Balance — Australia Country Annex
Effective date: 28 June 2026 Last updated: 28 June 2026
Owner: , Director, BabaYaga Program, TOO — Privacy Officer and Designated Child Safety Officer for every Australian resident covered by this Annex; the individual responsible for compliance under Australian Privacy Principle ("APP") 1.2 read with s 13 of the Privacy Act 1988 (Cth) ("Privacy Act"); the designated contact point for the Office of the Australian Information Commissioner ("OAIC") and the Australian Communications and Media Authority ("ACMA") under their respective intake protocols. Reviewed: at least once a year, by 9 June. Re-opened immediately on (a) any amendment to the Privacy Act 1988 (Cth) or to the Australian Privacy Principles (Schedule 1 to the Privacy Act) including the bringing into force of any provision of the Privacy and Other Legislation Amendment Act 2024 (Cth) ("POLA Act") that is not yet in force at the Effective date (in particular Schedule 1 Part 9 — the Children's Online Privacy Code — the OAIC has been directed to develop and register the Code within 24 months of Royal Assent on 10 December 2024, i.e., by 10 December 2026; and Schedule 2 — the statutory tort for serious invasions of privacy — in force from 10 June 2025); (b) any amendment to the Privacy Regulation 2013 (Cth); (c) the OAIC's registration of the Children's Online Privacy Code under Privacy Act s 26GC (in force from registration); (d) any amendment to the Online Safety Act 2021 (Cth) ("OSA") or to the Online Safety (Basic Online Safety Expectations) Determination 2022 (Cth) ("BOSE Determination"); (e) the bringing into force of any provision of the Online Safety Amendment (Social Media Minimum Age) Act 2024 (Cth) — the social-media-minimum-age framework that takes effect from 10 December 2025 (12 months after Royal Assent on 10 December 2024); (f) any amendment to the Criminal Code Act 1995 (Cth), in particular Division 273 (offences involving child abuse material outside Australia), Division 273A (possession of child-like sex dolls), Division 471 (postal services offences), Division 474 (telecommunications offences — including ss 474.19–474.27A, child abuse material, child-procurement, and grooming offences) and Part 10.6 (telecommunications offences); (g) any amendment to the Crimes Act 1900 (NSW), Crimes Act 1900 (ACT), Crimes Act 1958 (Vic), Criminal Code Act 1899 (Qld), Criminal Code Act 1913 (WA), Criminal Law Consolidation Act 1935 (SA), Criminal Code Act 1924 (Tas), Criminal Code Act 1983 (NT); (h) any amendment to the Spam Act 2003 (Cth); (i) any amendment to the Australian Consumer Law (Schedule 2 to the Competition and Consumer Act 2010 (Cth)) ("ACL") or to any fair-trading statute of any State or Territory; (j) any determination of the OAIC made under Privacy Act s 52 (including a determination on a representative complaint under s 38), any Direction of the OAIC, any Information Commissioner Decision, any Privacy Guideline, any registered APP Code under Privacy Act Part IIIB, or any binding determination by the Federal Court of Australia or the Federal Circuit and Family Court of Australia under Privacy Act Division 5; (k) any decision of the High Court of Australia that materially affects the constitutional implied freedom of political communication or the Australian Human Rights Commission Act 1986 (Cth) reading of Article 17 of the International Covenant on Civil and Political Rights ("ICCPR") as applied to privacy; (l) any determination of the eSafety Commissioner under the Online Safety Act 2021 (Cth), and any amendment to a registered industry code under OSA Part 9 (industry codes and standards) or industry standard under OSA Part 10; (m) any amendment to a sub-processor's Australian data-handling posture under our sub-processor register; (n) the bringing into force of any post-Effective-date Commonwealth or State or Territory regulation governing automated processing or related techniques (covered by the deliberate-silence carve-out in § 2 of this Annex). Classification: Public legal annex. This document is published at Privacy Policy alongside the global Privacy Policy (H1) and at Children's Privacy Notice alongside the Children's Privacy Notice (H2), and is incorporated by reference into both. It is one of the country annexes that travel with the global documents under the "global policy + per-country annex" architecture documented in our internal compliance plan § 6.3.
This Annex discharges the country-annex obligations referenced in:
- Privacy Policy § 18 (Country annexes — Australia row).
- Children's Privacy Notice § 14 (Country annexes — Australia row).
- Child Safety Standards § 13 (Country annexes — Australia row).
- Terms of Service § 19 (Australia consumer-protection carve-out under the ACL).
- Subscription Terms § 20 (Australia consumer-rights overlay — ACL consumer guarantees as to services + unsolicited consumer agreements + unfair contract terms).
- Data Retention & Deletion Policy § 14 (Australia OAIC complaint route).
- our breach-notification runbook § 9 (Australia breach-notification route via the Notifiable Data Breaches scheme under Privacy Act Part IIIC).
- our international-transfer pack § 6 (APP 8 cross-border-disclosure treatment + accountability paperwork + onward-flow contractual paperwork).
This Annex is the canonical Australia-resident extension of the global Privacy Policy and Children's Privacy Notice. Where this Annex grants an Australian resident a right that the global Policy does not, this Annex governs. Where the global Policy grants an Australian resident a right that this Annex does not, the global Policy governs. The two are read together.
This Annex is drafted in English (the de facto national language of Australia; no constitutional or statutory official-language designation exists at the Commonwealth level — see Sue v Hill [1999] HCA 30 and the Constitution of Australia generally). No translation is required at the Effective date.
1. Scope and applicability
This Annex applies to every Balance user (parent or kid) whose State or Territory of residence is one of the six States or two internal Territories of the Commonwealth of Australia: New South Wales (NSW), Victoria (VIC), Queensland (QLD), Western Australia (WA), South Australia (SA), Tasmania (TAS), Australian Capital Territory (ACT), and Northern Territory (NT) — or the Jervis Bay Territory. The external Territories (Norfolk Island, Christmas Island, Cocos (Keeling) Islands, Heard Island and McDonald Islands, Coral Sea Islands, Ashmore and Cartier Islands, Australian Antarctic Territory) are classified as Cat-3 (excluded markets) per the full country classification table § 2 carve-out (e) — small or unpopulated; the Privacy Act nonetheless applies to any resident of those territories who has the Commonwealth as their administering authority, and this Annex's protections extend to them on a most-protective reading.
We determine country and State/Territory of residence at install/sign-up time by (a) the country and State/Territory the parent self-declares in the in-app onboarding flow, (b) the IP-geolocation read at sign-up (which we discard immediately after the residence decision — our internal data-flow map § 2.1 stores no IP after the authentication request closes), and (c) the Play Store account locale that Google Play passes to us at install. The residence determination is reviewable at any time by the parent at Settings → Account → Region.
Where any of the three signals identifies Australia as the country of residence, this Annex applies, even if the other signals are non-Australian. The most-protective-for-the-data-subject reading is the controlling reading per our internal compliance plan § 6.3.
The Privacy Act has extraterritorial effect under s 5B: it applies to "an act done, or practice engaged in, outside Australia and the external Territories by an organisation" where the organisation "has an Australian link" — defined to include carrying on business in Australia and collecting or holding personal information in Australia. The Federal Court of Australia in Optus v ACMA (No 2) [2018] FCAFC 36 and the OAIC's published Australian Privacy Principles guidelines Chapter B confirm that targeting Australian-resident consumers from outside Australia satisfies the "carrying on business in Australia" limb. Balance squarely targets Australian residents through Google Play Australia, through publication of this Annex at balance.babayagaprogram.com, and through delivery of the parental-control service to Australian-resident parents and kids; the Privacy Act applies in full.
The Privacy Act applies to Balance as a "private sector organisation" (Privacy Act s 6C) regardless of whether Balance's annual turnover would meet the AU$3 million threshold under the small business operator carve-out at Privacy Act s 6D, because Balance's core activity is the processing of personal information of children, which engages the carve-out exception at Privacy Act s 6D(4)(b) (an organisation that provides a service that involves the collection or disclosure of personal information about a child to another person other than the child for a benefit, service, or advantage). Balance also provides a health service in the secondary sense of supporting a parent's care of a child but does not collect health information of any kind from any Australian resident, so the health service provider carve-out exception at s 6D(4)(a) is engaged only in the alternative.
State and Territory privacy laws (e.g., Privacy and Personal Information Protection Act 1998 (NSW), Privacy and Data Protection Act 2014 (Vic), Information Privacy Act 2009 (Qld), Personal Information Protection Act 2004 (Tas), Information Privacy Act 2014 (ACT), Information Act 2002 (NT)) apply principally to the public sector of the respective State or Territory and to State / Territory Government contracted service providers; they do not apply to Balance as a private-sector organisation. The Commonwealth Privacy Act is the controlling framework for Balance's Australian-resident processing in every State and Territory.
2. Statutory framework — what applies
The Australian personal-information-protection regime is a Commonwealth-dominant framework with overlay statutes for online-safety, spam, criminal-content, consumer-protection, and human-rights. The Privacy Act 1988 (Cth), incorporating the 13 Australian Privacy Principles at Schedule 1 (in force from 12 March 2014, the consolidating amendment delivered by the Privacy Amendment (Enhancing Privacy Protection) Act 2012 (Cth)), is the principal statute. The Privacy and Other Legislation Amendment Act 2024 (Cth) ("POLA Act"), which received Royal Assent on 10 December 2024, is the most significant amendment to the Privacy Act in over a decade and is phased into force as set out in § 2.1 below. The Online Safety Act 2021 (Cth) is the principal online-safety statute and is administered by the eSafety Commissioner. The Criminal Code Act 1995 (Cth) Division 474 contains the federal CSAM and online-luring offences; State and Territory Crimes Acts / Criminal Codes contain parallel offences. The Spam Act 2003 (Cth) governs commercial electronic messages. The Australian Consumer Law (Schedule 2 to the Competition and Consumer Act 2010 (Cth)) governs the subscription flow.
2.1 POLA Act 2024 — phased commencement
The POLA Act amends the Privacy Act in three substantive tranches. The Effective date is in the middle of the commencement schedule. The provisions in force at the Effective date are:
- In force from Royal Assent (10 December 2024): increased civil penalties (Privacy Act s 13G — penalty for serious or repeated interference with the privacy of an individual increased to the greater of AU$50 million / 3 times the benefit / 30 per cent of adjusted turnover in the relevant period); new tiered civil penalty for minor interferences (Privacy Act s 13H — civil penalty up to AU$3.3 million); new infringement notice power for the OAIC; expanded OAIC investigative and enforcement powers; OAIC power to make APP determinations on the OAIC's own motion (Privacy Act ss 33C and 33D); OAIC requirement to publish guidance on PIAs; expanded transparency requirements at APP 1.4(b) for cross-border disclosures.
- In force from 10 June 2025 (six months after Royal Assent): the statutory tort for serious invasions of privacy at Schedule 2 to the POLA Act (a new cause of action for an individual whose privacy has been seriously invaded by intrusion upon seclusion or misuse of information, where the invasion is intentional or reckless, the privacy interest outweighs the public interest, and the invasion is in fact serious).
- In force from 10 December 2025 (12 months after Royal Assent): the direct right of action for an individual to apply to the Federal Court of Australia or the Federal Circuit and Family Court of Australia for an order under Privacy Act s 80W, after the OAIC complaint mechanism is exhausted or the OAIC declines to investigate.
- To be in force by 10 December 2026 (24 months after Royal Assent): the Children's Online Privacy Code to be developed and registered by the OAIC under Privacy Act s 26GC — addressing the privacy of children whose personal information is handled by online services likely to be accessed by children. Not in force at the Effective date. The § 18 versioning protocol provides for an immediate off-cycle update of §§ 5, 7 of this Annex on the Code's registration.
2.2 Instrument table
| Instrument | Short cite | What it does | Balance's posture |
|---|---|---|---|
| Constitution of Australia | Commonwealth of Australia Constitution Act 1900 (Imp) — s 51(v) (postal, telegraphic, telephonic, and other like services) + s 51(xx) (foreign, trading, financial corporations) + s 51(xxix) (external affairs) + implied freedom of political communication as recognised in Lange v Australian Broadcasting Corporation (1997) 189 CLR 520 + Comcare v Banerji [2019] HCA 23 | The constitutional anchor for the Commonwealth's legislative competence over privacy (via s 51(v), s 51(xx) and s 51(xxix) — external affairs power activated by Australia's ratification of the ICCPR on 13 August 1980). The Constitution does not contain an explicit privacy right; the privacy right is statutory (Privacy Act) supplemented by the common-law and equitable causes of action and (from 10 June 2025) the statutory tort for serious invasions of privacy. | Applies as the constitutional layer. Treatment in §§ 3, 6, 13 below. |
| Australian Human Rights Commission Act 1986 (Cth) | AHRC Act | Establishes the Australian Human Rights Commission (AHRC) and gives effect to Australia's obligations under the ICCPR and other treaties. Schedule 2 to the AHRC Act incorporates the ICCPR, including Art 17 (no one shall be subjected to arbitrary or unlawful interference with their privacy, family, home, or correspondence). | The AHRC has a complaints jurisdiction in respect of human-rights matters where the Commonwealth is involved (s 11(1)(f) AHRC Act). The OAIC remains the principal forum for Privacy-Act-grounded complaints. |
| Privacy Act 1988 (Cth) | Privacy Act — including the 13 Australian Privacy Principles ("APPs") at Schedule 1, in force from 12 March 2014: APP 1 (open and transparent management of personal information — privacy policy + APP 1.4(b) cross-border-disclosure transparency); APP 2 (anonymity and pseudonymity); APP 3 (collection of solicited personal information); APP 4 (dealing with unsolicited personal information); APP 5 (notification of the collection of personal information — collection notice); APP 6 (use or disclosure of personal information — primary and secondary purpose); APP 7 (direct marketing — opt-out mechanism); APP 8 (cross-border disclosure of personal information — accountability + 5 carve-outs); APP 9 (adoption, use, or disclosure of government related identifiers); APP 10 (quality of personal information); APP 11 (security of personal information — reasonable steps to protect from misuse, interference, loss, unauthorised access, modification, disclosure); APP 12 (access to personal information — 30 calendar days); APP 13 (correction of personal information — reasonable steps within 30 calendar days). Substantive sections: s 5B (extraterritorial application — Australian link); s 6 (definitions — personal information, sensitive information, health information); s 6C (private-sector organisation); s 6D (small business operator carve-out + s 6D(4)(b) collection-or-disclosure-of-children's-information exception that applies to Balance); s 13G (serious or repeated interference — civil penalty); s 13H (minor interference — civil penalty); s 16A (permitted general situations); s 16B (permitted health situations); Part IIIC — Notifiable Data Breaches scheme (ss 26WE through 26WT, in force since 22 February 2018); s 26WK (eligible data breach assessment — 30 days); s 26WL (notification to OAIC); s 26WM (notification to affected individuals); Part IV — Privacy Codes (ss 26B through 26F + Part IIIB ss 26C through 26R); Part V — Functions of the Commissioner; Part VI — Investigations (s 36 complaints, s 40 own-motion investigations, s 41 declined investigations, s 52 determinations); s 80W (Federal Court applications); POLA Act amendments (in force as set out in § 2.1 above). | The principal Commonwealth statute. Applies in full to Balance as a private-sector organisation engaged in the collection or disclosure of personal information of children (Privacy Act s 6D(4)(b) exception to the small business operator carve-out). Treatment in §§ 3, 4, 6, 7, 8, 11, 13 below. | |
| Privacy Regulation 2013 (Cth) | The principal regulation under the Privacy Act. | Operationalises specified Privacy Act sections, including the prescribed circumstances under APP 6.2(c)/(d), the prescribed amount under s 6D(1) (turnover threshold — currently AU$3 million), and the prescribed circumstances for Part IIIC notification. | Applies in full as the operational layer. |
| Privacy (Notifiable Data Breaches) Determination 2018 (Cth) | Privacy Act Part IIIC determination | Operationalises Part IIIC. | Applies in full. |
| OAIC Guidelines and Determinations | The OAIC's Australian Privacy Principles guidelines (most recent consolidated edition published progressively from 2014 through 2024) — Chapter B (extraterritorial application), Chapter 1 (APP 1), Chapter 5 (APP 5 collection notice), Chapter 6 (APP 6 use/disclosure), Chapter 7 (APP 7 direct marketing), Chapter 8 (APP 8 cross-border disclosure), Chapter 11 (APP 11 security), Chapter 12 (APP 12 access), Chapter 13 (APP 13 correction); the Notifiable Data Breaches scheme — Guide to the NDB scheme (most recent edition); the OAIC Privacy Impact Assessment Guide; the OAIC Privacy management framework — enabling compliance and encouraging good practice; the OAIC Guide to securing personal information; the OAIC's Guide to the privacy of children and young people; the body of OAIC determinations and own-motion findings published at https://www.oaic.gov.au/privacy/privacy-decisions/. |
Sets the OAIC's binding interpretive layer on the Privacy Act + APPs. | Applies. Balance's posture is operationalised consistently with the OAIC's published guidance — in particular the Guide to the privacy of children and young people. |
| Online Safety Act 2021 (Cth) | OSA — in force 23 January 2022, replacing the Enhancing Online Safety Act 2015 (Cth). Establishes the eSafety Commissioner (s 26) with functions over: Part 5 (adult cyber-abuse); Part 6 (cyber-bullying material targeted at an Australian child); Part 7 (non-consensual intimate images); Part 8 (material that depicts abhorrent violent conduct); Part 9 (industry codes and standards); Part 10 (industry standards); Part 11 (Online Content Scheme — class 1 and class 2 material); the Basic Online Safety Expectations (BOSE) made by determination under s 45 (in force per the Online Safety (Basic Online Safety Expectations) Determination 2022 (Cth) since 23 January 2022). | The principal online-safety statute. Applies to "social media services", "relevant electronic services", "designated internet services", "internet carriage services", and "hosting services" as defined in OSA Part 2. Balance is not a "social media service" (OSA s 13 — Balance has no functionality of enabling end-users to publish material on the service for distribution to other end-users), not a "relevant electronic service" (OSA s 13A — Balance is not an email, messaging, or VoIP service), not a "designated internet service" (OSA s 14 — Balance is not an Internet service that allows end-users to access material using a carriage service) in the sense engaged by Parts 5–8 and the BOSE Determination's broad-content-moderation expectations, and not a "hosting service" (OSA s 17 — Balance does not host third-party content for the public); Balance is best characterised as a private parental-control client that does not provide a content-distribution surface to the public. The OSA's content-removal-notice regime (Parts 5–8) does not engage Balance's architecture (which contains no public-distribution surface). | Applies to the extent of Balance's voluntary best-effort honor of the substantive child-safety obligations of the BOSE Determination — in particular the expectation that "the provider of the service will take reasonable steps to ensure that the service is safe to use" (BOSE s 6) and the expectation that the provider of a service "will take reasonable steps to minimise the extent to which the material on the service is unlawful or harmful" (BOSE s 14). Cross-reference: Child Safety Standards § 5 + § 6. |
| Online Safety Amendment (Social Media Minimum Age) Act 2024 (Cth) | The 2024 amendment to the OSA, introducing a minimum age of 16 for use of "age-restricted social media platforms" (defined narrowly to mean a social media service of which the sole or significant purpose is to enable online social interaction between two or more end-users, where the service allows end-users to link to or interact with another end-user, post material, generate a profile, and where the service is not exempted), in force from 10 December 2025. Imposes "reasonable steps" obligations on providers of age-restricted social media platforms. Civil penalties up to AU$49.5 million per contravention. | Balance is not an "age-restricted social media platform" within the meaning of the 2024 amendment: Balance does not enable online social interaction between two or more end-users in the public sense, does not allow end-users to link to or interact with another end-user outside the parent-kid pairing of a single household, does not allow end-users to post material to the public, and is not a service of which the sole or significant purpose is to enable online social interaction. The 2024 amendment therefore does not impose a direct statutory obligation on Balance. | Applies as a context-setting fact (the 2024 amendment confirms the Commonwealth's most-protective-of-children online-safety policy direction). |
| Criminal Code Act 1995 (Cth) | Criminal Code — Division 273 (offences involving child abuse material outside Australia); Division 273A (possession of child-like sex dolls); Division 471 (postal-services offences); Division 474 (telecommunications offences — including ss 474.19 (using a carriage service for child abuse material — production, possession, controlling access to, soliciting, transmitting), 474.20 (possession of child abuse material in Australia obtained or accessed using a carriage service), 474.22 (using a carriage service for child abuse material outside Australia), 474.23 (possession etc of child-like sex doll obtained or accessed using a carriage service), 474.25A (using a carriage service for sexual activity with a person under 16), 474.25B (using a carriage service to procure a person under 16), 474.25C (using a carriage service to "groom" a person under 16), 474.27 (using a carriage service to procure persons under 16 years of age), 474.27A (using a carriage service to transmit indecent communication to a person under 16)) | The principal Commonwealth criminal statute for CSAE, online-luring, and grooming offences. | Applies. Cross-reference in Child Safety Standards § 8.1 + § 14 below. |
| State and Territory Crimes Acts / Criminal Codes | Crimes Act 1900 (NSW); Crimes Act 1958 (Vic); Criminal Code Act 1899 (Qld); Criminal Code Act 1913 (WA); Criminal Law Consolidation Act 1935 (SA); Criminal Code Act 1924 (Tas); Crimes Act 1900 (ACT); Criminal Code Act 1983 (NT). Each contains State / Territory-specific CSAE, grooming, and indecent-image offences. | The State / Territory criminal regimes layer parallel to the Commonwealth Criminal Code. | Applies. State / Territory police forces enforce within their jurisdiction; the AFP enforces the Commonwealth offences. |
| Spam Act 2003 (Cth) | Spam Act — regulates the sending of commercial electronic messages ("CEMs") to or from a telecommunications-related computer in Australia. Requires consent (express or inferred) at s 16, identification of the sender at s 17, and an unsubscribe facility at s 18. Enforced by the Australian Communications and Media Authority ("ACMA"). | Regulates commercial electronic messages sent to or from Australia. Includes civil penalties under Part 4 administered by ACMA (up to AU$2.22 million per day for repeated breach by a body corporate). | Applies. Balance does not send commercial electronic messages to Australian residents; the only email Balance sends is transactional (account creation, password reset, subscription receipts, security alerts, parent-action notifications). Treatment in § 12.3 below. |
| Do Not Call Register Act 2006 (Cth) | Establishes the Australian Do Not Call Register. | Applies to telemarketing calls and faxes — not to email or push notifications. | Not engaged. Balance does not place telemarketing calls. |
| Telecommunications (Interception and Access) Act 1979 (Cth) | TIA Act — governs lawful interception of telecommunications by Commonwealth and State / Territory law-enforcement and security agencies. | The lawful-access framework for telecommunications. | Applies to the lawful-access response posture in § 13 below. |
| Telecommunications Act 1997 (Cth) | Telecommunications Act — Part 14 + Part 15 industry assistance regime + s 313 industry-assistance obligations. | The lawful-access framework for telecommunications service providers. | Balance is not a "carrier" or "carriage service provider" within the meaning of the Telecommunications Act, so Part 14 / Part 15 / s 313 obligations do not engage Balance directly. Applies as a context-setting fact. |
| Australian Consumer Law (ACL) | Australian Consumer Law, Schedule 2 to the Competition and Consumer Act 2010 (Cth) — s 18 (misleading or deceptive conduct); s 23 (unfair contract terms — standard form consumer contracts and small business contracts); s 29 (false or misleading representations about goods or services); s 36 (misleading representations about future matters); s 49 (referral selling — prohibition); ss 60–62 (consumer guarantees as to services — due care and skill, fit for any disclosed purpose, reasonable time for supply); ss 64–64A (limits on liability for failure to comply with consumer guarantees); ss 69–95 (unsolicited consumer agreements — 10-business-day cooling-off period for in-person solicitations); s 232 (injunctions); s 236 (compensatory damages); s 237 (compensatory orders for non-party consumers); s 246 (non-punitive orders); s 247 (adverse publicity orders); civil penalties up to the greater of AU$50 million / 3x benefit / 30% of adjusted turnover (consistent with the 2022 Treasury Laws Amendment (More Competition, Better Prices) Act 2022 (Cth)). Enforced by the Australian Competition and Consumer Commission ("ACCC") + State / Territory Fair Trading agencies. | The principal consumer-protection statute. | Applies in full. Treatment in § 16 below. |
| State / Territory Fair Trading Acts | NSW Fair Trading Act 1987; Vic Fair Trading Act 1999 + Australian Consumer Law and Fair Trading Act 2012; Qld Fair Trading Act 1989; WA Fair Trading Act 2010; SA Fair Trading Act 1987; Tas Australian Consumer Law (Tasmania) Act 2010; ACT Fair Trading (Australian Consumer Law) Act 1992; NT Consumer Affairs and Fair Trading Act 1990. Each applies the ACL within the State / Territory. | Each State / Territory Fair Trading agency enforces the ACL within the State / Territory + a small additional layer of State / Territory consumer-protection rules. | Applies. Treatment in § 16 below. |
| EU adequacy | None. Australia does not hold an EU adequacy decision under GDPR Art 45 at the Effective date. Australia is not listed in the European Commission's Adequacy decisions register. EU/EEA → Australia transfers are governed by EU SCCs + a Transfer Impact Assessment. | Applies as a context-setting fact. Cross-reference in EU / EEA annex § 8 — the EU/EEA Annex confirms that EU/EEA residents' data may flow to Australia only under EU SCCs + supplementary measures. | The absence of EU adequacy does not affect Balance's posture because Balance has no Australian data residency (the backend is in the US — see § 9 below). |
| Convention 108 | Not applicable. Australia is not a party to the Council of Europe Convention 108 or Convention 108+. | Applies as a context-setting fact. | The Council-of-Europe layer is not engaged for the Australian-resident flows. |
(Any prospective Commonwealth or State or Territory regulation governing automated processing, algorithmic decisions, or related techniques — including the proposed automated decision-making transparency requirements that may be developed by the OAIC under the POLA Act 2024 framework, any future Australian AI Safety Standard (the Department of Industry, Science and Resources' voluntary AI Safety Standard published 5 September 2024 is voluntary and does not impose a binding statutory obligation), any future AI Act before the Commonwealth Parliament, and any State or Territory automated-decision regulation, and any OAIC or ACMA guidance in that area — is intentionally omitted from this Annex on the principle that this Annex makes no affirmative or negative statement about whether Balance does or does not process personal data using techniques within the scope of any such Australian regulation. Balance's substantive product posture is described elsewhere in the policy bundle and is the controlling reference; this Annex's silence on the topic is deliberate and is not to be read as an implicit statement either way.)
3. Supervisory authorities
3.1 OAIC — Office of the Australian Information Commissioner
The principal supervisory authority is the Office of the Australian Information Commissioner ("OAIC"), established under the Australian Information Commissioner Act 2010 (Cth). The OAIC is led by the Australian Information Commissioner + the Privacy Commissioner + (from December 2024) the Freedom of Information Commissioner — three separate statutory officers within the OAIC.
| Field | Value |
|---|---|
| Name | Office of the Australian Information Commissioner (OAIC) |
| Headquarters | GPO Box 5288, Sydney NSW 2001 + Level 3, 175 Pitt Street, Sydney NSW 2000 |
| Website | https://www.oaic.gov.au/ |
| Complaint channel | OAIC online complaint form at https://www.oaic.gov.au/privacy/privacy-complaints/lodge-a-privacy-complaint-with-us, by mail to GPO Box 5288, Sydney NSW 2001, or by phone at 1300 363 992 (cost of a local call within Australia) |
| Breach-notification channel | OAIC online Notifiable Data Breach form per Privacy Act Part IIIC at https://www.oaic.gov.au/privacy/notifiable-data-breaches/report-a-data-breach |
| Australian Information Commissioner | At the Effective date — Elizabeth Tydd (or successor as published at the OAIC website) |
| Privacy Commissioner | At the Effective date — Carly Kind (or successor as published at the OAIC website) |
The OAIC is the first-line forum for any Privacy-Act-grounded complaint from any Australian resident. An Australian resident may petition the OAIC without first raising the matter with Balance, provided the resident has first attempted to resolve the matter directly with the respondent organisation (Privacy Act s 40(1A)). We accept all DSAR / privacy enquiries at (named individual: , in his capacity as the individual responsible for compliance under APP 1.2 + s 13 of the Privacy Act) and we respond within the APP timelines (see § 6 below).
An Australian resident may also pursue private remedies against Balance via the statutory tort for serious invasions of privacy (in force from 10 June 2025 — see § 2.1 above); via the direct right of action to the Federal Court of Australia or the Federal Circuit and Family Court of Australia (in force from 10 December 2025); via the Federal Court of Australia under Privacy Act s 80W after an OAIC determination; via the ordinary State / Territory courts; or via the criminal route under the Commonwealth Criminal Code Act 1995 or the State / Territory Crimes Acts where criminal offences are engaged.
3.2 eSafety Commissioner
The eSafety Commissioner is established under Online Safety Act 2021 s 26 (succeeding the Children's eSafety Commissioner of 2015). The eSafety Commissioner administers the OSA Parts 5–8 (adult cyber-abuse, child cyber-bullying, non-consensual intimate images, abhorrent violent material), the BOSE Determination, the Online Content Scheme (Part 11), and the registered industry codes and standards (Parts 9–10).
| Field | Value |
|---|---|
| Name | eSafety Commissioner |
| Headquarters | PO Box Q500, Queen Victoria Building NSW 1230 + Level 16, 207 Kent Street, Sydney NSW 2000 |
| Website | https://www.esafety.gov.au/ |
| Complaint channel | eSafety online reporting forms at https://www.esafety.gov.au/report — separate forms for adult cyber-abuse, child cyber-bullying, non-consensual intimate images, illegal and restricted content |
| Phone | (02) 9219 5000 |
| eSafety Commissioner | At the Effective date — Julie Inman Grant (or successor as published at the eSafety website) |
3.3 ACMA — Australian Communications and Media Authority
The Australian Communications and Media Authority ("ACMA") administers the Spam Act 2003 (Cth), the Telecommunications Act 1997 (Cth), and certain provisions of the OSA in cooperation with the eSafety Commissioner.
| Field | Value |
|---|---|
| Name | Australian Communications and Media Authority (ACMA) |
| Headquarters | PO Box Q500, Queen Victoria Building NSW 1230 + Level 16, 207 Kent Street, Sydney NSW 2000 |
| Website | https://www.acma.gov.au/ |
| Spam complaint channel | ACMA online Spam complaint at https://www.acma.gov.au/forms/lodge-spam-complaint; phone 1800 226 003 |
3.4 ACCC — Australian Competition and Consumer Commission
The Australian Competition and Consumer Commission ("ACCC") administers the ACL.
| Field | Value |
|---|---|
| Name | Australian Competition and Consumer Commission (ACCC) |
| Headquarters | 23 Marcus Clarke Street, Canberra ACT 2600 + GPO Box 3131, Canberra ACT 2601 |
| Website | https://www.accc.gov.au/ |
| Complaint channel | ACCC online complaint at https://www.accc.gov.au/consumers/complaints-and-problems/make-a-consumer-complaint; phone 1300 302 502 |
| State / Territory Fair Trading agencies | NSW Fair Trading (https://www.fairtrading.nsw.gov.au/); Consumer Affairs Victoria (https://www.consumer.vic.gov.au/); Queensland Office of Fair Trading (https://www.qld.gov.au/law/fair-trading/); Consumer Protection WA (https://www.commerce.wa.gov.au/consumer-protection); Consumer and Business Services SA (https://www.cbs.sa.gov.au/); Consumer Affairs Tasmania (https://www.cbos.tas.gov.au/); ACT Office of Regulatory Services (https://www.accesscanberra.act.gov.au/); NT Consumer Affairs (https://consumeraffairs.nt.gov.au/) |
3.5 The Privacy Officer / individual responsible for compliance
APP 1.2 + Privacy Act s 13 read with the OAIC's APP Guidelines Chapter 1 require an organisation to take reasonable steps to implement practices, procedures, and systems that will ensure compliance with the APPs — including the designation of a contact point for the organisation's privacy obligations.
The Balance Privacy Officer is:
- , Director, BabaYaga Program, TOO —
.
The Privacy Officer's contact details are published in this Annex and in the global Privacy Policy (Privacy Policy § 1). The Privacy Officer is the contact point for the OAIC, the eSafety Commissioner, the ACMA, and the ACCC on any regulatory matter; and for data subjects on rights-exercise matters.
4. Lawful bases — APP 3 + APP 6
The Privacy Act does not use the GDPR "lawful bases" taxonomy. Instead:
- APP 3.1 allows an APP entity to collect personal information (other than sensitive information) only if the information is reasonably necessary for, or directly related to, one or more of the entity's functions or activities.
- APP 3.3 allows the collection of sensitive information only with the consent of the individual + the information is reasonably necessary for one or more of the entity's functions or activities; or one of the permitted general situations (s 16A) or permitted health situations (s 16B) applies.
- APP 6 governs use and disclosure: the primary purpose is the purpose for which the information was collected; secondary purposes require consent or one of the limited carve-outs (related purpose; required or authorised by law; etc.).
Balance processes personal information of Australian residents under the following primary-purpose mapping:
| Processing purpose | APP basis | Cross-reference |
|---|---|---|
| Run the parental-control service the parent signed up for (account creation, family configuration, kid profile, limits, schedules, tasks, earned-time ledger, end-to-end-encrypted proof media) | APP 3.1 (reasonably necessary for the entity's function of providing the parental-control service) + APP 3.6 (collection from the individual — the parent — to whom the information relates) + APP 3.5 (lawful and fair means) + APP 6.1 (use for the primary purpose) | H1 § 4; H7 PA-01 through PA-08; § 7 of this Annex |
| Process the kid's personal information | APP 3.1 + APP 3.6 (collection from the kid + collection from the parent, both with the parent's consent on behalf of the kid + OAIC Guide to the privacy of children and young people on capacity test) + s 16A permitted general situation (collection necessary to lessen or prevent a serious threat to the life, health, or safety of any individual — applies only in safeguarding edge cases) | § 7 of this Annex; our Data Protection Impact Assessment § 6 |
| Deliver operational alerts | APP 6.1 (primary purpose) | H1 § 4; H7 PA-09; M3 |
| Detect, prevent, and respond to security incidents, abuse, fraud, and unauthorised access | APP 11 (security duty) + APP 6.2(b) (use or disclosure for a secondary purpose reasonably necessary for one or more enforcement-related activities) + s 16A (permitted general situation) | H7 PA-15; § 13 below |
| Comply with legal, regulatory, and supervisory obligations | APP 6.2(b) (required or authorised by or under an Australian law or a court / tribunal order) | § 13 below; M1; § 14 below |
| Process Verifiable Parental Consent for the kid's data | APP 3.1 + APP 3.6 — collection of the parent's information for the primary purpose of obtaining VPC | § 7 of this Annex; A-US § 5 |
| Process the parent's billing / subscription data | APP 3.1 — necessary for the entity's function of providing the subscription service; ACL overlay in § 16 below | H4; § 16 below |
Balance does not collect sensitive information (Privacy Act s 6) from any Australian resident: no health information, no biometric information, no information about racial or ethnic origin, no political opinions, no religious beliefs, no sexual orientation or practices, no criminal record, no membership of a professional or trade association, no membership of a trade union, no philosophical beliefs. The APP 3.3 sensitive-information consent regime is therefore not engaged.
Balance also does not collect government related identifiers (Privacy Act s 6) from any Australian resident: no Tax File Number, no Medicare number, no driver's licence number, no passport number, no Centrelink customer reference number, no Department of Veterans' Affairs file number, no individual healthcare identifier. The APP 9 government-related-identifiers regime is therefore not engaged.
5. Children's rights overlay
Australia does not have a federal children-specific data-protection statute equivalent to COPPA (US), GDPR Art 8, or Quebec Private Sector Act s 8.1, at the Effective date. The POLA Act 2024 directs the OAIC to develop and register the Children's Online Privacy Code under Privacy Act s 26GC within 24 months of Royal Assent (by 10 December 2026). At the Effective date, the Code has not yet been registered; the § 18 versioning protocol provides for an immediate off-cycle update of this section on the Code's registration.
The children's regime at the Effective date is built up from (i) Privacy Act + APPs read with the OAIC's Guide to the privacy of children and young people; (ii) the capacity test at common law (whether a child has sufficient understanding and intelligence to enable them to understand fully what is proposed — the Gillick competence test as adopted in Australia in Secretary, Department of Health and Community Services v JWB and SMB (Marion's Case) (1992) 175 CLR 218); (iii) State and Territory child-welfare statutes setting cooperation and mandatory-reporting obligations (e.g., Children and Young Persons (Care and Protection) Act 1998 (NSW), Children, Youth and Families Act 2005 (Vic), Child Protection Act 1999 (Qld), Children and Community Services Act 2004 (WA), Children and Young People (Safety) Act 2017 (SA), Children, Young Persons and Their Families Act 1997 (Tas), Children and Young People Act 2008 (ACT), Care and Protection of Children Act 2007 (NT)); (iv) the UN Convention on the Rights of the Child (Australia ratified 17 December 1990).
5.1 Definitions
For the purposes of this Annex:
- Child: every person under the age of 18 (the age of majority across all Australian States and Territories).
- Young person: the OAIC's Guide to the privacy of children and young people recognises the 15-and-over threshold as the operating point at which a young person is generally taken to have sufficient capacity to consent on their own behalf in respect of their personal information, with the parent consenting on behalf of younger children — but the assessment is on a case-by-case capacity basis per the Gillick / Marion's Case approach.
5.2 Verifiable Parental Consent (VPC) for Australian kids
Balance applies the most-protective reading and obtains Verifiable Parental Consent for every Australian kid regardless of age, using the VPC mechanism in United States annex § 5 (email-verified parent account creation + payment-method capture at subscription time + parent's affirmative in-app action of creating the kid profile and pairing the kid's device). The VPC screen for Australian residents itemises the categories of personal information being authorised, the purposes for which it is being processed, the third parties to whom it may be disclosed (sub-processors), and the data subject's rights under the Privacy Act.
5.3 No kid-self-serve consent path
Balance does not provide a kid-self-serve consent path inside the app. The parent always consents on behalf of the kid; the kid app's UI is designed for the kid to see their own limits, schedules, tasks, and earned-time ledger, and to request changes through the in-app "request change" affordance, which is forwarded to the parent device for the parent's decision. This is the most-protective reading of APP 3 + APP 5 + APP 6 + the OAIC Guide + Marion's Case.
5.4 No advertising directed at children
Balance does not display advertising to any user (parent or kid), does not allow any third party to display advertising in Balance, and does not build a behavioural-advertising profile of any user. This is consistent with: (i) the OAIC's interpretive position that Privacy Act APP 7 direct-marketing restrictions apply with particular force where the recipient is a child; (ii) the Australian Association of National Advertisers Code for Advertising and Marketing Communications to Children (the AANA Children's Code); (iii) the BOSE Determination s 8 expectations regarding the impact of services on the safety of children. Cross-references: the Play Console Data Safety form § 2 (Contains ads: No); the Play Console Child Safety Standards declaration § 3 ATTESTATION-D.
5.5 Cooperation routes
The principal Australian child-protection bodies are: (i) the Australian Federal Police — Australian Centre to Counter Child Exploitation ("ACCCE") — the federal law-enforcement node for online CSAE; (ii) the eSafety Commissioner — for cyber-bullying, image-based abuse, and online safety; (iii) the State and Territory police forces — NSW Police, Victoria Police, Queensland Police, Western Australia Police, South Australia Police, Tasmania Police, Northern Territory Police, ACT Policing; (iv) the State and Territory child-protection agencies — Department of Communities and Justice (NSW), Department of Families, Fairness and Housing (Vic), Department of Child Safety, Seniors and Disability Services (Qld), Department of Communities (WA), Department for Child Protection (SA), Department for Education, Children and Young People (Tas), Community Services Directorate (ACT), Department of Territory Families, Housing and Communities (NT); (v) Kids Helpline — Australia's national 24-hour confidential helpline for young people aged 5–25; (vi) National Office of Child Safety within the Attorney-General's Department. Balance cooperates with each on incidents involving Australian kids — see § 14 below.
6. Privacy Act + APP rights catalogue
6.1 The rights catalogue
An Australian resident has the following rights under the Privacy Act + APPs as in force at the Effective date. The article-list mirrors the APPs as in force at the Effective date (incorporating the POLA Act 2024 amendments in force).
- APP 1.4 — Privacy policy access. The right to obtain access to the APP entity's privacy policy free of charge. Satisfied by the global Privacy Policy + this Annex.
- APP 5 — Collection notice. The right to be notified, at or before the time of collection (or as soon as practicable thereafter), of the matters at APP 5.2 (identity and contact details of the APP entity; the fact of and circumstances of the collection; consequences if information not collected; usual disclosures; cross-border disclosures and likely countries of recipients; etc.). Satisfied by the in-app consent screen + the global Privacy Policy.
- APP 12 — Access to personal information. The right to obtain access to personal information about the individual that the APP entity holds. Honored at
and in-app at Settings → Family → [kid name] → "Export this kid's data". Format: machine-readable JSON archive, with a plain-language English summary. - APP 13 — Correction of personal information. The right to require the APP entity to correct personal information that is inaccurate, out of date, incomplete, irrelevant, or misleading. Honored in-app at Settings → Account → Edit and at
. - APP 7.2 + 7.3 — Opt-out of direct marketing. The right to opt out of direct marketing communications. Balance does not send direct marketing; the right is honored to the extent applicable.
- Privacy Act s 36 — Complaint to the OAIC. The right to make a complaint to the OAIC about an act or practice that may be an interference with the privacy of the individual.
- Privacy Act s 80W — Federal Court / Federal Circuit and Family Court of Australia application after an OAIC determination.
- POLA Act Schedule 2 — Statutory tort for serious invasions of privacy (in force from 10 June 2025). The right to commence a civil cause of action for a serious invasion of privacy by intrusion upon seclusion or misuse of information, where the invasion is intentional or reckless, the privacy interest outweighs the public interest, and the invasion is in fact serious. Heard by the Federal Court of Australia and the Federal Circuit and Family Court of Australia + the supreme courts of each State and Territory.
- POLA Act direct right of action (in force from 10 December 2025). The right to apply directly to the Federal Court of Australia or the Federal Circuit and Family Court of Australia after exhausting the OAIC complaint mechanism.
- Equitable remedies — the equitable cause of action for breach of confidence (still operative); equitable injunctive relief.
6.2 Timeline
- APP 12 access: within 30 calendar days of the request (the OAIC's APP Guidelines Chapter 12 sets 30 calendar days as the maximum reasonable period).
- APP 13 correction: within 30 calendar days of the request.
- OAIC complaint: the OAIC's published target is to resolve complaints within 12 months; complex matters may take longer.
- POLA Act direct right of action: standard court timelines.
- Statutory tort: standard court timelines.
Where the request is manifestly unfounded or excessive, Balance may charge a reasonable fee based on administrative cost (APP 12.8 — Balance does not charge for the application itself; only for access, and only at reasonable cost) or refuse to act on the request, telling the data subject the reason and informing them of the right to complain to the OAIC.
6.3 Identity verification
Where there is reasonable doubt about the identity of the natural person making the request, Balance may request additional information necessary to confirm the identity (APP 12.6). The identity-verification protocol uses the parent's existing authentication credential. Out-of-band identity verification is requested only as a last resort, only for the parent, and only for the categories of personal information that require a higher assurance of identity.
6.4 No cost
The exercise of the APP 12 access right is free of charge for the application (APP 12.7); Balance may charge for actually giving access only if the charge is not excessive (APP 12.8). Balance does not charge for access in practice.
6.5 Language
A request may be submitted in English. The OAIC accepts complaints in English.
7. Children's data — APP 3 + APP 5 + APP 6 + OAIC Guide to the privacy of children and young people
Balance processes personal information of Australian kids under the following layered framework:
- APP 3.1 + APP 3.6 + APP 5 + APP 6.1 collection-and-use regime + the OAIC's Guide to the privacy of children and young people published practice that an APP entity should obtain the consent of a parent or guardian where a child does not have the capacity to consent on their own behalf, with the capacity assessed on a case-by-case basis using a Gillick / Marion's Case approach.
- Common-law capacity test — Marion's Case (1992) 175 CLR 218 read with Gillick v West Norfolk and Wisbech Area Health Authority [1986] AC 112 — a child has sufficient understanding and intelligence to enable them to understand fully what is proposed.
- State and Territory child-protection statutes (per § 5.5 above) — set cooperation and mandatory-reporting obligations on certain occupations and on the public.
- Children's Online Privacy Code (to be registered by 10 December 2026) — not in force at the Effective date; § 18 versioning protocol covers its eventual registration.
- UN Convention on the Rights of the Child (Australia ratified 17 December 1990) — internalised through the AHRC Act Schedule 2 (which incorporates the ICCPR, not the CRC; the CRC is incorporated through the Family Law Act 1975 (Cth) s 60B + s 60CA "best interests of the child" principle) and through State / Territory child-protection statutes.
For Balance:
- Verifiable Parental Consent. Identical mechanism to A-US § 5. The VPC screen is in English (Australia has no statutory translation requirement at the Effective date).
- No kid-self-serve consent path. Per § 5.3 above.
A parent may revoke consent at any time at Settings → Family → [kid name] → "Delete this kid" (or by email to ). Revocation triggers the cascade documented in Data Retention & Deletion Policy § 7. Revocation does not affect the lawfulness of processing carried out before the revocation.
8. International data transfers from Australia — APP 8
The controller (BabaYaga Program, TOO) is established in Kazakhstan. The backend (Emergent Labs Inc.) is hosted in the United States. Proof-media storage (Google Cloud Storage) is in the United States. Push (Firebase Cloud Messaging), sign-in (Google Sign-In), and billing (Google Play Billing) are operated by Google LLC and dispatched from the United States. Transactional email (Resend) is dispatched from the United States. Accordingly, every Australian resident's personal information leaves Australia at the point of being uploaded to the Balance backend.
8.1 The Australia-to-US transfer mechanism — APP 8
APP 8 governs the disclosure of personal information by an APP entity to an overseas recipient. The general rule (APP 8.1): before an APP entity discloses personal information about an individual to a person (the overseas recipient) who is not in Australia or an external Territory and who is not the entity, the entity must take reasonable steps to ensure that the overseas recipient does not breach the APPs (other than APP 1) in relation to the information. The five carve-outs to APP 8.1 are at APP 8.2 (the entity reasonably believes the recipient is subject to a law / binding scheme that has the effect of protecting the information in a way that, overall, is at least substantially similar to the APPs, and the individual is able to access mechanisms to enforce it; or the individual consents to the disclosure after being expressly informed that APP 8.1 will not apply; or the disclosure is required or authorised by an Australian law; or the disclosure is required by a court / tribunal order; or one of the permitted general situations (s 16A) applies).
In addition, Privacy Act s 16C sets the "accountability" rule: where an APP entity has discloses personal information about an individual to an overseas recipient and the recipient handles the information in a way that would breach the APPs (had APP 8 applied), the entity is taken to have done the act or engaged in the practice that breached the APPs — i.e., the disclosing entity remains liable for the recipient's mishandling.
Balance relies on the following stack to satisfy APP 8 + s 16C for the Australia → US transfer:
- Express consent (APP 8.2(b)). The parent's sign-up consent prominently and expressly discloses the cross-border transfer, expressly states that APP 8.1 will not apply (in plain language: "Balance will not be required to ensure that the overseas recipient handles your personal information consistent with the Australian Privacy Principles"), and lists the country of destination (the United States) and the categories of recipients. Cross-reference: Privacy Policy § 12 + the in-app consent screen.
- Reasonable steps under APP 8.1 (alongside the consent carve-out). Each US sub-processor (Emergent Labs Inc.; Google LLC for GCS, FCM, Sign-In, and Play Billing; Resend, Inc.) is bound by a written processor agreement that contractually requires the recipient to handle the information in accordance with the APPs. The full transfer pack is in our international-transfer pack § 6. The contractual safeguards are reinforced by EU SCC substance + EU UK IDTA substance as the substantive overlay.
- Supplementary measures — most importantly, the end-to-end encryption of proof media documented in our encryption-posture record. The E2EE is the principal supplementary measure ensuring that even a compelled-production scenario in the US yields only opaque ciphertext, not plaintext media.
- Onward-transfer restrictions — every sub-processor's processor agreement forbids onward transfer of Australian-resident personal information to a third country outside the framework above without the controller's prior written authorisation.
8.2 APP 8 transparency overlay — APP 1.4(b) and APP 5
The POLA Act 2024 amendment to APP 1.4 (in force from 10 December 2024) strengthened the transparency obligations on cross-border disclosures: the privacy policy must now state the countries in which overseas recipients are likely to be located. The Balance global Privacy Policy and this Annex satisfy that obligation by naming the United States as the destination country (§ 9 below); the in-app collection notice under APP 5 names the United States and the categories of recipients.
8.3 The Australia-to-KZ axis (controller administrative access)
The controller's personnel in Kazakhstan have administrative access to the US-hosted backend for operational purposes. Because Kazakhstan is a third country and Kazakhstan is not on any Australian "substantially similar" list (because Australia does not maintain such a list under APP 8.2(a) at the Effective date), the Australia-KZ axis is covered by the parent's express consent (APP 8.2(b)) + written processor agreements signed between Emergent Labs (as processor) and BabaYaga Program, TOO (as controller) in inverse, with EU-SCC substance preserved. The transfer-impact analysis for the KZ leg is in our international-transfer pack § 7.
9. Data residency for Australian residents
| Question | Answer |
|---|---|
| Where is the backend hosted? | United States. Emergent Labs Inc. (Delaware) on US infrastructure. |
| Where is the MongoDB database located? | United States. |
| Where is the proof-media storage located? | United States — Google Cloud Storage us multi-region. |
| Where are push notifications dispatched from? | United States — Firebase Cloud Messaging. |
| Is any Australian resident's personal information held in Australia? | No. Every Australian resident's personal information is held in the United States. The APP 8 transfer mechanism in § 8 above is the legal basis for the transfer. |
| Where is the controller? | Kazakhstan (BabaYaga Program, TOO). The controller has administrative access to the US-hosted backend via written processor agreements. |
| Is there an Australian establishment? | No. Balance has no permanent establishment in Australia. The Privacy Act's extraterritorial reach (s 5B + the Australian link test) is the basis for Balance's Australian-Privacy-Act compliance. |
| Where is the supervisory authority? | Australia — OAIC + eSafety Commissioner + ACMA + ACCC. |
The decision to centralise on a US-only backend is documented in our internal compliance plan § 6. Australia does not impose a comprehensive data-localisation mandate on parental-control services at the Effective date, with the exception of certain sector-specific regimes (e.g., the My Health Records Act 2012 (Cth) s 77 — health-information data-localisation; not applicable to Balance because Balance does not collect health information) and certain national-security regimes (Security of Critical Infrastructure Act 2018 (Cth); not applicable to Balance because Balance is not a critical infrastructure asset).
10. Sub-processors touching Australian-resident data
| Sub-processor | Role | Location of processing | Australian transfer paperwork |
|---|---|---|---|
| Emergent Labs Inc. (Delaware, USA) — using MongoDB Atlas (MongoDB, Inc., US) for the production database; relationship governed by Emergent ToS (22 Dec 2025) + Privacy Policy (28 May 2026) as the GDPR Art 28(3) "other legal act" (no standalone DPA available outside Enterprise per Emergent final position 2026-06-10; full handling in our internal vendor-handling plan); MongoDB Atlas Customer DPA + EU SCCs Module 2 + UK IDTA Addendum at https://www.mongodb.com/legal/dpa cover the storage layer | Hosts the FastAPI backend + MongoDB cluster | United States | Parent's express consent (APP 8.2(b)) + written processor agreement with APP-aligned safeguards (APP 8.1 reasonable steps) on file per our international-transfer pack § 6; E2EE supplementary measure for proof media. |
| Google LLC — Google Cloud Storage (USA) | Stores end-to-end-encrypted proof-media ciphertext | United States (us multi-region) |
Parent's express consent + written processor agreement (Google Cloud Data Processing Addendum) with APP-aligned safeguards; ciphertext-only handling. |
| Google LLC via Google Cloud (USA) | Periodic (daily) backups of our operational database | United States (us multi-region) |
Parent's express consent + written processor agreement (Google Cloud Data Processing Addendum) with APP-aligned safeguards; the backup archive holds the operational data we hold about the resident (account, family, kid profile, usage totals, tasks, earned-time ledger, device identifiers, push tokens), other than the items that never reach our backend in readable form (the kid's proof media and the media-encryption keys); retained on a 30-day rolling window, then automatically deleted. |
| Google LLC — Firebase Cloud Messaging | Delivers push notifications to Australian kid + parent devices | United States | Parent's express consent + written processor agreement as above; push body deliberately free of sensitive content (cross-reference: the just-in-time permission disclosures). |
| Google LLC — Google Sign-In | Authenticates parent Google identity (when used) | United States | Parent's express consent + written processor agreement as above. |
| Google LLC — Google Play Billing | Processes subscription purchases | United States | Parent's express consent + Google Play Developer Distribution Agreement. |
| Resend, Inc. (San Francisco, CA, USA) | Delivers transactional email to Australian parent users | United States | Parent's express consent + written processor agreement on file. |
Every sub-processor is bound by a written data-processing agreement that forbids processing of any data we transmit for any purpose other than performing the service we engaged them for, and that incorporates the security and confidentiality controls in our Records of Processing Activities (Article 30) § 7 + APP 11 (security duty). The full sub-processor list, with each row's processor-agreement status, is at our sub-processor register.
11. Breach notification — Privacy Act Part IIIC (NDB scheme)
Privacy Act Part IIIC (the Notifiable Data Breaches scheme, in force since 22 February 2018) sets the breach-notification regime:
| Audience | Trigger | Deadline | Channel |
|---|---|---|---|
| OAIC | An eligible data breach has occurred — defined at Privacy Act s 26WE as (i) unauthorised access to, or unauthorised disclosure of, personal information held by the entity, or (ii) loss of personal information in circumstances where unauthorised access or disclosure is likely to occur, and (iii) a reasonable person would conclude that the access or disclosure would be likely to result in serious harm to one or more of the individuals to whom the information relates (the "serious harm" test). | As soon as practicable after the entity becomes aware that the breach has occurred (Privacy Act s 26WL). The entity has 30 calendar days to conduct an assessment to determine whether the breach is an eligible data breach (s 26WK). Balance internal anchor: 72 hours (consistent with the GDPR Art 33 benchmark; faster than the Privacy Act "as soon as practicable" floor). | OAIC online Notifiable Data Breach form per Privacy Act Part IIIC + the Privacy (Notifiable Data Breaches) Determination 2018 (Cth) |
| Affected individuals | Same trigger as the OAIC notification. | As soon as practicable after the entity is satisfied that the breach is an eligible data breach (Privacy Act s 26WL). Balance internal anchor: 72 hours. | Direct email to the affected parent on file; in-app banner where the parent is logged in; out-of-app contact via the public-website incident page if email is no longer deliverable. The notification is in English. |
| CSAE-specific | An incident with a CSAE component. | Per § 14 below + the internal runbook (M1). | AFP ACCCE + eSafety Commissioner + State / Territory police. |
The internal breach-decision SLA is at our breach-notification runbook § 5.4 + § 9: preliminary classification within one business day, fuller assessment within seven days, OAIC notification within the 72-hour Balance internal anchor, affected-individual notification at the same point unless a court / tribunal order requires deferral.
11.1 Minimum content of the OAIC NDB notification (Privacy Act s 26WK + s 26WL + Determination)
The OAIC notification states:
- the identity and contact details of the entity;
- a description of the eligible data breach;
- the kind or kinds of information concerned;
- the recommendations about the steps that individuals should take in response to the eligible data breach;
- the DPO / Privacy Officer contact point (, named individual: ).
The English-language template lives in our breach-notification runbook § 8.1.
11.2 No notification carve-out (s 26WM)
Where Balance takes remedial action that prevents the access or disclosure from resulting in serious harm to the individual (s 26WF), Balance is not required to notify; Balance records the action taken in the breach register at our breach-notification runbook § 11.
12. Cookies, spam, and electronic direct marketing
Australia does not have a dedicated ePrivacy / cookies statute. The substantive position on cookies and electronic direct marketing is derived from: (i) APP 3 + APP 5 + APP 6 for any cookie that processes personal information; (ii) the OAIC's APP Guidelines Chapter 5 (Collection Notice) and Chapter 7 (Direct Marketing); (iii) the Spam Act 2003 (Cth) for commercial electronic messages; (iv) the Do Not Call Register Act 2006 (Cth) for telemarketing; (v) the Privacy Act s 7C (allows direct marketing for related primary purpose with opt-out); (vi) State / Territory consumer-protection statutes.
12.1 In-app — strictly-necessary storage only
The Balance app (parent and kid) does not deploy any cookie-equivalent storage that is not strictly necessary for the service. The strictly-necessary storage Balance uses (authentication tokens in Android SecureStore; the device-pairing key wrap; the kid app's earned-time cache) is operationally necessary and is covered by the parent's sign-up consent.
12.2 Public legal-documents site — no analytics, no advertising, no tracking
The public legal-documents site (balance.babayagaprogram.com) uses only strictly-necessary cookies; no analytics cookies; no advertising cookies; no third-party trackers; no fingerprinting; no embedded social plugins.
12.3 Electronic direct marketing — not sent
Balance does not send commercial electronic messages within the meaning of Spam Act 2003 s 6 to Australian residents. The only email Balance sends to Australian parent users is transactional — account creation, password reset, subscription receipts, security alerts, and parent-action notifications. The Spam Act s 6(4) carve-out for factual information and the s 6(5) carve-out for transactional messages (where the message is about a transaction the recipient has agreed to enter into) cover the Balance transactional posture. If Balance ever introduces a marketing channel, we will comply with Spam Act s 16 (consent — express or inferred), s 17 (identification), and s 18 (unsubscribe).
12.4 No telemarketing
Balance does not place telemarketing calls. The Do Not Call Register Act 2006 is not engaged.
13. Lawful-access requests and the encryption posture
Australian authorities may serve a lawful-access request on Balance via:
- A judicial production order or search warrant under the Crimes Act 1914 (Cth) Part IAA + Part IAB.
- A judicial intercept order under the Telecommunications (Interception and Access) Act 1979 (Cth) — the Commonwealth lawful-intercept framework. Note: Balance is not a "carrier" or "carriage service provider" within the meaning of the TIA Act, so the TIA Act's direct intercept obligations on carriers do not apply to Balance; the TIA Act's stored communications warrant regime (Part 3-3) may apply to stored personal information in limited circumstances.
- A technical assistance request / technical assistance notice / technical capability notice under the Telecommunications Act 1997 (Cth) Part 15 (the Telecommunications and Other Legislation Amendment (Assistance and Access) Act 2018 (Cth) framework). Balance is not a "designated communications provider" within the narrow technical meaning at Telecommunications Act s 317C in the sense that engages the s 317L technical-assistance-notice regime, because Balance does not provide a communications service to the public.
- An OAIC investigation request under Privacy Act ss 33C, 33D, 44, 80, 80A, 80W.
- A mutual legal assistance request from a foreign state via the Mutual Assistance in Criminal Matters Act 1987 (Cth).
- An ordinary State / Territory court production order or subpoena duces tecum under the procedural rules of the issuing State / Territory (e.g., Uniform Civil Procedure Rules 2005 (NSW); Supreme Court (General Civil Procedure) Rules 2015 (Vic); Uniform Civil Procedure Rules 1999 (Qld); etc.).
- A Federal Court of Australia production order or subpoena under the Federal Court Rules 2011 (Cth).
- A Federal Court of Australia order under the Cybercrime Act 2001 (Cth) — Australia's domestic implementation of the Budapest Convention on Cybercrime (Australia acceded to the Budapest Convention on 30 November 2012; the Convention entered into force for Australia on 1 March 2013).
The Balance architectural posture interacts with these mechanisms as follows:
- Proof media is end-to-end encrypted. The kid's device generates a fresh per-file file-encryption key, encrypts the proof file with XChaCha20-Poly1305, wraps the file-encryption key to each authorised parent device's X25519 public key, and uploads only the resulting ciphertext + the recipient-wrap envelopes. We do not retain a master key, a backdoor, or any other means by which we could ourselves decrypt the proof media.
- No assistance with bulk plaintext interception. Balance does not perform bulk plaintext content scanning. Balance does not deploy a server-side content-moderation engine on the proof-media payload. There is no plaintext on our side to be intercepted.
- Response protocol. On receipt of a lawful-access request directed at proof media, we will: 1. acknowledge receipt within one business day; 2. engage Australian counsel to assess the validity of the request and the appropriate response under APP 6.2(b) (required or authorised by or under an Australian law or a court / tribunal order); 3. preserve the relevant ciphertext for the period the request requires (subject to our retention rules); 4. inform the requesting authority that the proof media is end-to-end encrypted and that plaintext is not available from us; 5. cooperate in identifying and serving the lawful-process route to the parent — who holds the decryption key — if that is the appropriate channel.
- CSAE-cooperation overlay. Notwithstanding the encryption posture, Balance cooperates fully with the AFP Australian Centre to Counter Child Exploitation, with State / Territory police forces, with the eSafety Commissioner, and with the National Office of Child Safety on any CSAE-related referral, via the routes in § 14 below.
- Notification of the data subject. Where the lawful-access request is not accompanied by a non-disclosure obligation, we will inform the affected parent of the request (APP 1.3 + APP 5). Where the request is accompanied by a statutory non-disclosure obligation (e.g., under the Crimes Act 1914 (Cth) Part IAAA or the TIA Act s 63), we will comply with the order and inform the parent as soon as the order permits.
The full encryption posture is in our encryption-posture record.
14. CSAE reporting routes — Australia
An Australian resident (parent, kid, or third party) who wishes to report a CSAE concern about Balance, about a third party encountered outside Balance, or about a Balance user, may use any of the following routes:
- Balance Designated Child Safety Officer:
(named individual: ). Acknowledgement within one business day, in English. - Australian Federal Police — Australian Centre to Counter Child Exploitation (ACCCE) — the federal law-enforcement node for online CSAE. Online:
https://www.accce.gov.au/. Phone: 131 AFP (131 237). The principal Australian CSAE intake point. INHOPE-affiliated via Report a Cyber Crime + Cyber Report. - eSafety Commissioner — Report illegal and harmful content at
https://www.esafety.gov.au/report— separate intake forms for: (i) image-based abuse (OSA Part 7); (ii) child cyber-bullying (OSA Part 6); (iii) adult cyber-abuse (OSA Part 5); (iv) abhorrent violent material (OSA Part 8); (v) illegal and restricted content (Online Content Scheme — Part 11). - State and Territory police forces — emergency 000 (Triple Zero); non-emergency 131 444 (Police Assistance Line for NSW + VIC + QLD); State / Territory variations apply.
- Crime Stoppers Australia —
https://crimestoppers.com.au/; phone 1800 333 000. National anonymous reporting. - Kids Helpline — Australia's national 24-hour confidential helpline for young people aged 5–25. Phone: 1800 55 1800 (toll-free within Australia). Online chat at
https://kidshelpline.com.au/. - Bravehearts — child-sexual-abuse-survivor support and reporting line. Phone: 1800 272 831. Online:
https://bravehearts.org.au/. - Blue Knot Foundation — National Centre of Excellence for Complex Trauma. Phone: 1300 657 380. Online:
https://blueknot.org.au/. - National Office of Child Safety within the Attorney-General's Department. Online:
https://www.childsafety.gov.au/. - ICMEC — International Centre for Missing & Exploited Children —
https://www.icmec.org/. Australian coordination via AFP ACCCE + INTERPOL Canberra. - Te Protejo / regional INHOPE intake — for transnational reports (Australia does not host an independent INHOPE-member hotline at the Effective date; reports flow through ACCCE's Cyber Report channel and the eSafety Commissioner).
The full CSAE Country Routing Table is in Child Safety Standards § 8.6.
15. Complaint routes (summary)
An Australian resident who is dissatisfied with Balance's handling of a privacy enquiry or a child-safety concern may complain to any of the following authorities:
| Authority | Subject matter | Address / URL |
|---|---|---|
| Office of the Australian Information Commissioner (OAIC) | Privacy Act + APPs | GPO Box 5288, Sydney NSW 2001; https://www.oaic.gov.au/; phone 1300 363 992 |
| eSafety Commissioner | Online Safety Act 2021 + BOSE Determination + cyber-bullying / image-based abuse / illegal content | PO Box Q500, Queen Victoria Building NSW 1230; https://www.esafety.gov.au/; phone (02) 9219 5000 |
| Australian Communications and Media Authority (ACMA) | Spam Act 2003 + Telecommunications Act 1997 | PO Box Q500, Queen Victoria Building NSW 1230; https://www.acma.gov.au/; phone 1800 226 003 |
| Australian Competition and Consumer Commission (ACCC) | Australian Consumer Law | 23 Marcus Clarke Street, Canberra ACT 2600; https://www.accc.gov.au/; phone 1300 302 502 |
| Australian Human Rights Commission (AHRC) | Human-rights complaints under the ICCPR + AHRC Act | GPO Box 5218, Sydney NSW 2001; https://humanrights.gov.au/; phone 1300 369 711 |
| State / Territory Fair Trading agencies | State / Territory ACL enforcement + State / Territory consumer-protection | Per State / Territory — see § 3.4 above |
| Federal Court of Australia | Privacy Act s 80W application + statutory tort + direct right of action (from 10 December 2025) | https://www.fedcourt.gov.au/ |
| Federal Circuit and Family Court of Australia | Direct right of action (from 10 December 2025) + statutory tort | https://www.fcfcoa.gov.au/ |
| Supreme Court of NSW / Vic / Qld / WA / SA / Tas / ACT / NT | Statutory tort + State / Territory civil action | Per State / Territory |
An Australian resident may always first raise the matter with us at (DSAR; named individual: , in his capacity as the Privacy Officer). We will respond within the APP timelines. Raising the matter with us first is a precondition to the OAIC complaint (Privacy Act s 40(1A) — the OAIC may decide not to investigate if the complainant has not first complained to the respondent), unless the OAIC determines that requiring prior complaint would not be appropriate.
16. Consumer rights — the ACL overlay
The Australian Consumer Law (Schedule 2 to the Competition and Consumer Act 2010 (Cth)) applies to Balance's subscription flow as a consumer contract within the meaning of ACL s 23(3) (the supply is to a "consumer" under s 3 — a person who acquires services where the amount paid does not exceed the prescribed amount (currently AU$100,000) or where the services are of a kind ordinarily acquired for personal, domestic, or household use). Treatment is implemented in Subscription Terms § 20.
16.1 Consumer guarantees as to services (ACL ss 60–62)
The ACL implies into every consumer-services contract three non-excludable consumer guarantees:
- s 60 — Due care and skill. Services supplied must be rendered with due care and skill.
- s 61 — Fitness for a particular purpose. Where the consumer expressly or by implication makes known to the supplier a particular purpose for which the services are required, the services must be reasonably fit for that purpose.
- s 62 — Reasonable time for supply. Where the time for supply is not fixed, the services must be supplied within a reasonable time.
Failure to comply with a consumer guarantee triggers a major / non-major failure analysis (ACL ss 267–269) and a consumer's right to remedy (refund or compensation for reduction in value, or supply the services again).
16.2 Unfair contract terms (ACL ss 23–28A)
A term of a standard form consumer contract is unfair if it (i) would cause a significant imbalance in the parties' rights and obligations arising under the contract, (ii) is not reasonably necessary in order to protect the legitimate interests of the party advantaged by the term, and (iii) would cause detriment to a party if relied on. Unfair terms are void under s 23 + s 24. The 2022 amendments (in force from 9 November 2023) introduced civil penalties for proposing unfair terms (up to AU$50 million per term per individual / 3x benefit / 30% adjusted turnover for a body corporate). The Balance Terms of Service (Terms of Service) are drafted to avoid each ACL unfair-term risk.
16.3 Misleading or deceptive conduct (ACL s 18)
A person must not, in trade or commerce, engage in conduct that is misleading or deceptive or is likely to mislead or deceive. The Balance marketing copy at balance.babayagaprogram.com and on the Google Play Store listing is drafted to avoid each ACL s 18 risk.
16.4 Unsolicited consumer agreements (ACL ss 69–95)
Where the contract is an unsolicited consumer agreement (made in-person or by telephone away from the supplier's business premises), the consumer has a 10-business-day cooling-off period during which the consumer may terminate the agreement without penalty (ACL s 82). Balance's subscription is concluded in-app (i.e., it is a "distance" contract but not an "unsolicited" contract within the ACL meaning — the consumer initiated the subscription by downloading the app and proceeding through the subscription flow); the s 82 cooling-off does not directly apply. Balance honors a voluntary 14-day no-questions refund window via Google Play Billing, exceeding the s 82 standard.
16.5 Forum and choice of law
The Balance Terms of Service preserve the consumer's domicile forum (see Terms of Service § 19); choice-of-law clauses that would displace the ACL to the prejudice of the Australian consumer are unenforceable under ACL s 67 (where the proper law of the contract would be the law of a place outside the Commonwealth or a State or Territory, but for the term, the ACL applies to the contract).
17. Cross-references
- Global Privacy Policy: Privacy Policy (H1).
- Children's Privacy Notice: Children's Privacy Notice (H2).
- Terms of Service: Terms of Service (H3).
- Subscription Terms: Subscription Terms (H4).
- Child Safety Standards: Child Safety Standards (H5).
- Retention Policy: Data Retention & Deletion Policy (H6).
- Records of Processing: our Records of Processing Activities (Article 30) (H7).
- DPIA + LIA: our Data Protection Impact Assessment (H8).
- Breach Runbook: our breach-notification runbook (M1).
- Transfer Pack: our international-transfer pack (M2) — written processor agreements + APP 8 transfer paperwork on file.
- JIT Permission Disclosures: the just-in-time permission disclosures (M3).
- Play Console Permission Declarations: the Play Console permission declarations (M4).
- Play Console Data Safety: the Play Console Data Safety form (M5).
- Play Console Child Safety Standards Declaration: the Play Console Child Safety Standards declaration (M6).
- Play Console Target Audience + IARC: the Play Console Target Audience form (M7).
- US Country Annex: United States annex (A-US).
- UK Country Annex: United Kingdom annex (A-UK).
- EU/EEA Country Annex: EU / EEA annex (A-EU-EEA).
- Argentina Country Annex: Argentina annex (A-AR).
- Chile Country Annex: Chile annex (A-CL).
- Colombia Country Annex: Colombia annex (A-CO).
- Peru Country Annex: Peru annex (A-PE).
- Uruguay Country Annex: Uruguay annex (A-UY).
- Canada Country Annex: Canada annex (A-CA).
- App Classification: our country classification table.
- Sub-processor list: our sub-processor register.
- Android Permissions Register: our permissions register.
- Encryption Posture: our encryption-posture record.
- Data Flow / Inventory Map: our internal data-flow map.
- Phase-2 Placeholder Tracker: our internal compliance tracker.
- Compliance Plan: our internal compliance plan.
18. Versioning and review
This Annex follows the same strict versioning protocol as the rest of the Phase-1 bundle:
- Every change to a substantive row in §§ 2–16 bumps the Last updated date at the top of this file and triggers a re-publication at Privacy Policy and Children's Privacy Notice.
- A material amendment to the Privacy Act 1988 (Cth) or the APPs triggers an off-cycle rewrite of §§ 2, 4, 6, 8, and 11.
- The OAIC's registration of the Children's Online Privacy Code under Privacy Act s 26GC (expected by 10 December 2026 per the POLA Act 2024 framework) triggers an immediate off-cycle rewrite of §§ 5 + 7 + 18 of this Annex.
- The commencement of any further provision of the POLA Act 2024 not in force at the Effective date triggers an off-cycle update to the affected operational sections.
- A material amendment to the Online Safety Act 2021 (Cth) or to the BOSE Determination triggers an off-cycle update to § 5 + § 14.
- A material amendment to the Online Safety Amendment (Social Media Minimum Age) Act 2024 (Cth) framework triggers an off-cycle update to § 2 + § 5 of this Annex.
- A material amendment to the Criminal Code Act 1995 (Cth) (in particular Division 273 + Division 474) or to any State / Territory Crimes Act / Criminal Code triggers an off-cycle update to § 13 + § 14.
- A material amendment to the Spam Act 2003 (Cth), the Telecommunications Act 1997 (Cth) Part 15, the Telecommunications (Interception and Access) Act 1979 (Cth), or to the Cybercrime Act 2001 (Cth) triggers an off-cycle update to the relevant operational section.
- A material amendment to the Australian Consumer Law triggers an off-cycle update to § 16 + Subscription Terms.
- A material judgment of the High Court of Australia on the implied freedom of political communication, the Australian Human Rights Commission Act 1986 (Cth) ICCPR-incorporation reading, or on any Privacy Act provision triggers an off-cycle update to the relevant operational section.
- A material judgment of the Federal Court of Australia or the Federal Circuit and Family Court of Australia under Privacy Act s 80W or the statutory tort or the direct right of action triggers an off-cycle update to the relevant operational section.
- A material OAIC determination, APP Guideline, Privacy Code, or own-motion finding that materially affects Balance's posture triggers an off-cycle update.
- A material eSafety Commissioner determination or registered industry code / standard that materially affects Balance's posture triggers an off-cycle update.
- A new EU adequacy decision for Australia (currently none at the Effective date) triggers an off-cycle update to § 8 + § 9.
- A material change to a sub-processor's APP-aligned status triggers an off-cycle update to § 8 + § 10 + our sub-processor register.
- The annual review is by 9 June. The Privacy Officer signs the review off; the Designated Child Safety Officer co-signs any change to § 3 (supervisory authorities), § 5 (children's rights), § 11 (breach), § 13 (lawful-access), or § 14 (CSAE routes).
- This Annex is republished alongside H1 and H2 at the public legal-documents site (Privacy Policy and Children's Privacy Notice) and is incorporated by reference. No translation is required at the Effective date.
End of Australia Country Annex.