Skip to main content

Data Processing Addendum

The written terms on which we process personal information on your firm’s instructions, as PIPEDA and Quebec’s Law 25 require.

Version 1.0 · In effect since


This addendum forms part of the Terms of Service and applies whenever TVN Core Solutions Ltd.processes personal information on a firm’s behalf. It exists because both PIPEDA and Quebec’s Law 25 require the arrangement between an organisation and its service provider to be written down.

1. Roles

The firm decides whose personal information enters the service and for what purpose, and remains accountable for it. We process that information only to provide the service, and only on the firm’s documented instructions — which include the instructions implicit in using the software’s features.

Where the firm holds information about its own clients’ employees, the firm is itself acting for those clients. This addendum flows down: our obligations to the firm are available for the firm to rely on in its own engagement letters.

2. What we process

The categories of personal information and of individuals are set out in section 2 of the Privacy Policy. Processing continues for as long as the firm’s subscription is active, plus the return-or-delete period in section 8.

3. Our obligations

  • Process personal information only for the purpose of providing the service, and not for our own purposes.
  • Not sell personal information, and not use it to train machine-learning models.
  • Keep it confidential, and limit access to personnel who need it to do their job.
  • Apply the safeguards described in the Security Overview.
  • Assist the firm in responding to access, correction, portability and deletion requests it receives.
  • Assist the firm with privacy impact assessments and regulator enquiries relating to the service.
  • Make available the information a firm reasonably needs to demonstrate our compliance with this addendum.

4. Subprocessors

The firm authorises the subprocessors listed on the Subprocessorspage. We remain responsible for their performance. We give at least 30 days’ notice before adding one or materially changing what an existing one receives; a firm may object on reasonable data-protection grounds within that period, and where the objection cannot be resolved may terminate the affected part of its subscription without penalty and receive a pro-rated refund of fees paid for the unused term.

5. Transfers outside Canada

Personal information processed through the service is currently stored and processed in the United States, and is therefore subject to lawful access by US authorities. A firm subject to Quebec’s Law 25 must complete a privacy impact assessment before communicating personal information outside Quebec; we will provide the information about our providers, safeguards and data flows that such an assessment needs. The provider list, purposes and locations on the Subprocessors page are written to be usable as an input to one.

We are moving the primary database, file storage and application hosting to Canadian regions. This section will be amended, with a new version number, when that is complete.

6. Confidentiality incidents

We maintain a register of confidentiality incidents, as Law 25 requires. On becoming aware of a breach of security safeguards affecting a firm’s data we will notify that firm without undue delay, and provide what we know about the nature of the incident, the information involved, the likely consequences, and the steps taken. The firm decides whether its own notification obligations to individuals and regulators are triggered; we will support that assessment.

7. Requests from individuals

Where an individual approaches us directly about information we hold on a firm’s behalf, we will not respond substantively on the firm’s behalf. We will tell the individual to approach the firm, tell the firm the request was made, and help the firm answer it.

8. Return and deletion

  • A firm can export its data at any time while its subscription is active.
  • For 30 days after a subscription ends the firm may request an export, and we will provide one.
  • After that period we delete the firm’s data from live systems.
  • Backups age out on their own retention cycle and are not selectively edited; data in a backup stays subject to this addendum until the backup expires.
  • We may retain what the law requires us to retain, and no more.

9. Demonstrating compliance

We do not hold a SOC 2 report or an equivalent third-party certification, and we do not claim one. What we will do is answer a firm’s security questionnaire, describe our controls, and give reasonable written detail about our architecture and providers. If that is not enough for your professional obligations, tell us before you subscribe rather than after.

10. Order of precedence

Where this addendum conflicts with the Terms of Service on the handling of personal information, this addendum governs.