Data Processing Agreement — Launchr

Effective: 27 May 2026 · Last updated: 4 July 2026 · ABN 46 696 518 206 · Launchr Pty Ltd

1. AGREEMENT OVERVIEW

This Data Processing Agreement ("DPA") forms part of the Terms of Service for Launchr platform. It applies when you process personal data subject to the EU General Data Protection Regulation (GDPR) or similar data protection laws.

1A. AN AGENT-DRIVEN COMPANY

Launchr is an Agent-driven company. Our Agents — artificial intelligence (AI) systems — perform much of the Processor's work under this DPA, including automated processing of Personal Data, subject to human verification and the technical and organisational measures described in Schedule A. AI systems can make mistakes; we take all reasonable steps to catch errors before they affect Personal Data. Liability under this DPA is allocated in section 10 of this DPA and limited as set out in sections 10 and 11 of the Terms of Service, which do not exclude rights that cannot lawfully be excluded.

2. DEFINITIONS

2.1 GDPR Definitions

2.2 Agreement Definitions

3. ROLES AND RESPONSIBILITIES

3.1 Controller Responsibilities

As Controller, you are responsible for:

3.2 Processor Responsibilities

As Processor, we are responsible for:

3.3 Joint Responsibilities

Both parties are responsible for:

4. PROCESSING DETAILS

4.1 Subject Matter

Processing of Personal Data through the Platform for the purposes of providing the Services.

4.2 Duration

For the duration of your subscription to the Platform.

4.3 Nature and Purpose

Processing necessary to provide the Platform services, including:

4.4 Types of Personal Data

May include:

4.5 Categories of Data Subjects

May include:

5. PROCESSOR OBLIGATIONS

5.1 Processing Instructions

We will:

5.2 Confidentiality

We will:

5.3 Security Measures

We implement appropriate technical and organisational measures including:

Technical Measures:

Organisational Measures:

5.4 Sub-processing

5.4.1 Authorised Sub-processors

You authorise us to engage the following Sub-processors:

Sub-processor Purpose Location Safeguards
StripePayment processingGlobal (US-based)Standard Contractual Clauses
AnthropicAgent (AI) processing — see section 1AUnited StatesStandard Contractual Clauses, encryption
CloudflareHosting and infrastructureGlobal (US-based, Australian points of presence)Standard Contractual Clauses, encryption
ResendEmail communicationsGlobal (US-based)Standard Contractual Clauses
TwilioTelephony and SMSUnited StatesStandard Contractual Clauses
ElevenLabsVoice synthesisUnited StatesStandard Contractual Clauses

5.4.2 Sub-processor Requirements

We will:

5.5 Data Subject Rights

We will:

5.6 Data Breach Notification

We will:

5.7 Data Protection Impact Assessment

We will:

5.8 Records of Processing

We maintain records of processing activities as required by Article 30 of the GDPR.

6. CONTROLLER OBLIGATIONS

6.1 Lawful Basis

You must:

6.2 Instructions

You must:

6.3 Security

You must:

6.4 International Transfers

If transferring data to us from the EEA, you must:

7. DATA TRANSFERS

7.1 Transfer Mechanisms

For international data transfers, we rely on:

7.2 Supplementary Measures

We implement supplementary measures including:

7.3 Government Access Requests

We will:

8. DATA RETENTION AND DELETION

8.1 Retention Periods

We retain Personal Data:

8.2 Deletion Procedures

Upon termination of services:

8.3 Data Return

You may request return of your data at any time through Platform export features.

9. AUDIT RIGHTS

9.1 Audit Scope

You have the right to audit our compliance with this DPA, subject to:

9.2 Audit Methods

Audits may be conducted through:

9.3 Third-Party Audits

We undergo regular third-party security audits and will share:

9.4 Cost Allocation

You bear costs of audits, except where audits reveal material non-compliance.

10. LIABILITY AND INDEMNIFICATION

10.1 Liability Allocation

Each party is liable for its own violations of data protection laws.

10.2 Indemnification

You agree to indemnify us against claims arising from:

10.3 Limitation of Liability

Subject to applicable law, our liability under this DPA is limited as per the Terms of Service.

11. TERM AND TERMINATION

11.1 Term

This DPA remains in effect while we process Personal Data on your behalf.

11.2 Termination

Either party may terminate if:

11.3 Survival

Sections on confidentiality, liability, and data protection survive termination.

12. GOVERNING LAW AND DISPUTES

12.1 Governing Law

This DPA is governed by Queensland, Australia law, without regard to conflict of law principles.

12.2 Dispute Resolution

Disputes will be resolved as per the Terms of Service.

12.3 Supervisory Authority

For GDPR matters, the supervisory authority is the Office of the Australian Information Commissioner (OAIC), acting as lead authority for cross-border processing.

13. CONTACT INFORMATION

13.1 Data Protection Officer

Our Data Protection Officer can be contacted at: Email: [email protected]
Address: 81-83 Campbell St, Surry Hills NSW 2010

13.2 General Contact

Launchr Pty Ltd
81-83 Campbell St, Surry Hills NSW 2010
ABN: 46 696 518 206
Website: launchr.bot

14. SCHEDULES

Schedule A: Technical and Organisational Measures

Technical Measures:

  1. Encryption: AES-256 encryption at rest, TLS 1.2+ in transit
  2. Access Controls: Role-based access control, multi-factor authentication
  3. Network Security: Firewalls, intrusion detection, DDoS protection
  4. Monitoring: Regular security log review and scheduled automated scanning during Australian business hours (AEST 9:00–17:00, Mon–Fri, excluding public holidays). Incident detection and response operates during business hours with after-hours escalation for critical incidents via third-party status services.
  5. Backup: Regular backups, geographic redundancy

Organisational Measures:

  1. Policies: Data protection policy, security policy, incident response plan
  2. Training: Regular employee training on data protection
  3. Audits: Regular internal and external security audits
  4. Incident Response: Documented procedures for security incidents
  5. Vendor Management: Due diligence on Sub-processors

Schedule B: Sub-processor List

Sub-processor Service Location Data Transferred Safeguards
StripePayment processingGlobal (US-based)Payment informationSCCs, encryption
AnthropicAgent (AI) processingUnited StatesContent and communications submitted for processingSCCs, encryption
CloudflareHosting and infrastructureGlobal (US-based, AU points of presence)All Platform dataSCCs, encryption
ResendEmail communicationsGlobal (US-based)Email addresses, contentSCCs, encryption
TwilioTelephony and SMSUnited StatesPhone numbers, call/message contentSCCs, encryption
ElevenLabsVoice synthesisUnited StatesCall audio, transcriptsSCCs, encryption

Schedule C: International Transfer Mechanisms

Transfer Scenario Mechanism Supplementary Measures
EEA to AustraliaSCCsEncryption, access controls, audit rights
UK to AustraliaUK SCCsEncryption, access controls, audit rights
Switzerland to AustraliaSwiss SCCsEncryption, access controls, audit rights
Other countriesSCCs or BCRsCase-by-case assessment