Data Processing Addendum
September 6, 2026
This Data Processing Addendum ("DPA") forms part of the Terms of Service, Enterprise Agreement, Order Form, or other written agreement (collectively, the "Agreement") between Made It Enterprises Inc. ("Provider", "we", "us", or "our") and the customer identified in the applicable Agreement ("Customer").
This DPA applies where Provider Processes Personal Information on behalf of Customer in connection with the Services.
Capitalized terms not defined in this DPA have the meanings given in the Agreement.
1. Purpose and Scope
1.1 Scope of Processing. This DPA governs Provider's Processing of Personal Information contained within Customer Data when Provider acts as a service provider, processor, or equivalent role on behalf of Customer.
1.2 Customer Responsibilities. The parties acknowledge that:
(a) Customer determines the purposes for which Customer Data is submitted to the Services;
(b) Provider Processes Customer Data solely for the purposes described in the Agreement and this DPA; and
(c) Customer remains responsible for ensuring it has all necessary rights, permissions, notices, consents, and lawful bases required for Provider to Process Personal Information through the Services.
1.3 Relationship to the Agreement. This DPA supplements the Agreement and does not replace it. If there is a conflict between this DPA and the Agreement regarding privacy or data processing obligations, this DPA will control to the extent of the conflict.
2. Definitions.
"Applicable Privacy Law" means privacy, data protection, cybersecurity, and data security laws applicable to the Processing of Personal Information under the Agreement, including:
the Personal Information Protection and Electronic Documents Act (Canada) ("PIPEDA");
applicable provincial privacy laws;
Quebec's Act Respecting the Protection of Personal Information in the Private Sector, as amended;
The GDPR, where applicable;
the UK GDPR, where applicable;
applicable U.S. state privacy laws; and
regulations and subordinate legislation enacted under such laws.
"EU GDPR" means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016, as amended or replaced from time to time, concerning the protection of natural persons with regard to the processing of personal data and the free movement of such data.
"GDPR" means, as applicable, the EU GDPR, the UK GDPR, or any other law, regulation, or legal framework commonly referred to as a General Data Protection Regulation that applies to the Processing of Personal Information under the Agreement.
"Personal Information" means information about an identified or identifiable individual, or any equivalent concept under Applicable Privacy Law.
"Process" or "Processing" means any operation performed on Personal Information, including collection, use, storage, organization, consultation, transmission, disclosure, deletion, retrieval, or destruction.
"Security Incident" means unauthorized access to, acquisition of, disclosure of, alteration of, loss of, or destruction of Personal Information processed by Provider.
"Subprocessor" means a third party engaged by Provider to Process Personal Information on Provider's behalf.
3. Roles of the Parties
3.1 Customer Role. Customer is responsible for determining the purposes and means of its use of the Services and acts as the controller, business, organization, or equivalent responsible party under Applicable Privacy Law.
3.2 Provider Role. Provider acts as:
(a) a processor under GDPR and UK GDPR;
(b) a service provider or contractor under applicable U.S. privacy laws; and
(c) a service provider acting on behalf of Customer under Canadian privacy laws.
3.3 No Sale or Advertising Use. Provider does not sell Customer Personal Information or share Customer Personal Information for cross-context behavioural advertising.
4. Subject Matter and Details of Processing
4.1 Processing Activities. Provider Processes Personal Information to provide, maintain, support, secure, improve, and operate the Services.
4.2 Categories of Individuals. Personal Information may relate to:
Authorized Users personnel;
Customer contractors, suppliers, and clients; and
Individuals, counterparties, business contacts, or signatories whose Personal Information is included in the contracts, agreements, and other documents used by Customer in the Services.
4.3 Categories of Personal Information. Personal Information may include:
names;
business contact information;
email addresses;
job titles;
contractual information;
workflow records;
audit logs;
authentication records;
IP addresses;
system activity logs; and
other Personal Information submitted by Customer.
4.4 Nature of Processing. Processing activities may include:
hosting;
storage;
retrieval;
indexing;
search;
workflow management;
document review;
AI-assisted analysis, including generation and the content of AI Outputs;
summarization;
reporting;
customer support;
security monitoring; and
maintenance of the Services.
4.5 Processing Duration. Provider will Process Personal Information during the Subscription Term, the thirty (30) day post-termination retrieval period described in the Agreement, and for any post-termination retention period permitted or required by Applicable Privacy Law.
5. Processing Instructions
5.1 Authorized Processing. Provider will Process Personal Information only:
(a) to provide and support the Services;
(b) in accordance with Customer's documented instructions as reflected through Customer's use of the Services;
(c) as required by law; or
(d) as otherwise authorized under the Agreement.
5.2 Unlawful Instructions. Provider will notify Customer if Provider determines that an instruction violates Applicable Privacy Law, unless prohibited by law.
6. Confidentiality
6.1 Personnel Confidentiality Obligations
Provider will ensure that personnel authorized to Process Personal Information are subject to confidentiality obligations or appropriate statutory duties of confidentiality consistent with the requirements of the Agreement and Applicable Privacy Law.
6.2 Access Restrictions. Provider will limit access to Personal Information to personnel who require access to perform their responsibilities.
7. Security Measures
7.1 Security Safeguards. Provider will maintain reasonable administrative, technical, and organizational safeguards designed to protect Personal Information against unauthorized access, disclosure, alteration, destruction, misuse, or loss that meet the requirements of Applicable Privacy Law. Without limiting the foregoing, Provider’s security measures will include those described in Schedule 3 of this DPA.
7.2 Changes to Security Measures. Provider may modify its security measures from time to time, provided that the overall level of protection is not materially diminished from that existing at the time the Agreement was first entered into between Provider and Customer.
8. Security Incidents.
8.1 Security Incident Notification. Provider will notify Customer without undue delay, and in any event within forty-eight (48) hours, after becoming aware of a confirmed Security Incident affecting Customer Personal Information.
8.2 Incident Information. To the extent reasonably available and subject to the requirements of Applicable Privacy Law, notification of a Security Incident will include:
the nature of the Security Incident;
affected categories of information;
the categories of individuals impacted;
a reasonable estimate of the impact on the impacted individuals on the information available about the Security Incident at the time of the notification;
steps taken to mitigate the incident; and
recommended actions, if any.
8.3 No Admission of Liability. Notification of a Security Incident does not constitute an admission of liability or fault.
9. Subprocessors
9.1 Authorization to Use Subprocessors. Customer authorizes Provider to engage the Subprocessors listed in Schedule 2 in connection with the Services.
9.2 Subprocessor Obligations. Provider may update Schedule 2 from time to time. Provider will provide Customer with reasonable prior notice of any new Subprocessor engaged to Process Personal Information on behalf of Customer, which may be provided by email, in-product notice, posting to a subprocessor webpage, or other reasonable means. Customer may object to the appointment of a new Subprocessor on reasonable data protection grounds by providing written notice within fifteen (15) days after receiving notice. If Customer objects, Provider will use commercially reasonable efforts to address the objection. If the parties are unable to resolve the objection, Customer may terminate the affected Services to the extent the new Subprocessor is required for those Services.
10. Cross-Border Transfers
10.1 Processing Locations. Customer acknowledges that Personal Information may be Processed in Canada, the United States, and other jurisdictions where Provider or its Subprocessors maintain facilities or personnel, subject to the transfer safeguards described in this DPA and Applicable Privacy Law.
10.2 Transfer Safeguards. Provider will implement reasonable contractual, technical, and organizational safeguards for cross-border transfers of Personal Information consistent with the requirements of Applicable Privacy Law and the terms of the Agreement.
10.3 Quebec Requirements. Where Personal Information subject to Quebec privacy law is communicated outside Quebec, Provider will implement measures reasonably designed to ensure that such information receives protection equivalent to that required under applicable Quebec privacy laws. Provider will conduct and maintain assessments of cross-border transfers where required by applicable Quebec privacy laws.
11. Assistance with Privacy Requests
11.1 Assistance with Rights Requests. Considering the nature of the Services, Provider will provide reasonable assistance to Customer in responding to privacy rights requests.
11.2 Direct Requests from Individuals. If Provider receives a request directly from an individual concerning Customer Data, Provider may direct the individual to Customer unless prohibited by law.
11.3 Governmental and Regulatory Requests. If Provider receives a legally binding request, order, subpoena, warrant, or similar demand from a governmental authority, regulator, court, or law enforcement agency seeking access to Customer Personal Information, Provider will, unless prohibited by law, promptly notify Customer and provide reasonable cooperation at Customer’s expense to enable Customer to seek a protective order, challenge the request, or otherwise respond to the request. Provider may disclose Customer Personal Information to the extent required by applicable law or a valid legal process. Provider may notify Customer of the request unless prohibited by law or where Provider determines that providing such notice would present a risk of harm to individuals or compromise an ongoing investigation.
12. Compliance Information and Audits
12.1 Compliance Information
Upon reasonable written request no more than once per calendar year, Provider will make available information reasonably necessary to demonstrate compliance with this DPA.
12.2 Audit Limitations. Any audit rights shall be exercised in a manner that:
minimizes operational disruption;
protects the confidentiality of other customers;
protects Provider Confidential Information; and
is subject to reasonable confidentiality obligations.
Provider is not obligated to provide Customer with access to Provider facilities, source code, systems, networks, Derived Data, or similar assets.
12.3 Alternative Audit Documentation. Provider may satisfy audit requests by providing security documentation, questionnaires, certifications, policies, reports, or similar materials.
13. Return and Deletion of Data
13.1 Customer Retrieval Rights. Customer may export Customer Data using available export functionality during the Subscription Term and any applicable post-termination retrieval period.
13.2 Deletion of Customer Data. Following expiration of applicable retention periods, Provider may securely delete Customer Data in accordance with Provider's retention practices and the terms of the Agreement.
13.3 Exceptions to Deletion. Provider is not required to delete:
backup data retained through standard business operations;
information required by law to be retained;
de-identified information; or
Derived Data authorized under the Agreement.
14. Additional U.S. Privacy Law Terms
14.1 Restrictions on Use of Personal Information. Provider will not:
(a) sell Customer Personal Information within the meaning of Applicable Privacy Law in the United States;
(b) share Customer Personal Information for cross-context behavioural advertising; or
(c) retain, use, or disclose Customer Personal Information other than for the purposes described in the Agreement and this DPA.
14.2 Provider Status. The parties acknowledge that Provider receives Personal Information solely for the purpose of providing the Services.
14.3 Applicability Thresholds. Nothing in this DPA requires Provider to comply with obligations that apply only to entities meeting statutory applicability thresholds that neither party satisfies.
15. Additional GDPR and UK GDPR Terms
15.1 Processor Obligations. Provider will Process Personal Information only on documented instructions from Customer, maintain appropriate security measures, ensure personnel are subject to confidentiality obligations, assist Customer with applicable data subject rights obligations where reasonably possible, and delete or return Personal Information upon termination, subject to lawful retention requirements.
15.2 Nature of Processing. The parties acknowledge that:
(a) the Services are designed primarily for business-to-business contract administration and workflow management;
(b) Provider does not intentionally Process special categories of personal data as a core function of the Services; and
(c) Provider does not engage in automated decision-making that produces legal or similarly significant effects on individuals.
15.3 Standard Contractual Clauses. Where required under GDPR or UK GDPR for an international transfer, the applicable Standard Contractual Clauses shall be deemed incorporated into this DPA.
16. AI Processing
16.1 AI Service Providers. The Services include AI-powered functionality and may involve the transmission of Customer Data to Subprocessors and service providers approved by Provider for the purpose of generating AI Outputs requested by Customer.
16.2 Model Training Restrictions. Provider will not knowingly use Customer Data to train public foundation models or permit third-party AI providers to use Customer Data for training Third-Party AI Models.
16.3 Customer Responsibility for AI Inputs. Customer remains responsible for determining whether information submitted to the Services is appropriate for processing through AI-assisted features.
16.4 Operational Telemetry and Service Improvement. Provider may collect operational telemetry, service performance data, usage information, and feedback necessary to maintain, secure, improve, and support the Services.
17. Limitation of Liability
17.1 Application of Liability Limitations. The liability limitations, exclusions, disclaimers, and allocation of risk contained in the Agreement apply to this DPA and are incorporated by reference.
18. Order of Precedence. In the event of a conflict, the following order will apply: (1) a signed Enterprise Agreement or negotiated amendment; (2) this DPA; the Terms of Service; and; (4) documents, policies, or other references incorporated into this DPA.
Schedule 1
Privacy Contact
Contact Information
Privacy Officer
Made It Enterprises Inc.
privacy@madeit.legal
Schedule 2 — Authorized Subprocessors
Current Approved Subprocessors
Amazon Web Services, Inc. (AWS)
Purpose
Cloud hosting and infrastructure
Storage and backup
Authentication and identity services
Monitoring and security services
AI and machine learning services through Amazon Bedrock
Related platform operations
Anthropic, PBC
Purpose
AI-powered document review
Information extraction
Summarization
Analysis
Related customer-requested AI functionality
Framer B.V.
Purpose
Website hosting and content delivery
Website form processing and lead capture
Customer inquiries and contact form submissions
Website performance monitoring
Website analytics and usage reporting
Related website operations
Google LLC
Purpose
Website analytics
Communications services
Productivity tools
Operational monitoring
Related support services
HubSpot, Inc.
Purpose
Customer relationship management
Customer communications
Support operations
Marketing administration
Analytics
Langfuse Cloud GmbH (or applicable Langfuse contracting entity)
Purpose
AI application observability
Prompt and output logging
AI quality assurance and evaluation
Performance monitoring and analytics
Error detection and troubleshooting
AI workflow optimization and service improvement
Microsoft Corporation
Purpose
Cloud infrastructure
Storage and backup
Authentication and identity services
Monitoring and security services
Related platform operations
OpenAI, LLC
Purpose
AI-powered document review
Information extraction
Summarization
Analysis
Related customer-requested AI functionality
Stripe, Inc.
Purpose
Payment processing
Billing administration
Fraud prevention
Transaction management
Schedule 3 — Security Measures
Provider maintains administrative, technical, and organizational safeguards designed to protect Personal Information against unauthorized access, disclosure, alteration, destruction, misuse, or loss.
Administrative Safeguards
Personnel confidentiality obligations.
Access management and user provisioning procedures.
Personnel onboarding and offboarding procedures.
Incident response and security event management processes.
Vendor and Subprocessor risk management practices.
Security awareness and privacy training.
Business continuity and disaster recovery procedures.
Periodic review and assessment of security risks and controls.
Documented information security policies and procedures.
Technical Safeguards
Encryption of Personal Information in transit using industry-standard protocols.
Encryption of Personal Information at rest where supported by applicable systems and services.
Role-based access controls and least-privilege permissions.
Authentication, authorization, and identity management controls.
Audit logging and security event monitoring.
Monitoring, alerting, and incident detection systems.
Vulnerability scanning, vulnerability management, and security testing practices.
Timely application of security patches and remediation measures.
Logical segregation of customer environments and data.
Secure software development lifecycle practices.
Change management and production deployment controls.
Backup, recovery, and restoration capabilities.
Endpoint security controls for workforce devices used to access production systems.
Network security controls designed to restrict unauthorized access to systems and data.
Measures designed to maintain service availability and operational resilience.
Organizational Safeguards
Least-privilege and need-to-know access principles.
Restricted access to production systems containing Personal Information.
Periodic review of user access rights and permissions.
Security review and oversight of third-party service providers and Subprocessors.
Periodic review and testing of security controls.
Data retention and secure deletion procedures.
Measures designed to limit access to and retention of Personal Information to what is reasonably necessary for authorized purposes.
Procedures designed to maintain the confidentiality, integrity, and availability of Personal Information.
Access controls and monitoring procedures for AI-enabled systems and services used in connection with the Services.
Policies restricting the use of Customer Data for training public foundation models except as expressly authorized by Customer or otherwise permitted under the Agreement.