Legal
Data Processing Agreement
Last updated 15 July 2026.
1. Parties, roles and scope
1.1 This Data Processing Agreement ("DPA") forms part of, and is subject to, the Software as a Service Agreement between the Customer ("Controller") and Dumont Pty Ltd (ACN 699 956 271) ("Dumont", "Processor"), which supplies the applicable Dumont product (the "Service") to the Customer (the "Agreement").
1.2 The Controller determines the purposes and means of processing Personal Data. Dumont processes Personal Data only as a Processor on the Controller's documented instructions, being the provision of the Service (the services comprising the applicable Moveezi product).
1.3 Where the Controller is itself a processor for its own customers (for example a relocation management company or corporate account), Dumont acts as a sub-processor and these terms apply mutatis mutandis.
1.4 Capitalised terms not defined here have the meaning given in the Agreement or in the GDPR, the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), and, where applicable, the UK GDPR and the California Consumer Privacy Act (CCPA/CPRA).
2. Subject matter, duration, nature and purpose (Annex I)
- Subject matter: processing of Personal Data necessary to provide the Service.
- Duration: the term of the Agreement, plus the return/deletion period in clause 10.
- Nature and purpose: hosting, storage, structuring, transmission, display, routing, tracking and analytics strictly to operate the service for the Controller.
- Categories of data subjects: the Controller's staff and authorised users; the Controller's own customers and contacts; and other individuals whose Personal Data the Controller processes through the Service.
- Categories of Personal Data: identifiers (name, email, phone, address), account and login data, records and content created or uploaded through the Service, usage and log data, and billing data. Depending on the product, additional category-specific fields may be processed under the same terms.
- Special categories: the service is not designed to process special-category data; the Controller must not submit it except where expressly agreed in writing.
3. Processor obligations
3.1 Dumont will process Personal Data only on the Controller's documented instructions, including as to international transfers, unless required by law (in which case Dumont will notify the Controller unless legally prohibited).
3.2 Dumont will ensure persons authorised to process Personal Data are bound by confidentiality.
3.3 Dumont will implement the technical and organisational measures in clause 5 (Annex II).
3.4 Dumont will assist the Controller, taking into account the nature of processing, in responding to data-subject requests (access, rectification, erasure, restriction, portability, objection) and in meeting its obligations under Arts. 32–36 GDPR (security, breach, DPIA, prior consultation).
3.5 Dumont will make available information necessary to demonstrate compliance and allow for and contribute to audits (clause 8).
3.6 Dumont will notify the Controller without undue delay if, in its opinion, an instruction infringes applicable data protection law.
4. Sub-processors (Annex III)
4.1 The Controller grants general authorisation for Dumont to engage sub-processors in the categories set out below. Dumont imposes data-protection terms on each sub-processor no less protective than this DPA and remains liable for their performance.
4.2 Categories of sub-processor:
| Category | Purpose |
|---|---|
| Cloud hosting / infrastructure provider (Australia; United States for US-elected customers) | Hosting and storage of the Service and Customer Data |
| Communications provider | Email, SMS and voice notifications |
| Content delivery / security provider | CDN, DNS and network protection (data in transit) |
| Product analytics | Operated on Dumont's own infrastructure |
The specific, named and current sub-processor list is provided to Customers on request under the Agreement, and is not published, to protect the security of Dumont's operating environment.
Product analytics are operated on Dumont's own infrastructure rather than a third-party analytics service, so product-usage data does not leave Dumont's control to an external analytics provider.
4.3 Dumont will give the Controller at least 30 days' notice of any intended addition or replacement of a sub-processor (via the notice mechanism in the Agreement) and the Controller may object on reasonable data-protection grounds; the parties will work in good faith to resolve the objection.
5. Security measures (Annex II)
Dumont maintains an information security programme aligned to its certifications and the standards it is built to (ISO 9001, ISO 27001, NIST SP 800-171, CMMC Level 1 and Level 2), including:
- Encryption: TLS in transit; encryption at rest for stored Personal Data and backups.
- Access control: role-based access, least privilege, MFA on administrative access, per-tenant isolation so one Controller can never access another's data.
- Network security: WAF/DDoS protection, runtime threat detection (host and application), and controlled egress from automated systems.
- Operational security: logging and monitoring, patch management, weekly security posture review, and change control.
- Resilience: automated backups and documented restore procedures.
- Personnel: confidentiality obligations and security awareness.
Dumont may update measures provided the level of protection is not materially reduced.
6. International transfers
6.1 Customer production data is hosted in Australia (Sydney), or in the United States for US-elected customers. Where Personal Data is transferred to a country without an adequacy decision (for example via a US-based sub-processor for email or messaging), the transfer is governed by the EU Standard Contractual Clauses (SCCs) and, for UK data, the UK IDTA/Addendum, which are incorporated by reference and completed with the details in the Annexes.
6.2 For Australian data, Dumont takes reasonable steps under APP 8 before disclosing to an overseas recipient.
7. Personal data breach
7.1 Dumont will notify the Controller without undue delay, and in any case within 72 hours of becoming aware, of a Personal Data breach affecting the Controller's data, with the information required under Art. 33(3) GDPR to the extent available, and will cooperate on remediation.
8. Audit
8.1 Dumont will make available its certifications, security summaries and, on reasonable notice and subject to confidentiality, information reasonably necessary to demonstrate compliance. Where the Controller reasonably requires an audit beyond that, it may be conducted no more than once per year, on 30 days' notice, during business hours, without disrupting operations, at the Controller's cost.
9. Data-subject requests
9.1 Dumont will promptly notify the Controller of any request it receives directly from a data subject and will not respond except on the Controller's instruction, and will provide reasonable assistance (including self-service tooling where available) to help the Controller respond.
10. Return and deletion
10.1 On termination or expiry of the Agreement, Dumont will, at the Controller's choice, return or delete all Personal Data and existing copies within 30 days, unless retention is required by law, in which case Dumont will protect it and process it only as required by that law.
11. Liability, precedence and governing law
11.1 Liability under this DPA is subject to the limitations and exclusions in the Agreement.
- 11.2 In the event of conflict, this DPA prevails over the Agreement on data-protection matters;
- the SCCs prevail over this DPA on transfer matters.
11.3 This DPA is governed by the law of the jurisdiction specified in the Agreement (currently New South Wales, Australia).
Annexes (to complete on execution)
- Annex I — processing details (clause 2, per Controller).
- Annex II — technical and organisational measures (clause 5).
- Annex III — sub-processors (clause 4).
- SCCs — EU module 2 (controller-to-processor) / module 3 (processor-to-processor), plus UK Addendum, completed per Annexes.