DATA PROCESSING AGREEMENT

Data Processing Agreement

How Autofy handles the personal information of your store's customers, word for word.

LAST UPDATED

Every Autofy client accepts this agreement at checkout, together with their Statement of Work and the Service Agreement. Fields in [brackets] are filled in from your Statement of Work, and a copy of everything you accepted is emailed to you the day you sign up.

This Data Processing Agreement forms part of the Service Agreement between Autofy AI and Automation Solutions Inc. (“Processor” and “Autofy”) and [CLIENT LEGAL NAME] (“Controller” and “Client”) accepted on [EFFECTIVE DATE].

“Applicable Privacy Law” means the Personal Information Protection and Electronic Documents Act (PIPEDA) and any provincial private-sector privacy law that applies to the Client, including the Personal Information Protection Act (Alberta) and the Personal Information Protection Act (British Columbia).

Under Applicable Privacy Law, the Controller remains accountable for personal information transferred to Autofy for processing.

1. Roles

The Client decides why and how their customers’ personal information is used. Autofy processes the personal information of customers only on the Client’s documented instructions, as needed to provide the Service.

2. What Autofy processes

(a) Categories of individuals: the Client’s retail customers, and the Client’s own staff who use the Service.

(b) Personal information processed:

Data Source Purpose
Customer name Inventory system / staff entry Identify whose order it is
Customer email address Inventory system / staff entry Send arrival notifications
Customer phone number (if provided) Inventory system / staff entry Held for reference so staff can call the customer
Order contents, value, dates Inventory system Track the order and detect arrival
Order status history and notification log Generated by the Service Prove the customer was contacted
Staff name, email, role Client Access control and audit trail

(c) Autofy does not process payment card numbers, or full addresses beyond what the Client’s inventory system supplies with the order, and the Client will not enter health, financial or other sensitive personal information into any free-text field in the Service.

(d) Where the data lives. Autofy reads the Client’s inventory system and also stores these records in a database operated by Autofy in order to run the pipeline, detect arrivals and prove notifications were sent. See clause 4 for location.

3. Our obligations as Processor

Autofy will:

(a) process personal information only on the Client’s documented instructions, and only to provide the Service, except that Autofy may create and use Aggregated Data as described in Service Agreement clause 7.5;

(b) not sell, rent or disclose personal information to third parties, other than the sub-processors authorized under clause 4 or as required by law, and not use it for Autofy’s own marketing (Aggregated Data is not personal information for this purpose);

(c) apply security safeguards appropriate to the sensitivity of the information (clause 5);

(d) ensure anyone with access is bound by confidentiality obligations;

(e) assist the Client in responding to individuals exercising their Applicable Privacy Law rights (clause 6);

(f) notify the Client of a breach without undue delay (clause 7);

(g) delete or return personal information on termination (clause 8); and

(h) make available the information reasonably needed to demonstrate compliance with this DPA.

4. Sub-processors

The Client authorizes Autofy to use the following sub-processors:

Sub-processor Purpose Data location
Supabase Database hosting where Client order and customer records are stored Provisioned per Client, as recorded in the Statement of Work. Defaults to the Client’s country of operation; another location may be requested.
Vercel Application hosting United States
Resend Sending customer email notifications United States
Stripe Billing the Client (no customer data) Canada / US
The Client’s inventory system — Shopify, Lightspeed or WooCommerce Source of order data (already the Client’s own processor) Per the Client’s own agreement with that provider

Autofy will give the Client 30 days’ notice before adding or replacing a sub-processor. If the Client reasonably objects, the Client may terminate the Service Agreement without penalty.

Cross-border transfer. The Client’s order and customer database (Supabase) is hosted in the Client’s country of operation by default, or in another location on the Client’s request, as recorded in the Statement of Work. Application hosting (Vercel) and the sending of customer email notifications (Resend) are provided from the United States regardless of where the Client’s database is hosted. Client data, including the personal information of the Client’s customers, is therefore transferred to and processed in the United States in the course of providing the Service, and is subject to United States law, including lawful access requests by US authorities, in respect of that processing.

Applicable Privacy Law permits this provided the Controller uses contractual means to ensure a comparable level of protection — which this DPA is intended to provide. The Client remains accountable for the information and must disclose this transfer in its own privacy policy. By accepting, the Client consents to it.

5. Security safeguards

Autofy maintains:

(a) encryption of data in transit (TLS) and at rest;

(b) encryption of third-party access tokens at the application layer, with keys held separately from the database;

(c) tenant isolation: each Client’s data is stored in a separate database instance dedicated to that Client, so that one Client cannot access another Client’s data;

(d) role-based access control, with staff access scoped to their own organization;

(e) access to production systems limited to personnel who need it;

(f) audit logging of access to and changes of order records;

(g) regular backups with point-in-time recovery; and

(h) prompt application of security updates.

6. Individual rights

Applicable Privacy Law gives individuals the right to access their personal information and challenge its accuracy.

(a) If Autofy receives such a request directly from one of the Client’s customers, Autofy will not respond substantively; Autofy will forward it to the Client within 5 Business Days, since the Client is accountable for the response.

(b) Autofy will assist the Client in responding, including by providing, correcting, or deleting records, at no additional charge for reasonable volumes.

7. Breach notification

If Autofy becomes aware of a breach of security safeguards involving the Client’s personal information, Autofy will:

(a) notify the Client without undue delay and within 72 hours of becoming aware;

(b) describe what happened, what information was involved, how many individuals are affected, and what Autofy is doing about it;

(c) assist the Client in assessing whether the breach creates a real risk of significant harm, which triggers the Client’s obligation to report to the Office of the Privacy Commissioner of Canada and notify affected individuals; and

(d) keep a record of the breach and give the Client a copy on request, so the Client can meet its record-keeping obligation.

The Client is responsible for regulatory notification as the organization accountable for the information, and Autofy will provide the information reasonably needed to support it.

8. Retention and deletion

Personal information is retained while the Service Agreement is in effect.

(a) On termination, data is retained for 30 days so the Client can export it, then permanently deleted (or, where the Agreement ends for non-payment, at the time set out in Service Agreement clause 4.1).

(b) The Client may request earlier deletion in writing, and Autofy will comply within 30 days.

(c) Backups containing deleted data are purged on the normal backup rotation, within 7 days.

(d) Autofy may retain Aggregated Data.

(e) Autofy’s sub-processors delete Client personal information in accordance with their own retention periods, which are [●].

9. Audit

On reasonable written notice, no more than once a year, the Client may request information reasonably necessary to verify Autofy’s compliance with this DPA. Autofy will respond within 30 days.

10. Liability

Liability under this DPA is subject to the exclusions and limits in clause 11 of the Service Agreement, including the separate limit for breach of the security obligations in clause 5.

Questions about any of this? Email contact@autofyinc.ca or call +1 (204) 999-8255.