Data Processing Agreement
Version 1.0 · Effective 21 August 2026
This Data Processing Agreement ("DPA") forms part of the agreement between the Customer and Bamtech Lab Pty Ltd (ACN 699 027 668, ABN 50 699 027 668), trading as Captr ID ("CaptrID"), under which the Customer subscribes to the CaptrID service (the "Services").
It applies automatically to every Customer — no separate signature is required. If your organisation requires a countersigned bilateral copy, or needs us to review your own DPA template, contact [email protected].
Related: Security & Sub-Processors · Privacy Notice · Terms of Service
1. Parties and roles
The Customer is the Controller and CaptrID is the Processor in respect of personal data processed to provide the Services. Where Australian law applies, the Customer is the entity with the obligations of an APP entity in respect of that data, and CaptrID processes it on the Customer's behalf.
For California personal information, the Customer is a Business and CaptrID is a Service Provider. CaptrID does not "sell" or "share" personal information and processes it only to provide the Services.
2. Scope, subject matter, nature and purpose
- Subject matter: processing of personal data to provide photo capture, identity-credential production, digital wallet passes, and related administration.
- Nature: capture and intake, validation and quality analysis, standardisation, storage, credential and pass issuance, and deletion, on the Customer's documented instructions.
- Purpose: to deliver the Services the Customer has subscribed to.
- Duration: the term of the underlying agreement, plus the deletion and return steps in section 9.
3. Customer instructions
CaptrID processes personal data only on the Customer's documented instructions, including as set out in this DPA and in the Customer's configuration of the Services — for example its chosen capture-quality profile, retention policy, and jurisdiction settings. The Customer's use and configuration of the Services constitute its instructions.
CaptrID will inform the Customer if, in its opinion, an instruction infringes applicable data protection law.
4. CaptrID's obligations
CaptrID shall:
- Confidentiality — ensure personnel authorised to process personal data are bound by confidentiality.
- Security — implement the technical and organisational measures in Annex B.
- Sub-processors — engage only the sub-processors identified in Annex C, under written terms imposing equivalent obligations, and give the Customer at least 30 days' notice of any intended addition or replacement, during which the Customer may object on reasonable data-protection grounds.
- Assistance — taking into account the nature of the processing, assist the Customer by appropriate measures with data subject requests and with security, breach notification, data protection impact assessments and prior consultation.
- Breach notification — notify the Customer without undue delay after becoming aware of a personal data breach, with the information the Customer reasonably needs to meet its own notification duties.
- Records — make available the information necessary to demonstrate compliance and allow for and contribute to audits, as set out in section 7.
5. Data subject requests
Where legally permitted, CaptrID will promptly notify the Customer of a request received directly from a data subject, and will not respond to it except on the Customer's instruction.
The Services provide self-service tooling — person erasure, data export, and retention controls — that the Customer can use to fulfil access, deletion, correction and portability requests.
One limitation the Customer should be aware of. Where the Customer has enabled a write-back to one of its own systems — for example a photograph pushed to its student management system, or a card number pushed to its print-management server — that copy resides on infrastructure the Customer controls, and erasure by CaptrID does not remove it. CaptrID will identify the affected downstream systems when assisting with an erasure request; removing the copy is the Customer's responsibility.
6. International transfers
Primary customer data — accounts, rosters, photographs and quality verdicts — is hosted and processed in Australia.
Where the Services involve a transfer of personal data from the UK or EU to a third country, the parties will rely on an appropriate transfer mechanism (for example the UK IDTA or EU Standard Contractual Clauses), and CaptrID will assist with any required Transfer Impact Assessment. Ancillary providers listed in Annex C process limited data outside Australia under their own transfer safeguards.
7. Audit
CaptrID will make available the information reasonably necessary to demonstrate compliance with its obligations as processor, and will allow for and contribute to audits, including inspections, conducted by the Customer or its auditor on reasonable notice, no more than once per twelve months or following a personal data breach, subject to confidentiality and to minimising disruption to the Services.
A current third-party report or a completed security questionnaire may be provided in satisfaction of an audit request where reasonable.
8. Sub-processors
The Customer provides general authorisation for CaptrID to engage the sub-processors identified in Annex C. CaptrID remains liable for its sub-processors' performance of their data-protection obligations. Change notification and objection rights are as set out in section 4.3.
9. Return and deletion
On termination, or on the Customer's request, CaptrID will delete or return all personal data and delete existing copies, except where retention is required by law. Standard deletion follows the Services' retention controls and the procedures described on our Security page.
10. Liability, conflict, governing law
Liability is as set out in the underlying agreement. In the case of conflict between this DPA and the underlying agreement on a matter of data protection, this DPA prevails. Governing law follows the underlying agreement unless a mandatory data protection law requires otherwise.
Annex A — Details of processing
| Categories of data subjects | The Customer's members whose ID credentials are produced — for example employees, students, members or contractors — and the Customer's administrative users. |
|---|---|
| Categories of personal data | Identity and contact fields on the roster (name, identifier, and Customer-defined fields); photographs; credential and card data; digital wallet pass payloads; a non-biometric photo-quality verdict or score; account and audit metadata. |
| Special-category or sensitive data | Transient face-detection signals used solely for photo-quality assurance — ephemeral and never stored. No template, landmark, measurement or biometric identifier is persisted. See A.5 below. Photographs may otherwise reveal personal characteristics; they are processed only for credential production. |
| Children's data | May include minors, for example in schools. Server-side face detection is governed by an organisation-level administrator setting that is off by default; where it is not enabled, no face detection is performed on the Customer's data. See A.5. |
| Frequency | Continuous for the term. |
| Retention | Per the Customer's configured retention policy; deletion via retention enforcement and/or person erasure. |
A.5 — Face detection: instruction and Customer warranty
The Customer instructs CaptrID to perform on-device and in-memory face detection for photo-quality assurance, as configured by the Customer, and warrants that it: (a) has authority to instruct such processing in respect of its data subjects; and (b) has provided those data subjects with the notices required by applicable law.
CaptrID performs no facial recognition, matching, verification, liveness detection or identification, creates no face template or embedding, and persists nothing biometric.
Server-side face detection runs only where the Customer has enabled it. The control is off by default, and is additionally disabled automatically where the Customer's configured jurisdiction or a data subject's declined consent requires it. Where it is not enabled, photographs are assessed for image quality only — sharpness, lighting, resolution and framing — and no face detector runs.
Annex B — Technical and organisational measures
The full and current description is published on our Security & Sub-Processors page, which governs. In summary:
- Hosting and residency — Australian region: Supabase Sydney, and the capture-quality engine and wallet-pass signer in Google Cloud
australia-southeast1(Sydney). - Encryption — in transit (TLS 1.2+) and at rest (AES-256).
- Access control — row-level security scoping all data to the owning organisation; role-based access across four tiers; multi-factor authentication available; rate-limited authentication endpoints.
- Storage — time-limited signed URLs for media; EXIF metadata stripped on processing.
- Biometric minimisation — no persistence of face geometry; only a quality verdict is retained. Architecturally enforced and verified by automated test.
- Auditability — immutable audit logs for sensitive actions. IP addresses and user-agent strings are deliberately not captured, as a data-minimisation measure.
- Data subject tooling — person erasure and configurable retention with advance-warning notifications.
- Breach response — a documented process for notifying the Customer without undue delay.
Annex C — Sub-processors
The authoritative list of CaptrID's sub-processors — with the purpose, data categories, location and lawful basis for each, and a link to each provider's own data processing agreement — is published and maintained at captrid.com/security. That published list governs and is not reproduced here, so that there is only ever one list to keep current.
CaptrID will give the Customer at least 30 days' notice by email before a new sub-processor begins processing Customer personal data, or before any material change to where processing occurs, giving a reasonable opportunity to object.
Systems that are not sub-processors. Systems the Customer connects to the Services — its directory, student information system or broker, data platform, identity provider, or cloud storage — remain the Customer's own services under the Customer's own agreements. CaptrID neither selects nor instructs them. Section 11 of the Security page describes them, including the two flows in which CaptrID writes data out to a Customer system on the Customer's documented instruction.
Acceptance and versioning
This DPA is incorporated into the Terms of Service and applies to every Customer from the effective date shown at the top of this page. No signature is required for it to take effect.
Where a material change is made to this DPA, CaptrID will notify customer account administrators by email at least 30 days before it takes effect, giving a reasonable opportunity to object. Superseded versions are retained and available on request.
If your organisation requires a countersigned bilateral copy, or wishes CaptrID to review its own DPA template, contact [email protected].
Version 1.0 · Effective 21 August 2026 · Bamtech Lab Pty Ltd (ACN 699 027 668) trading as Captr ID