Legal
Data Processing Agreement
Effective date: April 1, 2025
1. Purpose
This Data Processing Agreement (DPA) forms part of the agreement between PropCare AI Inc. (Processor) and the customer (Controller) and governs the processing of personal data by PropCare on behalf of the customer in connection with the PropCare platform and services.
2. Definitions
- •Personal Data: Any information relating to an identified or identifiable natural person processed in connection with the Services.
- •Controller: The customer who determines the purposes and means of processing personal data.
- •Processor: PropCare AI Inc., which processes personal data on behalf of the Controller.
- •Sub-processor: Any third party engaged by PropCare to process personal data.
3. Processing Instructions
PropCare will process personal data only in accordance with the Controller's documented instructions, including for the purposes of operating, maintaining, and improving the PropCare platform. PropCare will inform the Controller if any instruction infringes applicable data protection laws.
4. Security Measures
- •Encryption of personal data in transit (TLS 1.2+) and at rest (AES-256).
- •Access controls restricting data access to authorized personnel only.
- •Regular security assessments and penetration testing.
- •Incident response procedures with breach notification within 72 hours of discovery.
5. Sub-processors
PropCare may engage sub-processors to assist in providing the Services. PropCare will ensure sub-processors are bound by data protection obligations no less protective than those in this DPA. A current list of sub-processors is available upon request at [email protected].
6. Data Subject Rights
PropCare will assist the Controller in responding to data subject rights requests (access, correction, deletion, portability) within applicable timelines. PropCare will promptly notify the Controller of any such request received directly from a data subject.
7. Data Transfers
PropCare processes and stores data primarily within Canada. Where data is transferred to other jurisdictions, appropriate safeguards will be in place in accordance with PIPEDA and applicable data protection laws.
8. Term and Termination
This DPA remains in effect for the duration of the service agreement. Upon termination, PropCare will, at the Controller's option, return or securely delete all personal data within 30 days, unless retention is required by law.
9. Contact
For DPA-related inquiries or to request a signed copy, contact [email protected].
Related Policies
Questions about this document? Contact us at [email protected].