1. Status, parties and scope
1.1 Parties
This Data Processing Addendum, including its schedules (DPA), is entered into between GNR Media Pty Ltd, ABN 80 668 188 289, trading as GNR Media (GNR Media, we, us or our), and the person or organisation identified as the Client in the Agreement (Client, you or your). Each is a Party and together they are the Parties.
1.2 Automatic incorporation and acceptance
This DPA forms part of the agreement between the Parties comprising the applicable Order, plan or checkout record, the Terms and Conditions, the Privacy Policy, and any expressly accepted written variation (together, the Agreement).
The DPA applies automatically when GNR Media processes Client Personal Data on behalf of the Client. It is accepted when the Client accepts the Terms, signs or accepts an Order that refers to the Terms or this DPA, starts or continues using the Services after receiving notice of this DPA, or otherwise accepts it electronically or in writing. A separate handwritten signature is not required, although either Party may request an executed copy for its records.
1.3 Processing covered by this DPA
This DPA applies only to Client Personal Data that GNR Media processes in the role of processor, subprocessor, service provider or contractor for the purpose of providing the Services. It applies regardless of the country from which the data originates, the location of a Data Subject or the place of Processing, to the extent Applicable Data Protection Law governs that Processing.
1.4 Processing outside the processor role
GNR Media also processes some information for its own purposes as an independent controller or business. This includes account administration, billing, fraud prevention, security, legal compliance, service management, GNR Media's own communications, and the lawful use of Publicity Materials and Service Data under the automatic publicity, evidence and data licence in the Terms.
Client Personal Data processed solely on the Client's instructions does not become publicity material merely because it is held in the Platform. GNR Media will not use raw Client customer lists, private CRM contact records, passwords, payment card information, health information, government identifiers or other excluded sensitive information for GNR Media's own publicity or unrelated direct marketing.
Where the same item is lawfully processed in more than one role, this DPA governs the processor activity and the Terms and Privacy Policy govern the separate independent-controller activity. Nothing in this clause permits either Party to avoid mandatory privacy rights by relabelling a processing activity.
1.5 Affiliates and authorised users
A Client affiliate may rely on this DPA only where it is covered by the Agreement, uses the Services through the Client's account or is identified in an Order. The Client remains responsible for the acts and omissions of its affiliates and authorised users unless a separate agreement states otherwise.
1.6 No legal advice to the Client
This DPA records the contractual allocation of data-processing responsibilities between the Parties. It does not replace the Client's own assessment of the laws, notices, permissions, sector rules and transfer requirements that apply to the Client's business and intended use of the Services.
Back to top2. Definitions
- Applicable Data Protection Law
- Any privacy, data-protection, data-security or breach-notification law that applies to the Processing, including where applicable the Privacy Act 1988 (Cth) and Australian Privacy Principles; the EU GDPR; the UK GDPR and United Kingdom data-protection legislation; the Swiss Federal Act on Data Protection; the California Consumer Privacy Act and its regulations; and other applicable United States state privacy laws.
- Client Data
- Data, content and information submitted, connected, collected, generated or made available by or for the Client through the Services.
- Client Personal Data
- Personal Data contained in Client Data that GNR Media Processes on behalf of the Client to provide the Services. It excludes information GNR Media Processes as an independent controller or business, including Account Data, lawfully controlled Publicity Materials and GNR Media's separate business records.
- Account Data
- Information GNR Media uses for its direct relationship with the Client, including account owner details, authorised-user details, subscription and billing information, support history, security records and acceptance records.
- Controller, Processor, Data Subject and Processing
- These terms have the meanings given by Applicable Data Protection Law. Their corresponding terms, including business, service provider, contractor, consumer and personal information, are interpreted consistently with the relevant law.
- Personal Data
- Information relating to an identified or identifiable natural person, or any equivalent concept such as personal information under Applicable Data Protection Law.
- Personal Data Breach
- A confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Client Personal Data processed by GNR Media.
- Publicity Materials and Service Data
- These terms have the meanings given in the Terms and include the material, feedback, evidence and data covered by the automatic publicity, evidence and data licence.
- Restricted Transfer
- A transfer of Personal Data to a country, recipient or international organisation that requires an adequacy decision, contractual safeguard, approved certification, binding corporate rules, derogation or another lawful transfer mechanism.
- SCCs
- The European Commission's standard contractual clauses adopted under Commission Implementing Decision (EU) 2021/914, as lawfully amended, replaced or supplemented.
- Security Measures
- The technical and organisational measures in Schedule B, as updated with measures that provide a materially equivalent or stronger level of protection.
- Sensitive Data
- Special-category data, criminal-offence data, government identifiers, health, biometric or genetic data, precise location data, financial account credentials, information about children, or any other data subject to enhanced protection under Applicable Data Protection Law.
- Services
- The services purchased under the Agreement, including applicable Platform, CRM, automation, website, content, Campaigner, reporting, support, publishing, marketing, Website Optimisation and connected-service functions.
- Subprocessor
- A third party engaged by GNR Media to Process Client Personal Data on behalf of the Client in connection with the Services.
- UK Addendum
- The International Data Transfer Addendum to the EU Commission Standard Contractual Clauses, version B1.0 issued by the UK Information Commissioner's Office and in force from 21 March 2022, as lawfully amended, replaced or superseded.
A capitalised term not defined in this DPA has the meaning given in the Agreement. A reference to a law includes an amendment, replacement and subordinate instrument in force from time to time.
Back to top3. Roles and documented instructions
3.1 Normal role allocation
For Client Personal Data, the Client is the controller or business and GNR Media is the processor, service provider or contractor. If the Client processes the data on behalf of another controller, the Client is a processor and GNR Media is the Client's subprocessor.
Each Party is an independent controller or business for Account Data and other Personal Data it determines to process for its own lawful purposes. The Parties do not become joint controllers merely because they exchange information or use the same technology.
3.2 Documented instructions
The Client instructs GNR Media to Process Client Personal Data as reasonably necessary to provide, secure, support, maintain, configure, improve and administer the purchased Services, and as further directed through:
- the Agreement and Schedule A;
- the Client's authorised configuration, connected accounts, workflows, campaigns, settings and permissions;
- instructions from an authorised user through the Platform, email, support request, meeting record or another agreed channel; and
- actions reasonably necessary to prevent fraud, respond to a security threat, debug a service issue, maintain availability or comply with law.
The Client authorises the international transfers and use of Subprocessors described in this DPA. An instruction to publish, send, disclose or connect data through a third-party service includes an instruction to transmit the relevant data to that service.
3.3 Legally required Processing
GNR Media may Process Client Personal Data other than on the Client's instructions where required by a law binding on GNR Media. Unless prohibited, GNR Media will inform the Client of that legal requirement before the Processing.
3.4 Potentially unlawful instructions
GNR Media will inform the Client if, in GNR Media's reasonable opinion, an instruction infringes Applicable Data Protection Law. GNR Media may suspend the affected instruction while the Parties assess it and may refuse an instruction that would require unlawful Processing, materially weaken security or breach another binding obligation.
3.5 Changes to purpose
GNR Media will not determine a new purpose for Client Personal Data within the processor role. If GNR Media lawfully determines an additional purpose and Applicable Data Protection Law treats GNR Media as a controller or business for that purpose, the Processing falls outside the processor scope of this DPA and is governed by the Privacy Policy, the Terms and the applicable law.
Back to top4. Client responsibilities
The Client must:
- comply with Applicable Data Protection Law in its collection, use, disclosure, instruction and other Processing of Client Personal Data;
- have a valid legal basis, authority, permission or other lawful ground for the Processing and each instruction given to GNR Media;
- provide required privacy notices and, where required, obtain and record consent for email, SMS, profiling, cookies, advertising, call recording, AI use and other relevant activities;
- ensure Client Personal Data is relevant, reasonably accurate, limited to what is necessary and not retained through the Services longer than required;
- respond to Data Subjects and regulators as the responsible controller, with GNR Media's assistance where required by this DPA;
- configure sender identification, unsubscribe, suppression, preference and consent controls appropriate to the Client's campaigns;
- ensure that purchased, scraped, unlawfully obtained or prohibited lists are not imported into or used through the Services;
- use reasonable access controls, strong passwords, multifactor authentication where available, role-based permissions and prompt offboarding of former users;
- notify GNR Media promptly of an incorrect instruction, suspected security incident, unlawful campaign, rights request or material change in risk; and
- give GNR Media accurate contact details for data-protection, security and Subprocessor notices.
4.1 Sensitive Data and regulated data
The Services are not designed by default for unrestricted Processing of Sensitive Data, protected health information, payment card numbers, banking credentials, children's data or data subject to professional secrecy. The Client must not submit such data unless the applicable Order expressly permits it and the Parties have agreed any required additional controls, industry addendum or provider feature.
GNR Media may remove, quarantine, restrict or require the Client to delete data that appears to be prohibited, unnecessary or materially higher risk than the agreed Services support.
4.2 Client instructions to connected services
The Client is responsible for selecting and lawfully configuring any Client-controlled website, social network, search account, advertising account, payment service, calendar, mailbox, domain, analytics tool or other connected service. The independent terms and privacy practices of those providers apply to the Client's use of them.
Back to top5. GNR Media processor obligations
For Client Personal Data processed under this DPA, GNR Media will:
- Process the data only on documented instructions, except where law requires otherwise;
- use the data only for the specific business purposes stated in the Agreement, this DPA and Schedule A;
- not sell or share the data, as those terms are defined under Applicable Data Protection Law, while acting as the Client's service provider, contractor or processor;
- not retain, use or disclose the data outside the direct business relationship with the Client except as instructed or lawfully permitted;
- not combine the data with Personal Data obtained from another source except as instructed by the Client or otherwise expressly permitted by Applicable Data Protection Law;
- apply the Security Measures and require appropriate protection from authorised Subprocessors;
- provide the assistance described in this DPA, taking into account the nature of Processing and information available to GNR Media;
- notify the Client if GNR Media determines it can no longer meet a material obligation applicable to its processor role; and
- take reasonable and appropriate steps to stop and remediate unauthorised Processing identified by the Client or GNR Media.
5.1 Aggregated and de-identified information
GNR Media may create aggregated or de-identified information from Client Personal Data where permitted by law. GNR Media will take reasonable measures designed to prevent the information from being associated with an individual, will not attempt to re-identify it except to test the effectiveness of de-identification where lawful, and will require a recipient to observe equivalent restrictions before the information is disclosed.
This clause does not limit the broader rights in the Terms concerning GNR Media's methodologies, derived insights, benchmarking structures and lawfully controlled Service Data, provided that mandatory privacy law continues to apply.
5.2 Artificial intelligence and automated tools
Where GNR Media selects an AI provider to Process Client Personal Data as a processor, GNR Media will use a business, enterprise or API service governed by contractual data-processing terms appropriate to the use. GNR Media will not intentionally enable public general-purpose model training on raw Client Personal Data processed under this DPA.
The Client must not send Sensitive Data to an AI-enabled workflow unless the Order expressly permits it and the required safeguards are in place. AI features selected directly by the Client through HighLevel or another connected service are also subject to that provider's data-processing terms and configuration.
Back to top6. Confidentiality and personnel
GNR Media will limit access to Client Personal Data to personnel who require access for the Services, support, security, legal compliance or another authorised purpose. Those personnel will be bound by contractual, professional or statutory confidentiality obligations and will receive privacy and security guidance appropriate to their role.
GNR Media will use reasonable measures to confirm the reliability of personnel with material access, apply role-based or least-privilege access where practical, and remove access when it is no longer required.
Personnel includes employees and individual contractors acting under GNR Media's direct authority. An independent organisation engaged to Process Client Personal Data is treated as a Subprocessor and is governed by clause 11.
Back to top7. Security
7.1 Security Measures
GNR Media will implement and maintain the Security Measures in Schedule B, taking into account the state of the art, implementation cost, nature, scope, context and purposes of Processing, and the likelihood and severity of risks to individuals.
GNR Media may update the Security Measures as technology, providers, threats and Services evolve, provided the overall level of protection is not materially reduced during a current paid service period without a lawful reason and reasonable notice where practicable.
7.2 Shared responsibility
Security depends on both Parties. The Client remains responsible for its devices, networks, administrator accounts, user permissions, passwords, connected services, lawful campaign configuration, data minimisation and independent backups. GNR Media is not responsible for an incident caused solely by the Client's insecure device, credential sharing, unauthorised user, misconfiguration or instruction, except to the extent GNR Media caused or contributed to the incident.
7.3 Security information
GNR Media may withhold or redact information where disclosure would create a security risk, expose another client's information, reveal confidential vulnerability details, disclose source code or breach a third-party obligation. GNR Media will provide alternative evidence where reasonably available.
Back to top8. Personal Data Breaches
8.1 Notice to the Client
GNR Media will notify the Client without undue delay after becoming aware of a Personal Data Breach affecting Client Personal Data. Where practicable, GNR Media aims to provide an initial notice within 48 hours after confirming that the incident affects Client Personal Data. This operational target does not extend the obligation to notify without undue delay.
8.2 Information supplied
To the extent known and reasonably available, the notice will include:
- the nature of the incident and the affected systems or Services;
- the categories and approximate number of affected Data Subjects and records;
- the likely consequences or material risks;
- the containment, investigation and remediation steps taken or proposed;
- a contact point for follow-up; and
- information reasonably required for the Client's assessment and notification obligations.
GNR Media may provide information in phases as the investigation develops. A notice is not an admission of fault or liability.
8.3 Cooperation and notifications
GNR Media will take reasonable steps to contain, investigate and remediate the incident and will reasonably assist the Client with legally required notifications. The Client is responsible for determining whether and how to notify Data Subjects, customers, regulators or other parties, unless law places that obligation directly on GNR Media.
Each Party will preserve relevant evidence, avoid misleading public statements and coordinate external communications where reasonably necessary. GNR Media may notify a regulator or individual directly where required by law or where urgent action is reasonably necessary to reduce harm.
Back to top9. Data-subject rights
Taking into account the nature of the Processing, GNR Media will provide reasonable assistance through appropriate technical and organisational measures so the Client can respond to requests concerning access, correction, deletion, restriction, objection, portability, consent withdrawal, sale or sharing opt-out, targeted-advertising opt-out, profiling or other rights under Applicable Data Protection Law.
If GNR Media receives a request directly relating to Client Personal Data, GNR Media will forward it to the Client without undue delay where the Client can be identified. GNR Media will not respond substantively except on the Client's documented instruction or where required by law. GNR Media may direct the person to contact the Client.
Standard assistance available through the Platform or normal support is included in the Services. GNR Media may charge a reasonable fee, agreed in advance, for disproportionate, repetitive or bespoke assistance not caused by GNR Media's breach, where the law permits charging.
Back to top10. DPIAs and regulatory assistance
GNR Media will provide information and reasonable assistance available to it for the Client's data-protection impact assessment, transfer assessment, risk assessment, cybersecurity audit, prior consultation or regulator enquiry where the request relates to GNR Media's Processing of Client Personal Data.
The Client remains responsible for conducting and documenting its assessment, determining the lawfulness and proportionality of the intended Processing, consulting a regulator where required, and implementing Client-side controls.
GNR Media may satisfy this obligation through this DPA, provider documentation, security summaries, questionnaires, audit reports, transfer information or other reasonable evidence. Bespoke legal, technical or onsite assistance may be chargeable where permitted and agreed in advance.
Back to top11. Subprocessors
11.1 General authorisation
The Client gives GNR Media general written authorisation to engage the Subprocessors listed in Schedule C and their disclosed downstream subprocessors to Process Client Personal Data for the Services. GNR Media will ensure that each Subprocessor is bound by written data-protection obligations that are materially no less protective than the obligations applicable to the relevant Processing under this DPA.
11.2 Notice of changes
GNR Media will give at least 15 days' notice before appointing a new direct Subprocessor that will materially Process Client Personal Data, ordinarily by email to the Client's account contact, an in-Platform notice, or an update to the Subprocessor section of this DPA accompanied by notice. The Client must keep its contact details current.
A shorter notice period may apply where an urgent change is reasonably necessary to address a security incident, service outage, legal requirement or provider failure. GNR Media will give notice as soon as reasonably practicable in those circumstances.
11.3 Objection process
The Client may object in writing within 10 days after receiving notice, but only on reasonable and documented data-protection grounds directly related to the proposed Subprocessor. The Parties will work in good faith to address the concern through available configuration, safeguards, an alternative provider or another commercially reasonable solution.
If the objection cannot reasonably be resolved before the proposed appointment and the Subprocessor is necessary for the affected Service, the Client may terminate only that affected Service before the Subprocessor begins Processing and receive a pro-rata refund of any prepaid unused fee for that Service. The Client does not have a right to object for a purely commercial, competitive or unrelated reason.
11.4 Responsibility
GNR Media remains responsible to the Client for a Subprocessor's performance of the data-protection obligations GNR Media has delegated to it, subject to the Agreement and any mandatory rights under the SCCs or Applicable Data Protection Law.
11.5 Client-selected and connected services
A provider selected, contracted, controlled or independently enabled by the Client is not automatically GNR Media's Subprocessor. GNR Media may transmit data to that provider on the Client's instruction, but the Client remains responsible for the provider's selection, lawful use, settings and independent terms unless the Order expressly allocates responsibility differently.
Back to top12. International transfers
12.1 General authorisation and safeguards
The Client authorises GNR Media and approved Subprocessors to store, access, support and Process Client Personal Data in Australia, the United States and other locations reasonably required for the Services, subject to this DPA and Applicable Data Protection Law.
Where a Restricted Transfer requires a safeguard, the Parties will rely on an applicable adequacy decision, recognised certification, binding corporate rules, approved contractual clauses, consent or another lawful mechanism. The SCCs, UK Addendum and Swiss adaptations below apply only where needed and do not replace a more appropriate lawful mechanism that already covers the transfer.
12.2 EU and EEA transfers
For a Restricted Transfer governed by the EU GDPR, the European Commission Standard Contractual Clauses under Decision (EU) 2021/914 are incorporated into this DPA and deemed executed by the Parties. The applicable module and completed annex information are stated in Schedule D.
12.3 United Kingdom transfers
For a Restricted Transfer governed by United Kingdom data-protection law, the UK International Data Transfer Addendum, version B1.0, is incorporated into the applicable SCCs. The completed tables are stated in Schedule E.
12.4 Swiss transfers
For a Restricted Transfer governed by the Swiss Federal Act on Data Protection, the SCCs apply with the adaptations in Schedule F, but only to the extent required for Swiss law. Those adaptations do not modify the SCCs for a transfer also governed by the EU GDPR.
12.5 Transfer assessments and supplementary measures
Each Party will reasonably cooperate with transfer-impact, data-protection or risk assessments that it is legally required to perform. Taking into account the nature of the data and Services, GNR Media will apply reasonable supplementary contractual, technical or organisational measures where necessary and will make relevant information available to the Client, subject to confidentiality and security restrictions.
12.6 Government and compulsory requests
If GNR Media receives a legally binding request from a public authority for Client Personal Data, GNR Media will, to the extent lawful and reasonably practicable:
- review the request for validity and jurisdiction;
- direct the authority to the Client where appropriate;
- notify the Client before disclosure unless prohibited;
- challenge an unlawful, overbroad or disproportionate request where there are reasonable grounds to do so;
- disclose only the minimum data legally required; and
- document the request and response as required by law.
12.7 Replacement mechanism
If a competent authority adopts a replacement transfer mechanism, or if an existing adequacy decision, certification or other lawful mechanism becomes available and covers the transfer, the Parties may rely on it. GNR Media may update the relevant schedule to reflect a mandatory legal change, provided the update does not reduce legally required protection.
Back to top13. Return, deletion and retention
13.1 During the Services
The Client may access, correct, export or delete Client Personal Data using available Platform functions and normal support processes. The Client should export business-critical data before cancellation or expiry because Platform access may end when the subscription ends.
13.2 End of Services
On written request made before or within 30 days after the affected Service ends, GNR Media will provide a reasonable export or return of Client Personal Data in a commonly available format where technically supported. After that period, GNR Media may delete the data from active systems unless retention is required by law, the Client has renewed the Service or a different period is stated in an Order.
Subject to provider capability, legal holds and routine backup cycles, GNR Media will delete or cause the deletion of remaining Client Personal Data within a reasonable period, ordinarily within 90 days after the relevant retention period ends. Backup copies may remain securely isolated until overwritten through the provider's normal cycle and will not be restored for ordinary Processing except where required for disaster recovery, security or law.
13.3 Information not governed by the Client's processor-deletion choice
The return or deletion choice in this clause does not require deletion of Account Data, billing and tax records, security logs, records required to establish or defend legal rights, lawfully de-identified data, or Publicity Materials and Service Data that GNR Media lawfully retains and uses as an independent controller under the Terms and Privacy Policy.
13.4 Legal retention
Where law requires retention, GNR Media will isolate the retained Client Personal Data from ordinary use, protect it under this DPA and delete it when the legal requirement ends, unless another lawful basis applies.
Back to top14. Records, audits and compliance
14.1 Compliance information
GNR Media will make available information reasonably necessary to demonstrate compliance with the processor obligations in this DPA. This may include the DPA and schedules, completed questionnaires, relevant provider documentation, security summaries, incident information, transfer information and available independent assurance reports.
14.2 Audit process
The Client may conduct one audit in any 12-month period, and an additional audit after a material Personal Data Breach or where a regulator requires it. Audits must:
- be limited to GNR Media's Processing of that Client's Client Personal Data;
- begin with a remote document review or questionnaire where reasonable;
- be requested on at least 30 days' written notice, except for an urgent regulator request or confirmed material incident;
- occur during normal business hours and avoid unreasonable disruption;
- be conducted by the Client or an independent auditor that is not a direct competitor of GNR Media and is bound by confidentiality; and
- not require access to another client's data, source code, privileged material, penetration-test details that would create a security risk, or information GNR Media is prohibited from disclosing.
GNR Media may satisfy an onsite audit request through recent independent assurance, provider audits or equivalent evidence where that evidence reasonably addresses the request. The Client bears its audit costs and GNR Media may charge reasonable professional-service costs for disproportionate assistance, unless the audit identifies a material breach by GNR Media, in which case GNR Media will bear its own reasonable costs of remediation and ordinary audit cooperation.
14.3 Remediation
If an audit identifies a substantiated material deficiency, GNR Media will prepare and implement a reasonable remediation plan proportionate to the risk. The Client must keep audit findings confidential except where disclosure is required by law, a regulator or the Client's professional adviser under confidentiality.
Back to top15. United States terms
15.1 California service-provider and contractor terms
To the extent the California Consumer Privacy Act and its implementing regulations (CCPA) apply to Client Personal Data and GNR Media is a service provider or contractor, the Client discloses the data to GNR Media only for the limited and specified business purposes below:
- providing, configuring, hosting, maintaining and supporting the Platform and purchased Services;
- operating CRM, calendar, form, landing-page, pipeline, automation, email, SMS, campaign and connected-service functions instructed by the Client;
- creating, editing, scheduling, publishing and reporting on content or campaigns for the Client;
- providing Website Optimisation, analytics, measurement, migration, support, troubleshooting and service communications;
- maintaining security, integrity, availability, fraud prevention, debugging and quality assurance; and
- complying with law and enforcing the Agreement.
For Client Personal Data within that role, GNR Media will:
- not sell or share the data;
- not retain, use or disclose it for a purpose other than the specified business purposes or another purpose permitted by the CCPA;
- not retain, use or disclose it outside the direct business relationship with the Client, except as permitted by the CCPA;
- not combine it with Personal Data received from another source except as directed by the Client or permitted by the CCPA;
- provide the same level of privacy protection required of businesses for the relevant data;
- implement reasonable security procedures and practices appropriate to the nature of the data;
- assist with applicable consumer requests, risk assessments, cybersecurity audits and automated-decision requirements to the extent required and relevant to GNR Media's Processing;
- notify the Client if GNR Media determines it can no longer meet its CCPA obligations;
- allow the Client to take reasonable and appropriate steps to monitor compliance; and
- allow the Client, on notice, to take reasonable and appropriate steps to stop and remediate unauthorised use.
15.2 Other United States state laws
Where another applicable United States state privacy law uses comparable controller, processor, business, service-provider or contractor requirements, the Parties will interpret this DPA to satisfy those requirements. GNR Media will Process Client Personal Data only on the Client's instructions and will provide assistance and contractual restrictions required of a processor under the applicable law.
15.3 Independent-controller activities
This clause applies only to Client Personal Data processed in the service-provider, contractor or processor role. Where GNR Media lawfully Processes Account Data, Publicity Materials or Service Data as a business or independent controller, GNR Media will comply with the Privacy Policy and applicable consumer rights for that separate Processing. The classification of data under the CCPA is determined by the actual Processing, not solely by the label used in the Agreement.
Back to top16. Australian terms
To the extent the Privacy Act 1988 (Cth), Australian Privacy Principles or a binding Australian privacy or data-breach rule applies, each Party will comply with its applicable obligations. As a contractual minimum, GNR Media will handle Client Personal Data consistently with the protections in this DPA even where a particular statutory obligation does not directly apply to GNR Media.
16.1 Overseas handling
The Client authorises the overseas Processing described in this DPA. GNR Media will take reasonable steps appropriate to the circumstances to require an overseas Subprocessor to protect Client Personal Data consistently with this DPA and, where applicable, the Australian Privacy Principles. The Client acknowledges that some Services depend on providers and infrastructure outside Australia.
16.2 Security and destruction
GNR Media will take reasonable steps to protect Client Personal Data from misuse, interference, loss and unauthorised access, modification or disclosure, and to delete or de-identify it when it is no longer required within the processor role, subject to clause 13.
16.3 Eligible data breaches
The Parties will cooperate in assessing whether an incident is an eligible data breach under the Notifiable Data Breaches scheme. The Client is responsible for notifications relating to data it controls unless the law requires GNR Media to notify directly or the Parties agree otherwise in writing.
Back to top17. Liability and precedence
17.1 Liability framework
The liability exclusions, caps, indemnities, dispute process and governing-law provisions in the Agreement apply to this DPA, except to the extent the SCCs, UK Addendum or Applicable Data Protection Law require otherwise. Nothing in the Agreement or this DPA limits a Data Subject's third-party beneficiary rights under the SCCs or a liability that cannot lawfully be limited.
17.2 Order of precedence
If documents conflict in relation to Client Personal Data, the following order applies to the extent of the conflict:
- the mandatory terms of the SCCs or UK Addendum for the relevant Restricted Transfer;
- an expressly negotiated Client-specific data-processing term signed by authorised representatives of both Parties;
- this DPA;
- the remainder of the Agreement.
This priority applies only to processor Processing. The Terms and Privacy Policy continue to govern GNR Media's independent-controller Processing, including the automatic publicity, evidence and Service Data licence, subject to applicable mandatory law.
17.3 No reduction of mandatory rights
The Parties intend this DPA to provide the protections required by Applicable Data Protection Law. A provision must be read down only to the minimum extent necessary to make it valid, and the remainder continues in effect.
Back to top18. Term, updates and contact
18.1 Term
This DPA begins when it is incorporated into the Agreement and continues while GNR Media Processes Client Personal Data. Obligations concerning confidentiality, security, deletion, audit, Restricted Transfers and liability continue for as long as required by their nature or Applicable Data Protection Law.
18.2 Updates
GNR Media may update this DPA to reflect a change in law, regulator guidance, transfer mechanism, provider, Service or security practice. A material update will ordinarily be notified at least 30 days before it applies to an existing Client's next renewal, unless a shorter period is reasonably required for law, security or an urgent provider change.
An update will not materially reduce the legally required protection of Client Personal Data. If a materially detrimental change is not required by law and the Client reasonably objects before it takes effect, the Parties will seek a solution under clause 11.3 or the Client may cancel the affected Service before the change applies.
18.3 Electronic records
Electronic acceptance, account records, Order records, payment records and service-use records may be used to establish the Parties, effective date and acceptance of this DPA. A copy may be disclosed to a regulator, court, professional adviser or Data Subject where reasonably required.
Data-protection contact
GNR Media Pty Ltd
ABN 80 668 188 289
Melbourne, Victoria 3126, Australia
Email: [email protected]
Subject line: Data Processing Addendum
Schedule A. Details of Processing
| Item | Details |
|---|---|
| Subject matter | Processing Client Personal Data to provide the Services purchased under the Agreement. |
| Duration | The term of the affected Service, plus the limited export, deletion, backup, legal-retention and dispute periods described in the Agreement and clause 13. |
| Nature of Processing | Collection, recording, organisation, structuring, hosting, storage, retrieval, consultation, use, analysis, alignment, formatting, transmission, disclosure to authorised recipients, restriction, migration, support, troubleshooting, backup, deletion and other operations instructed through the Services. |
| Purposes | Providing CRM, forms, calendars, pipelines, automation, email and SMS workflows; drafting and publishing Client content; campaign execution; website and search optimisation; analytics and reporting; support; security; account migration; Client-directed integrations; and other purchased functions stated in the Order. |
| Data Subjects | Client owners, directors, employees, contractors and authorised users; the Client's prospects, leads, customers, subscribers, event attendees, website visitors, social followers, suppliers, partners and professional contacts; and other individuals whose data the Client lawfully submits. |
| Categories of Personal Data | Names, business and contact details; job title and organisation; account and user data; CRM fields and notes; communication content; marketing preferences, consent and suppression records; appointment and event information; website, device, log, search, social, content and engagement data; transaction metadata; campaign activity; images, audio or video supplied by the Client; and other data selected by the Client. |
| Sensitive Data | Not intentionally required for the standard Services. It may be Processed only where the Order expressly permits it, the Client has a lawful basis and the Parties implement appropriate enhanced safeguards. |
| Frequency | Continuous, regular, intermittent or one-off, depending on the Client's use and configuration of the Services. |
| Retention criteria | Active subscription and service requirements; Client instructions; platform capability; security and backup cycles; suppression and consent obligations; legal, tax, dispute and record-keeping requirements; and clause 13. |
| Transfers | Australia, the United States and other approved provider or support locations required for the Services, subject to clause 12 and Schedules C to F. |
| Client rights and obligations | The Client determines the purpose, lawful basis, categories, Data Subjects, retention and instructions, and may exercise the rights stated in the Agreement and this DPA. |
Schedule B. Technical and Organisational Security Measures
GNR Media maintains a proportionate, risk-based security programme for Client Personal Data. The exact controls may vary by Service and provider, but the following measures form the contractual baseline.
| Control area | Measures |
|---|---|
| Governance and accountability | Documented privacy and security responsibilities; provider review; incident escalation; periodic review of this DPA, access and risks; and records appropriate to the size and nature of the Services. |
| Confidentiality | Confidentiality obligations for personnel with access to Client Personal Data and restrictions on use outside authorised duties. |
| Access control | Role-based or least-privilege access where supported; administrator access limited to personnel with a business need; prompt review and removal of access when roles change or end. |
| Authentication | Strong passwords, multifactor authentication for privileged or sensitive systems where supported, secure session controls and protection of recovery methods. |
| Secure transmission | Encrypted transport using current industry-standard protocols, ordinarily TLS 1.2 or stronger where supported, for GNR-controlled web connections, provider connections and integrations. |
| Data at rest | Use of reputable cloud, CRM and platform providers that support encryption at rest or equivalent storage protection for applicable production data; restricted access to storage and backups. |
| Secrets and credentials | Credentials, access tokens and API keys are limited to necessary personnel and systems, stored using provider-supported secret or credential controls where available, and rotated or revoked when risk or role changes require it. |
| Cloud and infrastructure security | Use of established providers with contractual security commitments; logical tenant or account separation; provider security features; secure DNS, content-delivery, firewall or traffic-protection controls where enabled. |
| Endpoint security | Reasonable device protection, supported operating systems, screen locking, malware protection where appropriate, security updates and restrictions on unnecessary local storage. |
| Logging and monitoring | Platform, provider, authentication, support or security logs used where available to investigate incidents, detect suspicious activity, troubleshoot and maintain accountability. |
| Vulnerability and patch management | Reasonable review of material vulnerabilities; timely application of security updates proportionate to risk; provider patching for managed services; and escalation of critical issues. |
| Change and development controls | Reasonable testing, change review, separation of production credentials from development where practical, controlled deployment and rollback planning for material technical changes. |
| Availability and resilience | Use of providers with backup, redundancy, availability or disaster-recovery capability appropriate to the Service; documented response and recovery steps; and reasonable restoration testing where within GNR Media's control. |
| Incident response | Processes for identification, escalation, containment, investigation, evidence preservation, remediation and Client notification under clause 8. |
| Data minimisation and segregation | Collection limited to service needs; use of separate Client accounts, locations, folders, records or logical access boundaries where supported; avoidance of unnecessary Sensitive Data. |
| Retention and disposal | Deletion, export and retention processes aligned with clause 13; secure disposal of local copies and credentials when no longer required; isolated backup retention. |
| Subprocessor management | Privacy and security review proportionate to risk; written processing terms; international-transfer safeguards where required; provider-list maintenance; and change notice under clause 11. |
| Physical security | Physical datacentre security is principally provided by the selected cloud, CRM, hosting and platform providers. GNR Media restricts physical access to devices and workspaces under its control. |
| Training and awareness | Privacy, confidentiality, phishing, credential, data-handling and incident-awareness guidance appropriate to personnel roles and access. |
| AI controls | Use of approved business or API services for Client Personal Data; instruction and access limits; no intentional public general-purpose model training on raw Client Personal Data; heightened restrictions on Sensitive Data. |
| Review and improvement | Periodic review after material incidents, major system changes, provider changes or identified control gaps, with proportionate remediation. |
| Client-side controls | The Client controls its users, devices, permissions, content, lawful collection, campaign settings, connected services, consent records and independent backups, as described in clause 7.2. |
This Schedule describes contractual controls and does not represent that GNR Media itself holds a particular certification unless GNR Media expressly confirms that certification in writing. Provider certifications apply only to the provider and services within their stated scope.
Back to topSchedule C. Approved Subprocessors and connected services
Initial direct Subprocessor list reviewed 2 August 2026.
| Entity | Purpose | Principal locations | Provider information |
|---|---|---|---|
| HighLevel, Inc. and relevant affiliates 5473 Blair Rd Ste 100, PMB 383313, Dallas, Texas 75231-4227, USA |
Core Platform and CRM; forms, websites, funnels, calendars, pipelines, workflow automation, email and SMS orchestration, reporting, support and selected AI features. | United States; support and affiliate Processing may also occur in India and other locations disclosed by HighLevel. | HighLevel DPA HighLevel Subprocessors |
| Cloudflare, Inc. 101 Townsend Street, San Francisco, California 94107, USA |
DNS, content delivery, web security, traffic protection, hosting, Workers, storage, logs and related infrastructure where enabled for a Service. | Global network and approved support locations. | Cloudflare DPA Cloudflare Subprocessors |
| Microsoft Corporation and applicable affiliates One Microsoft Way, Redmond, Washington 98052-6399, USA |
Business email, file storage, calendar, collaboration, identity, support, office productivity and related commercial cloud services where enabled. | Australia, United States and other regions selected or used under the applicable Microsoft service. | Microsoft privacy and DPA overview Microsoft Trust Center |
| OpenAI OpCo, LLC and applicable affiliates 1455 3rd Street, San Francisco, California 94158, USA |
AI-assisted drafting, classification, analysis, summarisation, research support and automation only where GNR Media directly enables an OpenAI business or API service outside a provider's embedded feature. | United States and other locations disclosed under OpenAI's business DPA and Subprocessor list. | OpenAI DPA OpenAI Subprocessors |
Downstream providers
A direct Subprocessor may use the downstream providers stated in its current published Subprocessor list or DPA. Those lists are incorporated for the limited purpose of identifying the authorised Processing chain. GNR Media does not control every downstream provider's corporate restructuring or location change but will enforce the protections available under its contract with the direct Subprocessor.
Client-directed, independent or service-specific providers
Depending on the Client's selections, GNR Media may connect or transmit data to services such as Google Search Console, Google Analytics, Google Business Profile, LinkedIn, Meta, a Client website or WordPress host, a domain registrar, a payment processor, an advertising platform, an email or SMS carrier, a publisher, or another integration chosen by the Client. These providers may act as the Client's processor, GNR Media's Subprocessor, an independent controller, or a separate third party depending on the configuration and contract.
A service-specific provider that will act as a new direct GNR Media Subprocessor is not treated as approved merely by this general description. It must be identified in the Order or added through the notice process in clause 11 before materially Processing Client Personal Data.
Schedule D. EU Standard Contractual Clauses
This Schedule completes and selects the relevant parts of the SCCs. The official SCC text is incorporated without modification except for the selections the SCCs expressly permit.
D1. Applicable module
| Transfer relationship | Applicable SCC module |
|---|---|
| The Client is a controller and GNR Media is a processor. | Module Two: Controller to Processor |
| The Client is a processor acting for another controller and GNR Media is a subprocessor. | Module Three: Processor to Processor |
| The Client and GNR Media are independent controllers for a transfer covered by the Agreement and no other lawful mechanism applies. | Module One: Controller to Controller, only for that independent-controller transfer. |
D2. SCC selections
- Clause 7, Docking Clause: applies.
- Clause 9, use of subprocessors: Option 2, general written authorisation, applies. The advance notice period is 15 days, subject to the urgent-change provision in clause 11.2.
- Clause 11, independent dispute-resolution body: the optional language does not apply.
- Clause 17, governing law: Option 1 applies and the SCCs are governed by the laws of Ireland.
- Clause 18(b), courts: the courts of Ireland have jurisdiction.
D3. Annex I.A: list of Parties
| Data exporter | Data importer |
|---|---|
|
Name and address: the Client and relevant affiliate identified in the Agreement, Order or account. Contact: the Client's account owner or privacy contact. Activities: use of the Services and transfer of Client Personal Data under the Agreement. Role: controller or processor, as applicable. Signature and date: deemed signed on electronic acceptance of this DPA. |
Name: GNR Media Pty Ltd, ABN 80 668 188 289. Address: Melbourne, Victoria 3126, Australia. Contact: [email protected]. Activities: provision of the Services in Schedule A. Role: processor, subprocessor or independent controller, as applicable. Signature and date: deemed signed on electronic acceptance of this DPA. |
D4. Annex I.B: description of transfer
The categories of Data Subjects, categories of Personal Data, Sensitive Data safeguards, frequency, nature, purpose, duration and retention are stated in Schedule A. Transfers to Subprocessors are described in Schedule C and occur as necessary for the Services during the term and limited retention period.
D5. Annex I.C: competent supervisory authority
The competent supervisory authority is determined under Clause 13 of the SCCs based on the data exporter's establishment, representative or affected Data Subjects. Where Clause 13 permits a choice and no other authority is mandatory, the Irish Data Protection Commission is selected.
D6. Annex II and Annex III
Annex II, technical and organisational measures: Schedule B.
Annex III, authorised subprocessors: Schedule C.
D7. Additional safeguards
Clause 12.5 and 12.6 of this DPA supplement the SCCs without contradicting them. If this Schedule conflicts with the unaltered mandatory SCC text, the SCC text prevails.
Back to topSchedule E. UK International Data Transfer Addendum
The UK Addendum is incorporated where United Kingdom data-protection law applies to a Restricted Transfer. The following information completes its tables.
Table 1: Parties
| Exporter | Importer | Key contact |
|---|---|---|
| The Client identified in the Agreement, Order or account. | GNR Media Pty Ltd, ABN 80 668 188 289, Melbourne, Victoria 3126, Australia. | Client: account owner or privacy contact. GNR Media: [email protected]. |
Table 2: Selected SCCs and modules
The approved EU SCCs are those incorporated in Schedule D. Module Two applies where the Client is a controller; Module Three applies where the Client is a processor; and Module One applies only to a covered independent-controller transfer. The selections in Schedule D apply except where the UK Addendum requires a different interpretation.
Table 3: Appendix information
The Parties are identified in Schedule D3. The transfer description is Schedule A. The Security Measures are Schedule B. The Subprocessor list is Schedule C.
Table 4: Ending the Addendum when the approved Addendum changes
Either Party may end the UK Addendum in accordance with the termination provision in the approved UK Addendum if the Information Commissioner issues a revised approved Addendum and the conditions for termination are met. Ending the UK Addendum does not end the Agreement, but the Parties must implement another lawful transfer mechanism before continuing the affected Restricted Transfer.
The mandatory clauses in Part 2 of the UK Addendum apply and prevail over inconsistent commercial terms for a United Kingdom Restricted Transfer.
Back to topSchedule F. Swiss adaptations
Where the Swiss Federal Act on Data Protection (FADP) governs a Restricted Transfer, the SCCs in Schedule D apply with the following adaptations only to the Swiss transfer:
- references to the GDPR are interpreted to include the FADP to the extent necessary for the Swiss transfer;
- the term Personal Data includes information protected as personal data under the FADP;
- references to an EU Member State are interpreted to include Switzerland where required for the FADP-only transfer;
- the competent supervisory authority for the FADP is the Swiss Federal Data Protection and Information Commissioner;
- Data Subjects in Switzerland may exercise the rights granted to them by the SCCs and the FADP;
- where the transfer is governed only by the FADP, Swiss law and competent Swiss courts apply to the extent required by Swiss law; and
- where both the GDPR and FADP apply, the EU selections in Schedule D remain unchanged and these Swiss adaptations supplement them without reducing GDPR protection.
The Parties will make any further limited adaptation recognised or required by the Swiss Federal Data Protection and Information Commissioner, provided it does not alter the SCCs for an EU GDPR transfer.
Back to topSchedule G. Execution details
This Schedule records the information used to identify the Parties without requiring a separate signature page.
| Field | GNR Media | Client |
|---|---|---|
| Legal name | GNR Media Pty Ltd | The legal name recorded in the Order, checkout, invoice or account. |
| Registration | ABN 80 668 188 289; ACN 668 188 289 | The Client's ABN, company number, tax number or other recorded identifier, where supplied. |
| Address | Melbourne, Victoria 3126, Australia | The address recorded in the Order, invoice or account. |
| Contact | [email protected] | The Client's account owner, authorised representative or privacy contact. |
| Effective date | The date the Client first accepts this DPA or the date it becomes applicable to the Client under the Agreement, whichever is later. | |
| Acceptance | Electronic acceptance under clause 1.2 and clause 18.3 has the same contractual effect as signature to the extent permitted by law. | |

