Data Processing Agreement — Launchr

Effective: 27 May 2026 · Last updated: 4 July 2026 · ABN 46 696 518 206 · Launchr Pty Ltd

1. AGREEMENT OVERVIEW

This Data Processing Agreement ("DPA") forms part of the Terms of Service for Launchr platform. It applies when you process personal data subject to the EU General Data Protection Regulation (GDPR) or similar data protection laws.

1A. AN AGENT-DRIVEN COMPANY

Launchr is an Agent-driven company. Our Agents — artificial intelligence (AI) systems — perform much of the Processor's work under this DPA, including automated processing of Personal Data, subject to human verification and the technical and organisational measures described in Schedule A. AI systems can make mistakes; we take all reasonable steps to catch errors before they affect Personal Data. Liability under this DPA is allocated in section 10 of this DPA and limited as set out in sections 10 and 11 of the Terms of Service, which do not exclude rights that cannot lawfully be excluded.

2. DEFINITIONS

2.1 GDPR Definitions

2.2 Agreement Definitions

3. ROLES AND RESPONSIBILITIES

3.1 Controller Responsibilities

As Controller, you are responsible for:

3.2 Processor Responsibilities

As Processor, we are responsible for:

3.3 Joint Responsibilities

Both parties are responsible for:

4. PROCESSING DETAILS

4.1 Subject Matter

Processing of Personal Data through the Platform for the purposes of providing the Services.

4.2 Duration

For the duration of your subscription to the Platform.

4.3 Nature and Purpose

Processing necessary to provide the Platform services, including:

4.4 Types of Personal Data

May include:

4.5 Categories of Data Subjects

May include:

5. PROCESSOR OBLIGATIONS

5.1 Processing Instructions

We will:

5.2 Confidentiality

We will:

5.3 Security Measures

We implement appropriate technical and organisational measures including:

Technical Measures:

Organisational Measures:

5.4 Sub-processing

5.4.1 Authorised Sub-processors

You authorise us to engage the following Sub-processors:

| Sub-processor | Purpose | Location | Safeguards | |---------------|---------|----------|------------| | Stripe | Payment processing | Global (US-based) | Standard Contractual Clauses | | Anthropic | Agent (AI) processing — see section 1A | United States | Standard Contractual Clauses, encryption | | Cloudflare | Hosting and infrastructure | Global (US-based, Australian points of presence) | Standard Contractual Clauses, encryption | | Resend | Email communications | Global (US-based) | Standard Contractual Clauses | | Twilio | Telephony and SMS | United States | Standard Contractual Clauses | | ElevenLabs | Voice synthesis | United States | Standard Contractual Clauses |

5.4.2 Sub-processor Requirements

We will:

5.5 Data Subject Rights

We will:

5.6 Data Breach Notification

We will:

5.7 Data Protection Impact Assessment

We will:

5.8 Records of Processing

We maintain records of processing activities as required by Article 30 of the GDPR.

6. CONTROLLER OBLIGATIONS

6.1 Lawful Basis

You must:

6.2 Instructions

You must:

6.3 Security

You must:

6.4 International Transfers

If transferring data to us from the EEA, you must:

7. DATA TRANSFERS

7.1 Transfer Mechanisms

For international data transfers, we rely on:

7.2 Supplementary Measures

We implement supplementary measures including:

7.3 Government Access Requests

We will:

8. DATA RETENTION AND DELETION

8.1 Retention Periods

We retain Personal Data:

8.2 Deletion Procedures

Upon termination of services:

8.3 Data Return

You may request return of your data at any time through Platform export features.

9. AUDIT RIGHTS

9.1 Audit Scope

You have the right to audit our compliance with this DPA, subject to:

9.2 Audit Methods

Audits may be conducted through:

9.3 Third-Party Audits

We undergo regular third-party security audits and will share:

9.4 Cost Allocation

You bear costs of audits, except where audits reveal material non-compliance.

10. LIABILITY AND INDEMNIFICATION

10.1 Liability Allocation

Each party is liable for its own violations of data protection laws.

10.2 Indemnification

You agree to indemnify us against claims arising from:

10.3 Limitation of Liability

Subject to applicable law, our liability under this DPA is limited as per the Terms of Service.

11. TERM AND TERMINATION

11.1 Term

This DPA remains in effect while we process Personal Data on your behalf.

11.2 Termination

Either party may terminate if:

11.3 Survival

Sections on confidentiality, liability, and data protection survive termination.

12. GOVERNING LAW AND DISPUTES

12.1 Governing Law

This DPA is governed by Queensland, Australia law, without regard to conflict of law principles.

12.2 Dispute Resolution

Disputes will be resolved as per the Terms of Service.

12.3 Supervisory Authority

For GDPR matters, the supervisory authority is the Office of the Australian Information Commissioner (OAIC), acting as lead authority for cross-border processing.

13. CONTACT INFORMATION

13.1 Data Protection Officer

Our Data Protection Officer can be contacted at: Email: dpo@launchr.bot
Address: 81-83 Campbell St, Surry Hills NSW 2010

13.2 General Contact

Launchr Pty Ltd
81-83 Campbell St, Surry Hills NSW 2010
ABN: 46 696 518 206
Website: launchr.bot

14. SCHEDULES

Schedule A: Technical and Organisational Measures

Technical Measures:

  1. Encryption: AES-256 encryption at rest, TLS 1.2+ in transit
  2. Access Controls: Role-based access control, multi-factor authentication
  3. Network Security: Firewalls, intrusion detection, DDoS protection
  4. Monitoring: Regular security log review and scheduled automated scanning during Australian business hours (AEST 9:00–17:00, Mon–Fri, excluding public holidays). Incident detection and response operates during business hours with after-hours escalation for critical incidents via third-party status services.
  5. Backup: Regular backups, geographic redundancy

Organisational Measures:

  1. Policies: Data protection policy, security policy, incident response plan
  2. Training: Regular employee training on data protection
  3. Audits: Regular internal and external security audits
  4. Incident Response: Documented procedures for security incidents
  5. Vendor Management: Due diligence on Sub-processors

Schedule B: Sub-processor List

| Sub-processor | Service | Location | Data Transferred | Safeguards | |---------------|---------|----------|------------------|------------| | Stripe | Payment processing | Global (US-based) | Payment information | SCCs, encryption | | Anthropic | Agent (AI) processing | United States | Content and communications submitted for processing | SCCs, encryption | | Cloudflare | Hosting and infrastructure | Global (US-based, AU points of presence) | All Platform data | SCCs, encryption | | Resend | Email communications | Global (US-based) | Email addresses, content | SCCs, encryption | | Twilio | Telephony and SMS | United States | Phone numbers, call/message content | SCCs, encryption | | ElevenLabs | Voice synthesis | United States | Call audio, transcripts | SCCs, encryption |

Schedule C: International Transfer Mechanisms

| Transfer Scenario | Mechanism | Supplementary Measures | |------------------|-----------|------------------------| | EEA to Australia | SCCs | Encryption, access controls, audit rights | | UK to Australia | UK SCCs | Encryption, access controls, audit rights | | Switzerland to Australia | Swiss SCCs | Encryption, access controls, audit rights | | Other countries | SCCs or BCRs | Case-by-case assessment |