Back to Trust Centre

Data Processing Addendum

Draft

DPA

Last updated: 3 August 2026

Draft document

This Data Processing Addendum is a working draft while the CrewGrid legal entity, ABN or ACN and public business address are being finalised. It will be reviewed before CrewGrid accepts paying customers.

1. Purpose and Application

This Data Processing Addendum forms part of the CrewGrid Terms of Service or another written agreement between CrewGrid and the Customer.

It describes how CrewGrid handles Customer Data when providing the CrewGrid platform and related services.

This Addendum applies where Customer Data includes personal information relating to employees, contractors, customer representatives, project contacts or other individuals.

2. Parties

The “Customer” is the company, business or organisation using CrewGrid.

“CrewGrid” means the entity operating the CrewGrid platform under the CrewGrid trading name. The intended operating entity is CrewGrid Pty Ltd, registration pending.

Each party is responsible for complying with the privacy, employment, workplace and other laws that apply to its own handling of personal information.

3. Definitions

  • Authorised User means a person permitted by the Customer to access its CrewGrid account.
  • Customer Data means information, documents, images, records, messages, drawings and other content submitted to or generated through the Customer’s use of CrewGrid.
  • Personal Information means information or an opinion about an identified individual, or an individual who is reasonably identifiable.
  • Processing or Handle means collecting, storing, organising, accessing, using, transmitting, displaying, backing up, deleting or otherwise dealing with Customer Data.
  • Security Incident means unauthorised access to, disclosure of, alteration of, loss of or destruction of Customer Data affecting its confidentiality, integrity or availability.
  • Service Provider means a third party engaged by CrewGrid to help provide, host, secure, support or maintain the service.

4. Customer Control and Ownership

As between CrewGrid and the Customer, the Customer retains its rights in Customer Data.

CrewGrid does not claim ownership of Customer Data merely because it is uploaded, stored, analysed or processed through the platform.

The Customer determines:

  • Which Authorised Users may access CrewGrid.
  • Which company and branch records are created.
  • Which employee, contractor, client, project and site information is entered.
  • Which CrewGrid features are used.
  • Which reports, documents, images and messages are created or uploaded.
  • How Customer Data is used within the Customer’s workplace and business.

5. Permitted Processing by CrewGrid

The Customer authorises CrewGrid to process Customer Data only as reasonably necessary to:

  • Create and administer customer and user accounts.
  • Authenticate users and manage sessions.
  • Apply company, branch and role-based permissions.
  • Store and display employee, project, compliance and operational records.
  • Provide shifts, attendance, GPS verification and clock-related features.
  • Store attendance selfies, documents, photos and signatures.
  • Provide private messaging, group messaging and announcements.
  • Generate reports, PDFs, timesheets, summaries and payroll-related outputs.
  • Provide scaffold handover, inspection and reporting workflows.
  • Provide estimating, document-processing, automation and AI-assisted features where enabled.
  • Process subscription, invoice and payment-status information.
  • Provide support, troubleshooting and customer communications.
  • Maintain security, service availability, backups and incident response.
  • Comply with legal obligations and protect lawful rights.

CrewGrid will not sell Customer Data.

6. Customer Instructions

The Terms of Service, this Addendum, the Customer’s configuration and the Customer’s lawful use of CrewGrid constitute the Customer’s instructions to CrewGrid.

A Customer may give additional written instructions where they are consistent with the agreed service and applicable law.

CrewGrid may decline an instruction that:

  • Is unlawful.
  • Would compromise platform security.
  • Would expose another customer’s information.
  • Is technically unavailable within the standard service.
  • Would require a materially different or separately priced service.

7. Customer Responsibilities

The Customer is responsible for:

  • Having a lawful basis and authority to collect, upload, use and disclose Customer Data.
  • Providing any required employee, contractor, privacy, GPS, camera or workplace-surveillance notices.
  • Obtaining any required permissions or consents.
  • Ensuring Customer Data is relevant, accurate and not excessive.
  • Assigning appropriate roles and permissions.
  • Removing or disabling access when it is no longer required.
  • Protecting administrator accounts and credentials.
  • Responding to employment, safety, payroll and operational matters under the Customer’s control.
  • Reviewing generated reports, calculations and AI-assisted outputs before relying on them.

The Customer must not instruct CrewGrid to process information in a manner that breaches applicable law or another person’s rights.

8. CrewGrid Responsibilities

CrewGrid will:

  • Process Customer Data only for the agreed service, lawful instructions and permitted operational purposes.
  • Apply authentication and access controls appropriate to the current service.
  • Take reasonable steps to protect Customer Data against misuse, interference, loss and unauthorised access, modification or disclosure.
  • Limit internal access to people who reasonably require it for service delivery, support, security or legal compliance.
  • Use Service Providers only where reasonably required to provide or support the platform.
  • Investigate relevant Security Incidents.
  • Support reasonable data-access, correction, export and deletion requests within the available service capabilities.

9. Confidentiality

CrewGrid will take reasonable steps to ensure that its personnel and contractors who are authorised to access Customer Data are subject to confidentiality obligations or equivalent professional duties.

Customer Data may be accessed only where reasonably necessary for:

  • Operating and supporting the service.
  • Investigating an error, support request or Security Incident.
  • Maintaining security and service availability.
  • Complying with lawful obligations.

10. Security Measures

CrewGrid maintains reasonable technical and organisational security measures appropriate to the current platform and the nature of the information being processed.

  • Authenticated user access.
  • Company, branch and role-based permissions.
  • Encrypted HTTPS connections.
  • Managed database and file-storage infrastructure.
  • Private file-storage controls for selected file categories.
  • Temporary signed access links for protected message photos.
  • Service-health monitoring and operational logging.
  • Administrative access restrictions.
  • Security, dependency and infrastructure updates.
  • Incident assessment and response processes.
  • Data-retention and deletion processes.

Further general information is available on the CrewGrid Data Security page.

View Data Security

11. Service Providers

The Customer authorises CrewGrid to engage Service Providers where reasonably necessary to operate, host, secure, support and maintain CrewGrid.

Current provider categories include:

  • Authentication, database and file-storage providers.
  • Web hosting and server-function providers.
  • Payment processors.
  • Email providers.
  • Address-geocoding and mapping providers.
  • Browser and device push-notification services.

CrewGrid will maintain a public list of material Service Providers on its Subprocessors page.

12. Provider Changes

CrewGrid may appoint, replace or remove a Service Provider as its infrastructure and product requirements change.

CrewGrid will take reasonable steps to assess material providers that handle Customer Data and to use providers offering suitable contractual, privacy and security protections for the services they perform.

Where a provider change is likely to materially alter how Customer Data is processed, CrewGrid will update its published provider information and provide reasonable notice where appropriate.

13. Data Location and Overseas Processing

CrewGrid’s primary production database and managed file storage are currently hosted through Supabase in Sydney, Australia.

CrewGrid’s application hosting and server-side functions are provided through Vercel. Other providers, including Stripe, email, geocoding and browser-notification services, may operate globally.

Customer Data or limited service information may be processed or accessed outside Australia where reasonably necessary for those services.

The Customer authorises this processing subject to CrewGrid’s obligations under this Addendum and applicable law.

14. Data Access and Correction Requests

The Customer is generally responsible for responding to requests from its employees, contractors and other individuals concerning Customer-controlled employment or operational records.

Where reasonably required, CrewGrid will assist the Customer by:

  • Providing access to information available through authorised platform features.
  • Correcting information where the Customer cannot reasonably do so through the platform.
  • Locating relevant records within available systems.
  • Applying a requested deletion where lawful and technically available.

CrewGrid may require identity and authority verification before acting on a request.

Additional work outside the ordinary service may be subject to a reasonable fee agreed in advance.

15. Security Incidents

If CrewGrid becomes aware of a Security Incident affecting Customer Data, CrewGrid will take reasonable steps to:

  • Investigate the incident.
  • Contain or reduce ongoing risk where reasonably possible.
  • Assess the information and customers affected.
  • Preserve relevant evidence and records.
  • Notify affected Customers where legally required or where notification is reasonably necessary for the Customer to respond.
  • Cooperate with reasonable Customer enquiries and response actions.

A notification may be provided in stages as information becomes available.

Notification of an incident does not by itself constitute an admission of fault or liability.

16. Customer Security Incidents

The Customer must promptly notify CrewGrid if it becomes aware of:

  • A compromised CrewGrid account.
  • Unauthorised access by a current or former user.
  • Lost or exposed credentials.
  • Improper downloading or disclosure of Customer Data.
  • A device or browser session that may allow unauthorised CrewGrid access.

CrewGrid may suspend sessions, reset credentials or restrict access where reasonably necessary to protect the Customer, other customers or the platform.

17. Data Export

During an active subscription and the 30-day read-only period, the Customer may use available CrewGrid features to view and download supported reports, PDFs and records.

Before standard access ends, the Customer should download information required for its legal, employment, operational and record-keeping obligations.

A Customer administrator may request a reasonably available export before the end of the 90-day retention period.

CrewGrid does not guarantee that every internal system field can be provided in a custom format.

18. Retention After Trial or Subscription

Customer Data will be retained during an active trial or paid subscription as required to provide the service.

  • For 30 days after trial or paid access ends, the account may remain available in read-only mode.
  • During read-only access, existing information may be viewed and available reports or PDFs may be downloaded.
  • From day 31 to day 90, standard user access may be removed while Customer Data is temporarily retained for authorised export, reactivation or deletion requests.
  • After 90 days, Customer operational data may be deleted from active systems unless longer retention is required for legal, billing, accounting, security, fraud, dispute or enforcement purposes.
  • Residual copies may remain temporarily in protected backups until removed through the normal backup-rotation process.

19. Early Deletion Requests

An authorised Customer representative may request deletion before the standard retention period ends by contacting info@crewgrid.co.

CrewGrid may verify the requester’s identity, role and authority before deleting Customer Data.

CrewGrid may retain limited information where reasonably required for:

  • Billing, tax or accounting records.
  • Security, fraud or incident investigations.
  • An active or reasonably anticipated dispute.
  • Compliance with law or a lawful direction.
  • Evidence of accepted agreements and policy versions.

20. Return and Deletion at Termination

When the agreement ends, CrewGrid will manage Customer Data according to the export, read-only, retention and deletion process in this Addendum and the Terms of Service.

After the applicable period, CrewGrid may delete Customer Data from active systems and is not required to maintain ongoing access unless otherwise agreed in writing.

Deletion from active systems may occur before residual backup copies expire through normal rotation.

21. De-Identified and Aggregated Information

CrewGrid may create and use statistics, analytics and aggregated or de-identified information where individuals and Customers are not reasonably identifiable.

This information may be used to:

  • Monitor performance and reliability.
  • Understand feature usage.
  • Improve CrewGrid workflows and services.
  • Develop general product insights.
  • Identify operational and security trends.

CrewGrid will not attempt to re-identify properly de-identified information except where reasonably necessary to test the effectiveness of de-identification, protect security or comply with law.

22. AI-Assisted Processing

Where the Customer enables or uses an AI-assisted feature, the Customer authorises CrewGrid to process the relevant drawings, documents, project information and other Customer Data to provide that feature.

CrewGrid does not obtain ownership of those materials.

AI-assisted outputs may contain errors or omissions and must be reviewed by competent and authorised personnel before being used for engineering, safety, employment, pricing or commercial decisions.

23. Audits and Compliance Information

On reasonable written request, CrewGrid may provide available information reasonably necessary to explain its data-processing and security practices.

CrewGrid is not required to provide:

  • Another customer’s confidential information.
  • Passwords, keys, security secrets or exploitable technical details.
  • Information restricted by a Service Provider or law.
  • A physical or technical audit that would create a security risk or unreasonable operational disruption.

Any broader audit requirement must be agreed in writing, scheduled reasonably, protected by confidentiality and, where it creates material cost, may be subject to an agreed fee.

24. Legal Requests

CrewGrid may disclose Customer Data where required by a valid law, court order, regulatory direction or other binding legal process.

Where legally permitted and reasonably practicable, CrewGrid will notify the affected Customer before disclosure so the Customer may seek appropriate protection.

CrewGrid will limit the disclosure to information reasonably required by the legal request.

25. Order of Precedence

If this Addendum conflicts with the Terms of Service on a matter concerning the processing or protection of Customer Data, this Addendum prevails to the extent of that conflict.

If CrewGrid and the Customer sign a separate data processing or enterprise agreement, that signed agreement prevails to the extent of any inconsistency.

26. Liability

Liability arising under this Addendum is subject to the liability, Australian Consumer Law and dispute provisions in the Terms of Service or another applicable signed agreement.

Nothing in this Addendum excludes or limits a right, remedy or liability that cannot lawfully be excluded or limited.

27. Changes to This Addendum

CrewGrid may update this Addendum when its services, providers, security practices, business structure or legal obligations change.

Updated versions will be published with a revised “Last updated” date.

CrewGrid will provide reasonable notice of a material change that significantly reduces the protections applying to current Customer Data.

28. Governing Law

This Addendum is governed by the laws of Western Australia, Australia, consistently with the CrewGrid Terms of Service.

29. Contact

Questions, data requests or Security Incident notices relating to this Addendum may be sent to:

CrewGrid

Intended legal entity: CrewGrid Pty Ltd — registration pending

Western Australia, Australia

support@crewgrid.co