Legal · Enterprise
Data Processing Agreement
Last updated: 27 July 2026
This Data Processing Agreement ("DPA") applies where Noble Performance Solutions Pty Ltd (ABN 45 107 629 149) of PO Box 83, Keiraville NSW 2500, Australia ("Noble", the processor) processes personal data on behalf of a customer organisation (the controller) that has enrolled its people in a program or otherwise uses the Service under our terms. It forms part of the agreement between us. A countersignable copy is available on request at hello@nobleperformance.com.
1. Scope & roles
The customer is the controller and Noble is the processor for personal data processed to deliver the Service. Noble processes that data only to provide and support the Service and only on the customer's documented instructions (including those given through the product), unless required by law.
2. Subject matter, duration, nature & purpose
Noble processes the data for the duration of the agreement to host and deliver the leadership programs and tools, operate the manager/cohort dashboards, send program and renewal communications, and provide support — as described in the order and the privacy policy.
3. Types of data & categories of data subjects
Data subjects:the customer's enrolled leaders/participants and nominated managers/sponsors.
Personal data: name and email; program and self-assessment responses, reflections, knowledge-check scores, report-backs and uploaded artefacts; usage data; and billing contact details. We do not require special-category data and ask that none be submitted through free-text fields.
4. Confidentiality
Noble ensures that personnel authorised to process the data are bound by confidentiality and access it only as needed to deliver the Service.
5. Security measures
Noble maintains appropriate technical and organisational measures, including encryption in transit, access controls and role-based authorisation, a private default-deny store for program videos served only via short-lived signed links to enrolled learners, scoped database access, and audit logging of administrative actions. Personal data is stored in the Australia (Sydney) region where configured, isolated per account by row-level database policies, and rate-limited at the edge. Noble will provide its current security measures summary on request, and will not materially reduce the overall level of security during the term.
6. Sub-processors
The customer authorises Noble to engage the sub-processors listed at /legal/subprocessors. Noble imposes data-protection obligations on each sub-processor no less protective than this DPA, remains liable for their performance, and will give the customer at least 30 days' prior notice of any new or replacement sub-processor, during which the customer may object on reasonable data-protection grounds. If the parties cannot resolve a reasonable objection, the customer may terminate the affected part of the Service and receive a pro-rata refund of any prepaid fees for the unused period.
7. Assistance to the controller
Taking into account the nature of the processing, Noble will assist the customer with data-subject requests (access, correction, deletion, portability, objection) and with data protection impact assessments and consultations with authorities, including through the export and deletion features in the product.
8. Personal data breaches
Noble will notify the customer without undue delay, and in any event within 72 hours, after becoming aware of a personal data breach affecting the customer's data, with the information the customer reasonably needs to meet its own obligations — including the nature of the breach, the categories and approximate number of data subjects affected, the likely consequences, and the measures taken or proposed. Where Noble cannot provide all of that detail at once, it will provide it in phases without further undue delay.
9. Return & deletion
On termination the customer has 30 days to export its data using the export features in the product. At the customer's choice, Noble will return or delete the customer's personal data within 60 days of termination, except where retention is required by law — in which case Noble will isolate it and stop all other processing. Noble will certify deletion in writing on request.
10. Audits
Noble will make available the information reasonably necessary to demonstrate compliance with this DPA. The customer may audit once in any 12-month period, on at least 30 days' written notice, during business hours, without unreasonably disrupting Noble's operations, and subject to confidentiality. Noble may satisfy an audit request by providing a current third-party report or completed security questionnaire where that reasonably addresses the customer's scope. Additional audits are permitted where required by a supervisory authority or following a confirmed personal data breach. Each party bears its own costs.
11. International transfers
Where Noble or its sub-processors process personal data outside the UK/EEA, the transfer is governed by an appropriate safeguard. For transfers from the EEA, the parties incorporate the European Commission's Standard Contractual Clauses (Decision 2021/914), Module Two (controller to processor), with the controller as data exporter and Noble as data importer; onward transfers to our sub-processors are made under Module Three (processor to processor). For transfers from the UK, the same clauses apply as modified by the ICO's International Data Transfer Addendum (version B1.0). Docking is permitted, the optional clause on independent dispute resolution is not selected, and the audit and sub-processor terms in sections 8 and 9 of this DPA apply.
For personal information subject to the Australian Privacy Principles, Noble complies with APP 8 by taking reasonable steps to ensure each overseas recipient handles the information consistently with the APPs, through the binding contractual terms it holds with each sub-processor. Current processing locations are listed on the sub-processors page.
12. Governing terms
This DPA is governed by the laws of New South Wales, Australia and supplements, and is incorporated into, the main agreement between the parties. Where the Standard Contractual Clauses apply to a particular transfer, the governing law and forum specified in those clauses prevail for that transfer. Where this DPA conflicts with the main agreement on data protection, this DPA prevails. Contact: hello@nobleperformance.com.