Creately Data Processing Addendum
Data protection terms for Customer Personal Data
| Provider | Cinergix Pty Ltd (ABN 69 130 459 906), trading as Creately |
| Version | 1st July 2026 |
| Registered office | Unit 1, 20 Collins Street, Mentone, Victoria 3194, Australia |
Scope This DPA forms part of the Agreement whenever Creately processes Personal Data in Customer Data on the Customer's behalf. It is designed for Australian customers and also contains GDPR/UK GDPR transfer mechanics where applicable.
This Data Processing Addendum (DPA) is between Cinergix Pty Ltd, trading as Creately, and the Customer identified in an Order Form. It is incorporated into the Creately Master Subscription Agreement identified in that Order Form.
1. Definitions and roles
1.1 Applicable Data Protection Law means privacy, data protection and data breach notification laws applicable to the processing, including the Privacy Act 1988 (Cth) and Australian Privacy Principles; the EU General Data Protection Regulation 2016/679 (GDPR); the UK GDPR and Data Protection Act 2018; and other laws identified in the Order Form.
1.2 Customer Personal Data means Personal Data contained in Customer Data and processed by Creately for the Customer under the Agreement.
1.3 Personal Data Breach means a confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, Customer Personal Data.
1.4 Subprocessor means another processor engaged by Creately to process Customer Personal Data.
1.5 Terms such as controller, processor, data subject, personal data, process and supervisory authority have the meanings under Applicable Data Protection Law.
1.6 For Customer Personal Data, the Customer is controller or processor as applicable, and Creately is processor or subprocessor. Each party is independently responsible for Personal Data it processes as controller for account, billing, security, business-contact and relationship-management purposes.
2. Instructions and compliance
2.1 Creately will process Customer Personal Data only on documented instructions from the Customer, including the Agreement, use and configuration of the Service, support requests and other written instructions accepted by Creately.
2.2 Creately will inform the Customer if it reasonably believes an instruction infringes Applicable Data Protection Law and may suspend the affected processing while the parties resolve the issue.
2.3 The Customer is responsible for the lawfulness of Customer Personal Data, its instructions, required privacy notices, permissions and lawful bases, including for employee and sensitive information.
2.4 Creately will not sell Customer Personal Data, use it for third-party advertising, or use it to train a general-purpose or shared machine-learning model without express written Customer authorisation.
3. Confidentiality and personnel
3.1 Creately will ensure that personnel authorised to process Customer Personal Data are subject to confidentiality obligations and receive appropriate privacy and security training.
3.2 Access will be limited to personnel who need it to provide, secure or support the Service and will be subject to access controls and logging consistent with the Security & Support Schedule.
4. Security
4.1 Creately will implement and maintain appropriate technical and organisational measures designed to protect Customer Personal Data, taking into account the nature, scope, context and purposes of processing and the risk to individuals.
4.2 The measures are described in the Security & Support Schedule and include access control, encryption, logging, vulnerability management, incident response, backups and business continuity.
4.3 The Customer is responsible for secure configuration of Customer-controlled access, identity settings, permissions, endpoints and source systems.
5. Personal Data Breaches
5.1 Creately will notify the Customer without undue delay after confirming a Personal Data Breach and, where practicable, within 48 hours. Notification is not an admission of fault.
5.2 To the extent known, notice will describe the nature of the breach, affected data and data subjects, likely consequences, mitigation taken or proposed, and a contact for further information. Creately may provide information in phases.
5.3 Creately will take reasonable steps to contain, investigate and remediate the breach and will reasonably assist the Customer with legally required assessment and notifications. The Customer is responsible for notifications by the Customer as controller unless law requires Creately to notify directly.
6. Subprocessors
6.1 The Customer gives general authorisation for Creately to use Subprocessors to provide the Service.
6.2 Creately will maintain a current Subprocessor list at [INSERT SUBPROCESSOR URL] or provide it on request. Creately will give at least 15 days’ notice before a new Subprocessor begins materially processing Customer Personal Data, unless an urgent security or continuity need requires shorter notice.
6.3 The Customer may object during the notice period on reasonable data-protection grounds. The parties will work in good faith on a commercially reasonable solution. If none is available, either party may terminate the affected Service and Creately will refund prepaid unused Fees for it.
6.4 Creately will impose written data-protection obligations on each Subprocessor that are no less protective in material respects than this DPA and remains responsible for the Subprocessor’s performance of those obligations.
7. International processing and transfers
7.1 Customer Personal Data will be hosted in the region identified in the Order Form. Support, security, resilience or Subprocessor activities may involve access from another country as described in the Subprocessor list and security materials.
7.2 For Australian Personal Data, Creately will use contractual and organisational measures designed to support the Customer’s compliance with APP 8 and will require overseas Subprocessors to protect the data consistently with applicable contractual obligations.
7.3 For transfers of EEA Personal Data to a country without an adequacy decision, the parties incorporate the European Commission Standard Contractual Clauses adopted by Decision 2021/914 using the applicable module. Module Two applies for controller-to-processor transfers and Module Three for processor-to-processor transfers.
7.4 For UK Personal Data, the applicable EU Standard Contractual Clauses are modified by the UK International Data Transfer Addendum in force at the time of transfer.
7.5 The details in Annex 1 complete the transfer annexes. If a transfer mechanism is replaced or invalidated, the parties will cooperate to implement a valid replacement.
8. Data subject requests and regulatory assistance
8.1 Taking into account the nature of processing, Creately will provide reasonable assistance through available functionality or support to enable the Customer to respond to requests for access, correction, deletion, portability, restriction or objection.
8.2 If Creately receives a request relating to Customer Personal Data, it will refer the requester to the Customer unless legally prohibited. Creately will not respond substantively except on the Customer’s instruction or as required by law.
8.3 Creately will provide reasonable assistance with data-protection impact assessments, prior consultations and regulator enquiries relating specifically to the Service, taking into account the information available to Creately.
9. Audits and information
9.1 Creately will make available information reasonably necessary to demonstrate compliance, including relevant certifications and independent audit reports under confidentiality restrictions.
9.2 If that information is insufficient, the Customer may conduct one audit in any 12-month period on at least 30 days’ notice, during normal business hours, through an independent auditor bound by confidentiality. Additional audits may occur following a material Personal Data Breach or regulator requirement.
9.3 An audit must minimise disruption, avoid access to other customers’ data and Creately source code, and comply with security requirements. The Customer bears its audit costs and reimburses reasonable Creately costs for an audit beyond standard compliance materials, unless a material breach by Creately is found.
10. Return and deletion
10.1 During the Subscription Term and for 30 days after expiry or termination, the Customer may retrieve Customer Personal Data using available export features.
10.2 After that period, Creately will delete or render inaccessible Customer Personal Data from active systems within 90 days, unless law requires retention. Residual copies in backups will be isolated from ordinary use and deleted through the documented backup lifecycle.
10.3 On written request, Creately will confirm completion of deletion, subject to legal retention and backup exceptions.
11. Liability and precedence
11.1 The liability provisions of the MSA apply to this DPA.
11.2 If this DPA conflicts with the MSA concerning processing of Customer Personal Data, this DPA prevails. The Standard Contractual Clauses prevail to the extent required by their terms.
Annex 1 - Details of processing
| Item | Description |
|---|---|
| Subject matter | Provision, security, support and administration of the subscribed Creately Service. |
| Duration | The Subscription Term plus the export, retention and deletion periods in the Agreement. |
| Nature and purpose | Hosting, structuring, displaying, searching, analysing, transmitting, backing up, securing, supporting, integrating and deleting Customer Personal Data on Customer instructions. |
| Data subjects | Customer employees, workers, contractors, candidates, former personnel, managers, users, business contacts and other individuals represented in Customer Data. |
| Personal Data | Identity and contact data; employment, position and reporting data; organisational attributes; location; account and authentication data; succession, talent, performance, compensation and demographic fields selected by Customer; usage and audit data. |
| Sensitive / special-category data | May include health, disability, racial or ethnic origin, trade-union membership, diversity, performance, compensation or other sensitive workforce data if the Customer chooses to provide it. |
| Processing frequency | Continuous or periodic during the Subscription Term, depending on Customer use and connector schedules. |
| Retention | As described in clause 10 and the Agreement. |
| Hosting region | As stated in the Order Form. |
| Customer contact | [PRIVACY / SECURITY CONTACT] |
| Creately contact | privacy@creately.com / security@creately.com [CONFIRM ADDRESSES BEFORE PUBLICATION] |
Annex 2 - Technical and organisational measures
The measures in the Creately Security & Support Schedule identified in the Order Form are incorporated into this DPA.