VALUTTEN
  • Platform
  • Features
  • Pricing
  • Assess Your Loan Book

Data Processing Agreement

Version 1.0 | Effective Date: 23 July 2026

About This Agreement

This Data Processing Agreement (“Agreement”) is between Meister Athlete Pty Ltd ACN 162 434 513 (ABN 49 162 434 513) of Sunrise Beach, QLD 4567, Australia, trading as Valutten (“Valutten”), and the entity that subscribes to the Valutten platform (“Customer”).

It applies the same way to every Valutten customer. It takes effect for a Customer on the earlier of: (a) the commencement of the Customer’s subscription; or (b) the execution of a cover sheet or order form that incorporates this Agreement by reference. Enterprise customers who need a countersigned copy for their vendor file execute a one-page cover sheet identifying the parties and this version; the terms themselves do not change per customer.

Valutten does not accept or process Customer Data before this Agreement applies and the Customer’s subscription has commenced.

Table of Contents

  1. Purpose and Scope
  2. Definitions
  3. What Is Handled
  4. Instructions and Purpose Limitation
  5. Roles Under the Privacy Act
  6. Security
  7. Subprocessors and Overseas Disclosure
  8. Access, Correction, Retention and Deletion
  9. Assurance and Audit
  10. Data Breach
  11. Confidentiality
  12. Term, Survival and Termination
  13. General
  14. Security Schedule

1. Purpose and Scope

1.1 The Customer subscribes to the Valutten platform and, for the purpose of receiving the platform, provides Valutten with historical commission, loan book and related records sourced from its aggregator (the “Customer Data”).

1.2 This Agreement governs Valutten’s handling of the Customer Data for the duration of the Customer’s subscription. Valutten will not accept or process the Customer Data before both this Agreement applies and the subscription has commenced.

1.3 Valutten’s Terms of Service and Privacy Policy govern the supply of the platform. This Agreement governs the handling of personal information and prevails over those documents to the extent of any inconsistency on that subject.

1.4 Except as stated in the subscription terms, this Agreement does not oblige either party to proceed with any further transaction.

2. Definitions

  • Permitted Purpose means providing the Valutten platform to the Customer under its subscription, including onboarding and processing the Customer Data for that purpose.
  • Personal information has the meaning given in the Privacy Act 1988 (Cth).
  • Customer Data means the records described in clause 1.1 and any data the Customer or its users later load into or generate within the platform.
  • Security Schedule means the schedule at section 14 of this Agreement, which forms part of it.

3. What Is Handled

3.1 The Customer Data comprises aggregator commission and loan book records: broker identifiers, lender, loan reference, borrower name, loan amount, settlement date, commission amounts, and related fields present in the aggregator’s reports.

3.2 Valutten does not require and does not want bank account numbers, credit files, identity documents, or any data sourced under the Consumer Data Right. The Customer may redact any field Valutten does not need before transfer, without affecting the analysis.

3.3 Neither party will disclose to the other any data sourced under the Consumer Data Right except through a pathway permitted by the CDR rules.

4. Instructions and Purpose Limitation

4.1 Valutten will handle the Customer Data only:

  • for the Permitted Purpose;
  • in accordance with the Customer’s reasonable documented instructions; and
  • as required by Australian law, in which case Valutten will notify the Customer before complying unless the law prohibits that notice.

4.2 Valutten will not sell or licence the Customer Data, and will not disclose it to any third party other than the subprocessors identified under clause 7.

4.3 Valutten will not use the Customer Data to market to, contact, or solicit the Customer’s clients, brokers or staff.

4.4 Valutten may derive aggregate, de-identified statistical insight across its customer base, provided the output cannot reasonably identify the Customer, its clients or its brokers. Such output is Valutten’s property. The Customer Data itself remains the Customer’s property.

5. Roles Under the Privacy Act

5.1 The Customer is the entity responsible for the personal information within the Customer Data. The Customer determines the purposes for which it is handled, and warrants that it is entitled to disclose it to Valutten for the Permitted Purpose.

5.2 Valutten handles that personal information on the Customer’s behalf, for the Permitted Purpose only, and does not determine the purposes for which it is handled.

5.3 Each party will comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles in respect of the Customer Data.

6. Security

6.1 Valutten will implement and maintain the technical and organisational measures set out in the Security Schedule, which include: storage and processing in Google Cloud’s australia-southeast1 (Sydney) region; AES-256 encryption at rest; TLS 1.3 in transit; role-based access control with tenant isolation enforced server side; multi-factor authentication on administrative access; credentials held in a managed secret store; and immutable audit logging.

6.2 Valutten will not materially reduce those measures during the term.

6.3 Valutten will ensure that any personnel with access to the Customer Data are bound by confidentiality obligations and are limited to those who need access for the Permitted Purpose.

7. Subprocessors and Overseas Disclosure

7.1 The Customer authorises Valutten to engage the subprocessors identified in the Security Schedule.

7.2 Valutten remains responsible for its subprocessors’ handling of the Customer Data as if it were its own.

7.3 Valutten will notify the Customer before engaging any new subprocessor that will handle the Customer Data. The Customer may object on reasonable data protection grounds, in which case the parties will discuss a resolution in good faith, and the Customer may terminate this Agreement if none is reached.

7.4 Primary storage and processing are in Australia. Certain subprocessors identified in the Security Schedule process limited data overseas. Valutten will take reasonable steps consistent with APP 8 in respect of those disclosures, and the Security Schedule states for each what data it receives.

8. Access, Correction, Retention and Deletion

8.1 Access

The Customer and its authorised users access the Customer Data through the platform, under role-based controls. This is how Valutten makes the data available.

8.2 No Export

Valutten does not provide bulk exports of the Customer Data. Data remains within the platform. Nothing in this Agreement obliges Valutten to deliver the Customer Data in a file format, and the Customer acknowledges that it retains its own source records from its aggregator.

8.3 Individual Requests

If the Customer receives a request from an individual to access or correct their personal information, Valutten will provide reasonable assistance to enable the Customer to respond, including surfacing the relevant records within the platform.

8.4 Retention

Valutten retains commission records and audit logs for 7 years consistent with Australian financial services record-keeping obligations.

8.5 Deletion

Within 30 days of the termination of the Customer’s subscription, or of the Customer’s later written request, Valutten will delete the Customer Data and derived materials from its production systems and confirm the deletion in writing. Exceptions: records within the 7-year retention period under clause 8.4, one copy retained securely where required for legal or compliance records, and routine encrypted backups, which are overwritten in the ordinary backup cycle. Any retained copy remains subject to this Agreement until deleted.

9. Assurance and Audit

9.1 On request, and no more than annually unless there has been an eligible data breach affecting the Customer Data, Valutten will provide: its integrator security questionnaire responses, its subprocessor register, its logging and retention policy, its data breach response plan, and reasonable written answers to the Customer’s vendor security questionnaire.

9.2 The parties acknowledge that Valutten is a small business relying on Google Cloud’s certifications for the infrastructure layer and its own documented controls above that layer. Valutten is not SOC 2 audited. Assurance under this clause is documentary; it does not extend to on-site audit.

10. Data Breach

10.1 Valutten will notify the Customer without undue delay, and in any event within 72 hours, of becoming aware of unauthorised access to, disclosure of, or loss of the Customer Data.

10.2 That notice will include, to the extent known: what happened, when, what data was affected, what Valutten has done, and what Valutten recommends the Customer do.

10.3 Valutten will provide reasonable assistance to enable the Customer to assess the incident and to meet its own obligations under the Notifiable Data Breaches scheme, and will not make any public statement identifying the Customer without the Customer’s consent, except where required by law.

11. Confidentiality

11.1 Each party will keep confidential the other’s confidential information, including the Customer Data, the Valutten platform’s methods, architecture and pricing, and the existence and content of any commercial discussions between the parties.

11.2 A party may disclose confidential information only to its officers, employees and professional advisers who need it for the Permitted Purpose and who are bound by equivalent obligations, and remains responsible for their compliance.

11.3 Clause 11.1 does not apply to information that is or becomes public other than by breach, was lawfully known free of obligation before disclosure, is lawfully received from a third party without restriction, or is independently developed without reference to the discloser’s confidential information. These exceptions do not apply to personal information within the Customer Data, which is governed by the rest of this Agreement regardless.

11.4 Neither party will reverse engineer or decompile any software or system made available to it.

11.5 If a party is required by law or a regulator to disclose confidential information, it may do so to the extent required, provided it gives the other party prompt written notice where lawful.

12. Term, Survival and Termination

12.1 This Agreement commences for a Customer as described in “About This Agreement” above, no earlier than the commencement of that Customer’s subscription, and continues until the termination of that subscription.

12.2 Clauses 4.3, 5, 8, 10, 11 and 13 survive termination. Confidentiality obligations survive for 24 months after termination, and indefinitely in respect of personal information and any trade secret for as long as it remains one.

12.3 Either party may terminate this Agreement on written notice if the other materially breaches it and does not remedy the breach within 14 days of notice.

13. General

  • Nothing in this Agreement grants either party rights in the other’s intellectual property, except the limited rights needed for the Permitted Purpose.
  • This Agreement binds and benefits the parties and their successors and assigns; neither may assign it without the other’s written consent.
  • Governing law: the laws of the State of Queensland, and the parties submit to the courts of that State.
  • Each party agrees that a breach or threatened breach of clause 11 may cause irreparable injury and that the other party may seek an injunction in addition to any other remedy.
  • This Agreement, with the Security Schedule, is the entire agreement between the parties on its subject matter.
  • No failure to enforce any provision is a waiver of it.
  • Amendments to this Agreement are made by publishing a new version at this page; a new version applies to a Customer from its next subscription renewal, or earlier if the Customer agrees. For a Customer that has executed a cover sheet, the version named in the cover sheet applies until varied in writing signed by both parties.
  • Where executed by cover sheet, this Agreement may be signed in counterparts and by electronic signature.

14. Security Schedule

This schedule states the technical and organisational measures referred to at clause 6.1. It is maintained with the same version control as the Agreement.

14.1 Where Data Is Held

  • All production workloads and data stores are in Google Cloud region australia-southeast1 (Sydney). Region binding is asserted across the codebase and verified at build.
  • Services in scope: Firestore, BigQuery, Cloud Storage, Cloud Run, Secret Manager, Cloud Logging.
  • Encryption at rest: AES-256 with Google-managed keys.
  • Encryption in transit: TLS 1.3, HSTS preloaded, HTTP redirected to HTTPS at the edge. No plaintext endpoints.

14.2 Transfer of Files at Onboarding

  1. Direct upload by the Customer into the Valutten platform over TLS 1.3, once the Customer’s tenant exists. This is the only path that requires no copy outside the platform.
  2. A Google Drive link shared to a named Valutten address, access restricted to that address, link revoked by the Customer once ingestion is confirmed.

Client data is never sent as a plaintext email attachment in either direction.

14.3 Access Control

  • Tenant isolation: every record is bound to a company identifier. Datastore rules are deny by default and enforce tenant separation server side.
  • Role-based access: access within a tenant is scoped by role (super admin, administrator, office admin, credit analyst, broker, and others), and by office and entity allow-lists.
  • Valutten personnel with access to Customer Data: one. Valutten is a sole founder and director business. There is no support team browsing customer data.
  • Administrative access is MFA protected, with TOTP enforced on the administrative portal.
  • Credentials and API keys are held in Google Secret Manager, envelope encrypted, injected at runtime. Never in source, environment variables, build artefacts or the client bundle. CI authenticates by Workload Identity Federation, with no static service account keys. Secret scanning gates every commit.
  • Auditing: every mutation writes an immutable audit record, retained for 7 years, consistent with ASIC record keeping and APP 11.

14.4 Subprocessors

SubprocessorPurposeLocation of processing
Google Cloud Australia Pty LtdAll primary infrastructure and data storageaustralia-southeast1 (Sydney). Control plane metadata may transit the US.
StripeBilling and subscription management. Billing contact data only, no client data.US
ResendTransactional email (invitations, alerts). Recipient address and message metadata only, no client data in the body by design.US
PostHogProduct analytics on platform usage. No commission or client records.US
Anthropic, PBCThe in-platform AI features, where used. Receives the schema, the user’s typed question and tokenized aggregates only. No commission rows. See 14.5.US

The current subprocessor register, including each subprocessor’s own data protection terms, is provided on request. Customers are notified before any new subprocessor that handles Customer Data is engaged.

14.5 The AI Features, Stated Plainly

Valutten has two AI features: a first-login briefing for administrators, and an assistant that answers natural language questions about the tenant’s own commission data (availability depends on subscription tier). Both call Anthropic’s API in the United States, so this section sets out exactly what does and does not cross the border.

Commission rows never reach the model. For the assistant, the model’s only job is to convert a typed question into a database query. That query runs inside Valutten’s Australian infrastructure, and the answer the user reads is composed in code from the returned rows. Dollar figures, borrower names, loan records and any other value derived from the book are never sent to the model. For the first-login briefing, only aggregate figures are sent, with broker and lender names replaced by opaque tokens and loan identifiers omitted entirely; the tokens are mapped back to real names inside Australian infrastructure after the response is received.

What does cross the border: the database schema description, the user’s typed question, the tenant’s company identifier, and up to three earlier questions from the same conversation. Nothing else.

Residual, stated honestly: questions pass a sanitiser that redacts email addresses, phone numbers and names in quotes. If a user types an unquoted client name into a question, that name travels with the question. It is user-typed content rather than data drawn from the book, and it is the one path by which a name can reach the model.

Engineering controls: a CI gate blocks any new code path that talks to an AI provider from being added without explicit review, and fails closed if its own detection drifts. The assistant is restricted by role, rate limited per hour, and scoped to the caller’s own tenant. Neither feature runs in the background; nothing is processed unless a user opens the assistant or triggers the briefing. Prompts may be retained by Anthropic for up to 30 days for abuse monitoring and are not used to train models.

Opt-out: on request, Valutten applies an account-level block that switches AI features off for the Customer’s tenant and overrides the subscription entitlement, per section 9.4 of the Privacy Policy. The block is evaluated ahead of every entitlement grant, so it cannot be undone by a tier or add-on change. It is applied by Valutten rather than self-served in the product. Customers wanting it in place from day one should say so before any client data is loaded.

14.6 Incident Response

Valutten maintains a documented data breach response plan aligned to the Notifiable Data Breaches scheme, and notifies affected customers within 72 hours as stated at clause 10. As at the date of this version, Valutten has had no reportable data breach.

14.7 Assurance Posture

  • Aligned to the Australian Privacy Principles and ASIC record keeping obligations.
  • Google CASA Tier 2 assessment against OWASP ASVS Level 2 is in progress.
  • ISO 27001 readiness is on the roadmap, not certified.
  • Valutten is not SOC 2 audited. It relies on Google Cloud’s certifications for the infrastructure layer and on its own documented controls above that layer.

14.8 Known Gaps, Disclosed

Stated deliberately, because a vendor file that claims a clean sheet is not credible:

  1. Customer managed encryption keys (CMEK) are not configured. Encryption at rest uses Google-managed keys. Under assessment.
  2. The AI opt-out at 14.5 is applied by Valutten, not self-served. The account-level block exists and is enforced at the server; there is no customer-facing switch in the product, so exercising it means asking us.
  3. Long-term audit archival to cold storage is documented but not yet operational. Records are retained in the primary store for the full 7 years in the interim, so the retention obligation is met by the hot tier.
  4. Disaster recovery drill cadence. The runbook exists; the drill schedule is being established.
  5. Security awareness training and endpoint detection are sized for a sole operator business, with full disk encryption, host firewall, automatic updates and screen lock as the compensating controls.

14.9 Supporting Documents Available on Request

  • Third-Party Integrator Security Questionnaire Responses, the canonical answer set already used for aggregator security reviews.
  • Subprocessor Register.
  • Logging and Retention Policy.
  • Data Breach Response Plan.
  • Backup and Recovery Attestation.
  • Privacy Policy, Terms of Service and the Security overview.

Contact

Privacy Officer and security contact

Dieter Roylance, Founder and Director

Email

privacy@valutten.com

Entity

Meister Athlete Pty Ltd (ACN 162 434 513, ABN 49 162 434 513), trading as Valutten, Sunrise Beach, QLD 4567, Australia

Document Control

Version:
1.0
Effective Date:
23 July 2026
Last Reviewed:
23 July 2026
Next Review:
23 July 2027
Owner:
Legal
Approved By:
Dieter Roylance, Director

© 2026 Meister Athlete Pty Ltd (trading as Valutten). All rights reserved.

Privacy Policy  |  Cookie Notice  |  Terms of Service  |  Data Processing Agreement

valutten.com  |  app.valutten.com