Standard Data Processing Terms (Summary)

Last Updated: May 23, 2026

GDPR Article 28 Compliant
This is a Summary Document

This page provides a plain-language summary of TheDeskMonitor's standard Data Processing Terms. It is not a signed or countersigned agreement. A formal, countersigned DPA is available on request — email to request execution of a formal DPA. Enterprise customers may request a custom DPA review.

How to Execute a DPA

To request a countersigned Data Processing Agreement for your organisation, email with your company name, registered address, and the name of your Data Protection Officer or legal contact. We will provide a countersigned DPA within 5 business days.

1. Parties

This Data Processing Agreement is entered into between:

  • Data Controller: The entity that has subscribed to TheDeskMonitor services (the "Customer" or "Controller")
  • Data Processor: N.S. IT SERVICES PTY LTD (ABN 75 122 740 121 / ACN 122 740 121), the operator of the TheDeskMonitor platform (the "Processor")

2. Subject Matter, Nature and Purpose of Processing

The Processor provides workforce monitoring, time tracking, and productivity analytics services to the Controller. In providing these services, the Processor processes personal data of the Controller's employees (Data Subjects) on the documented instructions of the Controller.

Categories of data processed:

  • Employee identity data (name, email address, profile photo)
  • Activity data (keyboard and mouse interaction counts per minute)
  • Screenshot images of employee desktop screens
  • Time logs, shift records, and attendance data
  • Location data (IP-derived geolocation, GPS coordinates on mobile)
  • Application and URL usage data (process names, window titles)

Categories of Data Subjects: Employees and contractors of the Controller who are issued TheDeskMonitor accounts.

3. Controller Obligations

The Controller agrees to:

  • Ensure there is a valid lawful basis for the monitoring processing under applicable law (including GDPR Article 6 and the Privacy Act 1988 (Cth) where applicable)
  • Provide appropriate notices to employees regarding the monitoring activities
  • Only instruct the Processor to process data for purposes consistent with those notices
  • Cooperate with the Processor in responding to Data Subject requests
  • Comply with applicable workplace surveillance legislation in their jurisdiction, including the Workplace Surveillance Act 2005 (NSW) and equivalent state and territory legislation

4. Processor Obligations

The Processor agrees to:

  • Process data only on documented instructions from the Controller. These instructions include the Processor's standing authority — granted under the Terms of Service — to access, evaluate and process Personal Data as reasonably necessary to maintain, protect, develop and improve the Service, including through automated and AI-based methods.
  • Ensure persons processing data are bound by confidentiality obligations
  • Implement appropriate technical and organisational security measures
  • Assist the Controller in fulfilling Data Subject rights requests
  • Delete or return all data on termination of the agreement
  • Make available information necessary to demonstrate compliance

5. Sub-Processors

The Processor engages the following named sub-processors to assist in delivering the service. Each sub-processor is bound by data protection obligations equivalent to those in this DPA.

Sub-Processor Purpose Data Location Transfer Basis
Hetzner Online GmbH Primary cloud infrastructure — compute, storage, and database servers hosting all application data Germany (EU) — Falkenstein (fsn1) data centre Adequacy decision (EU to EU — no transfer)
Cloudflare, Inc. CDN, DDoS protection, WAF, DNS resolution, and encrypted tunnel services. Processes network-layer data (IP addresses, request metadata) only — no application data retained. United States (global edge network) Standard Contractual Clauses (EU) 2021/914
Paddle.com Market Ltd Payment processing and subscription billing as Merchant of Record. Paddle issues tax invoices and collects payments; billing contact details shared. United Kingdom / Ireland UK GDPR — adequacy; EU SCCs for international flows
Microsoft Corporation (Microsoft Clarity) Session analytics — page interaction heatmaps and session recordings. Enabled only with user consent (opt-in). Clarity masks all input fields, passwords, and payment elements. United States Standard Contractual Clauses (EU) 2021/914
Google LLC (Google Analytics 4) Aggregated usage analytics — page views, session counts, conversion tracking. Enabled only with user consent (opt-in). IP anonymisation enabled; no full IP retained. United States Standard Contractual Clauses (EU) 2021/914
Wise (formerly TransferWise Ltd) Partner and affiliate payout processing. Receives partner name and bank account details for approved payouts only. United Kingdom / European Union UK GDPR — adequacy; EU SCCs where applicable

Last updated: 20 May 2026. The Processor will notify the Controller of any intended changes to sub-processors via email with 30 days' notice, allowing the Controller the opportunity to object.

6. Technical and Organisational Security Measures

  • Encryption in transit (TLS 1.2/1.3) for all data transfers
  • Encryption at rest for all stored data
  • Role-based access controls with audit logging
  • 2-factor authentication mandatory for Administrator and OwnerAdmin roles; strongly recommended for all staff access to production systems
  • Regular security testing and vulnerability assessments
  • Incident response plan with 72-hour breach notification obligation to Data Controllers
  • Notifiable Data Breach notifications to the OAIC for eligible breaches under the Privacy Act 1988 (Cth)

7. Data Breach Notification

The Processor will notify the Controller without undue delay — and no later than 72 hours after becoming aware — of any personal data breach affecting the Controller's data. The notification will include all information required by GDPR Article 33(3) to the extent available. For breaches constituting an eligible data breach under the Privacy Act 1988 (Cth), the Processor will also notify the OAIC and affected individuals in accordance with the Notifiable Data Breaches scheme.

8. Return and Deletion on Termination

Upon termination of the Controller's TheDeskMonitor subscription, all personal data will be deleted within 30 days unless a longer retention period is required by applicable law. The Controller may request a data export in the 30-day window before deletion.

9. Governing Law

This DPA is governed by the laws of New South Wales, Australia. Disputes shall be resolved by mediation in Sydney, NSW, and if unresolved, by the courts of New South Wales. Where the Controller is based in the EU, Standard Contractual Clauses (Module 2, Controller to Processor) as adopted by the European Commission are incorporated into this DPA and take precedence for international transfers. Nothing in this DPA excludes, restricts or modifies any right or remedy, or any guarantee, warranty or other term or condition, implied or imposed by the Australian Consumer Law which cannot lawfully be excluded or limited.

N.S. IT SERVICES PTY LTD (ABN 75 122 740 121 / ACN 122 740 121) |

Request countersigned DPA

Email our legal team and receive a signed DPA within 5 business days.