Version 1.0 | Effective Date: 23 July 2026
This Data Processing Agreement (“Agreement”) is between Meister Athlete Pty Ltd ACN 162 434 513 (ABN 49 162 434 513) of Sunrise Beach, QLD 4567, Australia, trading as Valutten (“Valutten”), and the entity that subscribes to the Valutten platform (“Customer”).
It applies the same way to every Valutten customer. It takes effect for a Customer on the earlier of: (a) the commencement of the Customer’s subscription; or (b) the execution of a cover sheet or order form that incorporates this Agreement by reference. Enterprise customers who need a countersigned copy for their vendor file execute a one-page cover sheet identifying the parties and this version; the terms themselves do not change per customer.
Valutten does not accept or process Customer Data before this Agreement applies and the Customer’s subscription has commenced.
1.1 The Customer subscribes to the Valutten platform and, for the purpose of receiving the platform, provides Valutten with historical commission, loan book and related records sourced from its aggregator (the “Customer Data”).
1.2 This Agreement governs Valutten’s handling of the Customer Data for the duration of the Customer’s subscription. Valutten will not accept or process the Customer Data before both this Agreement applies and the subscription has commenced.
1.3 Valutten’s Terms of Service and Privacy Policy govern the supply of the platform. This Agreement governs the handling of personal information and prevails over those documents to the extent of any inconsistency on that subject.
1.4 Except as stated in the subscription terms, this Agreement does not oblige either party to proceed with any further transaction.
3.1 The Customer Data comprises aggregator commission and loan book records: broker identifiers, lender, loan reference, borrower name, loan amount, settlement date, commission amounts, and related fields present in the aggregator’s reports.
3.2 Valutten does not require and does not want bank account numbers, credit files, identity documents, or any data sourced under the Consumer Data Right. The Customer may redact any field Valutten does not need before transfer, without affecting the analysis.
3.3 Neither party will disclose to the other any data sourced under the Consumer Data Right except through a pathway permitted by the CDR rules.
4.1 Valutten will handle the Customer Data only:
4.2 Valutten will not sell or licence the Customer Data, and will not disclose it to any third party other than the subprocessors identified under clause 7.
4.3 Valutten will not use the Customer Data to market to, contact, or solicit the Customer’s clients, brokers or staff.
4.4 Valutten may derive aggregate, de-identified statistical insight across its customer base, provided the output cannot reasonably identify the Customer, its clients or its brokers. Such output is Valutten’s property. The Customer Data itself remains the Customer’s property.
5.1 The Customer is the entity responsible for the personal information within the Customer Data. The Customer determines the purposes for which it is handled, and warrants that it is entitled to disclose it to Valutten for the Permitted Purpose.
5.2 Valutten handles that personal information on the Customer’s behalf, for the Permitted Purpose only, and does not determine the purposes for which it is handled.
5.3 Each party will comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles in respect of the Customer Data.
6.1 Valutten will implement and maintain the technical and organisational measures set out in the Security Schedule, which include: storage and processing in Google Cloud’s australia-southeast1 (Sydney) region; AES-256 encryption at rest; TLS 1.3 in transit; role-based access control with tenant isolation enforced server side; multi-factor authentication on administrative access; credentials held in a managed secret store; and immutable audit logging.
6.2 Valutten will not materially reduce those measures during the term.
6.3 Valutten will ensure that any personnel with access to the Customer Data are bound by confidentiality obligations and are limited to those who need access for the Permitted Purpose.
7.1 The Customer authorises Valutten to engage the subprocessors identified in the Security Schedule.
7.2 Valutten remains responsible for its subprocessors’ handling of the Customer Data as if it were its own.
7.3 Valutten will notify the Customer before engaging any new subprocessor that will handle the Customer Data. The Customer may object on reasonable data protection grounds, in which case the parties will discuss a resolution in good faith, and the Customer may terminate this Agreement if none is reached.
7.4 Primary storage and processing are in Australia. Certain subprocessors identified in the Security Schedule process limited data overseas. Valutten will take reasonable steps consistent with APP 8 in respect of those disclosures, and the Security Schedule states for each what data it receives.
The Customer and its authorised users access the Customer Data through the platform, under role-based controls. This is how Valutten makes the data available.
Valutten does not provide bulk exports of the Customer Data. Data remains within the platform. Nothing in this Agreement obliges Valutten to deliver the Customer Data in a file format, and the Customer acknowledges that it retains its own source records from its aggregator.
If the Customer receives a request from an individual to access or correct their personal information, Valutten will provide reasonable assistance to enable the Customer to respond, including surfacing the relevant records within the platform.
Valutten retains commission records and audit logs for 7 years consistent with Australian financial services record-keeping obligations.
Within 30 days of the termination of the Customer’s subscription, or of the Customer’s later written request, Valutten will delete the Customer Data and derived materials from its production systems and confirm the deletion in writing. Exceptions: records within the 7-year retention period under clause 8.4, one copy retained securely where required for legal or compliance records, and routine encrypted backups, which are overwritten in the ordinary backup cycle. Any retained copy remains subject to this Agreement until deleted.
9.1 On request, and no more than annually unless there has been an eligible data breach affecting the Customer Data, Valutten will provide: its integrator security questionnaire responses, its subprocessor register, its logging and retention policy, its data breach response plan, and reasonable written answers to the Customer’s vendor security questionnaire.
9.2 The parties acknowledge that Valutten is a small business relying on Google Cloud’s certifications for the infrastructure layer and its own documented controls above that layer. Valutten is not SOC 2 audited. Assurance under this clause is documentary; it does not extend to on-site audit.
10.1 Valutten will notify the Customer without undue delay, and in any event within 72 hours, of becoming aware of unauthorised access to, disclosure of, or loss of the Customer Data.
10.2 That notice will include, to the extent known: what happened, when, what data was affected, what Valutten has done, and what Valutten recommends the Customer do.
10.3 Valutten will provide reasonable assistance to enable the Customer to assess the incident and to meet its own obligations under the Notifiable Data Breaches scheme, and will not make any public statement identifying the Customer without the Customer’s consent, except where required by law.
11.1 Each party will keep confidential the other’s confidential information, including the Customer Data, the Valutten platform’s methods, architecture and pricing, and the existence and content of any commercial discussions between the parties.
11.2 A party may disclose confidential information only to its officers, employees and professional advisers who need it for the Permitted Purpose and who are bound by equivalent obligations, and remains responsible for their compliance.
11.3 Clause 11.1 does not apply to information that is or becomes public other than by breach, was lawfully known free of obligation before disclosure, is lawfully received from a third party without restriction, or is independently developed without reference to the discloser’s confidential information. These exceptions do not apply to personal information within the Customer Data, which is governed by the rest of this Agreement regardless.
11.4 Neither party will reverse engineer or decompile any software or system made available to it.
11.5 If a party is required by law or a regulator to disclose confidential information, it may do so to the extent required, provided it gives the other party prompt written notice where lawful.
12.1 This Agreement commences for a Customer as described in “About This Agreement” above, no earlier than the commencement of that Customer’s subscription, and continues until the termination of that subscription.
12.2 Clauses 4.3, 5, 8, 10, 11 and 13 survive termination. Confidentiality obligations survive for 24 months after termination, and indefinitely in respect of personal information and any trade secret for as long as it remains one.
12.3 Either party may terminate this Agreement on written notice if the other materially breaches it and does not remedy the breach within 14 days of notice.
This schedule states the technical and organisational measures referred to at clause 6.1. It is maintained with the same version control as the Agreement.
Client data is never sent as a plaintext email attachment in either direction.
| Subprocessor | Purpose | Location of processing |
|---|---|---|
| Google Cloud Australia Pty Ltd | All primary infrastructure and data storage | australia-southeast1 (Sydney). Control plane metadata may transit the US. |
| Stripe | Billing and subscription management. Billing contact data only, no client data. | US |
| Resend | Transactional email (invitations, alerts). Recipient address and message metadata only, no client data in the body by design. | US |
| PostHog | Product analytics on platform usage. No commission or client records. | US |
| Anthropic, PBC | The in-platform AI features, where used. Receives the schema, the user’s typed question and tokenized aggregates only. No commission rows. See 14.5. | US |
The current subprocessor register, including each subprocessor’s own data protection terms, is provided on request. Customers are notified before any new subprocessor that handles Customer Data is engaged.
Valutten has two AI features: a first-login briefing for administrators, and an assistant that answers natural language questions about the tenant’s own commission data (availability depends on subscription tier). Both call Anthropic’s API in the United States, so this section sets out exactly what does and does not cross the border.
Commission rows never reach the model. For the assistant, the model’s only job is to convert a typed question into a database query. That query runs inside Valutten’s Australian infrastructure, and the answer the user reads is composed in code from the returned rows. Dollar figures, borrower names, loan records and any other value derived from the book are never sent to the model. For the first-login briefing, only aggregate figures are sent, with broker and lender names replaced by opaque tokens and loan identifiers omitted entirely; the tokens are mapped back to real names inside Australian infrastructure after the response is received.
What does cross the border: the database schema description, the user’s typed question, the tenant’s company identifier, and up to three earlier questions from the same conversation. Nothing else.
Residual, stated honestly: questions pass a sanitiser that redacts email addresses, phone numbers and names in quotes. If a user types an unquoted client name into a question, that name travels with the question. It is user-typed content rather than data drawn from the book, and it is the one path by which a name can reach the model.
Engineering controls: a CI gate blocks any new code path that talks to an AI provider from being added without explicit review, and fails closed if its own detection drifts. The assistant is restricted by role, rate limited per hour, and scoped to the caller’s own tenant. Neither feature runs in the background; nothing is processed unless a user opens the assistant or triggers the briefing. Prompts may be retained by Anthropic for up to 30 days for abuse monitoring and are not used to train models.
Opt-out: on request, Valutten applies an account-level block that switches AI features off for the Customer’s tenant and overrides the subscription entitlement, per section 9.4 of the Privacy Policy. The block is evaluated ahead of every entitlement grant, so it cannot be undone by a tier or add-on change. It is applied by Valutten rather than self-served in the product. Customers wanting it in place from day one should say so before any client data is loaded.
Valutten maintains a documented data breach response plan aligned to the Notifiable Data Breaches scheme, and notifies affected customers within 72 hours as stated at clause 10. As at the date of this version, Valutten has had no reportable data breach.
Stated deliberately, because a vendor file that claims a clean sheet is not credible:
Privacy Officer and security contact
Dieter Roylance, Founder and Director
Entity
Meister Athlete Pty Ltd (ACN 162 434 513, ABN 49 162 434 513), trading as Valutten, Sunrise Beach, QLD 4567, Australia