CB
CloudBookMod
Client Area Client

Shop

  • Catalog
  • Modules
  • Pricing
  • Integrations
  • Compare
  • ROI calculator

Learn

  • Blog
  • Guides
  • Academy
  • FAQ
  • Changelog
  • API

Company

  • About
  • Contact
  • Support
  • Security
Ready to plug into NewBook Cloud? Browse the shop
Home / Data Processing Agreement

Data Processing Agreement

Effective from: 11 August 2026. This Data Processing Agreement ("DPA") supplements the CloudBookMod Terms of Service and governs the handling of personal information by CloudBookModMod Pty Ltd on behalf of the Customer when the Customer uses one or more CloudBookMod Modules connected to its NewBook Cloud property management account. It is drafted to comply with the Privacy Act 1988 (Cth), the Australian Privacy Principles set out in Schedule 1 of that Act and the Notifiable Data Breaches scheme in Part IIIC of that Act.

1. Parties

This DPA is entered into by and between:

  • CloudBookModMod Pty Ltd, ABN 82 743 951 268, ACN 743 951 268, of 156 Collins Street, Level 12, Melbourne VIC 3000, Australia, acting as service provider and data handler for the Customer (referred to in this DPA as "CloudBookMod" or the "Processor"); and
  • the Customer, being the legal entity, business or sole trader identified as the account holder in the corresponding CloudBookMod Order, acting as the APP entity and data controller in respect of the personal information of its own guests (referred to in this DPA as the "Customer" or the "Controller").

Where the Customer is itself an APP entity within the meaning of the Privacy Act 1988 (Cth), it is responsible for its own compliance with the Australian Privacy Principles, including in relation to its collection of guest personal information through its NewBook Cloud account. CloudBookMod processes such information solely on the Customer's documented instructions as recorded in this DPA and in the applicable Module configuration.

2. Subject matter and duration

The subject matter of this DPA is the processing by CloudBookMod, on behalf of the Customer, of personal information belonging to the Customer's guests and other data subjects, transmitted through the CloudBookMod Modules connected to the Customer's NewBook Cloud account. This DPA takes effect on the Effective Date of the corresponding Order and remains in force for as long as CloudBookMod processes personal information on behalf of the Customer, and for such further period as is required by law after termination.

3. Nature and purpose of processing

CloudBookMod processes personal information for the sole purpose of providing the Modules ordered by the Customer and of performing the ancillary support and technical operations required for their proper functioning. The processing activities may include, without limitation, the reading of guest reservation records from NewBook Cloud, the enrichment or transformation of reservation and guest CRM data, the automated dispatch of guest communications, the storage of digital guest waivers, the reconciliation of guest folio charges and the export of aggregated statistics for the Customer's own analytics.

4. Types of personal information

Depending on the Modules activated by the Customer, the types of personal information processed on the Customer's behalf may include the following categories:

  • identity data: first name, surname, salutation and title;
  • contact data: postal address, email address, mobile and landline telephone numbers;
  • date of birth and nationality;
  • driver licence number (where required for pre-check-in verification enabled by the Customer);
  • dietary requirements and accessibility needs recorded by the Customer;
  • stay history: dates of arrival and departure, room or site number, rate plan, folio charges and payment status;
  • marketing preferences and consent records maintained by the Customer;
  • free-text notes entered by the Customer or its staff about a guest.

CloudBookMod does not require, and instructs the Customer not to transmit through the Modules, credit card numbers, government-issued identifiers other than those listed above, or any sensitive information within the meaning of section 6 of the Privacy Act 1988 (Cth) unless a specific Module expressly supports such a category and the Customer has activated it in writing.

5. Categories of data subjects

The categories of data subjects whose personal information is processed under this DPA are:

  • past, present and prospective guests of the Customer;
  • additional occupants recorded on a reservation such as accompanying family members;
  • emergency contacts nominated by a guest at the Customer's request;
  • staff members of the Customer who are recorded in NewBook Cloud as owners or actors on a record; and
  • corporate contacts of group-booking clients of the Customer.

6. Customer instructions

CloudBookMod processes personal information only on the documented instructions of the Customer, as expressed in this DPA, in the Order, in the configuration of each Module in the Client Area, and in any subsequent written instruction accepted by CloudBookMod. If CloudBookMod considers that a Customer instruction infringes the Privacy Act 1988 (Cth) or any other applicable Australian law, CloudBookMod will inform the Customer without undue delay and may suspend performance of that instruction pending clarification.

7. Confidentiality

CloudBookMod ensures that any employee, contractor or agent authorised to process personal information under this DPA is bound by a written obligation of confidentiality that survives termination of their engagement. Access to personal information is granted on a strict need-to-know basis, is logged, is reviewed quarterly by CloudBookMod's director and is revoked as soon as it is no longer required.

8. Sub-processors

The Customer authorises CloudBookMod to engage the following sub-processors in the performance of its services under this DPA. CloudBookMod remains fully responsible for the acts and omissions of its sub-processors as if they were its own.

Sub-processorPurposeLocation
Amazon Web Services, Inc.Production hosting of the application and databaseAsia Pacific (Sydney) region, ap-southeast-2, Australia
PostmarkTransactional email delivery (magic-link sign-in, order confirmations, service notices)United States (data centre and control plane)
SentryApplication error monitoring (redacted stack traces and error identifiers)United States

CloudBookMod maintains a current list of sub-processors and notifies the Customer at least thirty (30) days in advance of any addition or replacement, giving the Customer an opportunity to object on reasonable grounds. If the Customer objects, the parties will discuss the objection in good faith; if the objection cannot be resolved, the Customer may terminate the affected Module without penalty.

9. Overseas disclosure (APP 8)

Where a sub-processor listed in clause 8 is located outside Australia, CloudBookMod takes reasonable steps in accordance with Australian Privacy Principle 8 to ensure that the overseas recipient does not breach the APPs in relation to the personal information disclosed to it. Those steps include entering into written contracts that impose obligations substantially equivalent to the APPs, obtaining independent security certifications where available (such as SOC 2 Type II reports), restricting the categories of personal information disclosed and applying strong encryption in transit and at rest.

10. Security measures

Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, CloudBookMod implements appropriate technical and organisational measures to protect personal information against accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal information transmitted, stored or otherwise processed. Those measures include, at a minimum:

  • Encryption in transit: all connections to CloudBookMod infrastructure use Transport Layer Security 1.3 with modern cipher suites; obsolete versions are refused.
  • Encryption at rest: all customer data and NewBook Cloud API credentials are stored using AES-256 encryption with keys managed in a hardware security module.
  • Access controls: access to production systems is restricted to a named list of engineers, protected by multi-factor authentication and monitored by an intrusion detection system.
  • Audit logging: every access to personal information is logged with the identity of the actor, the record affected and the timestamp of the operation. Audit logs are retained for twelve (12) months.
  • Segregation of environments: production, staging and development environments are logically and physically separated. Production data is never copied into non-production environments.
  • Vulnerability management: dependency vulnerability scans run daily and patches are applied within a defined service-level target. Quarterly penetration tests are commissioned from an independent third party and remediation plans are tracked to completion.
  • Backups: encrypted backups are held in a separate Australian region and are tested for successful restoration.
  • Business continuity: a documented business continuity and disaster recovery plan is maintained and exercised at least annually.

11. Assistance with data subject requests

Taking into account the nature of the processing, CloudBookMod assists the Customer by appropriate technical and organisational measures, insofar as this is possible, in fulfilling the Customer's obligations to respond to requests by data subjects to exercise their rights under the Australian Privacy Principles, including the rights of access under APP 12 and correction under APP 13. Where CloudBookMod receives a request directly from a data subject in respect of personal information processed on behalf of the Customer, CloudBookMod will, without responding to the request itself, forward the request to the Customer within five (5) business days.

12. Data breach notification

CloudBookMod maintains a documented data breach response plan aligned with the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act 1988 (Cth). If CloudBookMod becomes aware of a data breach affecting personal information processed on behalf of the Customer, CloudBookMod will notify the Customer without undue delay and in any event within seventy-two (72) hours of becoming aware of the breach, providing at a minimum:

  • a description of the nature of the breach, including where possible the categories and approximate number of data subjects and records affected;
  • the likely consequences of the breach;
  • the measures taken or proposed to address the breach and to mitigate its possible adverse effects;
  • the contact point at CloudBookMod from whom more information can be obtained.

Where the breach is an "eligible data breach" within the meaning of section 26WE of the Privacy Act 1988 (Cth), the Customer is responsible for notifying the affected individuals and the Office of the Australian Information Commissioner in accordance with section 26WK of that Act. CloudBookMod will assist the Customer in preparing those notifications by providing the information reasonably required.

13. Audit rights

CloudBookMod makes available to the Customer, upon reasonable written request and no more than once per calendar year, all information necessary to demonstrate compliance with the obligations set out in this DPA, including summaries of the latest independent penetration test, of the SOC 2 Type II report of its hosting provider and of its own annual internal review. Where the Customer reasonably considers that further verification is required, the parties will agree in good faith on the scope, timing and cost of an audit conducted by an independent auditor bound by professional secrecy, at the Customer's expense, and carried out in a manner that does not interfere with the operation of CloudBookMod's other customers' services.

14. Return or deletion of data

Upon termination of the corresponding Subscription or Order, and in any event within thirty (30) days after the last effective date of processing, CloudBookMod will, at the Customer's written choice, either return to the Customer an export of the personal information in a structured, commonly used, machine-readable format, or securely delete such personal information from its production systems and, on the ordinary rotation schedule, from its backups. Where CloudBookMod is required to retain any personal information by an Australian law or court order, it will inform the Customer of that requirement and restrict its processing to the minimum necessary for compliance.

15. Liability

The liability of each party under this DPA is subject to the limitations and exclusions set out in the Terms of Service, subject always to the non-excludable rights and remedies of the Customer under the Australian Consumer Law. Where CloudBookMod is liable to the Customer for a breach of this DPA that also gives rise to a civil penalty under the Privacy Act 1988 (Cth), CloudBookMod's liability includes reimbursement of any civil penalty imposed on the Customer to the extent that the penalty is proximately caused by CloudBookMod's breach.

16. Order of precedence

In the event of any inconsistency between this DPA and the Terms of Service in respect of the handling of personal information, this DPA prevails to the extent of the inconsistency. In the event of any inconsistency between this DPA and the Privacy Act 1988 (Cth) or any other applicable Australian law, that law prevails.

17. Governing law and jurisdiction

This DPA is governed by and construed in accordance with the laws of the State of Victoria and the Commonwealth of Australia. Each party irrevocably submits to the non-exclusive jurisdiction of the courts of the State of Victoria, including the Supreme Court of Victoria in Melbourne, and the courts entitled to hear appeals from them.

18. Contact

CloudBookModMod Pty Ltd
156 Collins Street, Level 12, Melbourne VIC 3000, Australia
Director: Sarah Mitchell
Telephone: +61 3 9642 7853
Email: support@cloudbookmod.org
ABN: 82 743 951 268 — ACN: 743 951 268
Regulator: Office of the Australian Information Commissioner (OAIC), oaic.gov.au

Effective from 11 August 2026.

CloudBookMod

Modules, extensions and integrations for NewBook Cloud PMS

Independent shop of modules, extensions and integrations for NewBook Cloud PMS — the Australian holiday park and hotel property management platform.

Shop

  • All extensions
  • Pricing
  • Compare
  • ROI calculator
  • Checkout

Resources

  • Modules
  • Integrations
  • Blog
  • Guides
  • Academy
  • Changelog
  • API documentation

Company

  • About
  • Contact
  • Support
  • Security
  • Terms
  • Privacy
  • Cookies
  • DPA
  • Refund policy
CloudBookModMod Pty Ltd — ABN: 82 743 951 268 — ACN: 743 951 268 — 156 Collins Street, Level 12, Melbourne VIC 3000, Australia — Director: Sarah Mitchell — support@cloudbookmod.org — Tel: +61 3 9642 7853 — Commonwealth Bank of Australia, BSB 062-345, Acc 789012345.
CloudBookMod is an independent third-party marketplace and is in no way affiliated with, sponsored by or endorsed by NewBook Pty Ltd or its parent company. All trademarks, product names and logos are the property of their respective owners. Supervisory authority for data protection: Office of the Australian Information Commissioner (OAIC). Jurisdiction: Supreme Court of Victoria, Melbourne. Applicable legal framework: Privacy Act 1988 (Cth) — Australian Privacy Principles — Australian Consumer Law under the Competition and Consumer Act 2010 (Cth).
© 2024–2026 CloudBookModMod Pty Ltd. All rights reserved.
Terms Privacy Cookies DPA Refunds

Your cart

Total A$0.00
Checkout →

We use cookies to improve your experience and analyse site performance. Learn more