Reachable

Data Processing Agreement

Version 1.0 · Effective 26 August 2026

Processor: 121 Group Pty Ltd · ABN 49 152 344 780 · ACN 152 344 780
Address: Level 7, 222 Exhibition Street, Melbourne VIC 3000, Australia

This Data Processing Agreement (DPA) applies automatically to every customer under the Terms of Service when 121 Group Pty Ltd processes Personal Information in Customer Data. The customer identified in the subscription or order form is the Customer. A negotiated DPA signed by both parties prevails for that Customer.

1. Definitions

1.1 Customer Data means Personal Information supplied to or collected through Reachable at the Customer's direction, including contact lists, consent records, identifiers, message content, transactions and engagement events.

1.2 Personal Information has the meaning in the Privacy Act 1988 (Cth) and includes an analogous concept such as personal data where another applicable privacy law uses it.

1.3 Privacy Laws means the Privacy Act, Australian Privacy Principles, Notifiable Data Breaches scheme, Spam Act 2003 (Cth), and other privacy or data-protection laws applicable to the processing.

1.4 Subprocessor means a third party engaged by Reachable to process Customer Data to provide the Service.

2. Roles and instructions

2.1 The Customer controls Customer Data, its purpose and the relationship with its recipients. The Customer is responsible for its lawful collection, instructions, messages and consents.

2.2 Reachable processes Customer Data for the Customer only to provide, secure and support the Service; on instructions expressed through the Service, Terms, order form and this DPA; or as required by law. If law requires other processing, Reachable will inform the Customer unless legally prohibited.

2.3 Reachable will notify the Customer if it reasonably believes an instruction breaches Privacy Laws and may pause that instruction while the parties address it.

3. Processing details

3.1 Subject and purpose: hosting contact data; integration and import; segmentation; message transmission; recording delivery, engagement and transaction events; consent and suppression management; attribution, reporting, support and security.

3.2 Duration: the subscription term and 30-day export window, plus limited backup cycling, suppression and legally required retention described below.

3.3 People: the Customer's subscribers, customers, leads and other contacts. Data: names, email addresses, phone numbers, identifiers, consent, custom attributes, transaction and engagement history, message content and any information the Customer elects to supply.

3.4 Reachable does not sell Customer Data, use contact lists for its own marketing or disclose Customer Data to another customer. It may use aggregated or de-identified data only where no Customer, user or recipient is reasonably identifiable.

4. Confidentiality and security

4.1 Reachable will ensure authorised personnel are bound by confidentiality and receive appropriate privacy and security guidance.

4.2 Reachable will maintain technical and organisational safeguards appropriate to risk, including encryption in transit, role-based access, hashed passwords, optional user 2FA, session controls, secret management, logical tenant separation with row-level security, audit records for administrative actions and exports, backups and incident handling.

4.3 Internal access to individual records is restricted to authorised operational, support, abuse, security and legal need. Reachable does not represent that every record read is individually logged.

5. Location and international processing

5.1 The Reachable application, primary database and backups are configured in Australian Google Cloud regions. Customer campaign email is sent through Amazon SES in ap-southeast-2 (Sydney).

5.2 Limited processing may occur outside Australia through email or SMS transit, billing, edge security, account email, sign-in, recipient networks and integrations enabled by the Customer. Likely countries include Australia, the United States and locations in which the recipient network or Customer-selected integration operates.

5.3 Reachable will take reasonable steps to use appropriate contractual and organisational safeguards for cross-border processing required by applicable Privacy Laws.

6. Subprocessors

6.1 The Customer generally authorises the providers on the current Subprocessors page. Core and optional providers include:

ProviderPurposeLocation note
Google CloudApplication, database, backup and secrets infrastructureAustralian regions configured for Customer Data
Amazon Web ServicesSES campaign delivery, bounce and complaint processingap-southeast-2 (Sydney); message transit follows recipients
ResendPlatform account email and email delivery where configuredGlobal provider; may process in the United States
MobileMessage and carriersSMS delivery and receiptsAustralian provider path; transit depends on destination carrier
StripeCheckout, subscriptions, invoices and card billingGlobal infrastructure; card data is not stored by Reachable
CloudflareDNS, edge security, TLS and traffic deliveryGlobal edge network
Google Workspace / Google IdentitySupport email and optional Google sign-inGlobal infrastructure
ShopifyOptional customer, order, product and checkout integrationOnly when enabled by the Customer; global infrastructure

6.2 Reachable will impose appropriate data-protection obligations on each Subprocessor and remains responsible for its performance to the extent required by this DPA and applicable law.

6.3 Reachable will give at least 30 days' notice of a material new or replacement Subprocessor. If the Customer reasonably objects on data-protection grounds and no reasonable alternative resolves the objection, the Customer may terminate the affected Service without penalty before the change and receive a pro-rata refund of prepaid fees after termination.

7. Data breach

7.1 Reachable will notify the Customer without undue delay and, where practicable, within 72 hours after becoming aware of a security breach causing accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or access to Customer Data.

7.2 To the extent known, notice will describe the nature, affected records and people, likely consequences, containment and remediation. Reachable will provide reasonable updates and assistance with the Customer's Notifiable Data Breaches obligations.

8. Individual requests and compliance assistance

8.1 Taking account of the processing, Reachable will reasonably assist the Customer with access, correction, deletion, complaint and regulatory requests concerning Customer Data. Reachable will normally refer a direct recipient request to the Customer, except that unsubscribe and STOP requests are actioned automatically.

8.2 Reachable will make reasonably necessary information available to demonstrate compliance, including security and Subprocessor summaries.

8.3 Once in a 12-month period, and additionally following a breach affecting the Customer, the Customer may conduct a reasonable compliance audit by questionnaire or remote review on 30 days' notice. An audit must occur in business hours, protect confidentiality, not expose other customers' data, and avoid unreasonable disruption. Each party bears its costs. An appropriate independent report may satisfy the request.

9. Return and deletion

9.1 Customer Data may be exported in a standard machine-readable format during the subscription and for 30 days after service ends where the Customer has requested workspace closure.

9.2 After that window, Reachable will delete Customer Data from active systems and allow backups to cycle out, except minimal suppression information required to honour opt-outs and records required by law. On written request, Reachable will confirm completion.

10. General

10.1 This DPA prevails over the Terms for Customer Data processing. Liability is subject to the Terms.

10.2 Victorian law governs this DPA. Notices may be sent to privacy@121group.io and the Customer's nominated contact. To request a negotiated version, contact legal@121group.io.