Data Processing Agreement
Updated: October 7, 2026
In brief
- This DPA governs how Flatoutserver processes personal data on behalf of clients in the course of an engagement.
- Flatoutserver acts as a processor; the client remains the controller of any personal data provided.
- Sub-processors are AWS Canada (hosting) and FormSubmit.co (form processing); 30 days' notice is given before adding new sub-processors.
- Data breaches are notified to the client within 72 hours of discovery.
- All data is deleted or returned within 30 days of engagement end; accounting records are kept 7 years.
1. Subject and Scope
This Data Processing Agreement ("DPA") sets out the terms under which 9357-2841 Ontario Inc. o/a Flatoutserver ("Flatoutserver") processes personal data on behalf of its clients ("Client") in connection with the provision of journalism and media services described in the applicable engagement confirmation or statement of work.
This DPA forms part of the agreement between Flatoutserver and the Client and supplements the Terms of Service. In the event of any conflict between this DPA and the Terms of Service with respect to the processing of personal data, the provisions of this DPA shall prevail.
This DPA applies only where Flatoutserver processes personal data that belongs to, or is provided by, the Client. It does not apply to personal data that Flatoutserver collects directly from individuals through its own website or services for its own purposes (which is governed by the Privacy Policy).
This DPA is governed by Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), S.C. 2000, c. 5, and any other applicable provincial privacy legislation.
2. Definitions
For the purposes of this DPA, the following definitions apply:
- Controller
- The organisation or individual that determines the purposes and means of processing personal data. The Client is the Controller of personal data it provides to Flatoutserver.
- Processor
- An organisation or individual that processes personal data on behalf of, and under the instructions of, a Controller. Flatoutserver acts as Processor when processing personal data provided by the Client.
- Personal Data
- Any information about an identifiable individual, as defined in PIPEDA. This includes, but is not limited to, names, contact details, identification numbers, location data, and any other information that can be used directly or indirectly to identify a natural person.
- Processing
- Any operation or set of operations performed on personal data, including collection, organisation, storage, use, disclosure, and deletion.
- Data Breach
- Any accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored, or otherwise processed, as contemplated under PIPEDA and applicable breach reporting obligations.
- Sub-Processor
- Any third party engaged by Flatoutserver to process personal data on behalf of the Client.
3. Roles
When Flatoutserver processes personal data provided by the Client in the course of an engagement:
- The Client acts as Controller and retains responsibility for determining the lawful basis for processing and for complying with applicable privacy law with respect to the personal data provided.
- Flatoutserver acts as Processor and processes personal data only on the documented instructions of the Client, solely for the purposes of performing the agreed engagement.
The Client warrants that: (a) it has a lawful basis to share personal data with Flatoutserver; (b) the personal data it provides is accurate and up to date; and (c) it has obtained any necessary consents or authorisations for the processing described in this DPA.
Where Flatoutserver processes personal data for its own administrative purposes (e.g., billing, accounting), Flatoutserver acts as Controller with respect to that data, and the Privacy Policy applies.
4. Processing Instructions
Flatoutserver shall process personal data only on the written instructions of the Client, unless otherwise required by applicable law. Processing instructions must be provided in writing (including by email) and must be limited to the scope of the applicable engagement.
Flatoutserver shall inform the Client if, in its reasonable opinion, an instruction infringes applicable privacy law. In such cases, Flatoutserver may suspend processing pending written clarification from the Client.
Flatoutserver shall not process personal data for any purpose other than as instructed by the Client, and shall not disclose personal data to any third party without the Client's written consent, except as provided in this DPA with respect to authorised Sub-Processors or as required by applicable law.
All staff members of Flatoutserver who access personal data in connection with an engagement are subject to confidentiality obligations that survive the termination of their engagement or employment.
5. Sub-Processors
The Client grants Flatoutserver general authorisation to engage the following sub-processors, subject to the conditions set out in this Article:
-
Amazon Web Services Canada
120 Bremner Boulevard, Suite 2000
Toronto, Ontario M5J 0A8, Canada
Purpose: website hosting and infrastructure; personal data stored in Canada. -
FormSubmit.co
United States of America
Purpose: contact form processing; personal data transmitted to the USA with adequate protections.
Note: FormSubmit.co is used only for transmitting contact form submissions to Flatoutserver. Data is not retained by FormSubmit.co for its own purposes beyond what is necessary for transmission.
Flatoutserver shall provide the Client with at least thirty (30) days' advance written notice before engaging any new sub-processor or materially changing the role of an existing sub-processor. The Client may object to a new sub-processor within the notice period by providing written notice to Flatoutserver. In the event of a sustained objection, the Parties will work in good faith to find a reasonable solution; if no solution is found, the Client may terminate the relevant engagement with reasonable written notice.
Flatoutserver ensures that each sub-processor is bound by data processing obligations at least as protective as those set out in this DPA.
6. Data Subject Rights
Flatoutserver shall assist the Client in fulfilling its obligations to respond to requests by individuals exercising their rights under PIPEDA, including the right of access, the right to correction, and the right to withdraw consent.
When Flatoutserver receives a request directly from an individual relating to personal data processed on behalf of the Client, Flatoutserver shall promptly notify the Client and shall not respond to the request directly unless authorised to do so by the Client or required by applicable law.
Flatoutserver shall cooperate with the Client to respond to verified data subject requests within thirty (30) days of receipt, in accordance with PIPEDA requirements. If Flatoutserver requires additional time, it will notify the Client within the initial 30-day period.
7. Data Security
Flatoutserver implements and maintains appropriate technical and organisational security measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access, including:
- TLS encryption for all data transmitted over the internet, including form submissions and email communications containing personal data.
- Access controls limiting access to personal data to staff members who require such access to perform the engagement.
- Staff confidentiality obligations binding all persons who access personal data in connection with an engagement.
- Maximum retention limit of twenty-four (24) months for working files and engagement records, after which personal data is securely deleted, subject to applicable legal retention requirements (see Article 9).
Flatoutserver will periodically review and update these security measures to reflect current best practices and to address newly identified risks.
8. Data Breaches
In the event that Flatoutserver becomes aware of a confirmed data breach involving personal data processed on behalf of the Client, Flatoutserver shall notify the Client within seventy-two (72) hours of becoming aware of the breach.
The notification shall include, to the extent available at the time:
- A description of the nature of the breach, including the categories and approximate number of individuals and records affected.
- The name and contact details of the person who can provide further information.
- A description of the likely consequences of the breach.
- A description of the measures taken or proposed to address the breach, including steps to mitigate its possible adverse effects.
Flatoutserver shall cooperate with the Client in any required reporting to the Office of the Privacy Commissioner of Canada (OPC) or any other regulatory authority. The Client, as Controller, is responsible for determining whether a breach must be reported to the OPC and for making any required notifications to affected individuals.
9. Term and Deletion
This DPA remains in force for the duration of any engagement to which it applies and for as long as Flatoutserver retains personal data provided by the Client.
Upon the termination or expiration of an engagement, Flatoutserver shall, at the Client's election and upon written request, either:
- Return to the Client all personal data provided by the Client in a commonly used electronic format; or
- Securely delete or destroy all such personal data.
Such return or deletion shall be completed within thirty (30) days of the end of the engagement, unless otherwise required by applicable law. Flatoutserver will provide written confirmation of deletion upon request.
Notwithstanding the above, Flatoutserver may retain personal data contained in accounting and billing records for a minimum period of seven (7) years from the date of the final invoice, as required under applicable tax legislation. Such retained records are protected in accordance with this DPA and are used only for accounting and legal compliance purposes.
10. Governing Law
This DPA is governed by and shall be construed in accordance with the laws of the Province of Ontario and the applicable federal laws of Canada, including the Personal Information Protection and Electronic Documents Act (PIPEDA).
Any dispute arising out of or in connection with this DPA shall be subject to the exclusive jurisdiction of the Ontario Superior Court of Justice, sitting in the City of Ottawa, Ontario, Canada.
For any questions regarding this DPA, or to execute a customised written DPA for a specific engagement, please contact:
Flatoutserver - Data Protection218 Bank Street, Suite 205
Ottawa, Ontario K1P 1C2, Canada
Email: hello@flatoutserver.com
Phone: (613) 555-0192