CR
Cloudrms
Client Area Client
ShopFeaturesPricingIntegrationsCompareBlogGuidesFAQAboutSupport Client Area Contact
ShopFeaturesPricingIntegrationsCompareBlogGuidesFAQAboutSupport Contact
Home / Data Processing Agreement

Data Processing Agreement (DPA)

Effective from: 10 August 2026. This Data Processing Agreement (DPA) supplements the Terms and Conditions between the Customer and Cloudrms Pty Ltd, and governs the handling of personal information disclosed by the Customer to Cloudrms in the course of operating the modules for RMS Cloud. It is drafted to comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), and forms an integral part of the Terms and Conditions.

1. Parties

The Customer (referred to below as Customer) is the hotel or hospitality business that has entered into the Terms and Conditions with Cloudrms and that has disclosed personal information to Cloudrms in the course of using one or more modules. The Customer is the APP entity that decides why and how the personal information is handled.

The Service Provider (Service Provider or Cloudrms) is Cloudrms Pty Ltd, a proprietary limited company incorporated under the Corporations Act 2001 (Cth), ABN 47 856 234 891, ACN 654 789 123, with its registered office at 42 Pitt Street, Level 8, Sydney NSW 2000, Australia, represented by its sole director James Whitmore. Under APP 6, Cloudrms acts on the Customer’s instructions when it handles personal information disclosed to it under a module.

The Customer and the Service Provider are together referred to as the Parties. By accepting the Terms and Conditions at Order and by activating any module that handles personal information, the Customer enters into this DPA.

2. Definitions

Capitalised terms not defined here have the meaning given to them in section 6 of the Privacy Act 1988 (Cth). In particular:

  • Personal information means information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether recorded in a material form or not, within the meaning of section 6(1) of the Privacy Act 1988 (Cth).
  • Handle and handling mean any operation performed on personal information, including collection, use, disclosure, storage, security and destruction.
  • Eligible data breach has the meaning given by section 26WE of the Privacy Act 1988 (Cth).
  • Module has the meaning given in the Terms and Conditions.

3. Subject-matter and duration of the handling

The subject-matter of the handling is the operation of the modules ordered by the Customer, as described in the module page on cloudrms.org and in the Terms and Conditions. The handling starts on activation of the first module and lasts until termination of the last active Subscription plus any residual retention required by law (in particular, seven years for tax invoice records under s. 262A of the Income Tax Assessment Act 1936 (Cth)).

4. Nature and purpose of the handling

Cloudrms handles personal information solely for the purpose of providing the modules to the Customer, in accordance with the functional description of each module. Cloudrms will not handle personal information for any other purpose without the Customer’s prior written instruction.

5. Categories of individuals and personal information

The categories of individuals whose personal information is handled are the guests of the Customer’s properties, the Customer’s staff members with access to the RMS Cloud back office, and any third parties whose personal information may appear in a reservation record (for example, a payer distinct from the guest).

The categories of personal information typically handled are: identification data (name, date of birth, nationality, passport or ID number), contact data (email, phone, postal address), reservation data (arrival, departure, room type, rate, add-ons), stay history and preferences, staff account identifiers, and, where a specific module requires it, dietary preferences or accessibility requirements. Payment card data is handled directly by our PCI-DSS certified payment provider and is not stored on Cloudrms systems.

No sensitive information within the meaning of section 6(1) of the Privacy Act 1988 (Cth) is handled unless the Customer has expressly enabled a specific module that requires it, in which case the Customer warrants that a valid basis under APP 3.3 exists.

6. Customer obligations

The Customer warrants that (i) the personal information disclosed to Cloudrms was collected in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles and any other applicable law; (ii) the Customer has notified the individuals concerned of the disclosure of their personal information to Cloudrms and, where applicable, obtained their consent; (iii) the Customer’s instructions to Cloudrms are lawful; and (iv) the Customer maintains, if required, its own record of handling activities and complies with its own obligations under the Privacy Act 1988 (Cth).

7. Service Provider obligations under APP 6

Cloudrms undertakes to:

(a) Handle personal information only on documented instructions from the Customer

Cloudrms handles personal information only on documented instructions from the Customer. Acceptance of the Terms, Order of a module and configuration in the Client Area jointly constitute the initial documented instructions. Additional instructions are given in writing by email. Where an instruction is inconsistent with the Privacy Act 1988 (Cth) or Australian law, Cloudrms informs the Customer without undue delay.

(b) Confidentiality of authorised persons

All staff members and contractors with access to personal information are bound by a written confidentiality undertaking that survives the termination of their engagement with Cloudrms.

(c) Security measures (APP 11)

Cloudrms implements the technical and organisational measures set out in Annex II and no less protective measures for the duration of this DPA. These measures include, at a minimum: TLS 1.3 for all transport, AES-256 encryption at rest, multi-factor authentication for all administrator access, immutable audit logs of every administrative action, weekly vulnerability scanning, dedicated production networks with no direct human access, and encrypted daily backups stored in a separate Australian region.

(d) Sub-processors

The Customer authorises the appointment of the sub-processors listed in Annex III. Cloudrms informs the Customer of any intended addition or replacement of a sub-processor at least thirty (30) days in advance and the Customer has the right to object on reasonable grounds. Cloudrms remains fully liable to the Customer for the acts and omissions of its sub-processors.

(e) Assistance with individuals’ rights (APPs 12 and 13)

Taking into account the nature of the handling, Cloudrms assists the Customer by appropriate technical and organisational measures, insofar as this is possible, for the fulfilment of the Customer’s obligation to respond to requests for access and correction under APPs 12 and 13. Standard export and deletion features are available from the Client Area at no charge.

(f) Assistance with security, breaches and impact assessments (APP 11 and Part IIIC of the Privacy Act)

Cloudrms assists the Customer in ensuring compliance with the security obligations of APP 11 and with the obligations of the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act. In the event of an eligible data breach affecting personal information handled on the Customer’s behalf, Cloudrms escalates internally within 24 hours and notifies the Customer in writing without undue delay and in any event no later than 36 hours after becoming aware of the breach, so that the Customer can meet its own obligations under the Notifiable Data Breaches scheme. The notification includes, so far as available at the time, the categories and approximate number of individuals and records concerned, the likely consequences and the measures taken or proposed to address the breach and mitigate its adverse effects.

(g) Deletion or return of personal information

At the choice of the Customer, Cloudrms deletes or returns all personal information after the end of the provision of services relating to the handling, and deletes existing copies unless Australian law requires storage of the personal information (in particular, seven years for tax invoice records).

(h) Audits and information

Cloudrms makes available to the Customer all information necessary to demonstrate compliance with this DPA and allows for and contributes to audits conducted by the Customer or another auditor mandated by the Customer. Audits may be performed once per calendar year, on thirty (30) days’ written notice, at the Customer’s expense, during business hours and in a manner that does not disrupt Cloudrms’s operations or the confidentiality of other customers’ data. As an alternative to on-site audit, the Customer accepts the current independent audit report (ISO 27001, SOC 2 Type II or equivalent) issued to Cloudrms.

8. Cross-border disclosure (APP 8)

All personal information handled under this DPA is stored and handled within Australia. Cloudrms performs no cross-border disclosure of personal information within the meaning of APP 8. Should this ever change, Cloudrms will, before any disclosure, take such steps as are reasonable in the circumstances to ensure that the overseas recipient does not breach the APPs, in accordance with APP 8.1, and will notify the Customer in advance.

9. Liability

Each Party is liable for damage caused by handling in breach of the Privacy Act 1988 (Cth) to the extent provided by section 52 of the Privacy Act 1988 (Cth). As between the Parties, Cloudrms’s aggregate liability under this DPA is subject to the liability cap stated in the Terms and Conditions, save for liability that cannot lawfully be limited.

10. Term

This DPA applies for as long as Cloudrms handles personal information on behalf of the Customer under the Terms and Conditions.

11. Governing law and jurisdiction

This DPA is governed by the laws of New South Wales, Australia, and by the Privacy Act 1988 (Cth). Any dispute arising out of or in connection with this DPA falls within the non-exclusive jurisdiction of the Supreme Court of New South Wales, Sydney, without prejudice to the mandatory competence of the OAIC in matters within its remit.

12. Form of agreement

This DPA is validly concluded in electronic form. Acceptance is manifested by acceptance of the Terms and Conditions and by activation of any module that handles personal information. A copy of this DPA in force on the date of activation is available at any time in the Client Area under «Legal documents». A signed PDF copy is issued on written request to privacy@cloudrms.org.

Annex I — Description of the handling

Subject-matter: operation of the modules ordered by the Customer.
Duration: for the duration of the Subscription plus statutory retention.
Nature and purpose: hospitality operations, distribution, revenue management, guest CRM, invoicing and reporting.
Type of personal information: as listed in section 5.
Categories of individuals: guests, staff, third-party payers.

Annex II — Security measures (APP 11)

  • TLS 1.3 for all client and server-to-server transport; older TLS versions refused.
  • AES-256 encryption at rest for the database, backups and object storage.
  • RMS Cloud API keys encrypted at rest with a dedicated key hierarchy, decrypted only in memory.
  • Multi-factor authentication for all administrator access to production.
  • Dedicated production networks with no direct human SSH access; access only through an audited bastion.
  • Immutable audit logs of every administrative action, retained for 24 months.
  • Weekly automated vulnerability scanning; dependencies patched within a defined SLA.
  • Change management with peer review of every deployment.
  • Encrypted daily backups stored in a separate Australian region (Melbourne).
  • Annual disaster recovery test.
  • Documented incident response plan.
  • Staff training on the Privacy Act 1988 (Cth) and the Australian Privacy Principles at hire and annually.

Annex III — Authorised sub-processors

Sub-processorLocationPurpose
Australian cloud hosting provider (Sydney data centre)AustraliaApplication and database hosting
Australian transactional email providerAustraliaDelivery of magic-link sign-in emails, tax invoices and service notices
PCI-DSS certified payment service providerAustraliaCard and BECS direct debit processing
Australian object storage providerAustralia (Melbourne)Encrypted backup storage

Contact

Cloudrms Pty Ltd
42 Pitt Street, Level 8, Sydney NSW 2000, Australia
Director: James Whitmore
Privacy Officer: privacy@cloudrms.org
Telephone: +61 2 8756 3421
ABN: 47 856 234 891 — ACN: 654 789 123
Regulator: Office of the Australian Information Commissioner (OAIC).

Effective from 10 August 2026. Next scheduled review: 10 February 2027.

Cloudrms

Third-party modules and extensions for RMS Cloud PMS

Independent marketplace of modules and extensions for the RMS Cloud PMS.

Shop

  • All extensions
  • Pricing
  • Compare
  • ROI calculator
  • Checkout

Resources

  • Features
  • Integrations
  • Blog
  • Guides
  • Academy
  • Changelog
  • API documentation

Company

  • About
  • Contact
  • Support
  • Security
  • Terms
  • Privacy
  • Cookies
  • DPA
  • Refund policy
Cloudrms Pty Ltd — ABN: 47 856 234 891 — ACN: 654 789 123 — 42 Pitt Street, Level 8, Sydney NSW 2000, Australia — Director: James Whitmore — support@cloudrms.org — Tel: +61 2 8756 3421 — Westpac Banking Corporation, BSB 032-123, Acc 456789012.
Cloudrms is an independent third-party marketplace and is in no way affiliated with, sponsored by or endorsed by RMS Cloud Pty Ltd or its parent company. All trademarks, product names and logos are the property of their respective owners. Supervisory authority for data protection: Office of the Australian Information Commissioner (OAIC). Jurisdiction: Supreme Court of New South Wales, Sydney. Applicable legal framework: Privacy Act 1988 (Cth) + Australian Privacy Principles + Australian Consumer Law (Schedule 2, Competition and Consumer Act 2010).
© 2024–2026 Cloudrms Pty Ltd All rights reserved.
Terms Privacy Cookies DPA Refunds

Your cart

Total A$0.00
Checkout →

We use cookies to improve your experience and analyse site performance. Learn more