rxnet
Terms of Service
- Document
- Broadstack Pty Ltd-TOS-1
- Version
- 202609
- Effective from
- 2026-09-14
- Cited by
- D2, and D1 clause 2.2
Schedule 1 to the Master Subscription Agreement
rxnet — Software as a Service
1. ABOUT THESE TERMS
1.1 Purpose
These Terms of Service set the rules for day to day use of rxnet. They cover accounts, acceptable use, content, and the practical operation of the service.
1.2 Relationship to other documents
(a) These Terms of Service are Schedule 1 to the Master Subscription Agreement between Broadstack Pty Ltd (Provider) and the Customer (Customer). Agreement has the meaning given in clause 1.1 of that Master Subscription Agreement.
(b) Capitalised terms not defined here have the meaning given in the Agreement.
(c) If these Terms of Service are inconsistent with another document forming the Agreement, clause 2.2 of the Agreement determines which prevails.
1.3 Who these terms bind
These Terms of Service bind the Customer and every Authorised User.
1.4 Consumer rights preserved
Nothing in these Terms of Service excludes, restricts, or modifies a right or remedy under the Australian Consumer Law or another law that cannot lawfully be excluded. See Source Register, entry S-02. Clause 11 of the Agreement applies.
2. ACCEPTANCE
2.1 How the Customer accepts
The Customer accepts these Terms of Service by:
(a) clicking a button or ticking a box that indicates acceptance;
(b) completing an online order; or
(c) accessing or using rxnet.
2.2 How an Authorised User accepts
An Authorised User accepts these Terms of Service by creating an account or by accessing rxnet.
2.3 Authority
A person who accepts these Terms of Service on behalf of an organisation warrants that they have authority to bind that organisation.
2.4 Minimum age
A person must be at least 18 years old to hold an account. The Provider may require evidence of age.
3. ACCOUNTS AND AUTHORISED USERS
3.1 Account creation
(a) The Customer must give accurate and complete information when creating an account.
(b) The Customer must keep that information current.
3.2 Administrator account
(a) The Customer must nominate at least one Authorised User as an administrator of its tenant (Administrator).
(b) An Administrator may create, modify, and remove Authorised User accounts, and may access data and configuration within the Customer's tenant.
(c) The Customer is responsible for the acts and omissions of its Administrators.
3.3 Credentials
(a) Each Authorised User must have a unique account.
(b) An Authorised User must not share credentials with any other person.
(c) The Customer must enable multi-factor authentication for all Authorised Users.
(d) The Customer must notify the Provider without delay if it suspects that credentials have been compromised. Use the channels in Schedule 2, clause 6.2.
3.4 Authorised User accounts
There is no limit on the number of Authorised User accounts the Customer may create. Each Authorised User account may be charged in accordance with clause 6 of the Agreement.
3.5 Removing access
The Customer must disable an Authorised User account within 1 Business Day after the individual ceases to require access.
3.6 Responsibility for account activity
The Customer is responsible for all activity that occurs under its account, whether or not the Customer authorised that activity, except activity that results from the Provider's breach of the Agreement.
4. ACCEPTABLE USE
4.1 Permitted use
The Customer and each Authorised User may use rxnet only:
(a) for the Customer's internal business purposes;
(b) in accordance with the Agreement, these Terms of Service, and the Documentation; and
(c) in accordance with all applicable laws.
4.2 Prohibited conduct
The Customer and each Authorised User must not:
(a) use rxnet to store, send, or process unlawful content;
(b) infringe the Intellectual Property Rights, privacy rights, or other rights of any person;
(c) send unsolicited commercial electronic messages in breach of the Spam Act 2003 (Cth). See Source Register, entry S-14;
(d) introduce a virus, worm, ransomware, or other malicious code;
(e) gain or attempt to gain unauthorised access to rxnet, to another tenant, or to any connected system;
(f) probe, scan, or test the vulnerability of rxnet without the Provider's prior written consent;
(g) circumvent or attempt to circumvent an authentication, rate limiting, quota, or security control;
(h) reverse engineer, decompile, or disassemble rxnet, except to the extent this restriction cannot be excluded by law;
(i) use an automated method to extract data at a rate or volume that is not consistent with normal use, except through a documented application programming interface and within the published limits;
(j) resell, sublicense, or make rxnet available to a third party except as expressly permitted in the Order Form;
(k) use rxnet to build or assist in building a competing product or service;
(l) remove, obscure, or alter a proprietary notice; or
(m) impersonate another person or misrepresent an affiliation.
4.3 Prohibited content
The Customer must not upload to rxnet content that:
(a) is unlawful, defamatory, or harassing;
(b) depicts or promotes child abuse material;
(c) incites violence or unlawful discrimination;
(d) breaches a court order or a suppression order; or
(e) the Customer does not have the right to upload.
4.4 Restricted data categories
(a) Unless the Order Form expressly permits it, the Customer must not upload to rxnet:
(i) payment card data within the scope of the Payment Card Industry Data Security Standard. See Source Register, entry S-15;
(ii) health information as defined in section 6FA of the Privacy Act 1988 (Cth). See Source Register, entry S-01;
(iii) information classified above OFFICIAL under the Australian Government Protective Security Policy Framework. See Source Register, entry S-16; or
(iv) tax file numbers.
(b) If the Customer requires a data category in clause 4.4(a), the parties must record the agreed handling controls as a Special Condition in the Order Form.
4.5 Resource use
(a) The Customer must stay within the quotas, rate limits, and storage limits stated in the Order Form, the Current Pricing, or the Documentation.
(b) If the Customer's use materially degrades service for other tenants, the Provider may apply rate limiting after giving the Customer notice and a reasonable opportunity to reduce its use.
(c) Where the situation presents an immediate risk to service stability, the Provider may apply rate limiting immediately and must notify the Customer as soon as practicable.
(d) Rate limiting applied under clause 4.5(b) or 4.5(c) is not a failure of the availability target in Schedule 2, clause 3, unless the cause was the Provider's breach of the Agreement.
4.6 Reporting misuse
The Customer must notify the Provider without delay if it becomes aware of a breach of this clause 4 by an Authorised User. Use info@broadstack.com.au.
5. CUSTOMER DATA
5.1 Ownership
The Customer owns Customer Data. Clause 7.2 of the Agreement applies.
5.2 Customer responsibility
The Customer is responsible for:
(a) the accuracy, quality, and legality of Customer Data;
(b) obtaining the rights necessary for the Provider to handle Customer Data as described in the Agreement; and
(c) determining whether Customer Data is suitable for rxnet.
5.3 Provider use
The Provider may use Customer Data only as permitted by clause 7.2 of the Agreement.
5.4 Backup
(a) The Provider performs backups as described in Schedule 2, clause 11.
(b) Those backups are for the Provider's service continuity purposes. They are not a substitute for the Customer's own records management.
(c) The Customer is responsible for exporting and retaining its own copies of Customer Data at intervals that suit its record keeping obligations.
5.5 Data export
The Customer may export Customer Data at any time during the Term using the export functions described in the Documentation.
5.6 Deletion by the Customer
(a) If the Customer deletes Customer Data through the service interface, the Provider will remove it from production systems.
(b) Deleted data may persist in backups until the applicable retention cycle expires. See Schedule 2, clause 11.3.
6. THIRD PARTY SERVICES
6.1 Integrations
rxnet may allow the Customer to connect third party services.
6.2 Customer responsibility
(a) The Customer's use of a third party service is governed by that third party's terms.
(b) The Provider is not a party to that relationship and is not responsible for the third party service.
(c) If the Customer authorises a third party service to access Customer Data, the Provider may transmit Customer Data to that service as directed. That transmission is at the Customer's risk.
6.3 Availability
(a) The Provider does not warrant that a third party integration will remain available.
(b) A failure of a third party service is excluded from the availability calculation in Schedule 2, clause 3.5, unless the Provider supplies that service.
6.4 Cross-border disclosure through integrations
If a third party service the Customer connects processes Customer Data outside Australia, the Customer is responsible for compliance with Australian Privacy Principle 8. See Source Register, entry S-01. The Provider's residency obligation in clause 8.4 of the Agreement does not extend to a third party service the Customer connects.
7. PRE-RELEASE AND OPTIONAL FEATURES
7.1 Beta features
(a) The Provider may offer features marked as beta, preview, trial, or early access.
(b) Those features are supplied "as is". The service levels in Schedule 2 do not apply to them.
(c) The Provider may change or withdraw a beta feature at any time.
(d) Clause 7.1(b) does not exclude a right under the Australian Consumer Law that cannot lawfully be excluded.
7.2 Free trials
(a) A free trial runs for the period stated at sign-up.
(b) The service levels in Schedule 2 do not apply during a free trial.
(c) The Provider may delete data created during a free trial 30 days after the trial ends, if the Customer does not convert to a paid subscription.
8. SUPPORT
8.1 Scope
The Provider provides support as described in Schedule 2, clause 6.
8.2 Excluded from support
Support does not cover:
(a) the Customer's own network, devices, or third party software;
(b) training beyond the material published in the Documentation, unless purchased separately;
(c) custom development or configuration, unless purchased separately; or
(d) issues caused by the Customer's use of rxnet contrary to the Documentation.
8.3 Customer co-operation
The Customer must give the Provider the information, access, and diagnostic detail the Provider reasonably requires to investigate a support request.
9. SUSPENSION AND ENFORCEMENT
9.1 Provider rights
The Provider may suspend access under clause 15 of the Agreement.
9.2 Content removal
(a) If the Provider reasonably believes content in the Customer's tenant breaches clause 4.3, the Provider may remove or disable access to that content.
(b) The Provider must notify the Customer of the removal and the reason as soon as practicable.
(c) The Provider must restore the content if the Customer demonstrates that the content does not breach clause 4.3.
9.3 Individual user suspension
The Provider may suspend an individual Authorised User account where that user has breached clause 4, without suspending the Customer's tenant. The Provider must notify an Administrator of the Customer.
9.4 Proportionality
The Provider must limit any suspension or removal to the minimum scope and duration necessary.
10. FEEDBACK
If the Customer or an Authorised User gives the Provider feedback about rxnet, clause 7.4 of the Agreement applies. Feedback must not include Confidential Information of the Customer.
11. VARIATION OF THESE TERMS
11.1 Provider right to vary
The Provider may vary these Terms of Service in accordance with clause 21.2 of the Agreement.
11.2 Notice
The Provider will give notice of a variation by:
(a) email to the Customer's nominated notice address; and
(b) a notice in rxnet or at https://broadstack.com.au/p/rxnet/l/terms.
11.3 Version history
The Provider will maintain a record of previous versions at https://broadstack.com.au/p/rxnet/l/terms-archive, showing the effective date of each version.
11.4 Customer rights on variation
Clause 21.2(c) of the Agreement applies.
12. TERM AND TERMINATION
12.1 Duration
These Terms of Service apply for the Term of the Agreement.
12.2 Termination
Termination is governed by clause 16 of the Agreement.
12.3 Effect
Clause 17 of the Agreement governs what happens to Customer Data after termination.
13. LIABILITY
Liability under these Terms of Service is governed by clauses 11 and 13 of the Agreement.
14. PRIVACY
14.1 Handling of Personal Information
The Provider handles Personal Information in accordance with clause 8 of the Agreement and the Broadstack Pty Ltd Privacy Policy at https://broadstack.com.au/p/rxnet/l/privacy.
14.2 Precedence
If the Privacy Policy is inconsistent with clause 8 of the Agreement, clause 8 of the Agreement prevails for Customer Data.
14.3 Cookies and analytics
The Provider uses cookies and analytics in the rxnet web interface as described at https://broadstack.com.au/p/rxnet/l/cookies.
15. GENERAL
15.1 Notices
Notices are governed by clause 20 of the Agreement.
15.2 Governing law
These Terms of Service are governed by the laws of New South Wales, Australia. Clause 23 of the Agreement applies.
15.3 Severability
If a provision of these Terms of Service is void, voidable, or unenforceable, it is severed and the remaining provisions continue to apply.
15.4 Survival
Clauses 5, 10, 13, 14, and 15 survive termination or expiry.
ANNEXURE A — SOURCE REGISTER
Every legal instrument and standard referenced in this document is listed below. Each entry was verified on 17 August 2026. Entries S-01 to S-13 and S-26 to S-28 are in Annexure A to the Master Subscription Agreement and are not repeated here except where cited above. Entry S-02 was re-verified on 19 August 2026 and its reference was repointed from AustLII to the Federal Register, because AustLII resists automated retrieval.
| ID | Source | Citation | Reference |
|---|---|---|---|
| S-01 | Privacy Act 1988 (Cth), including the Australian Privacy Principles (Schedule 1), APP 8 (cross-border disclosure), and section 6FA (health information) | Privacy Act 1988 (Cth) | https://www.legislation.gov.au/C2004A03712/latest |
| S-02 | Australian Consumer Law, being Schedule 2 to the Competition and Consumer Act 2010 (Cth). Re-verified 19 August 2026 | Competition and Consumer Act 2010 (Cth) sch 2 | https://www.legislation.gov.au/C2004A00109/latest |
| S-14 | Prohibition on sending unsolicited commercial electronic messages | Spam Act 2003 (Cth) | https://www.legislation.gov.au/C2004A01214/latest |
| S-15 | Payment card data security requirements | PCI Security Standards Council, Payment Card Industry Data Security Standard v4.0.1 | https://www.pcisecuritystandards.org/document_library/ |
| S-16 | Australian Government information classification scheme, including the OFFICIAL and PROTECTED classifications | Attorney-General's Department, Protective Security Policy Framework | https://www.protectivesecurity.gov.au/ |
END OF TERMS OF SERVICE