Data Processing Addendum
Last updated: 06 July 2026
This Data Processing Addendum (“DPA”) forms part of the RAD Terms of Service
(the “Terms”) between you (the “Client”) and RAD Business Pty Ltd (ACN 698 339 507) trading as RAD (“RAD”). It governs how RAD processes data captured through the RAD App and reflects RAD's obligations under the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles.
Who we are
RAD is operated by RAD Business Pty Ltd (ACN 698 339 507) trading as RAD (“RAD”, “we”, “us”, “our”). Our registered office is Level 1, 171 William Street, Darlinghurst NSW 2010, Australia.
This Privacy Policy explains how we collect, use, disclose, store, and protect personal information in accordance with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
Roles and Definitions
1.1 Roles
Client: The Client is the data controller of the captured data, with primary responsibility for the lawfulness of capture under Australian law and the Client’s relationship with their employees and contractors.
RAD: RAD is the data processor, processing captured data on behalf of and under the instruction of the Client.
Sub-processors: Sub-processors are third parties engaged by RAD to process Client data, listed in Annex A.
1.2 Definitions
“Advisor” means a registered R&D tax advisor nominated by the Client at activation, who is authorised by the Client to access Client Data for the purpose of providing R&D advisory services.
“Client Data” means any data captured, transmitted, processed, or stored by RAD on behalf of the Client, including application context metadata, session duration data, contextual snapshots of application windows, and AI-generated Evidence Records.
“Personal Information” means information about an identified or reasonably identifiable individual, as defined in the Privacy Act 1988.
“Security Incident” means unauthorised access to, disclosure of, or loss of Client Data.
“Evidence Records” means the AI-generated written summaries of R&D activity produced by the RAD App, as defined in the Terms.
“RAD App” has the meaning given in the Terms.
“Terms” means the RAD Terms of Service between RAD and the Client, of which this DPA forms part.
“User” has the meaning given in the Terms.
2. Categories of Data Processed
RAD processes the following categories of data:
Application context metadata (which applications are open, in focus, and active)
Session duration data (start time, end time, duration of focused work sessions)
Contextual snapshots of the application window in focus, captured while the RAD App is running from applications the User has allowed (see clause 3 regarding RAD’s obligation to discard personal information captured outside R&D scope)
AI-generated written summaries of R&D activity
Account and authentication metadata (user identifiers, organisation identifiers, role, session tokens)
Configuration data (privacy settings, application exclusions, active hours, project structure)
3. Data Processing
3.1 Purpose of Processing
RAD processes Client Data solely for the following purposes:
Identifying and documenting R&D-eligible activity
Generating structured Evidence Records to support R&D Tax Incentive claims
Providing the Client and any Advisor nominated by the Client with access to Evidence Records
Estimating the Client's projected R&D claim value, to assist the Client and Advisor in tracking and substantiating claim estimates over time
Generating time-based records of R&D activity by user, to support the Client's and Advisor's documentation of R&D effort and time attribution
Improving the RAD App's performance through aggregated, de-identified analysis
Complying with legal obligations and responding to lawful requests
RAD will not process Client Data for any other purpose without the Client’s prior written consent. Where RAD incidentally captures personal information outside the scope of R&D-relevant activity (including content from in focus applications visible during a capture session), RAD will take reasonable steps to discard or de-identify that
information as soon as practicable after it is identified, and will not use it for any
purpose other than identifying and discarding it.
3.2 Processing on Instructions
RAD will process Client Data only on and in accordance with the Client’s lawful instructions, including as set out in the Terms and this DPA, unless RAD is required by
law to process Client Data otherwise (in which case RAD will, to the extent permitted
by law, notify the Client of that requirement before processing). If RAD considers that
an instruction from the Client breaches, or is likely to breach, the Privacy Act 1988 (Cth) or other applicable law, RAD will promptly inform the Client and may suspend performance of that instruction until it is confirmed or varied by the Client.
4. Data Flow and Architecture
Client Data flows through the RAD App as follows:
Capture: contextual snapshots and metadata are captured on the enrolled User's device from whichever application is in focus, provided the User has allowed capture
of that application, during the active hours configured by the Client (whether standard configuration or extended on-demand by the User).Transmission: captured data is transmitted via encrypted TLS 1.2+ connection to RAD's infrastructure.
Processing: captured snapshots are processed by AI to identify R&D-relevant activity and to generate Evidence Records. Activity not identified as R&D-relevant is discarded.
Storage: Evidence Records and any retained snapshots are encrypted at rest using AES-256 and stored in Australian data centres.
Access: Client Data is accessible only to the Client's enrolled team members, any nominated Advisor, and authorised RAD personnel as described in clause 8.
5. Data Storage and Sovereignty
All Client Data is stored in Australian data centres operated by Google Cloud Platform (Sydney region). Each Client's data is logically isolated from other Clients. Data is encrypted in transit using TLS 1.2 or higher, and at rest using AES-256. RAD does not
store Client Data offshore, but some processing activities may occur overseas. Client
Data is not transferred outside Australia for storage purposes without the Client's explicit written consent, except for some sub-processing activity which may occur overseas and which is disclosed and authorised in this DPA (see clause 6 below).
RAD engages the sub-processor(s) listed in Annex A to deliver the RAD App. Some
sub-processors operate infrastructure outside Australia. By accepting this DPA, the
Client consents to the disclosure of relevant Client Data to these sub-processors for
the purposes set out below.
6.1 AI processing
RAD uses a third-party Large Language Model (“LLM”) provider (Google) to process contextual snapshots and generate Evidence Records.
Snapshots are transmitted to the LLM provider's infrastructure (which is global and may include infrastructure located outside Australia) for processing.
RAD's contractual arrangements with this provider excludes Client Data from being used to train their AI models.
LLM providers retain processed data only as required for service delivery and abuse monitoring (typically up to 30 days), after which it is deleted from their systems.
Google maintains SOC 2 Type II certification and has published data processing policies available on request. RAD’s own SOC 2 Type II certification is in progress
and targeted shortly after commercial launch.
6.2 Cloud hosting
RAD's infrastructure is hosted on Google Cloud Platform. The Sydney region
(australia-southeast1) is used for all Client Data storage. Some operational functions (logging, monitoring) may use Google Cloud services in other regions, but no Client Data is stored outside Australia. Google Cloud maintains SOC 2 Type II, ISO 27001, ISO 27017, ISO 27018, and IRAP assessments; its data processing addendum is publicly available
and forms the basis of RAD's contractual relationship with Google Cloud.
6.3 Changes to sub-processors
RAD will provide the Client with at least 30 days’ written notice before adding a new
sub-processor or materially changing how an existing sub-processor handles Client
Data. The Client may object to such changes, and where the parties cannot agree, the Client may terminate this DPA and the underlying Terms with no penalty.
6.4 Sub-processor obligations
RAD will impose on each sub-processor, by written agreement, data protection obligations that are materially equivalent to those imposed on RAD under this DPA, including in relation to security, confidentiality, and limitations on use. Where a
sub-processor processes Client Data outside Australia, RAD will take reasonable steps, consistent with Australian Privacy Principle 8.1, to ensure that the sub-processor does
not breach the Australian Privacy Principles in relation to that data, including through contractual data handling commitments. RAD remains responsible to the Client for the acts and omissions of its sub-processors in relation to Client Data as if they were the
acts and omissions of RAD.
7. Security Measures
RAD implements the following technical and organisational security measures:
Encryption of data in transit (TLS 1.2+) and at rest (AES-256)
Logical isolation of each Client's data
Role-based access controls within RAD's systems, with multi-factor authentication
for staff access to production environmentsAccess logging and audit trails for all Client Data access
Regular security testing and vulnerability management
Staff confidentiality obligations and security training
SOC 2 Type II certification - in progress, targeted shortly after commercial launch
8. Access Controls
Client Data is accessible only to: (a) the Client's own team members with active RAD accounts; (b) any Advisor nominated by the Client; and (c) authorised RAD personnel
as described in this clause 8.
Authorised RAD support and engineering staff may access Client Data to debug the RAD App, resolve technical issues, and improve the RAD App. RAD staff remain under confidentiality obligations, and RAD will not disclose Client Data outside of authorised RAD personnel without the Client's consent, except as required by law. Client Data will not be used to train external AI models, and will not be used for any purpose other than running, debugging, and improving the RAD App.
Access by RAD staff is logged and made available to the Client on request.
The Client controls the membership of its enrolled team members and may revoke access at any time.
8A. Advisor Access
Where the Client nominates an Advisor, by accepting this DPA the Client:
Authorises RAD to grant their nominated R&D tax advisor (the "Advisor") access to the Client's Evidence Records, capture progress, and account information for the purpose of providing R&D Tax Incentive advisory services.
Acknowledges that the Advisor will be able to view, manage and export Client Data through their RAD dashboard for that purpose.
Confirms that the Advisor's access does not extend to any purpose beyond the R&D advisory engagement.
The Advisor is expected to maintain confidentiality and use Client Data only for the R&D advisory engagement, consistent with their professional obligations under the Tax Agent Services Act 2009. The Advisor’s use and access to Client Data using RAD will be subject to the Advisor’s professional terms of service with the Client.
The Client acknowledges that the Advisor remains professionally responsible to the Client for the Advisor’s services. RAD is not party to the engagement between the Client and the Advisor.
The Client may revoke the Advisor's access at any time by written request to RAD. RAD will action revocation within 5 business days of receipt. Revocation does not affect the Advisor's professional record-keeping obligations under the Tax Agent Services Act 2009 in respect of records exported during the engagement.
9. Retention and Deletion
Evidence Records are retained for the duration of the Client's active subscription.
Prior to termination, the Client may export aggregated data for its records. RAD is not obligated to retain any Client Data after termination of the services.
Deletion requests during the term of the Client’s agreement will be actioned within 30 days of receipt, provided the Client has been notified of and acknowledged in writing the record-keeping obligation under section 382-80 of the Income Tax Assessment
Act 1997 (Cth), which requires substantiation records to be retained for a minimum of 5 years from the date of lodgement of the relevant income tax return. Where the Client is subject to an active ATO audit or review, deletion may be deferred until the audit or review is resolved. Nothing in this clause requires RAD to maintain logs or information as a system of record if the Client is no longer subscribing to the RAD services.RAD will not action a deletion request without first confirming the Client has either exported their records or acknowledged the ATO retention obligation in writing.
Aggregated, de-identified data may be retained beyond deletion of identifiable Client Data, where it cannot reasonably be linked to the Client or any individual.
10. Aggregated and De-identified Data
RAD may use aggregated and de-identified data (data that cannot reasonably be linked to the Client or any individual) to improve the RAD App, train its models, and generate insights about R&D activity patterns. No identifiable Client Data is used for these purposes without explicit consent. For the avoidance of doubt, RAD's own use of
de-identified data for model training is distinct from the LLM provider's processing of Client Data under clause 6.1, under which the LLM provider is contractually prohibited from using Client Data for model training purposes. RAD will not use identifiable Client Data to train its models, and will take reasonable steps to ensure that de-identified data cannot be re-identified before use for model improvement purposes.
11. Security Incident Notification
In the event of a Security Incident affecting Client Data, RAD will notify the Client and their nominated Advisor as soon as reasonably practicable after becoming aware of the incident.
RAD's notification will include: a description of the nature of the incident, the categories and approximate volume of data affected, likely consequences, measures taken or proposed to address the incident, and contact information for further inquiries.
RAD will take prompt and reasonable steps to contain, investigate, and remediate any Security Incident, and will keep the Client reasonably informed of the status of remediation.
RAD will cooperate with the Client in meeting any obligations the Client has under the Notifiable Data Breaches scheme of the Privacy Act 1988.
RAD's own notification obligations to the Office of the Australian Information Commissioner (where applicable) will be met independently.
12. Complaints
12.1 Complaints from individuals
If RAD receives a request or complaint directly from an individual (including an enrolled User) relating to Personal Information contained in Client Data, including a request for access to or correction of that information, RAD will promptly refer the request to the Client and will not respond substantively to the individual except to direct them to the Client, unless required by law to do otherwise. RAD will provide the Client with reasonable assistance in responding to requests from individuals under the Privacy Act 1988 (Cth) in respect of Client Data, including by making relevant Client Data available through the RAD App’s access, correction, and export functionality. Where a request requires
material effort beyond the RAD App’s standard functionality, RAD may charge the
Client its reasonable costs of assistance.
12.2 Third-Party and Government Requests
If RAD receives a subpoena, warrant, regulatory notice (including a notice from the Australian Taxation Office or another taxation authority), or other legally binding
demand from a third party for access to or disclosure of Client Data, RAD will:
(a) unless legally prohibited from doing so, promptly notify the Client and provide reasonable cooperation to enable the Client to seek to limit or challenge the demand;
(b) disclose only the minimum Client Data legally required to comply with the demand; and (c) where disclosure is made, inform the Client of what was disclosed, to the extent permitted by law.
13. Audits and Compliance
RAD will respond to reasonable Client information requests about its data handling practices within 30 days. In addition, the Client (or a third-party auditor nominated by the Client and subject to confidentiality obligations no less stringent than those in this DPA) may audit RAD’s data handling practices on 30 days’ prior written notice to RAD, no more than once in any 12-month period, and at the Client’s cost. RAD will provide reasonable co-operation and access to relevant records for the purpose of such an audit. Audit findings are confidential to the Client and RAD.
Once RAD obtains SOC 2 Type II certification, RAD will provide a copy of the most recent SOC 2 report to Clients on written request, subject to confidentiality undertakings.
14. Liability
RAD’s liability under this DPA is governed by clause 7.1 of the Terms, except that: (a) for loss or damage arising from a Security Incident caused by failures in RAD’s own systems, infrastructure, or security controls, RAD’s liability is not subject to the exclusions or the general cap in clause 7.1 of the Terms, but is instead limited, in aggregate, to the Fees
paid by the Client to RAD in the 12 months preceding the Security Incident (the “Security Incident Cap”); and (b) nothing in this DPA or the Terms limits RAD’s liability to the extent it cannot lawfully be excluded under the Australian Consumer Law or the Privacy Act 1988 (Cth).
15. Term and Survival
This DPA commences when the Client accepts the Terms and continues for the duration of the Terms. The following clauses survive termination or expiry of this DPA: clause 9 (Retention and Deletion), clause 10 (Aggregated and De-identified Data), clause 11 (Security Incident Notification, in respect of Security Incidents occurring before termination), clause 13 (Audits and Compliance, for 12 months after termination), clause
14 (Liability), and clause 16 (Governing Law), together with any other provision which by its nature is intended to survive.
16. Governing Law
This DPA is governed by the laws of New South Wales, Australia, and is subject to the Privacy Act 1988 (Cth) and the Australian Privacy Principles. Questions about this DPA, including requests to access or correct Personal Information held by RAD, should be directed to RAD’s Privacy Coordinator at privacy@radrnd.com.
Annex A - Sub-Processors
RAD engages the following sub-processors in delivering the RAD App: