Version 1.0 · Last updated · 1 September 2026

Data Processing Addendum

This Data Processing Addendum (DPA) forms part of the agreement between Incentrix Operations Pty Ltd, ACN 699 994 922 (Incentrix, we, our or us) and the Customer under our Platform Terms of Use (the Agreement), where data protection law requires a written processing agreement or where the Customer has requested one under section 15.4 of the Agreement.

1. Definitions

In this DPA: Data Protection Laws means the data protection and privacy laws that apply to a party's processing of Personal Data under the Agreement, which may include the Privacy Act 1988 (Cth) and the Australian Privacy Principles, the EU General Data Protection Regulation 2016/679 (GDPR), the UK GDPR, and applicable United States State privacy laws. Personal Data means any personal data or personal information (as defined in applicable Data Protection Laws) contained in Customer Data. Controller, Processor, Data Subject, Processing and Personal Data Breach have the meanings given in applicable Data Protection Laws, or their nearest equivalents. Capitalised terms not defined here have the meanings given in the Agreement.

2. Roles and scope

2.1 The Customer is the Controller (or, where the Customer acts for its own clients, a Processor acting on their behalf) of Personal Data in Customer Data. Incentrix is the Customer's Processor (or sub-processor, as applicable).

2.2 This DPA applies to Processing of Personal Data by Incentrix on the Customer's behalf in the course of providing the platform. The subject matter, duration, nature and purpose of Processing, and the categories of Personal Data and Data Subjects, are set out in Annex A.

2.3 Workspace connections. Where Customer Data is shared with another workspace through a Connection under section 5 of the Agreement, Incentrix Processes that data on the instructions of the Sharing Workspace, and the Receiving Organisation Processes the data it receives as an independent Controller in its own right.

3. Processing on instructions

3.1 Incentrix will Process Personal Data only on the Customer's documented instructions, which are: the Agreement, this DPA, the Customer's configuration and use of the platform (including Sharing Scopes it accepts), and any other written instructions agreed between the parties — unless required to do otherwise by law, in which case Incentrix will inform the Customer of that legal requirement before Processing, where the law permits.

3.2 Incentrix will promptly inform the Customer if, in its opinion, an instruction infringes Data Protection Laws.

4. Personnel

4.1 Incentrix will ensure that personnel authorised to Process Personal Data are bound by confidentiality obligations, and will limit access to personnel who need it to provide the platform. Staff access uses single sign-on with multi-factor authentication; there is no standing administrative access to Customer Data, and emergency access is just-in-time and logged.

5. Security

5.1 Incentrix will implement and maintain the technical and organisational measures described in Annex B, and will not materially reduce the overall security of the platform during the Customer's Subscription Term.

6. Sub-processors

6.1 The Customer authorises Incentrix to engage the sub-processors listed at incentrix.io/subprocessors, and to engage new sub-processors in accordance with this section.

6.2 Before a new sub-processor begins Processing Personal Data, Incentrix will update that page and notify the Customer at least 30 days in advance. The Customer may object on reasonable data-protection grounds within that period. If the parties cannot resolve the objection, the Customer may terminate the affected Order on notice and Incentrix will refund unused prepaid fees for the terminated period.

6.3 Incentrix will impose data protection obligations on each sub-processor that are no less protective than those in this DPA, and remains responsible for each sub-processor's performance.

7. Assistance

7.1 Data subject requests. Taking into account the nature of the Processing, Incentrix will assist the Customer by appropriate technical and organisational measures, insofar as possible, to respond to requests from Data Subjects exercising their rights (access, correction, deletion, portability, restriction or objection). If Incentrix receives such a request directly, it will refer the requester to the Customer and will not respond on the Customer's behalf except on the Customer's instruction or as required by law.

7.2 Compliance assistance. Incentrix will provide reasonable assistance to the Customer with data protection impact assessments, consultations with supervisory authorities, and the Customer's own security and breach-notification obligations, taking into account the nature of the Processing and the information available to Incentrix.

8. Personal Data Breach

8.1 If Incentrix becomes aware of a Personal Data Breach affecting Personal Data, it will notify the Customer without undue delay, and in any event within 72 hours of confirming the breach. The notification will describe, to the extent known: the nature of the breach, the categories and approximate volumes of Personal Data and Data Subjects affected, the likely consequences, and the measures taken or proposed to address it.

8.2 Incentrix will cooperate with the Customer on remediation and on any notifications the Customer must make under Data Protection Laws. Incentrix's notification of a breach is not an admission of fault or liability.

9. International transfers

9.1 Personal Data is stored in the hosting region stated on our Security page, and may be accessed by Incentrix personnel and sub-processors in other countries as described at incentrix.io/subprocessors.

9.2 Where Personal Data is transferred out of a jurisdiction whose Data Protection Laws restrict international transfers, the parties will rely on a lawful transfer mechanism, including: an adequacy decision where one applies; the European Commission's Standard Contractual Clauses (Module 2: controller to processor), which are incorporated into this DPA by reference where the GDPR applies to the transfer; and the UK International Data Transfer Addendum where the UK GDPR applies. To the extent of any conflict between those clauses and this DPA, the clauses prevail for the transfer they govern.

10. Return and deletion

10.1 For 30 days after expiry or termination of the Agreement, Incentrix will make Customer Data available for export in a structured, commonly used, machine-readable format on request, as set out in section 13.6 of the Agreement.

10.2 After that period, Incentrix will delete Personal Data within 30 days, except where law requires retention or data persists in routine backups, which expire on a rolling 35-day schedule — meaning deleted data is removed from all backup copies within 35 days of primary deletion.

11. Audit

11.1 Incentrix will make available the information reasonably necessary to demonstrate compliance with this DPA, including its Security page, this DPA, its sub-processor list, and available third-party audit reports or certifications as they are obtained. Incentrix will respond to the Customer's reasonable written security questionnaires at no charge, no more than once per 12-month period.

11.2 Where Data Protection Laws give the Customer a right to audit that the material in clause 11.1 does not satisfy, the Customer may conduct an audit (by itself or an independent auditor that is not a competitor of Incentrix) on at least 30 days' written notice, during business hours, no more than once per 12-month period, at the Customer's cost, and subject to the confidentiality obligations in the Agreement.

12. Liability, precedence and duration

12.1 Each party's liability under or in connection with this DPA is subject to the exclusions and caps in section 19 of the Agreement.

12.2 This DPA takes effect when the parties execute it, or when the Agreement incorporates it, and continues for as long as Incentrix Processes Personal Data on the Customer's behalf. To the extent of any inconsistency about the Processing of Personal Data, this DPA prevails over the Agreement, and the Standard Contractual Clauses prevail over this DPA for the transfers they govern.

12.3 This DPA is governed by the same law, and subject to the same dispute-resolution provisions, as the Agreement.

Annex A — Details of Processing

  • Subject matter. Provision of the Incentrix platform: incentive discovery, eligibility pre-screening, analysis and reporting for managed service providers and technology partners.
  • Duration. The term of the Agreement, plus the export and deletion periods in section 10 of this DPA.
  • Nature and purpose. Hosting, storage, analysis (including AI-assisted document analysis), display, transmission to connected workspaces at the Customer's direction, and backup.
  • Categories of Data Subjects. The Customer's Authorised Users and billing contacts; the Customer's own personnel and client contacts appearing in uploaded documents or connected data sources.
  • Categories of Personal Data. Names, business email addresses, job titles and business contact details; user identifiers and usage records; personal data incidentally contained in uploaded documents (such as agreements and statements of work) or retrieved from connected services (such as Microsoft Partner Center) at the Customer's direction. The platform is not designed for, and the Customer must not submit, special categories of personal data.

Annex B — Technical and organisational measures

  • Hosting. Microsoft Azure, in the region stated on our Security page.
  • Encryption. TLS 1.2+ in transit; AES-256 at rest across database, file storage and backups.
  • Access control. Least-privilege access enforced down to the database credential; the customer application's database login cannot read administrative tables; staff sign in with Microsoft Entra ID SSO with MFA; no standing administrative access — emergency access is just-in-time and logged.
  • Tenant isolation. Logical separation scoped to each organisation, enforced on every query; dedicated single-tenant deployments available.
  • Availability and backups. Zone-redundant database high availability; file storage soft-delete; backups retained on a rolling 35-day window.
  • AI processing. Document analysis runs on Azure OpenAI within Azure; content is not used to train models and is held transiently (up to 30 days) for abuse monitoring only.
  • Logging. Audit and security logs retained on a 35-day rolling window, covering the deletion window to evidence deletions.

Contact

To execute this DPA, or for privacy questions, contact privacy@incentrix.io.