Skip to main content

This Data Processing Addendum (“DPA”) forms part of the Terms of Use or other written agreement (“Agreement”) between IDENTOS Inc. (“IDENTOS”) and the customer identified in the applicable Order Form (“Customer”) for access to and use of the PolicyArc PBAC Platform (“Platform”). This DPA applies to all subscription tiers, including free trials and evaluation access, and governs the processing of Personal Information by IDENTOS on behalf of Customer.

In the event of a conflict between this DPA and the Agreement, this DPA prevails with respect to the processing of Personal Information.

1. Definitions

  • “Applicable Privacy Law” means any law or regulation applicable to the processing of Personal Information under this DPA, including: the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation; Quebec’s Act respecting the protection of personal information in the private sector (Law 25); the General Data Protection Regulation (EU) 2016/679 (GDPR) and UK GDPR; the California Consumer Privacy Act (CCPA) as amended by the CPRA; and the Virginia Consumer Data Protection Act (VCDPA), Connecticut Data Privacy Act (CTDPA), Colorado Privacy Act (CPA), and Utah Consumer Privacy Act (UCPA), as applicable.
  • “Controller” means the entity that determines the purposes and means of processing Personal Information. Customer is the Controller.
  • “Processor” means the entity that processes Personal Information on behalf of the Controller. IDENTOS is the Processor.
  • “Personal Information” or “Personal Data” means any information relating to an identified or identifiable natural person that is processed by IDENTOS under this DPA.
  • “Processing” means any operation performed on Personal Information, including collection, storage, use, disclosure, or deletion.
  • “Sub-Processor” means any third party engaged by IDENTOS to process Personal Information on behalf of Customer.
  • “Data Subject” means the natural person to whom Personal Information relates.
  • “Data Subject Request” or “DSR” means a request by a Data Subject to exercise rights under Applicable Privacy Law.
  • “Security Incident” means any unauthorized access, use, disclosure, alteration, or destruction of Personal Information processed under this DPA.

2. Scope and nature of processing

2.1 Role of the parties

The parties acknowledge that: (a) Customer is the Controller of Personal Information processed through the Platform; and (b) IDENTOS is the Processor of such Personal Information, acting solely on Customer’s instructions.

2.2 Processing instructions

IDENTOS shall process Personal Information only: (a) in accordance with Customer’s documented instructions, including those set out in this DPA and the Agreement; (b) as necessary to provide the Platform and perform obligations under the Agreement; or (c) as required by Applicable Privacy Law, in which case IDENTOS shall inform Customer before such processing unless prohibited by law.

2.3 Details of processing

The subject matter, nature, purpose, duration of processing, types of Personal Information, and categories of Data Subjects are set out in Schedule A to this DPA.

3. IDENTOS obligations

3.1 Confidentiality of processing

IDENTOS shall ensure that persons authorized to process Personal Information are subject to appropriate obligations of confidentiality.

3.2 Security measures

IDENTOS shall implement and maintain appropriate technical and organizational security measures to protect Personal Information against Security Incidents. These measures are described in Schedule C and shall include, at a minimum: encryption of Personal Information at rest and in transit; access controls limiting access on a need-to-know basis; regular security assessments and vulnerability testing; and incident response and recovery procedures.

3.3 Compliance assistance

IDENTOS shall provide reasonable assistance to Customer in fulfilling Customer’s obligations under Applicable Privacy Law, including obligations relating to: (a) data subject rights; (b) security of processing; (c) notification of Security Incidents; (d) data protection impact assessments; and (e) prior consultation with supervisory authorities.

4. Sub-processors

4.1 Authorization

Customer authorizes IDENTOS to engage the Sub-Processors listed in Schedule B. IDENTOS shall impose data protection terms on each Sub-Processor that are no less protective than those in this DPA.

4.2 Changes to Sub-Processors

IDENTOS shall provide Customer with at least fourteen (14) days’ prior written notice of any intended addition or replacement of a Sub-Processor. Customer may object to the change within fourteen (14) days of receiving notice by notifying IDENTOS in writing at privacy@policyarc.com. If Customer raises a reasonable objection, IDENTOS shall use commercially reasonable efforts to: (a) provide a processing option that does not involve the objected-to Sub-Processor; or (b) if no such option is reasonably available, allow Customer to terminate the affected subscription without penalty, with a pro-rata refund of pre-paid fees.

4.3 Liability for Sub-Processors

IDENTOS shall remain fully liable to Customer for the performance of Sub-Processors’ obligations under this DPA to the same extent as if IDENTOS were performing such obligations directly.

5. Security incidents and breach notification

IDENTOS shall notify Customer without undue delay, and in any event within seventy-two (72) hours of becoming aware of any Security Incident that IDENTOS reasonably believes affects Personal Information processed under this DPA. Where the full details of the Security Incident are not yet available at the time of initial notification, IDENTOS shall provide the information available at that time and shall supplement the notification as additional details become known. For the avoidance of doubt, notification under this Section does not require that IDENTOS has completed its investigation of the Security Incident. Notification shall be provided by email to the contact designated in the applicable Order Form.

The notification shall include, to the extent known at the time: (a) a description of the nature of the Security Incident, including the categories and approximate number of Data Subjects and Personal Information records affected; (b) the likely consequences of the Security Incident; (c) the measures taken or proposed to address the Security Incident and mitigate its effects; and (d) contact details of IDENTOS’s privacy contact.

IDENTOS shall also: (a) cooperate with Customer in investigating and remediating the Security Incident; (b) take all steps necessary to contain, mitigate, and remedy the Security Incident; and (c) not make any public statement or notification regarding a Security Incident without Customer’s prior written consent, except as required by law. IDENTOS shall preserve all relevant logs, records, and forensic evidence related to a Security Incident for a minimum of twelve (12) months following the resolution of the incident, or such longer period as reasonably requested by Customer.

IDENTOS shall notify applicable supervisory authorities as required by Applicable Privacy Law, including the Office of the Privacy Commissioner of Canada, the Commission d’accès à l’information under Quebec Law 25, and EU or UK supervisory authorities under the GDPR, where IDENTOS is required to do so as a processor.

6. Data subject rights

6.1 Assistance with requests

Taking into account the nature of the processing, IDENTOS shall assist Customer in fulfilling Data Subject Requests under Applicable Privacy Law. Where IDENTOS receives a Data Subject Request directly, IDENTOS shall: (a) not respond to the request on Customer’s behalf, unless authorized by Customer or required by law; and (b) forward the request to Customer within three (3) business days of receipt.

6.2 Technical assistance

IDENTOS shall implement reasonable technical and organizational measures to assist Customer in responding to Data Subject Requests, including mechanisms to support access, rectification, erasure, restriction of processing, and data portability where applicable.

6.3 No cost recovery

IDENTOS shall not charge Customer for reasonable assistance provided in connection with Data Subject Requests, except where the volume or complexity of requests is manifestly excessive, in which case IDENTOS shall notify Customer and the parties shall agree on reasonable cost-sharing before IDENTOS proceeds.

7. Audit rights

IDENTOS shall, upon Customer’s written request and at Customer’s reasonable expense, make available to Customer all information reasonably necessary to demonstrate compliance with this DPA. IDENTOS shall allow for and contribute to audits, including inspections, conducted by Customer or a third-party auditor appointed by Customer, subject to: (a) reasonable advance notice of at least thirty (30) days; (b) the auditor being subject to appropriate confidentiality obligations; and (c) audits being conducted during normal business hours without unreasonable disruption to IDENTOS operations.

As an alternative or supplement to an on-site audit, IDENTOS shall provide Customer with its most recent SOC 2 Type II report or equivalent third-party audit report and ISO 27001 certificate upon reasonable request. Where such report is provided, Customer agrees to treat it as Confidential Information of IDENTOS.

8. International data transfers

8.1 Transfers from the EEA or UK

Where Personal Information is transferred from the European Economic Area (EEA) or United Kingdom (UK) to a country not recognized as providing an adequate level of protection, the parties shall rely on the Standard Contractual Clauses (SCCs) adopted by the European Commission (Controller-to-Processor, Module Two) and, where applicable, the UK International Data Transfer Addendum (IDTA). Where a Sub-Processor is certified under the EU–US Data Privacy Framework (DPF), transfers to that Sub-Processor may rely on the European Commission’s adequacy decision for the DPF, in addition to or in lieu of the Standard Contractual Clauses. The SCCs are incorporated into this DPA by reference. The SCCs shall be governed by the law of Ireland, in accordance with Clause 17 of the SCCs. The DPA itself (excluding the SCCs) shall be governed by the law specified in the Agreement.

8.2 Transfers from Canada

Where Personal Information is transferred from Canada to a country outside Canada, IDENTOS shall ensure appropriate safeguards are in place in accordance with PIPEDA Schedule 1 Principle 4.1.3 and applicable provincial law, including through contractual protections with Sub-Processors.

8.3 Canadian data residency

Upon Customer’s written request at the time of Order Form execution, IDENTOS shall make reasonable efforts to process and store Customer’s Personal Information within Canada. Customer acknowledges that certain Sub-Processors, such as cloud infrastructure providers, may store data in multiple regions; IDENTOS shall use commercially reasonable efforts to restrict such processing to Canada and the United States where Canadian residency is requested.

9. Jurisdiction-specific provisions

9.1 Quebec (Canada) — Law 25

Where Customer is subject to Quebec’s Act respecting the protection of personal information in the private sector (Law 25), IDENTOS shall: (a) process Personal Information only for the purposes described in Schedule A; (b) not communicate Personal Information outside Quebec without ensuring equivalent protection is provided; (c) maintain records of processing activities as required; and (d) inform Customer without delay if IDENTOS becomes aware that it is unable to comply with the applicable protection requirements.

9.2 PIPEDA (Canada)

IDENTOS shall, as a service provider under PIPEDA, handle all Personal Information transferred to it by Customer in accordance with PIPEDA’s Schedule 1 Fair Information Principles and Customer’s instructions under this DPA.

9.3 California (CCPA / CPRA)

To the extent Customer is a “business” and IDENTOS is a “service provider” under the CCPA/CPRA, IDENTOS shall: (a) not sell or share Personal Information; (b) not retain, use, or disclose Personal Information for any purpose other than providing the Platform; (c) not combine Personal Information received from Customer with Personal Information received from other sources except as permitted by law; and (d) notify Customer if IDENTOS determines it can no longer meet its obligations as a service provider.

9.4 Other US state privacy laws

To the extent Applicable Privacy Law includes the VCDPA, CTDPA, CPA, UCPA, or other US state privacy laws, IDENTOS shall comply with the processor obligations imposed by such laws, including restrictions on processing beyond the specified purposes, data security obligations, and requirements to assist Customer in responding to consumer rights requests.

10. Term and termination

This DPA is effective from the date the Agreement takes effect and shall continue in force for the duration of the Agreement. Upon termination or expiration of the Agreement, IDENTOS shall, at Customer’s election, delete or return all Personal Information processed under this DPA within sixty (60) days, and delete existing copies unless retention is required by Applicable Privacy Law. IDENTOS shall certify in writing to Customer that it has completed deletion or return of Personal Information upon Customer’s reasonable request.

11. Limitation of liability

Each party’s liability under this DPA shall be subject to the limitations set out in the Agreement. However, the limitations of liability in the Agreement shall not apply to: (a) breaches of Section 5 (Security incidents and breach notification); (b) IDENTOS’s failure to comply with its obligations under the Standard Contractual Clauses; or (c) claims by Data Subjects under Article 82 of the GDPR or equivalent provisions of Applicable Privacy Law, to the extent such claims cannot be contractually limited between the parties.

Schedule A: Details of processing

Subject matter

The processing of Personal Information by IDENTOS as Processor on behalf of Customer as Controller in connection with Customer’s use of the PolicyArc PBAC Platform.

Nature and purpose of processing

IDENTOS processes Personal Information to provide, maintain, and improve the Platform; provide customer support; ensure security of the Platform; perform obligations under the Agreement; and comply with legal obligations.

Duration of processing

For the duration of the Agreement, plus the period required to complete deletion or return of Personal Information following termination.

Types of Personal Information

Depending on Customer’s use of the Platform, Personal Information may include:

  • Identifiers — name, email address, username, employee ID
  • Authentication data — user credentials (hashed), session tokens
  • Access and authorization data — role assignments, policy decisions, access logs
  • Technical identifiers — IP address, device identifiers, user agent strings
  • Any other personal data submitted by Customer to the Platform

Categories of Data Subjects

Customers’ end users, employees, contractors, and other individuals whose access is managed through the Platform.

Schedule B: Approved sub-processors

The following Sub-Processors are authorized as of the Effective Date. IDENTOS will provide fourteen (14) days’ advance notice of changes and maintains a current list at PolicyArc.com/legal/sub-processors.

Sub-processorPurposeLocation
Microsoft AzureInfrastructure hosting and cloud servicesUnited States / Canada — Canadian data residency selected
Google WorkspaceCustomer support email servicesUnited States / Canada — Canadian data residency selected
SplunkApplication monitoring and loggingUnited States / Canada — Canadian data residency selected
SendGrid / TwilioTransactional email deliveryUnited States
StripePayment processing (subscription billing)United States

Schedule C: Technical and organizational security measures

IDENTOS implements and maintains the following security measures in connection with the processing of Personal Information under this DPA.

Encryption

Encryption of Personal Information at rest using AES-256 or equivalent; encryption in transit using TLS 1.2 or higher; and encryption of database backups.

Access controls

Role-based access controls limiting access to Personal Information on a need-to-know basis; multi-factor authentication for administrative access to production systems; and regular access reviews and revocation of unnecessary access.

Network security

Firewalls and network segmentation to isolate production environments; intrusion detection and prevention systems; and DDoS protection.

Vulnerability management

Regular vulnerability assessments (at minimum quarterly) and penetration testing (at minimum annually and following significant Platform changes); timely patching of identified vulnerabilities; regular testing of backup and recovery procedures (at minimum annually); security assessment of Sub-Processors prior to engagement and periodically thereafter; and secure software development lifecycle (SDLC) practices.

Incident response

Documented Security Incident response plan; designated security contact responsible for incident management; and post-incident reviews to prevent recurrence.

Personnel

Privacy and security training for all personnel with access to Personal Information; background checks for employees with access to production systems; and confidentiality obligations for all personnel.

Physical security

Physical access controls at data centre facilities operated by IDENTOS or its Sub-Processors. IDENTOS relies on Sub-Processors (including Microsoft Azure) for physical data centre security.

Audit and compliance

Annual SOC 2 Type II audit or equivalent. ISO 27001 certification maintained and renewed per certification cycle. IDENTOS will provide its most recent audit report and ISO 27001 certificate to Customer upon reasonable request.