Data Processing Agreement
Last updated: 17 July 2026 · Kainos Consultants Australia Pty Ltd, trading as CompliDesk
Your firm stays controller of your clients' data; CompliDesk processes it on your instructions. This page summarises the DPA that will govern that relationship when the platform launches.
1. Purpose of This Page
When the CompliDesk Ireland platform launches, customer firms will act as data controllers for the personal data of their clients, and CompliDesk will act as their data processor. Article 28 GDPR requires that relationship to be governed by a written Data Processing Agreement (DPA). This page summarises the DPA terms that will apply, so you can assess them before sign-up. The full signable DPA is presented at account creation and is available beforehand on request from admin@complidesk.com.au.
2. Roles
- Your firm: data controller for the personal data of your clients that you process in CompliDesk (identity documents, screening results, risk assessments, reports).
- CompliDesk (Kainos Consultants Australia Pty Ltd, trading as CompliDesk): data processor, acting only on your documented instructions.
- For website data (waitlist, demo requests) CompliDesk is the controller — see the Privacy Policy.
3. Subject Matter, Duration and Nature of Processing
Processing covers the hosting, storage, retrieval, analysis and deletion of client records needed to deliver the platform’s compliance features (CDD, identity verification, screening, risk assessment, reporting, record retention), for the duration of your subscription plus the agreed deletion period.
4. Categories of Data and Data Subjects
Data subjects: your clients and their beneficial owners, directors and representatives.
Data categories: identification data (name, date of birth, address, identity document details), verification and screening outcomes, risk assessments, transaction context you record, and documents you upload. You should not store special-category data in free-text fields.
5. Our Commitments as Processor
The DPA commits CompliDesk to the Article 28(3) requirements, including:
- Process only on your documented instructions
- Ensure persons authorised to process are bound by confidentiality
- Implement appropriate technical and organisational security measures (see the Security page)
- Engage sub-processors only under equivalent obligations, with a maintained public list and advance notice of changes
- Assist you with data subject rights requests and with your Articles 32–36 obligations
- Notify you without undue delay of a personal data breach affecting your data
- Delete or return all personal data at the end of the engagement, at your choice
- Make available information necessary to demonstrate compliance, and allow audits
6. Sub-Processors
The sub-processors used to deliver the platform (Supabase — EU-region database; Vercel — hosting; Stripe — payments; Resend — email; Didit — identity verification; Anthropic — AI-assisted screening analysis; Zoho — CRM) are listed with their roles on the Security page, which serves as the maintained public sub-processor list.
7. International Transfers
Irish customer platform data is hosted in the EU (AWS eu-west-1, Dublin). Where any sub-processor or CompliDesk personnel access involves a transfer outside the EU/EEA, the DPA applies appropriate safeguards under Chapter V GDPR, including Standard Contractual Clauses.
8. Data Subject Rights and Retention
The platform is designed to help you honour data subject rights and the AMLR’s record-keeping duty: records are retained for the required 5-year period and then deleted, with retention and deletion mechanics built into the product rather than left to manual housekeeping.
9. Getting the Full DPA
Email admin@complidesk.com.au for the current full DPA text. It will also be presented for acceptance at sign-up when the platform launches, and this page will be updated at that point.
This summary is provided for transparency during the pre-launch period and does not itself form a contract. Questions? Contact admin@complidesk.com.au.