Skip to content

rxnet

Terms of Service

Document
Broadstack Pty Ltd-TOS-1
Version
202609
Effective from
2026-09-14
Cited by
D2, and D1 clause 2.2

Schedule 1 to the Master Subscription Agreement

rxnet — Software as a Service


1. ABOUT THESE TERMS

1.1 Purpose

These Terms of Service set the rules for day to day use of rxnet. They cover accounts, acceptable use, content, and the practical operation of the service.

1.2 Relationship to other documents

(a) These Terms of Service are Schedule 1 to the Master Subscription Agreement between Broadstack Pty Ltd (Provider) and the Customer (Customer). Agreement has the meaning given in clause 1.1 of that Master Subscription Agreement.

(b) Capitalised terms not defined here have the meaning given in the Agreement.

(c) If these Terms of Service are inconsistent with another document forming the Agreement, clause 2.2 of the Agreement determines which prevails.

1.3 Who these terms bind

These Terms of Service bind the Customer and every Authorised User.

1.4 Consumer rights preserved

Nothing in these Terms of Service excludes, restricts, or modifies a right or remedy under the Australian Consumer Law or another law that cannot lawfully be excluded. See Source Register, entry S-02. Clause 11 of the Agreement applies.


2. ACCEPTANCE

2.1 How the Customer accepts

The Customer accepts these Terms of Service by:

(a) clicking a button or ticking a box that indicates acceptance;

(b) completing an online order; or

(c) accessing or using rxnet.

2.2 How an Authorised User accepts

An Authorised User accepts these Terms of Service by creating an account or by accessing rxnet.

2.3 Authority

A person who accepts these Terms of Service on behalf of an organisation warrants that they have authority to bind that organisation.

2.4 Minimum age

A person must be at least 18 years old to hold an account. The Provider may require evidence of age.


3. ACCOUNTS AND AUTHORISED USERS

3.1 Account creation

(a) The Customer must give accurate and complete information when creating an account.

(b) The Customer must keep that information current.

3.2 Administrator account

(a) The Customer must nominate at least one Authorised User as an administrator of its tenant (Administrator).

(b) An Administrator may create, modify, and remove Authorised User accounts, and may access data and configuration within the Customer's tenant.

(c) The Customer is responsible for the acts and omissions of its Administrators.

3.3 Credentials

(a) Each Authorised User must have a unique account.

(b) An Authorised User must not share credentials with any other person.

(c) The Customer must enable multi-factor authentication for all Authorised Users.

(d) The Customer must notify the Provider without delay if it suspects that credentials have been compromised. Use the channels in Schedule 2, clause 6.2.

3.4 Authorised User accounts

There is no limit on the number of Authorised User accounts the Customer may create. Each Authorised User account may be charged in accordance with clause 6 of the Agreement.

3.5 Removing access

The Customer must disable an Authorised User account within 1 Business Day after the individual ceases to require access.

3.6 Responsibility for account activity

The Customer is responsible for all activity that occurs under its account, whether or not the Customer authorised that activity, except activity that results from the Provider's breach of the Agreement.


4. ACCEPTABLE USE

4.1 Permitted use

The Customer and each Authorised User may use rxnet only:

(a) for the Customer's internal business purposes;

(b) in accordance with the Agreement, these Terms of Service, and the Documentation; and

(c) in accordance with all applicable laws.

4.2 Prohibited conduct

The Customer and each Authorised User must not:

(a) use rxnet to store, send, or process unlawful content;

(b) infringe the Intellectual Property Rights, privacy rights, or other rights of any person;

(c) send unsolicited commercial electronic messages in breach of the Spam Act 2003 (Cth). See Source Register, entry S-14;

(d) introduce a virus, worm, ransomware, or other malicious code;

(e) gain or attempt to gain unauthorised access to rxnet, to another tenant, or to any connected system;

(f) probe, scan, or test the vulnerability of rxnet without the Provider's prior written consent;

(g) circumvent or attempt to circumvent an authentication, rate limiting, quota, or security control;

(h) reverse engineer, decompile, or disassemble rxnet, except to the extent this restriction cannot be excluded by law;

(i) use an automated method to extract data at a rate or volume that is not consistent with normal use, except through a documented application programming interface and within the published limits;

(j) resell, sublicense, or make rxnet available to a third party except as expressly permitted in the Order Form;

(k) use rxnet to build or assist in building a competing product or service;

(l) remove, obscure, or alter a proprietary notice; or

(m) impersonate another person or misrepresent an affiliation.

4.3 Prohibited content

The Customer must not upload to rxnet content that:

(a) is unlawful, defamatory, or harassing;

(b) depicts or promotes child abuse material;

(c) incites violence or unlawful discrimination;

(d) breaches a court order or a suppression order; or

(e) the Customer does not have the right to upload.

4.4 Restricted data categories

(a) Unless the Order Form expressly permits it, the Customer must not upload to rxnet:

(i) payment card data within the scope of the Payment Card Industry Data Security Standard. See Source Register, entry S-15;

(ii) health information as defined in section 6FA of the Privacy Act 1988 (Cth). See Source Register, entry S-01;

(iii) information classified above OFFICIAL under the Australian Government Protective Security Policy Framework. See Source Register, entry S-16; or

(iv) tax file numbers.

(b) If the Customer requires a data category in clause 4.4(a), the parties must record the agreed handling controls as a Special Condition in the Order Form.

4.5 Resource use

(a) The Customer must stay within the quotas, rate limits, and storage limits stated in the Order Form, the Current Pricing, or the Documentation.

(b) If the Customer's use materially degrades service for other tenants, the Provider may apply rate limiting after giving the Customer notice and a reasonable opportunity to reduce its use.

(c) Where the situation presents an immediate risk to service stability, the Provider may apply rate limiting immediately and must notify the Customer as soon as practicable.

(d) Rate limiting applied under clause 4.5(b) or 4.5(c) is not a failure of the availability target in Schedule 2, clause 3, unless the cause was the Provider's breach of the Agreement.

4.6 Reporting misuse

The Customer must notify the Provider without delay if it becomes aware of a breach of this clause 4 by an Authorised User. Use info@broadstack.com.au.


5. CUSTOMER DATA

5.1 Ownership

The Customer owns Customer Data. Clause 7.2 of the Agreement applies.

5.2 Customer responsibility

The Customer is responsible for:

(a) the accuracy, quality, and legality of Customer Data;

(b) obtaining the rights necessary for the Provider to handle Customer Data as described in the Agreement; and

(c) determining whether Customer Data is suitable for rxnet.

5.3 Provider use

The Provider may use Customer Data only as permitted by clause 7.2 of the Agreement.

5.4 Backup

(a) The Provider performs backups as described in Schedule 2, clause 11.

(b) Those backups are for the Provider's service continuity purposes. They are not a substitute for the Customer's own records management.

(c) The Customer is responsible for exporting and retaining its own copies of Customer Data at intervals that suit its record keeping obligations.

5.5 Data export

The Customer may export Customer Data at any time during the Term using the export functions described in the Documentation.

5.6 Deletion by the Customer

(a) If the Customer deletes Customer Data through the service interface, the Provider will remove it from production systems.

(b) Deleted data may persist in backups until the applicable retention cycle expires. See Schedule 2, clause 11.3.


6. THIRD PARTY SERVICES

6.1 Integrations

rxnet may allow the Customer to connect third party services.

6.2 Customer responsibility

(a) The Customer's use of a third party service is governed by that third party's terms.

(b) The Provider is not a party to that relationship and is not responsible for the third party service.

(c) If the Customer authorises a third party service to access Customer Data, the Provider may transmit Customer Data to that service as directed. That transmission is at the Customer's risk.

6.3 Availability

(a) The Provider does not warrant that a third party integration will remain available.

(b) A failure of a third party service is excluded from the availability calculation in Schedule 2, clause 3.5, unless the Provider supplies that service.

6.4 Cross-border disclosure through integrations

If a third party service the Customer connects processes Customer Data outside Australia, the Customer is responsible for compliance with Australian Privacy Principle 8. See Source Register, entry S-01. The Provider's residency obligation in clause 8.4 of the Agreement does not extend to a third party service the Customer connects.


7. PRE-RELEASE AND OPTIONAL FEATURES

7.1 Beta features

(a) The Provider may offer features marked as beta, preview, trial, or early access.

(b) Those features are supplied "as is". The service levels in Schedule 2 do not apply to them.

(c) The Provider may change or withdraw a beta feature at any time.

(d) Clause 7.1(b) does not exclude a right under the Australian Consumer Law that cannot lawfully be excluded.

7.2 Free trials

(a) A free trial runs for the period stated at sign-up.

(b) The service levels in Schedule 2 do not apply during a free trial.

(c) The Provider may delete data created during a free trial 30 days after the trial ends, if the Customer does not convert to a paid subscription.


8. SUPPORT

8.1 Scope

The Provider provides support as described in Schedule 2, clause 6.

8.2 Excluded from support

Support does not cover:

(a) the Customer's own network, devices, or third party software;

(b) training beyond the material published in the Documentation, unless purchased separately;

(c) custom development or configuration, unless purchased separately; or

(d) issues caused by the Customer's use of rxnet contrary to the Documentation.

8.3 Customer co-operation

The Customer must give the Provider the information, access, and diagnostic detail the Provider reasonably requires to investigate a support request.


9. SUSPENSION AND ENFORCEMENT

9.1 Provider rights

The Provider may suspend access under clause 15 of the Agreement.

9.2 Content removal

(a) If the Provider reasonably believes content in the Customer's tenant breaches clause 4.3, the Provider may remove or disable access to that content.

(b) The Provider must notify the Customer of the removal and the reason as soon as practicable.

(c) The Provider must restore the content if the Customer demonstrates that the content does not breach clause 4.3.

9.3 Individual user suspension

The Provider may suspend an individual Authorised User account where that user has breached clause 4, without suspending the Customer's tenant. The Provider must notify an Administrator of the Customer.

9.4 Proportionality

The Provider must limit any suspension or removal to the minimum scope and duration necessary.


10. FEEDBACK

If the Customer or an Authorised User gives the Provider feedback about rxnet, clause 7.4 of the Agreement applies. Feedback must not include Confidential Information of the Customer.


11. VARIATION OF THESE TERMS

11.1 Provider right to vary

The Provider may vary these Terms of Service in accordance with clause 21.2 of the Agreement.

11.2 Notice

The Provider will give notice of a variation by:

(a) email to the Customer's nominated notice address; and

(b) a notice in rxnet or at https://broadstack.com.au/p/rxnet/l/terms.

11.3 Version history

The Provider will maintain a record of previous versions at https://broadstack.com.au/p/rxnet/l/terms-archive, showing the effective date of each version.

11.4 Customer rights on variation

Clause 21.2(c) of the Agreement applies.


12. TERM AND TERMINATION

12.1 Duration

These Terms of Service apply for the Term of the Agreement.

12.2 Termination

Termination is governed by clause 16 of the Agreement.

12.3 Effect

Clause 17 of the Agreement governs what happens to Customer Data after termination.


13. LIABILITY

Liability under these Terms of Service is governed by clauses 11 and 13 of the Agreement.


14. PRIVACY

14.1 Handling of Personal Information

The Provider handles Personal Information in accordance with clause 8 of the Agreement and the Broadstack Pty Ltd Privacy Policy at https://broadstack.com.au/p/rxnet/l/privacy.

14.2 Precedence

If the Privacy Policy is inconsistent with clause 8 of the Agreement, clause 8 of the Agreement prevails for Customer Data.

14.3 Cookies and analytics

The Provider uses cookies and analytics in the rxnet web interface as described at https://broadstack.com.au/p/rxnet/l/cookies.


15. GENERAL

15.1 Notices

Notices are governed by clause 20 of the Agreement.

15.2 Governing law

These Terms of Service are governed by the laws of New South Wales, Australia. Clause 23 of the Agreement applies.

15.3 Severability

If a provision of these Terms of Service is void, voidable, or unenforceable, it is severed and the remaining provisions continue to apply.

15.4 Survival

Clauses 5, 10, 13, 14, and 15 survive termination or expiry.


ANNEXURE A — SOURCE REGISTER

Every legal instrument and standard referenced in this document is listed below. Each entry was verified on 17 August 2026. Entries S-01 to S-13 and S-26 to S-28 are in Annexure A to the Master Subscription Agreement and are not repeated here except where cited above. Entry S-02 was re-verified on 19 August 2026 and its reference was repointed from AustLII to the Federal Register, because AustLII resists automated retrieval.

ID Source Citation Reference
S-01 Privacy Act 1988 (Cth), including the Australian Privacy Principles (Schedule 1), APP 8 (cross-border disclosure), and section 6FA (health information) Privacy Act 1988 (Cth) https://www.legislation.gov.au/C2004A03712/latest
S-02 Australian Consumer Law, being Schedule 2 to the Competition and Consumer Act 2010 (Cth). Re-verified 19 August 2026 Competition and Consumer Act 2010 (Cth) sch 2 https://www.legislation.gov.au/C2004A00109/latest
S-14 Prohibition on sending unsolicited commercial electronic messages Spam Act 2003 (Cth) https://www.legislation.gov.au/C2004A01214/latest
S-15 Payment card data security requirements PCI Security Standards Council, Payment Card Industry Data Security Standard v4.0.1 https://www.pcisecuritystandards.org/document_library/
S-16 Australian Government information classification scheme, including the OFFICIAL and PROTECTED classifications Attorney-General's Department, Protective Security Policy Framework https://www.protectivesecurity.gov.au/

END OF TERMS OF SERVICE