Legal
Data Processing Addendum
Last updated: 25 July 2026
This Data Processing Addendum (“DPA”) forms part of the VendorAlert Terms of Service between VendorAlert Pty Ltd (ABN 37 698 613 268) (“VendorAlert”) and the customer that accepts those Terms (“Customer”).
It applies when VendorAlert processes Customer Personal Data on the Customer's behalf. Capitalised terms not defined here have the meaning given in the Terms or applicable Data Protection Law.
1. Roles and applicable law
As between the parties, Customer is the controller or business and VendorAlert is the processor or service provider for Customer Personal Data. Each party will comply with the privacy and data-protection laws that apply to its role, including the Australian Privacy Act 1988 (Cth) and, where applicable, the EU GDPR and UK GDPR (“Data Protection Law”).
Customer remains responsible for its instructions, the lawfulness, fairness and transparency of its processing, and responding to data subjects unless this DPA expressly assigns assistance to VendorAlert.
2. Processing details
- Subject matter: hosting, synchronising, monitoring and comparing Xero contact payment details; recording changes; managing users and alert recipients; and delivering configured alerts and related support.
- Duration:for the Customer's use of the Service and the deletion and backup periods described in the Privacy Policy, unless law requires longer retention.
- Nature and purpose: collecting from Xero, storing, structuring, comparing, retrieving, displaying, transmitting in alerts, securing, troubleshooting, exporting and deleting data to provide the Service.
- Data subjects: Customer users, Xero organisation users, alert recipients, and the individuals associated with Xero contacts and suppliers.
- Personal data: names, email addresses, roles, identifiers, organisation details, bank account names and numbers, BSB/sort/routing codes, payment references, currencies, change history and attribution, alert and delivery records, access records, IP addresses, and limited diagnostic data.
3. Customer instructions
VendorAlert will process Customer Personal Data only on documented instructions from Customer, including the Terms, this DPA, the Customer's configuration and support requests, unless applicable law requires otherwise. If law requires processing outside those instructions, VendorAlert will inform Customer before processing unless the law prohibits notice.
VendorAlert will promptly tell Customer if, in its reasonable opinion, an instruction infringes Data Protection Law. VendorAlert may suspend the affected processing while the parties resolve the issue.
4. Confidentiality and security
VendorAlert will ensure that people authorised to process Customer Personal Data are bound by confidentiality obligations and access it only as needed for their duties.
Taking into account the nature of the data, available technology, implementation cost and processing risk, VendorAlert will maintain appropriate technical and organisational measures. Current measures include read-only Xero scopes, encryption of Xero OAuth tokens, encryption in transit, access controls and tenant isolation, signature verification for webhooks, audit logging, secure authentication cookies, backups and incident-response procedures. VendorAlert may update measures as long as overall protection is not materially reduced.
5. Subprocessors
Customer generally authorises VendorAlert to use the subprocessors below. VendorAlert will impose data-protection obligations that are no less protective in substance than the obligations in this DPA and remains responsible for each subprocessor's performance as required by Data Protection Law.
- Vercel, Inc. - application hosting and serverless processing; United States and global edge locations.
- Supabase, Inc. and its infrastructure providers - database, authentication and backups; configured project region and provider support locations, including Australia and the United States.
- Inngest, Inc. - durable background-job orchestration; United States.
- Resend, Inc. - transactional email delivery and delivery events; United States and email delivery locations.
- Functional Software, Inc. (Sentry) - error and diagnostic monitoring; United States.
Xero is the Customer-authorised source system rather than a VendorAlert subprocessor. Stripe processes Customer billing information, and Google processes marketing-site analytics only after visitor consent; neither receives Xero contact bank details as part of its ordinary role.
VendorAlert will give reasonable advance notice of a new subprocessor that will process Customer Personal Data. Customer may object on reasonable data-protection grounds within 14 days. The parties will work in good faith on a reasonable solution; if none is available, Customer may terminate the affected Service before the subprocessor begins processing and receive a pro-rata refund of unused prepaid fees for that Service.
6. International transfers
Customer authorises the transfers needed to provide the Service. VendorAlert will use a lawful transfer mechanism where Data Protection Law restricts a transfer, including an adequacy decision, the European Commission's standard contractual clauses, and the UK Addendum or International Data Transfer Agreement as applicable.
If the EU standard contractual clauses apply, the controller-to- processor module is incorporated by reference, this DPA supplies its annex information, the optional docking clause applies, subprocessor authorisation is general with the notice period in Section 5, and the law and courts of Ireland apply where the clauses require an EU Member State selection. The competent supervisory authority is determined under clause 13 of those clauses.
7. Data-subject requests
Taking into account the nature of processing, VendorAlert will provide reasonable assistance for Customer to respond to requests to access, correct, delete, restrict, object to or export Customer Personal Data. If VendorAlert receives a request concerning Customer Personal Data, it will refer the requester to Customer where lawful and will not respond substantively unless Customer instructs it or law requires it.
8. Security incidents
VendorAlert will notify Customer without undue delay after becoming aware of a confirmed personal-data breach affecting Customer Personal Data. The notice will include available information about the nature of the incident, affected data and people, likely consequences, and containment and remediation measures. VendorAlert will provide reasonable cooperation and updates. Notification is not an admission of fault or liability.
Customer is responsible for notifications to regulators and data subjects unless law places that obligation directly on VendorAlert.
9. Compliance assistance
VendorAlert will provide reasonable information and assistance needed for Customer's security assessments, breach obligations, data protection impact assessments and prior consultations, taking into account the processing and information available to VendorAlert.
10. Return and deletion
During an active account, Customer may use available exports. On disconnect, VendorAlert revokes the Xero connection and deletes the organisation's operational data after the 90-day grace period, unless an authorised user reconnects it. On verified account closure or at Customer's written request after the Service ends, VendorAlert will delete or de-identify Customer Personal Data unless law requires retention. Data in backups is isolated from ordinary use and removed as backups expire.
Limited billing, security and audit records may be retained under the Privacy Policy. Those records remain protected by this DPA while they contain Customer Personal Data.
11. Information and audits
On reasonable written request, VendorAlert will provide information needed to demonstrate compliance with this DPA. If that information is insufficient, Customer may conduct one audit per year through an independent, non-competing auditor bound by confidentiality, on at least 30 days' notice, during normal business hours and without unreasonably disrupting the Service. Additional audits are permitted after a relevant personal-data breach or where a regulator requires them.
Customer bears its audit costs and VendorAlert's reasonable costs for assistance beyond information routinely made available, unless an audit identifies a material breach by VendorAlert.
12. Order of precedence and liability
If this DPA conflicts with the Terms on processing Customer Personal Data, this DPA controls. The limitations and exclusions of liability in the Terms apply to this DPA to the extent permitted by Data Protection Law. Nothing in this DPA reduces a data subject's rights or limits liability that cannot lawfully be limited.
13. Contact
Data-protection questions and instructions may be sent to hello@vendoralert.com.au.