The short version
- Your data stays yours. CCS processes personal information inside your application only on your instructions, to run the service.
- We protect it with real safeguards — per-customer data isolation, encryption in transit, access controls — listed in Annex A.
- We use vetted service providers (published list) and stay responsible for them.
- If there's a confirmed or reasonably suspected breach affecting your people's personal information, we tell you within 72 hours of becoming aware and help you respond.
- Canadian clients: your data is processed in the United States — Part B explains what that means and how we support your PIPEDA obligations.
The short version is a summary only — the sections below are the agreement.
Part A — Data processing terms
1. Scope and roles
1.1. This Addendum is part of the Master Services Agreement ("MSA"); capitalized terms not defined here have the meanings in the MSA. It applies whenever CCS processes personal information contained in Client Data on the Client's behalf in the course of providing the Services. If this Addendum and the MSA conflict regarding the processing of personal information, this Addendum controls (MSA Section 3.2).
1.2. As between the parties, the Client controls the personal information in its Application (it decides what is collected and why), and CCS processes it as the Client's service provider. In privacy-law terms: the Client is the controller (or an organization with custody under Canadian law), and CCS is the processor/service provider acting on instructions.
1.3. "Personal information" means information about an identifiable individual contained in Client Data — for example names, contact details, account records, location data, photos, or communications belonging to the Client's customers, employees, or end users.
2. What CCS processes, and why
2.1. Purpose. CCS processes personal information only to provide, support, secure, and improve the Services for the Client, and as otherwise documented in the SOW or instructed in writing by the Client.
2.2. Categories; description of processing. Depending on the Application: contact and account details of the Client's staff and customers; operational records the Client's business generates; and usage and log data generated by the Application itself. The SOW may include a Description of Processing (categories of data and individuals, and the sensitivity tier) — where the Client's business involves sensitive personal information (for example, financial-distress, debt-enforcement, or health-related records), the parties will record that in the SOW, and Annex A's high-sensitivity measures apply.
2.3. Duration. For the subscription term, plus the export-and-deletion window in MSA Section 13.
2.4. No selling; no advertising. CCS does not sell personal information and does not use it for advertising.
2.5. AI features. The SOW identifies the Application's AI-assisted features. Personal information is sent to CCS's AI Sub-processors only as needed to provide those features, under agreements that prohibit the providers from using it to train their models, and using zero- or limited-retention configurations where the provider offers them. The Client may direct CCS in writing to disable an AI feature for its Application; for Applications whose SOW records a high-sensitivity tier, AI features that send personal information to AI Sub-processors are enabled only if the SOW says so.
3. CCS's obligations
3.1. Instructions only. CCS processes personal information only on the Client's documented instructions (this Addendum, the MSA, and the SOW are standing instructions), unless the law requires otherwise — in which case CCS will tell the Client before processing, where legally allowed. The Client is responsible for the lawfulness of its instructions; CCS may decline an instruction it reasonably believes violates the law, will tell the Client why, and declining such an instruction is not a breach.
3.2. Confidentiality. Everyone CCS authorizes to process personal information (its principals and any contractors) is bound by confidentiality obligations.
3.3. Security. CCS maintains the administrative, technical, and physical safeguards described in Annex A, reviewed as the Services evolve, applied at the tier matching the sensitivity recorded in the SOW.
3.4. Individuals' requests. If an individual contacts CCS directly to access, correct, or delete their personal information in a Client Application, CCS will forward the request to the Client promptly and will not respond on the Client's behalf except at the Client's direction. Where the Application's own tools cannot fulfill a request, CCS will provide the assistance the Client needs — including an export of the individual's personal information in a readable format — within 10 business days of the Client's written request.
3.5. Breach notice. CCS will notify the Client without undue delay, and in any event within 72 hours of becoming aware of a confirmed — or reasonably suspected and likely to require Client action — breach of security safeguards affecting personal information in the Client's Application. Initial notice may be preliminary and will be supplemented as facts develop, describing: the nature of the incident, the data and individuals likely affected, steps taken, and a contact point. CCS will cooperate with the Client's own notification and mitigation obligations, will keep records of such incidents for at least 24 months, and will not notify individuals or regulators about the incident on the Client's behalf without the Client's direction, unless the law requires. Notice of an incident is not an admission of fault.
3.6. Return, deletion, and legal holds. At the end of the engagement, MSA Section 13 applies: export at any time, a 30-day post-termination export window, deletion from active systems, and backup copies retained no longer than 35 days. If the Client notifies CCS in writing of a legal or regulatory hold identifying specific data, CCS will suspend deletion of that data until the Client lifts the hold.
3.7. Records and audits. Once per year on reasonable notice, CCS will answer the Client's reasonable written security questionnaire and provide a summary of its security measures and material incidents. In addition, where a regulator with jurisdiction over the Client requires it in writing, or within 12 months after a confirmed breach affecting the Client's personal information, the Client may conduct — directly or through an independent auditor under confidentiality obligations — an audit of CCS's controls relevant to the Client's personal information, at most once in any 12-month period, during business hours, on at least 15 business days' notice; each party bears its own costs. CCS will provide copies of third-party security attestations or penetration-test summaries if and when it holds them.
3.8. Government and third-party demands. If CCS receives a subpoena, warrant, court order, or other legal demand for Client Data, CCS will: (a) promptly notify the Client before disclosing, unless legally prohibited; (b) redirect the requester to the Client where possible; (c) challenge or seek to narrow a demand that appears overbroad or unlawful; (d) disclose only the minimum legally required; and (e) keep a log of such demands and, on the Client's request, report them (including a report that there were none).
4. Sub-processors
4.1. The Client generally authorizes CCS to use Sub-processors to provide the Services. The current list — who they are, what they do, and where they process — is published at creamcity-solutions.com/legal/subprocessors. Services the Client connects under its own accounts are Client-Connected Services (MSA Section 6.3), not Sub-processors.
4.2. CCS binds each Sub-processor that processes personal information to protections materially consistent with this Addendum, and remains responsible for their performance.
4.3. Before a new Sub-processor processes the Client's personal information, CCS will update the published list and notify the Client by email to the Client's notice address. The Client may object on reasonable data-protection grounds within 30 days of the notice. If the parties cannot resolve the objection, CCS will first use commercially reasonable efforts to provide the Client's Services without the new Sub-processor; if that is not practicable, the Client may terminate the affected SOW(s) on written notice without the MSA's 30-day notice period, with a pro-rata refund of prepaid fees and the export and transition rights in MSA Section 13. A change in a listed Sub-processor's name or controlling entity is notified the same way as an addition.
5. Changes to this Addendum
CCS may update this published Addendum as MSA Section 1.3 provides (30 days' notice for material changes; objection preserves the prior version for active SOWs), except that no update will materially decrease the protections in Annex A during a subscription.
Part B — Canadian addendum
This Part B applies to Clients subject to Canadian privacy law, including the federal Personal Information Protection and Electronic Documents Act (PIPEDA) and any substantially similar provincial law. For those Clients, Part B supplements Part A and controls over it where they differ.
6. Cross-border processing — plain disclosure
6.1. CCS is a United States company. Personal information in the Client's Application is stored and processed in the United States by CCS and the Sub-processors on the published list. While in the United States, it is subject to U.S. law, and may be accessible to U.S. courts, law enforcement, and national-security authorities under U.S. legal process. Section 3.8 (notice, redirection, narrowing, minimum disclosure, and logging of legal demands) applies to any such demand.
6.2. The Client is responsible for the transparency PIPEDA requires toward its own customers and employees — telling them, in its privacy notices, that their information may be stored and processed in the United States by a service provider. CCS will provide reasonable help with the wording, and the Client may reference CCS's published Sub-processor list.
6.3. Where a Client operates in a sector or province with data-residency requirements, Canadian data residency may be elected in an SOW as a custom hosting arrangement (subject to feasibility and pricing recorded in the SOW); otherwise U.S. processing is the standard service.
7. Comparable protection
7.1. As PIPEDA's accountability principle requires, this Addendum is the contractual means by which personal information transferred to CCS receives a comparable level of protection to what the Client must provide: purpose limitation (Section 2), safeguards (Section 3.3 and Annex A), confidentiality (Section 3.2), breach notice (Section 3.5), legal-demand protections (Section 3.8), audit rights (Section 3.7), and limits on onward transfer (Section 4).
7.2. CCS will use personal information only for the purposes in Section 2 and will not use or disclose it for CCS's own purposes, except to create de-identified, aggregated data as MSA Section 5.6 describes — de-identified so that there is no reasonable basis to re-identify an individual or the Client, with re-identification contractually prohibited.
8. Breach reporting support (real risk of significant harm)
Canadian law requires the Client to report breaches that create a "real risk of significant harm" to the Privacy Commissioner and affected individuals as soon as feasible, and to keep records of all breaches. CCS's notice under Section 3.5 (within 72 hours of awareness) is designed so the Client can meet that clock, will include the facts CCS knows that the Client needs for its risk assessment, and CCS will keep its own record of security incidents affecting the Client's personal information for at least 24 months and share it on request.
9. Regulatory access and continuity
9.1. The Client's regulators may require it to produce records on short timelines. In addition to the Client's self-serve export tools, CCS will provide an export of identified Client Data within 5 business days of a written request tied to a regulator demand, and no suspension under MSA Section 4.5 ever blocks the Client's read-only and export access to its Client Data.
9.2. If the Office of the Privacy Commissioner of Canada, a provincial commissioner or ombudsman, or another regulator with jurisdiction asks the Client about its service providers, CCS will promptly provide the Client with accurate information about CCS's role, safeguards, Sub-processors, and processing locations, will provide records relevant to the Client's data on a lawful demand, and will reasonably cooperate with any resulting inquiry.
Annex A — Security measures
CCS maintains safeguards including the following, as applicable to the Application's architecture and hosting model (MSA Section 6) — for client-hosted Applications they apply only to systems CCS controls. Specific implementations evolve; protections will not materially decrease during a subscription.
- Tenant isolation. Per-customer data isolation appropriate to the Application's architecture — database row-level security for shared deployments, or dedicated single-tenant databases — so one customer's users cannot read another customer's records.
- Encryption. Data encrypted in transit (TLS); data at rest encrypted by CCS's infrastructure providers.
- Access control. Role-based access in each Application; administrative access limited to CCS's principals and any engaged contractors, each under confidentiality obligations, on a least-privilege basis.
- Authentication. Strong authentication (single sign-on where supported) for CCS's own access to production systems; customer accounts provisioned by invitation, with open self-sign-up disabled unless the Application is designed for it.
- Secrets management. Credentials and API keys stored in managed environment configuration, not in code; rotated when exposure is suspected.
- Backups. Automated backups of production databases through CCS's infrastructure providers, with point-in-time recovery where available; backup retention bounded per MSA Section 13.2.
- Logging and monitoring. Application and infrastructure logs for security-relevant events, retained at least 12 months where the platform supports it; error monitoring in production.
- Updates. Dependencies and platforms patched on an ongoing basis, prioritized by severity.
- Incident response. Confirmed or suspected incidents are triaged, contained, assessed against the notice duties in Section 3.5, and documented.
- Vendor selection. Sub-processors chosen from established providers with published security programs; see the Sub-processor list.
- High-sensitivity tier. Where the SOW records a high-sensitivity Description of Processing (for example, debt-enforcement or financial-distress records): multi-factor authentication required for all administrative access, verified encryption at rest, documented access reviews at least annually, and a vulnerability review at least annually.