Legal · DPA

Data Processing Agreement

Last updated: May 28, 2026

1. Definitions

"Data Controller" refers to you, the customer. "Data Processor" refers to Dome. "Personal Data" means any information relating to an identifiable natural person processed through the Dome platform.

2. Processing Details

Dome processes personal data on your documented instructions to provide AI chatbot services, lead management, conversation analytics, ad optimization, and related features. The processing duration is the term of your agreement with Dome unless otherwise agreed in writing.

3. Processor Obligations

Dome will process personal data only on documented instructions from you, ensure the confidentiality of personnel authorized to process data, implement appropriate technical and organisational measures, and assist you in responding to requests from individuals to exercise their rights under applicable data protection laws, including the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

4. Sub-processors

You authorize Dome to engage sub-processors including Amazon Web Services (cloud infrastructure), Stripe (payment processing), and OpenAI (AI model inference). Dome conducts due diligence, requires contractual protections, and will provide notice of any material changes to sub-processors. Customers may object to a new sub-processor on reasonable grounds.

5. Cross‑border Transfers

Personal data may be transferred to jurisdictions outside Australia. Dome will implement suitable safeguards for cross‑border transfers (contractual clauses, binding corporate rules, or customer consent) consistent with the Privacy Act and APPs. Where transfers rely on SCCs or other mechanisms, Dome will make these available on request.

6. Security Measures

Dome maintains technical and organisational security measures including encryption in transit and at rest, access controls, logging, vulnerability management, regular penetration testing, and an incident response program. We align practices with recognised standards (e.g., ISO 27001, SOC 2) and will promptly notify you of any eligible data breach in accordance with the NDB scheme and applicable law.