Legal

Data Processing Addendum

This document forms part of the Master Services Agreement between AIDARO Suite (the Processor) and each subscribing organization (the Controller). It sets out how personal data is processed, where it is stored, and what protections are in place.

Last updated: September 2026  |  This addendum applies to all active subscriber agreements with AIDARO Suite.

About this document: This Data Processing Addendum ("DPA") forms part of the Master Services Agreement ("Agreement") between AIDARO Suite (the "Processor") and the subscribing organization (the "Controller"). Where this DPA conflicts with the Agreement, this DPA governs for all matters relating to personal data.

Section 1

Scope, Roles, and Responsibilities

Definitions: "Personal Data" means any information processed within the AIDARO system that relates to an identified or identifiable person. This includes information about victims, witnesses, family members, and the personnel of subscribing organizations.

Roles: The subscribing organization is the Data Controller under the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable Ontario law. AIDARO Suite is the Data Processor. We process personal data only on the Controller's behalf and according to the Controller's documented instructions.

Controller responsibilities: The subscribing organization confirms that it has the legal authority to collect and input personal data into the AIDARO system. This includes obtaining any necessary consents and providing any required privacy notices to the individuals whose information is entered.

Section 2

Infrastructure and Data Residency

AIDARO uses a segmented infrastructure model. Where data is stored depends on its type.

Uploaded files and documents (stored in Canada): All files, documents, images, audio, video, and static attachments uploaded to the system are stored exclusively on dedicated storage servers located within Canada. These files do not leave Canadian borders under any circumstances.

Application processing (United States): The core application logic and temporary session data are hosted on a dedicated server located in the United States. This server is owned and managed exclusively by AIDARO Suite. No shared or multi-tenant cloud infrastructure is used.

System backups (Ontario, Canada): All disaster recovery images, data backups, and system redundancy logs are encrypted and stored exclusively on servers located within Ontario, Canada. No US-based personnel or foreign entities have access to these backup archives.

Section 3

Cross-Border Processing Disclosure

Important disclosure: Because the application logic and active processing occur on a dedicated server in the United States, temporary data sets are subject to US law. Subscribing organizations should take this into account when evaluating their own obligations under PIPEDA.

US jurisdiction: The Controller confirms that it understands that temporary data sets processed through the US application server are subject to US federal law.

Government intercept risk: Under applicable US federal law including the CLOUD Act, US courts or law enforcement may compel AIDARO Suite to disclose data residing on or passing through the US server via valid legal orders. AIDARO Suite will use all available legal avenues to resist overbroad or improperly authorized requests. We will notify the Controller immediately unless we are legally prohibited from doing so.

Mitigation: The highest-sensitivity files, including police reports, witness statements, and case documents, are stored entirely in Canada and are not hosted on the US server. This limits the data that could be subject to a US disclosure order to temporary application data only.

Section 4

Handling Requests from Individuals

No direct fulfillment: If a victim, witness, family member, or staff member contacts AIDARO Suite directly to exercise their rights under PIPEDA (such as requesting access to or correction of their personal data), we will not fulfill that request directly. Those records belong to and are controlled by the subscribing organization.

Forwarding: We will forward any such request to the relevant Controller within 48 hours of receiving it. We will provide reasonable assistance to help the Controller respond within its statutory obligations under PIPEDA.

Section 5

Security Safeguards

AIDARO Suite maintains the following technical and organizational safeguards:

  • Encryption in transit: All data moving between user devices, the US application server, and the Canadian storage servers is protected using TLS encryption.
  • Encryption at rest: All data stored on our servers, including the US application server, the Canadian file servers, and the Ontario backup archives, is encrypted using AES-256 bit encryption.
  • Access controls: Role-based access control (RBAC) ensures users can access only the data their role permits. Multi-factor authentication (MFA) is available for all users and can be made mandatory by the Controller's administrators.
  • Audit logging: A full log of all user actions, including logins, data access, changes, and file downloads, is maintained at all times.
  • Administrative access: Physical and logical access to all infrastructure is strictly limited to vetted and background-checked internal system administrators. No external parties have standing access.

Breach notification: If AIDARO Suite confirms a security incident that results in unauthorized access, alteration, or loss of personal data, we will notify the Controller via email within 24 hours of confirming the incident. We will provide the technical details the Controller needs to meet its mandatory breach reporting obligations to the Office of the Privacy Commissioner of Canada.

Questions about this addendum?
Contact us at support@aidaro.ca. For new organizations requesting a signed copy of the DPA as part of a procurement process, please include your organization name and your legal contact in your email.

Privacy Policy Security & Data Residency FAQ Request a Demo