Data Processing Addendum
How Workshop Software processes End Customer personal information on behalf of its customers
Effective date: 8 November 2026
About this Addendum
This Data Processing Addendum (DPA) forms part of the Subscription Agreement between Workshop Software Pty Ltd (Workshop Software, we, us) and the Customer (you). It applies whenever we process personal information on your behalf in providing the Service, which in practice means the information you record about your End Customers, staff and other individuals (End Customer Data, as defined in the Subscription Agreement).
It is written to meet the requirements of the Privacy Act 1988 (Cth) and the Australian Privacy Principles, Article 28 of the EU GDPR and UK GDPR, the Privacy Act 2020 (NZ), and the “service provider” and “processor” requirements of US state privacy laws. Capitalised terms not defined here have the meaning given in the Subscription Agreement.
Where the GDPR or UK GDPR applies to your processing of End Customer Data, the transfer terms in clause 8 and Annex 3 also apply. Otherwise this DPA applies without Annex 3.
1. Roles
1.1 Sub-processor means a third party we engage to process End Customer Data on our behalf in providing the Service. For End Customer Data, you are the entity that collects and controls the information (the controller, or where you process it for another business, a processor) and we are your processor (or sub-processor). You determine the purposes and means of processing; we process only on your documented instructions.
1.2 For Account Data and Usage Data, we act as an APP entity and controller in our own right, as described in the Privacy Policy, and this DPA does not apply to that information. However, to the extent Usage Data, application logs or diagnostic data contain End Customer Data, this DPA applies to that End Customer Data.
1.3 You are responsible for: (a) the lawfulness of your collection of End Customer Data; (b) giving End Customers the privacy notices required by the laws that apply to you, including notice of any AI Features you use; (c) the accuracy of the instructions you give us; and (d) responding to requests and complaints from End Customers, with our help under clause 6.
2. Details of processing
2.1 The subject matter, duration, nature and purpose of the processing, the types of personal information and the categories of individuals are described in Annex 1.
2.2 Your instructions to us are: this DPA, the Subscription Agreement, your configuration of and actions within the Service (for example sending a message, connecting an integration or activating an AI Feature), and any other written instruction you give that is consistent with the Subscription Agreement. We will tell you if we believe an instruction breaches Privacy Laws, and may suspend processing under that instruction until it is resolved.
3. Our obligations as processor
3.1 We will:
- process End Customer Data only on your documented instructions, including with regard to transfers to another country, unless required to do otherwise by law, in which case we will tell you before processing (unless the law prohibits it);
- ensure that our personnel who access End Customer Data are bound by written confidentiality obligations and are informed of their responsibilities under this DPA;
- implement and maintain the technical and organisational security measures described in Annex 2, and take the reasonable steps required by APP 11 to protect the information from misuse, interference, loss and unauthorised access, modification or disclosure;
- engage sub-processors only in accordance with clause 5;
- help you respond to requests from individuals under clause 6;
- help you meet your obligations regarding security, breach notification, privacy impact assessments and consultation with regulators, taking into account the nature of the processing and the information available to us;
- delete or return End Customer Data at the end of the Subscription Agreement in accordance with clause 10;
- make available to you the information reasonably necessary to demonstrate our compliance with this DPA, and allow and contribute to audits under clause 7; and
- not sell End Customer Data, share it for cross-context behavioural advertising, retain, use or disclose it outside the direct business relationship with you or for any purpose other than providing the Service, or combine it with personal information from other sources, except as permitted by the Subscription Agreement (including clause 7 on de-identified and aggregated data) and applicable law.
3.2 De-identified and Aggregated Data. Clause 7 of the Subscription Agreement is your documented instruction to us to create De-identified Data and Aggregated Data from End Customer Data, and we do so as your processor in accordance with clause 7.3. Once data has been de-identified in accordance with that clause it is no longer End Customer Data or personal information, this DPA does not apply to it, and we hold and use it in our own right. We will not attempt to re-identify it and will apply the safeguards in clause 7.3 of the Subscription Agreement.
3.3 US state privacy laws. Where a US state privacy law treats us as your service provider, processor or contractor, then in addition to clause 3.1 we will: (a) notify you without undue delay if we determine that we can no longer meet our obligations under that law; (b) on reasonable notice, allow you to take reasonable and appropriate steps to stop and remediate any unauthorised use of End Customer Data; and (c) provide the same level of privacy protection as that law requires of you, for the specific business purposes described in Annex 1.
4. AI Features
4.1 If you use an AI Feature, End Customer Data needed for the task is disclosed to an AI Provider listed in Annex 4 as a Sub-processor. Our contract with each AI Provider requires it to process the data only as described in clause 3.3 of the AI Features Addendum, to keep it confidential, to delete it within the period stated in that clause and not to use it to train or improve its models. For End Customer Data to which the GDPR or UK GDPR applies, that contract includes data processing terms incorporating the EU Standard Contractual Clauses and the UK Addendum.
4.2 We do not use End Customer Data to train our own AI models. We may use De-identified Data and Aggregated Data for that purpose as clause 3.2 and clause 7 of the Subscription Agreement describe.
4.3 The AI Features Addendum sets out further terms, including your responsibility to review outputs and to give End Customers any notice required by law.
5. Sub-processors
5.1 You give us general authorisation to engage the sub-processors listed in Annex 4, and to engage additional or replacement sub-processors in accordance with this clause.
5.2 We will give you at least 30 days’ notice before a new sub-processor begins processing End Customer Data, by email to your Account email address or by notice in the Service, and will keep the published sub-processor list referred to in Annex 4 current. Where a replacement is urgently needed to maintain the security or continuity of the Service, we may engage the replacement immediately and notify you within 5 Business Days, and your objection right under clause 5.3 runs from that notice. This does not apply to End Customer Data covered by Annex 3, for which the advance notice period in Annex 3 applies in every case.
5.3 If you have a reasonable objection relating to data protection, you must tell us within 14 days of our notice. We will work with you in good faith to address it. If we cannot, you may terminate the affected part of the Service, or the Subscription Agreement, and we will refund any Fees prepaid for the period after termination.
5.4 We will impose on each sub-processor written obligations that protect End Customer Data to a standard no less protective than this DPA, and we remain responsible to you for each Sub-processor’s compliance with the data protection obligations in this DPA.
5.5 Payment processors. The payment processors listed in Annex 4 are Sub-processors when they process End Customer Data to complete payments taken through the Service. Each processor also uses some payment, transaction and device information for its own purposes, such as preventing fraud across its network, assessing risk, improving its services and meeting its legal and regulatory obligations. For those purposes it acts as an independent controller under its own terms and privacy policy, not as our Sub-processor, and clauses 5.2 to 5.4 do not apply to that use. The privacy notices you give End Customers under clause 1.3(b) should cover payment processing where the law requires it.
6. Requests from individuals
6.1 The Service includes features that let you view, correct, export and delete End Customer records yourself. You should use these to respond to most requests from End Customers.
6.2 If we receive a request directly from an End Customer we will not respond substantively (other than to direct them to you) and will pass the request to you within 5 Business Days, unless the law requires us to respond directly.
6.3 Where you need our help to respond to a request or complaint, we will provide reasonable assistance. We may charge a reasonable fee for assistance that goes beyond the features of the Service, which we will agree with you first.
7. Audits and information
7.1 On written request, no more than once in any 12 month period (or more often if required by a regulator or following a data breach affecting your data), we will provide you with the information reasonably necessary to demonstrate compliance with this DPA, which may include a description of the measures in Annex 2, our security documentation and our written responses to a reasonable security questionnaire.
7.2 If that information is not sufficient to satisfy a requirement of Privacy Laws that applies to you, you (or an independent auditor you appoint who is bound by confidentiality and is not our competitor) may audit our relevant systems and records on at least 30 days’ notice (or such shorter notice as a supervisory authority or regulator requires, or as is reasonable following a Data Breach affecting your End Customer Data), during business hours, no more than once a year (or more often where required by a regulator or following a Data Breach affecting your End Customer Data), in a way that does not unreasonably disrupt our business or compromise other customers’ data. You bear the costs of the audit, including our reasonable costs of assisting, unless the audit reveals a material breach of this DPA by us.
8. International transfers
8.1 End Customer Data is stored by the cloud infrastructure Sub-processor listed in Annex 4 in the region shown in Annex 1 for your market. Regardless of that region, emails sent from the Service are delivered from Australia (for Australian and New Zealand customers) or the United States (for all other customers), SMS messages sent from the Service are delivered from Australia for all customers, application logs that may contain End Customer Data are processed in Australia, our cloud operations support Sub-processor accesses it from Australia, the AI Provider listed in Annex 4 processes data in the United States, and the payment processors listed in Annex 4 process data in the countries shown for them in Annex 4. Where the GDPR or UK GDPR applies to your End Customer Data, each of these is a restricted transfer covered by Annex 3.
8.2 For Australian customers, we will take reasonable steps under APP 8 before disclosing End Customer Data to an overseas recipient to ensure it does not breach the APPs, including by contract.
8.3 For New Zealand customers, we will only disclose End Customer Data outside New Zealand where Information Privacy Principle 12 permits, including where the recipient is contractually bound to protect it to a comparable standard.
8.4 Where the GDPR or UK GDPR applies to your End Customer Data, transfers of that data to Workshop Software in Australia and to sub-processors outside the UK or EEA are made under the transfer terms in Annex 3: the EU Standard Contractual Clauses (Module 2, controller to processor, or Module 3 where you are a processor) for EEA data, and the UK Addendum to those clauses (or, at our election, the UK International Data Transfer Agreement) for UK data. We will carry out and document a transfer risk assessment and apply supplementary measures where needed.
8.5 For US customers, we act as your service provider or processor and this DPA is the written contract required by applicable state privacy laws.
9. Data breach notification
9.1 If we become aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to End Customer Data (Data Breach), we will notify you without undue delay, and in any case within 72 hours after becoming aware of it, which means having a reasonable degree of certainty that a Data Breach has occurred. Our first notice may be limited to the information then available, including what we know about the nature of the breach, the data and individuals affected, the likely consequences and the steps we have taken or propose, and we will update you as we learn more. Unsuccessful attempts to access our systems, and events that do not compromise End Customer Data, are not Data Breaches. A notice under this clause is not an admission of fault or liability.
9.2 We will take reasonable steps to contain and remediate the Data Breach and will cooperate with you on any notification you decide to make to individuals or regulators. Where the Data Breach also triggers our own obligations under the Notifiable Data Breaches scheme, we will coordinate our notification with yours so that individuals are not notified twice unnecessarily.
9.3 Neither party will name the other in a public statement or regulatory notification about a Data Breach without first consulting the other, except where the law requires otherwise.
10. Return and deletion
10.1 Clause 13 of the Subscription Agreement governs what happens to End Customer Data when the Subscription Agreement ends: after a paid subscription we may hold it for up to 12 months so that you can reactivate, and we delete or irreversibly de-identify it no later than the end of that period (or within 30 days after an unconverted free trial ends), or within 30 days of your earlier written request, subject to legal retention obligations and to the archival backup copies described in clause 13.3 of the Subscription Agreement and Annex 2. On request we will confirm deletion in writing.
10.2 Return of End Customer Data. If the GDPR or UK GDPR applies to you, we will hold your End Customer Data for at least 30 days after the Subscription Agreement ends so that you can choose between its return and its deletion. During that period, or any longer period in which we still hold it, you may ask us in writing to return a copy of your End Customer Data in a commonly used, machine-readable format before it is deleted, and we may charge a reasonable fee for preparing the export, which we will tell you before doing the work, except where clause 13.1 of the Subscription Agreement or its Schedule 1 provides the export at no charge. Exporting your data through the Service before your subscription ends is free and is the recommended course.
11. Liability and general
11.1 Each party’s liability under this DPA is subject to the exclusions and limitations in the Subscription Agreement, except to the extent the law or Annex 3 does not permit those limitations to apply.
11.2 If there is a conflict between this DPA and the Subscription Agreement about the processing of End Customer Data, this DPA prevails. If there is a conflict between this DPA and Annex 3, Annex 3 prevails for the data it covers.
11.3 This DPA continues for as long as we hold End Customer Data.
Annex 1: Details of processing
| Item | Description |
|---|---|
| Subject matter | Provision of the Workshop Software workshop management Service to the Customer, including hosting, support, messaging, payments, integrations, reporting and AI Features. |
| Duration | The term of the Subscription Agreement plus up to 12 months afterwards for a paid subscription (at least 30 days where clause 10.2 applies), or 30 days after an unconverted free trial ends, subject to earlier deletion on request. Archival backup copies in the Australian region may persist beyond that period as Annex 2 and clause 13.3 of the Subscription Agreement describe; they are kept beyond use and deleted at the end of the archive cycle. |
| Nature and purpose | Storage, organisation, retrieval, display, transmission (including sending messages the Customer chooses to send and sharing with Third Party Services the Customer connects), backup, analysis for the Customer’s reporting, and processing by AI Features the Customer activates; creation of De-identified and Aggregated Data under clause 7 of the Subscription Agreement. |
| Categories of individuals | The Customer’s End Customers (vehicle owners, fleet operators and their drivers, and their authorised contacts); the Customer’s employees, contractors and Users; suppliers and other business contacts the Customer records. |
| Types of personal information | Name, contact details, business name, address; vehicle registration, VIN and vehicle details; job, quote, invoice and payment records; messages exchanged with the Customer; notes, images and files recorded against a job. Sensitive information is not required by the Service and should not be recorded unless the Customer has a lawful basis. |
| Hosting region | Australia for customers in Australia and New Zealand; United States for customers in the United States and the rest of the world; European Union for customers in the United Kingdom and Europe. Backups are kept in the same region and are not replicated to another region. |
| Other processing locations | Email delivery: Australia (Australian and New Zealand customers) or United States (all other customers). SMS delivery: Australia (all customers). Application logs: Australia. AI Provider: United States. Payment processors: as shown in Annex 4. Cloud operations support: Australia. |
Annex 2: Technical and organisational security measures
We maintain the following measures. We hold no third-party security certifications and none are claimed.
- Encryption of data in transit (TLS 1.2 minimum).
- Logical separation of each customer’s data within the Service. Identifiers returned through our partner APIs are masked using a key unique to each Customer and reversed only inside our own infrastructure, so that an identifier held by a partner cannot be used against our systems or correlated between Customers.
- Role-based access control for Users, configured by the Customer, with unique logins and optional two-factor authentication. Passwords are never stored in readable form.
- Access to production systems restricted to authorised personnel on a need-to-know basis, with multi-factor authentication and logging of administrative access.
- Application and infrastructure monitoring, alerting and logging. Personal data is removed from application logs before indexing for customers hosted in our European region.
- Daily backups retained for 30 days, kept in the same region as the data and not replicated to another region. In the Australian region, additional weekly, monthly and annual backup copies are retained for disaster recovery for up to seven years.
- Code review of changes before release and quarterly third-party vulnerability scanning.
- Each AI Feature sends an AI Provider only the fields defined as permitted for that feature.
- Staff confidentiality obligations and an internal policy governing staff use of public generative AI tools.
- Documented incident response plan.
- Business continuity and disaster recovery arrangements, documented in a runbook, using the resilience features of our cloud infrastructure provider.
Annex 3: Transfer terms for UK and EEA customers
3.1 EEA data. The Standard Contractual Clauses approved by European Commission Decision 2021/914 (EU SCCs) are incorporated by reference. Module 2 applies where you are a controller; Module 3 applies where you are a processor. Clause 7 (docking) is included. Clause 9(a) Option 2 (general authorisation) applies with the notice period in clause 5.2 of this DPA. Clause 11 optional language is not included. Clause 13: where you are established in an EEA member state, the supervisory authority of that state is competent; where you are not established in the EEA but have appointed a representative under Article 27 of the GDPR, the supervisory authority of the member state in which the representative is established; otherwise, the supervisory authority of the member state in which the data subjects whose personal data is transferred are located. Clause 17 (Option 1): the law of Ireland governs. Clause 18: the courts of Ireland. Annex I.A to the EU SCCs (list of parties) is completed as follows: data exporter: you, with the name, address and contact details recorded in your Account and Order, acting as controller (Module 2) or processor (Module 3); data importer: Workshop Software Pty Ltd, ABN 72 165 417 916, Suite 2305, 4 Daydream Street, Warriewood NSW 2102, Australia, support@workshopsoftware.com, acting as processor. Each party’s acceptance of the Subscription Agreement is its signature of the EU SCCs and this Annex. Annex I.B is completed by Annex 1 and Annex 4 of this DPA; Annex I.C by the Clause 13 statement above; Annex II by Annex 2.
3.2 UK data. The International Data Transfer Addendum to the EU SCCs issued by the UK Information Commissioner under s 119A of the Data Protection Act 2018 (UK Addendum) is incorporated by reference and applies to the EU SCCs as set out in 3.1. Table 1 is completed with the parties’ details in the Subscription Agreement; Table 2 with the modules and options in 3.1; Table 3 with Annexes 1, 2 and 4 of this DPA; Table 4: either party may end the UK Addendum as set out in section 19 of it. We may instead elect to use the UK International Data Transfer Agreement, in which case we will tell you and complete it with the same information.
3.3 If the EU SCCs or UK Addendum are replaced or amended by the relevant authority, the parties will adopt the replacement, and this Annex will be read as referring to it.
3.4 To the extent the EU SCCs or UK Addendum conflict with this DPA or the Subscription Agreement, they prevail for the data they cover.
Annex 4: Sub-processors
The sub-processors that process End Customer Data, as at the date of this DPA, are listed below. The current list is published at https://workshopsoftware.com/legal/sub-processors/ and is updated in accordance with clause 5. Our CRM, billing and support tools hold Account Data and our correspondence with Customers and are described in the Privacy Policy. They are not used to store End Customer records and are not engaged as Sub-processors of End Customer Data. Where correspondence a Customer sends us incidentally includes End Customer Data, the provider of the relevant tool processes that data only for the purpose of storing, displaying and enabling us to manage that correspondence and, to that extent only, is a Sub-processor; those providers are identified on the published list. Customers can avoid that processing by not including End Customer Data in correspondence with us. Third Party Services that the Customer chooses to connect are not our sub-processors; they receive data on the Customer’s instruction and under their own terms.
| Sub-processor | What it does | Country of processing |
|---|---|---|
| Amazon Web Services | Cloud hosting, storage, backup and infrastructure for the Service | Australia, European Union or United States, by customer region (Annex 1) |
| Amazon Web Services (Simple Email Service) | Delivery of emails the Customer sends to End Customers from the Service | Australia for Australian and New Zealand customers; United States for all other customers, including the United Kingdom, Ireland and Europe |
| Anthropic | AI Provider for AI Features, and AI-assisted support and diagnostic tools used by our staff. For AI Features, receives the Input and returns an Output, as described in the AI Features Addendum. In both uses, contractually prohibited from training on the data and required to delete it within 30 days, subject to the exceptions in clause 3.3 of that Addendum | United States |
| Datadog | Application monitoring, logging and diagnostics. Logs may contain End Customer Data | Australia (Sydney region). Datadog, Inc. is a United States company |
| Thoughtworks | Cloud operations and engineering support. Personnel may access production systems containing End Customer Data | Australia |
| Stripe | Card payment processing and fraud screening for payments taken through the Service | United States and other countries where Stripe operates, including India |
| Nuvei (formerly Till Payments) | Card payment processing for payments taken through the Service | Australia and United States |
| Celero (formerly TransNational Payments) | Card payment processing for payments taken through the Service | United States |
| Westpac | Card payment processing for payments taken through the Service, for Customers who use the Westpac integration | Australia |
| SMSGlobal | Delivery of SMS messages the Customer sends to End Customers | Australia, for all customers |
If the published list and this Annex differ, the published list is current. Last updated: 8 November 2026.