nextroundnextround

Data Processing Addendum

Version 1.0 · Last updated: 2 July 2026

This Data Processing Addendum forms part of the Nextround Terms & Conditions between Nextround (the "Processor") and the customer organisation (the "Controller"). It applies whenever Nextround processes personal information on behalf of a customer in the course of providing the recognition and rewards service.

If there is any conflict between this Addendum and the Terms & Conditions on a data-processing matter, this Addendum prevails.

1. Definitions. "Personal information" means information about an identified or identifiable individual, as defined under the Australian Privacy Act 1988. "Processing" means any operation performed on personal information, including collection, storage, use, disclosure, and deletion. "Sub-processor" means a third party engaged by Nextround to process personal information on the Controller's behalf. "Australian Privacy Principles" or "APPs" means the principles set out in Schedule 1 of the Australian Privacy Act 1988.

2. Roles. The Controller determines the purposes for which its employees' personal information is processed in Nextround (workplace recognition). Nextround acts as Processor and processes that information solely on the Controller's documented instructions, except as required by law.

3. Scope of processing. Nextround processes the following categories of personal information about the Controller's employees: full name, mobile number, work email, organisation and team affiliation, recognition activity (recognitions sent and received, messages, value tags), and voucher activity (vouchers sent, received, redeemed). The processing is for the purpose of operating the Nextround recognition and rewards service and only for as long as the Controller's contract is in force.

4. Controller instructions. The Controller's documented instructions to Nextround are: (a) the Terms & Conditions; (b) this Addendum; (c) any written instructions issued via the Controller's nominated administrator. Nextround will notify the Controller if, in its opinion, an instruction infringes applicable data-protection law.

5. Confidentiality. Nextround ensures that personnel authorised to process personal information are bound by appropriate confidentiality obligations.

6. Security. Nextround implements technical and organisational measures appropriate to the risk, as described in Nextround's Information Security Program. These include: encryption at rest (AES-256) and in transit (TLS 1.2+); Row-Level Security enforcing tenant isolation in the database; mandatory multi-factor authentication for operator access; an append-only audit log of access to personal information; documented incident response and notifiable-data-breach procedures; and an annual restore drill and tabletop exercise.

7. Sub-processors. Nextround uses the sub-processors listed at /privacy (currently: Supabase for database and authentication, hosted in Sydney; Vercel for hosting and CDN, transit only; Twilio for OTP SMS delivery; Resend for transactional email when wired). Nextround will notify the Controller at least 30 days before adding or replacing a sub-processor that processes personal information for the Controller, and will give the Controller a reasonable opportunity to object on legitimate grounds.

8. Cross-border disclosure. The Controller acknowledges that the sub-processors listed at /privacy may process personal information outside Australia. The primary store of personal information remains in the Sydney (ap-southeast-2) region. Nextround takes reasonable steps, as required by APP 8, to ensure that overseas sub-processors handle personal information consistently with the APPs, including by binding each sub-processor to a data-processing agreement.

9. Data subject rights. Nextround will assist the Controller in responding to requests from individuals to exercise their rights under the APPs, including the right of access (APP 12) and the right of correction (APP 13). Nextround provides RPC endpoints (export_user_data, erase_user_data) that the Controller's administrators may use, subject to authorisation. Nextround responds to requests it receives directly within 30 days.

10. Breach notification. Nextround will notify the Controller without undue delay, and in any event within 48 hours, after becoming aware of an unauthorised access, unauthorised disclosure, or loss of personal information that is likely to result in serious harm to affected individuals. Notification will include: the nature of the breach, the categories and approximate number of individuals affected, the likely consequences, and the measures taken or proposed to address it. Nextround and the Controller will cooperate on notifications to the Office of the Australian Information Commissioner under the Notifiable Data Breaches scheme.

11. Audit and assurance. Nextround makes available to the Controller, on reasonable request and no more than once per 12-month period (except after a breach), evidence of its compliance with this Addendum, including: a written description of its security controls; the results of dependency, secret, and SAST scans (CI security workflow); audit-log review records; and, when available, the most recent SOC 2 Type II report under a non-disclosure agreement. The Controller may conduct an on-site audit only after exhausting these mechanisms and with reasonable notice.

12. Deletion or return on termination. On termination or expiry of the Terms & Conditions, Nextround will, at the Controller's election: (a) delete all personal information of the Controller's employees from the live service within 30 days, retaining only what is necessary to satisfy legal obligations; or (b) return the personal information in a structured, machine-readable format and then delete it. Audit-log records identifying that the deletion occurred are retained for 7 years.

13. Liability. Liability under this Addendum is governed by the limitations of liability in the Terms & Conditions, except that nothing limits any liability that cannot be limited under applicable law, including the Australian Consumer Law.

14. Governing law. This Addendum is governed by the laws of New South Wales, Australia. The parties submit to the exclusive jurisdiction of the courts of New South Wales.

15. Order of precedence. In the event of conflict between this Addendum and any data-processing terms in the Terms & Conditions, this Addendum prevails. In the event of conflict between this Addendum and a separately signed Enterprise DPA Addendum between Nextround and a specific customer, the signed Enterprise DPA Addendum prevails.

Contact for data-processing matters: privacy@nextround.live.

See also: Terms & Conditions · Privacy Policy · Cookies