This Data Processing Agreement ("DPA") forms part of the agreement between Exact Cabinets Ltd. ("Processor", "CabShopSoft") and the customer identified in the account ("Controller", "you") for use of the Service, and reflects the parties' obligations regarding the processing of personal data under PIPEDA and, where applicable, the GDPR.
For personal data that you or your users enter about your own clients, employees, and projects ("Controller Personal Data"), you are the Controller and CabShopSoft is the Processor. CabShopSoft processes Controller Personal Data only on your documented instructions, which include your configuration and use of the Service and this DPA.
| Item | Details |
|---|---|
| Subject matter | Provision of the CabShopSoft platform |
| Duration | The term of your subscription, plus the retention periods described below |
| Nature & purpose | Hosting, storage, and processing to deliver cabinet-shop management functions |
| Categories of data subjects | Your clients, your staff/employees, your installers and field workers, your contacts |
| Categories of personal data | Names, contact details, addresses; job/quote/invoice records; employee time and attendance; optional employee location (GPS); uploaded documents |
| Special categories | None intended. You must not enter special-category data except as lawfully permitted |
You authorize CabShopSoft to engage the sub-processors listed in our Privacy Policy to process Controller Personal Data. We impose data-protection obligations on sub-processors substantially similar to those in this DPA and remain responsible for their performance. We will give notice of intended additions or replacements and give you an opportunity to object on reasonable data-protection grounds.
Controller Personal Data may be hosted and processed in the United States and other countries. Where the GDPR applies, the parties agree that the European Commission's Standard Contractual Clauses (and UK/Swiss addenda where relevant) are incorporated by reference to cover such transfers. Under PIPEDA, CabShopSoft remains accountable for data transferred to sub-processors for processing.
Each party's liability under this DPA is subject to the limitations of liability in the Terms of Service. If there is a conflict between this DPA and the Terms regarding the processing of Controller Personal Data, this DPA controls.
CabShopSoft maintains safeguards including: encryption in transit (TLS/HTTPS); salted password hashing; optional multi-factor authentication; role-based access controls and tenant isolation; network firewalling and restricted administrative access; intrusion mitigation and rate limiting; audit logging; and a documented process for security incident response and breach notification.
To request an executed copy of this DPA for your organization, contact [email protected].