Data Processing Agreement

The terms on which Hey Dawn handles personal information for you: the people and businesses in your inbox, your bills and the documents you give Dawn.

Last updated 28 September 2026.

1. About this agreement

This Data Processing Agreement (the DPA) is part of the Terms of Service between you and Hey Dawn Pty Ltd (we, us or our). It applies whenever we handle personal information on your behalf in providing the Service, and it takes effect when you accept the Terms — there is nothing separate to sign. If your business needs a signed copy, write to legal@heydawn.ai.

Words defined in the Terms mean the same here. If this DPA and the Terms conflict, this DPA prevails on how we handle Customer Personal Data.

2. What it covers

Customer Personal Data means personal information that we handle on your behalf to provide the Service: what Dawn reads from an inbox you connect, the documents you give it, what you add in the app, and the details Dawn works out from them — wherever any of it is about an identified or reasonably identifiable person. Annex A sets out the details.

It does not cover the information we handle for our own purposes as a business: your account and sign-in details, how you use our website and app, and the early-access list. Our Privacy Policy covers that.

3. Our roles

You decide which inbox Dawn watches and which documents it is given, and we process Customer Personal Data for you. Under the GDPR and the UK GDPR, you are the controller, or a processor acting for one, and we are your processor. Under the Privacy Act 1988 (Cth), we are the service provider you disclose it to. Where another privacy law applies, we are the equivalent of a processor or service provider under it.

You are responsible for having the right to let us process Customer Personal Data — including any notice or consent the law requires for the people who write to you — and for your instructions to us being lawful.

4. Your instructions

We process Customer Personal Data only on your documented instructions, unless the law requires otherwise; if it does, we will tell you first, unless the law prevents that. Your instructions are the Terms, this DPA, and what you do in the app: connecting an inbox, giving Dawn documents, dealing with bills, approving rules, asking questions and changing settings. Any other instruction must be agreed in writing. We will tell you if we think an instruction breaks a privacy law.

We will not:

  • sell Customer Personal Data, or share it for anyone's advertising;
  • use it to train AI models, ours or anyone else's;
  • combine it with another customer's data; or
  • use it for any purpose other than providing the Service to you, keeping it secure and supporting you.

We may record how the Service is used and how it performs — which features are used, what it costs to run, and errors — and use that to run and improve the Service. That record is not a copy of Customer Personal Data, though an error report can include a fragment of what was being handled when something failed, which we use only to fix the fault.

5. Our people

Everyone at Hey Dawn who can access Customer Personal Data is bound to keep it confidential, and has access only as far as their work needs it. Our staff console does not show the content of your inbox, bills, contacts, documents or conversations. A person at Hey Dawn looks at that content only when you ask us to, when it is needed to investigate a security problem or abuse, or when the law requires it.

6. Security

We protect Customer Personal Data with the measures in Annex B, which are designed to guard it against accidental or unlawful destruction, loss or alteration, and against unauthorised disclosure or access. We may change them over time, but not in a way that lowers the protection they give overall.

7. Sub-processors

You authorise us to use the sub-processors listed in Annex C. Each is bound by a written agreement that requires it to protect Customer Personal Data to a standard consistent with this DPA, and we remain responsible to you for what they do with it.

Before we add or replace a sub-processor that handles Customer Personal Data, we will update Annex C and email you at least 30 days in advance — unless we must act sooner to keep the Service running or secure, in which case we will tell you as soon as we can. If you object on reasonable data protection grounds, tell us within that time. We will try to resolve it, and if we cannot, you can close your account before the change takes effect.

8. Where Customer Personal Data is processed

We store Customer Personal Data in Sydney, in Google Cloud, and the web app's servers run in Sydney too. Some of it is processed elsewhere: the AI models run on Google's global service, so what they are sent may be processed in whichever country Google serves the request from; Google Cloud keeps our service logs and database backups in locations it chooses, which may be outside Australia; and Annex C says where each other sub-processor operates.

Where the GDPR applies to a transfer of Customer Personal Data to us, the standard contractual clauses approved by the European Commission in Implementing Decision (EU) 2021/914 form part of this DPA: module two where you are a controller, and module three where you are a processor. For those clauses, clause 7 applies; clause 9(a) option 2 applies, with at least 30 days' notice; the optional wording in clause 11(a) does not apply; the competent supervisory authority is the one clause 13(a) identifies for you; clauses 17 and 18 choose the law and the courts of Ireland; and Annexes A, B and C of this DPA complete the clauses' Annexes I, II and III.

Where the UK GDPR applies, the International Data Transfer Addendum issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018 forms part of this DPA, completed with the information in this DPA and its annexes, and neither of us may end it under its section 19. Where Swiss data protection law applies, the clauses apply with references to the GDPR read as references to the Swiss Federal Act on Data Protection, and the Swiss Federal Data Protection and Information Commissioner as the supervisory authority. If a clause adopted under those laws conflicts with this DPA, the clause prevails.

9. Helping you meet your obligations

Taking into account what the Service does and the information available to us, we will help you:

  • respond to people exercising their rights over Customer Personal Data — through the app's download and disconnect features, and by finding, correcting or deleting specific records on request. If someone asks us directly, we will pass the request to you, and will not answer it ourselves unless you ask us to or the law requires it;
  • with any data protection impact assessment or consultation with a regulator about the Service, by giving you the information we reasonably can; and
  • meet your security and breach notification obligations, as sections 6 and 10 set out.

10. Data breaches

If we become aware of a breach of security that leads to the accidental or unlawful destruction, loss or alteration of Customer Personal Data, or to its unauthorised disclosure or access, we will tell you without undue delay, and in any event within 72 hours of becoming aware of it. We will tell you what we know — what happened, what information and roughly how many people are likely to be affected, the likely consequences, and what we are doing about it — and keep you updated as we learn more.

We will take reasonable steps to contain the breach and reduce any harm, and work with you on any assessment or notification the law requires, including under the Notifiable Data Breaches scheme in the Privacy Act, where we will agree with you which of us notifies. Telling you about a breach is not an admission of fault.

11. Deletion and return

While you have an account, you can download a copy of Customer Personal Data from Settings in the web app, and ask us for anything the download leaves out, including the original documents and attachments.

When you ask us to close your account, or we close it, we will delete Customer Personal Data from our database and our file store within 30 days, and ask our sub-processors to delete what they keep for your account, unless the law requires us to keep some of it — in which case we will tell you what and why, and keep protecting it for as long as we hold it. Copies in our database backups, and deleted files, are gone within seven days, and are not restored in the meantime except to recover the Service. Service logs, which can hold fragments such as an IP address or a page address, are deleted after 30 days.

12. Information and audits

We will give you the information reasonably necessary to show that we meet this DPA, including by answering a reasonable security questionnaire once a year. We do not yet hold an independent certification or audit report; when we do, we may provide it in place of some of that information.

If that is not enough to meet a legal requirement of yours, or a regulator requires it, you may audit our compliance with this DPA — at your cost, on at least 30 days' notice, no more than once a year unless there has been a breach, during business hours, without disrupting the Service or exposing other customers' data, and under a confidentiality agreement.

13. Liability

The limits on liability in section 21 of the Terms apply to this DPA, except where the law does not allow them to.

14. How long it lasts, and changes

This DPA applies for as long as we process Customer Personal Data for you, including after your account closes, until that data is deleted. We may change it in the same way, and with the same notice, as the Terms (section 23 of the Terms), and we may also change it where the law requires, or to adopt new standard contractual clauses.

15. Contact

Questions about this DPA, or a request about personal information we process for you: privacy@heydawn.ai. A request for a signed copy: legal@heydawn.ai.

Annex A — Details of the processing

  • Parties. You, the customer, as controller or as a processor acting for one, reached at your account's email address; and Hey Dawn Pty Ltd, as processor, reached at privacy@heydawn.ai.
  • Subject matter and duration. Providing the Service, for as long as your account is open and then until Customer Personal Data is deleted under section 11.
  • What we do with it. Read messages from an inbox you connect, with read-only access; keep a record of each message Dawn checks and copies of the documents and attachments it opens; work out which messages are bills and read their details, including with AI models; compare each bill with its sender's history, run fraud checks and apply the rules you approve; show you bills and the evidence behind them; answer your questions; secure and support the Service; and delete the data.
  • How often. Continuously while an inbox is connected — Dawn checks it about every 15 minutes, and when you ask — and whenever you use the app.
  • Whose information. Anyone who sends a message to a connected inbox or appears in one, including the businesses and people who bill you, their staff, and your own staff and contacts; people named in documents you give Dawn; and you.
  • What information. Names, email addresses, phone numbers and postal addresses in messages and documents; business identifiers such as ABNs; payment details — account names and numbers, BSBs, biller codes, payment references and links; amounts, due dates, invoice numbers and line items; message details — sender, recipients, subject, date, a set of technical headers, and the names, types and sizes of attachments; the first 400 characters of a message's text; the full content of the attachments Dawn opens and the documents you give it; and what you write in the app.
  • Sensitive information. The Service is not designed to process sensitive information — such as health, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, criminal records, union membership, genetic or biometric information — and Dawn does not look for it. A bill or a message can still reveal some, a medical practice's invoice for example. Dawn never opens an attachment whose file name marks it as a payslip, a medical record, or a Centrelink or Medicare letter. Documents you give Dawn yourself are not screened this way, so you should not give it documents like those.

Annex B — Security measures

  • The least access that works. Dawn reads Gmail with Google's read-only permission, and cannot send, delete, move or label anything. It reads in stages — a set of basic details first, the text only when a message is not bulk mail, an AI model only when the text or an attachment suggests a bill, and an attachment only when it passes checks written for that purpose and stays within daily limits.
  • Where it runs. Our database, file store and servers run in Google Cloud's Sydney region, and the web app's servers run in Sydney on Vercel. The database accepts only encrypted connections made through Google Cloud's authenticated connector. Stored documents are private, and reachable only through the signed-in app.
  • Encryption. Connections to the website and the app are encrypted, and browsers are told to use nothing else. Google Cloud encrypts stored data at rest. The credentials that let Dawn read an inbox are encrypted again, with keys kept apart from the database.
  • Keeping customers apart. Every record belongs to one account, and every request is checked against the signed-in person's account before any data is read.
  • Sign-in. Passwords must be at least 12 characters, are never stored in a form that can be reversed, and require a confirmed email address. A session ends after at most seven days without use, and is held in secure, HTTP-only cookies set for the app alone, or in the phone's secure storage. On the web, you can sign out every other session from Settings.
  • Staff access. The staff console is a separate application with its own sign-in, restricted to Hey Dawn's own Google Workspace accounts, and it does not show inbox content, bills, contacts, documents or conversations. Staff can pause an account or block a sign-in, and have no way to release a bill Dawn has held. Administrative access to the systems that run Dawn is limited to named Hey Dawn staff.
  • Treating email as untrusted. What arrives in an inbox is passed to AI models marked as data, never instructions. The models that read mail have no tools and cannot act; what they return is checked against a fixed shape, and a detail they cannot quote from the source is dropped.
  • Checks that are not AI. Whether to hold a bill is decided by fixed checks with no AI in them — a new contact, changed payment details, a sender pretending to be someone else, failed email authentication, a document that does not agree with itself. Some act on what a model read, but a model can cause a hold and never clear one. Only the customer can release a held bill.
  • A record that cannot be rewritten. The record of each message, Dawn's reading of it, and every decision about a bill are written once. The application and the database both refuse to change them.
  • How we build it. Every change runs through automated checks — types, linting, tests including end-to-end tests of the service as it ships, and a scan for leaked secrets. Updates to the libraries Dawn uses wait at least a week before we take them, and each release is deployed as a specific, recorded build.
  • Recovery and logs. The database is backed up daily and can be restored to any point in the previous seven days, and deleted files can be recovered for seven days. Service logs are kept for 30 days, to investigate problems.
  • Incidents. We handle a suspected breach as section 10 describes, and we accept reports of security problems as our Security page describes.

Annex C — Sub-processors

  • Google Cloud (Google LLC and its affiliates). Hosts the database, file store and servers in Sydney, Australia; keeps service logs and database backups in locations it chooses; and runs the Gemini models that read bills and answer questions, on Google's global service. Receives all Customer Personal Data.
  • Vercel (Vercel Inc., United States). Runs the web app's servers in Sydney and serves the app through its global network, so Customer Personal Data passes through it as you use the app.
  • PostHog (PostHog Inc., United States). Measures how the app is used, linked to your account ID and email address, and collects error reports. It is not sent the content of your inbox or your bills, except that an error report can include a fragment of what was being handled when something failed.
  • Resend (Resend Inc., United States). Sends the emails your account needs — confirming your address, resetting your password, or telling you Dawn has lost access to your inbox. They do not carry the content of your inbox or your bills.
  • Google Workspace (Google LLC). Hosts our own email, so it holds anything you or your staff send us, which may include Customer Personal Data.