Skip to content

Data Processing Agreement

How TorqueOS handles personal information it processes on your behalf when you use the Platform.

Last updated: 27 February 2026

1. Overview & Roles

This Data Processing Agreement ("DPA") forms part of, and is incorporated into, the Terms of Service between TorqueOS Pty Ltd (ABN [ABN to be inserted]) ("TorqueOS") and the customer ("you"). It applies whenever TorqueOS processes personal information on your behalf through the Platform. Capitalised terms not defined here have the meaning given in the Terms of Service.

Our roles differ depending on the data:

  • Customer Data (we are the processor / service provider): personal information you and your Users upload or create in the Platform about third parties - including your staff, drivers, contractors, and your own customers. You are the entity responsible for that information (the equivalent of a "controller"), and we process it only on your instructions to provide the Services.
  • Account & billing data (we are the controller): the information we collect to operate your account, bill you, secure the Platform, and communicate with you, as described in our Privacy Policy.

Because we are a processor of Customer Data, requests from an individual to access, correct, or delete personal information within Customer Data should be directed to you, not to TorqueOS. We will refer such requests to you and assist you in responding (see Section 7).

2. Details of Processing

  • Subject matter & duration: processing for the term of your Subscription and any post-termination export/deletion period described in the Terms of Service.
  • Nature & purpose: hosting, storing, organising, displaying, transmitting, backing up, and otherwise processing Customer Data as necessary to provide the fleet and workshop management Services.
  • Types of personal information: names, business and email addresses, phone numbers, roles/permissions, and any personal information you choose to include in vehicle records, work orders, inspections, defects, photographs, and notes.
  • Categories of individuals: your personnel and Users, your drivers and contractors, and (where you record them) your own customers and their contacts.

3. Your Obligations

  • You warrant that you have a lawful basis to provide the Customer Data to us and to authorise our processing of it, and that you have given any notices and obtained any consents required under the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles ("APPs") - including, where applicable, an APP 5 collection notice to your staff and drivers.
  • You are responsible for the accuracy, quality, and legality of Customer Data and for your instructions to us.
  • Where you connect to another organisation through the Platform (for example a fleet-workshop link), you authorise the resulting sharing of Customer Data described in the Privacy Policy and warrant you may lawfully do so.

4. Our Obligations

  • Instructions: we process Customer Data only on your documented instructions (including as set out in the Terms of Service and this DPA), except where required by law, in which case we will inform you unless legally prohibited.
  • Confidentiality: personnel authorised to process Customer Data are bound by confidentiality obligations.
  • Security: we maintain the technical and organisational measures described in the "Data Storage & Security" section of our Privacy Policy (encryption in transit and at rest, role-based access control, multi-factor authentication, tenant isolation, backups, and monitoring), consistent with APP 11.

5. Sub-processors

You authorise us to engage sub-processors to help provide the Services. Each sub-processor is bound by data-protection obligations no less protective than those in this DPA. Our current sub-processors include:

  • Amazon Web Services - cloud hosting and storage (Sydney, Australia).
  • Stripe - payment processing.
  • Resend - transactional and notification email delivery.
  • Google - Maps/Places address lookup and (where enabled) analytics.
  • Australian Business Register (ABR) - ABN/business-name verification at onboarding.

We will give you at least 30 days' notice before adding or replacing a sub-processor that processes Customer Data. If you reasonably object on data-protection grounds, you may terminate the affected Services without penalty if we cannot offer a reasonable alternative.

6. Data Breach Notification

If we become aware of a data breach (within the meaning of the Notifiable Data Breaches scheme under Part IIIC of the Privacy Act 1988) affecting your Customer Data, we will notify you without undue delay and in any event within 72 hours of confirming the breach. Our notice will include, to the extent known, the nature of the breach, the categories and approximate volume of data and individuals affected, the likely consequences, and the measures taken or proposed. We will reasonably assist you in meeting your own obligations under the Notifiable Data Breaches scheme.

7. Assistance & Individual Requests

Taking into account the nature of the processing, we will provide reasonable assistance to help you respond to requests from individuals to access or correct their personal information (APP 12 and APP 13), and to meet your security, breach notification, and compliance obligations. If an individual contacts us directly about Customer Data, we will refer them to you.

8. International Transfers

Customer Data is stored in Australia (AWS Sydney). Some sub-processors may process limited data overseas. Where this occurs we take reasonable steps under APP 8 to ensure the recipient handles the information consistently with the APPs, and we remain accountable for it as required by section 16C of the Privacy Act 1988.

9. Return & Deletion

During your Subscription you can export Customer Data through the Platform. On termination, we will make Customer Data available for export for 30 days, after which we will delete it from active systems, and from backups within a further 90 days, except where retention is required by law. We will confirm deletion in writing on request.

10. Audit

We maintain records of our processing and security measures. On reasonable written notice (no more than once a year, except following a data breach or where required by a regulator), we will provide information reasonably necessary to demonstrate compliance with this DPA, subject to confidentiality.

11. Liability & Precedence

Liability under this DPA is subject to the limitations and exclusions in the Terms of Service, including the enhanced cap that applies to data-breach, privacy, and confidentiality claims. In the event of a conflict between this DPA and the Terms of Service in relation to the processing of personal information, this DPA prevails.

12. Contact

For questions about this DPA or to raise a data-protection matter, contact privacy@torqueos.net.