For the purposes of this Data Processing Agreement ("DPA"), the following terms have the meanings set out below. Capitalized terms not defined herein have the meanings assigned to them in the SSMS Terms of Service.
"Breach" or "Data Breach" means any unauthorized access to, acquisition of, use of, disclosure of, or loss of Client Data or Personal Data processed under this DPA, whether accidental or unlawful.
"CAI" means the Commission d'accès à l'information du Québec, the supervisory authority responsible for overseeing compliance with Quebec privacy legislation.
"Client Data" means all data, content, and materials uploaded, submitted, or stored on the Platform by or on behalf of the Client, including SKU data, product images, PDF specification sheets, marketing assets, metadata, and product information.
"Data Controller" means the Party that determines the purposes and means of processing data. Under this DPA, the Client is the Data Controller for Client Data managed on the Platform.
"Data Processor" means the Party that processes data on behalf of the Data Controller. Under this DPA, SSMS is the Data Processor for Client Data managed on the Platform.
"Data Subject" means an identifiable individual to whom Personal Data relates.
"Law 25" means Quebec's Act respecting the protection of personal information in the private sector, as amended.
"OPC" means the Office of the Privacy Commissioner of Canada, the federal supervisory authority responsible for overseeing compliance with PIPEDA.
"Personal Data" means any information about an identifiable individual, as defined under PIPEDA and Law 25, that is processed by SSMS in connection with the Services.
"PIPEDA" means the Personal Information Protection and Electronic Documents Act (S.C. 2000, c. 5), as amended.
"Processing" means any operation or set of operations performed on Client Data or Personal Data, including collection, recording, organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination, alignment, combination, restriction, erasure, or destruction.
"Subprocessor" means any third party engaged by SSMS to process Client Data or Personal Data on behalf of the Client.
2.1 This DPA applies to the Processing of Client Data and Personal Data by SSMS in connection with the provision of the Platform and Services under the Terms of Service.
2.2 The purpose of Processing is limited to:
(a) hosting, storing, and managing Client Data on the Platform, including SKU records, product specifications, metadata, and digital assets;
(b) generating and resolving Eternal Links for public distribution of Client assets;
(c) managing Authorized User accounts, including authentication, authorization, and access control;
(d) maintaining audit logs and compliance records;
(e) providing reporting, analytics, and collaboration features as included in the applicable Subscription Plan; and
(f) performing technical operations necessary for the delivery, maintenance, and security of the Platform, including backups, monitoring, and incident response.
2.3 The duration of Processing corresponds to the term of the Agreement between the Parties, plus the thirty (30) day Export Period and any retention required by applicable law, as set forth in Section 12.
3.1 The Client is the Data Controller. The Client determines the purposes and means of Processing Client Data on the Platform. The Client decides what data to upload, which users to authorize, and how the Platform's features are used.
3.2 SSMS is the Data Processor. SSMS processes Client Data solely on behalf of the Client, in accordance with the Client's documented instructions and the terms of this DPA.
3.3 For Personal Data that SSMS collects independently (e.g., user account registration data, IP addresses, usage metrics), SSMS acts as an independent Data Controller. The collection and use of such data is governed by the SSMS Privacy Policy.
4.1 SSMS shall process Client Data only on documented instructions from the Client. The Client's use of the Platform and the configuration of features therein constitute documented instructions for the purposes of this DPA.
4.2 SSMS shall not process Client Data for any purpose other than providing the Services described in the Agreement, unless:
(a) required to do so by applicable law, in which case SSMS shall inform the Client of that legal requirement before Processing (unless prohibited by law from doing so); or
(b) the Client provides additional documented instructions.
4.3 SSMS shall promptly inform the Client if, in SSMS's opinion, an instruction from the Client infringes PIPEDA, Law 25, or any other applicable data protection legislation.
5.1 Client Data (Product Information). The following categories of Client Data are processed by SSMS on the Platform:
(a) SKU data, including product identifiers, names, descriptions, specifications, and attributes;
(b) digital assets, including product images, PDF specification sheets, and marketing materials;
(c) product metadata, including categorization, tagging, and organizational structures; and
(d) Eternal Link configurations and distribution records.
5.2 Personal Data (User Accounts). The following categories of Personal Data are processed in connection with Authorized User accounts:
(a) user names and display names;
(b) email addresses;
(c) IP addresses;
(d) browser and device information; and
(e) usage metrics and access logs.
5.3 Data Subjects. The Data Subjects whose data is processed under this DPA are:
(a) the Client's Authorized Users (Client Admins, Standard Users, and Viewers); and
(b) any individuals whose personal data the Client includes in Client Data (if applicable).
5.4 Nature of Client Data. The Parties acknowledge that Client Data consists primarily of publicly available product information — not sensitive personal data, trade secrets, or financial records. This DPA's security measures and obligations are calibrated accordingly.
6.1 SSMS shall implement and maintain appropriate technical and organizational measures to protect Client Data and Personal Data against unauthorized or unlawful Processing, accidental loss, destruction, or damage. These measures include, at a minimum:
6.2 Encryption.
(a) All data at rest is encrypted using AES-256 encryption.
(b) All data in transit is encrypted using TLS 1.2 or higher.
6.3 Tenant Isolation.
(a) Each Client's data is stored in a dedicated Amazon RDS for PostgreSQL database, providing complete logical separation from all other clients.
(b) Each Client's digital assets are stored under a dedicated Amazon S3 prefix with access controls preventing cross-tenant access.
(c) Each Client's users are authenticated through a dedicated Clerk Organization, which scopes that Client's user identities and authentication separately from all other Clients.
6.4 Access Controls.
(a) Role-based access controls (RBAC) limit access to Client Data based on the permissions assigned by the Client Admin.
(b) SSMS restricts internal access to Client Data to authorized personnel who require access for the performance of the Services.
6.5 Audit Logging.
(a) The Platform maintains immutable, append-only audit trails for all administrative actions.
(b) Audit logs are retained for the duration required by applicable law and the Agreement.
6.6 Legal Vault.
(a) Signed legal documents are archived using Amazon S3 Object Lock (Write Once Read Many) — providing tamper-proof, immutable records.
6.7 Infrastructure Security.
(a) The Platform is hosted on Amazon Web Services (AWS) infrastructure, which maintains SOC 2 Type II, ISO 27001, and ISO 27018 certifications.
(b) SSMS implements monitoring, alerting, and incident response procedures to detect and respond to security events.
6.8 SSMS shall review and update security measures periodically to address evolving threats and maintain alignment with industry standards for cloud-hosted SaaS platforms.
6.9 Availability, RPO, and RTO.
(a) Recovery Point Objective (RPO). SSMS maintains a Recovery Point Objective of one (1) hour or less for Client Data stored in the primary operational database, consistent with NFR11. Daily Amazon RDS automated backups and point-in-time recovery support this commitment.
(b) Recovery Time Objective (RTO). SSMS targets a Recovery Time Objective of twelve (12) minutes or less for the restoration of the primary operational database from the most recent usable backup, measured during the 2026-04-20 backup-restore rehearsal documented in SSMS's operational rehearsal records, available to the Client on reasonable request per Section 13.4. The twelve-minute figure is a preliminary baseline recorded at tier-3 rehearsal fidelity (staging smoke-level data set); a tier-1 rehearsal against production-scale data volume is scheduled to establish the binding baseline, after which this section will be updated to reflect the ratified RTO. The operational runbook for restore procedures is maintained in SSMS's internal documentation and summarized in the rehearsal records available on request.
(c) Observability commitment. SSMS maintains continuously-updated operational dashboards and alarm thresholds for availability, error rates, latency, and data-layer health, consistent with NFR45. Alarm-threshold ratification is a go-live gate for each new production tenant.
7.1 SSMS shall ensure that all personnel authorized to process Client Data:
(a) are bound by appropriate confidentiality obligations, whether contractual or statutory; and
(b) process Client Data only as necessary for the performance of the Services and in accordance with this DPA.
7.2 SSMS shall limit access to Client Data to those personnel who require such access for the purposes described in Section 2.2.
8.1 Authorized Subprocessors. The Client acknowledges and authorizes the use of the following Subprocessors as of the Effective Date:
| Subprocessor | Service | Purpose | Data Handled | Location |
|---|---|---|---|---|
| Amazon Web Services — RDS for PostgreSQL | Relational database | Per-tenant relational database | SKU data, user account records, audit logs | us-east-1 (United States) |
| Amazon Web Services — S3 | Object storage | Asset storage; Legal Vault (WORM) document archival | Product assets, signed legal documents | us-east-1 (United States) |
| Clerk (Clerk, Inc.) | Authentication, identity, and session management | Per-tenant user identity and authentication, scoped by a dedicated Clerk Organization | User identity, email, name, authentication metadata, session tokens | United States |
| Amazon Web Services — SES | Transactional email | Platform notifications, legal-activation prompts | Recipient email addresses, email subject and body | us-east-1 (United States) |
| Amazon Web Services — CloudWatch | Monitoring | Platform monitoring and logging | Usage metrics, application logs | us-east-1 (United States) |
| Amazon Web Services — SNS | Notifications | Operational alarm delivery to the operator | Operational alarm metadata (no Client Data or Personal Data) | us-east-1 (United States) |
| Amazon Web Services — Secrets Manager | Secrets management | Storage of platform credentials and configuration secrets | Service credentials / API keys (no Client Data or Personal Data) | us-east-1 (United States) |
| Amazon Web Services — KMS | Encryption key management | Management of data-at-rest encryption keys | Encryption keys only (no Client Data or Personal Data) | us-east-1 (United States) |
| Amazon Web Services — CloudFront | Content delivery network | Platform application and marketing-site delivery; public-link asset distribution (legacy/fallback of two CDN vendors) | Application and asset content, request IP, request timestamp | Global edge network (origin: us-east-1, United States) |
| Bunny.net (operated by BunnyWay d.o.o.) | Content delivery network + edge storage | Public-link asset distribution and edge storage (one of two CDN vendors) | Asset binary content, request IP, request timestamp | Edge storage: New York (United States) — the CDN vendor offers no Canadian storage region; global edge cache may include a Toronto edge node. Vendor domiciled in Slovenia (EU). |
| Stripe (Stripe, Inc. / Stripe Payments Canada Ltd.) | Payment processing, subscription billing, tax calculation | Self-serve checkout, recurring billing, and Stripe Tax (GST/HST + QST) calculation and invoicing | Billing contact name and email, billing address, payment-card data (processed by Stripe as a PCI-DSS Level 1 processor — SSMS does not store card numbers), business tax identifiers | United States |
| Cloudflare, Inc. | DNS authority + inbound email routing | Authoritative DNS resolution for SSMS domains; inbound email routing (Cloudflare Email Routing) | DNS query data; inbound email envelope/addresses (no Client Data) | Global anycast network |
8.2 Subprocessor Compliance Certifications. The Amazon Web Services, Inc. Subprocessors listed in Section 8.1 maintain SOC 2 Type II, ISO 27001, and ISO 27018 certifications. Clerk, Inc. maintains SOC 2 Type II certification and hosts authentication and identity data in the United States. Cloudflare, Inc. maintains SOC 2 Type II and ISO 27001. Stripe, Inc. maintains PCI-DSS Level 1, SOC 1 and SOC 2 Type II, and ISO 27001 certifications. Bunny.net (BunnyWay d.o.o.) is certified to ISO/IEC 27001 (information-security management; certified September 2024, under a UKAS-accredited body) and represents that it processes data in compliance with the EU GDPR. SSMS will provide evidence of any Subprocessor's then-current certifications on the Client's reasonable request.
8.3 Subprocessor Changes. SSMS shall notify the Client in writing at least thirty (30) days before engaging any new Subprocessor or replacing an existing Subprocessor. The notification shall include:
(a) the name and location of the proposed Subprocessor;
(b) the purpose and scope of Processing to be performed; and
(c) the categories of data to be processed.
8.4 Client Objection. If the Client objects to a proposed Subprocessor change on reasonable data protection grounds, the Client shall notify SSMS in writing within fifteen (15) days of receiving the notification. The Parties shall work in good faith to resolve the objection. If the Parties are unable to reach a resolution, the Client may terminate the Agreement in accordance with the Terms of Service, and such termination shall not be treated as a termination for cause by the Client.
8.5 Subprocessor Obligations. SSMS shall:
(a) enter into a written agreement with each Subprocessor imposing data protection obligations no less protective than those in this DPA;
(b) remain fully liable to the Client for the performance of each Subprocessor's obligations; and
(c) conduct appropriate due diligence on each Subprocessor's data protection practices.
9.1 Hosting Location. All Client Data and Personal Data processed under this DPA is hosted in the United States. The authoritative application infrastructure (database, object storage, transactional email, monitoring, secrets, and encryption-key management) is operated by Amazon Web Services in its us-east-1 region (United States). User authentication, identity, and session data is managed by Clerk (Clerk, Inc.), hosted in the United States. Public-link asset content is additionally delivered and cached through two content-delivery networks — Amazon CloudFront and Bunny.net; Bunny.net edge storage is located in New York, United States (the CDN vendor offers no Canadian storage region), with global edge caching that may include a Toronto edge node. Payment, billing, and tax data is processed by Stripe in the United States. DNS resolution and inbound email routing for SSMS domains are provided by Cloudflare on its global network. No Client Data or Personal Data is stored at rest in Canada.
9.2 Cross-Border Disclosure. The Parties acknowledge that the storage and processing of data in the United States constitutes a transfer of data outside of Canada within the meaning of Section 17 of Quebec's Law 25. In accordance with Law 25, the following is disclosed:
(a) Purpose of transfer: Data is transferred to the United States for the purpose of hosting, storing, processing, and delivering the Platform and Services, including all Subprocessor operations described in Section 8.1.
(b) Recipients: (i) Amazon Web Services, Inc. ("AWS"), a subsidiary of Amazon.com, Inc. (Seattle, Washington, USA), operating the core application infrastructure; (ii) Clerk, Inc. (United States), providing user authentication, identity, and session management; (iii) Bunny.net, operated by BunnyWay d.o.o. (Slovenia, EU), operating one of the two content-delivery networks, with edge storage in New York, USA; (iv) Stripe (Stripe, Inc., San Francisco, California, USA, and/or Stripe Payments Canada Ltd.), processing payment, billing, and tax data; and (v) Cloudflare, Inc. (United States), providing DNS resolution, edge security, and inbound email routing for SSMS domains on its global network, processing DNS query data and inbound email envelope and message data. Each acts as a Subprocessor for SSMS.
(c) Protection measures: Data transferred outside of Canada is protected by:
9.3 SSMS shall ensure that any cross-border transfer of Client Data or Personal Data complies with applicable Canadian federal and provincial data protection legislation, including PIPEDA and Law 25.
9.4 If SSMS proposes to transfer Client Data to a jurisdiction other than the United States, SSMS shall obtain the Client's prior written consent and ensure that equivalent or greater data protection measures are in place.
10.1 Notification to Client. In the event of a Data Breach involving Client Data or Personal Data processed under this DPA, SSMS shall notify the Client in writing without undue delay and in any event within seventy-two (72) hours of becoming aware of the Breach.
10.2 Breach Notification Content. The notification shall include, to the extent known at the time:
(a) a description of the nature of the Breach, including the categories and approximate number of Data Subjects and data records affected;
(b) the name and contact information of SSMS's point of contact for further information;
(c) a description of the likely consequences of the Breach;
(d) a description of the measures taken or proposed to be taken by SSMS to address the Breach, including measures to mitigate its possible adverse effects; and
(e) any information required for the Client to fulfill its own breach notification obligations under applicable law.
10.3 Supplementary Information. If SSMS is unable to provide all required information within the seventy-two (72) hour period, SSMS shall provide the information in phases without further undue delay as it becomes available.
10.4 Regulatory Notification. The Client, as Data Controller, is responsible for determining whether the Breach requires notification to the CAI, the OPC, or affected Data Subjects under applicable law. SSMS shall cooperate with and assist the Client in fulfilling any such notification obligations.
10.5 Remediation. SSMS shall take all commercially reasonable steps to contain, investigate, and remediate the Breach, and to prevent recurrence.
10.6 Record Keeping. SSMS shall maintain a record of all Data Breaches, including the facts relating to each Breach, its effects, and the remedial action taken.
11.1 SSMS shall, taking into account the nature of the Processing, assist the Client by appropriate technical and organizational measures, insofar as this is possible, in fulfilling the Client's obligation to respond to requests from Data Subjects exercising their rights under PIPEDA and Law 25, including rights of:
(a) access to their Personal Data;
(b) correction of inaccurate Personal Data;
(c) deletion of Personal Data; and
(d) portability of Personal Data.
11.2 If SSMS receives a request from a Data Subject directly, SSMS shall promptly redirect the request to the Client and shall not respond to the Data Subject directly, unless otherwise instructed by the Client or required by applicable law.
11.3 SSMS shall provide reasonable assistance to the Client in responding to Data Subject requests, within the timelines required by applicable law (thirty (30) days per PIPEDA).
12.1 Data Export. Upon termination or expiration of the Agreement, SSMS shall make Client Data available for export in standard, machine-readable formats for a period of thirty (30) days (the "Export Period"), as set forth in Section 19 of the Terms of Service.
12.2 Deletion. Upon expiration of the Export Period, SSMS shall permanently delete all Client Data from all active systems, databases, and storage, including Subprocessor systems. SSMS shall provide the Client with written certification of deletion upon request.
12.3 Deletion Method. Deletion shall be performed using industry-standard methods appropriate to the storage medium. For encrypted data, destruction of the encryption keys shall constitute acceptable deletion.
12.4 Legal Retention. SSMS may retain copies of Client Data to the extent strictly required by applicable law, regulation, or for the purpose of maintaining compliance records (including immutable audit logs and Legal Vault archives). Any retained data shall continue to be protected in accordance with the security and confidentiality obligations of this DPA.
12.5 Personal Data. Personal Data associated with Authorized User accounts shall be handled in accordance with the SSMS Privacy Policy and applicable law upon termination.
13.1 The Client may, upon at least thirty (30) days' prior written notice, audit SSMS's compliance with the obligations set forth in this DPA. Audits shall be:
(a) conducted at the Client's expense;
(b) limited in scope to SSMS's compliance with this DPA;
(c) conducted during normal business hours;
(d) limited to one (1) audit per twelve (12) month period, unless a Data Breach has occurred or a regulatory authority requires an additional audit; and
(e) conducted in a manner that minimizes disruption to SSMS's operations and does not compromise the security or confidentiality of other clients' data.
13.2 The Client may engage a qualified, independent third-party auditor to conduct the audit on its behalf, provided that such auditor is bound by confidentiality obligations acceptable to SSMS.
13.3 SSMS shall cooperate with the audit and provide reasonable access to relevant documentation, systems, and personnel. SSMS is not required to provide access to other clients' data, SSMS proprietary source code, or infrastructure that would compromise platform security.
13.4 Alternative Evidence. At SSMS's discretion, SSMS may satisfy audit requests by providing:
(a) relevant compliance certifications or reports (e.g., SOC 2 Type II reports from AWS);
(b) results of independent security assessments; or
(c) written responses to the Client's audit questionnaire,
provided that such evidence reasonably addresses the Client's audit objectives.
14.1 SSMS shall process Personal Data in compliance with PIPEDA and Law 25 to the extent applicable to its role as Data Processor.
14.2 PIPEDA Fair Information Principles. In its capacity as Data Processor, SSMS supports the Client's compliance with PIPEDA's 10 fair information principles by:
(a) Accountability: Maintaining this DPA and designating personnel responsible for data protection compliance;
(b) Identifying Purposes: Processing Personal Data only for the purposes documented in Section 2.2;
(c) Consent: Relying on the Client's obligation, as Data Controller, to obtain appropriate consent from Data Subjects;
(d) Limiting Collection: Processing only the categories of Personal Data described in Section 5.2;
(e) Limiting Use, Disclosure, and Retention: Using Personal Data only as described in this DPA and retaining it only for the duration described in Section 12;
(f) Accuracy: Providing the Client with the ability to correct Personal Data through the Platform;
(g) Safeguards: Implementing the security measures described in Section 6;
(h) Openness: Making this DPA and the Privacy Policy available to the Client and Data Subjects;
(i) Individual Access: Assisting the Client in responding to Data Subject access requests as described in Section 11; and
(j) Challenging Compliance: Cooperating with the Client and regulatory authorities in the investigation of complaints.
14.3 Law 25 Requirements. In its capacity as Data Processor, SSMS supports the Client's compliance with Law 25 by:
(a) disclosing the cross-border transfer of data to the United States as required by Section 17 of Law 25 (see Section 9 of this DPA);
(b) notifying the Client of Data Breaches within seventy-two (72) hours to enable the Client to fulfill its notification obligations to the CAI (see Section 10);
(c) maintaining documentation of Processing activities for regulatory inquiry; and
(d) assisting the Client with Privacy Impact Assessments to the extent relevant to the Processing activities described in this DPA.
15.1 The liability of each Party under this DPA is subject to the limitations and exclusions set forth in Section 14 (Limitation of Liability) of the Terms of Service.
15.2 Nothing in this DPA limits or excludes either Party's liability for:
(a) fraud or fraudulent misrepresentation; or
(b) any liability that cannot be limited or excluded by applicable law.
16.1 This DPA commences on the Effective Date of the Terms of Service and continues for the duration of the Agreement.
16.2 This DPA shall automatically terminate upon termination or expiration of the Agreement, subject to SSMS's ongoing obligations with respect to data return, deletion, and any data retained under Section 12.4.
16.3 Sections 7 (Confidentiality of Processing), 10 (Data Breach Notification), 12 (Data Return and Deletion), 13 (Audit Rights), 14 (PIPEDA and Law 25 Compliance), and 15 (Liability) shall survive termination of this DPA.
17.1 Governing Law. This DPA shall be governed by and construed in accordance with the laws of the Province of Quebec and the federal laws of Canada applicable therein, consistent with the governing law provisions of the Terms of Service.
17.2 Conflict. In the event of any conflict between this DPA and the Terms of Service, this DPA shall prevail with respect to data processing matters. In all other respects, the Terms of Service shall prevail.
17.3 Severability. If any provision of this DPA is held to be invalid, illegal, or unenforceable, such provision shall be modified to the minimum extent necessary to make it valid, legal, and enforceable, or if modification is not possible, severed from this DPA. The invalidity of any provision shall not affect the remaining provisions.
17.4 Amendment. This DPA may be amended only by written agreement executed by both Parties. Material amendments to this DPA shall follow the modification procedures set forth in Section 20 of the Terms of Service.
17.5 Entire Data Processing Agreement. This DPA constitutes the complete agreement between the Parties with respect to data processing and supersedes all prior negotiations, representations, and agreements relating to such subject matter.
By executing the Terms of Service via the Legal Vault digital signature process, the Client acknowledges that it has read, understood, and agrees to be bound by this Data Processing Agreement, which forms an integral part of the Agreement.
| SSMS | Client | |
|---|---|---|
| Organization | Manuel Delorme, o/a « Smart SKU Management System » (sole proprietorship — entreprise individuelle, NEQ 2281430332) 305-2370, rue Belvédère Sud Sherbrooke, QC, J1H 0N8, Canada |
[Client Organization Name] |
| Signatory Name | [Name] | [Name] |
| Title | [Title] | [Title] |
| legal@smartskumanagementsystem.com | [Email] | |
| Date | [Date] | [Date] |
| Digital Signature | [Captured via Legal Vault] | [Captured via Legal Vault] |
This document is archived immutably in the SSMS Legal Vault with S3 Object Lock (WORM) protection. The archived copy constitutes the authoritative record of consent.