Data Processing Agreement
For B2B clients of Auralis Associates
Summary
- This DPA applies when Auralis Associates processes personal data on behalf of a B2B client.
- We process data only as instructed by the client for the contracted services.
- Sub-processors are FormSubmit (form delivery) and WHC Inc. (hosting).
- We notify clients of data breaches within 72 hours of discovery.
- This agreement is governed by Ontario law.
1. Definitions
In this Data Processing Agreement ("DPA"):
- "Controller" means the B2B client that determines the purposes and means of processing personal data and engages Auralis Associates to process data on its behalf.
- "Processor" means Auralis Associates Inc. ("Auralis Associates"), which processes personal data on behalf of the Controller.
- "Personal Data" means any information relating to an identified or identifiable natural person, as defined by PIPEDA and, where applicable, the GDPR.
- "Sub-Processor" means a third party engaged by the Processor to process Personal Data on behalf of the Controller.
- "Data Subject" means the individual to whom the Personal Data relates.
- "Data Breach" means any accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data.
2. Scope and Purpose
This DPA applies when Auralis Associates processes Personal Data on behalf of a B2B client in connection with the services described in the project proposal and the Terms of Service. The categories of Personal Data processed, the categories of Data Subjects, and the duration of processing are defined in the project proposal. Auralis Associates processes Personal Data solely for the purpose of performing the contracted services and does not process Personal Data for any other purpose.
3. Processor Obligations
As Processor, Auralis Associates shall:
- Process Personal Data only on documented instructions from the Controller, including with regard to transfers to third countries, unless required by applicable law
- Ensure that persons authorized to process Personal Data have committed to confidentiality or are under an appropriate statutory obligation of confidentiality
- Implement appropriate technical and organizational security measures (Section 5)
- Assist the Controller in responding to Data Subject rights requests (Section 6)
- Assist the Controller with data protection impact assessments and prior consultations with supervisory authorities, where required
- Delete or return all Personal Data at the end of the engagement, at the Controller's choice (Section 10)
- Make available to the Controller all information necessary to demonstrate compliance with this DPA
4. Sub-Processors
Auralis Associates currently uses the following sub-processors:
| Sub-Processor | Purpose | Location |
|---|---|---|
| FormSubmit | Contact form submission delivery | United States |
| WHC Inc. | Website hosting and data storage | Canada (201-1000 Chemin Lucerne, Ville Mont-Royal, QC H3R 2P8, Canada) |
The Controller authorizes Auralis Associates to engage the listed sub-processors. Auralis Associates will inform the Controller of any intended changes to the list of sub-processors, giving the Controller the opportunity to object. Auralis Associates ensures that sub-processors are bound by data protection obligations no less protective than those in this DPA.
5. Security Measures
Auralis Associates implements and maintains the following technical and organizational measures to protect Personal Data:
- Encrypted data transmission (HTTPS/TLS) for all web communications
- Access controls limiting data access to authorized personnel only
- Secure file storage with access logging
- Regular review of security practices
- Staff training on data protection and confidentiality
- Physical security measures at our office (287 Elgin St., Suite 204, Ottawa, ON K2P 1L9)
- Secure destruction of data at the end of retention periods
6. Data Subject Rights
Auralis Associates will assist the Controller in fulfilling its obligation to respond to Data Subject requests to exercise their rights under PIPEDA and, where applicable, the GDPR (access, rectification, erasure, restriction, portability, objection). Upon receiving a request from a Data Subject, Auralis Associates will promptly inform the Controller and will not respond to the Data Subject directly unless instructed to do so by the Controller.
7. Data Breach Notification
Auralis Associates will notify the Controller of any Data Breach without undue delay and in any event within 72 hours of becoming aware of the breach. The notification will include:
- A description of the nature of the breach, including, where possible, the categories and approximate number of Data Subjects and records affected
- The name and contact details of the data protection contact
- A description of the likely consequences of the breach
- A description of the measures taken or proposed to address the breach, including measures to mitigate its possible adverse effects
Auralis Associates will cooperate with the Controller and take reasonable steps to assist in the investigation, mitigation, and remediation of the breach.
8. Audit Rights
The Controller has the right to audit Auralis Associates's compliance with this DPA. Audits may be conducted by the Controller or a qualified third party appointed by the Controller, subject to reasonable confidentiality obligations. Auralis Associates will provide reasonable cooperation and access to relevant records, systems, and personnel. Audits shall be conducted during business hours with reasonable prior notice (at least 15 business days), and shall not unreasonably interfere with Auralis Associates's operations. The Controller bears the costs of the audit.
9. International Transfers
Personal Data processed under this DPA may be transferred to the United States through the FormSubmit sub-processor (Section 4). For Controllers located in the EU/EEA, Auralis Associates ensures that international transfers are conducted in compliance with GDPR Chapter V, including the use of Standard Contractual Clauses or reliance on adequacy decisions where applicable. The Controller consents to the listed international transfers by entering into this DPA.
10. Termination and Data Return
Upon termination of the engagement or at the Controller's written request, Auralis Associates will, at the Controller's choice: (a) return all Personal Data to the Controller in a commonly used, machine-readable format; or (b) securely delete all Personal Data and certify the deletion in writing. This obligation is subject to any legal requirements to retain certain data (e.g., tax records retained for 7 years). Project files are archived for 36 months from final delivery as described in the Terms of Service, unless the Controller requests earlier deletion.
11. Liability
Each party's liability under this DPA is subject to the liability limitations set forth in the Terms of Service. This DPA does not limit either party's liability for breaches of data protection law that cannot be limited under applicable law.
12. Jurisdiction and Governing Law
This DPA is governed by the laws of the Province of Ontario and the federal laws of Canada applicable therein. Any dispute arising from this DPA shall be subject to the exclusive jurisdiction of the courts located in Ottawa, Ontario, Canada. Where the Controller is located in the EU/EEA, the provisions of the GDPR apply in addition to these terms.
For questions about this Data Processing Agreement, contact us at hello@auralisassociates.com or call (613) 555-0147. See also our Privacy Policy and Terms of Service.