This standard-form DPA applies where CanProcX processes personal data on a business or defence customer’s behalf. It supplements, and is incorporated into, the parties’ main subscription agreement (the “Agreement”). To put it in place, complete the party details and signature blocks below; the Annexes describe the processing, our security measures, and our authorised sub-processors. To request a countersigned copy, contact privacy@canprocx.ca.
This Data Processing Agreement (“DPA”) is entered into between Canadian Procurement Exchange Inc., operating as CanProcX (the “Processor”), and the customer identified in the Agreement (the “Controller” or “Customer”). It governs the Processor’s processing of personal data on the Controller’s behalf in connection with the CanProcX Service (including the SAFE Defence tier).
1.1 Capitalised terms - “personal data”, “processing”, “controller”, “processor”, “data subject”, “supervisory authority”, and “personal data breach” - have the meanings given in the GDPR (Regulation (EU) 2016/679). “Applicable Data Protection Law” means GDPR, PIPEDA, Quebec Law 25, and any other privacy or data-protection law applicable to the processing under this DPA. “Sub-processor” means any third party engaged by the Processor to process personal data.
2.1 The Customer is the Controller (or a processor acting on behalf of its own controller) of the personal data it submits to or processes through the Service. CanProcX is the Processor, acting only on the Controller’s documented instructions.
2.2 The Controller is responsible for ensuring it has a lawful basis and any necessary consents for the personal data it provides, and that its instructions comply with Applicable Data Protection Law.
3.1 The Processor processes personal data solely to provide and support the Service - procurement-intelligence functionality enabling the Controller to identify and pursue EU public-sector contract opportunities under CETA. The nature, purpose, categories of data, and categories of data subjects are described in Annex 1.
3.2 The duration of processing is the term of the Agreement, plus any limited period required for deletion or return of data under Section 11.
4.1 The Processor shall process personal data only on the documented instructions of the Controller, including with regard to international transfers, unless required to do otherwise by law. Where so required, the Processor shall (where legally permitted) inform the Controller before processing.
4.2 The Controller’s instructions are set out in this DPA, the Agreement, and the configuration of the Service. The Processor shall promptly inform the Controller if, in its opinion, an instruction infringes Applicable Data Protection Law.
5.1 The Processor shall ensure that persons authorised to process the personal data are bound by an appropriate obligation of confidentiality and are subject to suitable access controls and need-to-know restrictions, including any heightened controls applicable to SAFE Defence engagements.
6.1 Taking into account the state of the art, costs, and the nature, scope, context, and purposes of processing, the Processor shall implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, as described in Annex 2 (consistent with GDPR Article 32). The Controller acknowledges that no measures can guarantee absolute security.
7.1 The Controller provides general authorisation for the Processor to engage the sub-processors listed in Annex 3. The Processor shall impose data-protection obligations on each sub-processor that are substantially equivalent to those in this DPA, and remains liable for its sub-processors’ performance.
7.2 The Processor shall give the Controller prior notice of any intended addition or replacement of a sub-processor (at least 30 days in advance, save where a shorter period is required to address a security or legal risk). The Controller may object on reasonable data-protection grounds; if the parties cannot resolve the objection, the Controller may terminate the affected part of the Service.
8.1 Taking into account the nature of the processing, the Processor shall assist the Controller by appropriate technical and organisational measures, insofar as possible, in responding to requests from data subjects exercising their rights (access, rectification, erasure, restriction, portability, objection) under Applicable Data Protection Law.
8.2 If the Processor receives a request directly from a data subject relating to the Controller’s data, it shall promptly notify the Controller and shall not respond except on the Controller’s instructions or as required by law.
9.1 The Processor shall notify the Controller without undue delay, and in any event within 72 hours of becoming aware of a personal data breach affecting the Controller’s personal data, providing the information reasonably available to enable the Controller to meet its own notification obligations (GDPR Articles 33–34; applicable Canadian breach-reporting rules).
9.2 The Processor shall take reasonable steps to mitigate and remediate the breach and shall cooperate with the Controller’s investigation. The Processor shall not make public statements identifying the Controller without prior approval, except as required by law.
10.1 The Processor shall make available to the Controller information reasonably necessary to demonstrate compliance with this DPA and shall allow for and contribute to audits, including inspections, conducted by the Controller or an auditor it mandates, subject to reasonable notice, confidentiality, frequency limits, and the Processor’s security policies. Where available, the Processor may satisfy this obligation by providing third-party reports or certifications.
10.2 The Processor shall also assist the Controller, where applicable, with data protection impact assessments and prior consultation with supervisory authorities (GDPR Articles 35–36).
11.1 Any transfer of personal data outside the EU/EEA shall comply with GDPR Chapter V. Where the recipient country is not subject to an adequacy decision, the parties shall rely on the European Commission’s Standard Contractual Clauses (SCCs) (Module Two, controller-to-processor) for EU transfers and the UK International Data Transfer Addendum (IDTA) for UK transfers, each incorporated by reference and completed by the parties’ details in Annex 1 and the sub-processor locations in Annex 3, together with any required supplementary measures. The parties acknowledge Canada’s partial adequacy status for commercial organisations under PIPEDA.
12.1 On termination or expiry of the Agreement, the Processor shall, at the Controller’s choice, delete or return all personal data processed on the Controller’s behalf, and delete existing copies, within 30 days, unless retention is required by law. Public procurement reference data sourced from third-party portals is excluded from this obligation.
13.1 Each party’s liability arising out of or related to this DPA is subject to the limitations and exclusions of liability set out in the Agreement. Nothing in this DPA limits liability that cannot be limited under Applicable Data Protection Law.
14.1 This DPA forms part of the Agreement. In the event of conflict regarding the processing of personal data, this DPA prevails. It is governed by the laws of the Province of Ontario and the federal laws of Canada applicable therein, without prejudice to mandatory provisions of Applicable Data Protection Law.
Provision of the CanProcX procurement-intelligence Service, including hosting account and bid-profile data, matching the Customer to EU public-procurement opportunities, and delivering related notifications and support.
Special categories of data: None intended. The Customer shall not submit special-category data unless agreed in writing with appropriate safeguards.
For the term of the Agreement plus the deletion/return period set out in Section 12.
The Processor maintains measures appropriate to the risk (GDPR Art. 32). These describe current practice and may evolve provided protection is not materially reduced.
| Control Area | Measures |
|---|---|
| Encryption | TLS/HTTPS for data in transit; passwords hashed and salted by Firebase Authentication; data at rest encrypted by Google Cloud / Firestore platform encryption. |
| Access control | Role-based access on a least-privilege, need-to-know basis; unique accounts; multi-factor authentication required for administrative access. |
| Payment data | Card data handled exclusively by Stripe (PCI-DSS Level 1) via Stripe Checkout; CanProcX does not store full card numbers. |
| Hosting & infrastructure | Application and site hosted on Netlify; reliance on the provider’s platform security and resilience controls. |
| Network & application security | Standard hardening, dependency management, and secure-development practices; edge/CDN protections via Netlify; ongoing dependency and vulnerability management. |
| Logging & monitoring | Activity and security logging to detect and investigate incidents; security logs retained for 12 months. |
| Backups & resilience | Managed, redundant storage on Google Cloud / Firestore with platform-level backup and durability; periodic restoration checks. |
| Personnel | Confidentiality obligations for all personnel; access provisioned on onboarding and revoked on offboarding; security-awareness practices maintained. |
| Incident response | Defined process for identifying, escalating, and notifying personal data breaches (Section 9). |
| SAFE Defence tier | Enhanced controls available for defence-sector customers, including additional access restrictions, data segregation, and personnel screening, as set out in the applicable order form or SAFE Defence agreement. |
These measures describe our current practice and may evolve, provided the level of protection is not materially reduced. Specific control details for an individual engagement can be provided on request under a confidentiality obligation.
The Controller authorises the following sub-processors. The Processor will notify the Controller of changes per Section 7.
| Sub-processor | Service Provided | Data Processed | Location |
|---|---|---|---|
| Google Firebase / Google Cloud | Authentication, application & bid-profile data storage (Firestore), AI agent hosting (Cloud Run) | Account, profile, usage data | USA / global |
| Anthropic (Claude) | AI bid-drafting & tender-matching inference (via Google Cloud) | Company & bid-profile inputs | USA |
| Stripe | Payment processing (Stripe Checkout, subscription billing) | Billing-confirmation data; payment-card data (held by Stripe) | USA / EU |
| Netlify | Website & application hosting and content delivery | All Service data in transit/at rest on platform | USA / global CDN |
| Google Workspace (Gmail) | Transactional & account email delivery | Contact data, email content | USA / global |
| Google Analytics | Usage analytics (only where consent given) | Pseudonymous usage / device data | USA / global |
The current, authoritative list of sub-processors is published at canprocx.ca/legal/sub-processors. Transfers outside the EU/EEA and UK rely on the EU SCCs and UK IDTA, supported by Canada’s partial adequacy status for organisations subject to PIPEDA.