For institutions
Data Processing Addendum
Effective [EFFECTIVE DATE] · Last updated June 2026
Draft for review — not legal advice. This document is a working draft prepared from regulatory and industry guidance. It must be reviewed by qualified legal counsel before it is published or relied upon.
When an institution licenses or white-labels our products, the institution is the controller of its users' data and we act as its processor under this Data Processing Addendum (DPA). This page summarizes the key terms; the full text is available to download and is what the parties sign.
Key terms at a glance
| Topic | Summary |
|---|---|
| Roles | You are the controller; we are the processor, acting only on your documented instructions. |
| Security | Technical & organizational measures (Annex 2): encryption in transit, least-privilege access, monitoring, vendor review. |
| Sub-processors | General authorization with ≥ [30] days' notice of changes and a right to object. Current list at /subprocessors. |
| Breach notice | Notice without undue delay, within [72] hours, plus cooperation on your PIPA/PIPEDA “real risk of significant harm” assessment. |
| Transfers | EU/UK Standard Contractual Clauses; Canadian data-residency options where elected. |
| Return / deletion | Deletion or return of data within [60] days of termination, subject to legal retention. |
| Governing law | Alberta, Canada. |
Requesting the DPA
Download the full DPA above, or request a countersigned copy and our security documentation via the compliance page or by emailing privacy@ngnsimulation.com. White-label partners should also review the White-Label / Reseller Agreement.
