Data Processing Agreement
Version 1.0 · Effective date: June 10, 2026
Beta-period draft. A finalized, lawyer-reviewed version will replace this before general availability. Email privacy@preveio.com with questions.
1. Definitions
In this Data Processing Agreement ("DPA"), the following terms have the following meanings:
- "Controller" means the Broker or the Broker's organization, which determines the purposes and means of processing Personal Data through the Service.
- "Processor" means Preve.io, which processes Personal Data on behalf of the Controller to provide the Service.
- "Personal Data" means any information relating to an identified or identifiable natural person that is processed through the Service, including Applicant financial documents and extracted data.
- "Processing" means any operation performed on Personal Data, including collection, recording, organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure, dissemination, restriction, erasure, or destruction.
- "Sub-Processor" means a third party engaged by the Processor to process Personal Data on behalf of the Controller.
- "Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data.
- "Applicable Data Protection Law" means all applicable laws relating to the processing of Personal Data, including PIPEDA, CCPA/CPRA, and any other applicable privacy legislation.
2. Scope and Purpose
This DPA supplements the Terms of Service and applies to all Processing of Personal Data by the Processor on behalf of the Controller in connection with the Service. The purpose of Processing is to provide the Service as described in the Terms of Service, specifically: document classification, data extraction, validation, applicant profile aggregation, and lender matching.
The categories of data subjects are mortgage applicants whose documents are uploaded by the Controller. The types of Personal Data processed include: names, addresses, dates of birth, Social Insurance Numbers (SIN), Social Security Numbers (SSN), income information, employment details, banking information, property information, and government identification numbers.
3. Processing Instructions
The Processor shall process Personal Data only on documented instructions from the Controller, unless required to do so by applicable law. The Controller's instructions are set forth in the Terms of Service and this DPA. If the Processor believes that an instruction from the Controller infringes Applicable Data Protection Law, the Processor shall promptly inform the Controller.
4. Confidentiality
The Processor shall ensure that all personnel authorized to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality. The Processor shall ensure that access to Personal Data is limited to those personnel who require such access to perform the Service.
5. Security Measures
The Processor shall implement and maintain appropriate technical and organizational measures to protect Personal Data against unauthorized or unlawful Processing and against accidental loss, destruction, or damage. These measures include, at minimum:
- Encryption of Personal Data at rest (AES-256) and in transit (TLS 1.3).
- Row-Level Security (RLS) policies ensuring data isolation between Controller accounts.
- Multi-factor authentication for all accounts with access to Personal Data.
- Regular security assessments and vulnerability testing.
- Access controls limiting personnel access to Personal Data on a need-to-know basis.
- Logging and monitoring of access to Personal Data.
6. Sub-Processors
The Controller provides general authorization for the Processor to engage Sub-Processors to assist in providing the Service. The current list of Sub-Processors is maintained in the Privacy Policy. The Processor shall: (a) notify the Controller at least thirty (30) days before adding or replacing a Sub-Processor; (b) impose data protection obligations on each Sub-Processor that are no less protective than those in this DPA; and (c) remain liable for the acts and omissions of its Sub-Processors.
If the Controller objects to a new Sub-Processor, the Controller may terminate the affected Service by providing written notice within thirty (30) days of receiving notification of the new Sub-Processor.
7. Data Breach Notification
The Processor shall notify the Controller without undue delay, and in any event within forty-eight (48) hours, after becoming aware of a Data Breach affecting the Controller's Personal Data. The notification shall include: (a) a description of the nature of the Data Breach, including the categories and approximate number of data subjects affected; (b) the likely consequences of the Data Breach; (c) the measures taken or proposed to address the Data Breach; and (d) the contact details of the Processor's privacy officer.
The Processor shall cooperate with the Controller in investigating and remediating the Data Breach and in complying with any notification obligations under Applicable Data Protection Law.
8. Data Subject Rights
The Processor shall assist the Controller in responding to requests from data subjects to exercise their rights under Applicable Data Protection Law, including rights of access, correction, deletion, and portability. The Processor shall promptly forward any data subject request it receives directly to the Controller, unless otherwise instructed.
9. Data Deletion and Return
Upon termination of the Terms of Service, or upon the Controller's written request, the Processor shall: (a) return all Personal Data to the Controller in a commonly used, machine-readable format; or (b) delete all Personal Data and confirm deletion in writing. The Processor may retain copies of Personal Data only to the extent required by applicable law, and shall inform the Controller of any such retention and the legal basis for it.
Deletion shall be completed within ninety (90) days of termination or request, and shall include all copies in backup systems within the normal backup rotation cycle.
10. Audit Rights
The Controller has the right to audit the Processor's compliance with this DPA. The Processor shall make available to the Controller all information necessary to demonstrate compliance, and shall allow for and contribute to audits and inspections conducted by the Controller or an independent third-party auditor appointed by the Controller, upon reasonable notice (not less than thirty (30) days) and during normal business hours.
Audits shall be limited to once per year unless a Data Breach has occurred or the Controller has reasonable grounds to believe non-compliance. The Controller shall bear the costs of any audit.
11. International Transfers
Personal Data may be transferred to and processed in the United States by Sub-Processors listed in Section 6. The Processor ensures that such transfers are subject to appropriate safeguards, including contractual commitments requiring Sub-Processors to protect Personal Data to a standard no less protective than that provided under Applicable Data Protection Law.
12. Term and Termination
This DPA shall remain in effect for the duration of the Terms of Service and shall automatically terminate upon termination of the Terms of Service, subject to the Processor's obligations regarding data deletion under Section 9. The provisions of this DPA that by their nature should survive termination shall survive, including Sections 4 (Confidentiality), 7 (Data Breach Notification), 9 (Data Deletion), and 10 (Audit Rights).
13. Liability
The liability of each party under this DPA is subject to the limitations of liability set forth in the Terms of Service. Nothing in this DPA limits either party's liability for breaches of Applicable Data Protection Law to the extent such liability cannot be limited under applicable law.
14. Contact
For questions about this DPA or to exercise audit rights, contact: privacy@preveio.com.