This Schedule forms part of the Rev-Raise Master Client Terms and applies wherever we build or operate Systems that hold personal information about your customers, contacts or staff. Defined terms have the meaning given in clause 1 of those Terms.
This is the document your compliance team will ask for. It is published so you do not have to.
1.1 Australia does not use the controller and processor labels that appear in European law. Under the Privacy Act 1988 (Cth), the entity that decides what personal information is collected and why is the entity responsible for it.
1.2 For information held in Systems we operate for you: that entity is you.
(a) You decide what is collected, from whom, why, and what happens to it. (b) We act on your instructions, and only for the purpose of delivering the services in your Proposal. 1.3 You remain the entity accountable under the Australian Privacy Principles for that information, including for notice under APP 5, for use and disclosure under APP 6, and for any eligible data breach. Each party complies with the privacy obligations that apply to it. Where the Privacy Act applies to us in respect of information we hold for you, we meet our own obligations; this Schedule allocates responsibility between us and does not remove a statutory obligation from either party.
1.4 We are separately responsible for information we collect about you and your people in our own right. That is governed by our Privacy Policy at rev-raise.com/privacy, not by this Schedule.
1.5 Where your customers are in a jurisdiction with its own regime, the EU or UK GDPR, New Zealand, or another, tell us before we start. This Schedule is written to Australian law and does not by itself satisfy the GDPR. We will agree the additional terms you need.
2.1 We will:
(a) process it only to deliver the services in your Proposal, and on your documented instructions; (b) keep it in Systems configured for your account and separated from other clients' data; (c) restrict access to people who need it for their role; (d) require everyone with access to be bound by confidentiality that survives their engagement ending; (e) tell you promptly if we think an instruction from you would breach the Privacy Act; and (f) help you meet your own obligations, under clause 6.
2.2 We will not:
(a) use your data for our own purposes; (b) market to your customers, ever; (c) sell, rent or share your data; (d) use your data, or your customers' data, to train, fine-tune or improve any AI model, and we configure our tools to that setting where the tool offers it; (e) combine your data with another client's; (f) use your data to build a product; or (g) retain it after termination beyond the period in clause 8.
2.3 Clause 2.2(d) is a commitment, not an aspiration. Where a tool we need does not allow model training to be switched off, we will not put your customers' personal information through it without telling you first and getting your written agreement. Clause 10.2 of the Master Terms.
3.1 You warrant that:
(a) you have collected the personal information lawfully; (b) you have given the notices required under APP 5; (c) you hold the consents required for how it will be used in the Systems, including for marketing under the Spam Act 2003 (Cth); (d) your instructions to us comply with the Privacy Act; and (e) any list you provide meets clause 9.3 of the Master Terms and Schedule B clause 14.2.
3.2 Do not put sensitive information into Systems we operate, health information, biometric data, or anything else defined as sensitive under s 6 of the Privacy Act, without telling us first and agreeing the additional controls in writing. If you operate a clinic or any health service, this clause applies to you and you should raise it before onboarding.
3.3 You are the first point of contact for your customers. If one of them asks us for access, correction or deletion, we will refer them to you and tell you the same day.
4.1 We use third-party providers to deliver the services. The categories are listed in section 8 of our Privacy Policy.
4.2 A current list of named providers, and the countries in which each processes data, is attached to your Service Agreement and is available on request at any time. We will provide an updated list within 10 Business Days of a request.
4.3 We will give you 30 days notice before adding a new provider, or a new category of provider, that will process your customers' personal information. If you object on reasonable grounds, we will work with you on an alternative, and if there is none you may terminate the affected services on 30 days notice with no exit fee.
4.4 Every provider is bound by confidentiality obligations.
5.1 Some providers process data outside Australia, principally in the United States. The Privacy Policy names the categories and countries.
5.2 We take reasonable steps to ensure overseas recipients handle the information consistently with the Australian Privacy Principles, including through contractual commitments.
5.3 Section 16C of the Privacy Act makes an entity accountable for an overseas recipient's acts in some circumstances. We will give you what you need to assess your position, and we will tell you before moving your data to a new country.
Where you need something to discharge your own duties, ask and we will provide it.
| You need | We provide | Within |
|---|---|---|
| An extract of one individual's data, for an APP 12 access request | The extract | 10 Business Days |
| Correction or deletion of a record | The change, actioned | 5 Business Days |
| The named sub-processor list | The list | 10 Business Days |
| Information for a privacy impact assessment | What we hold about our processing | 15 Business Days |
| Information to assess a suspected breach | Everything we know | Immediately |
6.1 These are included in your fees. We do not charge you for helping you comply.
7.1 We apply the controls in section 9 of our Privacy Policy: access controls, encryption in transit, multi-factor authentication on administrative accounts, and access limited by role.
7.2 If we become aware of a data incident affecting personal information held in Systems we operate for you, being unauthorised access, disclosure, loss, alteration, corruption, ransomware or unavailability, we will notify you without undue delay and in any case within 72 hours of becoming aware. Clause 14.5 of the Master Terms.
7.3 That notification will include what we know about what happened, what information was involved, what we have done, and what we recommend.
7.4 Each party remains responsible for meeting its own notification obligations under the Notifiable Data Breaches scheme. The assessment of whether a breach involving your customers' information is an eligible data breach is yours to make, and we will help you make it. The parties will coordinate before notifying the OAIC or affected individuals where legally permitted and where doing so will not delay a required notification.
7.5 We will cooperate fully with your assessment and any remediation.
8.1 On termination, Schedule B clause 12 governs the export. You get a full export, free, within 10 Business Days of asking: structured records in CSV or JSON, files and media in their native format within a ZIP archive, and a manifest identifying what is provided, covering contacts with all custom fields and tags, notes, conversation history, appointment history, transaction records and uploaded files.
8.2 Access to the Systems continues for 30 days from termination so you can check the export.
8.3 We retain your data for 90 days after access ends, then delete it. That window exists so you can come back if something was missed.
8.4 You may ask us to delete it sooner, in writing, and we will, subject to anything we must keep by law.
8.5 We will confirm deletion in writing when it is done.
8.6 Backups. Data may persist in encrypted backups after deletion from live systems. Those backups are overwritten on their normal cycle, which does not exceed 90 days, and nothing is restored from them for any purpose other than disaster recovery.
9.1 On reasonable written notice, once in any 12 month period, you may ask us to demonstrate compliance with this Schedule.
9.2 We will respond by providing written information about our controls, our sub-processors and our practices. We do not offer on-site audits or access to our systems, because our systems hold other clients' data and their confidentiality is not ours to waive.
9.3 Where you reasonably require more than clause 9.2 provides, we will discuss it in good faith.
10.1 Clause 10 of the Master Terms governs how we use AI.
10.2 Where Systems we build for you make, or materially contribute to, automated decisions about individuals, we will tell you what those decisions are and what personal information they use, so that you can meet your own transparency obligations.
10.3 From 10 December 2026, Australian Privacy Principles 1.7 to 1.9 require a covered entity's privacy policy to disclose automated decision-making where the decision could reasonably be expected to significantly affect an individual's rights or interests. That obligation is yours, not ours, for decisions made in your Systems. We will give you the description you need to meet it.
10.4 On request we will provide an automated decision-making statement for your account, listing the kinds of personal information used and the kinds of decisions made or supported.
11.1 Where this Schedule conflicts with another Schedule on the handling of personal information, this Schedule wins.
11.2 Where a separate data processing agreement is signed between us, that agreement wins over this Schedule.
Privacy and data enquiries: [email protected]
Rev-Raise Group Pty Ltd ABN 45 691 400 594 Brisbane, QLD, Australia
© 2026 Rev-Raise Group Pty Ltd (ABN 45 691 400 594). All rights reserved.