Data Processing Agreement
Template DPA governing TechHouseCa Inc.'s processing of personal data on behalf of airport customers operating the Vectro Platform.
Effective Date: January 1, 2026 · TechHouseCa Inc. · Kelowna, BC, Canada
Contents
Important Notice
This is a template Data Processing Agreement (DPA). It is provided for review purposes only and does not constitute a binding legal agreement on its own. Final terms are negotiated and executed as a schedule or addendum to a master service agreement (MSA) between TechHouseCa Inc. and the Customer.
Both parties should obtain independent legal advice before executing any data processing agreement. Nothing on this page constitutes legal advice.
This template is drafted with reference to Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), the BC Personal Information Protection Act (PIPA), and is structured to align with internationally recognized data processing standards including those reflected in the EU General Data Protection Regulation (GDPR) for Customers with cross-border obligations.
1. Parties & Definitions
This Data Processing Agreement is entered into between:
Controller: The airport operator, aviation authority, or other organization identified in the applicable Master Service Agreement ('Customer' or 'Controller'), acting as the entity that determines the purposes and means of processing personal data.
Processor: TechHouseCa Inc., a corporation incorporated under the laws of British Columbia, Canada, with its principal place of business in Kelowna, British Columbia ('TechHouseCa' or 'Processor'), acting as the entity that processes personal data on behalf of the Controller.
For the purposes of this Agreement, the following definitions apply:
"Personal Data" means any information relating to an identified or identifiable natural person ('Data Subject'), as defined under PIPEDA, PIPA, and applicable equivalent legislation.
"Processing" means any operation or set of operations performed on Personal Data, including collection, recording, organization, structuring, storage, adaptation, retrieval, use, disclosure, transmission, or deletion.
"Sub-Processor" means any third party engaged by TechHouseCa to carry out specific processing activities on Personal Data on behalf of the Controller.
"Data Subject" means an identified or identifiable natural person to whom Personal Data relates, including airport staff, contractors, ground crew, drivers, and — where applicable — passengers.
"Security Incident" or "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data.
"Vectro Platform" means the suite of integrated airport operating system modules and cloud services developed and operated by TechHouseCa under the Vectro brand.
2. Subject Matter & Duration of Processing
TechHouseCa processes Personal Data solely for the purpose of providing the Vectro Platform services to the Controller under the applicable Master Service Agreement.
The subject matter of processing is the operation, maintenance, support, and improvement of the Vectro Airport Operating System modules as deployed for the Controller.
The duration of processing is coterminous with the term of the Master Service Agreement unless a longer or shorter retention period is required by applicable law or agreed in a separate schedule. Upon termination of the Master Service Agreement, TechHouseCa will cease processing and return or securely delete Personal Data as described in Section 13.
3. Nature & Purpose of Processing
TechHouseCa processes Personal Data on behalf of the Controller for the following purposes:
Operating and delivering Vectro Platform modules including, but not limited to: Vectro Boards (FIDS/BIDS), Vectro Queue, Vectro Apron, Vectro Flow, Vectro Access, Vectro Shield, Vectro Log, Vectro Command, Vectro Helix, Vectro Vault, and all other modules comprising the Vectro Airport Operating System.
Maintaining and supporting the secure operation of the Vectro Platform on behalf of the Controller, including performing system maintenance, applying security patches, diagnosing and resolving technical incidents, and ensuring platform availability.
Processing operational records, access logs, turnaround data, passenger flow metrics, and any other operational data generated through the Controller's use of the Vectro Platform.
Processing Personal Data strictly in accordance with the Controller's documented instructions, as set out in the Master Service Agreement and this DPA, and not for any other purpose unless required by applicable law.
4. Categories of Data Subjects
Personal Data processed under this Agreement may relate to the following categories of Data Subjects:
Airport operations staff: Personnel employed by or contracted to the airport operator, including operations controllers, airside staff, security personnel, and administrative employees.
Ground crew and service providers: Ground handling personnel, fueling crews, catering staff, maintenance technicians, and other contracted ground service providers.
Ground transport drivers: Taxi, rideshare, and commercial vehicle drivers registered with or operating through the airport's ground transportation system.
Visitors and contractors: Individuals issued temporary access credentials for the airport's restricted or controlled areas.
Passengers: Where applicable and only where the Controller has configured modules such as Vectro Flow or Vectro Apron (computer vision) to process identifiable passenger data, passengers transiting through the airport. TechHouseCa processes passenger data only to the extent directed by the Controller and in accordance with the Controller's applicable privacy notices.
5. Categories of Personal Data Processed
Depending on the Vectro modules deployed and the Controller's configuration, TechHouseCa may process the following categories of Personal Data:
Identity and credential data: Names, employee identification numbers, access badge identifiers, usernames, and authentication credentials (stored in hashed form).
Contact information: Email addresses and phone numbers of platform users for account management and notification purposes.
Operational records: Shift logs, access event logs, incident reports, work order assignments, and ground service event records attributable to named individuals.
Access and movement data: Records of physical access to controlled zones, including timestamp, zone, and credential information.
Vehicle data: Vehicle registration numbers and driver identifiers for ground transportation queue management.
Computer vision data: Where the Controller deploys Vectro Apron (CV Turnaround Intelligence), anonymized or pseudonymized visual data from apron cameras used for turnaround milestone detection. TechHouseCa does not process facial recognition data unless expressly agreed in a separate written instrument.
Special categories of data: TechHouseCa does not process special categories of sensitive personal data (as defined under GDPR Article 9 equivalents) through the Vectro Platform unless expressly agreed in writing.
6. Processor Obligations
TechHouseCa, as Processor, undertakes the following obligations:
Processing on instructions only: TechHouseCa will process Personal Data only on documented instructions from the Controller, as set out in the Master Service Agreement, this DPA, and any written instructions provided thereafter. If TechHouseCa is required by applicable law to process Personal Data beyond the Controller's instructions, TechHouseCa will inform the Controller before such processing, unless prohibited by law.
Confidentiality: TechHouseCa will ensure that all personnel authorized to process Personal Data are subject to binding confidentiality obligations and are trained on their data protection responsibilities.
Security: TechHouseCa will implement and maintain the technical and organizational security measures described in Section 7.
Sub-processors: TechHouseCa will engage Sub-Processors only as permitted by Section 8.
Data Subject rights: TechHouseCa will assist the Controller in fulfilling its obligations to respond to Data Subject rights requests as described in Section 9.
Breach notification: TechHouseCa will notify the Controller of a Personal Data Breach as described in Section 10.
DPIA assistance: TechHouseCa will provide reasonable assistance to the Controller in conducting Data Protection Impact Assessments as described in Section 11.
Return or deletion: TechHouseCa will return or securely delete Personal Data at the end of the service term as described in Section 13.
Audit rights: TechHouseCa will make available to the Controller the information necessary to demonstrate compliance with this DPA and will support audits as described in Section 14.
7. Security Measures
TechHouseCa implements and maintains the following technical and organizational security measures to protect Personal Data:
Encryption in transit: All data transmitted between clients and Vectro Platform services is encrypted using TLS 1.2 or higher.
Encryption at rest: All databases and storage containing Personal Data are encrypted at rest using AES-256 or equivalent industry-standard encryption.
Access controls and Role-Based Access Control (RBAC): Access to Personal Data and production systems is restricted to authorized TechHouseCa personnel on a need-to-know, least-privilege basis, enforced through role-based access control.
Multi-factor authentication (MFA): MFA is required for all TechHouseCa personnel accessing production systems and environments containing Personal Data.
Audit logging: All access to and significant actions within production environments containing Personal Data are logged and retained for security review and audit purposes.
Tenant data isolation: Each Customer's Personal Data is logically isolated within dedicated tenant environments. TechHouseCa does not combine or commingle Personal Data between Customer tenants.
Vulnerability management: TechHouseCa conducts periodic security reviews, penetration testing, and applies security patches in a timely manner.
Incident response: TechHouseCa maintains a documented security incident response procedure, including escalation, containment, assessment, and notification protocols.
Personnel security: TechHouseCa conducts background checks on personnel with access to production systems as permitted by applicable law.
TechHouseCa will review and update these security measures periodically and, where improvements are made, will implement them without undue delay.
8. Sub-Processors
The Controller provides general authorization for TechHouseCa to engage Sub-Processors, subject to the conditions in this Section.
Current Sub-Processors: TechHouseCa uses cloud infrastructure Sub-Processors including providers in the Amazon Web Services (AWS) and/or Microsoft Azure families to host and operate the Vectro Platform. These Sub-Processors provide compute, storage, networking, and database services.
Written agreements: TechHouseCa imposes data protection obligations on all Sub-Processors that are no less protective than those set out in this DPA, through binding written contracts.
Notice of changes: TechHouseCa will provide the Controller with reasonable advance written notice (not less than 30 days) of any intended changes to Sub-Processors, including the addition of new Sub-Processors or replacement of existing ones.
Right to object: The Controller may object to a new Sub-Processor within 14 days of receiving notice, providing written reasons for the objection. TechHouseCa will work in good faith with the Controller to address the objection. If the parties cannot resolve the objection and the Sub-Processor change is necessary for service delivery, either party may terminate the affected services with 30 days' written notice without penalty.
Liability: TechHouseCa remains fully liable to the Controller for the performance of Sub-Processor obligations under this DPA.
9. Data Subject Rights Assistance
TechHouseCa will provide reasonable technical and organizational assistance to the Controller to fulfil the Controller's obligations to respond to Data Subject rights requests under applicable privacy law, including requests for:
Access: providing a copy of the Data Subject's Personal Data.
Correction: correcting inaccurate or incomplete Personal Data.
Deletion: erasing Personal Data where there is no legal basis for retention.
Restriction of processing: restricting processing of Personal Data pending a dispute or objection.
Data portability: providing Personal Data in a structured, machine-readable format where technically feasible.
TechHouseCa will respond to reasonable assistance requests from the Controller within 10 business days. Costs associated with fulfilling Data Subject rights requests beyond standard platform capabilities may be subject to reasonable fees as agreed in the Master Service Agreement.
Data Subjects whose Personal Data is processed within the Controller's Vectro deployment should direct privacy rights requests to the Controller (airport operator), as the Controller is the data controller for that processing.
10. Personal Data Breach Notification
In the event that TechHouseCa becomes aware of a confirmed Personal Data Breach affecting Personal Data processed under this DPA, TechHouseCa will:
Notify the Controller without undue delay, and where feasible within 72 hours of becoming aware of the breach, via the contact details provided in the Master Service Agreement.
Provide, to the extent then known, the following information: a description of the nature of the breach; the categories and approximate number of Data Subjects affected; the categories and approximate number of Personal Data records affected; the likely consequences of the breach; and the measures taken or proposed to address the breach and mitigate its effects.
Where not all information is available at the time of initial notification, TechHouseCa will provide information in phases as it becomes available, without undue delay.
TechHouseCa will cooperate fully with the Controller and provide all reasonable assistance in managing, investigating, and mitigating the breach, and in notifying affected Data Subjects and relevant regulatory authorities where required.
TechHouseCa will take prompt steps to contain, investigate, and remediate the breach and will document all actions taken.
11. Data Protection Impact Assessment Assistance
Where the Controller is required by applicable privacy law to conduct a Data Protection Impact Assessment (DPIA) or Privacy Impact Assessment (PIA) in connection with processing activities carried out using the Vectro Platform, TechHouseCa will provide reasonable technical and organizational assistance.
Such assistance may include: providing information about the security measures and processing architecture of the Vectro Platform; completing security questionnaires or data processing information sheets; and participating in reasonable consultations with the Controller or its appointed data protection officer.
Costs associated with substantial DPIA assistance beyond standard documentation may be subject to reasonable fees as agreed in the Master Service Agreement.
12. International Data Transfers
TechHouseCa is a Canadian entity and seeks to process and store Personal Data within Canada and North America wherever practicable.
Some Sub-Processor services (including cloud infrastructure providers) may involve the transfer of Personal Data to the United States or other jurisdictions. When Personal Data is transferred outside Canada, TechHouseCa ensures that appropriate safeguards are in place, including contractual clauses or other mechanisms that provide protections substantially equivalent to those required under PIPEDA and applicable Canadian privacy law.
TechHouseCa will inform the Controller of the countries and regions in which Personal Data may be processed, upon request.
If the Controller has specific requirements regarding data residency or cross-border transfers (including compliance with GDPR adequacy requirements for Customers with EU-resident Data Subjects), the parties will address these requirements in the applicable Master Service Agreement or a supplementary data transfer instrument.
13. Return or Deletion of Data on Termination
Upon expiry or termination of the Master Service Agreement, TechHouseCa will, at the Controller's election:
Return: Provide the Controller with an export of all Personal Data processed under this DPA in a structured, portable format, within 30 days of termination; or
Delete: Securely delete or destroy all Personal Data processed under this DPA, including all copies held by TechHouseCa and its Sub-Processors, within 90 days of termination.
TechHouseCa will provide the Controller with written certification of deletion upon request.
Notwithstanding the above, TechHouseCa may retain Personal Data to the extent required by applicable law, regulation, or court order, provided that TechHouseCa notifies the Controller of any such retention obligation and continues to protect the retained data in accordance with this DPA.
14. Audit Rights
TechHouseCa will make available to the Controller, upon request, all information reasonably necessary to demonstrate TechHouseCa's compliance with this DPA.
The Controller has the right to audit TechHouseCa's compliance with this DPA, subject to the following conditions:
The Controller will provide TechHouseCa with not less than 30 days' prior written notice of any intended audit.
Audits will be conducted during TechHouseCa's normal business hours and in a manner that minimizes disruption to TechHouseCa's operations.
Audits will be conducted no more than once per year, except where a confirmed Security Incident warrants an additional audit.
The Controller and any appointed auditor will be subject to confidentiality obligations equivalent to those in the Master Service Agreement.
The Controller will bear all costs associated with the audit unless the audit reveals a material breach of this DPA, in which case the parties will negotiate cost sharing in good faith.
Where the Controller is satisfied with TechHouseCa's provision of industry-standard security certifications or third-party audit reports (e.g. SOC 2 Type II), the Controller agrees to accept such reports in lieu of conducting a direct audit, at TechHouseCa's reasonable discretion.
15. Liability & Indemnification
Each party's liability under this DPA is subject to the limitations and caps set out in the applicable Master Service Agreement.
To the extent permitted by applicable law, TechHouseCa's total liability arising out of or in connection with this DPA shall be subject to the aggregate liability cap specified in the Master Service Agreement.
Neither party shall be liable for indirect, incidental, consequential, punitive, or special damages arising out of or in connection with this DPA, to the maximum extent permitted by applicable law.
Each party will indemnify, defend, and hold harmless the other party from third-party claims, losses, and costs arising from its own breach of its obligations under this DPA, to the extent permitted by the Master Service Agreement.
16. Governing Law
This Data Processing Agreement shall be governed by and construed in accordance with the laws of the Province of British Columbia and the federal laws of Canada applicable therein, without regard to conflict of law principles.
Any disputes arising out of or in connection with this DPA shall be resolved in accordance with the dispute resolution provisions of the applicable Master Service Agreement.
This DPA is drafted with reference to Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and the BC Personal Information Protection Act (PIPA). Customers subject to other privacy regimes (including the EU GDPR) may request supplementary clauses to address specific compliance requirements.
17. Signature Blocks
This Data Processing Agreement is incorporated into and forms part of the Master Service Agreement between the parties. It becomes effective on the date the Master Service Agreement is executed, or on the date both parties execute a separate DPA execution page referencing this template.
FOR THE CONTROLLER (Airport Operator / Customer):
Name: ___________________________
Title: ___________________________
Organization: ___________________________
Signature: ___________________________
Date: ___________________________
FOR THE PROCESSOR (TechHouseCa Inc.):
Name: ___________________________
Title: ___________________________
Organization: TechHouseCa Inc.
Signature: ___________________________
Date: ___________________________
Contact for data protection inquiries: info@techhouseca.com