Skip to Footer

Data Processing Agreement

Last updated: April 29, 2026

This Data Processing Agreement (the "Agreement") forms part of, and is incorporated by reference into, any master services agreement, services agreement, order form, statement of work, data request, or other agreement (each, a "Master Agreement" as may be applicable) between AuraData Inc. ("AuraData") and the Canadian educational institution and/or professional body (each an "Institution") in which a data request is made in respect of the Services (defined below).

This DPA sets out the additional terms, requirements and conditions on which AuraData will process Personal Data when providing services under the Master Agreement. This Agreement contains the mandatory clauses required by Article 28(3) of the retained EU law version of the General Data Protection Regulation ((EU) 2016/679) (UK GDPR)

This Agreement applies only to the extent that applicable data protection laws, including the EU GDPR or UK GDPR apply to the Processing of Personal Data under a Master Agreement.

  1. Definitions

    1. The following definitions and rules of interpretation apply in this Agreement:

      1. "Commissioner" means the Information Commissioner (see Article 4(A3), UK GDPR).
      2. "Controller", "Processor", "Data Subject", "Personal Data", "Personal Data Breach" and "Processing" shall have the meanings given in the Data Protection Legislation.
      3. "Data Protection Legislation" means:
        1. To the extent the UK GDPR applies, the law of the United Kingdom or of a part of the United Kingdom which relates to the protection of Personal Data.
        2. To the extent the EU GDPR applies, the law of the European Union or any member state of the European Union to which the Institution or AuraData is subject, which relates to the protection of Personal Data.
      4. "Data Subject" means the identified or identifiable living individual to whom the Personal Data relates.
      5. "Domestic Laws" means all applicable privacy and data protection laws in Canada applicable to the Institution as may be amended from time to time, such as the Freedom of Information and Protection of Privacy Act, Personal Information Protection and Electronic Documents Act (2000, c.5) and substantially similar private sector provincial laws.
      6. "EU GDPR" means the General Data Protection Regulation ((EU) 2016/679).
      7. "Master Agreement" has the meaning given to it in the Preamble.
      8. "Personal Data" means any information relating to an identified or identifiable living individual that is processed by AuraData on behalf of the Institution as a result of, or in connection with, the provision of the Services; an identifiable living individual is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of the individual.
      9. "Personal Data Breach" means a breach of security leading to the accidental, unauthorised or unlawful destruction, loss, alteration, disclosure of, or access to, the Personal Data.
      10. "Records" has the meaning given to it in Clause 12.
      11. "Services" means the services to be provided by AuraData as described in ANNEX A.
      12. "Term" has the meaning given to it in Clause 10.
      13. "UK GDPR" has the meaning given to in section 3(10) (as supplemented by section 205(4)) of the Data Protection Act, 2018 (UK).
  2. Application and Interpretation

    1. By using AuraData's Services, the Institution agrees to be bound by this Agreement. AuraData reserves the right, in its sole discretion, to modify, alter or otherwise update this Agreement. Date of most recent update is April 29, 2026.
    2. The Annex forms part of this Agreement and will have effect as if set out in full in the body of this Agreement. Any reference to this Agreement includes the Annexes.
    3. If there is any inconsistency between any of the terms of this Agreement and the provisions of an existing Master Agreement between AuraData and the Institution, the provisions of the Master Agreement will prevail.
  3. Personal Data Types and Processing Purposes

    1. The Institution and AuraData agree and acknowledge that for the purpose of the Data Protection Legislation:

      1. the Institution is the Controller and AuraData is the Processor.
      2. the Institution retains control of the Personal Data and remains responsible for its compliance obligations under the applicable Data Protection Legislation, including but not limited to providing any required notices and obtaining any required consents, and for the written processing instructions it gives to AuraData.
      3. ANNEX A describes the subject matter, duration, nature and purpose of the processing and the Personal Data categories and Data Subject types in respect of which AuraData may process the Personal Data to fulfil the Services.
  4. Obligations

    1. AuraData will only process the Personal Data to the extent, and in such a manner, as is necessary for the Services in accordance with the Institution's written instructions. AuraData will not process the Personal Data for any other purpose or in a way that does not comply with this Agreement or the Data Protection Legislation.
    2. AuraData must comply promptly with any Institution written instructions requiring AuraData to amend, transfer, delete or otherwise process the Personal Data, or to stop, mitigate or remedy any unauthorised processing.
    3. AuraData will maintain the confidentiality of the Personal Data and will not (subject to section 5.1) disclose the Personal Data to third parties unless the Institution or this Agreement specifically authorises the disclosure, or as required by domestic law, court or regulator (including the Commissioner).
    4. AuraData will reasonably assist the Institution with meeting the Institution's compliance obligations under the Data Protection Legislation, taking into account the nature of AuraData's processing and the information available to AuraData, including in relation to Data Subject rights, data protection impact assessments and reporting to and consulting with the Commissioner or other relevant regulator under the Data Protection Legislation.
    5. Institution shall at all times provide clear written instructions for the use of Services in accordance with all applicable law.
  5. AuraData's Employees and Agents

    1. AuraData will ensure that all of its employees, contractors, agents and professional advisors:

      1. only access Personal Data if and when such employee reasonably needs to have such access for AuraData carry out the Services; and
      2. are informed of the confidential nature of the Personal Data and are bound by confidentiality obligations and use restrictions in respect of the Personal Data.
  6. Security

    1. AuraData must at all times implement appropriate technical and organisational measures against unauthorised or unlawful processing, access, copying, modification, reproduction, display or distribution of the Personal Data, and against accidental or unlawful loss, destruction, alteration, disclosure or damage of Personal Data.
    2. AuraData must implement such measures to ensure a level of security appropriate to the risk involved, including as appropriate:

      1. the pseudonymisation and encryption of personal data;
      2. the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services;
      3. the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident; and
      4. a process for regularly testing, assessing and evaluating the effectiveness of the security measures.
  7. Personal Data Breach

    1. AuraData will comply with the personal data breach response requirements in the UK GDPR and inform Institution of a data security incident if known to AuraData that may affect Personal Data, as soon as reasonably possible after discovery the incident, if the incident could pose a real risk of significant harm to individual.
    2. Following any accidental, unauthorised or unlawful Personal Data processing or Personal Data Breach, the parties will co-ordinate with each other to investigate the matter and AuraData will provide reasonable support to the Institution, insofar as possible, in order to assist the Institution with its compliance obligations, such as communicating with European Union data protection authorities.
  8. Subcontractors

    1. Other than those subcontractors as set out in Annex A, AuraData may only authorise a third party (subcontractor) to process the Personal Data if:

      1. the Institution is provided with an opportunity to object to the appointment of each subcontractor within 10 business days after AuraData supplies the Institution with notice in writing, including without limitation, by posting an updated Annex including such subcontractor;
      2. AuraData requires the subcontractor to implement appropriate technical and organizational security safeguards to protect Personal Data; and
      3. AuraData maintains control over all of the Personal Data it entrusts to the subcontractor.
    2. The Institution acknowledges and agrees that those subcontractors set out in ANNEX A are approved.
    3. Where the subcontractor fails to fulfil its obligations under the written agreement with AuraData which contains terms substantially the same as those set out in this Agreement, AuraData remains fully liable to the Institution for the subcontractor's performance of its agreement obligations.
    4. The Parties agree that AuraData will be deemed to control legally any Personal Data controlled practically by or in the possession of its subcontractors.
  9. Complaints, Data Subject Requests and Third-Party Rights

    1. AuraData must take such technical and organizational measures as may be appropriate, and promptly provide such information to the Institution as the Institution may reasonably require, to enable the Institution to comply with:

      1. the rights of Data Subjects under the Data Protection Legislation, including subject access rights, the rights to rectify, port and erase personal data, object to the processing and automated processing of personal data, and restrict the processing of personal data; and
      2. information or assessment notices served on the Institution by the Commissioner or other relevant regulator under the Data Protection Legislation.
    2. AuraData must promptly notify the Institution in writing if it receives any complaint, notice or communication that relates directly or indirectly to the processing of the Personal Data or to either party's compliance with the Data Protection Legislation.
    3. AuraData will give the Institution, at no additional cost to the Institution, its full co-operation and assistance in responding to any complaint, notice, communication or Data Subject request.
    4. AuraData must not disclose the Personal Data to any Data Subject or to a third party other than in accordance with the Institution's written instructions, or as required by domestic law.
    5. Institution acknowledges and agrees that Personal Data includes Personal Information (as such term is defined in Domestic Law), related to specific Data Subjects and such Data Subjects may request, and must be provided with, access to such information from AuraData, in accordance with applicable Domestic Laws. The Data Subject retains the right to share their Personal Data, or confirmation that such information was complete and accurate at a point in time, at their sole discretion, with any third party or individual deemed appropriate by the Data Subject.
  10. Term and Termination

    1. This Agreement will remain in full force and effect so long as AuraData retains any of the Personal Data in its possession or control (Term).
    2. This agreement shall terminate immediately if any of the following shall occur:

      1. AuraData has no Personal Data in its possession or control;
      2. the parties mutually agree in writing;
      3. on written notice from the Institution to AuraData.
  11. Data Return and Destruction

    1. On termination of the Master Agreement for any reason or expiry of its term, AuraData will securely delete or destroy or, if directed in writing by the Institution, return and not retain, all or any of the Personal Data related to this Agreement in its possession or control, except for Personal Data existing in search results conducted by a customer of AuraData, which shall be retained for a period of seven (7) years from the date of the search, or for such greater period time as may be required by any and all applicable laws. AuraData may also retain any documents or materials or Personal Data that may be required to be retained by applicable law. In addition to the foregoing, AuraData reserves the right to retain a record or log for the purposes of confirming an education verification validly requested by a subscriber was complete and accurate at a point in time.
  12. Records

    1. AuraData will keep detailed, accurate and up-to-date written records regarding any processing of the Personal Data, including but not limited to, the access, control and security of the Personal Data, approved subcontractors, the processing purposes, categories of processing, any transfers of personal data to a third country and related safeguards, and a general description of the technical and organisational security measures referred to in clause 6.1 (Records).
  13. Audits

    1. To the extent that Institution possesses any audit or inspection rights under applicable legislation, regarding the privacy and data security safeguards that AuraData has in place, AuraData shall fully cooperate with such audits. Any audit shall be conducted judiciously, ensuring a reasonable examination of all relevant aspects, while upholding strict adherence to AuraData's privacy and security requirements. Provided the foregoing requirements are satisfied, AuraData will give the Institution and its third-party representatives all necessary assistance to conduct such audits.
  14. Warranties

    1. AuraData warrants and represents that:

      1. it and anyone operating on its behalf will process the Personal Data in compliance with the Data Protection Legislation and other laws, enactments, regulations, orders, standards and other similar instruments;
      2. it has no reason to believe that the Data Protection Legislation prevents it from providing any of the Services; and
      3. considering the current technology environment and implementation costs, it will take appropriate technical and organisational measures to prevent the unauthorised or unlawful processing of Personal Data and the accidental loss or destruction of, or damage to, Personal Data, and ensure a level of security appropriate to:

        1. the harm that might result from such unauthorised or unlawful processing or accidental loss, destruction or damage;
        2. the nature of the Personal Data protected; and
        3. comply with all applicable Data Protection Legislation and its information and security policies, including the security measures required in clause 6.1.
    2. The Institution warrants and represents that AuraData's expected use of the Personal Data for the Services and as specifically instructed by the Institution will comply with the Data Protection Legislation.
  15. Notice

    1. Any notice given to a party under or in connection with this Agreement shall be in writing and shall be:

      1. in accordance with the notice provisions of the applicable Master Agreement; or
      2. if no such notice provision exists, by email to the Institution's primary contact associated with the Services.

ANNEX A Personal Data Processing Purposes and Details

Subject Matter of Processing
Education verification
Nature of Processing
Data collection, storage, and sharing
Services
AuraData is in the business of providing education verification services to third party entities who wish to confirm claims made by Data Subjects related to education and/or professional designations of said Data Subjects (the "Services")
Personal Data Categories
Names, birth date, student numbers, education histories
Data Subject Types
Employees, former students

AuraData's legal basis for processing Personal Data outside the European Economic Area in order to comply with cross-border transfer restrictions are as follows:

  • Located in Canada, a country with a current determination of adequacy

Approved Subcontractors

SubcontractorService ProvidedLocation
Microsoft AzureHosting of AuraData's application and databaseCanada
Independent customer service representatives and programmersSupport AuraData's Services on an as-needed basis with admin access to leased server spaceCanada