top of page

CommBox Data Processing Agreement

Effective date: 4 May 2026

1. About this Data Processing Agreement

This Data Processing Agreement explains how CommBox Pty Ltd handles personal information on behalf of customers using eligible CommBox products and services.

It applies where this Data Processing Agreement is:

  • referenced in a CommBox agreement, order form, proposal or subscription;

  • accepted by a customer when purchasing or activating a CommBox service; or

  • otherwise agreed between CommBox and the customer.

 

This Data Processing Agreement forms part of the agreement under which CommBox provides the relevant services to the customer.

A customer may request a signed version of this Data Processing Agreement. The signed version may include customer-specific details such as selected services, data locations, support arrangements, retention periods and additional privacy or security requirements.

If a signed Data Processing Agreement conflicts with this online version, the signed version prevails.

 

2. Services covered

This Data Processing Agreement may apply to the following services where selected by the customer:

  • CommBox OS Experience;

  • CommBox Classic S5 cloud-connected features;

  • CommBox Manage;

  • CommBox Signage;

  • CommBox Connect;

  • CommBox AI features;

  • CommBox support and remote-management services; and

  • other CommBox services expressly identified in an order form or customer agreement.

 

A service is covered only when it is supplied to or activated for the customer.

 

3. Key definitions

 

Customer means the organisation purchasing, subscribing to, administering or using the relevant CommBox service.

Customer Data means information, files, content, records, configurations, prompts, images, audio, telemetry, logs and other data submitted to, stored in, collected through or generated for the customer through the services.

Customer Personal Information means personal information that CommBox or a subprocessor processes on behalf of the customer.

Personal Information has the meaning given under applicable privacy law and includes information about an identified or reasonably identifiable person.

Processing includes collecting, recording, storing, accessing, using, transmitting, disclosing, securing, deleting or otherwise handling information.

Security Incident means an actual or reasonably suspected event that compromises, or is reasonably likely to compromise, the confidentiality, integrity or availability of Customer Data.

Student Data means Customer Data relating to a student, child or young person.

Subprocessor means a third party engaged by CommBox to process Customer Personal Information when delivering a service.

 

4. Privacy roles

 

For Customer Personal Information processed under the customer’s instructions:

  • the customer determines why and how the information is used; and

  • CommBox acts as the customer’s service provider or processor.

 

These descriptions are used for contractual clarity even where applicable privacy law uses different terminology.

CommBox may separately handle limited business-contact, billing, account-management, sales, support and compliance information for its own legitimate business and legal purposes. This information is managed under the CommBox Privacy Policy.

 

5. How CommBox processes Customer Data

CommBox processes Customer Data only where reasonably necessary to:

  • provide and operate the selected services;

  • enrol, configure and manage devices;

  • authenticate users and administrators;

  • deliver requested features;

  • provide customer support;

  • monitor performance, security and availability;

  • deploy authorised software, firmware and configuration updates;

  • prevent, investigate and respond to misuse, outages and Security Incidents;

  • meet the customer’s documented instructions; or

  • comply with applicable law.

 

Where CommBox is legally required to process Customer Personal Information outside the customer’s instructions, CommBox will notify the customer before processing unless the law prohibits that notification.

 

6. What CommBox does not do with Customer Data

 

CommBox does not:

  • sell, rent or trade Customer Data;

  • use Customer Data for targeted or behavioural advertising;

  • market directly to students through Customer Data;

  • operate as a data broker;

  • create profiles of users for purposes unrelated to delivering the services;

  • claim ownership of content supplied by the customer or its users; or

  • use Customer Personal Information, prompts, screen content, audio, captions or outputs to train or improve general-purpose or foundation AI models.

 

Customer Data is not disclosed to a third party except where the disclosure is required to deliver the selected services, authorised by the customer or required by law.

 

7. Customer responsibilities

 

The customer is responsible for:

  • having the legal authority to collect and provide Customer Data;

  • giving users appropriate privacy notices;

  • obtaining any required consent or authorisation;

  • configuring administrator roles and permissions;

  • selecting appropriate session, security and retention settings;

  • securing customer-controlled networks, identity providers and devices;

  • managing customer user accounts and credentials;

  • assessing customer-selected applications and integrations;

  • ensuring users do not submit excessive or unlawful information; and

  • informing CommBox before using a service to process Sensitive Information or other high-risk information.

 

Where the customer is a school or education authority, the customer remains responsible for any required student, parent or guardian notices and consents.

 

8. Student Data and Sensitive Information

 

CommBox applies data-minimisation and privacy-by-design principles to Student Data and Sensitive Information.

 

CommBox does not knowingly require Student Data or Sensitive Information that is unnecessary for the selected service.

Unless CommBox expressly agrees otherwise following an appropriate privacy and security assessment, the services must not be used as the sole system for:

  • clinical or medical diagnosis;

  • high-risk behavioural profiling;

  • biometric identification;

  • automated decisions that materially affect a student or employee;

  • determining access to education, employment or essential services; or

  • storing highly sensitive case records for which the service has not been designed.

CommBox will reasonably assist schools and education authorities with privacy impact assessments, security assessments and education-sector due-diligence requirements.

 

9. Security protections

 

CommBox maintains technical and organisational controls designed to protect Customer Data against:

  • unauthorised access;

  • unauthorised disclosure;

  • loss or destruction;

  • alteration or interference;

  • misuse; and

  • unlawful processing.

 

Depending on the selected service, these controls include:

 

Encryption

Customer Personal Information is encrypted in transit over public networks using current industry-standard protocols.

Stored Customer Personal Information is encrypted at rest where supported by the applicable service. CommBox cloud services use encryption technologies including AES-256 and secure key-management services.

 

Identity and access

Administrative access is protected through controls including:

  • role-based access;

  • least-privilege permissions;

  • protection by default;

  • unique user accounts;

  • multi-factor authentication;

  • access approval and review;

  • prompt access removal; and

  • administrator activity logging.

 

Secure development

CommBox maintains secure-development, change-management, vulnerability-management and patch-management processes.

CommBox cloud applications and relevant hardware products undergo security testing, vulnerability scanning and independent penetration testing appropriate to the service.

 

Device security

Supported CommBox devices may include:

  • digitally signed firmware;

  • verified boot;

  • hardware-backed key storage;

  • restricted developer and factory interfaces;

  • administrator controls over settings and ports;

  • authenticated firmware updates; and

  • support for secure network configuration.

 

Monitoring and resilience

CommBox maintains security monitoring, event management, incident-response, backup, business-continuity and disaster-recovery processes appropriate to the selected service.

 

10. CommBox support and remote access

Some services, including CommBox Manage, support remote administration and support features.

Depending on the customer’s configuration and assigned permissions, these features may include:

  • viewing or remotely controlling a display;

  • deploying applications, files or firmware;

  • changing authorised device settings;

  • collecting technical logs;

  • issuing device-management commands;

  • locking or wiping a managed device; and

  • viewing device-health and configuration information.

 

CommBox personnel may access a customer tenant or device only where:

  • the customer grants access to their account by adding CommBox Staff as auser;

  • there is an authorised support request or approved operational purpose;

  • the access is reasonably necessary;

  • the person has an appropriate role and permission;

  • multi-factor authentication and secure access controls are used; and

  • the access is logged where supported by the service.

 

CommBox support personnel can not intentionally inspect, retrieve or copy arbitrary user-created files or screen content. Access to files, logs, screen content or device data is limited to what is reasonably necessary for the authorised support purpose, approved by the customer or required to contain a Security Incident.

If emergency access occurs without prior customer approval, CommBox will notify the customer as soon as practicable and provide available audit information on request.

 

11. Subprocessors

 

The customer authorises CommBox to engage subprocessors to help deliver the selected services.

Before engaging a subprocessor that processes Customer Personal Information, CommBox takes proportionate steps to:

  • assess the provider’s security and privacy controls;

  • understand the provider’s processing purpose and locations;

  • enter into appropriate contractual protections;

  • limit processing to what is necessary;

  • require confidentiality and security;

  • require Security Incident notification;

  • address deletion, retention and overseas processing; and

  • periodically review material supplier risks.

 

CommBox remains responsible for the performance of its subprocessors to the extent set out in the customer agreement and applicable law.

 

Changes to subprocessors

CommBox will provide at least 30 days’ prior notice before:

  • adding or replacing a material subprocessor;

  • materially expanding a subprocessor’s processing purpose; or

  • moving material processing into a new country.

 

The notice will identify the provider, its function and the relevant processing countries.

The customer may object within 15 days on reasonable privacy, security, regulatory or data-residency grounds. CommBox and the customer will work in good faith to identify a reasonable alternative.

If no commercially reasonable alternative is available, the customer may discontinue the affected optional feature or terminate the affected service without an early-termination charge. Any prepaid fees for the unused terminated period will be refunded.

 

12. Current service providers and processing locations

The following summary describes the principal infrastructure and service providers used by CommBox. The providers that apply depend on the services and features selected by the customer.

 

CommBox OS Experience

Principal provider: Microsoft Azure
Primary purpose: Application hosting, authentication, databases, account information, configuration, Key Vault, logging, backup and security services.
Standard Australian deployment: Australia East, Australia.

 

Cloudflare

Purpose: DNS, edge proxy, TLS services, web application firewall, performance and distributed denial-of-service protection.
Location: Globally distributed edge network. CommBox’s standard Australian OS Experience origin environment remains in Australia.

 

CommBox Signage

Principal provider: Amazon Web Services
Purpose: Signage application hosting, databases and customer media storage.
Standard location: Sydney, Australia.

 

CommBox Manage

Principal platform provider: Radix Technologies
Infrastructure providers may include: Amazon Web Services, MongoDB, authentication services and device-notification providers.
Purpose: Device enrolment, inventory, telemetry, management commands, administrator accounts, logs, remote support and software delivery.
Location: CommBox Manage uses globally distributed infrastructure. The production, database, logging, backup, disaster-recovery and support-access countries applicable to a customer deployment are provided in the customer’s service schedule or signed Data Processing Agreement.

CommBox does not represent CommBox Manage as being hosted only in Australia unless that commitment is expressly stated in the customer’s agreement.

 

Firmware and software delivery

Principal provider: AWS - Australia and United States

CommBox devices may connect to CommBox and approved third-party firmware, activation and software-distribution services.

Relevant infrastructure may be located in Australia, the United States, Germany and other disclosed service locations.

 

CommBox AI

Principal provider: Microsoft Azure AI services & Gemini Enterprise Agent Platform

The Azure and Google deployment region, deployment type, content-logging configuration, retention arrangement and any failover location applicable to CommBox AI is the United States.

 

Customer-selected providers

Microsoft Entra ID, Microsoft 365, OneDrive, Google Workspace, Google Drive and customer-selected applications or websites operate under the customer’s agreement with those providers.

They are not CommBox subprocessors merely because the customer chooses to connect them to a CommBox service.

A current service-specific subprocessor and data-location schedule is available from CommBox on request.

 

13. Overseas processing

CommBox may process Customer Personal Information outside Australia or New Zealand where this is required to provide a selected service and the location has been disclosed.

CommBox takes reasonable steps to ensure overseas subprocessors protect Customer Personal Information through measures including:

  • contractual privacy and security requirements;

  • provider due diligence;

  • encryption;

  • access controls;

  • purpose restrictions;

  • incident-notification obligations;

  • deletion and retention controls; and

  • appropriate cross-border transfer safeguards.

 

CommBox will not move Customer Personal Information, logs, backups, disaster-recovery copies or support access into a new country without providing the notice described in this Data Processing Agreement, except where an urgent change is required by law or to respond to a Security Incident.

Where an urgent change occurs, CommBox will notify affected customers as soon as practicable.

 

14. CommBox AI features

This section applies only when a CommBox AI feature is enabled.

Depending on the feature, information transmitted for processing may include:

  • typed prompts;

  • voice or audio;

  • speech transcripts;

  • live captions;

  • translations;

  • selected screen regions;

  • images or diagrams;

  • displayed text;

  • generated outputs; and

  • security or content-safety metadata.

 

CommBox will:

  • disclose the applicable AI provider and processing location;

  • minimise the information transmitted;

  • restrict storage of prompts and outputs where supported;

  • apply available access, safety and content-filtering controls;

  • disclose any provider retention or human-review configuration;

  • prevent customer content from being used to train general-purpose AI models; and

  • support customer controls for disabling optional AI features where technically available.

 

CommBox AI must not be used as the sole basis for a decision that materially affects a student, employee or other person.

AI outputs may be incomplete, inaccurate or inappropriate. You remain responsible for reviewing outputs before relying on or sharing them.

 

15. Requests from individuals

CommBox will provide reasonable assistance to help the customer respond to requests concerning:

  • access;

  • correction;

  • deletion;

  • restriction;

  • objection;

  • consent withdrawal;

  • data portability; and

  • privacy complaints.

 

If CommBox receives a request directly from a person relating to Customer Personal Information, CommBox

will normally:

  1. acknowledge the request where appropriate;

  2. notify the customer without undue delay and ordinarily within two business days;

  3. not provide a substantive response without the customer’s instructions unless legally required; and

  4. preserve relevant records.

 

CommBox may require proportionate identity and authority verification before disclosing, correcting or deleting information.

 

16. Security Incidents and data breaches

CommBox maintains a documented process for detecting, assessing, containing, investigating, remediating and recovering from Security Incidents.

CommBox will notify the customer without undue delay and no later than 24 hours after becoming aware of a confirmed or reasonably likely Security Incident affecting Customer Personal Information.

An initial notification may be incomplete and may be updated as the investigation progresses.

Where known, notifications will include:

  • the nature of the incident;

  • when the incident occurred and was identified;

  • the affected services and systems;

  • the subprocessors or countries involved;

  • the types and approximate amount of information affected;

  • the number or categories of affected people;

  • actual or likely consequences;

  • containment and remediation measures;

  • recommended customer actions;

  • relevant regulatory or law-enforcement contact; and

  • the expected timing of the next update.

 

CommBox will:

  • provide material updates;

  • preserve relevant evidence and logs;

  • assist the customer’s legal assessment;

  • provide a written incident report or root-cause summary when reasonably available; and

  • provide available information needed for customer or regulatory notification.

 

The customer is responsible for determining whether it must notify a regulator or affected individuals, unless CommBox has an independent legal obligation.

CommBox will coordinate notifications with the customer to reduce delay, duplication and inconsistency.

 

17. Retention and deletion

CommBox retains Customer Personal Information only for as long as reasonably necessary to:

  • deliver the selected service;

  • follow the customer’s instructions;

  • maintain security and service continuity; or

  • comply with legal obligations.

 

Service-specific retention periods may be stated in an order form, service schedule or signed Data Processing Agreement.

Unless a different period is agreed:

  • Customer Personal Information will be deleted from active production systems within 30 days after service termination or a verified deletion instruction; and

  • backup copies will be deleted or rendered inaccessible through the normal backup cycle and within 90 days.

 

CommBox may retain information for longer where required by law, a binding government direction, legal hold or the establishment, exercise or defence of legal claims.

Information retained for these purposes remains protected and is isolated from routine use.

CommBox will provide reasonable export tools or assistance before deletion where the applicable service supports data export.

Written confirmation of deletion may be provided on reasonable request.

 

18. Physical devices and end-of-life handling

The customer is responsible for securely resetting, unenrolling and disposing of physical devices under its control.

Before a managed CommBox device is sold, returned, repurposed or disposed of, the customer should:

  1. export any required information;

  2. remove the device from CommBox Manage;

  3. revoke device-management tokens and associations;

  4. perform a factory reset;

  5. confirm the device returns to its initial setup state; and

  6. update the customer’s asset and disposal records.

 

CommBox provides available factory-reset and device-removal instructions through its support resources.

 

19. Audit and assurance

On reasonable request and subject to confidentiality, CommBox will provide available evidence relevant to the selected services, which may include:

  • privacy and security documentation;

  • architecture and network information;

  • subprocessor information;

  • data-location information;

  • certification evidence;

  • penetration-test attestations or summaries;

  • responses to reasonable customer questionnaires; and

  • information supporting privacy impact or security risk assessments.

 

Where the information provided is insufficient to demonstrate compliance, the customer may request one reasonable audit in a 12-month period by providing at least 15 business days’ notice.

Additional audits may be requested following:

  • a material Security Incident;

  • a regulator’s request; or

  • reasonable evidence of material non-compliance.

 

Audits must protect the security and confidentiality of CommBox, its providers and other customers.

 

20. Government and legal requests

If CommBox receives a legally binding request for Customer Personal Information from a court, regulator, law-enforcement agency or government authority, CommBox will, unless prohibited by law:

  • notify the customer before disclosure;

  • provide available details of the request;

  • refer the authority to the customer where appropriate;

  • seek clarification of an invalid or overbroad request where reasonably practicable;

  • disclose only the minimum information legally required; and

  • maintain a record of the disclosure.

 

21. Changes to this Data Processing Agreement

CommBox may update this online Data Processing Agreement to reflect:

  • changes in law;

  • new or changed services;

  • changes to security or privacy controls;

  • changes to subprocessors or processing locations; or

  • improvements to CommBox’s data-protection practices.

 

CommBox will not materially reduce the protection of Customer Personal Information during an active service term without providing at least 30 days’ notice.

The version effective when the customer’s agreement begins continues to apply until an updated version takes effect under the customer agreement or is accepted by the customer.

Changes required to address an urgent security risk or legal requirement may take effect sooner. CommBox will notify affected customers as soon as practicable.

 

22. Term and precedence

This Data Processing Agreement remains in effect while CommBox or its subprocessors process Customer Personal Information in connection with the customer’s services.

After termination, the provisions dealing with confidentiality, Security Incidents, retention, deletion, audit, legal requests and liability continue for as long as relevant.

The following order of precedence applies to privacy and data-processing matters:

  1. a customer-specific signed privacy or data-processing agreement;

  2. a customer-specific order form or privacy schedule;

  3. this online Data Processing Agreement; and

  4. the main customer agreement.

 

A customer-specific document may provide greater protection than this online Data Processing Agreement.

 

23. Liability and governing law

The liability limitations and exclusions in the customer’s main agreement apply to this Data Processing Agreement unless prohibited by law or expressly varied in writing.

Nothing in this Data Processing Agreement limits a right or remedy that cannot legally be limited.

The governing law is the law stated in the customer’s main agreement. If the main agreement does not identify a governing law, this Data Processing Agreement is governed by the laws of New South Wales, Australia.

 

24. Contact CommBox

Questions about this Data Processing Agreement, privacy, security, deletion or customer due diligence can be directed to:

CommBox Pty Ltd
Email: success@commbox.com.au

Please include your organisation’s name, the relevant CommBox service and enough information for CommBox to understand and verify the request.

 

25. Signed Data Processing Agreements

This online Data Processing Agreement is designed to meet the standard requirements of most CommBox customers.

A customer may request a signed version where it requires:

  • customer-specific service schedules;

  • exact processing and support-access countries;

  • agreed retention periods;

  • additional audit requirements;

  • specific public-sector or education requirements;

  • a nominated 24-hour incident contact;

  • additional data-residency commitments; or

  • execution by authorised representatives.

bottom of page