Data Processing Addendum

Effective: 6 July 2026

Forms part of your ALLWISE Service Agreement or Terms of Service.

1. Definitions

  • "Personal Information" has the meaning given in s.7 of the Privacy Act 2020.
  • "Processing" has the meaning given in s.7 of the Privacy Act 2020 (and includes collection, storage, use, disclosure, and deletion).
  • "Customer Data" means the Personal Information you upload or generate through ALLWISE in the course of providing your own services to your customers.
  • "Sub-processor" means any third party engaged by ALLWISE to Process Customer Data.
  • "DPA" means this Data Processing Addendum.

2. Roles

You ("Customer") are the agency in respect of Customer Data. ALLWISE Solutions Limited ("ALLWISE") acts as your service provider. ALLWISE will only Process Customer Data on your documented instructions, as set out in this DPA and the Service Agreement.

3. Scope of Processing

ALLWISE will Process Customer Data only to:

  • Provide the ALLWISE platform and its features to you
  • Store and retrieve assessment records, photos, and reports
  • Generate AI-assisted compliance verdicts using Google Gemini
  • Send transactional emails (welcome, expiry reminders, share links)
  • Process subscription payments via Stripe
  • Provide support and troubleshooting when you contact us

4. Sub-processors

ALLWISE engages the following Sub-processors. We will notify you at least 30 days in advance of adding or replacing any Sub-processor, giving you the opportunity to object on reasonable grounds.

Sub-processorPurposeLocation
Supabase Inc.Database, auth, file storageSydney, Australia
Vercel Inc.Application hosting, edge computeGlobal edge
Google LLC (Gemini)AI compliance evaluationUnited States
Stripe Inc.Payment processingUnited States
Resend Inc.Transactional email deliveryUnited States
Functional Software Inc. (Sentry)Error monitoringUnited States
Upstash Inc.Rate limitingUnited States

5. Security Measures

ALLWISE implements appropriate technical and organisational measures to protect Customer Data against unauthorised or unlawful Processing, accidental loss, destruction, or damage. These include:

  • TLS 1.3 encryption in transit; AES-256 encryption at rest (Supabase)
  • Row-Level Security (RLS) policies on every table containing Customer Data
  • Server-side input validation and HTML sanitisation on all user content
  • Rate limiting and CSRF protection on every API endpoint
  • Distributed rate limiting via Upstash Redis
  • Admin audit log of every PII access (NZ Privacy Act IPP 6 compliance)
  • Per-IP throttling on authentication, registration, and pack purchases

6. Your Rights and Our Obligations

Where Customer Data includes Personal Information of your customers (e.g. tenants), you may direct us to:

  • Delete specific Customer Data (subject to legal retention obligations)
  • Export Customer Data in a machine-readable format
  • Restrict Processing of specific Customer Data

We will action your written instructions within 20 working days, except where retention is required by law (financial records, active tenancy disputes, etc.).

7. Breach Notification

In the event of a notifiable privacy breach affecting Customer Data, ALLWISE will:

  • Notify you within 24 hours of becoming aware of the breach
  • Notify the Office of the Privacy Commissioner and affected individuals within 72 hours where required by s.115 of the Privacy Act 2020
  • Provide a full incident report within 5 working days, including root cause, scope, and remediation steps

8. Cross-border Transfers

Customer Data may be transferred to and Processed in Australia (Supabase) and the United States (other Sub-processors). By entering into this DPA, you consent to these transfers. ALLWISE relies on each Sub-processor's participation in recognised cross-border privacy frameworks where available.

9. Termination

On termination of your Service Agreement, ALLWISE will, at your option, return or delete Customer Data within 30 days, subject to legal retention obligations and standard backup deletion cycles (90 days).

10. Contact

To request a countersigned copy of this DPA, or to raise any data-protection concern, contact:

Allwise Solutions Limited — Privacy Officer
NZBN: [NZBN: TO UPDATE]
17 East Street, Petone, Lower Hutt, Wellington, 5012
Email: privacy@allwise.co.nz
Phone: +64 21 024 16717