Data Processing Agreement
Applies to all RILLA Shield customers. Enterprise customers may execute a countersigned copy.
Last updated: 3 August 2026
1. Roles of the parties
The customer is the data controller. Rilla Shield Defence Pty Ltd (ACN registered in Australia) is the data processor and processes personal information only on the customer's documented instructions, which include use of the platform by the customer's authorised users.
2. Subject matter and duration
Processing is limited to the provision of invoice, supplier, payee and pay-run fraud detection services for the duration of the customer's subscription, plus any retention period the customer selects for their audit trail.
3. Categories of data
- Business contact details of authorised users (name, work email, role).
- Supplier and payee business details (entity name, ABN, contact details, BSB and account number).
- Invoice and pay-run metadata (amounts, dates, references, document fingerprints).
- Access and verdict logs (who scanned what, when, and the resulting decision).
RILLA Shield does not require or request consumer credit data, health data, or government identity documents. Where an identifier must be shared across the network for cross-customer fraud signals, it is one-way hashed before it leaves the customer's workspace.
4. Read-only by design
Accounting and job-management integrations (Xero, QuickBooks Online, MYOB, Simpro, ServiceM8 and others) are connected with read scopes. RILLA Shield does not initiate payments, hold funds, or connect to a customer's bank account to move money. Bank details are checked for fraud signals only.
5. Security measures
- Encryption in transit (TLS 1.2+) and at rest for all customer data.
- Row-level access controls enforced at the database, scoped to the authenticated user's workspace.
- Optional SAML single sign-on, passkeys and multi-factor authentication for user access.
- Append-only, hash-chained audit logging of scans, verdicts, overrides and bank-detail changes.
- Least-privilege internal access with logged administrative actions.
- A published vulnerability disclosure programme and continuous automated security scanning.
6. Sub-processors
The customer authorises the sub-processors below. We give notice before adding a new sub-processor that processes customer personal information, and the customer may object on reasonable data-protection grounds.
| Sub-processor | Purpose | Region |
|---|---|---|
| Supabase (managed cloud database & auth) | Application database, authentication, file storage | Australia / Asia-Pacific |
| Cloudflare | Application hosting, edge delivery, DDoS protection | Global edge |
| Stripe | Subscription billing and payment processing | Global |
| Resend | Transactional and notification email | Global |
| Twilio | SMS one-time codes and payment-hold alerts | Global |
7. Confidentiality and personnel
Personnel with access to customer data are bound by confidentiality obligations and are granted access only where required to deliver or support the service.
8. Assistance to the controller
We will assist the customer, taking into account the nature of processing, with data subject access, correction and deletion requests, with privacy impact assessments, and with regulator engagement where the request relates to data we process on the customer's behalf.
9. Breach notification
We will notify the customer without undue delay, and in any case within 72 hours, of becoming aware of a personal data breach affecting their data, including the nature of the breach, likely consequences and the measures taken. Our incident handling process is described in our data breach response page.
10. Retention, return and deletion
Retention windows are configurable per workspace. On termination, the customer may export their audit trail and scan history. Unless a longer period is required by Australian law, customer data is deleted from production systems within 30 days of termination and purged from backups on the normal backup rotation.
11. International transfers
Customer data is primarily hosted in Australia. Where a sub-processor processes data outside Australia, we require contractual protections consistent with Australian Privacy Principle 8 before any transfer occurs.
12. Audit
On reasonable notice and no more than once per year (or after a material security incident), we will provide the information reasonably necessary to demonstrate compliance with this agreement, including our security documentation and the results of our automated security scanning.
13. Contact
Privacy and data protection enquiries: admin@rillashield.app. Enterprise customers requiring a countersigned DPA, security questionnaire response or vendor onboarding pack can request one via our contact page.
