Skip to content
AtheronLABS

You're visiting from the United States. Prices are shown in US dollars. Not right?

labs@atheron:~/legal/dpa$ cat dpa.md

Your data, your rules

How we handle personal information for you.

When software we build, host or support holds personal information, you decide what happens to it. This addendum is how we promise to follow your lead.

In force from
October 3, 2026
Version
2026-10-03

SHA-256 79d58e956dec6859a36841901562e7ee9e86977eee8caf9cf832418514dfecd7

Contents14 sections
  1. 01Who this addendum is between
  2. 02Your role and ours
  3. 03What is processed
  4. 04Our people
  5. 05Security measures
  6. 06Subprocessors
  7. 07Information outside Canada
  8. 08People's requests
  9. 09Breaches and incidents
  10. 10Assessments and audits
  11. 11When our work ends
  12. 12Law
  13. 13Contact
  14. 14Language

// in short

You decide what happens to the personal information in your project, and we act only on your instructions. It stays in Canada by default, only the services listed here help us process it, we tell you promptly about any breach, and we return or delete it when our work ends.

01Who this addendum is between

This addendum is between your organisation and Atheron Network Inc., a company incorporated in British Columbia, Canada.

It forms part of our master services agreement and applies whenever we handle personal information on your behalf: building, testing, hosting, supporting or running software that holds it, or working with data you give us.

Information we collect for our own purposes, such as the accounts of your people in the client portal, our messages with you and your invoices, is covered by our privacy notice and the client portal's privacy page, not by this addendum.

02Your role and ours

You are the organisation in control of the personal information: under the GDPR, the controller; under Quebec law, the enterprise that holds it and communicates it to us under a contract. We are your service provider, or under the GDPR your processor.

We handle the information only to provide the services in your statements of work, and only on your documented instructions: this addendum, the master services agreement, your SOWs, and what an owner asks of us in the client portal. If we believe an instruction breaks the law, we tell you and need not follow it.

You are responsible for having a lawful basis for the information, for what your own privacy notice tells people, and for the instructions you give.

03What is processed

ItemDetails
PurposeBuilding, testing, hosting, supporting and running the software and services in your SOWs
People concernedThose whose information your software or your data holds, such as your customers, users and staff
Kinds of informationWhatever your software holds, as your SOW describes. We ask you to tell us before it holds health, financial or other sensitive information, or information about children
DurationFor as long as we provide the services, then until it is returned or deleted as this addendum says
WhereCanada by default, with DigitalOcean in Toronto, unless your SOW names another region or provider

04Our people

Only people who need access to do the work get it, with the least access that work needs. Everyone who can reach your information is bound to keep it confidential. Access is granted by role and recorded.

05Security measures

We protect your information with measures that fit its sensitivity, including:

  • encryption in transit everywhere, and at rest for databases, backups and files;
  • each service signing in to its database with its own login, able to do only what it needs;
  • access by role, with grants and changes recorded in an audit log, and a fresh check at sign-in for sensitive actions;
  • servers snapshotted and databases backed up every 8 hours, with the copies rotated;
  • security updates applied to servers every night, and dependencies checked for advisories;
  • a written retention period for each kind of personal information, applied by code;
  • tests, reviews and change control before anything ships, as our security page describes.

We review these measures as our services and the risks change, and never lower their overall level during a SOW.

06Subprocessors

You authorise these services to help us process your information, each only for the purpose shown:

ServiceWhat it does for usWhere
DigitalOcean, LLCHosting: servers, managed databases, private file storage and backupsToronto, Canada, unless your SOW names another region
Cloudflare, Inc.DNS, delivering your site and protecting it from attacksIts global network, including the United States
Microsoft Corporation (Microsoft 365)Our email, calendar, Teams calls and documents, when information reaches us that wayCanada, the United States or other countries
Resend, Inc.Sending email from software we host, where your SOW uses itUnited States
Anthropic, PBCAI features built on Claude, where your SOW includes themUnited States

When your SOW chooses another hosting provider (Amazon Web Services, Google Cloud, Microsoft Azure, Hetzner or Vultr) or a service your product depends on (for example for messaging, maps or payments), that provider is a subprocessor for your project from the day the SOW is signed, in the region the SOW names. Where your product uses a service under your own account, that provider works for you, not for us.

We do not put personal information you control into any other service. Each subprocessor is bound by a written contract that protects your information at least as well as this addendum, and we remain responsible for its work.

We tell your owners at least 30 days before we add or replace a subprocessor. You may object on reasonable grounds. If we cannot meet the objection, you may end the affected service without penalty.

07Information outside Canada

Your information stays in Canada by default. It leaves Canada only through the subprocessors above, in the places shown, or as your SOW directs. Information held outside Canada is subject to the laws of the country where it is held.

Under Quebec's Law 25, you must assess the privacy impact before information about people in Quebec is communicated outside Quebec. We give you, at no charge, the information about our subprocessors and safeguards that the assessment needs.

Where the GDPR or the UK GDPR applies, Canada's adequacy decision covers transfers to us, and onward transfers to a subprocessor outside Canada rely on the safeguards it offers, such as the EU-U.S. Data Privacy Framework or the European Commission's standard contractual clauses.

08People's requests

If someone asks us directly to see, correct, move or delete their information, we pass the request to you within 5 business days and do not answer it ourselves unless you tell us to. We help you answer requests, as far as the services allow.

09Breaches and incidents

If we become aware of a breach of security that affects your information, a confidentiality incident under Quebec law, we tell you without undue delay and no later than 72 hours after we become aware of it. We tell you what happened, what information and how many people are affected as far as we know, what we have done and will do, and who to talk to. We send what we learn later as we learn it.

We take reasonable steps at once to reduce the harm and stop it happening again, and we help you assess the risk of serious harm, keep your record of incidents, and notify the regulators and people the law requires you to notify. We do not notify them ourselves for you unless you ask us to or the law requires it.

10Assessments and audits

We give you the information you reasonably need to show that this addendum is being kept, and to carry out a privacy impact assessment.

Once a year, or after a breach, you may audit our compliance yourself or through an independent auditor bound to confidentiality, with 30 days' notice, during business hours, at your cost, and without access to other clients' information.

11When our work ends

When a service ends, we return your information in a common format if you ask, and we delete it from our systems within 30 days. Copies in backups are deleted as the backups rotate out. We keep information only where the law requires us to, and then protect it under this addendum for as long as we keep it.

12Law

This addendum is written to meet the Personal Information Protection and Electronic Documents Act, Quebec's Act respecting the protection of personal information in the private sector as amended by Law 25, and, where they apply, Article 28 of the GDPR and the UK GDPR. If it conflicts with another document between us, this addendum wins on personal information.

The laws of British Columbia, Canada, and the federal laws of Canada that apply there, govern this document. Disputes are heard by the courts of British Columbia, Canada.

13Contact

Write to us about personal information at privacy@aton-network.org.

Report a security concern at security@aton-network.org.

14Language

This addendum is published in English and in French. Both versions are equally authoritative.

// who you are dealing with

Atheron Network Inc. 1631 Dickson Ave., Suite 1100 Kelowna, BC V1Y 0B5 CA Business Number 788400448 GST/HST 788400448 RT0001

Data processing addendum | Atheron Network Labs