EDMISS Data Processing Addendum

Last updated: 31 August 2026

This Data Processing Addendum (DPA) forms part of the agreement between Equator Pty. Ltd. trading as Equator Information Technology (Equator IT, we, us or our) and the customer that accepts the EDMISS Customer Terms of Service or enters into an Order Form with us (Customer, you or your) (the Agreement).

This DPA applies when Equator IT Processes Personal Information contained in Customer Data on the Customer’s behalf. It is a contract between Equator IT and the Customer. It does not replace the EDMISS Privacy Policy, which explains how Equator IT handles Personal Information and how individuals can exercise their privacy rights.

If this DPA conflicts with the Agreement on the Processing of Customer Data, this DPA prevails to the extent of the conflict.

1. Definitions and roles

Capitalised terms not defined in this DPA have the meanings given in the Agreement. In this DPA:

Applicable Data Protection Law means privacy, data-protection, cybersecurity, breach-notification and electronic-communications laws that apply to the Processing of Customer Data.

Personal Information means personal information, personal data and analogous terms under Applicable Data Protection Law.

Process and Processing mean any operation performed on Personal Information, including collecting, storing, accessing, using, disclosing, transmitting, altering, restricting, deleting and destroying it.

Security Incident means an actual or reasonably suspected unauthorised or unlawful destruction, loss, alteration, access to, disclosure of, or use of Customer Data.

Subprocessor means an Equator IT affiliate or third party engaged by Equator IT to Process Customer Data on Equator IT’s behalf in providing the Services.

As between the parties, the Customer is the Controller of Customer Data because it determines the purposes and means of Processing; Equator IT is the Customer’s Processor; and, where the Customer acts as a processor for another Controller, Equator IT is the Customer’s Subprocessor.

Equator IT is an independent Controller, rather than the Customer’s Processor, when it handles account, billing, support, website, security, product-telemetry and marketing information for the purposes described in the EDMISS Privacy Policy. This DPA does not apply to that independent Processing.

2. Processing instructions

The Customer instructs Equator IT to Process Customer Data only as necessary to:

  1. provide, operate, secure, maintain and support EDMISS and related services;
  2. perform the Agreement and functionality configured or requested by authorised Users;
  3. prevent, detect, investigate and remediate security, fraud, misuse, technical and service-integrity issues;
  4. comply with the Customer’s documented instructions that are consistent with the Agreement; and
  5. comply with Applicable Data Protection Law.

The details of this Processing are set out in Appendix A. Equator IT will notify the Customer if, in its reasonable opinion, an instruction infringes Applicable Data Protection Law, unless prohibited by law. If a law requires Equator IT to Process Customer Data other than in accordance with the Customer’s instructions, Equator IT will notify the Customer before doing so unless prohibited by law.

3. Confidentiality and security

Equator IT will ensure that personnel authorised to Process Customer Data are subject to enforceable confidentiality obligations and access Customer Data only where necessary to perform their duties.

Equator IT will implement and maintain appropriate technical and organisational measures designed to protect Customer Data against accidental, unlawful or unauthorised destruction, loss, alteration, access, disclosure or use. These measures are described in Appendix B and will take account of the nature, scope, context and purpose of Processing, the sensitivity and volume of Customer Data, and the risks to individuals.

Equator IT may update its measures as technology, threats and industry practice evolve, provided it does not materially reduce the overall security of the Services during the subscription term, except where reasonably necessary to comply with law or address an urgent security risk.

4. Assistance

Taking account of the nature of Processing and information reasonably available to it, Equator IT will provide reasonable assistance to enable the Customer to:

  1. respond to requests from individuals to access, correct, delete, restrict or otherwise exercise applicable privacy rights in relation to Customer Data;
  2. conduct a privacy impact assessment or consult a regulator where required in connection with the Services; and
  3. meet its applicable data-security and breach-response obligations.

If Equator IT receives a request directly from an individual about Customer Data, it will refer the request to the Customer unless the Customer instructs otherwise or law requires Equator IT to respond directly. Equator IT may charge reasonable professional-services fees for assistance beyond the ordinary functionality of the Services.

5. Security Incidents

Equator IT will notify the Customer of a Security Incident without undue delay and, in any event, within 48 hours after becoming aware of it. The initial notice will include information reasonably available at that time.

Equator IT will take reasonable steps to contain, investigate and remediate the Security Incident, provide material updates as information becomes available, and reasonably cooperate with the Customer’s assessment and response.

The Customer is responsible for determining whether Customer Data requires notification to individuals, regulators or other third parties, unless Applicable Data Protection Law requires Equator IT to notify directly. Where both parties may have notification obligations, they will cooperate and coordinate in good faith. Nothing in this DPA prevents either party from making a notification required by law.

6. Subprocessors and Customer-selected integrations

The Customer gives Equator IT general authorisation to use Subprocessors to provide the Services, subject to this section.

Equator IT will maintain a current EDMISS Subprocessor List identifying each Subprocessor that may Process Customer Data, its service and its processing location. Before allowing a Subprocessor to Process Customer Data, Equator IT will enter into a written agreement requiring privacy, confidentiality, security, incident-notification and deletion protections appropriate to the services it provides. Equator IT remains responsible for its Subprocessors’ Processing of Customer Data, subject to the liability provisions of the Agreement.

A third-party App, API connection, automation or workflow that the Customer enables, configures, directs or controls is a Customer-selected integration. It is not an Equator IT Subprocessor solely because Equator IT makes an API, connector or integration capability available. The Customer determines the Customer Data it transfers to that provider and is responsible for authorising and configuring it. A provider is an Equator IT Subprocessor only where Equator IT engages, operates or manages it to Process Customer Data for the Services.

7. International Processing

Before Equator IT discloses Customer Data to a recipient in another country or region on the Customer’s behalf, it will apply the transfer safeguards required by Applicable Data Protection Law. The EDMISS Privacy Policy and EDMISS Subprocessor List provide public information about Equator IT’s Processing practices and processing locations.

The Customer is responsible for assessing and authorising international transfers it directs through a Customer-selected integration.

8. Return and deletion

During the subscription term, the Customer may extract Customer Data using the functionality described in the Agreement.

Within 30 days after termination or expiry of the Agreement, Equator IT will securely delete Customer Data in its possession or control, including Customer Data in active systems, replicas, archives and backups, except information that has been properly de-identified or that Equator IT must retain by law. Retained information will remain protected, be used only for the required purpose, and be securely deleted when retention is no longer required.

9. Transparency and compliance support

On reasonable written request, Equator IT will make available information about its privacy and security practices relevant to the Services. This may include the EDMISS Privacy Policy, this DPA, the EDMISS Subprocessor List, Systems Reliability terms and reasonable responses to Customer security or privacy questions.

Equator IT may protect the confidentiality and security of its systems, other customers and its proprietary information when providing that information. Any additional audit or due-diligence arrangement may be agreed separately in writing.

10. Legal requests

If Equator IT receives a legally binding request for Customer Data, such as a court order, subpoena or regulator request, it will notify the Customer promptly where legally permitted. Equator IT will provide reasonable assistance to enable the Customer to seek a protective order or other appropriate remedy, and will disclose only the minimum Customer Data required by the request.

11. Term, survival and liability

This DPA starts when the Customer first accepts the Agreement and continues while Equator IT Processes Customer Data. The confidentiality, security, deletion, liability and other provisions that should survive will survive until Customer Data has been securely deleted or de-identified, except to the extent retention is required by law.

The liability provisions, exclusions and limitations in the Agreement apply to this DPA, except to the extent Applicable Data Protection Law does not permit their application.

Appendix A — Processing Details

Item Details
Controller / data exporter The Customer, or the Controller on whose behalf the Customer acts.
Processor / data importer Equator Pty. Ltd. trading as Equator Information Technology, PO Box 7033, Southport QLD 4215, Australia; support@equatorit.com.
Subject matter and purpose Provision, operation, hosting, security, maintenance and support of EDMISS and related services, and performance of the Agreement.
Duration The subscription term plus the limited retention period in section 8.
Nature of Processing Collection, recording, organisation, storage, access, retrieval, use, disclosure by transmission where directed or authorised, support, backup, restoration, security monitoring, restriction, deletion and destruction.
Frequency Continuous and on demand throughout the subscription term.
Data Subjects Any individual whose Personal Information is included in Customer Data. This may include students, prospective students, applicants, graduates, alumni, education agents, parents, guardians, emergency contacts, accommodation and welfare contacts, referees, employers, staff, contractors, authorised Users, suppliers, payers, recipients of communications and individuals recorded in documents, attachments, notes or Customer-configured fields or Services.
Personal Information Customer Data that the Customer, its Users or an authorised integration uploads, enters, generates, receives, transmits or otherwise Processes through the Services, to the extent it is Personal Information. This may include identity and contact information; date of birth and demographics; enrolment, course, attendance, assessment and academic information; communications; education-agent and commission information; billing, invoicing and payment information; government-related identifiers; immigration or visa information; welfare, support, accommodation and guardianship information; account, authentication, audit and technical usage data; documents and attachments; and information in Customer-configured fields or Services.
Sensitive Information Sensitive Information included in Customer Data where the Customer stores it and is permitted to do so. This may include health, disability, racial or ethnic origin, religious beliefs, sexual orientation, biometric information, criminal-record information or other Sensitive Information under Applicable Data Protection Law.
Processing locations The locations identified in the applicable Order Form, EDMISS Subprocessor List, EDMISS Privacy Policy or current hosting documentation.

Appendix B — Technical and Organisational Measures

Equator IT maintains measures designed to include:

  1. documented information-security, privacy and incident-response practices; personnel training; and confidentiality obligations;
  2. unique accounts, role-based access, least-privilege administration, appropriate authentication controls and prompt access revocation;
  3. protected API credentials, integration access controls and logging appropriate to the Services;
  4. appropriate protections for Sensitive Information and high-risk information according to authorised roles and product configuration;
  5. industry-standard protection of Customer Data and credentials in transit and at rest;
  6. network, endpoint, infrastructure, patching, vulnerability-management and monitoring measures appropriate to the Services;
  7. logging and monitoring designed to identify suspicious activity, faults and Security Incidents;
  8. backup, recovery, business-continuity and disaster-recovery measures appropriate to the Services;
  9. access-controlled development, review, testing and change-management practices proportionate to risk;
  10. Security Incident detection, containment, investigation, documentation and remediation processes; and
  11. proportionate privacy and security due diligence, written protections and oversight for Subprocessors.