Data Processing Agreement

Effective July 26, 2026

This is a self-serve DPA, incorporated by reference into our Terms of Service. If your organization requires a countersigned copy or has redline requests, email legal@layer8systems.ca.

1. Parties and Definitions

This Data Processing Agreement (“DPA”) is between Layer8 Systems Inc. (“Processor”, “we”, “us”) and the organization or individual using the Layer8 Systems platform under our Terms of Service (“Controller”, “you”). Terms not defined here (“personal data”, “processing”, “data subject”) take the meaning given to them in applicable data protection law, including PIPEDA, Quebec Law 25, and — where it applies to your organization — the GDPR.

This DPA applies to Processor’s processing of personal data on Controller’s behalf in the course of providing NetMapr, AssetTrakr, NoteTakr, and CryptKeepr (collectively, the “Service”), as described in our Privacy Policy.

2. Scope and Duration

This DPA takes effect when Controller begins using the Service and remains in effect for as long as Processor processes personal data on Controller’s behalf, coextensive with the term of the underlying Terms of Service.

3. Processor Obligations

Processor shall:

  • Process personal data only on Controller’s documented instructions, as reflected in the Terms of Service and Privacy Policy, unless required otherwise by law — in which case Processor will inform Controller of that legal requirement first, unless the law prohibits it.
  • Ensure that personnel authorized to process personal data are subject to a duty of confidentiality.
  • Implement the technical and organizational security measures described in our Security page and summarized in our Trust Center, appropriate to the risk of the processing.
  • Assist Controller, to the extent reasonably possible, in responding to requests from data subjects exercising their rights under applicable law.
  • Notify Controller without undue delay, and in any case within 72 hours of becoming aware, of any confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of personal data.
  • At Controller’s election, delete or return all personal data at the end of the Service relationship, except where retention is required by applicable law — a self-service export is always available from account settings, and account deletion removes personal data within 30 days per our Privacy Policy.
  • Make available information reasonably necessary to demonstrate compliance with this DPA, and allow for audits, including inspections, conducted by Controller or an auditor mandated by Controller, subject to reasonable notice and confidentiality.

4. Subprocessors

Controller authorizes Processor to engage the subprocessors listed below to provide the Service. Processor will give Controller at least 14 days’ notice (by email or in-product notice) before adding a new subprocessor or materially changing an existing one, per §11 of our Privacy Policy. Processor remains liable for each subprocessor’s performance of its data protection obligations, and imposes data protection terms on each subprocessor no less protective than those in this DPA.

SubprocessorPurposeLocation
ClerkAuthentication and session managementUnited States
ConvexApplication database and backend computeUnited States
VercelApplication hosting and content deliveryUnited States (global edge network)
PolarBilling and subscription managementUnited States
ResendTransactional email deliveryUnited States
SentryApplication error monitoringUnited States
Vercel Analytics & Speed InsightsProduct usage and performance analyticsUnited States

5. International Data Transfers

Processor is based in Canada. The subprocessors listed in §4 currently process data in the United States. Processor takes reasonable contractual measures to ensure personal data transferred outside Canada receives protection comparable to that required under Canadian privacy law.

6. Data Subject Requests

If Processor receives a request directly from one of Controller’s data subjects relating to their personal data, Processor will promptly redirect the request to Controller and will not respond to the data subject directly, except to confirm the request has been forwarded, unless legally required to do so.

7. Liability

Each party’s liability arising out of or in connection with this DPA is subject to the limitations and exclusions of liability set out in the Terms of Service.

8. Governing Law

This DPA is governed by the laws of the Province of Ontario and the federal laws of Canada applicable therein, consistent with §14 of our Terms of Service.

9. Contact

Questions about this DPA, or requests for a countersigned copy?

Legal, Layer8 Systems Inc.
Canada
legal@layer8systems.ca