Data Processing Agreement
Last modified: February 10, 2026
This document (Data Processing Agreement or DPA) sets out the terms and conditions governing the Processing of Revamp Biz Personal Data by us in connection with your use of our services.
In this DPA, “we”, “us” and “our” refers to Genius Level Pty Ltd t/a Revamp Biz ABN 36 661 536 232 (Revamp Biz), and “you” and “your” refers to an Revamp Biz client, being a user of Revamp Biz’s services under the applicable master agreement, online terms of service or services agreement (the Agreement).
By using Revamp Biz’s services or by otherwise indicating your assent, you accept and agree to this DPA.
1. Definitions and interpretation
The terms used in this DPA are defined below or in the EU GDPR / UK GDPR, as applicable.
Revamp Biz Personal Data means any personal data regarding an identified or identifiable natural person which are or will be Processed by us in any way whatsoever in the context of the use of Revamp Biz’s services by you, any of your organisations, employees, agents or contractors authorised or deemed to be authorised by you.
Contracted Processor means us or a Subprocessor.
Data Breach means a personal data breach within the meaning of Article 4(12) of the GDPR.
Data Protection Laws means all applicable data protection or privacy laws of any country, including, where applicable:
- the EU General Data Protection Regulation (Regulation (EU) 2016/679) (EU GDPR);
- the UK General Data Protection Regulation, as incorporated into UK law by the European Union (Withdrawal) Act 2018, and the Data Protection Act 2018 (UK) (UK GDPR); and
- any laws implementing, supplementing or replacing any of the above.
Data Subject means the person to whom Revamp Biz Personal Data relates.
EU Data Protection Laws means the EU GDPR and any implementing or supplementing laws in EU/EEA member states.
Terms of Service means our website and platform terms and conditions and/or any other online terms or services agreement into which this DPA is incorporated or which references this DPA.
GDPR means, as applicable, the EU GDPR and/or the UK GDPR.
Parties means you and us.
Processing means any operation or set of operations performed on personal data, whether or not by automated means, including collecting, recording, organising, structuring, storing, adapting or altering, retrieving, consulting, using, disclosing, disseminating or otherwise making available, aligning or combining, restricting, erasing or destroying (“Process”, “Processes” and “Processed” have corresponding meanings).
Subprocessor means any person (including any third party, but excluding our employees, contractors or professional advisors) appointed by or on behalf of us to Process Revamp Biz Personal Data.
Supervisory Authority means an independent public authority established by a member state of the European Union or the United Kingdom, or any replacement authority, responsible for monitoring the application of Data Protection Laws.
Capitalised terms not defined in this DPA have the meaning given to them in the Agreement.
2. Processing of Revamp Biz Personal Data
2.1 Role of the Parties
The Parties agree that, in relation to the Processing of Revamp Biz Personal Data:
- you are the Controller;
- we are the Processor;
- we may engage Subprocessors in accordance with clause 3; and
- users, your organisations, employees, agents or contractors using Revamp Biz’s services and providing Revamp Biz Personal Data are Data Subjects.
2.2 Our obligations
We agree that:
- We will comply with applicable Data Protection Laws in the Processing of Revamp Biz Personal Data.
- We will not Process Revamp Biz Personal Data other than on your documented instructions, unless such Processing is required by Data Protection Laws to which the relevant Contracted Processor is subject. In that case, to the extent permitted by law, we will inform you of that legal requirement before Processing.
- We will only Process Revamp Biz Personal Data to the extent necessary to provide the Revamp Biz services and any related services to you in accordance with the Agreement.
- We will not Process Revamp Biz Personal Data for our own benefit, for the benefit of any third party, or for our own purposes (including advertising or profiling) except as required by Data Protection Laws or as strictly necessary for security, fraud prevention, service improvement or compliance (and, in those cases, always in line with Data Protection Laws).
- We will notify you of material changes to our Processing activities relevant to Revamp Biz Personal Data if such changes are reasonably likely to impact your ability to comply with Data Protection Laws.
- Annexure 1 to this DPA sets out certain information regarding our Processing of Revamp Biz Personal Data as required by Article 28(3) GDPR (and equivalent requirements under other Data Protection Laws). Nothing in Annexure 1 confers any rights or imposes obligations on either Party beyond those in this DPA and the Agreement.
2.3 Your obligations
You agree that:
- You, as an Revamp Biz client and on behalf of each of your organisations, employees, agents or contractors authorised or deemed to be authorised by you, instruct us (and authorise us to instruct each Subprocessor) to Process Revamp Biz Personal Data as necessary to provide the services under the Agreement and as otherwise described in this DPA.
- You warrant and represent that you are and will remain duly and effectively authorised to give the instruction set out in clause 2.3(1) on behalf of each such organisation, employee, agent or contractor.
- In your use of Revamp Biz’s services, you will Process and otherwise deal with Revamp Biz Personal Data in accordance with Data Protection Laws. Your instructions for Processing Revamp Biz Personal Data must comply with Data Protection Laws.
- You have sole responsibility for the accuracy, quality, and legality of Revamp Biz Personal Data and the means by which such data are collected, including any notices to, and consents from, Data Subjects.
3. Use of subprocessors
3.1 You authorise us to appoint (and permit each Contracted Processor to appoint) Subprocessors in accordance with this clause 3.
3.2 We may continue to use those Subprocessors already engaged by us as at the effective date of this DPA, subject to us meeting the obligations set out in clause 3.4.
3.3 We will give you prior written notice (which may be via our website or email) of the appointment of any new Subprocessor, including details of the Processing to be undertaken by that Subprocessor. If, within 5 days of receipt of that notice, you notify us in writing of any reasonable objections to the proposed appointment, we will not appoint (or disclose Revamp Biz Personal Data to) that proposed Subprocessor until we have taken reasonable steps to address your objections and have provided you with a written explanation of those steps.
3.4 With respect to each Subprocessor, we will:
- carry out appropriate due diligence to ensure that the Subprocessor is capable of providing the level of protection for Revamp Biz Personal Data required by this DPA and Data Protection Laws;
- ensure that the arrangement between us and the Subprocessor is governed by a written contract including terms which offer at least the same level of protection for Revamp Biz Personal Data as those set out in this DPA and which meet the requirements of Article 28(3) GDPR (or equivalent under other Data Protection Laws); and
- on request, provide you with copies of relevant Subprocessor data protection terms (which may be redacted to remove confidential commercial information not relevant to this DPA).
3.5 We will ensure that each Subprocessor performs the obligations under this DPA as they apply to Processing of Revamp Biz Personal Data carried out by that Subprocessor, as if it were a party to this DPA in our place.
4. Security
4.1 We will implement appropriate technical and organisational measures to secure Revamp Biz Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, such data.
4.2 Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of Processing, as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, these measures will ensure a level of security appropriate to the risk, in accordance with Article 32 GDPR.
4.3 We will document these security measures and, on reasonable request, make a summary of such measures available to you.
4.4 On request, we will provide you with reasonable information relating to the security of Revamp Biz Personal Data, to the extent necessary for you to meet your obligations under Data Protection Laws.
5. Data breaches
5.1 We will notify you without undue delay after becoming aware of a Data Breach affecting Revamp Biz Personal Data, providing sufficient information to allow you to meet any obligations to report or inform Data Subjects or Supervisory Authorities under Data Protection Laws.
5.2 At a minimum, such notification will:
- describe the nature of the Data Breach;
- provide the categories and approximate number of Data Subjects and personal data records concerned (where reasonably known);
- describe likely consequences; and
- describe the measures taken or proposed to address the Data Breach and mitigate its possible adverse effects.
5.3 We will co‑operate with you and take such reasonable commercial steps as are directed by you to assist in the investigation, mitigation and remediation of each Data Breach, to the extent required by Data Protection Laws.
6. Data subject rights
6.1 To the extent permitted by Data Protection Laws, we will promptly notify you if we receive any request from a Data Subject under Data Protection Laws in respect of Revamp Biz Personal Data, including requests to exercise rights of access, rectification, restriction, erasure, data portability, objection, or rights relating to automated decision‑making (each a Data Subject Request).
6.2 Taking into account the nature of the Processing, we will assist you by appropriate technical and organisational measures, insofar as this is possible, to enable you to respond to Data Subject Requests under Data Protection Laws.
6.3 To the extent you do not have the ability to address a Data Subject Request, we will, upon your request, provide commercially reasonable assistance to help you respond, to the extent we are permitted to do so under Data Protection Laws.
6.4 To the extent permitted by law, you will be responsible for any reasonable costs arising from our assistance under this clause 6.
7. Data protection impact assessment and prior consultation
8.1 We will retain Revamp Biz Personal Data only:
- for the period necessary to perform the Agreement; and/or
- for as long as required by applicable law.
8.2 Where we retain Revamp Biz Personal Data because we are required to do so by law, we will use reasonable endeavours to ensure the confidentiality of such data and Process it only as necessary for the purpose(s) specified in the law requiring its retention.
8.3 We will not retain Revamp Biz Personal Data for longer than is necessary for the purposes set out above.
8. Retention of data
8.1 We will retain Genius Level Personal Data to the extent required by law and only to the extent and for such period as required by law and always provided that we will use our reasonable endeavours to ensure the confidentiality of all such Genius Level Personal Data and to ensure that such Genius Level Personal Data is only retained as necessary for the purpose(s) specified in the laws requiring its storage and for no other purpose.
8.2 We will not retain Genius Level Personal Data made available to us any longer than is necessary:
- for the performance of the Agreement; or
- to comply with any of our obligations at law.
9. Audit
9.1 Subject to clause 9.2, we will allow for and contribute to audits, including inspections, by you or an auditor mandated by you, relating to the Processing of Revamp Biz Personal Data by Contracted Processors, as required by Article 28(3)(h) GDPR.
9.2 You must give us reasonable prior written notice of any audit or inspection and use reasonable endeavours (and ensure that any mandated auditor uses reasonable endeavours) to minimise disruption to our business. A Contracted Processor is not required to give access:
- to any individual unless they produce reasonable evidence of identity and authority;
- to premises outside normal business hours, unless the audit must be conducted on an emergency basis and you have given us notice that this is the case; or
- for more than one audit or inspection per calendar year in respect of each Contracted Processor, except where:
- you reasonably consider an additional audit necessary due to genuine concerns regarding our compliance with this DPA; or
- you are required to carry out an additional audit by Data Protection Laws, a Supervisory Authority, or similar regulatory authority, and you identify the relevant requirement in your notice to us.
9.3 The costs of any audit or inspection requested by you under clause 9.1 will be borne by you.
9.4 If it is established during an audit that we have failed to comply with this DPA, we will take all reasonably necessary measures to remedy such non‑compliance.
10. International transfers
10.1 You acknowledge and agree that Revamp Biz Personal Data may be Processed in, and transferred to, countries outside the country in which the data were originally collected, including Australia, the European Economic Area (EEA), the United Kingdom, and other countries in which we or our Subprocessors operate, provided that such transfers comply with Data Protection Laws.
10.2 Where required by EU GDPR for transfers of personal data from the EEA to a country that does not provide an adequate level of protection, the Parties agree that the Standard Contractual Clauses (SCCs) adopted by the European Commission (as updated or replaced from time to time) are incorporated by reference and will apply as follows:
- you are the “data exporter”;
- we are the “data importer”; and
- the subject matter, categories of data, and Data Subjects are described in Annexure 1.
10.3 Where required by UK GDPR for transfers of personal data from the UK to a country that does not provide an adequate level of protection, the Parties agree that:
- the ICO International Data Transfer Agreement (IDTA) or
- the ICO International Data Transfer Addendum to the EU SCCs,
as applicable and as updated from time to time, will apply and are incorporated by reference.
10.4 If any additional or alternative transfer mechanism is required under Data Protection Laws (e.g. additional safeguards or updated SCCs), the Parties will work together in good faith to implement such mechanism.
11. Requests from authorities
11.1 If we receive a request or order from a Supervisory Authority, government agency or investigation, prosecution or national security agency to provide or allow access to Revamp Biz Personal Data, we will, to the extent permitted by law, promptly notify you.
11.2 When handling such request or order, we will (to the extent permitted by law) comply with your reasonable instructions and co‑operate with you as reasonably required.
12. Data Subjects and privacy information
12.1 We will co‑operate, insofar as possible, so that you may comply with your legal obligations in the event that a Data Subject exercises their rights under GDPR or other applicable Data Protection Laws.
12.2 If a Data Subject contacts us directly exercising rights in respect of Revamp Biz Personal Data for which you are the Controller, we will, where appropriate, advise them to direct the request to you and will notify you without undue delay.
12.3 Our Privacy Policy, available at [insert URL], is incorporated by reference and includes information about:
- our identity and contact details;
- the purposes for which we Process personal data;
- the categories of personal data we Process;
- the categories of recipients of personal data;
- the countries in which personal data may be Processed; and
- Data Subjects’ rights in relation to their personal data.
13. Limitation of liability
To the extent permitted by law, our liability under this DPA is subject to and forms part of the limitation of liability and exclusion provisions in the Agreement. Any reference in those provisions to our liability will be deemed to include our aggregate liability under both the Agreement and this DPA together.
14. Changes to Processing
14.1 If a change in the Revamp Biz Personal Data to be Processed or a risk analysis of the Processing of Revamp Biz Personal Data reasonably requires it, we will, at your request, consult with you on appropriate amendments to this DPA.
14.2 Any such changes must be recorded in writing and will form part of this DPA before they take effect.
14.3 The changes must not prevent you from complying with Data Protection Laws.
15. Duration and termination
15.1 This DPA will automatically terminate upon termination or expiry of the Agreement, subject to any surviving rights and obligations.
15.2 Upon termination or expiry of the Agreement, we will, at your cost (not exceeding our reasonable costs), and at your choice (to the extent permitted by law):
- delete Revamp Biz Personal Data;
- return Revamp Biz Personal Data to you; and/or
- make Revamp Biz Personal Data available to another service provider,
except to the extent we are required by law to retain any Revamp Biz Personal Data.
15.3 Provisions which, by their nature, are intended to continue after termination of this DPA (including confidentiality, limitation of liability, and applicable law/jurisdiction) will survive termination.
16. Contact
You may contact us in relation to any privacy or data processing concerns using the contact details set out below:
Email: hello@revampbiz.co
Annexure1- Details of processing activities
This Annexure 1 includes certain details of the Processing of Revamp Biz Personal Data as required by Article 28(3) GDPR and related provisions.
1. Subject matter, nature, purpose and duration of Processing
The subject matter, nature, purpose and duration of the Processing of Revamp Biz Personal Data are as set out in the Agreement and this DPA and typically include:
- design, implementation and operation of AI‑powered client engagement systems;
- processing of contact, communications and workflow data for leads and clients;
- analytics, reporting, optimisation and support relating to such systems;
- for the term of the Agreement and any additional retention period required by law.
2. Types of Revamp Biz Personal Data
You may submit Revamp Biz Personal Data to Revamp Biz, the extent of which is determined and controlled by you in your sole discretion, and which may include, but is not limited to, the following categories of personal data:
- first and last name;
- title or role;
- date of birth (if provided by you);
- contact information (email, phone, address);
- residence and mailing information;
- engagement and communication data (e.g. emails, messages, call notes, scheduling information);
- other types of information as set out in our Privacy Policy; and
- any other personal data collected by you and provided to us in connection with the services.
3. Categories of Data Subjects
You may submit Revamp Biz Personal Data to Revamp Biz, the extent of which is determined and controlled by you in your sole discretion, and which may include personal data relating to:
- your clients and prospective clients;
- employees of your organisation;
- consultants, contractors and agents of your organisation; and
- third parties with whom your organisation conducts business, or about whom your organisation obtains information in the course of and for the purpose of conducting business.
4. Obligations and rights of the Controller
Your obligations and rights as Controller are set out in the Agreement and this DPA.