Data Processing Agreement - Central AI Platform
Version 2.1 · Last updated July 2026
This DPA applies to processing conducted through centralai.app by DANIEL ROY FERNYHOUGH trading as CENTRAL AI (ABN 24 394 621 830). Unless mandatory law provides otherwise, this DPA is governed by the laws of Victoria, Australia.
1. Definitions
Data Controller means the customer (you) that determines the purposes and means of processing personal data.
Data Processor means Central AI, which processes personal data on behalf of the Data Controller.
Personal Data means information relating to an identified or identifiable natural person processed through the platform, including account data, messages, usage records, and content submitted to or processed by AI agents.
2. Scope
This Data Processing Agreement (DPA) applies when you use Central AI to process personal data through the platform. Central AI acts as a Data Processor and you act as the Data Controller for that data.
This DPA applies to both the persistent storage and the transient processing of data required to generate AI outputs and operate Platform features. Transient processing-including where personal data is passed to an AI model for inference and is not permanently stored on Central AI systems-constitutes processing governed by this DPA.
3. Processing Instructions
Central AI will process personal data only on your documented instructions (including platform configuration, API usage, and applicable agreements) and as required by law.
Central AI will not process personal data for purposes incompatible with providing and securing the services, supporting platform operations, or meeting legal obligations.
4. Confidentiality
Central AI ensures that persons authorised to process personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
5. Security Measures
- Encryption of data in transit (TLS) and at rest where applicable
- Access controls and authentication
- Secure development practices
- Monitoring and security assessments appropriate to risk
6. Sub-processors
Central AI may use sub-processors (for example hosting, payments, communications, and AI infrastructure providers) to perform the services.
Transient processing by sub-processors-including where personal data is passed to an AI model for inference and is not permanently stored by Central AI-is governed by this DPA.
Central AI remains responsible for sub-processor obligations required under applicable data protection law and this DPA.
Central AI will maintain a list of current sub-processors and make it available on reasonable request or as published on our website. We will notify you of any intended changes concerning the addition or replacement of sub-processors, giving you a reasonable opportunity to object to such changes. If you object on reasonable grounds relating to data protection, the parties will work in good faith to resolve the concern. Where resolution is not reasonably possible, you may terminate the affected services.
7. Data Breach Notification
Central AI will notify the Data Controller without undue delay after becoming aware of a personal data breach affecting personal data processed on your behalf.
Central AI will provide reasonable assistance to help the Controller meet breach notification obligations under the GDPR, UK GDPR, and the Australian Privacy Act (including the Notifiable Data Breaches scheme and any applicable 72-hour notification requirements).
To the extent available, notifications will include the nature of the breach, categories and approximate numbers of individuals and records affected, likely consequences, and measures taken or proposed to address the breach.
8. Data Subject Rights
To the extent required by law, Central AI will provide reasonable assistance for requests from data subjects, including access, correction, deletion, restriction, portability, and objection requests.
9. DPIA and Regulatory Assistance
Where required by applicable law, Central AI will provide reasonable assistance to the Data Controller in conducting Data Protection Impact Assessments (DPIAs) and related prior consultations with supervisory authorities, taking into account the nature of processing and information available to Central AI.
10. Data Retention and Deletion
Personal data is retained only as long as necessary to provide services, maintain platform integrity, and meet legal obligations.
Upon valid request and where applicable, Central AI will delete or de-identify personal data within a reasonable period, unless retention is required by law or for legitimate legal, security, or accounting purposes.
11. Audits
On reasonable written request, Central AI may provide information reasonably necessary to demonstrate compliance with this DPA, subject to confidentiality, security, and proportionality controls.
12. International Transfers
Central AI may process personal data in multiple jurisdictions, including outside Australia, the EEA, and the UK.
Where transfer safeguards are required by applicable law, Central AI will implement appropriate mechanisms, such as adequacy-based transfers or contractual safeguards.