The Australia-first processing terms for Business Customers, including roles, instructions, security, subprocessors, overseas processing, deletion and model providers.
KoalaFix Pty Ltd · ABN 99 696 245 959 · 425 Smith Street, Fitzroy VIC 3065 · support@koalafix.com
In this DPA:
The Customer is Controller and KoalaFix is Processor for Customer Personal Data processed to provide, secure, support and maintain the Service and carry out the Customer's documented instructions.
KoalaFix is an independent Controller for limited information it processes for its own legitimate business obligations, such as its corporate, tax and financial records; direct relationship with Customer administrators; fraud and security investigation; legal claims; and permitted business communications. The Privacy Policy applies to that processing.
KoalaFix does not become an independent Controller merely to train a general model on raw Business Customer conversation or Microsoft 365 content. It will not use that content for a general or cross-customer model unless the Customer's administrator gives a separate affirmative opt-in that clearly describes the use.
The Agreement, the Customer's use and configuration of the Service, support requests, Orders and other written directions are the Customer's documented instructions.
KoalaFix will process Customer Personal Data only on those instructions, unless law requires otherwise. Where legally permitted, KoalaFix will tell the Customer about a mandatory requirement before processing.
KoalaFix will promptly inform the Customer if it reasonably believes an instruction infringes Applicable Data Protection Law. KoalaFix may pause the affected processing while the parties address the issue.
The Customer must:
KoalaFix must:
The subject matter, duration, nature, purposes, data types and data-subject categories are in Schedule 1.
KoalaFix will maintain reasonable technical and organisational measures appropriate to the nature of Customer Personal Data, the Service, reasonably foreseeable threats and the cost and availability of safeguards. Current measures are summarised in Schedule 2.
KoalaFix may update controls as technology and risk change, provided the overall protection is not materially reduced during an active Order.
The Customer acknowledges that no system can guarantee absolute security and that security is shared: the Customer remains responsible for its devices, identity environment, Microsoft tenant, administrator permissions, backups and user conduct.
KoalaFix will ensure personnel with access to Customer Personal Data:
Access will be removed when no longer required.
The Customer generally authorises the Subprocessors listed at koalafix.com/subprocessors. That page forms part of this DPA.
KoalaFix will:
KoalaFix will give at least 30 days' advance notice before appointing a new Subprocessor that will materially process Customer Personal Data or materially changing such a Subprocessor. Notice may be shorter where an urgent security, legal or service-continuity event makes advance notice impracticable; in that case KoalaFix will notify the Customer promptly and explain the reason.
The Customer may object during the notice period on reasonable data-protection grounds. The parties will try in good faith to resolve the objection through additional safeguards, a configuration change or an alternative provider. If they cannot resolve a material objection, the Customer may terminate the affected Service and receive a pro-rata refund of prepaid fees for the unused affected period.
The Customer authorises processing in the countries and regions stated in the Subprocessor List.
KoalaFix will take reasonable steps required by Applicable Data Protection Law before disclosing Customer Personal Data to an overseas recipient, including appropriate contractual protections, data minimisation, access controls and provider review. This DPA does not reduce any accountability KoalaFix has under APP 8 or another applicable law.
If the Customer proposes to submit Personal Data subject to the EU GDPR, UK GDPR or another law requiring specific transfer clauses, the parties must complete an appropriate written transfer addendum before that processing begins. This web DPA does not, by itself, represent that the EU Standard Contractual Clauses or UK Addendum have been validly completed for every Customer.
Taking into account the nature of the processing, KoalaFix will provide reasonable assistance for the Customer to respond to an access, correction, deletion, objection or other data-subject request.
If KoalaFix receives a request relating to Customer Personal Data, it will refer the person to the Customer and notify the Customer where lawful. KoalaFix will not independently respond on the Customer's behalf unless instructed or legally required.
Routine self-service functions and reasonable assistance are included in the Service. KoalaFix may charge reasonable agreed costs for unusually extensive, repetitive or bespoke work not caused by KoalaFix's breach.
KoalaFix will notify the Customer without undue delay and, where practicable, within 48 hours, and no later than 72 hours, after becoming aware of a Data Breach affecting Customer Personal Data.
As information becomes available, the notice will describe:
KoalaFix will investigate, contain and remediate the Data Breach; preserve relevant evidence; provide reasonable updates; and assist the Customer with legally required assessment and notification. A notice is not an admission of fault.
The Customer controls notification for breaches where it is Controller, except to the extent KoalaFix has its own direct legal notification duty. The parties will coordinate public statements where practicable.
KoalaFix will provide reasonable information and assistance for a privacy impact assessment, security assessment or regulator consultation relating to the Service, taking into account the nature of processing and information available to KoalaFix.
On reasonable written request, no more than once in a 12-month period, KoalaFix will provide information reasonably necessary to demonstrate compliance, such as security documentation, responses to a questionnaire, relevant certifications or audit summaries if available.
Additional audits may occur after a material Data Breach, a regulator's lawful request, or credible evidence of material non-compliance. The parties will minimise disruption, protect other customers and confidential security information, and use an independent auditor where appropriate.
The Customer bears the cost of an ordinary bespoke audit. KoalaFix bears reasonable audit costs to the extent an audit identifies KoalaFix's material breach of this DPA.
During the Order, the Customer may use available export functions or request a reasonable export in a commonly used format.
After termination or on a valid Customer instruction, KoalaFix will delete or de-identify Customer Personal Data within 90 days, unless:
KoalaFix will not use retained data for another purpose. On request, it will confirm completion of the ordinary deletion process. The Customer acknowledges that properly de-identified information is not Customer Personal Data.
Microsoft Azure OpenAI Service processes customer-facing chat inputs and outputs. OpenAI processes query text for embeddings used in knowledge retrieval. Provider no-training commitments and current locations are described in the Privacy Policy and Subprocessor List.
KoalaFix will not opt Customer Personal Data into a model provider's training or improvement program.
KoalaFix will not select raw Customer Personal Data for its own general or cross-customer model improvement unless the Customer administrator has separately opted in under a clear written description of the use, safeguards, withdrawal process and retention.
The liability provisions in the Terms of Service apply to this DPA. Nothing in the Agreement limits liability to the extent it cannot lawfully be limited.
If this DPA conflicts with another part of the Agreement on the processing and protection of Personal Data, this DPA prevails. An Order may impose stronger data-protection obligations if it expressly identifies the provision being changed.
This DPA begins when KoalaFix first processes Customer Personal Data and continues until that processing ends. Sections that must continue to protect retained data survive termination.
Privacy and DPA enquiries: support@koalafix.com
This DPA is governed by the law governing the Terms of Service.
| Item | Description |
|---|---|
| Subject matter | AI-assisted IT diagnostics, remediation, Microsoft 365 integration, account administration, support, security and related Service functions |
| Duration | The subscription, trial or Pilot term plus the verified retention and deletion periods |
| Nature of processing | Collection, access, transmission, hosting, organisation, analysis, retrieval, generation, logging, support, export, deletion and de-identification |
| Purposes | Providing, securing, supporting and maintaining the Service; carrying out Customer-authorised actions; complying with documented instructions and law |
| Data subjects | Customer personnel, contractors, users, administrators, support contacts, and people whose information appears in a connected device, Microsoft 365 environment or submitted content |
| Account data | Name, email, organisation, role, account and workspace identifiers, subscription and administrator information |
| Service content | Prompts, conversations, AI responses, support content, issue descriptions, feedback and outcomes |
| Device and diagnostic data | Device identifiers, system and application configuration, service/process/network state, paths, error logs, crash information, remediation actions and outcomes |
| Microsoft 365 data | Authorised profile, mailbox, calendar, file, SharePoint, Teams, Planner, directory, group, licence, authentication-method, organisation and Intune information, depending on granted permissions and requested features |
| Usage and security data | IP address, timestamps, session and feature events, token/request counts, authentication, audit, fraud and security signals |
| Sensitive or special data | Not intentionally required as a general category. It can appear incidentally in free text, file paths, Microsoft 365 content or diagnostics. Customers should not submit it unless necessary and lawful. |
KoalaFix's measures include, as applicable:
This schedule does not claim SOC 2 certification, a particular penetration-test cadence, or a service level unless KoalaFix separately documents and verifies it.