Enterprise trust documentation by Megawebvision
RETURN TO CHIEF ↗ENTERPRISE AGREEMENT
Data Processing Addendum
This Data Processing Addendum (DPA) governs Megawebvision Inc.'s processing of Customer Personal Data on behalf of the applicable Customer in connection with CHIEF. It is designed to be incorporated into the customer agreement by reference.
Last updated: August 9, 2026
This public DPA is a baseline enterprise form. The signed customer agreement, order form and any negotiated schedule control the commercial relationship. Contact legal@megawebvision.com for execution or customer-specific terms.
01 / DPA
Scope and Incorporation into Customer Agreement
This DPA applies when Megawebvision Inc. (Megawebvision) processes Personal Data for the Customer in providing CHIEF. It forms part of the applicable agreement between Megawebvision and the Customer. If the Customer is not a party to a direct agreement with Megawebvision, this DPA applies through the agreement that governs the relevant CHIEF service.
02 / DPA
Definitions
Customer Personal Data means Personal Data processed by Megawebvision on behalf of the Customer. Processing, Personal Data, Controller, Processor, Business, Service Provider and Contractor have the meanings given by applicable privacy law. Subprocessor means a third party engaged by Megawebvision to process Customer Personal Data.
03 / DPA
Roles of the Parties
For GDPR processing, the Customer is the Controller and Megawebvision is the Processor, unless the parties document a different role for a particular processing activity. For CCPA/CPRA, Megawebvision acts as a Service Provider or Contractor where applicable. Each party remains responsible for its own legal obligations.
04 / DPA
Details of Processing
The subject matter, duration, nature, purpose, data categories and data-subject categories are described in Annex A. Megawebvision processes Customer Personal Data only to provide, secure, support and improve CHIEF in accordance with the Customer's documented instructions and the agreement.
05 / DPA
Customer Instructions
Megawebvision will process Customer Personal Data only on documented instructions from the Customer, including the agreement, order form, configured customer request or written direction. Megawebvision will inform the Customer if it believes an instruction infringes applicable law, unless prohibited from doing so.
06 / DPA
Purpose Limitation
Megawebvision will not sell Customer Personal Data or use it for cross-context behavioral advertising. It will not use Customer Personal Data for unrelated purposes or to train, fine-tune, distill, publicly benchmark or improve a shared model unless the Customer affirmatively opts into a separately stated purpose.
07 / DPA
Confidentiality
Persons authorized to process Customer Personal Data must be bound by confidentiality obligations or an appropriate statutory duty of confidentiality. Megawebvision will limit access to personnel and service providers who need it for the documented service purpose.
08 / DPA
Security Measures
Megawebvision will maintain appropriate technical and organizational measures considering the risk, state of the art, cost and processing context. The public description is available at Security Architecture & Controls ; a concise summary appears in Annex B.
09 / DPA
Subprocessors
Megawebvision may use the subprocessors listed at /subprocessors to provide CHIEF. Megawebvision will impose data-protection obligations appropriate to the relevant processing and remains responsible for its subprocessors' performance to the extent required by applicable law and the agreement.
10 / DPA
General Written Authorization
The Customer gives general written authorization for Megawebvision to engage the subprocessors listed in the public registry. The registry is the authoritative list for CHIEF. Megawebvision will update it for material additions or replacements.
11 / DPA
Subprocessor Change / Objection Process
Megawebvision will provide notice of a material subprocessor change by updating the public registry. The Customer may object on reasonable data-protection grounds by contacting the Privacy Officer within thirty days of the update. The parties will work in good faith toward a commercially reasonable resolution. If no resolution is available, the Customer may exercise the termination or service-remedy rights in the agreement.
12 / DPA
Data Subject Requests
Megawebvision will, taking into account the nature of the processing, provide reasonable assistance for the Customer's response to requests to access, correct, delete, restrict, object to or port Customer Personal Data. Megawebvision will not respond directly unless instructed or required by law and will refer the requester to the Customer where appropriate.
13 / DPA
Assistance With Privacy Compliance
Megawebvision will provide reasonable assistance with security, breach notifications, data-protection impact assessments, prior consultation and other Processor obligations under GDPR Article 28 and comparable applicable laws, taking into account the information available to Megawebvision and the nature of the processing.
14 / DPA
DPIA / Regulatory Cooperation
Upon reasonable request, Megawebvision will provide information reasonably necessary for the Customer to conduct a DPIA or consult a regulator. Requests must be proportionate and must not require disclosure of another customer's confidential information or security-sensitive details.
15 / DPA
Security Incidents
Megawebvision will notify the Customer without undue delay after confirming a Security Incident involving Customer Personal Data, subject to law and the information reasonably available at the time. The notice will describe known impact, affected data where known, response measures and reasonable next steps. Megawebvision will cooperate with the Customer's legally required notifications.
16 / DPA
Return and Deletion of Customer Personal Data
At the Customer's choice and subject to the agreement, Megawebvision will return or delete Customer Personal Data at the end of the applicable service, unless retention is required by law. Deletion from active systems and provider-held systems is subject to the applicable provider lifecycle and backup processes. Where requested, Megawebvision will confirm completion or explain a legal or technical exception.
17 / DPA
Demonstration of Compliance / Audit Information
Megawebvision will make available information reasonably necessary to demonstrate compliance with applicable Processor obligations. The parties may agree to a proportionate audit or review process, subject to confidentiality, security, customer segregation, reasonable notice and reimbursement of extraordinary costs. No audit may require access to credentials, private keys, unrelated customer data or exploitable defensive details.
18 / DPA
International Data Transfers
Where Customer Personal Data is transferred outside the jurisdiction permitted by applicable law, the parties will use a lawful transfer mechanism. Where required for EEA or UK restricted transfers, the parties may incorporate the applicable European Commission or UK Standard Contractual Clauses by reference or execute the relevant module and supplementary measures.
19 / DPA
EU Standard Contractual Clauses Where Applicable
If the Customer requires the EU Standard Contractual Clauses, the parties will identify the applicable module, complete the annex information, and incorporate the SCCs by reference. The SCCs will govern the restricted transfer to the extent required by their terms. The public Security page and this DPA provide the baseline technical and organizational information for the relevant annexes.
20 / DPA
CCPA Service Provider / Contractor Terms
To the extent Megawebvision processes Personal Information under CCPA/CPRA, Megawebvision will process it only for the limited business purposes in the agreement and Customer instructions; will provide the applicable privacy protections; will not sell or share it; will not retain, use or disclose it outside the permitted business purposes; will not combine it with other data except as permitted by law; and will notify the Customer if it can no longer meet these obligations. Megawebvision will cooperate with reasonable remediation requests.
21 / DPA
Canadian Privacy Requirements
The parties will cooperate to support accountability, purpose specification, consent where applicable, limiting collection, safeguards, openness, individual access and correction under PIPEDA and applicable provincial privacy law. Megawebvision will process Customer Personal Data only for the Customer's documented purposes.
22 / DPA
Québec Privacy Requirements
Megawebvision will support the Customer's obligations under Québec privacy legislation, including transparency, confidentiality, retention and destruction, incident handling, privacy-rights assistance and governance requirements. The Privacy Officer identified in Privacy is the organizational contact for Québec privacy matters.
23 / DPA
Order of Precedence
If this DPA conflicts with the agreement, this DPA controls only for the subject matter of data protection and only to the extent necessary to resolve the conflict. If incorporated SCCs conflict with this DPA, the SCCs control for the restricted transfer.
24 / DPA
Term / Termination
This DPA begins when the applicable agreement begins and continues while Megawebvision processes Customer Personal Data. It ends when the agreement ends and all Customer Personal Data has been returned or deleted, subject to permitted legal retention.
25 / DPA
Contact
Privacy Officer: Timur Grigorchuk, Founder, Megawebvision.
Megawebvision Inc., 6860 Av. Irwin, Montreal, Quebec H4E 2S9, Canada.
legal@megawebvision.com
Annex A / Processing
Processing Details
Provision, security, support and customer-requested operation of CHIEF.
For the term of the applicable agreement, plus permitted deletion, backup and legal-retention periods.
Hosting, storage, scoped connected-service access, workflow preparation, security, support and optional AI-assisted synthesis.
Business contact details, customer-provided operating context, connected-service content, technical request data and support or security-report information.
Customer personnel, contractors, business contacts, service users and other individuals represented in customer-provided business information.
The agreement, order form, configured service scope and explicit customer requests, subject to applicable law and approved boundaries.
Annex B / Controls
Technical and Organizational Measures
- HTTPS for public service transport
- Default-off, narrow and account-scoped connected-service access
- Keychain-backed secret handling and repository exclusion of credentials
- Request origin, size, field and allowed-value validation
- Rate limiting and honeypot handling on public intake
- Private storage settings for submitted intake records
- Scoped external-write controls and audit records that exclude credentials and message content
- Version-controlled application and dependency configuration with repository security checks
- Credential exposure response, access reset and write-containment procedures
Additional measures may be agreed for a particular enterprise service or customer environment. The public Security Architecture & Controls page is the baseline description and is supplemented by qualified enterprise review materials.
Annex C / Providers
Approved Subprocessors
The current approved subprocessor list, service descriptions, data categories, effective date and change process are maintained at /subprocessors . The public registry is incorporated into this Annex by reference.