Version 1.1 — 22 September 2026. This Addendum forms part of the Streamtime Licence Agreement and is incorporated into it by clause 1.4 of that Agreement.
1. Interpretation
1.1 This Data Processing Addendum (Addendum) forms part of the Streamtime Licence Agreement between the Customer and Streamtime Australia Pty Ltd ABN 52 654 231 777 (Streamtime). Capitalised terms not defined here have the meaning given in the Licence Agreement.
1.2 Applicable Data Protection Law means each law relating to the protection of personal information that applies to a party's processing of Customer Personal Data, including the Privacy Act 1988 (Cth), the EU General Data Protection Regulation (Regulation (EU) 2016/679) (EU GDPR), the UK GDPR and the Data Protection Act 2018 (UK), the Privacy Act 2020 (New Zealand) and the Personal Information Protection and Electronic Documents Act (Canada).
1.3 Customer Personal Data means personal information contained in Customer Data that Streamtime processes on behalf of the Customer under the Licence Agreement.
1.4 EU SCCs means the standard contractual clauses approved by European Commission Implementing Decision (EU) 2021/914, and UK Addendum means the International Data Transfer Addendum to those clauses issued by the UK Information Commissioner under s.119A(1) of the Data Protection Act 2018.
1.5 Security Incident means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or unauthorised access to, Customer Personal Data.
1.6 Sub-processor means a third party engaged by Streamtime to process Customer Personal Data.
1.7 The terms controller, processor, data subject, personal data and processing have the meanings given in the EU GDPR, and include the equivalent terms under any other Applicable Data Protection Law.
2. Scope and roles
2.1 This Addendum applies where Streamtime processes Customer Personal Data on behalf of the Customer in providing the Software. It applies to all Customers.
2.2 Where the Customer is a controller of Customer Personal Data, Streamtime acts as its processor. Where the Customer is itself a processor acting on behalf of a third party, Streamtime acts as its sub-processor, and the Customer warrants that it has the authority of the relevant controller to appoint Streamtime on these terms.
2.3 Streamtime is a controller in respect of personal information it collects about the Customer's personnel for its own purposes, including account administration, billing, support and improvement of the Software. Streamtime's Privacy Policy describes that processing and this Addendum does not apply to it.
3. Processing
3.1 Streamtime will process Customer Personal Data only to provide, maintain, support and secure the Software in accordance with the Licence Agreement, in accordance with the Customer's instructions (which this Addendum, the Licence Agreement, and the Customer's use of the features and settings of the Software constitute), and as required by law.
3.2 Where Streamtime is required by law to process Customer Personal Data otherwise than on the Customer's instructions, it will inform the Customer of that requirement before processing unless prohibited from doing so.
3.3 Annex I describes the subject matter, duration, nature and purpose of the processing and the categories of Customer Personal Data and of data subjects.
3.4 Streamtime will inform the Customer if, in its opinion, an instruction infringes Applicable Data Protection Law.
3.5 The Customer is responsible for the accuracy and lawfulness of the Customer Personal Data it loads into the Software, for having a lawful basis for its processing, and for giving any notices and obtaining any consents required from the individuals concerned, including the Customer's own personnel and the personnel of the Customer's clients.
3.6 Streamtime will not sell Customer Personal Data, will not use it for advertising, and will not use it to train any machine learning or artificial intelligence model.
4. Confidentiality and security
4.1 Streamtime will ensure that each person it authorises to process Customer Personal Data is subject to an appropriate duty of confidentiality, and will limit access to personnel who require it.
4.2 Streamtime will implement and maintain the technical and organisational measures described in Annex II. Streamtime may update those measures from time to time provided the updates do not materially reduce the overall level of protection.
5. Sub-processors
5.1 The Customer authorises Streamtime to engage Sub-processors. Those engaged from time to time are published at streamtime.net/legal/subprocessors, which Streamtime maintains.
5.2 Streamtime will give at least 30 days' notice before a new Sub-processor begins processing Customer Personal Data, by updating that page and providing a means by which the Customer may subscribe to notice of updates.
5.3 The Customer may object to a new Sub-processor on reasonable data protection grounds by notice within that period. The parties will discuss the objection in good faith, and if it cannot be resolved the Customer may terminate the affected subscription, in which case clause 23 of the Licence Agreement applies.
5.4 Streamtime will impose on each Sub-processor data protection obligations substantially as protective as those in this Addendum, to the extent applicable to the services that Sub-processor provides, and remains responsible to the Customer for its performance.
6. Assistance to the Customer
6.1 Taking into account the nature of the processing and the information available to it, Streamtime will provide reasonable assistance to enable the Customer to respond to a request by a data subject to exercise their rights. The Software includes features by which the Customer can access, export, correct and delete Customer Personal Data itself, and the Customer will use those features in the first instance.
6.2 If Streamtime receives a request directly from a data subject in respect of Customer Personal Data, it will not respond other than to direct the individual to the Customer, and will inform the Customer without undue delay.
6.3 Streamtime will provide the Customer with reasonable assistance in carrying out a data protection impact assessment, and in any prior consultation with a supervisory authority, relating to Streamtime's processing.
7. Security Incidents
7.1 Streamtime will notify the Customer of a Security Incident affecting Customer Personal Data without undue delay, and in any event within 72 hours of becoming aware of it.
7.2 The notification will include, to the extent then known, the nature of the incident, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed. Where Streamtime cannot provide all of that information at once it will provide it in phases, without undue delay.
7.3 Streamtime will take appropriate measures to address the Security Incident and mitigate its effects, and will cooperate reasonably with the Customer to enable the Customer to meet its own notification obligations. Notification is not an acknowledgement of fault or liability.
8. AI Features
8.1 Where the Customer uses the AI Features, Streamtime processes Customer Personal Data in order to respond to the Customer's instructions, as described in clause 14A of the Licence Agreement and in Streamtime's Privacy Policy. The providers of the foundational models are engaged as Sub-processors, are identified at streamtime.net/legal/subprocessors, and are contractually prohibited from using Customer Personal Data to train their models.
8.2 A record of each conversation with the Streamtime AI assistant, including the Customer Personal Data retrieved in order to respond, is retained for 30 days and is then deleted.
8.3 Where the Customer connects an artificial intelligence assistant of its own choosing to the Software through Streamtime's MCP server:
8.3.1 the Customer instructs Streamtime to disclose Customer Personal Data to the provider of that assistant, to the extent the assistant requests it;
8.3.2 that provider is not a Sub-processor, is not engaged by Streamtime, and Streamtime has no contractual relationship with it in respect of Customer Personal Data;
8.3.3 the Customer is responsible for satisfying itself that the provider's terms are appropriate, for any transfer of Customer Personal Data arising from the connection, and for having a lawful basis and giving any necessary notices; and
8.3.4 Streamtime's obligations under this Addendum do not extend to processing carried out by that provider.
8.4 Streamtime does not impose a confirmation step of its own on actions initiated through the MCP server. Whether the Customer's chosen assistant seeks approval before it changes Customer Data is determined by that assistant.
9. International transfers
9.1 Streamtime is established in Australia and Customer Personal Data is stored and processed in the United States, as described in Streamtime's Privacy Policy and at streamtime.net/legal/subprocessors.
9.2 Where the EU GDPR applies to the Customer's use of the Software and the transfer of Customer Personal Data to Streamtime or a Sub-processor is a transfer to a country not covered by a European Commission adequacy decision, the EU SCCs are incorporated into this Addendum and apply to that transfer, completed as set out in the Schedule. Module Two applies where the Customer is a controller and Module Three where the Customer is a processor.
9.3 Where the UK GDPR applies and the transfer is to a country not covered by United Kingdom adequacy regulations, the EU SCCs as varied by the UK Addendum are incorporated into this Addendum and apply to that transfer, completed as set out in the Schedule.
9.4 Where Customer Personal Data collected in Australia is disclosed to an overseas recipient, Streamtime takes such steps as are reasonable in the circumstances to ensure that the recipient does not breach the Australian Privacy Principles in relation to that information. Where Customer Personal Data collected in New Zealand is disclosed outside New Zealand, Streamtime does so in accordance with information privacy principle 12 of the Privacy Act 2020.
9.5 If a transfer mechanism relied on under this clause is invalidated, amended or replaced, the parties will in good faith put an alternative mechanism in place, and Streamtime may update the Schedule accordingly on notice to the Customer.
10. Information and audit
10.1 On the Customer's reasonable written request, and no more than once in any 12-month period unless required by a supervisory authority, Streamtime will make available information reasonably necessary to demonstrate its compliance with this Addendum, including responses to a reasonable security questionnaire and any third-party certifications or reports it holds or is entitled to pass on.
10.2 Where that information is not sufficient, the Customer may request an audit. An audit will be conducted on at least 30 days' notice, during business hours, at the Customer's cost, subject to confidentiality, and in a manner that does not disrupt Streamtime's operations or the security or confidentiality of any other customer's data.
11. Return and deletion
11.1 On expiry or termination of the Licence Agreement, Streamtime will deal with Customer Personal Data in accordance with clause 23 of the Licence Agreement, which provides for a transitional period to complete a switch, export in a structured, commonly used and machine-readable format, a subsequent retrieval period, and then erasure.
11.2 Streamtime may retain Customer Personal Data after that period only to the extent required by law, and will continue to protect it in accordance with this Addendum for as long as it is retained.
12. General
12.1 Precedence. If there is a conflict between this Addendum and the rest of the Licence Agreement, this Addendum prevails in respect of the processing of Customer Personal Data. If there is a conflict between this Addendum and the EU SCCs or the UK Addendum, those clauses prevail.
12.2 Liability. Each party's liability under this Addendum is subject to the exclusions and limitations of liability in clause 16 of the Licence Agreement. Nothing in this clause limits either party's liability to a data subject, or under the EU SCCs or the UK Addendum, to the extent that liability cannot lawfully be limited.
12.3 Term. This Addendum takes effect when the Licence Agreement takes effect and continues for as long as Streamtime processes Customer Personal Data.
12.4 Governing law. This Addendum is governed by the law of New South Wales, Australia. The EU SCCs and the UK Addendum are governed by the law identified in the Schedule.
12.5 Variation. Streamtime may vary this Addendum in accordance with clause 1.3 of the Licence Agreement, provided that no variation reduces the protections afforded to Customer Personal Data.
Annex I — Description of the processing
Parties
Data exporter: the Customer, as identified in the Order. Controller, or processor where clause 2.2 applies. Contact: the Customer's account administrator.
Data importer: Streamtime Australia Pty Ltd ABN 52 654 231 777, Level 17, 383 Kent Street, Sydney NSW 2000, Australia. Processor, or sub-processor where clause 2.2 applies. Contact: privacy@streamtime.net.
Categories of data subjects
The Customer's personnel, including employees, contractors and freelancers; the Customer's clients and their personnel; and any other individual whose personal information the Customer records in the Software.
Categories of personal data
Names, job titles, employers and business contact details; time entries recording who performed what work and when; work schedules, availability and capacity; individual cost and charge-out rates; job, quote, invoice, purchase order and expense records; the content of job posts and comments; authentication and usage records; and the content of conversations with the AI Features.
Sensitive data
The Software is not intended for the processing of special category or sensitive personal data, and the Customer is responsible for not loading it.
Frequency, nature and purpose
Continuous, for the term of the Licence Agreement. Hosting, storage and processing of Customer Data in order to provide project management, job and time tracking, scheduling, quoting, invoicing, reporting and AI-assisted features, together with support, maintenance and security of the Software.
Duration
For the term of the Licence Agreement and the periods described in clause 11.
Sub-processors
As published at streamtime.net/legal/subprocessors, for the duration and purposes stated there.
Competent supervisory authority
The supervisory authority of the EEA member state in which the Customer is established; or where the Customer is not established in the EEA, the supervisory authority of the member state in which the relevant data subjects are located.
Annex II — Technical and organisational measures
The measures in this Annex relating to the AI Features apply from the date those features are made available.
Encryption
- Customer Data is encrypted in transit using TLS.
- Data at rest is encrypted throughout the production estate. The database is encrypted with a customer-managed key, and every production object store, queue and table is encrypted. Files uploaded to the Software — contact import files, commercial document templates, branch logos and profile images — are held in the database and are covered by the same key. There is no unencrypted store in the production estate.
- Records of conversations with the AI Features are encrypted at rest using 256-bit AES.
- Payment card details are not stored by Streamtime; card transactions are processed by Stripe.
Access control
- Access to production systems is restricted to authorised personnel who require it, and is removed when an engagement ends.
- Multi-factor authentication is required for administrative access to production systems.
- Access within the Software is governed by the Customer's own user, role and permission settings. A Customer may require two-factor authentication for all of its users, or only for those who can see financial information.
- Access to the AI Features is disabled for each user by default and must be enabled by a Customer administrator.
Logging and accountability
- Changes to key fields, including job status and monetary values, are logged and retained for two years, recording whether the change was made through the Streamtime interface, the API, the MCP server or the Streamtime AI assistant.
- Actions initiated by the Streamtime AI assistant that change Customer Data require a user's confirmation before they are applied.
- The API and the MCP server are rate limited.
Vulnerability management
- Container images used in production are continuously scanned for known vulnerabilities.
Availability
- Customer Data is hosted on Amazon Web Services infrastructure. The database is backed up automatically with a 30 day retention period and point-in-time recovery, and deletion protection is enabled.
- Daily, weekly and monthly backups are retained for 8 days, 5 weeks and 13 months respectively, and are copied to a backup vault held in a separate Amazon Web Services account and encrypted.
- Service availability is published at streamtime.statuspage.io.
Retention
- Records of conversations with the AI Features are deleted 30 days after creation.
- A billing record for each AI request, recording the organisation, the user, a request reference and the credits and amount charged, and containing no conversation content, is retained as a financial record.
- Customer Data is retained and deleted in accordance with clause 11.
Supplier assurance
- Streamtime's infrastructure provider maintains ISO 27001, ISO 27017, ISO 27018 and ISO 27701 certification and SOC 1, SOC 2 and SOC 3 reporting, and is subject to annual independent audit.
- Sub-processors are engaged on terms substantially as protective as this Addendum and are published at streamtime.net/legal/subprocessors.
Schedule — Transfer clauses
EU Standard Contractual Clauses
Where clause 9.2 applies, the EU SCCs are completed as follows.
- Module — Module Two (controller to processor) where the Customer is a controller; Module Three (processor to processor) where the Customer is a processor.
- Clause 7 (docking clause) — Not used.
- Clause 9 (sub-processors) — Option 2 — general written authorisation, with the 30-day notice period in clause 5.2 of this Addendum.
- Clause 11 (redress) — The optional independent dispute resolution paragraph does not apply.
- Clause 13 — The competent supervisory authority is as identified in Annex I.
- Clause 17 (governing law) — Option 1 — the law of Ireland.
- Clause 18 (forum) — The courts of Ireland.
- Annexes I, II and III — Annex I and Annex II of this Addendum, and the Sub-processors published at streamtime.net/legal/subprocessors.
UK Addendum
Where clause 9.3 applies, the UK Addendum is completed as follows.
- Addendum EU SCCs — The EU SCCs as completed above.
- Table 1 — Parties — Exporter: the Customer, as identified in the Order. Importer: Streamtime Australia Pty Ltd, as identified in Annex I.
- Table 2 — Selected SCCs — As completed above.
- Table 3 — Appendix information — Annex I, Annex II and the Sub-processor list.
- Table 4 — Ending the Addendum — Neither party may end the Addendum as set out in Section 19 of the Mandatory Clauses.
- Governing law — The law of England and Wales.










