Navigate Network
ComputeSovereigntyUse casesPricingCompany
Talk to sales→
ComputeSovereigntyUse casesPricingCompany
Talk to sales→
Trust · Data Processing Addendum

How we process personal data on your behalf.

This Data Processing Addendum forms part of the Navigate Network Master Services Agreement. It applies whenever we process Customer personal data in providing the Services, and incorporates the Standard Contractual Clauses by reference where they apply.

OperatorAdd Data Pty Ltd
Version2.0
Last updated3 January 2026
Contactlegal@navigate.network

This Data Processing Addendum (the “DPA”) forms part of the Master Services Agreement between Navigate Network (Add Data Pty Ltd) and the Customer (the “Agreement”) and applies whenever Navigate Network processes Personal Data on the Customer’s behalf in providing the Services. It incorporates the Standard Contractual Clauses by reference where they apply. If there is a conflict on data-protection matters, this DPA prevails over the Agreement.

01 · Section

Definitions

“Applicable Data Protection Law”
All laws and regulations applicable to a party's processing of Personal Data under this DPA, including the Privacy Act 1988 (Cth) and the Australian Privacy Principles and, where applicable, the GDPR and other equivalent laws.
“Customer Data”
The Personal Data the Customer or its users upload to, or process using, the Services.
“Controller, Processor, Data Subject, Personal Data, Personal Data Breach, processing”
Have the meanings given under Applicable Data Protection Law (and, where it applies, the GDPR).
“Platform Controls”
The security features, configuration options and tools that Navigate Network makes available for the Customer to use in securing and managing its own environment and Customer Data.
“Standard Contractual Clauses”
The contractual clauses for the transfer of personal data approved under Commission Implementing Decision (EU) 2021/914 (controller-to-processor or processor-to-processor, as applicable), together with the UK International Data Transfer Addendum and any Swiss amendments where relevant.
“Sub-processor”
A third party engaged by Navigate Network to process Customer Data.
02 · Section

Scope and roles.

This DPA applies where Customer Data is processed by Navigate Network. In that context, the Customer is the Controller (or a processor acting for a third-party controller) and Navigate Network is the Processor. Because the Services include bare-metal and infrastructure offerings, the Customer retains direct control of, and responsibility for, the operating system, applications and Customer Data running on the infrastructure, and Navigate Network does not access Customer Data except as set out in Section 4.

03 · Section

Customer instructions.

This DPA and the Agreement (including the Customer’s use of Platform Controls and configuration options) are the Customer’s complete and documented instructions for Navigate Network’s processing of Customer Data. Navigate Network will process Customer Data only on those instructions, except where required by law (in which case it will notify the Customer unless legally prohibited). Instructions outside the documented scope require prior written agreement, including on any additional fees. If Navigate Network forms the view that an instruction infringes Applicable Data Protection Law, it will promptly inform the Customer, who may then withdraw or modify the instruction.

04 · Section

Confidentiality of Customer Data & government requests.

Navigate Network will not access, use, or disclose Customer Data to any third party except as necessary to provide or maintain the Services, or as required to comply with the law or a valid and binding order of a governmental body. If a governmental body demands Customer Data, Navigate Network will, where lawfully able, attempt to redirect the body to seek the data directly from the Customer, and may provide the Customer’s basic contact details for that purpose. If compelled to disclose, Navigate Network will give the Customer reasonable prior notice to allow it to seek a protective order, unless legally prohibited from doing so.

05 · Section

Confidentiality of personnel.

Navigate Network restricts access to Customer Data to personnel who need it to provide the Services, and ensures those personnel are bound by appropriate obligations of confidentiality and trained on their data-protection and security responsibilities.

06 · Section

Security of processing.

Navigate Network will implement and maintain the technical and organisational measures described in Annex 2, designed to protect Customer Data against accidental or unlawful destruction, loss, alteration, and unauthorised disclosure or access. Navigate Network may update those measures provided the level of protection is not materially reduced. The Customer is responsible for assessing whether those measures, together with its own use of Platform Controls, meet its requirements.

07 · Section

Customer responsibilities.

  • Configuring the Services and its environment securely, and managing access to its accounts and credentials;
  • Encrypting Customer Data and managing keys as it considers appropriate;
  • Backing up and archiving Customer Data so it can restore availability after an incident;
  • Ensuring it has a lawful basis and any necessary consents for the Customer Data it processes using the Services.
08 · Section

Sub-processors

The Customer provides general authorisation for Navigate Network to engage Sub-processors. Navigate Network will: (a) restrict each Sub-processor’s access to what is necessary to provide the Services; (b) enter a written agreement imposing data-protection obligations no less protective than this DPA; and (c) remain responsible for each Sub-processor’s performance. A current list of Sub-processors is at Annex 3. Navigate Network will give the Customer at least 30 days’ notice before adding or replacing a Sub-processor, and the Customer may object on reasonable data-protection grounds; if the parties cannot resolve the objection, the Customer may stop using the affected part of the Services or terminate the relevant Order Form.

09 · Section

Assistance with data subject requests.

Taking into account the nature of the processing, Navigate Network will assist the Customer (including through Platform Controls) to respond to requests by Data Subjects to exercise their rights. If a Data Subject makes a request directly to Navigate Network, Navigate Network will promptly forward it to the Customer and will not respond to the substance of the request itself, except to confirm that it has been forwarded.

10 · Section

Personal Data breach notification.

Navigate Network will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Data, take appropriate measures to mitigate and remediate it, and provide the Customer with the information then available to help the Customer meet its own notification obligations. The Customer is responsible for determining whether the breach requires notification to a regulator or Data Subjects and for making any such notification.

Unsuccessful security events that result in no unauthorised access to Customer Data — such as failed log-in attempts, port scans, pings, or blocked denial-of-service attempts — are not Personal Data Breaches under this Section. Navigate Network’s notification of, or response to, a Personal Data Breach is not an acknowledgement of fault or liability.

11 · Section

Data protection impact assessments.

Taking into account the nature of the processing and the information available to it, Navigate Network will provide reasonable assistance to the Customer with data-protection impact assessments and any prior consultation with a supervisory authority, primarily by making available the information in this DPA and the materials referred to in Section 12.

12 · Section

Certifications & audits.

Navigate Network uses independent third parties to assess its security measures at least annually and, on the Customer’s written request and subject to confidentiality, will make available its current certifications and summary audit reports so the Customer can verify compliance with this DPA. The Customer’s audit rights under Applicable Data Protection Law are satisfied by the provision of those reports. Where Applicable Data Protection Law or a supervisory authority nonetheless requires an on-site audit, it will be conducted on reasonable prior notice, during business hours, no more than once per year (absent a regulator requirement or a known breach), subject to confidentiality, and without compromising other customers’ security, with each party bearing its own costs.

13 · Section

International transfers.

The Customer may specify the region(s) in which Customer Data is processed. Navigate Network and its Sub-processors may process Customer Data in countries outside the Customer’s region — including the United States, the EEA, and Asia-Pacific — only as necessary to provide the Services or to comply with law. Where a transfer of Personal Data subject to the GDPR is made to a country without an adequacy decision, the applicable Standard Contractual Clauses apply (controller-to-processor where the Customer is a controller, processor-to-processor where the Customer is a processor), supplemented by the UK Addendum or Swiss amendments where relevant. For Personal Data subject to the Privacy Act, Navigate Network will take reasonable steps consistent with Australian Privacy Principle 8 before disclosing it overseas. The Standard Contractual Clauses will not apply where Navigate Network adopts an alternative recognised transfer mechanism.

14 · Section

Duties to inform.

If Customer Data becomes subject to confiscation, or to bankruptcy or insolvency proceedings or similar third-party measures while being processed by Navigate Network, Navigate Network will inform the Customer without undue delay and will notify the relevant parties that the Customer Data is the Customer’s property and under the Customer’s sole control.

15 · Section

Return or deletion of Customer Data.

On termination of the Agreement, and for up to 90 days afterwards, Navigate Network will, at the Customer’s choice, return or delete Customer Data, except where retention is required by law. After that period, Navigate Network may delete Customer Data remaining in its systems.

16 · Section

Liability

Each party’s liability under or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Agreement.

17 · Section

Term, conflict & precedence.

This DPA takes effect on the Effective Date and continues until the Agreement ends. It incorporates the Standard Contractual Clauses by reference where they apply, and nothing in this DPA varies them. Except as amended here, the Agreement remains in effect; if there is a conflict on data-protection matters, this DPA prevails.

Annex 01 · Processing

Details of processing.

The subject matter, duration, nature and purpose of processing, the types of Personal Data, the categories of Data Subjects, and the processing locations for a Customer’s use of the Services are set out in the applicable Order Form and recorded in a completed Annex 1 on execution of this DPA. On request, Navigate Network will provide a completed Annex 1 for the Customer’s deployment.

Annex 02 · Security

Security standards.

Navigate Network maintains an information security program designed to protect Customer Data and the infrastructure used to provide the Services, including the following measures. The program is reviewed periodically and updated to address new risks.

01Logical security

  • Access controls and authentication restricting the platform to authorised personnel, with tenant isolation between customers;
  • Least-privilege access, approval before elevated/administrator access, periodic access reviews, and multi-factor authentication for remote access;
  • Regular vulnerability assessments and penetration testing, with tracked remediation;
  • Change management — logging, testing, approval and documentation of changes, and detection of unauthorised changes;
  • Data integrity controls in transit and at rest, and the ability to delete Customer Data;
  • Secure media decommissioning (degauss, purge or physical destruction) before disposal.

02Physical security

  • 24/7 guarded data-centre facilities with biometric or multi-factor rack access and CCTV with retention;
  • Intrusion detection, logging and periodic review of physical access;
  • Redundant power, cooling and network designed to tolerate hardware failure.

03Personnel

  • Security-awareness training, reviewed at least annually;
  • Background checks for personnel where permitted by law, appropriate to their level of access;
  • Confidentiality obligations binding on personnel with access to Customer Data.

04Business continuity & incident response

  • Backups, snapshots and documented recovery objectives (aligned to the SLA);
  • A documented incident-response process to detect, contain, investigate and report security incidents;
  • A business-continuity and disaster-recovery program for events that could materially impair the Services.
Annex 03 · Sub-processors

Approved sub-processors.

The following Sub-processors are currently engaged by Navigate Network to process Customer Data. Navigate Network will give at least 30 days’ notice before adding or replacing a Sub-processor.

Sub-processorService providedLocation
Equinix Services Inc.Secure hosting of our application and database, data backupsAustralia (Sydney)
NextDC Pty LtdSecure hosting of our application and database, data backupsAustralia (Sydney)
Amazon Corporate Services Pty LtdSecondary storage and data backupsAustralia (Sydney)
Cloudflare, Inc.DNS hosting, Web Application Firewall (WAF), DDoS protection, traffic routing, CDNGlobal (including Australia/USA)
Xero Australia Pty LimitedAccounting and invoicingAustralia / New Zealand
Stripe Payments Australia Pty LtdCredit card payment processing and PCI complianceGlobal (including Australia/USA)
Google, LLCBusiness User data, End Customers' data and Visitors' dataGlobal (including Australia/USA)
Twilio, Inc.Business User data and End Customer dataGlobal (including Australia/USA)

Execution. This page is the current published version of the DPA incorporated into the Navigate Network Master Services Agreement. For a signed counterpart or to complete Annex 1 for a specific deployment, contact legal@navigate.network.

Questions about this DPA?

legal@navigate.network →
Navigate Network

Australian-headquartered neocloud for AI workloads. Sydney · Melbourne · Singapore · Kuala Lumpur · Dubai · Riyadh · Jakarta (soon) · Perth (2027).

Product

  • Compute
  • Pricing
  • Sovereignty
  • Use cases

Company

  • About
  • Careers
  • Press
  • Contact

Trust

  • SLA
  • Privacy
  • Terms
  • Acceptable Use
  • DPA
© 2026 NAVIGATE NETWORK · ABN 82 652 866 263Made in Sydney · Powered by Add Data