Skip to content
aicial
Legal

Data Processing Agreement

Version: 1.0

Effective date: 19 August 2026

Last reviewed: 19 August 2026

This Data Processing Agreement sets out the data-protection terms that apply when Aperim Pty Ltd, which operates the aicial brand, processes personal information on your documented instructions as your processor or service provider. It forms part of, and is incorporated into, the Terms of Service or, where an order form or statement of work references it instead, our Master Subscription and Services Agreement, and sets out the security, sub-processing and international-transfer safeguards that apply to that processing.

1. About this Agreement

This Data Processing Agreement (“Agreement”) sets out the terms that apply when we process personal information on your documented instructions as your processor or service provider. Aperim Pty Ltd (ABN 46150699737; ACN 150699737) is incorporated in New South Wales, Australia and operates the aicial brand. In this Agreement, “aicial” refers to that brand; “we”, “us” and “our” refer to Aperim Pty Ltd; “Customer Agreement” means the Terms of Service or, where an order form or statement of work you have signed or otherwise agreed to in writing references our Master Subscription and Services Agreement (“MSA”) instead, that MSA; and “you” and “your” refer to the customer that has agreed to the Customer Agreement and on whose documented instructions we process personal information as described in this Agreement.

This Agreement applies wherever we process personal information on your documented instructions in connection with a service you have ordered under the Customer Agreement, including our planned self-serve software service once it becomes available — for example, personal information within a social account, audience or content you connect or submit for analysis, content creation or account protection. It does not apply to personal information we handle as controller in our own right, such as your own account, billing and contact details, which the Privacy Policy addresses directly.

This Agreement forms part of, and is incorporated into, the Customer Agreement. A term defined in the Customer Agreement has the same meaning in this Agreement unless this Agreement defines it differently. If this Agreement conflicts with the Customer Agreement on a data-protection matter it expressly addresses, this Agreement prevails for that matter; the Customer Agreement otherwise continues to apply in full, including its provisions on liability and dispute resolution described in sections 10 and 11 of this Agreement.

“Data protection law” means a law that applies to the processing of personal information under this Agreement, including the Privacy Act 1988 (Cth), the UK GDPR and Data Protection Act 2018, the EU GDPR, the Personal Information Protection Law of China (PIPL), the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA) and any other applicable US state comprehensive privacy law, and, once its substantive provisions come into force, the Digital Personal Data Protection Act 2023 (India). “Personal data”, “controller”, “processor”, “business”, “service provider”, “data subject” and “personal data breach” have the meaning given in the data protection law that applies to the relevant processing.

2. Controller and processor roles

The Privacy Policy explains that we act as controller for account, billing and our own service-operations data, and as your processor or service provider where we process personal information solely on your documented instructions, such as data from a social account or audience you connect — see Privacy Policy, section 1. This Agreement applies only to that second category of processing and does not change or duplicate the Privacy Policy’s description of our role as controller.

As between us, you are the controller (or business, under a law that uses that term) of the personal data we process under this Agreement. You are responsible for the lawfulness of your instructions to us, for having a lawful basis for the processing you instruct, and for meeting your own notice and disclosure obligations to the individuals concerned. We act as your processor (or service provider) and process that personal data only as this Agreement, the Customer Agreement and your documented instructions permit.

Where the CCPA applies to personal data we process under this Agreement, we are a service provider: we do not sell or share that personal data, consistent with the Privacy Policy’s sharing and disclosure section; we process it only for the business purposes this Agreement and the Customer Agreement specify; we do not retain, use or disclose it outside our direct business relationship with you or combine it with personal information we receive from another source, except as the CCPA permits a service provider to do; and we certify that we understand these restrictions and will comply with them.

If we reasonably consider that an instruction you give us infringes data protection law, we will tell you promptly and may suspend the affected processing until we agree a lawful approach with you.

3. Subject matter, duration, nature and purpose of processing

Subject matter. The processing of personal data by us on your behalf in order to provide the services you order under the Customer Agreement.

Duration. Processing continues for as long as we provide you the relevant service under an active order form, statement of work or account, and afterwards only as needed to meet the obligations in section 9 (Return and deletion of data).

Nature and purpose. We process personal data to deliver the aicial services described in the Customer Agreement — cross-platform outcome analytics, a closed-loop content engine, identity-protection scanning, a social-listening layer, and deal infrastructure — together with the related storage, hosting, security, support and troubleshooting needed to provide them. Processing takes the form of collection, storage, organisation, analysis, generation, transmission and deletion of the personal data described in section 4, carried out by automated means on the infrastructure described in section 5.

4. Personal data and data subjects

The Privacy Policy’s Information we collect section describes the categories of personal data we may process, including information from a connected social account and information automatically collected in connection with a service. This Agreement applies to that same information whenever we process it on your documented instructions, and we do not repeat that description here.

The data subjects are typically your own personnel and representatives, your customers, and members of the audience connected to, or engaging with, the social account, content or benchmark data you connect or submit — including, where you enable it, the reference material used for identity-protection matching described in the Privacy Policy’s sensitive information and identity protection section.

5. Our obligations as your processor

We will:

  • process personal data only on your documented instructions — including instructions in the Customer Agreement, an order form or statement of work, and this Agreement — unless a law binding on us requires us to process it differently, in which case we will tell you of that legal requirement before processing, unless that law prohibits us from doing so;
  • ensure that anyone we authorise to process personal data is subject to a duty of confidentiality, whether contractual or statutory;
  • implement appropriate technical and organisational measures to protect personal data against misuse, interference, loss, and unauthorised access, modification or disclosure, having regard to the state of the art, the cost of implementation, and the nature, scope, context and purpose of the processing;
  • taking into account the nature of the processing and the information reasonably available to us, provide reasonable assistance to help you respond to a data subject’s request to exercise a right under data protection law, and to meet your own obligations relating to the security of processing, breach notification, and data protection impact assessment or prior consultation with a regulator; and
  • notify you without undue delay after becoming aware of a personal data breach affecting personal data we process on your behalf, and provide the information reasonably available to us to help you assess the breach and meet your own notification obligations.

Our infrastructure is built on Cloudflare’s platform: Cloudflare Workers for compute, Cloudflare D1 as our primary database, and Cloudflare Turnstile for bot and abuse protection on forms. We have also engaged Cloudflare’s own Email Service binding for transactional email. As our planned self-serve software service and additional integrations are built, we expect to bring object storage, caching and background job processing — and other Cloudflare infrastructure — into use; we will update this description and the Sub-processor List before each of those comes into actual use. This lets us combine Cloudflare’s network and data-centre security controls with measures we apply ourselves, including access controls based on role and need, authentication and secrets management, encryption in transit and, where appropriate, at rest, logging and monitoring, secure development and change control, and incident-response procedures, consistent with the Privacy Policy’s security section.

Where we act as controller for personal data affected by a breach — for example, the account or billing data described in section 2 — the Privacy Policy’s own breach-notification commitments to regulators and individuals apply directly and are not affected by this section.

6. Sub-processors

You agree that we may engage sub-processors to help us provide a service, including the infrastructure described in section 5 and the categories of provider described in the Privacy Policy’s sharing and disclosure section. The current Sub-processor List identifies each sub-processor, its location and its function.

Before we engage a new sub-processor to process personal data under this Agreement, we will update the Sub-processor List and give you at least 30 days’ advance notice by publishing the update and, for a material addition, emailing the address on your account. This is our elected mechanism for prior authorisation of a new sub-processor under the Standard Contractual Clauses referenced in section 7 — general written authorisation under Clause 9(a), Option 2, satisfied by that 30 days’ notice. If you object on reasonable grounds relating to the protection of personal data, tell us in writing within that period, and we will work with you in good faith to address the objection — for example, by adjusting the processing or proposing an alternative safeguard. If we cannot reasonably address your objection, either of us may terminate the affected service on written notice, and we will refund any fees you have prepaid for the period after termination takes effect.

We remain responsible to you for a sub-processor’s performance of the obligations we flow down to it. We impose data-protection obligations on each sub-processor that are no less protective than those in this Agreement, having regard to the nature of the service it provides.

7. International transfers

We are based in Australia and process personal data using the Cloudflare-native infrastructure and sub-processors described in sections 5 and 6, which may be located outside your country, including in the United States. The Privacy Policy’s international transfers section describes our general approach under Australian, UK, EU and Chinese law. This section sets out the specific transfer mechanism that applies between us under this Agreement.

Where personal data protected by the EU GDPR is transferred from the European Economic Area to us in Australia, or on to a sub-processor in a country the European Commission has not found to provide an adequate level of protection, the transfer is governed by the Standard Contractual Clauses approved by European Commission Implementing Decision (EU) 2021/914 of 4 June 2021, using the module appropriate to the parties’ roles for that transfer (Module Two, controller to processor, or Module Three, processor to processor). Those clauses are incorporated into, and form part of, this Agreement by reference and, in accordance with their own terms, prevail over the rest of this Agreement to the extent of any inconsistency. Their Annexes are populated as follows: Annex I.A and I.B by the parties’ identities and the description of processing in sections 1 to 4 of this Agreement; Annex I.C (competent supervisory authority) by the supervisory authority of the Member State where our Article 27 EU representative is established, once we appoint one as described in the Privacy Policy, or, until then and consistent with Clause 13, the supervisory authority of the Member State where the data subjects concerned are located; Annex II by the measures described in section 5; and Annex III by the current Sub-processor List.

Where personal data protected by the UK GDPR is transferred from the United Kingdom to us in Australia, or on to a sub-processor in a country the UK has not found to provide an adequate level of protection, the transfer is governed by the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018 and in force since 21 March 2022, applied to the Standard Contractual Clauses incorporated under the preceding paragraph. That Addendum is incorporated into, and forms part of, this Agreement by reference and, together with the Standard Contractual Clauses it applies, prevails over the rest of this Agreement to the extent of any inconsistency, in accordance with its own terms, including its Mandatory Clauses. Where we agree with you to use the UK International Data Transfer Agreement in place of the Addendum for a transfer, this section’s references to the Addendum are read as references to that Agreement for that transfer.

Where personal data collected in China is transferred across its border, we use an approved PIPL mechanism as described in the Privacy Policy’s international transfers section — a security assessment, the China Standard Contract, or personal-information protection certification — and this Agreement forms part of, or is supplemented by, the China Standard Contract or the relevant certification where data protection law requires that document to take a particular form.

Where the Digital Personal Data Protection Act 2023 (India) applies to personal data processed under this Agreement, we support your compliance with its cross-border transfer provisions once its substantive provisions come into force on 13 May 2027. In the meantime we design our practices toward those requirements, consistent with the Privacy Policy’s regional information for India.

8. Audit and information rights

On reasonable request, and no more than once every 12 months unless a data protection regulator requires otherwise or the request follows a personal data breach affecting your data, we will make available the information reasonably necessary to demonstrate our compliance with this Agreement, which may include a summary of the technical and organisational measures described in section 5, the current Sub-processor List, and, where we hold one, a relevant excerpt of an independent security assessment.

If that information does not reasonably satisfy your own compliance obligations, you may request a further audit of our processing of your personal data. We will agree a reasonable scope, timing and an independent auditor bound by confidentiality with you, allow the audit during business hours on at least 30 days’ notice, and ensure it does not unreasonably disrupt our business or expose another customer’s data. You bear your own costs of an audit, and our reasonable costs of supporting one, unless it identifies a material breach of this Agreement, in which case we bear our own costs of supporting it. You will share the resulting report with us and treat it as confidential information under the Customer Agreement.

9. Return and deletion of data

On termination or expiry of the service to which this Agreement relates, you may elect deletion or return of the personal data we process on your behalf by written request made within 30 days after termination or expiry. If you make no election within that period, we will delete that personal data, and delete existing copies, within a further 60 days. In either case we act consistent with the retention and deletion commitments in the Privacy Policy’s data quality, retention and deletion section, unless a law binding on us requires us to keep the data, in which case we keep it only for as long as that law requires and continue to protect it as this Agreement requires until deletion.

Consistent with our commitment in the Terms of Service or, where the MSA governs your engagement, its equivalent commitment, we make your data available for export for a reasonable period after termination so you can make your own request under this section before deletion.

10. Liability

Each of our total liability arising out of or in connection with this Agreement forms part of, and is subject to the same cap as, our total liability under the Customer Agreement — the limitation of liability in Terms of Service, section 14, or, where the MSA governs your engagement, in MSA, section 8. This Agreement does not create a separate or additional liability cap.

Nothing in this section limits a right or remedy under data protection law that cannot lawfully be excluded or limited, including a data subject’s right to compensation directly against us where that law confers it.

11. Governing law and dispute resolution

This Agreement is governed by the law of New South Wales, Australia. A dispute arising out of or in connection with this Agreement is resolved in the same way as a dispute under the Customer Agreement, under the binding arbitration clause at Terms of Service, section 16 (incorporated into the MSA, where that governs your engagement, under MSA, section 11), including its pre-arbitration good-faith step, its expedited and emergency-relief procedures, and its preservation of non-waivable statutory rights and of either party’s right to seek urgent injunctive relief to protect intellectual property or confidential information.

This section does not govern the Standard Contractual Clauses or the UK Addendum incorporated under section 7. Those clauses are governed by, and a dispute arising under them is resolved in accordance with, their own terms — including clauses 17 and 18 of the Standard Contractual Clauses, and the equivalent governing-law and jurisdiction provisions of the UK Addendum’s Mandatory Clauses — which prevail over this section to the extent of any inconsistency.

12. Term and changes to this Agreement

This Agreement takes effect when you first agree to the Customer Agreement and continues for as long as we process personal data on your documented instructions, or until the Customer Agreement ends, whichever is later, subject to section 9 (Return and deletion of data).

We may update this Agreement to reflect a change to our services, our sub-processors, our practices or data protection law. The version and effective date shown at the top identify the current Agreement. Where a change is material, we provide notice in the same way as a material change to the Customer Agreement before the change takes effect.

13. Contact us

For questions about this Agreement, or to make a request under it, contact:

Aperim Pty Ltd, which operates the aicial brand
ABN 46150699737
ACN 150699737
New South Wales, Australia
Email: privacy@aicial.com