GrantMe Data Processing Agreement

Between Grant Me Australia Pty Ltd (ABN 57 699 140 657) (“GrantMe”, “we”, “us”)

and the school or organisation named in the applicable pilot agreement, order form or account registration (“the School”)

Version 1.4 · Effective date: 14/09/2026

1. Purpose and scope

1.1 This Data Processing Agreement (DPA) sets out how GrantMe handles personal information on behalf of the School in connection with the GrantMe platform (the Service).

1.2 This DPA forms part of, and is to be read with, the GrantMe Terms of Service and any Foundation Member Pilot Agreement. If this DPA conflicts with those documents on a data protection matter, this DPA prevails. On all other matters, including the limits on liability in clause 12, the Terms of Service prevail.

1.3 Terms defined in the Terms of Service have the same meaning here.

2. Roles and instructions

2.1 The School determines the purposes for which personal information is entered into the Service. GrantMe handles that information only on the School’s behalf, and only:

  • to provide, secure and support the Service as described in the Terms of Service and Annex A;
  • in accordance with the School’s reasonable written instructions, given through the Service or in writing; and
  • as required by law, in which case, where lawful, GrantMe will inform the School of the requirement before acting on it.

2.2 GrantMe will notify the School if, in its reasonable opinion, an instruction would breach the Privacy Act 1988 (Cth) or other applicable privacy law, and may decline to act on it until the matter is resolved.

2.3 GrantMe will not sell School Data, and will not disclose it for any purpose other than those set out in this DPA.

3. What data is processed

3.1 The categories of personal information, the individuals it relates to, and the purposes of processing are set out in Annex A.

3.2 The Service is designed for school staff use only. The School must not enter student personal information, health information, financial account details, biometric information or other sensitive information into the Service.

3.3 If information of a kind described in clause 3.2 is received, GrantMe may de-identify or destroy it as soon as practicable where lawful to do so, and will inform the School.

4. Confidentiality and personnel

4.1 GrantMe limits access to School Data to personnel who need it to provide the Service and who are bound by written confidentiality obligations that survive the end of their engagement.

4.2 Access is role-based and logged. Access is removed on the same day a person ceases to require it.

4.3 GrantMe personnel do not access School Content except where necessary to support the School, to investigate a security incident, or where required by law. Such access is logged and available to the School on request.

5. Security

5.1 GrantMe will implement and maintain the technical and organisational measures described in Annex B.

5.2 GrantMe may update those measures over time, provided the overall level of protection is not reduced.

5.3 Per-school data isolation is enforced at the database layer as well as in the application, so that an Authorised User of one school cannot access another school’s data through the interface, the application programming interface, or the database.

6. Data location

6.1 School Data is hosted and processed in Australia. The application and database are hosted in Google Cloud’s australia-southeast1 (Sydney) region. Every service holding or processing School Data (the application runtime, the database, file storage, secrets and logging) is region-pinned to Australia, and School Data is not replicated to any region outside Australia. AI processing is carried out in Amazon Web Services’ ap-southeast-2 (Sydney) region using an inference configuration restricted to Australian regions.

6.2 Limited request metadata containing no School Content may be handled by GrantMe’s security and content-delivery subprocessor on its global edge network in the course of protecting the Service, as noted in Annex C.

6.3 Where the School chooses to sign in using its own Microsoft or Google identity provider, the authentication exchange is handled by that provider under the School’s own arrangements with it, as noted in Annex C.

6.4 Except as described in clauses 6.2 and 6.3 and Annex C, GrantMe will not transfer School Data outside Australia without the School’s prior written agreement.

7. Subprocessors

7.1 The School authorises the subprocessors listed in Annex C. GrantMe remains fully responsible for its subprocessors’ acts and omissions as if they were its own.

7.2 Each subprocessor is engaged under a written contract imposing data protection obligations no less protective than this DPA.

7.3 GrantMe will give the School at least 30 days’ written notice before adding or replacing a subprocessor that will process School Data. If the School reasonably objects on data protection grounds and the parties cannot agree a resolution within 30 days, the School may terminate the affected part of the Service without penalty and receive a pro-rata refund of prepaid Fees.

8. Assisting the School

8.1 Taking into account the nature of the processing, GrantMe will assist the School to respond to requests from individuals to access, correct or delete their personal information. Requests are handled free of charge.

8.2 School administrators can export and delete data directly from the GrantMe dashboard at any time.

8.3 GrantMe will promptly pass on to the School any request it receives directly from an individual, and will not respond to it except on the School’s instruction or as required by law.

8.4 GrantMe will provide reasonable assistance with any privacy impact assessment or consultation the School is required to carry out in relation to the Service.

9. Data breach notification

9.1 If GrantMe becomes aware of a data breach affecting School Data, GrantMe will:

  • notify the School as soon as possible, and keep the School informed as the investigation progresses;
  • provide all relevant details as they become known, including the nature of the breach, the individuals and information affected, the likely consequences, and the measures taken or proposed;
  • take prompt steps to contain and remediate the breach in accordance with its documented Incident Response Plan; and
  • provide reasonable assistance with the School’s own assessment and any notification obligations, including under the Notifiable Data Breaches scheme.

9.2 GrantMe will make the initial notification under clause 9.1 without undue delay and, in any event, within 48 hours of becoming aware of the breach. An initial notification will be given within that period even if the full details are not yet known.

9.3 The parties will cooperate on the content and timing of any notification to affected individuals or to the Office of the Australian Information Commissioner. Where GrantMe is the entity required to notify under the Privacy Act, it will do so within the timeframes the Act requires.

9.4 GrantMe will not make any public statement identifying the School in connection with a breach without the School’s prior written consent, unless required by law.

10. Return and deletion of data

10.1 On termination or expiry, GrantMe will make School Data available for export in a standard machine-readable format for 30 days, and will then delete or de-identify School Data within 30 days of the end of that export period, except where retention is required by law.

10.2 Encrypted backups are retained for up to 30 days and are overwritten on their normal cycle. Deleted data may persist in those backups for that period and is not restored except for disaster recovery.

10.3 GrantMe will provide the School with written confirmation once deletion is complete.

11. Verification and audit

11.1 On the School’s reasonable written request (no more than once per year, unless following a data breach), GrantMe will provide the information reasonably necessary to demonstrate compliance with this DPA, including its security documentation, security testing summaries, and any third-party certifications or assessment outcomes it holds.

11.2 Where that information is not sufficient, the School or its education authority may conduct an audit at its own cost, on at least 30 days’ notice, during business hours, under confidentiality, and without access to any other school’s data.

12. Liability

12.1 Each party’s liability under this DPA is subject to the exclusions, limitations and carve-outs in clause 13 of the Terms of Service, except to the extent liability cannot lawfully be limited.

12.2 For clarity, a claim arising from a breach of this DPA, or from unauthorised access to or disclosure of School Data caused by a failure to maintain the measures in Annex B, is subject to the higher data-breach sub-cap in clause 13.4 of the Terms of Service rather than the general cap in clause 13.3.

13. Duration

13.1 This DPA applies for as long as GrantMe processes School Data and, in respect of clauses 9 to 11, until deletion is confirmed under clause 10.3.

Annex A: Details of processing

Individuals

Authorised school staff who hold GrantMe accounts.

Categories of personal information

  • Staff user email address and display name, used for account identification and sign-in, including the identifier returned by the School’s own Microsoft or Google sign-in where that is used.
  • School details: name, ABN, sector and state.
  • Grant application content entered by staff, which should not contain personal information about other individuals.
  • Documents uploaded by the School to describe itself (for example a school improvement plan), and the text extracted from them.
  • System-generated records: AI interaction metadata, security audit logs (IP addresses hashed with a server-side salt), and a session cookie.

What is not processed

No student personal information, no health information, no financial account details, no biometric information.

Purposes

Providing grant discovery, drafting, submission tracking and acquittal management; securing and supporting the Service; and meeting legal obligations.

Duration

The subscription term, plus the deletion period in clause 10.

Annex B: Security measures

The following measures are in place unless expressly stated to be a future commitment.

  • Encryption of data in transit (TLS 1.2 or higher; TLS 1.3 supported) and at rest (AES-256).
  • Mandatory multi-factor authentication for all accounts. No password-only access.
  • Role-based access control with per-school data isolation enforced at the database layer as well as in the application.
  • Session cookies expiring after a maximum of five days, with a 15-minute idle timeout enforced on the server.
  • Cloudflare network-level protection against distributed denial-of-service and malicious traffic, rate limiting, request validation and cross-site request forgery protection.
  • Comprehensive audit logging of authentication events, data writes and AI requests, retained for at least 12 months. IP addresses are hashed with a server-side salt; no names or email addresses are recorded in log entries.
  • Automated dependency and vulnerability scanning on every build, with high and critical severity findings in production dependencies blocking the build. Continuous automated code and dependency scanning by an independent third-party security platform, with dependency review at least weekly.
  • Security patching within 14 days of disclosure, or within 48 hours where a known exploit exists.
  • Automated daily backups retained for 30 days in Australia, point-in-time recovery available for the preceding seven days, and deletion protection enabled on the production database. Restoration from backup is tested at least every six months.
  • Automated security-rules tests covering per-school data isolation run on every build.
  • Documented Incident Response, Business Continuity and Disaster Recovery plans, each reviewed at least annually.
  • Future commitment: a documented end-to-end cross-tenant isolation test, verifying that no school can access another school’s data through the interface, the application programming interface, or direct database access, will be completed before the Service is used with live School Data.
  • Future commitment: a penetration test of the platform by an accredited external provider will be completed by 30 June 2027, and at least annually thereafter and after any major change. A summary of results will be available to the School on request once completed. Until then, security testing is provided by the continuous automated scanning described above.
  • Cyber liability insurance maintained at not less than AUD $1,000,000, with a certificate of currency available on request.

Annex C: Approved subprocessors

The School authorises the following subprocessors. Changes are notified under clause 7.3.

SubprocessorPurpose and data processedLocationSafeguard
Google Cloud (Firebase, Cloud Run, Firestore, Firebase Authentication, Cloud Storage)Hosting, database, authentication, file storage and logging (all School Data)Australia (australia-southeast1, Sydney)Data processing addendum; all resources region-pinned to Australia
Amazon Web Services (Bedrock)AI drafting and review: school profile information, project information and grant application draft contentAustralia (ap-southeast-2, Sydney), using an inference configuration restricted to Australian regionsData processing addendum; contractual prohibition on training with customer data
Microsoft (Entra ID)Sign-in, where the School chooses to use its own Microsoft account. User email address and the authentication response only. No School Content. Where the School uses its own Microsoft tenant, Microsoft acts under the School’s own arrangements with Microsoft.Global (Microsoft Entra)Microsoft Online Services data protection terms
CloudflareNetwork-level DDoS protection, traffic filtering and content delivery. Request metadata only, no School ContentGlobal edge networkData processing addendum
UpstashDistributed rate limiting. Hashed request identifiers and user identifiers onlyAustralia (ap-southeast-2, Sydney)Data processing addendum
Vision6 (Constant Contact)Transactional email and the school-facing newsletter. Recipient email addresses and message contentAustralia (Vision6 Terms & Conditions cl. 11.5(d): Australian-based data centres for Australian customers)Vision6 Terms & Conditions cl. 11 (Privacy, Security and Confidentiality): Australian Privacy Principles compliance (cl. 11.1), industry-standard security measures (cl. 11.5), security incident and Notifiable Data Breaches notification (cl. 11.6–11.9); GDPR Data Processing Schedule incorporated by cl. 11.3

Signed for and on behalf of the parties as at the effective date, or accepted electronically through the Service.