Safer InventorySafer Inventory

Legal

Data Processing Agreement

Effective date: June 19, 2026 · Version 1.1 · Pistis Contracting Inc. operating as Safer Inventory

This Data Processing Agreement (“DPA”) is entered into between:

Processor:Pistis Contracting Inc., a corporation incorporated under the laws of Ontario, Canada, operating under the trade name Safer Inventory, with its principal office at 18 Strathearn Ave Unit 6B, Brampton, ON L6T 4X7, Canada (“Processor” or “Safer Inventory”).

Controller:The customer entity identified in the Safer Inventory Terms of Service (“Controller”).

This DPA is incorporated into and forms part of the Safer Inventory Terms of Service at saferinventory.com/terms. In the event of a conflict between this DPA and the Terms of Service on a data processing matter, this DPA governs.

1. Definitions

“Customer Data” means any personal information submitted to the Service by or on behalf of the Controller, including inventory records, supplier and customer contact information, and transactional data.

“Personal Information”has the meaning given in PIPEDA (S.C. 2000, c. 5) and, where the Controller is subject to Quebec Law 25, includes “personal information” as defined therein.

“Data Breach”means a loss of, unauthorized access to, or unauthorized disclosure of Customer Data resulting from a breach of the Processor’s security safeguards.

“Sub-processor” means any third-party service provider engaged by the Processor to process Customer Data.

“PIPEDA” means the Personal Information Protection and Electronic Documents Act, S.C. 2000, c. 5, and the Breach of Security Safeguards Regulations (SOR/2018-64), as amended.

2. Scope and Roles

The Controller is the data controller responsible for determining the purposes and means of processing Customer Data. The Processor processes Customer Data solely on the Controller’s behalf and only as necessary to provide the Service as described in the Terms of Service.

Categories of Customer Data processed include: names and email addresses of end users; business contact information; inventory, order, and transaction data entered by the Controller; authentication and session data; and usage and log data generated through use of the Service.

3. Processor Obligations

The Processor will:

(a) Process Customer Data only on documented instructions from the Controller (which include use of the Service as described in the Terms of Service), unless required to do so by applicable law (in which case the Processor will notify the Controller before processing, to the extent legally permitted);

(b) Ensure that personnel authorized to process Customer Data are subject to confidentiality obligations;

(c) Implement and maintain the technical and organizational security measures described in Section 5;

(d) Not sell or rent Customer Data to any third party;

(e) Notify the Controller in accordance with Section 4 in the event of a Data Breach;

(f) Assist the Controller in responding to requests from individuals exercising their rights under PIPEDA or applicable provincial privacy law, including Quebec Law 25;

(g) Upon termination of the Terms of Service, provide the Controller with a complete export of Customer Data within 30 days in CSV or JSON format, and thereafter securely delete Customer Data from the Processor’s systems within 90 days, unless retention is required by law.

4. Data Breach Notification

In the event of a Data Breach involving Customer Data:

(a) The Processor will notify the Controller within 72 hours of becoming aware of the breach, even if not all details are known at the time of initial notification;

(b) The initial notification will include, to the extent then known: a description of the nature of the breach, the categories and approximate volume of Customer Data affected, the likely consequences of the breach, and measures taken or proposed to address the breach;

(c) The Processor will provide additional details as they become available and will cooperate with the Controller’s incident response;

(d) The Processor will notify the Office of the Privacy Commissioner of Canada (OPC) as required under PIPEDA s. 10.1 (“as soon as feasible”) and will assist the Controller in notifying affected end-users where required;

(e) The Processor will maintain records of all Data Breaches, whether or not reportable, for a minimum of 24 months as required under the Breach of Security Safeguards Regulations (SOR/2018-64, s. 6).

Note: PIPEDA does not prescribe a fixed-hour deadline for OPC notification but requires action “as soon as feasible.” The 72-hour Controller notification commitment in clause (a) is a contractual commitment that exceeds the minimum statutory standard and reflects enterprise best practice.

5. Security Measures

The Processor maintains the following technical and organizational security measures:

(a) Encryption at rest: AES-256 encryption for all stored Customer Data;

(b) Encryption in transit: TLS 1.2 or higher for all data in transit;

(c) Access control: role-based access control (RBAC); access to Customer Data restricted to personnel who require it to perform their duties;

(d) Authentication: multi-factor authentication required for all administrative access to production systems;

(e) Vulnerability management: regular dependency and security patch updates; annual penetration testing or equivalent assessment;

(f) Incident response: documented breach detection, containment, and notification procedures.

The Processor may update security measures from time to time to reflect changes in technology and threats, provided that updates do not materially reduce the protections afforded to Customer Data.

6. Sub-Processors

6.1 Authorized Sub-processors

The Controller authorizes the Processor to engage the following Sub-processors to process Customer Data. This list matches the sub-processor table in the Privacy Policy at saferinventory.com/privacy:

Sub-processorCountryData Processed
Supabase Inc.United States (AWS us-east-1)Primary database — all Customer Data
Vercel Inc.United States (global CDN)Web application hosting and delivery
Railway Corp.United StatesAPI server and CMS hosting
Clerk Inc.United StatesAuthentication tokens and session data
Stripe Inc.United StatesPayment card data and billing records
Cloudflare Inc.United StatesFile uploads (object storage via R2)
Resend Inc.United StatesTransactional and notification email content
Pusher Ltd.United KingdomReal-time chat data (LiveDesk)
Anthropic PBCUnited StatesAI processing of LiveDesk chat messages
Functional Software Inc. (Sentry)United StatesError context including user identifiers
PostHog Inc.United StatesUsage events and user properties (consent-gated)
Upstash Inc.United StatesIP addresses and session data (rate limiting)

6.2 Changes to Sub-processors

The Processor will provide at least 30 days' written notice (by email to the Controller’s account email address or via in-app notification) before adding or replacing a Sub-processor that processes Customer Data.

The Controller may object to a new Sub-processor in writing within the 30-day notice period. If the parties cannot reach agreement within 15 days of the objection, the Controller may terminate the Terms of Service without penalty within 30 days of the original objection, and the Processor will refund any prepaid fees for the unused portion of the subscription term on a prorated basis.

7. Cross-Border Transfers

Customer Data may be transferred to and processed in Canada and other countries, including the United States and the United Kingdom, by the Sub-processors listed in Section 6. The Processor does not represent that Customer Data is stored exclusively in Canada.

The Processor ensures that:

(a) All cross-border Sub-processor transfers are subject to contractual data protection obligations no less protective than those in this DPA (PIPEDA Schedule 1, Principle 4.1.3 — Accountability for Onward Transfers);

(b) Controllers subject to Quebec Law 25 may request a summary of Privacy Impact Assessments (PIAs) conducted for cross-border transfers to non-Quebec jurisdictions.

8. Controller Responsibilities

The Controller represents and warrants that:

(a) It has the authority to provide Customer Data to the Processor for processing under this DPA;

(b) It has provided all required notices and obtained all necessary consents under applicable law for the personal information included in Customer Data;

(c) It will use the Service only in compliance with applicable law, including privacy laws applicable to its own jurisdiction and industry.

9. Audit Rights

Upon the Controller’s written request (no more than once per calendar year), the Processor will:

(a) Provide a written response to a security questionnaire or provide the results of its most recent third-party penetration test or independent security assessment, subject to reasonable confidentiality obligations; or

(b) Provide documentation of its technical and organizational security measures as described in Section 5, and any remediation actions taken following security assessments.

The Processor conducts annual penetration testing and vulnerability assessments and maintains documented security policies and incident response procedures.

10. Data Subject Rights

The Processor will, to the extent technically feasible, assist the Controller in fulfilling its obligations to respond to requests from individuals exercising rights under PIPEDA or applicable provincial privacy law, including rights of access, correction, deletion, and portability.

The Controller is the primary party responsible for responding to Data Subject requests. Requests received directly by the Processor from Data Subjects will be forwarded to the Controller within five (5) business days. The Controller acknowledges that the 30-day PIPEDA response clock runs from when the Controller receives the forwarded request.

11. Duration and Termination

This DPA remains in effect for the duration of the Terms of Service. Upon expiry or termination of the Terms of Service:

(a) The Processor will cease processing Customer Data for the purpose of providing the Service;

(b) The Processor will make Customer Data available for export for 30 days;

(c) Thereafter, the Processor will securely delete Customer Data within 90 days, except to the extent retention is required by law (e.g., financial records retained under the Income Tax Act for six years);

(d) Sections 4 (Data Breach Notification), 7 (Cross-Border Transfers), and 9 (Audit Rights) survive termination to the extent they relate to events occurring during the term.

12. Liability

Each party’s liability under this DPA is subject to the limitations and exclusions set out in the Terms of Service. Nothing in this DPA shall limit a party’s liability for fraud, gross negligence, or wilful misconduct, or for Data Breaches caused by the Processor’s failure to maintain the security measures described in Section 5.

13. Governing Law

This DPA is governed by the laws of the Province of Ontario and the federal laws of Canada applicable therein, including PIPEDA and, where applicable, Quebec Law 25. Disputes under this DPA are subject to the jurisdiction clause in the Terms of Service.

14. Contact

Data processing inquiries and DPA requests:
Pistis Contracting Inc. (operating as Safer Inventory)
Privacy Officer / DPA Inquiries
legal@saferinventory.com
18 Strathearn Ave Unit 6B, Brampton, ON L6T 4X7, Canada