Effective 13 August 2026
Legal

Data Processing Addendum

Tempa’s Data Processing Addendum covering the processing of Customer Personal Data in connection with the services.

01 / LEGAL

Effective date: 13 August 2026

Last updated: 13 August 2026

Brad AI Pty Ltd trading as Tempa · ABN 38 689 988 047 · ACN 689 988 047 · 28 Ossett Street, Sorrento, Australia

1. Status and parties

This Data Processing Addendum (DPA) is between the customer identified in the applicable written customer agreement (Customer) and Brad AI Pty Ltd trading as Tempa, ABN 38 689 988 047, ACN 689 988 047, Australia (Tempa).

This DPA forms part of a written customer agreement only once it is executed by the parties or expressly incorporated into that agreement.

Registered address: 28 Ossett Street, Sorrento, Australia.

Legal/privacy contact: max@tempa.agency.

2. Definitions

Applicable Data Protection Law
means data protection, privacy and breach-notification laws that apply to a party’s processing under the customer agreement, including, where applicable, the GDPR, UK GDPR, Australian Privacy Act 1988 (Cth) and Australian Privacy Principles.
Customer Personal Data
means personal data or personal information that Tempa processes on behalf of Customer in providing the Services.
Controller
means the entity that determines the purposes and means of processing personal data, including a “business” where that term applies.
Processor
means an entity that processes personal data on behalf of a Controller, including a “service provider” or equivalent where that term applies.
Subprocessor
means a third party appointed by Tempa to process Customer Personal Data on Customer’s behalf.
Services
means the services described in the applicable written customer agreement, statement of work or order.

3. Scope and roles

Customer is the Controller or Business and Tempa is the Processor or Service Provider only to the extent Tempa processes Customer Personal Data on Customer’s documented instructions in connection with the Services.

Each party will comply with the obligations that apply to its role under Applicable Data Protection Law. Customer is responsible for the lawfulness, transparency and accuracy of Customer Personal Data and for providing all notices and obtaining all permissions required for Tempa to process it as instructed.

If Tempa processes personal data for its own independent purposes, that processing falls outside this DPA and Tempa acts in the role determined by Applicable Data Protection Law.

4. Documented instructions and confidentiality

Tempa will process Customer Personal Data only on documented instructions from Customer, including the customer agreement, Customer’s configured use of the Services, and written directions consistent with that agreement, unless processing is required by applicable law. Where legally permitted, Tempa will inform Customer before processing required by law.

If Tempa reasonably believes an instruction infringes Applicable Data Protection Law, it will notify Customer and may pause the affected processing while the parties assess the instruction.

Tempa will restrict access to authorised personnel who need access to provide or support the Services. Those personnel will be subject to appropriate confidentiality obligations and instructions regarding Customer Personal Data.

5. Security and personal-data incidents

Tempa will maintain appropriate technical and organisational measures designed to protect Customer Personal Data, taking into account the nature, scope, context and purposes of processing and the risks to individuals. The current categories of measures are described in Schedule 2.

After becoming aware of a personal-data breach affecting Customer Personal Data, Tempa will notify Customer without undue delay and provide information reasonably available to Tempa to help Customer meet applicable notification obligations. Notification is not an admission of fault or liability.

Tempa will take reasonable steps to contain, investigate and remediate the breach and will provide material updates as appropriate.

6. Subprocessors

Customer generally authorises Tempa to appoint Subprocessors for the Services. Tempa will impose written data-protection obligations on each Subprocessor that are appropriate to the processing and materially consistent with Tempa’s obligations under this DPA. Tempa remains responsible for the performance of its Subprocessors to the extent required by Applicable Data Protection Law and the customer agreement.

Tempa’s current list and change-notice approach are set out on the Subprocessors page. Where the customer agreement gives Customer a right to object to a material new Subprocessor, the parties will work in good faith to address a reasonable data-protection objection.

7. Customer assistance

Data-subject requests

Taking into account the nature of the processing, Tempa will provide reasonable assistance through appropriate technical and organisational measures so Customer can respond to requests to exercise data-subject rights. If Tempa receives a request relating to Customer Personal Data, it will direct the requester to Customer where appropriate and will not respond on Customer’s behalf unless instructed or legally required.

DPIAs and regulator cooperation

Taking into account the information available to Tempa and the nature of the processing, Tempa will provide reasonable assistance with Customer’s data-protection impact assessments, prior consultations and cooperation with supervisory or regulatory authorities where required by Applicable Data Protection Law.

8. Return, deletion, information and audit support

Following termination or expiry of the Services, Tempa will, at Customer’s choice and subject to available service functionality, return or delete Customer Personal Data, except to the extent retention is required by applicable law. Data retained by law will remain protected and will not be used for other purposes.

Tempa will make available information reasonably necessary to demonstrate compliance with this DPA. Where that information is insufficient, Tempa will provide proportionate audit support, subject to reasonable notice, confidentiality, security, operational and scope safeguards, and coordination to minimise disruption and duplication.

9. International transfers

Where Customer Personal Data is transferred from the European Economic Area to a country without an applicable adequacy decision, the parties will use the relevant module of the European Commission 2021 Standard Contractual Clauses, as applicable to their roles.

Where Customer Personal Data is transferred from the United Kingdom and an approved safeguard is required, the parties will use the UK ICO International Data Transfer Addendum or another lawful transfer mechanism, as applicable.

Australian cross-border handling will be managed consistently with applicable Privacy Act 1988 (Cth) and Australian Privacy Principle 8 obligations where those apply.

10. Precedence and term

If this DPA conflicts with the customer agreement on the protection or processing of Customer Personal Data, this DPA prevails to the extent of that conflict. The customer agreement otherwise remains in effect.

This DPA starts only when executed or incorporated into the customer agreement and continues while Tempa processes Customer Personal Data for Customer.

Liability caps, exclusions, remedies and governing law are not created or changed by this DPA. They remain governed by the main customer agreement.

Schedule 1

Processing Details

Subject matter
Delivery of Tempa campaign planning, creative and copy generation, landing-page/site services, lead capture and booking workflows, attribution, reporting, optimisation and customer-authorised integrations.
Duration
Customer agreement plus return/deletion period and legal retention.
Nature
Collection, transmission, hosting, organisation, analysis, generation, retrieval, use and deletion.
Data subjects
Customer staff/users, website visitors, prospects/leads, campaign audiences and people who book or submit forms.
Data types
Business contact details; form/booking content; online identifiers; device/usage and attribution data; campaign interactions; customer-provided campaign context.
Exclusions
Payment-card data, credentials, special-category/sensitive data and unrelated personal data must not be supplied unless expressly agreed in writing with appropriate safeguards.

Schedule 2

Security Measures

Tempa’s measures are intended to be appropriate and proportionate to the risk and the Services. They evolve as risks, provider capabilities and the Services change. This schedule does not state or imply any certification.

  • TLS for production data in transit.
  • Managed hosting, database and object-storage controls supplied by Tempa’s infrastructure providers.
  • Role- and credential-based restrictions designed to limit access to authorised people and systems.
  • Secrets maintained in managed environment configuration rather than embedded in application source.
  • Separation of production and development environments appropriate to the Services.
  • Logging and monitoring appropriate to service operation, security investigation and reliability.
  • Vulnerability and dependency maintenance processes proportionate to identified risk.
  • Provider-backed backup and recovery capabilities appropriate to the relevant service and data store.
  • Incident response procedures and removal of access when it is no longer required.
  • Personnel confidentiality obligations.