← Back to home

Data Processing Agreement

Last updated: 1 April 2026

1. Purpose

This Data Processing Agreement ("DPA") sets out how AI Lab Australia Pty Ltd (ABN 29 689 971 364) processes personal information on behalf of clients using the SydClaw platform, in compliance with the Privacy Act 1988 (Cth) and the Privacy and Other Legislation Amendment Act 2024.

2. Data Categories

CategoryRetention
Contact informationDuration + 60 days
Communication contentDuration + 60 days
Financial dataDuration + 7 years
Safety recordsDuration + 7 years
Authentication dataDuration only

3. PII Tokenisation

Before any data is sent to external AI model providers (Anthropic, OpenAI), all personally identifiable information is tokenised using 17+ detection patterns. No PII is transmitted in plaintext. Token mappings are stored encrypted in the client's isolated database.

4. Data Location

All data is stored and processed in Australia (AWS ap-southeast-2, Sydney). No client data is stored outside Australia unless explicitly agreed in writing.

5. Sub-Processors

ProcessorPurposeData Sent
Supabase (AWS)DatabaseAll data (encrypted)
VercelHostingSession data
AnthropicAI inferenceTokenised only
OpenAIAI fallbackTokenised only
StripeBillingBilling data only

6. Encryption

At rest: AES-256-GCM with per-organisation keys. In transit: TLS 1.3. Credentials: AES-256-GCM with scrypt-derived keys. Backups: Supabase managed encryption.

7. Breach Notification

Client notified within 24 hours. OAIC notified within 72 hours if required under the Notifiable Data Breaches scheme.

8. Contact

Privacy enquiries: info@ailabaustralia.com

AI Lab Australia Pty Ltd | ABN 29 689 971 364 | Sydney, Australia