These Standard Terms govern every engagement between Opflow Automations (ABN 69 633 592 929) of Newcastle, NSW, Australia ("OpFlow", "we", "us") and the client named in the Engagement Form ("the Client", "you"). They are incorporated into, and form part of, the Engagement Form you sign. The Engagement Form sets out the specifics of your engagement: the parties, the scope of services, the fees, and the dates. Where the Engagement Form and these Standard Terms conflict, the Engagement Form prevails for that engagement.
These terms include OpFlow's data processing terms (Part B), under which OpFlow acts as your data processor. Each published version is dated; you are bound by the version referenced in your Engagement Form.
Part A: Engagement Terms
1. Services
OpFlow provides the services described in your Engagement Form, using reasonable skill and care. Any work outside that scope is quoted separately and agreed in writing before it begins.
2. Fees and payment
Fees are set out in the Engagement Form. Unless stated otherwise: one-off and setup fees are invoiced as set out in the proposal (typically on acceptance) and due within 14 days; ongoing fees (such as Bot Care) are invoiced monthly in advance; payment is by bank transfer or by credit or debit card via Stripe. If payment is more than 14 days overdue, OpFlow may suspend services after written notice. Platform operating costs (such as Make.com) and AI API usage costs are passed through at cost as separate line items, with estimates provided in the proposal.
3. Term and termination
One-off services end when delivered and signed off. Ongoing services continue until cancelled on the notice stated in the Engagement Form. OpFlow may terminate immediately for an unremedied material breach (14 days written notice). On termination, OpFlow returns or deletes Client data per Part B. Refunds for one-off and setup fees: full refund minus a $150 administration fee if cancelled before kickoff; non-refundable after kickoff (kickoff is the kickoff meeting or the provision of access credentials, whichever is first).
4. Client obligations
The Client provides timely access, responds within reasonable timeframes, provides accurate information, maintains valid software licences, and notifies OpFlow of changes affecting the services.
5. Access and credentials
OpFlow requests only the access necessary to deliver the agreed services; stores credentials in an encrypted password manager (never in email or plain text); collects any shared login through a secure, single-use link (secure.opflow.com.au) that stores it directly in the vault, never through email, text message, or chat; uses OAuth and scoped delegated access wherever possible; maintains an access register of all access granted; and revokes all access at the end of the engagement, or earlier if no longer required.
6. Confidentiality
Both parties keep confidential information confidential and do not disclose it without written consent. Standard exceptions apply (publicly available, independently developed, or required by law). Confidentiality survives for 3 years after the engagement ends.
7. AI usage
OpFlow uses AI tools (currently Anthropic's Claude, via its commercial API) to assist OpFlow in delivering the services, including analysis, drafting, and the building, configuration, and diagnosis of automations. AI inputs are not used for model training (per Anthropic's commercial API terms) and are deleted within the provider's retention period. How the Client's data is handled, including any use of AI, is governed by the data processing terms below. The Client may opt out of AI use in writing.
8. Cross-border data transfer
Client data may be processed outside Australia by the sub-processors in Appendix A. OpFlow takes reasonable steps to ensure overseas recipients handle data in accordance with the Australian Privacy Principles (APPs).
9. Intellectual property
The Client owns all their data. OpFlow owns its automation designs, templates, processes, prompts, and methodologies. The Client receives a non-exclusive, non-transferable licence to use the deployed automations for the duration of the active engagement. On termination, deployed automations remain in place but are no longer maintained, and the Client may not reuse the designs as the basis for new automations without OpFlow's written consent. A paid handover service is available.
10. Disclaimer and limitation of liability
To the maximum extent permitted by law, OpFlow provides all services on an "as is" and "as available" basis and disclaims all warranties, including merchantability, fitness for purpose, uninterrupted or error-free operation, the performance or security of any third-party platform or sub-processor, immunity of data from unauthorised access, and the accuracy of any output (including AI-assisted output). The Client assumes all risk associated with the use of the services. OpFlow's responsibility is limited to delivering the services with reasonable skill and care and selecting sub-processors that meet the security standards in Part B. The Client is the data controller and is responsible for the lawfulness of processing and its own regulatory compliance; these terms are not legal advice. OpFlow's total liability is limited to the fees paid in the 12 months before the claim, and OpFlow is not liable for indirect or consequential loss. Nothing limits liability that cannot be excluded by law. Neither party is liable for events beyond its reasonable control.
11. Indemnity
The Client indemnifies OpFlow against claims, losses, and costs arising from the Client's breach, the Client's failure to comply with applicable laws (including the Privacy Act 1988 and APPs), third-party claims arising from the Client's data or instructions, inaccurate information provided by the Client, the Client's failure to obtain necessary consents, and unauthorised access to the Client's own systems not caused by OpFlow's negligence. OpFlow does not indemnify the Client.
12. Insurance
OpFlow maintains appropriate professional indemnity and cyber liability insurance for the duration of the engagement.
13. Dispute resolution
The parties attempt good faith negotiation, then mediation, before legal proceedings. These terms are governed by the laws of New South Wales, Australia.
14. General
The Engagement Form and these Standard Terms are the entire agreement. Amendments to the Engagement Form must be in writing and signed. OpFlow may update these Standard Terms; the version referenced in your Engagement Form applies to your engagement. Neither party may assign without consent. Invalid provisions are severed.
Part B: Data Processing Terms
The Client is the data controller and OpFlow is the data processor. These terms apply to OpFlow's processing of personal information on the Client's behalf in connection with the services.
15. Definitions
Personal information and sensitive information have the meanings in the Privacy Act 1988 (Cth). Processing means any operation performed on personal information. A data breach is unauthorised access, disclosure, or loss likely to cause serious harm. A sub-processor is a third party engaged by OpFlow that processes personal information on the Client's behalf. APPs are the Australian Privacy Principles in Schedule 1 of the Privacy Act 1988 (Cth).
16. Roles and scope
The Client determines the purposes and means of processing. OpFlow processes personal information only on the Client's documented instructions, solely to deliver the agreed services, and never for marketing, profiling, or sale. OpFlow will inform the Client if it believes an instruction infringes applicable law. The categories of personal information, data subjects, purpose, and duration are those reasonably necessary to deliver the services in the Engagement Form.
17. Obligations of the processor
OpFlow processes personal information only on documented instructions; binds personnel to confidentiality; maintains the security measures in Appendix B; assists with data subject rights requests and the Notifiable Data Breaches scheme; returns or securely deletes personal information on termination (financial records excepted, see clause 21); makes compliance information available; and engages sub-processors only per clause 18.
18. Sub-processors
The Client consents to the sub-processors in Appendix A. Before engaging a new sub-processor, OpFlow notifies the Client at least 30 days in advance with the name, location, and purpose, and confirms equivalent security standards. If the Client objects within 14 days and the matter is unresolved within 30 days, the Client may terminate without penalty on 30 days notice. OpFlow remains liable for each sub-processor's performance.
19. Data subject rights
OpFlow promptly notifies the Client of any access, correction, or deletion request, does not respond directly unless authorised, and assists the Client to respond within the timeframes required by law (30 days under the Privacy Act 1988).
20. Data breach notification
If OpFlow becomes aware of a data breach involving the Client's personal information, it notifies the Client within 24 hours; describes the breach, the individuals and data affected, the likely consequences, and the measures taken; cooperates in assessing whether it is an eligible data breach; assists with OAIC and individual notifications if required; and provides a written breach report within 30 days.
21. Data retention and deletion
OpFlow retains personal information only for the duration of the engagement plus any period required by law. On termination, at the Client's instruction, OpFlow returns and deletes, or securely deletes and certifies deletion, within 30 days. Financial records are retained for five years per Australian tax law.
22. Audit rights
On reasonable notice and no more than once per 12-month period, the Client may request a written summary of security measures and the sub-processor list, submit a security questionnaire (completed within 30 days), and request relevant third-party audit reports, subject to confidentiality. On-site audits are not required, but OpFlow cooperates in good faith.
23. Liability under these data processing terms
The disclaimer, limitation of liability, and indemnity in Part A apply in full. The Client's indemnity extends to claims arising from the processing of personal information. OpFlow's total liability is subject to the limitation in clause 10.
Appendix A: Sub-processor list
Current as at the version date above.
| Sub-processor | Location | Purpose |
|---|---|---|
| Make.com (Celonis SE) | EU (Ireland) or US | Automation platform |
| Microsoft 365 and Power Automate | Australia | Email, files, calendar, automation |
| Anthropic (Claude API) | US | AI-assisted analysis and document drafting |
| Cloudflare (Workers, Pages) | Global / US | AI proxy, website hosting |
| Supabase | US or configured region | Configuration and usage logging |
| Zoho (CRM, Books) | Australia | Client management and invoicing |
| OpenSign (self-hosted) | Australia | E-signatures |
| Stripe | US and EU | Payment processing (PCI DSS Level 1) |
Client-owned platforms accessed via API (for example Google Analytics, Meta, Mailchimp, Shopify) are not sub-processors: the Client is the account holder. OpFlow accesses them on the Client's instruction with least-privilege access.
Appendix B: Security measures
Technical: AES-256 encryption at rest; TLS 1.2 or higher in transit; encrypted credential storage (Vaultwarden); multi-factor authentication on all OpFlow accounts; least-privilege scoped access; "data is confidential" on Make.com scenarios; restricted API keys with quarterly rotation; HTTPS-only signature-verified webhooks.
Organisational: quarterly access reviews; a documented access register per client; a documented breach response runbook with 24-hour client notification; access revoked within 48 hours of engagement end; personnel bound by confidentiality; a platform hardening checklist completed before engagement; data minimisation.
For any questions about these terms, contact [email protected].
Privacy Policy
How OpFlow collects, uses, and protects your personal information. Last updated: March 2026.
What information we collect
When you submit a form on our website, we collect your name, business name, email address, and optionally your phone number, industry, team size, referral source, and message. We also collect anonymous analytics data through Google Analytics. When you subscribe to our email list, we collect your email address.
How we use your information
We use your contact details to respond to your enquiry and to follow up on recommended automation solutions. We do not sell or share your personal information with third parties for marketing purposes. Email subscribers receive automation tips and business updates, and can unsubscribe at any time.
Cookies and analytics
We use Google Analytics 4 to understand how visitors use our website. This uses cookies to collect anonymous usage data including pages visited, time on site, and referral source. You can opt out by declining cookies or using a browser extension.
Third-party services
Form submissions are processed by Make.com. Analytics data is processed by Google. Email and CRM data is managed through Zoho. We do not use any third-party advertising or tracking services beyond Google Analytics.
Data retention
Contact form submissions are retained for 12 months unless you request deletion. Analytics data is retained per Google's standard retention policies. Email subscriber data is retained until you unsubscribe.
Your rights
You can request access to, correction of, or deletion of your personal information at any time by contacting us at [email protected].
Contact us
If you have questions about this policy, contact us at [email protected] or through the contact form on our website.
OpFlow, Hunter, NSW, Australia