Motivra OS — Data Processing Addendum
Version: 1.0
Effective date: [YYYY-MM-DD]
This Data Processing Addendum (“DPA”) forms part of the agreement between Strategies Beyond Limits (“Provider” or “Processor”) and the customer named on an Order Form (“Customer” or “Controller”) for the Motivra OS service (the “Service”), including the Terms of Service (the “Agreement”).
If there is a conflict between this DPA and the Agreement regarding the processing of Personal Information in Customer Data, this DPA controls.
1. Definitions
“Applicable Privacy Law” means privacy and data-protection laws applicable to the processing of Personal Information under this DPA, including Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) and substantially similar provincial laws, and applicable U.S. state privacy laws to the extent they apply to the parties’ roles.
“Customer Data” has the meaning in the Terms of Service.
“Personal Information” means information about an identifiable individual (or “personal information” / “personal data” as defined under Applicable Privacy Law) contained in Customer Data.
“Processing” means any operation performed on Personal Information, including collection, storage, use, disclosure, transmission, and deletion.
“Subprocessor” means a third party engaged by Provider to Process Personal Information on behalf of Customer in connection with the Service.
Other capitalized terms have the meanings in the Agreement.
2. Roles of the parties
2.1 Customer determines the purposes and means of Processing Personal Information in Customer Data and is the controller (or “organization” / “business,” as applicable).
2.2 Provider Processes Personal Information in Customer Data on behalf of Customer as a processor / service provider, solely to provide the Service and as otherwise described in this DPA and the Agreement.
2.3 Provider acts as an independent controller for account, billing, support, and website information about Customer’s personnel, as described in the Privacy Policy—not under this DPA’s controller/processor rules for that category, except where those individuals’ data also appears inside Customer Data.
3. Subject matter and details of Processing
| Item | Description |
|---|---|
| Subject matter | Hosting and operation of Motivra OS for Customer |
| Duration | For the Subscription term plus any post-termination export/deletion period, and as required by law |
| Nature / purpose | Host, store, transmit, display, backup, and otherwise Process Customer Data to provide, secure, support, and improve the Service per Customer’s configuration and instructions |
| Types of Personal Information | May include names, contact details (email, phone, address), account credentials metadata, appointment and service history, invoice/quote details, notification preferences, communication content, vehicle-related identifiers (including VIN) linked to individuals, and other data Customer chooses to submit |
| Categories of data subjects | Customer’s staff; end customers and dealership contacts; other individuals whose information Customer enters into the Service |
| Customer instructions | Documented in the Agreement, Order Form, this DPA, Customer’s use of the Service (configuration), and reasonable written instructions consistent with the Service |
4. Provider obligations
Provider will:
4.1 Process Personal Information only on documented instructions from Customer, including as set out in the Agreement and this DPA, unless required by Applicable Privacy Law (in which case Provider will notify Customer before Processing, unless legally prohibited).
4.2 Ensure persons authorized to Process Personal Information are bound by confidentiality obligations.
4.3 Implement appropriate technical and organizational measures to protect Personal Information against unauthorized access, loss, or alteration, taking into account the nature of the Service and the sensitivity of typical shop CRM data. Measures may include encryption in transit, access controls, authentication safeguards, logging, and least-privilege administration.
4.4 Not use Personal Information in Customer Data for Provider’s own marketing to data subjects, or sell such Personal Information.
4.5 Notify Customer without undue delay after becoming aware of a confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of or access to Personal Information in Customer Data (a “Security Incident”). Target initial notice: within seventy-two (72) hours of Provider’s confirmation, where feasible. Notice will include available details and steps taken or proposed. Provider will reasonably cooperate with Customer’s investigation and notification obligations. Provider’s notice is not an admission of fault.
4.6 Taking into account the nature of Processing, reasonably assist Customer (at Customer’s request and, where effort is material, at Customer’s expense) with: (a) data subject / individual requests; (b) security and breach assessments; and (c) privacy impact assessments required by Applicable Privacy Law, to the extent related to Provider’s Processing.
4.7 Upon termination or expiration of the Subscription, at Customer’s choice and request made within the export window in the Terms of Service, return a reasonably available export of Customer Data or delete Personal Information in Customer Data (and certify deletion on request), except where retention is required by law or contained in routine encrypted backups pending deletion cycles.
4.8 Make available information reasonably necessary to demonstrate compliance with this DPA and allow audits as described in Section 8.
5. Customer obligations
Customer will:
5.1 Comply with Applicable Privacy Law in its use of the Service and its Processing of Personal Information, including providing required notices and obtaining required consents (including for email/SMS under CASL, TCPA, and similar laws).
5.2 Ensure it has a lawful basis and all necessary rights to submit Personal Information to the Service and to instruct Provider to Process it.
5.3 Not instruct Provider to Process Personal Information in a manner that would cause Provider to violate Applicable Privacy Law.
5.4 Configure the Service and staff access appropriately (roles, approvals, retention practices within Customer’s control).
6. Subprocessors
6.1 Customer authorizes Provider to engage Subprocessors to Process Personal Information as needed to provide the Service. Provider will impose contractual obligations on Subprocessors no less protective in substance than this DPA regarding Personal Information.
6.2 Provider remains responsible for Subprocessors’ performance of their obligations with respect to Personal Information.
6.3 Current Subprocessors (as of the Effective Date; update as your stack changes):
| Subprocessor / category | Purpose | Typical location |
|---|---|---|
| Hosting / application platform (e.g. Render or successor) | Application hosting | [United States / as configured] |
| Managed PostgreSQL (or hosting DB) | Database | [United States / as configured] |
| Object storage (e.g. Amazon S3 or configured equivalent) | Images and file storage | [United States / as configured] |
| Email delivery (SMTP provider, SendGrid, and/or Microsoft Graph) | Transactional and notification email | [United States / as configured] |
| SMS (Twilio and/or Amazon SNS) | SMS notifications | [United States / as configured] |
| VIN decode API provider | Vehicle identification lookup | [As configured] |
| Bot protection (e.g. Google reCAPTCHA) | Abuse prevention on public forms | [United States / global] |
Replace bracketed locations and vendor names with your live production choices before first commercial use.
6.4 Provider will provide notice of material changes to the Subprocessor list (for example by updating this DPA, posting an updated list, or emailing Customer’s admin contact). Customer may object on reasonable data-protection grounds within fifteen (15) days. If the parties cannot resolve the objection, Customer may terminate the affected Subscription for convenience as to the impacted Service with a pro-rata refund of prepaid unused fees for the terminated portion—Customer’s exclusive remedy for such objection.
7. International transfers
Customer acknowledges that Personal Information may be transferred to and Processed in Canada, the United States, and other countries where Provider or Subprocessors operate. Customer is responsible for ensuring such transfers are permitted under Applicable Privacy Law for Customer’s use case. Provider will use reasonable contractual and organizational safeguards with Subprocessors for cross-border Processing.
8. Audits
Upon written request no more than once per twelve (12) months (unless required after a Security Incident or by a regulator), Provider will provide reasonable documentation or responses regarding security and Processing practices. On-site audits are not required unless mandated by Applicable Privacy Law or mutually agreed; any audit will be during business hours, on reasonable notice, subject to confidentiality, and at Customer’s expense unless a material breach of this DPA is confirmed.
9. Liability
Liability under this DPA is subject to the limitations and exclusions in the Terms of Service, except to the extent Applicable Privacy Law prohibits limiting liability for specific obligations.
10. Term
This DPA takes effect on the Order Form effective date (or first Processing of Personal Information under the Agreement, if earlier) and continues until Provider ceases Processing Personal Information under the Agreement.
11. General
11.1 This DPA is governed by the same governing law and venue as the Terms of Service (Ontario, Canada).
11.2 If any provision is unenforceable, the remainder remains in effect.
11.3 Electronic acceptance via Order Form constitutes execution of this DPA.
Contact
For privacy / DPA notices: [privacy@example.com]
Strategies Beyond Limits
[Ontario registered address]
This DPA is a template and not legal advice. Have counsel review before commercial use, and keep the Subprocessor list accurate.