Data Processing Addendum
How Celeris processes personal data on your behalf, including international transfer terms under GDPR, UK GDPR and CCPA.
This Data Processing Addendum ("DPA") forms part of the Terms of Service between Celeris Realtime Systems Inc. ("Celeris") and the Customer. It applies whenever Celeris processes Customer Personal Data on the Customer's behalf in providing the Service. By accepting the Terms, the Customer enters into this DPA. If you need a countersigned copy, email privacy@useceleris.com.
1. Definitions
- Data Protection Laws means all laws that apply to the processing of Customer Personal Data under this DPA. These include:
- Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and substantially similar provincial laws;
- the EU General Data Protection Regulation (GDPR);
- the UK GDPR and the UK Data Protection Act 2018;
- the Swiss Federal Act on Data Protection (FADP); and
- US state privacy laws, including the California Consumer Privacy Act (CCPA).
- Customer Personal Data means personal data that Celeris processes on the Customer's behalf. It includes personal data in Customer Content and personal data relating to End Users.
- Security Incident means a breach of security leading to the accidental or unlawful destruction, loss, alteration or unauthorized disclosure of, or access to, Customer Personal Data.
- SCCs means the standard contractual clauses approved by European Commission Implementing Decision (EU) 2021/914.
- UK Addendum means the International Data Transfer Addendum to the SCCs issued by the UK Information Commissioner.
- Subprocessor means any third party that Celeris engages to process Customer Personal Data.
The terms "controller", "processor", "data subject", "personal data", "processing" and "supervisory authority" have the meanings given in the GDPR. The terms "business", "service provider", "sell" and "share" have the meanings given in the CCPA. Other capitalized terms have the meanings given in the Terms.
2. Roles and scope
The Customer is the controller of Customer Personal Data, or a processor acting on behalf of its own controllers. Celeris is a processor, or a subprocessor where the Customer is itself a processor. Annex I describes the processing.
This DPA does not cover the personal data Celeris processes as a controller, such as account and billing information. Our Privacy Policy covers that data.
3. Instructions
Celeris processes Customer Personal Data only on the Customer's documented instructions, unless the law requires otherwise. In that case, Celeris will inform the Customer first unless the law prohibits it. The Customer's instructions are made up of:
- the Terms;
- this DPA; and
- the Customer's configuration and use of the Service.
Celeris will tell the Customer if it believes an instruction infringes Data Protection Laws.
The Customer is responsible for the lawfulness of the Customer Personal Data it sends through the Service. This includes providing any required notices and obtaining any required consents.
4. Confidentiality
Celeris ensures that everyone authorized to process Customer Personal Data is bound by an appropriate obligation of confidentiality.
5. Security
Celeris implements the technical and organizational measures described in Annex II. Celeris may update those measures, provided the overall level of security is not reduced.
6. Subprocessors
General authorization. The Customer gives Celeris general authorization to engage Subprocessors. The current list is on our Subprocessors page.
New Subprocessors. Celeris will update that page at least 30 days before a new Subprocessor begins processing Customer Personal Data. It will also email customers who have asked to be notified through privacy@useceleris.com.
Objections. The Customer may object to a new Subprocessor on reasonable data protection grounds within that 30-day period. The parties will then discuss the concern in good faith. If they cannot resolve it, the Customer may terminate the affected Service and receive a refund of the prepaid fees for the unused part of its billing interval.
Subprocessor obligations. Celeris imposes data protection obligations on each Subprocessor that are no less protective than this DPA. Celeris remains responsible for its Subprocessors' performance.
7. Data subject requests
If Celeris receives a request from a data subject about Customer Personal Data, it will pass the request to the Customer and will not respond itself, except to redirect the data subject. Celeris will give the Customer reasonable help in responding to such requests, taking into account the nature of the processing. Because the Service does not store message payloads durably, there is often no Customer Personal Data left to act on.
8. Security Incidents
Celeris will notify the Customer without undue delay, and in any event within 72 hours, after becoming aware of a Security Incident. The notice will include the information the Customer reasonably needs to meet its own obligations. Celeris will take reasonable steps to contain and mitigate the incident. Notifying the Customer of a Security Incident is not an admission of fault.
9. Assistance
Taking into account the information available to it, Celeris will give the Customer reasonable help with data protection impact assessments and with prior consultations with supervisory authorities.
10. Deletion
Customer Personal Data is deleted in the normal course of operation:
- message payloads within 15 minutes; and
- presence data within 10 minutes of the last activity.
When the Terms end, Celeris will delete any remaining Customer Personal Data within 30 days, unless the law requires Celeris to keep it. Residual copies in backups and logs expire within 90 days.
Because the Service does not store Customer Content durably, there is generally no Customer Personal Data to return.
11. Audits
Celeris will make available the information reasonably needed to demonstrate compliance with this DPA. This includes answering one reasonable security questionnaire per year.
An on-site audit may take place only if a supervisory authority requires it, or if that information is insufficient to demonstrate compliance. In that case, the Customer may conduct an audit:
- no more than once every 12 months;
- on at least 30 days' notice;
- during business hours;
- at the Customer's own cost; and
- subject to appropriate confidentiality obligations.
12. International transfers
Celeris is established in Canada. The European Commission has recognized Canada as providing adequate protection for commercial organizations subject to PIPEDA. Customer Personal Data may be processed in the United States and Germany, as described in Annex I and on our Subprocessors page.
To the extent Customer Personal Data is transferred from the EEA to a country without an adequacy decision, the parties agree to the SCCs, which are incorporated by reference. They apply as follows:
- Module Two applies where the Customer is a controller, and Module Three where the Customer is a processor.
- Clause 7 (the docking clause) applies.
- Under Clause 9, Option 2 (general authorization) applies, with the notice period set out in section 6 of this DPA.
- The optional language in Clause 11 does not apply.
- Under Clause 13, the competent supervisory authority is the one determined by the Customer's establishment or representative in the EEA.
- The SCCs are governed by Irish law (Clause 17), and disputes go to the courts of Ireland (Clause 18).
- Annexes I and II of this DPA complete Annexes I and II of the SCCs. Our Subprocessors page completes Annex III.
UK transfers. For transfers from the United Kingdom, the UK Addendum is incorporated. Its Tables 1 to 3 are completed with the information in this DPA, and either party may end it as described in Table 4.
Swiss transfers. For transfers from Switzerland, the SCCs apply with two adjustments: the Swiss Federal Data Protection and Information Commissioner is the competent supervisory authority, and references to Member States include Switzerland.
13. CCPA service provider terms
Where the CCPA applies, Celeris acts as the Customer's service provider. Celeris will not:
- sell or share Customer Personal Data;
- retain, use or disclose it for any purpose other than providing the Service, or as the CCPA otherwise permits;
- retain, use or disclose it outside the direct business relationship with the Customer; or
- combine it with other personal data, except as the CCPA permits.
Celeris will provide the level of privacy protection the CCPA requires. It will notify the Customer if it can no longer meet its obligations, and the Customer may then take reasonable steps to stop and remediate unauthorized use.
14. Liability and precedence
Each party's liability under this DPA is subject to the limitations in the Terms. If this DPA conflicts with the Terms on the processing of Customer Personal Data, this DPA prevails. If the SCCs conflict with this DPA, the SCCs prevail.
Annex I: Details of processing
Data exporter: the Customer, using the contact details on its Account. It acts as a controller, or as a processor on behalf of its own controllers.
Data importer: Celeris Realtime Systems Inc., 2920 Highway 7, Unit 3605, Vaughan, Ontario L4K 0P4, Canada. Contact: privacy@useceleris.com. It acts as a processor.
| Item | Details |
|---|---|
| Categories of data subjects | The Customer's End Users; the Customer's personnel who use the Service; any other individual whose personal data the Customer includes in Customer Content |
| Categories of personal data | Determined by the Customer. May include identifiers and other content in message payloads, presence labels, connection identifiers, IP addresses and connection metadata |
| Sensitive data | None intended. The Customer should not send special categories of personal data |
| Frequency of transfer | Continuous, for as long as the Customer uses the Service |
| Nature of processing | Receiving, routing, briefly buffering and delivering messages; tracking presence; metering usage |
| Purpose | Providing the Service under the Terms |
| Retention | Message payloads up to 15 minutes; presence data up to 10 minutes after the last activity; logs containing IP addresses up to 90 days |
| Subprocessors | As listed on our Subprocessors page, for the same nature, purpose and duration |
Annex II: Technical and organizational measures
- Encryption in transit. All public endpoints use TLS, including the API, the dashboard and WebSocket connections. Internal streaming traffic uses TLS with SCRAM authentication. Database connections require SSL.
- Encryption at rest. Databases, caches, storage volumes and application secrets are encrypted at rest.
- Credentials. Account passwords and API client secrets are hashed with Argon2. Application signing secrets are stored encrypted.
- Access control. Only authorized personnel can access production. Access uses least-privilege roles and requires multi-factor authentication for administrative access. Infrastructure changes go through reviewed and approved deployment pipelines.
- Network security. Data stores sit in private subnets and are not publicly accessible. Our edge network has managed DDoS protection.
- Availability and resilience.
- Databases and caches are replicated across multiple availability zones.
- Automated database backups are kept for 14 days, and cache snapshots for 7 days.
- Monitoring. Metrics, logs and alerting are centralized to detect and respond to incidents.
- Data minimization. Message payloads are not stored durably, and usage metrics never include message contents.
- Incident response. A defined process covers containing, investigating and notifying Security Incidents.
Annex III: Subprocessors
See our Subprocessors page.