CHIEF OSBETA

Enterprise trust documentation by Megawebvision

RETURN TO CHIEF

ENTERPRISE AGREEMENT

Data Processing Addendum

This Data Processing Addendum (DPA) governs Megawebvision Inc.'s processing of Customer Personal Data on behalf of the applicable Customer in connection with CHIEF. It is designed to be incorporated into the customer agreement by reference.

Last updated: August 9, 2026

Contract status

This public DPA is a baseline enterprise form. The signed customer agreement, order form and any negotiated schedule control the commercial relationship. Contact legal@megawebvision.com for execution or customer-specific terms.

01 / DPA

Scope and Incorporation into Customer Agreement

This DPA applies when Megawebvision Inc. (Megawebvision) processes Personal Data for the Customer in providing CHIEF. It forms part of the applicable agreement between Megawebvision and the Customer. If the Customer is not a party to a direct agreement with Megawebvision, this DPA applies through the agreement that governs the relevant CHIEF service.

02 / DPA

Definitions

Customer Personal Data means Personal Data processed by Megawebvision on behalf of the Customer. Processing, Personal Data, Controller, Processor, Business, Service Provider and Contractor have the meanings given by applicable privacy law. Subprocessor means a third party engaged by Megawebvision to process Customer Personal Data.

03 / DPA

Roles of the Parties

For GDPR processing, the Customer is the Controller and Megawebvision is the Processor, unless the parties document a different role for a particular processing activity. For CCPA/CPRA, Megawebvision acts as a Service Provider or Contractor where applicable. Each party remains responsible for its own legal obligations.

04 / DPA

Details of Processing

The subject matter, duration, nature, purpose, data categories and data-subject categories are described in Annex A. Megawebvision processes Customer Personal Data only to provide, secure, support and improve CHIEF in accordance with the Customer's documented instructions and the agreement.

05 / DPA

Customer Instructions

Megawebvision will process Customer Personal Data only on documented instructions from the Customer, including the agreement, order form, configured customer request or written direction. Megawebvision will inform the Customer if it believes an instruction infringes applicable law, unless prohibited from doing so.

06 / DPA

Purpose Limitation

Megawebvision will not sell Customer Personal Data or use it for cross-context behavioral advertising. It will not use Customer Personal Data for unrelated purposes or to train, fine-tune, distill, publicly benchmark or improve a shared model unless the Customer affirmatively opts into a separately stated purpose.

07 / DPA

Confidentiality

Persons authorized to process Customer Personal Data must be bound by confidentiality obligations or an appropriate statutory duty of confidentiality. Megawebvision will limit access to personnel and service providers who need it for the documented service purpose.

08 / DPA

Security Measures

Megawebvision will maintain appropriate technical and organizational measures considering the risk, state of the art, cost and processing context. The public description is available at Security Architecture & Controls ; a concise summary appears in Annex B.

09 / DPA

Subprocessors

Megawebvision may use the subprocessors listed at /subprocessors to provide CHIEF. Megawebvision will impose data-protection obligations appropriate to the relevant processing and remains responsible for its subprocessors' performance to the extent required by applicable law and the agreement.

10 / DPA

General Written Authorization

The Customer gives general written authorization for Megawebvision to engage the subprocessors listed in the public registry. The registry is the authoritative list for CHIEF. Megawebvision will update it for material additions or replacements.

11 / DPA

Subprocessor Change / Objection Process

Megawebvision will provide notice of a material subprocessor change by updating the public registry. The Customer may object on reasonable data-protection grounds by contacting the Privacy Officer within thirty days of the update. The parties will work in good faith toward a commercially reasonable resolution. If no resolution is available, the Customer may exercise the termination or service-remedy rights in the agreement.

12 / DPA

Data Subject Requests

Megawebvision will, taking into account the nature of the processing, provide reasonable assistance for the Customer's response to requests to access, correct, delete, restrict, object to or port Customer Personal Data. Megawebvision will not respond directly unless instructed or required by law and will refer the requester to the Customer where appropriate.

13 / DPA

Assistance With Privacy Compliance

Megawebvision will provide reasonable assistance with security, breach notifications, data-protection impact assessments, prior consultation and other Processor obligations under GDPR Article 28 and comparable applicable laws, taking into account the information available to Megawebvision and the nature of the processing.

14 / DPA

DPIA / Regulatory Cooperation

Upon reasonable request, Megawebvision will provide information reasonably necessary for the Customer to conduct a DPIA or consult a regulator. Requests must be proportionate and must not require disclosure of another customer's confidential information or security-sensitive details.

15 / DPA

Security Incidents

Megawebvision will notify the Customer without undue delay after confirming a Security Incident involving Customer Personal Data, subject to law and the information reasonably available at the time. The notice will describe known impact, affected data where known, response measures and reasonable next steps. Megawebvision will cooperate with the Customer's legally required notifications.

16 / DPA

Return and Deletion of Customer Personal Data

At the Customer's choice and subject to the agreement, Megawebvision will return or delete Customer Personal Data at the end of the applicable service, unless retention is required by law. Deletion from active systems and provider-held systems is subject to the applicable provider lifecycle and backup processes. Where requested, Megawebvision will confirm completion or explain a legal or technical exception.

17 / DPA

Demonstration of Compliance / Audit Information

Megawebvision will make available information reasonably necessary to demonstrate compliance with applicable Processor obligations. The parties may agree to a proportionate audit or review process, subject to confidentiality, security, customer segregation, reasonable notice and reimbursement of extraordinary costs. No audit may require access to credentials, private keys, unrelated customer data or exploitable defensive details.

18 / DPA

International Data Transfers

Where Customer Personal Data is transferred outside the jurisdiction permitted by applicable law, the parties will use a lawful transfer mechanism. Where required for EEA or UK restricted transfers, the parties may incorporate the applicable European Commission or UK Standard Contractual Clauses by reference or execute the relevant module and supplementary measures.

19 / DPA

EU Standard Contractual Clauses Where Applicable

If the Customer requires the EU Standard Contractual Clauses, the parties will identify the applicable module, complete the annex information, and incorporate the SCCs by reference. The SCCs will govern the restricted transfer to the extent required by their terms. The public Security page and this DPA provide the baseline technical and organizational information for the relevant annexes.

20 / DPA

CCPA Service Provider / Contractor Terms

To the extent Megawebvision processes Personal Information under CCPA/CPRA, Megawebvision will process it only for the limited business purposes in the agreement and Customer instructions; will provide the applicable privacy protections; will not sell or share it; will not retain, use or disclose it outside the permitted business purposes; will not combine it with other data except as permitted by law; and will notify the Customer if it can no longer meet these obligations. Megawebvision will cooperate with reasonable remediation requests.

21 / DPA

Canadian Privacy Requirements

The parties will cooperate to support accountability, purpose specification, consent where applicable, limiting collection, safeguards, openness, individual access and correction under PIPEDA and applicable provincial privacy law. Megawebvision will process Customer Personal Data only for the Customer's documented purposes.

22 / DPA

Québec Privacy Requirements

Megawebvision will support the Customer's obligations under Québec privacy legislation, including transparency, confidentiality, retention and destruction, incident handling, privacy-rights assistance and governance requirements. The Privacy Officer identified in Privacy is the organizational contact for Québec privacy matters.

23 / DPA

Order of Precedence

If this DPA conflicts with the agreement, this DPA controls only for the subject matter of data protection and only to the extent necessary to resolve the conflict. If incorporated SCCs conflict with this DPA, the SCCs control for the restricted transfer.

24 / DPA

Term / Termination

This DPA begins when the applicable agreement begins and continues while Megawebvision processes Customer Personal Data. It ends when the agreement ends and all Customer Personal Data has been returned or deleted, subject to permitted legal retention.

25 / DPA

Contact

Privacy Officer: Timur Grigorchuk, Founder, Megawebvision.
Megawebvision Inc., 6860 Av. Irwin, Montreal, Quebec H4E 2S9, Canada.
legal@megawebvision.com

Annex A / Processing

Processing Details

Subject matter

Provision, security, support and customer-requested operation of CHIEF.

Duration

For the term of the applicable agreement, plus permitted deletion, backup and legal-retention periods.

Nature and purpose

Hosting, storage, scoped connected-service access, workflow preparation, security, support and optional AI-assisted synthesis.

Personal Data categories

Business contact details, customer-provided operating context, connected-service content, technical request data and support or security-report information.

Data subjects

Customer personnel, contractors, business contacts, service users and other individuals represented in customer-provided business information.

Customer instructions

The agreement, order form, configured service scope and explicit customer requests, subject to applicable law and approved boundaries.

Annex B / Controls

Technical and Organizational Measures

  • HTTPS for public service transport
  • Default-off, narrow and account-scoped connected-service access
  • Keychain-backed secret handling and repository exclusion of credentials
  • Request origin, size, field and allowed-value validation
  • Rate limiting and honeypot handling on public intake
  • Private storage settings for submitted intake records
  • Scoped external-write controls and audit records that exclude credentials and message content
  • Version-controlled application and dependency configuration with repository security checks
  • Credential exposure response, access reset and write-containment procedures

Additional measures may be agreed for a particular enterprise service or customer environment. The public Security Architecture & Controls page is the baseline description and is supplemented by qualified enterprise review materials.

Annex C / Providers

Approved Subprocessors

The current approved subprocessor list, service descriptions, data categories, effective date and change process are maintained at /subprocessors . The public registry is incorporated into this Annex by reference.