Data Processing Agreement — Launchr
1. AGREEMENT OVERVIEW
This Data Processing Agreement ("DPA") forms part of the Terms of Service for Launchr platform. It applies when you process personal data subject to the EU General Data Protection Regulation (GDPR) or similar data protection laws.
1A. AN AGENT-DRIVEN COMPANY
Launchr is an Agent-driven company. Our Agents — artificial intelligence (AI) systems — perform much of the Processor's work under this DPA, including automated processing of Personal Data, subject to human verification and the technical and organisational measures described in Schedule A. AI systems can make mistakes; we take all reasonable steps to catch errors before they affect Personal Data. Liability under this DPA is allocated in section 10 of this DPA and limited as set out in sections 10 and 11 of the Terms of Service, which do not exclude rights that cannot lawfully be excluded.
2. DEFINITIONS
2.1 GDPR Definitions
- "Controller" means the entity that determines the purposes and means of processing personal data (you, the customer).
- "Processor" means the entity that processes personal data on behalf of the Controller (Launchr Pty Ltd).
- "Personal Data" means any information relating to an identified or identifiable natural person.
- "Processing" means any operation performed on personal data.
- "Data Subject" means the individual to whom personal data relates.
- "Sub-processor" means a third-party processor engaged by the Processor.
2.2 Agreement Definitions
- "Platform" means Launchr software-as-a-service platform.
- "Services" means the services provided under the Terms of Service.
- "Business Data" means data uploaded, processed, or generated through use of the Platform.
3. ROLES AND RESPONSIBILITIES
3.1 Controller Responsibilities
As Controller, you are responsible for:
- Determining the lawful basis for processing
- Obtaining necessary consents from Data Subjects
- Responding to Data Subject requests
- Ensuring accuracy of Personal Data
- Implementing appropriate security measures
3.2 Processor Responsibilities
As Processor, we are responsible for:
- Processing Personal Data only as instructed by you
- Implementing appropriate technical and organisational measures
- Assisting you with Data Subject requests
- Notifying you of data breaches
- Maintaining records of processing activities
3.3 Joint Responsibilities
Both parties are responsible for:
- Cooperating with supervisory authorities
- Ensuring compliance with applicable data protection laws
- Implementing appropriate safeguards for international transfers
4. PROCESSING DETAILS
4.1 Subject Matter
Processing of Personal Data through the Platform for the purposes of providing the Services.
4.2 Duration
For the duration of your subscription to the Platform.
4.3 Nature and Purpose
Processing necessary to provide the Platform services, including:
- Account management and authentication
- Customer relationship management
- Communication services (email, SMS)
- Payment processing
- Analytics and service improvement
4.4 Types of Personal Data
May include:
- Contact information (name, email, phone)
- Business information (company, position)
- Payment information (processed by Stripe)
- Communication content (messages, emails)
- Usage data (IP address, browser information)
4.5 Categories of Data Subjects
May include:
- Your customers and prospects
- Your employees and contractors
- Other individuals you interact with through the Platform
5. PROCESSOR OBLIGATIONS
5.1 Processing Instructions
We will:
- Process Personal Data only according to your documented instructions
- Not process Personal Data for our own purposes
- Notify you if we believe your instructions violate data protection laws
5.2 Confidentiality
We will:
- Ensure persons authorised to process Personal Data are bound by confidentiality
- Implement access controls and authentication
- Regularly review and update security measures
5.3 Security Measures
We implement appropriate technical and organisational measures including:
Technical Measures:
- Encryption of data in transit (TLS 1.2+)
- Encryption of data at rest (AES-256)
- Network security and firewalls
- Regular security assessments
- Vulnerability management
Organisational Measures:
- Data protection policies and procedures
- Employee training and awareness
- Access controls and authentication
- Incident response procedures
- Regular security reviews
5.4 Sub-processing
5.4.1 Authorised Sub-processors
You authorise us to engage the following Sub-processors:
| Sub-processor | Purpose | Location | Safeguards | |---------------|---------|----------|------------| | Stripe | Payment processing | Global (US-based) | Standard Contractual Clauses | | Anthropic | Agent (AI) processing — see section 1A | United States | Standard Contractual Clauses, encryption | | Cloudflare | Hosting and infrastructure | Global (US-based, Australian points of presence) | Standard Contractual Clauses, encryption | | Resend | Email communications | Global (US-based) | Standard Contractual Clauses | | Twilio | Telephony and SMS | United States | Standard Contractual Clauses | | ElevenLabs | Voice synthesis | United States | Standard Contractual Clauses |
5.4.2 Sub-processor Requirements
We will:
- Ensure Sub-processors provide sufficient guarantees
- Impose data protection obligations on Sub-processors
- Remain liable for Sub-processor compliance
- Notify you of new Sub-processors (30 days' notice)
- Allow you to object to new Sub-processors
5.5 Data Subject Rights
We will:
- Assist you in responding to Data Subject requests
- Implement technical measures to facilitate rights fulfilment
- Not respond directly to Data Subjects (unless required by law)
- Notify you of Data Subject requests received by us
5.6 Data Breach Notification
We will:
- Notify you without undue delay of any data breach
- Provide information to assist your breach assessment
- Cooperate with your investigation and response
- Implement corrective measures
5.7 Data Protection Impact Assessment
We will:
- Provide reasonable assistance with your DPIA requirements
- Share information about our security measures
- Cooperate with supervisory authorities
5.8 Records of Processing
We maintain records of processing activities as required by Article 30 of the GDPR.
6. CONTROLLER OBLIGATIONS
6.1 Lawful Basis
You must:
- Establish and document lawful basis for processing
- Obtain necessary consents from Data Subjects
- Maintain records of consent
- Respect Data Subject rights
6.2 Instructions
You must:
- Provide clear, lawful processing instructions
- Not instruct us to process data unlawfully
- Update instructions as needed
6.3 Security
You must:
- Implement appropriate security measures on your side
- Protect your account credentials
- Monitor your account for unauthorised access
6.4 International Transfers
If transferring data to us from the EEA, you must:
- Ensure appropriate safeguards are in place
- Comply with GDPR Chapter V requirements
- Document the transfer mechanism
7. DATA TRANSFERS
7.1 Transfer Mechanisms
For international data transfers, we rely on:
- Standard Contractual Clauses (EU Commission approved)
- Binding Corporate Rules (where applicable)
- Adequacy Decisions (where applicable)
- Other approved mechanisms
7.2 Supplementary Measures
We implement supplementary measures including:
- Technical measures (encryption, pseudonymisation)
- Organisational measures (policies, training)
- Contractual measures (DPA provisions)
7.3 Government Access Requests
We will:
- Challenge government access requests where appropriate
- Notify you of government access requests (unless prohibited)
- Minimise data disclosed to government authorities
8. DATA RETENTION AND DELETION
8.1 Retention Periods
We retain Personal Data:
- For the duration of your subscription
- As required by law or regulation
- For legitimate business purposes
8.2 Deletion Procedures
Upon termination of services:
- We will delete or return Personal Data as instructed
- Deletion will occur within 30 days
- Backups will be deleted according to backup rotation schedule
8.3 Data Return
You may request return of your data at any time through Platform export features.
9. AUDIT RIGHTS
9.1 Audit Scope
You have the right to audit our compliance with this DPA, subject to:
- Reasonable notice (minimum 30 days)
- Conduct during business hours
- Confidentiality obligations
- No disruption to our operations
9.2 Audit Methods
Audits may be conducted through:
- Review of security certifications
- Review of audit reports
- Questionnaires and interviews
- On-site inspection (if justified)
9.3 Third-Party Audits
We undergo regular third-party security audits and will share:
- Summary audit reports
- Certifications (ISO 27001, SOC 2, etc.)
- Evidence of compliance
9.4 Cost Allocation
You bear costs of audits, except where audits reveal material non-compliance.
10. LIABILITY AND INDEMNIFICATION
10.1 Liability Allocation
Each party is liable for its own violations of data protection laws.
10.2 Indemnification
You agree to indemnify us against claims arising from:
- Your violation of data protection laws
- Your unlawful processing instructions
- Your failure to obtain necessary consents
10.3 Limitation of Liability
Subject to applicable law, our liability under this DPA is limited as per the Terms of Service.
11. TERM AND TERMINATION
11.1 Term
This DPA remains in effect while we process Personal Data on your behalf.
11.2 Termination
Either party may terminate if:
- The other party materially breaches this DPA
- Required by law or regulation
- Mutual agreement
11.3 Survival
Sections on confidentiality, liability, and data protection survive termination.
12. GOVERNING LAW AND DISPUTES
12.1 Governing Law
This DPA is governed by Queensland, Australia law, without regard to conflict of law principles.
12.2 Dispute Resolution
Disputes will be resolved as per the Terms of Service.
12.3 Supervisory Authority
For GDPR matters, the supervisory authority is the Office of the Australian Information Commissioner (OAIC), acting as lead authority for cross-border processing.
13. CONTACT INFORMATION
13.1 Data Protection Officer
Our Data Protection Officer can be contacted at:
Email: dpo@launchr.bot
Address: 81-83 Campbell St, Surry Hills NSW 2010
13.2 General Contact
Launchr Pty Ltd
81-83 Campbell St, Surry Hills NSW 2010
ABN: 46 696 518 206
Website: launchr.bot
14. SCHEDULES
Schedule A: Technical and Organisational Measures
Technical Measures:
- Encryption: AES-256 encryption at rest, TLS 1.2+ in transit
- Access Controls: Role-based access control, multi-factor authentication
- Network Security: Firewalls, intrusion detection, DDoS protection
- Monitoring: Regular security log review and scheduled automated scanning during Australian business hours (AEST 9:00–17:00, Mon–Fri, excluding public holidays). Incident detection and response operates during business hours with after-hours escalation for critical incidents via third-party status services.
- Backup: Regular backups, geographic redundancy
Organisational Measures:
- Policies: Data protection policy, security policy, incident response plan
- Training: Regular employee training on data protection
- Audits: Regular internal and external security audits
- Incident Response: Documented procedures for security incidents
- Vendor Management: Due diligence on Sub-processors
Schedule B: Sub-processor List
| Sub-processor | Service | Location | Data Transferred | Safeguards | |---------------|---------|----------|------------------|------------| | Stripe | Payment processing | Global (US-based) | Payment information | SCCs, encryption | | Anthropic | Agent (AI) processing | United States | Content and communications submitted for processing | SCCs, encryption | | Cloudflare | Hosting and infrastructure | Global (US-based, AU points of presence) | All Platform data | SCCs, encryption | | Resend | Email communications | Global (US-based) | Email addresses, content | SCCs, encryption | | Twilio | Telephony and SMS | United States | Phone numbers, call/message content | SCCs, encryption | | ElevenLabs | Voice synthesis | United States | Call audio, transcripts | SCCs, encryption |
Schedule C: International Transfer Mechanisms
| Transfer Scenario | Mechanism | Supplementary Measures | |------------------|-----------|------------------------| | EEA to Australia | SCCs | Encryption, access controls, audit rights | | UK to Australia | UK SCCs | Encryption, access controls, audit rights | | Switzerland to Australia | Swiss SCCs | Encryption, access controls, audit rights | | Other countries | SCCs or BCRs | Case-by-case assessment |