This Canada Data Protection Agreement ("Canada DPA") is incorporated into the Terms of Use or any other agreement ("Agreement") between you ("Customer") and FortaTech Security, LLC d/b/a Bastion Intelligence ("FortaTech Security," "we," "us," or "our") when you use our services and provide personal information subject to Canadian privacy laws. It sets out the terms under which FortaTech Security processes personal information subject to the federal Personal Information Protection and Electronic Documents Act ("PIPEDA") and applicable provincial and territorial privacy legislation, including Ontario's Personal Health Information Protection Act, 2004 ("PHIPA"). If there is any conflict between a provision of this Canada DPA and a provision of the Agreement, this Canada DPA controls with respect to the processing of Canadian Personal Information.
This Canada DPA applies on every plan. It becomes effective when the Customer accepts the Agreement, and no separate signature, attestation, or in-product designation is required for it to take effect. A countersigned copy is available on request, as described in Section 9.4.
SECTION 01Scope of the Canada DPA
1.1 Applicability
This Canada DPA applies to the collection, use, and disclosure of personal information from individuals in Canada ("Canadian Personal Information") provided by the Customer in connection with their use of FortaTech Security's services (the "Services").
1.2 Relationship of the Parties
For the purposes of this Canada DPA, the Customer is the organization accountable for Canadian Personal Information, and FortaTech Security acts as a service provider processing that information solely on behalf of and under the direction of the Customer. Where the Customer is a health information custodian under PHIPA or an equivalent provincial statute, FortaTech Security acts as an agent or information manager of the Customer, as those terms are used in the applicable legislation.
SECTION 02Compliance with Canadian Privacy Legislation
This section describes how FortaTech Security applies the ten fair information principles in Schedule 1 to PIPEDA.
2.1 Accountability
We take responsibility for the management and protection of personal information under our control. A designated Privacy Officer oversees compliance with PIPEDA, PHIPA, and other applicable Canadian legislation, and can be reached at legal@bastionintelligence.com.
2.2 Identifying Purposes
We identify the purposes for which personal information is collected at or before the time of collection. Categories collected include:
- Contact details, such as name, email address, and phone number.
- Organization information, such as company and title.
- Payment information.
- Data generated through use of the Services.
- Any other information the Customer provides directly to us.
2.3 Consent
We obtain informed consent for the collection, use, or disclosure of personal information. Consent may be express or implied depending on the context and the sensitivity of the information. Where personal health information is involved, the Customer is responsible for obtaining and documenting patient consent, and for determining the lawful authority on which it relies, before using the Services to process that information. FortaTech Security publishes consent form templates that Customers may adapt to assist in meeting these requirements.
2.4 Limiting Collection
We collect only the personal information necessary to provide the Services, and collect it by fair and lawful means. Examples include the information required to create accounts, process payments, and deliver AI-generated documentation or analyses.
2.5 Limiting Use, Disclosure, and Retention
Personal information is used or disclosed only for the purposes for which it was collected, unless the Customer consents or a use or disclosure is required by law. Customer Content is not sold, and is not used to develop, train, fine-tune, or evaluate models, including the models of any third-party provider. Where personal health information is involved, we apply the retention and secure disposal practices described in Section 5.
2.6 Accuracy
We make reasonable efforts to keep personal information accurate, complete, and current for the purposes for which it is used. Customers can update account information directly within the platform or by contacting us.
2.7 Safeguards
We protect personal information with security safeguards appropriate to its sensitivity, including encryption in transit and at rest, access controls based on least privilege, tenant segregation, audit logging, and monitoring. Safeguards are described in Section 3.3 and in our Technical and Organizational Security Measures.
2.8 Openness
Our privacy practices are published and readily available. Our Privacy Policy describes how we collect, use, and protect information, and our sub-processor list identifies every provider we engage and whether it may process Customer Content.
2.9 Individual Access
Individuals may request access to their personal information. On request we will confirm the existence, use, and disclosure of that information and provide access to it within a reasonable time. Where access is refused, we will give reasons and inform the individual of their recourse.
2.10 Challenging Compliance
Individuals and Customers may challenge our compliance with these principles by contacting our Privacy Officer using the details in Section 9.4. We investigate all complaints, and where a complaint is justified we take appropriate corrective measures. Schedule A lists the oversight bodies to which a complaint may be escalated.
SECTION 03Obligations of FortaTech Security
3.1 Compliance with Applicable Laws
We will comply with PIPEDA and applicable provincial and territorial privacy legislation when processing Canadian Personal Information on behalf of the Customer.
3.2 Processing Purposes
We will process Canadian Personal Information only for the purposes of providing the Services in accordance with the Agreement and this Canada DPA, and only on the Customer's documented instructions.
3.3 Security Measures
We will implement appropriate technical, organizational, and administrative measures to protect Canadian Personal Information from unauthorized access, use, disclosure, alteration, or destruction. These measures include, but are not limited to:
- Encryption of data in transit (TLS 1.2 or higher) and at rest (AES-256).
- Access controls based on the principle of least privilege, granted on a need-to-know basis and limited to operational purposes such as security monitoring, abuse monitoring, and technical troubleshooting.
- Segregation of Customer data by tenant.
- Audit logging of access and actions, monitoring, and regular security assessments.
3.4 Sub-processors
We engage sub-processors to assist in providing the Services. Each sub-processor is bound by contractual obligations providing a comparable level of protection to that required under this Canada DPA, and FortaTech Security remains responsible for their performance. We publish the current list of sub-processors, including the purpose for which each is engaged, the categories of data involved, and whether that provider may process Customer Content.
3.5 Data Residency and Cross-Border Transfers
Canadian Personal Information belonging to Customers registered with a Canadian billing address is stored and processed in Canada during normal operation of the Services.
A limited set of operations may involve access to, or transfer of, Canadian Personal Information outside Canada, including to the United States. These are exceptions rather than routine processing, and they arise from specific circumstances rather than ordinary use of the Services. They include certain support requests where diagnosing or resolving an issue requires personnel or a sub-processor located outside Canada to access the relevant data, and optional sessions that the Customer initiates or agrees to, such as a screen share with our prompt engineering team.
Where such an operation is necessary, FortaTech Security conducts it in accordance with PIPEDA and applicable provincial legislation, applies the contractual and security protections described in this Canada DPA, and limits the transfer to the minimum information required for the purpose.
3.6 Breach Notification
In the event of a breach of security safeguards involving Canadian Personal Information, FortaTech Security will notify the Customer without unreasonable delay after discovery, and will provide sufficient information for the Customer to meet its obligations under PIPEDA and the Breach of Security Safeguards Regulations, including any obligation to report to the Office of the Privacy Commissioner of Canada, to notify affected individuals, and to maintain breach records. Where a breach involves personal health information, we will also support the Customer's notification and reporting obligations under the applicable provincial health privacy statute, including notification to the relevant Commissioner where required.
SECTION 04Individual Rights
4.1 Assistance with Requests
If FortaTech Security receives a request from an individual to exercise a right under PIPEDA or applicable provincial legislation, such as access, correction, or deletion, we will promptly notify the Customer and will not respond directly except to confirm receipt and to direct the individual to the Customer. We will assist the Customer in responding to the request to the extent required by law and the Agreement.
4.2 Customer Responsibility
The Customer is responsible for responding to individuals exercising their rights under PIPEDA or other applicable Canadian privacy legislation, and for determining what information must be provided.
SECTION 05Data Retention and Deletion
5.1 Retention Periods
FortaTech Security retains Canadian Personal Information only for as long as necessary to fulfil the purposes set out in the Agreement and this Canada DPA, or for such longer period as is required by law. Retention periods vary by feature. The current default retention period for each feature, and the range within which a configurable period may be set, are published in our help centre.
5.2 Customer Control Over Retention
The Customer controls the retention of its content. The Customer may:
- delete specific items, or all of its content, at any time from within the Services;
- set the retention period for transcription anywhere within the published range; and
- request deletion at any time by contacting us at legal@bastionintelligence.com.
Where a retention period is not configurable within the Services, the applicable default is published and the Customer may still request deletion at any time. Following deletion, a copy may persist for a short published period in a secure audit vault, which exists to support security monitoring, abuse monitoring, and required auditing, and is then removed.
5.3 Deletion or Return of Data
On termination of the Agreement, or on the Customer's request, FortaTech Security will delete or return Canadian Personal Information unless retention is required by applicable law. Personal health information is deleted using industry-standard secure deletion methods in accordance with applicable retention and destruction requirements.
SECTION 06Audits and Certifications
FortaTech Security maintains records of its data protection practices and will provide the Customer with reasonable documentation or certifications to demonstrate compliance with this Canada DPA. The Customer may request additional information or audits in accordance with the Agreement.
SECTION 07Applicable Laws and Jurisdictions
This Canada DPA is designed to support compliance with the federal, provincial, and territorial legislation governing the collection, use, and protection of personal information and personal health information across Canada. FortaTech Security's practices are designed with reference to the following legislation.
Federal
- Personal Information Protection and Electronic Documents Act, S.C. 2000, c. 5
- Breach of Security Safeguards Regulations, SOR/2018-64
- Privacy Act, R.S.C. 1985, c. P-21
Alberta
- Protection of Privacy Act (POPA)
- Access to Information Act (ATIA)
- Personal Information Protection Act (PIPA)
- Health Information Act (HIA)
British Columbia
- Personal Information Protection Act (PIPA)
- Freedom of Information and Protection of Privacy Act (FOIPPA)
- E-Health (Personal Health Information Access and Protection of Privacy) Act and E-Health Regulation
Manitoba
- The Freedom of Information and Protection of Privacy Act (FIPPA)
- The Personal Health Information Act (PHIA)
New Brunswick
- Right to Information and Protection of Privacy Act (RTIPPA)
- Personal Health Information Privacy and Access Act (PHIPAA)
Newfoundland and Labrador
- Access to Information and Protection of Privacy Act, 2015 (ATIPPA)
- Personal Health Information Act (PHIA)
Northwest Territories
- Access to Information and Protection of Privacy Act (ATIPP)
- Health Information Act (HIA)
Nova Scotia
- Freedom of Information and Protection of Privacy Act (FOIPOP)
- Personal Health Information Act (PHIA)
- Personal Information International Disclosure Protection Act (PIIDPA)
Nunavut
- Access to Information and Protection of Privacy Act (ATIPP)
Ontario
- Personal Health Information Protection Act, 2004 (PHIPA) and O. Reg. 329/04
- Freedom of Information and Protection of Privacy Act (FIPPA)
- Municipal Freedom of Information and Protection of Privacy Act (MFIPPA)
- Child, Youth and Family Services Act, 2017 (CYFSA), Part X
Prince Edward Island
- Health Information Act (HIA)
- Freedom of Information and Protection of Privacy Act (FOIPP Act)
Quebec
- Act respecting the protection of personal information in the private sector (P-39.1), as amended by Law 25
- Act respecting access to documents held by public bodies and the protection of personal information (A-2.1), as amended by Law 25
- Act respecting health and social services information (R-22.1)
Saskatchewan
- The Freedom of Information and Protection of Privacy Act (FOIP)
- The Local Authority Freedom of Information and Protection of Privacy Act (LA FOIP)
- The Health Information Protection Act (HIPA)
Yukon
- Access to Information and Protection of Privacy Act (ATIPP)
- Health Information Privacy and Management Act (HIPMA)
Nothing in this section is a representation that the Services are suitable for every regulated use in every jurisdiction. Customers remain responsible for determining whether their intended use of the Services complies with the legislation and professional obligations that apply to them.
SECTION 08Liability and Indemnification
FortaTech Security's liability arising from or related to this Canada DPA is subject to the limitations and exclusions of liability set out in the Agreement.
SECTION 09General Provisions
9.1 Governing Law
This Canada DPA is governed by the laws of the State of Texas, United States, being the jurisdiction of FortaTech Security's principal place of business. Nothing in this clause limits any right or remedy an individual or a Customer has under PIPEDA or applicable provincial legislation, or the jurisdiction of a Canadian privacy regulator.
9.2 Conflicts
In the event of any conflict between this Canada DPA and the Agreement, the terms of this Canada DPA prevail with respect to the processing of Canadian Personal Information.
9.3 Amendments
This Canada DPA may be amended from time to time to reflect changes in applicable law or in the Services. The effective date and version of the current text are shown at the top of this page.
9.4 Contact
For questions about this Canada DPA, to request a countersigned copy, or to make a request regarding personal information, contact our Privacy Officer:
FortaTech Security Legal11816 Inwood Rd # 3181
Dallas, TX 75244
United States
Email: legal@bastionintelligence.com
Website: https://bastionintelligence.com
9.5 Acknowledgment
By using the Services and providing Canadian Personal Information, the Customer acknowledges that it has read, understood, and agrees to the terms of this Canada DPA.
SCHEDULE ARegulatory Authorities
We are committed to resolving complaints promptly. If you believe our response to a privacy concern is inadequate, you may escalate it to the oversight body for your jurisdiction. Each office publishes its own current mailing address, telephone number, and complaint process on the site linked below.
| Jurisdiction | Oversight body | Website |
|---|---|---|
| Federal | Office of the Privacy Commissioner of Canada | priv.gc.ca |
| Alberta | Office of the Information and Privacy Commissioner of Alberta | oipc.ab.ca |
| British Columbia | Office of the Information and Privacy Commissioner for British Columbia | oipc.bc.ca |
| Manitoba | Manitoba Ombudsman | ombudsman.mb.ca |
| New Brunswick | Ombud NB | ombudnb.ca |
| Newfoundland and Labrador | Office of the Information and Privacy Commissioner | oipc.nl.ca |
| Northwest Territories | Office of the Information and Privacy Commissioner of the Northwest Territories | oipc-nt.ca |
| Nova Scotia | Office of the Information and Privacy Commissioner for Nova Scotia | oipc.novascotia.ca |
| Nunavut | Office of the Information and Privacy Commissioner of Nunavut | atipp-nu.ca |
| Ontario | Information and Privacy Commissioner of Ontario | ipc.on.ca |
| Prince Edward Island | Office of the Information and Privacy Commissioner | assembly.pe.ca |
| Quebec | Commission d'accès à l'information du Québec | cai.gouv.qc.ca |
| Saskatchewan | Office of the Saskatchewan Information and Privacy Commissioner | oipc.sk.ca |
| Yukon | Yukon Ombudsman and Information and Privacy Commissioner | yukonaccountability.ca |
Most concerns can be resolved directly. Contact our Privacy Officer at legal@bastionintelligence.com and we will investigate and respond in writing.
FOR REVIEWERSDocumentation for Your Privacy Assessment
The agreement ends at Section 9. What follows is a reading guide for privacy reviewers. Each document linked below governs its own subject matter.
| Document | What it covers | Where |
|---|---|---|
| Sub-processor list | Every provider we engage, the purpose, the data categories involved, and whether that provider may process Customer Content | Terms, section 3.4 |
| Technical and Organizational Security Measures | Encryption, access control, tenant segregation, logging, monitoring, and incident response | Terms, section 15 |
| Privacy Policy | What we collect, how it is used and disclosed, storage locations by region, and retention | bastionintelligence.com/privacy |
| Data retention and deletion | Default retention period for each feature, what is configurable, and how to delete content | support.bastiongpt.com |
| Security overview | Architecture, data handling, and answers to the questions that recur in security reviews | bastiongpt.com/security |
| Clinical validation | Accuracy methodology and published results | bastiongpt.com/clinical-validation |
| AI principles | How models are selected, evaluated, and governed | bastiongpt.com/company/ai-principles |
| HIPAA Business Associate Agreement | Relevant where a Canadian organization also handles information subject to United States requirements | bastionintelligence.com/baa |
Available on request
- A countersigned copy of this Canada DPA, as described in Section 9.4.
- Documentation or certifications evidencing our data protection practices, as described in Section 6.
If your assessment asks a question these documents do not answer, write to legal@bastionintelligence.com and tell us which framework you are working through. It helps to know whether you are completing an Alberta PIA, a Quebec section 17 assessment, or the Ontario IPC checklist, because the three ask for different things.