Legal Framework
Data Processing Addendum (DPA)
Last Modified: June 18, 2026
This Data Processing Addendum (“DPA”) is entered into and made part of the Agreement by and between PMG Consulting (“PMG”) and the Client (the “Client”), and shall govern the Processing of Personal Data by PMG in the course of providing access to and use of the the PMG App Suite (the “Service”). This DPA shall apply to the extent that PMG processes Personal Data on behalf of the Client in connection with the Agreement.
1. Definitions
For purposes of this DPA:
(a) “Personal Data” means any information relating to an identified or identifiable natural person, as such terms may be defined under applicable data protection laws, which PMG processes on behalf of the Client in connection with the Service.
(b) “Processing” means any operation or set of operations performed upon Personal Data, whether or not by automatic means, including but not limited to collection, recording, organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination, alignment, combination, restriction, erasure, or destruction.
(c) “Controller” refers to the Client, which determines the purposes and means of Processing Personal Data.
(d) “Processor” refers to PMG, which processes Personal Data on behalf of the Client.
(e) “Sub-Processor” means any third party engaged by PMG to process Personal Data in connection with the Service.
Unless otherwise defined herein, capitalized terms have the meanings ascribed in the Agreement.
2. Processing of Personal Data
PMG shall process Personal Data solely on behalf of, and in accordance with, the documented instructions of the Client, as outlined in the Agreement and this DPA. PMG shall not process Personal Data for any purpose other than as reasonably necessary to provide, maintain, and improve the Service, or as required by applicable law. PMG shall not sell, lease, or otherwise disclose Personal Data for its own commercial advantage.
Where PMG reasonably determines that an instruction from the Client infringes applicable law, PMG shall promptly notify the Client.
3. Sub-Processing
PMG may engage Sub-Processors to perform Processing activities in support of the Service. PMG shall ensure that any Sub-Processor is bound by a written agreement imposing data protection obligations no less protective than those contained in this DPA.
PMG shall, upon written request, provide the Client with a current list of Sub-Processors used to process Personal Data in connection with that Client’s use of the Service, and shall notify the Client of any intended changes to such list. The Client may object to such changes on reasonable grounds relating to data protection; provided, however, that if the Client objects and the parties cannot reach an agreement, PMG may terminate the portion of the Service affected without liability or refund.
For avoidance of doubt, PMG uses Google AI and GenKit AI as Sub-Processors to provide certain functionality within the Service. Such Sub-Processors are bound by agreements no less protective than those contained in this DPA. PMG shall provide notification of any material changes to its list of Sub-Processors, including AI technology providers, in accordance with this Section.
PMG remains responsible for selecting and engaging Sub-Processors under appropriate data protection agreements to the extent reasonably practicable, but is not liable for the independent failures or omissions of any Sub-Processor in performing their obligations.
4. Security Measures
PMG shall implement and maintain appropriate technical and organizational measures to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. These measures include, at a minimum:
- Encryption of Personal Data in transit and at rest, where technically feasible;
- Access controls and multi-factor authentication for personnel accessing Personal Data;
- Monitoring, logging, and auditing of system activity;
- Personnel confidentiality obligations;
- Review and update of security measures at least annually or upon significant Service changes; and
- With respect to support tickets or similar submissions made through Clarity Lite, no public-facing link to such a submission shall be generated or made accessible until authorized PMG personnel have manually reviewed the submission for Personal Data and confirmed that all such Personal Data has been redacted or that the submission is otherwise safe for public disclosure.
5. Data Transfers
PMG is a globally distributed organization and may process or access Personal Data from multiple regions in the course of providing the Service. While PMG does not typically store client data directly, personnel engaged in providing the Service may access Personal Data as needed.
PMG may use third-party service providers, including but not limited to Google (Firebase, Gemini, Workspace), Amazon (AWS), Microsoft (Office, web services), and others, to host or process data. PMG does not control the physical location of data storage by these providers, but PMG will, where feasible, direct Sub-Processors to store Personal Data in Canada, or alternatively in the United States.
Where Personal Data is transferred outside of Canada, PMG shall implement appropriate safeguards consistent with applicable data protection laws, including contractual protections such as Standard Contractual Clauses, Binding Corporate Rules, or other adequate safeguards consistent with applicable law.
6. Assistance with Data Subject Rights
To the extent the Client is required under applicable law to respond to requests from data subjects relating to rights of access, rectification, erasure, restriction, portability, or objection, PMG shall provide assistance only to the extent reasonably necessary to allow the Client to comply, at the Client’s expense.
PMG shall respond to requests sent to PMG’s DPO by email within 30 days of receipt. This timeframe begins only when the request is received by the DPO; no notice or request sent to any other person or contact at PMG will trigger a response. PMG will not forward requests internally, create new reports, or undertake actions beyond what is required to provide basic assistance, such as confirming data existence or providing standard access logs.
Where PMG receives a request directly from a data subject, PMG shall, to the extent legally permissible, promptly forward such request to the Client without responding directly.
7. Data Breach Notification
In the event of a confirmed Personal Data breach, PMG shall notify the Client within 72 hours of becoming aware of such breach. Such notification shall include information reasonably available to PMG at the time, including the nature of the breach, categories of data affected, and any remedial measures undertaken or proposed.
PMG will fulfil its reporting and disclosure obligations only to the maximum extent required under applicable law. PMG shall reasonably cooperate with the Client in any regulatory investigation or inquiry related to the breach, including providing information or assistance as legally permissible, but shall not be required to make any disclosure beyond what is mandated by applicable law.
Such notification or cooperation shall not constitute an admission of liability or fault by PMG.
8. Return or Deletion of Data
Upon termination or expiration of the Agreement, PMG shall, at the written direction of the Client, return or securely delete all Personal Data, except to the extent retention is required by applicable law or necessary to protect PMG's legitimate legal interests. In no event shall Personal Data (including Identity Data) be retained longer than sixty (60) days after the completion of the legitimate business purpose for which it was collected. Aggregated or anonymized data, which does not identify the Client or its data subjects, may be retained indefinitely.
With respect to support tickets submitted through Clarity Lite, PMG shall automatically remove the submitter's name, email address, and phone number from a ticket no later than sixty (60) days after that ticket's status is changed to "Closed." Following such removal, the ticket and its associated content may be retained, including for migration into the full Clarity application upon its launch, provided that: (i) the submitter may request access to the ticket's content by providing the ticket number together with identifying details about the ticket's subject matter sufficient for PMG to locate and verify the correct record; and (ii) PMG may, at its discretion, provide a redacted version of the ticket in response to such a request. For clarity, this mechanism constitutes removal of direct identifiers and not anonymization, and PMG shall continue to treat such tickets as containing Personal Data for so long as the submitter or PMG retains the practical ability to relink the ticket to an identifiable individual.
9. Audit Rights
PMG operates entirely remotely and maintains no central physical offices. As such, all audit requests will be fulfilled through remote access to relevant documentation, reports, system logs, and attestations. Physical inspections of PMG personnel or offices are not applicable. Audits are limited to reviewing PMG’s policies, procedures, and technical measures implemented to protect Personal Data, records demonstrating compliance with this DPA and applicable data protection laws, and documentation or attestations from Sub-Processors regarding their compliance with data protection obligations. PMG relies on third-party Sub-Processors, including Google, AWS, and Microsoft, to provide infrastructure and services. Audit rights do not extend to the physical facilities of these Sub-Processors; where applicable, PMG will provide independent audit reports, certifications, or attestations from Sub-Processors, such as SOC 2 or ISO 27001 reports, to satisfy the Client’s audit requirements.
Clients may request an audit no more than once per calendar year, provided at least thirty (30) days’ written notice is given. All audits will be conducted remotely and in a manner that avoids disruption to PMG’s operations. In rare circumstances where regulatory requirements necessitate verification at a Sub-Processor facility, PMG will coordinate access through the Sub-Processor and provide supporting documentation to the extent legally permissible, while PMG’s personnel or remote operations themselves remain exempt from on-site inspection. PMG will reasonably cooperate with the Client to demonstrate compliance, including providing documentation, reports, and evidence of Sub-Processor obligations, but will not be required to disclose confidential methods, internal trade secrets, or information beyond what is necessary to verify compliance. To the extent this section conflicts with other provisions of the Agreement, it shall control solely with respect to the Processing of Personal Data.
For clarity, this Section 9 shall supersede any conflicting audit provisions in the Agreement.
10. Governing Law and Jurisdiction
This Agreement shall be governed exclusively by and construed in accordance with the laws of the Province of Ontario, Canada, without regard to conflict of law principles. Any dispute, controversy, or claim arising out of or relating to this Agreement shall be submitted to binding arbitration in Ontario, conducted in accordance with the arbitration rules of the province then in effect. The party initiating the arbitration shall bear the costs of the arbitration. The decision of the arbitrator shall be final and binding, and judgment may be entered upon it in any court of competent jurisdiction.
11. Order of Precedence
This DPA shall be deemed incorporated into and form part of the Agreement. In the event of any conflict between the terms of the Agreement and this DPA, the provisions of this DPA shall control solely with respect to the Processing of Personal Data.