section 2.4
  • The support platform logs each request to its administrative surface, with the operator’s identity, the path and the time. These logs are kept for 90 days
  • Cloudflare sends security alerts, for example about DDoS attacks, to the Processor by email

5.3 Organisational Security Measures

The Processor implements the following organisational measures:

(a) Access Management:

  • Every person with access to support data is bound by a confidentiality obligation, by contract or by law
  • The ISMS Owner holds current professional security certifications
  • The Processor reviews access rights when they change, and at least once a year

(b) Privacy by Design:

  • downpipes is no-custody by design, so no data flows to the Processor through the product itself
  • Written design documents for new features of the support platform

(c) Vendor Management:

  • Security assessment for all Sub-Processors
  • Data Processing Agreements with Sub-Processors
  • Annual vendor security reviews

(d) Incident Response:

  • Documented incident response procedures
  • Restore drills of the support platform’s backups, with documented results
  • Support hours are Monday to Friday, 9am to 5pm Melbourne time. Outside those hours, the Processor responds on a best-efforts basis

5.4 ISO 27001 Alignment

The Processor’s Information Security Management System (ISMS) is aligned with ISO 27001:2022 and ISO 27701:2019 standards. The Processor is pursuing formal certification when commercially justified.

5.5 Personal Data Breach Notification

(a) The Processor shall notify the Controller without undue delay after becoming aware of a personal data breach. The notice shall also meet any time limit that applicable Data Protection Laws set.

(b) The notification shall include, to the extent possible:

  • Description of the nature of the breach
  • Categories and approximate number of data subjects affected
  • Categories and approximate number of personal data records affected
  • Likely consequences of the breach
  • Measures taken or proposed to address the breach and mitigate harm

(c) The Processor shall provide reasonable assistance to the Controller in:

  • Investigating the breach
  • Notifying supervisory authorities (if required within 72 hours under GDPR Article 33)
  • Notifying affected data subjects (if required under GDPR Article 34)

(d) The Processor shall document all personal data breaches and make such documentation available to the Controller and supervisory authorities upon request.

5.6 Security Documentation

Upon reasonable request, the Processor shall provide Controller with documentation demonstrating compliance with this Section 5, which may include:

  • ISO 27001/27701 certification (when obtained)
  • SOC 2 Type II reports (from Cloudflare)
  • Security policy summaries
  • Results of security audits or penetration tests, when available (subject to confidentiality)

6. Assistance with Data Subject Rights

6.1 General Assistance Obligation

The Processor shall, taking into account the nature of processing, assist the Controller by appropriate technical and organisational measures, insofar as possible, for the fulfilment of the Controller’s obligation to respond to requests for exercising data subject rights under Data Protection Laws.

6.2 Data Subject Rights Under GDPR

The Processor shall assist the Controller in responding to requests to exercise the following rights:

  • Right of access (Article 15)
  • Right to rectification (Article 16)
  • Right to erasure / “right to be forgotten” (Article 17)
  • Right to restriction of processing (Article 18)
  • Right to data portability (Article 20)
  • Right to object (Article 21)

6.3 Support Data Implications

(a) Full-Text Data: Unlike a masked or pseudonymised architecture, support data may include the data subject’s name, email address, and readable message and attachment content. Data subject access requests may require the Processor to search ticket content, not only technical logs.

(b) Controller-Supplied Content: Attachments and support bundles are supplied by the Controller’s personnel. The Processor does not inspect or filter their content beyond what is needed to operate the support service.

6.4 Request Handling Process

(a) Redirecting Requests: If a data subject submits a request directly to the Processor, the Processor shall redirect the data subject to the Controller and inform the Controller of the request within 2 business days.

(b) Controller Requests: If the Controller forwards a data subject request to the Processor, the Processor shall:

  • Acknowledge receipt within 2 business days
  • Search Processor systems for relevant personal data
  • Provide available data to Controller within 10 business days in machine-readable format (JSON)
  • Confirm data deletion if requested

(c) Support Data Access: For access requests, the Processor can provide the ticket content, attachments, and technical log records described in Section 2.4 that relate to the data subject, within the retention periods stated there.

(d) Erasure Requests: For deletion requests, the Processor shall:

  • Delete the identified ticket, message, attachment, or bundle content within 5 business days
  • Confirm deletion in writing to Controller
  • Note that closed tickets and attachments auto-delete after 365 days, and bundles after 30 days, regardless (Section 2.4)
  • Note that the backup copies in Section 2.4 keep the deleted content until the Processor prunes its backups

6.5 No Fee for Standard Assistance

The Processor shall provide assistance with data subject rights requests at no additional charge for up to 10 requests per calendar year. Additional requests may be subject to reasonable fees based on effort required.


7. International Data Transfers

7.1 Transfer Locations

Personal data may be transferred to and processed in the following locations:

  • United States (Cloudflare infrastructure)
  • European Union (Cloudflare infrastructure)
  • Australia (Processor headquarters)
  • Other locations where Cloudflare operates edge infrastructure (300+ global locations)

7.2 Transfer Mechanisms

Where personal data is transferred from the European Economic Area (EEA), United Kingdom, or Switzerland to countries not recognised as providing adequate protection:

(a) Standard Contractual Clauses: The parties shall execute the Standard Contractual Clauses (SCCs) approved by the European Commission (Decision 2021/914, Module 2: Controller-to-Processor), incorporated as Annex A to this Agreement.

(b) UK Addendum: For transfers from the United Kingdom, the parties shall execute the UK International Data Transfer Agreement (UK IDTA) or the UK Addendum to the EU SCCs, as applicable.

(c) Swiss Addendum: For transfers from Switzerland, the parties shall execute appropriate amendments to address Swiss data protection requirements.

7.3 Sub-Processor Transfers

The Processor shall ensure that its Sub-Processor for support data (Cloudflare) provides equivalent safeguards for international data transfers through:

  • Cloudflare’s Data Processing Addendum, which incorporates the SCCs
  • ISO 27001 and SOC 2 Type II certifications
  • Supplementary security measures (encryption at rest, TLS in transit, Cloudflare Access gating, defined retention periods)

7.4 Transfer Impact Assessment

The Processor has completed a Transfer Impact Assessment (TIA) for transfers to the United States via Cloudflare, concluding:

  • Risk Level. Low to medium (see the full assessment in the SCC Addendum Annex IV)
  • Reasoning. Defined retention periods (Section 2.4), encryption in transit and at rest, access controls, government access risk assessed as low
  • Supplementary Measures. Encryption at rest (Cloudflare-managed), TLS in transit, Cloudflare Access gating of the administrative surface

7.5 Notification of Legal Requests

If the Processor receives a legally binding request from a government authority for disclosure of personal data transferred under this Agreement, the Processor shall:

  • Notify the Controller immediately (unless prohibited by law)
  • Challenge the request if there are reasonable grounds to do so
  • Seek to redirect the request to the Controller
  • Provide minimum data necessary to comply if disclosure is legally required

7.6 Alternative Transfer Mechanisms

If SCCs are invalidated or become ineffective, the parties shall cooperate to implement alternative lawful transfer mechanisms, which may include:

  • EU-US Data Privacy Framework (if Processor certifies)
  • Binding Corporate Rules
  • Derogations under GDPR Article 49 (if applicable)
  • Localisation of data processing within EEA

8. Audits and Inspections

8.1 Audit Rights

The Processor shall make available to the Controller all information necessary to demonstrate compliance with this Agreement and Data Protection Laws, and allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller.

8.2 Audit Process

(a) Notice: The Controller shall provide at least 30 days’ advance written notice of any intended audit.

(b) Frequency: Audits may be conducted no more than once per calendar year, unless:

  • Required by a supervisory authority
  • Following a personal data breach
  • Based on reasonable evidence of non-compliance

(c) Scope: Audits shall be limited to:

  • Compliance with this Agreement
  • Security measures described in Section 5
  • Sub-Processor management (Section 4)
  • Processing activities relevant to Controller’s data

(d) Conduct: Audits shall be conducted:

  • During business hours (Australian Eastern Time)
  • With minimal disruption to Processor’s operations
  • Subject to Processor’s reasonable security and confidentiality requirements
  • By auditors bound by confidentiality obligations

8.3 Documentation Audits

As a less intrusive alternative to on-site audits, the Controller may request documentation audits, whereby the Processor provides:

  • ISO 27001/27701 certification reports (when available)
  • SOC 2 Type II reports (from Cloudflare)
  • Internal security audit results
  • Compliance documentation (ROPA, privacy policies, security policies)

8.4 Third-Party Certifications

The Processor shall pursue and, where held, maintain third-party security certifications and make summaries available to Controller:

  • ISO 27001:2022 certification (aligned with standard, certification planned when commercially justified)
  • ISO 27701:2019 certification (aligned with standard, certification planned when commercially justified)
  • Cloudflare SOC 2 Type II reports (annual)

8.5 Audit Costs

(a) The Controller shall bear the costs of audits, including:

  • Auditor fees
  • Controller personnel time
  • Reasonable Processor cooperation time (up to 16 hours per audit)

(b) If an audit exceeds 16 hours of Processor cooperation time, additional time may be charged at the Processor’s standard professional services rates.

(c) If an audit identifies material non-compliance by the Processor, the Processor shall bear the reasonable costs of remediation audits.

8.6 Supervisory Authority Audits

The Processor shall cooperate with and contribute to audits conducted by supervisory authorities, and shall inform the Controller of such audits upon request (unless prohibited by law).


9. Liability and Indemnification

9.1 Processor Liability

(a) The Processor shall be liable for damages caused by processing where it:

  • Has not complied with obligations under Data Protection Laws specifically directed to processors
  • Has acted outside or contrary to lawful instructions of the Controller

(b) The Processor shall not be liable where it proves that it is not in any way responsible for the event giving rise to the damage.

9.2 Limitation of Liability

(a) To the maximum extent permitted by law, the Processor’s total aggregate liability under this Agreement shall not exceed the amounts paid by Controller to Processor in the 12 months preceding the claim.

(b) Nothing in this Agreement excludes, restricts, or modifies any right or remedy, or any guarantee, warranty, or other term or condition, that cannot be excluded under applicable law, including under the Australian Consumer Law (Schedule 2 to the Competition and Consumer Act 2010 (Cth)) and the Privacy Act 1988 (Cth). Subject to that, nothing in this Agreement shall limit liability for:

  • Death or personal injury caused by negligence
  • Fraud or fraudulent misrepresentation
  • Breach of confidentiality obligations
  • Indemnification obligations under Section 9.3

9.3 Indemnification

(a) Processor Indemnity: The Processor shall indemnify and hold harmless the Controller from and against any losses, damages, costs, and expenses (including reasonable legal fees) arising from:

  • Processor’s breach of this Agreement
  • Processor’s violation of Data Protection Laws
  • Claims by data subjects arising from Processor’s processing
  • Personal data breaches caused by Processor’s negligence or failure to implement security measures

(b) Controller Indemnity: The Controller shall indemnify and hold harmless the Processor from and against any losses, damages, costs, and expenses (including reasonable legal fees) arising from:

  • Controller’s unlawful instructions to Processor
  • Controller’s breach of Data Protection Laws
  • Claims that Controller’s services or content violate applicable laws
  • Controller’s failure to provide required notices to data subjects

(c) Indemnification Process: The indemnified party shall:

  • Notify the indemnifying party promptly of any claim
  • Cooperate reasonably with the indemnifying party in the defence
  • Allow the indemnifying party to control the defence (subject to indemnified party’s approval of settlements)

9.4 Regulatory Fines and Penalties

(a) If the Processor is fined or penalised by a supervisory authority due to Controller’s unlawful instructions or Controller’s breach of Data Protection Laws, the Controller shall reimburse such fines and penalties.

(b) If the Controller is fined or penalised by a supervisory authority due to Processor’s breach of this Agreement or Data Protection Laws, the Processor shall reimburse such fines and penalties, subject to the limitation of liability in Section 9.2.

9.5 Insurance

The Processor does not assert any specific insurance coverage in this Agreement. Insurance details are available on request.

9.6 Disclaimer of Warranties

To the maximum extent permitted by law, and except as expressly set out in this Agreement, the Processor provides the Services without any warranty, express or implied, including any implied warranty of merchantability, fitness for a particular purpose, or non-infringement. Nothing in this section excludes any guarantee, warranty, or right that cannot be excluded under the Australian Consumer Law or any other applicable mandatory law.


10. Term and Termination

10.1 Term

This Agreement commences on the Effective Date and continues until:

  • Termination of the Service Agreement, or
  • Earlier termination in accordance with this Section 10

10.2 Termination Rights

(a) Termination for Convenience: Either party may terminate this Agreement upon 30 days’ written notice if the Service Agreement is also terminated.

(b) Termination for Breach: Either party may terminate this Agreement immediately upon written notice if:

  • The other party materially breaches this Agreement and fails to cure within 30 days of written notice
  • The other party becomes insolvent or subject to bankruptcy proceedings
  • Continued performance would violate applicable law

(c) Termination for Sub-Processor Objection: The Controller may terminate this Agreement if the parties cannot resolve a Sub-Processor objection under Section 4.3(d).

(d) Termination by Supervisory Authority: This Agreement may be terminated if required by a supervisory authority.

10.3 Data Deletion or Return

(a) Upon termination or expiration of this Agreement, the Processor shall, at the Controller’s election:

  • Delete all personal data processed under this Agreement and existing copies, OR
  • Return all personal data to the Controller in a commonly used machine-readable format (JSON)

(b) The Controller shall notify the Processor of its election within 30 days of termination. If no election is provided, the Processor shall delete all personal data.

(c) Timeline: Data deletion or return shall be completed within 30 days of termination (or Controller’s election).

(d) Certification: The Processor shall provide written certification of deletion or return within 10 days of completion.

(e) Automatic Deletion: Due to the support platform’s automated retention policies, closed tickets and attachments auto-delete 365 days after the ticket closes, regardless of Controller election, and support bundles auto-delete 30 days after upload or on ticket close, whichever is sooner (Section 2.4).

(f) Backup Copies: Personal data in the backup copies listed in Section 2.4 is deleted when the Processor prunes its backups.

10.4 Retention Exceptions

The Processor may retain personal data to the extent and for such period as required by applicable law, provided that:

  • The Processor ensures confidentiality of retained data
  • The Processor processes retained data only as required by law
  • The Processor deletes retained data when the legal requirement expires

10.5 Survival

The following provisions shall survive termination:

  • Section 3.2 (Confidentiality)
  • Section 5.5 (Breach Notification - for breaches discovered post-termination)
  • Section 9 (Liability and Indemnification)
  • Section 10.4 (Retention Exceptions)
  • Section 11 (General Provisions)

11. General Provisions

11.1 Entire Agreement

This Agreement, together with the Service Agreement and any annexes or schedules, constitutes the entire agreement between the parties concerning personal data processing and supersedes all prior agreements, whether written or oral.

11.2 Amendment

This Agreement may be amended only by written agreement signed by both parties, except that the Processor may update:

  • Sub-Processor lists (subject to Section 4.3 notification requirements)
  • Security measures (provided they maintain or improve the level of protection)
  • Contact details and addresses

11.3 Governing Law

This Agreement shall be governed by and construed in accordance with:

  • The laws of Victoria, Australia
  • To the extent applicable, the GDPR and other Data Protection Laws

11.4 Dispute Resolution

(a) Negotiation: The parties shall attempt in good faith to resolve any dispute through negotiation between senior executives.

(b) Mediation: If negotiation fails within 30 days, the parties shall attempt mediation before an agreed mediator.

(c) Arbitration/Litigation: If mediation fails, disputes shall be resolved through:

  • Litigation in the courts of Victoria, Australia, and each party irrevocably submits to the exclusive jurisdiction of such courts

(d) Injunctive Relief: Nothing herein shall prevent either party from seeking injunctive relief in any court of competent jurisdiction.

11.5 Supervisory Authority Rights

Data subjects and supervisory authorities are third-party beneficiaries of this Agreement to the extent required by Data Protection Laws, with rights to enforce applicable provisions.

11.6 Conflict

In the event of conflict between this Agreement and the Service Agreement, this Agreement shall prevail with respect to personal data processing.

11.7 Severability

If any provision of this Agreement is held invalid or unenforceable, the remaining provisions shall remain in full force and effect. In that case, the invalid provision shall be replaced with a valid provision that most closely approximates the intent of the original.

11.8 Waiver

No waiver of any provision of this Agreement shall be effective unless in writing and signed by the waiving party. No waiver shall constitute a continuing waiver.

11.9 Assignment

Neither party may assign this Agreement without the prior written consent of the other party, except that either party may assign to a successor in connection with a merger, acquisition, or sale of all or substantially all of its assets, provided the assignee agrees to be bound by this Agreement.

11.10 Notices

All notices under this Agreement shall be in writing and delivered to:

Controller: [Controller Name] [Address] Email: [Email]

Processor: Maelstrom AI Pty Ltd ATF Maelstrom AI Holding Trust (ABN 61 633 823 792) PO Box 169, St Arnaud VIC 3478, Australia Email: support@maelstrom.au

Mail sent to a maelstrom.au address is stored in Maelstrom’s company mailboxes, which Proton AG hosts (see the Sub-Processors page).

11.11 Counterparts

This Agreement may be executed in counterparts. Each counterpart shall be deemed an original, and all of them together shall constitute one and the same instrument.


12. Annexes

Annex A: Standard Contractual Clauses (EU Commission Decision 2021/914, Module 2) - See separate document: /trust/legal/dpa-sccs-addendum

Annex B: Technical and Organisational Security Measures (Detailed) - Incorporated by reference to Section 5

Annex C: Sub-Processor List - Available at https://maelstrom.au/trust/legal/sub-processors


Signatures

CONTROLLER:

By: __________________________ Name: Title: Date:

PROCESSOR: Maelstrom AI Pty Ltd ATF Maelstrom AI Holding Trust

By: __________________________ Name: Title: Date:


Document Information

Document Title: Data Processing Agreement (Standard) Version: 2.5 Status: In force. Legal counsel reviewed Version 2.0; review confirmed 2026-09-04. Date: 2026-02-13 Last Updated: 2026-09-29 Classification: Legal Template Owner: ISMS Owner Next Review: On material change to the agreement or the in-scope systems

Change History:

  • 2.5 (2026-09-29): Plain English rewrite. No change to any commitment, right or obligation.
  • 2.4 (2026-09-25): Section 5 states the security measures in place: the single operator, TLS 1.2 or higher, the logs of administrative requests, the rate limits, the WAF and the support hours. Section 5.3 drops background checks, annual training, quarterly access reviews, privacy impact assessments, tabletop exercises and the 24-hour detection target, which are not in place. Section 3.2(b) states the confidentiality obligation. Section 5.5 sets breach notice without undue delay and within any legal time limit, in place of 24 hours. Section 7 names Cloudflare as the only Sub-Processor for support data. Section 2.4 lists the 30-day export snapshots and the backup copies. Sections 6.4(d) and 10.3(f) say when backup copies are deleted. Section 11.10 says that Proton hosts the maelstrom.au mailboxes.
  • 2.3 (2026-09-25): Factual corrections. Sections 5.2, 7.3 and 7.4 state TLS for transport encryption, with no minimum version. Section 7 names Amazon Web Services. The advisory beacon is opt-in (Section 4.5). No change to obligations.
  • 2.2 (2026-09-24): Technical log records are kept for 90 days (Section 2.4).
  • 2.1 (2026-09-24): Editorial update. No change to obligations.
  • 2.0 (2026-09-04): Scope and sub-processor update.
  • 1.1 (2026-06-19): Editorial update.
  • 1.0 (2026-02-13): Initial draft.

DISCLAIMER: This document does not constitute legal advice. Parties should consult their own legal counsel before executing this Agreement.

Compliance Mapping (identified requirements addressed):

  • GDPR Article 28 (Processor obligations)
  • GDPR Article 32 (Security of processing)
  • GDPR Article 33 (Breach notification)
  • GDPR Article 46 (International transfers)
  • ISO 27701:2019 (A.7.4.8 - Contracts with processors)

END OF DOCUMENT