livewells A$699 a month excl. GST

Data Processing Agreement

Version: 1.0 Effective: 11 October 2026 Version date: 11 October 2026

Contents
  1. 0. Parties and scope
  2. 1. The two data categories, kept apart
  3. 2. Subject matter and details of processing
  4. 3. Roles
  5. 4. Supplier obligations
  6. 5. Sub-processors and service providers
  7. 6. International transfers
  8. 7. Security and support access
  9. 8. Retention and deletion
  10. 9. Information and audit
  11. 10. General
  12. Issue

This document applies to each Subscription.

0. Parties and scope

The "Supplier" in this document is Maelstrom AI Pty Ltd (ACN 679 356 702), which uses the name livewells. It is the trustee for the Maelstrom AI Holding Trust (ABN 61 633 823 792). "Customer" means the customer named at checkout. "The Agreement" means the livewells subscription terms that this document is part of (clause 10.1). Other capitalised terms have the meanings in the Agreement.

This document is part of the subscription terms. It applies from checkout.

livewells is a hosted Service. The Supplier runs the Service for the Customer and holds the Customer Content of the Customer. This is the links that the Customer submits, and the video, reports, network logs and enrichment results of its sessions. The Service opens links in a disposable, sandboxed browser for URL triage. It records what each page loaded and did.

For Customer Content, the Supplier is a processor and acts on the instructions of the Customer (clauses 1 and 3). For the account and billing data behind the Subscription, the Supplier is a controller in its own right.

This document uses GDPR terms (controller, processor, personal data) with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles.

1. The two data categories, kept apart

1.1 Customer Content (the Supplier is the processor)

The Analysts of the Customer submit links and open them in the Service. The Service keeps the link, a video of the session, a report of the redirect chain, domains and IP addresses, and a network log. It also keeps the IP context and reputation results that it adds to the report.

The link in each entry of the audit log of runs is Customer Content. A link or a page can contain personal information about other people. An example is an email address in a link or a name on a page.

A file that a page offers for download goes to the temporary disk of the disposable browser. Each file is limited to 512 MiB. The Service does not copy the file to storage. The file is destroyed when the browser is destroyed at the end of the session.

The Supplier processes all of this on the documented instructions of the Customer, and clauses 2 to 9 apply to it.

1.2 Account and billing data (the Supplier is the controller)

To deliver the Subscription in the Agreement, the Supplier processes a small set of business-contact personal data. It holds the names, work email addresses and role titles of the nominated contacts of the Customer. It holds the Microsoft Entra tenant and user identifiers of its Analysts. It also holds the identity record in the audit log (which Analyst started each run, and when), records of support correspondence, and the billing name, billing email, plan and subscription status.

The Supplier is a controller in its own right for this data (clause 3). Its purpose is to administer the Subscription and provide support. It does not process this data on the instructions of the Customer.

1.3 Threat Data

Threat Data is de-identified data that the Supplier derives from a Confirmed Malicious Case. The Agreement defines these terms. Threat Data holds attacker indicators (defanged), page structure, enrichment signals and the verdict label. It also holds the month of the session and the country of the exit, where known. Attacker indicators are part of Threat Data on purpose.

The Supplier redacts recipient identifiers first. Threat Data holds no video and no recipient identifier. The Supplier removes the domains, addresses and identifiers of the Customer, and does not keep a record that holds one. Threat Data holds no information about the Customer or its staff. If an indicator identifies a person, the Supplier applies the rules for personal information to it.

Threat Data is not Customer Content. Clause 3.3 applies to it.

2. Subject matter and details of processing

  • Subject matter: delivery of the Service to the Customer.
  • Duration: the term of the Subscription, plus the retention period in clause 8.
  • Nature and purpose: opening the links that the Customer submits in a sandboxed browser, recording what the page loaded and did, and enriching the report with IP context and reputation data. Also storing the results for the Customer, and deleting them in clause 8.
  • Types of personal data: for Customer Content, personal data in a submitted link, a captured page, a video or a network log, and the identity of the Analyst who ran each session. For account and billing data, the data in clause 1.2. A captured page can show special-category data.
  • Categories of data subjects: the Analysts and nominated staff of the Customer, and each person whose information appears in a link or a page that an Analyst opens.

3. Roles

3.1 For Customer Content, the Customer is the controller and the Supplier is the processor. The Customer is responsible for its lawful basis to submit each link and to have the Supplier process the personal data in it.

3.2 For account and billing data, the Supplier is a controller and not a processor. The Supplier decides the purpose and means of this processing (administering the Subscription and providing support). It is accountable for it in data-protection law in its own right, like each vendor for its own customer records. The Customer does not issue processing instructions for the business details of its own contacts. The undertakings of a conventional processor (processing only on instruction, and flow-down duties owed to the Customer) do not apply to this data, because the Supplier does not process it on behalf of the Customer. The Supplier's undertakings in clauses 4.9 to 4.14 apply to that data.

3.3 The Customer instructs the Supplier to de-identify Confirmed Malicious Cases and so make Threat Data. This applies unless the Customer excludes the case, or excludes all its cases, from threat data. The Supplier is the processor for this de-identification, on this instruction, and Customer Content stays Customer Content until it is de-identified.

The instruction is on by default. The Administrator of the Customer can withdraw it whenever they wish, in the Service. An Analyst who ran a case, or an Administrator, can exclude that case whenever they wish. When data is de-identified, the Supplier decides the purpose of the use of Threat Data (a threat feed and training of detection models). It is accountable for that use in data-protection law.

The Supplier de-identifies the data by removing the domains, addresses and identifiers of the Customer and the recipient identifiers in the link. It does not try to re-identify a person or organisation. If the Supplier supplies a threat feed, it does not allow a recipient to re-identify a person or organisation. Each recipient must agree to that in writing before it receives Threat Data. A recipient receives Threat Data and not Customer Content.

3.4 Pages that Analysts open can be hostile. The Customer instructs the Supplier to contact the destinations that its Analysts open, in a disposable browser. It also instructs the Supplier to record what those destinations load and do. A destination site is the target of the instruction of the Customer and is not a sub-processor. The Customer is responsible for its authority to open each link, including a link from its own phishing mailbox (clause 8 of the Agreement and the Acceptable Use Policy).

4. Supplier obligations

For Customer Content, the Supplier will:

4.1 process Customer Content only on the documented instructions of the Customer, unless the law requires otherwise (and then tell the Customer, unless the law forbids it). The instructions are this document, the Agreement, and the use of the Service and its settings by the Customer;

4.2 make sure that persons authorised to process the data are bound by a duty of confidence;

4.3 apply appropriate technical and organisational measures, with regard to the nature of the data, including those in clause 7;

4.4 assist the Customer with data subject requests and with its own security, breach-notification and assessment duties, to the extent that the Supplier reasonably can. The Supplier passes to the Customer each request that it receives from a person whose information is in Customer Content, without answering it itself. The exception is a request about Threat Data, which the Supplier answers itself in its role of controller of that data (clause 3.3);

4.5 notify the Customer without undue delay, and within 72 hours, after the Supplier becomes aware of a personal data breach that affects Customer Content. The Supplier gives the Customer the facts that it reasonably requires to meet its own notification duties. The Customer has the direct relationship with the people affected. It decides if a statutory notice is required and makes the notice, unless it asks the Supplier to make it. This does not limit a duty that the law places on the Supplier;

4.6 delete the data at the end of the relationship, in clause 8;

4.7 inform the Customer if, in the opinion of the Supplier, a documented instruction infringes data-protection law; and

4.8 not make Customer Content public, share it with another customer, sell it, or train a model on it. The only use beyond providing the Service is the making and use of Threat Data in clause 3.3. A model is trained on Threat Data and on no other data.

For account and billing data, the Supplier is a controller and will:

4.9 process the data only for the purposes in clause 2, and not repurpose it without a lawful basis;

4.10 make sure that persons authorised to process the data are bound by a duty of confidence, and apply appropriate technical and organisational measures;

4.11 respond to a data subject request from a nominated contact of the Customer (sent to support@livewells.io); and tell the Customer if a request affects its ability to receive support in the Agreement;

4.12 notify the Customer without undue delay after it becomes aware of a personal data breach that affects the account and billing data;

4.13 delete or return the data at the end of the relationship, in clause 8; and

4.14 make available the information in clause 9, so that the Customer can finish its own data-protection due diligence about this relationship.

5. Sub-processors and service providers

5.1 The Customer authorises the Supplier to use the sub-processors on the published sub-processor list to handle Customer Content. The list states what each receives and where.

5.2 No enrichment provider receives Customer Content. The Supplier enriches a report with two data sources that it stores and searches itself, IPinfo Lite and the abuse.ch lists. They send nothing to their publishers.

5.3 The Supplier maintains the published list. It gives notice by email to the contacts on the Subscription at least 30 days before a new sub-processor begins to handle Customer Content. For an emergency replacement of a sub-processor, it gives notice promptly. A Customer with a concern about a listed provider can raise it with the Supplier directly. If the Customer objects to a new sub-processor on reasonable data-protection grounds, the Customer can end the affected Subscription without penalty. It then receives a pro-rata refund of prepaid fees for the unused term.

5.4 The Supplier requires each sub-processor, by written contract, to meet data-protection obligations no less protective than those in this document. The Supplier stays responsible to the Customer for the performance of the sub-processor.

5.5 For account and billing data, the Supplier uses a small number of service providers, for example Stripe for subscription billing. The Supplier is a controller of this data (clause 3.2). These providers act on the instructions of the Supplier and are not sub-processors appointed for the Customer. The Supplier stays responsible for their handling of the data, in contracts that impose data-protection obligations no less protective than this document. Stripe collects card details directly, and they do not go to the Supplier.

6. International transfers

6.1 The Supplier is established in Australia, and it asks Cloudflare to store Customer Content in Oceania using a location hint. The hint is set on the R2 buckets, the D1 database and the Durable Objects of the Supplier. A hint is a request, not a guarantee. The Supplier does not set a location for session containers, which run in Cloudflare locations that the Supplier does not choose. Those locations can be in the countries where Cloudflare operates, including outside Australia. Named sub-processors (see the published list) can process Customer Content in their own regions.

6.2 The EU and UK GDPR restrict transfers out of the EEA or UK. Where those restrictions apply to a transfer for the Customer, the Supplier relies on an adequacy decision where one applies. Otherwise it relies on the 2021 Standard Contractual Clauses of the European Commission. These are Module Two (controller to processor) for Customer Content, and Module One (controller to controller) for account and billing data. The UK International Data Transfer Addendum applies where the UK GDPR applies. The Supplier executes these on request.

6.3 The Supplier requires each sub-processor that receives Customer Content outside Australia to give the protection that clause 6.2 requires.

7. Security and support access

7.1 The Supplier applies these measures:

  • The data of each customer is kept apart from the data of all other customers.
  • The Supplier encrypts the session files of each customer (the video, reports, network logs and enrichment results) with a key made for that customer alone.
  • The Supplier destroys the key when the Administrator of the Customer deletes all Customer Content. Cloudflare keeps point-in-time history of its databases for a limited period.
  • Analysts sign in with Microsoft Entra ID. The Supplier decides which customer a person belongs to from the Entra tenant that signs the person in.
  • Each session runs in a disposable, sandboxed browser that is destroyed when the session ends.
  • The browser cannot connect to private or internal network addresses.
  • Session browsers connect to the internet from the network of Cloudflare.
  • Traffic between a browser and the Service uses HTTPS.
  • Indicators on screen, in case exports and in the audit log are defanged. The exception is the blocklist copy (clause 6.9 of the Agreement). An Analyst confirms it first, and the audit log records counts only.
  • The Supplier keeps an audit log of each run.

The Supplier makes further detail of these measures available on request (clause 9.1).

7.2 The Supplier accesses Customer Content for support only with the written permission of the Customer. It agrees an end time with the Customer in writing. The Supplier also accesses Customer Content to investigate abuse or a security incident, in line with the Agreement. It accesses only the records that the investigation requires. It will give the Customer written notice promptly, unless the law or the investigation forbids it. The operator console of the Supplier shows no links, reports or videos.

8. Retention and deletion

8.1 The Supplier keeps Customer Content for the retention period. The default is 90 days from the end of the session. The Administrator of the Customer can set the period between 7 and 365 days. At the end of the period the Supplier deletes the session files and the links held in the audit log.

8.2 The Administrator of the Customer can delete one ended session, or all Customer Content of the Customer. The Customer can also ask the Supplier in writing to delete all of it, and the Supplier does so. When the Administrator deletes all Customer Content, the Supplier destroys the key. Cloudflare keeps point-in-time history of its databases for a limited period. The audit log keeps records of retention settings, deletions and operator actions. Before the Subscription ends, the Administrator can set a shorter retention period, or the Customer can ask the Supplier in writing to delete sooner.

8.3 When the Subscription ends, the Supplier will, at the request of the Customer, delete or return account and billing data. The exception is records that the Supplier must keep for legal, tax or accounting reasons. It keeps those only for the period that the law requires, and then deletes them.

8.4 The Supplier keeps the video, network logs and page content of a session only for the retention period. When the Customer excludes a case, or all its cases, from threat data, the Supplier uses no such case. It deletes the records that it holds from those cases at its next scheduled run. It puts none of them in a new export or a new training run.

8.5 Material in an earlier export or in a trained model stays, because it is de-identified and is not Customer Content. Deleting a session, or the end of the Subscription, leaves Threat Data in place unless the case is excluded.

8.6 On the written request of the Customer, the Supplier resumes a suspended account, for 7 days at most, so that the Administrator of the Customer can export Customer Content. The Supplier then suspends the account again. The Supplier deletes Customer Content at the end of the retention period.

9. Information and audit

9.1 The Supplier makes available the information that is reasonably necessary to show compliance with this document. This is mainly this document, the published sub-processor list, and written answers to reasonable security questions of the Customer, sent to support@livewells.io.

9.2 The Supplier allows and contributes to audits of its processing of Customer Content, including inspections. The Customer, or an auditor that it appoints, conducts them. The audit is subject to confidentiality and to reasonable limits on frequency and scope. It occurs no more than once in 12 months, on at least 30 days' written notice, during business hours, at the cost of the Customer. It starts from the information in clause 9.1 before an inspection.

9.3 The Supplier processes account and billing data in its role of controller, and not on the instructions of the Customer. Clause 9.2 therefore does not apply to that data. Nothing here limits the regulatory rights of the Customer.

10. General

10.1 This document is part of the Agreement, the livewells subscription terms in which the Subscription was bought. If this document and the Agreement conflict on data protection, this document prevails for the data that it covers.

10.2 The law of Victoria, Australia, governs this document. It is the law that governs the Agreement.

10.3 Liability in this document is subject to the limits of liability in the Agreement, to the extent that the law allows.


Related documents: livewells subscription terms, support SLA, acceptable use policy, privacy policy, sub-processor list.

Issue

Issued for Maelstrom AI Pty Ltd (ACN 679 356 702), the trustee for the Maelstrom AI Holding Trust (ABN 61 633 823 792), which uses the name livewells.

On request, the Supplier issues a copy that carries the issue date, the name and billing email of the Customer, and the subscription reference.