Data Processing Agreement (DPA) — Comprehendly
Provider / Processor: UltraDigital Limited (“StepCare”, “Comprehendly”, “Processor”)
Customer / Controller: The organisation accepting the Terms of Service (“Customer”, “Controller”)
Effective date: 1 August 2026
Version: 1.0
This DPA forms part of the agreement between Controller and Processor for Comprehendly. It applies when Processor processes Customer Personal Data on Controller’s behalf.
Online acceptance of the Terms constitutes acceptance of this DPA. Enterprise customers may request a countersigned copy from privacy@stepcare.app.
1. Definitions
| Term | Meaning |
|---|---|
| Customer Personal Data | Personal information submitted to the Service by or for Controller, including form submissions, voice metadata, transcripts (if enabled), phone metadata, audit events, and integration payloads |
| Applicable Privacy Law | Privacy Act 2020 (NZ), Privacy Act 1988 (AU), and other laws identified in Schedules A and B |
| Sub-processor | Third party engaged by Processor per Section 6 |
| Service | Comprehendly as described in the Terms |
2. Scope and roles
2.1 Controller determines purposes and means of processing Customer Personal Data.
2.2 Processor processes Customer Personal Data only on documented instructions from Controller (Terms, this DPA, configuration, and support requests within scope).
2.3 Processor will not process Customer Personal Data for its own marketing purposes, and will not use Customer form content to train public foundation models.
3. Processor obligations
Processor will:
| # | Obligation |
|---|---|
| 3.1 | Process only on instructions, unless required by law (and notify Controller unless prohibited) |
| 3.2 | Ensure personnel are bound by confidentiality |
| 3.3 | Implement appropriate technical and organisational security |
| 3.4 | Not disclose to third parties except Sub-processors or as instructed |
| 3.5 | Assist Controller with access, correction, and deletion requests (Section 8) |
| 3.6 | Assist with security and breach notifications (Section 7) |
| 3.7 | Delete or return data on termination (Section 9) |
| 3.8 | Make available information necessary to demonstrate compliance, subject to reasonable notice and confidentiality |
4. Controller obligations
Controller will:
- Provide lawful instructions and a valid legal basis for processing
- Provide required notices and consents to individuals (including voice, phone, embed, and sensitive data)
- Comply with spam, telemarketing, and Do Not Call rules for any outreach campaigns
- Not submit prohibited content (Acceptable Use Policy)
- Configure retention and access appropriately
- Notify Processor of complaints or regulator enquiries relating to the Service
5. Details of processing
| Element | Description |
|---|---|
| Subject matter | Provision of Comprehendly SaaS |
| Duration | Term of the Terms plus export/deletion period |
| Nature | Hosting, transcription, AI field mapping, telephony, storage, audit export, API delivery |
| Purpose | Structured form completion, evidence capture, and related Customer workflows |
| Categories of data subjects | Controller’s staff, contractors, applicants, residents, clients, or other subjects Controller defines |
| Categories of data | Identifiers, contact details, form responses, optional voice/transcript, phone metadata, attachments |
| Sensitive data | May include health or disability information — Controller must ensure lawful processing |
6. Sub-processors
6.1 Controller provides general authorisation for Processor to engage Sub-processors listed at /legal/subprocessors.
6.2 Processor will notify Controller of new Sub-processors at least 14 days before engagement via email to account administrators or an updated sub-processor page.
6.3 Controller may object on reasonable privacy grounds within 14 days. If unresolved, Controller may terminate the affected Service without penalty for that component.
6.4 Processor imposes data protection terms on Sub-processors substantially similar to this DPA and remains liable for Sub-processor acts and omissions as between the parties.
7. Security incidents
7.1 Processor will notify Controller without undue delay and within 72 hours of becoming aware of a confirmed breach affecting Customer Personal Data.
7.2 Notification will include, to the extent known: nature of incident, categories of data, likely consequences, and mitigation steps.
7.3 Controller is responsible for regulator and individual notifications under Applicable Privacy Law unless otherwise agreed in writing for Enterprise customers.
8. Data subject rights
8.1 Processor will forward to Controller any request received directly from an individual relating to Customer Personal Data.
8.2 Processor will assist Controller in responding within 15 business days, subject to reasonable fees for manifestly excessive requests.
9. Return and deletion
9.1 On termination, Controller may export data for 30 days.
9.2 Processor will delete Customer Personal Data from production systems within 90 days, except backups retained up to 90 additional days and logs retained for security/legal requirements.
9.3 Deletion confirmation is available on request for Enterprise plans.
10. Overseas transfers
Processor may transfer Customer Personal Data to Sub-processors outside New Zealand and Australia as listed in the Sub-processor list, including OpenAI in the United States for AI language processing. Processor will take steps required under Schedule A (APP 8) and Schedule B (IPP 13).
11. Audits
11.1 Processor will provide SOC 2 / ISO reports or security summaries when available under NDA.
11.2 On-site audits: once per year with 30 days’ notice, during business hours, subject to confidentiality and not disrupting operations. Controller bears costs unless an audit reveals a material uncured breach by Processor.
12. Liability
Liability under this DPA is subject to the limitations in the Terms, except where liability cannot be limited for privacy breaches under Applicable Privacy Law.
13. Order of precedence
Conflict: DPA prevails for processing of Customer Personal Data; Terms prevail for commercial matters.
14. Term
This DPA applies for the duration of the Terms and until all Customer Personal Data is deleted or returned.
Schedule A — Australia
A.1 Processor and APPs
Where Processor handles Customer Personal Data, Controller remains responsible for APP compliance regarding collection from individuals. Processor supports APP 11 security and APP 8 overseas disclosure steps through contractual and operational controls.
A.2 Notifiable Data Breaches
Controller must assess eligibility; Processor assists with information. Processor does not file OAIC notifications on Controller’s behalf unless expressly agreed.
Schedule B — New Zealand
B.1 IPPs and HIPC
Controller determines whether it is a health agency under the Health Information Privacy Code 2020. Processor supports Controller’s HIPC programme but does not assume health agency status.
B.2 IPP 3A
Where data is collected indirectly via embed/API, Controller must ensure individuals receive required notice.
B.3 Notifiable Privacy Breaches
Controller assesses serious harm; Processor notifies Controller per Section 7.
Optional execution block
| Controller | Processor |
|---|---|
| Name: __________________ | UltraDigital Limited |
| Title: __________________ | __________________ |
| Date: __________________ | Date: __________________ |
For online acceptance, clicking “I agree” to the Terms constitutes acceptance of this DPA.
End of DPA