← Trust centre

Data processing agreement

A committee contract schedule covering instructions, confidentiality, security, subprocessors, incidents and exit.

Version 1.1 · Updated 7 September 2026. Published by Glu IO Pty. Ltd., the owner and operator accountable for Helper Shifts. Committee-specific agreements take effect when signed.

Status and execution

This bilateral Data Processing Agreement (DPA) is between Glu IO Pty. Ltd., the owner and operator of Helper Shifts, and the legal entity or authorised individual responsible for the organising committee or association. It becomes effective when incorporated into a contract signed by both parties. Glu IO Pty. Ltd. remains accountable for the service and its delegated processing. Complete all schedules and obtain legal and operational sign-off first. Committee use does not create a relationship with any school. The school is not a party to this agreement and receives no rights to volunteer records under it.

The organising group determines the purposes of processing its volunteer records. The operator processes those records to deliver the service on documented instructions. “Controller” and “processor” may be useful contractual shorthand, but do not replace each party’s responsibilities under Australian law. The operator separately handles necessary account, security and legal-administration information as described in its privacy policy.

Processing schedule to complete

Parties and authority
Operator: Glu IO Pty. Ltd. Record the organising entity’s legal name, both parties’ ABNs if applicable, addresses, authorised signatories, group subdomains, contract reference and effective date.
Purpose, nature and duration
Collect, host, retrieve, display to authorised users, export and delete adult volunteer bookings for agreed events, for the contract term and the expressly agreed exit period.
People and data
Adult volunteers and organisers; names, emails, phones, group memberships, booking and consent records, event details, account credentials in protected form and necessary security metadata. Student and sensitive records are excluded from the intended scope.
Locations and suppliers
Attach the verified subprocessor register, exact storage/backup countries, remote-support countries, transfer safeguards and permitted changes. Service records, backups and operational logs are stored within Australia in AWS Sydney.
Security and service levels
Attach agreed technical and organisational measures, responsible officers, monitored incident contacts, notification period, support hours, backup frequency, recovery objectives and tested recovery evidence.
Retention and exit
Record committee retention authorities, export scope/format, live deletion period, maximum backup expiry, legal-hold process and deletion-certificate scope.

Instructions and confidentiality

Under this agreement, the operator processes group data only on documented lawful instructions, including authorised use of the service, and only as necessary to provide it. No sale, unrelated advertising, profiling or AI-model training is permitted. The operator must notify the committee if an instruction appears unlawful and pause the affected processing while the parties resolve it.

Access must be limited to authorised personnel subject to confidentiality obligations, appropriate training and role-based access reviews. Group data remains confidential during and after the agreement. The organising entity is responsible for its lawful collection authority, required notices and consents, accurate instructions and authorised-user management.

Security measures and assurance

Under this agreement, Glu IO Pty. Ltd. must maintain proportionate documented technical and organisational safeguards, including encrypted transport and storage, least-privilege access, privileged-account MFA, secure development and patching, tenant isolation, protected logs, vulnerability management, backups and tested recovery. Record the measures and evidence in the security schedule; several require implementation or verification before execution.

Provide reasonable information to support the committee’s privacy impact assessment, procurement review and audit. Permit proportionate audit by the committee, its authorised assessor and relevant public authorities, with confidentiality and safeguards for other customers’ data. An independent assurance report may support an audit but does not remove statutory access rights.

Subprocessors and international transfers

Under this agreement, Glu IO Pty. Ltd. must use only listed, authorised subprocessors under written obligations providing equivalent protection, and remain responsible for their performance of delegated processing. Give at least 30 days’ prior written notice of a planned new subprocessor or material location change. Allow a reasoned committee objection and work to resolve it; if unresolved, provide a practical exit for the affected service.

No change may override an Australian-only location restriction or agreed contractual requirement without written agreement. Record countries of storage, processing, backup and remote access separately. Assess overseas disclosure obligations and contractual safeguards; a consent checkbox does not by itself resolve a prohibited transfer.

Incident response and cooperation

Under this agreement, Glu IO Pty. Ltd. must notify the committee without undue delay and within 24 hours after becoming aware of a suspected or confirmed incident affecting its personal information. A shorter period may be specified in the signed schedule. Do not wait for complete forensic findings or a regulator-notification threshold before contacting the committee.

Provide known facts, affected data and people, likely consequences, containment steps, a contact officer and a schedule for updates. Preserve evidence securely, mitigate harm, assist the committee’s legal notifications and supply a post-incident report with corrective actions. Coordinate public statements while allowing each party to satisfy its own legal obligations.

The federal NDB scheme’s assessment period is not a contractual notification allowance. Where it applies, reasonable steps must be taken to assess suspected eligible breaches within 30 days, and eligible breaches notified as soon as practicable. State duties and committee contracts may differ. See OAIC NDB guidance.

Rights requests and lawful demands

Under this agreement, Glu IO Pty. Ltd. must promptly forward requests relating to group-controlled information to the committee, assist access, correction, deletion, complaints, privacy assessments and records requests, and avoid disclosing information to an unverified requester. Do not respond on the committee’s behalf unless instructed or legally required.

For a compulsory disclosure request, verify its legal validity, disclose only what is required, and notify the committee unless prohibited. Document the request and response, and challenge an overbroad request where reasonable and lawful.

Return, deletion and signatures

Unless the signed committee schedule specifies otherwise, on instruction or termination, provide an agreed machine-readable export and remove group data from live systems within 30 days, with residual backups expiring within 90 days. Record any different periods required by the committee’s lawful schedule in the signed agreement.

Retained data must be limited to a documented legal requirement, isolated from ordinary use and erased when the requirement ends. Backup copies must remain protected, must not return to ordinary processing except necessary recovery, and restored data must have applicable deletion instructions reapplied. Provide written confirmation identifying systems, dates and any retained exceptions.

Execution record: Glu IO Pty. Ltd. authorised signature; organising entity legal name and authorised signature; signature dates; agreed schedules and any agreed amendments. Do not sign until the residency, contact, security, incident-response and deletion schedules are complete and deliverable.

Document history: version 1.1 — clarified independent committee use and contact responsibilities, 7 September 2026; version 1.0 — published documents, Australian data storage and Glu IO Pty. Ltd. operator identity, 7 September 2026; version 0.2 — clarified administrator contact-use restrictions, 7 September 2026; version 0.1 — initial publication, 6 September 2026. Print or save this page as PDF to retain this version. Committee agreements and applicable law take priority over general guidance.