Skip to main content

Data Processing Agreement

Last updated: February 2026

1. Parties & Scope

This Data Processing Agreement ("DPA") is entered into between MCC Operation Systems Inc. ("Processor") and the subscribing organization ("Controller") and forms part of the Terms of Service. This DPA governs the processing of personal data by MCC Systems on behalf of the Controller when using the MCC Systems OS field service management platform ("Service").

The Controller determines the purposes and means of processing personal data. The Processor processes personal data only on documented instructions from the Controller, except where required by applicable law.

2. Definitions

  • Personal Data: Any information relating to an identified or identifiable natural person, including employee names, contact details, GPS location data, work records, and customer information entered into the Service.
  • Processing: Any operation performed on Personal Data, including collection, storage, retrieval, use, disclosure, erasure, or destruction.
  • Sub-processor: Any third party engaged by the Processor to process Personal Data on behalf of the Controller.
  • Data Breach: A breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of Personal Data.

3. Categories of Data Processed

CategoryExamples
Employee DataNames, emails, phone numbers, addresses, work hours, GPS locations, certifications
Customer DataNames, emails, phone numbers, service addresses, payment history, communication records
Vendor/Contractor DataCompany names, contact details, tax IDs, banking information, compliance documents
Operational DataWork orders, estimates, invoices, photos, notes, schedules, route data
Device & Usage DataIP addresses, browser type, session data, activity logs

4. Processing Instructions

The Processor shall process Personal Data only in accordance with the Controller's documented instructions, which include: (a) providing the Service as described in the Terms of Service; (b) processing initiated by authorized users in their use of the Service; and (c) processing to comply with applicable laws. The Processor shall immediately inform the Controller if it believes an instruction violates applicable data protection legislation.

5. Security Measures

The Processor implements and maintains appropriate technical and organizational security measures, including:

  • Encryption of data in transit (TLS 1.2+) and at rest (AES-256)
  • Role-based access controls with multi-factor authentication options
  • Regular security assessments and vulnerability scanning
  • Automated backup procedures with point-in-time recovery
  • Network segmentation and firewall protection
  • Employee security training and background checks
  • Incident response procedures and breach notification protocols
  • Session management with automatic timeout and invalidation

6. Sub-processors

The Processor may engage sub-processors to assist in providing the Service. A current list of sub-processors is maintained at /website/subprocessors. The Processor will notify the Controller of any intended changes to sub-processors, providing the Controller an opportunity to object. The Processor ensures that sub-processors are bound by data protection obligations no less protective than those in this DPA.

7. Data Breach Notification

The Processor shall notify the Controller without undue delay (and in any event within 72 hours) upon becoming aware of a Data Breach affecting Personal Data. The notification shall include: (a) the nature of the breach; (b) categories and approximate number of affected individuals; (c) likely consequences; and (d) measures taken or proposed to address the breach.

8. Data Subject Rights

The Processor shall assist the Controller in fulfilling its obligations to respond to data subject rights requests under PIPEDA, including requests for access, correction, deletion, or portability of Personal Data. The Service provides built-in tools for data export and deletion to facilitate these requests.

9. Data Retention & Deletion

Upon termination of the Service agreement, the Processor shall, at the Controller's election, return or delete all Personal Data within 30 days, unless retention is required by applicable law. The Controller may export their data at any time during the term of the agreement using the platform's built-in export functionality. See our Data Retention Policy for details.

10. Audits

The Processor shall make available to the Controller all information necessary to demonstrate compliance with this DPA and allow for and contribute to audits conducted by the Controller or a mandated auditor, subject to reasonable notice and confidentiality obligations.

11. International Data Transfers

MCC Systems primarily stores and processes data within Canada. Where data is transferred to jurisdictions outside Canada (e.g., through sub-processors), MCC Systems ensures that adequate safeguards are in place in accordance with PIPEDA and any applicable cross-border data transfer requirements.

12. Contact

For DPA inquiries:

Email: privacy@mccsys.ca

Data Protection Officer: dpo@mccsys.ca