Data Processing Agreement
Last Updated: August 11, 2026
This Data Processing Agreement ("DPA") forms part of the agreement between Vimsoft Inc. ("Processor", "Vimsoft", "we", "us") and the customer using Vimsoft products or services ("Controller", "Customer").
This DPA applies where Vimsoft processes Personal Data on behalf of Customer in connection with the provision of Vimsoft services, including VimBiz.
In the event of any conflict between this DPA and the applicable service agreement, Terms and Conditions, or subscription agreement, this DPA shall prevail solely with respect to the processing of Personal Data.
Definitions
For purposes of this DPA:
Personal Data means any information relating to an identified or identifiable natural person.
Controller means the entity that determines the purposes and means of processing Personal Data.
Processor means the entity that processes Personal Data on behalf of the Controller.
Data Subject means the individual to whom Personal Data relates.
Applicable Data Protection Laws means all applicable privacy and data protection laws, including, where applicable, the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the UK GDPR, and similar laws.
Subprocessor means a third party engaged by Vimsoft to process Personal Data on behalf of Customer.
Scope and Roles
Customer acts as the Controller with respect to Personal Data contained within Customer Data.
Vimsoft acts as the Processor and will process Personal Data only on documented instructions from Customer, except where otherwise required by applicable law.
Nothing in this DPA transfers ownership of Customer Data or Personal Data to Vimsoft.
Purpose of Processing
Vimsoft may process Personal Data solely to:
- Provide, operate, maintain, and support the Services;
- Authenticate users;
- Process customer requests;
- Maintain security and system integrity;
- Detect and prevent fraud, abuse, or unlawful activity;
- Comply with legal obligations;
- Perform other activities reasonably necessary to provide the Services.
- Names;
- Email addresses;
- Telephone numbers;
- Employee identifiers;
- User account information;
- Scheduling and workforce management information;
- Leave and attendance records;
- Job titles and organizational information;
- Communications and support requests;
- Any other Personal Data submitted by Customer through the Services.
- Customer employees;
- Contractors;
- Authorized users;
- Job applicants;
- Customers and business contacts;
- Other individuals whose information Customer chooses to process through the Services.
- Are subject to confidentiality obligations; or
- Are under an appropriate statutory duty of confidentiality.
- Encryption of data in transit;
- Access controls and authentication mechanisms;
- Role-based permissions;
- Logging and monitoring;
- Security patching and vulnerability management;
- Backup and recovery procedures;
- Employee security awareness training.
- Require Subprocessors to protect Personal Data through written agreements;
- Remain responsible for compliance with its obligations under this DPA;
- Make available information regarding current Subprocessors upon request or through a published Subprocessor list.
- Standard Contractual Clauses approved by applicable authorities;
- Adequacy decisions;
- Other lawful transfer mechanisms.
- Data Subject requests;
- Security obligations;
- Data protection impact assessments;
- Regulatory inquiries;
- Personal Data breach notifications.
- The nature of the breach;
- Categories of affected data;
- Known or likely consequences;
- Steps taken or proposed to address the breach.
- Notify Customer; and
- Not respond directly except as instructed by Customer or required by law.
Vimsoft shall not sell Customer Personal Data.
Categories of Data
Depending on Customer's use of the Services, Personal Data may include:
Categories of Data Subjects
Data Subjects may include:
Confidentiality
Vimsoft shall ensure that personnel authorized to process Personal Data:
Access to Personal Data shall be limited to personnel with a legitimate business need.
Security Measures
Vimsoft implements and maintains appropriate technical and organizational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access.
Such measures may include:
Vimsoft may update its security measures from time to time provided such changes do not materially reduce overall security.
Subprocessors
Customer authorizes Vimsoft to engage Subprocessors to support the delivery of the Services.
Vimsoft shall:
International Transfers
Where Personal Data is transferred outside the jurisdiction in which it was collected, Vimsoft shall implement appropriate safeguards as required under Applicable Data Protection Laws.
Where required, such safeguards may include:
Assistance to Customer
Taking into account the nature of processing and the information available to Vimsoft, Vimsoft shall provide reasonable assistance to Customer in fulfilling obligations relating to:
Vimsoft may charge reasonable fees for substantial assistance requests requiring significant effort.
Personal Data Breaches
Vimsoft shall notify Customer without undue delay after becoming aware of a confirmed Personal Data breach affecting Customer Personal Data.
Where reasonably available, such notification shall include:
Data Subject Requests
If Vimsoft receives a request directly from a Data Subject relating to Customer Personal Data, Vimsoft shall, unless prohibited by law:
Customer remains responsible for responding to Data Subject requests.
Audits and Information Requests
Upon reasonable written request, Vimsoft may provide information reasonably necessary to demonstrate compliance with this DPA, taking into account the nature of the Services, the sensitivity of Customer Data, and the confidentiality obligations owed to other customers. Vimsoft is not required to disclose confidential, proprietary, or security-sensitive information, including internal security documentation, vulnerability assessments, penetration testing results, or information that could compromise the security of the Services.
Return and Deletion of Data
Upon termination of the Services, Vimsoft shall handle Customer Data in accordance with the applicable service agreement or Terms and Conditions.
Unless otherwise required by law, Customer Data shall be deleted or anonymized following the applicable retention period.
Backup copies may remain for a limited period in secure backup systems and shall be deleted in accordance with Vimsoft's backup retention practices.
Liability
The liability of each party arising under this DPA shall be subject to the limitations of liability set out in the applicable Terms and Conditions or negotiated contract terms governing the Services, unless otherwise required by applicable law.
Order of precedence
Enterprise agreements or negotiated customer agreements may supplement or replace portions of this DPA where expressly agreed in writing. In the event of a conflict, the negotiated agreement shall prevail.
Governing Law
This DPA shall be governed by and interpreted in accordance with the governing law provisions contained in the agreement governing the Services between the parties.
Contact Information
Vimsoft Inc.
50 Rue du Marché
Dieppe, New Brunswick E1A 0K8
Canada
support@vimbiz.com

