Last updated: February 2026
This Data Processing Agreement ("DPA") is entered into between MCC Operation Systems Inc. ("Processor") and the subscribing organization ("Controller") and forms part of the Terms of Service. This DPA governs the processing of personal data by MCC Systems on behalf of the Controller when using the MCC Systems OS field service management platform ("Service").
The Controller determines the purposes and means of processing personal data. The Processor processes personal data only on documented instructions from the Controller, except where required by applicable law.
| Category | Examples |
|---|---|
| Employee Data | Names, emails, phone numbers, addresses, work hours, GPS locations, certifications |
| Customer Data | Names, emails, phone numbers, service addresses, payment history, communication records |
| Vendor/Contractor Data | Company names, contact details, tax IDs, banking information, compliance documents |
| Operational Data | Work orders, estimates, invoices, photos, notes, schedules, route data |
| Device & Usage Data | IP addresses, browser type, session data, activity logs |
The Processor shall process Personal Data only in accordance with the Controller's documented instructions, which include: (a) providing the Service as described in the Terms of Service; (b) processing initiated by authorized users in their use of the Service; and (c) processing to comply with applicable laws. The Processor shall immediately inform the Controller if it believes an instruction violates applicable data protection legislation.
The Processor implements and maintains appropriate technical and organizational security measures, including:
The Processor may engage sub-processors to assist in providing the Service. A current list of sub-processors is maintained at /website/subprocessors. The Processor will notify the Controller of any intended changes to sub-processors, providing the Controller an opportunity to object. The Processor ensures that sub-processors are bound by data protection obligations no less protective than those in this DPA.
The Processor shall notify the Controller without undue delay (and in any event within 72 hours) upon becoming aware of a Data Breach affecting Personal Data. The notification shall include: (a) the nature of the breach; (b) categories and approximate number of affected individuals; (c) likely consequences; and (d) measures taken or proposed to address the breach.
The Processor shall assist the Controller in fulfilling its obligations to respond to data subject rights requests under PIPEDA, including requests for access, correction, deletion, or portability of Personal Data. The Service provides built-in tools for data export and deletion to facilitate these requests.
Upon termination of the Service agreement, the Processor shall, at the Controller's election, return or delete all Personal Data within 30 days, unless retention is required by applicable law. The Controller may export their data at any time during the term of the agreement using the platform's built-in export functionality. See our Data Retention Policy for details.
The Processor shall make available to the Controller all information necessary to demonstrate compliance with this DPA and allow for and contribute to audits conducted by the Controller or a mandated auditor, subject to reasonable notice and confidentiality obligations.
MCC Systems primarily stores and processes data within Canada. Where data is transferred to jurisdictions outside Canada (e.g., through sub-processors), MCC Systems ensures that adequate safeguards are in place in accordance with PIPEDA and any applicable cross-border data transfer requirements.
For DPA inquiries:
Email: privacy@mccsys.ca
Data Protection Officer: dpo@mccsys.ca