This public baseline describes customer-instructed processing, product data flows, safeguards, and privacy-assistance obligations.
Deployment-specific providers, locations, retention, recovery, Restricted Data, and assurance commitments must be recorded in signed terms.
Scope and incorporation
This Data Processing Addendum forms part of a Customer Agreement between the customer identified in that agreement and Leva Nu Pty Ltd (ABN 20 694 850 747, ACN 694 850 747), of 5 Nerli Street, Everton Park, Queensland, Australia, only where the Customer Agreement expressly incorporates this DPA.
Publishing this DPA does not by itself make it binding. A checkout or other electronic flow incorporates this DPA only if it identifies the version being accepted and records an authorised acceptance.
Capitalised terms not defined in this DPA have the meanings given in the Customer Agreement.
This DPA governs the processing of Customer Personal Data within its scope. If it conflicts with another part of the Customer Agreement, the provision that gives greater protection to Customer Personal Data controls, unless the Customer Agreement expressly identifies and overrides the relevant DPA provision. Mandatory transfer terms control to the extent required by applicable law.
Definitions
| Term | Meaning |
|---|---|
| Applicable Data Protection Law | Privacy and data-protection law that applies to the processing, including where applicable the Privacy Act 1988 (Cth) and Australian Privacy Principles, EU GDPR, UK GDPR and Data Protection Act 2018, the California Consumer Privacy Act as amended, and other applicable US state privacy laws. |
| Customer Personal Data | Personal information or personal data contained in Customer Material, customer-specific Output, evidence metadata, audit or decision records, support material, or other information that Mitoma Systems processes on the customer’s behalf under the Customer Agreement. |
| Restricted Data | Classified, export-controlled, Defence-controlled, controlled technical, sensitive government, special-category, highly sensitive, or similarly restricted information that requires controls beyond the approved baseline deployment. |
| Security Incident | An unauthorised access to, acquisition, use, disclosure, alteration, destruction, or loss of Customer Personal Data. It does not include an unsuccessful attempt that does not compromise Customer Personal Data, such as a blocked scan or failed login. |
| Subprocessor | A third party engaged by Mitoma Systems to process Customer Personal Data on the customer’s behalf. |
Roles and customer responsibilities
For Customer Personal Data, the customer is the controller, business, or equivalent responsible party and Leva Nu Pty Ltd is the processor, service provider, contractor, or equivalent processing party, as those terms apply under Applicable Data Protection Law.
For personal information that Leva Nu Pty Ltd determines how and why to process for its own legitimate purposes—such as website operations, account administration, billing, service security, legal compliance, and business communications—it acts as an independent controller or equivalent responsible party. That processing is described in the Privacy Policy and is outside this DPA.
- The customer determines whether and how its Authorised Users submit Customer Personal Data and is responsible for the lawfulness, fairness, transparency, accuracy, and minimisation of that data and its instructions.
- The customer must provide required notices, establish a lawful basis, obtain required permissions or consents, and respond to data-subject or regulator requests for which it is responsible.
- The customer must not submit Restricted Data unless its data class, provider set, processing location, access model, and additional safeguards are expressly approved in the Customer Agreement or security schedule.
Processing details
The Customer Agreement, product configuration, and table below describe the processing instructed by the customer. A signed order form or security schedule may narrow or supplement these details for a deployment.
| Processing element | Description |
|---|---|
| Subject matter | Providing, securing, supporting, and administering Mitoma Systems workspaces, Explore, Blueprint, Validate, Automate, APIs, customer support, enabled integrations, and related account and usage functions. |
| Duration | The term of the Customer Agreement and the reasonable return, deletion, backup, legal-retention, dispute, and audit period that follows it, as further specified in the Customer Agreement. |
| Nature and purpose | Receiving, hosting, organising, retrieving, analysing, generating, recording, transmitting, securing, troubleshooting, exporting, and deleting data to provide requested product functions; create customer-specific Output; preserve evidence, provenance, reviews, and decision history; manage identity and permissions; meter usage and entitlements; provide support; and protect service integrity. |
| Data subjects | Authorised Users, customer personnel, contractors, advisers, supplier or partner contacts, support contacts, and other people whose information the customer includes in Customer Material or a connected service. |
| Personal-data types | Contact, account, organisation, role, permission, workspace, device, IP, authentication, usage, entitlement, audit, security, support, and diagnostic information; billing contact, subscription, purchase, credit, refund, tax, and payment-status metadata; and personal information contained in engineering inputs, requirements, mission descriptions, prompts, files, integrations, generated Output, evidence metadata, review actions, overrides, and decision history. Payment-card details submitted directly to a payment provider are not intended to be stored by Mitoma Systems. |
| Frequency | Intermittent or continuous according to the customer’s configuration and use of the Service. |
| Locations and providers | The providers, processing locations, residency constraints, and optional model or integration services approved for the deployment and recorded in the Customer Agreement, DPA schedule, or Subprocessors register. |
Documented instructions and purpose limitation
- We process Customer Personal Data only on the customer’s documented instructions, including the Customer Agreement, approved product configuration, Authorised User actions, support requests, and other written instructions that can be retained as a record.
- We process Customer Personal Data only as reasonably necessary to provide, secure, support, and administer the contracted Service, follow those instructions, and meet legal or contractual obligations.
- We do not sell or share Customer Personal Data for cross-context behavioural advertising, and we do not use it to train shared or public foundation models. We do not permit a contracted model provider to use it for such training unless the customer expressly agrees in writing.
- If law requires processing outside the customer’s instructions, we will inform the customer before processing unless the law prohibits notice. We will inform the customer if, in our reasonable opinion, an instruction infringes Applicable Data Protection Law.
- We may refuse or suspend an instruction to the extent reasonably necessary to prevent unlawful processing or a material security, safety, export-control, or compliance risk, and will explain the reason where legally permitted.
Confidentiality and access
Personnel authorised to process Customer Personal Data are subject to confidentiality obligations and may access it only where reasonably necessary for their role. Access is governed by the approved deployment, identity controls, organisation and mission scope, role or capability, and operational need.
We will take reasonable steps to ensure that authorised personnel understand their privacy and security responsibilities. Customer Material, customer-specific Output, and related evidence metadata remain the customer’s Confidential Information under the Customer Agreement whether or not they contain Customer Personal Data.
Security and deployment measures
We will maintain administrative, technical, and organisational measures appropriate to the nature of the Service, the Customer Personal Data, the state of the art, implementation cost, and the risks to individuals. The applicable measures may be supplemented in a security schedule or deployment plan.
- Measures are designed to include server-trusted identity and authorisation, organisation and mission scope, authentication and session controls, least-privilege access, transport protection, managed secrets and storage controls, logging, security-event handling, incident response, and secure development and testing appropriate to the configured environment.
- Hosting topology, provider set, tenancy, residency, customer-managed keys, network restrictions, backup scope, retention, restore testing, and recovery objectives are deployment-specific and apply only where documented in the Customer Agreement or security schedule.
- We regularly review the effectiveness of measures appropriate to the service stage. No measure eliminates all risk, and the customer remains responsible for its users, devices, identity policies, access reviews, instructions, and authorised integrations unless the Customer Agreement allocates those responsibilities differently.
AI, automation, and integrations
Where the customer enables AI-assisted or automated functionality, we may send the prompts, relevant Customer Material, Customer Personal Data, instructions, and generated Output reasonably necessary for the requested function to the approved model or automation provider.
The enabled provider, model route, processing geography, credential arrangement, retention conditions, content-safety or abuse-monitoring conditions, and any human-review limitation depend on the approved deployment. We represent processing as zero-retention, single-region, customer-keyed, or free from provider review only where that control has been confirmed and documented in writing.
AI assists with interpretation and review; it is not the final authority for decisions about a person, safety, certification, procurement, deployment, or operation. The customer must not configure the Service to make a solely automated decision producing legal or similarly significant effects for a person unless the Customer Agreement expressly permits it and the customer has established the required lawful basis, safeguards, notices, and review rights.
If the customer directs the Service to connect to a customer-controlled CAD, simulation, PLM, engineering, model, support, or other service, the parties will document the information exchanged and whether that provider acts as our Subprocessor or directly for the customer before Customer Personal Data is sent.
Subprocessors
The customer gives general written authorisation for us to use the Subprocessors listed on the public Subprocessors page and any deployment-specific schedule. We require each Subprocessor to protect Customer Personal Data under written terms that provide materially equivalent protection for the processing it performs, and we remain responsible for its performance of those obligations to the extent required by the Customer Agreement and Applicable Data Protection Law.
Where Applicable Data Protection Law requires notice of a new or replacement Subprocessor, we will provide reasonable advance notice through the customer’s nominated contact, account channel, or agreed notice process before that Subprocessor begins processing Customer Personal Data. If an urgent security, legal, or availability need makes advance notice impracticable, we will provide notice as soon as reasonably practicable.
The customer may object during the applicable notice period on reasonable, documented data-protection grounds. The parties will work in good faith to address the objection through additional safeguards, an alternative provider or configuration, or another commercially reasonable solution. Program-specific prior-approval rights must be recorded in the Customer Agreement.
Data-subject and compliance assistance
Taking into account the nature of the processing and information available to us, we will provide reasonable assistance so the customer can respond to requests to access, correct, delete, restrict, object to, or port Customer Personal Data and can meet applicable security, breach-notification, data-protection-impact-assessment, prior-consultation, and regulator-enquiry obligations.
If we receive a request from a person concerning Customer Personal Data for which the customer is responsible, we will direct the person to the customer where practicable and will not independently fulfil the request unless instructed by the customer or required by law.
Assistance beyond standard product and support capabilities may be subject to the process and reasonable charges stated in the Customer Agreement, except where the assistance is required because of our breach of this DPA.
Security incidents
We will notify the customer without undue delay after becoming aware of a Security Incident, unless notice is prohibited by law. A Customer Agreement or security schedule may specify a shorter outer notification period, incident contact, or additional procedure.
We will investigate, contain, remediate, recover, preserve relevant evidence, and take reasonable steps to mitigate the Security Incident. Notice will include information reasonably available about its nature, affected data and people, likely consequences, response measures, and a contact for further information. Information may be provided in phases without undue further delay.
The customer is responsible for determining whether it must notify individuals, regulators, or others, unless Applicable Data Protection Law assigns that duty directly to us. We will reasonably cooperate and will not notify on the customer’s behalf without authorisation unless legally required.
Return, deletion, and retention
During the Service term, available export and deletion functions depend on the contracted product and deployment. At termination or expiry, and at the customer’s choice, we will return or delete Customer Personal Data within the period and in the format stated in the Customer Agreement, or otherwise within a reasonable period, unless law requires retention.
Where backups exist, deleted data may remain in protected backups until the ordinary overwrite or expiry cycle. It will not be restored or otherwise processed except for recovery, security, audit, or legal purposes and will remain protected by this DPA while retained.
We may retain limited information where reasonably necessary for legal obligations, tax or accounting records, dispute resolution, security investigations, fraud prevention, evidence holds, or proof of contract and deletion. We will isolate retained Customer Personal Data from ordinary use and delete it when the retention basis ends.
Records, assurance, and audits
We will make available information reasonably necessary to demonstrate compliance with the processor obligations applicable to this DPA. We may satisfy a request first through current policies, architecture information, questionnaires, control matrices, test summaries, audit material, or other relevant evidence available for the deployment.
Where that information is reasonably insufficient and Applicable Data Protection Law requires further verification, we will allow and contribute to an audit or inspection by the customer or an independent auditor bound by confidentiality. Audits must use reasonable advance notice, avoid access to other customers’ data, minimise disruption and security risk, and normally occur no more than once in a twelve-month period unless a Security Incident, regulator, or material compliance concern reasonably requires another audit.
Audit allocation, scope, timing, costs, and access to sensitive evidence are governed by the Customer Agreement or security schedule. This DPA does not claim a certification, accreditation, penetration-test result, or completed independent audit that has not been expressly provided.
International transfers and government requests
We will process Customer Personal Data only in the countries and through the providers approved for the deployment. Where an Australian cross-border disclosure occurs, we will take reasonable steps required by Australian Privacy Principle 8 to ensure that the overseas recipient protects the information, subject to any applicable exception.
Where a restricted transfer from the European Economic Area or United Kingdom requires a safeguard, the parties will document and complete the applicable mechanism before the transfer. This may include the European Commission’s 2021 Standard Contractual Clauses using the applicable module, the UK International Data Transfer Agreement or UK Addendum, and any required transfer risk assessment, data-protection test, or supplementary measure.
If we receive a legally binding demand for Customer Personal Data, we will, where legally permitted, notify the customer, review the demand, disclose only what is legally required, and take reasonable steps to challenge an unlawful or disproportionate demand. Nothing in this DPA requires either party to breach applicable law.
US state privacy terms
Where the California Consumer Privacy Act or a materially similar US state privacy law applies to Customer Personal Data, we act as a service provider or contractor for the limited and specified business purposes described in the Customer Agreement and the Processing details section of this DPA.
- We will not sell or share Customer Personal Data, retain, use, or disclose it outside those specified purposes or the direct business relationship, or use it for cross-context behavioural advertising.
- We will not combine Customer Personal Data with personal information received from another customer or collected through our independent interactions with a person except as Applicable Data Protection Law permits.
- We will provide the level of privacy protection required of a service provider or contractor, require applicable subcontractors to do the same, notify the customer if we can no longer meet those obligations, and cooperate with reasonable steps the customer is legally entitled to take to monitor, stop, and remediate unauthorised use.
Changes and contact
We may update this public DPA as the Service or law changes. An update does not amend an existing Customer Agreement unless that agreement permits the change or the parties agree to it. We will not use an update to materially reduce protection for Customer Personal Data during a fixed term without the customer’s agreement, except where a change is required by law and we provide reasonable notice where permitted.
Privacy questions, data-subject requests, and DPA notices can be sent to our Privacy Officer at info@mitoma.systems. Security incidents should use the incident contact stated in the Customer Agreement or, if none is stated, info@mitoma.systems marked for the attention of Security.