Public contract terms
Data Processing Addendum
Version 1.0 · Effective July 10, 2026
1. Roles and scope
Customer determines why and how its project, evidence, employee, and expenditure data is placed in the Service and is the accountable organization or controller for that data. Provider acts as Customer's service provider or processor for that Personal Information, except where Provider processes limited account, billing, security, and legal-compliance data for its own legitimate business purposes as described in the Privacy Policy.
Each party will comply with privacy laws applicable to its role. This DPA does not certify compliance with PIPEDA or any other law, and Customer remains responsible for determining whether the Service is suitable for its industry, contracts, workforce, and data-classification rules.
2. Customer instructions and responsibilities
Provider will process Customer Personal Information only to provide, secure, support, and maintain the Service; follow Customer's feature selections and support requests; comply with documented instructions in the agreement; or meet legal obligations. If Provider believes an instruction violates applicable law, it may pause the affected processing and notify Customer unless prohibited by law.
Customer is responsible for:
- having authority and an appropriate legal basis to collect and disclose the data;
- providing employee, contractor, and other required privacy notices;
- limiting integrations, users, and evidence to what is necessary;
- reviewing role assignments and removing access promptly;
- not submitting passwords, private keys, authentication tokens, payment-card data, personal health information, or regulated data that requires controls not covered by a signed agreement; and
- maintaining authoritative source records and statutory archives outside the Service.
3. Confidentiality
Provider will limit access to Customer Personal Information to persons who need it to provide or secure the Service and who are subject to confidentiality obligations. Provider will not sell Customer Personal Information or use Customer content to train Provider-owned AI models. Customer content remains Customer's content.
4. Security measures
Provider will maintain the following current technical and organizational measures:
- TLS for data in transit and managed-platform disk encryption for data at rest;
- bcrypt password hashing and secure, HTTP-only authentication cookies in production;
- optional authenticator-app MFA with password-confirmed enrollment, encrypted setup secrets, one-time backup codes, login challenge, and audited lifecycle events;
- organization-scoped data access and owner, accountant, and member roles;
- application-level authenticated encryption for stored OAuth access and refresh tokens and for claim filing workspaces, with workspace ciphertext bound to its organization and project;
- rate limiting on authentication, general API, webhook, and narrative-generation routes;
- audit records for selected actions such as evidence changes, narrative generation and review, organization changes, and exports; and
- owner controls to disable external AI, require customer-supplied provider keys, restrict permitted AI providers, inspect a data inventory, export organization data, and choose imported-evidence disposition during disconnect; and
- reasonable vulnerability remediation, access restriction, and incident-response practices appropriate to the Service's current stage.
These measures do not include field-level encryption for all evidence, narratives, or expenditure fields; independent certification; or guaranteed Canadian residency. The current and planned posture is described in Security & Data Handling.
5. Security incidents
Provider will notify Customer without unreasonable delay after validating that unauthorized access to or disclosure, alteration, or loss of Customer Personal Information may have occurred. Provider's current target is an initial notice within 72 hours of that validation, unless applicable law or a signed agreement requires sooner. Notice will be based on information reasonably available at the time and may be supplemented or corrected.
Provider will take reasonable containment and remediation steps and provide information reasonably needed for Customer's own notification assessment. This clause does not create a default 24/7 forensic-services obligation.
6. Subprocessors
Customer gives general authorization for the providers in the current Subprocessor Register. Provider will require subprocessors to protect the data in a manner appropriate to their service and remains responsible for its obligations under this DPA to the extent required by applicable law.
Provider will update the register for material changes. A Customer with a reasonable data-protection objection may contact Provider before using the new provider. The parties will attempt a reasonable alternative; if none is available, Customer may stop the affected feature or terminate future use and request export and deletion under Section 9.
7. Cross-border processing
Customer acknowledges that core production hosting is currently in the United States on Render, and Personal Information may also be processed in Canada, the United States, or other locations used by a disclosed feature provider. Provider does not offer Canada-only data residency under the self-service Service. Customer must not use the Service if its requirements prohibit the disclosed transfers unless the parties first sign a suitable written arrangement.
8. Assistance and privacy requests
Taking into account the nature of the processing, Provider will provide reasonable assistance with Customer requests to access, correct, export, restrict, or delete Personal Information and with legally required privacy-impact or breach assessments. Customer should first use available product controls and then contact privacy@sredcopilot.ca. Extensive or customer-specific work may require a separate written scope where permitted by law.
9. Return, export, retention, and deletion
During active use, Customer can export project binders and generated documents using available product features. Customer should export regularly and before cancellation. On a verified request, Provider will take reasonable steps to delete Customer Personal Information from primary systems unless retention is required by law, necessary to resolve a dispute, or otherwise permitted by the agreement.
Backup copies are removed through provider rotation rather than immediate record-by-record deletion and remain protected while retained. During integration disconnect, an owner can retain imported evidence or permanently purge matching provider evidence and its citation links after reviewing impact counts. New workspaces use an 84-month advisory planning window; the setting flags older evidence and does not silently delete it. Customer remains responsible for its own archive.
10. Information and audit cooperation
On reasonable written request no more than once in a 12-month period, Provider will complete a reasonable security or privacy questionnaire and provide available non-confidential information needed to demonstrate compliance with this DPA. Provider does not currently have a SOC 2 or independent penetration-test report to provide. On-site audits, source-code access, audits of other customers' environments, and third-party testing require a separate written agreement and safeguards for security, confidentiality, cost, and operational impact.
11. Government and legal requests
Provider will disclose Customer Personal Information in response to a binding legal demand only to the extent required. Unless legally prohibited, Provider will notify Customer before disclosure so Customer can seek protection and will direct the requesting authority to Customer when reasonable.
12. Business transfers
If Provider proposes a transaction that would transfer control of Customer Personal Information, Provider will give notice as described in the Privacy Policy where legally and commercially practicable. Before the effective transfer, Customer may export available data, stop submitting new data, and request deletion. A successor must assume the applicable agreement or another lawful basis must apply before continuing the covered processing.
13. Term and conflicts
This DPA lasts while Provider processes Customer Personal Information under the Terms. If this DPA conflicts with the Terms on processing Personal Information, this DPA controls. Liability is governed by the Terms unless the parties sign a different allocation. Nothing limits rights or obligations that cannot lawfully be limited.
Schedule A — Processing details
- Subject matter and purpose
- Evidence collection, organization, claim-preparation workflows, AI-assisted drafting, expenditure tracking, collaboration, exports, support, and service security.
- Duration
- The account term plus the limited retention and deletion period described above.
- People
- Customer users, employees, contractors, project contributors, message authors, support contacts, and other people represented in customer-directed records.
- Data
- Names, business email addresses, roles, timestamps, project and experimental-work descriptions, commit/ticket/message metadata and selected text, expenditure and personnel records, assessment responses, narratives, citations, logs, and support communications.
- Operations
- Collection, transmission, storage, organization, retrieval, analysis, generation, display, export, support access, restriction, and deletion.
Customer-specific terms
Send your legal entity name, authorized contact, required privacy schedule, and any residency, notification, audit, or deletion requirements to legal@sredcopilot.ca. Do not upload restricted data while material terms remain unresolved.
Provider: Andrew Marc, carrying on business as SR&ED Copilot. See the Trust Centre.