Skip to main content
Bounty | Version 1.0 | 15 July 2026 This Data Processing Addendum (“DPA”) forms part of the agreement between Bounty and the customer identified in that agreement (“Customer”) governing Customer’s use of the Service (the “Agreement”). It applies when Bounty handles Customer Personal Data on Customer’s behalf.

Key details

1. Definitions

1.1 Applicable Privacy Law. means the Privacy Act 1988 (Cth), the Australian Privacy Principles and any other Australian privacy or data protection law that applies to the handling of Customer Personal Data under the Agreement. 1.2 Customer Personal Data. means personal information that Customer or its authorised users submit to, make available to, or generate through the Service and that Bounty handles on Customer’s behalf. 1.3 Security Incident. means a confirmed breach of security that results in accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Customer Personal Data. It excludes unsuccessful attempts and events that do not compromise Customer Personal Data. 1.4 Subprocessor. means a third party Bounty engages to handle Customer Personal Data on Customer’s behalf.

2. Scope and processing

2.1 Roles. Customer determines why and how Customer Personal Data is handled. Bounty handles it on Customer’s behalf to provide the Service. Each party will comply with Applicable Privacy Law as it applies to that party. 2.2 Customer responsibilities. Customer is responsible for Customer Personal Data and its instructions, including providing required notices, obtaining required consents or other authority, and ensuring that its collection and use of Customer Personal Data through the Service is lawful. 2.3 Purpose and duration. Bounty may collect, access, store, organise, query, analyse, transform, display, transmit and otherwise handle Customer Personal Data as necessary to provide, secure, support, maintain and improve the Service; carry out Customer’s use, configuration and written instructions; and comply with law. Handling continues for the term of the Agreement and any further period allowed by the Agreement or law. 2.4 People and information covered. Customer Personal Data may relate to Customer’s authorised users, personnel, business contacts, prospects, leads, customers, end users and other individuals represented in Customer-authorised data sources. It may include identifiers and business contact details; account, organisation and subscription information; marketing, advertising, campaign, CRM, analytics, product-usage and event data; queries, prompts, outputs, support communications and files; and credentials or tokens for Customer-authorised integrations. 2.5 Sensitive information. The Service is not intended for sensitive information, health information, payment-card data, government identifiers, children’s data or other highly regulated information unless Bounty has authorised it in writing. Customer must not submit that information without such authorisation.

3. Instructions and confidentiality

3.1 Instructions. The Agreement, this DPA, Customer’s configuration and use of the Service, and written support requests are Customer’s instructions. Bounty may decline or suspend an instruction that it reasonably believes is unlawful, unsafe, outside the Service or inconsistent with the Agreement. 3.2 Required handling. Bounty may handle Customer Personal Data where required by law. Unless prohibited, Bounty will notify Customer of the requirement before doing so. 3.3 Confidentiality. Bounty will limit access to authorised personnel who need it for their duties and who are subject to confidentiality obligations.

4. Security

4.1 Safeguards. Bounty will maintain technical and organisational measures appropriate to the nature of the Customer Personal Data and the reasonably foreseeable risks, designed to protect it from misuse, interference, loss and unauthorised access, modification or disclosure. 4.2 Current controls. Bounty’s current security-control summary is published at https://docs.bountygrowth.com/security-controls. Bounty may update its controls as the Service and technology develop, provided the overall level of protection is not materially reduced during the term of the Agreement. 4.3 Customer controls. Customer is responsible for its configuration of the Service, integrations, permissions, credentials, retention settings, exports, workflows and user access, and for systems and endpoints under its control.

5. Security incidents

5.1 Notification. Bounty will notify Customer without undue delay after becoming aware of a Security Incident and, where feasible, within 72 hours. Notice will be sent to Customer’s designated account or security contact. 5.2 Response. Bounty will take reasonable steps to contain, investigate, mitigate and remediate the Security Incident and will provide information reasonably available to Bounty that Customer needs to assess the incident and meet applicable notification obligations. 5.3 No admission. Notification or assistance concerning a Security Incident is not an admission of fault or liability.

6. Subprocessors

6.1 General authorisation. Customer generally authorises Bounty to engage, add, replace or remove Subprocessors as Bounty reasonably determines appropriate to operate and develop the Service. Bounty may do so without prior notice, consent or approval from Customer. 6.2 List. Bounty’s current Subprocessor list is published at https://docs.bountygrowth.com/subprocessors. Updating that page does not create a separate notice, consent, approval or objection right. 6.3 Protections. Bounty will impose written data-protection obligations appropriate to each Subprocessor’s services and remains responsible for its Subprocessors to the extent required by Applicable Privacy Law and the Agreement.

7. Overseas processing

7.1 Locations. Customer authorises Bounty and its Subprocessors to handle Customer Personal Data in Australia, the United States, and the other Subprocessor locations identified on Bounty’s current Subprocessor list. Bounty’s primary application and analytics data stores are hosted in AWS region us-east-2 (Ohio), United States. Customer-selected integrations may use the locations of those services. 7.2 Safeguards. Bounty will take reasonable steps required of it under Applicable Privacy Law in relation to overseas recipients. Customer remains responsible for determining whether its disclosure or use of Customer Personal Data through the Service satisfies Customer’s own overseas-disclosure obligations.

8. Assistance

8.1 Individual requests. Bounty will reasonably assist Customer with access or correction requests, privacy complaints and regulator enquiries concerning Customer Personal Data, taking into account the Service and information available to Bounty. Bounty may direct an individual who contacts it to Customer unless law requires otherwise. 8.2 Compliance support. Bounty will reasonably assist Customer with security-incident assessment and notifications, privacy impact assessments and other compliance enquiries concerning Bounty’s handling of Customer Personal Data. 8.3 Costs. Bounty may charge reasonable fees for unusually frequent, extensive or burdensome assistance unless Applicable Privacy Law requires it without charge. Bounty will advise Customer before incurring material fees.

9. Information and review

9.1 Compliance information. On reasonable request, Bounty will provide information reasonably necessary to demonstrate compliance with this DPA, including available security documentation, independent reports or certifications, or a reasonable written questionnaire. 9.2 Review process. Further review is available only where required by Applicable Privacy Law, a regulator or a material Security Incident and must begin remotely using available documents. An on-site inspection is permitted only if remote material is insufficient to meet a legal requirement. Reviews must be coordinated in advance, avoid unreasonable disruption, and protect Bounty’s and other customers’ confidential information. 9.3 Reviewer and costs. A reviewer must be independent, suitably qualified, not a competitor of Bounty and bound by confidentiality. Customer bears its review costs and Bounty’s reasonable costs for an on-site or unusually burdensome review, unless it identifies Bounty’s material breach of this DPA.

10. Term and general terms

10.1 Post-termination handling. Handling of Customer Personal Data after expiration or termination of the Agreement is governed by the Agreement and Applicable Privacy Law. 10.2 Liability. To the maximum extent permitted by law, each party’s liability arising from this DPA is subject to the exclusions, waivers and limitations in the Agreement. 10.3 Priority and governing terms. If this DPA conflicts with the Agreement about the handling of Customer Personal Data, this DPA controls to the extent of that conflict. Otherwise, the Agreement controls, including its governing law, dispute-resolution and notice terms.