YourCA
Terms of UsePrivacy PolicyDPAData & AI

DPA

Data Processing Addendum

On this page

  1. 1. Definitions
  2. 2. Scope and roles
  3. 2.1 Scope
  4. 2.2 Roles
  5. 2.3 Customer responsibilities
  6. 3. Processing of Personal Information
  7. 3.1 Documented instructions
  8. 3.2 Notification of unlawful instructions
  9. 3.3 Processing details
  10. 4. Confidentiality and personnel
  11. 5. Security
  12. 6. Sub-processors
  13. 6.1 General authorisation
  14. 6.2 Current Sub-processors
  15. 6.3 Sub-processor obligations
  16. 6.4 Notice of changes and right to object
  17. 6.5 Customer-connected sources are not Sub-processors
  18. 7. Data Subject rights
  19. 7.1 Assistance
  20. 7.2 Requests received by YourCA
  21. 7.3 Self-service tools
  22. 7.4 Cost
  23. 8. Personal Data Breach notification
  24. 8.1 Notice to Customer
  25. 8.2 Investigation and remediation
  26. 8.3 No admission
  27. 9. Data protection impact assessments and prior consultation
  28. 10. International transfers
  29. 10.1 Where processing happens
  30. 10.2 Transfers required to provide the Service
  31. 10.3 EU/UK/Swiss transfers
  32. 10.4 Conflict
  33. 10.5 Supplementary measures
  34. 10.6 Transfer impact
  35. 11. Audits
  36. 11.1 Information
  37. 11.2 On-site audits
  38. 12. Deletion and return of Personal Information
  39. 12.1 During the Subscription Term
  40. 12.2 On termination
  41. 12.3 Legal hold
  42. 12.4 Certification
  43. 13. Liability and precedence
  44. 13.1 Liability cap
  45. 13.2 Order of precedence
  46. 14. Term and termination
  47. 15. General
  48. 15.1 Notices
  49. 15.2 Governing law and jurisdiction
  50. 15.3 Severability
  51. 15.4 No third-party beneficiaries
  52. Annex 1: Description of processing
  53. Annex 2: Technical and organisational measures
  54. Access control
  55. Encryption
  56. Network and infrastructure security
  57. Application security
  58. Monitoring and incident response
  59. Business continuity
  60. Physical security
  61. Measures YourCA does not operate
  62. AI-specific measures
  63. Supplementary measures for Restricted Transfers
  64. Annex 3: Sub-processors
  65. Contact

Effective date: 8 September 2026 Last updated: 8 August 2026 Version: 2.0

This Data Processing Addendum (DPA) forms part of the YourCA Terms of Use (the Agreement) between Michael Dewick trading as YourCA (ABN 84 390 063 197), a sole trader, of Suite 302, 13/15 Wentworth Avenue, Sydney NSW 2000 (YourCA, Processor, we), and the customer entity identified in the Order (Customer, Controller, you).

This DPA governs the processing of Personal Information by YourCA on the Customer's behalf in connection with the Service. YourCA is one product, sold in different shapes; this DPA covers every module inside it, and there is no module-by-module variation in how Personal Information is processed.

If the Customer requires a signed copy, email admin@yourca.ai. By accepting the Agreement and using the Service, the Customer is deemed to accept this DPA without signature, except where a signed copy is required by applicable law.

In plain English. A plain-language summary to orient you; the numbered clauses and Annexes govern.

  • We process your data on your instructions, as your processor. (Clauses 2 and 3.)
  • We undertake not to train AI on your data. This is a contractual promise, backed by our model provider's commercial terms. It is not enforced by a technical control inside YourCA, and you should read it as a commitment rather than a switch. (Annex 2, AI-specific measures.)
  • Storage is in Australia. Inference is not. Your documents, database records, search index and OCR all sit in Sydney. AI text inference runs on Anthropic's API in the United States, and product analytics and error capture run on PostHog in the European Union, for events raised by our servers and for events raised by your browser alike, because both paths refuse that provider's United States host and send nothing at all rather than send offshore. Nothing in this DPA should be read as promising that all of your data stays onshore. (Clause 10 and Annex 3.)
  • Cross-border transfers use EU SCCs and the UK IDTA where they apply. (Clause 10.)
  • Your own connected accounts are yours, not ours. Where the Service offers a connection to Gmail, Microsoft 365, Dropbox, Google Drive, Xero or Procore and you connect it, that account is connected under your authorisation and is not our sub-processor. A connection is not read-only: while it is connected, the Service can write to it as well as read from it when you run an action. The Service also has an automatic chasing capability which, where it is offered and you switch it on for a supplier, can send a chase from your mailbox without you running it, and a scheduled reading of a connected mailbox that prepares a brief and drafts a chase. Neither is enabled in the Service today. This describes what a connection does when you have one, not that any particular connection or capability is available to you today. (Clause 6.5 and Annex 3.)
  • Breaches are notified without undue delay, within 48 hours of confirmation where feasible, and in any event in time for you to meet your own 72-hour obligation. We assist you with your own obligations as far as one person reasonably can. (Clause 8.)
  • What we will not do after a breach. We do not undertake to conduct or fund a forensic investigation, to notify your data subjects or your regulators, or to bear your costs of doing any of that. Our investigation is what one person can do with the information and tools to hand. Read clause 8 before you rely on us for any of it. (Clauses 8.1 and 8.2.)
  • We operate a small number of security controls and a long list of controls we do not operate. Annex 2 states both. Read the second list before you send us anything sensitive.
  • What we can be made to pay under this DPA is capped, and the cap is small. Everything we owe you under this DPA, including assistance, breach handling, audit responses and deletion, is subject to the same single capped amount as the rest of the Agreement: the greater of A$1,000 and the Fees you have actually paid us in the preceding 12 months. That cap is never nil, so it is A$1,000 even if you have paid us nothing, but A$1,000 is a small amount and we do not present it as a real remedy for a large loss. YourCA holds no professional indemnity insurance. Four things sit outside that cap: liability under the EU Standard Contractual Clauses and the UK IDTA to the extent capping it is prohibited; a wilful breach of confidence by us, which includes a deliberate unauthorised disclosure of your Personal Information; either party's infringement of the other's intellectual property; and any liability that cannot lawfully be excluded, which includes fraud and your rights under the Australian Consumer Law. Your consumer guarantees do not sit inside this cap. Read clause 15 of the Agreement before you buy. (Clause 13.1.)

#1. Definitions

Capitalised terms used but not defined here have the meaning given in the Agreement. In this DPA:

  • Applicable Data Protection Law means all laws relating to the protection of Personal Information that apply to the processing under this DPA, including the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), the General Data Protection Regulation (Regulation (EU) 2016/679) (GDPR), the UK General Data Protection Regulation (UK GDPR), and any other applicable privacy or data protection law.
  • Data Subject means an identified or identifiable natural person to whom Personal Information relates.
  • EU SCCs means the Standard Contractual Clauses approved by the European Commission in Decision 2021/914 of 4 June 2021.
  • Personal Data Breach means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Personal Information.
  • Personal Information has the meaning given in the Agreement and includes "personal data" under the GDPR/UK GDPR.
  • Processing has the meaning given under Applicable Data Protection Law. "Process", "processed", and "processes" are construed accordingly.
  • Restricted Transfer means a transfer of Personal Information from a jurisdiction whose laws restrict cross-border transfers (such as the EEA, UK, or Switzerland) to a jurisdiction that has not received an adequacy decision.
  • Sub-processor has the meaning given in the Agreement.
  • UK IDTA means the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018, version B1.0 in force from 21 March 2022.

#2. Scope and roles

#2.1 Scope

This DPA applies to all processing of Personal Information by YourCA on behalf of the Customer in providing the Service.

#2.2 Roles

For Customer Data:

  • the Customer is the Controller (or, where the Customer itself acts as a processor for a third-party controller, the Customer is the controller's authorised processor and YourCA is a sub-processor); and
  • YourCA is the Processor.

For Personal Information about the Customer's account administrators, billing contacts, and other business contacts that YourCA collects directly, YourCA is an independent Controller (see the Privacy Policy).

#2.3 Customer responsibilities

The Customer warrants that:

(a) it has a lawful basis to provide Personal Information to YourCA and to authorise the processing described in this DPA; (b) it has provided all notices and obtained all consents required under Applicable Data Protection Law from Data Subjects; and (c) its instructions to YourCA comply with Applicable Data Protection Law.


#3. Processing of Personal Information

#3.1 Documented instructions

YourCA will process Personal Information only:

(a) on the documented instructions of the Customer, as set out in the Agreement, this DPA, the Order, and the Customer's use of the Service through its administrators and Authorised Users; and (b) as required by law (in which case YourCA will, where lawful, notify the Customer before processing).

#3.2 Notification of unlawful instructions

YourCA will notify the Customer without undue delay if, in its opinion, an instruction infringes Applicable Data Protection Law. YourCA is not obliged to act on instructions it reasonably considers unlawful.

#3.3 Processing details

The subject matter, duration, nature, purposes, categories of Data Subjects, and categories of Personal Information processed are set out in Annex 1.


#4. Confidentiality and personnel

YourCA is operated by a sole trader and has no employees. Access to Personal Information is held by that sole trader and, where engaged, by contractors.

YourCA ensures that any person authorised to process Personal Information:

(a) is bound by written confidentiality obligations that survive termination of their engagement; and (b) accesses Personal Information only on a need-to-know basis.

YourCA does not operate a formal training programme; it does not have personnel to train.


#5. Security

YourCA implements and maintains the technical and organisational measures described in Annex 2, which are the measures actually in place. Annex 2 also states plainly which common controls YourCA does not operate. YourCA updates Annex 2 when its measures change.

YourCA will make Annex 2 available to the Customer, in full and free of charge, before the Customer purchases the Service, including the "Measures YourCA does not operate" section, and will keep it published so that it can be read at any time. YourCA will also provide a copy on request to admin@yourca.ai.

The Customer is responsible for satisfying itself that the measures in Annex 2 are appropriate for the Personal Information it chooses to provide, having regard to the costs of implementation, the nature, scope, context, and purposes of processing, and the risks for Data Subjects. The Customer must not provide Personal Information to the Service that requires controls YourCA has stated it does not operate.


#6. Sub-processors

#6.1 General authorisation

The Customer grants YourCA general written authorisation to engage Sub-processors to process Personal Information, subject to this clause 6.

#6.2 Current Sub-processors

A current list of Sub-processors is set out in Annex 3 and is updated from time to time.

#6.3 Sub-processor obligations

YourCA will:

(a) review a Sub-processor's published security and data processing terms before engagement; (b) engage each Sub-processor under terms (including that Sub-processor's own data processing agreement) that impose obligations in respect of Personal Information, and not knowingly engage a Sub-processor whose terms are materially less protective than this DPA; and (c) remain liable to the Customer for the acts and omissions of each Sub-processor as if they were its own.

#6.4 Notice of changes and right to object

YourCA will give the Customer at least 30 days' notice (which may be via in-product notification, email to the Customer's primary contact, or update to the Sub-processor list page) of any intended change to the Sub-processor list that materially affects the processing of the Customer's Personal Information.

The Customer may object to a change on reasonable data-protection grounds within 15 days of notice. The parties will discuss the objection in good faith. If YourCA cannot reasonably accommodate the objection, the Customer may terminate the affected Order on written notice and YourCA will refund the prepaid Fees attributable to the period after termination. That refund is calculated and paid by YourCA manually to the original payment method; the Service does not calculate or issue it automatically.

The Customer should understand the practical limit of this right. Every Sub-processor in Annex 3 is load-bearing: there is no second model provider, no second database, no second object store and no second payment processor. An objection to any of them cannot be accommodated by substitution, so in practice the outcome of a sustained objection is termination under this clause rather than a change of provider.

#6.5 Customer-connected sources are not Sub-processors

The Service offers, as a capability, connections made at the Customer's direction and under the Customer's own credentials to third-party services the Customer already uses. The sources for which a connection may be offered are Gmail, Microsoft 365 (including Outlook, Calendar, OneDrive, Teams, To Do and SharePoint), Dropbox, Google Drive, Xero and Procore. Which of them is offered to the Customer's account at any time is a matter for the Agreement, and this clause is not a statement that any particular connection is available to the Customer today. This clause applies where the Customer connects a source, and for as long as it stays connected.

Those services are the Customer's own accounts. YourCA does not appoint them, does not contract with them on the Customer's behalf, and they are not YourCA Sub-processors for the purposes of this DPA. They act as independent controllers or as the Customer's own processors, under the terms the Customer has with them. The Customer may revoke any connection at any time.

A connection is not read-only. Depending on the scopes the Customer grants and the actions the Customer runs, the Service can create, update, send, share and delete records in a connected service. YourCA performs such an action when an Authorised User runs a feature that does so. The Service also has an automatic chasing capability: where the Service offers it and an Authorised User switches it on for a supplier in the procurement module, the Service may send a chase email from the Customer's connected mailbox without further action by an Authorised User, the setting is off unless switched on for that supplier, the Service will not chase a supplier the Customer has not already emailed, and it sends at most one chase to a supplier in a day. That capability is not enabled in the Service today, and while it is not enabled every write to a connected source happens because an Authorised User ran it. The Customer is responsible for the consequences of actions it runs in its own connected systems.


#7. Data Subject rights

#7.1 Assistance

Taking into account the nature of the processing and the information available to YourCA, YourCA will assist the Customer, by appropriate technical and organisational measures and insofar as is possible, in fulfilling the Customer's obligations to respond to requests from Data Subjects to exercise their rights under Applicable Data Protection Law (including access, correction, deletion, restriction, portability, and objection).

#7.2 Requests received by YourCA

If YourCA receives a request directly from a Data Subject in respect of Customer Data, YourCA will:

(a) not respond to the request other than to acknowledge it and refer the Data Subject to the Customer; and (b) where lawful, notify the Customer of the request without undue delay.

#7.3 Self-service tools

YourCA provides self-service tools within the Service that allow the Customer to access, correct, export, and delete Customer Data. The Customer's use of these tools constitutes YourCA's assistance under clause 7.1 in respect of those rights.

#7.4 Cost

YourCA's assistance under this clause is included in the Fees, except where a request requires materially more effort than the self-service tools support, in which case YourCA may charge a reasonable cost-based fee on prior notice.


#8. Personal Data Breach notification

#8.1 Notice to Customer

On becoming aware of a confirmed Personal Data Breach affecting the Customer's Personal Information, YourCA will:

(a) notify the Customer without undue delay and, where feasible, within 48 hours of confirming the breach. YourCA will in any event use reasonable efforts to notify the Customer in time for the Customer to meet its own obligation to notify a supervisory authority within 72 hours of becoming aware of the breach; and (b) use reasonable efforts to provide the Customer with information reasonably necessary to enable the Customer to meet its own notification obligations, to the extent that information is then known to YourCA and available to it, including: the nature of the breach, categories and approximate number of Data Subjects and records affected, likely consequences, and measures taken or proposed. Information may be provided in phases as it becomes known.

YourCA is one person with no security team, no on-call rotation and no forensic capability of its own (Annex 2). This clause is an obligation to act promptly, honestly and with reasonable efforts. It is not a guarantee of a notification time, of the completeness or accuracy of early information, or of any investigative outcome, and it does not oblige YourCA to conduct or fund a forensic investigation, to notify the Customer's own Data Subjects or regulators, or to bear the Customer's costs of doing so. YourCA's liability under this clause is subject to clause 13.1.

#8.2 Investigation and remediation

YourCA will:

(a) investigate the Personal Data Breach using the information, logs and tools reasonably available to it. That investigation is what one person can carry out with what is to hand; it is not a forensic investigation, and clause 8.1 states that YourCA is not obliged to conduct or fund one; (b) take reasonable steps to contain, mitigate, and remediate it; and (c) cooperate with the Customer's reasonable requests for further information.

#8.3 No admission

A notification under this clause is not an admission of fault or liability.


#9. Data protection impact assessments and prior consultation

YourCA will provide reasonable assistance to the Customer in conducting data protection impact assessments (DPIAs) and prior consultations with supervisory authorities required by Applicable Data Protection Law, taking into account the nature of the processing and the information available to YourCA. This assistance is included in the Fees, except where it requires materially more than standard documentation, in which case YourCA may charge a reasonable cost-based fee on prior notice.


#10. International transfers

#10.1 Where processing happens

Stored in Australia. The primary Customer Data store (managed PostgreSQL and the pgvector search index), uploaded documents in object storage, and optical character recognition of scanned documents are all performed in the Sydney region (ap-southeast-2). Text embeddings are generated in the same region. For object storage, optical character recognition and embeddings, the region is enforced in the application by a check that raises an error and stops the component rather than allowing it to run elsewhere. The embedding client raises that error as the application loads; object storage and optical character recognition raise it on first use, and only where a storage bucket is configured or optical character recognition is switched on respectively. For the database, the region is fixed by the provider endpoint YourCA connects to rather than by a check in YourCA's own code. Application hosting and the queue service are not region-checked at all (Annex 3). YourCA will not transfer Customer Data outside Australia for primary storage without notice.

Processed outside Australia. Two categories leave Australia in normal operation:

(a) AI text inference, in the United States. All AI text generation and analysis, including chat, extraction and contract review, is performed by Anthropic in the United States. This is a Restricted Transfer where the Personal Information originates in the EEA, UK or Switzerland, and is handled under clauses 10.3 to 10.5.

(b) Product analytics and error capture, in the European Union. Usage events and application errors raised by YourCA's servers are processed by PostHog in the European Union, and pass through an automated scrub that removes credentials, tokens, authorisation headers and email addresses before egress. Usage events raised by the Customer's browser are sent to the same European host. Both the server path and the browser path apply the same region check: a PostHog United States host is refused, a host that cannot be parsed is refused, and where the host is refused, or where no host is configured for the browser, that telemetry is disabled rather than sent offshore. That check prevents the provider's United States cloud specifically; it does not establish that a configured host is located in Australia or the European Union. Browser events are not covered by the scrub and carry the network address the request comes from, which is Personal Information reaching the European host. Analytics is also the only error-capture channel YourCA operates.

In addition, payment processing (Stripe) and transactional email delivery (Resend) are not pinned to an Australian region, and email is necessarily delivered to the recipient's own mail provider wherever that provider operates.

The Customer should not rely on a statement that all of its data stays in Australia. Storage and indexing are onshore. Inference and telemetry are not.

#10.2 Transfers required to provide the Service

The Customer authorises transfers to and from countries where YourCA or its Sub-processors operate to the extent reasonably necessary to provide the Service (for example, support and incident response carried out by the sole trader, or by a contractor, located in Australia or another jurisdiction listed in Annex 3).

#10.3 EU/UK/Swiss transfers

Where the processing of Personal Information by YourCA involves a Restricted Transfer from the EEA, UK, or Switzerland to a country that has not received an adequacy decision, the parties agree:

(a) the EU SCCs, Module 2 (Controller-to-Processor) or Module 3 (Processor-to-Processor) as applicable, are incorporated into this DPA by reference and apply to that transfer with:

  • Clause 7 (docking clause): included;
  • Clause 9(a) (sub-processor authorisation): Option 2 (general written authorisation), with the notice period in clause 6.4 of this DPA;
  • Clause 11(a) (independent dispute resolution): optional language not included;
  • Clause 17 (governing law): the law of the Republic of Ireland;
  • Clause 18(b) (jurisdiction): the courts of the Republic of Ireland;
  • Annex I.A (parties): the Customer (data exporter) and YourCA (data importer). YourCA is entered as Michael Dewick trading as YourCA, an individual carrying on business as a sole trader in New South Wales, Australia (ABN 84 390 063 197), of Suite 302, 13/15 Wentworth Avenue, Sydney NSW 2000, contact admin@yourca.ai. YourCA is not a company and must not be described as one in any completed Annex, signature block or table; where a form calls for a company name, registration number or company officer, the sole trader's name and ABN are used and the signatory is the sole trader personally;
  • Annex I.B (description of transfer): Annex 1 of this DPA;
  • Annex I.C (competent supervisory authority): as determined under Clause 13 of the EU SCCs;
  • Annex II (technical and organisational measures): Annex 2 of this DPA;
  • Annex III (sub-processors): Annex 3 of this DPA;

(b) for transfers from the UK, the UK IDTA is incorporated into this DPA by reference. Tables 1, 2, and 3 are completed with the corresponding details from this DPA and the EU SCCs above, with the importer's details in Table 1 completed as the sole trader described above rather than as a company; Table 4 (importer's right to terminate the IDTA): neither party may end the IDTA when the Approved IDTA changes; and

(c) for transfers from Switzerland, the EU SCCs apply with the amendments specified by the Swiss Federal Data Protection and Information Commissioner: references to GDPR are interpreted as references to the Swiss Federal Act on Data Protection (FADP), and references to EU Member State supervisory authorities are interpreted as the FDPIC.

#10.4 Conflict

If there is any conflict between this DPA and the EU SCCs or UK IDTA in respect of a Restricted Transfer, the EU SCCs or UK IDTA (as applicable) prevail.

#10.5 Supplementary measures

The parties acknowledge that the supplementary measures YourCA applies to Restricted Transfers are those described in Annex 2 under "Supplementary measures for Restricted Transfers", and no others. YourCA does not offer customer-managed encryption keys.

#10.6 Transfer impact

The parties acknowledge that the two recurring transfers are AI text inference to the United States and telemetry to the European Union.

For the European Union transfer, the destination has the benefit of the GDPR in its own right and the practical risk to Data Subjects is low. Events raised by YourCA's servers are also scrubbed of credentials, tokens, authorisation headers and email addresses before they leave YourCA's servers. Events raised by the Customer's browser go to the same European host but are not scrubbed and carry the visitor's network address.

For the United States transfer, the parties acknowledge that United States surveillance law, including section 702 of the Foreign Intelligence Surveillance Act and Executive Order 12333, may apply to the importer, and that YourCA is a sole trader with no legal department. YourCA has not commissioned a formal transfer impact assessment and does not represent that one exists. What YourCA does apply is set out in Annex 2 under "Supplementary measures for Restricted Transfers": encryption in transit, minimisation of the content sent for each request, contractual no-training and limited-retention terms with the model provider, and a stated commitment to scrutinise and where appropriate challenge government access requests. The Customer must reach its own conclusion on whether those measures are sufficient for the Personal Information it chooses to send, and must not assume YourCA has reached that conclusion on its behalf.


#11. Audits

#11.1 Information

YourCA will, on the Customer's reasonable written request and no more than once per 12-month period (unless required by a regulator or following a confirmed Personal Data Breach affecting the Customer's Personal Information), make available:

(a) a summary of its current security measures, as set out in Annex 2; (b) responses to a reasonable security questionnaire, to the extent the information requested is available to YourCA; and (c) other information reasonably necessary to demonstrate compliance with this DPA and Applicable Data Protection Law, to the extent that information exists.

YourCA holds no independent security certification, attestation, or penetration test report (see Annex 2), so none can be made available. The Customer should not enter this DPA on the assumption that such a report exists or will be produced. YourCA is not obliged to create information that does not already exist, to commission a certification, attestation, audit or penetration test, or to complete a questionnaire in a particular format. Where a request under this clause requires materially more than providing the existing Annex 2 and answering a reasonable questionnaire, YourCA may charge a reasonable cost-based fee on prior notice. YourCA's liability under this clause is subject to clause 13.1.

#11.2 On-site audits

The Customer's audit rights under Article 28(3)(h) of the GDPR/UK GDPR are satisfied by YourCA's provision of information under clause 11.1. The Customer may request an on-site audit only where:

(a) required by a supervisory authority; or (b) following a confirmed Personal Data Breach materially affecting the Customer's Personal Information, where the information available under clause 11.1 is reasonably insufficient.

Any on-site audit is conducted at the Customer's cost during business hours, on at least 30 days' notice, by an independent auditor reasonably acceptable to YourCA, subject to confidentiality and reasonable security restrictions. The audit must not unreasonably interfere with YourCA's business and must not access Personal Information of other customers. The Customer bears its own and the auditor's costs in full, and reimburses YourCA's reasonable costs of time spent supporting the audit at YourCA's then-current rates, notified in advance. YourCA is not obliged to remediate a finding in a manner or on a timetable set by the Customer or the auditor.

YourCA does not operate its own data centres and physical audits of its facilities are not available. Physical audits of the infrastructure Sub-processors' data centres are not permitted; the parties rely on those providers' own compliance programs and third-party attestations.


#12. Deletion and return of Personal Information

#12.1 During the Subscription Term

The Customer may export Customer Data at any time using self-service tools, in the formats the Service supports for the item being exported. The whole-account export is a zip archive of JSON files. An individual register or similar item is exported as a spreadsheet, in XLSX or CSV. The export tools do not return the Customer's uploaded source files.

#12.2 On termination

Following termination or expiry of the Agreement, YourCA will:

(a) allow the Customer 30 days to export Customer Data; and (b) thereafter, on the Customer's written request, delete all Personal Information from production systems. That deletion is performed manually by YourCA and is not carried out by an automated process. Termination alone does not trigger it, and there is no self-service control that deletes an account and all of its Personal Information. YourCA will use reasonable efforts to complete a requested deletion within 30 days of the request. A contract the Customer deletes in the Service is an exception: that deletion is immediate and removes the document, its extracted text, its structure and its review history from production. Deleted data also ages out of the hosting providers' backup and point-in-time-recovery windows in the ordinary course; YourCA does not control those windows and cannot delete from them on demand.

#12.3 Legal hold

YourCA may retain Personal Information for so long as required by law. Any retained Personal Information remains subject to the confidentiality and security obligations of this DPA.

#12.4 Certification

YourCA will, on written request, use reasonable efforts to provide written certification of deletion from production systems within 30 days of completion. That certification is a statement, made honestly and on reasonable enquiry, of the deletion YourCA has carried out from production systems. It is not a warranty or guarantee, it does not extend to the backup and point-in-time-recovery windows of the hosting providers described in clause 12.2, and YourCA's liability in connection with it is subject to clause 13.1.


#13. Liability and precedence

#13.1 Liability cap

Each party's liability arising out of or in connection with this DPA is subject to the limits, exclusions and time bar of liability in the Agreement, and in particular to clauses 15.1, 15.2, 15.3 and 15.5 of the Agreement. Clause 15.3 of the Agreement, which places certain items outside those limits, applies to this DPA in full and is not narrowed by it. There is a single cap across the Agreement and this DPA together: a claim under this DPA does not create a separate or additional cap, and every payment obligation YourCA owes the Customer under this DPA draws on the same amount as every claim under the Agreement. That includes any obligation to indemnify or reimburse the Customer, to pay the Customer's costs, to fund or bear the cost of an investigation, a notification, a remediation, a supervisory-authority process or a Data Subject claim, and to pay any regulatory fine or penalty imposed on the Customer.

The cap imported from clause 15.2 of the Agreement is the greater of A$1,000 and the Fees actually paid in the relevant 12 months. It is not a Fees-only measure, and it is not nil where no Fees were paid.

For clarity, and because a small cap should not be discovered late: where the Fees actually paid in the relevant 12 months are small or nil, the amount recoverable from YourCA under this DPA is limited to A$1,000, whatever the scale of the Personal Data Breach or of the Customer's own loss. A$1,000 is a minimum rather than a remedy of any real size, and the Customer should read it that way. YourCA holds no professional indemnity insurance and no cyber liability insurance.

The exceptions are these, and only these. Liability under the EU SCCs and the UK IDTA in respect of Restricted Transfers, including a Data Subject's rights as a third-party beneficiary under those clauses, is not capped to the extent that capping it is prohibited. A wilful breach by YourCA of clause 10 (Confidentiality) of the Agreement is not capped, and for the purposes of this DPA that includes a deliberate unauthorised disclosure by YourCA of the Customer's Personal Information; the same applies to the Customer on the same terms. Either party's infringement of the other's Intellectual Property Rights is not capped. Liability that cannot lawfully be excluded or limited, including liability for fraud and liability under the Australian Consumer Law described in clause 14.4 of the Agreement, is unaffected. These exceptions are the same on both sides of this DPA as they are under clause 15.3 of the Agreement, and nothing in this DPA brings back inside the cap anything that clause 15.3 leaves outside it.

#13.2 Order of precedence

If there is any conflict between this DPA and the Agreement, this DPA prevails in respect of the processing of Personal Information. That precedence applies whether this DPA has been executed by the parties or accepted without signature under the terms set out above, and clause 17.2 of the Agreement is to be read accordingly. The EU SCCs and UK IDTA prevail over this DPA in respect of Restricted Transfers.


#14. Term and termination

This DPA takes effect on the effective date and continues for the term of the Agreement. The obligations under clauses 3, 4, 5, 6, 8, 10, 12, and 13 survive termination as necessary to fulfil their purpose. Clauses 3 and 6 are included because Personal Information is retained after termination under clause 12: the limits on how YourCA may process it, and the Sub-processor obligations that attach to it, continue to apply for as long as YourCA holds it.


#15. General

#15.1 Notices

Notices under this DPA are given in accordance with the Agreement. Privacy-specific notices may also be sent to admin@yourca.ai.

#15.2 Governing law and jurisdiction

This DPA is governed by the laws of New South Wales, Australia, except that for Restricted Transfers the governing law and jurisdiction provisions of the EU SCCs or UK IDTA (as applicable) prevail.

#15.3 Severability

If any provision of this DPA is held unenforceable, the remaining provisions continue in full force.

#15.4 No third-party beneficiaries

Except for Data Subjects' rights under the EU SCCs and UK IDTA, this DPA does not confer rights on any third party.


#Annex 1: Description of processing

Subject matter of processing: Provision of the YourCA software-as-a-service platform as a single product for subcontractors, including hosting, indexing, search, document management, contract review and the derivation of contract and project records from the Customer's own documents, AI-assisted processing (summarisation, classification, extraction, search, generation), integration with third-party services authorised by the Customer, and related support. The processing described in this Annex applies uniformly across every module of the product; it does not vary by which parts of the product the Customer uses or by which pricing shape the Customer is on.

Duration of processing: The term of the Agreement, plus the post-termination retention period set out in clause 12.

Nature of processing: Collection, recording, organisation, structuring, storage, retrieval, consultation, use, disclosure by transmission, alignment or combination, restriction, erasure, and destruction.

Purposes of processing:

  • providing the Service to the Customer and its Authorised Users;
  • securing the Service and detecting and preventing fraud and abuse;
  • maintaining the Service (backups, disaster recovery, troubleshooting, support);
  • complying with legal obligations; and
  • producing aggregated and de-identified analytics consistent with the Privacy Policy.

Categories of Data Subjects:

  • the Customer's Authorised Users (employees, contractors, agents);
  • the Customer's clients, suppliers, and other business contacts whose details are uploaded to the Service;
  • where applicable to the Customer's use case, individuals whose data appears in project records (for example, site visitors, subcontractor personnel, building occupants).

Categories of Personal Information:

  • identification and contact details (name, email, phone, business address, job title, employer);
  • account and authentication data (credentials, session identifiers, role/permissions);
  • profile and preference data;
  • communications (messages, comments, support requests);
  • usage and log data (IP address, device identifiers, timestamps, feature usage);
  • content uploaded by the Customer that may contain Personal Information (project documents, photos, drawings, records); and
  • billing and payment data (limited to the categories described in the Privacy Policy).

Special categories / sensitive information: Not solicited. The Customer must not upload sensitive information without an appropriate lawful basis and consent. Where the Customer's lawful use case requires sensitive information, the parties will agree additional safeguards in writing.

Frequency of processing: Continuous for the duration of the Agreement.

Retention: As set out in clause 12 and the Privacy Policy.


#Annex 2: Technical and organisational measures

YourCA is operated by a sole trader with no employees. This Annex states the measures that are actually in place, and then states plainly the common controls YourCA does not operate. It is written to be relied on as-is: nothing in it should be read as implying a control that is not listed.

#Access control

  • Role-based access control within the Service, with least-privilege defaults.
  • Optional multi-factor authentication (time-based one-time password) on user accounts.
  • Access revoked when a user is removed from the Customer's account.
  • Audit logging of administrative activity within the Service.
  • Production infrastructure access held only by the sole trader and, where engaged, a contractor under written confidentiality obligations.

#Encryption

  • TLS 1.2 or higher for data in transit on public networks.
  • Encryption at rest as provided by the infrastructure Sub-processors in Annex 3 for their managed storage, database, and object storage services.
  • Third-party integration credentials and access tokens encrypted with AES-256-GCM before they are stored, under a key held only in the deployment environment.

#Network and infrastructure security

  • Hosted on managed cloud infrastructure provided by the infrastructure Sub-processors in Annex 3. The database, object storage, optical character recognition and embedding components are pinned to the Sydney region (ap-southeast-2) by an in-application region check that stops the component if it is configured for any other region. Application hosting and the queue service are not pinned in this way (see Annex 3). Resilience, patching, and network-layer protection for those managed services are provided by those Sub-processors under their own programs.
  • Separate production and test environments; test suites run against a disposable database, never production.

#Application security

  • Server-side validation of request input on API routes (schema validation).
  • Tenant isolation enforced at the application and data layers, with every Customer-scoped query bound to the account.
  • Security response headers and request rate limiting on the API.
  • Secrets supplied by environment variables; no secrets committed to source code.
  • Every change proposed for, or merged into, the main branch of the codebase must pass automated typecheck, unit and integration tests, and a production build before it is released, and is reviewed by the sole trader.

#Monitoring and incident response

  • Structured application logging.
  • Application error monitoring and product analytics through a single Sub-processor (PostHog) configured for its European Union region. Server-side events pass through an automated scrub that removes credentials, tokens, authorisation headers and email addresses before the event leaves YourCA. Browser events are not scrubbed and carry the visitor's network address. The server path and the browser path each refuse a United States analytics host, and refuse a host they cannot parse: telemetry is disabled rather than sent offshore, which on the server path means error capture is disabled with it, and on the browser path an unconfigured host means no browser telemetry is sent at all. There is no separate error-tracking service.
  • Personal Data Breach notification per clause 8, handled by the sole trader.

#Business continuity

  • Backups and point-in-time recovery as provided by the managed database Sub-processor's standard retention window. YourCA does not run its own backup schedule and does not control that window.

#Physical security

  • YourCA operates no data centres and no premises at which Customer Data is stored. All Customer Data resides with the infrastructure Sub-processors in Annex 3.
  • Physical security of data centres for the AWS-hosted components (Amazon S3, Amazon Textract, and Amazon Bedrock) is provided by AWS under its own compliance program. The other infrastructure Sub-processors (Replit, Neon, Upstash) maintain their own data-centre physical security and compliance programs. YourCA has not independently verified any of those programs.

#Measures YourCA does not operate

YourCA states the following expressly so that no Customer or security reviewer relies on a control that does not exist:

  • No certification or attestation. YourCA holds no SOC 2 report, ISO 27001 certificate, IRAP assessment, or equivalent, and is not working to one.
  • No penetration testing. No third-party penetration test has been commissioned or performed.
  • No security team or 24/7 monitoring. There is no security team, no security operations centre, and no continuous human or automated security monitoring or alerting. There is no on-call rotation.
  • No intrusion detection, web application firewall, or dedicated DDoS protection beyond whatever the infrastructure Sub-processors apply to their own platforms by default.
  • No vulnerability, dependency, or static analysis scanning is run automatically against the codebase.
  • No malware or antivirus scanning of uploaded files. YourCA does not scan Customer Data for malicious content at upload, at rest, or on retrieval, and does not quarantine files. What YourCA does apply is an accepted-format allow-list, size and count limits, and a check that the leading bytes of each uploaded file match the type it declares, so that an executable, an archive, or a web page cannot be stored under a document extension. That check does not detect malicious content inside a file that genuinely is of the declared type. Stored objects are returned with a content type derived from the verified extension rather than from the upload, and with a download disposition on every format other than images and PDF. The Customer remains responsible for scanning any file it retrieves from the Service before opening it.
  • No formal governance programme. There is no documented information security management system, no annual risk assessment or treatment plan, no formal vendor risk management programme, and no accountable officer other than the sole trader.
  • No documented, tested incident response or disaster recovery plan, no defined recovery time or recovery point objectives, and no disaster recovery testing.
  • No customer-managed encryption keys and no key rotation programme operated by YourCA.
  • No personnel controls. There are no employees, and therefore no background checks, no security awareness training programme, and no joiner/mover/leaver process. Contractors, where engaged, are bound by written confidentiality obligations (clause 4).
  • No periodic access review cycle.

If the Customer's own obligations require any of the above, the Customer should not provide the affected Personal Information to the Service.

#AI-specific measures

  • Never-train undertaking. YourCA undertakes that Customer Data is not used to train, retrain, fine-tune, or benchmark any machine learning or AI model, whether foundation or tenant-scoped, and neither are any outputs, embeddings, indexes, or other derivatives of it. This is a contractual undertaking by YourCA, supported by the commercial terms of its model provider. It is not enforced by a technical control inside the Service, and the Customer should read it as a promise rather than as a mechanism. YourCA operates no training pipeline, no fine-tuning job and no model-customisation process of any kind, and adding one would breach this undertaking.
  • Retrieval, not training. The Service works by retrieval at inference time: the relevant part of the Customer's own documents and records is supplied to the model as context to answer a specific request, and is not accumulated into a training corpus. Embeddings used for that retrieval are generated in Australia.
  • Where inference happens. AI text generation and analysis are performed by Anthropic, using Claude models, served from the United States, under commercial terms that prohibit using inputs or outputs to train or improve any model and that provide only limited, short-term retention for safety and abuse monitoring. Where the underlying Personal Information originates in the EEA, UK or Switzerland this is a Restricted Transfer (clause 10).
  • Connected-source restrictions. Where the Service offers a connection to a source and the Customer connects it, Customer Data obtained through that connection is excluded from any model training, improvement, or fine-tuning. For Procore and for Google restricted scopes (Gmail and Google Drive), YourCA undertakes that, for as long as that connection is offered, it will handle data obtained through it consistently with the Procore developer and marketplace terms and with the Google API Services User Data Policy (including its Limited Use requirements), and will hold any certification or verification those terms require of it at the time the connection is offered. Data obtained through a Microsoft 365, Xero, or Dropbox connection is handled under those platforms' respective developer and API terms and is likewise excluded. These are undertakings that attach to a connection when it is offered, not assertions of a compliance or verification status held today.
  • YourCA does not use data from a source the Customer has connected to clone or build a competing replica of that source's own features.
  • AI is not optional. AI processing occurs whenever the Customer runs a feature that uses it, and most of the product does. The Service also has two capabilities that would process Personal Information without an Authorised User running anything, where the Service offers them and the Customer has connected a mailbox: a scheduled job that reads that mail to prepare a brief and to draft a chase, and an automatic chase sent from that mailbox where the Customer has switched it on for a supplier. Neither is enabled in the Service today, so no scheduled reading of a connected mailbox and no unattended send occurs. There is no account-wide switch to disable AI features while continuing to use the Service.
  • Outputs are drafts. Values the Service derives from a contract carry the clause reference and a quotation of the text they came from; where a value cannot be cited it is left blank rather than estimated. Generated documents are exported to the Customer to check, sign and send. YourCA does not sign or serve a document on the Customer's behalf.

#Supplementary measures for Restricted Transfers

  • Encryption in transit (TLS 1.2 or higher) to the model provider and to the analytics provider, and encryption at rest with provider-managed keys.
  • Only the content needed to answer the specific request is sent to the model provider; the model provider's terms prohibit use of inputs or outputs to train any model and provide only limited, short-term retention.
  • Telemetry sent to the analytics provider in the European Union from YourCA's servers is scrubbed of credentials, tokens, authorisation headers and email addresses before it leaves those servers. Telemetry sent from the Customer's browser is not scrubbed and carries the visitor's network address. Both paths refuse a United States analytics host and send nothing rather than send offshore.
  • Government access requests: assess each request for lawfulness, challenge overbroad or unlawful requests, minimise disclosure, and notify the Customer where lawful. This is a stated commitment, not a documented or tested procedure.
  • No formal transfer impact assessment has been commissioned (clause 10.6). There is no data-localisation option, no customer-selectable inference region, and no ability for the Customer to use the Service without the United States inference transfer.

#Annex 3: Sub-processors

The table below is the complete list of Sub-processors that may process Personal Information on YourCA's behalf. It reflects the stack actually deployed. If a provider is not in this table, it is not engaged. A current copy is provided on request to admin@yourca.ai, and the table is updated when material changes occur.

Sub-processorService providedLocation of processing
Anthropic, PBCAll AI text inference (Claude models) for chat, extraction, contract review and deep review, under terms prohibiting use of inputs or outputs to train any model, with only limited short-term retentionUnited States
Amazon Web Services, Inc. (AWS), Bedrock (Amazon Titan)Text embeddings for the search index. The deployed configuration routes text generation to Anthropic in the United States, so no text generation runs here in that configuration; the software also supports text generation on Bedrock in Sydney, and if YourCA switches to it that is a change to where inference happens, notified under clause 6.4Australia (Sydney, ap-southeast-2), pinned in application code
Amazon Web Services, Inc. (AWS), TextractOptical character recognition of scanned documents and imagesAustralia (Sydney, ap-southeast-2), pinned in application code
Amazon Web Services, Inc. (AWS), S3Object storage for uploaded documentsAustralia (Sydney, ap-southeast-2), pinned in application code
Neon, Inc.Managed PostgreSQL database (the primary Customer Data store) and the pgvector search indexAustralia (Sydney, ap-southeast-2), fixed by the provider endpoint rather than by a check in YourCA's code; US-incorporated entity
Upstash, Inc.Managed Redis for background job and queue processingRegion is a matter of deployment configuration and is not pinned in application code; see the note below
Replit, Inc.Application hosting and computeRegion is a matter of deployment configuration and is not pinned in application code; see the note below
Stripe (Stripe Payments Australia Pty Ltd and its group)Payment processing. Card details are entered directly with Stripe and raw card data never reaches YourCA systemsStripe group, including outside Australia
Resend, Inc.Email YourCA sends to the Customer: transactional and notification email such as sign-in verification codes and review-status notices, and also the daily brief, risk digest and urgent alert emails, which quote Customer Data including email subject lines and counterparty names. Processes the recipient's email address and the message contentNot pinned to an Australian region; email is delivered to the recipient's own mail provider wherever that provider operates
PostHog, Inc.Product usage analytics and the only application error capture YourCA operates. Server-side events are scrubbed of credentials, tokens, authorisation headers and email addresses before egress. Browser events are not scrubbed by YourCA and carry the network address they come fromEuropean Union (PostHog EU) for server-side events and for browser events alike. Each path refuses a United States host, and refuses a host it cannot parse, disabling that telemetry rather than sending it offshore; where no host is configured for the browser, no browser telemetry is sent. The refusal prevents the provider's United States cloud specifically and is not proof that a configured host sits in Australia or the European Union

Note on the two unpinned regions. For Neon, AWS and Anthropic, the location stated above is fixed either by a region check inside YourCA's own code or by the provider's endpoint. For Upstash and Replit it is not: those are deployment choices, and YourCA does not have an in-product control that would stop the service if either were configured outside Australia. YourCA deploys both to Sydney, but the Customer should treat the region for those two as a configuration commitment rather than an enforced control. Upstash holds queue and job metadata rather than the document corpus; Replit runs the application, so Customer Data passes through it in transit.

Removed from this Annex. Earlier versions of this DPA described AI inference as possibly moving to Amazon Bedrock in Sydney. That move has not started, it is not committed and it is not scheduled, so the intention has been removed rather than restated: the Customer should plan on inference remaining in the United States. No other Sub-processor has been removed, and no separate error-tracking or helpdesk provider is engaged.

Support. YourCA does not engage a helpdesk or customer-support Sub-processor. Support is handled by the sole trader over email.

Customer-connected services are not Sub-processors. Where the Service offers a connection to Gmail, Microsoft 365 (Outlook, Calendar, OneDrive, Teams, To Do, SharePoint), Dropbox, Google Drive, Xero or Procore and the Customer authorises it, those services act as independent controllers or as the Customer's own processors, under the Customer's own account and terms. They are not YourCA Sub-processors for the purposes of this Annex, and a change to their terms is not a change to this list. Clause 6.5 sets out what the Service can do inside them. Where the Service sends email on the Customer's behalf, it does so through the Customer's own connected mailbox under the Customer's authorisation, not through a YourCA Sub-processor.


#Contact

Michael Dewick trading as YourCA, Privacy Officer Suite 302, 13/15 Wentworth Avenue Sydney NSW 2000 Australia

Privacy, legal, security, and support: admin@yourca.ai

Michael Dewick trading as YourCA
ABN 84 390 063 197
admin@yourca.ai
Terms of UsePrivacy PolicyDPAData & AI