Data Processing Addendum
SysGuard is operated by K and M Finance Solutions Pty Ltd (ABN 99 653 784 064) ("we", "us", "our"). Registered address: Unit 22/67-71 Eton Street, Sutherland NSW 2232 Contact: office@sysguard.com.au
Effective: 1 July 2026
This Addendum forms part of the Platform Terms of Service and applies where we handle personal information on your behalf.
1. Roles
You determine what personal information is collected in your account and why. You are responsible for the lawfulness of that collection and use. We handle it on your behalf and on your documented instructions — which are the Terms, this Addendum, and your configuration and use of the Platform's features.
Where the *Privacy Act 1988* (Cth) uses different terminology, the parties intend that you occupy the position of the entity that controls the information and we occupy the position of a service provider handling it for you.
2. Our commitments
We will:
- process Customer Data only to provide, secure, support and improve the Platform, and as required by law;
- not sell Customer Data, and not disclose it except as set out in the Privacy Policy or as you direct;
- keep personnel who access Customer Data bound by confidentiality and limit access on a least-privilege basis;
- maintain reasonable technical and organisational security measures appropriate to the sensitivity of the data;
- keep each customer's data logically separated from every other customer's;
- assist you, so far as reasonably practicable, in responding to access, correction and complaint requests from individuals; and
- notify you without undue delay on becoming aware of a breach affecting your Customer Data, with the information reasonably available to us, so you can meet your own obligations.
3. Your commitments
You will:
- collect and provide Customer Data lawfully, and give your workers and clients the notices required about its handling, including its disclosure to us and to the providers listed below;
- obtain any consents required, including for tax file numbers and bank details;
- configure roles and permissions so people in your business see only what they should;
- keep your own copies of records as required by clause 8 of the Terms; and
- not upload sensitive information beyond what the Platform is designed for.
4. Subprocessors
We use the following categories of provider to operate the Platform. This list is maintained here and may change; we will give reasonable notice of a change that materially affects the processing of your data.
- Application hosting — hosting of the web application and its APIs.
- Database and file storage — the primary datastore, backups and uploaded documents.
- Email delivery — sending transactional email on your behalf (invoices, statements, notifications).
- AI document processing — reading uploaded timesheets and similar documents and returning structured data. Providers are selected on terms under which request content is not used to train their models.
- Payment processing — where payment features are used, handling card and bank payment data. Full card numbers are handled by the payment provider and are not stored by us.
- Accounting integrations — where you connect them, exchanging invoice and contact data at your direction.
Some providers process data outside Australia. See clause 8 of the Privacy Policy.
Note: the specific provider names, their roles and their processing locations should be listed here before publication.
5. Security measures
Without limiting clause 2: encryption of data in transit; credentials stored only as salted hashes; role-based access control enforced on every request; per-customer scoping of all data access; audit logging of significant actions; routine backups; restricted administrative access; and dependency and vulnerability monitoring.
6. Return and deletion
On termination, clause 22 of the Terms applies: a 30-day window to export, then deletion from active systems, with residual backup copies expiring in the ordinary cycle and retention only where the law requires it.
7. Audit
On reasonable written request, and not more than once a year unless required by a regulator or following a breach affecting your data, we will provide information reasonably necessary to demonstrate compliance with this Addendum. Where an on-site audit is genuinely required by law, the parties will agree reasonable scope, timing and cost in advance, and it must not compromise the confidentiality or security of other customers.