Data Processing Addendum

Last updated: April 30, 2026

This Data Processing Addendum (“DPA”) forms part of the agreement between Filament and the customer (“Customer”) governing Customer’s use of the Filament platform (the “Agreement”), as set out in our Terms of Use and Privacy Policy. By using the Service, Customer agrees to this DPA. Where Customer requires a counter-signed copy for its records, Customer may request one by contacting team@filamentanalytics.com.

This DPA reflects the parties’ agreement on the processing of Personal Data in accordance with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (“APPs”), the EU General Data Protection Regulation (“GDPR”) and the UK GDPR where applicable, and other applicable data protection laws.

1. Definitions

Capitalised terms used but not defined in this DPA have the meanings given in the Agreement. For the purposes of this DPA:

  • Customer Personal Data means any Personal Data that Filament processes on behalf of Customer in providing the Service.
  • Personal Data, Data Subject, Processing, Controller, Processor, Sub-processor, and Personal Data Breach have the meanings given in the GDPR (and equivalent terms under the Privacy Act).
  • Service means the Filament data warehouse and analytics platform.
  • Standard Contractual Clauses or SCCs means the standard contractual clauses adopted by the European Commission (Decision 2021/914) and, where applicable, the UK International Data Transfer Addendum.

2. Roles of the Parties

Customer is the Controller of Customer Personal Data. Filament acts as the Processor and processes Customer Personal Data only on Customer’s documented instructions, including with regard to transfers of Personal Data, unless required to do so by law.

Customer’s use of the Service in accordance with the Agreement constitutes Customer’s documented instructions to Filament. Filament will inform Customer if, in its opinion, an instruction infringes applicable data protection law.

3. Subject Matter and Duration

The subject matter, duration, nature, purpose, types of Personal Data, and categories of Data Subjects are set out in Schedule 1. Processing continues for the term of the Agreement and any additional period during which Filament is required to retain Customer Personal Data under Section 12.

4. Filament’s Obligations

Filament will:

  • process Customer Personal Data only on Customer’s documented instructions;
  • ensure that personnel authorised to process Customer Personal Data are bound by appropriate confidentiality obligations and have received security awareness training, in accordance with Filament’s Personnel Security Policy (available on request);
  • implement and maintain appropriate technical and organisational measures to protect Customer Personal Data, as set out in Schedule 3;
  • assist Customer in responding to Data Subject requests and in meeting Customer’s obligations under applicable data protection law, including in relation to security, breach notification, data protection impact assessments, and prior consultation;
  • make available to Customer all information necessary to demonstrate compliance with this DPA, and allow for and contribute to audits as described in Section 11; and
  • at the choice of Customer, return or delete all Customer Personal Data after the end of the provision of the Service, in accordance with Section 12.

5. Customer’s Obligations

Customer warrants and represents that:

  • it has all necessary rights, lawful bases, and consents to enable Filament to process Customer Personal Data as contemplated by the Agreement;
  • its instructions to Filament comply with applicable data protection law; and
  • it is responsible for the accuracy, quality, and legality of Customer Personal Data and the means by which Customer acquired it.

6. Security

Filament implements and maintains the technical and organisational measures described in Schedule 3, which include encryption of Personal Data in transit (TLS 1.2+) and at rest (AES-256), tenant isolation at the database level, multi-factor authentication on all administrative access, role-based access control, continuous vulnerability monitoring, and audit logging.

These measures are designed to ensure a level of security appropriate to the risk and to comply with the requirements of the GDPR (Art. 32), APP 11, and other applicable data protection laws. Filament will review and update its security measures as the threat landscape evolves; updates will not materially diminish the level of protection.

7. Sub-processors

Customer authorises Filament to engage Sub-processors to process Customer Personal Data, subject to the conditions in this Section. The current list of Sub-processors is published at /subprocessors and forms part of Schedule 2.

Before engaging a new Sub-processor with access to Customer Personal Data, Filament will:

  • provide at least 30 days’ prior notice by updating the sub-processor list and, where Customer has subscribed, by email; and
  • impose data protection obligations on the Sub-processor that are no less protective than those set out in this DPA.

Customer may object to a new Sub-processor on reasonable data protection grounds within the notice period by emailing team@filamentanalytics.com. If the parties cannot agree on a resolution, Customer may terminate the Agreement on written notice and receive a pro-rata refund of any prepaid fees for the unused portion of the term.

Filament remains liable for the acts and omissions of its Sub-processors to the same extent as for its own.

8. International Data Transfers and Data Residency

Customer selects the region in which its dedicated warehouse database is provisioned at the time of warehouse creation. Filament offers warehouse regions in the United States, the European Union (Germany), and Australia (Sydney). Customer warehouse data is stored exclusively in the selected region.

Where Customer selects an Australian warehouse region, Customer warehouse data (including Personal Data synchronised from connected integrations) is stored at rest in Australia. Operational metadata (authentication tokens, audit logs, application telemetry) and processing performed by certain Sub-processors may occur outside the selected region; the locations of such processing are disclosed in the sub-processor list.

Where transfers of Personal Data outside the EEA, UK, or Switzerland are necessary, Filament will rely on an appropriate transfer mechanism, including the Standard Contractual Clauses, the UK International Data Transfer Addendum, or an applicable adequacy decision. The SCCs are incorporated by reference into this DPA, with Module 2 (Controller-to-Processor) applying.

9. Personal Data Breaches

Filament will notify Customer without undue delay, and in any event within seventy-two (72) hours of becoming aware of a Personal Data Breach affecting Customer Personal Data. Notification will be made by direct email to Customer’s nominated account owner and will include, to the extent then known:

  • a description of the nature of the breach;
  • the categories and approximate number of Data Subjects and records affected;
  • the likely consequences of the breach;
  • the measures taken or proposed to address the breach and mitigate its adverse effects; and
  • contact details for further information about the incident.

Where information is not available at the time of the initial notification, Filament will provide it in subsequent updates as the investigation progresses. Filament will provide reasonable assistance to Customer in meeting Customer’s own breach notification obligations, including under the Notifiable Data Breaches scheme, GDPR Articles 33 and 34, and any contractual obligations Customer owes to its Data Subjects.

Filament’s incident response process is documented in its Incident Response Policy, a summary of which is available on request.

10. Data Subject Rights and Assistance

Taking into account the nature of the processing, Filament will assist Customer by appropriate technical and organisational measures, insofar as possible, in fulfilling Customer’s obligations to respond to requests from Data Subjects exercising their rights under applicable data protection law (including rights of access, rectification, erasure, restriction, portability, and objection).

If Filament receives a request from a Data Subject directly, Filament will, unless prohibited by law, redirect the Data Subject to Customer and notify Customer without undue delay. Filament will not respond to the request directly except on Customer’s instructions or as required by law.

Filament will assist Customer in carrying out data protection impact assessments and prior consultations with supervisory authorities where required by applicable data protection law, taking into account the nature of the processing and the information available to Filament.

11. Audit and Information Rights

Filament will make available to Customer, on reasonable request, the information necessary to demonstrate compliance with this DPA. This includes:

  • Filament’s published security documentation at /security;
  • summaries of relevant Filament policies, including the Information Security Policy, Incident Response Policy, Access Control Policy, Encryption Policy, Data Classification Policy, and Vendor Risk Management Policy;
  • SOC 2 Type II reports of Filament’s critical Sub-processors, subject to those Sub-processors’ confidentiality requirements.

Where Customer reasonably believes that the information made available is insufficient to demonstrate compliance, Customer may request an audit no more than once in any twelve (12) month period (or more frequently if required by a supervisory authority or following a Personal Data Breach). The audit will be conducted at Customer’s expense by Customer or a mutually agreed independent auditor bound by appropriate confidentiality obligations, on reasonable prior notice, during business hours, and in a manner that does not unreasonably interfere with Filament’s operations.

12. Return and Deletion of Customer Personal Data

Upon termination or expiry of the Agreement, Customer may request a full export of Customer warehouse data (SQL dump) within seven (7) days of termination. Filament will provide the export within seven (7) days of receipt of the request via an encrypted channel.

After the export period, or if no export is requested:

  • Customer warehouse data is retained for seven (7) days after subscription end, then deleted by dropping the customer’s database schema and allowing backups to expire;
  • Platform user account data (profiles, settings, authentication records) is retained for thirty (30) days after account deletion, then permanently removed;
  • Application logs containing Personal Data are retained for thirty (30) days, then automatically rotated; and
  • Backups expire automatically within their defined retention windows.

Filament may retain Customer Personal Data to the extent required by applicable law, in which case Filament will continue to ensure the confidentiality and security of such data and will not actively process it for any other purpose.

13. AI Processing and Model Training

Filament uses AI providers to power agent-based analytics within the Service. AI model requests are routed through the Vercel AI Gateway, which Filament configures to mandate zero data retention with every downstream provider. Model providers currently include Anthropic (Claude), Google (Gemini), and OpenAI (GPT). The current list is maintained at /subprocessors and updated under the sub-processor change procedure in Section 7.

Customer Personal Data processed by these providers as part of providing the Service is not used to train, improve, or develop AI models. This commitment is contractually enforced with each AI Sub-processor.

AI interactions are ephemeral: Customer queries and the schema or data context provided to support them are processed for the immediate purpose of returning a result and are not retained by the AI provider for training purposes. Filament does not use Customer Personal Data to train its own models.

14. Liability

Each party’s liability arising out of or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Agreement. Nothing in this DPA limits or excludes liability that cannot be limited or excluded under applicable law, including under the Privacy Act, the GDPR, or the Competition and Consumer Act 2010 (Cth).

15. General

  • Order of precedence. In the event of a conflict between this DPA and the Agreement, this DPA prevails to the extent of the conflict in matters relating to the processing of Personal Data. The Standard Contractual Clauses prevail over this DPA where applicable.
  • Updates. Filament may update this DPA from time to time to reflect changes in law, regulatory guidance, or to Filament’s practices. Material changes will be notified to Customer at least thirty (30) days before they take effect.
  • Governing law. This DPA is governed by the laws of New South Wales, Australia, except that, where the Standard Contractual Clauses apply, those Clauses are governed by the law of the EU member state specified therein.
  • Severability. If any provision of this DPA is found to be unenforceable, the remaining provisions will continue in effect.

Schedule 1 — Description of Processing

Subject matter of processing

Provision of the Filament data warehouse and analytics platform.

Duration of processing

The term of the Agreement, plus the retention periods set out in Section 12.

Nature and purpose of processing

Synchronising data from Customer’s connected sources to a dedicated warehouse database; storing, querying, and visualising that data; generating analytics and AI-assisted insights; supporting Customer’s use of the Service.

Types of Personal Data

Personal Data contained in Customer’s connected data sources and synchronised to the warehouse, which may include: contact details (names, email addresses, phone numbers, postal addresses); account identifiers; transaction and donation records; behavioural and analytics data; and other categories of Personal Data Customer chooses to import.

Categories of Data Subjects

Customer’s end users, customers, donors, employees, and other individuals whose Personal Data is contained in Customer’s connected data sources.

Special categories of Personal Data

Customer is responsible for determining whether to import special categories of Personal Data (sensitive information under the APPs, or special categories under GDPR Art. 9). Where Customer does so, the same technical and organisational measures apply.

Schedule 2 — Sub-processors

The current list of Sub-processors authorised under Section 7 is maintained at /subprocessors and incorporated by reference into this DPA.

Schedule 3 — Technical and Organisational Measures

Filament implements the following measures to protect Customer Personal Data. Detailed implementation is documented in Filament’s internal security policies, summaries of which are available on request.

Tenant Isolation

  • Each Customer organisation receives a dedicated PostgreSQL database with no cross-tenant query capability.
  • Per-organisation database roles enforce isolation at the warehouse layer.
  • Application-layer authorisation checks enforce organisation scoping on every API request.

Encryption

  • TLS 1.2 or higher for all data in transit, with no exceptions.
  • AES-256 encryption at rest for all platform and warehouse databases, and for all backups.
  • AES-256-CBC application-layer encryption for OAuth tokens and API keys before storage in the database.
  • scrypt with per-password salts for password hashing; plaintext storage of credentials is prohibited.

Access Control

  • Mandatory multi-factor authentication on all administrative and production accounts.
  • Role-based access control with least-privilege provisioning; quarterly access reviews.
  • Deprovisioning within 24 hours of an individual’s departure; shared secrets rotated within 48 hours.
  • Privileged access logged; production database access requires encrypted channels.
  • Customer-facing authentication with CSRF protection, session fixation prevention, rate limiting, and optional MFA and Passkeys.

Application and Network Security

  • Three-step authorisation model on every API endpoint: authenticate, authorise, scope to organisation.
  • Parameterised SQL queries with tagged template literals — string concatenation prohibited.
  • Input validation via Zod schemas on all server actions before processing.
  • Continuous dependency vulnerability scanning (Dependabot); security-critical updates applied within 48 hours.
  • DDoS protection at the edge (Vercel) covering L3, L4, and L7 attacks.
  • OWASP Top 10 controls implemented at each application layer.

Operational Security

  • Production deployments via authenticated CI/CD pipeline with automated security checks.
  • Real-time application monitoring (Dash0) for errors, performance anomalies, and potential security events.
  • Audit logging of critical operations on production systems.
  • Personnel screening, security awareness training at onboarding and annually thereafter, and signed confidentiality obligations for all personnel with access to Customer Personal Data.

Resilience

  • Encrypted, automated backups with point-in-time recovery on all platform and warehouse databases.
  • Backups stored across multiple availability zones in the selected region.
  • Documented business continuity and disaster recovery plan with defined RPO and RTO targets, tested annually.

Incident Response

  • Documented incident response process aligned with NIST four-phase lifecycle (Preparation, Detection and Analysis, Containment / Eradication / Recovery, Post-Incident Activity).
  • Customer notification within 72 hours of confirmation of a Personal Data Breach affecting Customer Personal Data.
  • Annual tabletop exercise to validate the incident response process.
  • Forensic evidence preserved with documented chain of custody for a minimum of 12 months.

Vendor Risk Management

  • Critical-tier Sub-processors are required to maintain SOC 2 Type II or ISO 27001 certification, reviewed annually.
  • DPAs executed with all Sub-processors that process Customer Personal Data.
  • Sub-processor changes published with at least 30 days’ notice at /subprocessors; Customer right to object.

Contact

Questions about this DPA, or requests for a counter-signed copy, should be sent to:

Email: team@filamentanalytics.com
Errinundra Pty Ltd t/a Filament ABN: 29 680 843 814
81–83 Campbell Street, Surry Hills NSW 2010, Australia