Product: VettiGuard Product owner and provider: Ikemba Tech (ABN 82 565 415 510) Effective date: 25 September 2026 Version: 1.3
1. Scope
This Data Processing Addendum (DPA) applies where VettiGuard processes personal information contained in Customer Data on behalf of a customer in connection with the Services. It supplements the Terms of Service and any applicable order form.
Australian privacy law does not generally use the European terms "controller" and "processor". Where those terms are used by a customer's other legal framework, they are used in this DPA only as functional descriptions and do not alter the allocation of responsibility under Australian law.
2. Customer instructions
VettiGuard will process Customer Data only to provide, secure, support and maintain the Services; comply with documented customer configuration and instructions; prevent abuse and security incidents; meet applicable legal obligations; and as otherwise permitted by the agreement.
The customer must ensure its instructions are lawful and that it has provided required notices and obtained required consent or authority.
3. Sensitive and biometric information
Where Customer Data includes biometric, identity-document, health-related or other sensitive information, the customer must ensure collection and use are reasonably necessary and proportionate to the configured purpose and supported by appropriate authority.
VettiGuard will restrict access to sensitive verification evidence and will not use customer biometric information for advertising or unrelated profiling.
4. Personnel confidentiality
VettiGuard will limit access to Customer Data to personnel and service providers who need access for authorised functions and who are subject to appropriate confidentiality obligations.
5. Security measures
VettiGuard will maintain reasonable technical and organisational measures appropriate to the risk, which may include encryption, access control, least-privilege permissions, workspace isolation, secret management, short-lived capabilities, server-side verification, replay protection, logging, monitoring, backup controls, vulnerability management and incident response.
6. Subprocessors
The customer authorises VettiGuard to use subprocessors necessary to provide the Services. Material subprocessors are identified in the Data Hosting & Subprocessor Notice.
VettiGuard uses material providers for production hosting and service communications. The current providers, purposes and relevant processing locations are maintained in the Data Hosting & Subprocessor Notice.
VettiGuard will require material subprocessors to protect Customer Data through appropriate contractual, confidentiality and security commitments where reasonably practicable.
7. Changes to subprocessors
VettiGuard may change subprocessors for security, reliability, service or business reasons. Material changes will be reflected in the Data Hosting & Subprocessor Notice. Enterprise customers that have a negotiated notification requirement will receive notice in accordance with their agreement.
8. Overseas processing
The customer acknowledges that VettiGuard's primary hosting is in the United States. Customer Data may also be processed through communications and recipient infrastructure outside Australia.
Where APP 8 applies, VettiGuard will take reasonable steps appropriate to the circumstances to address overseas handling, subject to applicable exceptions. Customers remain responsible for any additional data-residency or sector-specific restrictions applicable to their own use.
9. Data minimisation
The customer should provide only the minimum data required by the selected API or journey. Where an opaque identifier is sufficient, the customer should not send a name, email address, government identifier or other directly identifying information.
Passwords, access tokens, card numbers, CVVs, unrelated health information and raw identity documents must not be placed in generic reference, logging or custom-scope fields.
10. Data-subject and privacy requests
Where a person submits an access, correction, deletion or other privacy request relating to Customer Data controlled by the customer, VettiGuard may refer the person to the customer and will provide reasonable technical assistance where required by the agreement and applicable law.
11. Security incidents
VettiGuard will investigate confirmed unauthorised access to, disclosure of or loss of Customer Data under VettiGuard's control. Where the incident materially affects Customer Data, VettiGuard will notify the affected customer without undue delay once sufficient information is available to provide a meaningful notice, subject to legal and security restrictions.
The parties will cooperate reasonably in assessing whether notification under the Notifiable Data Breaches scheme or another applicable law is required.
12. Retention, return and deletion
VettiGuard will retain Customer Data according to the configured service, the Data Retention, Deletion & Legal Hold Policy, contractual requirements and applicable law. At termination, the customer should export available data it is entitled to retain. VettiGuard may then delete or de-identify remaining Customer Data, subject to backups, security records and lawful holds.
13. Audit and assurance
VettiGuard may provide reasonable security, architecture or compliance information to customers subject to confidentiality and security restrictions. On-site or invasive audits are not permitted unless separately agreed or legally required. VettiGuard may use questionnaires, evidence packs, independent assessments or scoped review sessions as practical alternatives.
14. Government and issuer services
VettiGuard native document screening is not government verification. A customer that separately enables a government or issuer identity service is responsible for eligibility, participation agreements, notices, consent, use restrictions and any additional statutory obligations applicable to that service.
15. Order of precedence
If this DPA conflicts with the Terms of Service on the handling of Customer Data, this DPA prevails for that issue. A specifically negotiated written data-processing agreement prevails over this standard DPA to the extent of conflict.