Data Processing Addendum
The standard data-processing terms available when EZ Support processes Customer Personal Data on a customer's documented instructions.
On this page
Last updated: July 28, 2026
This Data Processing Addendum (“DPA”) forms part of the agreement between EZ Support, Inc., PO Box 1408, Blackfalds AB T0M 0J0 (“EZ Support”), and the customer identified in an accepted document (“Customer”) only when that document expressly incorporates this DPA.
1. Roles and scope
For Customer Personal Data covered by this DPA, Customer is the organization that determines the purpose and means of processing and EZ Support processes the data on Customer’s documented instructions. Applicable privacy law may use terms such as controller, organization, processor, or service provider.
The incorporated Order or SOW describes the subject matter, duration, purpose, systems, data categories, individuals, locations, and responsibilities. EZ Support will not assume a category, processing purpose, or regulated-data commitment that is not identified there.
2. Documented instructions
EZ Support will process Customer Personal Data only to:
- Perform, secure, support, and administer the agreed services
- Follow documented Customer instructions consistent with the agreement
- Meet an applicable legal obligation, after notifying Customer when legally permitted
Customer is responsible for the lawfulness and accuracy of its instructions, required notices and consents, and authority to provide the data.
3. Confidentiality and access
EZ Support will limit access to personnel and approved providers who need Customer Personal Data for an authorized purpose. Those people will be subject to confidentiality obligations and appropriate access controls.
The parties will prefer delegated access, scoped tokens, service identities, and approved integrations. If reusable credentials are expressly required, the Order must define a secure exchange, storage, use, rotation, and revocation process.
4. Safeguards
EZ Support will maintain safeguards appropriate to the agreed processing and risk, which may include:
- Identity, authentication, authorization, and least-privilege controls
- Encryption in transit and, where appropriate, at rest
- Logging, monitoring, vulnerability, update, backup, and recovery practices appropriate to the service
- Personnel confidentiality and security responsibilities
- Supplier review and contractual protection
- Incident response, continuity, deletion, and change-management practices
The specific safeguards, evidence, exclusions, customer dependencies, recovery commitments, and monitoring coverage are those stated in the applicable Order or security schedule. No control eliminates all risk.
5. Subprocessors and locations
Customer authorizes EZ Support to use subprocessors needed for the agreed service, provided EZ Support:
- Selects them through a reasonable review appropriate to the processing
- Contractually requires data-protection obligations appropriate to their role
- Remains responsible for its obligations under this DPA
- Provides current material subprocessor and processing-location information on request or through the agreed notice method
If Customer reasonably objects to a new material subprocessor on substantiated data-protection grounds, the parties will work in good faith on a practical alternative. If none is reasonably available, either party may end the affected processing under the applicable Order.
Information may be processed outside Customer’s province or Canada where the Order permits it. EZ Support will use the contractual and other measures required for the applicable transfer.
6. Individual requests
Taking into account the nature of the processing, EZ Support will provide reasonable assistance when Customer must respond to an access, correction, deletion, consent-withdrawal, or complaint request involving Customer Personal Data.
If EZ Support receives a request relating to data controlled by Customer, it will direct the requester to Customer unless law requires another response. Customer remains responsible for deciding and communicating the response.
7. Security incidents
EZ Support will notify Customer without undue delay after confirming unauthorized access to, use, loss, or disclosure of Customer Personal Data for which EZ Support is responsible. The notice will provide available information reasonably needed for Customer’s assessment and legal obligations, without delaying initial notice until every fact is known.
The parties will cooperate on containment, investigation, remediation, required notices, and evidence preservation. A notification is not an admission of fault. Exact notification targets, contacts, and regulatory responsibilities may be stated in the Order.
8. Return, export, retention, and deletion
On termination of the affected service and subject to Customer’s payment, security, law, and the Order, EZ Support will make Customer Personal Data available for export for 30 days. After that period, EZ Support will delete or de-identify remaining copies unless retention is required by law, contract administration, security, fraud prevention, or dispute handling.
Backup copies may remain until overwritten through the documented backup cycle, protected from ordinary use in the meantime. The Order controls any different format, timing, transition work, or regulated retention requirement.
9. Information and review
EZ Support will make information reasonably necessary to demonstrate compliance with this DPA available to Customer, subject to confidentiality, security, privilege, third-party rights, and reasonable scope.
The parties will first use current policies, summaries, supplier reports, questionnaires, and other available evidence. Any additional audit or assessment must be agreed in advance regarding scope, timing, personnel, systems, confidentiality, disruption, and cost. EZ Support does not claim an assurance report or certification that it has not expressly identified.
10. Liability and priority
The liability limitations and dispute terms in the incorporated MSA or Order apply to this DPA. For data-processing subject matter, a specific accepted Order or SOW controls over this DPA, this DPA controls over the MSA, and the MSA controls over an incorporated policy unless the more specific document states otherwise.
11. Contact
Privacy and DPA questions may be sent to privacy@ezsupport.tech.