Dingo Data Processing Terms

Version 1.0 · Effective 8 September 2026
 

Dingo Mining Pty Ltd ABN 76 154 370 706.

These Data Processing Terms are a standalone document. They apply wherever DINGO and a customer enter into an agreement that incorporates them, and the same version applies across every DINGO contract that references them. They do not depend on any particular DINGO agreement.

1. Application and definitions

 

1.1 These Data Processing Terms apply to the extent that a Dingo processes Personal Information on behalf of a Customer under an agreement between them that incorporates these Data Processing Terms (the “Principal Agreement”). Where they are incorporated, they form part of the Principal Agreement.

1.2 Where the EU GDPR or the UK GDPR applies to that processing, these Data Processing Terms are the written contract required by Article 28(3) of the EU GDPR and of the UK GDPR.

1.3 In these Data Processing Terms:

  • “Anonymised” means processed so that no individual is identified or reasonably identifiable by any person, taking account of all means reasonably likely to be used and of any other information available to the recipient. Pseudonymisation alone is not sufficient.
  • “Customer” means the entity that has entered into the Principal Agreement with Dingo.
  • “Customer Data” means Personal Information that a Dingo processes on behalf of the Customer under the Principal Agreement, including Personal Information entered into DINGO software by or on behalf of the Customer.
  • “Dingo” means Dingo Mining Pty Ltd ABN 76 154 370 706. These Data Processing Terms apply to Dingo that is a party to the Principal Agreement.
  • “EU GDPR” means Regulation (EU) 2016/679. “UK GDPR” means the EU GDPR as incorporated into the law of the United Kingdom, together with the Data Protection Act 2018 (UK).
  • “Personal Information” means information or an opinion about an identified individual, or an individual who is reasonably identifiable, and includes “personal data”, “personal information” and any equivalent term under any applicable Privacy Law.
  • “Privacy Law” means each law relating to privacy, data protection or the handling of Personal Information that applies to a party in connection with the Principal Agreement, including the Privacy Act 1988 (Cth) and the Australian Privacy Principles, the EU GDPR, the UK GDPR, and any other applicable data protection law of a jurisdiction in which the Customer or Dingo operates.
  • “Privacy Policy” means the DINGO privacy policy published at dingo.com/privacy-policy.
  • “Term” means the term of the Principal Agreement, together with the period permitted by section 13.

2. Roles

 

2.1 In respect of Customer Data, the Customer is the controller and Dingo is the processor.

2.2 Dingo is an independent controller in respect of Personal Information it handles for its own account administration, billing and customer relationship management, for product security and abuse prevention, and in relation to data that has been Anonymised.

2.3 Nothing in these Data Processing Terms or the Principal Agreement makes Dingo a joint controller with the Customer.

3. Details of the processing

 

3.1 Unless the Principal Agreement states otherwise, the details of the processing are as follows.

Element Detail
Subject matter The provision of the products and services described in the Principal Agreement.
Duration The Term.
Nature and purpose Hosting, storage, analysis and reporting of the data the Customer provides or generates through those products and services.
Types of Personal Information Those described in the Privacy Policy, and any further types the Customer chooses to include in Customer Data.
Categories of individuals The Customer’s personnel, contractors and nominated users.

3.2 The Customer is responsible for determining what Personal Information is included in Customer Data and for ensuring that it has been collected lawfully. The Customer warrants that it has established a lawful basis, and given all notices and obtained all consents, required under applicable Privacy Law for Dingo to handle Customer Data for the purposes of the Principal Agreement, including disclosure to overseas recipients as described in the Privacy Policy.

3.3 The Customer must not include in Customer Data any Personal Information beyond what is reasonably necessary for the products and services, and must not include any sensitive information, special category data, health information, biometric information or information relating to criminal convictions or offences without the prior written agreement of Dingo.

4. Instructions

 

4.1 Dingo will process Customer Data only on the documented instructions of the Customer, being the instructions set out in the Principal Agreement and any further written instructions agreed by the parties, and as otherwise required by applicable law.

4.2 If Dingo is required by law to process Customer Data otherwise than on those instructions, it will inform the Customer before processing unless prohibited from doing so by law.

4.3 If Dingo considers that an instruction infringes applicable Privacy Law, it will inform the Customer without undue delay.

5. Our obligations

 

Dingo will:

  • comply with applicable Privacy Law in handling Customer Data;
  • use and disclose Customer Data only for the purposes of performing the Principal Agreement, the purposes set out in the Privacy Policy and the purposes permitted by these Data Processing Terms; and
  • take reasonable steps, appropriate to the risk, to protect Customer Data from misuse, interference and loss, and from unauthorised access, modification or disclosure.

6. Personnel

 

Dingo will ensure that the persons it authorises to process Customer Data are subject to a duty of confidentiality, are trained in their privacy obligations, and process Customer Data only as necessary for the purposes of the Principal Agreement.

7. Security

 

Dingo will implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, having regard to Article 32 of the EU GDPR and of the UK GDPR where applicable, including the measures described in the Privacy Policy.

8. Sub-processors

 

8.1 The Customer authorises Dingo to engage sub-processors, its affiliates and the categories of service provider described in the Privacy Policy.

8.2 On the Customer’s written request, Dingo will provide a current list of the sub-processors that process Customer Data.

8.3 Dingo will give the Customer at least 30 days’ written notice before adding or replacing a sub-processor, and the Customer may object on reasonable data protection grounds within that period. If the parties cannot resolve the objection, then despite any provision of the Principal Agreement restricting the Customer’s right to terminate, the Customer may terminate the affected part of the Principal Agreement by written notice, without liability other than payment of amounts owing for the period before termination.

8.4 Dingo will impose on each of its sub-processors data protection obligations no less protective than those in these Data Processing Terms.

9. Data breach notification

 

9.1 If Dingo becomes aware of any accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or unauthorised access to, Customer Data (a “Data Breach”), Dingo will notify the Customer without undue delay, and in any event within 48 hours of becoming aware of it where the Customer is subject to the EU GDPR or the UK GDPR, and otherwise within 5 business days.

9.2 The notification will include the information reasonably available to Dingo about the nature and extent of the Data Breach, the categories and approximate number of individuals and records affected, the likely consequences, and the measures taken or proposed to address it.

9.3 Dingo will take reasonable steps to contain and remediate the Data Breach, and will co-operate in good faith with the Customer in relation to any assessment, notification or communication required under Part IIIC of the Privacy Act 1988 (Cth), Articles 33 and 34 of the EU GDPR or of the UK GDPR, or any equivalent obligation under applicable Privacy Law.

10. Individual rights requests

 

10.1 If the Customer receives a request from an individual to exercise a right under applicable Privacy Law in relation to Customer Data — including a right of access, correction or rectification, restriction, objection, portability or erasure — Dingo will provide reasonable assistance, at no additional charge, to enable the Customer to respond within the time required by that Privacy Law.

10.2 If Dingo receives such a request directly, it will promptly refer the individual to the Customer and notify the Customer, except where Dingo is required or permitted by law to respond itself.

10.3 Requests may also be made to the DINGO Privacy Officer using the contact details set out in the Privacy Policy.

11. Audit and information

 

11.1 Dingo will make available to the Customer the information reasonably necessary to demonstrate compliance with these Data Processing Terms, and will allow for and contribute to audits, including inspections, by the Customer or an auditor appointed by the Customer.

11.2 Audits will be conducted no more than once in any 12-month period, unless required by a supervisory authority or following a Data Breach, on at least 30 days’ written notice, during business hours, subject to reasonable confidentiality and site security requirements, and at the Customer’s cost.

11.3 Dingo may satisfy this section by providing a current third-party audit report or certification covering the relevant controls.

12. Impact assessments and consultation

 

Dingo will provide reasonable assistance to the Customer with any data protection impact assessment and any prior consultation with a supervisory authority, in each case to the extent it relates to processing by Dingo and the Customer does not otherwise have the information it needs.

13. Export and deletion

 

13.1 Within 30 days after expiry or termination of the Principal Agreement, the Customer may request an export of the Customer Data then held by Dingo in a structured, commonly used, machine-readable format, and Dingo will provide the export at the Customer’s cost.

13.2 After that period, Dingo will destroy or return the Customer Data and destroy existing copies, except to the extent that retention is required by law or the data has been Anonymised.

13.3 On the Customer’s written request, Dingo will certify that it has done so.

14. International transfers

 

14.1 The Customer acknowledges that Dingo and its service providers operate in the countries identified in the Privacy Policy, and that Customer Data may be stored in, and accessed from, those countries.

14.2 Dingo will ensure that each transfer of Customer Data to a country outside the jurisdiction in which it was collected is made under a transfer mechanism valid under applicable Privacy Law.

14.3 Where Customer Data is transferred from the European Economic Area, the United Kingdom or Switzerland to a country that is not the subject of an adequacy decision, that transfer is made under the standard contractual clauses approved by the European Commission in Implementing Decision (EU) 2021/914 (Module Two, controller to processor, and Module Three, processor to processor, as applicable) and, for transfers from the United Kingdom, under the International Data Transfer Addendum issued by the Information Commissioner under section 119A of the Data Protection Act 2018 (UK). For transfers from Switzerland, those standard contractual clauses apply as recognised by the Swiss Federal Data Protection and Information Commissioner.

14.4 Those clauses and that Addendum are incorporated into the Principal Agreement by reference and are completed as follows: the Customer is the data exporter and Dingo is the data importer; the details in section 3 populate Annex I to those clauses; the measures described in the Privacy Policy populate Annex II; the sub-processor list provided under section 8.2 populates Annex III; the optional docking clause applies; and the governing law and forum for the purposes of Clauses 17 and 18 of those clauses are those of Ireland.

14.5 To the extent of any inconsistency between those standard contractual clauses or that Addendum and any other provision of the Principal Agreement or these Data Processing Terms, the standard contractual clauses or the Addendum prevail.

14.6 On the Customer’s reasonable request, the parties will execute standalone standard contractual clauses on the same terms.

14.7 Where a transfer is made from another jurisdiction whose Privacy Law requires a specific transfer mechanism, the parties will put that mechanism in place.

15. Other jurisdictions

 

Where the Customer is subject to a Privacy Law of another jurisdiction that requires additional or different terms in a contract of this kind, the parties will negotiate in good faith and enter into an addendum giving effect to those requirements. Until that addendum is entered into, Dingo will comply with the requirements of that Privacy Law that apply to it directly.

16. Liability

 

16.1 Nothing in the Principal Agreement or these Data Processing Terms limits or excludes any liability of a party that cannot be limited or excluded under applicable Privacy Law, including liability to an individual under Article 82 of the EU GDPR or of the UK GDPR, or under the Privacy Act 1988 (Cth).

16.2 Subject to section 16.1, any limitation or exclusion of liability in the Principal Agreement, and any provision of the Principal Agreement, applies to liability arising under these Data Processing Terms.

16.3 Dingo remains responsible to the Customer for the acts and omissions of its own sub-processors. Dingo is not responsible for the acts or omissions of sub-processors.

17. Precedence, versions and changes

 

17.1 The version of these Data Processing Terms that applies is the version current at the date the Principal Agreement is entered into. A copy of that version will be provided to the Customer on request.

17.2 A later version applies only if the Customer agrees to it in writing, except that Dingo may update these Data Processing Terms without the Customer’s agreement to the extent necessary to comply with applicable Privacy Law.

17.3 To the extent of any inconsistency in relation to the processing of Personal Information, these Data Processing Terms prevail over the Principal Agreement and over the Privacy Policy, unless the Principal Agreement expressly states that a specified provision of it prevails over these Data Processing Terms.

DINGO Privacy Officer: help@dingo.com