How CertAssist handles personal data on behalf of its customers.
Siege Group Pty Ltd trading as CertAssist (ABN 14 639 942 877) · Suite 411, Level 1, 16 McDougall Street, Milton QLD 4064 · privacy@certassist.io · Version 1.0, last updated 3 September 2026
This Data Processing Agreement ("DPA") forms part of, and is subject to, the CertAssist Terms and Conditions or other written agreement between the customer ("Customer") and Siege Group Pty Ltd trading as CertAssist ("CertAssist", "we", "us") governing the Customer's use of the CertAssist platform and related services (the "Services") (together, the "Agreement").
This DPA applies where, and only to the extent that, CertAssist processes Personal Data on behalf of the Customer in the course of providing the Services. Where there is any conflict between this DPA and the Agreement in relation to the processing of Personal Data, this DPA prevails.
By accepting the Agreement, or by signing this DPA, the Customer enters into this DPA on behalf of itself and, to the extent required under applicable Data Protection Law, in the name and on behalf of its authorized affiliates.
Capitalised terms used but not defined in this DPA have the meaning given in the Agreement.
The parties acknowledge that, in respect of the processing of Personal Data under the Agreement, the Customer is the Controller and CertAssist is the Processor. Where the Customer is itself a processor acting on behalf of a third party controller (for example, where the Customer is a consultant or managed service provider using CertAssist for its own client), CertAssist is a sub-processor, and the Customer warrants that it has the authority of the relevant controller to engage CertAssist on these terms.
CertAssist processes Personal Data only as a Processor on behalf of the Customer, and does not sell Personal Data or use it for its own independent purposes.
4.1 Instructions. CertAssist will process Personal Data only on the Customer's documented instructions, including with regard to international transfers, unless required to do otherwise by law that applies to CertAssist. The Agreement, this DPA, and the Customer's use and configuration of the Services constitute the Customer's complete and documented instructions. CertAssist will inform the Customer if, in its opinion, an instruction infringes Data Protection Law, unless legally prohibited from doing so.
4.2 Details of processing. The subject matter, duration, nature and purpose of the processing, the types of Personal Data, and the categories of Data Subjects are set out in Annex A.
4.3 Customer responsibilities. The Customer is responsible for the accuracy, quality and lawfulness of the Personal Data it provides to the Services, for having a valid legal basis for the processing, and for the manner in which it acquired the Personal Data. The Customer will not provide CertAssist with Personal Data where it is not permitted to do so.
4.4 Confidentiality. CertAssist ensures that persons authorized to process Personal Data are bound by an appropriate duty of confidentiality and are trained in their data protection obligations.
CertAssist implements and maintains appropriate technical and organizational measures to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access, as described in Annex B. CertAssist regularly reviews and, where appropriate, improves these measures, provided that any change does not materially reduce the overall level of security of the Services.
6.1 Authorization. The Customer provides general authorization for CertAssist to engage the Sub-processors listed in Annex C (also published at certassist.io/subprocessors.html) to process Personal Data in connection with the Services.
6.2 Obligations. CertAssist enters into a written contract with each Sub-processor imposing data protection obligations that are, in substance, no less protective than those in this DPA. CertAssist remains responsible for the acts and omissions of its Sub-processors to the same extent it would be responsible if performing the services directly.
6.3 Changes. CertAssist maintains an up to date list of Sub-processors and will give the Customer reasonable prior notice of the addition or replacement of a Sub-processor by updating that list. If the Customer reasonably objects to a new Sub-processor on data protection grounds, the parties will work in good faith to resolve the concern, and if it cannot be resolved, the Customer may terminate the affected Services.
CertAssist hosts customer workspace data (assessments, evidence, documents and user accounts) in Google Cloud data centers located in Australia (the australia-southeast1 region, Sydney). Where a Sub-processor processes Personal Data outside the country in which the Customer or its Data Subjects are located, CertAssist ensures that an appropriate transfer mechanism is in place, such as the Standard Contractual Clauses, a valid adequacy decision, or an equivalent safeguard recognized under Data Protection Law.
CertAssist will notify the Customer without undue delay, and where feasible within 72 hours, after becoming aware of a Personal Data Breach affecting the Customer's Personal Data. The notification will describe, to the extent known, the nature of the breach, the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed to address it. CertAssist will cooperate reasonably with the Customer to support the Customer's own obligations, including under the Australian Notifiable Data Breaches scheme and Articles 33 and 34 of the GDPR. A notification is not an acknowledgment of fault or liability.
Taking into account the nature of the processing and the information available to it, CertAssist will provide reasonable assistance to the Customer to:
The Services provide the Customer with tools to export and delete Personal Data at any time during the term. On termination or expiry of the Agreement, CertAssist will, at the Customer's choice, delete or return the Personal Data it processes on the Customer's behalf, and delete existing copies, within 90 days, unless retention is required by law. Routine backups are overwritten on their normal cycle in the ordinary course of operations.
CertAssist will make available to the Customer information reasonably necessary to demonstrate compliance with this DPA. On reasonable prior written notice, and no more than once in any 12 month period (unless required by a regulator or following a Personal Data Breach), the Customer may audit CertAssist's compliance, or appoint a mutually agreed independent auditor to do so, during business hours and in a manner that does not disrupt CertAssist's operations or compromise the security or confidentiality of other customers' data. Where available, CertAssist may satisfy an audit request by providing relevant certifications or third party audit reports.
Each party's liability under or in connection with this DPA is subject to the exclusions and limitations of liability set out in the Agreement.
This DPA takes effect on the earlier of the Customer's acceptance of the Agreement or the signing of this DPA, and continues for as long as CertAssist processes Personal Data on the Customer's behalf. This DPA is governed by the laws of Queensland, Australia, and the parties submit to the non exclusive jurisdiction of the courts of that state, without prejudice to any mandatory rights a Data Subject or regulator may have under Data Protection Law. In the event of any conflict, this DPA prevails over the Agreement in respect of the processing of Personal Data.
Subject matter: CertAssist's provision of the Services to the Customer under the Agreement.
Duration: For the term of the Agreement, plus any period during which Personal Data is retained in accordance with Section 10.
Nature and purpose: Hosting and processing of the Customer's compliance and certification workspace, including creating and managing assessments, storing evidence and documents, managing user accounts and access, sending service and authentication emails, and processing subscription billing, in each case to provide, secure, support and operate the Services.
Types of Personal Data: Names, business email addresses, user account and role information, authentication data, activity and audit records, billing contact and address details, and any Personal Data the Customer or its users choose to include in assessments, evidence files, documents or free text fields.
Categories of Data Subjects: The Customer's personnel and authorized users (administrators, staff, clients and auditors), the Customer's own clients where the Customer uses the Services on their behalf, and any individuals whose Personal Data appears in content the Customer uploads.
Sensitive data: The Services are not intended for special category or sensitive Personal Data. The Customer is responsible for not uploading such data except where it has a lawful basis and appropriate safeguards.
CertAssist maintains the following measures, which may be updated from time to time provided the overall level of protection is not materially reduced:
The current list of Sub-processors is published at certassist.io/subprocessors.html.