Data Processing Addendum (DPA)

Effective Date: August 1, 2026

This Data Processing Addendum ("DPA") forms part of the agreement between Corsantic ("Processor", "we", "our", or "us") and the customer ("Controller", "Customer", or "you") governing the processing of Personal Data in connection with Corsantic's Services.

This DPA supplements the Terms of Service and Privacy Policy. If there is any conflict between this DPA and the Terms of Service regarding Personal Data processing, this DPA will govern to the extent of that conflict.


1. Definitions

For purposes of this DPA:

Controller means the entity that determines the purposes and means of processing Personal Data.

Processor means Corsantic when processing Personal Data on behalf of the Customer.

Personal Data means information relating to an identified or identifiable individual.

Processing includes collecting, storing, organizing, using, transmitting, analyzing, deleting, or otherwise handling Personal Data.

Subprocessor means a third party engaged by Corsantic to assist in providing the Services.


2. Scope

This DPA applies whenever Corsantic processes Personal Data on behalf of a Customer while providing the Services.


3. Roles of the Parties

For Personal Data processed under this DPA:

The Customer is responsible for determining whether Personal Data may lawfully be processed through the Services.


4. Customer Instructions

Corsantic will process Personal Data only:


5. Types of Data

Depending on how the Services are used, Personal Data may include:

The exact categories depend on the Customer's use of the Services.


6. Purpose of Processing

Personal Data may be processed for purposes including:


7. Confidentiality

Corsantic will ensure that personnel authorized to process Personal Data are subject to appropriate confidentiality obligations.


8. Security Measures

Corsantic maintains reasonable administrative, technical, and organizational safeguards designed to protect Personal Data against unauthorized access, disclosure, alteration, or destruction.

These safeguards may include:


9. Subprocessors

Corsantic may engage trusted Subprocessors to provide portions of the Services, including:

Corsantic will use commercially reasonable efforts to ensure that Subprocessors are subject to contractual obligations appropriate to the services they provide.


10. International Transfers

Customer information may be processed or stored in Canada, the United States, or other jurisdictions where Corsantic or its Subprocessors operate.

Where required by applicable law, Corsantic will implement appropriate safeguards for international data transfers.


11. Data Subject Requests

Where legally required and reasonably practicable, Corsantic will assist the Customer in responding to requests from individuals regarding access, correction, deletion, or other rights relating to their Personal Data.


12. Security Incidents

If Corsantic becomes aware of a confirmed security incident affecting Personal Data under this DPA, Corsantic will:


13. Data Retention and Deletion

Upon termination of the Services, Corsantic will retain or delete Customer Personal Data in accordance with applicable law, contractual obligations, backup retention schedules, and the Customer's documented instructions where applicable.

Certain information may be retained where required by law or for legitimate business purposes such as security, auditing, or dispute resolution.


14. Audits

Upon reasonable written request, and subject to appropriate confidentiality protections, Corsantic may provide information reasonably necessary to demonstrate compliance with this DPA.

Any audit rights are subject to reasonable notice, security requirements, and limitations intended to protect other customers and confidential information.


15. Customer Responsibilities

The Customer is responsible for:


16. Liability

Each party's liability under this DPA is subject to the limitations of liability set out in the applicable agreement between the parties, unless otherwise required by applicable law.


17. Governing Law

This DPA is governed by the laws specified in the applicable agreement between the parties unless otherwise required by applicable law.


18. Changes

Corsantic may update this DPA from time to time to reflect changes in law, technology, or business operations.

Material changes will become effective upon publication or as otherwise communicated to Customers.


19. Contact

Questions regarding this Data Processing Addendum may be directed to:

Corsantic

Email: admin@corsantic.com

Website: https://corsantic.com


Last Updated: August 1, 2026