Version 1.0 — September 2026
This agreement applies automatically to every paid Dinopix subscription and forms part of our Terms of Service. You do not need to sign anything. If your organisation requires a countersigned copy, or needs us to review your own paper, contact us through our contact page.
This Data Processing Agreement (DPA) is between Dinopix Pty Ltd (Dinopix, we, us) and the customer identified on the Dinopix account (Customer, you). It governs our processing of personal information on your behalf when you use the Dinopix platform.
You are the controller of the personal information you place in, or connect to, Dinopix — including your customers' details, reviews, comments and messages. Dinopix is the processor of that information and processes it only on your documented instructions. Using the platform's features constitutes those instructions.
Dinopix is separately the controller of your own account information — the name, email address and billing details of your users. That is covered by our Privacy Policy, not by this DPA.
Subject matter: provision of the Dinopix review management and CRM platform. Duration: for as long as your subscription is active, plus the deletion periods in clause 8. Nature and purpose: collecting, storing, organising, analysing and transmitting personal information so that you can read and respond to customer feedback and manage customer records.
Categories of data subject: your customers and prospective customers, people who review or message your business on connected platforms, visitors to your website where you enable visitor tracking, and your own staff users. Categories of personal information: names, email addresses, telephone numbers, social media handles and profile identifiers, order and transaction details, review and message content, browsing activity on your website where you enable visitor tracking (pages viewed, referring page and timestamps, against a random identifier), and any other information you choose to store in your CRM records.
You must not use Dinopix to process sensitive information as defined in the Privacy Act 1988 (Cth), or special categories of data under the GDPR, unless we have agreed to it in writing. The platform is not designed for it.
Where you enable website visitor tracking, you confirm that you have obtained any consent required in your jurisdiction for the cookie and the collection it performs, and that your own privacy notice describes it. We provide the mechanism; the lawful basis for collecting from your visitors is yours. You can disable it at any time from the connection settings, and our script honours Global Privacy Control and Do Not Track regardless of your configuration.
We will:
You give general authorisation for Dinopix to engage sub-processors. Our current sub-processors, their purpose and the region each operates in, are listed at dinopix.ai/subprocessors.
We impose data protection obligations on each sub-processor that are no less protective than those in this DPA, and we remain liable to you for their performance. We will update the sub-processor page and give you at least 30 days' notice by email before a new sub-processor begins processing your personal information. If you reasonably object within that period and we cannot resolve it, you may terminate your subscription without penalty for the remainder of the term.
We maintain technical and organisational measures appropriate to the risk, including: encryption in transit (TLS) and at rest; row-level access controls that isolate each customer's data; role-based permissions within an account; encryption of third-party platform access tokens; access logging and audit trails; least-privilege administrative access; and regular automated security scanning of our codebase and dependencies.
No system is perfectly secure. These measures reduce risk; they do not eliminate it, and we do not claim otherwise.
We will notify you without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting personal information we process on your behalf. The notification will describe the nature of the breach, the categories and approximate number of individuals and records affected, the likely consequences, and the measures taken or proposed.
We will provide reasonable assistance so you can meet your own obligations, including under the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act 1988 (Cth) and Articles 33 and 34 of the GDPR.
Personal information is stored and processed outside Australia — principally in Singapore, with certain service providers operating in the United States and the European Union. The current position for each provider is on the sub-processors page.
We take reasonable steps to ensure overseas recipients handle personal information consistently with the Australian Privacy Principles, as required by APP 8. Where personal information originates in the European Economic Area, the United Kingdom or Switzerland, transfers are made under the European Commission's Standard Contractual Clauses, which are incorporated into this DPA by reference, with Dinopix as data importer and you as data exporter.
You can export your data at any time while your subscription is active. On termination, or on your written request, we will delete personal information processed on your behalf from the live service within 30 days.
Encrypted backups are retained on a rolling 7-day window for disaster recovery. Deleted data persists in those snapshots until they expire, after which it is gone. We do not restore backups to recover individual deleted records. We will retain information for longer only where a law requires it, and in that case we will keep processing it solely for that purpose.
We will respond to reasonable written requests for information needed to confirm our compliance with this DPA. Where that is not sufficient for your regulatory obligations, we will accommodate an audit on reasonable notice, no more than once in any 12-month period unless a regulator or a breach requires otherwise, conducted at your cost and subject to confidentiality.
This DPA is subject to the limitations and exclusions of liability in our Terms of Service. If there is a conflict between this DPA and those Terms on the processing of personal information, this DPA prevails. If there is a conflict between this DPA and the Standard Contractual Clauses, the Clauses prevail.
We may update this DPA to reflect changes in law or in the service. We will give at least 30 days' notice of material changes to customers on paid plans, and previous versions remain available on request.
This document is provided for transparency and is not legal advice. If you need advice on your own obligations as a controller, speak to a qualified practitioner in your jurisdiction.