These Data Processing Terms apply where Geepers (ABN 15 968 140 556) handles personal information on behalf of an organisation Customer as part of the Business Services (see our Organisation & API Terms). They are made under the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Our handling of personal information for our own purposes is covered by our Privacy Policy.
The Customer decides why and how personal information in its Customer Data is handled and is responsible for it. Geepers handles that personal information on the Customer's behalf, to provide the Business Services. Each party must comply with the Privacy Act and the APPs as they apply to it.
Geepers will handle personal information in Customer Data only to provide and support the Business Services, in line with these Terms and the Customer's reasonable documented instructions. If we believe an instruction would breach the Privacy Act or other law, we will tell the Customer.
The Customer warrants that it has authority to provide the Customer Data to us, that it has given any privacy notices and obtained any consents required (including for location or other sensitive information), and that our handling of it on the Customer's instructions is lawful. The Customer is responsible for the accuracy and lawfulness of the Customer Data it provides.
We will keep personal information in Customer Data confidential and limit access to personnel who need it to provide the Business Services and who are bound by confidentiality obligations.
We will take reasonable technical and organisational steps to protect personal information in Customer Data from misuse, interference, loss and unauthorised access, modification or disclosure, consistent with APP 11.
We use third-party service providers — such as cloud hosting, database, email and SMS providers — to help deliver the Business Services. We impose confidentiality and data-protection obligations on them and remain responsible for their handling of personal information in Customer Data.
Some service providers store or process data outside Australia, including in the United States. Where personal information is disclosed overseas, we take reasonable steps to ensure it is handled consistently with the APPs. The Customer acknowledges this and, where required, must inform the individuals concerned.
Taking into account the nature of the Business Services, we will provide reasonable assistance to help the Customer respond to requests from individuals to access or correct their personal information (APPs 12 and 13) and to handle privacy enquiries or complaints relating to Customer Data.
If we become aware of an eligible data breach, or a breach likely to result in serious harm, affecting personal information in Customer Data, we will notify the Customer without undue delay and cooperate reasonably so the parties can meet their obligations under the Notifiable Data Breaches scheme.
On termination of the Business Services, we will delete or, if reasonably requested, return personal information in Customer Data within a reasonable period, except for copies retained in routine backups for a limited time or where the law requires us to keep them.
On reasonable request, we will provide the Customer with information reasonably necessary to demonstrate our compliance with these Terms in relation to Customer Data.
These Terms form part of the Organisation & API Terms. If there is any conflict about the handling of personal information in Customer Data, these Terms prevail to the extent of the conflict.
These Terms are governed by the laws of New South Wales, Australia.
For questions about these Terms or data handling, contact our Privacy Officer at privacy@geepers.io.
ABN: 15 968 140 556
New South Wales, Australia
Made under Australian law.
