Data Processing Agreement
1. Parties + scope
This Data Processing Agreement ("DPA") is between you ("Controller") and 834770 Alberta Ltd. ("Processor"), an Alberta, Canada corporation operating as sensemakingwith.ai, and applies whenever we process personal data on your behalf in connection with the Service. It supplements our Terms of Service and Privacy Policy.
2. Subject matter, duration, nature, and purpose
- Subject matter: the personal data you upload to or generate within the Service while using collaborative-thinking frameworks.
- Duration: for the term of your subscription plus 30 days of grace deletion.
- Nature + purpose: hosting, persistence, real-time collaboration, and access control of the data you submit.
- Categories of data subjects: your team members, customers, and any individuals you choose to reference within the Service.
- Categories of personal data: identifiers (email), display names, content you submit (which may contain personal data at your discretion), and access logs.
3. Processor obligations (Art. 28(3))
- Process personal data only on documented Controller instructions.
- Ensure persons authorized to process the personal data have committed themselves to confidentiality.
- Implement appropriate technical and organizational measures (see /security).
- Engage subprocessors only with prior general written authorization (subprocessor list at /privacy; material changes announced with at least a 30-day objection window).
- Assist Controller in responding to data subject requests.
- Assist Controller in fulfilling Art. 32-36 obligations (security, breach notification, DPIA, prior consultation).
- At termination, delete or return all personal data within 90 days unless retention is required by law.
- Make available to Controller all information necessary to demonstrate compliance.
4. Subprocessors
Current subprocessors are listed on our Privacy Policy. We will notify Controller by email at least 30 days before adding or replacing a subprocessor; Controller may object in writing during that window and terminate the agreement if a reasonable resolution can't be reached.
5. International transfers
Where personal data is transferred outside the EEA / UK, the parties rely on the European Commission's Standard Contractual Clauses (SCCs, 2021/914), incorporated by reference. Module 2 (Controller→Processor) applies. Annexes I, II, III are populated below or in /security.
6. Security
We maintain the technical and organizational measures described at /security. We will not weaken these measures during the term.
7. Breach notification
We will notify Controller without undue delay (target: within 72 hours of becoming aware) of any personal data breach affecting Controller's data. Notification will include the nature of the breach, categories and approximate number of data subjects + records affected, likely consequences, and measures taken or proposed.
8. Audit rights
We will respond to reasonable, infrequent (no more than once per year unless required by regulators) audit requests from Controller, in writing, with at least 30 days' notice. We may satisfy this obligation by providing third-party audit reports (e.g., SOC 2) when available.
9. Data deletion at termination
On termination of the Service (or on Controller's written request), we will delete or return all personal data within 90 days, except where law requires retention. Backups expire on the standard 35-day cycle.
10. Liability
The liability provisions of the underlying Terms of Service apply to this DPA, except where Art. 82 GDPR mandates otherwise.
11. Contact
Privacy + DPA: privacy@sensemakingwith.ai. Security incidents: security@sensemakingwith.ai.