Cannvas · Legal
DRAFT — under legal review. These documents are working drafts, are not yet effective, and do not yet bind anyone. They are being finalized with counsel.

Data Processing Addendum

DRAFT v0.1 — FOR ATTORNEY REVIEW ONLY. NOT LEGAL ADVICE. NOT YET EFFECTIVE.

*Last updated: [EFFECTIVE DATE] · Version: 0.1-DRAFT*

Drafting note (non-operative): This is a first-draft template prepared for review and finalization by the client's own qualified counsel before use or execution. Bracketed items are placeholders. Statutory citations should be independently verified against the current text of the California Consumer Privacy Act as amended by the California Privacy Rights Act and its implementing regulations, and against the other U.S. state privacy statutes referenced herein, prior to reliance. Do not represent this document as effective, executed, or as legal advice.

This Data Processing Addendum ("DPA") supplements and forms part of the Master SaaS Subscription Agreement (the "MSA") between Cannvas, LLC, a Michigan limited liability company doing business as "Cannvas" ("Cannvas"), and the customer organization identified in the MSA or the applicable ordering document ("Customer," "Org," or "Organization"). Cannvas and Customer are each a "Party" and together the "Parties."

This DPA governs the Processing by Cannvas of Personal Data contained within Org Data in connection with Cannvas's provision of the Service under the MSA. This DPA is entered into as of the Effective Date and is incorporated into and made a part of the MSA.

RECITALS

A. Customer has engaged Cannvas to provide the Cannvas B2B dashboard and related cannabis-industry planning, sales, and compliance-reflection software (the "Service") under the MSA.

B. In providing the Service, Cannvas Processes certain business records of Customer ("Org Data"), a portion of which may constitute Personal Data or Personal Information. Much of the Org Data is mirrored from the applicable state cannabis track-and-trace system (e.g., METRC) and other systems designated by Customer.

C. With respect to such Personal Data, Customer acts as the Business/Controller and Cannvas acts as the Service Provider/Processor, and the Parties wish to set out their respective obligations under Applicable Data Protection Laws.

D. The Parties agree that this DPA reflects their agreement with respect to the Processing of Personal Data as required by Applicable Data Protection Laws, including the contractual terms required of a "service provider" under the California Consumer Privacy Act, as amended by the California Privacy Rights Act, and its implementing regulations.

NOW, THEREFORE, in consideration of the mutual covenants in the MSA and this DPA, the Parties agree as follows.


1. Definitions

1.1 Capitalized terms used but not defined in this DPA have the meanings given to them in the MSA. In the event of a conflict between a definition in this DPA and a definition in the MSA, the definition in this DPA controls for purposes of this DPA and the Processing of Personal Data.

1.2 For purposes of this DPA:

"Applicable Data Protection Laws" means all U.S. federal, state, and local laws, rules, and regulations relating to the privacy, protection, confidentiality, retention, disposal, or security of Personal Data that are applicable to the Processing of Personal Data under this DPA, in each case as amended, superseded, or replaced from time to time, including, without limitation: (a) the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act of 2020, and its implementing regulations (collectively, the "CCPA"); (b) the Virginia Consumer Data Protection Act; (c) the Colorado Privacy Act; (d) the Connecticut Data Privacy Act; (e) the Utah Consumer Privacy Act; and (f) any other U.S. state comprehensive consumer privacy or data protection law that is in effect and applicable to a Party's activities under the MSA. *(Drafting note: confirm and update the enumerated statutes as of the Effective Date; consider a forward-looking catch-all as drafted.)*

"Business" or "Controller" means the natural or legal person that, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. As between the Parties and with respect to Org Data, Customer is the Business/Controller. The terms "Business" and "Controller" have the meanings given to the equivalent terms (e.g., "controller") under Applicable Data Protection Laws.

"Business Purpose" means the operational purpose(s), or other notified purpose(s), for which Cannvas Processes Personal Data on behalf of Customer to provide, support, secure, maintain, and improve the Service under the MSA, as further described in Section 3 and Annex 1, and as such term is used under the CCPA.

"Consumer" or "Data Subject" means an identified or identifiable natural person about whom Personal Data relates, including a "consumer" as defined under the CCPA and a "consumer" or "data subject" as defined under other Applicable Data Protection Laws.

"Deidentified Data" means information that cannot reasonably be used to infer information about, or otherwise be linked to, a particular Consumer, and that is processed in accordance with the deidentification standards and commitments required by Applicable Data Protection Laws.

"MSA" means the Master SaaS Subscription Agreement between the Parties, including all ordering documents, order forms, and documentation incorporated therein.

"Org Data" means the business data of, or submitted, uploaded, or made available by or on behalf of, Customer to the Service, or generated by the Service for Customer, including data mirrored from state cannabis track-and-trace systems (e.g., METRC) and other Customer-designated sources. Org Data includes any Personal Data contained therein.

"Permitted Purposes" means the Business Purpose and the other limited and specified purposes set out in Section 3 and Annex 1 for which Cannvas is authorized to Process Personal Data.

"Personal Data" or "Personal Information" means any information within the Org Data that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular Consumer or household, as defined under Applicable Data Protection Laws. Personal Data does not include Deidentified Data, aggregate consumer information, or publicly available information to the extent excluded from the scope of Applicable Data Protection Laws.

"Process" or "Processing" means any operation or set of operations performed on Personal Data, whether or not by automated means, including collection, access, use, storage, disclosure, analysis, deletion, retention, transmission, hosting, or organization, as such term (or the term "processing") is defined under Applicable Data Protection Laws.

"Sell" or "Selling" and "Share" or "Sharing" have the meanings given to those terms under the CCPA, including the sale of Personal Information for monetary or other valuable consideration and the sharing of Personal Information for cross-context behavioral advertising.

"Security Incident" means a breach of Cannvas's security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of, or access to, Personal Data Processed by Cannvas or its Sub-processors, and includes a "breach of the security of the system" and any analogous "security breach" or "breach of security" event as defined under Applicable Data Protection Laws. A Security Incident does not include unsuccessful attempts or activities that do not compromise the security of Personal Data, such as pings, port scans, denied log-in attempts, or similar events.

"Service Provider" or "Processor" means the natural or legal person that Processes Personal Data on behalf of a Business/Controller. As between the Parties and with respect to Org Data, Cannvas is the Service Provider/Processor, and the term "Service Provider" has the meaning given under the CCPA. To the extent Cannvas is deemed a "contractor" under the CCPA rather than, or in addition to, a "service provider," the obligations and certification in this DPA apply to Cannvas in that capacity as well.

"Sub-processor" means any third party engaged by Cannvas (including a Cannvas affiliate) that Processes Personal Data on behalf of Cannvas in connection with the Service, and includes any "service provider," "contractor," or "subcontractor" of Cannvas as those terms are used under Applicable Data Protection Laws.


2. Roles of the Parties; Scope; Order of Precedence

2.1 Roles. The Parties acknowledge and agree that, with respect to the Processing of Personal Data contained in Org Data under the MSA: (a) Customer is the Business/Controller; and (b) Cannvas is the Service Provider/Processor acting on behalf of Customer. Cannvas Processes Personal Data only on behalf of and for the benefit of Customer and does not Process Personal Data as a Business/Controller, a third party, or for its own commercial purposes, except as expressly permitted by Applicable Data Protection Laws and this DPA.

2.2 Customer responsibilities. As between the Parties, Customer is responsible for the accuracy, quality, and legality of Org Data, the means by which Customer acquired Personal Data, and Customer's compliance with Applicable Data Protection Laws applicable to a Business/Controller, including providing any required notices to and obtaining any required consents from Consumers. Customer's instructions for the Processing of Personal Data shall comply with Applicable Data Protection Laws.

2.3 Scope. This DPA applies only to the Processing of Personal Data contained in Org Data by Cannvas as a Service Provider/Processor under the MSA. It does not apply to (a) Deidentified Data or aggregate information Processed in accordance with Applicable Data Protection Laws, or (b) any Processing by Cannvas for its own internal, lawful business purposes as permitted under Section 4.5.

2.4 Order of precedence. This DPA supplements the MSA. In the event of a conflict between this DPA and the MSA with respect to the Processing of Personal Data or the subject matter of Applicable Data Protection Laws, this DPA controls. In all other respects, the MSA remains in full force and effect. Except as expressly modified by Section 13, nothing in this DPA is intended to modify the MSA or any limitations of liability set forth therein.

2.5 Privacy Policy. Cannvas's privacy practices are further described in the Cannvas Privacy Policy referenced in the MSA and available at the Cannvas website. In the event of a conflict between the Privacy Policy and this DPA regarding Cannvas's obligations to Customer as a Service Provider/Processor, this DPA controls.


3. Details of Processing; Documented Instructions

3.1 Documented instructions. Cannvas shall Process Personal Data only in accordance with Customer's documented, lawful instructions, and only for the Permitted Purposes, except where otherwise required by applicable law (in which case, to the extent legally permitted, Cannvas shall inform Customer of that legal requirement before Processing). The MSA (including any ordering documents), this DPA, the Service's in-application configuration and settings selected by Customer, and the Service documentation together constitute Customer's complete and final documented instructions to Cannvas for the Processing of Personal Data.

3.2 Additional instructions. Any additional or alternative instructions must be agreed in writing between the Parties and may be subject to additional fees or timelines as set out in the MSA. Cannvas shall notify Customer if, in Cannvas's reasonable opinion, an instruction infringes Applicable Data Protection Laws; Cannvas is not obligated to perform an instruction it reasonably believes to be unlawful.

3.3 Details of Processing. The subject matter, nature and purpose of the Processing, the duration of the Processing, the categories of Personal Data, and the categories of Data Subjects are described in Annex 1 (Details of Processing).

3.4 METRC-sourced data. The Parties acknowledge that a significant portion of Org Data is mirrored from state cannabis track-and-trace systems (e.g., METRC) and other Customer-designated sources. Cannvas's role with respect to such data is to reflect and organize state-of-record information for Customer's operational and planning use; Cannvas does not act as the system of record for regulatory compliance.


4. Service Provider / Processor Restrictions and Compliance (CCPA/CPRA)

This Section 4 sets out the restrictions and obligations required of a "service provider" (and, to the extent applicable, a "contractor") under the CCPA and its implementing regulations, together with equivalent processor obligations under other Applicable Data Protection Laws.

4.1 Prohibition on Selling and Sharing. Cannvas shall not Sell or Share Personal Data. Cannvas is not permitted to, and shall not, sell or share Personal Data for monetary or other valuable consideration or for cross-context behavioral advertising.

4.2 Purpose limitation. Cannvas shall not retain, use, or disclose Personal Data:

(a) for any purpose other than the Business Purpose and the other Permitted Purposes specified in this DPA and Annex 1, including any commercial purpose other than the Permitted Purposes;

(b) outside the direct business relationship between Cannvas and Customer; or

(c) in a manner that would constitute Selling or Sharing.

The Parties agree that the Permitted Purposes are limited and specific and are not described in generic terms. Customer does not disclose Personal Data to Cannvas as consideration for the Service or any other thing of value.

4.3 No combining. Cannvas shall not combine Personal Data that Cannvas receives from, or on behalf of, Customer with Personal Data that Cannvas receives from, or on behalf of, any other person, or that Cannvas collects from its own interaction with a Consumer, except as necessary to perform a Business Purpose as permitted under the CCPA and its implementing regulations.

4.4 No independent use. Cannvas shall not retain, use, or disclose Personal Data for the purpose of building, or benefiting from building, any profile of a Consumer or otherwise for Cannvas's own commercial benefit, except to the extent expressly permitted for a Service Provider under Applicable Data Protection Laws.

4.5 Permitted internal uses. Notwithstanding the foregoing, Cannvas may Process Personal Data as reasonably necessary and proportionate to: (a) provide, maintain, secure, and support the Service for Customer; (b) perform the Business Purpose and the other Permitted Purposes; (c) detect, prevent, and respond to security incidents, fraud, and illegal activity; (d) debug and repair errors that impair intended functionality; (e) comply with applicable law and legal process; and (f) build or improve the quality of the Service, provided that Cannvas does not use Personal Data to perform services on behalf of another person and does not otherwise engage in conduct prohibited by Applicable Data Protection Laws. Cannvas may create and use Deidentified Data and aggregate information in accordance with Applicable Data Protection Laws.

4.6 Compliance and equivalent protection. Cannvas shall comply with all obligations applicable to a Service Provider/Processor under Applicable Data Protection Laws and shall provide the same level of privacy protection with respect to Personal Data as is required of a Business/Controller by the CCPA. Cannvas shall Process Personal Data in compliance with Applicable Data Protection Laws.

4.7 Customer's remediation rights. Customer has, and Cannvas grants Customer, the right to take reasonable and appropriate steps to help ensure that Cannvas Processes Personal Data in a manner consistent with Customer's obligations under Applicable Data Protection Laws. Upon reasonable notice, Customer has the right to take reasonable and appropriate steps to stop and remediate any unauthorized use of Personal Data by Cannvas, including as described in Section 11 (Audits).

4.8 Notice of inability to comply. Cannvas shall notify Customer promptly, and in any event without undue delay, if Cannvas makes a determination that it can no longer meet its obligations under Applicable Data Protection Laws with respect to the Processing of Personal Data. Following such notice, Customer may take the steps described in Section 4.7.

4.9 Certification. Cannvas certifies that it understands the restrictions and obligations set forth in this Section 4 and in the CCPA applicable to a service provider and, to the extent applicable, a contractor, and that Cannvas will comply with them. *(Drafting note: The CCPA requires this certification of a "contractor"; it is included here for both roles as a protective measure and to accommodate treatment of Cannvas as a contractor.)*

4.10 Deletion in response to Consumer requests. Where Customer receives and communicates a verifiable Consumer request to delete or correct Personal Data, Cannvas shall, as directed by Customer, delete or correct the Personal Data from its records and instruct its Sub-processors to do the same, in each case as required by and subject to the exceptions in Applicable Data Protection Laws and Section 10.


5. Confidentiality of Personnel

5.1 Cannvas shall ensure that any personnel authorized to Process Personal Data are subject to a duty of confidentiality (whether contractual or statutory) with respect to the Personal Data, and shall ensure that access to Personal Data is limited to those personnel who need access to perform the Permitted Purposes (least privilege).

5.2 Cannvas shall take reasonable steps to ensure the reliability, training, and awareness of any personnel who may have access to Personal Data with respect to their obligations under this DPA and Applicable Data Protection Laws.


6. Security

6.1 Security measures. Cannvas shall implement and maintain reasonable and appropriate technical and organizational measures designed to protect Personal Data against Security Incidents and to preserve the security, confidentiality, integrity, and availability of Personal Data, taking into account the nature, scope, context, and purposes of Processing as well as the risks to Consumers. Cannvas's current technical and organizational measures are described in Annex 2 (Technical and Organizational Security Measures).

6.2 Evolving measures. Customer acknowledges that the security measures are subject to technical progress and development, and Cannvas may update or modify the measures from time to time, provided that such updates and modifications do not materially degrade the overall security of the Service during the term of the MSA.

6.3 Customer responsibilities. Customer is responsible for its own secure use of the Service, including safeguarding account credentials, configuring available access controls and role-based permissions appropriately, managing its authorized users, and using the security functionality made available within the Service.


7. Sub-processors

7.1 General authorization. Customer provides a general authorization for Cannvas to engage Sub-processors to Process Personal Data in connection with the Service. The Sub-processors engaged by Cannvas as of the Effective Date are listed in Annex 3 (Authorized Sub-processors).

7.2 Flow-down obligations. Where Cannvas engages a Sub-processor, Cannvas shall enter into a written contract with the Sub-processor that imposes data protection obligations that are substantially equivalent to, and no less protective than, those set out in this DPA, to the extent applicable to the services provided by the Sub-processor, including the relevant restrictions and obligations required by Applicable Data Protection Laws.

7.3 Liability for Sub-processors. Cannvas remains responsible for its Sub-processors' Processing of Personal Data and shall be liable for the acts and omissions of its Sub-processors with respect to Personal Data to the same extent Cannvas would be liable if performing the services of the Sub-processor directly under this DPA, subject to the limitations of liability in the MSA as applied through Section 13.

7.4 Notice of changes; right to object. Cannvas shall notify Customer of any intended addition or replacement of a Sub-processor that Processes Personal Data, giving Customer a reasonable opportunity (at least [15] days, unless a shorter period is required for security or legal reasons) to object on reasonable, good-faith grounds relating to data protection. Notice may be provided by email to Customer's designated contact, by posting to a Sub-processor page or Service notification mechanism, or by another reasonable means. If Customer reasonably objects and the Parties cannot resolve the objection within a reasonable period, Customer may, as its sole and exclusive remedy, terminate the affected portion of the Service in accordance with the termination provisions of the MSA. Absent a timely objection, the new or replacement Sub-processor is deemed authorized.


8. Assistance to Customer

8.1 Consumer rights requests. Taking into account the nature of the Processing, Cannvas shall provide reasonable assistance to Customer, through appropriate technical and organizational measures and insofar as commercially reasonable, to enable Customer to respond to and fulfill verifiable requests by Consumers to exercise their rights under Applicable Data Protection Laws (including rights to access, delete, correct, know, opt out of Selling/Sharing, and limit the use of sensitive Personal Information). If Cannvas receives a request directly from a Consumer concerning Personal Data Processed on behalf of Customer, Cannvas shall, unless legally prohibited, promptly inform the Consumer that the request should be directed to Customer and shall notify Customer of the request; Cannvas shall not respond substantively except on Customer's documented instructions or as required by law.

8.2 Security, breach, and assessment assistance. Taking into account the nature of Processing and the information available to Cannvas, Cannvas shall provide reasonable assistance to Customer in relation to: (a) Customer's obligations to maintain the security of Personal Data; (b) Customer's obligations to notify and cooperate with respect to Security Incidents; and (c) as applicable under Applicable Data Protection Laws, Customer's completion of any legally required data protection assessments or risk assessments relating to the Processing under the MSA.

8.3 Cooperation with regulators. Cannvas shall provide reasonable cooperation and assistance to Customer in connection with any inquiry, investigation, or enforcement action by a competent supervisory or regulatory authority relating to the Processing of Personal Data under this DPA, subject to Section 11.

8.4 Costs. Cannvas may charge a reasonable fee for assistance under this Section 8 to the extent the assistance exceeds the functionality made generally available within the Service or requires material additional effort, as permitted by Applicable Data Protection Laws.


9. Security Incident Notification

9.1 Notification. Cannvas shall notify Customer of a Security Incident affecting Personal Data without undue delay after becoming aware of it, and in any event within seventy-two (72) hours after Cannvas confirms the Security Incident. Notification shall be made to Customer's designated security or administrative contact by email or another reasonable means.

9.2 Content of notification. To the extent known and available at the time of notification, and supplemented as further information becomes available, Cannvas's notification shall describe: (a) the nature of the Security Incident, including the categories and approximate number of Consumers and records affected; (b) the likely consequences of the Security Incident; (c) the measures taken or proposed to be taken to address the Security Incident and mitigate its adverse effects; and (d) a contact point from whom further information may be obtained.

9.3 Cooperation and mitigation. Cannvas shall take reasonable steps to investigate, contain, and mitigate the effects of the Security Incident and shall reasonably cooperate with Customer in Customer's investigation and response, including Customer's fulfillment of any legally required notifications to Consumers, regulators, or other third parties. Customer is solely responsible for determining whether, when, and how to make any such external notifications, unless otherwise required of Cannvas by law.

9.4 No admission. Cannvas's notification of, or response to, a Security Incident is not an acknowledgment or admission of fault or liability by Cannvas.


10. Return and Deletion of Org Data

10.1 On termination. Upon expiration or termination of the MSA, and upon Customer's written request, Cannvas shall, at Customer's election, return to Customer and/or delete the Org Data (including Personal Data) in Cannvas's possession or control, except as set out in this Section 10.

10.2 Deletion timeframe. Unless a shorter period is required by Applicable Data Protection Laws, Cannvas shall delete or return the Org Data within [30–90] days after the later of the effective date of termination and Customer's request, and shall instruct its Sub-processors to do the same.

10.3 Backups and technical limitations. Personal Data residing in routine, encrypted backup or archival systems, or in logs, need not be immediately deleted but shall be isolated, protected from further active Processing, and deleted or overwritten in the ordinary course of Cannvas's backup rotation and retention cycle. Cannvas shall continue to protect such residual Personal Data in accordance with this DPA until deletion.

10.4 Legal retention. Cannvas may retain Personal Data to the extent, and for so long as, required by applicable law, provided that Cannvas shall (a) maintain the confidentiality and security of such retained Personal Data, (b) limit further Processing to the purpose(s) that require retention, and (c) delete the Personal Data when the legal retention requirement lapses.

10.5 Certification. Upon Customer's reasonable written request, Cannvas shall provide written confirmation that it has complied with its return and deletion obligations under this Section 10.

10.6 Post-termination access. Customer acknowledges that, following the deletion or return of Org Data, Cannvas may no longer be able to provide access to, or recover, the Org Data.


11. Audits and Records

11.1 Records. Cannvas shall maintain records reasonably sufficient to demonstrate its compliance with its obligations under this DPA and Applicable Data Protection Laws.

11.2 Information on request. Cannvas shall make available to Customer, upon reasonable written request, information reasonably necessary to demonstrate Cannvas's compliance with this DPA, which may be satisfied through up-to-date certifications, attestations, audit reports (e.g., SOC 2 Type II, if and when available), security summaries, or responses to a reasonable security questionnaire.

11.3 Audits. Where the information made available under Section 11.2 is not sufficient to demonstrate compliance, or where required by Applicable Data Protection Laws or a supervisory authority, Cannvas shall allow for and contribute to audits, including inspections, of the Processing, subject to the following conditions:

(a) Customer provides at least [30] days' prior written notice, unless a shorter period is required by a regulator or by Applicable Data Protection Laws;

(b) audits occur no more than once in any twelve (12) month period, except (i) as required by a competent supervisory authority, or (ii) following a Security Incident affecting Personal Data;

(c) audits are conducted during Cannvas's regular business hours, in a manner that does not unreasonably disrupt Cannvas's operations, and in accordance with Cannvas's reasonable safety, security, and confidentiality requirements;

(d) audits do not require Cannvas to disclose or provide access to (i) the data or systems of any other customer, (ii) information subject to legal privilege or confidentiality obligations owed to third parties, or (iii) any internal accounting, pricing, or personnel information not relevant to the Processing;

(e) any third party conducting an audit is not a competitor of Cannvas and executes a confidentiality agreement reasonably acceptable to Cannvas; and

(f) Customer bears its own costs and any reasonable costs charged by Cannvas for time and resources expended in supporting the audit, except where the audit reveals a material breach by Cannvas of this DPA, in which case Cannvas shall bear its own reasonable costs of the audit.

11.4 Monitoring under the CCPA. The rights in this Section 11, together with the rights in Section 4.7, are intended to satisfy Customer's right under Applicable Data Protection Laws to take reasonable and appropriate steps to help ensure that Cannvas uses Personal Data in a manner consistent with Customer's obligations, and, where Cannvas is treated as a contractor, to monitor Cannvas's compliance no more than once every twelve (12) months.


12. Data Transfers

12.1 U.S.-only. The Service is designed to Process and store Personal Data within the United States, and the Parties do not intend for Personal Data to be transferred outside the United States. Cannvas shall not transfer Personal Data outside the United States without Customer's prior written consent, except to the extent any Sub-processor listed in Annex 3 provides incidental support functions from outside the United States, in which case Cannvas shall ensure appropriate contractual and technical safeguards consistent with this DPA and Applicable Data Protection Laws.

12.2 Change in law. If Applicable Data Protection Laws or the Parties' operations later require cross-border transfer mechanisms or additional safeguards, the Parties shall cooperate in good faith to implement them, and Section 16 (Changes) applies.


13. Liability

13.1 Each Party's liability arising out of or related to this DPA, whether in contract, tort, or under any other theory of liability, is subject to the exclusions and limitations of liability set forth in the MSA, and any reference in the MSA to a Party's aggregate liability applies to that Party's aggregate liability arising under both the MSA and this DPA taken together.

13.2 Nothing in this DPA limits or excludes any liability that cannot be limited or excluded under applicable law.


14. Term and Termination

14.1 Term. This DPA takes effect on the Effective Date and remains in effect for so long as Cannvas Processes Personal Data on behalf of Customer under the MSA, notwithstanding the expiration or termination of the MSA, until all Personal Data has been deleted or returned in accordance with Section 10.

14.2 Survival. The obligations that by their nature should survive termination, including Sections 4 (survival of restrictions with respect to retained Personal Data), 5, 9, 10, 11, 13, and this Section 14, survive termination or expiration of this DPA or the MSA.


15. Changes to this DPA; Legal Updates

15.1 Cannvas may amend this DPA from time to time as reasonably necessary to comply with Applicable Data Protection Laws or to reflect changes in the Service or Sub-processors, provided that no such amendment materially reduces the protections afforded to Personal Data under this DPA.

15.2 If either Party reasonably determines that a change in Applicable Data Protection Laws requires modification of this DPA, the Parties shall negotiate in good faith to amend this DPA to comply with such laws.

15.3 Material amendments will be communicated to Customer by a reasonable means (including email or in-Service notice) and, unless a shorter period is required by law, take effect no earlier than [30] days after notice.


16. Governing Law; Jurisdiction

16.1 This DPA is governed by, and construed in accordance with, the governing law and jurisdiction provisions set out in the MSA, which for reference are the laws of the State of Michigan, without regard to its conflict-of-laws principles, except to the extent Applicable Data Protection Laws require otherwise. *(Drafting note: confirm consistency with the MSA governing-law clause.)*


17. General

17.1 Entire agreement. This DPA, together with the MSA and the annexes hereto, constitutes the entire agreement of the Parties with respect to the Processing of Personal Data and supersedes any prior data processing terms between the Parties on that subject.

17.2 Severability. If any provision of this DPA is held invalid or unenforceable, the remaining provisions remain in full force and effect, and the invalid provision shall be reformed to the minimum extent necessary to make it enforceable while preserving its intent.

17.3 Notices. Notices under this DPA shall be given in accordance with the notice provisions of the MSA. Notices to Cannvas concerning this DPA may also be sent to [email protected] and to [NOTICE ADDRESS]. Notices to Customer may be sent to the administrative or security contact designated by Customer in its account or the MSA.

17.4 No third-party beneficiaries. Except as expressly provided in this DPA or required by Applicable Data Protection Laws, this DPA does not confer any rights on any third party.

17.5 Counterparts; electronic acceptance. This DPA may be executed in counterparts and by electronic signature, and may be accepted electronically (including by click-through, order-form reference, or continued use of the Service after notice), each of which is deemed an original and together constitute one instrument. If Customer has entered into the MSA and this DPA is incorporated by reference therein, this DPA is effective without a separate signature.


18. Signatures / Electronic Acceptance

Where a signed copy is used, the Parties execute this DPA as of the Effective Date.

Cannvas, LLC (d/b/a "Cannvas")

By: ______________________________

Name: ____________________________

Title: _____________________________

Date: _____________________________

CUSTOMER / ORGANIZATION

By: ______________________________

Name: ____________________________

Title: _____________________________

Date: _____________________________


Annex 1 — Details of Processing

A. Roles. Customer: Business/Controller. Cannvas: Service Provider/Processor.

B. Subject matter. Cannvas's Processing of Personal Data contained in Org Data in order to provide the Service under the MSA.

C. Nature and purpose of Processing. Hosting, storage, organization, retrieval, display, analysis, computation, transmission, backup, security, support, and deletion of Org Data for the purpose of providing the Cannvas B2B dashboard and related cannabis-industry planning, sales, inventory/production reflection, and compliance-support software, including reflecting data mirrored from state cannabis track-and-trace systems (e.g., METRC) and other Customer-designated sources. The Business Purpose is to provide, maintain, secure, support, and improve the Service for Customer, and the other Permitted Purposes set out in Section 4.5.

D. Duration of Processing. For the term of the MSA and until Org Data is returned or deleted in accordance with Section 10, plus any legally required retention period.

E. Frequency of Processing. Continuous and/or on a periodic/synchronization basis, as determined by Customer's configuration and use of the Service.

F. Categories of Data Subjects. Personal Data Processed under the Service may relate to the following categories of Data Subjects:

*(Note: The Service is a B2B tool. It is not designed to Process end-consumer/retail-purchaser personal information, and Customer should not upload such data except as contemplated by the Service.)*

G. Categories of Personal Data. The Personal Data Processed may include:

H. Sensitive / special categories. The Service is not intended to be used to Process, and Customer shall not submit, sensitive Personal Information or special categories of Personal Data (e.g., government identifiers, financial account numbers, health information, precise geolocation, biometric data, or information concerning protected characteristics), except to the limited extent inherently required by the state track-and-trace context and expressly supported by the Service. If Customer submits such data, Customer does so at its own risk and remains responsible for any additional legal requirements.

I. Retention. As set out in Section 10 and the MSA. Backup/archival copies are retained on a rolling basis and purged in the ordinary course.


Annex 2 — Technical and Organizational Security Measures

Cannvas maintains a security program that includes the following measures, as applicable to the Service and subject to Section 6.2 (evolving measures). *(Drafting note: confirm each measure reflects Cannvas's actual implementation before execution; remove or qualify any not yet in place.)*

1. Encryption.

2. Access controls and least privilege.

3. Authentication.

4. Logging and monitoring.

5. Network and application security.

6. Vendor / Sub-processor management.

7. Incident response.

8. Resilience, backup, and recovery.

9. Data minimization and deletion.

10. Organizational measures.


Annex 3 — Authorized Sub-processors

As of the Effective Date, Cannvas engages the following Sub-processors to Process Personal Data in connection with the Service. *(Drafting note: confirm entity names, functions, and processing locations before execution; update as the Sub-processor roster changes and provide notice under Section 7.4.)*

#Sub-processorFunction / Service ProvidedCategories of Personal DataProcessing Location
1Cloudflare, Inc.Application hosting/compute (Workers/Pages), content delivery network (CDN), edge security (WAF, DDoS mitigation, bot management), DNSAll categories of Personal Data transiting or hosted at the edge/compute layer; technical/log dataUnited States
2Supabase, Inc. (and its underlying cloud infrastructure provider)Managed database, storage, and authentication (identity/credential management)Identity/contact data, account/authentication data, business-transaction data, technical/log dataUnited States
3[EMAIL PROVIDER] *(e.g., transactional/notification email service — confirm)*Transactional and notification email delivery (e.g., invoices, restock/quote notifications)Identity/contact data (names, business email addresses) and message contentUnited States
4[ANALYTICS PROVIDER] *(e.g., product/usage analytics — confirm, or mark "None" if not used)*Product usage analytics, performance/diagnosticsTechnical/usage data; user/account identifiersUnited States

*(Drafting note: If any Sub-processor Processes data outside the United States, update the "Processing Location" column and address Section 12. If no analytics provider is used, remove row 4 and state "None.")*


End of DRAFT v0.1. *For attorney review only. Not legal advice. Not yet effective. Verify all statutory citations, bracketed placeholders, timelines, and Annex contents against current law and Cannvas's actual practices before use.*