Data Processing Agreement

Last updated: July 2, 2026

This Data Processing Agreement (“DPA”) forms part of the Terms of Service between North Refrigeration Inc. (“Maintaire”, the “Processor”) and the business customer (“Customer”, the “Controller”) and applies whenever the Customer stores personal information about its own clients, employees, or portal users in the Service. It is written to satisfy PIPEDA’s accountability requirements and Quebec Law 25’s mandatory written agreement for outsourced processing.

1. Roles and scope

The Customer decides what personal information to enter into the Service and why; it is responsible for the lawfulness of that collection. Maintaire processes that information only to provide, secure, and support the Service, and on the Customer’s documented instructions given through the Service’s features. Categories of data typically processed: client contact details and service addresses; portal user accounts; job, equipment, and service-history records; photos and documents; signed agreements and signature audit trails (name, signature image, IP address, timestamp); invoices and payment records.

2. Confidentiality

Maintaire limits access to Customer data to personnel who need it to operate or support the Service and who are bound by confidentiality obligations.

3. Security safeguards

Maintaire maintains safeguards appropriate to the sensitivity of the data, including encryption in transit, password hashing, organization-level tenant isolation, role-based access controls, rate limiting, and logging of administrative actions, as described at /legal/security.

4. Subprocessors

The Customer authorizes the subprocessors listed at /legal/subprocessors. Each subprocessor is bound by a written agreement imposing data-protection obligations no less protective than this DPA. Maintaire will update that page before adding or replacing a subprocessor; Customers who object may terminate and export their data.

5. Breach notice

Maintaire will notify the Customer without undue delay after becoming aware of a confidentiality incident affecting the Customer’s data, and will provide the information reasonably needed for the Customer to meet its own notification obligations (including to the OPC or, in Quebec, the CAI).

6. Assistance with individual rights

The Service’s built-in tools let the Customer access, correct, export, and delete the records it holds. Where a request can’t be completed with those tools, Maintaire will provide reasonable assistance on request to the Privacy Officer.

7. Deletion and return

On termination of the subscription, the Customer may request an export of its data within 30 days. Maintaire then deletes or anonymizes the Customer’s personal information in line with the retention schedule in the Privacy Policy, except where retention is required by law.

8. Demonstrating compliance

On written request (no more than once annually), Maintaire will provide information reasonably necessary to demonstrate compliance with this DPA.

9. Location of processing

Data is hosted in [FILL IN: Canada / the United States]. The Customer is responsible for any assessments its own regulators require for data it exports (for Quebec-resident data, Law 25 transfer assessments); Maintaire will provide reasonable cooperation.

10. Contact

Privacy Officer: [FILL IN: NAME] — privacy@maintaire.com