| Parties | Smart Buildings Inc. ("Processor") and the Customer ("Controller") |
| Product | ATLAS OS (the Habitat Twin) |
| Status | Draft v0.1 — review with counsel before signing |
| Incorporates | Terms of Service · Privacy Policy · Security & Data Compliance |
Disclaimer. Template for review by qualified counsel; not legal advice. This DPA applies where we process personal information on a customer's behalf (B2B deployments).
1. Roles
The Customer is the Controller (or, under PIPEDA, the organization accountable for the personal information); we act as Processor / service provider processing personal information only on the Controller's documented instructions.
2. Scope of processing
| Item | Detail |
|---|---|
| Subject matter | Provision of ATLAS OS |
| Duration | Term of the agreement + retention/return/deletion period |
| Nature & purpose | Hosting, telemetry processing, incident/broadcast handling |
| Data types | Operator accounts, resident contact data, operational telemetry, camera‑free presence; PHI only if telehealth is enabled |
| Data subjects | Operators, residents |
3. Processor obligations
- Process only on documented instructions; no unrelated use or sale.
- Ensure personnel are bound by confidentiality.
- Implement the security controls in Security & Data Compliance §4.
- Assist the Controller with data‑subject requests and regulator inquiries.
- Notify the Controller without undue delay on becoming aware of a breach, with details to support the Controller's PIPEDA/PHIPA obligations.
4. Sub‑processors
The Controller authorizes sub‑processors on our current list (hosting, database, email). We impose equivalent data‑protection terms and remain responsible for their performance; we give notice of changes and a chance to object.
5. International transfers
Where data is processed outside the Controller's jurisdiction, we apply contractual and technical safeguards and disclose processing locations on request.
6. Security & breach
See §4 and §7 of Security & Data Compliance. We maintain a record of breaches (PIPEDA) and support required notifications.
7. Audits
On reasonable notice and confidentiality terms, we provide information necessary to demonstrate compliance (e.g. SOC 2 report when available) and allow audits scoped to this DPA.
8. Return & deletion
On termination, at the Controller's choice, we return or delete personal information per the retention schedule §5, save where law requires retention.
9. PHI specifics (PHIPA)
Where PHI is processed, we act consistent with the Controller's role under PHIPA, restrict access to the minimum necessary, segregate PHI, and support the Controller's PHIPA duties.
10. Order of precedence
This DPA prevails over conflicting terms regarding personal‑information processing.
Signed for the Processor: ______________________ Date: __________ Signed for the Controller: ______________________ Date: __________