Data Processing Agreement

Version 4 · Last updated: July 19, 2026

1. Parties and Definitions

This Data Processing Agreement ("DPA") forms part of the agreement between TrackMyPlace (the "Processor") and the agency customer that subscribes to the TrackMyPlace platform (the "Controller") and applies to the Processor's handling of Personal Information on the Controller's behalf.

  • Personal Information has the meaning given in the Privacy Act 1988 (Cth) and includes the buyer, seller and prospect data the Controller imports into TrackMyPlace.
  • APPs means the Australian Privacy Principles in Schedule 1 to the Privacy Act 1988 (Cth).
  • Sub-processor means a third party engaged by TrackMyPlace to process Personal Information on the Controller's behalf (see Section 4).
  • Notifiable Data Breach or NDB has the meaning given in Part IIIC of the Privacy Act 1988 (Cth).

2. Scope of Processing

The Processor handles Personal Information solely to provide the TrackMyPlace platform to the Controller and its authorised users. Processing is described below:

  • Categories of data subjects: Controller's buyers, sellers, prospects, tenants, and agency staff invited as team members.
  • Categories of Personal Information: contact details, property addresses, campaign notes, document metadata, communications (email/SMS), and any additional fields the Controller chooses to record.
  • Purposes: hosting the campaign pipeline, delivering communications, surfacing analytics, and providing the Controller-enabled integrations described in our Privacy Policy.
  • Duration: for the term of the Controller's subscription, plus the deletion / return window in Section 9.

3. Processor Obligations

The Processor will:

  • Process Personal Information only on documented instructions from the Controller (the subscription agreement, the platform configuration, and any written request the Controller submits to privacy@trackmyplace.com).
  • Ensure personnel authorised to access Personal Information are bound by appropriate confidentiality undertakings.
  • Implement the security measures described in Section 7.
  • Assist the Controller in responding to data-subject requests and regulator queries to the extent reasonably possible given the nature of the processing.

4. Sub-processors

The Controller authorises the Processor to engage the sub-processors listed below to deliver the platform. The authoritative list of sub-processors, including data categories and country of processing, lives in our Privacy Policy (Section 7) and is reproduced here for convenience.

Sub-processorPurposeCountry of processing
SupabaseAuthentication, primary database (Postgres), file storage.Australia (Sydney, ap-southeast-2)
VercelApplication hosting, edge/serverless execution.US
StripeSubscription billing and payment processing.US / Ireland
XeroAccounting ledger for TrackMyPlace's own billing records (invoices, payments, refunds).US
TwilioSMS delivery to clients you contact through TrackMyPlace.US
ResendTransactional email delivery.US / EU
Google (Workspace APIs)Gmail, Calendar, Contacts and Drive integrations (opt-in per user).US
Google Maps PlatformAddress geocoding and Places autocomplete.US
Microsoft (Graph)Outlook email integration (opt-in per user).US / EU
VaultRE (MRI Software)CRM integration - property, listing and contact lookup (opt-in per team).Australia
SlackTeam messaging integration (opt-in per team).US
AnthropicOptional AI features (assistant, message drafting, summaries, text analysis) and the weekly agency digest narrative. Disabled by default at the platform level; only request text is sent - never client email/phone, document files, or images.US
SentryApplication error and performance monitoring.US / Germany
LinearEngineering issue tracking for in-app feedback submissions.US
UpstashRedis-backed rate limiting and short-lived caching, and the background-job queue (QStash) that runs deferred work such as email and SMS delivery; job payloads may transiently include a recipient email address in transit.US

5. Sub-processor Change Notice

The Processor will give the Controller at least 30 days' notice before engaging a new sub-processor or replacing an existing one. The Controller may object on reasonable data-protection grounds within that period. If the parties cannot agree on a resolution, the Controller may terminate the affected service and receive a pro-rata refund of any pre-paid fees that cover the remainder of the subscription term.

6. Data Subject Rights Co-operation

The Processor will provide the Controller with self-service tools (data export, deletion, agent-level revocation of integrations) sufficient to satisfy data-subject access, correction, and deletion requests under APP 12 and APP 13. Where a request cannot be fulfilled through the self-service tools, the Processor will assist the Controller on a best-efforts basis within 5 business days.

7. Notifiable Data Breach Co-operation

The Processor will notify the Controller as soon as practicable, and in any event within 72 hours, of becoming aware of an eligible data breach (as defined in Part IIIC of the Privacy Act 1988 (Cth)) affecting the Controller's Personal Information.

Notifications will be sent to:

  • The team owner's registered email address; and
  • Any additional NDB contact recorded by the Controller in Settings → Compliance.

The Processor will provide the information the Controller reasonably needs to fulfil its own notification obligations to the Office of the Australian Information Commissioner (OAIC) and affected data subjects.

8. Security Measures

The Processor maintains the following controls:

  • Encryption in transit: TLS 1.2 or higher for all client and sub-processor traffic.
  • Encryption at rest: Supabase platform-managed encryption for primary data; AES-256 for OAuth tokens stored in the database.
  • Access control: Postgres row-level security on Personal Information tables (including a restrictive tenant-isolation policy on the high-blast-radius PII tables), least-privilege staff access, and per-team administrator gating for sensitive operations.
  • Application monitoring: Sentry error and performance telemetry with a PII scrubber applied before persistence.
  • Backups: daily encrypted backups of the primary database, retained per Supabase's platform policy.

9. Audit Rights

On reasonable written notice and no more than once per calendar year, the Controller may request either:

  • A copy of the Processor's most recent third-party attestation (SOC 2 Type II or equivalent), where available; or
  • An on-site audit, conducted during business hours, by the Controller (or an independent third-party auditor mutually agreed by the parties) at the Controller's expense.

The parties will agree on the audit scope in writing in advance and will conduct the audit in a way that does not unreasonably disrupt the Processor's services to other customers.

10. Data Return and Deletion on Termination

On termination of the Controller's subscription, the Processor will:

  • Make the Controller's Personal Information available for export in a machine-readable format (JSON or XLSX, via Settings → Data Export) for 30 days after termination; and
  • Delete the Controller's Personal Information from active systems within 30 days after the export window closes, and from backups within the next backup-retention cycle, except where retention is required by law.

11. Liability and Indemnity

Liability under this DPA is subject to, and aggregated with, the liability cap in the agreement between the parties governing the Controller's subscription to the TrackMyPlace platform (which, for most agency customers, is our published Terms of Service). Nothing in this DPA limits:

  • The non-excludable rights and remedies the Controller has under the Australian Consumer Law (Schedule 2 of the Competition and Consumer Act 2010 (Cth));
  • Either party's liability for fraud, wilful misconduct, or unauthorised disclosure of Personal Information; or
  • The Processor's direct statutory obligations under the Privacy Act 1988 (Cth).

12. Acceptance

The Controller may countersign this DPA either at signup or, at any time after signup, by clicking Accept DPA in Settings → Compliance. The acceptance is recorded against the team and is binding on behalf of the agency. Re-acceptance is required whenever TrackMyPlace publishes a new version of this document.

13. Contact

Questions about this DPA, requests for the countersigned PDF, or NDB-related notifications: privacy@trackmyplace.com.

Back to sign in

Data Processing Agreement | TrackMyPlace