1.1 This agreement forms part of the Admin Tea Terms of Service between Admin Tea Pty Ltd ("we", "us") and the Customer ("you"). Words defined in the Terms have the same meaning here.
1.2 It applies to personal information in Customer Data ("Customer Personal Information"). If it conflicts with the Terms on anything about personal information, this agreement prevails.
1.3 "Privacy Law" means the Privacy Act 1988 (Cth), including the Australian Privacy Principles (APPs), the Privacy (Tax File Number) Rule 2015 and the Notifiable Data Breaches scheme, and any other Australian law about personal information that applies to a party.
2.1 You collect Customer Personal Information and decide the purposes for which it is handled. We handle it on your behalf to provide the Service.
2.2 Your instructions to us are: the Terms; this agreement; your choice of features and settings in the Service; and any other reasonable written instruction you give us that is consistent with them. If we believe an instruction would breach the law, we will tell you and need not follow it.
2.3 We are also an organisation bound by Privacy Law in our own right. Nothing in this agreement requires either party to breach Privacy Law.
You are responsible for:
We will:
5.1 We will take reasonable steps to protect Customer Personal Information from misuse, interference and loss, and from unauthorised access, modification and disclosure. This includes at least the measures in Schedule 1.
5.2 We may update our security measures, but will not reduce the overall level of protection they provide.
5.3 You are responsible for the security of your own devices and networks, for your Authorised Users' sign-in details, and for configuring access within your account appropriately.
6.1 You authorise us to use the service providers listed in Schedule 2 to help provide the Service.
6.2 Each provider is bound by written terms that require it to protect the information and use it only to provide its service. We remain responsible to you for their performance of our obligations under this agreement.
6.3 Before a new provider starts handling Customer Personal Information, we will update Schedule 2 and give you at least 30 days' notice by email. If you reasonably object on privacy or security grounds, tell us within that period. We will try to address your concern. If we cannot, you may end the agreement without penalty and receive a refund of any Fees paid in advance for the period after it ends.
6.4 We may replace a provider without notice if urgently needed for security or continuity of the Service. We will then notify you as soon as practicable, and section 6.3 applies from that notice.
6.5 Services you choose to connect, such as Xero, and government systems you lodge with through the Service, such as the Australian Taxation Office and the National Disability Insurance Agency, are not our service providers. Information is sent to them on your instruction and their own terms apply.
7.1 We store Customer Personal Information, including backups, in Australia, in Google Cloud's Sydney region, run our server code in that region, and send email through SMTP2GO's Sydney data centre. Operational server logs are held in Google Cloud Logging for 30 days in a store that is not limited to one region. They may contain internal identifiers, email addresses, IP addresses and error details, and we design and check them so they do not contain tax file numbers, bank or super details, pay amounts, case notes or message content.
7.2 Some providers in Schedule 2 handle limited information outside Australia, as described there. We will not move storage of Customer Personal Information outside Australia without notice under section 6.3.
7.3 Where we disclose Customer Personal Information outside Australia, we take reasonable steps to ensure the recipient does not breach the APPs in relation to it.
8.1 We will tell you without undue delay, and in any case within 72 hours of becoming aware, of any unauthorised access to, disclosure of, or loss of Customer Personal Information held by us or our service providers.
8.2 We will give you the information we have about what happened, the kinds of information and the individuals likely affected, and the steps taken, and update you as we learn more.
8.3 We will promptly take reasonable steps to contain the breach and reduce the risk of harm, and cooperate with you in assessing whether it is an eligible data breach under the Notifiable Data Breaches scheme.
8.4 Where a breach affects both of us, we will agree with you who prepares any statement to the Office of the Australian Information Commissioner and who notifies affected individuals, so that notification is timely and consistent. The Privacy Act allows one notification to satisfy both parties. Where the breach affects tax file numbers or payroll information, we will also report it to the Australian Taxation Office as our obligations as a software provider require.
8.5 Our notice of a breach is not an admission of fault or liability.
9.1 If an individual asks us to access or correct Customer Personal Information, or complains about how it is handled, we will tell you promptly and, unless the law requires otherwise, not respond to the substance without your agreement, other than to tell them we have passed the request on.
9.2 We will help you respond to requests within the time Privacy Law requires, including by giving you the information we hold or making corrections you ask for.
We will give you reasonable help, taking into account the information available to us, with privacy impact assessments, inquiries from the Office of the Australian Information Commissioner or another regulator, and NDIS Quality and Safeguards Commission audits, as they relate to the Service. We may charge reasonable costs for help that requires significant effort, and will tell you before we do.
If a government agency, court or other third party asks us for Customer Personal Information, we will refer it to you where we can. If we are legally required to disclose it, we will disclose only what is required and tell you first, unless the law prohibits us from telling you.
12.1 While your account is active, and for 60 days after the agreement ends, you can obtain a copy of Customer Personal Information as section 7.3 of the Terms describes.
12.2 After that period, we will securely delete or de-identify Customer Personal Information within a further 90 days, except:
12.3 We will confirm deletion in writing if you ask.
13.1 Once a year, or after a data breach affecting your data, we will on request answer a reasonable security questionnaire and give you a summary of our security controls and any independent assessment we hold.
13.2 If a regulator requires an audit of our handling of your data, or that information does not reasonably address a specific concern, you may arrange an audit by an independent auditor bound by confidentiality, with at least 30 days' notice, during business hours and at your cost. It must not give access to other customers' data or compromise the Service's security.
14.1 This agreement continues while we hold Customer Personal Information, including after the Terms end.
14.2 Each party's liability under this agreement is subject to the limits in the Terms, and nothing in this agreement limits liability that cannot be limited by law.
14.3 We may update this agreement in the same way as the Terms (section 19). We will not reduce the protections in it for your existing data without your agreement.
| Provider | What it does | Information | Location |
|---|---|---|---|
| Google Cloud (Firebase: Firestore, Cloud Functions, Cloud Storage) | Hosting, databases, file storage and processing | All Customer Data | Australia (Sydney) |
| SMTP2GO | Sending email | Recipient name and email address, and email content such as invitations, security alerts and roster details | Australia (Sydney) |
| Google Cloud Identity Platform | Sign-in | Email address, phone number, hashed password, multi-factor settings | United States |
| Google reCAPTCHA | Blocking automated sign-in abuse | IP address, browser and device information | United States |
| Google Maps | Showing addresses and clock-in locations on maps | Addresses and map coordinates, IP address | United States |
| Firebase Cloud Messaging and the Authorised User's browser push service (Google, Apple or Mozilla) | Urgent shift notifications | Device token and shift summary (role and time) | United States |
| Google Cloud Logging | Operational server logs, kept for 30 days | Internal identifiers, email addresses, IP addresses, error details | United States and Google's global network |
| Google Fonts, Firebase Hosting, jsDelivr, cdnjs (Cloudflare), jQuery CDN | Delivering web pages, fonts and page components | IP address and browser information | United States and the providers' global networks |
| YouTube, Vimeo | Playing training videos a Customer adds | IP address, browser information and viewing activity on the video | United States |
No tax file numbers, bank or super details, case notes or NDIS plans are sent to providers outside Australia.