Who this applies to: This Data Processing Agreement (DPA) applies to business customers who use Navo to process personal information of their own clients, such as buyers agents, property advisors, and development companies using Navo on behalf of third parties.
Individual users using Navo for their own projects are governed by the Privacy Policy only.
1. Definitions
In this DPA:
- Controller means the business customer who determines the purpose and means of processing personal data of their clients
- Processor means Yapa Technologies Pty Ltd, which processes personal data on behalf of the Controller
- Personal Data means any information relating to an identified or identifiable natural person
- Processing means any operation performed on personal data, including storage, retrieval, and deletion
- Australian Privacy Law means the Privacy Act 1988 (Cth) and the Australian Privacy Principles
2. Scope and Purpose
This DPA governs the processing of personal data that the Controller uploads to Navo in connection with its business operations. Yapa Technologies processes this data solely to provide the Navo platform services as described in the Terms of Service and on the instructions of the Controller.
Yapa Technologies does not process personal data for its own purposes beyond providing the platform service, and will not sell, trade, or disclose personal data to third parties except as required to provide the service (Supabase, Stripe, Resend, Vercel) or as required by law.
3. Controller Obligations
As the Controller, you are responsible for:
- Ensuring you have a lawful basis for uploading personal data of third parties to Navo
- Providing required privacy notices to the individuals whose data you upload
- Obtaining necessary consents from those individuals where required by Australian Privacy Law
- Ensuring the personal data you upload is accurate and up to date
- Responding to access and correction requests from individuals whose data you store in Navo
4. Processor Obligations (Yapa Technologies)
Yapa Technologies agrees to:
- Process personal data only on documented instructions from the Controller (as set out in these terms and the platform functionality)
- Ensure that persons authorised to process the data are bound by confidentiality obligations
- Implement appropriate technical and organisational security measures
- Assist the Controller in responding to access and deletion requests from individuals
- Delete or return personal data upon termination of the Controller's account, at the Controller's election
- Provide information reasonably necessary to demonstrate compliance with this DPA
- Notify the Controller within 72 hours of becoming aware of a personal data breach affecting Controller data
5. Sub-Processors
Yapa Technologies uses the following approved sub-processors to deliver the platform:
| Sub-processor | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication, storage | Australia (Sydney, ap-southeast-2) |
| Stripe | Payment processing | Ireland / United States |
| Resend | Transactional email | United States |
| Vercel | Platform hosting | Global edge network |
We will notify Controllers of any material changes to our sub-processor list with 30 days notice.
6. Data Security
Yapa Technologies implements the following security measures:
- Encryption in transit (TLS 1.2 or higher) and at rest (AES-256)
- Supabase Row Level Security ensuring logical data isolation between accounts
- Role-based access controls limiting staff access to personal data
- Regular security reviews and penetration testing (planned post-launch)
- Multi-factor authentication for platform administration
7. Data Retention and Deletion
Personal data uploaded by the Controller is retained for the life of the Controller's account. On account cancellation, data is retained for 12 months then deleted, unless the Controller requests earlier deletion. Financial records are retained for 7 years as required by Australian tax law, regardless of cancellation.
To request deletion of personal data before the standard retention period, email hello@navosuite.com.
8. International Transfers
Data may be transferred to or accessed from outside Australia by sub-processors (see Section 5). Yapa Technologies ensures appropriate safeguards are in place for all international transfers, consistent with the Australian Privacy Principles.
9. Audit Rights
Enterprise customers may request information to verify compliance with this DPA. Yapa Technologies will respond to reasonable audit requests within 30 days. On-site audits require 30 days notice and may be subject to a reasonable fee.
10. Term and Termination
This DPA is effective for the duration of the Controller's subscription to Navo and terminates automatically on account closure. Obligations relating to personal data already processed survive termination for the applicable retention period.
11. Governing Law
This DPA is governed by the laws of New South Wales, Australia, and the Australian Privacy Act 1988 (Cth).
12. Contact
Data processing enquiries: hello@navosuite.com
Yapa Technologies Pty Ltd · ABN 21 697 117 936 · NSW, Australia