Data Processing Addendum (DPA)
Effective Date: August 1, 2026
This Data Processing Addendum ("DPA") forms part of the agreement between Corsantic ("Processor", "we", "our", or "us") and the customer ("Controller", "Customer", or "you") governing the processing of Personal Data in connection with Corsantic's Services.
This DPA supplements the Terms of Service and Privacy Policy. If there is any conflict between this DPA and the Terms of Service regarding Personal Data processing, this DPA will govern to the extent of that conflict.
1. Definitions
For purposes of this DPA:
Controller means the entity that determines the purposes and means of processing Personal Data.
Processor means Corsantic when processing Personal Data on behalf of the Customer.
Personal Data means information relating to an identified or identifiable individual.
Processing includes collecting, storing, organizing, using, transmitting, analyzing, deleting, or otherwise handling Personal Data.
Subprocessor means a third party engaged by Corsantic to assist in providing the Services.
2. Scope
This DPA applies whenever Corsantic processes Personal Data on behalf of a Customer while providing the Services.
3. Roles of the Parties
For Personal Data processed under this DPA:
- The Customer acts as the Controller (or equivalent under applicable law).
- Corsantic acts as the Processor.
The Customer is responsible for determining whether Personal Data may lawfully be processed through the Services.
4. Customer Instructions
Corsantic will process Personal Data only:
- To provide the Services.
- According to documented Customer instructions.
- To comply with applicable law.
- As otherwise required to fulfill contractual obligations.
5. Types of Data
Depending on how the Services are used, Personal Data may include:
- Names
- Business contact information
- Email addresses
- Phone numbers
- User account information
- Uploaded documents
- Authentication information
- Technical identifiers
- Log information
- Other information submitted by the Customer
The exact categories depend on the Customer's use of the Services.
6. Purpose of Processing
Personal Data may be processed for purposes including:
- Delivering AI services.
- Processing uploaded documents.
- Providing technical support.
- Maintaining user accounts.
- Monitoring security.
- Preventing fraud.
- Maintaining system availability.
- Improving service reliability.
- Complying with legal obligations.
7. Confidentiality
Corsantic will ensure that personnel authorized to process Personal Data are subject to appropriate confidentiality obligations.
8. Security Measures
Corsantic maintains reasonable administrative, technical, and organizational safeguards designed to protect Personal Data against unauthorized access, disclosure, alteration, or destruction.
These safeguards may include:
- Encryption in transit
- Encryption at rest where supported
- Role-based access controls
- Multi-factor authentication for administrative access
- Logging and monitoring
- Network security controls
- Backup procedures
- Incident response processes
9. Subprocessors
Corsantic may engage trusted Subprocessors to provide portions of the Services, including:
- Cloud infrastructure providers
- Authentication providers
- Analytics providers
- Customer support providers
- Payment processors
- Infrastructure management providers
Corsantic will use commercially reasonable efforts to ensure that Subprocessors are subject to contractual obligations appropriate to the services they provide.
10. International Transfers
Customer information may be processed or stored in Canada, the United States, or other jurisdictions where Corsantic or its Subprocessors operate.
Where required by applicable law, Corsantic will implement appropriate safeguards for international data transfers.
11. Data Subject Requests
Where legally required and reasonably practicable, Corsantic will assist the Customer in responding to requests from individuals regarding access, correction, deletion, or other rights relating to their Personal Data.
12. Security Incidents
If Corsantic becomes aware of a confirmed security incident affecting Personal Data under this DPA, Corsantic will:
- Investigate the incident.
- Take reasonable steps to contain and mitigate its effects.
- Notify the Customer without undue delay where required by applicable law or contractual obligation.
- Cooperate with the Customer regarding the incident as reasonably necessary.
13. Data Retention and Deletion
Upon termination of the Services, Corsantic will retain or delete Customer Personal Data in accordance with applicable law, contractual obligations, backup retention schedules, and the Customer's documented instructions where applicable.
Certain information may be retained where required by law or for legitimate business purposes such as security, auditing, or dispute resolution.
14. Audits
Upon reasonable written request, and subject to appropriate confidentiality protections, Corsantic may provide information reasonably necessary to demonstrate compliance with this DPA.
Any audit rights are subject to reasonable notice, security requirements, and limitations intended to protect other customers and confidential information.
15. Customer Responsibilities
The Customer is responsible for:
- Obtaining all necessary permissions and legal bases for processing Personal Data.
- Providing appropriate notices to individuals.
- Ensuring uploaded information complies with applicable laws.
- Configuring the Services appropriately for its intended use.
- Maintaining the security of Customer-managed environments where applicable.
16. Liability
Each party's liability under this DPA is subject to the limitations of liability set out in the applicable agreement between the parties, unless otherwise required by applicable law.
17. Governing Law
This DPA is governed by the laws specified in the applicable agreement between the parties unless otherwise required by applicable law.
18. Changes
Corsantic may update this DPA from time to time to reflect changes in law, technology, or business operations.
Material changes will become effective upon publication or as otherwise communicated to Customers.
19. Contact
Questions regarding this Data Processing Addendum may be directed to:
Corsantic
Email: admin@corsantic.com
Website: https://corsantic.com
Last Updated: August 1, 2026