OnboardMe

Terms & policies

  • Privacy Policy
  • Terms of Service
  • Data Processing Agreement
  • Electronic records & signature disclosure
  • Chrome extension privacy
  • Google user data

Trust & security

  • Information security & business continuity
  • Subprocessors
  • Data storage & backups
Contact usLog in

© 2026 OnboardMe Pty Ltd

Data Processing Agreement

Last updated August 2026 · UK GDPR and the Data Protection Act 2018

Summary

This Data Processing Agreement ("DPA") is OnboardMe Pty Ltd's standard processor terms for this deployment of the Service (hosting: AWS London region). This DPA is intended to satisfy Article 28 of the UK GDPR (and equivalent requirements under the Data Protection Act 2018) for processing carried out on this United Kingdom deployment of the Service.

It is incorporated into, and forms part of, the Terms of Service between the organisation that subscribes to or otherwise uses the Service (the "Customer") and OnboardMe Pty Ltd ("OnboardMe", "we", "us"). The Privacy Policy describes how the platform handles personal information; this DPA is the contractual allocation of roles and instructions for processing done on the Customer's behalf.

In practice, this DPA applies as follows:

  1. Automatic application. When a person accepts the Terms on behalf of the Customer, or the Customer uses the Service in a way that involves Client Data, this DPA applies. No extra click or signature is required for it to be binding, unless OnboardMe and the Customer execute a separate written DPA.
  2. Who it binds. It binds the Customer (the practice or firm) and OnboardMe. Individual staff users accept on behalf of the Customer if they have authority to do so (as already stated in the Terms). The Customer's end clients are not parties. A client who wants access, correction, or deletion of their information should contact the Customer; OnboardMe will assist the Customer as set out below.
  3. What it enables. It authorises OnboardMe to host, store, transmit, and otherwise process Customer Personal Data only as needed to operate the features the Customer uses (onboarding, forms, engagements, documents, messaging, identity / AML verification where enabled, and optional integrations the Customer connects). It does not add product features, and it does not transfer professional or regulatory responsibility for the Customer's clients to OnboardMe.
  4. Signed copies. If the Customer's procurement or privacy policy requires a countersigned DPA, email [email protected] with the subject "DPA countersignature". A separately executed DPA prevails over this page to the extent of conflict.
  5. Regional deployments. If the Customer uses more than one OnboardMe regional product (for example Australia and the United Kingdom), each deployment has its own hosting location, subprocessor list, and DPA page. Read the DPA on the deployment the Customer actually uses.
  6. Not legal advice. This DPA is a contract. It is not legal, tax, or compliance advice to the Customer. The Customer must assess whether the Service and these terms meet its own professional and regulatory obligations.

Contents

  1. Summary
  2. Parties
  3. Definitions
  4. Roles
  5. What this DPA covers
  6. Instructions
  7. Customer obligations
  8. OnboardMe obligations
  9. Subprocessors and integrations
  10. International transfers
  11. Assistance with individual rights
  12. Personal data breaches
  13. Return and deletion
  14. Information and audits
  15. Liability and precedence
  16. Term, variation, and contact
  17. Annex 1 — Details of processing
  18. Annex 2 — Material subprocessors
  19. Annex 3 — Technical and organisational measures

Parties

Processor / service provider: OnboardMe Pty Ltd (ACN 680 379 640), trading as OnboardMe, an Australian company.

Customer: the organisation that has an OnboardMe account or subscription, or that otherwise uses the Service under the Terms, and on whose behalf Client Data is processed.

Definitions

  • Customer Account Data means information OnboardMe handles as an independent organisation about the Customer itself — for example practice user accounts, subscription and invoice records for fees payable to OnboardMe, security logs of staff logins, and product analytics about use of the Service. That processing is described in the Privacy Policy and is outside this DPA.
  • Customer Personal Data (also "Client Data" in the Terms) means personal information / personal data relating to the Customer's clients and other individuals that is submitted to, generated in, or processed through the Service on the Customer's behalf. Annex 1 lists typical categories.
  • Service means the OnboardMe platform for this deployment, including related APIs and the OnboardMe Assist Chrome extension where the Customer's users install it.
  • Subprocessor means a third party engaged by OnboardMe to process Customer Personal Data in providing the Service (Annex 2). It does not mean a system the Customer chooses to connect (for example Xero or FYI).
  • Terms defined in the Terms of Service or Privacy Policy have the same meaning unless this DPA says otherwise.

Roles

The Customer is the controller of Customer Personal Data. The Customer determines the purposes and means of that processing (including which clients to onboard, which features to enable, and how verification or screening results are used in the Customer’s own compliance decisions).

OnboardMe is the processor of Customer Personal Data. OnboardMe processes that data only to provide the Service on the Customer’s documented instructions, as described in this DPA.

In the language of UK GDPR and the Data Protection Act 2018, the Customer is the controller and OnboardMe is the processor for Customer Personal Data. Typical lawful bases for the Customer’s own use of the Service are a matter for the Customer. OnboardMe does not decide the Customer’s lawful basis for Client Data.

What this DPA covers (and what it does not)

Covered: all processing of Customer Personal Data by OnboardMe and its subprocessors to provide the Service, including the activities in Annex 1.

Not covered: Customer Account Data (OnboardMe as controller / APP entity for its own business); the Customer's own files and systems outside OnboardMe; processing by third parties the Customer instructs us to send data to (optional integrations); and professional advice, AML decisions, or regulatory filings, which remain the Customer's. OnboardMe is a software tool only, as stated in the Terms.

Instructions

The Customer instructs OnboardMe to process Customer Personal Data:

  • to provide and secure the Service as configured by the Customer;
  • in accordance with this DPA, the Terms, and the Privacy Policy; and
  • as the Customer directs through ordinary use of the Service (for example creating a client, enabling identity verification, sending an engagement, connecting an integration, or deleting a record).

OnboardMe will not process Customer Personal Data except on these documented instructions unless required by applicable law. If we are required by law to process other than as instructed, we will inform the Customer unless the law prohibits that notice. If we reasonably believe an instruction infringes applicable data-protection law, we will inform the Customer and may pause that instruction until it is clarified or withdrawn.

Written instructions outside the product must be sent to [email protected] by an authorised administrator and must be capable of being performed in the Service. OnboardMe is not obliged to build custom processing that the Service does not support.

Customer obligations

The Customer must:

  • have a lawful basis (and any required notices or consents) to submit Customer Personal Data, including identity documents and UTR where collected;
  • not instruct OnboardMe to process children's data (the Service is not directed at children);
  • use access controls, including MFA where offered, and keep staff credentials confidential;
  • configure optional integrations and identity / AML features only where the Customer accepts the additional sharing described in the Privacy Policy and Annex 1;
  • remain responsible for how ComplyCube or other verification results are used in the Customer's compliance decisions;
  • handle requests from its own clients about Customer Personal Data, and contact OnboardMe only where platform assistance is needed; and
  • notify OnboardMe promptly if it believes Customer Personal Data has been processed in error or without authorisation in the Customer's tenant.

OnboardMe obligations (Processor duties under UK GDPR Article 28)

OnboardMe will:

  • Process Customer Personal Data only on documented instructions, including regarding international transfers, unless required to do otherwise by UK or other applicable law (in which case we will inform the Customer unless the law prohibits that notice).
  • Ensure persons authorised to process Customer Personal Data are bound by confidentiality.
  • Implement appropriate technical and organisational measures under UK GDPR Article 32, as described in Annex 3.
  • Engage another processor only with general written authorisation as set out in the subprocessors section, and flow down equivalent data-protection obligations.
  • Assist the Customer, taking into account the nature of processing, with responding to data-subject requests under UK GDPR Chapter III.
  • Assist the Customer with Articles 32 to 36 (security, personal data breaches, data protection impact assessments, and prior consultation) taking into account the nature of processing and information available to us.
  • At the end of the provision of processing services, delete or return Customer Personal Data as set out in this DPA, and delete existing copies unless UK law requires storage.
  • Make available to the Customer all information reasonably necessary to demonstrate compliance with Article 28, and allow for and contribute to audits as set out in this DPA.

Where the Customer enables identity verification, Customer Personal Data may include special category data (for example biometric data used for unique identification). The Customer is responsible for having a UK GDPR condition for that processing. OnboardMe processes it only as required to provide the enabled feature, including via ComplyCube.

Subprocessors and optional integrations

The Customer authorises OnboardMe to engage the material subprocessors in Annex 2 (and the Privacy Policy) to process Customer Personal Data for the stated purposes. OnboardMe will impose confidentiality and data-protection obligations on those subprocessors that are no less protective in substance than this DPA, having regard to the service they provide.

OnboardMe may update the list from time to time. Material additions will be communicated in line with the Customer's agreement with us (for example in-product notice or email to organisation administrators). The Customer may object on reasonable data-protection grounds within 14 days of notice. If we cannot reasonably accommodate the objection, the Customer may stop using the affected feature or terminate the affected subscription in accordance with the Terms.

Practice-management, accounting, document, or email systems the Customer connects (for example Xero, FYI, GreatSoft, KloudConnect, or Google Workspace) are engaged at the Customer's direction. They are not OnboardMe subprocessors. Data shared with them is an instruction from the Customer; those providers' terms apply as between the Customer and that provider.

International transfers

Primary infrastructure and stored customer data for this deployment are located in the United Kingdom (AWS London). When your organisation enables identity verification or AML screening features, relevant personal information (such as identity documents, live facial or biometric capture used for verification, and screening data) is shared with ComplyCube, a United Kingdom-based identity and AML verification provider, and is processed and stored in the United Kingdom. Payment processing is handled by Stripe. Transfers to PostHog and Sentry in the EEA may rely on UK adequacy regulations where they apply. Email delivery via Resend or Mailgun may involve processing in the United States. Transactional email and SMS (Resend, Mailgun, TallBob), product analytics (PostHog EU Cloud), and error monitoring (Sentry in the EU) necessarily involve processing outside the primary hosting region. Optional integrations you connect may involve further disclosure at your or your organisation’s direction. Where UK GDPR requires a transfer tool for a restricted transfer, we use one (for example adequacy regulations, the UK International Data Transfer Agreement, or the UK Addendum to the EU SCCs), unless a permitted exception applies.

Where a transfer of Customer Personal Data outside the UK is required to provide the Service, OnboardMe will use a valid UK transfer mechanism where the law requires one (for example UK adequacy regulations for EEA recipients such as PostHog and Sentry, the UK International Data Transfer Agreement, or the UK Addendum to the EU SCCs), unless an exception permitted by UK GDPR applies. This includes email delivery that may involve processing in the United States.

Assistance with individual rights

If an individual asks OnboardMe to access, correct, delete, or otherwise exercise rights in Customer Personal Data, OnboardMe will (where we can identify the Customer) direct the individual to the Customer and/or notify the Customer, unless we are legally required to handle the request ourselves.

If the Customer cannot fulfil a request using the Service (for example deletion of an entity, download of documents, or correction of a client record), the Customer may email [email protected] with the subject "Privacy request — processor assistance". OnboardMe will provide reasonable assistance, taking into account the nature of processing and the information available to us. We may need the Customer to verify the request and specify the tenant and records involved.

Personal data breaches

OnboardMe will notify the Customer without undue delay after becoming aware of a personal data breach affecting Customer Personal Data, and in any event in time for the Customer to meet its own UK GDPR duties (including, where applicable, notifying the ICO within 72 hours of the Customer becoming aware).

Notification will describe, as then known: the nature of the breach, the categories and approximate number of individuals and records concerned, likely consequences, and measures taken or proposed. OnboardMe will reasonably cooperate with the Customer's investigation and with any required regulator or individual notification that the Customer must make. Public security reporting channels are described in the Security Policy.

Return and deletion

During the subscription, the Customer may export or delete Customer Personal Data using the Service (for example deleting a client entity or downloading documents). That is the primary way the Customer exercises deletion and portability in the product.

When the Customer's subscription or authorised use ends, OnboardMe will, within 90 days, delete Customer Personal Data from production systems, or return it in a reasonable commonly used form if the Customer requests export in writing within 30 days after termination. Copies in encrypted backups will drop out on the backup cycle and will not be restored into production except as needed for disaster recovery. OnboardMe may retain Customer Personal Data where required or authorised by law (including tax and accounting records of the Customer relationship, which are Customer Account Data), or in a form that no longer identifies individuals.

Information, DPIAs, and audits

OnboardMe will make available information reasonably necessary to demonstrate compliance with this DPA, including this page, the Privacy Policy, and the Security Policy. Taking into account the nature of processing, we will provide reasonable assistance with the Customer's data-protection impact assessments or equivalent risk assessments, and with any prior consultation with a regulator, to the extent the assessment concerns the Service.

If that information is not sufficient, the Customer may request an audit, no more than once per 12 months unless a confirmed personal data breach or a regulator requires otherwise. Audits must be reasonable in scope, on notice of at least 30 days, during business hours, and must not compromise other customers' security or confidentiality. OnboardMe may satisfy an audit by providing third-party certifications, questionnaire responses, or a call with security personnel. The Customer bears its own costs; OnboardMe may charge reasonable costs for on-site or unusually burdensome audits.

Liability and precedence

This DPA is an addendum to the Terms. Liability arising from processing under this DPA is subject to the limitations and exclusions in the Terms, except where applicable law prohibits that limitation. Each party remains liable for its own obligations as controller or processor under mandatory data-protection law.

Order of precedence for Customer Personal Data: (1) a separately executed DPA between the parties; (2) this DPA; (3) the Privacy Policy insofar as it describes processing; (4) the Terms. Commercial terms (fees, service availability, IP, governing law of the contract) remain as in the Terms unless a signed DPA expressly changes them.

Term, variation, and contact

This DPA starts when the Customer first uses the Service under the Terms after the Effective Date (or when a prior version applied, from that earlier date) and continues until OnboardMe has deleted or returned Customer Personal Data as required above. Confidentiality, deletion, audit (for the retention period), and liability clauses survive accordingly.

OnboardMe may update this DPA as described for the Terms (including notice of material changes). Continued use after the effective date of an update constitutes acceptance, except that a separately executed DPA changes only if the parties agree in writing.

This DPA is governed by the same law and courts as the Terms, without limiting mandatory data-protection law of this deployment. Questions: [email protected] (privacy) or [email protected] (security).

Annex 1 — Details of processing

A. Subject matter and nature

Hosting and operation of the OnboardMe cloud platform so the Customer can run client onboarding, engagement letters, forms and e-sign, document collection, identity verification and AML screening (where enabled), messaging, billing-related client workflows, and optional connections to the Customer's own practice systems. Processing includes collection, recording, organisation, storage, retrieval, consultation, use, disclosure by transmission, restriction, and erasure, as performed by the features the Customer uses.

B. Duration

For the term of the Customer's subscription (or other authorised use of the Service), plus the post-termination deletion / return period in this DPA, and any longer period required by law or encrypted backups that are deleted on the backup cycle.

C. Purpose

Solely to provide, maintain, secure, support, and improve the Service for the Customer, to communicate about the Service as the Customer directs (for example sending an engagement to a client), and to comply with law. OnboardMe does not sell Customer Personal Data and does not use it for OnboardMe's own marketing to the Customer's clients.

D. Categories of data subjects

  • The Customer's clients and prospective clients (individuals, and individuals associated with client organisations — for example directors, trustees, and contacts).
  • Recipients of onboarding, forms, engagements, ethical letters, identity verification, and similar workflows (including people who access a client portal or magic-link).
  • Other individuals whose information the Customer (or a client acting in the Customer's workflow) enters into the Service — for example referees, signatories, or related-party contacts.
  • Individuals named in documents the Customer uploads or generates (engagement PDFs, identity documents, supporting files).

Practice staff who hold OnboardMe user accounts are primarily described as Customer Account Data (outside this DPA). Staff names and contact details that appear inside Client Data (for example as the assigned adviser on an engagement) are processed as Customer Personal Data to the extent they form part of that Client Data.

E. Types of Customer Personal Data

Depending on the features the Customer uses, this may include:

  • Identity and contact: name, email, phone, job title, date of birth, address, employer or entity identifiers.
  • Tax and government identifiers: Unique Taxpayer References (UTRs) and similar tax identifiers, and similar identifiers the Customer collects.
  • Financial: bank account and payment details entered for the Customer's clients (as distinct from the Customer's own subscription billing to OnboardMe).
  • Service content: information entered into forms, proposals, engagements, ethical letters, custom fields, notes, and related workflows; electronic signatures and signing metadata.
  • Documents: uploaded files, generated PDFs, identity document images, and similar records stored in object storage.
  • Identity verification and AML: identity documents, live facial images or biometric capture used for matching, verification session identifiers, and AML / PEP / sanctions screening inputs and results — where the Customer enables those features.
  • Technical data created by use of the Service: IP address, device or session metadata, authentication events, and audit logs relating to Client Data access.

F. Processing activities in the product

ActivityTypical processingTypical recipients
Client / entity records and onboardingStore, display, update, and delete client information the Customer or the client submitsHosting (AWS London region); optional practice integrations the Customer connects
Forms, engagements, ethical letters, e-signCreate, send, collect responses, generate PDFs, record signaturesHosting; email and SMS providers when the Customer sends a workflow
Document collectionUpload, store, download (including short-lived signed URLs), optional push to the Customer's DMSHosting object storage; KloudConnect or similar only if the Customer connects it
Identity verification and AML screeningShare identity and screening inputs; receive outcomes and artefactsComplyCube (United Kingdom), when the Customer enables the feature
Transactional email and SMSDeliver invitations, reminders, and service messages the Customer triggersResend, Mailgun, TallBob
Client payment details (where used)Collect or display payment information for the Customer's billing of its clientsPinch, Apxium, Stripe, or Paystack as configured for this deployment and the Customer
Optional practice-system syncCreate, update, or retrieve clients, contacts, jobs, or documents in the connected systemThe provider the Customer connects (for example Xero, FYI, GreatSoft, Google Workspace) — at the Customer's direction
Chrome extension (OnboardMe Assist)Read bank / identity fields already in OnboardMe to fill empty fields in Xero Practice Manager, using session credentials in the browserProcessed in the authorised user's browser and via the Service APIs; not a separate hosting location
Security, support, and reliabilityLogs, backups, error diagnostics, and aggregated product analyticsHosting and monitoring for this deployment (AWS London region); PostHog; Sentry; UptimeRobot

OnboardMe does not itself make solely automated decisions with legal or similarly significant effects about the Customer's clients. ComplyCube may return automated verification or screening results; the Customer remains responsible for how those results are used.

Annex 2 — Material subprocessors

The Customer gives general written authorisation to the subprocessors listed below for this deployment. Optional integrations the Customer connects are not OnboardMe subprocessors and are not listed here. Where a name is linked, it opens that provider's privacy or security information.

SubprocessorPurposeLocation
Amazon Web Services (AWS)Cloud hosting, backups, logging, and monitoringUnited Kingdom (London region)
ComplyCubeIdentity verification and AML / PEP / sanctions screening (where enabled)United Kingdom
StripePayment processingAs operated by Stripe for United Kingdom payments
ResendTransactional and service email deliveryUnited States (and other locations as operated by Resend)
MailgunTransactional and service email deliveryUnited States and other locations as operated by Mailgun
TallBobSMS messagingAustralia (as operated by TallBob)
UptimeRobotExternal uptime and availability monitoringAs operated by UptimeRobot
PostHogProduct analytics and diagnosticsEuropean Economic Area (PostHog EU Cloud)
SentryApplication error monitoring and diagnosticsEuropean Union (error ingestion in Germany)

This list is the same material-subprocessor list published in the Privacy Policy for this deployment. If the two pages ever differ, the Privacy Policy list as updated on that page is the operative list, and this Annex will be treated as updated accordingly.

Annex 3 — Technical and organisational measures

OnboardMe implements the following measures, which may be updated as technology and threats change provided the overall level of security is not materially reduced. Backups, recovery, and controls are described in Information security & business continuity. Vulnerability reporting is on that same page.

  • Hosting and location: production Customer Personal Data for this deployment is stored in the AWS London region, with encrypted backups in the United Kingdom (London region).
  • Encryption: Customer data is encrypted in transit using TLS 1.2+. Data at rest on this AWS deployment is encrypted (including via AWS KMS / AES-256 for volumes and object storage), as described in our Information security & business continuity policy. Tax identifiers and other high-risk fields are subject to additional access restriction.
  • Access control: role-based access within the Customer's tenant; authentication including multi-factor authentication where enabled by the Customer; OnboardMe staff access limited to personnel who need it for support, security, or operations, on a least-privilege basis.
  • Isolation: Customer data is logically separated by practice / tenant identifiers in the application data model.
  • Monitoring and logging: authentication events, operational logs, and security alerting (including to [email protected]), with error monitoring configured to limit identifiable data to what is needed for diagnosis.
  • Personnel: confidentiality obligations for staff and contractors who may access Customer Personal Data; access reviewed when roles change.
  • Subprocessors: due diligence and contractual confidentiality / security obligations appropriate to the service they provide.
  • Vulnerability and incident management: vulnerability handling, an incident response process, and breach assessment aligned with Compliance with UK law.
  • Backups and restoration: encrypted backups and procedures to restore availability of the Service after an incident, within commercially reasonable timeframes.

No electronic system is perfectly secure. These measures are appropriate to the nature of the Service as a professional-services onboarding platform handling tax identifiers, identity documents, and similar information, taking into account the state of the art, implementation costs, and the risks for individuals.