1. Purpose
This Data Processing Agreement ("DPA") supplements the Terms of Service and governs the processing of personal data by ADGTech Solutions Inc. ("ADGTech") on behalf of customers ("Controller") in the delivery of Platform services.
This DPA is designed to support compliance with PIPEDA, GDPR (where applicable), and can be extended by enterprise contract addenda for HIPAA, PHIPA, FERPA, or sector-specific frameworks.
2. Roles of the Parties
Customer as Data Controller
The Customer (the organization subscribing to ADGTech services) is the data controller — the party that determines the purposes and means of processing personal data.
ADGTech as Data Processor / Service Provider
ADGTech acts as a data processor (or service provider under CCPA) when processing personal data on behalf of the Customer to deliver contracted Platform services. ADGTech does not determine the purposes of processing — it follows Customer instructions.
3. Processing Instructions
ADGTech processes personal data only on documented instructions from the Customer (as expressed through Platform configuration, subscription contract, and applicable addenda). ADGTech will inform the Customer if it believes an instruction violates applicable privacy law.
4. Confidentiality
ADGTech personnel authorized to process Customer personal data are bound by confidentiality obligations. Personal data is not disclosed to third parties except as required to deliver the Platform services or as required by law.
5. Security Measures
ADGTech implements technical and organizational measures appropriate to the risk, including: encryption in transit and at rest; access controls and role-based permissions; audit logging; vulnerability management; and incident response procedures. See the Security Center for detail.
6. Subprocessors
ADGTech engages subprocessors to assist in delivering Platform services. All subprocessors are bound by data protection obligations at least as protective as this DPA. A current list of subprocessors is available at the Subprocessors page. ADGTech will provide notice of material subprocessor changes to enterprise customers.
7. Data Subject Requests
ADGTech will assist Customers in responding to data subject requests (access, correction, deletion, portability, restriction) as technically feasible within the Platform. Customers remain responsible for responding to data subjects directly.
8. Breach Notification
In the event of a confirmed personal data breach, ADGTech will notify the affected Customer within 72 hours of discovery. Notification will include: nature of the breach; categories and approximate number of individuals affected; likely consequences; and measures taken or proposed to address the breach.
9. Data Retention and Deletion
Upon termination of the subscription or written request, ADGTech will return or delete Customer personal data within 90 days unless legal holds require longer retention. Data export should be completed by the Customer prior to account cancellation.
10. International Transfers
Some subprocessors may process data outside of Canada. ADGTech ensures appropriate contractual protections (such as Standard Contractual Clauses where applicable) are in place for cross-border transfers. Enterprise customers can discuss specific data residency requirements in their contract.
11. Audit Support
ADGTech will provide reasonable support to enterprise customers conducting compliance audits or regulatory inquiries, including responses to security questionnaires and provision of available compliance documentation.
12. Contact
To request a signed DPA for enterprise procurement: legal@adgtech.ai
For HIPAA BAA requests: enterprise@adgtech.ai