Data Processing Agreement
Effective date: July 8, 2025
1. Introduction
This Data Processing Agreement ("DPA") forms part of the Terms of Service between Tint Bolt and S3 Tint (collectively, the "Data Processor" or "we", "us", "our") and you (the "Data Controller" or "you", "your") regarding the processing of personal data in connection with our services.
2. Definitions
For the purposes of this DPA:
- "GDPR" means the General Data Protection Regulation (EU) 2016/679
- "Personal Data" means any information relating to an identified or identifiable natural person
- "Processing" means any operation performed on Personal Data
- "Data Subject" means the individual to whom Personal Data relates
- "Sub-processor" means any third party engaged by us to process Personal Data
3. Scope and Duration
This DPA applies to all Personal Data processed by us on your behalf in connection with the provision of our services. The duration of this DPA corresponds to the duration of our Terms of Service.
4. Nature and Purpose of Processing
We process Personal Data for the following purposes:
- Providing and maintaining our business management platform
- Managing user accounts and authentication
- Processing bookings and appointments
- Managing customer relationships and communications
- Processing payments and financial transactions
- Providing customer support and assistance
- Analyzing usage patterns to improve our services
- Ensuring security and preventing fraud
- Creating aggregated, anonymized market insights and industry reports
5. Types of Personal Data Processed
We process the following categories of Personal Data:
- Contact information (names, email addresses, phone numbers)
- Business information (company details, addresses, business metrics)
- Customer data (names, contact details, vehicle information, service history)
- Payment information (processed securely through Stripe or Square, depending on the transaction)
- Technical data (IP addresses, device information, usage logs)
- Communication data (support tickets, chat logs, emails)
6. Categories of Data Subjects
We process Personal Data relating to the following categories of Data Subjects:
- Your employees and authorized users
- Your customers and clients
- Prospective customers and leads
- Service providers and business partners
7. Our Obligations as Data Processor
We undertake to:
7.1 Processing in Accordance with Instructions
We will process Personal Data only on your documented instructions, including regarding transfers to third countries or international organizations, unless required to do so by applicable law.
7.2 Confidentiality
We will ensure that persons authorized to process Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
7.3 Security Measures
We will implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- Encryption of Personal Data in transit and at rest
- Regular testing and evaluation of security measures
- Access controls and authentication mechanisms
- Regular security audits and monitoring
- Incident detection and response procedures
7.4 Sub-processors
We may engage Sub-processors to assist in providing our services. We will:
- Inform you of any intended changes concerning Sub-processors
- Impose the same data protection obligations on Sub-processors
- Remain liable for the performance of Sub-processors' obligations
7.5 Data Subject Rights
We will assist you in responding to requests from Data Subjects to exercise their rights under the GDPR, including:
- Right of access
- Right to rectification
- Right to erasure
- Right to data portability
- Right to restrict processing
- Right to object
7.6 Data Breach Notification
We will notify you without undue delay after becoming aware of a Personal Data breach, providing you with:
- Description of the nature of the breach
- Categories and approximate number of Data Subjects concerned
- Categories and approximate number of Personal Data records concerned
- Likely consequences of the breach
- Measures taken or proposed to address the breach
7.7 Data Protection Impact Assessments
We will assist you in carrying out data protection impact assessments and prior consultations with supervisory authorities.
7.8 Deletion or Return of Personal Data
Upon termination of our services, we will delete or return all Personal Data to you, unless retention is required by applicable law.
8. Your Obligations as Data Controller
You undertake to:
- Ensure you have a legal basis for processing Personal Data
- Obtain necessary consents from Data Subjects
- Provide accurate and up-to-date Personal Data
- Notify us of any changes to processing instructions
- Cooperate with us in responding to Data Subject requests
- Maintain appropriate security measures for your systems
9. Sub-processors
We use the following Sub-processors to provide our services:
9.1 Infrastructure and Hosting
- Google Cloud Platform (Firebase): Data storage and hosting
- Google Analytics: Website analytics and usage tracking
- Google Tag Manager: Marketing tag management
9.2 Payment Processing
- Square: Payment processing and transaction management
- Stripe: Subscription payment processing
9.3 Customer Support and Communication
- Intercom: Customer support and communication platform
9.4 Marketing and Analytics
- Facebook Pixel: Advertising tracking and optimization
- Segment: Customer data platform and analytics
- Rewardful: Referral and affiliate marketing
10. International Transfers
Personal Data may be transferred to and processed in countries outside the European Economic Area (EEA). We ensure that such transfers comply with applicable data protection laws through:
- Adequacy decisions by the European Commission
- Standard contractual clauses approved by the European Commission
- Other appropriate safeguards as required by the GDPR
11. Audit Rights
You have the right to audit our compliance with this DPA. We will:
- Provide reasonable assistance with audits
- Allow inspections of our facilities and systems
- Provide relevant documentation and information
- Cooperate with supervisory authority audits
12. Liability
Our liability under this DPA is subject to the limitations set forth in our Terms of Service. We will be liable for any damages caused by our processing activities that are in breach of this DPA or applicable data protection laws.
13. Termination
This DPA will terminate automatically upon termination of our Terms of Service. Upon termination, we will delete or return all Personal Data in accordance with Section 7.8.
14. Governing Law and Jurisdiction
This DPA is governed by the laws of Canada, with specific reference to applicable data protection laws. Any disputes arising from this DPA will be resolved in accordance with the dispute resolution provisions of our Terms of Service.
15. Contact Information
For questions about this DPA or our data processing activities, please contact us at jay@s3tint.com.
16. Changes to This DPA
We may update this DPA from time to time to reflect changes in our data processing practices or applicable laws. We will notify you of any material changes and obtain your consent if required.