Data Processing Agreement
This Data Processing Agreement is issued by the Company. The Company's full identity, address, and legal contact details appear at the bottom of this page.
This Agreement governs the processing of personal information that the Customer entrusts to the Company, or that the Service processes on the Customer's behalf, in connection with the use of the Platform. It supplements the Terms of Service applicable to the Customer and applies as soon as the Customer uses the Service to process personal information relating to the Customer's own contacts or end users. It is drafted to align with Québec's Act respecting the protection of personal information in the private sector (the "Act 25") and the Personal Information Protection and Electronic Documents Act ("PIPEDA"), and remains transposable, at the level of principle, to other applicable frameworks where the Customer is established elsewhere.
Table of Contents
- Introduction
- Definitions
- Roles of the Parties
- Subject Matter, Duration, Nature, and Purpose of Processing
- Documented Instructions
- Personnel Confidentiality
- Security Measures
- Use of Subprocessors
- Assistance to the Customer
- Notification in the Event of a Privacy Incident
- Reasonable Audit Right
- International Data Transfers
- Fate of Data at the End of the Contract
- Order of Precedence
1. Introduction
> Plain language — This document sets out, in addition to the Terms of Service, how the Company processes personal information that the Customer entrusts to it through use of the Service, and what each party commits to in that regard.
This Agreement forms an integral part of the contract between the Customer and the Company for use of the Service, comprising the Terms of Service and any additional applicable contractual document (the "Principal Agreement"). It applies to any processing of personal information carried out by the Company on the Customer's behalf in connection with the provision of the Service, including where that processing is carried out, in whole or in part, through artificial intelligence features (text or voice conversational agents) built into the Platform.
2. Definitions
> Plain language — The terms below take the concepts used by Act 25 and PIPEDA and adapt them to the Platform's context; they remain understandable to a reader familiar with the GDPR.
"Personal Information": any information relating to an identified or identifiable natural person, including, where applicable, information collected or generated in the course of an interaction with a text or voice conversational agent operated through the Service.
"Controller" (or "person responsible for the protection of personal information" within the meaning of Act 25): the party that determines the purposes and means of processing personal information. For purposes of this Agreement, the Customer acts as controller with respect to the personal information of its own contacts and end users.
"Processor": the party that processes personal information on behalf of the controller, following the controller's documented instructions and within the limits of the mandate entrusted to it. For purposes of this Agreement, the Company acts as processor for the Customer, strictly in connection with the provision of the Service — to be distinguished from the use of the same term in our Privacy Policy and our Subprocessor List, where it instead designates the Company's own suppliers (see the definition of "Subprocessor" below).
"Privacy Incident": within the meaning of Act 25, any unauthorized access to, unauthorized use of, or unauthorized communication of personal information, as well as the loss of, or any other breach of the protection of, such information.
"Subprocessor": any third party engaged by the Company to process, in whole or in part, personal information on the Customer's behalf in connection with the provision of the Service.
"Service": the multi-tenant cloud platform operated by the Company, including its artificial-intelligence-based conversational agent features.
3. Roles of the Parties
> Plain language — For the personal information of its own contacts, it is the Customer who decides and who answers for those decisions; the Company carries out its instructions, as a technical service provider.
To the extent the Customer processes, through the Service, personal information relating to its own contacts or end users, the Customer acts as controller of that information. It is the Customer's responsibility to ensure it has an appropriate legal basis or consent to collect and process that information, and to comply with all of the obligations that this entails toward the individuals concerned.
The Company acts, with respect to that same information, as processor for the Customer. It processes that information only to the extent necessary to provide the Service and in accordance with the Customer's documented instructions, subject to any legal obligations that may exceptionally apply to it directly.
This allocation of roles does not extend to information that the Company collects for its own purposes, such as managing the Customer's account, billing, or the security of the Platform; with respect to that information, the Company acts as controller, in accordance with its Privacy Policy.
4. Subject Matter, Duration, Nature, and Purpose of Processing
> Plain language — The Company processes the Customer's personal information only to provide the Service, and only for as long as the contractual relationship between the parties lasts.
The subject matter of the processing entrusted to the Company is limited to the provision of the Service, including hosting, the execution of application features, the operation of text and voice conversational agent features, and the technical support necessary for those purposes.
The nature of the processing includes, depending on the configuration chosen by the Customer, the collection, recording, storage, consultation, structuring, transmission, and, where applicable, deletion of the personal information concerned.
The purpose of the processing is strictly limited to that agreed with the Customer through the Principal Agreement and this Agreement; the Company does not process the Customer's personal information for purposes of its own, other than those necessary for the operation, security, and technical improvement of the Service itself, within the limits permitted by the Principal Agreement.
The duration of the processing corresponds to the duration of the Principal Agreement between the Customer and the Company, subject to the provisions of Section 13 regarding the fate of data at the end of the contract.
5. Documented Instructions
> Plain language — The Company processes the Customer's information according to the Customer's instructions, including those given through simple configuration of the Service, not according to its own decisions.
The Company processes the Customer's personal information only on the Customer's documented instructions, except where a legal obligation requires otherwise, in which case the Company informs the Customer beforehand, to the extent the law permits it to do so.
The Customer's documented instructions include those given explicitly in writing, as well as those resulting from the configuration and settings the Customer chooses to apply to the Service, including settings relating to conversational agent features, enabled integrations, and applicable retention periods.
If the Company considers that an instruction from the Customer contravenes an applicable provision on the protection of personal information, it notifies the Customer without undue delay, as soon as reasonably practicable, without being required to carry out the instruction in question until the matter is clarified.
6. Personnel Confidentiality
> Plain language — Everyone within the Company who has access to the Customer's information is formally bound to keep it confidential.
The Company ensures that members of its personnel authorized to access personal information processed on the Customer's behalf are bound by a confidentiality commitment, whether contractual or of statutory origin, covering that information, and that they receive appropriate training on the proper processing of personal information in the course of their duties.
Access to personal information within the Company is limited to individuals whose duties require it, following the principle of least privilege, and relies on the role-based access control described in Section 7.
7. Security Measures
> Plain language — The Company applies concrete technical and organizational security measures to protect the Customer's information; the full detail is published separately.
The Company implements technical and organizational security measures appropriate to the risks presented by the processing, including: isolation of data by customer organization at the database level, through row-level security consistently applied; encryption of personal information in transit and at rest; role-based access control; and timestamped audit logging of access and relevant operations.
A detailed description of these measures is set out in the separate document entitled "Security Overview," which the Company keeps up to date and makes available to the Customer. The Company does not claim, in this Agreement or elsewhere, any third-party security or compliance certification with respect to the Service, except where expressly and documentedly stated in the Security Overview itself.
The Company reserves the right to evolve these measures over time, provided that such changes do not have the effect of lowering the overall level of protection of the Customer's personal information.
8. Use of Subprocessors
> Plain language — The Company relies on other specialized providers (hosting, payment, AI models, voice, and so on) to operate the Service; they are listed and kept current in a separate document, and the Customer is notified of any material change.
The Customer generally authorizes the Company to engage subprocessors for the performance of all or part of the processing necessary to provide the Service, in the following categories: database, authentication, and storage infrastructure; application hosting; payment processing; artificial intelligence model providers for text and voice processing; text-to-speech synthesis; video avatar generation; third-party messaging gateways, where the Customer itself chooses to connect an external messaging account; asynchronous processing orchestration; and mapping services. This general authorization is limited to these categories; use of a subprocessor category not listed here requires the notification procedure described below.
The current list of subprocessors actually used, identified by service category, is maintained in the separate document entitled "Subprocessor List," which the Company updates and makes available to the Customer.
The Company contractually imposes on each subprocessor data protection obligations substantially equivalent to those it bears under this Agreement, to the extent applicable to the nature of the service provided by that subprocessor.
In the event of the addition or replacement of a subprocessor resulting in a material change to the "Subprocessor List," the Company notifies the Customer by a reasonable means, in particular by updating the aforementioned document accompanied by an appropriate notice. The Customer has a reasonable right to object to a new subprocessor, which it may exercise by communicating its concerns to the Company within a reasonable time following the notice; the parties then collaborate in good faith to find an appropriate solution. If the parties fail to reach a satisfactory solution despite this good-faith collaboration, the Customer may terminate the Principal Agreement, without penalty, upon reasonable notice limited to the portion of the Service affected by the subprocessor in question.
9. Assistance to the Customer
> Plain language — The Company provides the Customer with concrete tools to respond to requests from its own users (access, deletion, correction), and supports it as needed in its privacy risk assessments.
The Company makes available to the Customer an integrated system for creating, tracking, and handling export, deletion, and rectification requests made by the Customer's end users, including status tracking for each request and retention of a processing history. This tool is the concrete means by which the Company assists the Customer in exercising its obligations toward the individuals concerned, without relieving the Customer of its own obligation, as controller, to respond to such requests itself within the applicable time limits.
To the extent the information required is reasonably available to the Company and relevant for this purpose, the Company also provides the Customer with reasonable assistance in carrying out privacy impact assessments, or any equivalent impact analysis, where such assessments are required by the law applicable to the Customer in connection with its use of the Service.
10. Notification in the Event of a Privacy Incident
> Plain language — If an incident affects information the Company processes for the Customer, the Company notifies the Customer without undue delay, as required by Act 25.
In the event of a privacy incident affecting personal information processed by the Company on the Customer's behalf, the Company notifies the Customer without undue delay, as soon as reasonably practicable after becoming aware of it, in accordance with the obligations applicable under Act 25 and, where applicable, PIPEDA.
This notice includes, to the extent such information is then available or subsequently becomes available, a description of the nature of the incident, the categories of personal information concerned, the measures taken or contemplated by the Company to mitigate the consequences of the incident, and, where applicable, measures the Customer may wish to consider on its own part. The Company collaborates in good faith with the Customer to provide it with additional information reasonably necessary to assess the incident and, where applicable, to fulfill its own notification obligations toward the individuals concerned or the competent authorities.
11. Reasonable Audit Right
> Plain language — The Customer may request information demonstrating that the Company honors its commitments, within reasonable limits as to frequency and the confidentiality of the information exchanged.
The Customer may request from the Company reasonable information demonstrating the Company's compliance with its obligations under this Agreement, including by providing relevant documentation on the security measures in place, within the limits of what can be disclosed without compromising the security of the Service or the confidentiality owed to other customers of the Platform.
This right is exercised at a reasonable frequency, upon written notice to the Company, and in a manner that limits disruption to the Company's normal operations. Information thus communicated to the Customer remains confidential and may only be used for the Customer's own assessment of compliance with this Agreement.
12. International Data Transfers
> Plain language — Information may be processed by subprocessors located outside Québec; the details on this subject appear in a separate document.
The processing of the Customer's personal information by the Company, or by its subprocessors, may involve a transfer of that information outside Québec. The principles and details applicable to such transfers, including the safeguards put in place in accordance with the requirements of Act 25 regarding privacy impact assessments for a transfer outside Québec, are detailed in the separate document entitled "Data Residency & Transfers," which the Company keeps up to date and makes available to the Customer.
13. Fate of Data at the End of the Contract
> Plain language — At the end of the contract, the Customer's information is deleted or returned according to the agreed terms; the precise time limits are detailed in the Data Retention Policy.
At the end of the Principal Agreement, regardless of the cause, the Company proceeds, in accordance with the terms agreed with the Customer or, absent a specific agreement, in accordance with its standard practices, to delete or return the personal information processed on the Customer's behalf, subject to any legal retention obligations that may apply to certain categories of information.
The retention periods applicable by data category, as well as the automated purge procedures applicable to certain technical categories, are detailed in the separate document entitled "Data Retention Policy," which the Company keeps up to date and makes available to the Customer.
14. Order of Precedence
> Plain language — In the event of a conflict with the Terms of Service on a matter of personal information protection, this document prevails.
In the event of a conflict or inconsistency between the provisions of this Agreement and those of the Terms of Service, or of any other contractual document binding the parties, specifically concerning the protection of personal information, the provisions of this Agreement prevail. For any matter not addressed by this Agreement, the Terms of Service and other applicable documents continue to apply.