Data Processing Addendum (DPA)
Last updated: April 29, 2026
This Data Processing Addendum (“DPA”) is incorporated into and forms part of the Underlying Agreement governing Customer’s use of the Services. This DPA applies to PostGrid’s Processing of Customer Data on behalf of Customer in connection with the Services. In the event of any conflict between the Underlying Agreement and this DPA, this DPA will control solely with respect to the Processing of Customer Data.
Capitalized terms not defined herein have the meanings given in the Underlying Agreement.
1. Definitions
For purposes of this DPA:
Customer Data means any personal information included in the data that Customer submits to the Services or otherwise provides to PostGrid as part of receiving the Services.
Data Protection Laws means the Privacy Act 1988 (Cth) and the Australian Privacy Principles (“APPs”), including the Notifiable Data Breaches scheme, and any other applicable Australian privacy or data protection laws.
Personal Information has the meaning given in the Privacy Act 1988 (Cth), being information or an opinion about an identified individual or an individual who is reasonably identifiable.
Process or Processing means any operation performed on Customer Data, including collection, use, storage, transmission, disclosure, or destruction.
2. Roles and Scope
2.1 Roles.
Customer determines the purposes and means of Processing Customer Data. PostGrid Processes Customer Data solely to provide the Services and acts as a service provider to Customer.
2.2 Scope.
This DPA applies only to the Processing of Customer Data necessary for PostGrid to provide the Services and fulfill Customer’s documented instructions under the Underlying Agreement.
2.3 Customer Instructions.
PostGrid will process Customer Data only in accordance with:
- the Underlying Agreement and this DPA;
- Customer’s configuration and use of the Services; and
- additional written instructions provided by Customer and accepted by PostGrid.
PostGrid will notify Customer if PostGrid determines that an instruction violates applicable Data Protection Laws.
2.4 Sensitive Information.
Customer must not provide “Sensitive Information” (as defined under the Privacy Act), including health information, biometric information, or government identifiers, unless expressly agreed in writing.
3. Customer Responsibilities
Customer is responsible for:
- ensuring Customer Data is collected and disclosed in accordance with the APPs;
- providing required privacy notices;
- obtaining all necessary consents;
- ensuring Customer Data does not violate applicable law; and
- determining the lawfulness of its use of the Services.
Customer remains accountable under APP 6 and APP 8 for Personal Information it discloses to PostGrid.
4. PostGrid Obligations
4.1 Confidentiality.
PostGrid will ensure personnel authorized to Process Customer Data are subject to confidentiality obligations.
4.2 Security Safeguards (APP 11).
PostGrid will implement reasonable technical and organisational measures designed to protect Customer Data against misuse, interference, loss, unauthorised access, modification, or disclosure, taking into account the sensitivity of the information.
Such measures include:
- encryption of data in transit and at rest;
- role-based access controls and multi-factor authentication;
- monitoring and incident response procedures;
- network security controls;
- periodic vulnerability testing;
- vendor risk management processes.
PostGrid maintains SOC 2 Type II attestation and renews such attestation at least annually.
4.3 Use Limitation.
PostGrid will Process Customer Data only:
- to provide and support the Services;
- to maintain and improve the Services; and
- as otherwise permitted under the Underlying Agreement.
PostGrid will not sell, rent, or commercially exploit Customer Data.
5. Subprocessors
5.1 Authorisation.
Customer authorises PostGrid to engage affiliates and third-party subprocessors to support the Services.
5.2 Safeguards.
PostGrid will ensure subprocessors are bound by written obligations that are no less protective of Customer Data than those set out in this DPA.
5.3 Subprocessor Information.
PostGrid will provide a list of active subprocessors upon reasonable request, subject to confidentiality obligations.
Customer has no approval or objection rights with respect to subprocessors.
6. Cross-Boarder Transfers (APP 8)
Customer acknowledges and authorises that Customer Data may be Processed outside Australia, including in the United States or other jurisdictions where PostGrid or its subprocessors operate.
PostGrid will take reasonable steps to ensure that any overseas recipient of Customer Data:
- is subject to contractual obligations requiring protection of the information consistent with the APPs; or
- is located in a jurisdiction with substantially similar data protection laws; or
- otherwise provides safeguards appropriate under the Privacy Act.
Customer remains responsible for complying with its obligations under APP 8 when disclosing Personal Information to PostGrid.
7. Notifiable Data Breaches
7.1 Notification.
If PostGrid becomes aware of a confirmed data breach involving Customer Data that is reasonably likely to result in serious harm to affected individuals, PostGrid will notify Customer without undue delay and provide reasonably available information to assist Customer in complying with its obligations under the Notifiable Data Breaches scheme.
7.2 Cooperation.
PostGrid will take reasonable steps to mitigate the effects of the breach and prevent recurrence.
PostGrid is not required to provide detailed forensic reports except where reasonably necessary or legally required.
8. Assistance with Individual Rights
To the extent reasonably practicable and required under Data Protection Laws, PostGrid will assist Customer in responding to requests for access or correction under APP 12 and APP 13.
PostGrid may charge reasonable fees for excessive or unusual requests requiring significant manual effort.
9. Retention and Deletion
Upon termination of the Underlying Agreement or upon Customer’s written request, PostGrid will delete or return Customer Data within thirty (30) days, unless retention is required or permitted by law or necessary for legitimate business purposes.
Customer Data retained in backups will be deleted in accordance with PostGrid’s standard retention schedule.
This DPA does not restrict PostGrid’s use of Aggregated Anonymous Data.
10. Government and Legal Requests
If PostGrid receives a legally binding request for access to Customer Data, PostGrid will notify Customer unless prohibited by law.
11. Audit Rights
Upon reasonable written request and no more than once per year, Customer may request information reasonably necessary to demonstrate PostGrid’s compliance with this DPA.
In lieu of any audits, PostGrid may provide its SOC 2 Type II report or equivalent third-party attestation.
Any audit must: (i) be conducted during normal business hours; (ii) be subject to confidentiality obligations; and (iii) not unreasonably interfere with PostGrid’s operations.
12. Governing Law
This DPA is governed by the same governing law and jurisdiction provisions set out in the Underlying Agreement.
13. Changes to this DPA
PostGrid may update this DPA from time to time to reflect changes in applicable Data Protection Laws, regulatory guidance, or processing practices.
Updates will be posted on the Legal Page and will not materially reduce PostGrid’s data protection obligations during an active Subscription Term without reasonable notice.
Customer’s continued use of the Services constitutes acceptance of the updated DPA.
Appendix A – Processing Details
Subject Matter
Processing of Customer Data necessary to provide the Services under the Underlying Agreement.
Nature and Purpose of Processing
Hosting, transmitting, validating, formatting, printing, mailing, storing, and otherwise processing Customer Data as required to provide and support the Services and fulfill Customer’s documented instructions.
Categories of Data Subjects
- Customer’s employees
- Customer’s users
- Customer’s clients and end customers
- Individuals whose information Customer submits to the Services
Categories of Personal Information
May include, depending on Customer’s use of the Services:
- Names
- Mailing addresses
- Email addresses
- Contact details
- Account identifiers
- Device identifiers
- IP addresses
- Transactional mailing data
- Other Personal Information included in Customer Data
Sensitive Information
Sensitive Information (as defined under the Privacy Act 1988 (Cth)) is not permitted unless expressly agreed in writing.
Duration of Processing
For the duration of the Underlying Agreement and any applicable retention period required by law or PostGrid’s standard backup policies.
Cross-Border Processing
Customer Data may be processed in the United States or other jurisdictions where PostGrid or its authorised subprocessors operate.
Previous Agreements
Archived versions for transparency
These are prior versions of PostGrid’s agreements and policies that are no longer in effect.
Each document below includes the date range during which it governed use of the Services.
For the current versions, please refer to the active Legal Hub above.
Effective: September 1, 2023 – April 29, 2026
View Archived Version →

