Data Processing Addendum
Schedule 1 to the Terms · Last updated: 7 October 2026
This Data Processing Addendum (DPA) forms part of the Terms between AI Core CRM Pty Ltd (ABN 77 670 376 879), trading as Effica, and the Customer. It explains how Effica handles personal information that the Customer and its Users put into Effica (Customer Personal Information). For personal information, this DPA prevails over the rest of the Terms. A data agreement that both parties sign separately prevails over this DPA.
1. Who decides what
The Customer decides why and how Customer Personal Information is used. Effica handles it only to provide, secure and support the service, to follow the Customer's instructions, and to comply with the law. The Customer's instructions are this agreement, the settings it chooses in Effica, and requests made by its authorised Users. If Effica believes an instruction breaks the law, it will tell the Customer and need not follow it.
Each party remains responsible for its own obligations under the Privacy Act 1988 (Cth), the Australian Privacy Principles, and NDIS and other laws that apply to it.
2. Information and people covered
Customer Personal Information can be about participants (including children), their families, guardians, nominees and contacts, the Customer's workers and contractors, and Users. It can include names and contact details, dates of birth, NDIS numbers and other government identifiers, health and disability information, support plans, notes, incidents, photos, audio, signatures, worker location during enabled shift workflows, and payroll and billing records.
3. People and security
Effica limits access to Customer Personal Information to staff and contractors who need it for the service. They are bound by confidentiality. Support access to a Customer's workspace is recorded with the reason given.
Effica maintains the safeguards described on its Security page. These include tenant separation enforced in the database, encryption in transit and at rest, extra encryption for selected high-risk records, two-step sign-in, an activity record kept for 7 years, and encrypted backups copied to a second Australian region and restored in regular drills. Effica may improve these safeguards but will not materially weaken them during the subscription.
4. Where information is stored and processed
Customer Personal Information is stored in Australia: in Sydney, with a standby copy and backups in Melbourne. Some services process information outside Australia, mainly in the United States: AI features and onboarding imports (OpenAI), email delivery (Resend) and push notifications (Expo, Apple and Google). Effica sends each supplier only what the service needs, holds contracts that protect the information, and takes reasonable steps so that suppliers handle it consistently with the Australian Privacy Principles.
5. Sub-processors
Effica uses the suppliers listed on its Sub-processors page and remains responsible for them. Before a new supplier starts handling Customer Personal Information, Effica will email the Customer's owners at least 30 days ahead. If a supplier must be replaced urgently for security or availability, Effica will tell owners as soon as it reasonably can.
The Customer may object in writing within that notice period, giving reasonable grounds. The parties will try in good faith to resolve the objection. If they cannot, the Customer may end the affected service and receive a pro-rata refund of fees it prepaid for the remaining period.
6. AI features
AI features work as described in section 6 of the Terms. Before any information is sent to an AI model, Effica Shield replaces tax file, Medicare, healthcare identifier, NDIS, Centrelink, DVA, passport, driver's licence, card and bank numbers with labels, and some documents are never sent at all. Names and care details are sent when the task needs them. OpenAI does not use the information to train its models. It may keep requests for up to 30 days to detect misuse, then deletes them. New participant records start with AI switched on. The Customer can switch AI off for its organisation or for any participant at any time.
7. Security incidents
Effica will notify the Customer without undue delay, and within 72 hours, after it confirms a security incident affecting Customer Personal Information. The notice will say what is known about what happened, the information and people affected, and the steps taken. Effica will update the Customer as it learns more, contain the incident, and help the Customer assess it under the Notifiable Data Breaches scheme. The parties will agree who notifies affected people and the OAIC, so that people receive one clear notice.
8. Requests from individuals and regulators
The Customer answers requests from people whose records it holds, such as access or correction requests. Effica provides tools for this, including record exports, and gives reasonable help when asked. If Effica receives such a request directly, it will pass it to the Customer within 5 business days, unless the request concerns Effica's own records.
If the law requires Effica to disclose Customer Personal Information to a government body or court, Effica will tell the Customer first unless the law prevents it, and disclose only what is required.
9. Keeping and deleting information
During the subscription, information is kept according to the Customer's records and settings and the periods in the Privacy Policy. The Customer is responsible for keeping records for as long as NDIS and other laws require it to.
When access ends, the Customer can ask for an export of its records within 30 days. Within 90 days after access ends, Effica will delete or de-identify Customer Personal Information in the live service. Backup copies are deleted as they expire, within a further 35 days. Effica keeps only what the law, a dispute, or a written agreement requires, and restricts access to that purpose.
10. Evidence and audits
Once a year, and after any security incident affecting the Customer, the Customer may ask for information showing how Effica meets this DPA. Effica will answer reasonable security questionnaires and share its security overview, relevant policies and its suppliers' certifications. An on-site audit needs both parties' agreement on scope, timing and cost, except where a regulator requires it.
11. Contact
Privacy and data-handling questions go to info@effica.com.au or Unit 2, 59 Pennington Terrace, North Adelaide SA 5006, Australia.