This DPA governs how Seideldexa Inc. processes personal data on behalf of business clients.
Processing is limited to what is necessary for delivering contracted editorial services.
Sub-processors are disclosed with their locations and roles.
Data breach notification within 72 hours of discovery.
Governed by the laws of Ontario, Canada, and PIPEDA.
1. Definitions
"Controller" means the business client who determines the purposes and means of processing personal data. "Processor" means Seideldexa Inc. (274 Spadina Avenue, Suite 301, Toronto, ON M5T 2C2, BN 725891403), which processes personal data on behalf of the Controller. "Personal data" means any information relating to an identified or identifiable natural person. "Processing" means any operation performed on personal data, including collection, storage, use, disclosure and deletion. "Sub-processor" means a third party engaged by the Processor to process personal data on behalf of the Controller.
2. Scope and purpose
This Data Processing Agreement supplements the Terms of Service between the Controller and the Processor. It applies when the Processor handles personal data provided by or collected on behalf of the Controller in the course of delivering editorial, investigative, fact-checking, production or consulting services as described in the service agreement.
The Processor shall process personal data only on documented instructions from the Controller, unless required to do so by applicable Canadian law.
3. Processing details
Nature: Storage, organization, retrieval and structured use of personal data for editorial production purposes.
Purpose: Delivery of contracted editorial services, including research, content creation, fact verification and media production.
Categories of data: Names, contact details, professional titles, organizational affiliations, interview transcripts, source materials and related metadata.
Categories of data subjects: Interview subjects, sources, contacts of the Controller, and individuals mentioned in editorial materials.
Duration: For the term of the service agreement, plus a retention period of 24 months for archived materials, unless the Controller instructs earlier deletion.
4. Obligations of the processor
Seideldexa Inc. shall:
Process personal data only in accordance with the Controller's documented instructions and the terms of this DPA.
Ensure that persons authorized to process personal data are bound by confidentiality obligations.
Implement appropriate technical and organizational security measures as described in Section 7.
Assist the Controller in responding to data subject requests as described in Section 9.
Not transfer personal data outside Canada without prior written consent from the Controller, except as required for sub-processors listed in Section 6.
Make available to the Controller all information necessary to demonstrate compliance with this DPA.
5. Obligations of the controller
The Controller shall:
Ensure that it has a lawful basis for providing personal data to the Processor.
Provide documented instructions for the processing of personal data.
Inform the Processor without undue delay of any changes to applicable privacy requirements that may affect the Processor's obligations.
6. Sub-processors
The Processor currently uses the following sub-processors:
Sub-processor
Location
Purpose
FormSubmit (formsubmit.co)
United States
Processing contact form submissions
HostPapa Inc.
115 George St, Suite 511, Oakville, ON L6J 0A2, Canada
Website hosting and infrastructure
The Processor shall inform the Controller at least 30 days in advance of any intended addition or replacement of sub-processors. The Controller may object in writing within 14 days. If the objection cannot be resolved, either party may terminate the affected service.
7. Security measures
The Processor implements the following technical and organizational measures:
Access controls limiting data access to authorized team members on a need-to-know basis.
Encrypted storage for sensitive documents and source materials.
Local infrastructure for recording and archive storage (not third-party cloud services).
Regular software updates and security patches on all workstations.
Secure deletion procedures for data that has passed its retention period.
Physical security measures at the office premises at 274 Spadina Avenue, Suite 301, Toronto.
8. Data breach notification
In the event of a personal data breach, the Processor shall notify the Controller without undue delay and in any case within 72 hours of becoming aware of the breach. The notification shall include the nature of the breach, the categories and approximate number of data subjects affected, the likely consequences, and the measures taken or proposed to address the breach.
The Processor shall cooperate with the Controller in investigating and remediating the breach and in meeting any notification obligations to the Office of the Privacy Commissioner of Canada or affected individuals.
9. Data subject requests
The Processor shall assist the Controller in fulfilling its obligations to respond to data subject requests under PIPEDA, including requests for access, correction, deletion and information about the processing of personal data. The Processor shall promptly forward any request received directly from a data subject to the Controller and shall not respond independently unless instructed to do so.
10. Audit rights
The Controller may audit the Processor's compliance with this DPA once per calendar year, upon 30 days' written notice. The audit shall be conducted during regular business hours and shall not unreasonably interfere with the Processor's operations. The Controller shall bear its own costs of the audit. The Processor may satisfy audit requests by providing relevant certifications, reports or summaries of its security practices.
11. Data return and deletion
Upon termination of the service agreement, the Processor shall, at the Controller's choice, return all personal data to the Controller or securely delete it within 30 days. The Processor may retain copies only where required by applicable Canadian law (for example, tax records retained for seven years under Canada Revenue Agency requirements). The Processor shall certify the deletion in writing upon the Controller's request.
Archived project materials are retained for 24 months from project completion, as stated in the Terms of Service, after which they are securely deleted unless the Controller requests earlier deletion or extended retention.
12. Governing law
This Data Processing Agreement is governed by the laws of the Province of Ontario and the federal laws of Canada applicable therein, including the Personal Information Protection and Electronic Documents Act (PIPEDA). Any disputes arising from this DPA shall be subject to the exclusive jurisdiction of the courts of Toronto, Ontario.
For questions about this agreement, contact the Processor's privacy contact at [email protected] or by post at the address above.
We use cookies and local storage to improve your experience. Read our cookie policy for details.