Updated: June 17, 2026
This Data Processing Addendum (“Addendum”), having as an effective date the same Effective Date given in the Master Agreement (defined below) is entered into by and between Wealth Write-Up Inc., a Canadian corporation with offices located at 600-1981 McGill College, Montréal, Québec, H3A 2Y1, Canada (“Provider”), and Customer (Provider and Customer may each be referred to as a "Party", or collectively, the "Parties").
WHEREAS, the Customer and the Provider have entered into that certain Agreement (the "Master Agreement"), the form of which is available at https://wealthwriteup.com/wwu-saas-agreement/ that may require the Provider to process personal information provided by or collected on behalf of the Customer; and
WHEREAS, this Addendum sets out additional terms, requirements and conditions for collecting, using, processing, disclosing, transferring or storing Personal Information when the Provider provides services under the Master Agreement;
NOW, THEREFORE, in consideration of the mutual covenants and agreements contained in this Addendum and for other good and valuable consideration, the receipt and sufficiency of which are hereby acknowledged, the Parties agree as follows:
The following definitions and rules of interpretation apply in this Addendum. Terms capitalized but not defined herein have the same meaning as given to them in the Master Agreement.
"Business Purpose" means the services described in the Master Agreement.
"Individual" means an individual who is the subject of Personal Information.
"Personal Information" means any information the Provider collects, uses, processes or maintains for the Customer that is about or relates to an identifiable individual or identifies or can be used to identify that individual, directly or indirectly, either alone or in combination with other information, and includes as applicable any “personal information”, “personally identifiable information” or “personal data” as defined under Privacy and Data Protection Laws. Personal information does not include anonymized information.
"Processing, processes, or process" means any activity that involves the use of Personal Information or that the relevant Privacy and Data Protection Laws may otherwise include in the definition of processing, processes, or process. It includes collecting, using, disclosing, or carrying out any operation or set of operations on the Personal Information.
"Privacy and Data Protection Laws" means all applicable federal, provincial, and foreign laws and regulations relating to the processing, protection, or privacy of the Personal Information, as each may be amended or replaced from time to time.
"Security Breach" means any act or omission that materially compromises the security, confidentiality, or integrity of Personal Information or the physical, technical, administrative, or organizational safeguards put in place to protect it.
This Addendum forms part of and is incorporated into the Master Agreement. In the case of conflict or ambiguity between any of the provisions of this Addendum and the provisions of the Master Agreement, the provisions of this Addendum will prevail.
The Customer remains at all times accountable for and in control of the Personal Information, and responsible for its compliance obligations under the applicable Privacy and Data Protection Laws, providing any required notices and obtaining any required consents, and for the processing instructions it gives to the Provider.
The Customer represents and warrants that the Provider's expected use of the Personal Information for the Business Purpose and as specifically instructed by the Customer under this Addendum will comply with all Privacy and Data Protection Laws.
The Provider will only process the Personal Information to the extent, and in such a manner, as is necessary for the Business Purpose. The Provider will not process the Personal Information in a way that does not comply with this Addendum, Customer’s instructions, or the Privacy and Data Protection Laws.
The Provider will promptly comply with any Customer request or instruction requiring the Provider to amend, transfer, or delete the Personal Information, or to stop, mitigate or remedy any unauthorized processing.
The Provider will maintain the confidentiality of all Personal Information and will not disclose Personal Information to third parties unless the Customer or this Addendum specifically authorizes the disclosure in compliance with Privacy and Data Protection Laws, or as otherwise required by law. If a law requires the Provider to process or disclose Personal Information, the Provider will first notify the Customer of the legal requirement and give the Customer an opportunity to object or challenge the requirement at the Customer’s sole cost and expense, unless the law prohibits such notice.
The Provider will reasonably assist the Customer with meeting the Customer's compliance obligations under the Privacy and Data Protection Laws, considering the nature of the Provider's processing and the information available to the Provider. The Customer acknowledges that the Provider is under no duty to investigate the completeness, accuracy, or sufficiency of any specific Customer instructions or the Personal Information other than as required under the Privacy and Data Protection Laws.
The Provider will limit Personal Information access to those employees who require it to meet the Provider's obligations under this Addendum and the Master Agreement.
The Provider will implement and maintain appropriate technical and organizational measures designed to safeguard Personal Information against unauthorized or unlawful processing, access, copying, modification, storage, reproduction, display, or distribution, and against accidental loss, destruction or damage.
Provider maintains appropriate technical and organizational measures to safeguard Customer Data, including the use of rolling backups with defined retention periods as set out in the Data Return and Destruction section below.
The Provider will promptly notify the Customer if it becomes aware of any Security Breach and will take steps to contain and mitigate the Security Breach. The Provider will reasonably co-operate with the Customer in the Customer's handling of the matter, including making available all relevant information to the extent required to comply with all Privacy and Data Protection Laws. The Provider will not inform any third party of any Security Breach without first obtaining the Customer's prior written consent, except when Privacy and Data Protection Laws, or other laws or regulations, require it. The Provider agrees that the Customer has the sole right, to the extent permitted by applicable laws, to determine whether to provide notice of the Security Breach to any Individuals, regulators, law enforcement agencies or others, as required by Privacy and Data Protection Laws.
Customer acknowledges and agrees that Provider may process the Personal Information on a global basis as necessary for the Business Purpose, and in particular that Personal Information may be transferred to and processed by Provider in Canada, the United States and other jurisdictions where Provider affiliates and subprocessors have operations. Wherever the Personal Information is transferred outside its country of origin, each party will ensure such transfers are made in compliance with the requirements of applicable Privacy and Data Protection Laws.
Customer agrees that Provider may engage subprocessors to process the Personal Information on Customer's behalf, provided the Provider enters into a written contract with the subprocessor that imposes data protection terms that require the subprocessor to protect the Personal Information to the standard required by applicable Privacy and Data Protection Laws. Customer acknowledges that, to the extent a subprocessor is a provider of AI Services, any Personal Information processed by such subprocessor may be subject to automated abuse monitoring by such subprocessor and, if flagged, may be reviewed by authorized subprocessor personnel. Upon written request, Provider will use commercially reasonable efforts to minimize such monitoring exposure, subject to such subprocessor’s then-current policies and approval processes. A list of current subprocessors is available at https://wealthwriteup.com/sub-processors.
The Provider will promptly notify the Customer if it receives any complaint, notice, or communication that directly or indirectly relates to the Personal Information processing or to either Party's compliance with the Privacy and Data Protection Laws.
The Provider will promptly notify the Customer if it receives a request from an Individual for access to their Personal Information or a request to correct, delete, or withdraw its consent from any use by Customer or Provider of same.
The Provider will cooperate with the Customer in responding to any complaint, notice, communication, or Individual request.
The Provider will not directly disclose the Personal Information to any Individual or to a third party unless the disclosure is required by law.
This Addendum will remain in full force and effect until the expiry or termination of the Master Agreement (the “Term”).
If a change in any Privacy and Data Protection Law prevents either Party from fulfilling all or part of its Master Agreement obligations, the Parties will suspend the processing of Personal Information until that processing complies with the new requirements. If the Parties are unable to bring the Personal Information processing into compliance with the applicable Privacy and Data Protection Law by making commercially reasonable efforts, either Party may terminate the Master Agreement upon written notice to the other Party, without prejudice to any fees incurred by Customer prior to suspension or termination.
On termination of the Master Agreement for any reason or expiration of its term, the Provider will securely destroy or, if directed in writing by the Customer, return and not retain, all or any Personal Information related to this Addendum in its possession or control, unless applicable law permits or requires retention by Provider.
If any law, regulation, or government or regulatory body requires the Provider to retain any documents or materials that the Provider would otherwise be required to return or destroy, to the extent permitted by law the Provider will notify the Customer in writing of that retention requirement and, to the extent determinable, when the retention requirement ends.
The Provider will certify in writing that it has destroyed the Personal Information upon Customer’s request.
Provider’s backup and storage policy is as follows: (i) daily backups are retained for thirty (30) days; (ii) monthly long-term retention (“LTR”) backups are retained for seven (7) years; and (iii) yearly LTR backups (week one) are retained for ten (10) years. Upon termination or expiry of the Master Agreement, Customer Data will be deleted from active systems and scheduled for deletion from backup systems in accordance with this retention policy, unless otherwise required by law. Provider will certify destruction upon Customer’s written request.
The Provider will permit the Customer and its third-party representatives to audit the Provider's compliance with its Addendum obligations, upon reasonable prior notice. The Provider will give the Customer and its third-party representatives access to such information as needed to conduct such audits in compliance with Privacy and Data Protection Laws. To the extent physical access to Provider’s records or premises is required to conduct such audits in compliance with Privacy and Data Protection Laws, (i) such access will only be provided during regular business hours and will be limited strictly to such records or premises as required to comply with Privacy and Data Protection Laws; and (ii) Customer and its third-party representatives agree to be accompanied by Provider’s representatives at all times and each shall execute confidentiality agreements as required by Provider. Under no circumstances will Customer be provided with access to information concerning, or the records or data of, other customers of Provider.
The limitations of liability set forth in the Master Agreement will apply to this Addendum.
Whether you’re managing books for a family office, an accounting firm, or a holding company, we’ll tailor the demo to what matters most to your practice.