Data Processing Agreement
How CommonMind processes personal data on your behalf, and the commitments that come with it.
This Data Processing Agreement (“DPA”) forms part of the agreement between your business (“Controller”, “you”) and CommonMind Pty Ltd (“Processor”, “we”, “us”) for the processing of personal data in connection with the CommonMind platform.
CommonMind operates two products — Construction Intelligence (tender analysis, shown in the application as “Trace”) and Venue Intelligence(hospitality). Where a clause applies to only one of them, it says so.
1. Parties and roles
The Controller determines the purposes and means of processing. The Processor processes data only on documented instructions from the Controller, as described in this DPA and the Terms of Service.
2. Purpose of processing
We process your data for the following purposes.
Both products:
- •Running analysis to detect signals, patterns, risks and anomalies in the data you provide.
- •Generating findings, recommendations and drafts for the Controller’s own review and decision.
- •Operating, securing, supporting and auditing the platform.
Construction Intelligence:
- •Ingesting, parsing, classifying and indexing tender documents supplied by the Controller.
- •Recording the Controller’s own judgements, decisions, actions and outcomes, and using them to improve analysis for that Controller only.
Construction data is never contributed to any pool, aggregate or cross-customer product without the Controller’s separate opt-in. With it, and only with it, the Controller’s tenders may be counted in (a) totals published on commonmind.co — rounded down, only once at least five consenting firms and A$100 million of tender value are counted, never naming a firm — and (b) de-identified pattern statistics across at least five consenting organisations, shown to a customer only as counts and only once that floor is met. Either consent is given, and may be withdrawn at any time, by the Controller’s administrator in the product’s Team settings or in writing to CommonMind. A de-identified record of the kinds of issue in each tender (no document text, names, prices or values) is kept, marked with the Controller’s consent, so that consent can be honoured; it is deleted with the tender or the organisation.
Venue Intelligence:
- •Ingesting and normalising venue operational data (POS, invoices, rosters).
- •Contributing de-identified aggregate data points to the network intelligence pool, subject to a minimum of five contributing businesses and to the Controller’s right to opt out.
3. Types of data processed
| Data category | Examples |
|---|---|
| Tender documents (construction) | Specifications, drawings, bills of quantities, contracts, addenda, scans. May incidentally contain names and contact details of individuals appearing in the documents |
| Commercial records (construction) | Declared estimates, supplier quotations, bid and no-bid decisions, awards, recorded outcomes |
| Judgement records (construction) | Verdicts, severity overrides and assignments recorded by named users against findings |
| POS transactions (venue) | Sales records, item-level data, payment breakdowns, revenue summaries |
| Invoice data (venue) | Supplier invoices, purchase orders, cost-of-goods records |
| Roster data (venue) | Staff schedules, labour hours, wage cost summaries |
| Business metadata | Business name, type, location, operational configuration; for construction, the company profile (sectors, geography, value range, delivery methods, capabilities) |
| Account data | User names, email addresses, hashed passwords |
We do not process personal data of your customers or patrons. Transaction data does not include individual customer identities.
For construction, we do not seek personal information. Tender documents may incidentally contain names, signatures or contact details of individuals — a consultant on a title block, a signatory to a contract. Such information is processed only as an inseparable part of the document, and is not extracted, indexed or used for any separate purpose. We do not ask for and do not want employee records, payroll data, or personal information about site workers.
4. Security measures
We implement the following technical and organisational measures:
- •Encryption in transit: TLS 1.2+ for all data in motion.
- •Encryption at rest: object storage uses server-side AES-256 encryption; other stored data resides on provider-managed encrypted volumes. Construction: every document is additionally encrypted by the application (Fernet: AES-128-CBC with HMAC-SHA256) before it reaches storage, and the database and document storage are encrypted with AWS KMS keys.
- •Access controls: Role-based access and audit logging. Construction: per-organisation isolation enforced by the application and, beneath it, by database row-level security; sign-in is by a one-time code sent to the person’s work email, and only addresses the Controller’s own pilot link admits can join its workspace; a code from an authenticator app is additionally required to delete or export tender data, to change who has access and to change consents, and CommonMind staff need one to create a workspace, make its sign-in link or change its tender allowance; no standing staff access — support access is a time-limited, read-only grant with a written reason, visible to and revocable by the Controller, with every use recorded; uploaded files are virus-scanned and anything not clean is quarantined. Venue: per-venue data isolation.
- •De-identification: a minimum of five contributing businesses (venue) or five consenting organisations (construction) before any cross-customer figure is produced, with identifiers removed. We call this de-identified, not anonymous: that is the claim the implementation supports.
- •Infrastructure: Construction: AWS in the Sydney region (ap-southeast-2) for the application, the database and document storage, with Vercel for the web app. Venue: Vercel for the web app and Railway for the application backend, with object storage in AWS S3 Sydney. Our infrastructure providers maintain their own SOC 2 / ISO 27001 programs.
5. Sub-processors
We use the following sub-processors to deliver the service:
| Sub-processor | Purpose | Location |
|---|---|---|
| Vercel | Web application hosting (frontend) — both products | US / global edge |
| Amazon Web Services | Construction: application hosting, the database and encrypted document storage. Venue: encrypted object storage for uploaded files | Sydney, Australia (ap-southeast-2) |
| Supabase | Sign-in (both products); database services (venue) | US / global |
| OpenRouter, and the host it routes to | LLM inference. Construction: passages of tender documents are sent to produce findings, routed to a host serving the configured model — currently Claude Opus 5.5 (anthropic/claude-opus-5.5, Anthropic) to write findings and GPT-6 Luna (openai/gpt-6-luna, OpenAI) to check them — with providers that train on prompts excluded (a provider may retain prompts for a limited period to monitor abuse); the Controller may ask for the AI reading to be switched off. Venue: operational context is sent to generate analysis, forecasts and drafts, routed to third-party model providers per configuration. | US / global; may be outside Australia |
| Railway | Application backend hosting and compute (venue) | US |
| OpenAI | Text embeddings (venue). Construction sends nothing to OpenAI unless the Controller asks for meaning-based search to be enabled | US |
| Together AI | LLM inference fallback (venue) | US |
| Databricks | Analytics and ML processing | Australia / US |
| Resend / Postmark | Email delivery — only for messages you approve to send | US |
| Twilio | SMS delivery — only for messages you approve to send | US |
| Square | POS price updates — only when you connect Square | US |
| Google (Places) | Venue and neighbourhood reference data | US / global |
| NewsAPI | Local news headlines for context | US / EU |
We will notify you before engaging any new sub-processor. You may object to a new sub-processor within 30 days of notification.
6. Data breach notification
In the event of a personal data breach, we will:
- •Notify you within 72 hours of becoming aware of the breach.
- •Provide details of the nature of the breach, categories and approximate number of records affected, and likely consequences.
- •Describe the measures taken or proposed to address the breach and mitigate its effects.
- •Cooperate with you in meeting your obligations under the Notifiable Data Breaches (NDB) scheme under the Australian Privacy Act.
7. Deletion on termination
Upon termination of the service agreement:
- •Construction: the Controller’s organisation is deleted from the live service — documents, findings, records and the de-identified pattern records — as soon as it is requested. Copies in database backups and in the document store’s version history expire within 90 days. The audit trail of who accessed or changed what, and a record that the deletion happened, are kept so the deletion can be verified; they hold account and action details, not documents. Totals already published are not recalculated retrospectively.
- •Venue: all identifiable venue data will be deleted from our systems within 30 days.
- •We will provide a data export upon request before deletion.
- •Venue: de-identified data already in the network intelligence pool is retained, as it cannot be attributed to any individual venue.
- •We will provide written confirmation of deletion upon request.
8. Audit rights
You have the right to audit our compliance with this DPA. We will make available all information necessary to demonstrate compliance and allow for reasonable audits, including inspections, conducted by you or an auditor you appoint. Audits should be conducted with reasonable notice and during normal business hours.
Contact
For questions about this DPA or to exercise any rights, contact us at:
