Data Processing Agreement

Launchr Pty Ltd
ABN 46 696 518 206
Brisbane, Queensland, Australia

Effective Date: 21 August 2026


Introduction

This Data Processing Agreement ("DPA") is a binding agreement between you (the "Client" or "Data Controller") and Launchr Pty Ltd ("Launchr", the "Data Processor"). It applies whenever you use any Launchr service (Build, Fix, Run, or Sites) and you are processing personal data of your own customers, users, or other individuals.

This agreement complies with the European Union's General Data Protection Regulation (GDPR) Article 28, which sets out how data processors must operate when they handle personal data on behalf of data controllers. Even if you are not in the EU, this agreement protects both of us and reflects how we actually work with your data.

Why This Matters

When you use Launchr to build an app, fix code, manage a live product, or create a website, you own the data that your customers provide. That data might include names, email addresses, payment details, location, or anything else your app collects. You are responsible for that data under privacy law. Launchr helps you process it—we hold it, store it, and help you use it—but we do not own it, and we do not decide what to do with it. You do.

This agreement makes clear what we do, what we do not do, and how we keep your data safe.


1. Roles and Responsibilities

1.1 You Are the Data Controller

You own your business and your app. You decide what personal data your app collects, how it uses that data, and what your privacy commitments are to your customers. You are the "Data Controller" under GDPR and similar privacy laws worldwide.

As the Data Controller, you are responsible for:

1.2 Launchr Is the Data Processor

Launchr is the "Data Processor". We hold, store, and process your customers' data on your behalf, but only to deliver the service you have asked us to provide. We do not decide what to do with it, and we do not use it for our own purposes.

As the Data Processor, we are responsible for:


2. What Personal Data Means

2.1 Personal Data in Launchr Services

"Personal Data" means any information that could identify an individual. In the context of Launchr services, this includes:

If you are using Build, Sites, or Fix:

If you are using Run (ongoing management):

2.2 What Is NOT Personal Data

We are not processing personal data when we store:


3. Purpose: Why We Process Your Data

3.1 Processing Purpose

Launchr processes your customers' personal data for one purpose only: to deliver the contracted Launchr service to you.

That means:

For Build: We process your data so we can develop, test, and hand over your app. We upload test data, analyse requirements, build features, and store the app code and databases. When your build is complete, you get everything—the code, the database, the domain. We delete our working copies unless you ask us to do something else (like Run).

For Sites: We process your data to build and host your website. If your website collects visitor data, we store and process it to serve your website to your visitors. You own the website; we host it.

For Fix: We scan your code and databases to find problems. We process data to diagnose issues and propose repairs. Once you decide to fix (or decide not to), we delete the scan copy unless you keep it.

For Run: We process your data to keep your live app running. That includes running your database, responding to user requests, storing and serving your customers' data, monitoring for problems, and backing up your system.

We do not use your data for any other purpose. We do not:

3.2 Sub-Processor Restrictions

Launchr only uses sub-processors (other services that help us run your app) that are listed in section 6 of this agreement. If we need to add a new sub-processor, we will tell you in advance. If you do not want us to use that sub-processor, we will find another way or stop the service.


4. What Data We Collect and Store

4.1 Scope of Processing

Collection: When you upload files, import data, or use Launchr services, we collect whatever data you provide. You control what we collect by choosing what you upload and import.

Analysis: We analyse your data to:

Storage: We store your data in databases and object storage on Cloudflare's global network. We keep multiple copies for safety (backups). We delete data when your contract ends or when you ask us to.

Transmission: We transmit your data:

We do not transmit your data to anyone else without your permission, except as required by Australian law.

4.2 Types of Personal Data We Process

ServiceTypes of Personal Data Processed
BuildCustomer lists, test data, user data you provide, database content, file uploads, contact details you import
SitesWebsite visitor data, contact form submissions, analytics data, any data submitted through your website
FixScan of your existing databases and app code, which may contain personal data
RunLive customer data: user accounts, transaction history, uploaded files, behaviour data, database records

5. Sub-Processors and Third Parties

5.1 Who We Use to Process Your Data

Launchr uses the following sub-processors to help deliver our services:

Sub-ProcessorPurposeLocation
CloudflareHosting, compute, databases, object storage, backupsGlobal network (US-headquartered)
StripeProcessing Launchr's payment to us (your payment invoice only)Global
ResendSending emails on your behalf (transactional emails, if your app uses email)United States
AnthropicAI processing during builds and agent operationsUnited States
OpenAIAI processing during some agent operationsUnited States
Other third-party integrationsAs you request them (e.g., if you integrate your app with Slack, payment gateways, or CRM tools)Varies

5.2 Important: Stripe and Payment Card Data

Launchr does NOT process payment card data. Your customers' credit and debit card information is handled entirely by Stripe or your own payment processor—it never comes to us. This is a critical boundary:

If you use Stripe in your app, your customers use a Stripe-hosted checkout (or embedded form) that you control. You maintain a Stripe account in your own name. The money goes to you. We never see it.

5.3 Integrations You Add

If you integrate your app with third-party services (Slack, HubSpot, Typeform, etc.), those services become sub-processors too. Launchr passes data to them only if you have explicitly connected them in your app settings. You control which integrations are active.

5.4 Adding or Changing Sub-Processors

If we need to add a new sub-processor or change an existing one, we will notify you before the change. You have the right to object. If you object, we will either:

We cannot force a sub-processor change on you.


6. Data Subject Rights

6.1 Your Customers' Rights

Your customers (the people whose data is in your app) have the following rights under privacy law (GDPR if they are in the EU, Australian Privacy Principles if they are in Australia, and similar laws elsewhere):

Right of Access: Your customers can ask you for a copy of their personal data. Launchr will help you provide it.

Right to Rectification: Your customers can ask you to correct wrong information about them. Your app should allow this; Launchr will store the corrections.

Right to Erasure ("Right to Be Forgotten"): Your customers can ask you to delete their data. When they do, we will delete it from your app. (Note: some data may need to be kept for tax or legal reasons—you control that rule, not us.)

Right to Restrict Processing: Your customers can ask you to limit what you do with their data. Your app must respect that; Launchr will store and honour the restriction.

Right to Data Portability: Your customers can ask you for their data in a portable format they can move to another service. Launchr will help you provide it.

Right to Object: Your customers can object to certain types of processing (like marketing emails). Your app should respect that.

Right Against Automated Decision-Making: If you use automated decision-making (like an AI model to make decisions about your customers), you must tell them. Launchr does not make these decisions for you—you do.

Rights Related to Profiling: Your customers have rights if you use their data to build profiles about them.

6.2 How We Help You Honour These Rights

When your customers exercise these rights, they usually ask you (the business). You are responsible for:

Launchr will help by:

We aim to help you respond within 30 days.

If you collected customer data with consent, your customers can withdraw it anytime. When they do, you must stop processing their data for that purpose (but you can keep it if you have another legal reason to keep it). Your app should provide an easy way for customers to do this.


7. Technical and Organisational Security Measures

7.1 How We Keep Your Data Safe

Launchr uses industry-standard security practices to protect your data. We cannot guarantee 100% security—no service can—but we take it seriously.

Encryption in Transit: When your data travels between your device and our servers, or between our servers, it is encrypted using TLS (Transport Layer Security). This means it is scrambled so no one can read it in the middle.

Encryption at Rest: Data stored in our databases is encrypted using AES-256 encryption. The encryption keys are separate from the data, and they are stored securely.

Access Controls: Only Launchr team members who need to access your data to deliver the service can access it. We use role-based access control—different team members have different permissions depending on their job.

Authentication: Our systems use secure authentication (passwords, API keys, multi-factor authentication). Team members must authenticate to access data.

Network Security: Our infrastructure on Cloudflare includes a web application firewall, DDoS protection, and network segregation to prevent unauthorised access.

Secure Development: When we write code for your app, we follow secure coding practices. We use code review, static analysis, and security testing.

Vulnerability Testing: We regularly test our systems for security weaknesses. We use automated vulnerability scanning and penetration testing.

Incident Response: We have a plan for what to do if there is a security breach (see section 8).

Physical Security: Our providers' data centres have physical security controls (guards, cameras, access badges, biometrics). Only authorised staff can enter the facilities where your data is stored.

Backup and Disaster Recovery: We back up your data regularly. Backups are encrypted and stored separately from production data. If disaster strikes, we can restore your data.

Monitoring and Logging: We log access to systems and databases. We monitor these logs for suspicious activity.

7.2 Your Responsibility

You are responsible for:

7.3 Security Limitations

Launchr is a service for small business owners building apps quickly. We invest in security, but we are not a security-first enterprise service. If you need HIPAA compliance (for health data), SOC 2 Type II certification, or specific data residency requirements, you should ask us before starting. We may not be the right fit.


8. Data Breaches and Notification

8.1 What Is a Breach?

A "data breach" is when personal data is accessed, copied, altered, or destroyed without permission. Examples:

8.2 What We Will Do

If we discover a breach that affects your data, we will:

  1. Investigate immediately: We will work to understand what happened, how much data was affected, who might have accessed it, and how to stop it happening again.
  1. Tell you within 24 hours: We will contact you at the email address on your account with details of what we know so far. We will not wait until we have all the answers—we will tell you early.
  1. Give you the facts: We will tell you what data was affected, when we think it happened, and what we are doing about it.
  1. Help you decide what to do next: If we think your customers' data is at risk, we will help you decide whether to tell them.

8.3 You Tell Your Customers (Usually)

You own the customer relationship. If your customers' data is breached, you decide whether to tell them. This is your legal responsibility, not ours.

Here is the rule: If a breach could be serious (names and email addresses were stolen, or payment data was exposed), you need to tell your customers and your privacy regulator. In the EU, privacy regulators must be told within 72 hours. In Australia, the Privacy Commissioner has similar expectations.

Launchr will give you the information you need to tell them. We may help you draft a notification, but the decision and message are yours.

8.4 Cooperation

We will help you:

This is separate from any other legal claims or compensation. Notifying you and cooperating is what the law requires; it does not mean Launchr admits fault or liability.


9. Data Retention and Deletion

9.1 How Long We Keep Your Data

Launchr keeps your data only as long as you need us to.

While Your Service Is Active: As long as you are using a Launchr service (Build, Sites, Fix, or Run), we keep your data so you can use the service.

After You End the Service:

ServiceWhat We KeepFor How LongThen What
BuildYour app code, databasesHanded over to you at the end of the buildYou keep it on your own hosting; we delete our working copies after handover
SitesYour websiteAs long as you keep it runningIf you cancel, we keep your website and data for 30 days, then delete it (unless you ask us to keep it)
FixScan resultsDuring the engagementIf you do not proceed with a fix, we delete the scan after 30 days
RunYour live app and databasesAs long as you keep the service activeIf you cancel, we keep your data for 30 days to let you download it, then delete it

9.2 Deletion Process

When the retention period ends, we delete your data by:

Deletion takes up to 90 days for backups to cycle through (we keep rolling daily and weekly backups for safety). Once deleted, the data is gone and cannot be recovered.

9.3 You Can Ask Us to Delete Anytime

You do not have to wait for the service to end. You can ask us to delete your data at any time, and we will delete it (unless we have a legal reason to keep it, like a court order or tax obligation).

9.4 Backup Limitations

We keep regular backups of your data for security. These backups are deleted on schedule, even if you ask us to delete live data. There may be a delay of up to 90 days for old backups to be cycled out of our backup system. We cannot expedite backup deletion; this is a technical limitation.

We may keep some data longer if the law requires it (for example, tax and accounting records). We will only keep what the law requires and will delete it as soon as we legally can.


10. International Data Transfers

10.1 Where Your Data Is Stored

Your data is stored on Cloudflare's global network, which stores and processes data across multiple countries (Cloudflare is headquartered in the United States). Some of our sub-processors (section 5) are also based in the United States.

10.2 Transfers Outside the EU

If you are in the EU and your customers are in the EU, their data may be stored and processed outside the EU (including in the United States and Australia). This is a transfer of personal data to non-EU countries. To make this transfer lawful, Launchr relies on the following legal mechanisms:

Standard Contractual Clauses (SCCs): This DPA incorporates the EU's Standard Contractual Clauses, which are approved transfer mechanisms. By agreeing to this DPA, you are accepting these clauses as the legal basis for the transfer.

What that means: The clauses require both Launchr and you to commit to specific data protection rules even though Australia is outside the EU. They are designed to make transfers safe.

Your rights: You have the right to object to this transfer mechanism if you have a specific reason to believe it does not provide adequate protection. If you object, we will discuss alternatives (like encrypting data so we cannot access it, or moving to EU hosting).

10.3 Sub-Processor Transfers

Some of our sub-processors are also outside the EU (for example, Cloudflare has global infrastructure, Stripe is in the US). The same transfer mechanisms (SCCs) apply to those transfers.

10.4 If You Are in Australia

If you are in Australia, your data may still be stored and processed overseas on our sub-processors' infrastructure. Australian Privacy Principle 8 (cross-border disclosure) applies: we take reasonable steps to ensure overseas providers handle your data consistently with Australian privacy law.


11. Audits and Inspections

11.1 Your Right to Audit

Under GDPR Article 28(3)(h), you have the right to audit Launchr and our sub-processors to make sure we are following this agreement.

You can ask us:

11.2 How We Will Help

We will provide:

11.3 Reasonable Limits

We will cooperate with reasonable audit requests. We cannot provide:

We aim to respond to audit requests within 30 days. Complex audits may take longer.


12. Australian Consumer Law

12.1 Consumer Guarantees Are Not Affected

This Data Processing Agreement does not replace or limit any rights you have under Australian Consumer Law (the Competition and Consumer Act 2010).

You may have guarantees that goods and services are of a certain quality, fit for a particular purpose, and supplied in a timely manner. This DPA does not remove those guarantees.

Launchr's data security and protection obligations sit on top of Australian Consumer Law. If we breach either, you have rights under both.

12.2 You Can Still Sue for Breach of ACL

If Launchr fails to provide services with due care and skill, or if we breach a consumer guarantee, you can take action under Australian Consumer Law. This DPA is not a waiver of those rights.

12.3 Launchr's Separate Warranty

Launchr provides a separate warranty in the Launchr Terms of Service: if we cannot deliver your service working as pitched, you are refunded in full. That warranty is separate from this DPA and your ACL rights.


13. Your Obligations as Data Controller

13.1 You Must Tell Us What to Do

As the Data Controller, you are responsible for giving Launchr instructions about how to process your customers' data. We will only process data in the way you have asked.

13.2 You Must Have Permission

You are responsible for:

We will assume you have done these things. If you have not, that is a breach of privacy law—and it is your responsibility, not ours.

If a court, government agency, or police asks you to provide your customers' data, you must tell Launchr. We will help if we can, but we cannot give data to third parties without your permission (except as required by law).

13.4 You Must Tell Us About Privacy Complaints

If one of your customers complains about privacy or asks to exercise a data subject right, let us know. We will help you respond.


14. Termination and Exit

14.1 What Happens When the Service Ends

When your contract with Launchr ends (because the build is complete or you cancel Run), here is what happens:

Handover: You get your complete app, source code, databases, and everything we have built. It is yours to keep or migrate to another host.

Deletion: We delete our working copies and backups, except where we have a legal obligation to keep records. This takes up to 90 days.

No New Processing: We stop processing your data the moment the service ends.

14.2 You Can Request Early Deletion

If you want us to delete your data before the service ends, ask us. We will do it unless you still need the service.

14.3 Survival

Some parts of this DPA survive termination:


15. Limitation of Liability

15.1 What Launchr Is Not Liable For

To the maximum extent permitted by law, Launchr is not liable for:

15.2 What We Are Liable For

Launchr is liable for:

15.3 Liability Cap

Launchr's total liability for any claim is capped at the amount you have paid us in the 12 months before the claim. If you have not paid us anything, the cap is AUD $1,000.

Exception: This cap does not apply to:

15.4 You Understand the Risks

You understand that:


16. Changes to This Agreement

16.1 When We Change the DPA

If we need to change this DPA (for example, if privacy law changes), we will:

16.2 Non-Negotiable Changes

Some changes are non-negotiable (like complying with a new law or fixing a security issue). Other changes we can discuss.


17. How to Contact Us

17.1 Questions About This Agreement

If you have questions about data processing, privacy, or this DPA, contact us:

Email: [email protected]
Web: launchr.bot/legal
Address: Launchr Pty Ltd, Brisbane, Queensland, Australia
ABN: 46 696 518 206

17.2 Data Breach Notification

If you discover a data breach or security issue, tell us immediately:

Email: [email protected] (mark urgent)
Phone: +61 7 4800 4040

17.3 Privacy Complaints

If you have a complaint about how we handle data, contact the Office of the Australian Information Commissioner:

Web: www.oaic.gov.au
Phone: 1300 363 992

If your customers are in the EU, they can complain to their local privacy regulator (Data Protection Authority).


18. Definitions

Data Controller: The person or organisation that decides why and how personal data is processed. For Launchr, this is you (the client).

Data Processor: The person or organisation that processes personal data on behalf of the Data Controller. For Launchr, this is us.

Personal Data: Any information about an identified or identifiable person.

Processing: Anything done with personal data: collecting it, storing it, analysing it, sharing it, deleting it, etc.

Sub-Processor: A third-party service that processes personal data on behalf of the Processor (Launchr).

Breach: Unauthorised access, disclosure, alteration, or destruction of personal data.

GDPR: General Data Protection Regulation (EU 2016/679).

Standard Contractual Clauses (SCCs): EU-approved terms for transferring personal data outside the EU.

TLS: Transport Layer Security, a protocol for encrypting data in transit.

AES-256: A strong encryption standard for data at rest.


19. Governing Law and Jurisdiction

19.1 Queensland Law

This Data Processing Agreement is governed by the laws of Queensland, Australia. Both you and Launchr agree to submit to the jurisdiction of the Queensland courts.

19.2 GDPR Compliance

To the extent this agreement is used for processing personal data of EU residents, it also complies with the GDPR (EU 2016/679) and equivalent privacy laws in other countries.

19.3 Conflict of Laws

If Queensland law and GDPR conflict, GDPR takes precedence for processing personal data of EU residents.


20. Entire Agreement

20.1 Complete Terms

This Data Processing Agreement, together with the Launchr Terms of Service, Privacy Policy, and Service Level Agreement, makes up the complete agreement between you and Launchr about data processing.

20.2 Precedence

If this DPA conflicts with another Launchr agreement, this DPA takes precedence on matters of data processing and personal data protection.

20.3 No Third-Party Beneficiaries

This agreement is between you and Launchr only. Your customers are not parties to this agreement, although they benefit from the data protection it provides.


21. Severability

If any part of this agreement is found to be illegal or unenforceable, that part will be removed, and the rest will stay in force. We will try to replace the removed part with something that achieves the same legal effect.


Appendix A: Standard Contractual Clauses (SCCs)

For transfers of personal data from the EU to Australia, this DPA incorporates the Standard Contractual Clauses approved by the European Commission. The clauses are set out in full at:

EU Implementing Decision 2021/914
Module Two (controller to processor) and Module Three (processor to processor)

By agreeing to this DPA, you are accepting these clauses as the legal mechanism for data transfers. Launchr and you are both bound by the terms of the SCCs, including:

A full copy of the SCCs is available on request.


Appendix B: Sub-Processor Details

Current Sub-Processors as of 21 August 2026

NameLocationPurposeContact
Cloudflare, Inc.USA (global network)Cloud hosting, compute, databases, storagewww.cloudflare.com/privacypolicy
StripeUSAProcessing your payments to Launchrwww.stripe.com/privacy
ResendUSATransactional email deliveryresend.com/legal/privacy-policy
AnthropicUSAAI processing (builds and agent operations)www.anthropic.com/legal/privacy
OpenAIUSAAI processing (agent operations)openai.com/policies/privacy-policy

Adding New Sub-Processors

If Launchr needs to add a new sub-processor, we will notify you at least 30 days before. You can object by contacting [email protected]. If you object, we will:

  1. Not use the new sub-processor for your data, or
  2. Help you move your data to another provider

Acknowledgment

By using any Launchr service, you are agreeing to this Data Processing Agreement. You confirm that:

  1. You have read and understood this DPA
  2. You have the authority to bind your organisation to this agreement
  3. You are the Data Controller for the personal data you process through Launchr
  4. You will instruct Launchr on how to process your data
  5. You understand the risks and limitations of Launchr's security
  6. You will comply with privacy law and your obligations to data subjects

Launchr Pty Ltd
ABN 46 696 518 206
Brisbane, Queensland, Australia

Effective: 21 August 2026


Version 1.0 — First Rewrite
This agreement replaces all previous data processing statements and is effective immediately for all new and existing Launchr contracts.