Data Processing Agreement
Last updated
This Data Processing Agreement (“DPA”) sets out how Galah Enterprises Pty Ltd (ACN 682 927 779), trading as DS160.io (“DS160.io”), processes personal data on behalf of a business customer that uses a DS160.io business workspace (the “Customer”). It forms part of DS160.io’s Terms of Service (the “Agreement”) and takes effect when the Customer accepts them, in any of the ways clause 1(e) of the Agreement sets out: ticking the box or clicking “I accept these Terms”, signing an agreement with DS160.io, or paying for or using a business workspace.
1. Definitions
Terms not defined here have the meaning given in the GDPR (Regulation (EU) 2016/679). “Data Protection Law” means the GDPR, the UK GDPR and the UK Data Protection Act 2018, the Swiss Federal Act on Data Protection, and any other data protection law that applies to the Customer’s Personal Data. “Customer Personal Data” means the personal data described in Annex I that DS160.io processes on the Customer’s behalf. “Applicant” means a person whose DS-160 is prepared in the Customer’s workspace. “Sub-processor” means a third party DS160.io engages to process Customer Personal Data. “SCCs” means the standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914.
2. Roles and scope
The Customer is the controller of Customer Personal Data and DS160.io is its processor. This DPA covers only Customer Personal Data: the applicant data in the Customer’s workspace. DS160.io processes the Customer’s own account and billing data, and its staff’s sign-in data, as a controller under its privacy policy.
Annex I describes the subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects.
3. The Customer’s obligations
The Customer is responsible for having a lawful basis for the processing it instructs, and for giving Applicants the information Articles 13 and 14 GDPR require. Because the DS-160 asks about health and about arrests and convictions, the Customer is responsible in particular for a condition under Article 9 GDPR for the health answers and a basis under Article 10 GDPR for the criminal-history answers, for example the Applicant’s explicit consent, before those answers are entered or collected through DS160.io.
The Customer’s instructions to DS160.io are this DPA, the Agreement, and the Customer’s use and configuration of DS160.io, including sending client links, entering and editing answers, and starting a filing on CEAC.
4. DS160.io’s obligations
Instructions. DS160.io processes Customer Personal Data only on the Customer’s documented instructions, including for transfers outside the EEA and the UK, unless the law requires otherwise; in that case DS160.io tells the Customer first, unless the law forbids it. DS160.io tells the Customer if it believes an instruction breaks Data Protection Law.
Confidentiality. Everyone DS160.io authorises to process Customer Personal Data is bound by a written confidentiality obligation and receives appropriate privacy and security training. DS160.io staff open the Customer’s workspace or an Applicant’s application only with the Customer’s permission to investigate a problem, and otherwise see only the diagnostic records of failed filing runs.
Security. DS160.io implements the technical and organisational measures in Annex II and keeps them at least as protective as described there.
Assistance. Taking into account the nature of the processing, DS160.io helps the Customer:
- answer requests from Applicants exercising their rights. The Customer can view, correct and delete Applicant answers in its workspace itself; DS160.io handles deletion of an Applicant’s data and provides copies on the Customer’s request. DS160.io forwards to the Customer any request it receives directly about Customer Personal Data and does not answer it except on the Customer’s instruction;
- meet its obligations under Articles 32 to 36 GDPR, including data protection impact assessments and prior consultation, with the information DS160.io has.
5. Personal data breaches
DS160.io notifies the Customer without undue delay, and in any event within 48 hours, after becoming aware of a personal data breach affecting Customer Personal Data. The notice describes, as far as then known, the nature of the breach, the categories and approximate number of Applicants and records concerned, the likely consequences, and the measures taken or proposed, and DS160.io adds to it as it learns more. DS160.io takes reasonable steps to contain the breach and does not notify a supervisory authority or Applicants about it except as the Customer instructs or the law requires.
6. Sub-processors
The Customer gives DS160.io general authorisation to engage Sub-processors. The Sub-processors engaged on the date of this DPA are listed in Annex III.
DS160.io gives the Customer at least 30 days’ notice, by email to the workspace owner and by updating Annex III, before adding or replacing a Sub-processor. The Customer may object on reasonable data protection grounds within that period; if the parties cannot resolve the objection, the Customer may end its use of DS160.io under clause 5(c) of the Agreement, with a pro-rata refund of any unused prepaid Fees.
DS160.io imposes on each Sub-processor, by written contract, data protection obligations that give at least the protection of this DPA, and remains liable to the Customer for each Sub-processor’s performance.
7. International transfers
DS160.io processes Customer Personal Data on its own servers at its headquarters in the United States, and its Sub-processors are in the United States. Where the Customer is subject to the GDPR and a transfer to DS160.io is a transfer to a third country, the parties enter into Module 2 (controller to processor) of the SCCs, which are incorporated by reference, with the Customer as data exporter and DS160.io as data importer, and with these choices:
- Clause 7 (docking clause) does not apply;
- Clause 9: option 2 (general written authorisation), with the notice period in section 6;
- Clause 11: the optional wording does not apply;
- Clause 13: the competent supervisory authority is as set out in Annex I;
- Clauses 17 and 18: the law and courts of Ireland;
- Annexes I, II and III of the SCCs are completed by Annexes I, II and III of this DPA.
Where the Customer is subject to the UK GDPR, the parties also enter into the UK International Data Transfer Addendum to the SCCs (version B1.0), with the tables completed from this DPA and neither party able to end it under its section 19.
Where the Customer is subject to the Swiss Federal Act on Data Protection (FADP), the SCCs also apply to transfers governed by the FADP, with these adaptations: references to the GDPR are to be read as references to the FADP; the competent supervisory authority is the Federal Data Protection and Information Commissioner; the term “Member State” does not prevent data subjects habitually resident in Switzerland from bringing claims before the courts there, in accordance with Clause 18(c); and Clauses 17 and 18 otherwise remain as set out in this section.
Filing an Applicant’s DS-160 on CEAC sends the Applicant’s answers to the US Department of State. That transfer is made on the Customer’s instruction, as the purpose of the service, and the US Department of State is a recipient, not a Sub-processor.
8. Deletion and return
When the Customer’s use of DS160.io ends, DS160.io makes an export of the Customer Personal Data available to the Customer, in a machine-readable format, for 30 days, and then deletes it (clause 11(e) of the Agreement). While the Customer uses DS160.io, DS160.io deletes the Customer Personal Data of a workspace or an Applicant within 30 days of the Customer’s request. Deleted data remains in DS160.io’s database backups, and earlier versions of stored files remain at its storage provider, for up to 7 days after deletion, encrypted and then overwritten. DS160.io keeps Customer Personal Data longer only where the law requires it, and then only for that purpose.
9. Audits and information
DS160.io makes available to the Customer the information necessary to demonstrate compliance with this DPA and Article 28 GDPR, and answers the Customer’s reasonable written questions about its processing. DS160.io allows audits, including inspections, by the Customer or an independent auditor it appoints, once in any 12 months (or more often after a personal data breach or where a supervisory authority requires it), on at least 30 days’ written notice, during business hours, under a duty of confidentiality, and at the Customer’s cost. DS160.io may meet an audit request with current documentation where that answers it.
10. Liability and precedence
Each party’s liability under this DPA is subject to the limitations in clause 12 of the Agreement (Liability), except where Data Protection Law does not allow those limitations. If this DPA conflicts with the Agreement, this DPA prevails; if it conflicts with the SCCs, the SCCs prevail.
This DPA lasts as long as DS160.io processes Customer Personal Data. Apart from the SCCs, which are governed as set out in section 7, this DPA is governed by the law of New South Wales, Australia, and each party submits to the exclusive jurisdiction of the courts of New South Wales and the courts of appeal from them.
Annex I: Description of the processing
A. Parties
Data exporter and controller: the Customer, as identified in its DS160.io business workspace. Contact: the workspace owner.
Data importer and processor: Galah Enterprises Pty Ltd, trading as DS160.io, 26 Knight Street, Arncliffe NSW 2205, Australia. Contact: privacy@ds160.io.
B. Description of the transfer and processing
Categories of data subjects
- Applicants: the Customer’s clients, and members of their families, including children, whose DS-160 is prepared in the Customer’s workspace.
- People named in an Applicant’s answers, such as family members, employers, travel companions and contacts in the United States.
- The Customer’s staff, as recorded in the edit history of an application.
Categories of personal data
- Everything the DS-160 asks: names, date and place of birth, nationality, national identification and passport details, addresses, phone numbers, email addresses and social media identifiers, travel plans and history, family members, education and work history.
- The Applicant’s visa photo and any documents uploaded for the application.
- Filing records: the CEAC Application ID, the security question answer, the confirmation page, and a PDF of every page CEAC showed back.
- The edit history of each answer: the old and new value, who made the change and when.
- Usage data from the client-intake pages an Applicant opens through a client link.
Special categories and criminal data: health data (Article 9 GDPR: communicable diseases, mental or physical disorders, drug use) and data relating to criminal convictions and offences (Article 10 GDPR: arrests, convictions and other criminal matters), from the DS-160’s security and background questions.
Frequency of the transfer: continuous, for as long as the Customer uses DS160.io.
Nature of the processing: collecting answers through client links and the Customer’s staff; storing and encrypting them; translating free-text answers into English; checking the visa photo automatically; sending client-link emails; and, when the Customer starts a filing, entering the answers on CEAC and recording the result.
Purpose: preparing and filing Applicants’ DS-160 applications for the Customer.
Retention: for as long as the Customer’s workspace exists, then as in section 8. Diagnostic records of a failed filing run are deleted after 90 days, and records of each filing run’s steps after 30 days.
Transfers to Sub-processors: as in Annex III, for the purposes and data listed there, for as long as DS160.io uses them.
C. Competent supervisory authority
The supervisory authority of the EU member state where the Customer is established or, where the Customer is not established in the EU but is subject to the GDPR, the authority of the member state where its representative under Article 27 GDPR is established. For the UK GDPR, the Information Commissioner’s Office. For the Swiss Federal Act on Data Protection, the Federal Data Protection and Information Commissioner.
Annex II: Technical and organisational measures
Encryption at rest. Applicant answers, their edit history, the copy of the application made at each filing, the CEAC Application ID and security answer, and the diagnostic records of filing runs are encrypted with AES-256 (GCM). The encryption key is held in a managed key store, apart from the database and its backups, so neither can be read without it. Only the Applicant’s name, year of birth, consulate and visa type stay readable, for the application lists.
Encryption in transit. All traffic to DS160.io is served over HTTPS. Secrets such as mail server passwords and authentication keys are stored encrypted.
Hosting. The database, application servers and the browser that files each DS-160 run on DS160.io’s own hardware, on premises at its headquarters in the United States. The premises are kept locked.
Access control. Only DS160.io’s team can reach the production systems. Staff open a workspace or an application only with the Customer’s permission to investigate a problem, and otherwise see only the diagnostic records of failed filing runs. Changes staff make during an investigation are recorded as made by DS160.io. Every account can turn on multi-factor authentication, and access within a workspace follows the roles the Customer assigns.
Minimisation in operations. DS160.io’s operational alerts run on its own servers and identify workspaces and applications by internal ID, never by name or email address. Visa photos are checked on DS160.io’s own servers, not by a third party.
Backups and recovery. The database is backed up, and backups are kept for 7 days. Earlier versions of stored files are kept by the storage provider for 7 days. Disaster recovery targets a recovery point and a recovery time of 24 hours.
Logging, monitoring and patching. DS160.io’s systems are logged and monitored, and vulnerabilities are managed with timely patching.
Training. Everyone with access to Customer Personal Data receives privacy and security training.
Retention. Diagnostic records of failed filing runs are deleted after 90 days, records of filing-run steps after 30 days, and data on a deletion request within 30 days, as in section 8.
Annex III: Sub-processors
| Sub-processor | Purpose | Customer Personal Data involved | Location | Transfer safeguard |
|---|---|---|---|---|
| Backblaze, Inc. (B2) | Storing photos, documents and filed-application PDFs | Photos, documents, filing records | United States | EU-U.S. Data Privacy Framework and UK Extension; SCCs in its data processing terms |
| Google LLC (Gemini API) | Translating free-text answers into English | The text of the answer being translated | United States | Data Privacy Framework and UK Extension; SCCs in its data processing terms |
| Amazon Web Services, Inc. (SES) | Sending client-link and status emails | Recipient email address, email contents | United States | Data Privacy Framework and UK Extension; SCCs in its data processing terms |
| PostHog, Inc. | Product analytics on client-intake pages | Usage data, in-product events | United States | Data Privacy Framework and UK Extension; SCCs in its data processing terms |
| Google LLC (Analytics) | Website analytics on client-intake pages | Usage data, cookie identifiers | United States | Data Privacy Framework and UK Extension; SCCs in its data processing terms |