vareon.
HomeCase StudiesContact
Free strategy sessionFree session ↗

▧Websites

Website designWeb developmentLanding pagesCMS integrationPerformance & SEO

◈Applications

Web applicationsMobile applicationsProduct designAccounts & paymentsAPIs & backends

⌘Custom & AI

Custom softwareBusiness systemsSystem integrationsAI assistantsWorkflow automation

↻Support

Ongoing maintenanceHosting & monitoringApplication handoverNew featuresTechnical review

↗Search & growth

SEOAEO & AI search visibilityLocal searchContent & conversion
6 weeks.

Initial Mixmentor build.
An audio workspace combining analysis, comparison and AI assistance.

Explore the case study ↗
hello@vareonhq.comBrisbane, AustraliaDesign · Build · Support
CJ Perry, founder of VareonDiscuss your next build ↗
✺
About VareonA software studio in Brisbane
CJ Perry
Meet the founderCJ Perry, and a direct line to the founder
⌘
How we workUnderstand. Design. Build. Support.
The cost
of custom.

What Custom Software Actually Costs in Australia

Commercial analysis · 6 min read
Build it.
Or buy it?

Where Your Business Should Bend

Decision essay · 6 min read
What does custom software cost?Custom or off-the-shelf?How long does a web app take?Our processAll insights ↗
hello@vareonhq.comBrisbane, AustraliaDesign · Build · Support
CJ Perry, founder of VareonDiscuss your next build ↗
Skip to content

Data Processing Agreement

How Vareon Group processes client data when acting as a data processor.

1. Definitions

For the purposes of this Data Processing Agreement (DPA), the following terms have the meanings set out below:

  • Data Controller: The entity that determines the purposes and means of processing Personal Data. In most Vareon engagements, the Client is the Data Controller.
  • Data Processor: The entity that processes Personal Data on behalf of the Data Controller. Vareon acts as Data Processor when handling Client data.
  • Personal Data: Information relating to an identified or identifiable natural person, as defined under applicable privacy laws including the Australian Privacy Act 1988.
  • Processing: Any operation performed on Personal Data, including collection, recording, organization, storage, adaptation, retrieval, consultation, use, disclosure, transmission, deletion, or destruction.
  • Sub-processor: A third-party processor engaged by Vareon to assist in processing Client data.
  • Data Subject: The individual to whom Personal Data relates.
  • Data Breach: A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data.

2. Scope & Roles

This Data Processing Agreement applies when Vareon Group Pty Ltd processes Personal Data on behalf of clients in the course of delivering operational consulting, automation engineering, data analytics, or related professional services.

In these arrangements:

  • The Client acts as the Data Controller, determining what data to provide, what purposes it serves, and what outcomes are desired.
  • Vareon acts as the Data Processor, handling Client data solely for the purpose of delivering the agreed services and following the Client's documented instructions.

This DPA forms part of and supplements the Terms of Service and any engagement agreement or statement of work between Vareon and the Client. In case of conflict, the terms of a specific written engagement agreement take precedence.

3. Purpose of Processing

Vareon processes Client data for the following purposes, as applicable to each engagement:

  • Operational consulting and process analysis
  • Workflow optimization and automation engineering
  • Data analysis, pattern detection, and insight generation
  • AI-driven recommendations and intelligent decision support
  • Development of custom internal tools, dashboards, and platforms
  • Integration of client systems with third-party automation and AI services
  • Performance monitoring, efficiency measurement, and outcome tracking
  • Documentation and knowledge capture

Processing is limited to what is necessary to deliver the contracted services and achieve the mutually agreed objectives as documented in the engagement scope.

4. Categories of Data & Data Subjects

The types of Personal Data processed by Vareon may include:

  • Business contact information (names, email addresses, phone numbers, job titles)
  • Employee or contractor identifiers and operational records
  • Process documentation, workflow data, and system logs
  • Performance metrics, productivity data, and operational KPIs
  • Customer or supplier information necessary for process analysis
  • Transaction data, operational records, and business communications
  • System access logs and usage analytics

Data Subjects may include:

  • The Client's employees, contractors, and consultants
  • The Client's customers, prospects, and business contacts
  • The Client's suppliers, vendors, and partners
  • Other individuals whose data appears in the Client's operational systems

The specific categories of data and data subjects vary by engagement and are determined by the Client's business context and the scope of work.

5. Data Processor Obligations (Vareon)

As Data Processor, Vareon commits to the following obligations:

Process Only on Instructions

Vareon will process Personal Data only in accordance with documented instructions from the Client, as provided through the engagement agreement, written communications, or authorized verbal instructions confirmed in writing. We will not process data for any other purpose unless required by law.

Confidentiality

Vareon personnel with access to Personal Data are bound by confidentiality obligations and will not disclose or use the data except as necessary to perform the services.

Security Measures

Vareon implements appropriate technical and organizational security measures to protect Personal Data against unauthorized access, disclosure, alteration, or destruction. These measures are detailed in Section 8 below.

Sub-processor Management

Vareon will ensure that any Sub-processors engaged are bound by data protection obligations equivalent to those in this DPA.

Data Subject Rights Assistance

Vareon will assist the Client in responding to Data Subject requests for access, rectification, erasure, or other rights under applicable privacy laws, to the extent feasible given the nature of our processing.

Breach Notification

Vareon will notify the Client without undue delay after becoming aware of a Data Breach affecting Client data.

Deletion or Return

Upon termination of the engagement or upon Client request, Vareon will delete or return all Personal Data unless retention is required by law.

6. Sub-processors

Vareon may engage carefully selected Sub-processors to assist in delivering services. These typically include:

  • AI and machine learning providers: OpenAI, Anthropic, and similar services for intelligent analysis and automation
  • Cloud infrastructure: AWS, Google Cloud, Microsoft Azure, or similar hosting and compute services
  • Database and storage: Supabase, PostgreSQL hosting providers, secure cloud storage
  • Automation platforms: n8n, Zapier, Make.com, or similar workflow automation tools
  • Analytics and monitoring: Privacy-respecting analytics and system monitoring services

Vareon maintains contracts with Sub-processors that include data protection obligations equivalent to those in this DPA. We conduct due diligence on Sub-processors' security practices, compliance certifications, and data handling policies before engagement.

The Client has the right to be informed of material changes in Sub-processors. If a Client objects to a new Sub-processor on reasonable grounds, Vareon will work with the Client to find an alternative solution or allow termination of the affected services without penalty.

7. International Data Transfers

In the course of delivering services, Personal Data may be transferred to or accessed from countries outside Australia, particularly when using cloud infrastructure or AI services hosted in the United States, Europe, or other jurisdictions.

Where international transfers occur, Vareon implements appropriate safeguards, which may include:

  • Use of Sub-processors that are certified under recognized frameworks (e.g., EU-U.S. Data Privacy Framework, ISO 27001)
  • Standard contractual clauses or equivalent data transfer mechanisms
  • Encryption of data in transit and at rest
  • Restricting data access to necessary personnel and systems
  • Compliance with Australian Privacy Principles regarding cross-border disclosure

Clients acknowledge that use of modern cloud and AI services necessarily involves some international data flows, and Vareon will use reasonable efforts to ensure these transfers are protected in accordance with applicable laws.

8. Security Measures

Vareon implements technical and organizational security measures appropriate to the risk, including:

  • Encryption: Data encrypted in transit (TLS 1.2+) and at rest (AES-256 or equivalent)
  • Access controls: Role-based access, multi-factor authentication, principle of least privilege
  • Logging and monitoring: Audit logs for data access and system activity
  • Network security: Firewalls, intrusion detection, secure network architecture
  • Secure development: Code review, vulnerability scanning, secure coding practices
  • Incident response: Procedures for detecting, responding to, and recovering from security incidents
  • Personnel security: Background checks, confidentiality agreements, security training
  • Physical security: Use of secure, certified data centers with appropriate physical controls

Security measures are reviewed and updated regularly to address evolving threats and industry best practices. Specific security controls may vary based on the sensitivity of data and requirements of each engagement.

9. Data Subject Rights & Assistance

As Data Controller, the Client is primarily responsible for responding to Data Subject requests to exercise rights such as access, rectification, erasure, restriction of processing, data portability, or objection.

Vareon will assist the Client in fulfilling these obligations by:

  • Providing information about what Personal Data we process on the Client's behalf
  • Facilitating access to or export of relevant data where technically feasible
  • Correcting or deleting data upon Client instruction
  • Restricting processing or providing data in machine-readable format as requested
  • Redirecting Data Subject requests received directly by Vareon to the Client for handling

Assistance will be provided promptly and in line with statutory timelines. If fulfilling a request requires significant additional effort beyond normal service delivery, Vareon may charge reasonable fees for the assistance provided.

10. Data Breach Notification

If Vareon becomes aware of a Data Breach affecting Personal Data processed on behalf of a Client, we will:

  • Notify the Client without undue delay and no later than 72 hours after becoming aware of the breach
  • Provide details of the nature of the breach, the categories and approximate number of affected Data Subjects and records, and the likely consequences
  • Describe measures taken or proposed to address the breach and mitigate its adverse effects
  • Provide a point of contact for further information
  • Cooperate with the Client in investigating the breach and notifying authorities or affected individuals as required by law

Vareon will take immediate steps to contain and remediate any breach, and will work collaboratively with the Client to minimize harm and prevent recurrence.

11. Data Retention, Return, and Deletion

Vareon retains Client data only for as long as necessary to deliver the contracted services and fulfill legal or contractual obligations.

Upon termination or expiry of an engagement, or upon Client request, Vareon will:

  • At the Client's election, either return all Personal Data to the Client in a commonly used machine-readable format, or securely delete it
  • Delete all copies of Personal Data from Vareon's systems, including backups, unless retention is required by applicable law (e.g., financial records, dispute resolution, regulatory obligations)
  • Provide written certification of deletion upon Client request

Where deletion is not immediate due to technical limitations (e.g., backup retention schedules), Vareon will isolate the data from active systems and ensure it is deleted in accordance with standard retention policies, typically within 90 days.

12. Audit & Compliance

Clients have the right to request reasonable information to demonstrate Vareon's compliance with this DPA and applicable data protection laws.

Upon reasonable notice and no more than once per year (or more frequently if required by regulatory authorities), Vareon will:

  • Provide information about our data processing practices, security measures, and Sub-processors
  • Allow the Client or an independent auditor to conduct audits or inspections of relevant systems and documentation
  • Cooperate with audits initiated by data protection authorities

Audit rights are subject to reasonable limitations to protect Vareon's confidential information, trade secrets, and the privacy and security of other clients. Audits must be conducted during business hours with minimal disruption to operations, and auditors must be bound by confidentiality obligations.

If an audit requires significant time or resources beyond normal service delivery, Vareon may charge reasonable fees to cover costs.

13. Liability & Indemnity

Each party is responsible for compliance with its obligations under this DPA and applicable data protection laws:

  • Client responsibility: The Client is responsible for the lawfulness of data collection, the accuracy and appropriateness of instructions to Vareon, and ensuring it has legal grounds to share Personal Data for processing.
  • Vareon responsibility: Vareon is responsible for processing data in accordance with Client instructions, implementing appropriate security measures, and managing Sub-processors appropriately.

To the extent permitted by law, each party indemnifies the other against losses arising from its own breach of data protection obligations. Total liability under this DPA is subject to the limitation of liability provisions in the Terms of Service and engagement agreement.

14. Governing Law & Jurisdiction

This Data Processing Agreement is governed by the laws of Queensland, Australia, and any disputes shall be subject to the exclusive jurisdiction of the courts of Queensland.

The parties acknowledge that this DPA is intended to comply with the Australian Privacy Act 1988, the Australian Privacy Principles (APPs), and other applicable Australian data protection laws. Where the Client is subject to additional regulatory requirements (e.g., GDPR, CCPA, health or financial sector regulations), specific supplementary terms may be agreed in the engagement agreement.

Last updated: November 24, 2025

vareon.

A software studio in Brisbane, Australia. Websites, applications, business systems and search visibility, from the first build to ongoing growth.

⌘YOUR CODE▤HANDOVER↻SUPPORT
Replies within one business day ↗
WebsitesWeb applicationsMobile applicationsCustom softwareAI & automationOngoing supportSEO & local searchAEO & AI visibility
About VareonMeet the founderHow we workCase studiesVareon labInsights
hello@vareonhq.comBrisbane, AustraliaPlan your project ↗ABN 64 108 741 214
© 2026 Vareon. All rights reserved.
Terms & handoverPrivacyCookiesAI policy▧ Discuss support ↗
vareon.Built around your business.