Data Processing Agreement

DATA PROCESSING AGREEMENT

Made Neat Pty Ltd

Effective Date: 1 October 2025

Last Updated: 3 November 2025

1. INTRODUCTION

This Data Processing Agreement (“DPA”) forms part of the terms of service between Made Neat Pty Ltd (“Made Neat”, “we”, “us”, or “our”) and our clients (“you”, “your”, or “Client”) concerning the processing of personal data in connection with our services.

Made Neat provides professional web design, hosting, security, and maintenance services to business clients. In the course of providing these services, we collect and process certain personal information from our clients as necessary to deliver our services.

1.1 Controller Details

Legal Name: Made Neat Pty Ltd

ABN: 54 619 331 252

Address: 7/10 Thomas Street, Noosaville QLD 4566, Australia

Email: [email protected]

Phone: +61 7 5370 2032

2. DEFINITIONS

For the purposes of this DPA, the following terms shall have the meanings set out below:

  1. “Data Controller” means Made Neat Pty Ltd, which determines the purposes and means of the processing of Personal Data.
  2. “Data Subject” means the identified or identifiable natural person to whom Personal Data relates, including our clients and their authorised representatives.
  3. “Personal Data” means any information relating to an identified or identifiable natural person, including but not limited to names, email addresses, phone numbers, and business addresses.
  4. “Processing” means any operation performed on Personal Data, including collection, recording, organisation, storage, use, disclosure, and erasure.
  5. “Sub-processor” means any third-party service provider engaged by Made Neat to process Personal Data on our behalf.
  6. “Data Protection Laws” means all applicable laws and regulations relating to the processing of Personal Data, including the Australian Privacy Act 1988 (Cth), the EU General Data Protection Regulation (GDPR), and the UK Data Protection Act 2018.

3. SCOPE AND PURPOSE OF PROCESSING

3.1 Nature and Purpose

We process Personal Data for the following purposes:

  • To communicate with clients regarding project management, support requests, and service delivery
  • To provide invoicing and payment processing services
  • To send important updates about our services, security alerts, and maintenance notifications
  • To maintain business records and financial reporting in compliance with legal obligations
  • To fulfil all obligations expected of a professional service provider

3.2 Categories of Data Subjects

We process Personal Data relating to the following categories of Data Subjects:

  • Business clients who engage our services
  • Authorised representatives and employees of our business clients
  • Prospective clients who enquire about our services

3.3 Categories of Personal Data

We process the following categories of Personal Data:

  • Full name
  • Email address
  • Contact telephone numbers (mobile and landline)
  • Business postal address
  • Payment and invoicing information

3.4 Duration of Processing

We process Personal Data for the duration of our client relationship and retain this data indefinitely in our financial systems (Xero) as required for financial reporting and legal compliance. Data in our project management systems is retained whilst we are working with clients and may be retained thereafter unless deletion is specifically requested.

4. DATA PROCESSING PRINCIPLES

Made Neat commits to processing Personal Data in accordance with the following principles:

  1. Lawfulness, fairness, and transparency: We process Personal Data lawfully, fairly, and in a transparent manner.
  2. Purpose limitation: We collect Personal Data for specified, explicit, and legitimate purposes only.
  3. Data minimisation: We collect only the Personal Data that is adequate, relevant, and limited to what is necessary for the purposes for which it is processed.
  4. Accuracy: We take reasonable steps to ensure that Personal Data is accurate and kept up to date.
  5. Storage limitation: We retain Personal Data only for as long as necessary for the purposes for which it was collected, or as required by law.
  6. Integrity and confidentiality: We process Personal Data securely using appropriate technical and organisational measures.

5. INTERNATIONAL DATA TRANSFERS

5.1 Transfer Locations

Our servers are located in Australia (via Vultr). However, we use various third-party services (Sub-processors) that may involve the transfer of Personal Data to countries outside Australia, the European Union, and the United Kingdom, including the United States.

5.2 Transfer Safeguards

Where Personal Data is transferred internationally, we ensure that such transfers are protected by appropriate safeguards, including:

  • European Commission’s Standard Contractual Clauses (SCCs) for transfers from the EU/EEA
  • UK International Data Transfer Agreement or Addendum for transfers from the UK
  • Adequacy decisions where applicable
  • Binding Corporate Rules implemented by our Sub-processors where applicable

5.3 Standard Contractual Clauses

We incorporate the European Commission’s Standard Contractual Clauses (Module One: Controller to Controller) into our data processing arrangements. These clauses are available at: https://commission.europa.eu/publications/standard-contractual-clauses-controllers_en

6. SUB-PROCESSORS

6.1 Authorised Sub-processors

Made Neat engages the following Sub-processors to assist in providing our services. All Sub-processors are bound by data protection obligations consistent with this DPA:

Sub-processor

Purpose

Location

Xero

Accounting and financial management

New Zealand (data centres in multiple regions)

Teamwork

Project management and collaboration

Ireland/United States

Google LLC

Website analytics (Google Analytics, Tag Manager, Ads)

United States (data centres worldwide)

Meta Platforms (Facebook)

Marketing and advertising (Facebook Ads)

United States (data centres worldwide)

Prospect WP

CRM and lead management

United States

Mailchimp (Intuit)

Email marketing and communications

United States

Stripe

Payment processing

United States (data centres worldwide)

PayPal

Payment processing

United States

GoCardless

Payment processing

United Kingdom

BetterProposals

Proposal creation and management

United States

Hotjar

Website user experience analytics

Malta/European Union

Vultr

Server hosting infrastructure

Australia (Sydney data centre)

Note: The locations listed indicate the primary headquarters or data centre locations of each Sub-processor. Some Sub-processors may process data across multiple global regions.

6.2 Changes to Sub-processors

We reserve the right to add, remove, or replace Sub-processors as necessary to provide our services. We will update this DPA and notify clients of any material changes to our Sub-processors through our website or via email where appropriate.

If you object to the appointment of a new Sub-processor, you may terminate our services upon written notice within 30 days of being notified of the change.

6.3 Sub-processor Obligations

We ensure that all Sub-processors are subject to data protection obligations that are substantially similar to those in this DPA, including appropriate technical and organisational security measures and international transfer safeguards where applicable.

7. TECHNICAL AND ORGANISATIONAL MEASURES

Made Neat implements appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:

7.1 Technical Measures

  • Encryption: SSL/TLS encryption for data in transit via secure HTTPS connections
  • Access Control: VPN-only access to servers with SSH authentication and user-level permission controls
  • Backups: Regular automated backups stored both locally and remotely to ensure data resilience
  • Network Security: Firewalls and intrusion detection systems to prevent unauthorised access
  • System Monitoring: Continuous monitoring for security threats and vulnerabilities

7.2 Organisational Measures

  • Staff Training: Regular training for team members on data protection and security practices
  • Access Restrictions: Limited access to Personal Data on a need-to-know basis
  • Confidentiality: Confidentiality obligations imposed on all personnel with access to Personal Data
  • Incident Response: Documented procedures for responding to data breaches and security incidents
  • Regular Reviews: Periodic review and updating of security measures

8. DATA SUBJECT RIGHTS

We respect the rights of Data Subjects and will assist with requests to exercise the following rights:

  1. Right of Access: Data Subjects have the right to obtain confirmation of whether we process their Personal Data and to access such data.
  2. Right to Rectification: Data Subjects may request correction of inaccurate Personal Data.
  3. Right to Erasure: Data Subjects may request deletion of their Personal Data, subject to our legal obligations to retain certain information for financial reporting purposes.
  4. Right to Restriction: Data Subjects may request restriction of processing in certain circumstances.
  5. Right to Data Portability: Where technically feasible, Data Subjects may request their Personal Data in a structured, commonly used, and machine-readable format.
  6. Right to Object: Data Subjects may object to processing based on legitimate interests or for direct marketing purposes.
  7. Right to Withdraw Consent: Where processing is based on consent, Data Subjects may withdraw consent at any time.

To exercise these rights, Data Subjects should contact us at [email protected]. We will respond to requests within the timeframes required by applicable Data Protection Laws (generally within 30 days).

9. DATA BREACH NOTIFICATION

In the event of a Personal Data breach, Made Neat will:

  1. Notify affected clients without undue delay, and where feasible, within 72 hours of becoming aware of the breach
  2. Provide information about the nature of the breach, the categories and approximate number of Data Subjects affected, and the likely consequences
  3. Describe the measures taken or proposed to address the breach and mitigate its potential adverse effects
  4. Cooperate with clients to fulfil any obligations they may have to notify Data Subjects or supervisory authorities

10. DATA RETENTION AND DELETION

10.1 Retention Periods

We retain Personal Data as follows:

  • Financial Systems (Xero): Personal Data is retained indefinitely as required for financial reporting, tax compliance, and audit purposes in accordance with Australian taxation laws.
  • Project Management Systems (Teamwork): Personal Data is retained whilst we are working with clients and may be retained thereafter for business reporting purposes. Data can be deleted from these systems upon client request.

10.2 Deletion Requests

Clients may request deletion of their Personal Data from our project management systems by contacting [email protected]. Please note that we cannot delete data from our financial systems (Xero) where retention is legally required, but we can restrict processing of such data where appropriate.

11. COOPERATION AND AUDITS

Made Neat will:

  • Provide reasonable assistance to clients in responding to Data Subject requests
  • Cooperate with clients and supervisory authorities in relation to Data Protection Law compliance
  • Upon reasonable notice and subject to confidentiality obligations, make available to clients information necessary to demonstrate compliance with this DPA

12. LIABILITY AND INDEMNIFICATION

Made Neat shall be liable for damages caused by processing that violates applicable Data Protection Laws where Made Neat has not complied with its obligations under this DPA or has acted outside of or contrary to lawful instructions.

Each party shall indemnify the other against claims, losses, and damages arising from that party’s breach of this DPA or applicable Data Protection Laws, except to the extent caused by the other party’s breach or negligence.

13. TERM AND TERMINATION

13.1 Term

This DPA remains in effect for the duration of our service relationship with clients and continues until all Personal Data has been deleted or returned in accordance with this DPA.

13.2 Effect of Termination

Upon termination of our services, we will continue to process Personal Data only to the extent necessary to comply with legal obligations (such as tax and financial reporting requirements). Clients may request deletion of data from non-essential systems as described in Section 10.

14. GOVERNING LAW AND DISPUTES

This DPA shall be governed by and construed in accordance with the laws of Queensland, Australia. Any disputes arising from this DPA shall be subject to the exclusive jurisdiction of the courts of Queensland, Australia.

For matters relating to GDPR or UK Data Protection Laws, the parties acknowledge the jurisdiction of the relevant EU or UK supervisory authorities and courts as may be required under those laws.

15. CONTACT INFORMATION

For questions, concerns, or requests relating to this DPA or our data processing practices, please contact us:

Made Neat Pty Ltd

7/10 Thomas Street, Noosaville QLD 4566, Australia

Email: [email protected]

Phone: +61 7 5370 2032

16. UPDATES TO THIS AGREEMENT

We may update this DPA from time to time to reflect changes in our data processing practices, Sub-processors, or legal requirements. We will notify clients of material changes by updating the “Last Updated” date at the top of this document and, where appropriate, via email or through our website.

Continued use of our services following notification of changes constitutes acceptance of the updated DPA.

ACCEPTANCE

This Data Processing Agreement is accepted and entered into by Made Neat Pty Ltd as of the Effective Date stated above.

Made Neat Pty Ltd

ABN: 54 619 331 252

Apply Now

If we sound like a good fit then we would love to hear from you.

"*" indicates required fields

This field is for validation purposes and should be left unchanged.
Name*
Agree to Privacy Policy*