Legal
Data Processing Addendum
- Fecha de vigencia
- Vigencia July 4, 2026
- Última actualización
- Última actualización August 23, 2026
This Data Processing Addendum (“DPA”) describes how Agnotiq, Inc. processes Customer Data on behalf of a customer (“Customer”) in connection with Agnotiq MarginTide Price Checker (the Service). It forms part of, and is incorporated by reference into, our Terms of Service, and applies automatically to every customer — no separate signature is required to rely on it, and a countersigned copy is available on request (§12).
Customer is the controller. We are the processor.
For the Customer Data a Customer submits to run the Service, Customer is the controller (or, under U.S. law, the business) and Agnotiq, Inc. is the processor (or service provider), acting only on Customer’s documented instructions as set out in the Terms of Service, this DPA, and Customer’s configuration of the Service.
01Parties & roles
This DPA is between Customer and Agnotiq, Inc. (“Agnotiq, Inc.”, “we”, “us”), a company based in Toronto, Ontario, Canada. It governs the processing of personal information contained within Customer Data — for example, competitor contact details, supplier names, or employee names Customer includes in a product catalog or configuration — that Agnotiq, Inc. processes solely to provide the Service. It does not cover account, billing, and website information for which Agnotiq, Inc. acts as an independent controller, described in our Privacy Policy.
02Definitions
Terms defined in the Terms of Service (including “Customer Data”, “Output”, and “Subscription”) have the same meaning here. “Personal data,” “processing,” “controller,” and “processor” have the meanings given in applicable data-protection law (including PIPEDA and, where applicable, the EU/UK GDPR). “Subprocessor” means a third party Agnotiq, Inc. engages to process Customer Data in providing the Service, listed at /legal/subprocessors.
03Processing scope & duration
Subject matter and duration.
Agnotiq, Inc.processes Customer Data for the duration of Customer’s Subscription (including any trial, archived, or grace period), and thereafter only as needed to comply with §9 (deletion & return) or applicable law.
Nature and purpose.
Processing is limited to what is necessary to run the Service: ingesting configuration and catalog data Customer supplies, executing the agent pipeline to research competitor prices and produce Output and Recommendations, storing run history for the retention window Customer’s plan provides, delivering alerts and notifications Customer configures, and providing support at Customer’s request.
Categories of data subjects and personal data.
Data subjects may include Customer’s personnel (account, workspace, and support users) and, where Customer includes them in Customer Data, third parties such as competitors’ publicly listed contact information or supplier names. Categories of personal data are limited to what Customer chooses to submit — typically identifiers and business-contact information; Agnotiq, Inc. does not request or require special categories of personal data and asks Customer not to submit them.
Instructions.
Agnotiq, Inc.will process Customer Data only on Customer’s documented instructions (given through the Service’s configuration and this DPA), unless required to do otherwise by law — in which case, to the extent permitted, Agnotiq, Inc. will inform Customer before processing.
04Confidentiality
Agnotiq, Inc. restricts access to Customer Data to personnel and subprocessors who need it to provide the Service, and binds them to confidentiality obligations no less protective than this DPA. These obligations survive the end of any engagement.
05Security measures
Agnotiq, Inc. maintains technical and organizational measures designed to protect Customer Data, described in detail on our Security page — including workspace-scoped row-level security enforced at the database, encryption in transit and at rest, passwordless authentication, consent-gated support access, an immutable audit log, and least-privilege access controls. Those measures may be updated over time provided they do not materially reduce the overall level of protection.
06Subprocessors
Customer authorizes Agnotiq, Inc. to engage the subprocessors listed, on an ongoing and current basis, at /legal/subprocessors — the authoritative, current list, including each subprocessor’s purpose, data categories, and processing location. Agnotiq, Inc. will give at least 30 days’ advance notice before adding or replacing a subprocessor (by email to the workspace owner and to anyone enrolled in the notification signup on that page). Customer may object on reasonable data-protection grounds within that notice period by emailing legal@agnotiq.com; the parties will work in good faith to address the objection, and if unresolved, Customer’s remedy is to terminate the affected Service in accordance with the Terms of Service. Agnotiq, Inc.remains responsible for each subprocessor’s performance of its data-protection obligations to the same extent Agnotiq, Inc. would be liable if performing those services directly.
07Personal-data breach notification
If Agnotiq, Inc. becomes aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Data (a “Personal Data Breach”), we will notify Customer without undue delay and, in any event, within seventy-two (72) hours of becoming aware of it, and will provide the information reasonably available to us to help Customer meet its own notification obligations — including a description of the breach, the categories and approximate number of data subjects and records concerned, the likely consequences, and the measures taken or proposed to address it. Agnotiq, Inc.will cooperate reasonably with Customer’s investigation and any required notice to regulators or affected individuals.
08International transfers
Agnotiq, Inc. and its subprocessors store and process Customer Data in Canada, the United States, and other countries where our infrastructure operates (see /legal/subprocessors for locations by vendor). Where a transfer of personal data originating in the European Economic Area, the United Kingdom, or Switzerland requires a specific transfer mechanism under applicable law, the parties will rely on the European Commission’s Standard Contractual Clauses and, for transfers subject to UK data-protection law, the UK International Data Transfer Addendum, each incorporated by reference and deemed executed between the parties for that purpose upon Customer’s acceptance of this DPA, together with any additional safeguard Agnotiq, Inc. reasonably implements from time to time.
09Deletion & return on termination
On termination of the Subscription (or earlier at Customer’s written request), Agnotiq, Inc.will, at Customer’s choice, make Customer Data available for export in a standard format, and will delete or de-identify remaining Customer Data in accordance with the retention practices described in our Privacy Policy (including the archived- and abandoned-workspace windows), except where we are required by law to retain it, or where it is contained in backups that follow our standard backup-rotation schedule. Customer is responsible for exporting anything it needs before termination.
10Audit information rights
On reasonable prior written request, no more than once per 12-month period (or more often if required following a Personal Data Breach or by a supervisory authority), Agnotiq, Inc. will make available the information reasonably necessary to demonstrate compliance with this DPA — including a summary of the technical and organizational measures described in §5, our Security page, and, where available, a copy of any independent security assessment covering the Service (see Securityfor our pen-test summary). Where Customer reasonably requires more than this documentary review, the parties will agree a mutually convenient scope, timing, and confidentiality protocol for an on-site or remote audit, at Customer’s expense.
- Agnotiq, Inc. will promptly notify Customer if an instruction, in Agnotiq, Inc.’s reasonable opinion, infringes applicable data-protection law.
- Agnotiq, Inc.will assist Customer, at Customer’s reasonable expense, in responding to data-subject requests and in meeting Customer’s own data-protection-impact- assessment and prior-consultation obligations, to the extent information is reasonably available to us.
11Order of precedence
This DPA applies only to the processing of personal data contained within Customer Data and forms part of the Terms of Service. If there is a conflict between this DPA and the Terms regarding the processing of personal data, this DPA controls; for every other subject, the Terms control. Nothing in this DPA reduces Agnotiq, Inc.’s or Customer’s obligations under the Terms.
12How to contact us
For DPA questions, a countersigned copy, or to exercise a right described here, contact Agnotiq, Inc. at legal@agnotiq.com. For subprocessor questions, see /legal/subprocessors. For security questions, see Security.

