Legal
Data Processing Agreement
Last updated: July 2026
This Data Processing Agreement ("DPA") forms part of theTerms of Service or other written agreement between you ("Customer") and Consystence Pty Ltd ("Consystence") for the Consystence platform (the "Agreement"). It applies where Consystence processes Customer Personal Data on the Customer's behalf. If you require a countersigned copy, contactlegal@consystence.com.
1. Roles and scope
Consystence handles personal data in two capacities, and this DPA covers only the first:
- As processor — for the personal data within your tenant and the software you operate (the "Customer Personal Data"), which Consystence processes on your documented instructions to provide the platform. You are the controller. This DPA governs that relationship.
- As controller — for the limited personal data Consystence collects for its own purposes (your account, billing, and website enquiries). That handling is governed by our Privacy Policy, not this DPA.
"Controller", "processor", "data subject", "personal data", and "processing" have the meanings given under applicable data-protection law. Australian privacy law does not use the controller/processor distinction, but the parties adopt it contractually here; the governing standard for Consystence's handling is the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), together with any additional law that applies to the Customer's data.
2. Processing instructions
Consystence processes Customer Personal Data only on the Customer's documented instructions — comprising the Agreement, this DPA, and the Customer's configuration and use of the platform — and as required by law (in which case Consystence will, where lawful, inform the Customer first). Consystence will tell the Customer if, in its opinion, an instruction infringes applicable data-protection law. The Customer is responsible for the accuracy and lawfulness of the Customer Personal Data and for having the necessary rights and notices in place, including telling its personnel about the operational audit records the platform keeps.
3. Confidentiality
Consystence ensures that personnel authorised to process Customer Personal Data are bound by confidentiality obligations and access it only as needed to provide the platform.
4. Security
Consystence maintains technical and organisational measures appropriate to the risk, described in Annex 2 and summarised on our Security & data residencypage. These include architectural single-tenant isolation, encryption in transit, credentials held only in hashed form, encrypted secrets at rest, and role-based access enforced server-side. Consystence may update these measures provided the level of protection is not materially reduced.
5. Sub-processors
The Customer authorises Consystence to engage the sub-processors listed in oursubprocessor register (Annex 3), each bound by data-protection obligations no less protective than this DPA. Consystence remains liable for its sub-processors' performance. Consystence will update the register and give the Customer a reasonable opportunity to object to a new sub-processor before it begins processing Customer Personal Data; if the Customer reasonably objects on data-protection grounds and the parties cannot resolve it, the Customer may terminate the affected service.
6. Data subject requests
The platform gives the Customer controls to access, correct, export, and delete data within its tenant. Taking account of the nature of the processing, Consystence will also provide reasonable assistance for the Customer to respond to data-subject requests. If Consystence receives a request directly from a data subject relating to Customer Personal Data, it will refer the individual to the Customer and not respond substantively except on the Customer's instruction or as required by law.
7. Personal data breach
Consystence will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, with the information reasonably available to help the Customer meet its own obligations (including under the Notifiable Data Breaches scheme). Consystence will take reasonable steps to mitigate and remediate. Notification is not an acknowledgement of fault.
8. Data protection impact assessments
Taking account of the nature of the processing and the information available to it, Consystence will provide reasonable assistance with the Customer's data-protection impact assessments and any prior consultation with a regulator.
9. Return and deletion
The Customer may export tenant data at any time using the platform's export mechanisms (including tenant-configuration export and the historian APIs). On termination or expiry of the Agreement, and on written request, Consystence will delete or return the Customer Personal Data within a reasonable period, and delete existing copies except to the extent Consystence is required by law to retain them or is reasonably required to retain specific records as audit evidence — in which case Consystence will keep them confidential and process them only as required for that purpose. Deletion of a tenant removes its directory entry, account-to-tenant associations, and elevated roles immediately; deletion of associated operational stores is completed as part of offboarding.
10. International transfers
Customer Personal Data is hosted in Australia (Azure Australia East), and production AI inference runs in Australia (AWS, Australian regions) by default. Certain sub-processors operate overseas as disclosed in the register; Consystence takes reasonable steps to ensure overseas recipients handle personal data consistently with the APPs. Where the Customer Personal Data is subject to a law requiring a specific transfer mechanism (for example, EU/UK personal data requiring Standard Contractual Clauses), the parties will enter into and comply with that mechanism, which is incorporated by reference on execution.
11. Audit
Consystence will make available information reasonably necessary to demonstrate compliance with this DPA and, on reasonable prior written notice and no more than once per year (unless required by a regulator or following a breach), allow the Customer or an independent auditor bound by confidentiality to verify compliance — conducted so as not to compromise the security or availability of the platform or other customers' data, at the Customer's cost.
12. Liability and precedence
Each party's liability under this DPA is subject to the limitations and exclusions of liability in the Agreement. If there is a conflict between this DPA and the Agreement on the processing of Customer Personal Data, this DPA prevails. This DPA is governed by the laws of Queensland, Australia.
Annex 1 — Details of processing
| Subject matter | Provision of the Consystence industrial platform and related services under the Agreement. |
| Duration | The term of the Agreement, plus the deletion/return period in section 9. |
| Nature and purpose | Hosting, processing, transmitting, and displaying Customer Personal Data to operate the platform — device-type authoring, simulation, server-driven operator screens, the provenance historian, organisation and site management, and the advisory AI tier. |
| Categories of data subjects | The Customer's personnel and authorised users — operators, engineers, administrators, and other individuals the Customer grants access. |
| Categories of personal data | Account and identity data (email, Microsoft object identifier, display name, role); authentication data (site-PIN hashes, session IP address and user-agent); operational records that attribute actions to a user (command audit, alarm acknowledgements, AI usage metering); and any personal data the Customer includes in tenant configuration or plant data. |
| Special categories | None intended or required. The Customer must not submit sensitive information (as defined by the Privacy Act) except as expressly agreed in writing. |
Annex 2 — Security measures
- Architectural single-tenant isolation; an account never spans a tenant boundary, and internal host names never appear in customer-facing surfaces.
- Encryption in transit (TLS) across all services.
- Credentials stored only in non-reversible form — PBKDF2 for site PINs, HMAC with a separately-held pepper for API keys, one-time SHA-256 hashes for invitation and activation codes, constant-time comparison throughout.
- Secrets at rest encrypted with rotating data-protection keys.
- Delegated identity (OpenID Connect); role-based access enforced server-side; independent cloud and site authentication authorities.
- Advisory-only AI with no path to command equipment; short-lived federated cloud credentials for AI inference; audit by content hash, never prompt or completion text.
- Authentication rate limiting, failed-sign-in lockout, and HttpOnly, SameSite session cookies.
The current description is maintained on our Security & data residency page.
Annex 3 — Sub-processors
The authorised sub-processors are maintained at thesubprocessor register, which forms part of this DPA.
Contact
Questions about this DPA, or to request a countersigned copy:legal@consystence.com.