Data Processing Addendum
Effective date: [Effective date to be set by the owner]
This Data Processing Addendum (the “DPA”) forms part of, and is incorporated by reference into, the Terms of Service between Peakify Hub Inc., 214 Selkirk Avenue, Winnipeg, Manitoba, Canada (“Peakify”) and the customer that accepted those Terms (the “Customer”). It applies automatically to every Customer and requires no further action or signature on your part.
It governs Peakify’s processing of personal information on the Customer’s behalf in connection with Peakify CX (the “Services”), and is intended to satisfy the contractual requirements of Canada’s PIPEDA, Quebec’s private sector privacy act as amended by Law 25, the GDPR and UK GDPR, and the California Privacy Rights Act, to the extent any of them applies to a given engagement. Where this DPA conflicts with the Terms on a matter of data protection, this DPA prevails.
1. Definitions
- Personal Information means any information relating to an identified or identifiable natural person, and has the same meaning as “personal information” under PIPEDA and Quebec Law 25, “personal data” under the GDPR, and “personal information” under the CPRA.
- Customer Data means Personal Information about the Customer, its personnel and its administrative users: identity, billing, configuration, authentication and audit data.
- End-User means a natural person who interacts with the Services through the Customer’s account, typically the Customer’s leads, prospects or clients, and End-User Personal Information means Personal Information about an End-User that Peakify processes on the Customer’s behalf.
- Controller, Processor, Sub-Processor, Processing and Personal Data Breach have the meanings given to them, or to their equivalents, under Applicable Data Protection Law. A Personal Data Breach includes a “breach of security safeguards” under PIPEDA and a “confidentiality incident” under Quebec Law 25.
- Applicable Data Protection Law means each statute, regulation and binding regulatory guidance that governs the Processing under this DPA, including PIPEDA, Quebec Law 25, the Alberta and British Columbia PIPAs, the GDPR, the UK GDPR and the CCPA as amended by the CPRA.
2. Roles of the parties
End-User Personal Information. The Customer is the Controller and Peakify is the Processor. Peakify acts on the Customer’s documented instructions as set out in this DPA, the Terms and the configuration the Customer maintains in the Services.
Customer Data. For records about the Customer’s own staff and administrators (account registration, authentication, sessions, billing and audit logs), Peakify is an independent Controller for the limited purposes of account provisioning, billing and tax compliance, platform security and fraud prevention, statutory record-keeping, and product analytics in aggregate form. That processing is governed by our Privacy Policy, not by this DPA, except where this DPA says otherwise.
Where one record contains both, the more protective of the two regimes applies to the overlapping element. Nothing in this DPA makes the parties joint controllers.
3. Subject matter, duration, nature and purpose
Peakify processes End-User Personal Information to deliver the Services the Customer configures and operates: a shared inbox across web chat, SMS, WhatsApp, Instagram, Messenger and email; an AI response desk; client-journey tasks, a staff work queue, time tracking, documents and payment requests (the Customer’s own back office); missed-call-to-text automation; inbound voice handling; and scheduled follow-up sequences. Peakify sends and tracks payment requests but never touches the Customer’s money.
Processing lasts for the term of the Terms plus the return-and-deletion window in section 13. The categories of End-User Personal Information include contact data (name, phone, email, channel preference), conversation transcripts across every connected channel, voice-call metadata, recordings where the Customer enables recording, and AI-generated call summaries, consent and opt-out events, pipeline stage and qualification status, and anything an End-User chooses to disclose during a conversation, which may include health, financial or other sensitive details.
The Services are not intended for the deliberate processing of sensitive personal information. The Customer is responsible for not soliciting it through the Services.
4. Customer instructions
Peakify processes End-User Personal Information only on the Customer’s documented instructions, unless required otherwise by law. The Terms, this DPA, the Customer’s configuration of the Services (including AI prompts, knowledge-base content, routing rules and retention settings) and any further written instruction Peakify reasonably accepts together make up those instructions.
If Peakify reasonably believes an instruction breaks Applicable Data Protection Law, it will tell the Customer without undue delay and may suspend that instruction until the issue is resolved. Where Peakify must process Personal Information to comply with a legal obligation, it will inform the Customer of that obligation first, where the law allows.
5. Confidentiality of personnel
Every person Peakify authorizes to process Personal Information under this DPA is bound by a written confidentiality obligation or an equivalent statutory duty, and has received reasonable training on this DPA and the Applicable Data Protection Law relevant to their role.
6. Security measures
Peakify maintains appropriate technical and organizational measures to protect Personal Information against accidental or unlawful destruction, loss, alteration, unauthorized disclosure and unauthorized access, taking into account the state of the art, the costs of implementation, the nature and purposes of the Processing and the risks to the people concerned. The measures in Annex A form part of this DPA. Peakify may update them from time to time provided the overall level of protection is not materially reduced. Our Security Overview describes them in plain language.
7. Sub-processors
7.1 General authorization. The Customer authorizes Peakify to engage Sub-Processors to process End-User Personal Information, subject to this section.
7.2 Current list. The current list of Sub-Processors, with what each one does and where it processes data, is published at /sub-processors and is incorporated by reference.
7.3 Notice of changes. Peakify gives the Customer at least thirty (30) days’ notice before a new or replacement Sub-Processor begins processing End-User Personal Information, by email to the Customer’s administrative address and by updating the published list. Where a change is needed urgently for security or legal reasons, Peakify may shorten the notice and will explain why.
7.4 Objection. The Customer may object to a proposed Sub-Processor on reasonable data-protection grounds by written notice within fifteen (15) days of the notice. The parties will discuss the objection in good faith. If it cannot be resolved within thirty (30) days, the Customer may terminate the affected portion of the Services without penalty; that termination is the Customer’s exclusive remedy for an unresolved objection.
7.5 Flow-down and liability. Peakify imposes on each Sub-Processor written terms that are materially equivalent to this DPA, taking into account the Sub-Processor’s services, and remains liable to the Customer for its Sub-Processors’ acts and omissions to the same extent as for its own, subject to the limitations of liability in the Terms.
8. Data subject rights
Taking into account the nature of the Processing, Peakify will give the Customer reasonable assistance, including self-service tools in the Services where available, to respond to requests from individuals exercising their rights under Applicable Data Protection Law: access, correction, deletion, restriction, objection, portability, withdrawal of consent, and the right not to be subject to automated decision-making. If such a request reaches Peakify directly, Peakify will forward it to the Customer promptly and will not answer it on the merits except on the Customer’s instruction or as required by law. Routine assistance is free; substantial bespoke work may be charged at a reasonable rate notified in advance.
9. Personal data breach notification
Peakify will notify the Customer of a Personal Data Breach affecting End-User Personal Information without undue delay and in any event within seventy-two (72) hours of confirming it. To the extent known, the notice will describe the nature of the breach (including the categories and approximate number of individuals and records concerned), the name and contact details of Peakify’s privacy contact, the likely consequences, and the measures taken or proposed. Information not available at first is provided as the investigation proceeds.
Peakify will cooperate reasonably with any notification the Customer must make to a regulator (including the Office of the Privacy Commissioner of Canada and the Commission d’accès à l’information du Québec) or to affected individuals. A notice under this section is not an admission of fault.
10. Impact assessments and prior consultation
Where Applicable Data Protection Law requires the Customer to carry out a data protection impact assessment, a Quebec privacy impact assessment or a prior consultation with a regulator in respect of the Services, Peakify will provide reasonable assistance in proportion to the information only Peakify holds. Peakify may meet this by publishing standard materials describing the Services and their security measures.
11. Audit
No more than once in any twelve (12) month period, on at least thirty (30) days’ written notice, the Customer may audit Peakify’s compliance with this DPA, at the Customer’s expense, during business hours, through the Customer or an independent auditor who is not a competitor of Peakify and who signs Peakify’s standard non-disclosure agreement, on terms that do not unreasonably interfere with Peakify’s operations or other customers’ confidentiality. More frequent audits are allowed only where the law requires, a regulator directs, or a confirmed breach materially affected the Customer in the previous twelve months.
Peakify does not currently hold a SOC 2 report, an ISO/IEC 27001 certification or another formal third-party attestation, and this DPA does not say otherwise. If Peakify obtains one in future it may offer that report, under non-disclosure, in place of a direct audit, except where the report does not address the matter under audit or the law requires a direct audit. The Customer will share its audit findings with Peakify, and Peakify will respond within thirty (30) days with a plan for any material finding.
12. International transfers
Several Sub-Processors are located in, or run infrastructure in, the United States and other jurisdictions outside Canada. Using the Services therefore involves transfers of Personal Information outside Canada, and, for a Customer in the EEA or the United Kingdom, restricted transfers. Peakify relies, in order of preference, on adequacy decisions where available, the EU Standard Contractual Clauses (Module Two, Controller to Processor, incorporated by reference for an EEA Customer, with the docking clause included, Irish governing law and forum, and the annexes completed from this DPA), the UK International Data Transfer Addendum for a UK Customer, and other lawful mechanisms consistent with current regulatory guidance. Where Peakify onward-transfers to a Sub-Processor in a third country, Module Three applies between Peakify and that Sub-Processor.
For a Customer subject to Quebec Law 25, Peakify has assessed the cross-border communication of Personal Information under section 17 of that Act and will summarize the assessment on reasonable request. In short: the information is routine contact and conversational data, the principal destination is the United States, and, subject to the contractual, technical and organizational measures in this DPA, the transfer affords an adequate level of protection.
13. Return and deletion
For thirty (30) days after the Terms end, the Customer can export its data through the Services or with reasonable help from Peakify. Within sixty (60) days after that window, Peakify deletes or anonymizes the End-User Personal Information held in production systems and requires its Sub-Processors to do the same under their contracts with Peakify. Routine backup media are overwritten on Peakify’s standard backup cycle and are inaccessible for live use in the meantime.
Peakify may keep Personal Information for as long as the law or a court order requires. Signup-attempt metadata kept for fraud and abuse prevention is retained for ninety (90) days. On written request within ninety (90) days of termination, Peakify will certify in writing that the deletion has been completed.
14. Liability
Each party’s aggregate liability under this DPA is subject to the limitations of liability in the Terms, except where Applicable Data Protection Law prohibits such a limitation, and nothing here limits a party’s liability to an individual under GDPR Article 82 or an equivalent provision. Where the parties are jointly liable to an individual, each bears its share in proportion to its responsibility, and a party that has paid full compensation may seek contribution from the other. A regulatory fine is borne by the party it is addressed to, except where it is attributable to the other party’s breach of this DPA and the law allows reimbursement.
15. Quebec Law 25
Peakify’s privacy officer for the purposes of Quebec Law 25 and PIPEDA is Philip Akoji, reachable at support@peakifyhub.com.
Where the Customer uses the Services to make a decision based exclusively on automated processing that produces legal or similarly significant effects on an End-User, the Customer is responsible for the notice section 12.1 of that Act requires; Peakify will provide, on reasonable request, technical information about the personal information and factors involved.
The Customer will not configure the Services in a way that would mislead an End-User into believing they are talking with a person when they are talking with an automated system (see our Acceptable Use Policy). Peakify will cooperate with the Customer in any notification to the Commission d’accès à l’information required in connection with a confidentiality incident.
16. California and other US state privacy laws
For the Personal Information of California residents processed on the Customer’s behalf, Peakify acts as a “service provider” under the CPRA, and equivalent terms apply under the laws of Virginia, Colorado, Connecticut, Utah, Texas, Oregon and other states with comparable statutes. Peakify will not sell or share that Personal Information; will not retain, use or disclose it outside the direct business relationship with the Customer or for any purpose other than performing the Services, except as the CPRA permits; and will not combine it with Personal Information received from anyone else except as the CPRA permits for a service provider. Peakify will assist with verifiable consumer requests, certifies that it understands these restrictions, and will notify the Customer if it can no longer meet them.
17. GDPR and UK GDPR
For a Customer established in the EEA or the United Kingdom, this DPA is intended to satisfy Article 28(3) of the GDPR and the UK GDPR: the instructions are in section 4, the categories of data and individuals in section 3, the security measures in section 6 and Annex A, the assistance obligations in sections 8 to 11, the sub-processor regime in section 7, and the return-and-deletion regime in section 13. Where the Standard Contractual Clauses or the UK Addendum apply and conflict with this DPA, they prevail on the matter in conflict.
18. Order of precedence and general terms
On a data-protection matter this DPA prevails over the Terms; the Standard Contractual Clauses or the UK Addendum, where they apply, prevail over this DPA. This DPA is governed by the laws of Manitoba and the federal laws of Canada applicable there, and the courts of Manitoba sitting in Winnipeg have exclusive jurisdiction, subject to either party’s right to seek equitable relief elsewhere and to the forum rules of the Standard Contractual Clauses where they apply. Notices about data-protection matters should be copied to support@peakifyhub.com. The severability, no-waiver, entire-agreement, assignment and force-majeure clauses of the Terms apply to this DPA with the necessary changes. Headings are for convenience only.
Annex A. Technical and organizational measures
- Encryption in transit. TLS between end-user clients and the Services; TLS or private networks between internal services.
- Encryption at rest. Provider-managed encryption of database storage, object storage of attachments and recordings, and backups.
- Tenant isolation. Database row-level security policies that enforce access on the authenticated principal’s organization, reviewed before deployment and checked by automated tests.
- Secrets management. Application secrets, third-party API tokens and webhook signing keys held in a managed secret store, never in source control.
- Access control. Least-privilege, role-based access to production systems, reviewed periodically; multi-factor authentication for every administrative account; logged production database access.
- Authentication. Industry-standard password hashing and optional multi-factor enrolment for end users of the Services.
- Vulnerability management. Dependency advisories monitored and patches applied on a risk-prioritized basis; static analysis on the main branch.
- Logging and audit. Authentication, role changes, privileged actions and configuration changes logged and retained in proportion to operational and legal need.
- Secure development. Peer-reviewed code changes, gated by automated tests, deployed through an auditable pipeline.
- Vendor due diligence. Sub-Processors reviewed for their data-protection commitments and security posture before engagement and periodically after.
- Backup and recovery. Continuous, point-in-time database backups by the hosting Sub-Processor, with restores exercised on a defined cadence.
- Incident response. A written runbook covering detection, containment, eradication, recovery, notification and post-incident review.
- Personnel. Confidentiality undertakings and privacy and security training for everyone with access to Personal Information.
- Physical security. Peakify operates no data centres and relies on its infrastructure Sub-Processors’ physical-security certifications.
Annex B. Sub-processor list
The current list is published at /sub-processors and is incorporated by reference into this DPA, with the function and data location of each Sub-Processor set out there.