For Canada & International Clients – PIPEDA / PHIPA
Important: This Data Processing Agreement is required for all clients based in Canada and other international locations to ensure compliance with PIPEDA, PHIPA, and other applicable data protection regulations.
Data Processing Agreement (DPA)
Between:
PRECISION SMILES CAD TECHNOLOGIES INC.
("Processor")
and
The Client ("Controller")
This Data Processing Agreement ("Agreement") governs the processing of personal and health-related data by Processor on behalf of Controller in connection with the provision of dental CAD design services.
Processor shall process personal data solely for the purpose of providing the services described in the main service agreement and as instructed by Controller.
Processor shall only process personal data where Controller has obtained appropriate consent from data subjects or where another lawful basis exists.
Personal data shall be processed only for the specific purposes identified in this Agreement and the service agreement.
Processor shall only process personal data that is necessary for the provision of services.
Processor shall implement industry-standard security measures including:
All personal data shall be treated as confidential information. Processor shall ensure that personnel authorized to process personal data have committed to confidentiality obligations and shall not disclose personal data to third parties except as necessary to provide services or as required by law.
Processor may engage sub-processors (including cloud service providers) to assist in providing services. Sub-processors shall be required to comply with data protection standards equivalent to those in this Agreement.
Current sub-processors include cloud infrastructure providers compliant with international data protection standards.
Processor shall support Controller in responding to data subject requests for:
Personal data shall be retained only as long as necessary for service provision, legal compliance, or dispute resolution.
Standard retention periods:
Upon termination of services or upon Controller's request, Processor shall return personal data to Controller or securely destroy it and certify such destruction.
Processor shall notify Controller within 72 hours of becoming aware of any personal data breach. Such notification shall include:
This Agreement shall be governed by and construed in accordance with the laws of the Province of Ontario, Canada.
Precision Smiles CAD Technologies Inc.
Ontario, Canada