All legal documents

Legal

Data Processing Addendum

Last updated: 2026-06-29

This Data Processing Addendum ("DPA") forms part of the Terms of Service (02) or other agreement (the "Agreement") between Resonix Labs (Canada) Inc. ("Resonix") and the customer ("Customer") and applies where and to the extent Resonix processes Personal Data on behalf of the Customer as a processor. It is intended to satisfy GDPR Article 28 (and UK GDPR) and to support Canadian privacy compliance.

1. Definitions

Terms such as "Personal Data", "Processing", "Controller", "Processor", "Data Subject", and "Supervisory Authority" have the meanings in the GDPR. "Data Protection Laws" means all applicable privacy laws, including GDPR/UK GDPR and Canada's PIPEDA (and Quebec Law 25 where applicable).

2. Roles & scope

2.1 As between the parties, the Customer is the Controller (or processor for its own customers) and Resonix is the Processor of the Personal Data described in Annex I.

2.2 Resonix will Process Personal Data only: (a) to provide the services under the Agreement; (b) per the Customer's documented instructions (including the Agreement); and (c) as required by law (with notice where lawful).

3. Resonix obligations

Resonix will:

  • (a) ensure persons authorized to Process are under confidentiality;
  • (b) implement appropriate technical and organizational security measures (Annex II), considering the state of the art and risk;
  • (c) respect the conditions in §4 for engaging sub-processors;
  • (d) assist the Customer, taking into account the nature of Processing, with (i) responding to Data Subject requests, and (ii) security, breach notification, data protection impact assessments, and prior consultation (Arts. 32–36);
  • (e) notify the Customer without undue delay and in any event within 72 hours after becoming aware of a Personal Data breach, with the information reasonably available to support the Customer's own notification obligations;
  • (f) at the Customer's choice, delete or return Personal Data at the end of the services and delete existing copies unless retention is legally required; and
  • (g) make available information necessary to demonstrate compliance and allow for and contribute to audits. Audit rights are satisfied by Resonix's annual third-party security report or audit summary once available; otherwise, the Customer may conduct no more than one written-questionnaire audit per 12 months at the Customer's cost, subject to reasonable confidentiality and security conditions. An on-site audit is permitted only where a confirmed material breach has occurred and is subject to Resonix's security, facility, and personnel-clearance requirements.

4. Sub-processors

4.1 The Customer provides general authorization for Resonix to engage the sub-processors listed in Annex III.

4.2 Resonix will impose data-protection obligations on each sub-processor that are no less protective than this DPA and remains liable for its sub-processors' performance.

4.3 Resonix will inform the Customer of intended changes (addition/ replacement) of sub-processors with at least 30 days' prior notice. The Customer may object on reasonable data-protection grounds within 14 days of the notice; the parties will work in good faith to resolve the objection, and if they cannot, the Customer may terminate the affected service for the un-remediated portion. Notice may be given by email to the Customer's designated contact or via a subscribed sub-processor-change list.

5. International transfers

Where Processing involves transfer of Personal Data of EU/UK Data Subjects outside the EEA/UK, the parties will rely on a valid transfer mechanism. Where Resonix acts as the Customer's processor, the EU Standard Contractual Clauses (Module 2 — Controller-to-Processor), and where a sub-processor is engaged (Module 3 — Processor-to-Processor), apply and are incorporated by reference, together with the UK International Data Transfer Addendum for UK transfers and the EU-UK Addendum as applicable. The SCC annexes are completed using Annexes I–III of this DPA (parties, processing details, and TOMs).

6. Liability

Each party's liability under this DPA is subject to the limitations of liability in the Agreement, except where Data Protection Laws provide otherwise. For clarity, third-party Data Subject claims under GDPR Article 82 are not subject to the Agreement's liability cap to the extent the cap is unenforceable against such claims under applicable law. Carve-outs here are intended to be consistent with Terms of Service (02) §9.3.

7. Quebec (Law 25)

Where the Processing involves personal information of Quebec residents, Resonix will support the Customer's compliance with Quebec's Law 25, including: (a) effecting transfers outside Quebec only with appropriate safeguards and a privacy-impact assessment of the transfer; (b) cooperating with the Customer's confidentiality-incident obligations (notification of incidents presenting a risk of serious injury); and (c) supporting requests relating to access, correction, de-indexing, and (where applicable) automated decision-making. The Customer's and Resonix's Privacy Officers are the points of contact (see Privacy Policy 01 §14).

8. Export-controlled / defense engagements

Where the Customer requires controls under ITAR, EAR, or equivalent export laws (e.g., US-persons-only access, ITAR-compliant storage/segregation, or controlled-goods handling), those controls are addressed in a separate addendum to the Agreement and govern over this DPA to the extent of any conflict. See the Export Control & Compliance Policy (09).

9. Conflict & term

This DPA prevails over conflicting terms of the Agreement regarding the Processing of Personal Data. It remains in effect for as long as Resonix Processes Customer Personal Data.


Annex I — Details of Processing

  • Subject matter / nature & purpose: provision of the services under the Agreement.
  • Duration: the term of the Agreement (plus legally required retention).
  • Categories of Data Subjects: Customer's authorized users, investors, contacts.
  • Categories of Personal Data: name, business email, company, job title, IP address, user-agent, access/audit logs. No special-category data unless expressly agreed.

Annex II — Technical & organizational measures

Access controls and tiered authorization; password hashing (bcrypt, cost factor 12 — verified in code 2026-06-29); encryption in transit (TLS) and database SSL; audit logging; rate limiting; least-privilege; secure SDLC; backup; incident response.

Annex III — Approved sub-processors

Sub-processorServiceDataLocation(s)
Vercel Inc.Website hosting, analytics, performanceRequest metadata, usage/perf, content served
Neon (PostgreSQL) on AWSManaged databaseAccount, access/audit, application data
Cloudflare, Inc. (R2)Object/document storageUploaded documents and assets
our email-delivery providerTransactional email deliveryRecipient email, message content