Data Processing Agreement

1) Introduction and application

‍

1.1 This Data Processing Agreement (the “DPA”) is published by Telamont Technologies Inc. (“Provider”, “we” or “us”) and governs Provider’s Processing of Personal Data on behalf of its customers (each, “Customer” or “you”) in connection with the Service.

1.2 This DPA is incorporated into, and forms part of, the Agreement. It applies to the extent Provider Processes Customer Personal Data on Customer’s behalf and that Processing is subject to Applicable Data Protection Laws. Where Processing is not subject to Applicable Data Protection Laws, the Agreement governs on its own.

1.3 No separate signature is required. Customer accepts this DPA by entering into the Agreement or by accessing or using the Service. Section 19 addresses requests for a signed counterpart.

1.4 This DPA does not relieve either party of any obligation it owes directly under Applicable Data Protection Laws.

1.5 Customer enters into this DPA on its own behalf and, to the extent required by Applicable Data Protection Laws, in the name of and on behalf of its Data Controller Affiliates. For the purposes of this DPA, “Customer” includes Customer and its Data Controller Affiliates. No third-party beneficiaries are intended.

1.6 Annex IV sets out terms that apply where a particular jurisdiction’s Applicable Data Protection Laws govern the Processing. Those terms are incorporated into this DPA.

‍

2) Definitions

‍

“Agreement” means the subscription, services or other written agreement between Provider and Customer governing Customer’s access to and use of the Service, including any order form and, where no separate written agreement applies, Provider’s published Terms of Service.

“AI System” means any machine-based system that, for explicit or implicit objectives, infers from the input it receives how to generate outputs such as predictions, content, recommendations or decisions.

“Applicable Data Protection Laws” means all laws and regulations governing the Processing of Personal Data that apply to the Processing under this DPA, including the GDPR, the UK GDPR, the Swiss Federal Act on Data Protection, the Personal Information Protection and Electronic Documents Act (Canada), the Act respecting the protection of personal information in the private sector (Québec), and applicable United States state privacy laws.

“Controller”, “Processor”, “Data Subject”, “Processing” and “Supervisory Authority” have the meanings given to them in the GDPR, or the equivalent meanings given under other Applicable Data Protection Laws.

“Data Controller Affiliate” means an affiliate of Customer that has not entered into its own order with Provider, that is subject to Applicable Data Protection Laws, and that is permitted to use the Service under the Agreement.

“Losses” means losses, damages, claims, actions, judgments, settlements, penalties, fines, costs and expenses, including reasonable legal fees.

“including” and its derivatives mean “including but not limited to”.

“Customer Personal Data” means Personal Data that Customer or its authorized users upload to, submit to, or make available through the Service, or that Provider Processes on Customer’s behalf under the Agreement.

“EEA SCCs” means the standard contractual clauses annexed to European Commission Implementing Decision (EU) 2021/914 of 4 June 2021.

“GDPR” means Regulation (EU) 2016/679.

“Personal Data” means any information relating to an identified or identifiable natural person, or information otherwise treated as personal data or personal information under Applicable Data Protection Laws.

“Security Incident” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Personal Data Processed by Provider or a Subprocessor.

“Service” means Provider’s risk operations platform for the construction industry, including the ingestion and analysis of project and contractual documentation, AI-assisted identification of technical, contractual and regulatory or code-related risks, and the related workflow, collaboration, integration and support functionality made available to Customer.

“Special Category Data” means the categories of Personal Data described in Article 9 of the GDPR, and equivalent categories under other Applicable Data Protection Laws.

“Subprocessor” means any third party engaged by Provider to Process Customer Personal Data in connection with the Service.

“UK Addendum” means the International Data Transfer Addendum to the EEA SCCs issued by the United Kingdom Information Commissioner under section 119A of the Data Protection Act 2018.

“UK GDPR” means Regulation (EU) 2016/679 as it forms part of the law of the United Kingdom by virtue of section 3 of the European Union (Withdrawal) Act 2018.

‍

3) Roles of the parties

‍

3.1 Where Customer is a Controller of Customer Personal Data, Provider acts as a Processor on Customer’s behalf.

3.2 Where Customer is itself a Processor acting on behalf of a third-party Controller, Provider acts as a Subprocessor. In that case Customer warrants that it has the Controller’s authorization to engage Provider on the terms of this DPA, and that its own agreement with the Controller requires it to comply with Applicable Data Protection Laws.

3.3 Provider acts as a Controller in respect of account administration, billing, and Provider’s own business operations. That Processing is governed by Provider’s Privacy Policy rather than by this DPA.

‍

4) Processing of Customer Personal Data

‍

4.1 Provider will Process Customer Personal Data only on Customer’s documented instructions, including with regard to transfers, unless required to Process it by a law to which Provider is subject. Where such a law applies, Provider will inform Customer of that requirement before Processing, unless the law prohibits doing so on important grounds of public interest.

4.2 Customer’s documented instructions comprise: this DPA; the Agreement; Customer’s configuration and use of the Service, including features Customer enables; and any further written instructions Customer gives and Provider acknowledges.

4.3 Instructions outside the scope of the documented instructions described in Section 4.2 require prior written agreement between the parties, including agreement on any additional fees payable for carrying them out.

4.4 The subject matter, duration, nature and purpose of the Processing, the categories of Data Subjects and the categories of Customer Personal Data are described in Annex I.

4.5 Provider will immediately inform Customer if, in Provider’s opinion, an instruction infringes Applicable Data Protection Laws, or if Provider is unable to comply with an instruction.

4.6 If Customer requires Provider to carry out an instruction that Provider has notified as infringing Applicable Data Protection Laws, or that Provider is unable to carry out lawfully, Provider may suspend performance of that instruction and, where the instruction cannot be separated from the Service, suspend the affected part of the Service, until the matter is resolved. Provider will limit any suspension to what is necessary and will cooperate with Customer in good faith to find a lawful alternative. If no lawful alternative can be found within thirty (30) days, either party may terminate the affected part of the Agreement on written notice.

4.7 Customer is responsible for the lawfulness of the Customer Personal Data it submits and of Provider’s Processing of it on Customer’s instructions, including for providing any notices and obtaining any consents required under Applicable Data Protection Laws.

4.8 Provider will not sell Customer Personal Data, will not share it for cross-context behavioural advertising, and will not Process it for Provider’s own commercial purposes or for any purpose outside the direct business relationship with Customer, except for the use of aggregated and de-identified or anonymized data permitted by Section 7.3.

4.9 Provider and its Subprocessors do not intentionally collect or Process Special Category Data in connection with the Service, and the Service is not designed for it. Customer may nonetheless choose to include Special Category Data within the content it instructs Provider to Process on its behalf. Where Customer does so, Customer is responsible for determining that the Processing is lawful, for providing any notices and obtaining any consents or authorizations required, and for assessing whether the measures in Annex II are appropriate to that data.

‍

5) Confidentiality and personnel

‍

5.1 Provider limits access to Customer Personal Data to personnel who require it to perform the Agreement, on a documented need-to-know basis and according to the principle of least privilege.

5.2 Provider ensures that personnel authorized to Process Customer Personal Data are bound by written confidentiality obligations, and that obligations surviving the end of their engagement are communicated to them at that time.

5.3 Provider ensures that such personnel receive security and data privacy training appropriate to their role and data handling responsibilities.

‍

6) Security

‍

6.1 Provider implements and maintains the technical and organisational measures described in Annex II, taking into account the state of the art, the costs of implementation, and the nature, scope, context and purposes of the Processing, as well as the risks to Data Subjects.

6.2 Provider may update the measures in Annex II from time to time, provided that no update materially reduces the overall level of protection of Customer Personal Data.

6.3 Customer is responsible for its own use of the Service, including configuring access controls, managing its authorized users, and determining whether the measures in Annex II are appropriate for the Customer Personal Data it submits.

‍

7) Artificial intelligence

‍

7.1 Provider will not use Customer Personal Data to train, fine-tune, or otherwise create or modify the parameters or weights of any AI System, whether operated by Provider or by a third party, and will not permit any Subprocessor to do so. This prohibition applies to Customer Personal Data in any form, including de-identified, anonymized and aggregated form, and is not limited or qualified by Sections 7.2 or 7.3.

7.2 Provider may Process Customer Personal Data to operate, secure, maintain, evaluate and improve the Service. Such Processing is limited to Provider’s personnel and the Subprocessors identified in the list referenced in Annex III, must not result in one Customer’s Customer Personal Data being disclosed or made available to another Customer, and is subject to Section 7.1.

7.3 Customer instructs Provider to create aggregated and de-identified or anonymized data derived from Customer Personal Data. Provider may use that data to operate, secure, analyze and improve the Service and to produce industry-level insights and benchmarks, provided that it does not identify and cannot reasonably be used to identify Customer, any authorized user, any Data Subject or any project, that it is not disclosed to any third party in a form that identifies Customer, and that it is not used for any purpose prohibited by Section 7.1. De-identification and anonymization are carried out in accordance with Applicable Data Protection Laws, including the criteria applicable under Québec law.

7.4 Provider engages its inference providers on terms that prohibit the use of Customer Personal Data to train or improve their models. Provider has in addition entered into zero data retention arrangements with certain of those providers. Zero data retention is not offered by every provider and is not in place with every Subprocessor. Where it applies, it is identified against the relevant Subprocessor in the list referenced in Annex III.

7.5 Where an output generated by an AI System from Customer Personal Data itself contains Personal Data, that output is Customer Personal Data under this DPA and is protected accordingly. This Section concerns data protection only and does not affect ownership of, or any rights in, outputs generated through the Service, which are governed by the Agreement.

7.6 Provider will not attempt to re-identify any de-identified or aggregated information derived from Customer Personal Data, and will inform Customer if re-identification occurs accidentally.

7.7 The list referred to in Annex III identifies which Subprocessors operate AI Systems and the Processing each performs.

‍

8) Subprocessors

‍

8.1 Customer gives Provider general written authorization to engage Subprocessors to Process Customer Personal Data, subject to this Section 8.

8.2 The current list of Subprocessors, including each Subprocessor’s identity, country of location and Processing tasks, is published at the location referenced in Annex III and forms part of this DPA.

8.3 Provider will give notice of any intended addition or replacement of a Subprocessor by updating that list and publishing an update to its subscribers, at least ten (10) business days before the new Subprocessor begins Processing Customer Personal Data. Customer may subscribe to those updates at the location referenced in Annex III and is responsible for maintaining a current subscription address.

8.4 Where a Subprocessor must be replaced urgently to preserve the security, integrity or availability of the Service, including following a security incident at the Subprocessor, its insolvency, its acquisition, or the loss of its certifications or its ability to perform, Provider may make the replacement without the advance notice period in Section 8.3. Provider will update the list referenced in Annex III and notify Customer as soon as practicable, and Customer’s rights in Sections 8.5 and 8.6 apply to that notice.

8.5 Customer may object to an intended change on reasonable grounds relating to data protection. If Customer does not object within ten (10) days of notice, the Subprocessor is deemed accepted.

8.6 Where Customer objects, Provider may resolve the objection by any of the following, selected at Provider’s discretion: cancelling its plans to use the Subprocessor in respect of Customer Personal Data; taking the corrective steps Customer requested and proceeding to use the Subprocessor; ceasing to provide, or Customer agreeing not to use, the part of the Service that involves the Subprocessor; or providing Customer with a written description of commercially reasonable alternatives. If Provider cannot provide an alternative, or Customer does not accept one offered, either party may terminate the affected part of the Agreement on written notice. Termination does not relieve Customer of fees owed for the Service provided up to the effective date of termination.

8.7 Before engaging a Subprocessor, Provider assesses it under Provider’s third-party management process and engages it under a written agreement imposing data protection obligations no less protective than those in this DPA, including, where the GDPR applies, the obligations referred to in Article 28(3).

8.8 Provider remains fully liable to Customer for the performance of each Subprocessor’s obligations, and will notify Customer of any failure by a Subprocessor to fulfil a material data protection obligation of which Provider becomes aware.

8.9 On written request, Provider will describe the data protection terms it has imposed on a Subprocessor.

‍

9) Data Subject rights

‍

9.1 The Service provides Customer with functionality to access, correct, export and delete Customer Personal Data. Customer is responsible for using that functionality to respond to requests from Data Subjects.

9.2 Taking into account the nature of the Processing, Provider will assist Customer by appropriate technical and organisational measures, insofar as possible, in fulfilling Customer’s obligation to respond to requests from Data Subjects exercising their rights under Applicable Data Protection Laws, to the extent Customer cannot do so through the Service.

9.3 If Provider receives a request from a Data Subject relating to Customer Personal Data, Provider will promptly inform Customer and will not respond to the request itself, except that Customer authorizes Provider to redirect the request to Customer so that Customer can respond directly, and except where Applicable Data Protection Laws require Provider to respond. Where Provider is required to respond, it will inform Customer first unless prohibited from doing so.

‍

10) Assistance and cooperation

‍

10.1 Taking into account the nature of the Processing and the information available to Provider, Provider will provide reasonable assistance to Customer in meeting Customer’s obligations in relation to the security of Processing, Security Incident notification, data protection impact assessments, privacy impact assessments required under Québec law in respect of communications of personal information outside Québec, and prior consultation with Supervisory Authorities.

10.2 Where assistance under Section 9 or this Section 10 requires significant effort beyond what the Service provides, Provider may charge a reasonable fee, notified to Customer in advance.

‍

11) Security Incidents

‍

11.1 Provider will notify Customer without undue delay, and in any event within seventy-two (72) hours, after confirming a Security Incident that is known or reasonably suspected to affect Customer Personal Data, except where notification is prohibited by law.

11.2 The notification will describe, to the extent known at the time and supplemented as further information becomes available: the nature of the Security Incident, including where possible the categories and approximate number of Data Subjects and records concerned; the likely consequences; the measures taken or proposed to address it and to mitigate its effects; and a contact point at Provider from whom further information can be obtained.

11.3 Provider will take reasonable steps to contain, investigate and remediate the Security Incident, and will provide reasonable cooperation to Customer in Customer’s own response, including any notification Customer is required to make. Section 10.2 applies to cooperation that requires significant effort beyond what the Service provides.

11.4 Sections 11.1 to 11.3 do not apply to a Security Incident caused by Customer, Customer’s authorized users, or the misuse or compromise of Customer’s access credentials.

11.5 Provider’s notification of or response to a Security Incident is not an acknowledgement of fault or liability.

‍

12) Government and law enforcement access

‍

12.1 Where Provider receives a request for Customer Personal Data from a law enforcement agency, regulator or other governmental authority, Provider will seek to redirect the requester to Customer. Provider will not disclose Customer Personal Data in response to such a request unless disclosure is mandatory under applicable law or Customer has approved it in writing. This Section does not restrict Provider from making disclosures relating to its own legal position, including reporting an offence committed against Provider or responding to an authority regarding Provider’s own compliance.

12.2 Where not prohibited by applicable law, Provider will notify Customer before any proposed disclosure of any order, demand, warrant or similar instrument compelling production of Customer Personal Data, and will provide the nature of the instrument, the information sought, the issuing authority, and the date and any deadline for response, in time for Customer to respond or challenge it. Where notice is prohibited, Provider will use reasonable efforts to obtain a waiver of the prohibition.

12.3 As of the Effective date and to the best of Provider’s knowledge, Provider declares that it has not created back doors or similar programming capable of being used to access its systems or Customer Personal Data, that it has not designed or altered its business processes to facilitate such access, and that no national law or government policy applicable to Provider requires it to create or maintain such access or to surrender encryption keys.

‍

13) Audits, reports and due diligence

‍

13.1 Provider will make available to Customer the information reasonably necessary to demonstrate compliance with this DPA and with Article 28 of the GDPR where it applies. Provider’s information security policies and supporting control documentation may be requested through Provider’s Trust Center at https://trust.telamont.com. That material is Provider’s Confidential Information, and Provider may condition access on Customer entering into a non-disclosure agreement.

13.2 Provider maintains a programme of independent third-party examination against the SOC 2 Trust Services Criteria and of independent penetration testing, and intends to renew each annually. On written request, Provider will provide Customer with a copy of its then-current audit report and most recent penetration test report, on a confidential basis. Customer agrees that these reports are the primary means of verifying Provider’s compliance.

13.3 Reports provided under Section 13.2 are Provider’s Confidential Information. Provider will also provide, on request, third-party audit reports relating to its Subprocessors to the extent those reports may be shared with Customer. Customer acknowledges that such reports are also the confidential information of the Subprocessor, and that a Subprocessor may require Customer to enter into a non-disclosure agreement before the report is made available.

13.4 Provider will respond to reasonable security due diligence requests, including security questionnaires, made in writing to the contact in Section 20. Such requests may be made once in any twelve (12) month period.

13.5 Where Applicable Data Protection Laws entitle Customer to an audit or inspection that cannot be satisfied under Sections 13.1 to 13.3, or where a Supervisory Authority requires one, Customer or an independent auditor appointed by Customer and reasonably acceptable to Provider may conduct an audit, on at least thirty (30) days’ written notice, during business hours, no more than once in any twelve (12) month period, subject to confidentiality obligations, and in a manner that does not interfere unreasonably with Provider’s operations or compromise the confidentiality of other customers’ data. Customer bears the cost of such an audit.

13.6 Provider maintains records of its compliance with this DPA for three (3) years after this DPA ends.

‍

14) International transfers

‍

14.1 Customer authorizes Provider to transfer Customer Personal Data outside the jurisdiction in which it was collected as necessary to provide the Service, subject to this Section 14. Annex II describes where Customer Personal Data is hosted, and the list referenced in Annex III identifies the location of each Subprocessor.

14.2 Where the GDPR applies, the transfer is from Customer within the European Economic Area to Provider outside it, and the transfer is not covered by an adequacy decision of the European Commission, the parties are deemed to have entered into the EEA SCCs, which are incorporated into this DPA by reference and completed as follows:

  • Module Two (Controller to Processor) applies where Customer is a Controller. Module Three (Processor to Processor) applies where Customer is a Processor.
  • The optional docking clause in Clause 7 does not apply.
  • In Clause 9, Option 2 (general written authorization) applies, with a notice period of ten (10) business days as set out in Section 8.3.
  • The optional language in Clause 11 does not apply.
  • In Clause 17 (Option 1), the EEA SCCs are governed by the law of Ireland.
  • For the purposes of Clause 18(b), disputes are resolved before the courts of Ireland.
  • Annex I of this DPA serves as Annex I to the EEA SCCs, Annex II of this DPA serves as Annex II, and the list referenced in Annex III of this DPA serves as Annex III.

14.3 Where the UK GDPR applies and the transfer is not covered by United Kingdom adequacy regulations, the parties are deemed to have entered into the UK Addendum, which is incorporated into this DPA by reference. In Table 1, the exporter is Customer and the importer is Provider. In Table 2, the version of the EEA SCCs is as completed in Section 14.2. In Table 3, the Annexes of this DPA apply as described in Section 14.2. In Table 4, neither party may end the UK Addendum as set out in section 19 of the UK Addendum.

14.4 Where Swiss law applies to the international nature of the transfer, references in the EEA SCCs to the GDPR are to be read as references to the Swiss Federal Act on Data Protection to the extent legally required, and the competent authority includes the Swiss Federal Data Protection and Information Commissioner.

14.5 If a transfer mechanism in this Section 14 is invalidated or replaced, the parties will cooperate in good faith to implement a valid alternative mechanism.

‍

15) Return and deletion

‍

15.1 Customer may delete Customer Personal Data at any time through the functionality of the Service, and may export it in a commonly used format.

15.2 On expiry or termination of the Agreement, Provider will delete Customer accounts and Customer Personal Data within thirty (30) days, unless Customer instructs return of the data within that period, or unless further retention is required by applicable law. Return is made in a format Provider supports or can readily produce. Where Customer requires a format Provider does not support, the parties will agree a commercially reasonable approach and any associated fee before the data is produced.

15.3 Customer Personal Data held in Provider’s routine backups is not deleted on demand. It is overwritten or expires in the ordinary course of Provider’s backup rotation, remains subject to the measures in Annex II for as long as it persists, and is not restored to production except as part of a disaster recovery event.

15.4 Where further retention is required by applicable law, Provider will retain the Customer Personal Data only for the period and purpose required, and will continue to protect it in accordance with this DPA.

15.5 Customer acknowledges that the Service operates as a system of record for project and contractual documentation, and that such records may need to be retained for the establishment, exercise or defence of legal claims. As an equivalent to deletion, Provider may permanently and securely anonymize Customer Personal Data so that no individual can be identified from it.

15.6 Provider will certify deletion or anonymization in writing on Customer’s request.

‍

16) Indemnification and liability

‍

16.1 To the maximum extent permitted by applicable law, and in addition to any indemnity in the Agreement, Customer will defend, indemnify and hold harmless Provider, its affiliates and its Subprocessors, and their respective officers, directors, employees and agents, from and against any Losses resulting from Customer’s breach of this DPA or from the infringement or violation by Customer or its authorized users of any privacy or other right of any person under Applicable Data Protection Laws.

16.2 Provider is not liable for any loss, damage, corruption or failure to recover Customer Personal Data arising from Customer’s breach of its obligations under this DPA.

16.3 Each party’s liability arising out of or related to this DPA is subject to the exclusions and limitations of liability set out in the Agreement, to the maximum extent permitted by Applicable Data Protection Laws.

16.4 Nothing in this Section limits either party’s responsibility to pay penalties imposed on it by a regulatory authority, or either party’s liability for Data Subject claims where Applicable Data Protection Laws impose joint and several liability.

16.5 Nothing in this DPA limits any liability to a Data Subject in respect of that Data Subject’s rights under Applicable Data Protection Laws, or any liability between the parties under the EEA SCCs or the UK Addendum.

16.6 Claims arising out of or related to this DPA may be brought only by the Customer entity that is party to the Agreement. The liability caps in the Agreement apply in aggregate to Customer and all of its Data Controller Affiliates taken together, and not individually to each of them.

‍

17) Term

‍

17.1 This DPA takes effect when Customer accepts the Agreement and continues until the Agreement expires or is terminated. Provider’s obligations in respect of Customer Personal Data continue for as long as Provider Processes it.

‍

18) Order of precedence and governing law

‍

18.1 In the event of a conflict, the following order applies: first, the EEA SCCs or the UK Addendum; second, this DPA; third, the Agreement.

18.2 This DPA is governed by the laws of the Province of Québec and the federal laws of Canada applicable in that province, and the parties submit to the exclusive jurisdiction of the courts of the judicial district of Québec. This Section does not affect the governing law and forum that apply to the EEA SCCs or the UK Addendum under Section 14, which prevail over this Section to the extent of any conflict.

‍

19) Changes and acceptance

‍

19.1 This DPA applies automatically and does not require signature. Provider does not ordinarily execute signed counterparts or customer-specific data processing agreements. Where Customer’s procurement process requires a signed instrument, Provider may, at its sole discretion, execute a counterpart of this DPA without changes, ordinarily in connection with an enterprise order form. Nothing in this DPA obliges Provider to execute a counterpart or to enter into a customer-specific data processing agreement.

19.2 This DPA is published on standard terms and is not ordinarily negotiated. Provider will consider requested amendments at its sole discretion. Nothing in this Section obliges Provider to enter into a customer-specific data processing agreement. Any amendment is effective only if set out in a separate written document signed by both parties, and until then this DPA applies as published.

19.3 A counterpart executed under Section 19.1 records the version of this DPA in effect on the date of signature. It does not prevent updates made under Section 19.4 from applying, and Customer remains subject to the current published version.

19.4 Provider may update this DPA from time to time, including to reflect changes to the measures described in Annex II or to the list referenced in Annex III. Provider will update the “Last updated” date above and, for changes that materially affect Customer’s rights, will give Customer reasonable advance notice. No update will materially reduce the overall level of protection of Customer Personal Data.

‍

20) Contact and notices

‍

Privacy and legal: legal@telamont.com (Attn: Legal)

Security: security@telamont.com

Telamont Technologies Inc., 2720, rue de Moscou, Québec (Québec) G2B 0M3, Canada. Telamont Technologies Inc. is also registered under the French-language name Technologies Telamont inc.

20.1 Notices to Provider under this DPA are validly given by email to legal@telamont.com, and security matters may also be raised at security@telamont.com. Notices to Customer are validly given by email to the administrative or billing contact in Customer’s account or in the Agreement.

20.2 A notice is deemed received on the day it is sent if sent on a business day, and otherwise on the next business day.

20.3 For changes to the Approved Subprocessors, publication of an update to the list referenced in Annex III together with a Trust Center update to subscribers constitutes notice, as described in Section 8.3. It is Customer’s responsibility to maintain a current subscription address.

‍

21) Language

‍

21.1 This DPA is published in English and in French. In the event of any discrepancy between the two versions, the English version governs.

‍

Annex I: Description of the Processing

‍

‍

A. Parties

‍

Data exporter: Customer, as identified in the Agreement, at the address set out in the Agreement or the applicable order form. Customer uses the Service to upload, store, analyze and act upon project and contractual documentation relating to its construction or design projects. Customer acts as Controller, or as Processor where it Processes the Customer Personal Data on behalf of a third-party Controller. Signature and date are recorded on Customer’s entry into the Agreement, which incorporates this DPA.

Data importer: Telamont Technologies Inc., 2720, rue de Moscou, Québec (Québec) G2B 0M3, Canada. Contact: legal@telamont.com (Attn: Legal); security matters: security@telamont.com. Provider hosts and operates the Service and Processes Customer Personal Data to provide and maintain it in accordance with Customer’s instructions. Provider acts as Processor, or as Subprocessor where Customer acts as a Processor. Signature and date are recorded on Customer’s entry into the Agreement, which incorporates this DPA.

‍

B. Categories of Data Subjects

‍

  • Customer’s personnel, contractors and other authorized users of the Service.
  • Individuals identified in the project and contractual documentation that Customer uploads to, or connects to, the Service, including employees, representatives and agents of project owners, general contractors, subcontractors, design professionals, consultants, suppliers and other project participants.
  • Individuals named in correspondence, notices, meeting records and other project records submitted to the Service.

‍

C. Categories of Personal Data

‍

  • Identification and contact data: name, job title, employer or organization, business email address, business telephone number, business address.
  • Account and authentication data: user and organization identifiers, account role and permissions, authentication events and metadata, multi-factor authentication status, and optional telephone number.
  • Technical and usage data: IP address, device and browser information, log data, session data and feature usage data.
  • Content data: Personal Data appearing incidentally within the documents and records Customer submits to the Service, including contracts, subcontracts, plans, specifications, geotechnical studies, schedules, change documentation, correspondence and notices, together with the analysis, extracted references and draft notices the Service generates from that content.
  • Configuration data: information Customer enters to configure its projects, organization and workflows within the Service.

‍

D. Special Category Data

‍

Provider does not intentionally collect or Process Special Category Data in connection with the Service. Section 4.9 governs Special Category Data that Customer nonetheless elects to submit.

‍

E. Frequency of transfer

‍

Continuous, on an ongoing basis for the duration of the Agreement.

‍

F. Nature and purpose of the Processing

‍

Provider Processes Customer Personal Data to provide and maintain the Service, including to:

  • host, store, index, transmit and back up Customer Personal Data;
  • process and structure submitted documentation, including text extraction, segmentation and the generation of vector representations, in order to make it searchable and analyzable;
  • perform AI-assisted analysis to identify technical, contractual and regulatory or code-related risks, and to generate the resulting findings, clause references and draft notices;
  • retrieve publicly available web information in order to identify and map counterparties named in submitted documentation;
  • generate voice or audio output where Customer enables features that use it;
  • authenticate users and administer access, roles and permissions;
  • synchronize documentation from Customer-authorized third-party systems where Customer enables such an integration;
  • send transactional, service and product notification messages to authorized users, and product update communications where permitted;
  • provide support, troubleshooting and service communications; and
  • monitor, secure, maintain and improve the availability, integrity and performance of the Service;
  • create aggregated and de-identified or anonymized data as described in Section 7.3.

‍

G. Duration of the Processing

‍

For the term of the Agreement, followed by deletion in accordance with Section 15.

‍

H. Processing by Subprocessors

‍

Each Subprocessor Processes Customer Personal Data only for the Processing task described for it in the list referenced in Annex III, only to the extent required to perform the obligations subcontracted to it, and only for the duration of the Agreement.

‍

I. Competent Supervisory Authority

‍

Where the EEA SCCs apply, the competent Supervisory Authority is that of the European Economic Area member state in which Customer is established. Where Customer is not established in a member state but has appointed a representative under Article 27 of the GDPR, it is that of the member state in which the representative is established. Where neither applies, it is the Data Protection Commission of Ireland. Where the UK Addendum applies, it is the United Kingdom Information Commissioner’s Office.

‍

Annex II: Technical and organisational measures

‍

Provider maintains a documented information security program comprising the policies named below. Each policy is owned by a named executive and is subject to periodic review and re-approval.

This Annex describes the controls Provider operates. The policies named under each heading govern how those controls are implemented, including the frequencies, thresholds and procedures that apply to them, and that operating detail may change as those policies are reviewed, subject to Section 6.2. The policies do not reduce or override the commitments stated in this DPA.

The current policies, and the control documentation supporting them, may be requested through Provider’s Trust Center at https://trust.telamont.com. They are Provider’s Confidential Information, and access may be conditioned on Customer entering into a non-disclosure agreement.

‍

1. Governance

‍

Governing policies: Information Security Policy, Information Security Roles and Responsibilities, Risk Management Policy, Code of Conduct.

  • Information security roles and responsibilities are defined and assigned, with an accountable security owner.
  • The policy set covers information security, access control, cryptography, data management, operations security, secure development, asset management, physical security, human resource security, third-party management, risk management, incident response, and business continuity and disaster recovery.
  • Formal risk assessments are performed under an established methodology, with risks recorded in a risk register and addressed through documented treatment plans.

‍

2. Data classification and handling

‍

Governing policy: Data Management Policy.

  • Customer Data and Personal Data are classified at Provider’s highest sensitivity level and handled accordingly.
  • Systems holding data at that level do not permit unauthenticated or anonymous access.
  • Such data is not used or stored in non-production systems or environments except with documented executive approval, and is scrubbed of sensitive information wherever feasible when approved.
  • Such data may not be stored on personal devices or removable media, and is transferred outside Provider only under a written contract or arrangement and with documented approval.

‍

3. Encryption

‍

Governing policy: Cryptography Policy.

  • Customer Personal Data is encrypted in transit over public networks and encrypted at rest, using strong algorithms and key lengths aligned to recognized standards.
  • Endpoint devices used to access data at Provider’s highest sensitivity level are encrypted.
  • Cryptographic keys are managed across their lifecycle, with access to keys and secrets controlled under the Access Control Policy.

‍

4. Access control and authentication

‍

Governing policy: Access Control Policy.

  • Access to Customer Personal Data is limited to personnel with a business need, granted on the principle of least privilege through role-based access control, and documented.
  • Access beyond standard pre-approved access requires documented approval from the system or data owner.
  • Multi-factor authentication is enforced for access to production systems.
  • Personnel hold unique identifiers and do not share credentials. Where shared administrative credentials are operationally necessary, they are held in an enterprise credential management system and their use is restricted.
  • Access rights are reviewed and documented on a recurring basis and on any role change, and are revoked promptly on termination of employment or engagement.
  • Production authentication for the Service uses a dedicated identity provider with tenant-level separation of Customer organizations.

‍

5. Endpoints, media and disposal

‍

Governing policies: Asset Management Policy, Data Management Policy, Information Security Policy.

  • Endpoint devices are centrally managed, encrypted, and configured to lock automatically after a period of inactivity.
  • Assets holding classified information are inventoried and owned by a named individual or group, and are returned on termination.
  • Devices and media that stored or processed data at Provider’s highest sensitivity level are securely erased before disposal or re-use using a method selected in accordance with recognized media sanitization standards, or destroyed by a third party against a certificate of destruction.

‍

6. Operations security, logging and vulnerability management

‍

Governing policy: Operations Security Policy.

  • Changes to production systems are documented, tested, reviewed and approved before deployment, with emergency changes subject to retrospective review.
  • Production infrastructure and applications are logged and monitored, with alerting to on-call personnel. Logs record user and administrator activity, including administrator access to customer data, are protected against tampering, and are retained for a defined minimum period.
  • Technical vulnerabilities are identified through vulnerability scanning, penetration testing and vendor advisories, assessed for severity, and remediated within timeframes defined by severity. A vulnerability that cannot be remediated within the standard timeline requires a documented risk treatment plan.
  • Independent penetration testing of the applications and production network is performed on a recurring basis and following major changes. The most recent report is available on request.
  • Anti-malware protection is deployed on company-issued endpoints, with threat detection and response applied to company email.
  • Production systems are provisioned against documented configuration and hardening standards aligned to recognized baselines, with network access rules subject to recurring review.

‍

7. Secure development

‍

Governing policy: Secure Development Policy.

  • Secure-by-design and privacy-by-design principles are applied across the development lifecycle.
  • Source code is version controlled with access restricted by role. Significant changes are reviewed and approved by a senior developer before merging to a production branch, and no single individual develops, tests and deploys a change without approval and oversight.
  • Production, staging and development environments are logically or physically segregated. Customer data is not used for testing without explicit documented approval.
  • Application code is scanned before deployment, and code is not deployed to production without documented successful test results and evidence of remediation.
  • Developers receive secure development training on a recurring basis.

‍

8. Resilience and business continuity

‍

Governing policies: Business Continuity and Disaster Recovery Plan, Operations Security Policy.

  • Backups of in-scope systems are taken on a recurring schedule, are held in Canadian cloud locations, and are stored separately from the production data location.
  • Backups are protected by security measures appropriate to the sensitivity of the data they contain.
  • Disaster recovery, including restoration from backup, is tested on a recurring basis, and the plan is subject to periodic review.

‍

9. Incident response

‍

Governing policy: Incident Response Plan.

  • A documented incident response plan is maintained, and is subject to periodic review and testing.
  • A dedicated reporting channel is maintained at security@telamont.com, with defined severity classification, escalation paths and documentation requirements.
  • Breach determinations are made by Provider’s security owner together with legal counsel and executive management.
  • Root cause analysis and post-incident review are performed and documented for critical incidents.

‍

10. Personnel

‍

Governing policies: Human Resource Security Policy, Code of Conduct.

  • Background verification is carried out on personnel in accordance with applicable law and proportionate to the classification of information accessed. Third parties with privileged or administrative access to production systems are subject to equivalent screening.
  • Personnel and contractors sign non-disclosure and confidentiality agreements, and obligations surviving termination are communicated at that time.
  • Personnel, and third parties with privileged technical access, complete security awareness training on hire and on a recurring basis thereafter, and receive security and data privacy training appropriate to their role.
  • Physical and logical access is revoked and company equipment is returned on termination.

‍

11. Physical security

‍

Governing policy: Physical Security Policy.

  • Customer Personal Data is hosted in the data centres of Provider’s cloud infrastructure provider, which maintains physical and environmental controls audited under recognized third-party assurance programs.
  • Provider does not store Customer Personal Data in paper form or on local media at its own premises. Provider’s facilities apply entry controls, visitor management and environmental protections appropriate to the information held.

‍

12. Data location

‍

Project documentation, the production database, file storage and backups are hosted in Canada. Certain Subprocessors Process limited categories of Customer Personal Data outside Canada, principally in the United States, including model inference, logging and error monitoring, product analytics, in-app feedback, email delivery and web retrieval. The location of each Subprocessor is identified in the list referenced in Annex III.

‍

13. Subprocessor management

‍

Governing policy: Third-Party Management Policy.

  • Data at Provider’s highest sensitivity level is not shared with or transmitted to a third party before a risk assessment has been performed and a written contract executed.
  • Assessments consider the third party’s information security program, risk management, operations security, access control, secure development, physical security, personnel screening, and its protection, retention and disposition of customer data.
  • Supplier security and service delivery performance is subject to recurring review.

‍

14. Assurance

‍

  • Provider maintains independent third-party examination against the SOC 2 Trust Services Criteria, as described in Section 13.2.
  • Continuous control monitoring is maintained through a third-party compliance platform.

‍

Annex III: Subprocessors

‍

The current list of Subprocessors, including each Subprocessor’s identity, country of location and Processing tasks, is published at https://trust.telamont.com and forms part of this DPA. Customer may subscribe at that location to receive notice of changes, as described in Section 8.3.

Where a Subprocessor publishes its own trust centre or security documentation, the list includes a link to it, so that Customer can review that Subprocessor’s controls directly. Those materials describe the Subprocessor’s own security posture. The data protection terms Provider has imposed on a Subprocessor are addressed separately in Section 8.9.

‍

Annex IV: Jurisdiction-specific terms

‍

The terms in this Annex apply where the Applicable Data Protection Laws of the named jurisdiction govern the Processing. Provider’s obligations under those laws are only the obligations those laws impose on a processor or equivalent role.

‍

A. Canada

‍

This Part applies where the Personal Information Protection and Electronic Documents Act or the Act respecting the protection of personal information in the private sector (Québec) applies.

  • Provider Processes the personal information only to perform the Agreement and for no other purpose, and will not retain it longer than necessary for that purpose or as required by law.
  • Provider applies the protection measures described in Annex II, which are intended to provide a level of protection comparable to that required of Customer.
  • Where Customer is required to conduct a privacy impact assessment before communicating personal information outside Québec, Provider will provide the information reasonably necessary for that assessment, including the measures in Annex II and the locations identified in the list referenced in Annex III.
  • Provider will notify Customer of any confidentiality incident in accordance with Section 11, and will provide the information Customer requires to maintain its own register of confidentiality incidents.
  • The terms Controller and Processor are to be read as referring to the equivalent roles under the applicable Canadian legislation.

‍

B. United States

‍

This Part applies where a United States federal or state privacy law applies, including the California Consumer Privacy Act as amended by the California Privacy Rights Act.

  • Provider will not sell or share Customer Personal Data.
  • Provider will not retain, use or disclose Customer Personal Data for any purpose other than performing the Service, including for any commercial purpose other than performing the Service, and will not do so outside the direct business relationship between the parties. This does not restrict Provider’s use of deidentified or aggregated information as permitted by Section 7.3 and by the applicable law.
  • Provider will not combine Customer Personal Data with personal information it receives from another source, except as permitted by applicable law or as authorized by Customer.
  • In this Part, Personal Data means personal information, Controller means business, Processor means service provider, and Data Subject means consumer, each as defined in the applicable law.
  • Provider will notify Customer if it determines it can no longer meet its obligations under the applicable law.

‍

C. European Economic Area, United Kingdom and Switzerland

‍

Section 14 sets out the transfer mechanisms and the elections that apply to the EEA SCCs and the UK Addendum. Where the GDPR applies, Provider’s obligations are those imposed on a processor by Article 28 of the GDPR.

‍

Effective date: October 8, 2026

Last updated: October 8, 2026