Legal

Data Processing Agreement

How we process personal information on your behalf. We are happy to sign a countersigned DPA on request — contact [[FILL: privacy@antio.io]].

Last updated 26 July 2026· Draft — under review by counsel before relied upon

Roles

For personal information contained in the content you upload, you determine the purposes for which it is handled, and Antio handles it on your behalf and on your documented instructions to provide the service.

Scope & purpose

We process the categories of information and individuals contained in your tender or business content and account, for the purpose of providing tender analysis and the platform features you use, for the duration of your use of Antio.

Our commitments

  • Handle personal information only on your instructions and for the stated purposes.
  • Keep it confidential and ensure personnel are bound by confidentiality.
  • Apply appropriate technical and organisational measures (see our security overview): encryption in transit and at rest, access controls, tenant isolation, and audit logging.
  • Assist you with requests from individuals and with your own compliance obligations.
  • Notify you without undue delay on becoming aware of a breach involving personal information, and support statutory breach notifications under the Notifiable Data Breaches (NDB) scheme in the Privacy Act 1988 (Cth).
  • Delete or return personal information at the end of the service, per your instruction.

Sub-processors

We use the service providers necessary to run the service (hosting, email, AI), each under contract and with equivalent data-protection obligations. We maintain a list of these providers, available on request, and we will tell you about material changes so you may object. AI providers process content under terms that exclude training on it.

Data location & transfers

Personal information is hosted in Australia. Where a third-party provider we engage to operate the service processes data outside Australia, we limit it to what the task requires and require contractual data-protection terms.

Audits

On reasonable prior notice, no more than once per year, and without access to other customers’ data, we will provide the information reasonably needed to demonstrate compliance, including available security documentation and, where available and under NDA, the results of independent security testing.

Executing a DPA

This page is a summary only; a signed DPA governs and creates the binding obligations. To put a signed DPA in place (including any additional data-protection terms you reasonably require), contact [[FILL: privacy@antio.io]].