# Data Processing Addendum

> Review how Twirling Umbrellas processes and protects client personal information under its Data Processing Addendum.

Last updated: July 3, 2026

This Data Processing Addendum (“DPA”) forms part of Twirling Umbrellas Ltd.’s Master Services Agreement (“MSA”) and applies where Twirling Umbrellas processes Client Personal Information on behalf of Client in connection with Services provided under an applicable Order.

This DPA does not apply to personal information that Twirling Umbrellas collects, uses, or discloses for its own business purposes, such as business development, account administration, billing, CRM records, communications, security, analytics, internal operations, or legal compliance. That information is governed by Twirling Umbrellas’ Privacy Policy.

In this DPA, “Twirling Umbrellas,” “Agency,” “we,” “us,” and “our” mean Twirling Umbrellas Ltd. “Client,” “you,” and “your” mean the person or organization that accepts Services subject to the MSA.

1. Relationship to the MSA

Incorporation. This DPA applies only where it is incorporated into an Order, where the MSA states that it applies to the relevant processing, or where Twirling Umbrellas processes Client Personal Information on behalf of Client in connection with Services subject to the MSA.

Conflict. If there is a conflict between this DPA and the MSA, this DPA will govern only with respect to the processing of Client Personal Information on Client’s behalf. The MSA will govern all other matters.

Online Updates. We may update this DPA from time to time by posting an updated version on our website and updating the “Last updated” date. Updates apply in accordance with the “Changes to this MSA” section of the MSA, unless an applicable Order states otherwise.

No Separate Signature Required. This DPA does not need to be signed as a standalone document. It applies when incorporated into or made applicable to Services under the MSA.

2. Definitions

Applicable Privacy Laws means privacy, data protection, and data security laws that apply to the processing of Client Personal Information under the applicable Order.

Client Personal Information means Personal Information that is provided by or on behalf of Client, or collected, stored, hosted, accessed, transmitted, migrated, configured, supported, or otherwise processed by Twirling Umbrellas on Client’s behalf in connection with the Services.

Controller, Processor, Business, Service Provider, Contractor, Data Subject, Consumer, and similar terms have the meanings given to them under Applicable Privacy Laws, where those laws use such terms.

Security Incident means a breach of security safeguards involving unauthorized access to, collection, use, disclosure, copying, modification, disposal, loss, destruction, or similar compromise of Client Personal Information under Twirling Umbrellas’ control.

Subprocessor means a third party engaged by Twirling Umbrellas to process Client Personal Information on Client’s behalf in connection with the Services.

Capitalized terms not defined in this DPA have the meanings given to them in the MSA.

3. Roles of the Parties

Client Responsibilities. Client is responsible for determining the purposes and means of processing Client Personal Information, identifying the Applicable Privacy Laws, providing required notices, obtaining required consents or other legal authority, responding to individual rights requests, and ensuring that Client’s instructions to Twirling Umbrellas comply with Applicable Privacy Laws.

Twirling Umbrellas’ Role. To the extent Twirling Umbrellas processes Client Personal Information on Client’s behalf, Twirling Umbrellas will act as Client’s service provider, processor, contractor, or equivalent role under Applicable Privacy Laws.

Independent Processing. Twirling Umbrellas may also process personal information for its own business purposes, such as account administration, billing, business communications, CRM records, legal compliance, security, internal reporting, and relationship management. That processing is not governed by this DPA and is addressed in Twirling Umbrellas’ Privacy Policy.

4. Processing Instructions

Instructions. Twirling Umbrellas will process Client Personal Information only:

to provide, support, secure, maintain, troubleshoot, improve, or administer the Services;

as described in the applicable Order;

as reasonably necessary to comply with the MSA;

as instructed by Client through written or electronic instructions, including emails, tickets, support requests, project-management systems, and other approved communications;

as required by Applicable Privacy Laws or other laws; or

as otherwise permitted by this DPA.

Scope of Instructions. The MSA, the applicable Order, this DPA, approved Change Orders, support requests, tickets, and other written or electronic instructions form Client’s documented instructions to Twirling Umbrellas.

Unlawful or Unclear Instructions. If Twirling Umbrellas reasonably believes that an instruction may violate Applicable Privacy Laws, create material security risk, exceed the applicable scope, or require work not included in the applicable Order, Twirling Umbrellas may pause the affected processing, request clarification, require a Change Order, or decline the instruction.

5. Description of Processing

Subject Matter. The subject matter of processing is the Client Personal Information processed in connection with the Services described in the applicable Order.

Duration. Processing will continue for the duration of the applicable Services, plus any period reasonably required for transition, backup retention, legal compliance, dispute resolution, security, or recordkeeping.

Nature and Purpose. The nature and purpose of processing may include website hosting, website maintenance, support, troubleshooting, development, migration, testing, deployment, analytics configuration, form handling, integrations, email delivery, CRM or AMS integrations, backups, security, project delivery, and related digital services.

Types of Client Personal Information. Depending on the applicable Services, Client Personal Information may include names, email addresses, phone numbers, mailing addresses, IP addresses, account identifiers, usernames, form submissions, membership or customer information, transaction-related information, website usage data, analytics data, support information, uploaded files, and other information processed through the applicable Services.

Categories of Individuals. Depending on the applicable Services, individuals may include Client’s employees, contractors, members, registrants, customers, donors, users, applicants, stakeholders, website visitors, account holders, or other individuals whose information is processed through the Services.

Special or Regulated Data. Client must not provide or make available sensitive, special-category, regulated, health, financial, government, child-related, or highly confidential personal information unless the applicable Order expressly identifies that information and the safeguards required for processing it.

6. Use Restrictions

Twirling Umbrellas will not sell Client Personal Information.

Twirling Umbrellas will not retain, use, or disclose Client Personal Information for purposes outside the Services, except as permitted by this DPA, the MSA, the applicable Order, Client’s documented instructions, or Applicable Privacy Laws.

Twirling Umbrellas will not use Client Personal Information to build profiles, market unrelated services, or combine Client Personal Information with personal information received from other clients or sources, except where permitted by Applicable Privacy Laws and reasonably necessary to provide, secure, support, or improve the Services.

To the extent the California Consumer Privacy Act or similar laws apply, Twirling Umbrellas will act as a service provider or contractor for Client Personal Information processed under the applicable Order and will comply with restrictions required for that role, including restrictions on selling, sharing, retaining, using, or disclosing personal information outside the permitted business purposes. California’s CCPA regulations include specific contract requirements for service providers and contractors, including prohibitions on selling or sharing personal information and restrictions on retaining, using, or disclosing it outside specified business purposes.  

7. Confidentiality

Twirling Umbrellas will ensure that personnel authorized to process Client Personal Information are subject to confidentiality obligations or professional duties of confidentiality.

Twirling Umbrellas will limit access to Client Personal Information to personnel, contractors, Subprocessors, and service providers who need access for the purposes permitted by this DPA.

8. Security Measures

Twirling Umbrellas will implement and maintain reasonable administrative, technical, and physical safeguards appropriate to the nature of the Services, the sensitivity of the Client Personal Information, and the risks associated with the processing.

Depending on the applicable Services, safeguards may include:

access controls;

role-based permissions;

strong password practices for systems under our control;

multi-factor authentication where reasonably available and appropriate;

secure transmission using HTTPS or other appropriate methods;

managed hosting, firewall, CDN, or security tools where included in the applicable Order;

software, plugin, server, and dependency updates where included in the applicable Order;

malware scanning, monitoring, or log review where included in the applicable Order;

backup tools or restoration support where included in the applicable Order;

confidentiality obligations for personnel and contractors;

reasonable vendor review for relevant Subprocessors; and

internal procedures for responding to suspected Security Incidents.

Security measures may vary depending on the applicable Order, Third-Party Services, hosting environment, platform, budget, scope, risk profile, and Client’s instructions.

Client acknowledges that no system, service, website, hosting environment, backup system, or method of transmission is completely secure. Twirling Umbrellas does not guarantee that Security Incidents, data loss, unauthorized access, malware, outages, or other security issues will never occur.

Client is responsible for maintaining secure access controls, passwords, multi-factor authentication, user permissions, internal policies, endpoint security, account recovery settings, third-party accounts, payment methods, and other safeguards for systems and accounts under Client’s control. BC PIPA requires reasonable security arrangements to protect personal information under an organization’s control, and PIPEDA breach guidance focuses on safeguards and risk assessment, so this section should stay practical and tied to the actual services being purchased.  

9. Subprocessors

General Authorization. Client authorizes Twirling Umbrellas to use Subprocessors to process Client Personal Information as reasonably necessary to provide, support, secure, maintain, host, troubleshoot, or administer the Services.

Subprocessor Terms. Twirling Umbrellas will use reasonable efforts to ensure that Subprocessors processing Client Personal Information are subject to contractual, technical, organizational, or legal obligations appropriate to the nature of the processing.

Changes to Subprocessors. Twirling Umbrellas may update its Subprocessors from time to time. Where a new Subprocessor is materially relevant to Client’s Services, Twirling Umbrellas may provide notice by updating the Subprocessor list, notifying Client, updating the applicable Order, or another reasonable method.

Objections. If Client has a reasonable privacy or security objection to a new Subprocessor, Client must notify Twirling Umbrellas promptly. The parties will work in good faith to resolve the concern. If the concern cannot reasonably be resolved, either party may terminate the affected Services, subject to the MSA and the applicable Order.

Third-Party Terms. Subprocessors and Third-Party Services may be subject to their own terms, privacy policies, data processing terms, service descriptions, security practices, and limitations.

10. Subprocessor List

The following providers may process Client Personal Information depending on the Services included in the applicable Order. Not every provider is used for every client or every project.

Hosting, Infrastructure, Security, and Development

ProviderTypical purposePantheonWebsite hosting and related platform servicesGoogle Cloud PlatformCloud hosting, infrastructure, and application services where usedCanadian Web HostingHosting services for select client websites or systemsCloudflareCDN, DNS, WAF, security, bot mitigation, and performance servicesGitHubSource code hosting, version control, issue tracking, and development collaboration

Website, Platform, and Application Services

ProviderTypical purposeAutomattic / WooCommerce / JetpackWordPress-related e-commerce, security, performance, and platform functionality where usedTwilio SendGridTransactional email delivery, such as form notifications, account emails, or password resetsWeglot / WPML / OnTheGoSystemsWebsite translation and multilingual functionality where usedZapierWorkflow automation and data integration where configured for ClientGoogle AnalyticsWebsite analytics and measurement where configured for Client

Business, Design, Project, and Collaboration Systems

These providers may process Client contact information, project information, design assets, feedback, files, or communications in connection with project delivery and account administration.

ProviderTypical purposeGoogle WorkspaceEmail, calendar, document storage, and internal collaborationProductive.ioProject management, CRM, agency operations, time tracking, budgeting, and client communicationFigmaDesign, prototyping, collaboration, and design reviewMarkup.ioWebsite and design feedbackBrowserStackCross-browser and device testing

AI-Assisted Tools

Twirling Umbrellas may use AI-assisted tools to support internal workflows, drafting, summarization, coding, analysis, or project delivery. Twirling Umbrellas will not intentionally submit Client Personal Information to AI-assisted tools unless authorized by the applicable Order, approved by Client, or reasonably necessary under Client’s documented instructions and subject to appropriate safeguards. If a specific AI tool, such as OpenAI, is used to process Client Personal Information on Client’s behalf, it will be treated as a Subprocessor for that processing.

11. International Processing and Storage

Client Personal Information may be processed or stored in Canada, the United States, the European Economic Area, the United Kingdom, or other jurisdictions where Twirling Umbrellas or its Subprocessors operate.

Client authorizes Twirling Umbrellas and its Subprocessors to process Client Personal Information in those jurisdictions as reasonably necessary to provide the Services, unless the applicable Order expressly requires a specific data residency commitment.

Client is responsible for identifying any data residency, public-sector, health-sector, education-sector, contractual, procurement, or regulatory restrictions that apply to Client Personal Information before providing it to Twirling Umbrellas or authorizing the Services.

Where GDPR, UK GDPR, or other international transfer requirements apply, any required transfer mechanism, standard contractual clauses, UK international data transfer addendum, supplementary measures, or additional terms must be expressly incorporated into the applicable Order or agreed in writing. PIPEDA allows outsourcing, including cross-border processing, but the transferring organization remains accountable for protecting personal information under the outsourcing arrangement.  

12. Individual Rights Requests

If Twirling Umbrellas receives a request from an individual seeking to exercise privacy rights in relation to Client Personal Information, Twirling Umbrellas will, where reasonably practical, forward the request to Client or instruct the individual to contact Client directly.

Client is responsible for responding to individual rights requests relating to Client Personal Information, including requests for access, correction, deletion, portability, restriction, objection, opt-out, or similar rights, unless Applicable Privacy Laws require otherwise.

Twirling Umbrellas will provide reasonable assistance to Client in responding to individual rights requests, taking into account the nature of the Services and the information available to Twirling Umbrellas. Assistance outside the scope of the applicable Order may be billed as On-Demand Services.

13. Security Incidents

Twirling Umbrellas will notify Client without undue delay after becoming aware of a confirmed Security Incident involving Client Personal Information.

Notice may include, to the extent known and reasonably available:

a summary of the nature of the Security Incident;

the categories of Client Personal Information involved;

the systems, services, or Subprocessors involved;

steps taken or proposed to contain, investigate, and mitigate the Security Incident; and

information reasonably available to assist Client in meeting its own notification or reporting obligations.

Client is responsible for determining whether the Security Incident must be reported to individuals, regulators, clients, members, customers, insurers, law enforcement, or other parties, unless Applicable Privacy Laws require Twirling Umbrellas to report directly.

Twirling Umbrellas will provide reasonable cooperation to support Client’s breach assessment and response. Cooperation outside the scope of the applicable Order may be billed as On-Demand Services unless the Security Incident was caused by Twirling Umbrellas’ breach of this DPA.

A notice or communication about a Security Incident is not an admission of fault, liability, or breach by Twirling Umbrellas. For organizations subject to PIPEDA, breach reporting and notification obligations apply where a breach of security safeguards creates a real risk of significant harm, and organizations must keep records of breaches.  

14. Return and Deletion

Upon termination or completion of the applicable Services, Client may request return or deletion of Client Personal Information in Twirling Umbrellas’ possession or control, subject to the MSA, the applicable Order, technical feasibility, legal requirements, backup systems, security obligations, dispute resolution, and reasonable business recordkeeping.

Twirling Umbrellas may retain Client Personal Information to the extent reasonably required for legal, tax, accounting, insurance, security, backup, archival, compliance, dispute resolution, or internal recordkeeping purposes, provided that retained information remains protected in accordance with this DPA, the MSA, or Twirling Umbrellas’ Privacy Policy, as applicable.

Client Personal Information stored in backups may not be immediately deleted, but will be overwritten, deleted, or rendered inaccessible in accordance with applicable backup cycles and retention practices.

15. Audits and Compliance Information

Upon reasonable written request, Twirling Umbrellas will provide information reasonably necessary to demonstrate compliance with this DPA, such as summaries of security measures, relevant policies, Subprocessor information, or responses to reasonable security and privacy questionnaires.

Any audit, review, questionnaire, assessment, or due-diligence request must be reasonable in scope, frequency, timing, and burden, and must not compromise the security, confidentiality, or privacy of Twirling Umbrellas, its systems, its personnel, its other clients, or its service providers.

Onsite audits, technical testing, penetration testing, vulnerability scanning, access to systems, access to personnel, or review of confidential vendor contracts are not permitted unless expressly required by Applicable Privacy Laws and agreed in writing in advance.

Assistance with audits, questionnaires, procurement reviews, privacy impact assessments, security assessments, data mapping, or compliance documentation outside the scope of an applicable Order may be billed as On-Demand Services.

16. Client Obligations

Client will:

comply with Applicable Privacy Laws;

provide all notices, consents, lawful bases, and authorizations required for the processing of Client Personal Information;

ensure that Client Personal Information provided to Twirling Umbrellas is accurate, lawful, and appropriate for the Services;

identify any sensitive, regulated, public-sector, health-sector, education-sector, child-related, payment-related, financial, or high-risk personal information before providing it to Twirling Umbrellas;

identify any data residency, procurement, records management, retention, archival, privacy impact assessment, or regulatory requirements that apply to Client Personal Information;

maintain appropriate internal access controls, credentials, security policies, user permissions, and backups;

avoid providing unnecessary personal information to Twirling Umbrellas; and

ensure that Client’s instructions do not cause Twirling Umbrellas to violate Applicable Privacy Laws.

17. Liability

All claims, losses, liabilities, damages, costs, expenses, remedies, and indemnities arising out of or related to this DPA are subject to the limitations, exclusions, and liability caps in the MSA, unless an applicable Order expressly states otherwise. If Client requires higher liability limits, special insurance, enhanced security commitments, specific data residency, formal audit rights, regulated-data processing, or other privacy commitments beyond this DPA, those requirements must be expressly stated in the applicable Order and may require additional fees, revised scope, or separate written terms.

18. Term

This DPA remains in effect for as long as Twirling Umbrellas processes Client Personal Information on behalf of Client under an applicable Order. Sections that by their nature should survive termination will survive, including confidentiality, security, return and deletion, audit and compliance information, liability, and any accrued rights or obligations.
