Data Processing Addendum
Last updated: September 18, 2026
1. Scope and incorporation
This Data Processing Addendum ("DPA") supplements the Terms of Service and applies automatically, without a separate signature, whenever you use Varify to process personal information about your own staff or other individuals ("Customer Personal Data"). It governs Lutherborrow Systems' handling of that data on your behalf. If your organization requires a countersigned copy for internal record-keeping, contact us using the details in section 9 and we'll provide one on the same terms.
2. Roles
You are the data controller for Customer Personal Data. You decide what's stored in Varify and why. Lutherborrow Systems is the data processor: we handle that data only to provide the Service, following your instructions as given through your use of Varify and this DPA.
3. Nature and purpose of processing
Subject matter: hosting and processing Customer Personal Data within Varify's stock-take and inventory management features. Duration: for as long as your subscription is active, plus the retention period described in section 6 of this DPA. Nature: storage, retrieval, and display of records you create or upload: bin/site assignments, stock-take sessions, and user accounts. Categories of data subjects: typically your employees or contractors with Varify accounts, or named individuals referenced in count records. Categories of data: names, email addresses, role/site assignments, and any other personal information you choose to include in Customer Data.
4. Our obligations
We will:
- process Customer Personal Data only to provide the Service, and not use it for our own independent purposes;
- keep it confidential and limit access to personnel who need it to operate or support the Service;
- apply the security measures described in our Privacy Policy §7, consistent with Australian Privacy Principle 11;
- notify you without undue delay if we become aware of a data breach affecting Customer Personal Data, so you can meet any notification obligations you have as controller (see section 5);
- reasonably assist you in responding to a data subject's access, correction, or deletion request concerning their own information held in Varify.
5. Data breach notification
If we become aware of a data breach affecting Customer Personal Data, we'll notify you as soon as practicable after confirming it, with the information we have available at the time, and update you as our investigation progresses. This is in addition to, not instead of, our own obligations to affected individuals and the OAIC under the Notifiable Data Breaches scheme where we're independently required to notify.
6. Return and deletion of data
On termination of your subscription, we retain Customer Data for a reasonable period to allow export, consistent with Terms of Service §11. After that we delete or de-identify it, except where we're required to retain it longer for legal, tax, or dispute-resolution purposes. You can request export or early deletion at any time before that period ends by contacting us.
7. Sub-processors
We use the following sub-processors to provide the Service, each restricted by contract to processing data only as needed to deliver its service to us:
- Stripe: payment processing and subscription billing;
- Railway: application hosting and database infrastructure;
- Resend: sending transactional email such as sign-in codes, password resets, and invitations;
- Cloudflare: content delivery, DNS, and DDoS protection.
You authorize our use of these sub-processors generally. If we add a new sub-processor with access to Customer Personal Data, we'll update this page and, for Enterprise customers, provide reasonable advance notice on request so you can raise an objection before the change takes effect.
8. International transfers
Some sub-processors may store or process Customer Personal Data outside Australia. By agreeing to this DPA, you consent to that handling, consistent with Australian Privacy Principle 8. See Privacy Policy §5.
9. Contact and audit
Questions about this DPA, sub-processor changes, or reasonable audit requests (on notice, no more than once per year absent a specific concern) can be sent to jayden@lutherborrowsystems.com.au.
10. Liability and term
Liability under this DPA is subject to the same limitation set out in Terms of Service §10. This DPA remains in effect for as long as we process Customer Personal Data on your behalf, and ends automatically when your subscription ends and the retention period in section 6 has passed.