Data Processing Addendum
Last updated: July 24, 2026
Parties and Scope
This Data Processing Addendum (DPA) forms part of the Customer Subscription Agreement between the organisation using TaskForceOne (Customer) and ROVYN (ABN 85 581 687 451) (ROVYN, we, us). It applies to personal information ROVYN processes to provide the TaskForceOne service on the Customer's behalf (Customer Personal Information).
Australian privacy law does not use “controller” and “processor” as general statutory roles. In this DPA, those expressions may be used descriptively: the Customer decides why workforce information is used, and ROVYN processes it to provide the configured service.
Customer Instructions
The Customer instructs ROVYN to process Customer Personal Information to provide, secure, support, maintain, and improve the subscribed service; enable integrations selected by the Customer; prevent fraud and misuse; comply with applicable law; and carry out other documented instructions agreed by the parties.
ROVYN will not sell Customer Personal Information or use it for independent advertising. If an instruction appears unlawful or outside the service, ROVYN may pause the affected processing and notify the Customer.
Customer Responsibilities
The Customer is responsible for:
- having authority to collect, disclose, and instruct processing of Customer Personal Information;
- providing collection, monitoring, workplace-surveillance, and privacy notices and obtaining required consents;
- configuring access, retention, integrations, location features, and exports appropriately;
- ensuring instructions and Customer Data are lawful, accurate, relevant, and not excessive; and
- responding to workforce complaints, corrections, employment matters, and record-keeping duties.
Confidentiality and Access
ROVYN will limit access to personnel and service providers who need it for an authorised purpose and who are subject to confidentiality obligations. ROVYN will maintain role and authentication controls appropriate to the nature of the service. The Customer remains responsible for its authorised users, role assignments, and account-security practices.
Security Measures
Taking account of the nature of the information and reasonably foreseeable harm, ROVYN will maintain a security program that includes, as appropriate:
- encryption in transit;
- logical separation of customer organisations and role-based access controls;
- credential, secret, and integration-token protections;
- security logging and error monitoring.
Security is a shared responsibility. No internet service can guarantee that every incident or data loss will be prevented.
Security Incidents
ROVYN will notify the Customer without undue delay after confirming unauthorised access to or loss, disclosure, or alteration of Customer Personal Information that materially affects the Customer (Security Incident). We will provide information reasonably available to help the Customer assess impact, meet notification duties, and take protective action.
ROVYN may investigate, contain, remediate, and make legally required notifications. Notification is not an admission of fault. Routine unsuccessful attacks, scans, and blocked attempts are not Security Incidents unless they result in unauthorised access or material impact.
Individual Requests and Regulatory Assistance
Where the Customer cannot reasonably fulfil an access, correction, deletion, or complaint request using the service, ROVYN will provide reasonable assistance appropriate to its role. If ROVYN receives a request relating mainly to Customer-controlled workforce information, it may refer the person to the Customer unless law prevents this.
ROVYN will provide reasonable information needed for a privacy impact assessment, regulator enquiry, or Notifiable Data Breaches assessment concerning the service. Material assistance beyond standard documentation may be chargeable if agreed in advance.
Subprocessors and Overseas Processing
The Customer generally authorises ROVYN to use the applicable subprocessors in the Service Provider and Subprocessor Register. ROVYN will require providers handling Customer Personal Information to protect it under written terms appropriate to their role.
Some providers operate in multiple countries. ROVYN will take reasonable steps required of it under applicable Australian privacy law for overseas disclosures. The Customer acknowledges that enabling an integration instructs ROVYN to send relevant information to that integration provider.
Return, Deletion, and Account Closure
During the subscription, the Customer may use available export and deletion functions or request reasonable assistance. On termination, organisation access may be restricted or archived. Deletion, de-identification, and return requests are handled subject to the retention and account-closure limits described in the Privacy Policy, Customer instructions, backup cycles, legal requirements, security needs, and dispute-preservation obligations.
The Customer must export records it needs before termination. ROVYN does not assume the Customer's Fair Work, payroll, tax, or employment record-keeping duties and does not promise to retain an accessible archive for the Customer after termination unless agreed in writing.
Review and Assurance
On reasonable request, ROVYN will provide available security and privacy information needed to assess compliance with this DPA. If that is insufficient and law requires further review, the parties will agree a proportionate method that protects other customers, confidential information, and service security. Reviews must not include access to another customer's data or disruptive production testing.
Processing Details
- People: Customer administrators, workers, contractors, applicants or invitees, workplace contacts, and people appearing in uploaded material.
- Information: identity and contact details; employment and role information; rosters; availability; leave; time and attendance; precise clock-in location; pay settings; integration identifiers; messages; files; licences; certificates; signatures; audit, device, and usage data.
- Purpose: workforce scheduling, time and attendance, communications, document workflows, payroll exports, account administration, support, security, and related configured functions.
- Duration: the subscription and the limited period afterwards required for documented deletion, de-identification, backups, legal obligations, security, and dispute handling.
Conflict and Changes
This DPA prevails over the Customer Subscription Agreement for a direct conflict about processing Customer Personal Information. ROVYN may update it to reflect service or legal changes, subject to the material-change notice provisions in the Customer Subscription Agreement.
Contact
Privacy and DPA enquiries can be sent to [email protected].