⚠️ DRAFT — pending legal counsel review. This Data Processing Addendum is a working draft published for transparency. It has not been reviewed or approved by counsel and is not a binding contract. The final, counsel-approved version will replace this draft. Until then, Canadian enterprise customers requiring an executable addendum should contact [email protected].
1. Scope and Roles
This Canadian Data Processing Addendum (the "Addendum") supplements the SIPSTACK Terms of Service and applies where SIPSTACK Inc. ("SIPSTACK") processes Personal Information on behalf of a customer (the "Customer") that is subject to Canadian privacy law, including the federal Personal Information Protection and Electronic Documents Act ("PIPEDA") and Québec's Act respecting the protection of personal information in the private sector, as amended by Law 25 ("Law 25").
For the Personal Information processed under the Services, the Customer is the party that determines the purposes of processing and SIPSTACK processes that information on the Customer's behalf and on its instructions to deliver the Services. SIPSTACK also acts in its own right for limited operational purposes (billing, security, fraud prevention, and regulatory compliance) as described in the Privacy Policy.
"Personal Information" has the meaning given under PIPEDA and Law 25. "Customer Data" means the data the Customer and its users submit to or generate through the Services.
2. Purpose and Nature of Processing
SIPSTACK processes Customer Data only to:
- provide and operate the Services (telephony, messaging, AI, and portal features) the Customer has contracted for;
- maintain, secure, and support the Services;
- comply with legal and telecommunications-regulatory obligations; and
- act on the Customer's documented instructions.
SIPSTACK does not sell Personal Information and does not use it for cross-context behavioural advertising. SIPSTACK does not use Customer Data to train AI model weights; AI knowledge-base improvement uses de-identified, human-reviewed content only, as described in the Privacy Policy.
3. Data Residency and Regional Model
SIPSTACK operates a regional data model for Customer user-generated content.
For Customers billed under the SIPSTACK Canadian entity (CAD), user-generated
content — call recordings, voicemail, music-on-hold, TTS audio, and other PBX
media — is stored in Canada (Wasabi S3 sipstack-ca, ca-central-1, Toronto).
SIP registration and call signaling for Canadian-region tenants are handled by
the Canadian nexus cluster; cross-region session border controllers carry SIP
signaling only — no voice or message media transits an SBC.
A bounded set of operational data flows crosses the Canada–U.S. border. Each such flow is itemized in Schedule 1 with its purpose and safeguards. These are the flows assessed under Law 25, s. 17. A summary of the corresponding Privacy Impact Assessment is available to enterprise Customers on request, subject to confidentiality.
4. SIPSTACK Obligations
SIPSTACK will:
- process Personal Information only on the Customer's documented instructions and as described in this Addendum and the Privacy Policy;
- ensure personnel authorized to process Personal Information are bound by confidentiality and are granted access on a need-to-know basis;
- implement and maintain the technical and organizational security measures described in Schedule 2;
- assist the Customer, taking into account the nature of processing, in responding to requests from individuals exercising their rights and in meeting the Customer's own breach-notification and assessment obligations;
- notify the Customer without undue delay after becoming aware of a confidentiality incident (breach) affecting the Customer's Personal Information, with the information reasonably available to support the Customer's notification obligations under PIPEDA and Law 25;
- on termination of the Services, delete or de-identify Customer Data in accordance with the retention schedule in the Privacy Policy and applicable law. Call recordings, voicemail and other PBX media objects are deleted from object storage. Certain records are retained rather than deleted where law or regulation requires (billing and payment records, call detail records) or where they form an audit trail; in those records direct identifiers are removed or replaced. That process is pseudonymization, not anonymization: the resulting records remain Personal Information and remain linkable by SIPSTACK. Backup and disaster-recovery archives rotate on their own schedule, so a copy of a deleted record may persist in an archive for a limited period after deletion from the live system; and
- make available information reasonably necessary to demonstrate compliance with this Addendum.
5. Sub-Processors
SIPSTACK uses the sub-processors listed in Schedule 1 and in the Privacy Policy sub-processor list. Each sub-processor is bound by a written agreement imposing data-protection obligations no less protective than this Addendum (see the draft note in section 6). SIPSTACK remains responsible for its sub-processors' performance.
SIPSTACK will provide notice of any intended addition or replacement of a sub-processor that processes Canadian Personal Information, giving the Customer a reasonable opportunity to object on reasonable data-protection grounds.
6. Cross-Border Transfers — Contractual Safeguards
For transfers of Personal Information to the United States listed in Schedule 1, SIPSTACK relies on contractual safeguards equivalent to standard contractual clauses (SCCs) with each recipient, supplemented by technical measures (encryption in transit and at rest) and, where applicable, no-training and no-secondary-use commitments. SIPSTACK has drafted Privacy Impact Assessments (Law 25, s. 17) for the principal cross-border flows (the WAL archive, Sentry, Together AI, and application logging), assessing the protection afforded in the destination jurisdiction; those assessments are currently undergoing legal review.
Draft note — read before relying on this section. The formal SCC mechanism, the executed sub-processor DPAs, and the s. 17 equivalence findings referenced in this Addendum have not been verified against counterparty contracts as at the date of this draft. They state SIPSTACK's intended contractual position. Counsel must substantiate each one against the executed agreement before this Addendum is published or offered for execution.
7. Individual Rights Assistance
The Services provide self-serve export and deletion tools (Switchboard → Account → Privacy), whose available scopes and limits are set out in the Privacy Policy. For requests that cannot be fulfilled self-serve, SIPSTACK will provide reasonable assistance to the Customer in responding to access, correction, withdrawal-of-consent, and deletion requests under PIPEDA and Law 25, taking into account the nature of the processing.
Draft note: the self-serve deletion scopes advertised in the Privacy Policy are under engineering review; counsel should confirm the published scopes against implemented behaviour before this Addendum is offered for execution, since this section incorporates them by reference.
8. Audit
SIPSTACK will make available to the Customer information reasonably necessary to demonstrate compliance with this Addendum and, on reasonable prior written notice and subject to confidentiality, will respond to the Customer's reasonable inquiries (including security questionnaires) relating to its processing.
9. Governing Law
This Addendum is governed by the laws of the Province of Ontario and the federal laws of Canada applicable therein. Nothing in this Addendum derogates from, or limits, any right or protection conferred on a Customer or an individual by Québec's Law 25 or by any other applicable mandatory law; where a provision of this Addendum conflicts with such a law, that law prevails and the remainder of this Addendum continues in force.
Draft note — French language. This Addendum is offered as a contract of adhesion. Under Québec's Charter of the French Language (s. 55), a contract of adhesion presented to a Québec party must be drawn up in French unless the parties have first been presented with a French version and expressly agree to contract in English. A French version does not yet exist. Counsel must resolve this before the Addendum is offered to any Québec customer; publishing or executing an English-only version would not comply.
Schedule 1 — Cross-Border Data Flows
The following itemizes each flow of Canadian Personal Information that crosses
the Canada–U.S. border, its purpose, the data involved, and the safeguard
relied upon. User-generated media for Canadian-entity Customers does not
appear below because it remains in Canada (Wasabi sipstack-ca).
| # | Recipient | Destination | Purpose | Personal Information involved | Safeguard |
|---|-----------|-------------|---------|-------------------------------|-----------|
| 1 | Cloudflare R2 (sipstack-wal) | United States | PostgreSQL WAL archive + base backups for point-in-time / disaster recovery | Incidental row-level PI inside binary WAL segments (not in queryable form) | Encryption in transit; provider-side encryption at rest (SIPSTACK holds no client-side key); bucket-scoped credentials; rolling ~14-day archive window. Draft PIA under review (s. 17). |
| 2 | Sentry | United States | Application error / crash monitoring | Error messages and stack traces, device metadata, and — for errors raised while handling an API request — the request method, query string, body and session cookie | TLS; encryption at rest; production-only; redaction of error text and attached context. Request-context redaction is not yet implemented. Draft PIA under review (s. 17). |
| 3 | Together AI | United States | Primary LLM inference for SARA AI text responses (support email, portal chat, SMS) | Inbound message content + RAG retrieval context | TLS; no-training commitment; transient processing. No customer opt-out from this routing exists today. Draft PIA under review (s. 17). |
| 4 | Stripe | United States | Payment processing and billing | Billing address, payment method details (card data handled by Stripe; not stored by SIPSTACK) | Stripe DPA + SCCs; PCI-DSS. |
| 5 | Bandwidth | United States | Voice/SMS carrier, DID provisioning, E911 | Phone numbers, in-transit call/message content, routing metadata | Carrier interconnection (telco-necessary); DPA + SCCs. |
| 6 | HyperDX | United States | Application logging and observability | Application and server access logs, error diagnostics, request/response metadata, IP addresses (incidental PI in log payloads) | TLS; encryption at rest. Draft PIA under review (s. 17); recipient entity, storage region and vendor DPA pending confirmation. |
| 7 | Cloudflare (CDN/DNS) | Global (transit) | CDN, DDoS protection, DNS, bot protection | Web traffic, IP addresses (transit only; no payload retention) | DPA + SCCs. |
Optional Text-to-Speech sub-processors (AWS Polly, Google Cloud TTS, United States) receive only text strings for synthesis, and only where the Customer enables those optional features. Mobile build/distribution (Expo / EAS, United States) receives build artifacts and app metadata, not Customer end-user data.
Schedule 2 — Technical and Organizational Measures
- Encryption in transit: TLS 1.2+ for all API, portal, and SIP traffic.
- Encryption at rest: Databases, object storage, and backups are encrypted at rest by the systems that hold them. The off-site database archive relies on the storage provider's server-side encryption; SIPSTACK does not hold a client-side encryption key for it.
- Access controls: Role-based access control, MFA for administrative accounts, least-privilege, and access logging.
- Segregation / residency: Regional Wasabi buckets keep Canadian-entity user-generated media in Canada; only the operational flows in Schedule 1 cross the border.
- Security monitoring: Continuous monitoring and alerting, anomaly detection, and documented incident-response procedures.
- Breach notification: Notification to affected individuals and authorities as required by applicable law (promptly for PIPEDA / Law 25; 72 hours for GDPR where applicable).
- Retention and deletion: Tier-based auto-purge for recordings/voicemail; documented retention schedule; self-serve export and deletion tooling.
This is a DRAFT Data Processing Addendum published for transparency. It is not binding and is subject to legal counsel review. For an executable addendum, contact [email protected].