Data Processing Agreement
Effective 21 June 2026 · Last updated 21 June 2026
Effective date: 21 June 2026 Last updated: 21 June 2026
In short: This Data Processing Agreement ("DPA") governs how IVS Digital Limited processes the Client Personal Information that a Broker uploads, forwards or generates in InsuredIn. It records that the Broker is the agency (controller) of that information and that IVS Digital processes it on the Broker's behalf as the Broker's service provider (processor). It forms part of, and is incorporated by reference into, the InsuredIn Terms & Conditions (the "Terms", clause 8.5), and a separately countersigned copy is available to enterprise Brokers on request. Capitalised terms not defined here have the meaning given in the Terms or the Privacy Policy.
1. Roles and scope
1.1 Roles. Under the New Zealand Privacy Act 2020, the Broker is the agency responsible for the Client Personal Information it holds in the Platform, and IVS Digital acts on the Broker's behalf and on its instructions in processing that information. In controller/processor terms, the Broker is the controller and IVS Digital is the processor (service provider). For individuals in Australia, the Broker is the APP entity responsible for the personal information and IVS Digital handles it on the Broker's behalf.
1.2 What this DPA covers. This DPA applies only to Client Personal Information that IVS Digital processes on the Broker's behalf. It does not apply to the Broker's own account information (such as the Broker's business and billing details and its users' login details), for which IVS Digital is the agency in its own right — that information is governed by the Privacy Policy, not this DPA.
1.3 Details of processing. The subject matter, duration, nature and purpose of the processing, the types of Client Personal Information, and the categories of individuals are set out in Schedule 1.
2. The Broker's instructions
2.1 Processing on instructions. IVS Digital will process Client Personal Information only:
(a) to provide, secure, maintain, support and improve the Platform in accordance with the Terms;
(b) as further instructed by the Broker through its configuration and use of the Platform's features; and
(c) as required by law (and where the law requires processing, IVS Digital will, where it is lawfully able, inform the Broker before processing).
2.2 Broker warranties. The Broker warrants that its instructions, and its provision of Client Personal Information to the Platform, comply with applicable law, and that it has all necessary authority and consents to do so (see clause 8 of the Terms).
2.3 Unlawful instructions. IVS Digital will inform the Broker if, in its reasonable opinion, an instruction infringes applicable privacy law. IVS Digital is not obliged to provide legal advice and is not responsible for the lawfulness of the Broker's instructions.
3. Confidentiality and personnel
3.1 IVS Digital will treat Client Personal Information as Confidential Information under section 9A of the Terms, will ensure that personnel authorised to process it are bound by appropriate confidentiality obligations, and will limit access to those personnel (and authorised sub-processors) who need it to perform their role.
4. Security
4.1 Security measures. IVS Digital will implement and maintain appropriate technical and organisational measures to protect Client Personal Information against loss, misuse and unauthorised access, use, modification or disclosure, consistent with IPP 5 of the Privacy Act 2020 and APP 11. Current measures are summarised in Schedule 1 and include encryption in transit and at rest, multi-tenant isolation using row-level security, access controls, and audit logging.
4.2 Changes. IVS Digital may update its security measures from time to time, provided the overall level of protection is not materially reduced.
5. Sub-processors
5.1 Authorisation. The Broker authorises IVS Digital to engage the sub-processors listed in the InsuredIn Privacy Policy (as updated from time to time) to process Client Personal Information, under contracts that require data-protection obligations consistent with this DPA.
5.2 Responsibility. IVS Digital remains responsible for its sub-processors' performance of the obligations in this DPA.
5.3 Change notification. Before adding or replacing a sub-processor that processes Client Personal Information, IVS Digital will update the sub-processor list in the Privacy Policy and, where the Broker has subscribed to sub-processor notifications, give the Broker at least 30 days' prior notice. If the Broker reasonably objects on data-protection grounds within that notice period, the parties will discuss the objection in good faith; if it cannot be resolved, the Broker's remedy is to stop using, or to terminate, the affected part of the Platform in accordance with the Terms.
6. Overseas (cross-border) handling
6.1 Where processing occurs. Client Personal Information is stored and processed as described in the Privacy Policy. The primary database, document and file storage, inbound email, the application's server-side compute, and the AI extraction all occur in Australia (Sydney). Some ancillary processing — such as outbound transactional email, billing, and delivery through a global content-delivery edge — occurs outside New Zealand and Australia.
6.2 Safeguards. Where Client Personal Information is processed outside New Zealand, IVS Digital relies on contractual safeguards requiring privacy protections comparable to those under the Privacy Act 2020, consistent with IPP 12 and (for Australia) APP 8.
7. Assistance to the Broker
7.1 Individuals' requests. Taking into account the nature of the processing, IVS Digital will provide reasonable assistance (including through Platform functionality) to help the Broker respond to requests from individuals to access or correct their Personal Information under IPPs 6 and 7 of the Privacy Act 2020 and APPs 12 and 13. If IVS Digital receives such a request directly from an individual that relates to a Broker's Client, it will, where appropriate, refer the individual to the relevant Broker.
7.2 Compliance assistance. IVS Digital will provide the Broker with reasonable information and assistance the Broker needs to meet its own privacy obligations in relation to the processing IVS Digital carries out — for example, to support privacy impact assessments or engagement with a privacy regulator.
8. Personal Information breach
8.1 Notification to the Broker. IVS Digital will notify the Broker without undue delay, and in any event within 72 hours, after becoming aware of a confirmed Personal Information breach affecting that Broker's Client Personal Information.
8.2 Contents. The notification will include, to the extent known at the time (and updated as more becomes known): the nature of the breach, the categories and approximate volume of Client Personal Information and individuals affected, the likely consequences, and the measures taken or proposed to address it.
8.3 Mitigation and notification responsibility. IVS Digital will take reasonable steps to mitigate and remediate the breach and will cooperate with the Broker. As between the parties, the Broker is responsible for assessing the breach and making any notifications it is required to make to the Office of the Privacy Commissioner (NZ) and affected individuals under the Notifiable Privacy Breach scheme (Privacy Act 2020), and to the Office of the Australian Information Commissioner (AU) and affected individuals under the Notifiable Data Breaches scheme (Privacy Act 1988 (Cth)). IVS Digital will not notify individuals on the Broker's behalf without the Broker's instruction, unless required by law to do so.
9. Audit and information
9.1 Information rights. On reasonable written request — no more than once a year, except where required by a regulator or following a Personal Information breach — IVS Digital will make available to the Broker information reasonably necessary to demonstrate its compliance with this DPA, such as a description of its security controls or any available third-party assurance reports.
9.2 Audits. The information and reports described in clause 9.1 are ordinarily sufficient to verify compliance. Any further audit will be at the Broker's cost, on reasonable notice, during business hours, conducted so as not to disrupt IVS Digital's operations or compromise the confidentiality of other customers' data, and subject to confidentiality obligations.
10. Return and deletion
10.1 Export. On termination of the Broker's subscription, the Broker may export Your Data as set out in clause 11.4 of the Terms.
10.2 Deletion. After the export window, IVS Digital will retain, de-identify or delete Client Personal Information in accordance with the Privacy Policy and applicable law, and will delete it (or render it de-identified) within a reasonable period, unless it is required by law to retain it. On request, IVS Digital will confirm deletion.
11. Liability, precedence and general
11.1 Liability. Each party's liability under or in connection with this DPA is subject to the limitations and exclusions in the Terms, including the liability cap in clause 10.3 of the Terms.
11.2 Precedence. This DPA forms part of the Terms. In the event of any conflict between this DPA and the rest of the Terms in relation to the processing of Client Personal Information, this DPA prevails. In all other respects, the Terms continue to apply in full.
11.3 General. This DPA is governed by the laws of New Zealand and is subject to the jurisdiction, notices and other general provisions in section 13 of the Terms.
Schedule 1 — Details of processing
| Item | Detail |
|---|---|
| Controller / agency | The Broker. |
| Processor / service provider | IVS Digital Limited (NZBN 9429052933127). |
| Subject matter | Provision of the InsuredIn Platform — receiving, extracting, organising, storing, reviewing and sharing insurance documents and policy information. |
| Duration | The term of the Broker's subscription, plus the retention period set out in the Privacy Policy. |
| Nature and purpose | Hosting and storage; AI-assisted extraction of data from insurance documents; display of approved information in Broker-branded Client portals; transactional communications; security, support and maintenance. |
| Types of Personal Information | Names and contact details of policyholders and Authorised Users; insurance policy documents and the data within them; risk items (vehicles, property/homes, businesses); invoices and payment information relating to policies; excesses; cover sections, extensions and policy terms; claims information; and any sensitive information (which may include health information and, in some cases, criminal-history information) contained in documents a Broker uploads. |
| Categories of individuals | The Broker's Clients (policyholders and Authorised Users) and third parties named in documents the Broker provides. |
| Sub-processors | As listed in the InsuredIn Privacy Policy, as updated from time to time. |
| Security measures | Encryption in transit and at rest; multi-tenant isolation via row-level security; access controls; audit logging; in-region (Sydney, Australia) storage, compute and AI processing, as described in the Privacy Policy. |
IVS Digital Limited · NZBN 9429052933127 · 18B Manuka Road, Glenfield, Auckland, New Zealand · legal@insuredin.app
This DPA forms part of the InsuredIn Terms & Conditions and should be read together with the InsuredIn Privacy Policy.