OnboardMe

Terms & policies

  • Privacy Policy
  • Terms of Service
  • Data Processing Agreement
  • Electronic records & signature disclosure
  • Chrome extension privacy
  • Google user data

Trust & security

  • Information security & business continuity
  • Subprocessors
  • Data storage & backups
Contact usLog in

© 2026 OnboardMe Pty Ltd

Data Processing Agreement

Last updated August 2026 · POPIA (operator agreement)

Summary

This Data Processing Agreement ("DPA") is OnboardMe Pty Ltd's standard processor terms for this deployment of the Service (hosting: Rackzar in Cape Town). This DPA is intended to operate as an operator agreement under the Protection of Personal Information Act 4 of 2013 (POPIA) for processing carried out on this South African deployment of the Service.

It is incorporated into, and forms part of, the Terms of Service between the organisation that subscribes to or otherwise uses the Service (the "Customer") and OnboardMe Pty Ltd ("OnboardMe", "we", "us"). The Privacy Policy describes how the platform handles personal information; this DPA is the contractual allocation of roles and instructions for processing done on the Customer's behalf.

In practice, this DPA applies as follows:

  1. Automatic application. When a person accepts the Terms on behalf of the Customer, or the Customer uses the Service in a way that involves Client Data, this DPA applies. No extra click or signature is required for it to be binding, unless OnboardMe and the Customer execute a separate written DPA.
  2. Who it binds. It binds the Customer (the practice or firm) and OnboardMe. Individual staff users accept on behalf of the Customer if they have authority to do so (as already stated in the Terms). The Customer's end clients are not parties. A client who wants access, correction, or deletion of their information should contact the Customer; OnboardMe will assist the Customer as set out below.
  3. What it enables. It authorises OnboardMe to host, store, transmit, and otherwise process Customer Personal Data only as needed to operate the features the Customer uses (onboarding, forms, engagements, documents, messaging, identity / AML verification where enabled, and optional integrations the Customer connects). It does not add product features, and it does not transfer professional or regulatory responsibility for the Customer's clients to OnboardMe.
  4. Signed copies. If the Customer's procurement or privacy policy requires a countersigned DPA, email [email protected] with the subject "DPA countersignature". A separately executed DPA prevails over this page to the extent of conflict.
  5. Regional deployments. If the Customer uses more than one OnboardMe regional product (for example Australia and the United Kingdom), each deployment has its own hosting location, subprocessor list, and DPA page. Read the DPA on the deployment the Customer actually uses.
  6. Not legal advice. This DPA is a contract. It is not legal, tax, or compliance advice to the Customer. The Customer must assess whether the Service and these terms meet its own professional and regulatory obligations.

Contents

  1. Summary
  2. Parties
  3. Definitions
  4. Roles
  5. What this DPA covers
  6. Instructions
  7. Customer obligations
  8. OnboardMe obligations
  9. Subprocessors and integrations
  10. International transfers
  11. Assistance with individual rights
  12. Personal data breaches
  13. Return and deletion
  14. Information and audits
  15. Liability and precedence
  16. Term, variation, and contact
  17. Annex 1 — Details of processing
  18. Annex 2 — Material subprocessors
  19. Annex 3 — Technical and organisational measures

Parties

Processor / service provider: OnboardMe Pty Ltd (ACN 680 379 640), trading as OnboardMe, an Australian company.

Customer: the organisation that has an OnboardMe account or subscription, or that otherwise uses the Service under the Terms, and on whose behalf Client Data is processed.

Definitions

  • Customer Account Data means information OnboardMe handles as an independent organisation about the Customer itself — for example practice user accounts, subscription and invoice records for fees payable to OnboardMe, security logs of staff logins, and product analytics about use of the Service. That processing is described in the Privacy Policy and is outside this DPA.
  • Customer Personal Data (also "Client Data" in the Terms) means personal information / personal data relating to the Customer's clients and other individuals that is submitted to, generated in, or processed through the Service on the Customer's behalf. Annex 1 lists typical categories.
  • Service means the OnboardMe platform for this deployment, including related APIs and the OnboardMe Assist Chrome extension where the Customer's users install it.
  • Subprocessor means a third party engaged by OnboardMe to process Customer Personal Data in providing the Service (Annex 2). It does not mean a system the Customer chooses to connect (for example Xero or FYI).
  • Terms defined in the Terms of Service or Privacy Policy have the same meaning unless this DPA says otherwise.

Roles

The Customer is the responsible party for Customer Personal Data. The Customer determines why and how that information is processed in the Service, including which clients to onboard and how verification or screening results are used.

OnboardMe is the operator of Customer Personal Data. OnboardMe processes that information with the knowledge and authorisation of the Customer, only to provide the Service, and not for OnboardMe’s own unrelated purposes.

In the language of POPIA (operator agreement), the Customer is the responsible party and OnboardMe is the operator for Customer Personal Data. The Customer remains responsible for compliance with POPIA conditions for lawful processing in respect of its clients, including information quality and openness where those duties sit with the responsible party.

What this DPA covers (and what it does not)

Covered: all processing of Customer Personal Data by OnboardMe and its subprocessors to provide the Service, including the activities in Annex 1.

Not covered: Customer Account Data (OnboardMe as controller / APP entity for its own business); the Customer's own files and systems outside OnboardMe; processing by third parties the Customer instructs us to send data to (optional integrations); and professional advice, AML decisions, or regulatory filings, which remain the Customer's. OnboardMe is a software tool only, as stated in the Terms.

Instructions

The Customer instructs OnboardMe to process Customer Personal Data:

  • to provide and secure the Service as configured by the Customer;
  • in accordance with this DPA, the Terms, and the Privacy Policy; and
  • as the Customer directs through ordinary use of the Service (for example creating a client, enabling identity verification, sending an engagement, connecting an integration, or deleting a record).

OnboardMe will not process Customer Personal Data except on these documented instructions unless required by applicable law. If we are required by law to process other than as instructed, we will inform the Customer unless the law prohibits that notice. If we reasonably believe an instruction infringes applicable data-protection law, we will inform the Customer and may pause that instruction until it is clarified or withdrawn.

Written instructions outside the product must be sent to [email protected] by an authorised administrator and must be capable of being performed in the Service. OnboardMe is not obliged to build custom processing that the Service does not support.

Customer obligations

The Customer must:

  • have a lawful basis (and any required notices or consents) to submit Customer Personal Data, including identity documents and Tax number where collected;
  • not instruct OnboardMe to process children's data (the Service is not directed at children);
  • use access controls, including MFA where offered, and keep staff credentials confidential;
  • configure optional integrations and identity / AML features only where the Customer accepts the additional sharing described in the Privacy Policy and Annex 1;
  • remain responsible for how ComplyCube or other verification results are used in the Customer's compliance decisions;
  • handle requests from its own clients about Customer Personal Data, and contact OnboardMe only where platform assistance is needed; and
  • notify OnboardMe promptly if it believes Customer Personal Data has been processed in error or without authorisation in the Customer's tenant.

OnboardMe obligations (Operator duties under POPIA)

OnboardMe will:

  • Process Customer Personal Data only with the Customer’s knowledge and authorisation, and only for the purposes of providing the Service.
  • Treat Customer Personal Data as confidential and not disclose it except as required to provide the Service, as permitted by this DPA, or as required by law.
  • Apply security safeguards appropriate to the nature of the information, as described in Annex 3.
  • Notify the Customer where there are reasonable grounds to believe that Customer Personal Data has been accessed or acquired by an unauthorised person.
  • Ensure that any further operator we engage (a subprocessor) is subject to equivalent security and confidentiality obligations.
  • At the end of the relationship, return or destroy Customer Personal Data as set out in this DPA, except where law requires retention.

Identity verification may involve special personal information (including biometric information). The Customer is responsible for having a POPIA justification for that processing. OnboardMe processes it only to provide the enabled feature, including via ComplyCube.

Subprocessors and optional integrations

The Customer authorises OnboardMe to engage the material subprocessors in Annex 2 (and the Privacy Policy) to process Customer Personal Data for the stated purposes. OnboardMe will impose confidentiality and data-protection obligations on those subprocessors that are no less protective in substance than this DPA, having regard to the service they provide.

OnboardMe may update the list from time to time. Material additions will be communicated in line with the Customer's agreement with us (for example in-product notice or email to organisation administrators). The Customer may object on reasonable data-protection grounds within 14 days of notice. If we cannot reasonably accommodate the objection, the Customer may stop using the affected feature or terminate the affected subscription in accordance with the Terms.

Practice-management, accounting, document, or email systems the Customer connects (for example Xero, FYI, GreatSoft, KloudConnect, or Google Workspace) are engaged at the Customer's direction. They are not OnboardMe subprocessors. Data shared with them is an instruction from the Customer; those providers' terms apply as between the Customer and that provider.

International transfers

Primary infrastructure and stored customer data for this deployment are located in South Africa (Rackzar, Cape Town). When your organisation enables identity verification or AML screening features, relevant personal information (such as identity documents, live facial or biometric capture used for verification, and screening data) is shared with ComplyCube, a United Kingdom-based identity and AML verification provider, and is processed and stored in the United Kingdom. Payment processing is handled by Paystack. Transactional email and SMS (Resend, Mailgun, TallBob), product analytics (PostHog EU Cloud), and error monitoring (Sentry in the EU) necessarily involve processing outside the primary hosting region. Optional integrations you connect may involve further disclosure at your or your organisation’s direction. Those transfers are made only as needed to perform the Services, with appropriate safeguards and in line with POPIA section 72 where it applies.

Where a transfer of Customer Personal Data outside South Africa is required to provide the Service (including to ComplyCube in the United Kingdom), OnboardMe will do so only as needed to perform this DPA and the Service, with appropriate safeguards and in line with POPIA section 72 where it applies.

Assistance with individual rights

If an individual asks OnboardMe to access, correct, delete, or otherwise exercise rights in Customer Personal Data, OnboardMe will (where we can identify the Customer) direct the individual to the Customer and/or notify the Customer, unless we are legally required to handle the request ourselves.

If the Customer cannot fulfil a request using the Service (for example deletion of an entity, download of documents, or correction of a client record), the Customer may email [email protected] with the subject "Privacy request — processor assistance". OnboardMe will provide reasonable assistance, taking into account the nature of processing and the information available to us. We may need the Customer to verify the request and specify the tenant and records involved.

Personal data breaches

OnboardMe will notify the Customer without undue delay after becoming aware of a security compromise affecting Customer Personal Data, with enough information reasonably available to us for the Customer to assess its own POPIA notification duties to the Information Regulator and to data subjects.

Notification will describe, as then known: the nature of the breach, the categories and approximate number of individuals and records concerned, likely consequences, and measures taken or proposed. OnboardMe will reasonably cooperate with the Customer's investigation and with any required regulator or individual notification that the Customer must make. Public security reporting channels are described in the Security Policy.

Return and deletion

During the subscription, the Customer may export or delete Customer Personal Data using the Service (for example deleting a client entity or downloading documents). That is the primary way the Customer exercises deletion and portability in the product.

When the Customer's subscription or authorised use ends, OnboardMe will, within 90 days, delete Customer Personal Data from production systems, or return it in a reasonable commonly used form if the Customer requests export in writing within 30 days after termination. Copies in encrypted backups will drop out on the backup cycle and will not be restored into production except as needed for disaster recovery. OnboardMe may retain Customer Personal Data where required or authorised by law (including tax and accounting records of the Customer relationship, which are Customer Account Data), or in a form that no longer identifies individuals.

Information, DPIAs, and audits

OnboardMe will make available information reasonably necessary to demonstrate compliance with this DPA, including this page, the Privacy Policy, and the Security Policy. Taking into account the nature of processing, we will provide reasonable assistance with the Customer's data-protection impact assessments or equivalent risk assessments, and with any prior consultation with a regulator, to the extent the assessment concerns the Service.

If that information is not sufficient, the Customer may request an audit, no more than once per 12 months unless a confirmed personal data breach or a regulator requires otherwise. Audits must be reasonable in scope, on notice of at least 30 days, during business hours, and must not compromise other customers' security or confidentiality. OnboardMe may satisfy an audit by providing third-party certifications, questionnaire responses, or a call with security personnel. The Customer bears its own costs; OnboardMe may charge reasonable costs for on-site or unusually burdensome audits.

Liability and precedence

This DPA is an addendum to the Terms. Liability arising from processing under this DPA is subject to the limitations and exclusions in the Terms, except where applicable law prohibits that limitation. Each party remains liable for its own obligations as responsible party or operator under mandatory data-protection law.

Order of precedence for Customer Personal Data: (1) a separately executed DPA between the parties; (2) this DPA; (3) the Privacy Policy insofar as it describes processing; (4) the Terms. Commercial terms (fees, service availability, IP, governing law of the contract) remain as in the Terms unless a signed DPA expressly changes them.

Term, variation, and contact

This DPA starts when the Customer first uses the Service under the Terms after the Effective Date (or when a prior version applied, from that earlier date) and continues until OnboardMe has deleted or returned Customer Personal Data as required above. Confidentiality, deletion, audit (for the retention period), and liability clauses survive accordingly.

OnboardMe may update this DPA as described for the Terms (including notice of material changes). Continued use after the effective date of an update constitutes acceptance, except that a separately executed DPA changes only if the parties agree in writing.

This DPA is governed by the same law and courts as the Terms, without limiting mandatory data-protection law of this deployment. Questions: [email protected] (privacy) or [email protected] (security).

Annex 1 — Details of processing

A. Subject matter and nature

Hosting and operation of the OnboardMe cloud platform so the Customer can run client onboarding, engagement letters, forms and e-sign, document collection, identity verification and AML screening (where enabled), messaging, billing-related client workflows, and optional connections to the Customer's own practice systems. Processing includes collection, recording, organisation, storage, retrieval, consultation, use, disclosure by transmission, restriction, and erasure, as performed by the features the Customer uses.

B. Duration

For the term of the Customer's subscription (or other authorised use of the Service), plus the post-termination deletion / return period in this DPA, and any longer period required by law or encrypted backups that are deleted on the backup cycle.

C. Purpose

Solely to provide, maintain, secure, support, and improve the Service for the Customer, to communicate about the Service as the Customer directs (for example sending an engagement to a client), and to comply with law. OnboardMe does not sell Customer Personal Data and does not use it for OnboardMe's own marketing to the Customer's clients.

D. Categories of data subjects

  • The Customer's clients and prospective clients (individuals, and individuals associated with client organisations — for example directors, trustees, and contacts).
  • Recipients of onboarding, forms, engagements, ethical letters, identity verification, and similar workflows (including people who access a client portal or magic-link).
  • Other individuals whose information the Customer (or a client acting in the Customer's workflow) enters into the Service — for example referees, signatories, or related-party contacts.
  • Individuals named in documents the Customer uploads or generates (engagement PDFs, identity documents, supporting files).

Practice staff who hold OnboardMe user accounts are primarily described as Customer Account Data (outside this DPA). Staff names and contact details that appear inside Client Data (for example as the assigned adviser on an engagement) are processed as Customer Personal Data to the extent they form part of that Client Data.

E. Types of Customer Personal Data

Depending on the features the Customer uses, this may include:

  • Identity and contact: name, email, phone, job title, date of birth, address, employer or entity identifiers.
  • Tax and government identifiers: Tax and revenue identifiers, and similar identifiers the Customer collects.
  • Financial: bank account and payment details entered for the Customer's clients (as distinct from the Customer's own subscription billing to OnboardMe).
  • Service content: information entered into forms, proposals, engagements, ethical letters, custom fields, notes, and related workflows; electronic signatures and signing metadata.
  • Documents: uploaded files, generated PDFs, identity document images, and similar records stored in object storage.
  • Identity verification and AML: identity documents, live facial images or biometric capture used for matching, verification session identifiers, and AML / PEP / sanctions screening inputs and results — where the Customer enables those features.
  • Technical data created by use of the Service: IP address, device or session metadata, authentication events, and audit logs relating to Client Data access.

F. Processing activities in the product

ActivityTypical processingTypical recipients
Client / entity records and onboardingStore, display, update, and delete client information the Customer or the client submitsHosting (Rackzar in Cape Town); optional practice integrations the Customer connects
Forms, engagements, ethical letters, e-signCreate, send, collect responses, generate PDFs, record signaturesHosting; email and SMS providers when the Customer sends a workflow
Document collectionUpload, store, download (including short-lived signed URLs), optional push to the Customer's DMSHosting object storage; KloudConnect or similar only if the Customer connects it
Identity verification and AML screeningShare identity and screening inputs; receive outcomes and artefactsComplyCube (United Kingdom), when the Customer enables the feature
Transactional email and SMSDeliver invitations, reminders, and service messages the Customer triggersResend, Mailgun, TallBob
Client payment details (where used)Collect or display payment information for the Customer's billing of its clientsPinch, Apxium, Stripe, or Paystack as configured for this deployment and the Customer
Optional practice-system syncCreate, update, or retrieve clients, contacts, jobs, or documents in the connected systemThe provider the Customer connects (for example Xero, FYI, GreatSoft, Google Workspace) — at the Customer's direction
Chrome extension (OnboardMe Assist)Read bank / identity fields already in OnboardMe to fill empty fields in Xero Practice Manager, using session credentials in the browserProcessed in the authorised user's browser and via the Service APIs; not a separate hosting location
Security, support, and reliabilityLogs, backups, error diagnostics, and aggregated product analyticsHosting and monitoring for this deployment (Rackzar in Cape Town); PostHog; Sentry; UptimeRobot

OnboardMe does not itself make solely automated decisions with legal or similarly significant effects about the Customer's clients. ComplyCube may return automated verification or screening results; the Customer remains responsible for how those results are used.

Annex 2 — Material subprocessors

The Customer gives general written authorisation to the subprocessors listed below for this deployment. Optional integrations the Customer connects are not OnboardMe subprocessors and are not listed here. Where a name is linked, it opens that provider's privacy or security information.

SubprocessorPurposeLocation
RackzarCloud hosting, backups, and related infrastructureSouth Africa (Cape Town)
ComplyCubeIdentity verification and AML / PEP / sanctions screening (where enabled)United Kingdom
PaystackPayment processingAs operated by Paystack for South Africa payments
ResendTransactional and service email deliveryUnited States (and other locations as operated by Resend)
MailgunTransactional and service email deliveryUnited States and other locations as operated by Mailgun
TallBobSMS messagingAustralia (as operated by TallBob)
UptimeRobotExternal uptime and availability monitoringAs operated by UptimeRobot
PostHogProduct analytics and diagnosticsEuropean Economic Area (PostHog EU Cloud)
SentryApplication error monitoring and diagnosticsEuropean Union (error ingestion in Germany)

This list is the same material-subprocessor list published in the Privacy Policy for this deployment. If the two pages ever differ, the Privacy Policy list as updated on that page is the operative list, and this Annex will be treated as updated accordingly.

Annex 3 — Technical and organisational measures

OnboardMe implements the following measures, which may be updated as technology and threats change provided the overall level of security is not materially reduced. Backups, recovery, and controls are described in Information security & business continuity. Vulnerability reporting is on that same page.

  • Hosting and location: production Customer Personal Data for this deployment is stored in the Rackzar in Cape Town, with encrypted backups in South Africa (Cape Town).
  • Encryption: Stored customer data is encrypted at rest. Data in transit is protected using TLS 1.2+. Further controls are described in our Information security & business continuity policy.
  • Access control: role-based access within the Customer's tenant; authentication including multi-factor authentication where enabled by the Customer; OnboardMe staff access limited to personnel who need it for support, security, or operations, on a least-privilege basis.
  • Isolation: Customer data is logically separated by practice / tenant identifiers in the application data model.
  • Monitoring and logging: authentication events, operational logs, and security alerting (including to [email protected]), with error monitoring configured to limit identifiable data to what is needed for diagnosis.
  • Personnel: confidentiality obligations for staff and contractors who may access Customer Personal Data; access reviewed when roles change.
  • Subprocessors: due diligence and contractual confidentiality / security obligations appropriate to the service they provide.
  • Vulnerability and incident management: vulnerability handling, an incident response process, and breach assessment aligned with Compliance with South African law.
  • Backups and restoration: encrypted backups and procedures to restore availability of the Service after an incident, within commercially reasonable timeframes.

No electronic system is perfectly secure. These measures are appropriate to the nature of the Service as a professional-services onboarding platform handling tax identifiers, identity documents, and similar information, taking into account the state of the art, implementation costs, and the risks for individuals.