Legal
Data Processing Addendum
A lightweight MVP data processing addendum for Aspire 2: CMS tenants.
Last updated: 2 June 2026. This MVP DPA is pending lawyer review. For signed terms, contact legal@aspire2cms.com.
1. Parties
This addendum applies between Aspire 2: CMS, a product operated by Mitchell Craig Roemling trading as Aspire 2: X, ABN 21 658 558 016, and the tenant business using the platform.
2. Roles
For tenant account data, Aspire uses personal information for its own platform, billing, security, and support purposes. For lead form data submitted through tenant websites, Aspire processes that data to provide the CMS and lead delivery service to the tenant.
3. Processing Instructions
Aspire will process tenant lead data to host forms, receive submissions, store enquiries, deliver email notifications, provide admin access, support the tenant, secure the service, and comply with law.
4. Confidentiality And Security
Aspire will use reasonable access controls, tenant scoping, provider security features, and operational safeguards appropriate for an MVP SaaS platform. People with access to tenant data must use it only for platform operations, support, security, or legal compliance.
5. Sub-processors
Aspire may use the providers listed at /legal/subprocessors. Aspire remains responsible for selecting providers appropriate for the service and for maintaining the public list.
6. Assistance
Aspire will provide reasonable assistance for privacy requests, deletion requests, security incidents, and data export requests, taking into account the MVP nature of the service and the tenant's own customer relationship.
7. Deletion Or Return
On cancellation or written request, Aspire will delete or make available tenant data according to the Terms, Privacy Policy, retention policy, and any legal, billing, tax, backup, security, or dispute constraints.
8. Incidents
Aspire will assess suspected data incidents and, where required, assist with notifications to affected tenants, individuals, regulators, or providers.