← Back to Derive

Data Processing Addendum

In force from 7 September 2026

A draft data processing addendum for schools and institutions that ask "do you have a DPA". It is a starting point for negotiation, not an executed agreement, and Derive has no institutional product today.

This is a draft, not a contract. Derive Notes Pty Ltd publishes it so that a school or institution asking whether we have a data processing addendum gets an honest answer about what exists. It has not been signed with anyone. It needs legal review on both sides and a signed agreement before any institutional deal, and several clauses describe commitments we would have to build the capability to keep. Nothing in it binds Derive or any counterparty until it is executed.

Derive is currently licensed for individual personal study. There are no institutional seats, no administrator role, no roster, and no way for an institution to reach or delete its users' data. See Children and students. Enquiries go to matt@derivenotes.com.

Parties and scope

This addendum would form part of the agreement between Derive Notes Pty Ltd (ACN 696 859 597) of 2/290 Boundary Street, Spring Hill QLD 4000, Australia ("Derive") and the customer named in the agreement ("Customer"). It would apply where Derive processes personal data on the Customer's behalf in providing the Derive service.

Roles

  1. Where an institution buys Derive for its students or staff, the Customer is the controller (or, in Australia, the APP entity) and Derive is the processor for the personal data in those accounts.
  2. Derive remains a controller in its own right for: billing records, its own security and fraud prevention, service diagnostics, and aggregate service statistics that do not identify an individual.
  3. Model training. Derive currently trains its own recognition models on user content as a controller, on an opt out basis, as described in the AI disclosure. A processor may not process for its own purposes, so an institutional agreement would need a commitment that Derive does not use institution directed accounts' content for model training. Derive does not yet have a per account flag to enforce that commitment. It must be built before this clause can be given.

Derive's instructions

  1. Derive processes personal data only on the Customer's documented instructions, which are: the agreement, this addendum, and the Customer's use of the service.
  2. Derive tells the Customer if an instruction appears to breach applicable data protection law.
  3. Advertising. Derive does not sell personal data, does not target advertising at anyone, and never uses Customer content for advertising. Derive does measure whether its own adverts work, as section 13.6 of the Privacy Policy describes: on the web app only, for accounts created since that section came into force, held by people 18 or over who have accepted analytics, Meta is told that a sign up, a trial or a payment happened. Derive does not have a per account flag that would exclude institution directed accounts from that measurement. As with model training above, that flag must be built before this clause can be given.

Confidentiality

Derive ensures that anyone authorised to process the personal data is bound by confidentiality. Today that is the founder. Any future contractor would be engaged under written confidentiality terms before being given access.

Security measures

Derive maintains the following technical and organisational measures. This list describes what is in place today, and what is not.

In place.

  • Row level access control is enabled on every application table, so one account cannot read another's data.
  • All file stores are private and scoped to the owning account's folder. Files are served through expiring links.
  • All traffic is encrypted in transit. Strict transport security and a restrictive content security policy ship on every response.
  • Payment card numbers are never received or stored by Derive. Only the card brand, last four digits and expiry month are stored, copied from the payment provider.
  • Analytics and diagnostics traffic is routed through Derive's own servers, which remove the user's IP address before the data reaches the provider.
  • Free text search queries retained for diagnostics are encrypted at rest at the application layer, and are not stored at all if the encryption key is missing.
  • Endpoints enforce per user and global rate limits and a spend ledger.
  • Webhooks fail closed on signature and secret checks.
  • Session recording in the error monitoring tool is fully masked and the canvas is deliberately excluded.

Not in place, and needed before an institutional deal.

  • No documented incident response process and no published breach notification commitment.
  • No in application audit log, so a privileged read of user content by an operator is not recorded.
  • No penetration test on a recurring schedule. One adversarial test was run on 16 June 2026 and its findings are being remediated. There is no recurring programme.
  • No client side encryption of the on device copy of notebooks.
  • No formal information security policy, no security training record, no personnel screening, and no third party certification such as SOC 2 or ISO 27001.

Subprocessors

  1. The Customer gives general authorisation for Derive to engage subprocessors.
  2. The current list is published at Subprocessors.
  3. Proposed: Derive gives the Customer at least 30 days' notice before adding or replacing a subprocessor, and the Customer may object on reasonable data protection grounds. If the objection cannot be resolved, the Customer may terminate the affected part of the service and receive a pro rata refund.
  4. Derive would impose on each subprocessor data protection obligations no less protective than this addendum, and would remain liable for their performance. This clause depends on executed agreements with each provider, which must be confirmed before signing.

International transfers

  1. Notebooks, account records, files and derived content are stored with Supabase in Sydney, Australia.
  2. Personal data leaves Australia only to the recipients and for the purposes listed on the Subprocessors page. In practice that means: handwriting and page text to AI providers in the United States and to Google's global endpoints; analytics to PostHog in the European Union for the app and the United States for the website; diagnostics to Sentry in the United States; payments to Stripe and Apple; and, if the user connects it, notebook content to Anthropic. Email is sent through Amazon Web Services in Sydney and does not leave Australia.
  3. For transfers out of the European Economic Area, the United Kingdom or Switzerland, the parties would rely on the European Commission's standard contractual clauses, the UK addendum and the Swiss annex as applicable. For disclosures out of Australia, Derive would take the steps Australian Privacy Principle 8.1 requires. Before signing, the executed clauses for each destination and a transfer impact assessment for each United States destination must be in place.

Assistance with individual rights

  1. Derive assists the Customer in responding to requests from individuals to access, correct, delete, restrict, object to or port their personal data.
  2. If Derive receives such a request directly from an individual in a Customer account, it refers the individual to the Customer, unless the law requires otherwise.
  3. Proposed: Derive responds to a Customer assistance request within 10 business days.

Today there is no self service export in the product beyond a local backup of the notebook cache. Access and portability requests are answered by hand.

Personal data breach

  1. Proposed: Derive notifies the Customer without undue delay, and in any event within 48 hours of becoming aware of a personal data breach affecting the Customer's personal data.
  2. The notification describes the nature of the breach, the categories and approximate number of individuals and records affected, the likely consequences, and the measures taken or proposed.
  3. Derive assists the Customer with its own notification obligations.

There is no written incident response process today. One must exist before this clause can be signed.

Deletion and return

  1. On termination, and at the Customer's choice, Derive deletes or returns the personal data it processes on the Customer's behalf.
  2. An individual can delete their own account at any time from Settings, Account. Deletion is staged: a request is recorded, there is a seven day window in which it can be cancelled, and then a daily job destroys the account.
  3. Some records deliberately survive account deletion. They are listed in the retention schedule in the Privacy Policy. In summary: the money ledger and raw payment provider records are kept for Australian tax purposes, and a small number of records that are keyed to an email address rather than to an account are kept as a business record.
  4. Proposed: Derive commits to a maximum time to erasure of 30 days from the request.

Deletion does not yet reach every store. Some rendered page previews, feedback attachments and evaluation records survive account deletion today, and no deletion request is sent to Sentry, RevenueCat or the Stripe customer object. These gaps must be closed before this clause can be signed.

Audit

  1. Derive makes available to the Customer the information necessary to demonstrate compliance with this addendum.
  2. Proposed: Derive allows for and contributes to audits, including inspections, conducted by the Customer or an auditor it mandates, on 30 days' notice, no more than once a year unless required by a regulator or following a breach, at the Customer's cost.
  3. Where available, Derive may satisfy an audit request by providing a current third party report instead of an on site inspection. No such report exists today.

Liability, order of precedence, and governing law

To be settled in legal review. In particular: whether the liability cap in the Terms of Service applies to this addendum, and the order of precedence between the agreement, this addendum, the Refund Policy and the Privacy Policy. Governing law would follow the main agreement.

Privacy Policy, Terms of Service, Cookies, Subprocessors, Children and students, AI disclosure.