Standard Data Processing Terms (Summary)
Last Updated: May 23, 2026
GDPR Article 28 CompliantThis is a Summary Document
This page provides a plain-language summary of TheDeskMonitor's standard Data Processing Terms. It is not a signed or countersigned agreement. A formal, countersigned DPA is available on request — email [email protected] to request execution of a formal DPA. Enterprise customers may request a custom DPA review.
How to Execute a DPA
To request a countersigned Data Processing Agreement for your organisation, email [email protected] with your company name, registered address, and the name of your Data Protection Officer or legal contact. We will provide a countersigned DPA within 5 business days.
1. Parties
This Data Processing Agreement is entered into between:
- Data Controller: The entity that has subscribed to TheDeskMonitor services (the "Customer" or "Controller")
- Data Processor: N.S. IT SERVICES PTY LTD (ABN 75 122 740 121 / ACN 122 740 121), the operator of the TheDeskMonitor platform (the "Processor")
2. Subject Matter, Nature and Purpose of Processing
The Processor provides workforce monitoring, time tracking, and productivity analytics services to the Controller. In providing these services, the Processor processes personal data of the Controller's employees (Data Subjects) on the documented instructions of the Controller.
Categories of data processed:
- Employee identity data (name, email address, profile photo)
- Activity data (keyboard and mouse interaction counts per minute)
- Screenshot images of employee desktop screens
- Time logs, shift records, and attendance data
- Location data (IP-derived geolocation, GPS coordinates on mobile)
- Application and URL usage data (process names, window titles)
Categories of Data Subjects: Employees and contractors of the Controller who are issued TheDeskMonitor accounts.
3. Controller Obligations
The Controller agrees to:
- Ensure there is a valid lawful basis for the monitoring processing under applicable law (including GDPR Article 6 and the Privacy Act 1988 (Cth) where applicable)
- Provide appropriate notices to employees regarding the monitoring activities
- Only instruct the Processor to process data for purposes consistent with those notices
- Cooperate with the Processor in responding to Data Subject requests
- Comply with applicable workplace surveillance legislation in their jurisdiction, including the Workplace Surveillance Act 2005 (NSW) and equivalent state and territory legislation
4. Processor Obligations
The Processor agrees to:
- Process data only on documented instructions from the Controller. These instructions include the Processor's standing authority — granted under the Terms of Service — to access, evaluate and process Personal Data as reasonably necessary to maintain, protect, develop and improve the Service, including through automated and AI-based methods.
- Ensure persons processing data are bound by confidentiality obligations
- Implement appropriate technical and organisational security measures
- Assist the Controller in fulfilling Data Subject rights requests
- Delete or return all data on termination of the agreement
- Make available information necessary to demonstrate compliance
5. Sub-Processors
The Processor engages the following named sub-processors to assist in delivering the service. Each sub-processor is bound by data protection obligations equivalent to those in this DPA.
| Sub-Processor | Purpose | Data Location | Transfer Basis |
|---|---|---|---|
| Hetzner Online GmbH | Primary cloud infrastructure — compute, storage, and database servers hosting all application data | Germany (EU) — Falkenstein (fsn1) data centre | Adequacy decision (EU to EU — no transfer) |
| Cloudflare, Inc. | CDN, DDoS protection, WAF, DNS resolution, and encrypted tunnel services. Processes network-layer data (IP addresses, request metadata) only — no application data retained. | United States (global edge network) | Standard Contractual Clauses (EU) 2021/914 |
| Paddle.com Market Ltd | Payment processing and subscription billing as Merchant of Record. Paddle issues tax invoices and collects payments; billing contact details shared. | United Kingdom / Ireland | UK GDPR — adequacy; EU SCCs for international flows |
| Microsoft Corporation (Microsoft Clarity) | Session analytics — page interaction heatmaps and session recordings. Enabled only with user consent (opt-in). Clarity masks all input fields, passwords, and payment elements. | United States | Standard Contractual Clauses (EU) 2021/914 |
| Google LLC (Google Analytics 4) | Aggregated usage analytics — page views, session counts, conversion tracking. Enabled only with user consent (opt-in). IP anonymisation enabled; no full IP retained. | United States | Standard Contractual Clauses (EU) 2021/914 |
| Wise (formerly TransferWise Ltd) | Partner and affiliate payout processing. Receives partner name and bank account details for approved payouts only. | United Kingdom / European Union | UK GDPR — adequacy; EU SCCs where applicable |
Last updated: 20 May 2026. The Processor will notify the Controller of any intended changes to sub-processors via email with 30 days' notice, allowing the Controller the opportunity to object.
6. Technical and Organisational Security Measures
- Encryption in transit (TLS 1.2/1.3) for all data transfers
- Encryption at rest for all stored data
- Role-based access controls with audit logging
- 2-factor authentication mandatory for Administrator and OwnerAdmin roles; strongly recommended for all staff access to production systems
- Regular security testing and vulnerability assessments
- Incident response plan with 72-hour breach notification obligation to Data Controllers
- Notifiable Data Breach notifications to the OAIC for eligible breaches under the Privacy Act 1988 (Cth)
7. Data Breach Notification
The Processor will notify the Controller without undue delay — and no later than 72 hours after becoming aware — of any personal data breach affecting the Controller's data. The notification will include all information required by GDPR Article 33(3) to the extent available. For breaches constituting an eligible data breach under the Privacy Act 1988 (Cth), the Processor will also notify the OAIC and affected individuals in accordance with the Notifiable Data Breaches scheme.
8. Return and Deletion on Termination
Upon termination of the Controller's TheDeskMonitor subscription, all personal data will be deleted within 30 days unless a longer retention period is required by applicable law. The Controller may request a data export in the 30-day window before deletion.
9. Governing Law
This DPA is governed by the laws of New South Wales, Australia. Disputes shall be resolved by mediation in Sydney, NSW, and if unresolved, by the courts of New South Wales. Where the Controller is based in the EU, Standard Contractual Clauses (Module 2, Controller to Processor) as adopted by the European Commission are incorporated into this DPA and take precedence for international transfers. Nothing in this DPA excludes, restricts or modifies any right or remedy, or any guarantee, warranty or other term or condition, implied or imposed by the Australian Consumer Law which cannot lawfully be excluded or limited.
N.S. IT SERVICES PTY LTD (ABN 75 122 740 121 / ACN 122 740 121) | [email protected]
Request countersigned DPA
Email our legal team and receive a signed DPA within 5 business days.
Request countersigned DPA