Canadian Data Processing Agreement

Last updated: July 13, 2026

This Canadian Data Processing Agreement (“DPA”) forms part of the Master Services Agreement (“MSA”) between PaymentEvolution Corporation (“PaymentEvolution”) and Client. It applies when PaymentEvolution processes Personal Information for Client in providing the Services.

This DPA governs privacy processing only. The MSA continues to govern general, payment, Client Fund, commercial and liability matters. Applicable Privacy Law always prevails. Capitalized terms not defined here have the MSA meanings.

1. Definitions

“Client Personal Information” means Personal Information that PaymentEvolution processes for Client in providing the Services. It does not include information PaymentEvolution handles independently for the purposes listed in section 3.3.

“Individual” means the identifiable person to whom Personal Information relates.

“Privacy Law” means Canadian federal, provincial and territorial law that applies to the processing of Personal Information under the Agreement, including PIPEDA and, where applicable, Quebec’s Act respecting the protection of personal information in the private sector.

“Process” or “Processing” means to collect, access, use, disclose, transmit, store, alter, de-identify, return, delete or otherwise handle Personal Information.

“Security Incident” has the MSA meaning and, for this DPA, is limited to an incident involving Client Personal Information.

“Subprocessor” means a third party engaged by PaymentEvolution to Process Client Personal Information for Client. It does not include an independent bank, government authority, insurer, professional or other recipient that determines its own purposes.

2. Scope and processing details

2.1 Instructions

PaymentEvolution will Process Client Personal Information only:

  • to provide, secure and support the Services described in the Agreement and Documentation;

  • on Client’s documented instructions, including instructions submitted through the Services;

  • as needed to prevent or address fraud, abuse or a Security Incident affecting the Services; or

  • as required by Applicable Law.

The Agreement and Client’s authorized use are documented instructions. If an instruction appears to violate Privacy Law, PaymentEvolution will tell Client unless prohibited, may pause the affected Processing and will work with Client on a lawful alternative. PaymentEvolution is not required to follow an unlawful instruction.

2.2 Duration

Processing continues for the term of the affected Service and any limited period needed for return, deletion, backup expiry, legal retention, an unresolved Transaction, a legal hold or another obligation in the Agreement.

2.3 Nature and purposes

Depending on the Services, Processing may include collection, validation, calculation, hosting, organization, transmission, reporting, filing, payment administration, benefits administration, user support, security, backup and deletion for payroll, HR, benefits, business-payment and related purposes.

2.4 Individuals and information

Individuals may include Client and End Client personnel, job applicants, contractors, owners, directors, payers, payees, dependents, beneficiaries, Authorized Users, customers, vendors and support contacts.

Information may include identifiers and contact information; government and tax identifiers; employment, time, compensation, deduction and leave information; financial and transaction information; bank details; benefits and dependent information; account, device, security and support information; and other data Client submits. Client must not submit health, biometric, criminal, union, immigration or similarly sensitive information unless the selected Service requires it, the Documentation permits it and Client has lawful authority.

3. Roles and responsibilities

3.1 Client role

Client determines the employment, business, payroll, HR, benefits and other purposes for Client Personal Information and is the organization responsible for those purposes. Client is responsible for lawful authority, notices, consent where required, data accuracy, minimization, retention instructions, Authorized Users and responding to Individuals, with PaymentEvolution’s assistance under this DPA.

3.2 PaymentEvolution service-provider role

PaymentEvolution Processes Client Personal Information for Client and will not use or disclose it for another purpose except as allowed by this DPA, Client’s instructions or Applicable Law. PaymentEvolution will make its personnel aware of confidentiality obligations and limit access to those who need it.

3.3 PaymentEvolution independent purposes

PaymentEvolution independently determines the Processing needed to:

  • create and administer its contractual relationship and Accounts;

  • verify identity, authority, beneficial ownership, businesses and bank information;

  • prevent, detect and investigate fraud, misuse, sanctions issues and security threats;

  • safeguard and reconcile end-user funds and perform payment-service duties;

  • bill Fees, keep financial records and manage legal claims;

  • report to and cooperate with regulators, tax authorities, courts and law enforcement; and

  • create and use De-Identified Data that meets MSA section 6.3.

For those activities, the public Privacy Policy applies and PaymentEvolution is responsible for compliance. This independent role does not permit PaymentEvolution to use employment records for unrelated marketing or to train a general-purpose generative AI model without express written permission.

3.4 No transfer of statutory responsibility

Each party remains responsible for duties Privacy Law places on it. A party cannot avoid a duty by calling itself a processor, service provider, controller, organization or agent if the facts or law require another result.

4. PaymentEvolution obligations

PaymentEvolution will:

  1. Process Client Personal Information only as allowed by section 2;

  2. use reasonable efforts to keep it accurate when PaymentEvolution creates or changes it, while relying on Client for source accuracy;

  3. apply the safeguards in Schedule 1;

  4. ensure personnel with access are bound by confidentiality and receive appropriate privacy and security training;

  5. keep records reasonably needed to show compliance with this DPA;

  6. assist Client with Individual requests, privacy assessments, regulator inquiries, Security Incidents and legally required notices as described below;

  7. notify Client of a legally binding request for Client Personal Information unless prohibited by law and, where reasonable, direct the requester to Client;

  8. challenge or narrow a request where there are reasonable grounds and it is lawful to do so; and

  9. delete, return or retain information at the end of the Service under section 11.

5. Client obligations

Client will:

  1. give Individuals clear, accessible privacy notices and obtain consent or other authority required for the Services;

  2. collect and submit only information reasonably needed for an authorized purpose;

  3. ensure its instructions, configurations and uses comply with Privacy Law and employment law;

  4. keep information accurate and promptly correct material errors;

  5. control Authorized Users, permissions, devices, integrations, exports and credentials;

  6. not use the Services to make an unlawful decision or conduct prohibited monitoring;

  7. give PaymentEvolution the information and cooperation reasonably needed to meet this DPA; and

  8. notify PaymentEvolution promptly if authority for Processing changes or an Individual withdraws a consent relevant to the Services.

Client is responsible for Resellers, Partners, Automated Agents and third-party integrations it authorizes, except to the extent PaymentEvolution is responsible under a separate agreement or Applicable Law.

6. Security

6.1 Program

PaymentEvolution will maintain a written information-security program with administrative, technical and physical safeguards appropriate to the sensitivity, volume and risk of Client Personal Information. Schedule 1 describes the baseline controls. PaymentEvolution may update controls to address changing threats and technology, provided overall protection is not materially reduced.

6.2 Access and confidentiality

PaymentEvolution will use role-based access, least privilege and authentication controls, review access, and revoke it when no longer needed. Personnel and contractors with access will be bound by confidentiality obligations that survive their access.

6.3 Client security

Client is responsible for security outside PaymentEvolution’s systems, including its devices, credentials, networks, Partner Platform, Automated Agents, exports and copies. PaymentEvolution’s responsibilities are not reduced to the extent an incident was caused by PaymentEvolution or a Subprocessor.

7. Security Incidents

7.1 Notice

PaymentEvolution will notify Client without unreasonable delay and, where reasonably possible, within 48 hours after confirming a Security Incident. If Privacy Law requires earlier notice, that requirement applies. A notice may be delivered to Client’s privacy, security or Account contact.

7.2 Information and response

As information becomes available, PaymentEvolution will provide a description of the incident, approximate date and duration, types of information and Individuals affected, likely consequences, containment and remediation, and a contact. PaymentEvolution will take reasonable steps to contain, investigate, remediate and reduce recurrence and will preserve relevant evidence.

7.3 Notices to Individuals and regulators

Client controls notices for Client-directed Processing unless Privacy Law requires PaymentEvolution to notify. The parties will coordinate content and timing and avoid inaccurate or inconsistent statements. PaymentEvolution will provide reasonable assistance and may charge reasonable professional-service fees for extensive assistance caused by Client, but not for work caused by PaymentEvolution’s breach.

7.4 Unsuccessful events

PaymentEvolution need not report routine unsuccessful attempts that do not compromise Client Personal Information, such as blocked scans or failed logins, but will provide reasonable aggregate assurance information on request.

8. Individual requests and complaints

If PaymentEvolution receives an access, correction, deletion, portability, consent-withdrawal, automated-decision or complaint request about Client Personal Information, it will direct the Individual to Client where appropriate and notify Client unless prohibited. PaymentEvolution will provide tools or reasonable assistance so Client can respond within legal time limits.

PaymentEvolution may verify identity and authority before acting. It will not delete or change a record where law requires retention, the record is needed for an unresolved payment or legal claim, or Client has not authorized the action. It will explain the limitation so Client can respond accurately.

Client remains responsible for the final response and for notifying PaymentEvolution of a correction or consent change that affects continued Processing.

9. Cross-border processing

Client authorizes PaymentEvolution and approved Subprocessors to Process Client Personal Information in Canada, the United States and other jurisdictions identified in the subprocessor information made available by PaymentEvolution. Information may be subject to the laws and lawful-access powers of those jurisdictions.

PaymentEvolution will use written contracts, security controls and vendor oversight appropriate to the risk. Before a transfer from Quebec or where another law requires it, PaymentEvolution will conduct or support a privacy impact or transfer assessment proportionate to the information and arrangement. Client will provide facts about its purposes and Individuals reasonably needed for the assessment.

If a new location materially increases privacy risk and Client reasonably objects under section 10.3, the parties will seek a practical alternative.

10. Subprocessors

10.1 Authorization

Client gives general authorization for PaymentEvolution to use Subprocessors needed for the Services. PaymentEvolution will maintain a current list through its legal site, trust centre or another stable client channel, including the Subprocessor’s function and processing country.

10.2 Contract and responsibility

PaymentEvolution will assess a Subprocessor’s relevant privacy and security controls and bind it in writing to protections materially consistent with this DPA for the Processing it performs. PaymentEvolution remains responsible for a Subprocessor’s performance of those obligations to the same extent PaymentEvolution would be responsible if it performed the Processing itself.

10.3 New Subprocessors

PaymentEvolution will give at least 30 days’ notice — through an update to the list described in section 10.1 or another direct notice — before a new Subprocessor begins Processing Client Personal Information, except for an emergency measure needed to protect the Services or Individuals. Client may object during that period on reasonable, documented privacy or security grounds. The parties will work in good faith on added safeguards, a configuration change or another provider. If no reasonable solution exists, Client may terminate only the affected Service before the new Processing begins and receive a prorated refund of prepaid Fees for the unused period.

11. Return, deletion and retention

During the term, Client may export Client Personal Information using available features. On termination, PaymentEvolution will make a standard export available as stated in MSA section 6.7 and then delete or de-identify Client Personal Information under its documented retention schedule.

PaymentEvolution may retain a limited copy where required for payroll, tax, payment, safeguarding, fraud, audit, legal-claim, backup or regulatory purposes. It will isolate retained information from ordinary product use, protect it under this DPA and delete it when the reason ends. Backup copies will expire through the normal secure cycle and will not be restored except for continuity or recovery.

Client is responsible for preserving its legally required records before deletion. PaymentEvolution will not withhold Client Personal Information solely because of a disputed Fee where doing so would prevent Client from meeting a legal duty, but may use other lawful collection remedies.

12. De-identified information

PaymentEvolution may create and use aggregated or de-identified information only if it cannot reasonably identify an Individual, Client or End Client; it uses safeguards appropriate to re-identification risk; and it does not attempt to re-identify the information except to test safeguards or as required by law. If information can reasonably be re-identified, this DPA continues to apply.

13. Demonstrating compliance and audits

13.1 Assurance information

On request and subject to confidentiality and security limits, PaymentEvolution will provide reasonably available information such as relevant policies, control summaries, penetration-test summaries, certifications or independent audit reports. PaymentEvolution may redact information that would expose another customer’s data, security-sensitive detail or privileged advice.

13.2 Client audit

If the information in section 13.1 is not reasonably sufficient to meet a legal or regulator requirement, Client may conduct a focused audit no more than once a year on at least 20 Business Days’ notice. The audit must occur during business hours, use an independent qualified reviewer bound by confidentiality, avoid access to other customers’ data and avoid unreasonable disruption. Client pays the audit cost unless it identifies a material breach by PaymentEvolution. More frequent or urgent review is allowed after a material Security Incident or where a regulator lawfully requires it.

13.3 Regulators and assessments

PaymentEvolution will reasonably cooperate with a privacy regulator with jurisdiction and provide information needed for Client’s legally required privacy impact assessment. Each party bears its ordinary internal cost; Client will pay reasonable extraordinary cost for a bespoke assessment not caused by PaymentEvolution’s breach.

14. Liability, term and conflict

If a separate MSA has been accepted or signed, MSA section 9 governs liability, including its separate privacy and security cap and exceptions. If this DPA is incorporated into a standalone agreement without a separate MSA, the liability provision in that standalone agreement governs. This DPA starts with the Agreement and continues while PaymentEvolution holds Client Personal Information. Termination of this DPA does not require deletion contrary to section 11 or end obligations that need to survive.

If this DPA conflicts with another Agreement document about Processing Client Personal Information, this DPA controls for that subject. It does not override MSA section 5 on Client Funds, payment status, safeguarding or interest. An Order Form may change this DPA only if it identifies the provision and the change complies with Privacy Law.

15. Contact

Questions and privacy notices may be sent to:

Privacy Office
PaymentEvolution Corporation
2600 Skymark Ave, Building 1, Unit 200
Mississauga, Ontario, Canada L4W 5B2
privacy@paymentevolution.com

Schedule 1 — Baseline security measures

PaymentEvolution will maintain controls appropriate to the Services and risk, including:

A. Governance

  • assigned security and privacy responsibility;

  • written policies, risk assessment and control review;

  • personnel screening where appropriate, confidentiality and training;

  • incident, continuity and disaster-recovery plans; and

  • vendor risk management.

B. Access and identity

  • unique user identities and least-privilege role-based access;

  • multi-factor authentication for privileged access and where risk requires;

  • controlled joiner, mover and leaver processes;

  • periodic access review; and

  • credential and secret management.

C. Data protection

  • encryption in transit using current industry protocols;

  • encryption at rest where appropriate to sensitivity and architecture;

  • data minimization, environment separation and controlled production access;

  • secure deletion and media handling; and

  • backup protection and tested recovery.

D. Systems and development

  • secure development and change management;

  • code, dependency and vulnerability scanning appropriate to the system;

  • patching based on risk;

  • malware and endpoint protections;

  • network and cloud configuration controls; and

  • independent testing or penetration testing at reasonable intervals.

E. Monitoring and response

  • security logging and monitoring proportionate to risk;

  • alert triage, investigation and evidence preservation;

  • documented incident classification, escalation and communication;

  • post-incident remediation and lessons learned; and

  • retention of security records as required by law and risk.

These measures describe outcomes, not a promise to use a particular vendor or technology. Equivalent or stronger controls may replace them as technology changes.

Canada's most loved payroll, HR, and benefits

Canada's most loved payroll, HR, and benefits

Trusted by thousands of businesses, PaymentEvolution is Canada's largest and most loved cloud payroll, HR and benefits management service. Accountants, bookkeepers and financial institutions in Canada rely on us for payroll expertise and payroll services for their clientele. See why over 20,000 businesses trust us every day.

Trusted by thousands of businesses, PaymentEvolution is Canada's largest and most loved cloud payroll, HR and benefits management service. Accountants, bookkeepers and financial institutions in Canada rely on us for payroll expertise and payroll services for their clientele. See why over 20,000 businesses trust us every day.

© 2026 PaymentEvolution Corporation