ValdraBY CANUCKT All legal documents →

Data Processing Agreement

Valdra — Canuckt Synergy Solutions Inc. Version 1.0 · Effective 28 July 2026


This Data Processing Agreement ("DPA") forms part of the Valdra Terms of Service between Canuckt Synergy Solutions Inc. ("Valdra", "we", "us") and the customer organisation named in the Valdra Order Form, or if there is none, the organisation that holds the Valdra subscription ("Customer", "you").

It sets out how we handle personal information you put into Valdra. We have written it to be read, not just signed. If anything here is unclear, ask us and we will explain it in plain terms.


1. Roles

You are the controller of the personal information you place in Valdra. Where the Personal Health Information Protection Act, 2004 (Ontario) ("PHIPA") applies, you are the health information custodian.

We are your processor (and, under PHIPA, act as your agent or service provider). We process personal information only on your documented instructions, and we do not determine the purposes for which it is processed.

Using the Valdra service is itself an instruction to process your data as needed to provide it.

2. Scope of processing

Subject matter Provision of the Valdra compliance and AI-governance platform
Duration For the term of your subscription, plus the retention period in §9
Nature and purpose Hosting, storing, analysing and displaying your compliance records; generating assessments, policies, assessments and reports at your request
Types of personal information Names, business contact details and roles of your personnel; records you create about data subjects (for example privacy requests and breach records); any personal information you choose to enter into free-text fields
Categories of data subjects Your personnel; individuals who make privacy requests to you; individuals referenced in your compliance records

What Valdra is not designed for. Valdra is a governance and compliance platform. It is not a clinical system and should not be used as a repository for patient records or bulk personal health information. You control what you enter; we ask that you enter the minimum necessary. Where you record a privacy request or a breach involving health information, reference the individual rather than reproducing their clinical record.

3. Our obligations

We will:

4. Security

We maintain the safeguards described in Annex A. We may update them, but we will not materially reduce the overall level of protection during your subscription.

5. Sub-processors

You give us general authorisation to engage sub-processors. Our current sub-processors, their function and their location are listed in our Sub-processor List, provided with this DPA and kept current.

Before adding or replacing a sub-processor we will give you at least 30 days' notice by email to your account administrator. If you have a reasonable, good-faith objection on data protection grounds, tell us within those 30 days and we will work with you to find an alternative. If we cannot, you may terminate the affected part of the service and receive a pro-rata refund of prepaid fees for the terminated portion.

This refund is a deliberate exception to the non-refund provision in the Terms of Service. It applies only where a sub-processor objection cannot be resolved, and not to cancellation generally.

We remain responsible to you for our sub-processors' performance.

6. Assisting you with individual rights

If an individual contacts us directly about data held in your account, we will not respond on your behalf. We will forward it to your account administrator promptly.

Valdra provides self-service tools to search, export and delete records. Where those tools are not sufficient, we will assist you at no additional charge for reasonable volumes.

7. Breach notification

If we become aware of a breach of security leading to accidental or unlawful destruction, loss, alteration, or unauthorised disclosure of or access to your personal information, we will:

  1. notify you without undue delay, and in any event within 48 hours of becoming aware of it, at the email address on your account;
  2. provide the information you reasonably need to meet your own reporting obligations — including, under PIPEDA, reporting to the Office of the Privacy Commissioner of Canada, and under PHIPA, reporting to the Information and Privacy Commissioner of Ontario;
  3. tell you what we know: what happened, what data was involved, likely consequences, and the steps we are taking;
  4. keep you updated as we learn more, and provide a written summary once resolved.

We will not make a public statement identifying you without your consent, unless required by law.

Our named contact for security matters is [email protected].

8. Location of data and cross-border transfers

Your data is stored and processed in Canada. Production infrastructure is located in Beauharnois, Québec. Backups are held on separate Canadian infrastructure.

Certain sub-processors listed in the Sub-processor List operate outside Canada. Where that is the case, it is identified in the list along with the safeguards in place. We will not move primary storage of your data outside Canada without giving you at least 30 days' notice and the right to terminate.

9. Retention, return and deletion

While your subscription is active, you may export your data at any time using the in-product export tools.

On termination:

We will confirm deletion in writing on request.

10. Audit and assurance

We will respond to reasonable security and privacy questionnaires once per twelve-month period at no charge.

You may audit our compliance with this DPA on 30 days' written notice, no more than once per twelve-month period (unless a breach has occurred, or a regulator requires it), during business hours, without unreasonably disrupting our operations, and subject to confidentiality. Where an independent audit report covering the relevant controls is available, providing it satisfies this obligation.

11. PHIPA — additional terms for Ontario health information custodians

Where you are a health information custodian under PHIPA and personal health information is placed in Valdra, the following apply in addition:

12. Liability

Each party's liability under this DPA is subject to the limitations of liability in the Terms of Service. Nothing in this DPA limits either party's liability for death or personal injury caused by negligence, or for anything else that cannot lawfully be limited.

13. Order of precedence

If this DPA conflicts with the Terms of Service on the processing of personal information, this DPA prevails.

14. Governing law

This DPA is governed by the laws of the Province of Nova Scotia and the federal laws of Canada applicable there, consistent with the Terms of Service. Where PHIPA applies to your use of the service, nothing in this DPA is to be read as displacing your obligations or ours under Ontario law.


Annex A — Technical and organisational measures

These are the safeguards in place as at the version date of this DPA.

Data residency

Encryption

Access control

Logging and monitoring

Resilience

Development and change management

Personnel

Sub-processor management

Certification status — stated plainly

Valdra operates a formal information security and AI management programme aligned to SOC 2 Type II, ISO/IEC 27001 and ISO/IEC 42001, run inside Valdra itself.

We are not yet certified against those standards. We will not claim otherwise, and we will tell you when that changes. We would rather you knew exactly where we stand than discover it during an audit.