ONTARIO® DATA PROCESSING AGREEMENT
Date: 07/01/2026
This Ontario Data Processing Agreement (this “DPA”) is entered into by and between Customer and Ontario Technologies, LLC and/or its applicable Affiliate identified in the applicable Order (“Ontario”), and is incorporated into and governed by the Ontario® Master Subscription and Services Agreement between the parties (the “Agreement”).
This DPA applies only to the extent Ontario processes Personal Data on behalf of Customer in connection with the Ontario Services. This DPA is an Ontario Policy incorporated into, and governed by, the Agreement. Capitalized terms used but not defined in this DPA have the meanings given in the Agreement, including the definitions applicable to Affiliate, Customer, Customer Data, Documentation, Excluded Data, Ontario Policies, Ontario Services, AI Output, Inputs, Order, Personal Data, Professional Services, Required Support, Security Incident, Software Subscription Services, Statement of Work or SOW, One-Time Services, and Subscription Term.
In the event of a conflict between this DPA and the Agreement, this DPA will control solely with respect to the processing of Personal Data covered by this DPA, as provided in Section 16 of the Agreement. Except as expressly modified by this DPA, the Agreement remains in full force and effect.
Nothing in this DPA relieves either party of its obligations under applicable data protection laws.
1.Scope and Applicability
a. Scope
This DPA governs Ontario’s processing of Personal Data on behalf of Customer in connection with the applicable Ontario Services.
Unless otherwise expressly stated in an applicable Order, this DPA applies only to Personal Data processed by Ontario as a processor or service provider on behalf of Customer in connection with the generally available production Software Subscription Services and, where applicable, related Professional Services or One-Time Services to the extent such services expressly involve Ontario’s processing of Personal Data on behalf of Customer.
This DPA does not expand Ontario’s obligations beyond those expressly stated in the Agreement, this DPA, and the applicable Ontario Policies.
b. Subject Matter, Duration, Nature, and Purpose of Processing
The subject matter, duration, nature, and purpose of processing under this DPA are as follows:
Subject Matter:
Ontario will process Personal Data on behalf of Customer solely as necessary to provide, operate, secure, support, maintain, and improve the Ontario Services for Customer, and as otherwise permitted by the Agreement, this DPA, and the applicable Ontario Policies.
Duration:
Ontario is authorized to process Personal Data for the duration of the applicable Subscription Term, and any period thereafter during which Ontario retains Personal Data in accordance with the Agreement, this DPA, and applicable law.
Nature of Processing:
Processing may include collection, receipt, access, hosting, storage, organization, structuring, adaptation, retrieval, consultation, use, transmission, disclosure by transfer, combination, restriction, deletion, destruction, and other processing activities reasonably necessary to provide the Ontario Services.
Purpose of Processing:
The purposes of processing are to provide the Ontario Services to Customer, including hosting and operating the Software Subscription Services, account administration, support, maintenance, troubleshooting, security, monitoring, backup and recovery, implementation, configuration, migration, and other agreed services, in each case as contemplated by the Agreement, applicable Orders, and applicable SOWs.
c. Categories of Data Subjects
Depending on Customer’s use of the Ontario Services, Personal Data may relate to:
- Customer’s employees, personnel, contractors, and Authorized Users;
- Customer’s customers, prospects, vendors, suppliers, and business contacts; and
- other individuals whose Personal Data is included in Customer Data submitted to the Ontario Services by or on behalf of Customer.
d. Categories of Personal Data
Depending on Customer’s use of the Ontario Services, Personal Data may include:
- business contact information;
- account and profile information;
- employment-related or professional information;
- business transaction data;
- communications data;
- AI Output and Customer Inputs
- usage data;
- support-related data; and
- other Personal Data included in Customer Data submitted by or on behalf of Customer.
For clarity, Customer shall not upload, submit, transmit, process, or store Excluded Data in the Software Subscription Services, and nothing in this DPA authorizes processing of Excluded Data.
2. Roles of the Parties
a. Customer as Controller / Business
As between the parties, Customer determines the purposes and means of the processing of Personal Data submitted to the Ontario Services by or on behalf of Customer and is responsible for ensuring that it has all rights, consents, permissions, and other lawful authority necessary for Ontario to process such Personal Data as contemplated by the Agreement and this DPA.
b. Ontario as Processor / Service Provider
To the extent applicable data protection laws apply to Ontario’s processing of Personal Data on behalf of Customer, Ontario will process such Personal Data as a processor, service provider, or similar role under applicable law, and only on Customer’s documented instructions as set forth in the Agreement, this DPA, applicable Orders and SOWs, Documentation, and Customer’s authorized use of the Ontario Services.
c. Compliance with Law
Each party will comply with the data protection laws applicable to it in connection with this DPA.
If Ontario determines that an instruction from Customer violates applicable data protection law, Ontario will promptly inform Customer to the extent legally permitted. The parties will cooperate in good faith to address the issue.
3. Customer Instructions
a. Documented Instructions
Customer instructs Ontario to process Personal Data to:
- provide, operate, secure, support, maintain, and improve the Ontario Services for Customer;
- perform processing initiated by Customer and its Authorized Users through their use of the Ontario Services;
- perform processing described in the Agreement, this DPA, applicable Orders, applicable SOWs, Documentation, and applicable Ontario Policies; and
- comply with other reasonable documented instructions from Customer that are consistent with the terms of the Agreement and applicable law.
b. Limits on Instructions
Ontario is not required to comply with any instruction that would:
- violate applicable law;
- conflict with the Agreement, this DPA, or applicable Ontario Policies;
- require Ontario to process Excluded Data;
- materially alter the nature or scope of the Ontario Services without mutual written agreement; or
- impose obligations on Ontario beyond those expressly agreed by the parties.
To the extent Customer requests assistance or measures beyond those required by this DPA, Ontario may provide such assistance as Professional Services or One-Time Services at Ontario’s then-current rates, if the parties so agree.
4. Ontario Personnel and Confidentiality
Ontario will ensure that persons authorized to process Personal Data are subject to appropriate confidentiality obligations and are bound to protect Personal Data in accordance with the Agreement, this DPA, and applicable law.
Ontario will restrict access to Personal Data to personnel, contractors, and subprocessors who have a legitimate need to know such Personal Data for purposes consistent with the Agreement and this DPA.
5. Security of Processing
a. Security Measures
Taking into account the state of the art, the costs of implementation, the nature, scope, context, and purposes of processing, and the risks to individuals, Ontario will implement and maintain commercially reasonable administrative, technical, organizational, and physical safeguards designed to protect Personal Data, as described in the Agreement and the Ontario InfoSec Standard Policy.
The Ontario InfoSec Standard Policy is incorporated into this DPA by reference as a description of Ontario’s security measures applicable to the relevant Ontario Services.
b. No Absolute Security Guarantee
Nothing in this DPA or the Ontario InfoSec Standard Policy constitutes a guarantee that the Ontario Services will be uninterrupted, error-free, or completely secure. Ontario’s obligations are subject to the exclusions, limitations, and allocation of responsibilities set forth in the Agreement, this DPA, and the applicable Ontario Policies.
c. Customer Security Responsibilities
Customer acknowledges and agrees that Customer remains responsible for:
- the content, quality, integrity, legality, accuracy, and permitted use of Customer Data;
- maintaining the security of Customer-controlled systems, devices, credentials, configurations, and access methods;
- implementing reasonable internal administrative, technical, and organizational safeguards appropriate to Customer’s use of the Ontario Services;
- reviewing and following the Documentation and applicable Ontario Policies; and
- providing all Required Support reasonably requested by Ontario.
6. Subprocessors
a. Authorization
Customer generally authorizes Ontario to engage Affiliates, subcontractors, cloud providers, hosting providers, model providers, and other service providers as subprocessors in connection with the provision of the Ontario Services, consistent with the Agreement.
b. Subprocessor Obligations
Where Ontario engages a subprocessor to process Personal Data on behalf of Customer, Ontario will impose contractual obligations on the subprocessor that are materially consistent with Ontario’s applicable obligations under this DPA with respect to the protection of such Personal Data.
c. Responsibility
Ontario remains responsible for the performance of its obligations under this DPA notwithstanding its use of subprocessors, to the extent required by applicable law and subject to the Agreement’s liability framework.
d. Changes to Subprocessors
Ontario may update its subprocessors from time to time in the ordinary course of business. Upon Customer’s written request, Ontario will provide information regarding relevant subprocessors, subject to confidentiality, security, and third-party restrictions.
If applicable law requires a notice-and-objection process for new subprocessors, Ontario will provide notice in a commercially reasonable manner, and the parties will work in good faith to address any reasonable written objection by Customer based on legitimate data protection concerns. If the parties cannot resolve the objection, either party may terminate the affected Ontario Services to the extent directly impacted by the proposed subprocessor change, subject to the Agreement.
7. Assistance with Data Subject Requests
Taking into account the nature of the processing, Ontario will provide commercially reasonable assistance to Customer, through appropriate technical and organizational measures where feasible, to enable Customer to respond to requests from individuals exercising their rights under applicable data protection laws.
If Ontario receives a request directly from an individual relating to Personal Data processed by Ontario on behalf of Customer, Ontario may direct the individual to Customer and will notify Customer of the request to the extent legally permitted. Ontario will not respond to such request except:
- on Customer’s documented instruction;
- as required by applicable law; or
- as otherwise permitted under the Agreement.
Customer is responsible for responding to data subject requests and for verifying that any requestor is entitled to exercise the relevant rights.
8. Security Incidents and Personal Data Breaches
a. Notification
Ontario shall notify Customer without undue delay after becoming aware of any unauthorized access to Customer’s account or any Security Incident affecting Customer Data, as provided in the Agreement.
To the extent a Security Incident involves Personal Data processed by Ontario on behalf of Customer and subject to this DPA, Ontario will provide information reasonably available to Ontario and reasonably necessary for Customer to understand the nature of the incident and meet any notification obligations under applicable data protection laws.
b. Mitigation and Cooperation
Ontario will use commercially reasonable efforts to contain, investigate, mitigate, and remediate the effects of a Security Incident, as provided in the Agreement, the Ontario InfoSec Standard Policy, and this DPA.
Customer will provide all Required Support reasonably requested by Ontario in connection with investigating, containing, mitigating, or remediating the Security Incident.
c. No Admission
Ontario’s notification of or response to a Security Incident does not constitute an admission of fault or liability.
9. Assistance with DPIAs and Regulatory Cooperation
Taking into account the nature of processing and the information available to Ontario, Ontario will provide commercially reasonable assistance to Customer with data protection impact assessments, transfer impact assessments, prior consultations, or similar regulatory assessments that Customer is required to perform under applicable data protection laws, to the extent such assistance relates to Ontario’s processing of Personal Data under this DPA.
Ontario may satisfy its obligations under this Section by providing documentation, summaries, audit materials, security information, or other information made available under the Agreement, the Ontario InfoSec Standard Policy, or this DPA, subject to confidentiality, security, and third-party restrictions.
To the extent Customer requests assistance beyond Ontario’s standard obligations, Ontario may provide such assistance as billable Professional Services or One-Time Services.
10. Audit and Compliance Information
a. Compliance Information
Ontario will make available to Customer information reasonably necessary to demonstrate Ontario’s compliance with this DPA, including by providing appropriate summary information or selected materials concerning relevant security reviews, assessments, certifications, or audits, subject to confidentiality obligations, access controls, nondisclosure requirements, and third-party restrictions.
b. Audit Limitations
Nothing in this DPA obligates Ontario to disclose information that would compromise the security of the Ontario Services, other customers, Ontario’s systems, or any third-party environment, or that Ontario is prohibited from disclosing by contract, law, or security policy.
c. Customer Audits
To the extent applicable data protection laws require audit rights beyond the materials described above, any such audit shall:
- be upon reasonable prior written notice;
- occur no more than once annually, unless required by a regulator or following a confirmed Security Incident materially affecting Personal Data;
- be conducted during normal business hours;
- be limited in scope to matters relevant to Ontario’s processing of Personal Data under this DPA;
- be subject to Ontario’s reasonable confidentiality, security, and operational requirements;
- not unreasonably interfere with Ontario’s business operations or the services provided to other customers; and
- be conducted by Customer or an independent auditor not reasonably unacceptable to Ontario and bound by written confidentiality obligations.
Customer shall bear its own costs of any audit unless otherwise required by applicable law. Ontario may satisfy an audit request through recent third-party audit reports, certifications, or comparable independent assessments where appropriate.
11. International Transfers
a. General
Customer acknowledges that Ontario is based in the United States and may process Personal Data in the United States and other jurisdictions where Ontario, its Affiliates, subprocessors, or service providers operate.
To the extent Ontario transfers Personal Data subject to applicable cross-border transfer restrictions, Ontario will implement an appropriate transfer mechanism recognized under applicable data protection law.
b. EEA / Switzerland Transfers
For transfers of Personal Data subject to the EU GDPR from the EEA, or subject to the Swiss Federal Act on Data Protection from Switzerland, to a country not recognized as providing an adequate level of protection, the parties incorporate by reference the European Commission Standard Contractual Clauses, Module Two (Controller to Processor), or Module Three (Processor to Processor), as applicable (the “EU SCCs”).
For purposes of the EU SCCs:
- the applicable module will be determined based on the parties’ roles for the relevant processing;
- Clause 7 (Docking Clause) is optional and will apply if needed to permit additional parties to accede;
- in Clause 9, Option 2 (general written authorization) applies, subject to Section 6 of this DPA;
- Clause 11 optional language does not apply unless otherwise required by law;
- Clause 17 will specify the law of Ireland;
- Clause 18 will specify the courts of Ireland; and
- the annex information required by the EU SCCs will be deemed completed using the information set out in this DPA, the Agreement, and any applicable Order.
c. UK Transfers
For transfers of Personal Data subject to the UK GDPR from the United Kingdom to a country not recognized as adequate under UK law, the parties incorporate by reference the UK International Data Transfer Addendum to the EU SCCs (the “UK Addendum”).
The tables in the UK Addendum will be deemed completed using the information in this DPA, the Agreement, and any applicable Order, and the governing law and forum for the UK Addendum will be England and Wales, to the extent required by the UK Addendum.
d. Priority
To the extent there is a conflict between the EU SCCs or the UK Addendum, on the one hand, and this DPA or the Agreement, on the other hand, the EU SCCs or UK Addendum will control solely with respect to the applicable restricted transfer.
12. Return, Deletion, and Retention
a. Return or Deletion
Upon expiration or termination of the applicable Order, or upon termination of the applicable Ontario Services to which the relevant Customer Data relates, Ontario will return or delete Customer Data, including Personal Data, in accordance with Section 4 of the Agreement and subject to Customer’s timely written direction, technical limitations, and payment of applicable fees.
b. Retention
Notwithstanding the foregoing, Ontario may retain Personal Data:
- as required by applicable law;
- for routine backup, disaster recovery, archival, legal hold, compliance, or recordkeeping purposes;
- as otherwise expressly permitted under the Agreement; or
- in secure backup media for the periods described in the Agreement and Ontario InfoSec Standard Policy.
Any retained Personal Data will remain protected under the Agreement and this DPA for so long as retained.
c. Residual Copies
Customer acknowledges that backup copies may remain in secure backup media after deletion from the production environment and may be overwritten, deleted, or rendered inaccessible in the ordinary course of Ontario’s retention practices, subject to applicable law, legal hold requirements, and the Agreement.
13. Excluded Data
Customer shall not upload, submit, transmit, process, or store any Excluded Data in the Software Subscription Services. The Ontario Excluded Data Policy is incorporated into this DPA by reference.
If Excluded Data is provided to Ontario or introduced into the Ontario Services, Ontario may take actions permitted under the Agreement and the Ontario Excluded Data Policy, including removing, deleting, quarantining, blocking, disabling access to, or requiring Customer to remove the Excluded Data.
Ontario is not obligated to accept, host, process, remediate, segregate, return, export, or preserve Excluded Data except to the extent expressly agreed in writing.
14. Relationship to Other Ontario Policies
This DPA supplements, and should be read together with, the Agreement and applicable Ontario Policies, including:
- the Ontario InfoSec Standard Policy;
- the Ontario Support and SLA Policy;
- the Ontario Excluded Data Policy; and
- the Ontario Customer Platform Development Policy.
For clarity:
- the Ontario InfoSec Standard Policy describes Ontario’s security program and safeguards;
- the Ontario Support and SLA Policy governs support channels, support obligations, severity levels, response targets, availability commitments, and support exclusions;
- the Ontario Excluded Data Policy governs prohibited data categories and related operational responses; and
- the Ontario Customer Platform Development Policy governs ownership, classification, and treatment of customer-specific items, but does not expand Ontario’s data protection obligations beyond the Agreement and this DPA.
Nothing in this DPA expands Ontario’s support, service level, warranty, indemnity, or other obligations beyond those expressly stated in the Agreement and applicable Ontario Policies.
15. Liability
This DPA does not alter the parties’ disclaimers, exclusions, indemnities, or limitations of liability under the Agreement, except to the extent prohibited by applicable law.
16. Term
This DPA will become effective on the effective date of the applicable Order incorporating the Agreement, or such other effective date as the parties may specify in writing, and will remain in effect for so long as Ontario processes Personal Data on behalf of Customer under the Agreement.
17. Miscellaneous
a. Governing Law
Except to the extent the EU SCCs or UK Addendum require otherwise for purposes of those transfer mechanisms, this DPA will be governed by the law governing the Agreement.
b. Severability
If any provision of this DPA is held unenforceable, the remaining provisions will remain in full force and effect.
c. Amendments for Legal Compliance
The parties will cooperate in good faith to amend this DPA as reasonably necessary to address changes in applicable data protection laws or recognized transfer mechanisms, provided that no amendment will materially diminish Customer’s rights or materially increase Customer’s obligations during the then-current Subscription Term except as required by law or mutually agreed.
ONTARIO® DATA PROCESSING AGREEMENT
SCHEDULE 1 – DESCRIPTION OF PROCESSING
SCHEDULE 1 – DESCRIPTION OF PROCESSING
This Schedule 1 forms part of the DPA.
A. List of Parties
Data Exporter / Controller / Business:
Customer, as identified in the applicable Order.
Data Importer / Processor / Service Provider:
Ontario Technologies, LLC and/or its applicable Affiliate identified in the applicable Order.
B. Categories of Data Subjects
- Customer personnel and Authorized Users
- Customer customers and prospects
- Customer vendors, suppliers, and business contacts
- Other individuals whose Personal Data is included in Customer Data
C. Categories of Personal Data
- Names and business contact details
- User and account information
- Employment or professional information
- Business records and transaction-related information
- Communications and support information
- Usage and activity information
- User AI Output or Inputs
- Other Personal Data included in Customer Data
D. Sensitive Data / Special Categories
The parties do not intend for Customer to submit special category data, highly sensitive regulated data, or other Excluded Data into the Software Subscription Services unless expressly authorized in a signed Order and supported by supplemental written terms. Customer shall not upload or submit Excluded Data.
E. Frequency of Transfer
Continuous, on a rolling basis, as initiated by Customer and its Authorized Users in connection with use of the Ontario Services.
F. Nature of the Processing
Collection, storage, hosting, organization, retrieval, use, disclosure by transmission, support access, analysis, backup, deletion, and other processing reasonably necessary to provide the Ontario Services.
G. Purpose of the Transfer and Processing
To provide, operate, secure, support, maintain, and improve the Ontario Services for Customer and to perform related obligations under the Agreement.
H. Retention
For the duration described in the Agreement and this DPA, including any permitted post-termination retention in backups, archives, or legally required records.
ONTARIO® DATA PROCESSING AGREEMENT
SCHEDULE 2 – TECHNICAL AND ORGANIZATIONAL MEASURES
SCHEDULE 2 – TECHNICAL AND ORGANIZATIONAL MEASURES
Ontario will maintain commercially reasonable administrative, technical, organizational, and physical safeguards as described in the Agreement and the Ontario InfoSec Standard Policy, including measures relating, as appropriate, to:
- information security governance and risk management;
- access control and least-privilege practices;
- personnel confidentiality and security awareness;
- logging, monitoring, and incident management;
- network and endpoint security;
- vulnerability management and patching;
- change management and secure development practices;
- backup, recovery, and business continuity; and
- physical and environmental security.
The Ontario InfoSec Standard Policy is incorporated by reference as the primary description of Ontario’s technical and organizational measures.
