← Back to Home

Data Processing Addendum

Last updated: August 2026

Between: CRADD PTY LTD (“Processor”) and the Bakery/Merchant (“Controller”).

This DPA forms an integral part of the ibakepro Terms of Service. It applies where ibakepro processes “Personal Data” on your behalf to provide our SaaS services.

1. Roles and Scope

Controller: You (the Merchant/Bakery) determine the purpose of collecting customer data. You are responsible for ensuring you have a legal basis (e.g., consent) to collect this data.

Processor: We (ibakepro) process that data only to provide the ERP and AI services you have requested.

Data Categories: This includes but is not limited to: customer names, delivery addresses, contact details, order history, and custom bakery-specific fields (allergies, event locations, cake preferences).

2. Processor Obligations

ibakepro agrees to:

  • Instruction: Process personal data only on your documented instructions (e.g., when you enter an order, sync an invoice, or trigger an AI insight).
  • Confidentiality: Ensure all ibakepro personnel authorised to process the data are committed to confidentiality.
  • Security: Maintain technical and organisational safeguards including AES-256 encryption at rest, TLS encryption in transit, and Google Cloud Identity management for authentication.
  • Assistance: Assist you (at your cost) in fulfilling your obligations to respond to requests from individuals exercising their rights (e.g., “Right to Access” or “Right to be Forgotten”).
  • Audit & information: On written request (no more than once per year, unless required by a regulator or following a Personal Data Breach), make available the information reasonably necessary to demonstrate compliance with this DPA, such as summaries of security measures, certifications, or third-party audit reports where available. Where that information is insufficient, ibakepro will allow for and contribute to audits conducted by you or an independent auditor you mandate, at your cost, on reasonable notice and subject to confidentiality obligations.

3. Sub-processors

The Controller provides a general authorisation for the Processor to engage sub-processors to provide the Service. The current list of sub-processors, including each sub-processor's role and processing location, is maintained at ibakepro.com/sub-processors and forms part of this DPA.

Independent third parties. Payment gateways the Controller chooses for accepting payments from their own customers (Stripe, PayPal, Square), accounting integrations the Controller chooses to connect (e.g. Xero), e-commerce integrations (e.g. Shopify), and shipping providers the Controller connects with their own account (e.g. Interparcel) act as independent controllers (or the Controller's own processors) for the data the Controller pushes to them. They are not engaged by ibakepro as sub-processors.

Changes to sub-processors. ibakepro will give at least 14 days' prior notice of any addition or replacement of a sub-processor by email or in-app notice. The Controller may object on reasonable data-protection grounds. If ibakepro cannot accommodate the objection, the Controller may terminate the affected portion of the Service for convenience; prepaid fees are not refunded except where required by law.

4. Global Data Transfers

Data residency. ibakepro stores your primary database in the region selected at signup: Australia (Sydney), the United States, or the United Kingdom (London). The London region serves European customers and is subject to the UK GDPR and the UK Data Protection Act 2018.

EU / EEA transfers. Personal Data transferred from the EU/EEA to ibakepro's London (United Kingdom) region is currently permitted under the European Commission's adequacy decision for the United Kingdom (Decision 2021/1772, as renewed). Where ibakepro must transfer EU/EEA Personal Data to a country without an adequacy decision (for example to its team or sub-processors in Australia or the United States), the parties incorporate by reference the European Commission's Standard Contractual Clauses (Commission Implementing Decision 2021/914) (the “EU SCCs”):

  • Module Two (Controller to Processor) applies where the Controller is the controller of the relevant Personal Data and ibakepro acts as processor.
  • Module Three (Processor to Processor) applies where the Controller is itself a processor and ibakepro acts as a sub-processor.
  • Clause 7 (docking clause) is included.
  • Clause 9 — Option 2 (general written authorisation) applies, with the 14 days' prior notice period set out in Section 3.
  • Clause 11 (optional independent dispute-resolution body) is not selected.
  • Clause 17 — Option 1 applies; the governing law is the law of Ireland.
  • Clause 18 — Forum and jurisdiction is the courts of Ireland.
  • Annex I (parties and processing details) is populated by the order form and this DPA. Annex II (technical and organisational measures) is set out in Section 2. Annex III (sub-processors) is the list maintained at ibakepro.com/sub-processors.

UK transfers. Personal Data subject to the UK GDPR that is transferred outside the United Kingdom (for example to ibakepro in Australia or to sub-processors in the United States) is governed by the UK International Data Transfer Addendum to the EU SCCs (Version B1.0, in force 21 March 2022). Transfers within the United Kingdom do not require an additional mechanism.

Swiss transfers. Where Personal Data subject to the Swiss FADP is transferred, the EU SCCs apply by analogy, with references to “EU Member State” and “EU supervisory authority” read as references to Switzerland and the Swiss FDPIC.

Australia (APP 8). Where ibakepro discloses Personal Data subject to the Australian Privacy Act to overseas recipients, ibakepro takes reasonable steps to ensure the recipient handles that data in a manner consistent with the Australian Privacy Principles, as required by APP 8.

5. AI Processing & Aggregate Statistics

ibakepro pseudonymises direct identifiers (customer names, business names, emails, phone numbers, and addresses) before transmitting any query to its AI provider. The AI provider is contracted under terms that prohibit retention of, or training on, customer inputs.

ibakepro may compute aggregate or statistical measures from Personal Data (for example, total orders processed across the platform, popular product categories, or end-of-year usage summaries) for the purpose of operating, analysing, and improving the Service, and surfacing non-identifying benchmarks to users. Such aggregate outputs do not identify any individual, Controller, or specific business and are not Personal Data once produced. ibakepro does not train AI models on Personal Data and does not use Personal Data to improve the underlying AI models. See the Terms of Service for the licence grant supporting this processing.

6. Data Breaches

In the event of an “eligible data breach” (as defined by the Australian Privacy Act) or a “personal data breach” (as defined by GDPR) affecting your customer data, ibakepro will notify you without undue delay and in any event no later than 72 hours after becoming aware of a Personal Data Breach. You are responsible for notifying your customers and the relevant regulator (e.g. the OAIC, ICO, or your local EU supervisory authority) if required.

7. Termination & Deletion

Upon termination of your account, ibakepro will handle data as follows:

  • Operational Data: Retained for 2 years to allow for reactivation or export, followed by permanent, secure deletion.
  • Compliance Data: Retained for 7 years to satisfy legal, tax, and accounting requirements.
  • Backups: Deleted Personal Data may persist in encrypted disaster-recovery backups for a limited period until those backups are automatically overwritten. Backups are used only to restore the Service in the event of a failure, not to recover individual records, and any Personal Data restored from a backup remains subject to this DPA.
  • Deletion or return at your choice: At any time before the end of the 2-year retention period, you may instruct us in writing to delete the Personal Data we process on your behalf, or to have it returned, and we will act on the instruction within a reasonable period. Return is fulfilled through the self-service export tools: where your account is closed, we may temporarily re-enable access so you can run an export, and a reasonable fee may apply. Deletion does not extend to data whose retention is required by applicable law (such as tax and accounting records).

8. Conflict

In the event of any conflict between this DPA and the Terms of Service, the terms of this DPA shall prevail regarding the processing of Personal Data.