Data Processing Agreement
This Data Processing Agreement ("DPA") is entered into between Customer, acting as Data Controller ("Controller"), and Wave Connect Inc., 63 Rue de Brésoles, Suite 101, Montréal, Québec H2Y 1V7, Canada, acting as Data Processor ("Processor").
This DPA forms part of the agreement governing Customer's use of the Services (the "Main Agreement") between the Parties. Capitalized terms not defined in this DPA have the meaning given in the Main Agreement.
1. Subject Matter and Duration
(a) The Processor provides the services specified in the Main Agreement. In doing so, the Processor may process Personal Data on behalf of the Controller.
(b) This DPA remains in force for the Term of the Main Agreement and as long as the Processor processes Personal Data on behalf of the Controller.
2. Roles of the Parties
(a) The Controller determines the purposes and means of processing Personal Data.
(b) The Processor processes Personal Data only on behalf of the Controller and in accordance with documented instructions.
3. Processor Obligations
The Processor shall:
- comply with applicable Data Protection Laws;
- process Personal Data only as instructed by the Controller and only for the purposes of providing the Services;
- ensure that persons authorized to process Personal Data are bound by confidentiality obligations;
- implement industry standard technical and organizational measures as described in Annex 2;
- notify the Controller without undue delay, and in any event within seventy-two (72) hours after the Processor confirms a Personal Data breach affecting the Controller's Personal Data;
- implement reasonable mitigation measures in the event of a Personal Data breach, as required by applicable Data Protection Laws;
- provide reasonable assistance to the Controller in responding to Data Subject requests;
- make available to the Controller the information necessary to demonstrate compliance with this DPA. The Processor's then-current SOC 2 Type II report shall satisfy this obligation. Where such report is demonstrably insufficient, where a supervisory authority requires an inspection, or following a confirmed Personal Data breach affecting the Controller's Personal Data, the Controller may conduct an on-site inspection no more than once per calendar year, at the Controller's expense, during normal business hours, on at least thirty (30) days' prior written notice, and subject to confidentiality obligations;
- return or securely delete Personal Data at the end of the Main Agreement, unless retention is required by Law.
As part of our commitment to data privacy and compliance, you can request access to, correction of, or deletion of your personal data processed under our Data Processing Agreement (DPA). Please fill out the form to submit your request.
4. Sub-Processors
(a) The Controller provides a general authorization for the Processor to engage sub-processors listed in Annex 3 and any additional sub-processors notified to the Controller.
(b) The Processor shall ensure sub-processors are bound by obligations no less protective than those set out in this DPA.
(c) The Controller may object to a new sub-processor for material data protection reasons within two weeks of notice.
5. International Transfers and Personnel Access
Personal Data may be transferred outside the EEA, Switzerland, or the UK only in compliance with Data Protection Laws (e.g., Standard Contractual Clauses). The Processor uses recognized safeguards and the providers listed in Annex 3. The Controller acknowledges and agrees that authorized personnel of the Processor located in Canada may access Personal Data for the purpose of providing support and maintaining the Services, subject to the confidentiality and security obligations in this DPA and the Main Agreement.
6. Liability
The Parties' liability under this DPA is subject to and limited by the limitations of liability set out in the Main Agreement. Nothing in this DPA limits liability that cannot be limited under applicable Law.
7. Governing Law
This DPA is governed by the laws specified in the Main Agreement, and disputes shall be resolved exclusively in the forum specified therein.
Annex 1 - Categories of Data & Data Subjects
- Employees: names, contact details, position, department, profile photo, company details, social media links.
- Interested parties / prospects: names, contact details, company information.
Annex 2 - Technical and Organizational Measures
- Authentication and access controls (2FA, password policies, role-based permissions).
- Encryption of data in transit and at rest.
- Firewalls and mobile device management.
- Regular backups with resiliency measures.
- Logging of access and changes to data.
- Annual privacy and security training for employees.
- SOC 2 Type II audited annually.
- Appointed Data Protection Officer: Rickert Rechtsanwaltsgesellschaft m.b.H., Bonn, Germany (info@rickert.law).
Annex 3 - Sub-Processors
| Sub-Processor | Purpose | Location |
| Google LLC | Cloud hosting, analytics, AI processing of scanned badge and paper images (Gemini) | US |
| PlanetScale | Database hosting | US |
| Microsoft | Productivity and integrations | US |
| Stripe | Payments | US |
| Twilio / SendGrid | SMS & email delivery | US |
| Loops | Email marketing | US |
| Vercel | Hosting | US |
| Intercom | Customer service | US |
| MaxMind | IP services | US |
| Shopify | E-commerce | Canada/US |
| HubSpot | CRM / communications | US |
| PostHog | Analytics | US |
Where the Controller uses the Processor's contact capture features, the Processor also engages data enrichment providers located in the United States, which receive the contact details captured by the Controller and return additional business contact and company information. The complete and current list of Sub-processors, including these providers, is set out in the Controller's signed Data Processing Agreement and is available under a non-disclosure agreement by contacting security@wavecnct.com.