Data Processing Schedule
How SOARR handles personal information inside your Automation Kits. Part of the Automation Services Agreement. Version NOVON-LEG-KIT-02 v1.0.
Parties and status
This Schedule is made between SOARR Pty Ltd ACN 696 424 898 trading as NOVON HQ (SOARR) and the Client named in an Order Form under the NOVON Automation Services Agreement (NOVON-LEG-KIT-01) (the Agreement). It forms part of the Agreement and, on any matter concerning Personal Information, prevails over the rest of the Agreement to the extent of any inconsistency (Agreement clause 2.2).
Agreed terms
1. Definitions and interpretation
1.1 Capitalised terms defined in the Agreement have the same meaning in this Schedule. In addition:
(a) APPs means the Australian Privacy Principles in Schedule 1 to the Privacy Act 1988 (Cth) (the Privacy Act).
(b) Client Personal Information means Personal Information contained in Client Data.
(c) Documented Instructions means the Agreement, the Order Form, the Kit documentation, the Go-Live Schedule and any other written instruction the Client gives through the Platform.
(d) Eligible Data Breach has the meaning given in section 26WE of the Privacy Act.
(e) Handle means collect, hold, use, disclose, store, transmit, access, process, copy or delete, and Handling has a corresponding meaning.
(f) Security Incident means any actual or reasonably suspected unauthorised access to, unauthorised disclosure of, or loss of Client Personal Information held by SOARR, a Certified Installer or a Subprocessor, or any compromise of a credential or key that gives access to a Client Account.
(g) Subprocessor Register means Annexure A, as updated under clause 6.
2. Roles of the parties
2.1 The Client is responsible for its customers' information. The Client is the entity that collects Client Personal Information from its customers, staff, suppliers and callers, decides why it is collected and how it is used, and holds it in the Client Accounts. The Client remains responsible for that information under the Privacy Act and any other law that applies to it.
2.2 SOARR handles it for the Client. SOARR Handles Client Personal Information only as a service provider to the Client, only to supply the Services, and only in accordance with the Documented Instructions and this Schedule, unless an Australian law requires otherwise (in which case SOARR will tell the Client first where it is lawful to do so).
2.3 APP standard applies either way. Whether or not SOARR or the Client is an "APP entity" at a given time (for example, because of the small business exemption in section 6D of the Privacy Act), SOARR must Handle Client Personal Information as if SOARR were an APP entity bound by the APPs, and in accordance with this Schedule.
2.4 No independent use. SOARR must not use Client Personal Information for its own purposes, including marketing, profiling, product analytics that identifies an individual, or training any AI model, and must not sell it or disclose it for a benefit.
2.5 Instructions that would breach the law. If SOARR considers that a Documented Instruction would breach the Privacy Act or another law, it must tell the Client and may decline to follow the instruction until it is changed.
3. Categories of personal information and individuals
3.1 The Client Personal Information Handled for each Kit is set out below. SOARR must configure each Kit to Handle no more Personal Information than the Kit reasonably needs.
| Kit | Individuals | Personal information | Where it primarily lives |
|---|---|---|---|
| Never Miss a Job | Callers, customers, Client staff who receive transfers | Phone number, name, reason for call, address or job details given, booking time, call audio recording, call transcript and AI summary | Client calendar and email; call record in the voice platform for the retention period (clause 9) |
| Win the Quote | Leads and enquirers | Name, email, phone, enquiry content, quote status, message history | Client email and CRM |
| Inbox Under Control | Anyone who emails the Client, and people named in email | Email content and attachments, sender details, category labels, drafted replies | Client mailbox |
| Get Paid | Customers and debtors | Name, contact details, invoice lines and amounts, payment status, reminder history | Client Xero organisation and Stripe account |
| Paperwork Off | Suppliers who are individuals or sole traders, and Client staff submitting receipts | Supplier name, ABN, contact and bank details shown on bills, receipt images, amounts | Client Xero organisation (draft bills) |
| Morning Brief | The owner, and people named in the calendar, email or accounts summarised | Names, meeting details, amounts owed, email subjects and short summaries | Delivered to the owner by call or text; source data stays in Client Accounts |
3.2 Sensitive information. No Kit is designed to collect sensitive information (as defined in section 6(1) of the Privacy Act, including health information). Such information may arrive incidentally, for example in an email or a call. SOARR must not configure an Automation to extract, label or store sensitive information separately, and each Kit's guardrails direct the Automation to hand such matters to a person. The Client must tell SOARR if its business ordinarily receives sensitive information, and SOARR will advise whether additional controls or a different configuration are needed before Go-Live.
3.3 Children. Kits are not designed to deal with children. Where a caller or correspondent appears to be under 16, the Automation hands over to a person.
3.4 Payment and identity data. Automations must never ask for, repeat or store card numbers, passwords or government identifiers. Bank details appearing on a supplier bill may be read into a draft bill but may never be created or changed in a payee record by an Automation (Agreement clause 8.3(b)).
4. Security measures
4.1 SOARR must take the steps reasonable in the circumstances to protect Client Personal Information from misuse, interference and loss, and from unauthorised access, modification or disclosure, including technical and organisational measures (the standard in APP 11.1 and 11.3). At a minimum, SOARR must maintain the following measures, and ensure its Certified Installers comply with them.
| Area | Measure |
|---|---|
| Delegated access | Connect each Client Account by OAuth or an equivalent delegated sign-in approved by the Client, with the narrowest scopes the Kit needs. No Client password is sent by email, text or chat. |
| Password vault | One vault per Client in SOARR's business password manager. Any credential or API key that cannot be connected by OAuth is stored only in that vault. Certified Installers are given access to the vault for their Job only. |
| No copying or reuse | No person may copy a Client credential, key or token out of the vault, store it on a device or in a file, message or code repository, or reuse it for any other client or purpose. Kit workflow files in the Kit library contain blanks, never Client credentials or Client Personal Information. |
| Least privilege and separation | Each Client has its own workflow instance or workspace, its own AI workspace and API keys, and its own spend cap. No Automation can reach another client's data. |
| Authentication | Multi-factor authentication on every SOARR and Certified Installer account that can reach a Client Account, the vault or the Kit library. |
| Devices | Certified Installers and SOARR staff work only from devices with full-disk encryption, a screen lock, current operating system updates and no shared user profile. No Client Personal Information is downloaded to a device except transiently to complete a task, and it is deleted afterwards. |
| Test data | Kits are built and certified using SOARR's own sandbox accounts and synthetic data. Acceptance Tests in a Client Account use scripted test items, not real customer records, wherever possible. |
| Access ending | A Certified Installer's access to the Client Accounts and vault is removed at Sign-off, and re-granted temporarily only for a warranty fix. All SOARR access is revoked at offboarding (Agreement clause 25). |
| Activity reporting | Each Automation reports to the NOVON platform only the action type, a system reference, an invoice or job value where relevant, and the time. No names, contact details or message content. The NOVON platform replaces the system reference with a one-way code unique to the Client's plan before storing it. Used only for the Client's own Money page and Care Plan report. |
| Logging and monitoring | Access to Client vaults and administrative actions are logged. Monitoring hooks report workflow failures and error metadata to SOARR, not message content, except to the extent needed to diagnose a failure. |
| Encryption | Client Personal Information is encrypted in transit between systems. SOARR relies on each Subprocessor's encryption at rest, as described in its current security documentation. |
| People | Every SOARR staff member and Certified Installer who can reach Client Personal Information is bound by written confidentiality and privacy obligations and completes SOARR's privacy and security training before first access. |
4.2 SOARR must review these measures at least annually and when a Kit or Subprocessor changes, and must not reduce the overall level of protection without the Client's agreement.
5. Personnel and Certified Installers
5.1 SOARR must ensure that only its staff and Certified Installers who need access to perform the Services have access to Client Personal Information, and only for as long as they need it.
5.2 SOARR is responsible for the Handling of Client Personal Information by its Certified Installers as if it were SOARR's own (Agreement clause 6.2).
6. Subprocessors
6.1 The Client authorises SOARR to engage the Subprocessors in the Subprocessor Register for the purposes stated there. Where a Client Account is held in the Client's own name, the provider is the Client's own supplier; SOARR lists it in Annexure A so the Client has a complete picture of where data goes.
6.2 SOARR must have a written agreement with each Subprocessor that SOARR engages directly that requires it to protect Client Personal Information to a standard at least substantially similar to the APPs and to use it only to provide its service, and, where the provider offers it, must use the provider's contractual commitment that customer content will not be used to train its models.
6.3 SOARR must give the Client at least 30 days' notice through the Platform before adding or replacing a Subprocessor that will Handle Client Personal Information. If the Client reasonably objects on privacy or security grounds, the parties will discuss the objection in good faith. If it is not resolved, the Client may cancel the Care Plan for the affected Kits without charge before the change takes effect, and SOARR must complete offboarding under Agreement clause 25.
6.4 In an emergency (for example, a Subprocessor's security failure or sudden withdrawal of service), SOARR may replace a Subprocessor on shorter notice and must tell the Client as soon as practicable.
7. Cross-border disclosure (APP 8)
7.1 What goes overseas. Several Subprocessors process data outside Australia, as shown in Annexure A. In particular, the text of emails, call transcripts, messages and documents that an Automation asks an AI model to read, sort, summarise or draft from is sent to Anthropic, PBC in the United States for processing.
7.2 The rule. APP 8.1 requires an APP entity, before disclosing personal information to an overseas recipient, to take such steps as are reasonable in the circumstances to ensure that the recipient does not breach the APPs (other than APP 1) in relation to the information. Under section 16C of the Privacy Act, if the overseas recipient does something that would breach the APPs, the act may be treated as the act of the disclosing APP entity.
7.3 Steps SOARR takes. For each overseas Subprocessor that SOARR engages directly, SOARR must: (a) contract on terms that restrict the provider's use of the data to providing its service; (b) use the provider's no-training commitment where available; (c) send only the data the Automation needs for the task; (d) where the provider offers Australian hosting or reduced retention at reasonable cost, use it; and (e) keep a record of these steps and give it to the Client on request.
7.4 The Client's part. The Client acknowledges the overseas processing described in Annexure A, and must disclose it in its privacy policy (clause 11). The Client should not rely on the consent exception in APP 8.2(b) as its main basis for overseas disclosure; the steps in clause 7.3 are designed to support the reasonable-steps basis in APP 8.1.
7.5 SOARR must not transfer Client Personal Information to any other overseas location, or to a new overseas Subprocessor, except under clause 6.
8. Security Incidents and the Notifiable Data Breaches scheme
8.1 SOARR must notify the Client without undue delay, and in any event within 48 hours, after SOARR becomes aware of a Security Incident, and must give the information then available: what happened, when, which Client Accounts and kinds of information are affected, the likely number of individuals, and what SOARR has done to contain it.
8.2 SOARR must immediately take reasonable steps to contain the Security Incident, including pausing affected Automations and revoking and rotating affected credentials and keys, and must preserve relevant logs.
8.3 Assessment. Where there are reasonable grounds to suspect an Eligible Data Breach, the Privacy Act requires an entity to carry out a reasonable and expeditious assessment and to take all reasonable steps to complete it within 30 days (section 26WH). SOARR must cooperate with the Client's assessment and give it the information it reasonably needs within the time it reasonably requests.
8.4 Statement and notification. Where there are reasonable grounds to believe an Eligible Data Breach has occurred, the Privacy Act requires a statement to the Commissioner (section 26WK) and notification of affected or at-risk individuals (section 26WL). Where the breach is an Eligible Data Breach of both parties, section 26WJ allows compliance by one entity to satisfy the other. The parties agree that the Client leads the assessment, statement and notification for Client Personal Information, unless they agree otherwise in writing or a law requires SOARR to act itself. SOARR must not notify the Commissioner, individuals or the media about a Security Incident affecting Client Personal Information without first consulting the Client, except where the law requires it to.
8.5 SOARR bears its own costs of complying with this clause. Where the Security Incident was caused by SOARR's, a Certified Installer's or a SOARR-engaged Subprocessor's breach of this Schedule, SOARR must also reimburse the Client's reasonable costs of notification, subject to Agreement clause 21.
9. Call recordings and transcripts
9.1 Opening disclosure. Every call answered by an Automation must open with the disclosure in Annexure B, part 1, or words to the same effect approved by SOARR, before any substantive conversation. It cannot be removed.
9.2 If a caller objects. If a caller says they do not want to be recorded, the Automation must not continue the conversation. It must offer to transfer the caller to a person, telling them the transferred call may still be recorded unless the Client has set recording to stop at transfer, or invite them to call back in business hours, and then end the call. The Kit's acceptance tests must include this case.
9.3 Transfers. Where a call is transferred to Client staff, recording continues or stops as chosen in the Order Form. The Client is responsible for informing its staff.
9.4 Retention. Call audio is kept in the voice platform for no more than 30 days, or a shorter period set in the Order Form, and is then deleted. Transcripts and summaries are delivered into the Client Accounts (for example, as an email or calendar note) and are kept there under the Client's own retention policy. SOARR must configure the voice platform accordingly.
9.5 Access. Only the Client, and SOARR staff or Certified Installers who need to diagnose a failure, may access recordings. Recordings are not used to train AI models and are not shared with anyone else except as required by law.
9.6 Publication. Section 11 of the Surveillance Devices Act 2007 (NSW) restricts publishing or communicating a private conversation obtained by use of a listening device in contravention of that Act. SOARR and the Client must not publish recordings, and SOARR must not use them in marketing or case studies.
10. Retention, return and deletion
10.1 Client Personal Information lives primarily in the Client Accounts. SOARR must configure its own and SOARR-engaged Subprocessors' systems to keep copies only as long as needed:
| System | What is kept | Retention |
|---|---|---|
| Workflow engine execution logs | Inputs and outputs of each workflow run, for diagnosis | 14 days, then pruned |
| AI model provider | Prompts and outputs processed through SOARR's workspace | As set by the provider's commercial terms in force from time to time. SOARR tells the Client the current period on request (clause 13.3) |
| Voice platform | Call audio, transcript, summary | 30 days (clause 9.4) |
| SOARR monitoring | Error type, time, workflow and Client identifier; no message content except as needed to diagnose | 90 days |
| NOVON activity events | Action type, system reference (stored as a one-way code), invoice or job value where relevant, and time | Life of the Agreement, then deleted under clause 10.2 |
| Client vault | Credentials and keys for the Client | Deleted at offboarding |
| SOARR records | Order Forms, Acceptance Notices, Sign-off records, invoices and incident records (which may contain limited Personal Information) | 7 years, as for SOARR's other financial and legal records |
10.2 Within 30 days after the Agreement ends, or earlier if the Client asks after offboarding, SOARR must delete or de-identify all Client Personal Information it or its SOARR-engaged Subprocessors hold, other than records it must keep by law, and must confirm this in writing. Before deletion SOARR will return any Client Data the Client asks for in a commonly used format. This reflects the destruction or de-identification standard in APP 11.2.
11. Transparency: the Client's privacy notice
11.1 Before Go-Live the Client must include in its privacy policy, and where practical in any collection notice, a description of the AI processing and overseas disclosure involved in its Automations. Annexure B, part 2 is a ready-to-paste paragraph for that purpose.
11.2 SOARR must tell the Client promptly if a change to a Kit or Subprocessor makes that text inaccurate, and provide updated text.
12. Automated decisions
12.1 The coming obligation. The Privacy and Other Legislation Amendment Act 2024 (Cth), Schedule 1 items 87 to 89, inserts APP 1.7 to 1.9, commencing on 10 December 2026. From then, an APP entity's privacy policy must describe the kinds of personal information used, and the kinds of decisions made, where a computer program makes, or does a thing substantially and directly related to making, a decision that could reasonably be expected to significantly affect the rights or interests of an individual, and personal information about the individual is used in the program's operation. The examples include decisions affecting an individual's rights under a contract and access to a significant service or support (APP 1.9).
12.2 How Kits are designed. Kits are designed so that no Automation makes a decision that could reasonably be expected to significantly affect an individual's rights or interests. In particular, the following are Restricted Actions that always require a person (Agreement clause 8.3): accepting, refusing or cancelling a customer, job or booking on grounds other than calendar availability; imposing a fee or charge; stopping work; referring a debt to collection; refunds and credits; and any assessment of a person's eligibility, creditworthiness or suitability.
12.3 Borderline functions. Some Automations do things that relate to decisions, for example offering a booking time from free calendar slots, sorting an email as urgent, or sending a polite overdue reminder. The parties' view is that these are unlikely to significantly affect an individual's rights or interests, but the threshold has not been tested. For that reason Annexure B, part 3 contains optional APP 1.8 wording the Client may add, and SOARR recommends it for any Client that is an APP entity.
12.4 The Client must not change an Automation, or add an action to the Go-Live Schedule, so that it makes a decision of the kind described in clause 12.1 without SOARR's written agreement and an updated privacy notice.
13. Requests, complaints and cooperation
13.1 If SOARR receives a request from an individual to access or correct Client Personal Information, or a privacy complaint about an Automation, SOARR must pass it to the Client within 5 Business Days and must not respond to the individual except to acknowledge receipt, unless the Client asks it to.
13.2 SOARR must give the Client the reasonable assistance it needs to respond to access and correction requests under APPs 12 and 13, complaints, and any inquiry by the Office of the Australian Information Commissioner, concerning an Automation.
13.3 On request, no more than once a year (or at any time after a Security Incident), SOARR must give the Client a written summary of the measures in clause 4, the current Subprocessor Register, and the results of its most recent access review. SOARR is not required to allow on-site audits, but will answer a reasonable written security questionnaire.
14. Conduct risk: serious invasions of privacy
14.1 The statutory tort for serious invasions of privacy in Schedule 2 to the Privacy Act (in force from 10 June 2025) applies to everyone, including small businesses, and is actionable without proof of damage where an intrusion upon seclusion or misuse of information is intentional or reckless and serious. SOARR must ensure its staff and Certified Installers access Client Accounts only for the task in hand, never browse or search Client Data for any other purpose, and never take screenshots or copies of Client Data except as the Kit documentation requires for diagnosis.
15. General
15.1 This Schedule continues for as long as SOARR or a SOARR-engaged Subprocessor holds Client Personal Information, even after the Agreement ends.
15.2 SOARR may update this Schedule to reflect a change in law or in a Subprocessor, with at least 30 days' notice, and the Client has the rights in clause 6.3. A change that reduces the protection of Client Personal Information requires the Client's agreement.
15.3 Privacy questions: privacy@novonhq.com.au. Security incidents: the Project Architect's mobile, then safety@novonhq.com.au.
Annexure A · Subprocessor Register
Processing locations are as stated in each provider's published terms on 6 October 2026. Where an account is held by the Client, the provider is the Client's own supplier and the Client's own terms with it apply. SOARR keeps this register current under clause 6.
| Provider | Purpose in the Kits | Account holder | Data handled | Processing location |
|---|---|---|---|---|
| Anthropic, PBC (Claude API) | Reading, sorting, summarising and drafting text; voice agent reasoning | SOARR (one workspace per Client) | Text of emails, messages, transcripts, bills and Business Facts sent for each task | United States |
| n8n (workflow engine) | Runs the Client's workflows and connects its systems | Client, or SOARR for the Client (System Register) | All data passing through a workflow; execution logs | Sydney, Australia (SOARR's instance), or the Client's own instance where the System Register says so |
| Twilio | Australian phone numbers, SMS, call carriage | Client, or SOARR for the Client (System Register) | Phone numbers, SMS content, call metadata | United States and other countries |
| Vapi | Voice agent (speech to text, text to speech, call handling) | Client, or SOARR for the Client (System Register) | Call audio, transcripts, summaries | United States |
| Deepgram | Speech to text for calls (through Vapi) | Client, or SOARR for the Client (System Register) | Call audio, transcript | United States |
| Text-to-speech provider selected in Vapi | Text to speech for calls (through Vapi) | Client, or SOARR for the Client (System Register) | Assistant speech text only | United States; SOARR names the provider in the Order Form and changes it only under clause 6 |
| Xero | Accounting: invoices, bills, contacts | Client | Customer and supplier contacts, invoices, bills | United States and other countries, per Xero's terms |
| Stripe | Pay links on invoices (Client account); NOVON held payments and Care Plan billing (SOARR account) | Client (pay links); SOARR (NOVON billing) | Payer name, email, payment status | United States and other countries, per Stripe's terms |
| Google Workspace or Microsoft 365 | Email and calendar the Automations read and write | Client | Email, calendar, contacts | Per the Client's own tenancy |
| 1Password | Access vault for Client credentials and keys | SOARR | Credentials and keys (encrypted) | United States (contents end-to-end encrypted, so the provider cannot read them) |
| SOARR (NOVON platform) | Orders, Sign-off records, monitoring, support | SOARR | Order and contact details, error metadata | Australia (per NOVON Privacy Policy cl 6.1) |
Annexure B · Ready-to-use wording
Words in square brackets below are for the Client to replace with its own details.
Part 1: Call opening line (mandatory, Agreement clause 16.2). To be spoken before anything else on every call the Automation answers:
If the caller says they do not want to be recorded: "No problem. I can put you through to the team, but the call may still be recorded, or you're welcome to call back in business hours. Which would you prefer?"
Part 2: Privacy policy paragraph (paste into the Client's privacy policy before Go-Live, Agreement clause 16.6).
Part 3: Automated decision paragraph (optional, recommended for Clients that are APP entities, from 10 December 2026).
Part 4: Message footer for automated emails and texts (Spam Act 2003 ss 17 and 18). Email: "Sent by [Business Name], [ABN], [contact]. You can unsubscribe from these messages [link]." SMS: "[Business Name]. Reply STOP to opt out."
Questions about this document
Privacy questions: privacy@novonhq.com.au. Security incidents: safety@novonhq.com.au.
