CommonMind
How it worksPlatform demoAbout
Sign inTry it free
Legal

Data Processing Agreement

How CommonMind processes personal data on your behalf, and the commitments that come with it.

Last updated 23 September 2026

This Data Processing Agreement (“DPA”) forms part of the agreement between your business (“Controller”, “you”) and CommonMind Pty Ltd (“Processor”, “we”, “us”) for the processing of personal data in connection with the CommonMind platform.

CommonMind operates two products — Construction Intelligence (tender analysis, shown in the application as “Trace”) and Venue Intelligence(hospitality). Where a clause applies to only one of them, it says so.

1. Parties and roles

Controller:The business entity that creates an account and uploads data to CommonMind — the contractor, or the venue operator.
Processor:CommonMind Pty Ltd, which processes data on behalf of the Controller to provide the intelligence platform services.

The Controller determines the purposes and means of processing. The Processor processes data only on documented instructions from the Controller, as described in this DPA and the Terms of Service.

2. Purpose of processing

We process your data for the following purposes.

Both products:

  • •Running analysis to detect signals, patterns, risks and anomalies in the data you provide.
  • •Generating findings, recommendations and drafts for the Controller’s own review and decision.
  • •Operating, securing, supporting and auditing the platform.

Construction Intelligence:

  • •Ingesting, parsing, classifying and indexing tender documents supplied by the Controller.
  • •Recording the Controller’s own judgements, decisions, actions and outcomes, and using them to improve analysis for that Controller only.

Construction data is never contributed to any pool, aggregate or cross-customer product without the Controller’s separate opt-in. With it, and only with it, the Controller’s tenders may be counted in (a) totals published on commonmind.co — rounded down, only once at least five consenting firms and A$100 million of tender value are counted, never naming a firm — and (b) de-identified pattern statistics across at least five consenting organisations, shown to a customer only as counts and only once that floor is met. Either consent is given, and may be withdrawn at any time, by the Controller’s administrator in the product’s Team settings or in writing to CommonMind. A de-identified record of the kinds of issue in each tender (no document text, names, prices or values) is kept, marked with the Controller’s consent, so that consent can be honoured; it is deleted with the tender or the organisation.

Venue Intelligence:

  • •Ingesting and normalising venue operational data (POS, invoices, rosters).
  • •Contributing de-identified aggregate data points to the network intelligence pool, subject to a minimum of five contributing businesses and to the Controller’s right to opt out.

3. Types of data processed

Data categoryExamples
Tender documents (construction)Specifications, drawings, bills of quantities, contracts, addenda, scans. May incidentally contain names and contact details of individuals appearing in the documents
Commercial records (construction)Declared estimates, supplier quotations, bid and no-bid decisions, awards, recorded outcomes
Judgement records (construction)Verdicts, severity overrides and assignments recorded by named users against findings
POS transactions (venue)Sales records, item-level data, payment breakdowns, revenue summaries
Invoice data (venue)Supplier invoices, purchase orders, cost-of-goods records
Roster data (venue)Staff schedules, labour hours, wage cost summaries
Business metadataBusiness name, type, location, operational configuration; for construction, the company profile (sectors, geography, value range, delivery methods, capabilities)
Account dataUser names, email addresses, hashed passwords

We do not process personal data of your customers or patrons. Transaction data does not include individual customer identities.

For construction, we do not seek personal information. Tender documents may incidentally contain names, signatures or contact details of individuals — a consultant on a title block, a signatory to a contract. Such information is processed only as an inseparable part of the document, and is not extracted, indexed or used for any separate purpose. We do not ask for and do not want employee records, payroll data, or personal information about site workers.

4. Security measures

We implement the following technical and organisational measures:

  • •Encryption in transit: TLS 1.2+ for all data in motion.
  • •Encryption at rest: object storage uses server-side AES-256 encryption; other stored data resides on provider-managed encrypted volumes. Construction: every document is additionally encrypted by the application (Fernet: AES-128-CBC with HMAC-SHA256) before it reaches storage, and the database and document storage are encrypted with AWS KMS keys.
  • •Access controls: Role-based access and audit logging. Construction: per-organisation isolation enforced by the application and, beneath it, by database row-level security; sign-in is by a one-time code sent to the person’s work email, and only addresses the Controller’s own pilot link admits can join its workspace; a code from an authenticator app is additionally required to delete or export tender data, to change who has access and to change consents, and CommonMind staff need one to create a workspace, make its sign-in link or change its tender allowance; no standing staff access — support access is a time-limited, read-only grant with a written reason, visible to and revocable by the Controller, with every use recorded; uploaded files are virus-scanned and anything not clean is quarantined. Venue: per-venue data isolation.
  • •De-identification: a minimum of five contributing businesses (venue) or five consenting organisations (construction) before any cross-customer figure is produced, with identifiers removed. We call this de-identified, not anonymous: that is the claim the implementation supports.
  • •Infrastructure: Construction: AWS in the Sydney region (ap-southeast-2) for the application, the database and document storage, with Vercel for the web app. Venue: Vercel for the web app and Railway for the application backend, with object storage in AWS S3 Sydney. Our infrastructure providers maintain their own SOC 2 / ISO 27001 programs.

5. Sub-processors

We use the following sub-processors to deliver the service:

Sub-processorPurposeLocation
VercelWeb application hosting (frontend) — both productsUS / global edge
Amazon Web ServicesConstruction: application hosting, the database and encrypted document storage. Venue: encrypted object storage for uploaded filesSydney, Australia (ap-southeast-2)
SupabaseSign-in (both products); database services (venue)US / global
OpenRouter, and the host it routes toLLM inference. Construction: passages of tender documents are sent to produce findings, routed to a host serving the configured model — currently Claude Opus 5.5 (anthropic/claude-opus-5.5, Anthropic) to write findings and GPT-6 Luna (openai/gpt-6-luna, OpenAI) to check them — with providers that train on prompts excluded (a provider may retain prompts for a limited period to monitor abuse); the Controller may ask for the AI reading to be switched off. Venue: operational context is sent to generate analysis, forecasts and drafts, routed to third-party model providers per configuration.US / global; may be outside Australia
RailwayApplication backend hosting and compute (venue)US
OpenAIText embeddings (venue). Construction sends nothing to OpenAI unless the Controller asks for meaning-based search to be enabledUS
Together AILLM inference fallback (venue)US
DatabricksAnalytics and ML processingAustralia / US
Resend / PostmarkEmail delivery — only for messages you approve to sendUS
TwilioSMS delivery — only for messages you approve to sendUS
SquarePOS price updates — only when you connect SquareUS
Google (Places)Venue and neighbourhood reference dataUS / global
NewsAPILocal news headlines for contextUS / EU

We will notify you before engaging any new sub-processor. You may object to a new sub-processor within 30 days of notification.

6. Data breach notification

In the event of a personal data breach, we will:

  • •Notify you within 72 hours of becoming aware of the breach.
  • •Provide details of the nature of the breach, categories and approximate number of records affected, and likely consequences.
  • •Describe the measures taken or proposed to address the breach and mitigate its effects.
  • •Cooperate with you in meeting your obligations under the Notifiable Data Breaches (NDB) scheme under the Australian Privacy Act.

7. Deletion on termination

Upon termination of the service agreement:

  • •Construction: the Controller’s organisation is deleted from the live service — documents, findings, records and the de-identified pattern records — as soon as it is requested. Copies in database backups and in the document store’s version history expire within 90 days. The audit trail of who accessed or changed what, and a record that the deletion happened, are kept so the deletion can be verified; they hold account and action details, not documents. Totals already published are not recalculated retrospectively.
  • •Venue: all identifiable venue data will be deleted from our systems within 30 days.
  • •We will provide a data export upon request before deletion.
  • •Venue: de-identified data already in the network intelligence pool is retained, as it cannot be attributed to any individual venue.
  • •We will provide written confirmation of deletion upon request.

8. Audit rights

You have the right to audit our compliance with this DPA. We will make available all information necessary to demonstrate compliance and allow for reasonable audits, including inspections, conducted by you or an auditor you appoint. Audits should be conducted with reasonable notice and during normal business hours.

Contact

For questions about this DPA or to exercise any rights, contact us at:

contact@commonmind.co

How it worksPlatform demoAboutQuestionsSign in© 2026 CommonMind Pty Ltd · Melbourne
PrivacyTermsData Processing