Doorwise

Effective 31 August 2026 · Version 2026-08-31

Data Processing Terms

These terms describe Doorwise’s processing of personal information contained in Customer Data and form part of the Terms and Conditions for organisations using Doorwise.

1. Roles and scope

These Data Processing Terms apply when Doorwise processes personal information in Customer Data for a customer organisation. The customer determines why and how that information is used for its prospecting and agency activities and acts as the organisation responsible for that handling. Doorwise processes it as a service provider on the customer’s documented instructions, except where Doorwise must process information for its own account administration, security, billing or legal obligations as described in the Privacy Policy.

Customer Data may include property contacts, addresses, phone numbers, email addresses, notes, activities, appointments, marketing permissions, contact outcomes, team assignments and imported records. Data subjects may include property owners, prospects, customers, agency personnel and other contacts. Processing continues for the subscription term and applicable retention or recovery periods.

2. Customer instructions and responsibilities

The customer instructs Doorwise to collect, host, organise, match, retrieve, transmit, export, delete and otherwise process Customer Data as needed to provide and secure the service and as users direct through its features.

The customer must:

  • have a lawful basis and provide any required notices for Customer Data;
  • ensure instructions comply with privacy, Spam Act, Do Not Call Register and other applicable laws;
  • configure user access, retention and contact-permission records appropriately;
  • avoid entering unnecessary sensitive information into free-text notes; and
  • respond to individuals and regulators where the customer is responsible for the relevant processing.

3. Doorwise obligations

Doorwise will:

  • process Customer Data only to provide, secure and support the service, follow documented customer instructions, or comply with law;
  • ensure people authorised to process Customer Data are subject to confidentiality obligations;
  • use reasonable technical and organisational safeguards appropriate to the risk;
  • notify the customer if an instruction appears to breach applicable privacy law, where reasonably able to determine this;
  • provide reasonable assistance with access, correction, deletion, complaints, impact assessments and regulator enquiries, taking account of the nature of the processing; and
  • maintain records reasonably necessary to demonstrate compliance with these terms.

4. Security measures

Doorwise’s measures include tenant-level access controls, encryption in transit, protected credentials, restricted privileged access, multi-factor controls for administrative access, audit and security records, rate limiting, backups, monitoring, dependency and configuration checks, and procedures for deployment and incident response. Measures may evolve as technology and risk change, provided overall protection is not materially reduced.

5. Subprocessors

The customer authorises Doorwise to use subprocessors necessary to operate the service, including:

  • Supabase for database and authentication services;
  • Stripe for checkout, subscription and billing services;
  • Cloudflare for network security and abuse prevention;
  • infrastructure, backup and email delivery providers; and
  • mapping and property-data providers when a requested feature requires them.

Doorwise will require subprocessors to protect Customer Data consistently with their role and applicable law. We will update these public terms when subprocessors materially change. A customer with a reasonable data-protection objection may contact us before continuing affected use.

6. Overseas processing

The customer authorises processing in Australia and in countries where authorised subprocessors operate, which may include the United States and other locations. Doorwise will take reasonable steps appropriate to the circumstances to require suitable privacy and security protections for overseas processing where Australian privacy law applies.

7. Security incidents

Doorwise will investigate a confirmed unauthorised access to, disclosure of, loss of or material interference with Customer Data. We will notify the affected customer without undue delay after confirming an incident where notification is reasonably required, provide available information needed for the customer’s assessment, take reasonable containment and remediation steps, and cooperate with legally required notifications. Notification is not an admission of fault.

8. Access, export, return and deletion

Doorwise provides workspace export and retention controls. During the subscription, the customer may use those controls or request reasonable assistance. On termination, the customer should export required data promptly. Subject to legal retention, security and backup cycles, Doorwise will delete or de-identify Customer Data after the applicable retention and recovery period. Retention holds requested or configured by the customer may delay deletion.

9. Reviews and information

On reasonable written request, Doorwise will provide information reasonably necessary to demonstrate compliance with these terms. If that information is insufficient and the customer has a substantiated compliance concern, the parties will agree on a proportionate independent review that protects other customers, security and confidential information. The customer bears review costs unless a material breach by Doorwise is found.

10. Priority, liability and contact

If these Data Processing Terms conflict with the Terms and Conditions about processing Customer Data, these Data Processing Terms prevail for that issue. The liability provisions in the Terms and Conditions apply. Data-protection requests may be sent to support@doorwise.com.au.

Data Processing Terms | Doorwise