Data Processing Agreement
Template · Governed by Law 25 (Quebec) / PIPEDA · Version 2.1.0 — September 5, 2026
Scope: This agreement applies when iCivic, acting as processor, processes personal information on behalf of a client organization. To put this agreement in place or ask questions: legal@icivic.app
Between Solutions iCivic inc. ("iCivic" or "the Processor"), a company based in Gatineau, Quebec, Canada, and [ORGANIZATION NAME] ("the Client" or "the Controller"), hereinafter collectively referred to as "the Parties."
Article 1 — Purpose
This agreement governs the processing by iCivic, acting as processor, of personal information entrusted by the Client in connection with the use of the iCivic institutional dashboard, in accordance with section 18.3 of Law 25. It supplements the service agreement concluded between the Parties (the Institutional Terms of Service). In the event of conflict, this agreement prevails on matters of personal information protection.
Article 2 — Term
This agreement enters into force on the date of its signature by both Parties and remains in force for the entire duration of the service agreement. Confidentiality and data destruction obligations survive termination for a period of five (5) years.
Article 3 — Nature, purpose and legal basis of processing
iCivic processes the personal information described in Schedule A for the following purposes:
- Operator account management — creation, authentication, role assignment (RBAC) and deactivation of dashboard access;
- Audit log — recording administrative actions and data access for security and traceability purposes;
- Operational notifications — sending threshold alerts and periodic reports to the email addresses designated by the Client.
The Client is responsible for ensuring that the processing rests on a valid legal basis under Law 25 (operator consent or legitimate interest within the employment relationship) before entrusting this information to iCivic.
Article 4 — Documented instructions
iCivic processes personal information only in accordance with the Client's documented instructions, as set out in the service agreement and this agreement. If iCivic is required by law to carry out processing not provided for herein, it will inform the Client in advance, unless prohibited by law.
If iCivic considers that a Client instruction infringes Law 25 or any other applicable legal provision, it informs the Client without delay.
Article 5 — iCivic's obligations (processor)
5.1 Confidentiality
iCivic ensures that every person authorized to process the Client's personal information is bound by a confidentiality undertaking or subject to an appropriate statutory duty of confidentiality. This obligation survives the end of the agreement.
5.2 Security
iCivic implements and maintains the following technical and organizational measures:
- TLS 1.3 encryption of all communications;
- Encryption of data at rest (AES-256);
- Role-based access control (RBAC) and multi-organization isolation via Row Level Security (RLS), verified by automated tests;
- IP address handling: salted hashing (SHA-256) before any storage on consumer-facing surfaces; for the institutional dashboard's audit logs, retention in clear text for a maximum of ninety (90) days for security and traceability purposes, then automatic truncation of the final segment (/24 for IPv4, /48 for IPv6), which permanently removes host identification;
- Audit logs of administrative access;
- Centralized secrets management (no secrets in clear text in the code);
- Periodic security audits.
5.3 Sub-processors
The Client authorizes iCivic to engage the sub-processors listed in Schedule B. iCivic imposes on each sub-processor obligations at least equivalent to those in this agreement and remains responsible for their compliance.
iCivic will inform the Client with thirty (30) days' prior notice of any addition or replacement of a sub-processor. The Client may object in writing within that period; failing that, the change is deemed accepted.
5.4 Assistance with data subject rights
iCivic will assist the Client, to the extent reasonably possible and according to the nature of the processing, in responding to requests to exercise rights (access, rectification, erasure, portability, cessation of dissemination) made by data subjects, within the time limits set by Law 25.
5.5 Incident notification
In the event of a privacy incident affecting the Client's personal information, iCivic will notify the Client without delay and no later than seventy-two (72) hours after becoming aware of the incident. The notification will specify: nature of the incident, data affected, measures taken or planned, and the contact details of iCivic's point of contact.
iCivic will assist the Client with its obligations to notify the Commission d'accès à l'information du Québec (CAI) and the data subjects, and will record the incident in its incident register in accordance with Law 25.
5.6 Audit
iCivic will provide the Client, upon written request, with the information necessary to demonstrate compliance with this agreement, including relevant audit logs and available security attestations. iCivic may charge reasonable fees for the preparation of audit reports beyond the usual scope.
Article 6 — Client's obligations (controller)
- Provide processing instructions that comply with Law 25 and any other applicable legislation;
- Establish and document the legal basis for processing before entrusting personal information to iCivic;
- Inform its operators of the processing of their personal information by iCivic, in accordance with its own disclosure obligations;
- Designate authorized operator accounts and promptly revoke them upon departure or change of role;
- Notify iCivic without delay of any privacy incident it becomes aware of that could affect iCivic's systems.
Article 7 — Transfers of personal information outside Quebec
Certain iCivic sub-processors (Schedule B) are established outside Quebec. In accordance with Law 25, iCivic has conducted or will conduct a privacy impact assessment (PIA) before any transfer to a jurisdiction offering a lower level of protection, and ensures adequate contractual safeguards.
The Client, by signing this agreement, authorizes these transfers under the conditions described in Schedule B.
Article 8 — Retention periods and destruction
- Active operator accounts — retained as long as the account is active.
- Deactivated operator accounts — access is revoked immediately. Account information is retained for the duration of the service agreement, so that actions already recorded in the audit log remain attributable; it is deleted or anonymized upon the Client's written request, or automatically upon termination as set out below.
- Audit logs — retained for seven (7) years, a period adopted for traceability and compliance purposes (SOC 2). The IP address they contain is in clear text only for the first ninety (90) days: beyond that, it is automatically truncated (/24 for IPv4, /48 for IPv6) and can no longer identify a workstation.
- Upon termination of the service agreement — all personal information of the Client's operators is deleted or anonymized within thirty (30) days of termination. iCivic will provide the Client, upon request, with a certificate of destruction.
Article 9 — Data subject rights
As the Client is the controller for this processing, operators exercise their rights with the Client. iCivic assists the Client in accordance with section 5.4.
An operator may also write directly to legal@icivic.app; iCivic acknowledges receipt and responds within thirty (30) days, in coordination with the Client. The dashboard also allows each operator to update their own authentication settings (password, two-factor).
Two limits, stated here rather than discovered in use: an operator cannot delete their own account, which falls under the Client's access management (section 6); and audit log entries cannot be erased at the operator's sole initiative, their retention serving the security and traceability purposes described in section 8.
Article 10 — Liability
Each Party is responsible for damages caused by its own breaches of this agreement or of Law 25. iCivic's liability is limited, to the extent permitted by law, to the amounts paid by the Client during the twelve (12) months preceding the damaging event. This limitation does not apply in the event of gross negligence or willful misconduct.
Article 11 — Governing law and dispute resolution
This agreement is governed by the laws of Quebec and the applicable federal laws of Canada. Any dispute will be submitted to the competent courts of Quebec, district of Gatineau. The Parties agree to attempt amicable resolution within thirty (30) days following notification of a dispute.
Article 12 — French version and language primacy
This agreement is drawn up in French. An English version is made available to the Client for convenience. In the event of any discrepancy between the French version and the English version, the French version prevails.
The governing version is the one whose number and fingerprint appear on the copy signed by the Parties.
Article 13 — Amendments
iCivic may amend this agreement to reflect regulatory or operational changes, with thirty (30) days' prior notice. If the Client objects, it may terminate the service agreement in accordance with the procedures set out in the Institutional Terms of Service.
Article 14 — Contact — Privacy Officer
iCivic — Privacy Officer
Gatineau, Quebec, Canada
legal@icivic.app
Schedule A — Personal information processed
| Category | Data | Purpose |
|---|---|---|
| Operator accounts | First name, last name, professional email address, role, preferred language | Authentication and access management |
| Audit logs | Action performed, timestamp, IP address (clear text for at most 90 days, then truncated /24 – /48), operator identifier | Security, traceability, compliance |
| Operational notifications | Professional email address, alert preferences | Sending alerts and reports |
The wait-time data accessible in the dashboard consists of aggregated, anonymized statistics containing no personal information and is not covered by this agreement.
Schedule B — Authorized sub-processors
| Sub-processor | Role | Processing location | Data covered |
|---|---|---|---|
| Supabase | Database, authentication | Canada (ca-central-1) | All (Schedule A) |
| OVH | Hosting of the CRM (ERPNext) and messaging support (Chatwoot), both self-hosted | Canada (Beauharnois, Quebec) | Business contact details of the Client's representatives, support conversation content |
| Vercel | Web application hosting | Canada (Montreal) | Web requests (IP hashed in transit) |
| Brevo | Transactional emails (alerts, reports) | European Union (France) | Operator email addresses |
| PostHog | Pseudonymized dashboard analytics (cookieless) | United States | Pseudonymous identifier, screens viewed |
| Sentry | Crash reports (PII removed before sending) | United States | Technical logs (no PII) |
| Anthropic | Integrated AI assistant | United States (pinned inference) | AI request content (deleted within 30 days, up to 2 years if flagged by automated safety systems, not used for training) |
| Inngest | Asynchronous task orchestration | United States | Task metadata (no operator PII) |
| Chatwoot (self-hosted) | Customer support messaging | Canada (OVH, Beauharnois) | Support exchange content, operator identifier |
Signatures
The Parties acknowledge having read and accepted this agreement. It takes effect on the date of the last signature affixed below.
| For Solutions iCivic inc. | For [ORGANIZATION NAME] |
|---|---|
| Signature: ______________________ | Signature: ______________________ |
| Name: ______________________ | Name: ______________________ |
| Title: ______________________ | Title: ______________________ |
| Date: ______________________ | Date: ______________________ |
For any question: legal@icivic.app · Solutions iCivic inc. — Privacy Officer · Gatineau, Quebec, Canada