Data Processing Addendum
Last updated: July 1, 2026
Draft for review
This document is provided for transparency and is under review by legal counsel. It is not legal advice. For questions, contact our Privacy Officer at privacy@embaylms.com.
Our Data Processing Addendum (DPA) sets out how Embay Consulting Inc. processes personal information on behalf of its customers when they use EmbayLMS. This page is a faithful summary of its key commitments — it is not the full executed contract. The DPA is incorporated into our Master Services Agreement (MSA) and is available to customers on request from legal@embaylms.com.
Roles
The customer is the controller of the personal information in its workspace, and Embay acts as its processor (service provider). Embay processes personal information only to provide the service and only on the customer’s documented instructions.
Scope and purpose limitation
Processing is limited to what is necessary to deliver the service and to follow the customer’s instructions. Embay does not use customer personal information for its own unrelated purposes.
Confidentiality
Personnel authorized to process personal information are bound by confidentiality obligations and receive appropriate training.
Security measures (Annex)
- TLS 1.2+ encryption in transit;
- AWS KMS encryption at rest;
- bcrypt password hashing;
- role-based access control (RBAC);
- multi-factor authentication (MFA);
- append-only audit logging;
- schema isolation between tenants.
Sub-processors
Embay may engage sub-processors to support the service. We impose data-protection obligations that flow down our commitments, notify customers of additions or replacements per the DPA, and publish the current list on our Sub-processors page.
International transfers
Where personal information is transferred outside Canada or, for GDPR data, outside the EEA/UK, the DPA relies on appropriate safeguards such as Standard Contractual Clauses or an adequacy determination where applicable, consistent with our Law 25 section 17 assessment.
Assistance with data subject requests
Embay assists the customer in responding to requests from individuals to exercise their rights (access, rectification, deletion, portability, and others), including through self-serve and administrative tooling.
Breach notification
Embay notifies the customer of a confidentiality incident affecting its data without undue delay, targeting notification within 72 hours of detection, with information to help the customer meet its own obligations.
Audit and reporting
Embay makes available information to demonstrate compliance. A SOC 2 report is available on request under NDA. Our SOC 2 controls operate from day one; a SOC 2 Type II report is targeted as our audit history matures.
Return and deletion of data
On termination, Embay offers an export of customer data first; tenant data becomes read-only 30 days after termination and is purged 90 days after termination.
How to obtain the DPA
To receive the full DPA or to have it countersigned, contact legal@embaylms.com.
Privacy Officer
Mathieu Brillon, acting Privacy Officer, Embay Consulting Inc. — privacy@embaylms.com