Data Processing Agreement
Version 7 · Effective
DealerStak Canada Inc.
About This DPA
This Data Processing Agreement ("DPA") forms part of the agreement between DealerStak Canada Inc. ("DealerStak", "we", "us") and the Dealer ("you", "Controller") and governs DealerStak's processing of personal information on behalf of the Dealer in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation.
This DPA supplements and is incorporated into the DealerStak Terms and Conditions and Privacy Policy. In the event of conflict between this DPA and the Terms and Conditions, this DPA governs with respect to data processing matters.
This DPA replaces Version 1 (May 2026) and reflects the current platform architecture, including the migration to dedicated third-party object storage for all files and documents.
1. Definitions
Personal Information — any information about an identifiable individual as defined under PIPEDA, including but not limited to client names, contact details, financial information, and Social Insurance Numbers.
Controller — the Dealer, who determines the purposes and means of processing personal information entered into the Platform.
Processor — DealerStak Canada Inc., which processes personal information on behalf of and under the instructions of the Controller.
Processing — any operation performed on personal information including collection, storage, retrieval, use, disclosure, or deletion.
Subprocessor — a third party engaged by DealerStak to process personal information in connection with providing the Platform services.
Data Subject — an individual whose personal information is processed through the Platform.
2. Roles and Responsibilities
2.1 — The Dealer is the Controller of personal information entered into the Platform. DealerStak acts as the Processor of that information.
2.2 — DealerStak processes personal information only on documented instructions from the Dealer, which instructions are deemed given by the Dealer's use of the Platform features.
2.3 — DealerStak will not process personal information for any purpose other than to provide Platform services and as expressly permitted in the Terms and Conditions (including StakScore anonymized aggregate data collection, for which separate consent is obtained).
2.4 — DealerStak will promptly notify the Dealer if in DealerStak's opinion an instruction from the Dealer would violate PIPEDA or applicable Canadian privacy law.
3. Types of Personal Information Processed
DealerStak processes the following categories of personal information on behalf of the Dealer:
Dealer employee and user information — names, email addresses, roles, license numbers, activity logs
Client personal information — names, addresses, phone numbers, email addresses, employment information
Client financial information — banking information, credit application data
Client SIN numbers (Retail Module only) — stored encrypted, never displayed in plain text
Vehicle transaction records — deal financials, purchase and sale prices, trade-in data
Uploaded documents — photos, invoices, business records, compliance documents
4. Technical and Organizational Security Measures
4.1 Encryption
All uploaded files and documents are encrypted at rest using AES-256 in DealerStak's object storage — the same standard used by financial institutions and government agencies worldwide
All data in transit is protected using TLS 1.2 or higher. Unencrypted connections are disabled.
Social Insurance Numbers are encrypted at rest using industry-standard encryption and are never displayed or transmitted in plain text
4.2 Infrastructure Security Certifications
DealerStak's file storage infrastructure is independently audited and certified to the following standards:
SOC 2 Type II — Security, Confidentiality, and Availability trust principles, audited annually by independent third parties
ISO 27001 — Information Security Management System standard
ISO 27701 — Privacy Information Management extension (directly relevant to PIPEDA compliance)
Security reports are available to Dealers upon request at support@dealerstak.com, subject to confidentiality requirements.
4.3 Access Controls
Role-based access controls limit data access to authorized users within each dealer portal
All data access and modifications are logged in a comprehensive audit trail
New user access requires explicit approval from the Dealer Principal
DealerStak employees access dealer data only when required to provide support and only with appropriate authorization
4.4 Data Isolation
Each dealer's data is logically isolated by unique dealer identifier in all storage systems
Cross-dealer data access is technically prevented at the infrastructure level
4.5 Incident Response
DealerStak maintains a documented incident response plan
In the event of a breach affecting personal information, DealerStak will notify the affected Dealer within 72 hours as required by PIPEDA
DealerStak will cooperate fully with any regulatory investigation
5. Subprocessors
DealerStak engages third-party subprocessors to process personal information in connection with the Platform. DealerStak ensures all subprocessors are bound by appropriate data protection obligations. Subprocessors fall within the following categories:
5.1 Categories of Subprocessor
| Category | Categories of personal information processed | Purpose |
|---|---|---|
| Cloud application infrastructure | All categories held in the application database; authentication identifiers | Database, authentication, server-side compute |
| Object storage | All uploaded documents and images, including signed Bills of Sale, signature specimens, statements and receipts | Primary object storage |
| Payment processing | Dealer billing contact and payment instrument data | Subscription billing |
| Email delivery | Recipient email addresses and message content | Transactional and Dealer-facing email |
| Artificial intelligence — document extraction | Contents of documents submitted to extraction features — may include financial account numbers, transaction counterparty names, names, addresses, telephone numbers, business and tax registration numbers, and government-issued identification numbers | Automated document extraction; in-app support assistant |
| Artificial intelligence — image processing | Vehicle photographs only — no personal information | Background replacement on vehicle imagery |
| Error monitoring and security alerting | Staff email addresses; IP addresses; error event content | Error monitoring and authentication-anomaly alerting |
| Vehicle data enrichment | Vehicle Identification Number only — no personal information | Vehicle specification enrichment |
| Push notification delivery | Device push token; notification title and body | Mobile push notification delivery |
| Weather and geocoding | Dealership city and coordinates — business location, not individual location; User IP address where radar imagery loads directly in the browser | Hail-risk forecasting and radar display |
| Messaging | Dealer and staff names and telephone numbers; vehicle identifiers; pickup and delivery addresses; free-text notes; vehicle photographs sent as media; inbound sender number and message body | SMS and MMS vendor quote requests |
| Administrative tooling | Dealer administrative records; data-access request and export workflows | Hosting of the internal control panel used by DealerStak staff |
5.1.1 — Subprocessor register. The identity of each subprocessor within the categories above, the jurisdiction in which it operates, its current status, and the categories of information it receives are recorded in DealerStak's subprocessor register. DealerStak will provide the current register to the Dealer on written request to privacy@dealerstak.com. The register is confidential information of DealerStak and is provided for the Dealer's own compliance and vendor-review purposes only.
5.1.2 — Public and third-party data sources. DealerStak additionally queries public, governmental and vehicle-manufacturer data sources for recall, safety, specification, window-sticker and meteorological information. These receive a Vehicle Identification Number or a geographic bounding box only, and never personal information. They are not subprocessors for the purposes of this DPA.
5.1.3 — Vendor recipients initiated by the Dealer. Where a Dealer uses the transport-quote or tire-quote features, the request — including the pickup and delivery contact names and telephone numbers the Dealer enters — is emailed to the third-party vendor named in the feature. These are recipients acting on the Dealer's instruction rather than DealerStak's subprocessors. Both features are currently unused.
5.2 — DealerStak will notify the Dealer of any intended changes to its subprocessors (additions or replacements) at least 30 days before the change takes effect. The Dealer may object to such changes by notifying DealerStak at support@dealerstak.com within 14 days of notification.
5.3 — DealerStak remains fully responsible to the Dealer for the performance of subprocessors' obligations under this DPA.
6. Data Retention and Deletion
6.1 — DealerStak retains personal information for the duration of the active subscription and for 30 days following contract termination.
6.2 — Upon the Dealer's written request following termination, DealerStak will provide a full export of all Dealer data within 10 business days.
6.3 — After the 30-day retention period, DealerStak will permanently delete all Dealer personal information from its systems, including all copies held by subprocessors. DealerStak will provide written confirmation of deletion within 10 business days of the deletion date.
6.4 — Technical logs and audit records may be retained for up to 7 years for legal compliance purposes but are not considered personal information for the purposes of this DPA.
7. Data Subject Rights
7.1 — If DealerStak receives a request from a Data Subject exercising rights under PIPEDA, DealerStak will promptly forward the request to the Dealer. DealerStak will cooperate with the Dealer to fulfill such requests within the timeframes required by PIPEDA.
7.2 — DealerStak will not respond directly to Data Subject rights requests without the Dealer's authorization, except where required by law.
8. Data Transfers
8.1 — The system of record is the application database, hosted by DealerStak's cloud infrastructure provider on infrastructure located in the United States (Oregon), together with the object store holding every uploaded document. Personal information in the system of record is therefore stored and processed outside Canada and is subject to the laws of the United States, which may permit access by its courts, law enforcement and government authorities.
8.2 — The object-storage infrastructure is located in Western North America data centres.
8.2A — In accordance with section 13.1 of Alberta's Personal Information Protection Act, a Dealer or an individual whose personal information DealerStak handles may obtain (a) information about DealerStak's policies and practices with respect to service providers outside Canada, and (b) the name and contact details of a person able to answer questions about the collection, use, disclosure and storage of personal information by those service providers. Both are available from the Privacy Officer at privacy@dealerstak.com.
8.3 — Several subprocessors within the categories set out in Section 5.1 operate outside Canada. The cloud infrastructure, object storage, payment processing, email delivery, artificial intelligence, error monitoring, vehicle data enrichment, push notification, messaging and administrative tooling providers are United States entities; the weather and geocoding providers operate outside North America. The jurisdiction of each is identified in the subprocessor register described in Section 5.1.1. Personal information transferred to any of them is subject to the laws of the jurisdiction in which they operate and may be accessible to the courts, law enforcement and government authorities of that jurisdiction. DealerStak requires each to be bound by data protection terms comparable to this DPA but cannot exempt any of them from the law applicable to them.
8.4 — The most significant such transfer is to the artificial-intelligence provider that performs document extraction, which receives the contents of documents the Dealer submits to the extraction features described in Section 5.1. A Dealer who does not wish personal information to leave Canada in this way should use the manual-entry alternative available for every affected feature.
9. Audit Rights
9.1 — DealerStak will make available to the Dealer all information reasonably necessary to demonstrate compliance with this DPA.
9.2 — DealerStak will provide copies of relevant subprocessor security certifications (SOC 2 Type II reports, ISO certificates) upon request, subject to any confidentiality obligations.
9.3 — The Dealer may request an audit of DealerStak's data processing activities no more than once per year with at least 30 days' written notice. Costs of any audit are borne by the Dealer unless the audit reveals a material breach by DealerStak.
10. Governing Law
This DPA is governed by the laws of the Province of Alberta and the federal laws of Canada, including PIPEDA. Any disputes shall be resolved in the courts of the Province of Alberta.
11. Term and Termination
This DPA is effective for the duration of the Dealer's subscription agreement with DealerStak and terminates automatically upon expiry or termination of that agreement, subject to the data retention provisions of Section 6.
12. Execution
This DPA is entered into by the parties on the date the Dealer electronically signs the Dealer Subscription Agreement and accepts the Incorporated Documents during onboarding. The electronic signature collected at that time constitutes execution of this DPA as well as of the Terms and Conditions. The version of this DPA in force between DealerStak and a particular Dealer, together with its SHA-256 content hash and the date and time of acceptance, is recorded in DealerStak's records and is available to the Dealer on request.
13. Contact
Privacy enquiries and data access requests: privacy@dealerstak.com. Questions about this DPA, and requests for security documentation: support@dealerstak.com. Formal notices under Section 14.4 of the Terms and Conditions: legal@dealerstak.com.
DealerStak Canada Inc., Calgary, Alberta, Canada — dealerstak.com
Questions about this document? Email support@dealerstak.com.