Data Processing Addendum

Ethical Prospecting Pty Ltd (ABN 34 605 805 409)
Trading as Comparable (www.comparable.com.au)

1. Purpose & Relationship to Main Agreement

This DPA forms part of and is incorporated into the [Master Services Agreement / Panel Agreement / Commercial Agreement] between the Parties (the “Main Agreement”). It governs the handling of Personal Information/PII processed under the Main Agreement.

This DPA is designed to align with ISO/IEC 27701 (Privacy Information Management), extending the Parties’ ISO 27001-style information security practices to privacy, and to comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), including the Notifiable Data Breaches (NDB) scheme.

2. Definitions

  • APPs means the Australian Privacy Principles in the Privacy Act 1988 (Cth).
  • Controller / PII Controller means the entity determining purposes and means of Processing Personal Information.
  • Processor / PII Processor means the entity Processing Personal Information on behalf of a Controller.
  • Data Subject / PII Principal means an identified or reasonably identifiable individual.
  • Personal Information / PII means information about an identified individual, or an individual who is reasonably identifiable (including contact data, sign-up data, call recordings, IDs, and workforce data).
  • Panel Partners means retailers/providers on Comparable’s panel.
  • Sub-processor means a third party engaged by a Processor to Process Personal Information.
  • Privacy Officer / Data Protection Officer (DPO) means the individual appointed by a Party responsible for privacy compliance, incident coordination, and liaison with regulators/data subjects.
  • Processor List means the list in Annex C describing Sub-processors.

3. Role Matrix (Controller/Processor) — ISO 27701 Mapping

Comparable as Controller (PII Controller)

  • Lead generation and acquisition (own websites and third-party sites).
  • Pre-sales consultation, comparison, and customer communications.
  • Marketing (subject to Spam Act and DNC rules), analytics, and service improvement.
  • Workforce/HR data as employer (not shared with Panel Partners).

Comparable as Processor (PII Processor) to Panel Partners

Where Comparable Processes Personal Information solely on a Panel Partner’s documented instructions to submit/sign up customers with the Panel Partner and transmit required data to open/manage accounts (e.g., EIC capture, sign-up payloads, status updates). In this mode, the Panel Partner is Controller and Comparable is Processor.

Counterparty Roles: Counterparty may be a Controller (e.g., Panel Partner managing the customer relationship) and/or a Processor (e.g., receiving limited data to perform a service for Comparable). Roles are set out in Annex A.

Joint/Independent Controllers: If both Parties determine purposes/means for a specific Processing activity, they act as independent controllers unless expressly documented as joint controllers in Annex A (with responsibilities allocated).

4. Details of Processing (Annex A)

The nature, purpose, types of Personal Information, categories of Data Subjects, and retention are described in Annex A and Annex E.

5. Lawful Basis & Transparency (APPs)

Each Party will:

  • Ensure collection and use are lawful and fair and (where required) based on consent or other APP-consistent basis.
  • Provide clear privacy notices (APP 1/5).
  • Handle access/correction requests (APP 12/13).
  • Honour marketing opt-outs and the Spam Act 2003 (Cth) and Do Not Call Register Act 2006 (Cth).

6. Instructions (Processor Mode)

When acting as Processor, Comparable will:

  • Process only on documented instructions from the Controller (including API specs, order forms, written emails).
  • Inform the Controller if an instruction infringes applicable law.
  • Assist the Controller with Data Subject requests, security, breach assessment/notification, and PIA/Privacy Impact Assessments to the extent reasonably required.

7. Confidentiality & Personnel

Each Party ensures that personnel (including India back-office) with access to Personal Information:

  • Are bound by confidentiality obligations.
  • Receive role-appropriate privacy & security training (initial and annual refresh).
  • Undergo appropriate screening consistent with local law and company policy.

8. Security (Annex B)

Each Party maintains a risk-based security program aligned to ISO 27001 and extends privacy controls per ISO 27701 (roles: PII Controller/Processor). At minimum: access control and MFA, encryption in transit/at rest, network security/WAF, patching and vulnerability management, logging/monitoring, incident response, vendor due diligence, secure disposal. See Annex B for detail.

9. Sub-processors (Annex C) & Change Management

Comparable may use Sub-processors (e.g., Zoho, Aircall, AWS, Cloudflare, Twilio) and is responsible for their compliance. Comparable will:

  • Maintain the Processor List (Annex C).
  • Impose written terms requiring comparable protections to this DPA.
  • Provide advance notice of material changes to Sub-processors; Controllers may object on reasonable, documented grounds relating to data protection.

10. Cross-Border Handling & India Back-Office (APP 8)

Where Personal Information is disclosed overseas (including to Comparable’s back-office in India):

  • The disclosing Party will take reasonable steps to ensure the overseas recipient does not breach the APPs in relation to the information (APP 8).
  • Transfers use secure channels and are limited to personnel with a need-to-know; contractual, organisational, and technical safeguards will apply (see Annex D).
  • No workforce data will be shared with Panel Partners unless explicitly required and agreed.

11. Data Subject Requests

Each Party will promptly notify the other of Data Subject requests received and cooperate as needed. Controllers remain responsible for responding to requests under APP 12/13. Processors will support Controllers with appropriate technical/organisational measures.

12. Records, Risk & PIAs

Each Party will maintain appropriate records of Processing, perform risk assessments/PIAs where warranted by risk or law, and maintain a PIMS per ISO 27701 Annex A/B controls relevant to its role.

13. Breach Management (NDB Scheme)

  • Each Party will maintain an incident response plan and notify the other without undue delay and no later than 48 hours after becoming aware of an incident likely to involve Personal Information shared under this DPA.
  • Parties will cooperate to assess within 30 days (or as soon as practicable) whether the incident is an eligible data breach under the NDB scheme and, if so, support notifications to the OAIC and affected individuals by the Controller (or by the Party otherwise obligated by law).
  • Notifications between the Parties will include available facts, categories and volume of data, likely impacts, and steps taken.

14. Retention & Deletion (Annex E)

Retention will follow Annex E (no longer than necessary for the purposes or legal/accounting obligations). On termination/expiry or completion of services, Processors will delete or return Personal Information (at Controller’s option) unless retention is required by law; deletion includes backups on normal cycles, with certificate of destruction upon request.

15. Audits & Assurance

Upon reasonable prior notice, a Controller may:

  • Review relevant third-party audit reports/certifications (e.g., ISO, SOC), security summaries, and penetration test summaries; and
  • Conduct (or commission) a confidential audit once per 12 months (or following a material incident), during business hours, without disrupting operations, and subject to confidentiality and reasonable cost/recovery principles.

16. Liability & Indemnity

As per the Main Agreement. Where not specified, each Party is responsible for its own acts/omissions and those of its Sub-processors relating to Personal Information under this DPA.

17. Order of Precedence; Changes

If there is a conflict, this DPA prevails over the Main Agreement with respect to privacy/security matters. Comparable may update Annexes for accuracy and will notify material changes.

18. Privacy Officer / DPO Contact

Comparable DPO: Tarun Chhimwal, Email: privacy@comparable.com.au.

Annex A — Details of Processing

A1. Activities & Roles

  • Lead Generation & Pre-Sales (Comparable as Controller): Collect, enrich, and manage leads from Comparable websites and third-party publishers; consult, compare offers, schedule calls, send Explicit informed consent (EIC) (digital or voice recording)/SMS, track attribution.
  • Sign-Up Fulfilment (Comparable as Processor to Panel Partners): Capture and transmit sign-up data to Panel Partners to open/manage customer accounts, in accordance with the Panel Partner’s instructions and API specs.
  • Workforce/HR (Comparable as Controller): Employee/contractor data for HR, payroll, IT access, QA/training. Not shared with Panel Partners.

A2. Categories of Data Subjects

  • Consumers/leads, prospective and current customers.
  • Comparable employees and contractors (workforce).

A3. Types of Personal Information

  • Identity & contact: name, address, email, phone, DOB.
  • Service information: distributor/tariff, NMI/MIRN (if applicable), plan preferences, usage estimates, EIC artefacts, order IDs, account numbers.
  • Interaction data: call recordings/notes, chat logs, CRM activity, attribution (UTM, gclid/Meta click IDs).
  • Technical: IP, device, cookies where applicable.
  • Workforce: employment details, contact, role, training/QA records, device identifiers.

A4. Special/Sensitive Information

If sensitive information (e.g., concession card identifiers) is processed, it will be limited to what is necessary, protected proportionately, and retained per Annex E.

A5. Duration

For the term of the Main Agreement plus retention in Annex E.

A6. Panel Partner Instructions (Processor Mode)

  • Accept and validate customer sign-up data;
  • Capture/attach EIC evidence;
  • Transmit required payloads to Panel Partner systems;
  • Provide error/status callbacks;
  • Support lawful customer service follow-ups.

Annex B — Security & PIMS Controls (Minimum)

  • B1. Governance & ISO Alignment: ISMS aligned to ISO 27001; PIMS aligned to ISO 27701 with role mapping (Controller/Processor). Policies covering access, acceptable use, classification, retention/disposal, vendor risk, incident response, privacy by design/default.
  • B2. Access & Identity: RBAC, least privilege; MFA for privileged and remote access; joiner-mover-leaver with timely revocation.
  • B3. Encryption & Key Management: TLS 1.2+ in transit; AES-256 or equivalent at rest; managed keys; secrets management.
  • B4. Endpoint & Network Security: Managed endpoints with EDR/AV, disk encryption, patch SLAs; hardened servers; segmented networks; WAF/CDN (e.g., Cloudflare) and rate limiting.
  • B5. Application Security: Secure SDLC, code review, dependency scanning; annual pen tests; vulnerability remediation SLAs.
  • B6. Monitoring & Logging: Centralised logging, anomaly detection, alerting; protected, time-synchronised logs; admin audit trails.
  • B7. Business Continuity & Backup: Tested backups; DR objectives defined; cloud region resilience.
  • B8. Vendor/Sub-processor Management: Risk-based due diligence; contractual clauses; continuous monitoring; change notifications.
  • B9. Data Handling & Minimisation: Purpose limitation, data minimisation, masking/pseudonymisation where practical; secure test data handling.
  • B10. Training & Awareness: Mandatory privacy/security training on hire and annually (APPs, Spam Act, DNC compliance, social engineering, data handling).

Annex C — Processor List (Comparable Sub-processors)

Sub-processorService/FunctionPersonal Information ProcessedPrimary Region(s)Notes/Security Posture
Zoho One (CRM, Desk, etc.)CRM & support toolsLead/customer profiles, interactions, tickets, workforceSydney, AUEnterprise security; regional hosting options; MFA supported
AircallContact centre/diallerCall metadata & recordingsSydney, AUEnterprise security; regional hosting options; MFA supported
AWSCloud hostingApplication/DB hosting, backups, logsap-southeast-2 (Sydney)ISO/SOC certified; robust security
CloudflareCDN/WAF/DDoSEdge traffic (IP, headers), cachingGlobal edge (incl. AU)Security & performance; minimal PII retention
TwilioSMSPhone numbers, message content/metadataPer service/regionSecurity & performance; minimal PII retention
Comparable Back-Office (India)Back-office processing, QA, validationCustomer data required for QA, processing, marketing.IndiaOrganisational controls; RBAC

Annex D — Overseas Disclosures & India Back-Office Controls (APP 8)

  • Contractual Controls: Confidentiality, purpose limitation, APP-consistent privacy clauses, audit rights, and breach cooperation.
  • Organisational Controls: Need-to-know access, named roles, training, secure workspace standards, device management, no local copies unless necessary.
  • Technical Controls: Encrypted transport/storage; MFA; remote-wipe capability; restricted export/download; IP allow-listing for admin access.
  • Monitoring: Activity logging for data access; periodic access reviews; quarterly vendor/back-office reviews.
  • Data Flows: Clearly documented datasets accessible to India team; no workforce HR files shared with Panel Partners; minimal data for task fulfilment.

Annex E — Retention & Deletion Schedule

Data CategoryTypical PurposeRetentionNotes
Leads (unconverted)Follow-up, analyticsUntil opted outRespect opt-outs; suppress on request
Converted customer sign-up dataEstablish service with Panel Partners; evidence, remarketingUntil opted outRespect opt-outs; suppress on request
EIC artefacts (digital/voice)Evidence of consent & complianceActive 2 years, archive up to 5 years (total up to 7)Secure archive; restricted access
Attribution data (gclid/Meta IDs)Fraud prevention, performance analytics12–24 monthsPseudonymise where possible
Call recordings (sales/service)QA, training, dispute resolutionActive 2 years, archive up to 5 yearsRedact sensitive data where feasible
Workforce HR filesEmployment, payroll, complianceUp to 7 years post-employmentSegregated; not shared with Panel Partners

Deletion on Exit: Upon request or contract end (and where legally permissible), data is securely erased from active systems and removed from backups on standard cycles.

Annex F — ISO 27701 Role & Control Mapping (Guide)

ProcessComparable RoleCounterparty RoleExample ISO 27701 Controls
Lead capture & nurturingControllerA.7.2.1 (privacy policies), A.7.2.2 (roles), A.7.4.x (PII principals’ rights)
Sign-up fulfilment to Panel PartnerProcessorControllerA.8.2.x (Controller-Processor), A.8.3.x (Processor obligations), A.7.5.x (PII sharing/transfer)
Workforce/HRControllerA.7.2.5 (retention), A.7.4.5 (access/correction), A.7.4.6 (objection/consent)
Cross-border (India back-office)Controller/ProcessorController/ProcessorA.7.5.1–A.7.5.4 (PII sharing/transfer, cross-border)
Vendor/Sub-processor mgmtController/ProcessorController/ProcessorA.6.12, A.8.2.1, A.8.2.5 (due diligence, terms, monitoring)

Annex G — Contact & Notices

Annex H — Privacy Summary (Plain English)

Who we are

Ethical Prospecting Pty Ltd T/A Comparable (34 605 805 409) of 7 Cooks Way, Taylors Hill, Victoria 3037 (“Comparable”) helps Australians compare and switch to better deals across our Panel Partners. We generate and purchase leads, consult with customers, and—when they choose a Panel Partner—send their sign-up information to that Panel Partner to open and manage the customer’s account.

Scope of this summary

This summary explains, in simple terms, how we handle personal information when we act as:

  • a Controller for our own lead generation, consulting, marketing, QA/training, and workforce activities; and
  • a Processor for Panel Partners when we process data solely on their instructions to complete sign-ups and service transitions.

It complements (but does not replace) the detailed obligations in the Data Processing Addendum (DPA).

What we collect

  • Customer & lead data: name, contact details, address, plan preferences, distributor/tariff info (e.g., NMI/MIRN where applicable), usage estimates, sign-up details, consent records (EIC), interactions (calls/chats/emails), and attribution data (e.g., gclid/Meta click IDs).
  • Technical data: IP address, device/browser info, activity logs for security and service performance.
  • Workforce data (employees/contractors): contact and employment details, training/QA records, device identifiers, access logs.

We generally don’t need sensitive information. If a service requires it (e.g., concession status), we’ll limit collection to what’s necessary and protect it appropriately.

Why we collect it (purposes)

  • Compare & switch: consult with customers, present options, complete sign-ups to chosen Panel Partners, provide required sign-up payloads and evidence of consent.
  • Operate, secure, and improve services: troubleshooting, QA, training, analytics, fraud prevention.
  • Communications & compliance: service updates, lawful marketing with easy opt-out, compliance with the Privacy Act 1988 (Cth), APPs, Spam Act 2003, and Do Not Call Register Act 2006.
  • Workforce management: onboarding, payroll, training, system access, compliance.

Our roles at a glance

  • Comparable as Controller: lead generation and nurturing, consulting, analytics, marketing (opt-out honoured), QA/training, workforce management.
  • Comparable as Processor to Panel Partners: processing the customer’s sign-up details and related actions only on the Panel Partner’s documented instructions.

Who we share with

  • Panel Partners: when a customer chooses a Panel Partner, we send necessary information so the partner can open and manage the account.
  • Trusted Sub-processors (service providers): Zoho (CRM/support), Aircall (dialler/call recordings), AWS (hosting), Cloudflare (WAF/CDN), Twilio (SMS/voice). These providers help deliver our services and are bound by contracts requiring strong privacy and security controls.
  • Comparable back-office (India): limited, role-based access to support operations/QA.
  • Required disclosures: where the law requires or to protect rights, safety, and security.

We do not sell personal information.

Overseas disclosures (APP 8)

Some processing occurs outside Australia, including our back-office in India and global cloud/edge services. We take reasonable steps to ensure overseas recipients don’t breach the APPs, including contractual, organisational, and technical controls (encryption, access controls, monitoring, least-privilege, audit rights).

Security (ISO 27001/27701-aligned)

We run an Information Security Management System aligned to ISO 27001 and extend privacy controls per ISO 27701. Core measures include encryption in transit/at rest, MFA and role-based access, secure development and change control, logging/monitoring, vulnerability management, vendor due diligence, incident response, and tested backups/DR.

Retention & deletion (high level)

We keep personal information only as long as needed for the purposes above and legal/accounting requirements. Typical periods (see DPA Annex E for detail):

  • Leads (unconverted): until opted out.
  • Converted sign-up data & evidence (EIC/call recordings): up to 7 years (with archival).
  • Attribution data (e.g., gclid/Meta IDs): 12–24 months.
  • Workforce records: up to 7 years post-employment (as required by law).

On request or contract end (where legally permitted), we delete or return data and remove it from backups on normal cycles, with a certificate available on request.

Your choices & rights

  • Access & correction (APP 12/13): request access to, or correction of, your personal information.
  • Marketing opt-out: every marketing message includes an easy opt-out; we maintain suppression lists.
  • Complaints: contact us first; you can also contact the OAIC.

Breaches (NDB scheme)

If we suspect a data breach likely to result in serious harm, we’ll act quickly to assess and, where required, notify the OAIC and affected individuals, and cooperate with Panel Partners as appropriate. We also notify counterparties promptly under the DPA.

Contact (Privacy Officer / DPO)

Email: privacy@comparable.com.au
For security/urgent matters: privacy@comparable.com.au

Updates to this summary

We may update this summary from time to time to reflect changes to our services or law. The DPA governs if there’s any inconsistency.