Data Processing Agreement
Last updated: June 2025
This document is pending final legal review and does not yet constitute the company's binding legal terms. It will be updated before public launch.
Terms under which Becide processes personal information on your behalf.
1. Parties and scope
This Data Processing Agreement (DPA) forms part of the agreement between the client (Controller) and Klair Technology (Processor) when Becide processes personal information on the Controller's behalf.
It applies to personal information in client data, user accounts provisioned for the Controller, and processing activities described in the Service documentation.
2. Definitions
Personal information, processing, and related terms have the meanings given in the Privacy Act 1988 (Cth) unless otherwise defined in the main agreement.
3. Processing instructions
We process personal information only on documented instructions from the Controller, including configuration of the Service, connector authorisation, and documented support requests.
If we are required by law to process personal information otherwise, we will inform the Controller unless prohibited by law.
4. Confidentiality
Personnel with access to personal information are bound by confidentiality obligations. Access is limited to those who need it to perform the Service.
5. Security measures
We implement technical and organisational measures appropriate to the risk, including:
- AES-256 encryption at rest with per-client dedicated encryption keys
- TLS encryption in transit
- Least-privilege access controls and tenant isolation by organisation
- secure credential storage for connector credentials
- Audit logging of AI runs and administrative actions in Australia
- Regular review of access controls and incident response procedures
6. Subprocessors
The Controller authorises use of subprocessors necessary to deliver the Service. Primary subprocessors include Amazon Web Services (Australia) for hosting and storage, our authentication service and approved AI providers.
We maintain a subprocessor register available on request. We will notify Controllers of material subprocessor changes where required by agreement.
We impose data protection obligations on subprocessors through contract.
7. International transfers
Personal information is primarily stored in Australia. Where processing occurs outside Australia, we take reasonable steps to ensure APP 8 compliance, including contractual safeguards.
8. Assistance with data subject rights
We assist the Controller in responding to requests from individuals to access, correct, or delete personal information, within reasonable timeframes and subject to the Controller's instructions.
9. Personal information breaches
We will notify the Controller without undue delay after becoming aware of a personal information breach affecting the Controller's data, providing information reasonably available to support the Controller's assessment and notification obligations under the Privacy Act.
10. Deletion and return
On termination or at the Controller's instruction, we delete or return personal information per the exit process: export on request, deletion from all layers, and scheduling encryption key destruction so ciphertext is unreadable.
11. Audits and information
We make available information reasonably necessary to demonstrate compliance with this DPA. Enterprise Controllers may request security questionnaires or architecture summaries subject to confidentiality.
On-site audits may be arranged for enterprise agreements, subject to reasonable notice, scope limits, and confidentiality.
12. Liability
Liability under this DPA is subject to the limitation of liability in the main agreement. Each party remains responsible for its obligations under the Privacy Act.
13. Term and precedence
This DPA remains in effect while we process personal information on behalf of the Controller. If inconsistent with the main agreement, this DPA prevails on data protection matters.
A countersigned PDF is available on request at hello@foresight.app.
Download PDF
Enterprise customers can request a countersigned PDF for their records. The content matches this page.
Request DPA PDF