Legal

Data Processing Addendum

Last updated: 5 August 2026

This Data Processing Addendum forms part of our Terms & Conditions and governs how EvenBetter processes personal data on the Customer's behalf when providing the Service. It sets out our obligations as processor, our security measures, and how sub-processors, data-subject requests, breaches, and international transfers are handled.

1. Introduction and how this DPA applies

This Data Processing Addendum (“DPA”) forms part of, and is incorporated into, the Terms & Conditions between you (the “Customer”) and EvenBetter Technology Pty Ltd (ABN 69 681 536 149) (“EvenBetter”, “we”, “us”). It applies wherever EvenBetter processes personal data on the Customer's behalf in the course of providing the EvenBetter salary-benchmarking service (the “Service”).

On data-protection matters this DPA prevails over any conflicting term in the Terms. In all other respects the Terms continue to apply. This DPA does not apply where EvenBetter acts as a controller in its own right (for example, our own account, billing, and Service-improvement activities), which are addressed in our Privacy notice.

2. Definitions

Capitalised terms not defined here have the meaning given in the Terms or in Applicable Data Protection Law.

  • Controller — the party that determines the purposes and means of the processing of personal data.
  • Processor — the party that processes personal data on behalf of the Controller.
  • Personal Data — any information relating to an identified or identifiable individual that is processed under this DPA.
  • Data Subject — the individual to whom Personal Data relates.
  • Processing — any operation performed on Personal Data, whether or not by automated means (including collection, use, storage, disclosure, and deletion).
  • Sub-processor— any third party engaged by EvenBetter to process Personal Data on the Customer's behalf.
  • Applicable Data Protection Law — all laws relating to data protection and privacy that apply to the processing under this DPA, including the EU General Data Protection Regulation (EU GDPR), the UK GDPR, the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), and the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), in each case as applicable.
  • Standard Contractual Clauses — the standard data-protection clauses adopted by the European Commission (EU SCCs) and, for the United Kingdom, the UK International Data Transfer Agreement or Addendum (UK IDTA), as applicable.

3. Roles of the parties and scope

For processing under this DPA the Customer is the Controller and EvenBetter is the Processor. Where Applicable Data Protection Law uses the terms “business” and “service provider” (CCPA/CPRA), the Customer is the business and EvenBetter is the service provider. The details of the processing are:

  • Subject-matter — providing the EvenBetter salary-benchmarking Service to the Customer.
  • Duration — the term of the Terms, and any period afterwards required to return or delete Personal Data under this DPA.
  • Nature and purpose — processing job descriptions, offer details, and related inputs to generate benchmark reports and to operate and secure the Service.
  • Types of Personal Data— identifiers and employment details contained in the job descriptions, offers, and inputs the Customer submits, which may include the names, roles, locations, and pay details of the Customer's employees or candidates.
  • Categories of Data Subjects— the Customer's personnel, candidates, and other individuals referenced in the Customer's inputs.

4. Processor obligations

EvenBetter will:

  • process Personal Data only on the Customer's documented instructions, including the instructions set out in the Terms and this DPA, and as needed to provide the Service, unless required to process by law (in which case we will inform the Customer of that legal requirement before processing, unless the law prohibits it);
  • inform the Customer if, in our opinion, an instruction appears to infringe Applicable Data Protection Law; and
  • ensure that personnel authorised to process the Personal Data are bound by an appropriate obligation of confidentiality.

5. Security measures

Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, EvenBetter implements technical and organisational measures appropriate to the risk, consistent with Article 32 of the GDPR, including:

  • encryption of Personal Data in transit (TLS 1.3) and at rest;
  • scoped access controls limiting access to authorised personnel;
  • audit logging of relevant access to and operations on Personal Data; and
  • regular dependency-vulnerability scanning.

EvenBetter will assist the Customer in ensuring compliance with its own security obligations under Applicable Data Protection Law, taking into account the nature of processing and the information available to EvenBetter.

6. Sub-processors

The Customer gives EvenBetter general authorisation to engage Sub-processors to process Personal Data in connection with the Service. Our current Sub-processors are listed in our Privacy notice and include Cloudflare, AWS, Clerk, Stripe, Resend, HubSpot, Mixpanel, Sentry, Langfuse, Arize, Anthropic, and the AI research models provided by Anthropic, Google, OpenAI, and xAI.

EvenBetter will give the Customer notice of any new Sub-processor before that Sub-processor begins processing Personal Data, and the Customer may object on reasonable data-protection grounds. EvenBetter imposes on each Sub-processor data-protection obligations equivalent to those in this DPA, and remains liable to the Customer for the performance of its Sub-processors' obligations.

As a data-protection safeguard in our benchmark research pipeline, EvenBetter sends only role and market context — title, seniority, location, and extracted requirements — to the AI research models; it does not send offer or salary figures or identifiers. In addition, a Haiku PII pre-pass redacts personal information from job descriptions before persistence.

7. Data subject requests

Taking into account the nature of the processing, EvenBetter will assist the Customer by appropriate technical and organisational measures, insofar as this is possible, to respond to requests from Data Subjects to exercise their rights (such as access, rectification, erasure, restriction, portability, and objection). If EvenBetter receives such a request directly from a Data Subject in relation to the Customer's Personal Data, it will not respond to the request itself except on the Customer's documented instructions, and will instead route the request to the Customer without undue delay.

8. Personal data breaches

EvenBetter will notify the Customer without undue delay after becoming aware of a personal data breach affecting the Customer's Personal Data, and will provide the Customer with reasonable information about the breach to help the Customer meet its own obligations to notify supervisory authorities and affected Data Subjects, to the extent required by Applicable Data Protection Law.

9. Data protection impact assessments and prior consultation

EvenBetter will provide the Customer with reasonable assistance with data protection impact assessments and any prior consultation with supervisory authorities that the Customer is required to carry out under Applicable Data Protection Law, taking into account the nature of the processing and the information available to EvenBetter.

10. International transfers

Personal Data processed under this DPA is primarily hosted in Australia (AWS RDS, ap-southeast-2), and some Sub-processors are located in the United States. Where EvenBetter transfers Personal Data to a country that is not the subject of an adequacy decision, it will put in place an appropriate transfer mechanism, including the EU Standard Contractual Clauses and, for the United Kingdom, the UK IDTA, as applicable.

11. Deletion or return of data

On termination or expiry of the Terms, EvenBetter will, at the Customer's choice, delete or return the Customer's Personal Data in accordance with the retention terms set out in our Privacy notice, except that de-identified or aggregated data and billing records required to be retained by law may be kept in accordance with those terms.

12. Audits and information

EvenBetter will make available to the Customer the information reasonably necessary to demonstrate compliance with its obligations under this DPA, and will allow for and contribute to reasonable audits, including inspections, conducted by the Customer or an auditor it mandates, on reasonable prior notice and subject to appropriate confidentiality obligations.

13. Liability

This DPA is subject to the Limitation of Liability set out in the Terms.

14. Governing law

This DPA is governed by the laws of New South Wales, Australia, consistent with the governing law of the Terms.

15. Contact

Questions about this DPA or about how EvenBetter processes Personal Data on the Customer's behalf? Reach us via our contact page.

EvenBetter is operated by EvenBetter Technology Pty Ltd (ABN 69 681 536 149). This DPA is provided in plain English for the Customer's counsel to review; a fully lawyer-reviewed version (with executed Standard Contractual Clauses / UK IDTA where applicable) will replace it before public use.