OnboardMe

Terms & policies

  • Privacy Policy
  • Terms of Service
  • Data Processing Agreement
  • Electronic records & signature disclosure
  • Browser extension privacy
  • Google user data

Trust & security

  • Information security & business continuity
  • Subprocessors
  • Data storage & backups
Contact usLog in

© 2026 OnboardMe Pty Ltd

Data Processing Agreement

Last updated August 2026 · Australian and New Zealand privacy law

Summary

This Data Processing Agreement ("DPA") is OnboardMe Pty Ltd's standard processor terms for this deployment of the Service (hosting: AWS Sydney region). This DPA records how OnboardMe handles personal information as a service provider on this Australia / New Zealand deployment. It is intended to support the Customer’s duties under the Privacy Act 1988 (Cth) and Australian Privacy Principles where Australian law applies, and the Privacy Act 2020 and Information Privacy Principles where New Zealand law applies — including APP 8 / overseas disclosure, APP 11 / security, and equivalent New Zealand security and disclosure expectations.

It is incorporated into, and forms part of, the Terms of Service between the organisation that subscribes to or otherwise uses the Service (the "Customer") and OnboardMe Pty Ltd ("OnboardMe", "we", "us"). The Privacy Policy describes how the platform handles personal information; this DPA is the contractual allocation of roles and instructions for processing done on the Customer's behalf.

In practice, this DPA applies as follows:

  1. Automatic application. When a person accepts the Terms on behalf of the Customer, or the Customer uses the Service in a way that involves Client Data, this DPA applies. No extra click or signature is required for it to be binding, unless OnboardMe and the Customer execute a separate written DPA.
  2. Who it binds. It binds the Customer (the practice or firm) and OnboardMe. Individual staff users accept on behalf of the Customer if they have authority to do so (as already stated in the Terms). The Customer's end clients are not parties. A client who wants access, correction, or deletion of their information should contact the Customer; OnboardMe will assist the Customer as set out below.
  3. What it enables. It authorises OnboardMe to host, store, transmit, and otherwise process Customer Personal Data only as needed to operate the features the Customer uses (onboarding, forms, engagements, documents, messaging, identity / AML verification where enabled, and optional integrations the Customer connects). It does not add product features, and it does not transfer professional or regulatory responsibility for the Customer's clients to OnboardMe.
  4. Signed copies. If the Customer's procurement or privacy policy requires a countersigned DPA, email [email protected] with the subject "DPA countersignature". A separately executed DPA prevails over this page to the extent of conflict.
  5. Regional deployments. If the Customer uses more than one OnboardMe regional product (for example Australia and the United Kingdom), each deployment has its own hosting location, subprocessor list, and DPA page. Read the DPA on the deployment the Customer actually uses.
  6. Not legal advice. This DPA is a contract. It is not legal, tax, or compliance advice to the Customer. The Customer must assess whether the Service and these terms meet its own professional and regulatory obligations.

Contents

  1. Summary
  2. Parties
  3. Definitions
  4. Roles
  5. What this DPA covers
  6. Instructions
  7. Customer obligations
  8. OnboardMe obligations
  9. Subprocessors and integrations
  10. International transfers
  11. Assistance with individual rights
  12. Personal data breaches
  13. Return and deletion
  14. Information and audits
  15. Liability and precedence
  16. Term, variation, and contact
  17. Annex 1 — Details of processing
  18. Annex 2 — Material subprocessors
  19. Annex 3 — Technical and organisational measures

Parties

Processor / service provider: OnboardMe Pty Ltd (ACN 680 379 640), trading as OnboardMe, an Australian company.

Customer: the organisation that has an OnboardMe account or subscription, or that otherwise uses the Service under the Terms, and on whose behalf Client Data is processed.

Definitions

  • Customer Account Data means information OnboardMe handles as an independent organisation about the Customer itself — for example practice user accounts, subscription and invoice records for fees payable to OnboardMe, security logs of staff logins, and product analytics about use of the Service. That processing is described in the Privacy Policy and is outside this DPA.
  • Customer Personal Data (also "Client Data" in the Terms) means personal information / personal data relating to the Customer's clients and other individuals that is submitted to, generated in, or processed through the Service on the Customer's behalf. Annex 1 lists typical categories.
  • Service means the OnboardMe platform for this deployment, including related APIs and the OnboardMe Assist Chrome extension where the Customer's users install it.
  • Subprocessor means a third party engaged by OnboardMe to process Customer Personal Data in providing the Service (Annex 2). It does not mean a system the Customer chooses to connect (for example Xero or FYI).
  • Terms defined in the Terms of Service or Privacy Policy have the same meaning unless this DPA says otherwise.

Roles

The Customer remains the organisation responsible for Customer Personal Data about its clients. The Customer decides which individuals’ information is submitted, which features are used, and how onboarding, engagement, and verification outcomes are used in its practice.

OnboardMe holds and handles Customer Personal Data on the Customer’s behalf solely to provide the Service. OnboardMe is not the Customer’s client’s accounting, tax, legal, or AML adviser, and does not become the APP entity (or NZ agency) for that client relationship.

In the language of Australian and New Zealand privacy law, the Customer is the APP entity (or NZ agency) responsible for the information and OnboardMe is the service provider / contracted processor for Customer Personal Data. The Customer is responsible for having a lawful purpose and any required notices or consents before submitting Client Data into the Service.

What this DPA covers (and what it does not)

Covered: all processing of Customer Personal Data by OnboardMe and its subprocessors to provide the Service, including the activities in Annex 1.

Not covered: Customer Account Data (OnboardMe as controller / APP entity for its own business); the Customer's own files and systems outside OnboardMe; processing by third parties the Customer instructs us to send data to (optional integrations); and professional advice, AML decisions, or regulatory filings, which remain the Customer's. OnboardMe is a software tool only, as stated in the Terms.

Instructions

The Customer instructs OnboardMe to process Customer Personal Data:

  • to provide and secure the Service as configured by the Customer;
  • in accordance with this DPA, the Terms, and the Privacy Policy; and
  • as the Customer directs through ordinary use of the Service (for example creating a client, enabling identity verification, sending an engagement, connecting an integration, or deleting a record).

OnboardMe will not process Customer Personal Data except on these documented instructions unless required by applicable law. If we are required by law to process other than as instructed, we will inform the Customer unless the law prohibits that notice. If we reasonably believe an instruction infringes applicable data-protection law, we will inform the Customer and may pause that instruction until it is clarified or withdrawn.

Written instructions outside the product must be sent to [email protected] by an authorised administrator and must be capable of being performed in the Service. OnboardMe is not obliged to build custom processing that the Service does not support.

Customer obligations

The Customer must:

  • have a lawful basis (and any required notices or consents) to submit Customer Personal Data, including identity documents and TFN or IRD number where collected;
  • not instruct OnboardMe to process children's data (the Service is not directed at children);
  • use access controls, including MFA where offered, and keep staff credentials confidential;
  • configure optional integrations and identity / AML features only where the Customer accepts the additional sharing described in the Privacy Policy and Annex 1;
  • remain responsible for how ComplyCube or other verification results are used in the Customer's compliance decisions;
  • handle requests from its own clients about Customer Personal Data, and contact OnboardMe only where platform assistance is needed; and
  • notify OnboardMe promptly if it believes Customer Personal Data has been processed in error or without authorisation in the Customer's tenant.

OnboardMe obligations (Service-provider handling rules)

OnboardMe will:

  • Use and disclose Customer Personal Data only to provide the Service, to comply with law, or as otherwise documented in this DPA and the Privacy Policy.
  • Take reasonable steps to protect Customer Personal Data from misuse, interference, loss, and unauthorised access, modification, or disclosure (APP 11 and equivalent NZ duties), as described in Annex 3.
  • Cooperate with the Customer so it can respond to access and correction requests about Customer Personal Data we hold on its behalf.
  • Notify the Customer of relevant data breaches as set out in this DPA so the Customer can meet NDB / NZ notifiable privacy breach duties that sit with it.
  • Ensure material subprocessors are bound by confidentiality and security obligations appropriate to their role.
  • Delete or return Customer Personal Data at the end of the Service as set out in this DPA, except where we are required or authorised by law to retain it.

The Service may handle biometric verification capture (sensitive information / special category data where those definitions apply), identity documents, and government identifiers such as tax file numbers or IRD numbers (which are subject to extra restrictions, including the TFN Rule in Australia, but are not “sensitive information” under the Privacy Act). The Customer is responsible for collecting that information only where permitted. OnboardMe applies tighter access control as described in the Privacy Policy and Annex 3, including encryption of tax identifiers where collected.

Subprocessors and optional integrations

The Customer authorises OnboardMe to engage the material subprocessors in Annex 2 (and the Privacy Policy) to process Customer Personal Data for the stated purposes. OnboardMe will impose confidentiality and data-protection obligations on those subprocessors that are no less protective in substance than this DPA, having regard to the service they provide.

OnboardMe may update the list from time to time. Material additions will be communicated in line with the Customer's agreement with us (for example in-product notice or email to organisation administrators). The Customer may object on reasonable data-protection grounds within 14 days of notice. If we cannot reasonably accommodate the objection, the Customer may stop using the affected feature or terminate the affected subscription in accordance with the Terms.

Practice-management, accounting, document, or email systems the Customer connects (for example Xero, FYI, GreatSoft, KloudConnect, or Google Workspace) are engaged at the Customer's direction. They are not OnboardMe subprocessors. Data shared with them is an instruction from the Customer; those providers' terms apply as between the Customer and that provider.

International transfers

Primary infrastructure and stored customer data for this deployment are located in Australia (AWS Sydney, with encrypted replicas in AWS Melbourne). When your organisation enables identity verification or AML screening features, relevant personal information (such as identity documents, live facial or biometric capture used for verification, and screening data) is shared with ComplyCube, a United Kingdom-based identity and AML verification provider, and is processed and stored in the United Kingdom. Payment processing for New Zealand customers may involve Stripe. Transactional email and SMS (Resend, Mailgun, TallBob), product analytics (PostHog EU Cloud), and error monitoring (Sentry in the EU) necessarily involve processing outside the primary hosting region. Optional integrations you connect may involve further disclosure at your or your organisation’s direction. Any such disclosure is handled in line with applicable Australian and New Zealand privacy laws.

Where Customer Personal Data is disclosed overseas in order to provide the Service (in particular identity verification and AML screening via ComplyCube in the United Kingdom; error monitoring via Sentry in the EU; product analytics via PostHog EU Cloud; and transactional email that may be processed in the United States by Resend or Mailgun), OnboardMe takes reasonable steps so that the overseas recipient does not breach the Australian Privacy Principles (APP 8), unless an exception applies, or, where New Zealand law applies, comparable safeguards under information privacy principle 12. Optional integrations the Customer connects may involve further overseas disclosure at the Customer’s direction.

Assistance with individual rights

If an individual asks OnboardMe to access, correct, delete, or otherwise exercise rights in Customer Personal Data, OnboardMe will (where we can identify the Customer) direct the individual to the Customer and/or notify the Customer, unless we are legally required to handle the request ourselves.

If the Customer cannot fulfil a request using the Service (for example deletion of an entity, download of documents, or correction of a client record), the Customer may email [email protected] with the subject "Privacy request — processor assistance". OnboardMe will provide reasonable assistance, taking into account the nature of processing and the information available to us. We may need the Customer to verify the request and specify the tenant and records involved.

Personal data breaches

OnboardMe will notify the Customer without undue delay after becoming aware of a data breach affecting Customer Personal Data that is likely to require assessment under the Notifiable Data Breaches scheme (Australia) or as a notifiable privacy breach (New Zealand), with enough information reasonably available to us for the Customer to complete that assessment and any notification to the OAIC, the Office of the Privacy Commissioner, and affected individuals.

Notification will describe, as then known: the nature of the breach, the categories and approximate number of individuals and records concerned, likely consequences, and measures taken or proposed. OnboardMe will reasonably cooperate with the Customer's investigation and with any required regulator or individual notification that the Customer must make. Public security reporting channels are described in the Security Policy.

Return and deletion

During the subscription, the Customer may export or delete Customer Personal Data using the Service (for example deleting a client entity or downloading documents). That is the primary way the Customer exercises deletion and portability in the product.

When the Customer's subscription or authorised use ends, OnboardMe will, within 90 days, delete Customer Personal Data from production systems, or return it in a reasonable commonly used form if the Customer requests export in writing within 30 days after termination. Copies in encrypted backups will drop out on the backup cycle and will not be restored into production except as needed for disaster recovery. OnboardMe may retain Customer Personal Data where required or authorised by law (including tax and accounting records of the Customer relationship, which are Customer Account Data), or in a form that no longer identifies individuals.

Information, DPIAs, and audits

OnboardMe will make available information reasonably necessary to demonstrate compliance with this DPA, including this page, the Privacy Policy, and the Security Policy. Taking into account the nature of processing, we will provide reasonable assistance with the Customer's data-protection impact assessments or equivalent risk assessments, and with any prior consultation with a regulator, to the extent the assessment concerns the Service.

If that information is not sufficient, the Customer may request an audit, no more than once per 12 months unless a confirmed personal data breach or a regulator requires otherwise. Audits must be reasonable in scope, on notice of at least 30 days, during business hours, and must not compromise other customers' security or confidentiality. OnboardMe may satisfy an audit by providing third-party certifications, questionnaire responses, or a call with security personnel. The Customer bears its own costs; OnboardMe may charge reasonable costs for on-site or unusually burdensome audits.

Liability and precedence

This DPA is an addendum to the Terms. Liability arising from processing under this DPA is subject to the limitations and exclusions in the Terms, except where applicable law prohibits that limitation. Each party remains liable for its own obligations as APP entity (or NZ agency) responsible for the information or service provider / contracted processor under mandatory data-protection law.

Order of precedence for Customer Personal Data: (1) a separately executed DPA between the parties; (2) this DPA; (3) the Privacy Policy insofar as it describes processing; (4) the Terms. Commercial terms (fees, service availability, IP, governing law of the contract) remain as in the Terms unless a signed DPA expressly changes them.

Term, variation, and contact

This DPA starts when the Customer first uses the Service under the Terms after the Effective Date (or when a prior version applied, from that earlier date) and continues until OnboardMe has deleted or returned Customer Personal Data as required above. Confidentiality, deletion, audit (for the retention period), and liability clauses survive accordingly.

OnboardMe may update this DPA as described for the Terms (including notice of material changes). Continued use after the effective date of an update constitutes acceptance, except that a separately executed DPA changes only if the parties agree in writing.

This DPA is governed by the same law and courts as the Terms, without limiting mandatory data-protection law of this deployment. Questions: [email protected] (privacy) or [email protected] (security).

Annex 1 — Details of processing

A. Subject matter and nature

Hosting and operation of the OnboardMe cloud platform so the Customer can run client onboarding, engagement letters, forms and e-sign, document collection, identity verification and AML screening (where enabled), messaging, billing-related client workflows, and optional connections to the Customer's own practice systems. Processing includes collection, recording, organisation, storage, retrieval, consultation, use, disclosure by transmission, restriction, and erasure, as performed by the features the Customer uses.

B. Duration

For the term of the Customer's subscription (or other authorised use of the Service), plus the post-termination deletion / return period in this DPA, and any longer period required by law or encrypted backups that are deleted on the backup cycle.

C. Purpose

Solely to provide, maintain, secure, support, and improve the Service for the Customer, to communicate about the Service as the Customer directs (for example sending an engagement to a client), and to comply with law. OnboardMe does not sell Customer Personal Data and does not use it for OnboardMe's own marketing to the Customer's clients.

D. Categories of data subjects

  • The Customer's clients and prospective clients (individuals, and individuals associated with client organisations — for example directors, trustees, and contacts).
  • Recipients of onboarding, forms, engagements, ethical letters, identity verification, and similar workflows (including people who access a client portal or magic-link).
  • Other individuals whose information the Customer (or a client acting in the Customer's workflow) enters into the Service — for example referees, signatories, or related-party contacts.
  • Individuals named in documents the Customer uploads or generates (engagement PDFs, identity documents, supporting files).

Practice staff who hold OnboardMe user accounts are primarily described as Customer Account Data (outside this DPA). Staff names and contact details that appear inside Client Data (for example as the assigned adviser on an engagement) are processed as Customer Personal Data to the extent they form part of that Client Data.

E. Types of Customer Personal Data

Depending on the features the Customer uses, this may include:

  • Identity and contact: name, email, phone, job title, date of birth, address, employer or entity identifiers.
  • Tax and government identifiers: Australian tax file numbers (TFNs), New Zealand IRD numbers, and similar identifiers the Customer collects.
  • Financial: bank account and payment details entered for the Customer's clients (as distinct from the Customer's own subscription billing to OnboardMe).
  • Service content: information entered into forms, proposals, engagements, ethical letters, custom fields, notes, and related workflows; electronic signatures and signing metadata.
  • Documents: uploaded files, generated PDFs, identity document images, and similar records stored in object storage.
  • Identity verification and AML: identity documents, live facial images or biometric capture used for matching, verification session identifiers, and AML / PEP / sanctions screening inputs and results — where the Customer enables those features.
  • Technical data created by use of the Service: IP address, device or session metadata, authentication events, and audit logs relating to Client Data access.

F. Processing activities in the product

ActivityTypical processingTypical recipients
Client / entity records and onboardingStore, display, update, and delete client information the Customer or the client submitsHosting (AWS Sydney region); optional practice integrations the Customer connects
Forms, engagements, ethical letters, e-signCreate, send, collect responses, generate PDFs, record signaturesHosting; email and SMS providers when the Customer sends a workflow
Document collectionUpload, store, download (including short-lived signed URLs), optional push to the Customer's DMSHosting object storage; KloudConnect or similar only if the Customer connects it
Identity verification and AML screeningShare identity and screening inputs; receive outcomes and artefactsComplyCube (United Kingdom), when the Customer enables the feature
Transactional email and SMSDeliver invitations, reminders, and service messages the Customer triggersResend, Mailgun, TallBob
Client payment details (where used)Collect or display payment information for the Customer's billing of its clientsPinch, Apxium, Stripe, or Paystack as configured for this deployment and the Customer
Optional practice-system syncCreate, update, or retrieve clients, contacts, jobs, or documents in the connected systemThe provider the Customer connects (for example Xero, FYI, GreatSoft, Google Workspace) — at the Customer's direction
Chrome extension (OnboardMe Assist)Read bank / identity fields already in OnboardMe to fill empty fields in Xero Practice Manager, using session credentials in the browserProcessed in the authorised user's browser and via the Service APIs; not a separate hosting location
Security, support, and reliabilityLogs, backups, error diagnostics, and aggregated product analyticsHosting and monitoring for this deployment (AWS Sydney region); PostHog; Sentry; UptimeRobot

OnboardMe does not itself make solely automated decisions with legal or similarly significant effects about the Customer's clients. ComplyCube may return automated verification or screening results; the Customer remains responsible for how those results are used.

Annex 2 — Material subprocessors

The Customer gives general written authorisation to the subprocessors listed below for this deployment. Optional integrations the Customer connects are not OnboardMe subprocessors and are not listed here. Where a name is linked, it opens that provider's privacy or security information.

SubprocessorPurposeLocation
Amazon Web Services (AWS)Cloud hosting, backups, logging, and monitoringAustralia (Sydney primary; Melbourne replicas)
ComplyCubeIdentity verification and AML / PEP / sanctions screening (where enabled)United Kingdom
Pinch PaymentsPayment processing (Australia)Australia
ApxiumPayment processing (Australia, where used)Australia
StripePayment processing (New Zealand)As operated by Stripe for New Zealand payments
ResendTransactional and service email deliveryUnited States (and other locations as operated by Resend)
MailgunTransactional and service email deliveryUnited States and other locations as operated by Mailgun
TallBobSMS messagingAustralia (as operated by TallBob)
UptimeRobotExternal uptime and availability monitoringAs operated by UptimeRobot
PostHogProduct analytics and diagnosticsEuropean Economic Area (PostHog EU Cloud)
SentryApplication error monitoring and diagnosticsEuropean Union (error ingestion in Germany)

This list is the same material-subprocessor list published in the Privacy Policy for this deployment. If the two pages ever differ, the Privacy Policy list as updated on that page is the operative list, and this Annex will be treated as updated accordingly.

Annex 3 — Technical and organisational measures

OnboardMe implements the following measures, which may be updated as technology and threats change provided the overall level of security is not materially reduced. Backups, recovery, and controls are described in Information security & business continuity. Vulnerability reporting is on that same page.

  • Hosting and location: production Customer Personal Data for this deployment is stored in the AWS Sydney region, with encrypted backups in Australia (Sydney primary; nightly encrypted replicas in AWS Melbourne).
  • Encryption: Customer data is encrypted in transit using TLS 1.2+. Data at rest on this AWS deployment is encrypted (including via AWS KMS / AES-256 for volumes and object storage), as described in our Information security & business continuity policy. Tax identifiers and other high-risk fields are subject to additional access restriction.
  • Access control: role-based access within the Customer's tenant; authentication including multi-factor authentication where enabled by the Customer; OnboardMe staff access limited to personnel who need it for support, security, or operations, on a least-privilege basis.
  • Isolation: Customer data is logically separated by practice / tenant identifiers in the application data model.
  • Monitoring and logging: authentication events, operational logs, and security alerting (including to [email protected]), with error monitoring configured to limit identifiable data to what is needed for diagnosis.
  • Personnel: confidentiality obligations for staff and contractors who may access Customer Personal Data; access reviewed when roles change.
  • Subprocessors: due diligence and contractual confidentiality / security obligations appropriate to the service they provide.
  • Vulnerability and incident management: vulnerability handling, an incident response process, and breach assessment aligned with Compliance with Australian and New Zealand law.
  • Backups and restoration: encrypted backups and procedures to restore availability of the Service after an incident, within commercially reasonable timeframes.

No electronic system is perfectly secure. These measures are appropriate to the nature of the Service as a professional-services onboarding platform handling tax identifiers, identity documents, and similar information, taking into account the state of the art, implementation costs, and the risks for individuals.