Data Processing Addendum
Last updated: 5 August 2026
This Data Processing Addendum forms part of our Terms & Conditions and governs how EvenBetter processes personal data on the Customer's behalf when providing the Service. It sets out our obligations as processor, our security measures, and how sub-processors, data-subject requests, breaches, and international transfers are handled.
1. Introduction and how this DPA applies
This Data Processing Addendum (“DPA”) forms part of, and is incorporated into, the Terms & Conditions between you (the “Customer”) and EvenBetter Technology Pty Ltd (ABN 69 681 536 149) (“EvenBetter”, “we”, “us”). It applies wherever EvenBetter processes personal data on the Customer's behalf in the course of providing the EvenBetter salary-benchmarking service (the “Service”).
On data-protection matters this DPA prevails over any conflicting term in the Terms. In all other respects the Terms continue to apply. This DPA does not apply where EvenBetter acts as a controller in its own right (for example, our own account, billing, and Service-improvement activities), which are addressed in our Privacy notice.
2. Definitions
Capitalised terms not defined here have the meaning given in the Terms or in Applicable Data Protection Law.
- Controller — the party that determines the purposes and means of the processing of personal data.
- Processor — the party that processes personal data on behalf of the Controller.
- Personal Data — any information relating to an identified or identifiable individual that is processed under this DPA.
- Data Subject — the individual to whom Personal Data relates.
- Processing — any operation performed on Personal Data, whether or not by automated means (including collection, use, storage, disclosure, and deletion).
- Sub-processor— any third party engaged by EvenBetter to process Personal Data on the Customer's behalf.
- Applicable Data Protection Law — all laws relating to data protection and privacy that apply to the processing under this DPA, including the EU General Data Protection Regulation (EU GDPR), the UK GDPR, the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), and the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), in each case as applicable.
- Standard Contractual Clauses — the standard data-protection clauses adopted by the European Commission (EU SCCs) and, for the United Kingdom, the UK International Data Transfer Agreement or Addendum (UK IDTA), as applicable.
3. Roles of the parties and scope
For processing under this DPA the Customer is the Controller and EvenBetter is the Processor. Where Applicable Data Protection Law uses the terms “business” and “service provider” (CCPA/CPRA), the Customer is the business and EvenBetter is the service provider. The details of the processing are:
- Subject-matter — providing the EvenBetter salary-benchmarking Service to the Customer.
- Duration — the term of the Terms, and any period afterwards required to return or delete Personal Data under this DPA.
- Nature and purpose — processing job descriptions, offer details, and related inputs to generate benchmark reports and to operate and secure the Service.
- Types of Personal Data— identifiers and employment details contained in the job descriptions, offers, and inputs the Customer submits, which may include the names, roles, locations, and pay details of the Customer's employees or candidates.
- Categories of Data Subjects— the Customer's personnel, candidates, and other individuals referenced in the Customer's inputs.
4. Processor obligations
EvenBetter will:
- process Personal Data only on the Customer's documented instructions, including the instructions set out in the Terms and this DPA, and as needed to provide the Service, unless required to process by law (in which case we will inform the Customer of that legal requirement before processing, unless the law prohibits it);
- inform the Customer if, in our opinion, an instruction appears to infringe Applicable Data Protection Law; and
- ensure that personnel authorised to process the Personal Data are bound by an appropriate obligation of confidentiality.
5. Security measures
Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, EvenBetter implements technical and organisational measures appropriate to the risk, consistent with Article 32 of the GDPR, including:
- encryption of Personal Data in transit (TLS 1.3) and at rest;
- scoped access controls limiting access to authorised personnel;
- audit logging of relevant access to and operations on Personal Data; and
- regular dependency-vulnerability scanning.
EvenBetter will assist the Customer in ensuring compliance with its own security obligations under Applicable Data Protection Law, taking into account the nature of processing and the information available to EvenBetter.
6. Sub-processors
The Customer gives EvenBetter general authorisation to engage Sub-processors to process Personal Data in connection with the Service. Our current Sub-processors are listed in our Privacy notice and include Cloudflare, AWS, Clerk, Stripe, Resend, HubSpot, Mixpanel, Sentry, Langfuse, Arize, Anthropic, and the AI research models provided by Anthropic, Google, OpenAI, and xAI.
EvenBetter will give the Customer notice of any new Sub-processor before that Sub-processor begins processing Personal Data, and the Customer may object on reasonable data-protection grounds. EvenBetter imposes on each Sub-processor data-protection obligations equivalent to those in this DPA, and remains liable to the Customer for the performance of its Sub-processors' obligations.
As a data-protection safeguard in our benchmark research pipeline, EvenBetter sends only role and market context — title, seniority, location, and extracted requirements — to the AI research models; it does not send offer or salary figures or identifiers. In addition, a Haiku PII pre-pass redacts personal information from job descriptions before persistence.
