Data Processing Agreement

Version: 10 August 2026

View previous versions

How this is structured

This Data Processing Agreement (DPA) sets out how Minikai Pty Ltd handles Customer Personal Information. Sections 1 to 10 apply to every customer. One schedule then applies, according to where the Customer is established:

  • Schedule A for customers established or primarily based in the United Kingdom, where the UK GDPR applies.
  • Schedule B for customers established or primarily based in Australia or New Zealand, under the Privacy Act 1988 (Cth) and the Privacy Act 2020 (NZ).

Where a schedule and sections 1 to 10 differ, the schedule prevails.

The Order Form incorporates this DPA by version and names the applicable schedule, which is what makes it part of the customer agreement (the Agreement) and gives it precedence over the Terms of Service on a privacy or data protection matter. Minikai will execute it as a separate document where a Customer's procurement requires one.

Capitalised terms not defined here have the meaning given in the Agreement. Customer Personal Information means the Personal Information and Sensitive Information within Customer Data that Minikai handles on the Customer's behalf. Nothing in this DPA limits either party's own obligations under Privacy Laws.

This DPA covers Customer Personal Information only. Account Data and Company Data are separate categories governed by the Agreement and the published Privacy Policy.

1. Roles

The Customer decides the purposes for which Customer Personal Information is handled and is responsible for the lawfulness of the handling it instructs. Minikai handles it only to provide the Services on the Customer's instructions and never for its own purposes. The applicable schedule states how each regime characterises that relationship.

The Customer warrants that its collection of Customer Personal Information complied with the requirements in its schedule, and that it holds a current executed Consent Form for each Participant as the Agreement requires.

2. Instructions

Minikai handles Customer Personal Information only on the Customer's instructions: the Agreement, this DPA, the Customer's configured use of the platform, and any written instructions the Customer provides from time to time. Minikai handles it otherwise only where required by law, and tells the Customer first unless the law prohibits it. Minikai tells the Customer if an instruction would cause either party to breach Privacy Laws.

Annex 1 sets out the nature and purpose of the handling, the kinds of information, and the categories of individuals.

3. Restrictions

Minikai does not:

  • handle Customer Personal Information for any purpose other than the Permitted Purpose;
  • use it to train AI models;
  • use it for direct marketing;
  • sell it, or disclose it except as the Agreement permits or the law requires; or
  • make decisions about an individual by automated means without a person. Platform outputs are recommendations or drafts a person reviews and acts on.

4. Minikai's obligations

a. Confidentiality. Personnel authorised to handle Customer Personal Information are bound by confidentiality and trained on their responsibilities.

b. Security. Minikai implements the technical and organisational measures in Annex 2, which meet the standard set by the Customer's schedule.

c. Individual rights. Minikai does not respond to an individual on the Customer's behalf. It refers any request it receives to the Customer without undue delay, and supports the Customer's response through export, correction, re-sync and deletion of a person's record.

d. Assistance. Minikai assists the Customer with breach assessment and notification, data protection and privacy impact assessments, and enquiries from a regulator with authority over the Customer, taking into account the nature of the handling and the information available to Minikai.

5. Sub-processors

The Customer authorises Minikai to engage sub-processors. The current list, and the countries in which they operate, is at trust.minikai.com/subprocessors.

Minikai binds each sub-processor by written contract to obligations no less protective than those in this DPA, and remains responsible to the Customer for each sub-processor's handling of Customer Personal Information.

Minikai gives the Customer prior notice before adding or replacing a sub-processor. The Customer may object on reasonable data protection grounds within the notice period, and Minikai works with the Customer in good faith to resolve the objection, including by describing the additional safeguards in place.

6. Where data is held

Minikai holds Customer Data in the Data Region recorded in the Order Form. Two Data Regions are available, Australia and the United Kingdom. New Zealand customers are served from the Australian Data Region. The Data Region changes only on the Customer's written instruction, and Customer Data does not leave it except as the Agreement permits or the law requires.

The Customer's schedule states how its law treats handling that crosses a border.

Where the Customer directs a disclosure for continuity of care under the Agreement, that disclosure is the Customer's, made on the consents it holds.

7. Data breaches

Minikai notifies the Customer of a data breach affecting Customer Personal Information without undue delay and within 24 hours of becoming aware of it, and gives the Customer the information it reasonably needs to assess and meet its own obligations.

The Customer decides whether a breach is notifiable and makes any notification to a regulator or to individuals. Minikai does not notify the Customer's regulator on its behalf. The Customer's schedule sets out the duties the 24-hour commitment is sized to support.

8. Return and deletion

On termination or expiry, the Customer may request in writing within 30 days that Minikai return Customer Data in a standard machine-readable format reasonably determined by Minikai, or permanently delete it from its active systems and confirm the deletion, as the Agreement's Return and Destruction clause provides.

9. Assurance

Minikai holds ISO/IEC 27001:2022 and ISO/IEC 42001:2023 certification and makes available its certifications and, subject to confidentiality, summary audit reports. The Customer relies on these in the first instance.

Where the Customer reasonably requires further assurance, Minikai contributes to an audit: a remote documentary review, on reasonable notice, no more than once in any 12-month period except where a regulator requires it or following a data breach, by the Customer or an independent auditor it mandates who is not a competitor of Minikai and is bound by confidentiality, conducted so as to protect other customers' data. An on-site inspection occurs only where the documentary review does not resolve the Customer's concern or a regulator requires one. The Customer bears its own costs and Minikai's reasonable costs beyond the information and reports described above.

10. General

The liability of each party under this DPA is subject to the limitations and exclusions in the Agreement. The Customer's schedule states the governing law for this DPA. All other terms of the Agreement remain in full force.

Schedule A: United Kingdom

Applies where the Customer is established or primarily based in the United Kingdom.

Roles. The Customer is the controller and Minikai is the processor. The Customer warrants that it has a lawful basis for the processing it instructs and, for special category data such as health and care records, an Article 9 condition.

Article 28(3). Minikai meets the processor obligations in Article 28(3): it processes only on documented instructions (section 2); ensures confidentiality (4a); implements Article 32 security measures (4b and Annex 2); engages sub-processors only on the conditions in section 5; assists with data subject rights (4c); assists with Articles 32 to 36 (4d); returns or deletes on termination (section 8); and makes available the information necessary to demonstrate compliance and contributes to audits (section 9).

Transfers. Where Minikai makes a restricted transfer of Customer Personal Information, including remote access from outside the Data Region (whether to Customer Data held on Minikai's systems or, for integration development, to the Customer's own source systems), it relies on the UK International Data Transfer Agreement (IDTA) as its Article 46 safeguard. The IDTA is incorporated into this DPA by reference and executed with the Order Form, because its Part 1 carries the parties and their signatures and it is not a valid safeguard without them. Its Mandatory Clauses prevail over this DPA and the Agreement on transfer matters, its tables mirror Annex 1, and a change to the processing scope requires them to be re-agreed. The transfer is supported by Minikai's Transfer Risk Assessment, available on request.

Breaches. The 24-hour commitment in section 7 is sized so the Customer can meet Articles 33 and 34: notification to the Information Commissioner's Office without undue delay and, where feasible, within 72 hours, and to affected individuals where the breach is likely to result in a high risk to them.

Governing law. This DPA is governed by the laws of England and Wales, and the parties submit to the exclusive jurisdiction of the courts of England and Wales in respect of it. This prevails over any contrary provision in the Agreement for matters arising under this DPA.

Schedule B: Australia and New Zealand

Applies where the Customer is established or primarily based in Australia or New Zealand. Neither Act uses the controller and processor roles, so the positions are stated in each Act's own terms.

Roles, Australia. The Customer collects Customer Personal Information from the individuals it supports. It does not release the information from its effective control by providing it to Minikai, so that provision is a use rather than a disclosure. Minikai complies with the Australian Privacy Principles (APPs) in respect of the information it holds. The Customer's collection must have complied with APP 3.

Roles, New Zealand. Minikai holds Customer Personal Information solely for safe custody and processing on the Customer's behalf, so under section 11 of the Privacy Act 2020 it is treated as held by the Customer. Minikai never uses or discloses it for its own purposes, which is the only circumstance in which section 11 would also treat it as held by Minikai. Returning it, or anything derived from processing it, is not a use or disclosure by Minikai. The Customer's collection must have complied with Rules 1 to 4 of the Health Information Privacy Code 2020 (HIPC) where that Code applies.

Security standard. The Annex 2 measures meet the reasonable steps required by APP 11, IPP 5 and HIPC Rule 5.

Individual rights. Section 4c supports the Customer's obligations under APP 12 and APP 13, IPP 6 and IPP 7, and HIPC Rules 6 and 7.

Cross-border handling, Australia. Australian Customer Data stays in the Australian Data Region under Minikai's effective control, so handling it is a use and APP 8 is not engaged. Where handling does cross a border, Minikai takes the reasonable steps APP 8.1 requires through binding contractual terms, and acknowledges that under section 16C an overseas recipient's act that would breach the APPs is taken to be Minikai's act and Minikai's breach.

Cross-border handling, New Zealand. New Zealand Customer Data is held in Australia. Because Minikai holds it on the Customer's behalf under section 11 and never uses it for its own purposes, that holding is not a disclosure and IPP 12 is not engaged by it; the Customer remains responsible for the information. IPP 12 and HIPC Rule 12 apply to any onward disclosure by Minikai to a person outside New Zealand who does not hold it on the Customer's behalf, and Minikai makes such a disclosure only where that person is bound by contractual terms providing comparable safeguards.

Breaches. The 24-hour commitment in section 7 is sized so the Customer can meet its own duties: in Australia, notification to the Office of the Australian Information Commissioner and affected individuals as soon as practicable where an eligible data breach is likely to result in serious harm, with the assessment completed within 30 days where that is not yet clear (Part IIIC); in New Zealand, notification to the Office of the Privacy Commissioner as soon as practicable under section 114, and to affected individuals under section 115 unless an exception in section 116 applies.

Governing law. This DPA is governed by the law stated in the Agreement and is subject to the Agreement's dispute resolution provisions.

Annex 1: Details of processing

FieldDetail
CustomerAs recorded in the Order Form
MinikaiMinikai Pty Ltd (ABN 32 674 548 577), Australia
Subject matter and durationProvision of the Minikai platform under the Agreement, for the Term plus the return or deletion period.
Nature and purposeHosting, handling, and AI-assisted support of care and support records for the Permitted Purpose. Includes Minikai personnel accessing the Customer's source systems on its instructions to build, configure and maintain the integration, and accessing the platform for support, quality assurance and monitoring; and transfer to another provider where the Customer directs it for continuity of care.
Kinds of informationAbout people who draw on care and support: identifiers and contact details; care, support and funding details; and health and care records (special category data under the UK GDPR; Sensitive Information under the Privacy Act 1988; health information under the HIPC). About people delivering their care: identifiers and contact details, and workforce records such as role, qualifications, training, rostering and time and billing, where the Customer's configured use includes them.
Categories of individualsPeople who draw on care and support, and the people delivering their care.
Data RegionAustralia, or the United Kingdom where the Order Form records it.

Annex 2: Technical and organisational measures

  • encryption of Customer Data at rest and in transit using current industry-standard algorithms and protocols;
  • role-based access control on least privilege, with multi-factor authentication for all staff accounts;
  • tenant isolation between customers;
  • private network endpoints for database and storage services;
  • audit logging of access and handling, with security monitoring and alerting;
  • minimisation of personal information in operational telemetry, and pseudonymisation where appropriate;
  • documented access request, onboarding and offboarding procedures, and staff confidentiality obligations and training; and
  • business continuity and disaster recovery arrangements.

Annex 3: Sub-processors

Listed, with the countries in which they operate, at trust.minikai.com/subprocessors.