This Data Processing Addendum (“DPA”) forms part of the Terms of Service between Easy Annotation (“we”, “Processor”) and a business customer that uses the Service to process personal information contained in its documents (“Customer”, “Controller”). It applies automatically when a business customer accepts the Terms. If Customer needs a signed copy, contact support@easyannotation.com.
Scope and roles
- This DPA applies to personal information that Customer or its users upload to the Service as Customer Content (“Customer Personal Data”).
- Customer is the controller of Customer Personal Data and we process it as its processor (or service provider). We are the controller of account, billing and usage information about Customer’s users, which our Privacy Policy covers.
- “Data Protection Laws” means the privacy and data-protection laws that apply to the processing, which may include PIPEDA and provincial privacy laws in Canada, the EU and UK General Data Protection Regulation, and U.S. state privacy laws.
Processing on Customer’s instructions
- We process Customer Personal Data only to provide the Service in accordance with the Terms, Customer’s use and configuration of the Service (including whether AI processing is turned on), and Customer’s other documented instructions, unless the law requires otherwise; in that case we will tell Customer unless the law prohibits it.
- We do not sell Customer Personal Data, use it for advertising, or use it to train artificial-intelligence models.
- Customer is responsible for having a lawful basis and any notices or consents needed for the processing, including for any AI processing it enables.
Confidentiality
Personnel authorized to process Customer Personal Data are bound by confidentiality obligations and access it only as needed to provide the Service, support Customer, maintain security or comply with the law.
Security
We maintain the technical and organizational measures in Annex B, and we may update them as long as the overall level of protection is not reduced.
Sub-processors
- Customer authorizes us to use the sub-processors listed on our Sub-processors page.
- We impose data-protection terms on each sub-processor that are at least as protective as this DPA, and we remain responsible for their performance.
- On request, we will give Customer at least 30 days’ notice by email of a new sub-processor. Customer may object on reasonable data-protection grounds; if we cannot reasonably accommodate the objection, Customer may stop using the affected part of the Service.
Assistance with requests
Taking into account the nature of the processing, we will help Customer respond to requests from individuals to exercise their rights, and with security, breach-notification, impact-assessment and regulator-consultation obligations. The Service lets Customer’s users access, export and delete their data themselves. If we receive a request directly from an individual about Customer Personal Data, we will refer them to Customer.
Personal information breaches
We will notify Customer without undue delay after we become aware of a breach of security affecting Customer Personal Data. The notice will describe, as far as known, the nature of the breach, the categories and approximate volume of data affected, likely consequences, and the measures taken or proposed. We will take reasonable steps to contain the breach and cooperate with Customer’s response.
Return and deletion
Customer can export and delete Customer Personal Data at any time using the Service. When Customer deletes data, or its account is deleted, we delete Customer Personal Data from primary storage straight away and from versioned storage and backups within 30 days, unless the law requires us to keep it.
Information and audits
On reasonable written request, we will provide information needed to demonstrate compliance with this DPA. If that information is not sufficient to meet a requirement of Data Protection Laws, Customer may request an audit on at least 30 days’ notice, no more than once a year, during business hours, at Customer’s cost and subject to confidentiality obligations.
International transfers
We store Customer Personal Data in Canada. Some sub-processors process data in the United States and other countries. Where Data Protection Laws require a transfer mechanism, the applicable standard contractual clauses, including the UK International Data Transfer Addendum where relevant, are incorporated into this DPA by reference, with Customer as data exporter and us as data importer.
Liability, precedence and duration
Each party’s liability under this DPA is subject to the limitations in the Terms, except where the law does not allow it. If this DPA conflicts with the Terms, this DPA prevails for Customer Personal Data. This DPA lasts for as long as we process Customer Personal Data.
Annex A — Description of processing
| Subject matter and nature | Hosting, storing, converting, displaying, annotating and analysing documents; delivering copies Customer chooses to share; and, if turned on, AI-assisted claim extraction. |
|---|---|
| Purpose | Providing the Service to Customer. |
| Duration | For the term of the Customer’s use of the Service, plus the deletion periods in section 8. |
| Data subjects | People named or described in Customer’s documents, such as authors, investigators, reviewers, and employees or contacts of Customer and its clients. |
| Types of personal information | Names, professional titles and affiliations, contact details and other information that appears in Customer’s documents. Customer must not upload identifiable patient health information or other highly sensitive information unless agreed in writing. |
Annex B — Security measures
- Encryption in transit (HTTPS) and HTTP Strict Transport Security.
- Uploaded files are stored encrypted at rest in private cloud storage and are available only through the application after an ownership check, or through short-lived signed links.
- Tenant isolation: every document request is checked against the signed-in user’s ownership or organization permissions.
- Passwords are stored as salted one-way hashes. Two-factor authentication is available to all users and required for administrators. Sessions end when a password is changed.
- Least-privilege credentials for cloud resources and restricted administrative access.
- Daily encrypted database backups, kept for 14 days, with alerts if a backup fails.
- Security headers against clickjacking and content sniffing; bot protection on sign-in and registration.
- Application and server logs kept for 14 days; errors alert the operations team.
- Dependency security checks on every deployment.
- A documented incident and breach-response procedure.