Data Processing Agreement
Effective date: 12 May 2026 · Version 1.0
1. Parties and acceptance
This Data Processing Agreement (“Agreement”) is published by Content Maximiser Pty Ltd (ACN 601 294 071, ABN 34 601 294 071), a company incorporated in Australia (“we”, “us”, “Content Maximiser”), and applies to all customers who engage us for services under any of our brands, including the Content Maximiser brand and the Dental Masters TV (DMTV) brand. By engaging us, the customer (referred to as the Data Controller) agrees to the terms of this Agreement.
| Data Processor | Data Controller |
|---|---|
| Content Maximiser Pty Ltd ACN 601 294 071 ABN 34 601 294 071 1417 / 243 Pyrmont Street, Pyrmont NSW 2009, Australia Email: [email protected] |
The customer as identified in the applicable service agreement, order form, or media release. Referred to as “the Customer” or “the Data Controller”. |
Together, we are referred to as “the Parties”.
2. Purpose
This Agreement governs how Content Maximiser Pty Ltd handles personal information on behalf of its customers in connection with the delivery of digital marketing, website, content production, paid advertising, SEO, DMTV episode production, and related services (collectively, the “Services”).
This Agreement is designed to ensure compliance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles in a practical, proportionate way, without imposing unnecessary administrative burden on either party.
3. Definitions
- Privacy Act means the Privacy Act 1988 (Cth).
- APPs means the Australian Privacy Principles under the Privacy Act.
- Personal Information has the meaning given in the Privacy Act: information or an opinion about an identified individual, or an individual who is reasonably identifiable.
- Sensitive Information means Personal Information that includes health data, racial or ethnic origin, or other data classified as sensitive under the Privacy Act.
- Data Breach means any unauthorised access to, disclosure of, or loss of Personal Information held by Content Maximiser Pty Ltd.
- Services means the services provided by Content Maximiser Pty Ltd to the Customer under any applicable service agreement, order form, or media release.
- Sub-processor means any third-party platform or service provider engaged by Content Maximiser Pty Ltd that processes Personal Information in connection with the Services.
4. Compliance with law
Each party agrees to comply with the Privacy Act, the APPs, and any other applicable Australian law in relation to the collection, use, disclosure, storage, and destruction of Personal Information under this Agreement.
Content Maximiser Pty Ltd will take reasonable steps to ensure its Sub-processors handle Personal Information consistently with Australian privacy law. A current list of key Sub-processors is set out in clause 9 and a full list is available on request from the Privacy Officer.
5. Permitted use of Personal Information
Content Maximiser Pty Ltd will:
- only use Personal Information for the purpose of delivering the Services to the Customer;
- not use Personal Information for direct marketing to individuals without their consent;
- not use Personal Information, materials provided by the Customer, or any data flowing through the Services to train, fine-tune, or evaluate any artificial intelligence or machine learning model for general use or for any purpose outside the delivery of the Services to the Customer; and
- not disclose Personal Information to third parties except where required to deliver the Services (for example, sharing contact data with an email platform or analytics tool), where required by law, or with the Customer’s prior written consent.
Where Personal Information is disclosed to a Sub-processor for service delivery, Content Maximiser Pty Ltd will use reasonable commercial efforts to ensure that Sub-processor handles the data consistently with this Agreement.
6. Customer obligations and AI training prohibition
The Customer must not use any of Content Maximiser’s confidential information, proposals, dashboards, account structures, campaign logic, prompt sets, workflows, templates, automations, strategy documents, training materials, or any other materials or methodologies provided by Content Maximiser Pty Ltd to train, fine-tune, or evaluate any artificial intelligence or machine learning model, or to build any competing product, service, methodology, or marketing framework.
7. Retention and deletion
Content Maximiser Pty Ltd will retain Personal Information only for as long as it is reasonably necessary to deliver the Services, or as required by law.
When Personal Information is no longer needed, Content Maximiser Pty Ltd will take reasonable steps to delete or de-identify it from its active systems. Automated backups held within third-party platforms will be deleted in accordance with those platforms’ standard retention policies. Specific retention periods may be agreed in writing by the Parties.
8. Data security
Content Maximiser Pty Ltd implements security measures appropriate for a small business handling the relevant type of Personal Information. These include:
- restricting access to Personal Information to authorised personnel only;
- using secure passwords and, where available, two-factor authentication;
- using reputable, industry-standard third-party platforms that maintain their own security controls;
- applying confidentiality obligations to personnel with access to Personal Information; and
- promptly notifying the Customer in the event of a confirmed Data Breach.
9. Data Breach notification
If Content Maximiser Pty Ltd becomes aware of a confirmed Data Breach affecting a Customer’s Personal Information, it will:
- notify the Customer as soon as practicable, and in any event within 72 hours of becoming aware;
- provide reasonable details of the breach, including the nature of the data affected and the steps being taken to contain it;
- reasonably cooperate with the Customer to investigate and contain the breach; and
- assist the Customer in meeting notification obligations under the Notifiable Data Breaches Scheme (Part IIIC of the Privacy Act), where applicable.
The Customer retains primary responsibility for determining whether a Data Breach triggers notification obligations to the Office of the Australian Information Commissioner or to affected individuals.
10. Cross-border disclosure and Sub-processors
Content Maximiser Pty Ltd uses cloud-based platforms and Sub-processors that may be based overseas, including in the United States. By engaging Content Maximiser Pty Ltd, the Customer acknowledges and consents to such disclosures to the extent necessary for delivery of the Services.
Content Maximiser Pty Ltd will take reasonable steps to ensure that overseas recipients handle Personal Information consistently with the APPs, as required by APP 8, including by relying on Sub-processors that maintain appropriate certifications such as SOC 2 or ISO 27001.
| Sub-processor | Purpose | Location |
|---|---|---|
| Google (Workspace, Analytics, Ads) | Email, document storage, website analytics, advertising campaign management | USA / Global |
| Meta (Facebook, Instagram) | Paid advertising, audience management | USA |
| OpenAI | AI-assisted content generation and post-production support | USA |
| WordPress / WP Engine | Website hosting and content management | USA / Global |
| YouTube | Video distribution for DMTV episodes and related content | USA / Global |
A full and current list of Sub-processors is available on request from [email protected].
11. Return or destruction of data
Upon termination of the Services or written request by the Customer, Content Maximiser Pty Ltd will take reasonable steps to return or securely delete the Customer’s Personal Information from its active systems within 30 days, unless retention is required by law.
Backups held within third-party platforms will be deleted in accordance with those platforms’ standard data retention schedules. The Customer is responsible for exporting any data it requires before termination of the Services.
12. Audit and evidence
On reasonable written notice and no more than once in any 12-month period (except where a Data Breach has occurred or is reasonably suspected), the Customer may request:
- a written summary of Content Maximiser’s information security practices, the categories of Personal Information processed on the Customer’s behalf, the Sub-processors involved, and any third-party certifications held;
- copies of relevant policies and procedures; and
- reasonable additional information necessary to verify Content Maximiser’s compliance with this Agreement.
Content Maximiser Pty Ltd will respond within a reasonable time, having regard to the proportionate nature of this Agreement and the small-business context. The Parties agree that audit assistance which involves disproportionate cost or that would compromise the confidentiality of other customers’ data may be limited or substituted with equivalent assurances.
Content Maximiser Pty Ltd may rely on access logs, system metadata, communications records, and other reasonable forms of evidence to investigate any suspected breach of this Agreement, including misuse of materials, unauthorised retention of Personal Information, or unauthorised AI training activity. On reasonable notice, the Customer must assist with any such investigation and, where breach is found, must certify the return, deletion, or destruction of affected materials.
13. Term and termination
13.1 Term
This Agreement applies for the duration of any active service engagement between Content Maximiser Pty Ltd and the Customer, commencing on the date the Customer engages Content Maximiser Pty Ltd for Services.
13.2 Termination for cause
Either party may terminate this Agreement by written notice if the other party commits a material breach that is not remedied within 30 calendar days of written notice specifying the breach.
13.3 Effect of termination
On termination, Content Maximiser Pty Ltd will cease processing Personal Information and comply with clause 11. Provisions that by their nature survive termination (including confidentiality, audit rights, AI training prohibition, and liability) will continue to apply.
14. Liability
Each party is responsible for its own acts and omissions in relation to Personal Information.
Content Maximiser Pty Ltd’s liability under this Agreement is limited to direct losses caused by its failure to comply with this Agreement or the Privacy Act, and is capped at the total fees paid by the Customer to Content Maximiser Pty Ltd in the 12 months preceding the relevant event.
Content Maximiser Pty Ltd is not liable for any loss caused by the Customer’s own acts or omissions, the acts of Sub-processors operating within their own platforms, or events outside Content Maximiser Pty Ltd’s reasonable control.
Nothing in this clause limits or excludes any right that cannot lawfully be limited or excluded under the Australian Consumer Law or other applicable law.
15. Governing law, dispute resolution, and injunctive relief
This Agreement is governed by the laws of New South Wales, Australia. The Parties submit to the non-exclusive jurisdiction of the courts of New South Wales for any dispute arising from this Agreement.
The Parties will attempt to resolve any dispute in good faith through direct negotiation before initiating formal proceedings. If a dispute is not resolved within 20 business days of written notice, either party may refer the matter to mediation or commence proceedings in a court of competent jurisdiction.
Nothing in this clause prevents either party from seeking urgent injunctive, interlocutory, or other equitable relief from a court of competent jurisdiction at any time, in particular to protect Personal Information, confidential information, intellectual property rights, or to prevent unauthorised disclosure, retention, or use of materials.
Content Maximiser Pty Ltd acknowledges the role of the Office of the Australian Information Commissioner (OAIC) in receiving and investigating privacy complaints. Customers and individuals who are unsatisfied with how a privacy matter is handled may contact the OAIC at www.oaic.gov.au.
16. Privacy Officer and contact
In accordance with Australian Privacy Principle 1.2, Content Maximiser Pty Ltd has designated a Privacy Officer responsible for receiving and handling privacy enquiries, access requests, correction requests, and complaints. All privacy matters should be directed to the Privacy Officer:
Privacy Officer, Content Maximiser Pty Ltd (ACN 601 294 071, ABN 34 601 294 071)
1417 / 243 Pyrmont Street, Pyrmont NSW 2009, Australia
Email: [email protected]
This Agreement may be updated from time to time. Material updates will be notified to active customers with 30 days notice. Continued use of the Services after the notice period constitutes acceptance of the updated terms.






In the 2nd month of launching the site, we have 10X our traffic and double the quality leads we are getting. It has been our biggest month in the clinic so far.
Content Maximiser is a full-service digital team of experts who not only creates and develops online strategies, but also helps bolster the company’s online reputation and works to optimize all online content for search.