Data Processing Agreement
This Data Processing Agreement governs the processing of personal data by Completix on behalf of a customer in connection with the Completix project and portfolio management platform. It is entered into pursuant to Article 28 of the GDPR and forms part of the terms governing the provision of the Completix services. Where this DPA conflicts with the principal agreement, this DPA prevails on data protection matters.
This is the standard version of the DPA offered to Completix customers. Terms may be varied by signed amendment or by the applicable order form. To execute a signed copy referencing your organisation and effective date, contact [email protected].
| Controller | The client organisation identified in the applicable order form or principal agreement ("Client" or "Controller") |
|---|---|
| Processor | Completix Inc., a corporation incorporated in Ontario, Canada ("Completix" or "Processor") |
| Version | 3.0, August 2026 |
| Governing Law | Province of Ontario, Canada |
Jump to a section within this document
1. Definitions
In this Agreement, the following terms have the meanings set out below.
"Applicable Data Protection Laws" means the GDPR, the UK GDPR as retained in UK law, PIPEDA, and any other data protection or privacy legislation applicable to the processing under this Agreement, as amended from time to time.
"GDPR" means Regulation (EU) 2016/679.
"Personal Data" means any information relating to an identified or identifiable natural person, processed by Completix on behalf of the Client under this Agreement.
"Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data processed under this Agreement.
"Processing" has the meaning given in Article 4(2) GDPR.
"Standard Contractual Clauses" or "SCCs" means the standard contractual clauses adopted by European Commission Decision 2021/914/EU.
"Sub-processor" means any third party engaged by Completix to process personal data on behalf of the Client.
Terms not defined in this Agreement have the meaning given in Applicable Data Protection Laws or in the principal agreement.
2. Roles, Scope and Duration
2.1 The Client acts as controller and Completix acts as processor in respect of personal data processed under this Agreement.
2.2 The subject matter, duration, nature and purpose of the processing, the types of personal data, and the categories of data subjects are set out in Annex I.
2.3 The Client is responsible for ensuring it has a lawful basis for the processing it instructs Completix to perform.
2.4 This Agreement commences on the Effective Date and continues for the duration of the Services. Section 9 survives termination.
2.5 The Services are not designed to process special categories of personal data under Article 9 GDPR or criminal conviction data under Article 10 GDPR. The Client shall not submit such data without a separate written addendum. Where such data is submitted inadvertently, Completix shall apply the measures in Annex III to it.
3. Processing Instructions
3.1 Completix shall process personal data only on documented instructions from the Client, including with regard to transfers to a third country. The Client's instructions are given through its use and configuration of the Services, through this Agreement and the principal agreement, and through written communications from authorised Client representatives.
3.2 Completix shall not process personal data for its own purposes. Without limiting this, Completix shall not use personal data or Client content to train, fine-tune, or improve any machine learning or artificial intelligence model, and shall not permit any sub-processor to do so. Completix may generate and use aggregated statistical information that does not identify the Client, any data subject, or any Client content.
3.3 If Completix considers that an instruction infringes Applicable Data Protection Laws, it shall inform the Client without delay and shall not be obliged to follow the instruction until the Client has confirmed or modified it.
3.4 If Completix is required by Union or Member State law to process personal data other than on the Client's instructions, it shall inform the Client of that requirement before processing, unless the law prohibits notification.
4. Processor Obligations
In accordance with Article 28(3) GDPR, Completix shall:
4.1 Confidentiality
Ensure that personnel authorised to process personal data are bound by appropriate confidentiality obligations, and that access is limited to those who need it to perform the Services.
4.2 Security
Implement and maintain the technical and organisational measures set out in Annex III, in accordance with Article 32 GDPR.
4.3 Sub-processing
Engage sub-processors only in accordance with Section 5.
4.4 Data subject rights
Taking into account the nature of the processing, provide reasonable assistance to the Client in responding to requests from data subjects exercising rights under Articles 15 to 22 GDPR, to the extent the Client cannot address the request through its own use of the Services.
4.5 Assistance under Articles 32 to 36
Taking into account the nature of the processing and the information available to Completix, assist the Client in complying with its obligations regarding security of processing, breach notification, data protection impact assessments, and prior consultation with supervisory authorities.
4.6 Deletion or return
At the choice of the Client, delete or return personal data in accordance with Section 9.
4.7 Demonstrating compliance
Make available to the Client the information necessary to demonstrate compliance with Article 28 GDPR, and allow for and contribute to audits in accordance with Section 7.
5. Sub-processing
5.1 The Client grants general written authorisation for Completix to engage the sub-processors identified in Annex II as at the Effective Date.
5.2 Completix has entered into a written agreement with each sub-processor that provides for data protection obligations equivalent in substance to those set out in this Agreement. Completix remains liable to the Client for the performance of each sub-processor's data protection obligations.
5.3 Completix shall notify the Client of any intended addition or replacement of a sub-processor at least fifteen (15) days before the change takes effect. The Client may object on reasonable data protection grounds within that period. If the parties cannot resolve the objection within a further fifteen (15) days, either party may terminate the affected Services on written notice.
6. International Data Transfers
6.1 Canada. Completix is established in Ontario, Canada. Canada benefits from an adequacy decision of the European Commission in respect of organisations subject to PIPEDA. Transfers of personal data from the EU/EEA to Completix are therefore made under Article 45 GDPR without additional transfer safeguards.
6.2 Onward transfers. Personal data may be transferred to sub-processors located in the United States, as identified in Annex II. Such transfers are made under the Standard Contractual Clauses, incorporated into Completix's agreements with each such sub-processor. Module 2 applies where the sub-processor acts as Completix's processor, and Module 1 applies where the sub-processor acts as an independent controller. Completix maintains evidence of these arrangements and shall make it available to the Client on request.
6.3 Change in transfer mechanism. If the adequacy decision referred to in Section 6.1 is invalidated, suspended, withdrawn, or amended so that it no longer covers transfers under this Agreement, the Standard Contractual Clauses (Module 2, controller to processor) shall apply automatically to those transfers from the effective date of that change, without further action by either party. The Client is the data exporter and Completix is the data importer. Annex I of this Agreement populates Annex I of the SCCs and Annex III populates Annex II of the SCCs. Clause 7 (docking) does not apply. In Clause 9(a), Option 2 applies with the notice period set out in Section 5.3. In Clause 11, the optional language does not apply. In Clause 17, Irish law governs, and under Clause 18(b) disputes are heard before the courts of Ireland. The UK International Data Transfer Addendum applies on equivalent terms to transfers from the United Kingdom.
6.4 Requests from public authorities. If Completix receives a legally binding request from a public authority for disclosure of personal data processed under this Agreement, it shall notify the Client without undue delay unless prohibited by law, and where prohibited shall use best efforts to obtain a waiver. Completix shall disclose only the minimum personal data permissible on a reasonable interpretation of the request, and shall challenge requests where it concludes on careful assessment that there are reasonable grounds to consider them unlawful.
7. Audit
7.1 Completix shall make available to the Client the information necessary to demonstrate compliance with Article 28 GDPR, and shall allow for and contribute to audits, including inspections, conducted by the Client or a mandated third-party auditor.
7.2 Audits shall be conducted no more than once per calendar year, save where required by a supervisory authority or following a confirmed Personal Data Breach, and shall require at least thirty (30) days' prior written notice.
7.3 Audits shall not extend to source code, other customers' data, or underlying cloud infrastructure beyond the compliance documentation published by the relevant provider, and are subject to confidentiality obligations at least equivalent to those in the principal agreement.
7.4 Completix may satisfy its obligations under this Section, in whole or in part, by providing current third-party certifications and audit reports, including SOC 2 reports and ISO 27001 certificates, and by responding to written questionnaires.
7.5 Audits are conducted at the Client's expense unless otherwise required by law or by a supervisory authority.
8. Personal Data Breach
8.1 Completix shall notify the Client without undue delay after becoming aware of a Personal Data Breach affecting personal data processed under this Agreement.
8.2 The notification shall include, to the extent known:
- The nature of the breach, including the categories and approximate number of data subjects and records affected
- The contact point at Completix for further information
- The likely consequences of the breach
- The measures taken or proposed to address the breach, including measures to mitigate its possible adverse effects
8.3 Where complete information is not available at the time of notification, Completix shall provide further information as it becomes available.
8.4 Completix shall provide reasonable assistance to the Client in relation to any notification obligations the Client has to supervisory authorities or data subjects.
8.5 Notification under this Section is not an acknowledgement of fault or liability.
9. Deletion and Return
9.1 On termination or expiry of the Services, or at the Client's written request, Completix shall, at the Client's choice:
- Return all personal data to the Client in a machine-readable format, or
- Securely delete all personal data and existing copies
This applies unless Union or Member State law requires continued storage.
9.2 Completix shall complete the return or deletion within thirty (30) days and shall confirm completion in writing on request.
9.3 Personal data in system backups is overwritten in accordance with Completix's backup rotation, up to a maximum of ninety (90) days. Backup copies are not used for operational processing.
9.4 Completix shall ensure sub-processors are subject to equivalent obligations.
10. Liability
10.1 Each party's liability under this Agreement is subject to the limitations set out in the principal agreement.
10.2 Each party is responsible for damage caused by breach of its own obligations under this Agreement.
10.3 Nothing in this Agreement limits either party's liability to data subjects under Article 82 GDPR.
11. Governing Law
11.1 This Agreement is governed by the laws of the Province of Ontario and the federal laws of Canada applicable therein, save that Section 6.3 is governed as set out in that Section.
11.2 Disputes are subject to the exclusive jurisdiction of the courts of Ontario, save where a supervisory authority or court in the EU/EEA is entitled to exercise jurisdiction.
12. General
12.1 Amendments to this Agreement must be in writing and signed by authorised representatives of both parties, except that Completix may update Annex III provided the changes do not materially reduce the overall level of security.
12.2 If any provision is found invalid or unenforceable, the remaining provisions continue in full force.
12.3 Neither party may assign this Agreement without the other's prior written consent, except that Completix may assign to a successor entity in connection with a merger, acquisition, or sale of all or substantially all of its assets, provided the successor is bound by this Agreement.
Annex I: Description of Processing
GDPR Article 28(3), subject matter, nature, purpose, and duration.
| Subject Matter | Provision of the Completix project and portfolio management platform and related services (the "Services"). |
|---|---|
| Nature of Processing | Storage, retrieval, organisation, analysis, and deletion of personal data in the operation of the Services, on documented instructions from the Client. |
| Purpose | To enable the Client and its authorised users to create, manage, and collaborate on projects, tasks, files, and related work items within the Completix platform; to authenticate authorised users; to deliver transactional system notifications; and to provide customer support. |
| Duration | For the duration of the Services, plus such additional period as required for secure deletion in accordance with Section 9 of this Agreement. |
| Processing Locations | As specified in the applicable order form or principal agreement. Where not specified, the default region applies. Authentication data is processed in the United States in all configurations. Sub-processor locations are identified in the list referred to in Annex II. |
Categories of Personal Data
- Business contact details: name, corporate email address, optional business telephone number
- User account and profile data: username, role, preferences, timezone
- Authentication data: authentication tokens and session identifiers, IP address, login timestamps
- Project content: tasks, files, time entries, comments, metadata, and audit logs created by or for the Client within the Services
- Support ticket content: name, email, and contents of support communications
- Billing contact data: billing name, address, and email
Categories of Data Subjects
- The Client's employees, contractors, and consultants authorised to use the Services
- External stakeholders or collaborators invited by the Client to the Services
- The Client's billing contacts
Special Categories
None. The Services are not designed or intended to process Special Categories of Personal Data. See Section 2.5.
Annex II: Sub-processor List
The current list of Completix Inc. sub-processors is published online and updated whenever a sub-processor is added, removed, or materially changed.
| Published List | completix.com/legal/privacy-policy |
|---|---|
| Detailed Disclosure | The Completix Sub-processor Disclosure, including processing purpose, location, and transfer mechanism for each sub-processor, is available on request from [email protected] |
| Change Notifications | Clients may subscribe to email notification of changes by contacting [email protected] |
| Update Frequency | Updated whenever a sub-processor is added, removed, or materially changed. The Client is notified of changes in accordance with Section 5.3 of this Agreement. |
By entering into this Agreement, the Client authorises the sub-processors identified in that list as at the Effective Date. Changes are notified and may be objected to in accordance with Section 5.3.
Annex III: Technical and Organisational Measures
GDPR Article 32, security of processing. The following measures are implemented by Completix Inc. to protect personal data processed under this Agreement.
| Control Area | Measure Implemented |
|---|---|
| Access Control | Role-based access control with least-privilege assignment. Conditional access and multi-factor authentication for administrative access. Passwordless authentication for platform users. |
| Encryption in Transit | TLS 1.2 or higher enforced for all data in transit between clients, services, and sub-processors. |
| Encryption at Rest | Provider-managed encryption at rest for all storage services. |
| Secrets Management | Credentials and secrets stored in a managed key vault. No plaintext credentials in source code or configuration files. |
| Network Security | Managed network isolation. Firewall rules and network security groups applied to all infrastructure components. HTTPS-only endpoints enforced. |
| Tenant Isolation | Logical multi-tenant isolation, with each customer's data segregated at the data tier. |
| Audit Logging | Centralised audit logging with retention of at least 90 days by default, monitored for anomalies. Extended retention may be agreed in the order form. |
| Vulnerability Management | Regular dependency patching and security updates applied to application code and infrastructure. Automated security scanning in the deployment pipeline. |
| Change Management | Formal change approval process for all production changes. Environment separation between production and development. |
| Incident Response | Documented incident response procedure with defined roles, escalation paths, and notification timelines. |
| Business Continuity | Documented business continuity and disaster recovery procedures, tested and reviewed annually. |
| Personnel Security | Personnel with access to personal data are subject to confidentiality obligations. Security awareness training conducted annually. Access reviewed periodically. |
| Sub-processor Oversight | Sub-processors assessed before engagement and reviewed annually. |
These measures are reviewed at least annually and updated to reflect changes in technology, organisational structure, or risk profile. Further detail, including Completix's Information Security Policy, SOC 2 reporting, and supporting control documentation, is available to Clients under a non-disclosure agreement on written request.
Need a signed copy referencing your organisation, or have questions about this DPA? Contact [email protected].