Valdra — Canuckt Synergy Solutions Inc. Version 1.0 · Effective 28 July 2026
This Data Processing Agreement ("DPA") forms part of the Valdra Terms of Service between Canuckt Synergy Solutions Inc. ("Valdra", "we", "us") and the customer organisation named in the Valdra Order Form, or if there is none, the organisation that holds the Valdra subscription ("Customer", "you").
It sets out how we handle personal information you put into Valdra. We have written it to be read, not just signed. If anything here is unclear, ask us and we will explain it in plain terms.
You are the controller of the personal information you place in Valdra. Where the Personal Health Information Protection Act, 2004 (Ontario) ("PHIPA") applies, you are the health information custodian.
We are your processor (and, under PHIPA, act as your agent or service provider). We process personal information only on your documented instructions, and we do not determine the purposes for which it is processed.
Using the Valdra service is itself an instruction to process your data as needed to provide it.
| Subject matter | Provision of the Valdra compliance and AI-governance platform |
| Duration | For the term of your subscription, plus the retention period in §9 |
| Nature and purpose | Hosting, storing, analysing and displaying your compliance records; generating assessments, policies, assessments and reports at your request |
| Types of personal information | Names, business contact details and roles of your personnel; records you create about data subjects (for example privacy requests and breach records); any personal information you choose to enter into free-text fields |
| Categories of data subjects | Your personnel; individuals who make privacy requests to you; individuals referenced in your compliance records |
What Valdra is not designed for. Valdra is a governance and compliance platform. It is not a clinical system and should not be used as a repository for patient records or bulk personal health information. You control what you enter; we ask that you enter the minimum necessary. Where you record a privacy request or a breach involving health information, reference the individual rather than reproducing their clinical record.
We will:
We maintain the safeguards described in Annex A. We may update them, but we will not materially reduce the overall level of protection during your subscription.
You give us general authorisation to engage sub-processors. Our current sub-processors, their function and their location are listed in our Sub-processor List, provided with this DPA and kept current.
Before adding or replacing a sub-processor we will give you at least 30 days' notice by email to your account administrator. If you have a reasonable, good-faith objection on data protection grounds, tell us within those 30 days and we will work with you to find an alternative. If we cannot, you may terminate the affected part of the service and receive a pro-rata refund of prepaid fees for the terminated portion.
This refund is a deliberate exception to the non-refund provision in the Terms of Service. It applies only where a sub-processor objection cannot be resolved, and not to cancellation generally.
We remain responsible to you for our sub-processors' performance.
If an individual contacts us directly about data held in your account, we will not respond on your behalf. We will forward it to your account administrator promptly.
Valdra provides self-service tools to search, export and delete records. Where those tools are not sufficient, we will assist you at no additional charge for reasonable volumes.
If we become aware of a breach of security leading to accidental or unlawful destruction, loss, alteration, or unauthorised disclosure of or access to your personal information, we will:
We will not make a public statement identifying you without your consent, unless required by law.
Our named contact for security matters is [email protected].
Your data is stored and processed in Canada. Production infrastructure is located in Beauharnois, Québec. Backups are held on separate Canadian infrastructure.
Certain sub-processors listed in the Sub-processor List operate outside Canada. Where that is the case, it is identified in the list along with the safeguards in place. We will not move primary storage of your data outside Canada without giving you at least 30 days' notice and the right to terminate.
While your subscription is active, you may export your data at any time using the in-product export tools.
On termination:
We will confirm deletion in writing on request.
We will respond to reasonable security and privacy questionnaires once per twelve-month period at no charge.
You may audit our compliance with this DPA on 30 days' written notice, no more than once per twelve-month period (unless a breach has occurred, or a regulator requires it), during business hours, without unreasonably disrupting our operations, and subject to confidentiality. Where an independent audit report covering the relevant controls is available, providing it satisfies this obligation.
Where you are a health information custodian under PHIPA and personal health information is placed in Valdra, the following apply in addition:
Each party's liability under this DPA is subject to the limitations of liability in the Terms of Service. Nothing in this DPA limits either party's liability for death or personal injury caused by negligence, or for anything else that cannot lawfully be limited.
If this DPA conflicts with the Terms of Service on the processing of personal information, this DPA prevails.
This DPA is governed by the laws of the Province of Nova Scotia and the federal laws of Canada applicable there, consistent with the Terms of Service. Where PHIPA applies to your use of the service, nothing in this DPA is to be read as displacing your obligations or ours under Ontario law.
These are the safeguards in place as at the version date of this DPA.
TLS_AES_256_GCM_SHA384) for all connections to the service.
HTTP Strict Transport Security enforced.Valdra operates a formal information security and AI management programme aligned to SOC 2 Type II, ISO/IEC 27001 and ISO/IEC 42001, run inside Valdra itself.
We are not yet certified against those standards. We will not claim otherwise, and we will tell you when that changes. We would rather you knew exactly where we stand than discover it during an audit.