1. Application and roles
This Data Processing Addendum (“DPA”) forms part of the agreement between the Customer and RestoreCheck IQ when RestoreCheck IQ processes personal information in Customer Data on the Customer’s behalf. The Customer is the organization that determines the business purposes and instructions; RestoreCheck IQ is its service provider or processor for that data. Each party remains independently responsible for personal information it controls for account, billing, security, legal, or business-administration purposes.
Terms such as controller, processor, service provider, personal information, and processing have the meaning given by applicable privacy law. The agreement, product configuration, and documented support instructions constitute the Customer’s processing instructions.
2. Processing details
- Subject matter: hosting and operating a restoration workflow, evidence, requirement, QC, reporting, integration, and support platform.
- Duration: the subscription term plus the agreed export, retention, deletion, backup, and legal-hold periods.
- Nature and purpose: collection, storage, organization, comparison, validation, display, transmission, export, backup, support, security, and customer-directed deletion.
- People: Customer personnel, clients, claimants, property occupants or owners, contractors, vendors, insurer or carrier contacts, and others represented in Customer Data.
- Data: identity and contact information, project and claim context, property and loss details, documents, photos, invoices, comments, requirements, workflow decisions, audit records, and other data the Customer chooses to provide.
- Sensitive data: may be present in evidence or claim materials. Customers must minimize it, restrict it, and obtain written agreement before intentionally using the Services for special categories that require controls not documented in the order.
3. RestoreCheck IQ obligations
- Process Customer Personal Information only on documented instructions, unless law requires otherwise.
- Ensure personnel with access are authorized, trained, subject to confidentiality, and limited by role and need.
- Maintain safeguards appropriate to sensitivity and risk, including tenant scope, access control, auditability, encryption, backup, secure change management, and incident response.
- Notify the Customer without undue delay after confirming a breach of security safeguards affecting Customer Personal Information, and provide reasonably available information needed for the Customer’s obligations.
- Assist reasonably with access, correction, deletion, privacy-impact, security, audit, and regulator requests, considering the nature of processing and information available.
- Delete or return Customer Personal Information at the end of Services as agreed, unless law requires retention.
- Make information reasonably necessary to demonstrate these obligations available, subject to confidentiality, security, proportionality, and protection of other customers.
4. Customer obligations
The Customer will provide lawful instructions, establish a valid authority for processing, deliver required notices, obtain required consent, configure appropriate access and retention, respond to people whose data it controls, and avoid uploading information not necessary for its business purpose.
The Customer will review source documents and material outputs, secure its users and integrations, and promptly notify RestoreCheck IQ of suspected unauthorized access or unlawful instructions.
5. Subprocessors and transfers
The Customer generally authorizes the subprocessors listed in the current Subprocessor Register for the described functions. RestoreCheck IQ will require appropriate data protection and confidentiality terms, remain responsible for its subprocessor obligations as required by law and contract, and provide notice of material additions where the agreement requires it.
Cross-border processing will use legally appropriate safeguards and privacy assessment where required. The Customer must identify binding residency restrictions before production use.
6. Audit, conflict, and signatures
We will first satisfy reasonable assurance requests using current policies, control descriptions, independent reports, and written responses. On-site review is reserved for a material unresolved concern or legal requirement and must protect security and other customers.
This DPA is a baseline template and becomes binding only as part of an accepted service agreement or signed order. Jurisdiction-specific schedules may be required. Contact legal@restorecheckiq.ca.