Data Processing Agreement

Last updated: April 2026

Introduction

This Data Processing Agreement governs the processing of personal data by CHISTY DIGITAL FORGE (ABN 25864140160) trading as ProposalVault on behalf of our customers. It forms part of the agreement between ProposalVault ("Processor") and the customer ("Controller") who uses the ProposalVault service.

This DPA sets out the terms under which the Processor processes personal data on behalf of the Controller in connection with the ProposalVault service. It is incorporated into and subject to the ProposalVault Terms of Service and Privacy Policy.

1. Definitions

  • Data Controller — the customer entity that determines the purposes and means of processing personal data (the organisation using ProposalVault).
  • Data Processor — ProposalVault (Chisty Digital Forge), which processes personal data on behalf of the Controller.
  • Personal Data — any information relating to an identified or identifiable natural person, as defined under applicable privacy law including the Australian Privacy Act 1988 (Cth) and the EU General Data Protection Regulation (GDPR).
  • Processing — any operation performed on personal data, including collection, storage, use, disclosure, and deletion.
  • Sub-processor — any third party engaged by the Processor to carry out Processing activities on behalf of the Controller.

2. Scope and Purpose of Processing

ProposalVault processes personal data on behalf of the Controller solely for the purpose of providing the ProposalVault service, including:

  • AI-powered answer generation from uploaded documents
  • Document storage, indexing, and semantic search (vector embeddings)
  • Knowledge base management and retrieval
  • Project management and collaboration features
  • User authentication and account management

3. Details of Processing

Types of Personal Data

  • Business contact details (name, email address, company name)
  • Content of uploaded documents (which may contain personal data)
  • Security questionnaire questions and answers
  • Account details, session records, social identity identifiers, and one-way password hashes
  • Usage metadata (pages visited, features used, timestamps, and rate-limit identifiers)

Categories of Data Subjects

  • Employees of the Controller organisation using ProposalVault
  • End users and contacts whose information appears in uploaded documents
  • Third parties referenced in questionnaire responses

Duration of Processing

Personal data is processed for the duration of the Controller's use of the Service and thereafter as necessary to process verified deletion requests, meet legal obligations, prevent fraud, resolve disputes, or comply with applicable provider backup-retention schedules.

4. Processor Obligations

The Processor agrees to:

  • Process personal data only on documented instructions from the Controller (as set out in this DPA and the Terms of Service), unless required to do so by law.
  • Ensure that persons authorised to process the personal data are bound by confidentiality obligations.
  • Implement appropriate technical and organisational security measures (see Section 6).
  • Assist the Controller in responding to requests from data subjects exercising their rights under applicable privacy law.
  • Delete or return all personal data to the Controller upon termination, at the Controller's choice, unless retention is required by law.
  • Make available reasonable information about its processing practices, subject to the Processor's confidentiality, security, and legal obligations.
  • Notify the Controller of any Sub-processor additions or changes prior to engagement.

5. Sub-processors

The Controller authorises the Processor to engage the following Sub-processors. The Processor will notify the Controller of any intended changes, and the Controller may object within 14 days.

Sub-processorPurpose
NeonDatabase hosting
BrevoTransactional email delivery
VercelHosting & edge functions
OpenAIText embeddings
GroqAI inference
StripePayment processing

6. Security Measures

The Processor implements the following technical and organisational measures to protect personal data:

Encryption

  • Encrypted connections for data in transit
  • Encryption at rest provided by applicable infrastructure providers

Access Controls

  • Application-level role-based access control (Viewer, Editor, and Admin)
  • Application-level workspace scoping and role-based access control
  • Access to customer data restricted to authorised personnel only

Monitoring & Logging

  • Activity logging for selected project mutations
  • Security headers and infrastructure monitoring where available

7. Data Breach Notification

In the event of a personal data breach, the Processor will:

  • Notify the Controller without undue delay where notification is required by applicable law or the parties' contractual commitments.
  • Provide sufficient information to enable the Controller to meet its own notification obligations to supervisory authorities and affected data subjects.
  • Include in the notification: the nature of the breach, categories and approximate number of data subjects and records concerned, likely consequences, and measures taken or proposed to address the breach.

8. Data Subject Rights

The Processor will assist the Controller in fulfilling its obligations to respond to data subject requests under applicable privacy law, including requests to:

  • Access personal data held about them
  • Correct inaccurate personal data
  • Delete personal data ("right to erasure" / "right to be forgotten")
  • Restrict or object to processing
  • Receive personal data in a portable format

To submit a data subject request, contact us at support@proposalvault.cloud. We will review and respond to requests in accordance with applicable law.

9. International Data Transfers

Some Sub-processors are located in the United States. Data transfers to the US are made in accordance with applicable data transfer mechanisms, including reliance on Sub-processors' Standard Contractual Clauses (SCCs) or equivalent frameworks.

10. Data Deletion and Return

Upon termination of the Controller's account or upon written request, the Processor will, at the Controller's choice:

  • Delete all personal data processed on behalf of the Controller; or
  • Provide available export options or reasonable assistance with return, where technically feasible.

Deletion requests are verified before data is removed from active systems. Legal, accounting, fraud-prevention, and dispute records may be retained where required. Backup copies expire according to the applicable infrastructure provider's retention schedule.

11. Audit Rights

The Controller may, upon 30 days' prior written notice, request an audit of the Processor's processing activities to verify compliance with this DPA. Audits will be conducted during normal business hours and at the Controller's expense. The Processor may require the Controller to sign a non-disclosure agreement prior to the audit.

12. Governing Law

This DPA is governed by the laws of New South Wales, Australia, and the Commonwealth of Australia, including the Privacy Act 1988 (Cth) and the Australian Privacy Principles. You agree to submit to the exclusive jurisdiction of the courts of New South Wales.

Where the Controller is located in the European Union or European Economic Area, this DPA also incorporates the requirements of the EU General Data Protection Regulation (GDPR).

13. Contact

For questions about this Data Processing Agreement or to submit data subject requests, contact:

Chisty Digital Forge (ABN: 25864140160), trading as ProposalVault

Email: support@proposalvault.cloud