Data Processing AgreementEffective 15 September 2026Version 2.1 (Canadian)15 pages
SYSTEM SUPPORT CANADA INC.
Data Processing Agreement
Effective 15 September 2026 · Version 2.1 (Canadian) · Federally incorporated · Head office in Ontario
Effective 15 September 2026. This Data Processing Agreement supersedes and replaces all prior versions.
This Data Processing Agreement (the “DPA”) is between System Support Canada Inc., a corporation incorporated under the Canada Business Corporations Act with its head office in Ontario and carrying on business throughout Canada (“Provider”) and the client identified on the applicable Order (“Client”) and, together with the Order, the Master Services Agreement (the “MSA”), the Schedule of Services and the applicable Service Attachments, forms the Agreement between the parties. Capitalized terms not defined here have the meanings given in the MSA.
Modules apply only when named in the Order. Part 1 (General Terms) applies whenever Provider processes Personal Information on Client’s behalf. Parts 2 through 7 each apply only where the corresponding statute or regime is identified in the Order. No module binds Provider unless the Order names it.
PART 1 — GENERAL TERMS
Applies whenever Provider processes Personal Information on Client’s behalf.
1. ROLES, SCOPE AND INSTRUCTIONS
1.1 Roles. Client is the organization that determines the purposes for which and the means by which Personal Information is collected, used and disclosed, and is accordingly the “organization having control” of that Personal Information (and, where the terminology of an applicable statute or of Part 7 so requires, the “controller”, “custodian” or “health information custodian”). Provider processes Personal Information solely on Client’s behalf as a service provider (and, where that terminology applies, as a “processor”, “agent”, “service provider” or “person acting on behalf of” Client). Provider does not determine the purposes of the processing.
1.2 Instructions. Provider shall process Personal Information only (a) as necessary to deliver the Services described in the Order and the applicable Service Attachment, (b) in accordance with Client’s documented instructions, and (c) as required by applicable law. Provider shall promptly inform Client if, in Provider’s opinion, an instruction from Client would contravene applicable privacy law, and may suspend the affected processing until the instruction is confirmed or amended.
1.3 No secondary use. Provider shall not collect, use, disclose, retain or sell Personal Information for any purpose other than delivering the Services, and shall not combine Personal Information received from Client with Personal Information received from or on behalf of any other person, except in aggregated and de-identified form that does not identify Client or any individual and that is not reasonably capable of being used to re-identify any individual.
1.4 Statement of processing. The subject matter and duration of the processing, its nature and purpose, the categories of Personal Information and of individuals concerned, and the systems within which the processing occurs, are described in the Order, the applicable Service Attachment and the Schedule of Services, which together form the statement of processing for the purposes of this DPA.
1.5 Limiting collection. Provider shall limit the Personal Information it collects, accesses and retains to what is necessary for the purposes identified in the statement of processing, and shall configure the Services to that end where it is technically able to do so.
1.6 Client’s prerequisites. Client represents and warrants that (a) it has the authority to instruct Provider to process the Personal Information, (b) it has identified the purposes of the collection and given every notice and obtained every consent required of it by applicable law, (c) it has completed every assessment required of it before Personal Information is communicated to Provider or outside its province, and (d) its instructions to Provider comply with applicable law.
2. CONFIDENTIALITY AND PERSONNEL
2.1 Provider shall ensure that every person acting under its authority who has access to Personal Information is subject to a written duty of confidentiality that survives the end of that person’s engagement, and is trained on Provider’s information security programme and on the handling of Personal Information.
2.2 Provider shall limit access to Personal Information to those of its personnel who require it to deliver the Services, shall maintain role-based access controls, and shall revoke access promptly on a change of role or on the end of an engagement.
3. SAFEGUARDS
3.1 Provider maintains a written information security programme containing administrative, technical and physical safeguards appropriate to (a) the size, scope and nature of Provider’s business, (b) the resources available to Provider, (c) the volume and sensitivity of the information Provider holds, and (d) the risk of significant harm to the individuals concerned. The programme is designed to protect the confidentiality, integrity and availability of Personal Information and to protect against unauthorized or unlawful access, use, disclosure, alteration, loss and destruction.
3.2 The programme includes, using safeguards proportionate to risk:
(a) a mandatory security awareness and training programme for all personnel, including management;
(b) logical and physical access controls, including role-based access, unique named accounts and multi-factor authentication on remote and administrative access;
(c) encryption of Personal Information in transit over public networks and at rest, and full-disk encryption on every laptop and portable device used by Provider’s personnel and by any subcontractor accessing Personal Information;
(d) current anti-malware detection and prevention on devices used to access Personal Information, maintained on a supported release;
(e) a documented change and configuration management process, including risk-based security patching;
(f) audit logging and monitoring of access to systems holding Personal Information, and review of privileged access;
(g) a documented incident response plan assigning roles and responsibilities, and covering investigation, communication, record-keeping and root cause analysis;
(h) contingency planning, including scheduled backups and a documented and periodically tested recovery capability;
(i) secure disposal of media and tangible material containing Personal Information, so that it cannot practicably be read or reconstructed;
(j) a designated individual with overall responsibility for the programme; and
(k) periodic testing of key controls, and periodic vulnerability assessment of Provider’s own environment.
3.3 Programme review. Provider monitors, evaluates and adjusts the programme in light of relevant changes in technology, internal and external threats, applicable privacy and security law, and changes in Provider’s own business arrangements.
3.4 Description, not guarantee. This Section describes Provider’s programme and the safeguards it applies. It is not a warranty of any particular outcome, and Section 15.3 of the MSA continues to apply.
4. SUBCONTRACTORS AND SUB-PROCESSORS
4.1 General authorization. Client authorizes Provider to engage the subcontractors and third-party service providers identified in the Schedule of Third-Party Services, and any successor or replacement, to process Personal Information in delivering the Services.
4.2 Notice and objection. Provider shall give Client not less than thirty (30) days’ notice before engaging a new subcontractor that will process Personal Information, by updating the Schedule of Third-Party Services and notifying Client. Client may object on reasonable grounds relating to data protection within that period. Where Client objects, the parties shall discuss in good faith whether the Services can be delivered without the subcontractor; where they cannot, either party may terminate the affected Service on thirty (30) days’ notice without termination fee.
4.3 Flow-down. Provider shall enter into a written agreement with each subcontractor that processes Personal Information, imposing obligations of confidentiality, purpose limitation, safeguards, incident notification and return or destruction that are no less protective than those imposed on Provider under this DPA.
4.4 Responsibility. Provider remains responsible to Client for the performance of any subcontractor’s obligations in respect of the processing of Personal Information, subject to Section 18 of the MSA. Nothing in this Section makes Provider responsible for the acts or omissions of a Third-Party Service Provider engaged directly by Client, or for a service that Client purchases, enables or engages itself, to which Section 16 of the MSA applies.
4.5 Register. Provider maintains a register of subcontractors that process Personal Information, recording the purpose of the processing and the principal region in which it occurs, and shall make it available to Client on reasonable request.
5. CROSS-BORDER PROCESSING
5.1 Disclosure. Provider uses third-party platforms that store and process data outside Canada, principally in the United States and the European Union. Personal Information processed under the Agreement may be transferred to, stored in and accessed from those jurisdictions. While outside Canada, Personal Information may be subject to lawful access by the courts, law enforcement and government authorities of the jurisdiction concerned.
5.2 Comparable protection. Provider shall use contractual and other means to provide a comparable level of protection for Personal Information while it is being processed by a subcontractor, whether inside or outside Canada, having regard to the sensitivity of the information and the purposes of the processing.
5.3 Information for Client’s assessment. On reasonable request, Provider shall supply the information Client requires to complete a privacy impact assessment or an assessment of the privacy-related factors applicable to a communication of Personal Information outside its province, including the identity and location of each subcontractor, the categories of information processed, the purposes of the processing, and the vendor’s published security and certification documentation. Completing the assessment, and deciding whether the communication may proceed, remains Client’s responsibility.
5.4 Canada-only processing. Where Client requires that Personal Information be stored and processed only within Canada, that requirement must be stated in the Order. Provider will identify whether it can be met for each Service and any additional cost of meeting it.
6. INDIVIDUAL RIGHTS REQUESTS
6.1 Where Provider receives a request from an individual for access to, correction of, deletion of, or information about the processing of Personal Information, or a request to withdraw consent, Provider shall not respond substantively. Provider shall, without undue delay, (a) confirm receipt to the individual, (b) inform the individual that the request has been referred to Client, and (c) forward the request to Client. Responding to the request is Client’s responsibility.
6.2 Provider shall provide Client with reasonable assistance, having regard to the nature of the processing and the information available to Provider, in responding to a request under Section 6.1, including by searching for and retrieving Personal Information within systems Provider manages. Assistance beyond what is incidental to the Services is billable at Provider’s then-prevailing rates.
6.3 Where Client instructs Provider to correct, delete or restrict the processing of Personal Information, Provider shall give effect to that instruction within systems it manages, so far as it is technically able to do so, and shall confirm to Client what it has done.
6.4 Provider shall provide Client with reasonable assistance in responding to an inquiry, investigation or order of a privacy commissioner or other supervisory authority relating to Provider’s processing, unless Provider elects to respond to the authority directly, in which case it shall keep Client informed.
7. INCIDENTS AFFECTING PERSONAL INFORMATION
7.1 Notification to Client. Provider shall notify Client without undue delay, and in any event within seventy-two (72) hours after Provider confirms an incident involving the loss of, unauthorized access to, or unauthorized use or disclosure of Personal Information within systems Provider manages under an applicable Order.
7.2 Provider’s notification shall include, to the extent then known and as it becomes known: a description of the incident; the date or period of the incident and the date of Provider’s confirmation; the categories and approximate volume of Personal Information affected; the categories and approximate number of individuals affected; the cause, if known; the steps Provider has taken and proposes to take to contain and remediate the incident; and a contact at Provider from whom further information may be obtained.
7.3 Provider shall investigate the incident promptly and thoroughly, take reasonable steps to contain it and to mitigate its effects, preserve relevant evidence and logs, and cooperate with Client in Client’s own investigation.
7.4 Reporting and notification obligations are Client’s. Client is solely responsible for determining whether an incident gives rise to an obligation to report to a privacy commissioner or other authority, to notify affected individuals or third parties, or to record the incident in a register, and for discharging any such obligation. Provider shall not report or notify on Client’s behalf unless the Order or Client’s written instruction expressly requires it. Provider shall supply the technical facts Client reasonably requires in order to make that determination.
7.5 Provider maintains a record of incidents affecting Personal Information processed on Client’s behalf, and shall make the record relating to Client available to Client on request.
7.6 No admission. A notification under this Section is not an admission of fault or liability by Provider.
8. RETENTION, RETURN AND DESTRUCTION
8.1 Provider shall retain Personal Information only for as long as necessary to deliver the Services, together with any period required by applicable law or reasonably required for Provider to evidence its own compliance, and shall not extend a retention period without first notifying Client and providing a justification.
8.2 At Client’s election, and on termination or expiry of the Services to which the processing relates, Provider shall return Personal Information to Client in a commercially reasonable format, or securely destroy it, and shall destroy existing copies, except to the extent retention is required by applicable law or by Section 8.3.
8.3 Records Provider retains. Provider may retain (a) records evidencing Client’s instructions and authorizations, (b) records required to demonstrate Provider’s own compliance with this DPA or with an obligation Provider owes to a Third-Party Service Provider, and (c) backup copies until they expire in the ordinary course of Provider’s backup cycle. Provider shall continue to apply the safeguards in Section 3 to any Personal Information it retains, shall not use it for any other purpose, and shall destroy it when the retention purpose is discharged.
8.4 Thirty (30) days after termination of the Agreement, Provider has no obligation to maintain Client Data and shall, unless legally prohibited or permitted to retain it under Section 8.3, delete or securely destroy all Client Data in its possession or control. Provider shall certify destruction in writing on request.
9. DEMONSTRATING COMPLIANCE AND AUDIT
9.1 Provider shall make available to Client the information reasonably necessary to demonstrate Provider’s compliance with this DPA, including a description of its safeguards, its subcontractor register, its most recent independent audit or certification report where one exists, and the results of its most recent vulnerability assessment in summary form.
9.2 Audit. Client, or an independent auditor mandated by Client and not a competitor of Provider, may audit Provider’s compliance with this DPA not more than once in any twelve-month period, on not less than thirty (30) days’ written notice, during Provider’s business hours, in a manner that does not unreasonably disrupt Provider’s operations, and subject to the confidentiality obligations in Section 7 of the MSA. Client bears the cost of the audit and of Provider’s reasonable assistance at Provider’s then-prevailing rates. An audit may not extend to the data or environment of any other client of Provider.
9.3 Provider may satisfy an audit request by supplying a current independent third-party audit or certification report covering the relevant controls, and Client shall accept such a report where it reasonably addresses the matters Client wishes to verify.
9.4 Client may audit more frequently than Section 9.2 permits where required by a privacy commissioner or other authority with jurisdiction, or following an incident notified under Section 7 that affected Client.
9.5 An audit report and any information Provider supplies under this Section are Provider’s Confidential Information, and Client shall not disclose them except as permitted by Section 7 of the MSA.
10. INSURANCE, LIABILITY AND TERM
10.1 Insurance. In addition to Section 17 of the MSA, where the Order engages any of Parts 2 through 7, Client shall maintain privacy and cyber liability insurance of not less than two million dollars (CAD $2,000,000) per occurrence, covering costs arising from data destruction, unauthorized access, incident response and crisis management, and claims for privacy violation, together with breach notification and regulatory defence costs.
10.2 Liability. Provider’s liability under or in connection with this DPA is subject to Sections 18 and 19 of the MSA. Any obligation of Provider under this DPA to reimburse Client for a cost is subject to the limit in Section 18.2 of the MSA.
10.3 Term. This DPA takes effect on the effective date of the first Order engaging it and continues for so long as Provider processes Personal Information on Client’s behalf.
10.4 Termination for cause. Client may terminate this DPA and the Services to which it relates where Provider has committed a material breach of this DPA and has failed to cure it within thirty (30) days after written notice describing the breach. That period aligns with the cure period in Section 5.4 of the MSA and Section 20.5 of the Service Attachment for Managed Services.
10.5 Effect of termination. Section 8 governs the treatment of Personal Information on termination. Provider’s obligations under Sections 2, 3, 7.5, 8 and 9.5 survive termination.
10.6 Precedence. This DPA forms part of and is subject to the Agreement, except that where a term of this DPA conflicts with another term of the Agreement in respect of the processing of Personal Information, this DPA prevails, consistent with Section 2.1(b) of the MSA. Where a term of Parts 2 through 7 conflicts with Part 1, the more specific Part prevails in respect of the regime it addresses.
10.7 No third-party rights. Except as expressly stated in Part 7 in respect of the standard contractual clauses, this DPA confers no right on any person other than the parties.
PART 2 — PIPEDA
Applies where the Order identifies the Personal Information Protection and Electronic Documents Act (Canada).
11. PIPEDA MODULE
11.1 This Part documents the safeguards imposed on the parties in respect of Personal Information subject to the Personal Information Protection and Electronic Documents Act (“PIPEDA”). Where the Order identifies PIPEDA, this Part applies to Provider’s activities as an organization processing Personal Information on Client’s behalf.
11.2 Accountability. Client remains accountable for Personal Information transferred to Provider for processing. Provider shall use the Personal Information only for the purposes Client identifies and shall provide, through this DPA, a comparable level of protection to that which Client is required to provide.
11.3 The ten principles. Provider’s obligations under Part 1 are intended to support Client’s compliance with the fair information principles in Schedule 1 to PIPEDA, as follows: accountability (Sections 1.1, 4.4 and 9), identifying purposes (Sections 1.2 and 1.4), consent (Client’s responsibility under Section 1.6), limiting collection (Section 1.5), limiting use, disclosure and retention (Sections 1.3 and 8), accuracy (Section 6.3), safeguards (Section 3), openness (Sections 4.5 and 9.1), individual access (Section 6) and challenging compliance (Sections 6.4 and 9).
11.4 Breach of security safeguards. Where an incident notified under Section 7 constitutes a breach of security safeguards, Client is responsible for determining whether it creates a real risk of significant harm to an individual and, if so, for reporting the breach to the Privacy Commissioner of Canada, notifying affected individuals and any organization or government institution that may be able to reduce the risk, and maintaining the record of every breach of security safeguards that PIPEDA requires. Provider shall supply the technical facts Client requires for those purposes and shall maintain its own record under Section 7.5.
11.5 Openness to individuals. On Client’s request, Provider shall supply the information Client needs in order to make its policies and practices relating to the management of Personal Information available to individuals, including a general account of Provider’s use of subcontractors outside Canada.
PART 3 — ALBERTA PIPA
Applies where the Order identifies the Personal Information Protection Act (Alberta).
12. ALBERTA MODULE
12.1 This Part applies where the Order identifies the Personal Information Protection Act (Alberta) (“Alberta PIPA”), and applies to Provider’s activities as a service provider processing Personal Information on Client’s behalf.
12.2 Notice of service providers outside Canada. Client acknowledges that Provider uses service providers outside Canada, as described in Section 5.1 and identified in the Schedule of Third-Party Services. Where Alberta PIPA requires Client to notify individuals that it uses a service provider outside Canada, and to provide the way in which individuals may obtain information about Client’s policies and practices in respect of that use and the name or position of a person able to answer questions about it, Provider shall supply the information Client needs in order to give that notice. Giving the notice is Client’s obligation.
12.3 Written policies. Provider shall, on request, supply Client with a description of Provider’s policies and practices in respect of the collection, use, disclosure, storage and destruction of Personal Information outside Canada, in a form Client may use in responding to an individual’s inquiry.
12.4 Breach notification. Where an incident notified under Section 7 involves the loss of or unauthorized access to or disclosure of Personal Information, Client is responsible for determining whether a reasonable person would consider that there exists a real risk of significant harm to an individual and, if so, for giving notice to the Information and Privacy Commissioner of Alberta in the required form and for complying with any direction of the Commissioner to notify affected individuals.
12.5 Employee personal information. Where the Personal Information includes personal employee information, Client is responsible for having given the notice that Alberta PIPA requires before collecting, using or disclosing it without consent, and Provider shall process it only for the purposes Client identifies.
PART 4 — BRITISH COLUMBIA PIPA
Applies where the Order identifies the Personal Information Protection Act (British Columbia).
13. BRITISH COLUMBIA MODULE
13.1 This Part applies where the Order identifies the Personal Information Protection Act (British Columbia) (“BC PIPA”), and applies to Provider’s activities as a service provider processing Personal Information on Client’s behalf.
13.2 Safeguards and accuracy. Provider shall protect Personal Information in its custody or under its control by making reasonable security arrangements to prevent unauthorized access, collection, use, disclosure, copying, modification, disposal or similar risks, in accordance with Section 3, and shall assist Client in ensuring that Personal Information is accurate and complete for the purposes for which it is used.
13.3 Privacy management programme. Provider shall supply, on request, the information Client requires in order to develop and maintain its own privacy management programme, including a description of Provider’s safeguards, its subcontractors and its incident response process.
13.4 Breach notification. Where an incident notified under Section 7 involves unauthorized access to or disclosure of Personal Information, Client is responsible for determining whether it could reasonably be expected to result in significant harm to an individual and, if so, for notifying the Office of the Information and Privacy Commissioner for British Columbia and affected individuals as BC PIPA requires, and for maintaining the record of the incident that BC PIPA requires.
13.5 Employee personal information. Where the Personal Information includes employee personal information, Client is responsible for having given the notice BC PIPA requires, and Provider shall process it only for the purposes Client identifies.
PART 5 — QUEBEC (LAW 25)
Applies where the Order identifies the Act respecting the protection of personal information in the private sector (Quebec).
14. QUEBEC MODULE
14.1 This Part applies where the Order identifies the Act respecting the protection of personal information in the private sector (Quebec), as amended by the Act to modernize legislative provisions as regards the protection of personal information (commonly “Law 25”) (together, the “Quebec Act”), and applies to Provider’s activities as a person carrying out a mandate or performing a contract for services on Client’s behalf.
14.2 Mandate in writing. The Order, this DPA and the applicable Service Attachment together constitute the written mandate or contract for services required by the Quebec Act. They set out the measures Provider must take to protect the confidentiality of the Personal Information entrusted to it, to ensure it is used only for carrying out the mandate, and to prevent Provider from keeping it once the mandate is completed.
14.3 Privacy officer. Provider has designated a person responsible for the protection of Personal Information, whose title and contact details are published in Provider’s privacy policy and stated in Section 16. Client confirms that it has designated its own person responsible for the protection of Personal Information, whose contact details Client shall publish as the Quebec Act requires.
14.4 Assessment before communication outside Quebec. Client acknowledges that the Quebec Act requires it to conduct an assessment of privacy-related factors before communicating Personal Information outside Quebec, and to determine that the information will receive adequate protection in light of generally recognized principles regarding the protection of personal information. Provider shall supply the information Client requires for that assessment under Section 5.3, including the identity, location, security posture and certifications of each subcontractor. Conducting the assessment, recording its result and deciding whether the communication may proceed are Client’s responsibilities.
14.5 Confidentiality incidents. An incident notified under Section 7 that constitutes a confidentiality incident within the meaning of the Quebec Act shall be notified to Client with diligence and in any event within the seventy-two (72) hour period in Section 7.1. Client is responsible for determining whether the incident presents a risk of serious injury to a person, and if so for notifying the Commission d’accès à l’information and the persons concerned with diligence, for notifying any other person able to reduce the risk, and for maintaining the register of confidentiality incidents that the Quebec Act requires. Provider maintains its own record under Section 7.5 and shall supply the entries relating to Client on request.
14.6 Automated decisions. Where a Service uses Personal Information to render a decision based exclusively on automated processing, Client is responsible for informing the person concerned at or before the time of the decision, for providing on request the Personal Information used, the reasons and principal factors leading to the decision and the person’s right to have it corrected, and for giving the person an opportunity to submit observations to a member of Client’s personnel able to review the decision. Provider shall supply the technical information Client requires for those purposes.
14.7 Biometric information. Client shall not instruct Provider to create or use a database of biometric characteristics or measurements, or to implement a system using biometric identification or verification, unless the Order expressly provides for it. Client is responsible for obtaining the express consent of each person concerned and for making any disclosure to the Commission d’accès à l’information that the Quebec Act requires, within the time it requires.
14.8 Portability and destruction. Provider shall, on Client’s instruction, and so far as it is technically able, supply computerized Personal Information in a structured, commonly used technological format so that Client may respond to a request for portability, and shall destroy Personal Information on completion of the mandate in accordance with Section 8.
14.9 French language. Section 22.12 of the MSA applies to this DPA. Where Client is situated in Quebec, Provider shall make a French-language version of this DPA available to Client before it is agreed to, and any client-facing privacy notice Provider implements on Client’s instruction shall be implemented in French, and in any other language Client directs, in accordance with the Charter of the French Language.
PART 6 — PERSONAL HEALTH INFORMATION
Applies where the Order identifies the health privacy legislation of any province or territory.
15. HEALTH INFORMATION MODULE
15.1 Application. This Part applies where the Order identifies the Personal Health Information Protection Act, 2004 (Ontario) (“PHIPA”) and its regulations, or the health privacy legislation of another province or territory, including the Health Information Act (Alberta), the Health Information Protection Act (Saskatchewan), the Personal Health Information Act of Manitoba, New Brunswick, Nova Scotia, Newfoundland and Labrador or Prince Edward Island, the E-Health (Personal Health Information Access and Protection of Privacy) Act (British Columbia), or, in Quebec, the Act respecting health services and social services read with the Act respecting the protection of personal information in the private sector. Where legislation other than PHIPA applies, this Part is to be read with the corresponding terminology and obligations of that legislation, and the Order shall identify the governing statute.
15.2 Roles. Client is the health information custodian. Provider acts either (a) as an agent of Client, where Provider collects, uses, discloses, retains or disposes of personal health information on Client’s behalf and in accordance with Client’s authorization, or (b) as a health information network provider, where Provider supplies services to two or more custodians primarily to enable them to use electronic means to disclose personal health information to one another. The Order shall state which role applies. Provider is not itself a health information custodian in respect of personal health information it handles for Client.
15.3 A HIPAA business associate agreement is not used. The parties acknowledge that the Health Insurance Portability and Accountability Act of the United States does not apply to Client, and that a business associate agreement under that statute would not satisfy the written agreement requirements of PHIPA. This Part replaces any such agreement.
Provider as agent
15.4 Where Provider acts as Client’s agent, Provider shall:
(a) collect, use, disclose, retain and dispose of personal health information only as necessary in the course of delivering the Services, only as permitted by Client’s written authorization, and only as PHIPA permits or requires;
(b) not collect, use, disclose, retain or dispose of personal health information if Client itself could not do so;
(c) not use personal health information for any purpose other than delivering the Services, and not disclose it to any person except as Client directs or as required by law;
(d) take steps that are reasonable in the circumstances to ensure that personal health information is protected against theft, loss and unauthorized use or disclosure, and that records are protected against unauthorized copying, modification or disposal, in accordance with Section 3;
(e) notify Client at the first reasonable opportunity where personal health information is stolen, lost, used or disclosed without authority, or where records are copied, modified or disposed of without authority, and in any event within the period in Section 7.1;
(f) assist Client in responding to a request from an individual for access to or correction of a record of personal health information, in accordance with Section 6; and
(g) return or securely dispose of personal health information as Client directs on completion of the Services, in accordance with Section 8, and provide a certificate of secure disposal on request.
15.5 Client’s obligations as custodian. Client shall (a) authorize Provider in writing to collect, use, disclose, retain or dispose of personal health information, and specify the limits on that authorization, (b) notify Provider of any restriction, withdrawal of consent or lockbox instruction that affects Provider’s handling of personal health information, (c) maintain its own information practices, privacy notice and statement describing its use of agents, and (d) determine whether an incident requires notification to individuals or to the Information and Privacy Commissioner of Ontario, and give any notification required. Provider shall not notify an individual, the Commissioner or a College on Client’s behalf unless Client instructs it in writing to do so.
Provider as health information network provider
15.6 Where the Order states that Provider acts as a health information network provider, Provider shall, in addition to Section 15.4:
(a) notify every applicable custodian at the first reasonable opportunity of any unauthorized use, disclosure or handling of personal health information;
(b) provide each custodian with a plain-language description of the services it provides, including a general description of the safeguards it has in place to protect against unauthorized use and disclosure and to protect the integrity of the information, in a form suitable for the custodian to share with individuals;
(c) make available to each custodian, on request, a written description of the administrative, technical and physical safeguards it maintains;
(d) perform and provide to each custodian, on request, an assessment of the services respecting threats, vulnerabilities and risks to the privacy of individuals and the confidentiality, integrity and availability of personal health information;
(e) keep, and make available to each custodian on request, an electronic record of all accesses to personal health information held on the equipment Provider controls, setting out the person accessing it and the date and time of access;
(f) keep, and make available to each custodian on request, an electronic record of all transfers of personal health information by means of the equipment Provider controls, setting out the person transferring it and the destination and the date and time of transfer; and
(g) not use personal health information except as necessary in the course of providing the services, and not disclose it.
15.7 No de-identification or secondary use. Provider shall not de-identify, aggregate, analyze or otherwise use personal health information for its own purposes, including for research, benchmarking or service improvement, and the licence in Section 1.3 does not extend to personal health information.
15.8 Location of personal health information. Personal health information shall be stored and processed only in the locations stated in the Order. Client acknowledges that any requirement for storage within Canada or within a particular province must be stated in the Order in accordance with Section 5.4, and that Provider may not be able to deliver every Service subject to such a requirement.
PART 7 — GDPR
Applies where the Order identifies the General Data Protection Regulation or the UK GDPR.
16. GDPR MODULE
16.1 Application. This Part applies where the Order identifies Regulation (EU) 2016/679 (the “GDPR”) or the United Kingdom General Data Protection Regulation as retained in UK law together with the Data Protection Act 2018 (the “UK GDPR”). It applies to Provider’s activities as a processor of Personal Data on Client’s behalf. Capitalized terms used in this Part and not otherwise defined have the meanings given in Article 4 of the GDPR.
16.2 Processor obligations. Provider shall comply with the obligations of a processor under Article 28 of the GDPR. Sections 1.2, 2, 3, 4, 6, 7 and 8 of this DPA are the terms by which Provider does so, and shall be read as follows for the purposes of this Part: Section 1.2 gives effect to Article 28(3)(a); Section 2 to Article 28(3)(b); Section 3 to Articles 28(3)(c) and 32; Section 4 to Articles 28(2) and 28(4); Section 6 to Article 28(3)(e); Section 7 to Articles 28(3)(f), 33 and 34; and Section 8 to Article 28(3)(g).
16.3 Article 32 measures. Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of the processing, as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, Provider shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including as appropriate the pseudonymization and encryption of Personal Data, the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems, the ability to restore availability and access to Personal Data in a timely manner following an incident, and a process for regularly testing, assessing and evaluating the effectiveness of those measures.
16.4 Assistance with assessments. Taking into account the nature of the processing and the information available to it, Provider shall provide Client with reasonable assistance in respect of data protection impact assessments under Article 35 and prior consultation under Article 36. Assistance beyond what is incidental to the Services is billable at Provider’s then-prevailing rates.
16.5 Records and unlawful instructions. Provider shall maintain the records required by Article 30(2) and shall make those relating to Client available to Client on request. Provider shall immediately inform Client if, in its opinion, an instruction infringes the GDPR or other applicable data protection law.
16.6 Audit. Section 9 governs audits under Article 28(3)(h), including the once-per-twelve-month limit, the notice period, the allocation of cost and Provider’s right to satisfy a request with an independent third-party report.
International transfers
16.7 Standard contractual clauses. Where Provider processes Personal Data subject to the GDPR outside the European Economic Area in a country not benefiting from an adequacy decision, the parties shall enter into the standard contractual clauses adopted by the European Commission in Implementing Decision (EU) 2021/914, Module Two (controller to processor), which are incorporated into this DPA by reference and completed as follows:
(a) Client is the data exporter and Provider is the data importer;
(b) the optional docking clause in Clause 7 applies;
(c) for the purposes of Clause 9, Option 2 (general written authorization) applies, and the notice period for changes to sub-processors is the thirty (30) day period in Section 4.2 of this DPA;
(d) the optional redress clause in Clause 11(a) does not apply;
(e) for the purposes of Clause 17, these clauses are governed by the law of Ireland, being the law of a European Union Member State that allows for third-party beneficiary rights;
(f) for the purposes of Clause 18(b), the courts of Ireland shall resolve any dispute arising from these clauses; and
(g) Annexes I, II and III are completed by the statement of processing in Section 1.4, the description of safeguards in Section 3, and the subcontractor register in Section 4.5 respectively.
16.8 United Kingdom. Where Provider processes Personal Data subject to the UK GDPR outside the United Kingdom in a country not covered by UK adequacy regulations, the parties shall enter into the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the Information Commissioner’s Office, which is incorporated by reference and applies to the clauses described in Section 16.7 with the modifications that Addendum requires. Table 4 of that Addendum is completed by selecting neither party as entitled to end the Addendum.
16.9 Government access requests. Provider shall, unless prohibited by law, notify Client of any legally binding request from a public authority for disclosure of Personal Data, shall challenge a request that it considers unlawful, shall disclose only the minimum required, and shall document its assessment of the request. Provider shall notify Client if it becomes subject to a law that prevents it from complying with this DPA.
16.10 Allocation of compliance. Provider shall comply with the data protection laws applicable to it in its role as a processor. Provider is not responsible for complying with laws applicable to Client as a controller or to Client’s industry, and Client shall comply with all such laws. Assistance Provider gives Client with Client’s own compliance obligations is billable at Provider’s then-prevailing rates.
16.11 Defence of claims. Where Provider faces an actual or potential claim arising out of or relating to a violation of an obligation under the GDPR concerning the Services, including a claim under Article 82, Client shall promptly provide the materials and information Provider reasonably requests that are relevant to the defence of the claim and to the circumstances giving rise to it.
17. PROVINCIAL VARIATIONS
17.1 Multi-province clients. Provider carries on business across Canada. Where Client operates in more than one province or territory, the Order shall identify the privacy legislation applicable to each category of Personal Information processed, and the corresponding Part of this DPA applies to that category. Where more than one regime is identified, each applies to the Personal Information within its scope, and the more protective obligation governs where they overlap.
17.2 Federal and provincial interaction. PIPEDA applies to Personal Information collected, used or disclosed in the course of commercial activity in a province that has not enacted substantially similar legislation, and to Personal Information that crosses a provincial or national border. Alberta PIPA, BC PIPA and the Quebec Act apply to activity within those provinces. Part 2 applies by default; Parts 3, 4 and 5 apply in addition where the Order identifies them.
17.3 Quebec external clauses. Section 23.3 of the MSA applies to this DPA. Where Client is domiciled in Quebec, Provider shall expressly bring this DPA and each applicable Part to Client’s attention before the Order is signed, and shall deliver a copy of each.
17.4 Data residency by province. Where the legislation of Client’s province, a regulator, a professional college or Client’s own policy requires that Personal Information be stored or processed within Canada or within a particular province, that requirement must be stated in the Order. Provider will identify whether it can be met for each Service and any additional cost of meeting it. Section 15.8 applies to personal health information.
18. CONTACT AND PRIVACY OFFICER
System Support Canada Inc.
[Street address, City, Ontario, Postal Code]Attention: Privacy Officer / Personne responsable de la protection des renseignements personnels
Email: [[email protected]] Telephone: [ ]
Notices under this DPA shall be given in accordance with Section 22.3 of the MSA.
19. MODULES REMOVED FROM THE PREVIOUS VERSION
For the avoidance of doubt and to assist counsel reviewing the change, the following modules contained in the version of this document dated 7 July 2026 have been removed, on the basis that they addressed United States law that does not apply to Provider or to Provider’s Canadian client base, and that a defective or unused module creates risk without corresponding benefit:
| REMOVED MODULE | REPLACED BY |
|---|---|
| HIPAA business associate agreement | Part 6 (PHIPA and comparable provincial health privacy legislation) |
| Gramm-Leach-Bliley Act | Part 1 and Part 2, together with the regulated-environment standards in the Service Attachment |
| DoD CUI, CMMC and DFARS | Removed. Reinstate by separate addendum only if Provider takes on a United States defence supply chain client |
| California Consumer Privacy Act / CPRA | Removed. Part 1 and Part 2 govern Canadian processing |
| Colorado Privacy Act | Removed |
| Connecticut Data Privacy Act | Removed |
| New York SHIELD Act | Section 3 (safeguards), which carries forward the substance of the security programme description |
| Virginia Consumer Data Protection Act | Removed |
Where a Client is subject to a United States federal or state privacy regime, Provider will prepare a specific addendum for that engagement rather than reinstating a general module.
Master Services AgreementEffective 15 September 2026Version 2.1 (Canadian)19 pages
SYSTEM SUPPORT CANADA INC.
Master Services Agreement
Effective 15 September 2026 · Version 2.1 (Canadian)
Effective 15 September 2026. This Master Services Agreement supersedes and replaces all prior versions.
This Master Services Agreement (the “MSA”) is between System Support Canada Inc., a corporation incorporated under the Canada Business Corporations Act with its registered and head office in the Province of Ontario (“Provider”), and the client identified on the applicable quotation, estimate, statement of work, proposal or order (the “Order” and the “Client”). The Order, this MSA, the applicable Service Attachments, the Schedule of Services, the Schedule of Third-Party Services and, where engaged, the Data Processing Agreement together form the agreement between the parties (the “Agreement”).
Client accepts the Agreement by signing an Order, by instructing Provider to commence the Services, or by continuing to receive the Services after being notified of a change to these terms.
1. STATEMENT OF SERVICES
1.1 The services to be delivered by Provider (the “Services”), the fees for those Services, and the specific terms applicable to them are described in the Order or in one or more Service Attachments referencing this Agreement.
1.2 Provider may decline to perform any service requested by Client that would contravene applicable law, that falls outside the range of services Provider ordinarily provides, or that Provider reasonably considers would expose it to disproportionate risk.
1.3 Business-to-business agreement. The Services are supplied to organizations for business purposes. Client confirms that it is not acquiring the Services for personal, family or household purposes, and the parties agree that this Agreement is not a consumer agreement within the meaning of Ontario consumer protection legislation or comparable legislation of any other province.
1.4 Independent contractor. Provider performs the Services solely as an independent contractor and not as an employee, partner, joint venturer, agent or representative of Client, except where Client expressly appoints Provider as its agent under a Service Attachment for the purpose of procuring third-party services.
1.5 Provider’s status. Provider is a corporation incorporated under the Canada Business Corporations Act, is in good standing, and maintains its registered office and head office in the Province of Ontario. Provider’s corporate name is protected across Canada by virtue of its federal incorporation.
1.6 Operations across Canada. Provider carries on business throughout Canada and delivers the Services to Clients located in any province or territory, whether remotely or on site. Provider represents that it is, or before commencing Services in a province or territory will become, registered, licensed or otherwise authorized to carry on business extra-provincially in each province and territory in which such registration is required by reason of its activities there, and that it will maintain that authorization for so long as it carries on business there.
1.7 Client location does not alter the Agreement. The province or territory in which Client is located, in which the Services are delivered, or in which Client’s systems or personnel are situated does not alter the governing law or the forum for disputes set out in Section 20, except to the extent provided in Section 23 (Provincial Variations) or required by a rule of law that the parties cannot contract out of.
2. ORDER OF PRECEDENCE
2.1 In the event of a conflict or inconsistency among the documents comprising the Agreement, precedence is as follows:
(a) a written amendment signed by authorized representatives of both parties;
(b) the Data Processing Agreement, in respect of the processing of Personal Information only;
(c) the Order;
(d) the applicable Service Attachment;
(e) this MSA; and
(f) the Schedule of Services and the Schedule of Third-Party Services.
2.2 Protected provisions. Notwithstanding Section 2.1, the provisions of this MSA addressing LIMITATION OF LIABILITY, INDEMNIFICATION, INTELLECTUAL PROPERTY, PROVIDER WORKS, NON-DISCLOSURE AND CONFIDENTIALITY, and DISPUTE RESOLUTION prevail over any inconsistent term contained in an Order, Service Attachment or Schedule, unless that term is contained in a written amendment signed by authorized representatives of both parties that expressly identifies the section of this MSA being modified.
3. FEES AND PAYMENT
3.1 Currency. All fees and amounts stated in the Agreement are in Canadian dollars unless the Order expressly states another currency.
3.2 Fees for Services are set out in an Order. Unless otherwise stated in writing, Services are performed on a time-and-materials basis at Provider’s then-current rates.
Adjustments to fees
3.3 Increased or revised usage. Provider may adjust fees to reflect revised or increased usage or Services as described in the Order or applicable Service Attachment.
3.4 Statutory and regulatory charges. Provider may adjust its rates, or impose additional charges, to recover amounts that Provider is required or permitted by any governmental or regulatory authority to collect from others or to pay in support of statutory or regulatory funds or programs, including any contribution payable in respect of telecommunications services.
3.5 Rate increases. Provider may increase the fees charged under an Order. Where an increase exceeds ten percent (10%) in any twelve-month period, Provider will give Client not less than thirty (30) days’ written notice. Within thirty (30) days after receiving that notice, Client may terminate the affected Order without incurring any termination fee that would otherwise apply.
Payment
3.6 Payment deadline and interest. Client shall pay the full amount of each invoice on or before the due date stated in the invoice (the “Payment Deadline”). Client shall pay interest on all amounts not paid by the Payment Deadline at the rate of one and one-half percent (1.5%) per month, being eighteen percent (18%) per annum, or the maximum rate permitted by applicable law, whichever is less, calculated and compounded monthly from the Payment Deadline until paid in full.
3.7 Disputed amounts. If Client disputes an invoiced amount in good faith, Client shall notify Provider in writing before the Payment Deadline, describing the nature and basis of the dispute. Client shall pay the undisputed portion of the invoice by the Payment Deadline, and shall pay the disputed portion within ten (10) business days after the dispute is resolved. Where Provider determines that an amount ought not to have been charged, Provider shall credit that amount against fees owing for the following month.
3.8 Special rates apply to Services requested outside normal business hours. After-hours Services are charged at one and one-half (1.5) times Provider’s normal hourly rates and holiday Services at two (2) times those rates, in each case with a one-hour minimum.
3.9 Taxes. All fees are exclusive of goods and services tax, harmonized sales tax, Quebec sales tax, provincial sales tax and any other applicable tax or duty. Client shall pay all such amounts in addition to the fees, or shall provide Provider with a valid exemption certificate.
3.10 Reimbursable expenses. Client shall reimburse Provider’s reasonable out-of-pocket expenses incurred in performing the Services, including incremental third-party service fees, travel, mileage at Provider’s then-current rate, parking, lodging and meals.
3.11 No set-off. Client shall make all payments without set-off, deduction, counterclaim or withholding of any kind.
3.12 Client delay. If Provider is unable to commence delivery of the Services on the service start date because of any act or omission of Client, including failure to provide timely access to Client’s premises, personnel, systems or credentials, Client nonetheless begins to incur fees on that date and shall pay them in accordance with the Order.
3.13 Collection costs. In addition to all amounts owing, Client shall pay on demand all costs and expenses of collection and enforcement incurred by Provider, including reasonable legal fees on a full indemnity basis, court costs, collection agency fees, the cost of registrations and searches under the Personal Property Security Act (Ontario) or comparable provincial legislation, service of process, investigation, pre-judgment and post-judgment interest, and the costs of any appeal, arbitration, insolvency or bankruptcy proceeding, whether incurred before, during or after proceedings or after judgment.
4. SUSPENSION OF SERVICE
4.1 If Client fails to pay any amount owing under the Agreement when due, then upon not less than ten (10) business days’ prior written notice, and in addition to any other remedy available to it, Provider may suspend the Services.
4.2 Following suspension and after Client has paid all amounts owing, Provider may restore the Services once it has validated that all components to be monitored or managed under the applicable Order or Service Attachment comply with Provider’s standards for security, updates and configuration. Client shall pay a reactivation fee equal to one month of the recurring Service Fees for that restoration.
4.3 Client access to its own information preserved. Provider shall not withhold from Client, on account of non-payment, (a) Client Data, (b) individual user credentials, or (c) administrative credentials for accounts, tenancies or systems owned or licensed by Client. Provider’s remedies for non-payment are those set out in Sections 3, 4.1 and 12.
4.4 Provider’s right to suspend under this Section is in addition to its right to terminate under Section 12.
5. TERM AND TERMINATION
5.1 This MSA commences on the effective date of the first Order and continues until terminated in accordance with this Section.
5.2 Either party may terminate this MSA on not less than thirty (30) days’ advance written notice to the other. Termination of this MSA does not by itself terminate any Order or Service Attachment, and this MSA continues to govern each Order and Service Attachment until that Order or Service Attachment expires or is terminated according to its terms.
5.3 Off-boarding. Cancellation, termination or transition of the Services to Client’s control or to another service provider (“Off-Boarding”) may require a separate billable project. Off-Boarding is subject to a separate Order billed at Provider’s then-prevailing rates. Client shall also pay all remaining third-party service fees and any third-party termination charges arising from the Off-Boarding.
5.4 Termination for cause. Either party may terminate the Agreement immediately on written notice if the other party (a) commits a material breach and fails to cure it within thirty (30) days after written notice describing the breach, (b) becomes insolvent, makes a proposal or assignment in bankruptcy, has a receiver or trustee appointed over a substantial part of its property, or takes or suffers any similar step under the Bankruptcy and Insolvency Act or the Companies’ Creditors Arrangement Act, or (c) ceases to carry on business.
5.5 Provider may terminate the Agreement immediately on written notice where Client uses the Services for any unlawful purpose, or engages in conduct that is abusive or threatening toward Provider’s personnel.
6. INTELLECTUAL PROPERTY
6.1 Provider property. Provider retains all right, title and interest in and to (a) the Services and their components, (b) all software, tools, scripts, templates, methodologies, processes, know-how, calculation algorithms, analytical routines, network and system designs, hardware and software configurations, and documentation used by Provider to deliver the Services, and (c) any writing or work of authorship, in any medium, created or developed by Provider in the course of performance under the Agreement that is derived from or related to any of the foregoing (each, a “Provider Work”). No Provider Work is a work made for hire. To the extent any Provider Work is for any reason determined not to be owned by Provider, Client irrevocably assigns to Provider all of its right, title and interest in it, including copyright, patent, trade secret and all other proprietary rights, and waives in favour of Provider all moral rights it or its personnel may have in it.
6.2 Licence to Provider Works. Where a Provider Work resides on equipment owned by Client, Provider grants Client a non-exclusive, non-transferable, revocable, royalty-free licence to use that Provider Work during the term of the Agreement for Client’s internal business purposes only. That licence terminates automatically, without notice, on termination or expiry of the applicable Services or the Agreement.
6.3 Client property and Deliverables. Client retains all right, title and interest in and to (a) Client Data, (b) all material Client supplies to Provider, and (c) each item expressly identified in an Order as a deliverable owned by Client (a “Deliverable”). Title to a Deliverable passes to Client on Provider’s receipt of payment in full for it. Until then, Client has a licence to use the Deliverable for its internal business purposes only.
6.4 Reconciliation. A Deliverable does not include any Provider Work embedded in or required to operate it. Where a Deliverable incorporates a Provider Work, Client receives the licence in Section 6.2 in respect of that Provider Work and does not acquire ownership of it.
6.5 Residual rights. Nothing in the Agreement restricts Provider’s right to use the general knowledge, skills, experience, ideas, concepts and techniques acquired in the course of performing the Services, or to develop, use and supply services and materials that are similar to or compete with any Deliverable, provided Provider does not use Client’s Confidential Information in doing so.
6.6 Client shall not, and shall not permit any third party to: modify, copy, translate or create derivative works based on the Services or any Provider Work; build a product or service using the ideas, features, functions or graphics of the Services; frame or mirror any part of the Services other than on Client’s own intranet for its internal business purposes; rent, sell, lease, sublicense or otherwise make the Services available to any third party or use them for the benefit of any third party; remove or obscure any proprietary notice; or reverse assemble, decompile, disassemble or otherwise attempt to derive source code or underlying proprietary information from the Services, except to the extent that activity cannot lawfully be prohibited.
6.7 No liability for Client’s use. Provider is not liable for any claim arising from Client’s use of a Deliverable, of work in progress, or of any music, image, footage or other component comprising a Deliverable, after termination of the Agreement or otherwise outside the scope for which it was supplied.
7. NON-DISCLOSURE AND CONFIDENTIALITY
7.1 In the course of performance, either party may be exposed to or acquire the other’s proprietary or confidential information (“Confidential Information”). Each party shall hold the other’s Confidential Information in strict confidence, shall use it only for the purposes of the Agreement, shall protect it with at least the degree of care it applies to its own confidential information of like importance, and shall not disclose it to any third party except to those of its personnel and professional advisers who need it for those purposes and who are bound by obligations of confidentiality no less protective than this Section.
7.2 Confidential Information includes, without limitation:
(a) of Provider: Provider’s unpublished prices and rates, audit and security reports, network and server configuration designs, firewall and other hardware configurations, credentials, business plans, technical information and data, product ideas, methodologies, calculation algorithms, analytical routines and other proprietary technology;
(b) of Client: Client Data, and content transmitted to, from or stored on systems operated or managed by Provider for Client; and
(c) of both parties: information conspicuously marked “confidential”, or identified as confidential at the time of disclosure where disclosed in non-tangible form.
7.3 Confidential Information does not include information that: is or becomes available to the public without fault of the recipient; was in the recipient’s possession at the time of disclosure and was not acquired directly or indirectly from the disclosing party; is received from a third party entitled to disclose it without restriction; or is independently developed by the recipient without use of the disclosing party’s Confidential Information.
7.4 Compelled disclosure. A party may disclose Confidential Information to the extent required by applicable law, court order, subpoena or regulatory requirement, provided that, unless prohibited by law, it gives the other party prompt written notice so that the other party may seek a protective order, and discloses only the minimum required.
7.5 Agreement confidentiality. Neither party shall disclose the Order, this MSA, any Service Attachment or Schedule, or the discussions, negotiations, terms or conditions relating to any of them, to any third party without the prior written consent of the other party, except as required by legal, accounting or regulatory obligation or as permitted by Section 7.4.
7.6 Each party’s obligations under this Section survive termination or expiry of the Agreement and continue for so long as the information retains its confidential character.
8. CLIENT OBLIGATIONS
8.1 Assistance. Client shall provide, in a timely and professional manner and at no cost to Provider, the cooperation, complete and accurate information and data, equipment, access to computing and telecommunications facilities, networks, firewalls, servers, programs, files, documentation, credentials, a suitable work environment and other resources reasonably requested by Provider to enable it to perform the Services (collectively, “Assistance”). Assistance includes designating a representative with authority to make decisions and give approvals on Client’s behalf. Provider is not liable for any deficiency in the Services to the extent it results from Client’s failure to provide Assistance.
8.2 Access. Client shall provide Provider with broadband internet access, secure remote access to covered equipment by virtual private network or comparable means, appropriate cabling, adequate power and surge protection, appropriate environmental conditions for covered equipment as specified by the applicable manufacturer, and convenient and timely physical access to covered equipment together with adequate working space. Client may be required to perform preliminary diagnostic steps or supply additional information before a technician is dispatched.
8.3 Remote access consent. Client grants Provider the right to access Client’s systems remotely, using the remote access and remote monitoring and management software Provider deems necessary, for the purpose of delivering the Services, without the need to obtain express permission on each occasion. Provider shall maintain a record of remote access sessions and shall make that record available to Client on reasonable request. Client is responsible for ensuring that its own electronic monitoring policy, where one is required under Part XI.1 of the Employment Standards Act, 2000 (Ontario) or comparable legislation, accurately describes this access.
8.4 Software licensing. Client represents and warrants that it holds title to, or a valid licence or right to use and to permit Provider to use, access and modify, all software that Client asks Provider to use, access or modify as part of the Services. Client is solely responsible for ensuring that all software in its environment is properly licensed and for maintaining records of its licences. Provider will not promote the use of, or knowingly support, software that is not properly licensed. Assistance with software audits or licensing compliance is billable at Provider’s then-prevailing rates.
8.5 Independent backup. Unless expressly agreed otherwise in an Order or Service Attachment, Client shall maintain an independent backup of all files sent to any cloud or data backup service, with copies stored off-site, and is responsible for verifying that backups are performed and for verifying their integrity. Provider is not liable for data loss, backup software failure, backup selection, backup hardware or media failure, or backup system failure, even where Provider was engaged to perform the backups, except to the extent the loss is caused by Provider’s negligence or wilful misconduct.
8.6 Physical security. Client is responsible for the physical security of its premises and of its on-premises hardware and software systems.
8.7 Notification. Client shall promptly notify Provider of any security incident, suspected unauthorized access, system malfunction, non-conforming Service, or planned material change to its environment.
9. SECURITY, MALICIOUS EVENTS AND THIRD-PARTY CRIMINAL ACTIVITY
9.1 Allocation of responsibility. Unless expressly agreed otherwise in an Order, Client is responsible for determining what measures are necessary to secure its data and voice networks and circuits from unauthorized access. A vendor-supported hardware firewall must be in place and wireless traffic must be securely encrypted. Client has an affirmative obligation to protect its network environment and to train its personnel in respect of spam, malware, phishing and social engineering.
9.2 Where security services are included. Where a security service is included in the Services, Provider shall use commercially reasonable efforts to protect Client’s network from computer viruses, worms, intrusions and other malicious activity. Client acknowledges that no security measure can guarantee complete protection, since such attacks commonly involve deliberate action by third parties. EXCEPT TO THE EXTENT CAUSED BY PROVIDER’S NEGLIGENCE OR WILFUL MISCONDUCT, CLIENT AGREES TO HOLD PROVIDER HARMLESS FROM ANY LOSS, INJURY OR DAMAGE TO CLIENT OR TO ANY HARDWARE, SOFTWARE OR DATA OF CLIENT CAUSED BY MALICIOUS ACTIVITY.
9.3 Third-party criminal activity. Provider is not responsible for the criminal acts of third parties, including intrusion or unauthorized access of any kind, hacking, phishing, credential theft, crypto-locking or ransomware. EXCEPT TO THE EXTENT CAUSED BY PROVIDER’S NEGLIGENCE OR WILFUL MISCONDUCT, CLIENT AGREES TO HOLD PROVIDER HARMLESS IN RESPECT OF ANY ACTIVITY AFFECTING THE SECURITY OF CLIENT’S ENVIRONMENT THAT ARISES FROM THIRD-PARTY CRIMINAL ACTIVITY. Any work required to rebuild or restore systems is billable at Provider’s then-prevailing rates.
9.4 No ransom payment. Provider will not pay, facilitate, negotiate, or advise on the payment of any ransom or extortion demand, and nothing in the Agreement obliges Client to do so. Client acknowledges that a payment of that kind may contravene the Criminal Code, the Special Economic Measures Act or other sanctions legislation, and that any decision in respect of such a demand is Client’s alone, taken on its own legal advice.
9.5 Unsupported software. Provider is not responsible or liable for any consequence arising from the use of software that is no longer under manufacturer or publisher support (“Unsupported Software”). CLIENT AGREES TO HOLD PROVIDER HARMLESS FROM ANY LOSS, INJURY OR DAMAGE TO CLIENT OR TO ANY HARDWARE, SOFTWARE OR DATA OF CLIENT CAUSED BY THE USE OF UNSUPPORTED SOFTWARE.
9.6 Theft of service. Client shall notify Provider immediately in writing if it becomes aware that the Services are being stolen or used fraudulently. Client is liable for all use of the Services made using equipment stolen from Client and for all fraudulent use of the Services. Provider will not issue credits for charges resulting from fraud arising out of third parties gaining access to equipment, including modem or wireless hijacking, or from a failure of Client’s internal procedures.
9.7 Password management. Where Provider supplies password management services, Client is responsible for the use of credentials by its personnel. CLIENT AGREES TO HOLD PROVIDER HARMLESS FROM ANY LOSS, INJURY OR DAMAGE ARISING FROM CLIENT’S USE OF THOSE SERVICES, EXCEPT TO THE EXTENT CAUSED BY PROVIDER’S NEGLIGENCE OR WILFUL MISCONDUCT.
10. RECOMMENDATIONS AND CLIENT DECLINATION
10.1 Provider is under no obligation to make recommendations. Provider may from time to time deliver written recommendations regarding security, regulatory compliance, safety or data protection related to Client’s environment or practices, including multi-factor authentication, patching, segmentation, backup configuration or staff training (each, a “Recommendation”).
10.2 Declination record. Where Client declines, defers or fails to implement a Recommendation, Provider shall record the Recommendation and Client’s response in writing and deliver a copy to Client. Client’s continued receipt of the Services after delivery of that record constitutes acknowledgment of its accuracy, unless Client objects in writing within ten (10) business days.
10.3 Consequences. Client is responsible for all damages arising from or related to a declined, deferred or unimplemented Recommendation, including administrative monetary penalties, breach notification costs, malware and ransomware costs, forensic investigation, restoration of backups and any other cost or damage related to Client’s decision.
10.4 Adoption does not transfer responsibility. Client’s adoption of a Recommendation does not make Provider responsible for Client’s compliance with any legal or regulatory requirement, nor for the outcome of any audit, assessment or regulatory proceeding.
11. COMPLIANCE WITH LAWS; NO LEGAL ADVICE
11.1 Provider shall comply with all laws applicable to Provider in its role as a managed information technology and cybersecurity service provider. For the avoidance of doubt, and unless otherwise provided in an Order, Provider is not responsible for complying with laws applicable to Client or to Client’s industry. Client shall comply with all laws applicable to it, and shall obtain and maintain every permit, licence and approval required for Provider to perform the Services.
11.2 PROVIDER IS NOT A LAW FIRM AND DOES NOT PROVIDE LEGAL ADVICE. Any assistance Provider furnishes in connection with policies, privacy notices, regulatory frameworks, breach notification, records or compliance programs is technical and administrative in nature only. Client is solely responsible for obtaining legal advice from its own qualified counsel and for its own compliance with all applicable laws, regulations, frameworks and standards. Provider does not issue and will not issue any certification, attestation or opinion of compliance, and does not warrant that the Services will meet the requirements of any financial, regulatory or certification auditor.
11.3 Sanctions and export. Each party represents that it is not a person in respect of which dealings are prohibited under the Special Economic Measures Act, the United Nations Act, the Justice for Victims of Corrupt Foreign Officials Act or any other applicable sanctions legislation, and that it will not use the Services in contravention of Canadian export control or sanctions law.
11.4 Litigation holds, testimony and e-discovery. If Provider receives a clear and unambiguous litigation hold, subpoena, summons or request for assistance with litigation or electronic discovery, Provider will use commercially reasonable efforts to comply. None of these activities is included in the scope of the Services, and Provider’s assistance is billable at its then-prevailing rates. Provider takes no responsibility for ambiguous requests, and compliance with litigation holds, discovery obligations and court orders remains Client’s sole responsibility.
12. CREDENTIALS
12.1 Provider administrative credentials. While it is delivering the Services, Provider must hold exclusive network administrative credentials for the environment it manages. Provider will not release those credentials to Client or to any third party during the term without a written release acceptable to Provider, because concurrent administrative access materially increases the risk of misconfiguration and compromise.
12.2 Provider Credentials. Credentials for third-party tools and platforms licensed by Provider and used across Provider’s client base are Provider’s Confidential Information and will not be released to Client under any circumstances.
12.3 Client-owned credentials. Individual user credentials, and administrative credentials for accounts, tenancies, domains and systems owned or licensed by Client — including tenant global administrator credentials — are the property of Client. Provider shall release them to Client, and shall remove its own administrative access, on termination or expiry of the applicable Services, whether or not amounts remain outstanding. Nothing in this Section limits Provider’s right to recover any unpaid fees as a debt due and owing, together with the amounts described in Section 3.13.
12.4 Provider shall, on request and at Client’s cost at Provider’s then-prevailing rates, provide reasonable assistance with the orderly transfer of administrative control to Client or to a successor provider.
13. PROVIDER-SUPPLIED EQUIPMENT, SOFTWARE AND HARDWARE SALES
13.1 Equipment. “Equipment” means any computing, networking or telephony equipment, racking or associated hardware that Provider installs at Client’s premises or ships to Client to facilitate delivery of the Services. Equipment does not include hardware that Provider sells to Client or procures on Client’s behalf, which is governed by Section 13.6.
13.2 Provider is and remains the sole owner of all Equipment, which is supplied on a rental or temporary basis only. The Agreement transfers no ownership right in Equipment to Client, and Client acquires no lien or other similar right in relation to it. Client shall not remove or obscure any marking identifying Provider as owner.
13.3 Provider determines the appropriate Equipment and associated software to be used at Client’s location, provided that its determination does not materially impair the availability or delivery of the Services, and determines the necessity of maintenance, repair or improvement. Except as expressly stated in a Service Attachment, Provider makes no representation or warranty in respect of Equipment; any manufacturer warranty is Client’s exclusive remedy, and Provider will take commercially reasonable steps to ensure Client receives the benefit of it.
13.4 Client shall take reasonable care of Equipment and shall not damage, tamper with, move, remove, attempt to repair, or install software on it. Client is financially responsible up to the full replacement value of Equipment for all loss of or damage to it, other than loss or damage caused by Provider, and shall maintain insurance with a reputable insurer for that full replacement value naming Provider as an insured beneficiary in respect of the Equipment. Client shall produce evidence of that insurance on demand. Client shall provide the power, network connection and environment necessary to support the Equipment.
13.5 On termination, Client shall allow Provider and its personnel reasonable access to its premises to remove Equipment or, at Provider’s request, shall return the Equipment by a carrier of Provider’s choice at Provider’s cost. Client is responsible for removing all Client Data from Equipment before return, and Provider is not responsible for Client Data remaining on returned Equipment.
13.6 Hardware and products sold to Client. Where Provider sells hardware or other products to Client, or procures them on Client’s behalf: (a) title passes to Client on payment in full and risk of loss passes on delivery; (b) the sole warranty is the applicable manufacturer’s warranty, which Provider passes through to Client without adding to it; (c) to the fullest extent permitted by law, all implied conditions and warranties, including those arising under the Sale of Goods Act of the applicable province, or under the Civil Code of Québec where Quebec law applies, are excluded to the fullest extent that legislation permits; (d) returns are subject to the manufacturer’s or distributor’s return policy and any applicable restocking charge; and (e) until Provider has been paid in full, Client grants Provider a security interest in the goods and their proceeds, Client shall not permit any other security interest to attach to them, and Client shall execute any document and provide any information Provider reasonably requires to register and perfect that security interest under the Personal Property Security Act of the province in which the goods are situated or, where the goods are situated in Quebec, to create and publish a movable hypothec with or without delivery at the Register of Personal and Movable Real Rights.
13.7 Provider-supplied software. “Software” means software installed on Equipment or supplied by Provider for installation on Client’s equipment to facilitate delivery of the Services. The Agreement transfers no right, title or interest in Software to Client. Client’s use of Software is subject to the applicable end user licence agreement, a copy of which Provider will make available on request. Client shall not, and shall not permit any third party to, distribute, tamper with, reproduce, modify, copy, rent, sell, lease or transfer the Software or any part of it, use it for the benefit of a third party, or reverse assemble, decompile or reverse engineer it except to the extent permitted by law.
13.8 Client hardware. Client equipment must be in working order and maintained under a manufacturer’s warranty or current maintenance contract. Provider is not responsible for Client equipment that is not so maintained or that is otherwise out of order, and all fees assume that it is. Provider may, on its reasonable opinion supported by manufacturer information, designate equipment as obsolete or defective and exclude it from coverage.
14. CLIENT DATA, PRIVACY AND DATA PROTECTION
14.1 Client Data. “Client Data” means all electronic data, content and Personal Information submitted by Client to Provider, or stored, processed or transmitted using the Services, including data stored on virtualized machines assigned to Client and locally stored personal information of Client’s personnel. As between the parties, all Client Data is owned exclusively by Client and constitutes Client’s Confidential Information.
14.2 Provider shall not use, edit or disclose Client Data to any party other than Client, except as requested or instructed by Client, as necessary to deliver the Services, or as required by law or court order. Provider may access Client’s user accounts, including Client Data, solely to respond to a service or technical problem or at Client’s request.
14.3 Compliance with Canadian privacy law. Provider shall comply with all data protection and privacy laws applicable to Provider in its role as a service provider and, where applicable, as a person processing Personal Information on Client’s behalf, including the Personal Information Protection and Electronic Documents Act (Canada), the Personal Information Protection Act (Alberta), the Personal Information Protection Act (British Columbia) and the Act respecting the protection of personal information in the private sector (Quebec). For the avoidance of doubt, Provider is not responsible for complying with laws applicable to Client, to Client’s industry, or to Client in its capacity as the organization having control of Personal Information. Client shall comply with all such laws.
14.4 Regulated Data requires an Order and a DPA. Client shall not provide to Provider any Personal Information or other data that is subject to a specific statutory or regulatory regime beyond general Canadian private-sector privacy law (“Regulated Data”) — including personal health information subject to the Personal Health Information Protection Act, 2004 (Ontario) or comparable provincial health privacy legislation, personal information subject to Quebec’s Law 25 requirements for assessments and biometric data, information subject to the General Data Protection Regulation, payment card data subject to PCI-DSS, or data subject to the requirements of a federally regulated financial institution — without first entering into an Order with Provider that expressly identifies the Regulated Data and the applicable regime, together with the applicable module of Provider’s Data Processing Agreement.
14.5 Processing outside Canada. Client acknowledges that Provider uses third-party platforms that store and process data outside Canada, principally in the United States and the European Union, and that Client Data may be transferred outside Canada for that purpose. While outside Canada, that information may be subject to lawful access by foreign courts, law enforcement and government authorities. Provider will identify the location of processing for any Service on Client’s reasonable request. Client is responsible for making any disclosure to individuals, and for completing any privacy impact assessment, that applicable privacy law requires of it in respect of that transfer.
14.6 Security incidents. Provider shall notify Client without undue delay, and in any event within seventy-two (72) hours after Provider confirms a security incident affecting Client Data within systems managed by Provider under an applicable Order. Determining whether an incident gives rise to a real risk of significant harm, a risk of serious injury, or any obligation to report, notify or record under applicable privacy law, and discharging any such obligation, is Client’s sole responsibility.
14.7 Return and deletion. On Client’s written request, and provided Client is current in all payments, Provider shall return Client Data in a commercially reasonable format at Provider’s then-prevailing rates. Thirty (30) days after termination of the Agreement, Provider has no obligation to maintain Client Data and shall, unless legally prohibited, delete or securely destroy all Client Data in its possession or control.
15. WARRANTIES AND DISCLAIMER
15.1 Provider’s security practices. Provider maintains a written information security program containing administrative, technical and physical safeguards appropriate to the size and nature of its business and the sensitivity of the information it holds. Provider monitors its own network and systems for intrusion attempts and security events, applies security updates to internet-facing services and applications in a timely manner based on risk, maintains anti-malware protection on its systems, and investigates and escalates security incidents. This Section describes Provider’s practices and is not a warranty of any particular outcome.
15.2 Service warranty. Provider warrants that the Services will be performed in a professional and workmanlike manner and substantially as described in the applicable Service Attachment or Schedule of Services. Services are deemed accepted unless Client notifies Provider in writing within ten (10) business days after performance that the Services did not conform to this warranty. Provider shall promptly correct any non-conformity and notify Client in writing that it has done so.
15.3 PROVIDER DOES NOT WARRANT THAT THE SERVICES WILL BE PERFORMED ERROR-FREE OR UNINTERRUPTED, THAT PROVIDER WILL CORRECT ALL ERRORS, THAT THE SERVICES WILL MEET CLIENT’S REQUIREMENTS OR EXPECTATIONS, OR THAT THE SERVICES WILL BE COMPLETELY SECURE. THERE ARE RISKS INHERENT IN INTERNET CONNECTIVITY THAT MAY RESULT IN LOSS OF SERVICE AVAILABILITY, CONFIDENTIALITY OR PROPERTY. PROVIDER IS NOT RESPONSIBLE FOR ANY ISSUE RELATING TO THE PERFORMANCE, OPERATION OR SECURITY OF THE SERVICES THAT ARISES FROM CLIENT’S CONTENT, THIRD-PARTY CONTENT OR SERVICES SUPPLIED BY THIRD PARTIES.
15.4 FOR ANY BREACH OF THE WARRANTY IN SECTION 15.2, CLIENT’S EXCLUSIVE REMEDY AND PROVIDER’S ENTIRE LIABILITY IS CORRECTION OF THE DEFICIENT SERVICES OR, WHERE PROVIDER CANNOT SUBSTANTIALLY CORRECT THE DEFICIENCY IN A COMMERCIALLY REASONABLE MANNER, TERMINATION OF THE DEFICIENT SERVICES AND REFUND OF FEES PRE-PAID FOR THE PERIOD AFTER THE EFFECTIVE DATE OF TERMINATION.
15.5 TO THE FULLEST EXTENT PERMITTED BY LAW, THE WARRANTIES IN THIS SECTION ARE EXCLUSIVE AND REPLACE ALL OTHER WARRANTIES, CONDITIONS, REPRESENTATIONS AND GUARANTEES, WHETHER EXPRESS, IMPLIED, STATUTORY, COLLATERAL OR OTHERWISE, INCLUDING ANY IMPLIED WARRANTY OR CONDITION OF MERCHANTABILITY, MERCHANTABLE QUALITY, DURABILITY, SATISFACTORY QUALITY, FITNESS FOR A PARTICULAR PURPOSE, DATA ACCURACY, DATA SECURITY OR NON-INFRINGEMENT, ALL OF WHICH ARE DISCLAIMED. NO THIRD-PARTY VENDOR OF SOFTWARE, HARDWARE, SYSTEMS, NETWORKS OR ENVIRONMENTS PROVIDES ANY WARRANTY THROUGH THIS AGREEMENT, AND EACH SUCH VENDOR DISCLAIMS ALL LIABILITY, WHETHER DIRECT, INDIRECT OR CONSEQUENTIAL, ARISING FROM THE SERVICES.
16. THIRD-PARTY SERVICES
16.1 Client acknowledges that Provider uses third-party solutions and service providers to deliver some or all of the Services (“Third-Party Service Providers”). PROVIDER IS NOT RESPONSIBLE FOR THE ACTS OR OMISSIONS OF THIRD-PARTY SERVICE PROVIDERS. CLIENT’S RIGHTS IN RESPECT OF CLAIMS AGAINST A THIRD-PARTY SERVICE PROVIDER ARE GOVERNED BY THAT PROVIDER’S OWN END USER LICENCE AGREEMENT OR TERMS AND CONDITIONS.
16.2 Provider’s current Third-Party Service Providers, and the terms and policies governing their services, are listed in the Schedule of Third-Party Services, which Provider may update at any time and which is incorporated into the Agreement by reference. Provider will provide a copy of the version in effect on Client’s request.
16.3 Any purchase, enabling or engagement of a third-party service — including implementation, customization, consulting, email, web hosting, server hosting and telephony — is solely between Client and the applicable Third-Party Service Provider and is subject to that provider’s terms. Provider does not warrant third-party services and is not responsible or liable for them, or for any loss arising from Client’s use of them.
16.4 Where Client purchases, enables or engages a third-party service for use in connection with the Services, Client acknowledges that Provider may permit that provider to access Client Data as required for interoperation. Client represents that its use of the third-party service constitutes its independent consent to that access and use, that such consent and access are outside Provider’s control, and that Provider is not responsible for any disclosure, modification or deletion of data resulting from it.
16.5 Unless Provider expressly undertakes otherwise in writing, Client is responsible for all Third-Party Service Provider fees and charges, and for arranging and paying for the disconnection or termination of services with its existing carriers or providers.
17. INSURANCE
17.1 Client. Client shall maintain throughout the term, with insurers of recognized standing: (a) commercial general liability insurance of not less than two million dollars (CAD $2,000,000) per occurrence; (b) coverage under the workers’ compensation regime of each province or territory in which its personnel work, including the Workplace Safety and Insurance Board in Ontario, the Commission des normes, de l’équité, de la santé et de la sécurité du travail in Quebec, and the workers’ compensation board of any other province or territory; and (c) first-party cyber and privacy liability insurance of not less than one million dollars (CAD $1,000,000) per occurrence, covering data restoration, business interruption, incident response, extortion, breach notification costs and regulatory defence.
17.2 Provider. Provider shall maintain throughout the term professional liability insurance, including errors and omissions coverage, with aggregate limits of not less than two million dollars (CAD $2,000,000).
17.3 Client’s insurance is primary over Provider’s insurance in respect of any loss arising in Client’s environment. Client waives, and shall require its insurers to waive, all rights of subrogation and recovery against Provider and its directors, officers, employees, contractors and agents.
17.4 Each party shall provide the other with a certificate of insurance evidencing the coverage required by this Section on request, and shall give the other party notice of cancellation or material reduction in coverage.
17.5 Where Provider assists Client with an insurance application or supplies technical information for underwriting, Client is solely responsible for reviewing that information for accuracy and for any adverse action taken by an insurer in connection with underwriting or claims administration.
18. LIMITATION OF LIABILITY
18.1 TO THE FULLEST EXTENT PERMITTED BY LAW, NEITHER PARTY IS LIABLE TO THE OTHER FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY OR PUNITIVE DAMAGES, OR FOR ANY LOSS OF PROFIT, REVENUE, GOODWILL, PRODUCTIVITY, ANTICIPATED SAVINGS, DATA, PROGRAMS OR INFORMATION, OR FOR BUSINESS INTERRUPTION, ARISING OUT OF OR IN CONNECTION WITH THE AGREEMENT OR THE SERVICES, EVEN IF PREVIOUSLY ADVISED OF THE POSSIBILITY AND REGARDLESS OF WHETHER THE CLAIM IS FRAMED IN CONTRACT, TORT, NEGLIGENCE, BREACH OF STATUTORY DUTY, RESTITUTION OR OTHERWISE.
18.2 TO THE FULLEST EXTENT PERMITTED BY LAW, PROVIDER’S TOTAL AGGREGATE LIABILITY ARISING OUT OF OR IN CONNECTION WITH THE AGREEMENT AND THE SERVICES, FOR ALL CLAIMS COMBINED, IS LIMITED TO DIRECT DAMAGES ACTUALLY INCURRED BY CLIENT AND WILL NOT EXCEED THE GREATER OF (A) THE PROCEEDS ACTUALLY AVAILABLE UNDER PROVIDER’S PROFESSIONAL LIABILITY INSURANCE IN RESPECT OF THE CLAIM, AND (B) THE AGGREGATE AMOUNTS PAID BY CLIENT TO PROVIDER UNDER THE AGREEMENT DURING THE SIX (6) MONTH PERIOD IMMEDIATELY PRECEDING THE EVENT GIVING RISE TO THE CLAIM. THIS IS THE ONLY LIMIT ON PROVIDER’S LIABILITY, AND NO OTHER PROVISION OF THE AGREEMENT REDUCES IT.
18.3 Insurance coverage disputes. Provider is not required to dispute an insurer’s coverage determination or to commence a declaratory proceeding in respect of coverage. Where insurance proceeds are unavailable, the limit in Section 18.2 is the amount described in Section 18.2(b).
18.4 Excluded from the limits. Sections 18.1 and 18.2 do not apply to (a) Client’s obligation to pay fees and the amounts described in Section 3.13, (b) either party’s indemnification obligations under Section 19, (c) a party’s breach of Section 7, or (d) liability that cannot be limited or excluded at law, including liability for fraud or fraudulent misrepresentation.
18.5 Release of unknown claims. Each party acknowledges that a release given under or in connection with the Agreement extends to claims that the releasing party does not know or suspect to exist in its favour at the time of the release and which, if known, would have materially affected its decision to give the release, and each party expressly waives any rule of law or equity to the contrary.
18.6 Basis of the bargain. Client acknowledges that Provider would not enter into the Agreement for the consideration given but for the limitations in this Section, that the right to receive the Services in exchange for those limitations constitutes a bargain that is fair and reasonable, and that the fees have been set on that basis.
18.7 Limitation period. Other than a claim by Provider for non-payment, no claim may be brought more than six (6) months after the date on which the fault or failure giving rise to it was discovered or ought reasonably to have been discovered. A claim not brought within that period is forever barred. The parties agree that the Agreement is a “business agreement” within the meaning of section 22 of the Limitations Act, 2002 (Ontario) and that this Section varies the basic limitation period accordingly. This Section is subject to Section 23.2, which applies where the prescriptive periods of Quebec law govern.
18.8 Continued performance during dispute. Unless Provider is pursuing a claim for non-payment of undisputed amounts, Provider shall continue to deliver the Services and Client shall continue to pay for them in accordance with the Agreement while the parties seek resolution of a dispute.
19. INDEMNIFICATION
19.1 By Client. Client shall defend, indemnify and hold harmless Provider and its directors, officers, employees, contractors and agents from and against all claims, losses, liabilities, damages, administrative monetary penalties, costs and expenses, including reasonable legal fees on a full indemnity basis, arising out of or in connection with:
(a) any claim that Provider’s use, access or modification of software that Client asked Provider to use, access or modify infringes any patent, copyright, trademark, trade secret or other intellectual property right;
(b) any claim relating to software licensing or software licensing compliance in Client’s environment;
(c) any claim relating to any privacy, data protection or data breach law to which Client is subject, including any regulatory investigation of Client;
(d) Client’s breach of Section 8.4, Section 11 or Section 14.4;
(e) any claim by an individual arising from Client’s failure to give a notice, obtain a consent or complete an assessment required of it by applicable privacy law; and
(f) any claim brought against Provider by a Third-Party Service Provider arising from Client’s acts or omissions.
19.2 By Provider. Subject to Section 18, Provider shall defend, indemnify and hold harmless Client from and against all claims, losses, liabilities, damages, costs and expenses, including reasonable legal fees, caused by Provider’s negligent act, error, omission or misrepresentation in performing the Services, or by Provider’s wilful misconduct.
19.3 Procedure. The indemnified party shall give the indemnifying party prompt written notice of any claim, shall not admit liability or settle without the indemnifying party’s written consent, and shall provide reasonable cooperation at the indemnifying party’s expense. The indemnifying party controls the defence and settlement, provided that it shall not agree to any settlement that imposes a non-monetary obligation or an admission on the indemnified party without that party’s written consent. The indemnified party may participate with its own counsel at its own expense.
20. DISPUTE RESOLUTION
20.1 Good faith discussion. The parties shall attempt to settle amicably, by mutual discussion between representatives with authority to resolve the matter, any dispute, difference or claim arising out of or relating to the Agreement, within sixty (60) days after the dispute arises.
20.2 Arbitration. Failing amicable settlement, any dispute — including a claim relating to the existence, validity, interpretation, performance, termination or breach of the Agreement — shall be finally settled by arbitration administered by the ADR Institute of Canada, Inc. in accordance with its Arbitration Rules then in effect. The arbitration shall be conducted in English before a single arbitrator, and the seat of arbitration shall be Toronto, Ontario. The arbitrator has no authority to award punitive or exemplary damages. Each party bears its own expenses and the parties share equally the fees and expenses of the arbitrator and of the Institute. The award is final and binding, and judgment on it may be entered in any court of competent jurisdiction. The arbitration and the award are confidential.
20.3 Carve-out. Notwithstanding Section 20.2, either party may apply to the Ontario Superior Court of Justice for injunctive or other interim or equitable relief, and Provider may commence a proceeding in that court for the recovery of fees and other amounts owing under the Agreement and for the enforcement of any security interest granted under Section 13.6.
20.4 Costs. In any arbitration or proceeding arising out of or relating to the Agreement, the prevailing party is entitled to an award of its reasonable legal fees and disbursements.
20.5 Governing law. The Agreement is governed by and shall be construed in accordance with the laws of the Province of Ontario and the federal laws of Canada applicable in Ontario, without regard to conflict-of-laws principles, regardless of the province or territory in which Client is located or in which the Services are delivered, and subject only to Section 23. The United Nations Convention on Contracts for the International Sale of Goods does not apply.
21. NON-SOLICITATION OF PERSONNEL
21.1 During the term and for twelve (12) months after termination of the Agreement, neither party shall solicit, recruit, hire or engage any employee or contractor of the other party who was involved in the delivery or receipt of the Services, except in response to a general advertisement not directed at that person.
21.2 Each party acknowledges that injury resulting from a breach of Section 21.1 would be significant and that the actual damages would be extremely difficult to ascertain. Accordingly, on a breach, and in addition to any other remedy available at law or in equity, the breaching party shall make a one-time payment to the other party equal to one hundred percent (100%) of the total amounts paid by the other party to the affected person during the preceding twelve months. The parties agree that this amount is a genuine pre-estimate of the loss, reflects the reasonable projected cost of identifying, recruiting, hiring and training a suitable replacement, and is not intended as a penalty.
22. GENERAL
22.1 Force majeure. Neither party is liable for any failure or delay in performance caused by an event beyond its reasonable control, including fire, flood, severe weather, interruption of electrical power or telecommunications, national, provincial or regional emergency, epidemic, pandemic, public health order, quarantine, civil disorder, act of terrorism, riot, labour disruption, act of God, or any law, regulation, directive or order of the Government of Canada, of any province or territory, or of any municipality or other authority having jurisdiction (an “Affected Performance”). The affected party shall give prompt written notice describing the Affected Performance, and the parties shall confer in good faith to minimize its impact. Where the event continues for more than thirty (30) days, the parties shall attempt to negotiate an equitable modification; failing agreement, either party may terminate the Agreement on thirty (30) days’ written notice in respect of the Affected Performance only. Client shall pay for that portion of the Affected Performance completed or in progress through the effective date of termination. This Section does not excuse Client’s obligation to pay amounts owing.
22.2 Assignment. Neither party may assign the Agreement, in whole or in part, without the prior written consent of the other. Provider may assign or transfer its rights and obligations without consent on a change of control of fifty percent (50%) or more of its equity, a sale of substantially all of its assets, or a reorganization of Provider or its affiliates. A purported assignment by Client without consent is invalid, and Client remains responsible for all fees under the Agreement whether or not it continues to derive benefit from the Services. Provider may engage subcontractors to deliver some or all of the Services; no such engagement is an assignment, Provider shall use commercially reasonable efforts to ensure each subcontractor abides by the terms of the Agreement, and Provider remains responsible for the performance of its obligations.
22.3 Notices. All notices must be in writing and are deemed given: on the date of personal delivery; on the date sent by electronic mail to the address stated in the Order, provided no delivery failure is received; on the next business day after deposit with a recognized courier; or on the third business day after mailing by Canada Post registered mail, postage prepaid, to the address stated in the Order. Either party may change its address by notice given in accordance with this Section.
22.4 Marketing and references. Client grants Provider the right to reference Client’s name, industry, logo and website address in Provider’s marketing materials, website and correspondence with prospective clients, and to identify Client publicly as a client of Provider. That information is not Confidential Information. Any other public reference to Client by Provider requires Client’s written consent. Client may withdraw the rights granted in this Section on thirty (30) days’ written notice.
22.5 Electronic messages. Client consents to Provider sending electronic messages relating to the delivery, security, availability and administration of the Services to the addresses Client provides. Provider will send newsletters, service announcements, invitations and other commercial electronic messages only where Client has separately consented, will identify itself in each such message, and will include a functioning unsubscribe mechanism. Client may withdraw consent to commercial electronic messages at any time without affecting Provider’s delivery of Service-related messages.
22.6 Observed holidays. Provider identifies its observed holidays and may adjust its holiday schedule from time to time. Where a holiday falls on a weekend, Provider may close on the nearest business day in observance. After-hours emergency support remains available and is charged at Provider’s then-prevailing holiday rates.
22.7 Non-disparagement. Neither party, nor any of its principals, officers, directors, employees, affiliates, agents or representatives, shall initiate or participate in any conduct intended to injure, bring into disrepute or damage the goodwill of the other party. This Section does not prevent a party from exercising its rights under the Agreement, complying with a legal obligation or professional responsibility, or reporting or disclosing information to a government agency, authority or official in the ordinary course of business or as required by law. Where a party breaches this Section, the other party is no longer bound by it.
22.8 Amendment. Provider may amend this MSA, the Service Attachments, the Schedules and the other terms identified in an Order by publishing an amended version and giving Client notice. An amendment takes effect thirty (30) days after notice. Where an amendment materially and adversely affects Client, Client may, within those thirty (30) days, terminate the affected Order without incurring any termination fee that would otherwise apply. No amendment proposed by Client is effective unless in writing and signed by an authorized representative of Provider.
22.9 Waiver and severability. No delay in exercising, course of dealing in respect of, or partial exercise of any right or remedy constitutes a waiver of it. If any provision is held invalid or unenforceable by a court or arbitrator of competent jurisdiction, that provision shall be severed or read down to the minimum extent necessary and the remaining provisions continue in full force, to be interpreted so as to give effect as nearly as possible to the parties’ original intention.
22.10 Third-party beneficiaries. The Agreement is for the sole benefit of the parties and their respective successors and permitted assigns, and confers no right on any other person, except that a Third-Party Service Provider may enforce Sections 6.6, 7 and 16 to the extent required by its own terms.
22.11 Survival. Sections 3.13, 6, 7, 8.4, 8.5, 9, 10.3, 11, 12.2, 12.3, 13.6, 14, 15.3 through 15.5, 16, 18, 19, 20, 21, 22 and 23 survive termination or expiry of the Agreement.
22.12 Language. The parties have expressly requested that the Agreement and all related documents be drawn up in English. Les parties ont expressément demandé que la présente entente et tous les documents qui s’y rattachent soient rédigés en anglais. Where Client is situated in Quebec, Provider shall make a French-language version of the Agreement available to Client before it is signed, and Client’s election to proceed in English is recorded in the Order, in accordance with the Charter of the French Language. Where Client is situated in New Brunswick, Provider shall make the Agreement available in either official language on request.
22.13 Entire agreement. The Agreement sets out the entire understanding of the parties in respect of its subject matter and supersedes all prior discussions, proposals, representations and agreements. There are no understandings, representations, warranties or agreements other than those expressly set out in it. Each party has had the opportunity to obtain independent legal advice, and accordingly no ambiguity shall be construed in favour of or against either party by reason of authorship.
22.14 Counterparts and electronic signature. An Order may be executed in counterparts and delivered electronically. An electronic signature has the same effect as an original signature, and the parties consent to the formation of the Agreement by electronic means.
23. PROVINCIAL VARIATIONS
23.1 Purpose. Provider carries on business across Canada. This Section adapts the Agreement to the law of the province or territory in which Client is located where that law differs from Ontario law on a point the parties cannot contract out of. Except as this Section provides, the Agreement applies without variation regardless of Client’s location.
23.2 Quebec — prescription. Where the prescriptive periods of Quebec law govern a claim, the parties acknowledge that the Civil Code of Québec does not permit the prescriptive period to be changed by agreement. In that case Section 18.7 does not apply, and the prescriptive periods of the Civil Code of Québec govern instead. Section 18.7 continues to apply in every other province and territory to the extent the applicable limitations legislation permits parties to a business agreement to vary a limitation period.
23.3 Quebec — external clauses and acknowledgment. Where Client is domiciled in Quebec, or the Agreement is otherwise a contract of adhesion governed by Quebec law, Provider shall expressly bring to Client’s attention, before the Order is signed, each Service Attachment, the Schedule of Services, the Schedule of Third-Party Services and the Data Processing Agreement, and shall deliver a copy of each to Client. The Order records Client’s acknowledgment that it received and read them. The parties intend that no such document be treated as an external clause of which Client was unaware.
23.4 Quebec — sale of goods. Where Quebec law governs a sale of hardware or products under Section 13.6, the legal warranty of quality provided by the Civil Code of Québec applies and is limited or excluded only to the extent that the Code permits between parties acting in the course of their respective businesses. Nothing in Section 13.6 purports to exclude liability that the Code does not permit a professional seller to exclude.
23.5 Security interests. The security interest granted under Section 13.6 is created, registered and enforced under the Personal Property Security Act of the province or territory in which the goods are situated or, where the goods are situated in Quebec, as a movable hypothec published at the Register of Personal and Movable Real Rights.
23.6 Privacy legislation. Section 14.3 applies the privacy legislation of the province in which Client operates. In Alberta and British Columbia the applicable Personal Information Protection Act governs; in Quebec the Act respecting the protection of personal information in the private sector governs; elsewhere the Personal Information Protection and Electronic Documents Act governs. Where Client handles personal health information, the health privacy legislation of Client’s province applies and the Data Processing Agreement must be engaged under Section 14.4.
23.7 Employment and labour legislation. Where the Agreement refers to an obligation of Client under employment or labour legislation — including any requirement to maintain a written electronic monitoring policy, to give notice of workplace monitoring, or to consult a bargaining agent — that reference is to the legislation of the province or territory in which the affected personnel work, and the obligation is Client’s in every case.
23.8 Trades and licensed work. Where the Services involve work reserved to a licensed trade, including electrical work, that work shall be performed by a contractor holding the licence required in the province or territory where the work is performed, and Section 18.1 of the Service Attachment for Managed Services applies.
23.9 Federal legislation applies nationally. The parties acknowledge that the Interest Act, Canada’s anti-spam legislation, the Competition Act, the Special Economic Measures Act and the requirements of the Canadian Radio-television and Telecommunications Commission apply throughout Canada, and that the corresponding provisions of the Agreement apply without variation by province.
23.10 Mandatory local law. Nothing in the Agreement displaces a rule of law of the province or territory in which Client carries on business that applies notwithstanding the parties’ choice of law and that the parties cannot contract out of. Where such a rule applies, the affected provision is to be read down to the minimum extent necessary for it to comply, and the remainder of the Agreement continues in full force in accordance with Section 22.9.
Schedule of ServicesEffective 15 September 2026Version 2.1 (Canadian)8 pages
SYSTEM SUPPORT CANADA INC.
Schedule of Services
Effective 15 September 2026 · Version 2.1 (Canadian) ·
Effective 15 September 2026. This Schedule of Services supersedes and replaces all prior versions.
This Schedule describes the Services that System Support Canada Inc. — a corporation incorporated under the Canada Business Corporations Act, with its head office in Ontario and carrying on business throughout Canada (“Provider”) — may offer. A Service applies to Client only where it is itemized on an Order. This Schedule is incorporated into the Agreement by reference, may be updated by Provider in accordance with Section 22.8 of the Master Services Agreement, and is subject to the Master Services Agreement and the applicable Service Attachment, which prevail over any description in this Schedule.
Two limits that apply to every description in this Schedule.
1. Effort standard. Every obligation described in this Schedule is an obligation to use commercially reasonable efforts. No description in this Schedule is a warranty, a guarantee of any outcome, or a service level, and no service credit arises from any of them.
2. No legal advice. PROVIDER IS NOT A LAW FIRM AND DOES NOT PROVIDE LEGAL ADVICE. Where a description refers to policies, privacy notices, regulatory requirements, breach notification, records or compliance programs, Provider’s role is technical and administrative only: implementing, configuring, documenting and maintaining frameworks that Client and its own counsel have determined to be appropriate. Client is solely responsible for obtaining legal advice from its own qualified counsel and for its own compliance. Provider issues no certification, attestation or opinion of compliance.
1. DEFINED TERMS USED IN THIS SCHEDULE
1.1 Capitalized terms not defined here have the meanings given in the Master Services Agreement. In this Schedule:
“Personal Information” means information about an identifiable individual, as that expression is understood under the Personal Information Protection and Electronic Documents Act and comparable provincial privacy legislation. It replaces the term “NPI” used in earlier versions of this Schedule, which was defined inconsistently and is no longer used.
“Sensitive Personal Information” means Personal Information that, by reason of its nature or context, carries a heightened risk of significant harm if disclosed, including personal health information, financial account information, government identifiers, biometric information and information about children.
“Regulated Data” has the meaning given in Section 14.4 of the Master Services Agreement.
“Demarcation Point” means the outermost point of Provider’s firewall with the public internet.
PART 1 — CORE MANAGED SERVICES
Help Desk Support Available during normal business hours. After-hours support is intended for critical systems outages and may incur additional charges as defined by the Order. |
On-Site Support Provider’s intention is to provide remote support wherever possible. On-site support is available once Provider determines support cannot be delivered remotely, typically for hardware or connectivity issues. May incur additional charges. |
|---|---|
Server Monitoring and Management Alert monitoring and management of servers, prioritization of alerts to identify high-priority incidents, periodic reporting and performance tuning. Includes remote remediation as needed and backup software monitoring. Excludes major hardware or software upgrades, replacements and new server installations. |
Endpoint Monitoring and Management Alert monitoring and management of desktops, prioritization of alerts, remote remediation as needed, configuration backups, firmware updates as required by the manufacturer, reporting and performance tuning. Excludes hardware replacement and new hardware installations. |
Core Security Services Monthly Microsoft patch management, anti-malware software and management, and remote software installation. Includes new and terminated employee account setup and configuration. |
Problem Management Provider begins problem management as soon as its monitoring staff becomes aware of an incident. All incidents, with status and resolution, are documented in the incident ticket tracking system assigned to Client. |
Network and Systems Management Provider: monitors network devices and servers for performance, availability and security; performs regular maintenance, updates and patching on managed devices. Client: provides physical access as needed; notifies Provider of planned changes; maintains an up-to-date inventory of network devices and servers. |
Strategy and Planning Provider: provides guidance and recommendations on technology strategy and planning; assists in evaluating and selecting new technologies. Client: collaborates on planning; makes all final decisions on technology investments; communicates strategy to its own stakeholders. |
PART 2 — SECURITY SERVICES
Firewall, Anti-Malware and Intrusion Detection Provider installs and configures firewall traffic policies, applies firmware updates where applicable, and makes configuration changes as needed. Includes intrusion prevention against network threats; URL filtering to block known malicious sites and inappropriate content; and gateway antivirus using continuously updated signatures. |
Security Log Management Provider configures log sources to capture and retain information without excessive logging, limits user access to log files, avoids logging Sensitive Personal Information where practicable, secures the processes that generate logs, resolves logging errors, and analyzes and prioritizes log entries. |
|---|---|
Security Incident Event Management (SIEM) Supported by a security operations centre. Provider deploys SIEM monitoring probes across critical network devices including domain controllers, firewalls, switches and routers. Where a regulatory requirement applies, deployment extends to all Windows devices. |
Security Operations Centre Advanced malware protection supported by a security operations centre, deployed to Windows-based devices on the covered network. 24x7 analysis of quarantined applications and files to reduce false positives. Rapid identification of malware variants and their root causes. Ransomware rollback to restore files to a previous safe version where supported. |
Anti-Malware Provider supplies and installs anti-malware software of its choosing for each covered Device. Provider will use commercially reasonable efforts to keep Devices and the network free of harmful content, but does not guarantee that Devices or the network cannot be infected. Where infection occurs, Provider will provide commercially reasonable mitigation services. |
Threat Detection and Response Security data collected from the firewall is correlated with threat intelligence to detect and prioritize malware attacks and enable action. |
DNS Filtering Detects and blocks malicious DNS requests and redirects users to a notice page reinforcing security practices. |
Client-Side DNS Filtering Provider assigns licences to deploy client-side DNS filtering on laptop systems, protecting them while away from the corporate network. |
Spam and Phishing Prevention Continuous filtering of spam and phishing attempts at the mail gateway. |
Application Control Allows, blocks or restricts access to applications based on department, job function and time of day. |
Advanced Threat Protection Detects and blocks ransomware, zero-day threats and advanced malware designed to evade traditional network defences. |
Data Loss Prevention Scans text and files to detect Sensitive Personal Information and other designated content leaving the network by email, web or file transfer. Client defines the categories of content to be detected and the action taken on detection. |
Network Discovery Generates a visual map of nodes on the network to identify areas of risk. |
Reputation-Based Threat Prevention Cloud-based web reputation service aggregating multiple feeds to provide protection from malicious sites and botnets. |
Multi-Factor Authentication and Credential Management Provider configures multi-factor authentication for compatible applications, institutes single sign-on where compatible, and configures security policies. Following a security assessment, Provider works with Client to prepare a revised set of policies and procedures. |
Security Awareness Training and Phishing Simulations Provider assigns licences to support the Client environment and schedules simulated phishing campaigns at random times over a defined period. Campaigns are trackable and customizable, recording each user’s participation. Client is responsible for notifying its personnel that simulations may occur and for any obligation it has under the employment or labour legislation of the province or territory in which those personnel work. |
Cyber Awareness Training Programme Provider implements and manages a managed cybersecurity awareness training platform ordered through a third party on Client’s behalf. Enrolment of technology-facing workforce members; a customizable curriculum; management reporting on participation and performance; regular test campaigns; and automated enrolment in remedial training where appropriate. |
Security Risk Assessment Malware and vulnerability review using one or more tools to determine the existence of malware or vulnerabilities. Review of practices relating to Personal Information, including location, handling and risk mitigation. Findings are delivered in a risk assessment report. The report is technical and is not a legal or regulatory opinion. |
Remote Access Provider installs remote access and remote monitoring and management software on covered Devices and other equipment at Client’s premises. Client grants permission for that installation under Section 8.3 of the Master Services Agreement, and is responsible for reflecting that access in its own electronic monitoring policy where the employment or labour legislation of the relevant province or territory requires one. |
PART 3 — BACKUP, RECOVERY AND CLOUD
Local Backups Performed on the basis specified in the Order using Client-provided hardware and backup software, which Client owns. Where Client subscribes to periodic server maintenance, Provider reviews backups during maintenance and notifies Client of failures. Client notifies Provider of failures it observes and, on request, performs simple on-site tasks. |
Remote Backups Provider, through its Third-Party Service Providers, will use commercially reasonable efforts to protect and recover Client information. Data files are backed up by a third-party client-side application, encrypted, and sent to a storage server at the vendor’s data centre. There is no local copy. Files can be restored from the cloud but a server cannot be recovered or booted in the cloud. THIS SERVICE IS NOT A DISASTER RECOVERY SOLUTION. Provider monitors backups daily, notifies Client of failures and works with the vendor to resolve them. |
|---|---|
Cloud Backup Provider, through its Third-Party Service Providers, will use commercially reasonable efforts to protect and recover Client information. Data is backed up by a third-party client-side application, encrypted, stored locally on a Provider-owned storage device, then sent to a vendor-owned storage server at the vendor’s data centre. Provider monitors scheduled backup jobs, notifies Client of Provider-owned storage failures and corrective actions, and provides remote administration on request. Offsite backup copies have a one-year retention period unless the Order specifies otherwise. On termination, Provider requests return of the backup hardware and removes the application from Client systems. |
Disaster Recovery Provider works with Client to develop a disaster recovery plan incorporating the Services delivered under the applicable Service Attachment. The plan is a technical document. Client is responsible for approving it, for testing participation and for any business continuity obligation imposed on it by law, regulator or contract. |
Backup and Disaster Recovery Management Provider: develops and maintains a backup and disaster recovery plan in collaboration with Client; manages and monitors backup processes for managed systems; periodically tests backup and recovery procedures. Client: identifies the critical data and systems to be covered; provides the necessary access; participates in testing and validation. |
Public Cloud Provider migrates Client data to a cloud computing platform, provides access by virtual desktop from Client-owned or Provider-supplied devices, and manages the cloud environment. Client acknowledges that the platform may store and process data outside Canada, and that Section 14.5 of the Master Services Agreement applies. |
Hybrid Cloud Provider migrates some Client data to a cloud computing platform and, on request, places a server on premises. Data to be moved must be agreed in writing beforehand, with instructions identifying which data is moved and whether it is managed or unmanaged, and identifying its location on a particular server. Data not moved, or not specifically identified, is treated as unmanaged. Provider is not responsible for the identification, classification or location of data. CLIENT IS SOLELY RESPONSIBLE FOR ITS DATA UP TO THE DEMARCATION POINT. Once data has been identified, classified, its final location determined, and moved past the Demarcation Point, Provider becomes responsible for it. |
Private Cloud and Software Subscriptions Provider maintains Client data on premises at Client’s location, manages the environment and software subscriptions, and supplies hardware that remains Provider-owned and is licensed under an appropriate agreement. Where an environment or subscription is identified in the Order as unmanaged, Provider has no monitoring, patching or support obligation in respect of it. |
PART 4 — COMPLIANCE AND PRIVACY SUPPORT SERVICES
Every Service in this Part is subject to the “No legal advice” limitation on the first page of this Schedule and to Section 11.2 of the Master Services Agreement.
Information Security Programme Implementation Provider assists Client in implementing and maintaining a written information security programme scaled to Client’s size, needs and complexity. Provider establishes and maintains the administrative, technical and physical safeguards Client directs, including access controls, encryption, firewalls, secure disposal procedures and staff training. Client determines the content and adequacy of the programme on the advice of its own counsel. |
Privacy Notice and Policy Implementation Provider assists with the technical implementation and maintenance of privacy notices and policies that Client and its counsel have prepared, including publishing them, configuring consent and preference mechanisms, and building the workflows needed to honour access, correction and withdrawal requests. PROVIDER DOES NOT DRAFT, REVIEW OR ADVISE ON THE LEGAL SUFFICIENCY OF ANY PRIVACY NOTICE OR POLICY. |
|---|---|
Risk Assessment Provider conducts a technical risk assessment to identify and evaluate risks to the privacy and security of Personal Information, including risks associated with its collection, storage, transmission and disposal. Provider assists Client in developing a risk management plan, prioritizing risks by likelihood and potential impact. Where Client must complete a privacy impact assessment under applicable law, Provider supplies the technical information Client needs; the assessment remains Client’s. |
Ongoing Compliance Monitoring and Support Provider conducts periodic technical reviews of Client’s information security controls against the framework Client has adopted. Provider provides ongoing technical support in respect of control operation and reports on control status. Provider does not monitor Client’s legal compliance, does not interpret regulatory developments, and issues no compliance opinion. |
Incident Response Support Provider assists Client in developing and implementing a technical incident response plan to detect, contain and remediate security incidents. Provider supplies the technical facts Client needs in order to assess an incident and to prepare any notification. DETERMINING WHETHER A REPORTING OR NOTIFICATION OBLIGATION ARISES, AND PREPARING AND DELIVERING ANY NOTIFICATION TO AN INDIVIDUAL, A PRIVACY COMMISSIONER OR ANY OTHER AUTHORITY, IS CLIENT’S SOLE RESPONSIBILITY, TAKEN ON ITS OWN LEGAL ADVICE. This Service is subject to the 24-hour limit in Section 9.4 of the Service Attachment unless the Order provides otherwise. |
Employee Training and Awareness Provider implements and administers an ongoing training programme covering the policies, procedures and practices Client has adopted for protecting Personal Information. Provider conducts periodic refresher training and reports on completion. Client determines the content and adequacy of the training. |
Vendor Technical Assessment Provider maintains a register of Client’s technology vendors that have access to Personal Information and conducts technical assessments of their security posture using questionnaires and available third-party reports. PROVIDER DOES NOT REVIEW, DRAFT OR NEGOTIATE VENDOR CONTRACTS. Provider will identify, from a technical standpoint, controls a contract may need to address, for Client’s counsel to act on. |
Reporting and Documentation Provider provides regular reports on the status of the Services in this Part, including progress of risk mitigation activities, training completion rates and vendor assessment status. Provider maintains current technical documentation of the information security programme, risk register and control descriptions. Client is responsible for the accuracy and currency of its own policies and notices. |
PART 5 — ARTIFICIAL INTELLIGENCE SERVICES
Subject to Part A of the Service Attachment for Managed Services, including the disclaimer of warranty for AI Services.
Strategic AI Consulting AI readiness assessment: Provider evaluates Client’s technology infrastructure, data readiness and organizational readiness for AI adoption, documenting findings in a readiness report. AI strategy development: Provider assists Client in developing a plan for AI deployment aligned with Client’s business objectives. Innovation workshops: Provider conducts sessions with Client’s teams to identify potential use cases relevant to Client’s industry. |
Implementation Support Vendor and technology selection: Provider advises on selecting appropriate AI technologies and vendors given Client’s use cases, budget and infrastructure. Proof of concept: Provider assists in developing and executing proofs of concept to validate feasibility before full-scale implementation. Implementation oversight: Provider provides oversight and guidance during delivery of AI projects. |
|---|---|
AI Solution Design and Planning Use case identification and prioritization based on business impact and technical feasibility. Solution architecture design, including selection of models and technologies, establishment of data pipelines and integration with existing systems. Phased implementation roadmap detailing milestones, resource requirements and timelines. |
Data Governance and AI Ethics Provider advises on a data strategy addressing the integrity, accessibility and security of data used in AI solutions. Provider provides technical guidance on measures for bias mitigation, transparency and record-keeping. Client is solely responsible for determining what its legal and ethical obligations are, and for meeting them. |
Training and Change Management AI literacy training covering fundamental concepts, tools and practices. Change management support addressing cultural shifts, skill gaps and workflow adjustments arising from adoption. |
Performance Measurement and Optimization Provider assists Client in defining key performance indicators and metrics to evaluate the effect of AI initiatives. Provider provides ongoing support to optimize solution performance based on analytics and to identify areas for enhancement. |
AI-Driven Client Interaction Services Provider develops and deploys chatbots and voice assistants, integrates AI-driven interaction tools, and provides ongoing training and support. Client is responsible for disclosing to individuals that they are interacting with an automated system where applicable law requires it, and for the content and conduct of the deployed system. |
PART 6 — TELEPHONY, SURVEILLANCE, AUDIO/VISUAL AND DIGITAL SERVICES
VoIP Services Provider delivers the voice over internet protocol and associated telephony and collaboration services specified on the Order, which may be delivered through third-party vendors. Client agrees to be bound by the applicable third-party vendor agreements, which may change without notice. SUBJECT TO PART B OF THE SERVICE ATTACHMENT, INCLUDING THE 9-1-1 LIMITATIONS AND THE REQUIREMENT FOR A SIGNED 9-1-1 ACKNOWLEDGMENT. |
Video Surveillance Provider, through third-party vendors, will use commercially reasonable efforts to provide video surveillance services for Client’s premises through third-party hosted and cloud surveillance solutions. Client designates Provider as its agent to procure the services and to enter into the necessary third-party relationships. Client acknowledges that the vendors and their licensors own all intellectual property in the solutions and software, and agrees to be bound by their terms, which may change without notice. THIS SERVICE DOES NOT INCLUDE MONITORING SERVICES. Client is responsible for notice to individuals, camera placement, retention periods, access, and its own privacy and employment obligations under the legislation of the province or territory where the cameras are installed. |
|---|---|
Audio/Visual System Design Custom design of audio/visual systems tailored to Client’s requirements, including site evaluation, system layout and equipment recommendations. |
Audio/Visual Equipment Installation Installation of displays, projectors, audio systems, video conferencing systems, control systems and digital signage. Electrical work requiring a licensed contractor is Client’s responsibility and must be performed by a contractor licensed in the province or territory where the work is performed. |
Audio/Visual Training and User Adoption Training to help Client’s staff operate the installed audio/visual systems and equipment. |
Third-Party Cloud and SaaS Vendors Provider supplies, installs and supports the third-party cloud or software-as-a-service vendors listed on the Order, including Microsoft. Client designates Provider as its agent to provide the service and to enter into the necessary third-party relationships. Use is subject to the applicable vendor’s terms, which Provider has made available to Client and which are subject to change by the vendor without notice. |
Search and Content Optimization Keyword strategy: identifying and recommending keywords to drive traffic to identified websites. Content development: creating and optimizing content to improve search rankings and engage visitors. Optimization and monitoring: ongoing optimization with regular reporting on performance metrics and site health. Provider makes no representation as to ranking, traffic or revenue outcomes. |
Cost Analysis Provider evaluates cost-effective technology options for Client and reports its findings. All investment decisions remain Client’s. |
Schedule of Third-Party ServicesEffective 15 September 2026Version 2.1 (Canadian)3 pages
SYSTEM SUPPORT CANADA INC.
Schedule of Third-Party Services
Effective 15 September 2026 · Version 2.1 (Canadian) · Federally incorporated · Head office in Ontario
Effective 15 September 2026. This Schedule of Third-Party Services supersedes and replaces all prior versions.
This Schedule is issued by System Support Canada Inc., a corporation incorporated under the Canada Business Corporations Act with its head office in Ontario and carrying on business throughout Canada, and is incorporated into the Agreement by reference. Provider may modify or update it at any time in its sole discretion. Provider maintains a dated archive of every version and will provide the version in effect on any given date on request.
1. THIRD-PARTY SERVICES
1.1 “Third-Party Services” are products or services that are not exclusively operated or controlled by Provider, or that involve significant participation by an entity outside Provider’s control. Provider uses Third-Party Services to assist it in delivering the Services under the Agreement. The agreements and policies of each Third-Party Service provider apply to Client’s and Provider’s use of those services.
1.2 UNDER NO CIRCUMSTANCES WILL PROVIDER BE RESPONSIBLE OR LIABLE FOR ANY CLAIM CAUSED BY ANY THIRD-PARTY SERVICE. IF HARM OCCURS TO CLIENT AS A RESULT OF A THIRD-PARTY SERVICE, CLIENT ACKNOWLEDGES AND AGREES THAT IT WILL SEEK REMEDIES ONLY FROM THE THIRD-PARTY SERVICE PROVIDER. CLIENT REPRESENTS THAT IT HAS REVIEWED AND UNDERSTANDS THE AGREEMENTS AND POLICIES OF THE THIRD-PARTY SERVICE PROVIDERS LISTED BELOW AND AGREES THAT ITS RIGHTS ARE GOVERNED AND LIMITED BY THOSE AGREEMENTS.
1.3 Scope of Provider’s support. Provider provides first-line technical support and coordination in respect of the Third-Party Services it uses to deliver the Services, in accordance with Section 8.2 of the Service Attachment for Managed Services. Warranties, remedies, service levels and liability in respect of a Third-Party Service remain those of the applicable provider under its own terms.
1.4 Completeness. The table below lists the Third-Party Services in general use by Provider as at the effective date of this Schedule. Provider may use additional third-party products or services in delivering the Services, including a product introduced between versions of this Schedule or one used for a single Client at that Client’s request. Sections 1.2 and 1.3 apply to every Third-Party Service used by Provider, whether or not it appears in the table. Provider will identify the Third-Party Services applicable to a particular Service on Client’s request.
2. PROCESSING OUTSIDE CANADA
2.1 Client acknowledges that most of the Third-Party Services listed below store and process data outside Canada, principally in the United States and the European Union, and that Client Data may be transferred outside Canada in the course of delivering the Services. While outside Canada, information may be subject to lawful access by the courts, law enforcement and government authorities of the jurisdiction in which it is held, and may be subject to the laws of that jurisdiction.
2.2 Client’s responsibilities. Client is responsible for (a) making any disclosure to individuals that applicable privacy law requires of it in respect of the use of a service provider outside Canada, (b) completing any privacy impact assessment or assessment of privacy-related factors required by the legislation of Client’s own province before Personal Information is communicated outside that province or outside Canada, and (c) obtaining any consent required of it. Provider will supply, on reasonable request, the information about a Third-Party Service that Client needs in order to complete an assessment of that kind, including the location of processing and the vendor’s published security documentation.
2.3 Where a Service must remain in Canada. Where Client requires that Personal Information be stored and processed only within Canada, Client must state that requirement in the Order. Provider will identify whether the requirement can be met for each Service requested, and any additional cost of meeting it. Absent such a statement in the Order, Client accepts the processing locations of the Third-Party Services Provider uses.
3. THIRD-PARTY SERVICE PROVIDERS
The following table lists the Third-Party Services that may be used by Provider, the purpose for which each is used, and the principal region in which each processes data. Links to each provider’s terms of service and privacy policy are published with the online version of this Schedule.
| THIRD-PARTY PROVIDER | PURPOSE | PRINCIPAL PROCESSING REGION |
|---|---|---|
| 1Password | Credential and secrets management | United States / Canada |
| 3CX | VoIP and unified communications platform | European Union / United States |
| Adobe | Document and creative software | United States |
| Amazon Web Services | Cloud infrastructure and hosting | Canada / United States |
| Cloudflare | DNS, content delivery and network security | Global edge network |
| CodeTwo | Email signature and Microsoft 365 management | European Union |
| ConnectWise | Remote monitoring, management and service desk | United States |
| CrowdStrike | Endpoint detection and response | United States |
| Duo Security (Cisco) | Multi-factor authentication | United States |
| ID Agent / Dark Web ID (Kaseya) | Compromised credential and dark web exposure monitoring | United States |
| Kaseya | Remote monitoring and management, backup, security tooling | United States |
| Microsoft | Microsoft 365, Azure, Entra ID, Defender and related services | Canada / United States |
| OVHcloud | Cloud infrastructure and hosting | Canada / European Union |
| QuickBooks Online (Intuit) | Accounting and billing | United States / Canada |
| SentinelOne | Endpoint protection and response | United States |
| SonicWall | Firewall, gateway security and secure remote access | United States |
4. CLIENT ACKNOWLEDGMENTS
4.1 Client acknowledges that a Third-Party Service provider may change its terms, policies, pricing, features, security posture or processing locations at any time without notice to Client or to Provider, and that Provider has no control over any such change.
4.2 Client acknowledges that a Third-Party Service provider may discontinue a product or service, or cease to make it available to Provider, and that Provider may in that event substitute a comparable product or service. Provider will notify Client of a substitution that materially changes how a Service is delivered.
4.3 Client acknowledges that credentials held by Provider for the third-party tools it licenses across its client base are Provider’s Confidential Information and will not be released to Client, in accordance with Section 12.2 of the Master Services Agreement. Credentials for accounts and tenancies owned or licensed by Client are Client’s property and are governed by Section 12.3 of that agreement.
4.4 Client acknowledges that certain third-party software publishers, including Microsoft, are intended third-party beneficiaries of the Agreement with rights of enforcement and verification, in accordance with Section 8.4 of the Service Attachment for Managed Services.
Service Attachment — Managed ServicesEffective 15 September 2026Version 2.1 (Canadian)15 pages
SYSTEM SUPPORT CANADA INC.
Service Attachment
Managed Services
Effective 15 September 2026 · Version 2.1 (Canadian) ·
Effective 15 September 2026. This Service Attachment supersedes and replaces all prior versions.
This Service Attachment is between System Support Canada Inc., a corporation incorporated under the Canada Business Corporations Act with its head office in Ontario and carrying on business throughout Canada (“Provider”) and the client identified on the applicable Order (“Client”) and, together with the Order, the Master Services Agreement (the “MSA”), the Schedule of Services and any other applicable Service Attachment, forms the Agreement between the parties. Capitalized terms not defined here have the meanings given in the MSA.
1. SERVICES
1.1 Provider will deliver only the Services itemized in the Services section of the Order. Additional Services may be added only by a new Order that includes them.
1.2 Help desk support. Help desk support is available during normal business hours. After-hours support is intended for critical systems outages and may incur additional charges as set out in the Order.
1.3 On-site support. Provider’s intention is to provide remote support wherever possible. On-site support is available once Provider determines that support cannot be provided remotely, typically because of a hardware or network connectivity issue, and may incur additional charges as set out in the Order.
1.4 Maintenance windows. Routine server and application maintenance and upgrades occur during scheduled maintenance windows. Some applications, systems or devices may be unavailable or unresponsive during those windows.
1.5 Licence. Provider grants Client the right to access and use, during the term, only those software solutions and information technology Services specified on the Order. Those Services may be hosted on servers operated by one or more third parties. As between the parties, Provider retains all right, title and interest in and to the Services and their components, together with all intellectual property rights in them. No licence or right in the Services is granted except as expressly set out in the Agreement, and all other licences and rights are reserved.
1.6 Provider Materials. “Provider Materials” means any text, graphical content, technique, method, design, software, hardware, source code, data, credential, application programming interface or documentation, and any improvement or upgrade to any of them, used by or on behalf of Provider to deliver the Services. The restrictions in Section 6.6 of the MSA apply to Provider Materials.
2. MINIMUM STANDARDS FOR THE CLIENT ENVIRONMENT
2.1 Client represents, warrants and agrees that its environment meets, or that Client will obtain the upgrades necessary for it to meet, the following minimum standards:
(a) every server runs a version of its operating system that remains under vendor support, with current recommended patches and updates installed;
(b) every desktop, notebook and laptop runs a version of its operating system that remains under vendor support, with current recommended patches and updates installed;
(c) all server and desktop software is genuine, properly licensed and vendor-supported;
(d) Provider holds exclusive network administrative credentials for the managed environment, in accordance with Section 12 of the MSA;
(e) a currently licensed, vendor-supported hardware firewall sits between the internal network and the internet;
(f) a static external IP address is assigned to a network device, permitting secure remote access;
(g) a supported anti-malware solution is installed on every covered device with a valid update subscription; and
(h) wireless data traffic in the environment is securely encrypted.
2.2 All costs required to bring Client’s environment up to the minimum standards are excluded from this Service Attachment and require a separate Order. If Client’s environment fails to satisfy the minimum standards at any time during the term, Provider may suspend further delivery of the Services or terminate this Service Attachment on five (5) business days’ advance written notice.
Additional standards for regulated environments
2.3 Where Client is subject to a specific statutory, regulatory or contractual security regime — including the Personal Health Information Protection Act, 2004 (Ontario), the Health Information Act (Alberta), the Personal Health Information Act of Manitoba, Nova Scotia or Newfoundland and Labrador, the Health Information Protection Act (Saskatchewan), the E-Health (Personal Health Information Access and Protection of Privacy) Act (British Columbia), Quebec’s Act respecting the protection of personal information in the private sector as amended, PCI-DSS, or the technology, cyber and third-party risk expectations that the Office of the Superintendent of Financial Institutions applies to federally regulated financial institutions — the following additional standards apply, and bringing the environment up to them requires a separate Order:
(a) a centrally managed identity and access management system, with unique named accounts, role-based access, and documented joiner, mover and leaver processes;
(b) multi-factor authentication on all remote access, all administrative accounts and all access to systems holding Regulated Data;
(c) network segregation separating any payment card environment, and separating guest and operational wireless networks, from the network holding Regulated Data;
(d) encryption of Regulated Data at rest and in transit, and full-disk encryption on every portable device;
(e) audit logging on systems holding Regulated Data, with a defined retention period and protection against alteration; and
(f) a documented and tested backup and recovery capability for systems holding Regulated Data.
2.4 Client remains responsible for compliance. Provider will use commercially reasonable efforts to assist Client in meeting the technical requirements of an applicable regime. Client remains ultimately responsible for its own compliance with all applicable laws, regulations, frameworks and standards. Provider does not warrant that the Services will meet the requirements of any financial, regulatory or certification auditor and will not issue any certification of compliance.
3. RESTORABLE BACKUP
3.1 Before any installation, access or use of the Services, Client shall create a full, complete and restorable backup of all systems that may be affected, in whole or in part, by the installation or maintenance of any software solution or Service. CLIENT AGREES TO HOLD PROVIDER HARMLESS IN THE EVENT OF ANY DAMAGE TO ANY SYSTEM OR APPLICATION SOFTWARE ARISING FROM CLIENT’S FAILURE TO DO SO, EXCEPT TO THE EXTENT THE DAMAGE IS CAUSED BY PROVIDER’S NEGLIGENCE OR WILFUL MISCONDUCT.
3.2 Section 8.5 of the MSA continues to apply to backups generally.
4. PROVIDER-SUPPLIED EQUIPMENT
4.1 Provider will deliver the equipment and applications identified in the Order (“Equipment”) on a rental basis only, subject to Section 13 of the MSA.
4.2 Where the Order provides for a monthly service fee covering Equipment, that fee includes all charges for the use of Provider-owned hardware, software and operating systems, and all labour required to install and maintain them.
4.3 Client shall use Equipment only for its intended purpose and in the manner contemplated by the manufacturer and in accordance with law. Client shall not permit Equipment to be serviced by anyone other than Provider, shall not connect accessories supplied by anyone other than Provider without Provider’s written consent (which shall not be unreasonably withheld), and shall not permit anyone other than Provider to disconnect or move Equipment from the location stated in the Order. Provider must be free to make any change required to the Equipment. Client shall back up any critical business data stored on Equipment.
4.4 Client acknowledges that its interest in any software installed by Provider on Equipment is that of a licensee, that the software remains Provider’s property, and that it must be returned or rendered unusable if requested by Provider or on termination. Client shall cease using any software or Equipment that remains Provider’s property on cancellation or termination.
4.5 Site preparation and agency. Client designates Provider as its agent for the limited purpose of ordering services from, or entering trouble tickets with, telephone service carriers and internet access providers. Client shall (a) furnish and install all conduit, raceway and low-smoke cable and create all holes and wireways required for installation, (b) provide all commercial alternating-current power circuits required for operation, (c) pay for all electrical current necessary for operation, and (d) provide suitable space for operation consistent with the manufacturer’s recommendations, including a dry and dust-free environment. Provider has no duty to make structural alterations to the premises, and is not responsible for restoring the premises to their original condition on removal or relocation of Equipment. Client shall provide reasonable access during Provider’s working hours, together with elevator service where necessary, heat, light, sanitary facilities, electrical power and protection of the Equipment from theft during installation.
4.6 Software media. Client shall obtain and supply all necessary software media with installation keys on request. Except for software supplied by Provider in connection with the Services, Client is solely responsible for obtaining all required software licences, including client access licences.
4.7 Minor on-site tasks. Provider may occasionally ask Client to perform simple on-site tasks, such as powering down and restarting a device. Client agrees to cooperate with reasonable requests of that kind. Client shall not perform server upgrades or repairs without notifying Provider, and Provider authorizes all server upgrades and repairs within the managed environment.
5. NETWORK CHANGE COORDINATION
5.1 Client shall notify Provider by email of all significant proposed changes to its network and shall give Provider a reasonable opportunity to comment before those changes are made.
5.2 Evaluation of a network change request may require significant research, design and testing. Work of that kind is excluded from this Service Attachment and is billable at Provider’s then-current time-and-materials rates.
6. PROVIDER OBLIGATIONS
6.1 Standards. Provider shall use commercially reasonable efforts to perform the Services in compliance with the laws, regulations and industry standards applicable to Provider in its role as a managed information technology and cybersecurity service provider, and shall maintain the licences and authorizations required for it to perform the Services. Section 11 of the MSA governs the allocation of compliance responsibility between the parties.
6.2 Data protection and security. Provider shall implement and maintain commercially reasonable administrative, technical and physical safeguards, appropriate to the nature and sensitivity of the information concerned, to protect Client Data within systems under Provider’s direct control against unauthorized access, disclosure, alteration or destruction.
6.3 Incident notification. Provider shall notify Client without undue delay, and in any event within seventy-two (72) hours after Provider confirms a security incident affecting Client Data within systems managed by Provider under an applicable Order. Provider’s notification obligation does not extend to systems outside its management. Determining whether an incident gives rise to any obligation of Client to report, notify or record under applicable privacy law, and discharging that obligation, is Client’s sole responsibility.
6.4 Issue resolution and escalation. Provider shall maintain an issue resolution and escalation process and shall use commercially reasonable efforts to address service-related issues raised by Client through it.
6.5 Reporting. Provider shall provide Client with periodic reports, at the frequency stated in the Order, covering the Services delivered and, where applicable, usage and performance metrics.
6.6 Advice. Provider may advise Client on emerging technologies and practices that could benefit Client’s operations. Advice of that kind is informational, is not a Recommendation unless delivered as one under Section 10 of the MSA, and creates no obligation or liability on Provider’s part.
7. ADDITIONAL CLIENT OBLIGATIONS
7.1 In addition to Section 8 of the MSA, Client shall:
(a) provide all information regarding its systems, software and hardware that Provider reasonably requires, and promptly disclose any change in its operational processes, technology infrastructure or business objectives that may affect the Services;
(b) ensure that Provider’s access to its facilities and systems complies with Client’s internal security policies and with applicable law;
(c) designate one or more representatives with authority to make decisions and give approvals in respect of the Services;
(d) obtain and maintain every permit, licence and approval required for Provider to perform the Services;
(e) use and operate systems and equipment in accordance with the guidelines and instructions provided by the manufacturer and by Provider, and take reasonable precautions against damage, misuse and unauthorized access;
(f) maintain an up-to-date inventory of network devices and servers, implement the security policies and procedures Provider recommends, and provide the access Provider requires for monitoring and management; and
(g) regularly back up and secure its own data and content, and implement appropriate data protection measures including encryption, access controls and firewalls.
7.2 Insurance. In addition to Section 17 of the MSA, where Client handles Regulated Data it shall maintain privacy and cyber liability insurance appropriate to the volume and sensitivity of that data and to the regulatory regime that applies to it.
7.3 Indemnification. In addition to Section 19 of the MSA, Client shall indemnify and hold Provider harmless in respect of any claim, administrative monetary penalty, defence cost or damage arising out of or related to a regulatory investigation of Client.
8. THIRD-PARTY SERVICE PROVIDERS
8.1 Some components of the Services may be supplied through or licensed from Third-Party Service Providers, including third-party software, products and services.
8.2 Scope of Provider’s support. Provider will provide first-line technical support and coordination in respect of third-party components used in delivering the Services, including logging and escalating tickets with the applicable vendor and acting as Client’s point of contact. Warranties, remedies, service levels and liability in respect of those components remain those of the applicable vendor under its own terms, and Provider makes no warranty in respect of them. Nothing in this Section makes Provider responsible for the acts or omissions of a Third-Party Service Provider, and Section 16 of the MSA continues to apply.
8.3 Under the terms of certain third-party licence or service agreements, Provider may be obliged to provide information to a vendor regarding the Services or Client’s identity. Client consents to those disclosures.
8.4 Third-party software publishers, including Microsoft, are intended third-party beneficiaries of the Agreement with the right to enforce its provisions and to verify compliance. Where a publisher believes in good faith that Client is not complying with its end user licence terms, Provider will cooperate in good faith with the publisher to investigate and remedy the non-compliance.
8.5 Within thirty (30) days after termination of the Agreement, Provider shall remove, or cause to be removed, all copies of the Services and Provider Materials from Client’s devices, or shall otherwise render them permanently unusable. Provider may require Client to return or destroy all copies of the software, the Services and the Provider Materials it received, and Client shall reasonably cooperate.
9. EXCLUSIONS
9.1 Provider is not responsible for a failure to provide the Services caused by any of the following:
(a) parts, equipment or software not covered by a current vendor or manufacturer warranty or support agreement;
(b) any repair made necessary by the alteration or modification of equipment, or by a software installation, other than as authorized by Provider, including work performed by Client’s personnel or by any third party;
(c) a defect or malfunction in any hardware or software not caused by Provider that adversely affects Provider’s ability to perform;
(d) a problem arising from a Client resource that is not under Provider’s management or control;
(e) a change to the network environment that was not communicated to or approved by Provider;
(f) a prioritization or reprioritization of tasks by Client;
(g) a force majeure event as described in Section 22.1 of the MSA;
(h) any act or omission of Client, or Client’s failure to fulfil an obligation under the Agreement;
(i) loss of internet connectivity at a Client location for any reason;
(j) maintenance of application software packages, whether acquired from Provider or another source; or
(k) home or remote computers not covered by an Order.
9.2 Provider is not responsible for a failure to provide the Services during any period in which any of the following exists:
(a) the interval between the initial occurrence of a malfunction or other issue affecting functionality and the time Client reports it to Provider;
(b) a failure of battery, electrical supply, power-protective equipment or uninterruptible power supply that renders Provider unable to connect to the network or troubleshoot the device concerned; or
(c) third-party criminal activity or malicious code, in respect of which Sections 9.3 through 9.5 of the MSA apply. Any work required to rebuild or restore systems is provided and charged separately.
9.3 The following are excluded from the scope of the included Services and may incur additional charges or require a separate Order:
(a) unusual work resulting from a failed software patch or update that interrupts Client’s business, other than in respect of Microsoft Windows updates and patches;
(b) programming, modification of software code, and program maintenance;
(c) training of any kind, unless otherwise agreed in an Order;
(d) software and web development work;
(e) home or remote computers not specified in an Order;
(f) implementation of new or replacement software;
(g) office relocation or satellite office setup;
(h) equipment refreshes; and
(i) incident response beyond the limit in Section 9.4.
9.4 Incident response limit. Provider will assist Client during the first twenty-four (24) hours following identification of a data breach or security incident, to help identify the likely source and to begin formulating a response. All assistance after that period — including breach notification planning, in-depth forensic examination, regulatory correspondence and significant post-incident reconfiguration — is excluded from this Service Attachment and requires a separate Order specifying the applicable charges. Where the Schedule of Services describes incident response, breach notification support or compliance monitoring, those descriptions apply only where the Service is named on an Order and remain subject to this Section and to Section 11.2 of the MSA.
9.5 The following costs are separate from the Service pricing: parts, equipment and shipping charges of any kind; software, licensing, renewal and upgrade fees of any kind; third-party vendor or manufacturer support and incident fees of any kind; and the cost of additional facilities, equipment, replacement parts, software or service contracts.
9.6 Provider does not perform printer hardware repair or maintenance, and does not manage or become involved in disputes or charges with any third-party vendor other than in respect of technical service matters.
PART A — ARTIFICIAL INTELLIGENCE SERVICES
This Part applies where the Order includes an AI Service.
10. DEFINITIONS AND SCOPE
10.1 In this Part:
(a) “AI Services” means the artificial-intelligence-based services identified on the Order, which may include AI-driven analytics, process automation, client interaction services, strategic AI consulting, implementation support and AI application development.
(b) “AI Models” means the computational models developed or used by Provider that simulate human intelligence processes, including machine learning models, neural networks and algorithms.
(c) “AI-Generated Outputs” means any data, content, analysis or other material generated by the AI Services as a result of processing Client Data or through interaction with Client’s systems.
(d) “Client AI Data” means data, information and material provided by Client to Provider for the purpose of receiving AI Services.
(e) “Third-Party Components” means software, data or services not developed or owned by Provider that are used in delivering the AI Services, including open-source software and third-party application programming interfaces.
11. CLIENT OBLIGATIONS FOR AI SERVICES
11.1 Client shall provide the data necessary for the AI Services and shall ensure that it meets the quality standards Provider specifies, including accuracy, completeness and relevance.
11.2 Client represents and warrants that it holds all rights necessary to use and to provide Client AI Data to Provider for the purposes of the AI Services, and that its provision of that data complies with applicable privacy and data protection law.
11.3 Client is responsible for ensuring that its use of the AI Services and of AI-Generated Outputs complies with all applicable laws, regulations and industry standards, including privacy law, intellectual property law and any regulation specific to Client’s industry.
11.4 Client agrees to use the AI Services ethically, in a manner that respects privacy rights and avoids unlawful discrimination, and shall promptly notify Provider of any issue, concern or malfunction affecting them.
11.5 Human review. Client acknowledges that it must review and validate AI-Generated Outputs for accuracy and appropriateness before relying on them, and shall not use an AI-Generated Output as the sole basis for a decision that produces a legal effect for an individual or that significantly affects an individual, without independent human review. Where applicable privacy law requires Client to inform an individual of a decision based exclusively on automated processing, or to provide an opportunity to make representations, discharging that obligation is Client’s responsibility.
12. INTELLECTUAL PROPERTY IN AI SERVICES
12.1 Each party retains all right, title and interest in and to its pre-existing intellectual property. Client grants Provider a non-exclusive, worldwide, royalty-free licence to use Client’s pre-existing intellectual property solely for the purpose of performing the AI Services.
12.2 Client owns the intellectual property rights in AI-Generated Outputs generated specifically for Client’s use under the Agreement, subject to any third-party right in the underlying data or algorithms, and subject to Sections 6.3 and 6.4 of the MSA in respect of any Provider Work embedded in them.
12.3 Any custom AI model, algorithm or application created by Provider specifically for Client under an Order is a Deliverable for the purposes of Section 6.3 of the MSA, and title passes to Client on payment in full for it. Provider retains the right to use the general knowledge, skills and experience, and all non-Client-specific developments, gained in performing the AI Services.
12.4 Provider may use Third-Party Components in delivering the AI Services. Provider shall use commercially reasonable efforts to ensure that its use complies with the applicable licences and imposes no unagreed obligation on Client, and shall inform Client of any Third-Party Component that requires attribution or that restricts the use of AI-Generated Outputs.
12.5 Licence to Provider. Client grants Provider a non-exclusive, worldwide, royalty-free licence to use, reproduce, modify and display Client AI Data and AI-Generated Outputs solely as necessary to perform the Services. Provider may additionally use data derived from Client AI Data and AI-Generated Outputs for analytics, benchmarking and improvement of Provider’s services only in aggregated and anonymized form that does not identify Client or any of its personnel, clients or customers, and only to the extent permitted by the Data Processing Agreement and applicable law. Provider shall not use Client AI Data to train any AI Model made available to any other client except in that aggregated and anonymized form.
12.6 In addition to Section 19 of the MSA, Client shall indemnify Provider against any claim, damage, loss or expense arising from Client’s use of an AI-Generated Output in violation of a third party’s intellectual property rights.
13. AI SERVICE EXCLUSIONS AND DISCLAIMER
13.1 Provider is not responsible for a failure of the AI Services caused by, or for any outcome arising from, any of the following:
(a) a third-party service or product not directly supplied or controlled by Provider;
(b) Client’s disregard of Provider’s recommendations or instructions;
(c) an unauthorized alteration to the service or system by Client or a third party;
(d) a force majeure event as described in Section 22.1 of the MSA;
(e) a condition pre-dating the Agreement or unrelated to the Services;
(f) unauthorized access or a security breach;
(g) bias inherent in an AI Model or in the data on which it was trained;
(h) inaccuracy or fabrication produced by an AI Model, commonly described as hallucination;
(i) the absence of a detailed explanation for a model decision, arising from the opaque nature of certain AI technologies;
(j) unforeseen or unpredictable AI system behaviour producing unintended outcomes;
(k) limitations arising from inadequate or poor-quality data supplied by Client or inherent in a dataset used;
(l) a change in AI behaviour resulting from continuous learning processes not directly managed by Provider;
(m) a claim of intellectual property infringement arising from AI-Generated Outputs;
(n) interruption or cessation of access to a data source or third-party service required to operate the AI Services, including discontinuation, a change in terms of service, or an access restriction imposed by a data provider;
(o) sudden failure, degradation or unpredicted behaviour of an AI Model that cannot be promptly resolved through reasonable efforts;
(p) a change in law, regulation or government policy that prohibits, restricts or imposes additional burdens on the deployment or use of AI technologies; or
(q) a failure in critical infrastructure supporting the AI Services, including cloud computing platforms, data storage systems and networking services.
13.2 PROVIDER SUPPLIES ALL AI SERVICES, INCLUDING AI MODELS, ALGORITHMS, SOFTWARE AND AI-GENERATED OUTPUTS, ON AN “AS IS” AND “AS AVAILABLE” BASIS. TO THE FULLEST EXTENT PERMITTED BY LAW, PROVIDER DISCLAIMS ALL WARRANTIES AND CONDITIONS, WHETHER EXPRESS, IMPLIED, STATUTORY OR OTHERWISE, INCLUDING ANY IMPLIED WARRANTY OR CONDITION OF MERCHANTABILITY, MERCHANTABLE QUALITY, FITNESS FOR A PARTICULAR PURPOSE OR NON-INFRINGEMENT. PROVIDER MAKES NO WARRANTY THAT THE AI SERVICES WILL MEET CLIENT’S REQUIREMENTS OR ACHIEVE ANY INTENDED RESULT, AND NO WARRANTY AS TO THE ACCURACY, COMPLETENESS OR RELIABILITY OF ANY AI-GENERATED OUTPUT. CLIENT ASSUMES FULL RESPONSIBILITY FOR ITS SELECTION OF THE AI SERVICES AND FOR THE RESULTS OBTAINED FROM THEM.
PART B — VOIP AND TELEPHONY SERVICES
This Part applies where the Order includes a VoIP or telephony Service.
14. DELIVERY AND ACCEPTANCE
14.1 Provider will deliver the Voice over Internet Protocol and associated telephony and collaboration services specified on the Order, which may be provided through third-party vendors listed on the Order. Client acknowledges and agrees to be bound by the applicable third-party vendor agreements, which may change without notice, and Provider is not responsible for third-party vendor service failures.
14.2 The service start date stated in the Order for installed Equipment is approximate. IN NO EVENT IS PROVIDER LIABLE FOR SPECIAL, CONSEQUENTIAL OR PUNITIVE DAMAGES ARISING FROM A DELAY IN DELIVERY OR INSTALLATION CAUSED BY CIRCUMSTANCES BEYOND ITS REASONABLE CONTROL.
14.3 Where Client is represented by a consultant, Provider may require the consultant to provide completed key sheets and floor plans, to arrange all necessary services with the local telephone utility, and to provide Client training and directories.
15. 9-1-1 EMERGENCY CALLING — LIMITATIONS AND ACKNOWLEDGMENT
15.1 How 9-1-1 calls are routed. When a 9-1-1 call is placed using the Service, the call is routed from Provider’s network to a public safety answering point or to local emergency service personnel using the civic address that Client has registered with Provider. Client acknowledges that the call may be routed to an administrative or general telephone number for that answering point rather than to a dispatcher designated to receive 9-1-1 calls, and that the caller’s telephone number and registered address may not be transmitted automatically. A caller must therefore be prepared to state the nature of the emergency and the caller’s location promptly and clearly.
15.2 Service interruptions. 9-1-1 calling does not function without electrical power and an active internet connection. Following a power failure or interruption, Client may need to reset or reconfigure affected equipment before the Service, including 9-1-1 calling, will function. Any Service outage for any reason — including suspension of Client’s account for non-payment — prevents all Service, including 9-1-1 calling. PROVIDER IS NOT RESPONSIBLE OR LIABLE FOR ANY EVENT OR OUTCOME OCCURRING DURING A PERIOD OF SERVICE INTERRUPTION OR SUSPENSION.
15.3 Registered address. The civic address Client registers with Provider is the address applied to the Service for 9-1-1 purposes. Client shall notify Provider immediately of any change of address. A change of address may take up to three (3) business days to take effect. Failure to register the current and correct civic address and physical location of equipment will result in 9-1-1 calls being routed to the wrong emergency service provider.
15.4 Nomadic use. 9-1-1 calling may not function properly, or at all, if equipment is used away from the registered civic address. If Client changes its primary telephone number, the 9-1-1 registered address cannot be changed for seventy-two (72) hours, and during that period 9-1-1 calls are routed using the address on record before the change.
15.5 Warning labels. Provider will supply warning labels describing the 9-1-1 limitations for affixing to each device that can be used to place calls. Client shall affix them and shall replace any that are removed or become illegible.
15.6 Regulatory basis. This Section is intended to satisfy Provider’s obligations under applicable Canadian Radio-television and Telecommunications Commission requirements respecting 9-1-1 service for local voice over internet protocol services, which apply uniformly throughout Canada, including the obligations to notify subscribers of the limitations of the service and to obtain an express acknowledgment of those limitations.
15.7 Rogue 9-1-1 calls. A “rogue 9-1-1 call” means a call placed to 9-1-1 through Provider from an unregistered automatic number identification. Rogue 9-1-1 calls are subject to a charge of five hundred dollars (CAD $500) per call. Client shall ensure that every call uses a registered automatic number identification with a correct civic address.
15.8 Indemnity. In addition to Section 19 of the MSA, Client shall defend, indemnify and hold harmless Provider, its directors, officers, employees, affiliates and agents, and any other service provider furnishing services to Client in connection with the Agreement, from and against all claims, losses, damages, fines, penalties, costs and expenses, including reasonable legal fees, brought by Client or by any third party or user of the Service relating to the absence, failure or outage of the Service, including 9-1-1 calling, or to the inability of any person to dial 9-1-1 or to reach emergency service personnel.
16. USE RESTRICTIONS AND INTERNATIONAL SERVICES
16.1 Client shall not use any VoIP Service: for any unlawful purpose; for making calls that use automatic dialing devices and terminate into electronic information services, pay-per-call services or other audiotext services; or for international call-back offerings using uncompleted call signalling to any country that has prohibited such an offering by statute or regulatory decision. Client shall not resell or transfer the Services or Equipment to any other person without Provider’s express written permission.
16.2 Provider may deny a request for Service for any lawful reason, and may limit or allocate the facilities available to or used by any Service where necessary to manage its network efficiently, to meet reasonable service expectations, or to furnish service to existing and future clients based on forecast requirements.
16.3 Consistent with applicable law and regulation, Provider may without notice block traffic to or from specific countries, country codes, cities, city codes, local telephone exchanges, individual telephone stations, groups or ranges of stations, or calls using certain authorization codes, where necessary to prevent unlawful use of the Services, non-payment, use in breach of the Agreement, or network blockage or degradation of service.
16.4 Foreign carriers or regulatory agencies may impose limitations or restrictions on the portion of an end-to-end international service they provide, and Client shall conform to them. Provider is not liable for the acts or omissions of other carriers or foreign telecommunications administrations. International calls are priced on the basis of the country and city codes dialled, and Provider is not liable for refunds or damages where calls do not terminate in the country, city or area code associated with the number called. Provider does not offer collect call or operator services with the Services.
PART C — MANAGED VIDEO SURVEILLANCE
This Part applies where the Order includes a video surveillance Service.
17. TESTING, COMMISSIONING AND WARRANTY
17.1 Provider will test the cabling, components, cameras, surveillance solutions and controls it installs before the commissioning walkthrough, and will provide a report detailing that testing. Provider will arrange to walk each surveillance space with a Client representative, demonstrate functionality, identify outstanding items, create a checklist of them, address them and demonstrate their completion.
17.2 Limited installation warranty. In addition to the warranties in the MSA, Provider warrants surveillance solution installations for one (1) year from the original invoice date. The warranty covers the items listed in the Order and other equipment sold and installed by Provider as part of the original installation, and covers parts, labour and standard shipping required to return the system to proper working condition.
17.3 The limited warranty covers improper workmanship directly associated with Provider’s installation of equipment, premature failure of equipment under normal operation as determined by Provider or the manufacturer, and the labour required to restore the system to its original operating condition.
17.4 The limited warranty does not cover: consumable items, including cameras and remote-control batteries; ground loop problems caused by faulty or unclean power; camera issues such as a dirty lens, alignment, focus or dust; routine maintenance recommended by the manufacturer or required by conditions; programming changes, including user interface changes, preset controls and the addition of buttons or pages; firmware or software updates released after the original installation; service requested as a result of operator error; service required as a result of negligence, misuse or attempted repair by anyone other than Provider or the manufacturer; connections or disconnections made by others; removal or reinstallation of equipment; or damage caused by lightning, electrical surge, brownout, overloaded circuits or acts of God.
17.5 The limited warranty begins at substantial completion of the Service and does not modify the manufacturer’s warranty.
17.6 NO MONITORING. THE SERVICES UNDER THIS PART DO NOT INCLUDE LIVE OR RECORDED MONITORING, ALARM VERIFICATION, GUARD RESPONSE OR NOTIFICATION OF ANY EVENT. PROVIDER DOES NOT WATCH, REVIEW OR RESPOND TO SURVEILLANCE FOOTAGE, AND IS NOT LIABLE FOR ANY LOSS, INJURY OR DAMAGE ARISING FROM AN EVENT THAT WAS OR WAS NOT CAPTURED.
17.7 Client’s privacy obligations. Client determines the purposes for which video surveillance is conducted, the placement and field of view of every camera, the retention period for recordings, and who may access them. Client is solely responsible for giving notice of surveillance to individuals, for limiting collection to what is reasonable and necessary, for compliance with applicable privacy legislation and any guidance issued by a privacy commissioner in respect of video surveillance, and, where cameras may capture its own personnel, for its obligations under applicable employment standards and labour legislation, including any requirement under the employment or labour legislation of the relevant province or territory to maintain a written electronic monitoring policy or to give notice of workplace monitoring. Provider’s role is limited to installing, configuring and maintaining the equipment specified in the Order.
PART D — MANAGED AUDIO/VISUAL SERVICES
This Part applies where the Order includes an audio/visual Service.
18. SCOPE, RESPONSIBILITIES AND EXCLUSIONS
18.1 Electrical, data and telecom. Client acknowledges that Provider is not a licensed electrical contractor and will not provide electrical wiring or connections. Electrical work is a regulated trade in every province and territory. Client is responsible for ensuring that sufficient power outlets are available for displays, screens, racks, furniture, lighting and other equipment, and for providing the data, CATV, CCTV and telecommunications connections required. Any work requiring a licensed electrician is Client’s responsibility and must be performed by a contractor holding the licence required in the province or territory where the work is performed.
18.2 Client shall provide timely and reasonable access to its facilities, systems, equipment and network; shall ensure that Provider’s access complies with Client’s internal security policies and applicable law; shall cooperate fully and designate representatives with decision-making authority; shall obtain and maintain all necessary permits, licences and approvals; shall operate the audio/visual systems in accordance with the manufacturer’s instructions and Provider’s directions; shall take reasonable precautions against damage, misuse and unauthorized access; and shall promptly notify Provider of any issue, defective equipment or system malfunction.
18.3 Client is responsible for backing up and securing its data and content stored on or transmitted through the audio/visual systems, and for implementing appropriate data protection measures including encryption, access controls and firewalls.
18.4 The following are excluded from the Services under this Part unless expressly agreed in an Order: consumables such as batteries and projector lamps; cosmetic repairs, including scratches and dents that do not affect functionality; damage or issues caused by user error, negligence, misuse or improper handling; issues or damage resulting from unauthorized modification, repair or alteration by Client or a third party; integration, support or maintenance of third-party services or software; relocation or removal of equipment from Client’s premises; loss, corruption of or unauthorized access to Client data or content stored on or transmitted through the audio/visual systems, except to the extent caused by Provider’s negligence or wilful misconduct; Services provided outside normal business hours, on weekends or on holidays; and the development, support or maintenance of custom software or applications not provided by Provider.
PART E — FEES, TERM AND TERMINATION
This Part applies to all Services delivered under this Service Attachment.
19. ONBOARDING FEE AND FEE ADJUSTMENTS
19.1 Before delivery of the Services, Provider may charge an onboarding fee to deploy and configure them. Provider will identify the onboarding fee in an initial invoice, payable in accordance with the MSA. Provider has no obligation to commence delivery of any Service until the onboarding fee is paid.
19.2 End-user and network growth. In addition to the fee adjustments described in the MSA, if during the term of an Order the number of Users or Devices in Client’s environment, or the types or quantities of Services or Equipment within the scope of the Order, exceeds the numbers previously ordered, Provider may adjust the total fees accordingly and Client shall pay them as they become due. If those numbers fall below the quantities previously ordered, Provider will, on Client’s request, apply a corresponding downward adjustment, provided that no adjustment may reduce the covered quantities below those ordered at the time Client signed the Order.
19.3 Definitions. “User” means an employee, consultant, contractor or agent of Client who is authorized to use the Services and has been supplied with credentials by Client or, at Client’s request, by Provider. Users do not include Client’s own customers or other third parties. “Device” means any equipment included in the Services, whether owned by Client or supplied by Provider, including computers, printers, servers, routers, mobile and handheld devices, together with the software necessary to operate them.
20. TERM, RENEWAL AND TERMINATION
20.1 This Service Attachment takes effect on the effective date of the Order referencing the Services and, unless properly terminated, continues to the end of the term specified in the Order (the “Initial Term”).
20.2 RENEWAL. THIS SERVICE ATTACHMENT RENEWS AUTOMATICALLY ON EXPIRY OF THE INITIAL TERM, AND ON EXPIRY OF EACH RENEWAL TERM, FOR A FURTHER TWELVE (12) MONTH PERIOD, UNLESS ONE PARTY GIVES THE OTHER WRITTEN NOTICE OF ITS INTENT TO TERMINATE AT LEAST SIXTY (60) DAYS BEFORE THE EXPIRY OF THE THEN-CURRENT TERM. ALL RENEWALS ARE SUBJECT TO PROVIDER’S THEN-CURRENT TERMS AND CONDITIONS AND, SUBJECT TO SECTION 3.5 OF THE MSA, ITS THEN-CURRENT RATES.
20.3 Renewal reminder. Provider shall use commercially reasonable efforts to give Client written notice of an approaching automatic renewal not less than ninety (90) days before the expiry of the then-current term. Failure to give that notice does not prevent the renewal from taking effect.
20.4 Month-to-month Services. Where the Order specifies no Initial Term for a Service, Provider will deliver that Service on a month-to-month basis until one party gives the other written notice of its intent to terminate, in which case delivery ceases at the end of the calendar month following the month in which notice is received.
20.5 Early termination by Client with cause. Client may terminate this Service Attachment for cause on sixty (60) days’ advance written notice where (a) Provider fails to fulfil in any material respect its obligations under this Service Attachment and fails to cure that failure within thirty (30) days after receiving written notice of it, or (b) Provider terminates or suspends its business operations, unless succeeded by a permitted assignee.
20.6 Early termination by Client without cause. Where Client has satisfied all of its obligations, then no sooner than ninety (90) days after the service start date, Client may terminate this Service Attachment without cause during the Initial Term or a Renewal Term on sixty (60) days’ advance written notice, provided that Client pays a termination fee equal to the aggregate of (a) all discounts and concessions provided to Client, and (b) fifty percent (50%) of the recurring monthly Service Fees remaining from the effective date of termination to the end of the then-current term, calculated at the prices then in effect. The parties agree that this amount is a genuine pre-estimate of Provider’s loss, reflects the fixed costs Provider has committed on the basis of the term, and is not a penalty.
20.7 Termination by Provider. Provider may terminate this Service Attachment on thirty (30) days’ advance written notice, with or without cause. Provider may terminate immediately for illegal or abusive conduct by Client. Provider may suspend the Services on ten (10) days’ notice where Client violates a third party’s end user licence agreement in respect of provided software, and on fifteen (15) days’ notice where Client’s act or omission prevents Provider from delivering the contracted Services.
20.8 Effect of termination. Provided Client is current in the payment of (a) the fees under this Service Attachment, (b) the fees under any Off-Boarding Order, and (c) any termination fee, Provider will assist Client in the orderly termination of the Services, including timely transfer of the Services to another designated provider, at Provider’s then-prevailing rates. Termination immediately ends Client’s access to the Services. Provider will uninstall affected software from Client’s devices and Client consents to that uninstallation. Section 12.3 of the MSA governs the release of Client-owned credentials, which is not conditional on payment. On request, Provider will provide Client with a copy of Client Data in exchange for a data-copy fee at Provider’s then-prevailing rates, not including the cost of media. Thirty (30) days after termination, Provider has no obligation to maintain Client Data and shall, unless legally prohibited, delete or securely destroy all Client Data in its possession or control. Provider may audit Client in respect of third-party services, may increase Off-Boarding fees to reflect third-party charges passed on to Provider, and Client shall pay all remaining third-party service fees and any third-party termination charges.