Skip to content
TradePilot
Features Pricing Why TradePilot Contact Help Centre Log in Book a demo
Home/Legal & Privacy/Data Processing Terms
TRADEPILOT LEGAL & PRIVACY

Data Processing Terms

The processing arrangements for personal information that a customer entrusts to TradePilot as part of its workspace.

Published 20 September 2026Version 2026-09-R1
On this page +
  1. 1. Application, definitions and priority
  2. 2. Documented instructions and permitted use
  3. 3. Confidentiality and personnel
  4. 4. Security measures
  5. 5. Subprocessors and customer-selected integrations
  6. 6. Individual rights and compliance assistance
  7. 7. Personal Data Breach notification
  8. 8. International processing and transfer safeguards
  9. 9. Information, audit and assurance
  10. 10. Return, deletion and retained copies
  11. Annex A. Description of processing
  12. Annex B. Minimum security control objectives
← All policies & terms

1. Application, definitions and priority

These Data Processing Terms (DPT) form part of the accepted agreement between TradePilot Pty Ltd and the Customer when TradePilot processes Customer Personal Data: personal information contained in Customer Data on the Customer's behalf.

Applicable Data Protection Law means the privacy and data-protection laws applying to the relevant processing, including the Australian Privacy Act where applicable and the EU GDPR or UK GDPR where either actually applies. A Personal Data Breach is a security breach leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to Customer Personal Data.

The Customer determines its processing purposes and instructions. Where those legal concepts apply, the Customer is controller and TradePilot is processor, or TradePilot is a subprocessor where the Customer acts for another controller. The Customer must have authority for its instructions. TradePilot's separate handling of its own business, billing and service-security records is described in the Privacy Policy.

For processing matters, these DPT take priority over conflicting general Terms. Mandatory law and any valid mandatory transfer clauses take priority over both. Mandatory duties apply even if an annex or commercial arrangement needs further detail; neither party may rely on an incomplete document to avoid the law.

2. Documented instructions and permitted use

TradePilot processes Customer Personal Data only on documented lawful instructions, including the accepted agreement, configured features, authorised user actions and additional instructions agreed in writing. Processing is limited to delivering, supporting, securing and administering the agreed Service and legally required handling.

TradePilot will inform the Customer if, in its opinion, an instruction infringes Applicable Data Protection Law and may suspend that instruction until resolved. Where processing beyond instructions is required by law, TradePilot gives prior notice unless legally prohibited. For processing governed by GDPR Article 28(3)(a), the legal-requirement exception is limited as that provision requires; other demands are assessed under applicable data-protection and transfer law rather than automatically overriding instructions.

There is no general permission to sell Customer Personal Data, use it for unrelated marketing or train general-purpose models on identifiable or confidential records. A new incompatible purpose requires its own lawful basis, appropriate notice and any required agreement or consent.

3. Confidentiality and personnel

TradePilot limits access to personnel and service providers who need it for an authorised purpose. Personnel authorised to process Customer Personal Data must be subject to appropriate confidentiality obligations and given guidance appropriate to their roles. Access and authorisation must be managed and removed when no longer needed.

Support access and information requested for troubleshooting must be proportionate. Neither party should disclose live passwords or unnecessary personal records in support correspondence.

4. Security measures

TradePilot must implement and maintain technical and organisational measures appropriate to the nature of processing and risk, taking account of the state of the art, implementation cost and potential consequences for individuals. Where GDPR applies, this includes the measures required by Article 32.

The minimum control objectives are described in Annex B. They are contractual requirements rather than a certification or a claim that every possible security product is installed. Measures may evolve, but changes must not materially reduce the overall protection required by this agreement and law.

The Customer manages the matters within its control, including data minimisation, recipient selection, permissions, lawful instructions and its own devices and integrations. TradePilot's own obligations remain in place.

5. Subprocessors and customer-selected integrations

The Customer generally authorises TradePilot to appoint subprocessors disclosed for the relevant processing before they are engaged. TradePilot must maintain and make available their identities, functions and processing locations. The public Service Providers page identifies a website subset and is not a substitute for a complete deployment-specific subprocessor schedule.

TradePilot must impose written obligations offering at least the protection required for the relevant processing under these DPT and remains responsible for its appointed subprocessors' performance to the extent required by Applicable Data Protection Law. A customer-selected independent integration is distinguished from a provider appointed by TradePilot; the label does not remove obligations that actually apply.

TradePilot gives at least 30 days' advance notice of a planned new or replacement subprocessor that will process Customer Personal Data, allowing reasonable data-protection objections. Where an urgent security, legal or continuity need makes that impracticable, notice is given as early as practicable and the Customer still has a meaningful opportunity to object; processing must not proceed where applicable law requires prior authorisation that has not been obtained.

The parties discuss a timely, reasonable objection in good faith and consider a practicable alternative. If no appropriate resolution is possible, the Customer may terminate the affected service without an additional termination penalty and receive a pro-rata refund for its unused prepaid period. This does not require disclosure of other customers' confidential information.

6. Individual rights and compliance assistance

Taking account of the processing and information available to it, TradePilot assists the Customer with access, correction, erasure, restriction, portability, objection and other rights that apply. It promptly forwards a request relating to Customer Personal Data where the Customer should handle it, while meeting any direct legal duty of its own.

TradePilot provides reasonable information and assistance concerning security, breach assessment and notification, data-protection impact assessments and prior consultation with regulators, including assistance required by GDPR Articles 32 to 36 where applicable.

Routine compliance information is provided without a separate charge. Exceptional additional assistance may be charged at a reasonable rate only where lawful and agreed in advance. TradePilot does not charge for remedying its own breach or make an urgent mandatory duty conditional on agreeing a fee.

7. Personal Data Breach notification

TradePilot notifies the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data in its processing. This obligation does not depend on TradePilot first deciding that the breach poses a serious-harm or high-risk threshold. Unsuccessful attacks that do not compromise Customer Personal Data are not automatically Personal Data Breaches.

As information becomes available, the notice describes the nature of the breach, affected categories and approximate numbers of individuals and records where known, likely consequences, measures taken or proposed and a contact for follow-up. Information may be provided in stages without undue further delay; initial notice is not withheld until the investigation is complete.

TradePilot takes appropriate containment and remediation steps, preserves relevant evidence and cooperates with the Customer. The Customer keeps an effective incident contact and handles its own notification duties. Neither party prevents the other's legally required notification or assumes it can contract out of a duty to individuals or a regulator.

Where GDPR applies, the controller's possible 72-hour regulator-notification deadline is separate from the processor's duty to notify the controller without undue delay. Australian assessment and notification requirements are addressed in the Privacy Policy and do not replace this processor notice obligation.

8. International processing and transfer safeguards

Processing locations and overseas access must be disclosed for the actual services, support arrangements and subprocessors in use. Neither party assumes that Australian hosting alone resolves international-transfer requirements. TradePilot complies with applicable restrictions and assists the Customer with relevant information.

Where a transfer requires EU standard contractual clauses, a UK international data transfer agreement or addendum, an adequacy basis or another valid safeguard, the appropriate instrument and annexes must be completed and the required transfer assessment undertaken before that transfer proceeds. Merely referring to such an instrument here does not execute it or make an otherwise unlawful transfer lawful.

Customers with EU/UK or other restricted-transfer requirements must raise them before the affected processing so that scope, roles, subprocessors, security details and safeguards can be completed. This is not a promise of EEA-only, UK-only or Australia-only processing.

9. Information, audit and assurance

TradePilot makes available information reasonably necessary to demonstrate compliance with these DPT and permits and contributes to audits, including inspections, by the Customer or a suitably qualified independent auditor it appoints where required by law.

The parties ordinarily begin with relevant documentation and remote review and arrange any further audit on reasonable notice, during normal business hours and subject to proportionate confidentiality, safety and third-party privacy safeguards. These arrangements must not prevent a required or justified audit, including after a significant incident, evidence of non-compliance or a regulator's request.

An auditor cannot receive another customer's records or unnecessary security secrets. Existing assurance materials may be used where adequate, but TradePilot may not insist that a generic certificate replaces a legally required audit. Each party bears its ordinary costs; any exceptional charge must be lawful and agreed in advance and cannot obstruct mandatory oversight. TradePilot bears reasonable additional costs caused by its demonstrated material non-compliance.

10. Return, deletion and retained copies

At the Customer's choice, TradePilot returns or deletes Customer Personal Data at the end of the processing services and deletes remaining copies, except where Applicable Data Protection Law permits or requires retention. The Terms provide a 30-day window to request an export of data still held, but do not remove a mandatory return or deletion right or justify delay beyond what the law allows.

TradePilot informs the Customer about available export formats, expected deletion timing and justified exceptions. Protected backup copies are restricted from ordinary processing and deleted through a documented, appropriate retention cycle. If the law requires earlier deletion, backup convenience does not override it. Restoring a backup must not permanently reinstate data that should have been deleted.

Any legally retained data remains protected, used only for the permitted retention purpose and deleted when that purpose ends. TradePilot provides reasonable confirmation of completion on request. These DPT continue to protect retained data until it is lawfully deleted or effectively de-identified.

Annex A. Description of processing

Subject matter and purpose
Provision, support, security and administration of the Customer's configured TradePilot trade-business workspace.
Nature of operations
Collection through authorised use and imports; storage; organisation; retrieval; display; editing; document generation; calculations and extraction where enabled; controlled sharing and messaging; integration synchronisation; recovery; export and deletion.
Duration and frequency
As required during the service term, with continuing protection during agreed export, lawful retention and deletion. Processing is ongoing or triggered by customer use, service operation or a particular instruction.
Categories of people
Customer administrators, staff, apprentices, contractors, customers, suppliers, site contacts, emergency contacts and other people lawfully included in the Customer's records.
Types of information
Contact and identity details; workforce, licence and time records; customer, job, site, asset, communication, commercial and accounting records; uploaded media and documents; signatures; and associated identifiers and metadata, limited by the enabled features.
Sensitive information
Limited health, allergy or safety information and sensitive content in lawful workforce or job records where necessary. Such processing requires an appropriate legal basis, minimisation and restricted access. No general instruction to process unrelated specially regulated data is given.
Customer rights and duties
Determine lawful purposes and instructions, provide required notices and consents, manage authorised access, request assistance and assurance, choose return or deletion and comply with the agreement and applicable law.
Contacts and further detail
The Customer's designated account/privacy contact and TradePilot at sales@tradepilot.com.au. A negotiated Order or processing schedule must record any additional deployment-specific requirements, subprocessors and transfer information before the relevant processing.

Annex B. Minimum security control objectives

  • Access and confidentiality: authenticated, authorised access, proportionate least-privilege permissions, separation of customer access, personnel confidentiality and timely access removal.
  • Transmission and storage: appropriate protection for information in transit and at rest, selected for the data, system and risks; effective management of credentials and privileged access.
  • Operations: reasonable maintenance and vulnerability management, proportionate logging and monitoring, controlled changes and management of service-provider access.
  • Resilience and recovery: appropriate arrangements to protect availability and integrity and restore access where needed; documented recovery and retention arrangements and appropriate checks of their effectiveness.
  • Information lifecycle: data minimisation, authorised disclosure, secure export and disposal and controls against unnecessary retention.
  • Response and review: procedures to identify, assess and respond to incidents, provide required notifications, train relevant personnel and review whether controls remain appropriate.

These objectives do not specify a recovery-time guarantee, backup interval, particular cryptographic algorithm or certification. Any required measurable commitment must be recorded in the agreed technical schedule. Where applicable law requires more specific or stronger measures, that law prevails.

TradePilot Pty Ltd · 2026-09-R1

Back to top ↑
TradePilot

Job management, scheduling, commercial controls, compliance and field workflows for trade businesses.

PlatformFeaturesPricingBook a demo
CompanyWhy TradePilotContactHelp Centre
Contactsales@tradepilot.com.auCustomer loginAustralia
Legal & Privacy
© 2026 TradePilot Pty Ltd. All rights reserved.
Site by Grape Tech