MafcoBook™ Request your workspace

Legal

Data Processing Agreement

Effective July 30, 2026 · How we process personal information on your behalf.

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Mafco Technology Ltd. ("MafcoBook", "we", "us", the Processor) and the business that uses the Service ("Customer", "you", the Controller). It governs our processing of Personal Information you provide or make available through the Service (your Client Data) and applies to the extent Canadian privacy laws apply to that processing.

Roles. You determine the purposes and means of processing your Client Data and are the Controller (and, where you handle personal health information in Ontario, a health information custodian under PHIPA). We process that data only on your behalf and on your instructions as your Processor (and, under PHIPA, your agent). You are responsible for the accuracy of your instructions and for having the authority and consents to provide the Client Data to us.

Contents

  1. Definitions
  2. Scope & roles
  3. Our processing obligations
  4. Confidentiality
  5. Security
  6. Sub-processors
  7. Assisting you
  8. Breach notification
  9. Data location & transfers
  10. Return & deletion
  11. Audits
  12. PHIPA agent terms
  13. Liability & term

Appendices: A — Processing details · B — Security measures · C — Sub-processors

1. Definitions

  • Personal Information — information about an identifiable individual, as defined by PIPEDA and applicable provincial law; includes Personal Health Information ("PHI") as defined by PHIPA and equivalent provincial health-privacy laws.
  • Applicable Privacy Law — PIPEDA and any provincial privacy or health-privacy laws applicable to the processing (including Ontario's PHIPA).
  • Client Data — Personal Information within the data a Customer submits to or generates in the Service about its End Clients.
  • Processing — any operation performed on Personal Information (collection, use, storage, disclosure, retention, deletion).
  • Sub-processor — a third party we engage to process Client Data on our behalf.

2. Scope & roles

We will process Client Data only as a Processor acting on the Customer's behalf, for the purpose of providing and supporting the Service and as otherwise set out in Appendix A. The Customer is and remains responsible, as Controller, for the lawfulness of the Client Data and of its instructions, and for providing any notices and obtaining any consents required for us to process the Client Data. The Terms of Service, this DPA, and the in-product configuration you choose constitute your documented instructions to us.

3. Our processing obligations

We will:

  • process Client Data only on your documented instructions, including as configured through the Service, unless required by law (in which case we will inform you where legally permitted);
  • not sell Client Data and not use it for our own purposes, including advertising or profiling;
  • ensure personnel authorized to process Client Data are bound by confidentiality and are trained appropriately;
  • implement and maintain the security measures described in Appendix B;
  • engage Sub-processors only as permitted by Section 6; and
  • assist you as described in Sections 7 and 8.

4. Confidentiality

We will treat Client Data as confidential and will not disclose it except to our personnel and Sub-processors who need it to provide the Service and are under confidentiality obligations, or as required by law.

5. Security

We will implement appropriate technical and organizational measures to protect Client Data against unauthorized or unlawful processing and accidental loss, destruction, or damage, taking into account the state of the art, the costs of implementation, and the nature, scope, and sensitivity of the data (including any PHI). A summary of current measures is in Appendix B. We may update our measures provided the level of protection is not materially reduced.

6. Sub-processors

You grant general authorization for us to engage the Sub-processors listed in Appendix C to process Client Data. We will impose data-protection and security obligations on each Sub-processor that are no less protective than those in this DPA, and we remain responsible for their performance. We will give reasonable notice of any intended addition or replacement of a Sub-processor (for example, by updating Appendix C and/or by email); if you have a reasonable, data-protection-based objection, you may raise it and, if we cannot address it, you may terminate the affected part of the Service.

7. Assisting you with individuals' requests

Taking into account the nature of the processing, we will provide reasonable assistance (including through functionality in the Service) to help you respond to requests from individuals to access, correct, or delete their Personal Information, and to meet your obligations under Applicable Privacy Law. If we receive such a request directly, we will refer the individual to you and will not respond on your behalf except on your instruction or as required by law.

8. Personal-data breach notification

We will notify you without undue delay after becoming aware of a breach of security safeguards affecting Client Data, and will provide information reasonably available to us to help you assess the breach and meet your obligations (including any reporting to the Office of the Privacy Commissioner, the Information and Privacy Commissioner of Ontario, or affected individuals). We will take reasonable steps to contain and remediate the incident. Our notification is not an acknowledgement of fault or liability.

9. Data location & cross-border processing

We host the primary database and files for the Service in Canada (Supabase ca-central-1). Certain Sub-processors may process limited Client Data (such as email metadata or global content delivery) outside Canada; where they do, we require appropriate contractual and security safeguards, and you acknowledge such data may be subject to the laws of those jurisdictions. [Confirm and disclose any routine processing outside Canada.]

10. Return & deletion of Client Data

You may export Client Data through the Service during your subscription. On termination, we will make Client Data available for export for a limited period (targeted at thirty (30) days), after which we will delete or de-identify it in the ordinary course, unless retention is required by law. Deletion from backups occurs on our regular backup-rotation cycle.

11. Audits & compliance information

On reasonable written request (no more than once per year unless required by a regulator or following a breach), we will make available information reasonably necessary to demonstrate our compliance with this DPA. Any audit will be conducted on reasonable notice, during business hours, subject to confidentiality, and in a manner that does not disrupt our operations or compromise other customers' data.

12. PHIPA agent terms (personal health information)

Where the Client Data includes PHI and the Customer is a health information custodian under Ontario's PHIPA (or an equivalent custodian/trustee under another province's health-privacy law), we act as the Customer's agent and information manager. In that capacity we will: (a) collect, use, disclose, retain, and dispose of PHI only as necessary to provide the Service and only as permitted by the Customer and PHIPA; (b) not use or disclose PHI except as the Customer may and as authorized; (c) maintain safeguards as described in Appendix B; (d) notify the Customer at the first reasonable opportunity of any unauthorized access, use, disclosure, loss, or theft of PHI; and (e) make records of our information practices available to the Customer as reasonably required for the Customer to meet its PHIPA obligations.

13. Liability, term & governing law

This DPA is subject to the limitations and exclusions of liability in the Terms of Service. It takes effect when you accept the Terms and continues while we process Client Data. This DPA is governed by the laws of the Province of Ontario and the federal laws of Canada applicable there. If there is a conflict between this DPA and the Terms regarding processing of Client Data, this DPA controls.

Appendix A — Details of processing

  • Subject matter: provision of the MafcoBook booking and client-management Service.
  • Duration: for the term of the Customer's subscription, plus the deletion window in Section 10.
  • Nature & purpose: hosting, storage, and processing of Client Data to enable booking, scheduling, client records, invoicing, communications, and reporting.
  • Categories of data subjects: the Customer's End Clients (e.g. patients, clients, customers) and the Customer's Authorized Users.
  • Categories of Personal Information: identity and contact details; appointment and scheduling data; billing and invoice data; notes entered by the Customer; and, where the Customer chooses to record it, health-related information (PHI).

Appendix B — Security measures

Confirm each item matches what is actually implemented.

  • Encryption: TLS/HTTPS for data in transit; encryption at rest at the database/storage layer.
  • Tenant isolation: per-tenant separation enforced by database row-level security so one Customer cannot access another's data.
  • Access control: least-privilege access for personnel; role-based access within the Service; multi-factor authentication required for administrative access.
  • Authentication: managed authentication with secure credential storage and session handling.
  • Application safeguards: server-side authorization on privileged actions, audit logging of administrative commands, upload validation, and bot protection on public forms.
  • Resilience: managed, backed-up infrastructure with monitoring.
  • Data residency: primary data stored in Canada (see Section 9).

Appendix C — Sub-processors

Sub-processorService providedProcessing location
SupabaseDatabase, authentication, file storageCanada (ca-central-1)
CloudflareWebsite hosting/CDN, bot protection (Turnstile)Global edge; content served from Canada
ResendTransactional email deliverySee provider [confirm]
[Payment processor]Subscription billingSee provider

Contact

Mafco Technology Ltd. — Privacy Officer
Ottawa, ON, Canada
Email: [email protected]
Phone: 613-299-9830

MafcoBook™ Online booking & CRM for personal service businesses.
Home Terms Privacy DPA Request a workspace

© 2026 Mafco Technology Ltd. All rights reserved.