Data Processing

GCS Data Processing Addendum

Last updated July 27, 2026 · Version 2026-07-27-ca-1
Issued by Grizzly Asset Holdings Inc., doing business as Grizzly Client Services.

Parties and roles

This Data Processing Addendum ('DPA') applies between Grizzly Asset Holdings Inc., doing business as Grizzly Client Services ('GCS'), and the Client wherever GCS processes Customer Data on the Client's behalf. The Client is the organization responsible for its Customer Data: it decides why that data is collected and what it is used for. GCS acts in a service-provider (processor-style) role, processing Customer Data on the Client's documented instructions to deliver the services.

Covered data

Covered data is the Customer Data handled inside the Client's workspace: customer and prospect names, contact details, service requests, quotes, follow-up history, call records where voice features are configured, and message metadata. Client account data (the Client's own business and billing information) is handled by GCS as described in the Privacy Policy.

Processing instructions

GCS processes Customer Data to provide, secure, and support the services, following the Client's instructions given through account configuration, approvals, and support requests. GCS may refuse instructions that appear unlawful, insecure, or outside the service scope, and will say so rather than silently complying.

Confidentiality

Access to Customer Data is limited to personnel and providers who need it to operate, secure, support, or bill the services, and who are bound by confidentiality duties appropriate to their role.

Subprocessors and providers

GCS uses these categories of subprocessors and providers: payment processing (Stripe), email delivery (Postmark), voice and telephony (Vapi, Telnyx) where configured, local business data (Foursquare) for lead research, and hosting, database, and security infrastructure. The Provider Integration Addendum lists the integrations. GCS gives notice of material subprocessor changes through the workspace or by email and requires comparable data-protection commitments from providers that touch Customer Data.

Safeguards

GCS applies the safeguards in the Security Policy: account scoping, role-based access, password hashing, two-step verification, session and CSRF protections, audit logging, encrypted transport, and privacy-safe hashing of network identifiers on acceptance records.

Breach notice

If GCS confirms a breach of security safeguards affecting the Client's Customer Data, GCS notifies the Client without undue delay with what is known: the nature of the breach, the data and individuals involved, the containment steps taken, and what GCS recommends. GCS assists the Client with the Client's own notification duties (including under PIPEDA's real-risk-of-significant-harm standard, Alberta PIPA, or Québec Law 25 where they apply) and meets GCS's own reporting duties.

Assistance with individual requests

If an individual asks GCS for access to or correction of Customer Data controlled by the Client, GCS refers the request to the Client and provides reasonable assistance — locating records, exporting data, correcting entries — so the Client can answer within its legal timelines.

Retention, return, and deletion

During the subscription, the Client manages its Customer Data in the workspace. On termination or archive, GCS blocks workspace access, returns or exports Customer Data on request made before closure, and then retains or deletes data under the Account Lifecycle, Archive, and Data Retention Policy — keeping billing, legal acceptance, audit, security, and call records where law or legitimate business-record needs require, and letting backups cycle out on schedule.

Cross-border processing

Subprocessors may process Customer Data outside Canada, including in the United States, where it is subject to local law and lawful access. GCS uses contractual safeguards requiring comparable protection and discloses this in the Privacy Policy so clients can meet their own transparency duties.

Audit and security information

GCS answers reasonable security questionnaires, provides summaries of its safeguards and this DPA's implementation, and shares relevant incident information. Direct system, code, or infrastructure access is not granted, because it would expose other clients and platform controls.

Québec service-provider terms

For Clients subject to Québec's private-sector privacy law, this DPA constitutes the written service contract required for entrusting personal information to a service provider: GCS processes only for the purposes above, keeps the information confidential, applies the safeguards described, notifies the Client of confirmed breaches involving their data, and does not keep Customer Data after the retention limits in the lifecycle policy.

Order of precedence

If this DPA conflicts with the Terms of Service on the subject of Customer Data processing, this DPA governs for that subject.

Support / Contact

Questions about this data processing record may be sent to [email protected].