Data Processing Agreement
How ID Posture processes Personal Data on a customer's behalf in connection with the Service.
1. Definitions
- Personal Data: has the meaning given to “personal information” in the Privacy Act 1988 (Cth), and includes any personal data processed by the Processor on the Controller's behalf under this DPA.
- Processing: any operation performed on Personal Data, including collection, storage, use, disclosure, and deletion.
- Data Subject: an identified or identifiable individual to whom Personal Data relates.
- Subprocessor: any third party engaged by the Processor to process Personal Data on the Processor's behalf in providing the Service.
- Personal Data Breach: an unauthorised or unlawful access to, or disclosure, loss, alteration, or destruction of, Personal Data.
2. Roles of the parties
The Controller determines the purposes and means of processing its own identity data by connecting its Microsoft Entra ID tenant (and, optionally, Azure subscriptions) to the Service and configuring which permissions to grant and which optional features to enable. The Processor processes Personal Data solely on the Controller's documented instructions, as set out in this DPA and the Controller's own configuration of the Service, and for no other purpose.
3. Subject matter, duration, nature and purpose of processing
- Subject matter: provision of the ID Posture identity security posture management Service.
- Duration: for the term of the Controller's subscription (including any trial period), plus the retention period described in section 8.
- Natureautomated collection (via read-only Microsoft Graph API and Azure Resource Manager access), evaluation, scoring, storage, and presentation of identity configuration data and, where the Controller has connected Azure subscriptions and enabled the relevant optional category, Azure resource configuration data (e.g. database, networking, Key Vault, storage, and container-service configuration).
- Purpose: to assess and report on the security posture of the Controller's Microsoft Entra ID tenant and (where connected) Azure subscriptions, for the Controller's own use.
4. Categories of Data Subjects
- Members of the Controller's own workforce whose accounts exist in the connected Microsoft Entra ID tenant (“member users”)
- External/guest accounts in the connected tenant (“guest users”)
- Individuals the Controller invites to sign into the ID Posture portal itself
5. Categories of Personal Data
Processing is limited to the following, and nothing beyond it:
- Directory metadata: display name, user principal name / email, account status, licence assignment, sign-in activity timestamps, MFA registration status, group and role memberships
- Application/service principal metadata: display name, owner identities, credential expiry dates (not credential values)
- Azure role assignment metadata (subscription/resource-group/resource scope), where the Controller has connected Azure subscriptions
- Azure resource configuration metadata, where the Controller has connected Azure subscriptions and enabled the relevant optional category: e.g. whether an Azure SQL Server/database, Cosmos DB account, Azure Cache for Redis/Managed Redis instance, virtual network/network security group, Key Vault, Storage account, or Azure Kubernetes Service cluster requires Microsoft Entra ID authentication, its network access configuration, and similar security-relevant settings. This is configuration data about how a resource is set up, not Personal Data about an identifiable individual, but is processed as part of the Service.
- ID Posture portal account details for individuals the Controller invites: name, email address, role
The Processor does not process passwords, authentication secret values, credential/certificate values, sign-in log content, email content, or file content. All processing is via read-only API access; the Processor has no ability to modify the Controller's Microsoft 365 or Azure environment.
By design, the categories of Personal Data above are stored separately from aggregate scoring data, and are not held in the Processor's primary relational database except for two narrowly-scoped features (Drift Detection and Accepted Risks) that the Controller may optionally enable, each of which stores only a display name/object identifier snapshot of the specific object each record concerns.
6. Processor obligations
The Processor:
- will process Personal Data only on the Controller's documented instructions (including as configured through the Service itself), unless required otherwise by Australian law, in which case the Processor will inform the Controller before processing unless legally prohibited from doing so;
- ensures personnel authorised to process Personal Data are subject to confidentiality obligations;
- implements appropriate technical and organisational security measures (section 7);
- will not engage a Subprocessor without providing the notice described in section 9;
- will assist the Controller, taking into account the nature of the processing, in responding to requests from Data Subjects to exercise their rights, to the extent the Controller cannot reasonably fulfil this itself using the Service's own functionality;
- will assist the Controller in meeting its obligations relating to the security of processing, data breach notification, and (if applicable) data protection impact assessments, taking into account the information available to the Processor;
- at the Controller's election, will delete or return all Personal Data on termination of the Service, per section 8, except to the extent retention is required by law;
- will make available to the Controller information reasonably necessary to demonstrate compliance with this DPA, and allow for and contribute to audits, including inspections, conducted by the Controller or an auditor mandated by the Controller, subject to reasonable notice and to the confidentiality obligations in the Terms of Service.
7. Security measures
The Processor maintains the following technical and organisational measures:
- Hosting in Microsoft Azure's Australia East region
- Row-level security enforced at the database layer on every tenant-scoped table, in addition to application-layer access controls
- All secrets and cryptographic material held in a dedicated key management service (Azure Key Vault), never in application code or configuration files
- Certificate-based, read-only, application-only authentication to the Controller's tenant (no client secret is used, and no write permission is ever requested or held)
- Encryption of data in transit (TLS) and at rest
- Separation of structured/aggregate data (Azure SQL) from underlying identity records (Blob storage), limiting the blast radius of any single-layer compromise
- Regular patching and dependency/vulnerability updates across the Processor's own codebase and infrastructure
- Periodic review of which personnel have access to Controller Personal Data
Not yet formalised, and not claimed above until true: a documented incident response runbook, and a defined employee background-check policy.
8. Data retention and deletion
- During a trial, Personal Data is retained for the 30-day trial period plus a further 14 days, after which it is permanently deleted if the trial is not converted to a paid subscription.
- For paying customers, Personal Data is retained for the term of the subscription.
- On termination, disconnection, or the Controller's written request, the Processor will delete all Personal Data (across database records, file storage, and any generated reports) within 30 days, except where retention is required by law.
- Where the Controller has enabled the customer-facing activity log feature, the Controller separately controls its retention period (30/90/365 days) via the Service's own settings.
9. Subprocessors
The Controller provides general authorisation for the Processor to engage the following Subprocessors:
- Microsoft Azure (Australia East): cloud infrastructure hosting (database, storage, compute)
- Azure Communication Services (Australia East): transactional email delivery
- Cloudflare (global edge network): DNS, content delivery, and DDoS protection in front of Service domains, plus bot-verification on the marketing site's contact form. Handles network/traffic metadata for routing and verification purposes only, not Personal Data at rest
- GitHub (United States, private repository): unattended engineering diagnosis of scan-pipeline failures. Receives operational telemetry only for a failed scan, an internal ID Posture tenant identifier, scan identifier, status, and the raw system error message, to trigger an automated root-cause pass. Never receives the Controller's organisation name, or the identity/directory data described in section 5
The Processor will notify the Controller of any intended addition or replacement of a Subprocessor with access to Personal Data, giving the Controller the opportunity to object on reasonable grounds within 30 days.
Google Analytics and Cloudflare Web Analytics are used on the Processor's marketing website only, for aggregate visitor analytics; they do not process Controller Personal Data under this DPA and are addressed in the Privacy Policy instead, not listed as Service Subprocessors here.
The system error message sent to GitHub is free text generated by underlying Microsoft Graph/Azure APIs. While it is not expected to contain Personal Data, it could in rare cases incidentally include a fragment of directory data (for example, a user principal name) if the originating API error happened to include it. This is a recorded, accepted residual risk, not a designed data flow.
10. International data transfers
Personal Data processed as part of the Service (section 5) is stored exclusively in Microsoft Azure's Australia East region. Cloudflare's role is limited to network-layer routing, DDoS protection, and bot verification for Service domains: it operates on network/traffic metadata only (source/destination addresses, request routing information) and never has access to Personal Data content as defined in section 5. This is not a disclosure of Personal Data requiring APP 8 treatment: APP 8 governs disclosure of personal information to an overseas recipient, and Cloudflare's transient, metadata-only routing role does not constitute access to or disclosure of the Personal Data itself.
11. Liability
Liability, indemnification, and insurance terms are as set out in the underlying subscription agreement between the Controller and the Processor, and are not repeated in this DPA.
12. Personal Data Breach notification
The Processor will notify the Controller without undue delay, and in any event within 30 days, after becoming aware of a Personal Data Breach affecting the Controller's Personal Data, and will provide reasonably available information to assist the Controller in meeting any notification obligations it has under the Notifiable Data Breaches scheme (Privacy Act 1988, Part IIIC).
13. Term, governing law, and precedence
This DPA remains in effect for as long as the Processor processes Personal Data on the Controller's behalf under the Service. It is governed by the laws of Victoria, Australia. In the event of a conflict between this DPA and the underlying subscription agreement regarding the processing of Personal Data, this DPA prevails.
For execution/signature purposes, this DPA forms part of the agreement between SOLUTIONWARE PTY LTD (ABN 81 630 109 643), trading as ID Posture, and the Controller identified in the applicable order form or subscription agreement.