Data Processing Addendum
The DPA governing BrightPath AI Solutions processing customer data in DeskMate. Last updated 27 July 2026.
Scope and roles
This addendum forms part of the agreement between BrightPath AI Solutions Pty Ltd (Processor) and the Customer (Controller) and applies wherever DeskMate processes personal data on the Customer's behalf.
Subject matter and duration
Processing continues for the term of the agreement and for the deletion window that follows it, and covers only the categories of data the Customer connects.
Nature and purpose of processing
Execution of Customer-configured Skills, storage of the resulting artefacts and audit records, and provision of support requested by the Customer.
Categories of data subjects
- The Customer's personnel
- The Customer's clients and their personnel
- Any individual named in content the Customer connects
Processor obligations
We process only on documented instruction, ensure personnel are bound by confidentiality, and implement the technical and organisational measures described in the security schedule.
Sub-processing
The Customer authorises the sub-processors on our published list. We give notice before adding one, and the Customer may object on reasonable data-protection grounds.
Security measures
- Encryption in transit (TLS 1.3) and at rest
- OAuth tokens encrypted with AES-GCM
- Fail-closed tenant isolation before any primitive executes
- Least-privilege access with audit logging
Assistance to the Controller
We assist with data subject requests, impact assessments and regulator engagement, taking into account the nature of the processing and the information available to us.
Personal data breach
We notify the Customer without undue delay and within 72 hours of assessing a breach, with the facts known at that point and updates as the assessment continues.
Deletion and return
On termination we delete tenant personal data within 30 days including backups, or return it in a structured export if requested before that window closes.
Audit
We make available the information necessary to demonstrate compliance and will accommodate one audit per year on reasonable notice, subject to confidentiality.
International transfers
Processing occurs solely in australia-southeast1. No international transfer occurs in the ordinary operation of the service.
Questions about this?
Legal and privacy enquiries go straight to a human, not a ticket queue.
Contact us