Skip to content

Legal

Data Processing Addendum

This DPA describes how PactCanvas processes personal data for merchants and forms part of our Terms of Service.

Effective July 20, 2026

1. Scope and roles

This Data Processing Addendum (“DPA”) is between the Merchant that accepts the Terms of Service (“Controller”) and TechImprovement Inc. (“Processor”). It applies when Processor processes personal data on Controller’s behalf through PactCanvas Sign & Proof. The Terms, this DPA, and the Merchant’s documented in-app configuration are Controller’s instructions.

Each party will comply with data-protection law applicable to its role. Controller is responsible for its lawful basis, notices, agreement content, signer instructions, data minimization, and retention choice.

2. Processing details

  • Subject: agreement assignment, signing, checkout validation, order evidence, support, and related security operations.
  • Duration: the subscription and configured retention period, plus limited backup rotation or legally required retention.
  • People: Merchant staff, customers, prospective customers, company representatives, signers, and individuals submitting support or privacy requests.
  • Data: identifiers, contact information, company/role information, agreement and order details, typed or drawn signature data, acknowledgements, timestamps, device/network evidence, and operational records.
  • Operations: collection, organization, display, matching, validation, storage, generation, transmission, export, restriction, deletion, and de-identification.
  • Sensitive data: not intentionally required; Controller must not submit payment credentials, government identifiers, health information, or other unsupported sensitive data.

3. Instructions and confidentiality

Processor will process personal data only on Controller’s documented instructions, including as needed to provide and secure the service, unless law requires otherwise. If legally permitted, Processor will notify Controller before processing required by law. Processor will inform Controller if an instruction appears to violate applicable law.

People authorized to process personal data are bound by confidentiality and receive access only where needed for their responsibilities.

4. Security measures

Processor maintains measures appropriate to the service’s risks, including:

  • tenant-scoped authorization and restricted production access;
  • HTTPS for public traffic and verified Shopify OAuth/webhooks;
  • private evidence storage and application encryption for proof files, drawn signatures, and completed PDFs;
  • separate development and production identities, credentials, services, and keys;
  • integrity events, diagnostic logging, dependency controls, privacy and retention workflows, release checks, and incident procedures.

Further public information is available on the Security page.

5. Subprocessors

Controller authorizes subprocessors needed to provide the service, including Shopify and providers for infrastructure, hosting, transactional email, domain/certificates, backup storage, and monitoring or incident response. Processor remains responsible for subprocessor obligations to the extent required by law and enters into data-protection terms appropriate to their services.

A current list is available from info@techimprovement.net. Processor will provide reasonable notice of a material new subprocessor when required, allowing Controller to raise a documented data-protection objection. If the parties cannot resolve it, Controller may stop the affected processing and terminate the affected service.

6. Individual requests and compliance assistance

Taking into account the nature of processing, Processor will reasonably assist Controller with verified access, correction, deletion, restriction, portability, objection, security, impact-assessment, and regulator-consultation obligations. Shopify privacy webhooks and app workflows support customer data access and erasure. Controller remains responsible for responding to the individual.

7. Personal data incidents

Processor will notify Controller without undue delay after confirming a personal data breach affecting Controller data and will provide available information reasonably needed for Controller’s assessment and notifications. Notice is not an admission of fault. Processor will take reasonable steps to contain, investigate, remediate, and document the incident.

8. International transfers

Where processing involves a restricted international transfer, the parties will use a legally recognized transfer mechanism. If the EU Standard Contractual Clauses or UK Addendum applies, the appropriate controller-to-processor module is incorporated and completed using the processing and security information in this DPA, subject to counsel’s confirmation of governing selections.

9. Return and deletion

During the service, Controller can access or export available evidence. At termination or on documented instruction, Processor will delete or de-identify personal data after active workflow, legal, and configured retention requirements are satisfied, unless law requires continued retention. Residual backup copies can remain until normal rotation. Processor may retain minimal records documenting deletion, security, billing, or legal compliance.

10. Information and audits

Processor will provide information reasonably necessary to demonstrate compliance. Where that information is insufficient and law requires, Controller may request an audit no more than annually, during business hours, with reasonable notice, confidentiality, security, scope, and cost protections. Audits must avoid exposing another merchant’s data or compromising the service.

11. Order of precedence and contact

If this DPA conflicts with the Terms on personal-data processing, this DPA controls. Otherwise the Terms remain effective. Data-protection questions and notices should be sent to info@techimprovement.net.