This Data Processing Agreement ("DPA") forms part of the Terms & Conditions between your company ("Customer") and MineDesk, and describes how MineDesk handles personal data on Customer's behalf when Customer uses Approve2Go.
For personal data entered into Approve2Go (employee records and safety-form submissions), Customer is the data controller and determines the purposes and means of processing. MineDesk acts as data processor, processing that personal data only on Customer's documented instructions as set out in this DPA and the Terms.
| Category | Examples |
|---|---|
| Employee identity & contact data | Full name, role, site, contact email and/or phone number, login PIN (for PIN-based accounts) |
| Safety submission data | Answers given on safety forms, timestamps, GPS location at time of submission, approval decisions and who made them |
| Billing contact data | Admin name and email associated with a paid subscription (payment card details are never held by MineDesk — see Section 7) |
MineDesk processes this data solely to provide, operate, and support Approve2Go for Customer — including hosting, displaying, and storing it; enabling the approval workflow; sending account-related emails (e.g. login credentials, password resets); and, where applicable, providing the platform-level support described in the Terms.
MineDesk will: process personal data only on Customer's instructions (which Approve2Go's own configuration and features constitute); ensure personnel with access are subject to confidentiality obligations; implement appropriate technical and organisational security measures (see MineDesk's Security Overview, available on request); assist Customer in responding to data subject requests and, where legally required, in meeting Customer's own obligations relating to data security and breach notification; and not engage a new subprocessor without giving Customer reasonable notice and an opportunity to object.
Customer authorises MineDesk to engage the following subprocessors, each of which processes personal data only to the extent needed to provide their respective infrastructure or communication service to Approve2Go:
| Subprocessor | Purpose |
|---|---|
| Supabase | Database hosting, authentication |
| Vercel | Web application hosting |
| Stripe | Payment processing (subscription billing) |
| Resend | Transactional email delivery (login credentials, notifications) |
| Cloudflare | DNS, bot/abuse protection |
| Anthropic | AI-assisted PDF form extraction, used only when an Admin uploads a form to be digitised |
MineDesk remains responsible for each subprocessor's compliance with data protection obligations equivalent to those in this DPA.
Approve2Go's infrastructure is provided by the subprocessors listed above, each operating their own global hosting regions. If your organisation has a specific data-residency requirement (for example, data remaining within Australia), contact us via enquiry@minedesk.com.au and we'll confirm the specific configuration available for your account before you rely on it.
Where an individual (such as an employee) asks Customer to access, correct, or delete their personal data, MineDesk will provide reasonable assistance to help Customer respond. Employees may also contact MineDesk directly, and we will refer such requests to the relevant Customer where the request concerns data that Customer controls.
Card payment details are collected and processed directly by Stripe on MineDesk's behalf — MineDesk's own systems never receive, transmit, or store payment card numbers.
MineDesk maintains technical and organisational measures appropriate to the risk, including encryption in transit (TLS) and at rest, database-level tenant isolation between customers, server-side re-verification of every privileged action, and system-generated (never admin-typed) account credentials. A fuller description is available in MineDesk's Security Overview document on request.
MineDesk will notify Customer without undue delay after becoming aware of a data breach affecting Customer's personal data, and will provide reasonably available information to help Customer meet any notification obligations it may have, including under the Notifiable Data Breaches scheme (Privacy Act 1988 (Cth)).
On termination of the Terms, MineDesk will, at Customer's request, delete or return Customer's personal data, except where retention is required by law. Currently, employee accounts are deactivated immediately on request (login disabled), with full deletion available for accounts that have no submission history; deletion of accounts with submission history is handled as a manual request to preserve Customer's own audit trail unless Customer confirms it should be removed regardless.
On reasonable written notice, and no more than once per 12 months (except following a suspected data breach), MineDesk will provide Customer with reasonably requested information to demonstrate compliance with this DPA, which may include making available relevant documentation such as MineDesk's Security Overview.
This DPA remains in effect for as long as MineDesk processes personal data on Customer's behalf under the Terms. Liability under this DPA is subject to the limitation of liability set out in the Terms.
Questions about this DPA can be sent via the in-app Contact Us form or to enquiry@minedesk.com.au.