Data Processing Agreement
Version 1.0 — Effective Date: June 5, 2026 — Last Updated: June 7, 2026
Parties
This Data Processing Agreement ("Agreement") is entered into between:
Data Processor: MapOutcomes Inc., a corporation incorporated under the Canada Business Corporations Act (Canadian Corporations Number 1791669-8), with its registered office in the Province of Ontario ("Processor" or "MapOutcomes");
Data Controller: The customer organization that determines the purposes and means of processing personal information through the MapOutcomes Platform ("Controller").
1. Definitions
- 1.1 Personal Information
- Has the meaning given in section 4(1) of PIPEDA and includes any information about an identifiable individual.
- 1.2 Processing
- Any operation performed on Personal Information, including collection, use, retention, disclosure, and deletion.
- 1.3 Platform
- The MapOutcomes software-as-a-service platform, including all features, functionality, content, and related services.
- 1.4 Sub-processor
- A third-party service provider engaged by MapOutcomes to perform Processing activities on behalf of MapOutcomes.
- 1.5 Applicable Law
- PIPEDA, applicable provincial privacy legislation (including but not limited to Quebec Act 25, Alberta PIPA, BC PIPA), and any other applicable Canadian privacy laws.
2. Scope of Processing
2.1 Subject Matter
MapOutcomes processes Personal Information solely to operate the Platform and provide the Services described in the ToS, including:
- User account management and authentication
- Accreditation data management and analysis
- Course-program-outcome mapping and gap analysis
- Data export and reporting functionality
- Customer support and technical maintenance
2.2 Categories of Personal Information
The Personal Information processed under this Agreement includes:
- Account information: Name, institutional email, job title, role, institution name
- Usage data: Login timestamps, IP addresses, feature usage patterns
- User-created content: Course descriptions, learning outcomes, accreditation mappings, assessment criteria, aggregate scoring data, configuration settings
2.3 Categories of Data Subjects
- Employees, faculty, and staff of Controller's institution
- Accreditation coordinators and program administrators
2.4 Duration
Processing continues for the duration of the Controller's subscription and for up to 90 days thereafter (data retention and deletion period as described in Section 7).
3. Obligations of the Processor
3.1 Processing Instructions
MapOutcomes shall process Personal Information only on the documented instructions of the Controller, unless required to do so by Applicable Law. In the event of a legal requirement that conflicts with Controller's instructions, MapOutcomes shall notify the Controller before complying, unless legally prohibited from doing so.
3.2 Confidentiality
MapOutcomes ensures that all persons authorized to process Personal Information are subject to appropriate confidentiality obligations. Access is restricted to personnel who need it to perform their duties, and all personnel receive regular privacy and security training.
3.3 Security Measures
MapOutcomes implements and maintains appropriate technical and organizational security measures, including at minimum:
| Measure | Implementation |
|---|---|
| Encryption in transit | TLS at CDN edge (Cloudflare); origin server TLS in development |
| Access control | Role-based access control (RBAC) with principle of least privilege |
| Authentication | Secure password hashing (bcrypt) |
| Application security | CSRF token protection; input validation and output encoding |
| Network security | Firewall protection (pfSense); physical server security controls |
| Data hosting | Secure, physically-secured infrastructure in Ontario, Canada |
3.4 Sub-processing
3.4.1 General Rule. MapOutcomes shall not engage another processor (Sub-processor) to carry out processing activities on behalf of MapOutcomes without the prior notice to Controller. MapOutcomes provides general authorization for the categories of Sub-processors listed below. Controller may object to any new Sub-processor within 15 days of receiving notice.
3.4.2 Current Sub-processors.
| Sub-processor | Service | Data Location |
|---|---|---|
| Canadian hosting infrastructure | Infrastructure hosting | Canada (Hamilton, ON) |
| Transactional email service | Email delivery | As per their privacy policy |
| Support ticketing system | Customer support management | As per their privacy policy |
3.4.3 Sub-processing Obligations. MapOutcomes imposes on each Sub-processor obligations no less protective than those set out in this Agreement. MapOutcomes remains fully liable to Controller for the acts and omissions of its Sub-processors.
3.5 Data Residency
All Personal Information is hosted on servers located in Canada. MapOutcomes shall not transfer Personal Information to servers located outside Canada without Controller's prior written consent and appropriate safeguards (such as standard contractual clauses or binding corporate rules).
4. Assistance with Data Subject Rights
4.1 Requests
MapOutcomes shall assist Controller, by appropriate technical and organizational measures, to fulfill its obligations to respond to data subject requests exercising their rights under Applicable Law, including:
- Right of access (Section 3 of PIPEDA)
- Right to correction (Section 4.3 of PIPEDA)
- Right to withdraw consent (Section 4.3 of PIPEDA)
- Right to deletion
- Right to data portability
4.2 Response Timeline
MapOutcomes will respond to Controller's requests for assistance within 10 business days of receipt. Controller remains responsible for communicating directly with data subjects.
5. Data Breach Notification
5.1 Notification Obligation
In the event of a personal information breach (as defined by PIPEDA), MapOutcomes shall:
- Notify Controller without undue delay, and in no case later than 24 hours after becoming aware of the breach;
- Provide sufficient information to enable Controller to meet its own notification obligations under PIPEDA and Applicable Law;
- Cooperate with Controller in investigating and mitigating the breach;
- Maintain a record of all breaches including facts, effects, and remedial measures.
5.2 Notification Content
Breach notifications will include:
- The nature of the breach and categories of affected Personal Information
- The likely consequences of the breach
- Measures taken or proposed to address the breach, including measures to mitigate adverse effects
- Contact information for MapOutcomes' Privacy Officer
5.3 Privacy Officer
For breach-related inquiries, contact MapOutcomes' Privacy Officer at: [email protected]
6. Audit and Inspection
6.1 Audit Rights
Upon reasonable notice (at least 10 business days), Controller may audit MapOutcomes' compliance with this Agreement, including inspections of facilities, systems, and procedures relevant to Processing. Audits may be conducted no more than once per calendar year unless a breach or material compliance concern is identified.
6.2 Compliance Evidence
MapOutcomes shall, at Controller's request, provide documented evidence of compliance, including but not limited to:
- Security assessment reports
- Penetration testing results
- Employee training records
- Incident response documentation
7. Return and Deletion
7.1 End of Service
Upon termination of the Services or expiration of the subscription, MapOutcomes shall, at Controller's choice:
- Return all Personal Information in a structured, commonly used, and machine-readable format; or
- Delete all Personal Information and existing copies, unless Applicable Law requires storage for longer periods.
7.2 Deletion Timeline
- Data export window: 30 days following termination
- Permanent deletion from active systems: Within 5 business days following the export window
- Backup purging: Up to 90 days from termination, in accordance with standard backup rotation
8. Governing Law and Dispute Resolution
8.1 Governing Law
This Agreement is governed by the laws of the Province of Ontario and the federal laws of Canada applicable therein.
8.2 Jurisdiction
Any dispute arising out of this Agreement is subject to the exclusive jurisdiction of the courts of the Province of Ontario.
8.3 Good-Faith Negotiation
Before pursuing formal legal remedies, the parties agree to attempt to resolve any dispute through good-faith negotiation for at least 30 days.
9. General Provisions
9.1 Relationship to ToS
This DPA supplements the ToS. In the event of inconsistency, this DPA prevails with respect to data processing matters.
9.2 Amendments
MapOutcomes may amend this DPA with 30 days' written notice. Material changes affecting Controller's rights will be communicated via email and/or Platform notice.
9.3 Survival
Sections 3.2 (Confidentiality), 5 (Data Breach Notification), 7 (Return and Deletion), 8 (Governing Law), and 9 (General Provisions) survive termination of this Agreement.
9.4 Contact
MapOutcomes Inc.
Privacy Officer: [email protected]
Support: [email protected]
Legal: [email protected]
This Data Processing Agreement has been prepared by the MapOutcomes Legal & Compliance function. For legal advice regarding data processing compliance, consult a qualified Canadian privacy lawyer.