Skip to content
Information Security and Privacy Compliance Terms

Version V1.0 – published July 2026

1. DEFINITIONS

1.1 Any capitalised terms used but not defined in this Security and Compliance Schedule, shall have the meaning given in the Agreement.

1.2 The following capitalised terms shall have the meaning given in this Security and Compliance Schedule:

(a) Applicable Data Protection Laws means all data protection, privacy or personal information laws or regulations in any jurisdiction applicable to the Processing of Personal Data under the Agreement, as updated, amended, replaced or superseded from time to time.

(b) Data means any information, content, records, files, documents, materials, or other data, in any form or medium, that is provided, submitted, uploaded, transmitted, stored, generated, collected, Processed or otherwise made available by or on behalf of a party through the Services, including any Personal Data, business information, metadata, reports, and derivative data generated from such information, and includes Infomedia Material and Customer Data.   

(c) Individual means any individual whose Personal Data is disclosed by a party to the other party pursuant to the terms of this Agreement.  

(d) Personal Data means  information about an identified or identifiable natural person, or which otherwise constitutes “personal data”, “personal information”, “personally identifiable information” or similar terms as defined in Applicable Data Protection Laws.

(e) Personal Data Breach  means any act or omission that compromises either the security, confidentiality or integrity of Personal Data Processed by Infomedia that is likely to create a risk to the privacy rights or harm to any Individual. Without limiting the foregoing, a material compromise shall include unauthorised access to or disclosure or acquisition of Personal Data. 

(f) Processing (and Process andProcessed) means any operation or set of operations which is performed on Personal Data or on sets of Personal Data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction. 

(g) Security Incidents means one or more of: (i) a Personal Data Breach; (ii) Suspected Personal Data Incident; or (iii) a denial-of-service attack, a cyber-attack, malware or other event that has materially impacted, or is reasonably likely to materially  impact, the security or integrity of  Customer Data, Infomedia Material or Infomedia Systems.   

(h) Suspected Personal DataIncident means unauthorised access to or disclosure of Personal Data that is reasonably suspected, but not yet confirmed by Customer or Infomedia.  

(i) Systems means the software, applications, platforms, databases, networks, hardware, infrastructure, cloud environments, interfaces, APIs, security tools, and other technology resources used by a party to provide, access, support, maintain, or operate the Services.

2. ACKNOWLEDGEMENT

Each party acknowledges and agrees that it is solely responsible for the security of their respective Systems.  Each party must implement, maintain and periodically test, at its own cost, commercially reasonable technical and organisational measures designed to protect the security, integrity, and confidentiality of their respective products and Systems .  Such measures shall include but are not limited to identification of security gaps and cyber risks, protection of its Systems and Data, detection of suspicious activity and threats, and ability to respond to Security Incidents and recovery from them in a timely manner.  

3. INFORMATION SECURITY OBLIGATIONS

3.1 Infomedia will: 

(a) monitor the use of the Services for any unusual or unauthorised activity, including anomalies in network traffic, fluctuations in access volume or frequency, irregular usage patterns, or unexpected access origins;  

(b) maintain recognised information security compliance, such as certification to ISO/IEC 27001 and/or SOC 2 Type II, or an equivalent industry-accepted standard for the duration of the Services, and Infomedia shall provide current certification evidence to Customer on request; 

(c) maintain an ongoing risk management program to identify, assess and mitigate security risks to the platform and Customer Data, ensuring that risk treatment actions are documented and regularly reviewed; and 

(d) implement a formal vulnerability management process that includes:

(i) regular vulnerability scanning (at a minimum, monthly scanning) of all systems and applications;

(ii) penetration testing of all API endpoints to identify and remediate any weaknesses before go-live and at least annually thereafter;

(iii) remediation of critical and high-severity findings from pre-go-live testing before the  Services go live;

(iv) timely patching of all dependencies (with any critical and high severity vulnerabilities discovered being addressed as a priority and remediated within agreed timeframes);

(v) documentation of findings and remediation actions. 

3.2 If unusual or unauthorised activity is detected or reasonably suspected by Infomedia:

(a) Infomedia may, at its sole discretion, restrict or suspend access to the Services, in whole or in part, to protect the integrity and security of the Services, Infomedia Material and the Infomedia Systems, and Infomedia shall promptly notify Customer of any such restriction or suspension of the Services; and

(b) where the activity originates from or involves Systems or users under the control of or used by Customer, Customer is solely responsible for taking all necessary actions to stop the activity, mitigate any associated risks, and prevent its recurrence, and Customer must also cooperate with Infomedia in any related investigation or remediation efforts.

3.3 Customer: 

(a) is responsible for the acts and omissions of its personnel (including subcontractors and advisors), and a breach of this Security and Compliance Schedule by any such personnel is a breach by Customer; 

(b) acknowledges that Infomedia is reliant on Customer for direction regarding Infomedia’s right to use Customer Data disclosed to it in connection with this Agreement;

(c) acknowledges that Customer’s use of Infomedia Material is limited to purposes authorised by Infomedia in the Agreement or this Schedule;  

(d) must conduct ongoing risk management to identify, assess, and mitigate security risks to Infomedia’s Systems and Infomedia Material; 

(e) must have formal internal vulnerability management processes that include regular scanning, assessment, prioritisation, and remediation of security vulnerabilities; 

(f) must conduct penetration testing to identify security risks that may impact Infomedia Systemsat least once a year; and

(g) must meet the following requirements if it wishes to conduct penetration testing on Infomedia platforms or products:

(i) Customer must provide Infomedia with at least ten (10) Business Days written notice in advance via email to security@infomedia.com.au, including details of the scope of such penetration testing; and 

(ii) Customer must not commence penetration testing until written approval has been received from Infomedia (to be received from this address: security@infomedia.com.au). 

4. RETENTION AND DESTRUCTION

On expiry or termination of this Agreement, each party must cease using the other party’s Data (except as may be permitted under the Agreement or an SOW) in accordance with the terms of the Agreement).  

5. LOCATION OF PROCESSING  

Where Infomedia Processes Customer Data, Customer acknowledges and agrees that Infomedia may transfer, store, Process, access and disclose Customer Data in multiple regions for systems and data redundancy, backup and high availability purposes, unless stated otherwise in the Agreement or a SOW. 

6. PRIVACY COMPLIANCE 

6.1 To the extent either party obtains access to or collects, uses, holds, controls, manages or otherwise Processes, any Personal Data in connection with the Agreement (the Relevant Party), the Relevant Party must comply with:  

(a) the Applicable Data Protection Laws in relation to its Processing of Personal Data; and  

(b) all obligations set out in this Schedule.   

6.2 To the extent Infomedia Processes Personal Data on behalf of the Customer and such Processing is subject to Applicable Data Protection Laws, the Data Processing Addendum (DPA) is incorporated into this Agreement and forms part of it.

7. SECURITY INCIDENTS  

7.1 If either party (the Affected Party) becomes aware of, or has reasonable grounds to suspect, a Security Incident that affects or may affect the other party’s Systems, Services, Data or Personal Data, the Affected Party shall:  

(a) provide an initial written notice to the other party without undue delay and, in any event, no later than two (2) Business Days (or such other shorter timeframe as may be required by Applicable Data Protection Laws) containing the following information (the Initial Notice):

(a) date of the Security Incident;  

(i) description of the Security Incident;  

(ii) how the Security Incident occurred (if known); and

(iii) an estimate or preliminary assessment of whether Personal Data is affected; 

(b) promptly take steps to contain and resolve the incident and, to the extent the Security Incident involves Personal Data of the Customer, use reasonable endeavours to prevent any further serious harm to affected Individuals; and

(c) conduct an investigation and provide written findings to the other party within 30 days of the initial discovery (or sooner if the incident is resolved) of the Security Incident.

7.2 On and from the date of the Initial Notice, the Affected Party shall provide written updates to the other party at least weekly (or more frequently if reasonably requested by the other party) regarding:

(a) investigation progress and findings;

(b) containment and remediation actions taken; and

(c) estimated timeline to incident closure.

7.3 If the Security Incident involves confirmed or reasonably suspected unauthorised access to or disclosure of Personal Data of the Customer:

(a) the parties must cooperate in good faith to determine whether notifications to regulatory authorities, affected Individuals or other third parties are required under Applicable Data Protection Laws;

(b) where notification is required, the parties shall, as soon as reasonably practicable after determining notifications may be required, agree in writing which party will notify regulatory authorities and affected Individuals;

(c) if the parties cannot agree, the Customer shall be responsible for any required notifications, and Infomedia shall provide all investigation findings, available evidence and reasonable cooperation needed to complete the notifications; and

(d) to the extent legally feasible and reasonably practicable, the Customer shall inform Infomedia of the notification at least 24 hours before sending (where legally feasible) to allow for factual review.

7.4 Neither party shall make public or media statements regarding the Security Incident without notifying the other party at least five (5) Business Days in advance. The other party may request changes to factual inaccuracies only.

8. AUDIT   

8.1 Customer may conduct audits of Infomedia to assess its compliance with this Security and Compliance Schedule.   

8.2 Customer must give Infomedia at least thirty (30) days’ notice of any requested audit.  

8.3 Customer’s right to audit under this paragraph shall be exercised no more than once per calendar year, unless Customer has a material compliance concern which it can demonstrate justifies an audit, in which case an additional audit may be performed on not less than fourteen (14) days’ prior written notice to Infomedia, limited in scope to the specific concern identified. 

8.4 Before exercising its right to audit under this paragraph, Customer shall attempt to obtain/request all the information it requires from Infomedia and only proceed with its audit request in relation to matters which are not adequately addressed by the information provided on request.

8.5 All audits conducted by Customer: 

(a) must be performed in accordance with ISO 27001 or SOC 2; 

(b) shall be limited to a review of relevant documentation and evidence reasonably necessary to demonstrate compliance; and

(c) must be conducted through the exchange of written responses, supporting documentation, and relevant summaries of third-party reports. 

8.6 Where Infomedia, acting reasonably, believes the scope or execution of a proposed audit poses a risk to the security of Infomedia Systems or the security, integrity and confidentiality of another customer’s Personal Data, Intellectual Property Rights or Infomedia Material, Infomedia has the right to limit the scope and/or execution of the audit to mitigate such risk.  

8.7 The audit report, audit details and other information arising in relation to the audit shall constitute Confidential Information of Infomedia and may only be shared with a third party in accordance with and subject to the terms of the Agreement (or with Infomedia’s prior written consent). 

8.8 Audits shall be conducted during business hours and in a way which minimises the impact on Infomedia’s operations.  

8.9 Each party shall be liable for its own costs in relation to any audit.   

9. VARIATIONS

Infomedia may amend, update, or otherwise vary this Schedule from time to time. Changes to this Schedule that materially and adversely affect the Customer require the Customer’s express written acceptance before taking effect as against the Customer.

10. SECURITY CONTACT

For all information security-related enquiries or obtaining Infomedia security certifications, please email security@infomedia.com.au.