Data Processing Agreement

Between Raynux Pty Ltd (ABN 38 700 717 166), Level 29, 221 St Georges Terrace, Perth WA 6000, Australia (Raynux, the Processor) and the customer that accepts it (the Customer, the Controller). Version 2.0. Effective date: 30 September 2026. Supersedes the previous Data Processing Agreement (2018).

This Data Processing Agreement (DPA) forms part of, and is incorporated into, the Librarika Terms of Use between Raynux and the Customer (the Agreement). It applies where Raynux processes personal data on the Customer’s behalf in providing Librarika. Where this DPA and the Agreement conflict on the processing of personal data or the rights of data subjects, this DPA prevails. A counter-signed copy is available on request at info@raynux.com.

1. Definitions

Data protection law means all laws applicable to the processing of personal data under the Agreement, including the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), and, where they apply, the EU General Data Protection Regulation (GDPR) and the UK GDPR. Controller, Processor, Personal data, Processing, Data subject, Personal data breach and Supervisory authority have the meanings given in the GDPR. Sub-processor means a third party engaged by Raynux to process personal data in providing Librarika. SCCs means the Standard Contractual Clauses in European Commission Implementing Decision (EU) 2021/914. UK Addendum means the UK Information Commissioner’s International Data Transfer Addendum to the SCCs. Customer Personal Data means personal data that Raynux processes on the Customer’s behalf under the Agreement, as described in Annex 1.

2. Roles and scope

For patron, member and other personal data that the Customer puts into or generates in Librarika, the Customer is the Controller and Raynux is the Processor, processing that data on the Customer’s behalf. Each party will comply with its obligations under data protection law. The Customer is responsible for the lawfulness of the personal data it provides and for having any notices or consents required to collect and use it. The subject matter, duration, nature and purpose of the processing, the types of personal data and the categories of data subjects are set out in Annex 1.

3. Processing on documented instructions

Raynux will process Customer Personal Data only on the Customer’s documented instructions, including as set out in the Agreement, this DPA, and the Customer’s configuration and use of Librarika, unless required to do otherwise by a law to which Raynux is subject (in which case Raynux will, where lawful, inform the Customer first). Raynux will inform the Customer if, in its opinion, an instruction infringes data protection law. Raynux will not sell Customer Personal Data or use it for its own purposes; any use to improve or develop Librarika is limited to the Customer’s instructions or uses de-identified or aggregated data that does not identify any individual.

4. Confidentiality

Raynux will ensure that persons authorised to process Customer Personal Data are bound by appropriate obligations of confidentiality and are given access only on a need-to-know basis.

5. Security

Raynux will implement and maintain the technical and organisational measures set out in Annex 2 to protect Customer Personal Data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, appropriate to the risk. Raynux may update those measures provided the level of protection is not reduced.

6. Sub-processors

The Customer gives Raynux general authorisation to engage sub-processors to process Customer Personal Data. Raynux maintains a current list of its sub-processors, published on our Sub-processors page and also available on request at info@raynux.com. Raynux will impose data-protection obligations on each sub-processor that are substantially the same as those in this DPA, and remains liable to the Customer for its sub-processors’ performance. Raynux will give at least 30 days’ prior notice before a new or replacement sub-processor begins processing; Raynux may give this notice by a general notice — for example through the Service, a notice on its website, or an update to the sub-processor list — and is not required to notify each Customer individually by email. If the Customer reasonably objects on data-protection grounds within that period, the parties will work in good faith to resolve it, and if they cannot, the Customer may terminate the affected part of the Service.

7. International transfers

Librarika is a global service, so Customer Personal Data may be processed outside the Customer’s country, including in countries that do not have an adequacy decision. Where Raynux transfers personal data that is subject to the GDPR or UK GDPR from the EEA or UK to a country without an adequacy decision, the SCCs are incorporated into and form part of this DPA and apply to that transfer, as follows: Module Two (controller to processor) applies between the Customer (data exporter) and Raynux (data importer); and Module Three (processor to processor) applies to onward transfers by Raynux to a sub-processor. For transfers of UK personal data, the UK Addendum applies to and amends the SCCs. The optional docking clause applies; for the SCCs, the governing law is the law of Ireland and the forum is the courts of Ireland (or, where the SCCs require, the law and courts of the Member State of the data exporter); and the annexes to the SCCs are populated by Annex 1 and Annex 2 of this DPA, with the sub-processor list serving as the list of sub-processors. Raynux supports these transfers with a transfer risk assessment and appropriate supplementary measures. For personal data subject to the Australian Privacy Act, Raynux takes reasonable steps under APP 8 so that overseas recipients handle the data consistently with the APPs, and remains accountable under section 16C.

8. Assistance to the Customer

Taking into account the nature of the processing, Raynux will assist the Customer by appropriate technical and organisational measures, so far as reasonably possible, to: (a) respond to requests from data subjects exercising their rights; and (b) meet the Customer’s own obligations regarding security, personal-data-breach notification, data-protection impact assessments and prior consultation with supervisory authorities. If Raynux receives a request from a data subject relating to Customer Personal Data, it will refer the data subject to the Customer and, unless legally prohibited, promptly inform the Customer rather than responding itself except on the Customer’s instructions.

9. Personal data breach

Raynux will notify the Customer without undue delay, and where feasible within 72 hours, after becoming aware of a personal data breach affecting Customer Personal Data, and will provide the information the Customer reasonably needs to meet its own notification obligations and will assist the Customer in responding to and mitigating the breach.

10. Return or deletion

On termination of the Agreement, and at the Customer’s choice, Raynux will return or delete Customer Personal Data (and existing copies) within a reasonable period, unless a law to which Raynux is subject requires it to retain the data, and subject to back-ups being overwritten in the ordinary course. On request, Raynux will certify that it has done so. Retention and deletion are otherwise as described in the Agreement and the Privacy Policy.

11. Audit

Raynux will make available to the Customer the information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by the Customer or an auditor it mandates. To minimise disruption, Raynux may satisfy this obligation by providing current certifications, third-party audit reports or a completed security questionnaire; a Customer-led inspection may be conducted no more than once a year (unless required by a supervisory authority or following a breach), on reasonable notice, during business hours, subject to confidentiality, and without giving access to other customers’ data.

12. Liability, term and general

The liability of each party under or in connection with this DPA is subject to the limitations and exclusions of liability in the Agreement. This DPA takes effect on the effective date above (or, if later, when the Customer accepts the Agreement) and continues for as long as Raynux processes Customer Personal Data. It is governed by the law and jurisdiction stated in the Agreement, except that the SCCs are governed as stated in the SCCs. If any provision is unenforceable, the rest continues. This DPA applies to the Customer as part of the Agreement and takes effect when the Customer accepts the Agreement — no separate signature is required. Where a Customer needs a counter-signed copy for its own records, it may request one at info@raynux.com, and Raynux will provide a counter-signed copy (Raynux’s signature is provided in advance).

Annex 1 — Details of the processing

  • Subject matter and duration: provision of the Librarika Integrated Library System to the Customer for the term of the Agreement and any wind-down period.
  • Nature and purpose: hosting, storage, and processing of library and member records to operate, secure, support and improve the Service on the Customer’s instructions.
  • Types of personal data: identity and contact details (name, membership number, address, phone, email, and, where the Customer chooses, photo); library-activity data (loans, holds, reservations, fines, reviews and community/catalogue contributions, including borrowing history); files and content uploaded by the Customer or its users (which may contain personal data); account and administrator data; technical, usage and diagnostic data (IP address, device/browser information, log data, usage analytics and crash/error diagnostics); and any other fields the Customer configures — including, where the Customer records staff or employee details, identifiers such as a national identity number.
  • Categories of data subjects: the Customer’s library patrons and members, and the Customer’s staff and administrators; where the Customer serves children, that may include children.
  • Frequency of transfer: continuous, for the term of the Agreement.

Annex 2 — Technical and organisational measures

  • Encryption of personal data in transit (TLS/SSL); access controls, authentication and role-based permissions; least-privilege access for personnel and sub-processors.
  • Network, application and hosting security controls; logging and monitoring; and measures to restore availability and access to personal data after an incident.
  • Confidentiality obligations on personnel and sub-processors; no storage of production personal data on personal or unapproved devices, accounts or systems.
  • Processes for regular testing and review of the effectiveness of these measures, and for detecting, responding to and notifying personal-data and security incidents.