Data Processing Agreement
This Data Processing Agreement ("DPA") applies where a customer uses Talisk to process personal information for which the customer (or the customer's own clients) is responsible — for example, a bookkeeper managing client books, or a business processing the personal information of its customers and workers inside Talisk. It forms part of the agreement between Talisk Technologies Inc. ("Talisk", the "Processor") and the customer accepting the Terms of Service (the "Customer", the "Controller"), and applies to the extent Talisk processes Customer Personal Information on the Customer's behalf.
01Roles and scope
- The Customer is the controller (the organization responsible for the personal information, within the meaning of PIPEDA, BC PIPA, and the Quebec private-sector Act as amended by Law 25) of the personal information it syncs into or creates in the Service — including personal information of its own clients, contacts, workers, and correspondents ("Customer Personal Information").
- Talisk is the processor / service provider: it processes Customer Personal Information only to provide the Service, on the Customer's documented instructions as expressed through the Terms, this DPA, and the Customer's use and configuration of the Service.
- For clarity, Talisk remains independently responsible (as described in the Privacy Policy) for the account and billing information of the Customer itself.
02Processing details
- Subject matter and duration: the provision of the Talisk email and bookkeeping service, for as long as the Customer maintains an account (plus the deletion window in section 9).
- Nature and purpose: hosting, syncing, organizing, displaying, analyzing (including AI-assisted features invoked by the Customer), backing up, and exporting the Customer's mail, contacts, and business records.
- Categories of data subjects: the Customer's correspondents, clients, vendors, workers, and other individuals appearing in the Customer's mailbox and business records.
- Types of personal information: names and contact details; email content and metadata; business and financial records (invoices, bills, bank transactions, time entries) that identify individuals; and any other personal information the Customer chooses to process in the Service.
03Instructions
Talisk processes Customer Personal Information only on the Customer's documented instructions, unless processing is required by applicable law (in which case Talisk informs the Customer of that legal requirement before processing, unless the law prohibits it). Talisk will inform the Customer if, in its opinion, an instruction violates applicable privacy law.
04Confidentiality
Talisk ensures that every person it authorizes to process Customer Personal Information is bound by a duty of confidentiality, and that access is limited to what is needed to provide, secure, and support the Service (see the Limited Use commitments in the Privacy Policy).
05Security measures
Talisk implements technical and organizational measures proportional to the sensitivity of the information, described on the Security page, including: per-account database schema isolation with database-enforced row-level security; encryption of personal content at rest with per-account keys; TLS in transit; GPG-encrypted off-site backups with segregated key custody; two-factor authentication; and least-privilege database access. Material degradations of these measures will not be made during a subscription term.
06Sub-processors
- The Customer authorizes the sub-processors listed at talisk.ai/subprocessors, which identifies each sub-processor's purpose, data categories, and location.
- Talisk updates that page before a new sub-processor begins processing Customer Personal Information. Customers may request change notifications at legal@talisk.ai; a Customer who objects on reasonable data-protection grounds may terminate the affected services and receive a pro-rata refund of prepaid fees.
- Talisk imposes data-protection obligations on its sub-processors consistent with this DPA and remains responsible to the Customer for their performance.
07Assistance with data-subject requests
Taking into account the nature of the processing, Talisk assists the Customer in fulfilling access, correction, deletion, portability, and cessation-of-dissemination requests from individuals — primarily through the Service's own search, correction, export, and deletion capabilities, and beyond that on request to privacy@talisk.ai. If an individual contacts Talisk directly about Customer Personal Information, Talisk will refer them to the Customer without undue delay.
08Breach notification
Talisk notifies the Customer without undue delay after becoming aware of a confidentiality incident affecting Customer Personal Information, and provides the information reasonably available to it — the nature of the incident, the categories and approximate volume of information involved, measures taken, and recommended mitigations — supplemented as the investigation progresses. Talisk maintains a register of incidents as required by Law 25 and assists the Customer with the Customer's own notification obligations (PIPEDA breach reporting; Quebec CAI notification).
09Deletion and return
During the term, the Customer can export Customer Personal Information using the Service's export tools. On termination of the account, Talisk deletes Customer Personal Information as described in the Privacy Policy — removal from live systems normally within 30 days of a deletion request, with encrypted backups aging out on a rolling schedule of at most 90 days — except where applicable law requires retention.
10Audit
Talisk makes available the information reasonably necessary to demonstrate compliance with this DPA — the Security page, the sub-processor list, and completed third-party assessment reports as they become available (see the Security page's Assessments section) — and will answer reasonable written security questionnaires from Customers no more than once per year. Where those materials are insufficient to demonstrate compliance, the Customer may request an audit of relevant controls, at the Customer's cost, on reasonable notice, no more than once per year, conducted so as not to compromise other customers' data or the security of the Service.
11International transfers
Customer Personal Information is stored and processed in the United States (and by sub-processors in the locations listed at talisk.ai/subprocessors). The Customer — as the party accountable under Canadian law for information it entrusts to service providers — can rely on this DPA, the contractual commitments with sub-processors, and the measures on the Security page as the protections applicable to those transfers, including for the Customer's own Law 25 cross-border assessment. Talisk will provide reasonable cooperation for that assessment on request.
12Liability and order of precedence
This DPA is subject to the limitations of liability in the Terms of Service. If this DPA conflicts with the Terms on a data-protection matter, this DPA prevails. This DPA is governed by the same law and forum as the Terms (British Columbia).
13Contact
To execute a countersigned copy of this DPA, request the French version, or ask
questions: legal@talisk.ai.
Talisk Technologies Inc., British Columbia, Canada