Data Processing Addendum
How Getme Online processes personal information on your behalf as your processor, including security measures, sub-processors, international transfers, and your rights as the controller.
Last updated:
1. Background and Roles
This Data Processing Addendum ("DPA") forms part of, and is incorporated by reference into, the Getme Online Terms of Service and any order form or service agreement between you ("you", the "Customer") and Getme Technologies Inc. ("we", "us", "Getme"). It applies whenever we process Personal Information on your behalf in the course of providing the Services.
For the purposes of this DPA, you act as the controller (or, where you are yourself processing on behalf of another organization, as a processor), and Getme acts as your processor (or sub-processor). You determine the purposes and means of processing the Personal Information you load into or collect through the Platform; we process it only to provide the Services and on your instructions.
Where this DPA conflicts with the Terms of Service or the Privacy Policy on a matter of data processing, this DPA controls. In all other respects the Terms of Service remain in full force.
2. Definitions
"Applicable Data Protection Law" means all privacy and data protection laws that apply to the processing of Personal Information under this DPA, including, as applicable, Canada’s Personal Information Protection and Electronic Documents Act ("PIPEDA"), British Columbia’s Personal Information Protection Act ("BC PIPA"), Alberta’s Personal Information Protection Act, and Quebec’s Law 25, together with other substantially similar provincial laws; the EU General Data Protection Regulation (Regulation (EU) 2016/679) ("GDPR"); the UK GDPR and Data Protection Act 2018; and applicable U.S. state privacy laws including the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA").
"Personal Information" (also "personal data") means any information relating to an identified or identifiable individual that we process on your behalf through the Services, such as customer name, email address and phone number, shipping and billing addresses, order and booking details, customer and CRM records, and related payment and shipping metadata.
"Data Subject" (also "End User") means the individual to whom Personal Information relates — typically your customer or contact. "Sub-processor" means any third party engaged by Getme to process Personal Information on your behalf. The terms "controller", "processor", "processing", "service provider", "sale", and "share" have the meanings given to them in Applicable Data Protection Law.
3. Scope and Processing Instructions
We will process Personal Information only on your documented instructions, including with regard to international transfers, unless a law to which we are subject requires otherwise — in which case we will inform you of that legal requirement before processing, unless that law prohibits such notice on important grounds of public interest.
Your instructions are set out in this DPA, the Terms of Service, the configuration choices and integrations you enable in the Platform, and any written instructions you give us through the Services. We will not sell or share Personal Information. We may process Personal Information only to provide, secure, support, and operate the Services, to comply with law, and as otherwise permitted by this DPA and Applicable Data Protection Law. We may use aggregated, de-identified, or non-customer-identifying information to improve the Services, and we will not use Personal Information for advertising or for unrelated product or AI-model training unless permitted by law and agreed with you in writing.
If we believe an instruction infringes Applicable Data Protection Law, we will inform you without undue delay. You are responsible for ensuring that your instructions, and your collection and use of Personal Information, comply with Applicable Data Protection Law and that you have a valid legal basis for the processing.
4. Details of the Processing (Annex A)
Subject matter and duration: processing of Personal Information for the duration of your use of the Services and until deletion or return in accordance with Section 14.
Nature and purpose: hosting, storing, organizing, retrieving, transmitting, and otherwise processing Personal Information to operate the Platform, manage customer and CRM records, process orders and bookings, calculate shipping rates and support tax-related settings, calculations, or records where enabled in the Services, send transactional communications, generate invoices and reports, and provide support and security.
Types of Personal Information: identifiers and contact details (name, email, phone); shipping and billing addresses; order, booking, and transaction details; customer, contact, and CRM records; and payment and shipping metadata (we do not store full card numbers or CVV codes — these are handled by PCI-compliant payment processors). The Services are not designed for regulated medical records, diagnosis records, insurance claim files, government identification numbers, biometric data, children’s data requiring special legal consent or regulated child-specific processing, payment card numbers, CVV codes, or other sensitive or special-category personal information, and you must not upload such data unless the relevant feature expressly supports that data type and Getme has agreed in writing. In particular, the Services are not intended to store clinical records, diagnosis or treatment notes, insurance claim files, or other regulated health information; Customers in wellness or health-adjacent industries (for example kinesiology, massage, beauty, or clinic services) must avoid entering such information into CRM records, booking notes, or other free-text fields unless Getme has expressly agreed in writing to support that use case.
Categories of Data Subjects: your customers, prospective customers, contacts, booking parties, and other End Users whose Personal Information you collect or load through the Services.
| Area | Getme-specific content |
|---|---|
| Website / storefront | Business website data, page forms, customer enquiries |
| Checkout / orders | Cart, order, shipping, billing, discount, and tax settings |
| Bookings | Appointment times, customer contact details, booking notes |
| CRM | Customer records, preferences, visit history, internal notes |
| Invoices / payments | Invoice records, payment metadata, payment-processor metadata |
| Support | Merchant support tickets, onboarding calls, troubleshooting data |
| AI tools | Prompts, merchant inputs, and generated business content, where enabled |
5. Confidentiality
We ensure that persons authorized to process the Personal Information are bound by an appropriate duty of confidentiality (whether contractual or statutory) and are made aware of the confidential nature of the information.
We limit access to Personal Information to those personnel and Sub-processors who need it to provide, support, or maintain the Services.
6. Security Measures (Annex B)
Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risk to individuals, we implement appropriate technical and organizational measures to protect Personal Information against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access.
Our security measures include, where applicable to the Services: encryption of Personal Information in transit; role-based access controls and least-privilege permissions; authentication and password controls; regular backups; logging and security monitoring; and use of reputable cloud infrastructure providers operating secured data centers.
We may update our security measures over time, provided the updates do not materially reduce the overall level of protection. You are responsible for the security of the credentials, configurations, and integrations within your control.
| Measure | What it covers |
|---|---|
| Encryption in transit | Personal Information is encrypted as it moves between browsers, the Platform, and integrations |
| Access controls | Role-based access and least-privilege permissions limit who can reach Personal Information |
| Authentication | Password and authentication controls protect access to Platform accounts |
| Backups | Personal Information is backed up regularly to support recovery |
| Monitoring & logging | Security logging and monitoring of Platform activity |
| Infrastructure | Reputable cloud infrastructure providers operating secured data centres |
7. Sub-processors (Annex C)
You provide general authorization for Getme to engage Sub-processors to process Personal Information in connection with the Services. Where we engage a Sub-processor, we impose data protection obligations on it that are substantially the same as those in this DPA through a written contract, and we remain responsible for the Sub-processor’s performance.
A current list of our Sub-processors — with each provider’s purpose, the categories of Personal Information processed, processing location, and a link to its privacy or data-processing terms — is maintained on our Subprocessors page at /legal/subprocessors. Categories include payment processing, shipping and logistics infrastructure, cloud hosting and backup, email and communications, video conferencing for onboarding and support, and accounting, invoicing, and CRM-related tools.
We will give you reasonable advance notice (for example, by updating the Privacy Policy or by notice through the Platform) before adding or replacing a Sub-processor that processes Personal Information, so that you have an opportunity to object on reasonable data-protection grounds. If you object and we cannot reasonably accommodate the objection, you may terminate the affected Services as your sole remedy.
| Sub-processor category | Purpose |
|---|---|
| Payment processing | Processing payments and related transaction metadata |
| Shipping & logistics | Calculating shipping rates and fulfilling shipments |
| Cloud hosting & backup | Hosting and backing up Platform data |
| Email & communications | Sending transactional and support communications |
| Video conferencing | Onboarding and support calls |
| Accounting, invoicing & CRM | Accounting, invoicing, and CRM-related tooling |
8. Assisting You with Data Subject Requests
Taking into account the nature of the processing, we will assist you by appropriate technical and organizational measures, insofar as this is possible, to respond to requests from Data Subjects to exercise their rights under Applicable Data Protection Law (such as access, correction, deletion, portability, restriction, or objection).
If we receive a request directly from a Data Subject in respect of Personal Information we process on your behalf, we will not respond to it ourselves (except to confirm that it should be directed to you) and, where legally permitted, will forward it to you without undue delay.
9. Assistance with Security, Impact Assessments, and Consultation
Taking into account the nature of processing and the information available to us, we will provide reasonable assistance to help you comply with your obligations regarding the security of processing, personal data breach notification, data protection impact assessments, and prior consultation with supervisory authorities, where applicable.
10. Personal Data Breach Notification
We will notify you without undue delay, and where feasible within 72 hours, after becoming aware of a personal data breach affecting Personal Information processed on your behalf. The notification will describe, to the extent known and reasonably available to us, the nature of the breach, the likely consequences, and the measures taken or proposed to address it.
We will reasonably cooperate with you and take reasonable steps to mitigate the effects of the breach. We will maintain records of breaches of security safeguards as required by Applicable Data Protection Law and provide the information reasonably needed for you to assess your notification obligations, including under PIPEDA’s real risk of significant harm threshold. Our notification is not an acknowledgement of fault or liability. You remain responsible for any notifications you are required to make to authorities or affected individuals.
11. International Data Transfers
We and our Sub-processors may process Personal Information in locations outside your province or country, including in Canada, the United States, or other jurisdictions, where different privacy laws may apply.
Where Applicable Data Protection Law requires a transfer mechanism for Personal Information transferred from the EEA, the UK, or Switzerland, the parties will enter into the applicable European Commission Standard Contractual Clauses, including the correct modules and any required annexes, transfer details, and processing details, together with the UK International Data Transfer Addendum where applicable. For transfers from Canada, we use contractual and other means to provide a comparable level of protection, consistent with PIPEDA.
12. California and U.S. Service Provider Terms
Where the CCPA/CPRA or a substantially similar U.S. state law applies, we act as your "service provider" (or "contractor"). We will process Personal Information solely to perform the Services under the Terms of Service and this DPA, and for no other purpose.
We will not: sell or share Personal Information; retain, use, or disclose it for any purpose other than the business purposes specified in the Terms of Service and this DPA, including outside the direct business relationship between you and us; or combine it with personal information from other sources, except as permitted by Applicable Data Protection Law. We certify that we understand and will comply with these restrictions.
13. PIPEDA Comparable Protection (Canada)
Where PIPEDA or a substantially similar provincial law applies, you remain accountable for the Personal Information you transfer to us for processing. We use contractual and other means, including this DPA and our security measures, to provide a comparable level of protection while the Personal Information is being processed by us or our Sub-processors.
14. Return and Deletion of Personal Information
On termination or expiry of the Services, or earlier on your written request, we will, at your choice, delete or return the Personal Information we process on your behalf, and delete existing copies, unless retention is required by applicable law.
We may retain Personal Information to the extent and for the period required by applicable law (for example, accounting, tax, or fraud-prevention records), and in routine backups for a limited period until those backups are overwritten or expire in the ordinary course, during which it remains protected under this DPA.
15. Audits and Demonstrating Compliance
We will make available to you, on reasonable written request, information reasonably necessary to demonstrate compliance with this DPA.
We may satisfy audit requests by providing security documentation, written responses to a reasonable security questionnaire, or third-party reports or certifications where available. On-site or inspection-based audits are available only where legally required by a supervisory authority, following a personal data breach affecting your Personal Information, or as agreed in a separate enterprise agreement, and will be conducted on reasonable prior notice, no more than once in any twelve-month period, during business hours, and in a manner that does not unreasonably disrupt our operations.
16. Liability, Term, and Order of Precedence
This DPA takes effect when you accept the Terms of Service or first use the Services and remains in force for as long as we process Personal Information on your behalf. Each party’s liability under this DPA is subject to the limitations and exclusions of liability in the Terms of Service.
In the event of any conflict between this DPA and any Standard Contractual Clauses entered into under Section 11, the Standard Contractual Clauses prevail with respect to transfers they govern. Otherwise, this DPA prevails over the Terms of Service and the Privacy Policy on matters of data processing.
17. AI Features
Where AI features are enabled, Customer Content or Personal Information may be processed to generate, summarize, classify, or otherwise assist with business content inside the Services.
We do not use Customer Personal Information to train, fine-tune, or improve first-party or third-party AI models unless expressly agreed in writing.
AI-related Sub-processors, if any, will be listed on our Subprocessors page at /legal/subprocessors.
18. Electronic Messaging and Marketing Consent (CASL)
You are responsible for ensuring that any marketing, promotional, or commercial electronic messages sent through the Services comply with applicable anti-spam and marketing laws, including Canada’s Anti-Spam Legislation ("CASL") where applicable, which generally requires consent, sender identification, and a functioning unsubscribe mechanism for commercial electronic messages.
We act as your processor (or service provider) in transmitting the communications you enable — such as transactional emails, booking reminders, invoices, and order updates, together with any marketing follow-ups you configure. We may provide tools to help manage consent, preferences, and unsubscribe settings, but you remain responsible for your message content and for ensuring you have the necessary recipient permissions.
19. Governing Law
Except where Applicable Data Protection Law or an incorporated transfer mechanism requires otherwise, this DPA is governed by the laws of the Province of British Columbia and the federal laws of Canada applicable therein, consistent with the Terms of Service.
20. Contact
For any questions about this DPA, or to make a request or give an instruction under it, please contact our Privacy Officer at [email protected] or through the contact form on our website.