Data Processing Agreement

Australia

Effective date: 26 August 2026

This Data Processing Agreement (“DPA”) forms part of the Terms of Service between you (“Customer”, the practice) and Aku Online Limitedtrading as DoulaOne (“DoulaOne”, “we”). It governs personal information — including health information — that we hold and handle on your behalf about your clients, and it is written to the Privacy Act 1988(Cth) and the Australian Privacy Principles (“APPs”). By using DoulaOne to record information about your clients, you agree to this DPA. Terms not defined here have the meaning given in the Privacy Act.

1. Roles of the parties

For personal information you enter about your clients and their families (“Customer Personal Information”), your practice decides what is collected and why, and is the entity responsible for that information under the Privacy Act. DoulaOne holds and handles it on your behalf and only to provide the Service to you.

DoulaOne is separately responsible for your own account, billing, support, and enquiry information, as described in our Privacy Policy.

Where you record information on behalf of another organisation, we handle it as that organisation's downstream provider through you, and you remain responsible to them for our involvement.

2. Scope and your instructions

We handle Customer Personal Information only on your instructions, as set out in this DPA and the Terms, unless we are required to do otherwise by law (in which case we will tell you where we are legally permitted to). Your use of the platform's features constitutes your instructions.

We will not use, disclose, or retain Customer Personal Information for our own purposes, will not sell it, will not use it for advertising or profiling, and will not use it to train artificial intelligence or machine learning models.

3. Details of the information we handle

  • Subject matter: provision of the DoulaOne practice-management platform.
  • Duration: the term of your account, plus the limited retention described in Section 10.
  • Purpose: storing, organising, displaying, transmitting, and deleting Customer Personal Information so the Service works for you.
  • Types of information: contact details, due dates, appointments (including the timezone a family chose when they booked), care notes, birth preferences, contracts and e-signatures (including signer IP address and browser/user-agent captured for signature audit), intake responses, invoices and payment references, messages, and uploaded documents.
  • Individuals: your clients, their partners, family members, and emergency contacts.
  • Sensitive information: health information about pregnancy, birth, and postpartum care that you choose to record.

4. Your responsibilities

You are responsible for:

  • Collecting Customer Personal Information lawfully and only where it is reasonably necessary for your practice (APP 3), including obtaining consent for health information and other sensitive information.
  • Giving your clients an appropriate collection notice (APP 5), including that their information is stored in a practice-management platform and disclosed to recipients outside Australia (see Section 8).
  • The accuracy, quality, and relevance of what you record, and for responding to your clients' access and correction requests.
  • Ensuring your instructions to us comply with the Privacy Act and any other law that applies to your practice.
  • Managing who in your workspace can see what, including team access, backup-doula access, and owner-only notes.

5. Confidentiality and personnel

We ensure that personnel authorised to handle Customer Personal Information are bound by appropriate confidentiality obligations and access it only as needed to provide and support the Service.

6. Security (APP 11)

We take reasonable steps to protect Customer Personal Information from misuse, interference, loss, and unauthorised access, modification, or disclosure, including:

  • Row-level security isolating each workspace's data
  • Private, access-controlled file storage with signed URLs
  • Encryption in transit (HTTPS/TLS) and encryption at rest
  • Server-side authentication, session controls, and idle logout
  • Owner-only access controls for sensitive notes
  • Consent-gated, reduced access for backup doulas
  • Restricted access to production systems and secrets

7. Service providers we use

You authorise us to engage the providers below to help deliver the Service. Each is bound by written terms requiring it to protect the information and handle it only on our instructions.

  • Supabase— database, authentication, and file storage (European Union, Paris region)
  • Vercel— application and website hosting
  • Brevo— transactional and (where recipients opt in) marketing email delivery
  • Stripe— payment processing, where you enable online client payments
  • Mapbox— map display on public directory pages
  • Google— optional Sign-in and Calendar / Meet integration (only if you connect it)
  • Zoom— optional meeting links for appointments (only if you connect it)
  • Calendly— optional booking import (only if you connect it)
  • OpenAI— optional AI assists (only if a workspace owner enables them). When enabled, the content you choose to process is sent to OpenAI to generate a draft you review, which may include health information. OpenAI does not use data submitted through its API to train its models.

We will give notice of any intended addition or replacement of a provider by updating this page and, where you have subscribed to notices, by email. You may object on reasonable privacy grounds by contacting contact@doulaone.com; if we cannot accommodate your objection, you may stop using the affected feature or terminate.

8. Overseas disclosure (APP 8)

Customer Personal Information is held outside Australia. The system of record is in the European Union (Supabase, Paris region) and DoulaOne is operated from the United Kingdom. The providers in Section 7 may also handle information in other countries, including the United States.

Before disclosing personal information overseas we take steps that are reasonable in the circumstances to ensure recipients do not breach the APPs, including written agreements requiring them to protect the information, handle it only on our instructions, and keep it confidential.

You must tell your clients about this in your collection notice before you enter their information. You acknowledge that you are instructing us to hold Customer Personal Information overseas, and that enforcing Australian privacy protections against an overseas recipient may be difficult. If you require Australian data residency, contact us before storing client information in the Service.

9. Access, correction, and complaints assistance

Taking into account the nature of our role, we will give you reasonable assistance to respond to your clients' requests for access to or correction of their information under APP 12 and APP 13, and to privacy complaints. In-product tools cover most cases: you can view and edit records, export your full workspace as JSON, and delete individual clients or your whole account.

If an individual contacts us directly about Customer Personal Information, we will, where permitted by law, refer them to you or forward the request to you rather than responding ourselves.

10. Data breaches (Part IIIC)

We will notify you without undue delay after becoming aware of unauthorised access to, unauthorised disclosure of, or loss of Customer Personal Information, and will give you the information reasonably available to us about what happened, the kinds of information involved, and the steps we are taking.

We will cooperate with you so you can carry out any assessment required under the Notifiable Data Breaches scheme and, where the breach is an eligible data breach, notify affected individuals and the Office of the Australian Information Commissioner within the time the Privacy Act requires. You are responsible for deciding whether a notifiable breach has occurred in relation to information you are responsible for, and for making any required notification. Notice of an incident is not an admission of fault or liability.

11. Retention, return, and deletion

You can export and delete Customer Personal Information through the platform at any time. On termination of your account, we will delete or return Customer Personal Information within a reasonable period, except where retention is required by law. Backups are deleted on our routine backup-expiry cycle.

You are responsible for determining and meeting your own record-keeping obligations, including any professional, insurance, or state and territory health-records requirements that apply to your practice, before you delete records.

We may create and retain aggregated or de-identified data that no longer identifies any individual (for example, statistical or performance insights), and may continue to use it after termination to operate and improve the Service. This is not Customer Personal Information.

12. Verification and audits

We will make available information reasonably necessary to demonstrate compliance with this DPA and, on reasonable prior request and subject to confidentiality, respond to your privacy and security enquiries. Where available, third-party certifications or reports from our providers may be used to satisfy those enquiries.

13. Health records and clinical obligations

DoulaOne is administrative software. We are not a health service provider, we do not provide clinical care, and this DPA does not make us a party to any care relationship between you and your client.

Some Australian states and territories have their own health-records legislation that may apply to records you keep about your clients. You are responsible for determining whether those laws, or your professional association's standards, apply to your practice and for meeting them. Contact us before storing client information if your obligations require controls we do not currently offer.

14. Other jurisdictions

If your processing also involves personal data protected by the EU or UK GDPR — for example, clients located in the United Kingdom or Europe — our GDPR Data Processing Agreement applies to that data in addition to this DPA, including its international-transfer safeguards.

15. Changes to this DPA

We may update this DPA from time to time to reflect changes in the Service, our providers, or legal requirements. We will post the revised version on this page and update the effective date, and for material changes will provide notice through the Service or by email where appropriate.

16. Liability and precedence

This DPA is subject to the limitations and exclusions of liability set out in the Terms, which are themselves subject to the Australian Consumer Law. If there is a conflict between this DPA and the Terms regarding the handling of Customer Personal Information, this DPA prevails.

17. Contact

For privacy enquiries, objections to a service provider, or to request a signed copy of this DPA:

contact@doulaone.com

See also our Privacy Policy and Terms of Service.