1. Scope and application
This Data Processing Addendum (DPA) is between Proe Ai Pty Ltd (ABN 55 696 128 631) (Proe) and the Customer identified in the agreement for PROE (Customer). It applies when Proe processes Personal Information contained in Customer Data to provide the service.
This DPA begins when the agreement begins and continues while Proe processes that Personal Information. If this DPA conflicts with the Terms on a data-protection matter, this DPA prevails. A signed agreement prevails only where it expressly identifies the provision it overrides.
2. Definitions
- Applicable Data Protection Law
- The Privacy Act 1988 (Cth), the Australian Privacy Principles, the Notifiable Data Breaches scheme and any other privacy or data-protection law that applies to a party's processing under the agreement.
- Customer Data
- Data submitted to, stored in, transmitted through or made available to PROE by or for Customer and all customer-specific content and artefacts generated from that information or to deliver Customer's configured features. It includes connected communications, attachments, CRM records, contacts, calendar data, knowledge files, prompts, outputs, summaries, classifications, priority signals, embeddings, retrieval indexes, account-specific profiles and any customer-specific fine-tuned model or other model artefact.
- Personal Information
- Information or an opinion about an identified individual or an individual who is reasonably identifiable, and any equivalent concept under Applicable Data Protection Law.
- Service Data
- Content-free technical and operational information generated through use of PROE, such as device and app details, timestamps, feature events, job metadata, performance, crash and security signals. It excludes Customer content, customer-specific outputs and information derived from either. Technical or operational information that contains or derives from Customer Data remains Customer Data.
- Security Incident
- Confirmed unauthorised access to, acquisition, use, alteration, disclosure, loss or destruction of Personal Information processed by Proe under this DPA. It excludes unsuccessful attempts that do not compromise Personal Information.
- Subprocessor
- A third party appointed by Proe to process Personal Information in Customer Data on Proe's behalf.
3. Roles and compliance
Customer determines the purposes for which Customer Data is collected and used. Proe processes Personal Information in Customer Data on Customer's behalf and documented instructions. “Controller” and “processor” have the corresponding meanings where those concepts apply; they do not replace the terminology of Australian privacy law.
Each party will comply with the obligations that Applicable Data Protection Law assigns to it. Proe remains independently responsible for Personal Information it collects for its own account administration, security, billing and direct business relationship with Customer, as explained in the Privacy Policy.
4. Customer instructions and permitted processing
Customer instructs Proe to process Customer Data to:
- provide the features described in the agreement and Customer's configuration;
- personalise and improve those features for Customer's account or organisation;
- secure, monitor, maintain, troubleshoot and support the service;
- perform connected-provider and subprocessor operations necessary for the service;
- comply with Customer's lawful documented instructions; and
- comply with law, in which case Proe will notify Customer before processing unless legally prohibited.
Proe will not use Customer Data to train, fine-tune, evaluate, benchmark or otherwise improve a model, dataset, algorithm or feature serving another customer, or for cross-customer analytics, benchmarks, research, market intelligence, advertising or sale. Except for the expressly authorised processing above, Proe will not disclose Customer Data to data brokers or process it for an unrelated independent purpose.
Proe will promptly inform Customer if, in its reasonable opinion, an instruction infringes Applicable Data Protection Law and may pause the affected processing while the parties resolve it.
5. Customer obligations
Customer represents that it has provided required notices and has a lawful basis, authority and any required consent to collect Customer Data, connect provider accounts, instruct Proe's processing and make Personal Information available to Proe and the listed Subprocessors.
Customer is responsible for the accuracy and lawfulness of its instructions, configuring access for authorised users, handling requests from individuals for whom Customer is responsible, and not submitting sensitive information unless reasonably necessary and lawfully permitted.
6. Confidentiality and personnel
Proe will ensure that personnel authorised to process Customer Data are bound by confidentiality obligations, receive access only where needed for their role and are informed of applicable security and privacy responsibilities. Personnel access to Customer content is not routine and is limited to authorised support, security, recovery, operational or legal needs. Access is subject to logging and review.
7. Security measures
Proe will maintain reasonable technical and organisational measures appropriate to the nature of Customer Data and the risks of processing. Current measures are summarised in Schedule 2 and the Security Centre.
Proe may update security measures as technology and the service evolve, provided the overall protection of Customer Data is not materially reduced during a current paid term. Customer acknowledges that no system can guarantee absolute security.
8. Subprocessors
Customer gives Proe general authorisation to use the Subprocessors in Schedule 3 only for the specified purposes needed to operate the service. Proe will require each Subprocessor to protect Personal Information through contractual or other binding terms appropriate to the services it provides and restrict its use of Customer Data to the contracted service. Proe remains responsible for its obligations under this DPA. AI providers must not use Customer Data to train or improve their models.
Proe will maintain a current Subprocessor list and give reasonable prior notice of a material new Subprocessor that will process Customer content, normally at least 15 days where practicable. Customer may object during that period on reasonable, documented data-protection grounds. The parties will work in good faith on a commercially reasonable solution. If none is available, either party may terminate the materially affected feature or service without penalty beyond fees accrued before termination.
9. Processing locations and overseas recipients
Customer authorises processing in the locations listed in Schedule 3. Proe's primary production database, authentication, file storage, application compute and private queue infrastructure are hosted in Australia. Approved providers may process limited data in the United States, European Union or global infrastructure.
Where APP 8 applies, each party will take the reasonable steps required of it in relation to overseas disclosures. If another Applicable Data Protection Law requires an additional transfer mechanism, the parties will cooperate in good faith to put that mechanism in place before the affected restricted transfer.
10. AI providers and data-use restrictions
Proe may submit only relevant Customer Data to approved AI API providers to perform classification, priority, extraction, summarisation and draft generation for Customer. Proe uses commercial business/API offerings under terms that do not permit provider training on or model improvement from Proe API inputs or outputs.
Neither Proe nor an AI provider may use Customer Data to train, fine-tune, evaluate, benchmark or improve a public, foundation, private or proprietary model, dataset, algorithm or feature serving another customer. If Proe creates an embedding, retrieval index, account-specific profile, customer-specific fine-tuned model or other model artefact, it remains Customer Data and may be used only for that Customer's account or organisation.
Standard provider safety and abuse-monitoring processes may retain submitted inputs and outputs for up to 30 days unless a zero-data-retention arrangement or shorter period applies. OpenAI requests explicitly disable application-state storage where supported.
11. Individual rights and regulatory assistance
Taking into account the nature of processing, Proe will provide reasonable assistance for Customer to respond to an individual's access, correction, deletion or other lawful request relating to Customer Data. If Proe receives such a request directly and can identify Customer as the responsible organisation, Proe will direct the requester to Customer and will not respond substantively unless authorised or legally required.
Proe will provide reasonable information needed for Customer's privacy impact assessment, regulator consultation or compliance inquiry concerning the service. Material assistance beyond standard documentation or normal support may be subject to reasonable fees where permitted by law and agreed in advance.
12. Security Incidents
Proe will notify Customer without undue delay and no later than 72 hours after determining that a Security Incident has affected, or is reasonably likely to affect, Customer Data. The initial notice may be preliminary and will include known information reasonably useful to Customer, such as the nature of the incident, affected data or systems, containment, likely consequences and recommended action.
Proe will investigate, contain, mitigate and remediate the incident; preserve appropriate evidence; provide material updates; and reasonably assist Customer to assess notification duties. Proe's notice is not an admission of fault. Customer is responsible for notifications it is legally required to make as the organisation controlling the affected information, with Proe's reasonable assistance.
Security notices to Proe must be sent to alex@proe.ai.
13. Return, export and deletion
On written request made before termination or during the 30 days following it, Proe will make a reasonable export of Customer Data available in a commonly used machine-readable format, subject to security verification and technical feasibility.
Proe retains raw AI prompts, model responses and diagnostic traces for no more than 30 days. User-visible outputs and customer-specific learning needed to provide the configured service may be retained while the account is active and remain subject to this DPA.
Proe will delete Customer Data from active systems within 30 days after termination or Customer's valid deletion instruction, unless law requires retention. On request, Proe will provide written confirmation of active-system deletion. Deleted data may remain temporarily in protected rolling provider backups until it ages out under normal backup lifecycles; while retained it remains protected by this DPA and will not be restored except for disaster recovery.
14. Information and audit
Proe will make information reasonably necessary to demonstrate compliance available through the Security Centre, current security documentation and, on request, the full security pack. Customer may submit one reasonable security questionnaire each year and additional questions following a material Security Incident or material service change.
If that information is insufficient and Applicable Data Protection Law requires further verification, Customer may request a proportionate audit on at least 20 business days' notice. Audits must protect other Customers and Proe Confidential Information, avoid production disruption, use an independent qualified auditor where appropriate and occur during normal business hours. Customer bears its audit costs unless the audit identifies a material breach by Proe.
15. Legally compelled disclosure
If Proe receives a legally binding request for Customer Data from a government or authority, it will review the request, disclose only what is legally required and notify Customer before disclosure where legally permitted. Proe will reasonably challenge an unlawful or overbroad request where there are grounds to do so.
16. Liability and term
The liability limitations and exclusions in the agreement apply to this DPA to the maximum extent permitted by law. This DPA terminates when Proe no longer processes Personal Information in Customer Data, except that obligations concerning confidentiality, deletion and retained backup data continue for as long as relevant information remains.
Schedule 1 — Processing details
| Subject matter | Provision of the PROE communication, mailbox, messaging, calendar, CRM and AI-assisted service. |
|---|---|
| Duration | The agreement term plus the export and deletion period described in section 13. |
| Nature and purpose | Collection from authorised connected services; hosting; encryption; organisation; search; synchronisation; classification; priority ranking; extraction; summarisation; drafting; customer-specific personalisation; user-directed sending and provider actions; configured CRM and calendar workflows; support; security; export and deletion. |
| People concerned | Customer personnel and users; vendors, buyers, landlords, tenants, prospects, solicitors, tradespeople and other correspondents or CRM contacts whose information appears in Customer Data. |
| Data categories | Identity and contact details; communications and attachments; mailbox and calendar metadata; property and listing context; CRM records and notes; provider account identifiers; user instructions; knowledge files; prompts; AI-assisted outputs; summaries; classifications; priority signals; account-specific profiles; authentication, device, diagnostic and operational metadata. |
| Sensitive information | Not intentionally required as a distinct category, but may appear incidentally in communications or files connected by Customer. |
Schedule 2 — Security measures
- Governance: CTO accountability, documented security policies, data classification and periodic risk review.
- Access: named personnel access, least privilege, access logging and review, administrative MFA where supported, periodic and change-triggered access review, and prompt offboarding.
- Tenant isolation: organisation-scoped server authorisation and RLS on direct client-access paths.
- Encryption: HTTPS/TLS in transit, managed platform encryption at rest for stored Customer Data, and AES-256-GCM application-layer encryption for selected credentials and secret fields. Application-layer encryption is not represented as applying to every Customer Data field.
- Secrets: platform secret stores, company password manager, no deliberate logging of tokens, keys or message bodies.
- Development: version control, dependency lockfiles, CI type checking and linting, automated tests, attributable releases and rollback capability.
- Infrastructure: managed cloud platforms, private worker/queue networking and restricted production database network access.
- Monitoring: application errors, authorisation failures, job failures, health events and selected domain traces in restricted provider tooling, with raw AI prompts, model responses and diagnostic traces limited to 30 days.
- Incident response: documented severity, containment, evidence, communication, recovery and post-incident process.
- Personnel and devices: confidentiality, acceptable-use requirements, full-disk encryption, supported software, automatic updates, firewall and screen lock.
- Subprocessors: review of purpose, data, location, security terms and permitted use before material processing changes.
- Recovery and deletion: managed-provider backup and recovery capabilities, export support, active-system deletion and protected backup ageing.
Schedule 3 — Current Subprocessors
The following providers may process Personal Information depending on the features Customer enables. Provider-specific details are maintained in Proe's internal Subprocessor Register and full security pack.
| Provider | Purpose | Data | Location |
|---|---|---|---|
| Supabase, Inc. | Primary database, authentication, file storage and realtime services | Customer content, attachments, account and organisation records, encrypted credentials and AI outputs | Australia |
| Fly.io, Inc. | Application, API, background worker and private job-queue hosting | Customer Data processed transiently; operational job metadata | Australia |
| Google LLC | Gmail, Google Calendar, Pub/Sub and connected-account operations | Google mailbox, calendar and account data as authorised by the Customer | Global provider infrastructure |
| Microsoft Corporation | Outlook and Microsoft Graph connected-account operations | Microsoft mailbox, calendar and account data as authorised by the Customer | Global provider infrastructure |
| Unipile | WhatsApp account connection, synchronisation, sending and webhooks | WhatsApp content, participant identifiers and media metadata | European/global provider infrastructure |
| Reapit Ltd / Agentbox | Customer-authorised CRM lookup, contact workflows and activity notes | CRM contact details, property references and activity-note content | Australia |
| OpenAI, L.L.C. | AI classification, priority, extraction, summarisation and draft generation | Relevant Customer Data submitted for API inference | United States |
| Anthropic PBC | Optional AI classification and draft generation | Relevant message and thread context submitted for API inference | United States |
| PostHog, Inc. | Content-free product analytics, error diagnostics and session replay | Account identifier, agent email, device and operational usage events; no Customer content or customer-specific outputs | United States |
| Expo / 650 Industries, Inc., Apple and Google | Mobile push-notification delivery | Push token, generic notification count/title and in-app route | Global provider infrastructure |
| Vercel, Inc. | Public website and web application asset hosting | Public-site enquiries and web request metadata; no agent mailbox data | Global provider infrastructure |
| Resend / Plus Five Five, Inc. | Delivery of public book-a-demo enquiries to Proe | Demo requester name, phone number, optional email address and source page; no agent mailbox data | United States |
Book demo