Product Pricing Partners Demo Security Q&A Log in Start free

This Data Processing Agreement ("DPA") applies where a customer uses Talisk to process personal information for which the customer (or the customer's own clients) is responsible — for example, a bookkeeper managing client books, or a business processing the personal information of its customers and workers inside Talisk. It forms part of the agreement between Talisk Technologies Inc. ("Talisk", the "Processor") and the customer accepting the Terms of Service (the "Customer", the "Controller"), and applies to the extent Talisk processes Customer Personal Information on the Customer's behalf.

01Roles and scope

02Processing details

03Instructions

Talisk processes Customer Personal Information only on the Customer's documented instructions, unless processing is required by applicable law (in which case Talisk informs the Customer of that legal requirement before processing, unless the law prohibits it). Talisk will inform the Customer if, in its opinion, an instruction violates applicable privacy law.

04Confidentiality

Talisk ensures that every person it authorizes to process Customer Personal Information is bound by a duty of confidentiality, and that access is limited to what is needed to provide, secure, and support the Service (see the Limited Use commitments in the Privacy Policy).

05Security measures

Talisk implements technical and organizational measures proportional to the sensitivity of the information, described on the Security page, including: per-account database schema isolation with database-enforced row-level security; encryption of personal content at rest with per-account keys; TLS in transit; GPG-encrypted off-site backups with segregated key custody; two-factor authentication; and least-privilege database access. Material degradations of these measures will not be made during a subscription term.

06Sub-processors

07Assistance with data-subject requests

Taking into account the nature of the processing, Talisk assists the Customer in fulfilling access, correction, deletion, portability, and cessation-of-dissemination requests from individuals — primarily through the Service's own search, correction, export, and deletion capabilities, and beyond that on request to privacy@talisk.ai. If an individual contacts Talisk directly about Customer Personal Information, Talisk will refer them to the Customer without undue delay.

08Breach notification

Talisk notifies the Customer without undue delay after becoming aware of a confidentiality incident affecting Customer Personal Information, and provides the information reasonably available to it — the nature of the incident, the categories and approximate volume of information involved, measures taken, and recommended mitigations — supplemented as the investigation progresses. Talisk maintains a register of incidents as required by Law 25 and assists the Customer with the Customer's own notification obligations (PIPEDA breach reporting; Quebec CAI notification).

09Deletion and return

During the term, the Customer can export Customer Personal Information using the Service's export tools. On termination of the account, Talisk deletes Customer Personal Information as described in the Privacy Policy — removal from live systems normally within 30 days of a deletion request, with encrypted backups aging out on a rolling schedule of at most 90 days — except where applicable law requires retention.

10Audit

Talisk makes available the information reasonably necessary to demonstrate compliance with this DPA — the Security page, the sub-processor list, and completed third-party assessment reports as they become available (see the Security page's Assessments section) — and will answer reasonable written security questionnaires from Customers no more than once per year. Where those materials are insufficient to demonstrate compliance, the Customer may request an audit of relevant controls, at the Customer's cost, on reasonable notice, no more than once per year, conducted so as not to compromise other customers' data or the security of the Service.

11International transfers

Customer Personal Information is stored and processed in the United States (and by sub-processors in the locations listed at talisk.ai/subprocessors). The Customer — as the party accountable under Canadian law for information it entrusts to service providers — can rely on this DPA, the contractual commitments with sub-processors, and the measures on the Security page as the protections applicable to those transfers, including for the Customer's own Law 25 cross-border assessment. Talisk will provide reasonable cooperation for that assessment on request.

12Liability and order of precedence

This DPA is subject to the limitations of liability in the Terms of Service. If this DPA conflicts with the Terms on a data-protection matter, this DPA prevails. This DPA is governed by the same law and forum as the Terms (British Columbia).

13Contact

To execute a countersigned copy of this DPA, request the French version, or ask questions: legal@talisk.ai.
Talisk Technologies Inc., British Columbia, Canada