
Data Processing Agreement
Effective: August 24, 2026
This Data Processing Agreement (“DPA”) forms part of the agreement between Port 443 Inc. (“Port 443”, “we”, “us” or “Processor”) and the customer using the Port 443 Services (“Customer”, “you” or “Controller”), including the applicable Port 443 Terms of Service.
This DPA applies where Port 443 Processes Personal Data on behalf of Customer in connection with the Services.
If there is any conflict between this DPA and the Terms of Service concerning the Processing of Personal Data, this DPA will prevail to the extent of that conflict.
1. Definitions
1.1 “Applicable Data Protection Laws” means all data protection and privacy laws applicable to the Processing of Personal Data under this DPA, including, as applicable:
- Regulation (EU) 2016/679 (“EU GDPR”);
- the EU GDPR as incorporated into United Kingdom law (“UK GDPR”);
- the United Kingdom Data Protection Act 2018;
- Canada’s Personal Information Protection and Electronic Documents Act (“PIPEDA”) and applicable substantially similar provincial privacy legislation;
- applicable United States state privacy laws; and
- any amendment, replacement or successor legislation to the foregoing.
1.2 “Controller” means the person or entity that determines the purposes and means of Processing Personal Data.
1.3 “Data Subject” means an identified or identifiable natural person to whom Personal Data relates.
1.4 “Personal Data” means any information relating to an identified or identifiable natural person that is Processed by Port 443 on behalf of Customer through the Services.
1.5 “Personal Data Breach” means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Personal Data.
1.6 “Process”, “Processed” and “Processing” have the meanings given to those terms under Applicable Data Protection Laws.
1.7 “Processor” means a person or entity that Processes Personal Data on behalf of a Controller.
1.8 “Restricted Transfer” means a transfer of Personal Data that requires an adequacy regulation, adequacy decision or other international data-transfer safeguard under Applicable Data Protection Laws.
1.9 “Services” means the Port 443 products and services provided to Customer under the applicable Terms of Service, including TutorBird, My Music Staff and AthletaDesk, as applicable.
1.10 “Subprocessor” means a third party engaged by Port 443 to Process Personal Data on behalf of Customer in connection with the Services. A third party acting as an independent controller rather than as a processor is not a Subprocessor for purposes of this DPA.
2. Details of Processing
2.1 Subject Matter and Purpose. Port 443 Processes Personal Data as necessary to provide, secure, maintain, support and operate the Services in accordance with the agreement between Port 443 and Customer and Customer’s documented instructions.
2.2 Duration. Port 443 will Process Personal Data for the duration of Customer’s use of the Services and thereafter only for the period reasonably necessary to complete deletion, return, backup-retention or other obligations described in this DPA or required by applicable law.
2.3 Categories of Data Subjects. Depending on Customer’s use of the Services, Data Subjects may include:
- students and prospective students;
- parents, guardians and family contacts;
- instructors, tutors, teachers, coaches and other service providers;
- Customer’s employees, contractors and authorized users;
- customers, prospective customers and other contacts of Customer; and
- other individuals whose Personal Data Customer chooses to enter into or Process through the Services.
2.4 Types of Personal Data. Depending on Customer’s use and configuration of the Services, Personal Data may include:
- names and contact information;
- postal addresses, email addresses and telephone numbers;
- account and profile information;
- student, customer, parent or guardian information;
- lesson, appointment, attendance and scheduling information;
- billing, invoice and transaction-related information;
- communications and correspondence;
- notes and other information entered by Customer into the Services;
- device, IP address and technical usage information; and
- other Personal Data submitted by or on behalf of Customer through the Services.
Port 443 does not determine the categories of Personal Data that Customer chooses to submit to the Services except to the extent necessary to provide the functionality of the Services.
3. Controller Instructions and Responsibilities
3.1 Port 443 will Process Personal Data only:
- on Customer’s documented instructions;
- as necessary to provide the Services in accordance with Customer’s use and configuration of the Services; or
- where required to do so by applicable law.
Customer’s use and configuration of the Services, together with this DPA, the Terms of Service and any additional documented instructions accepted by Port 443, constitute Customer’s documented instructions.
3.2 If applicable law requires Port 443 to Process Personal Data other than on Customer’s instructions, Port 443 will notify Customer of that legal requirement before carrying out the Processing unless applicable law prohibits such notification.
3.3 If Port 443 reasonably believes that an instruction from Customer infringes Applicable Data Protection Laws, Port 443 will inform Customer without undue delay and may suspend the affected Processing until the parties have resolved the issue.
3.4 Customer is responsible for:
- determining the lawful purposes and legal basis for its Processing of Personal Data;
- providing any notices and obtaining any consents required by Applicable Data Protection Laws;
- ensuring that its instructions to Port 443 comply with Applicable Data Protection Laws; and
- determining which Personal Data Customer chooses to collect, enter and maintain through the Services.
4. Confidentiality and Personnel
Port 443 will ensure that persons authorized to Process Personal Data:
- are subject to appropriate contractual, statutory or professional confidentiality obligations;
- are provided access only where reasonably necessary for their duties; and
- Process Personal Data only in accordance with this DPA and Customer’s documented instructions.
- Port 443 will maintain appropriate access controls designed to restrict access to Personal Data to authorized personnel.
5. Security
5.1 Taking into account the state of the art, costs of implementation, nature, scope, context and purposes of Processing, and the risks to the rights and freedoms of individuals, Port 443 will implement and maintain appropriate technical and organizational measures designed to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access.
5.2 Such measures will include, as appropriate to the Processing and associated risks:
- controls governing access to systems and Personal Data;
- authentication and authorization controls;
- security protections for data in transit and at rest where appropriate;
- system monitoring and logging;
- vulnerability, patch and security management processes;
- backup and disaster-recovery procedures;
- confidentiality obligations and personnel security measures; and
- processes for responding to security incidents and Personal Data Breaches.
6. Subprocessors
6.1 General Authorization. Customer provides Port 443 with general authorization to engage Subprocessors where reasonably necessary to provide the Services.
6.2 Existing and New Subprocessors. Port 443 may continue to use its existing Subprocessors. Port 443 will provide at least 30 days’ notice before a new Subprocessor begins Processing Personal Data where required by Applicable Data Protection Laws.
6.3 Objections. Customer may object to the appointment of a new Subprocessor on reasonable grounds relating to the protection of Personal Data. The parties will work in good faith to address a reasonable objection.
6.4 Subprocessor Requirements. Before permitting a Subprocessor to Process Personal Data, Port 443 will:
- conduct appropriate diligence concerning the Subprocessor;
- enter into a written agreement requiring the Subprocessor to provide data-protection obligations substantially equivalent to those applicable to Port 443 under this DPA, to the extent required by Article 28 of the EU GDPR or UK GDPR;
- ensure that an appropriate international transfer mechanism is in place where required; and
- limit the Subprocessor’s access to Personal Data to what is reasonably necessary to perform the applicable services.
6.5 Responsibility. Port 443 remains responsible to Customer for the performance of its Subprocessors’ data-protection obligations to the extent required by Applicable Data Protection Laws.
6.6 Current List. Customer may request Port 443’s current list of Subprocessors, including applicable processing locations, by contacting privacy@port443.io.
7. International Data Transfers
7.1 Processing Locations. Personal Data may be Processed in Canada, the United States and other jurisdictions in which an approved Subprocessor operates, subject to the requirements of this section.
7.2 UK Restricted Transfers. Where Personal Data subject to the UK GDPR is transferred internationally, Port 443 may rely on applicable UK adequacy regulations, including the United Kingdom’s adequacy regulations applicable to Canada where the Processing is subject to PIPEDA, and the UK Extension to the EU-U.S. Data Privacy Framework where the U.S. recipient is an eligible certified participant.
7.3 Other UK Restricted Transfers. Where a Restricted Transfer is not covered by applicable UK adequacy regulations, Port 443 will ensure that an appropriate safeguard is in place as required by UK Data Protection Laws, which may include the UK International Data Transfer Agreement or the European Commission Standard Contractual Clauses together with the UK International Data Transfer Addendum.
7.4 Port 443 will take such additional measures as are reasonably required by Applicable Data Protection Laws in connection with a Restricted Transfer.
8. Data Subject Requests
8.1 Taking into account the nature of the Processing, Port 443 will provide reasonable assistance to Customer, through appropriate technical and organizational measures where practicable, to enable Customer to respond to requests by Data Subjects exercising their rights under Applicable Data Protection Laws.
8.2 If Port 443 receives a request directly from a Data Subject concerning Personal Data Processed by Port 443 solely on behalf of Customer, Port 443 may direct the Data Subject to Customer unless applicable law requires Port 443 to respond directly.
9. Personal Data Breaches
9.1 Port 443 will notify Customer without undue delay after becoming aware of a Personal Data Breach affecting Personal Data Processed on behalf of Customer.
9.2 Taking into account the nature of the Personal Data Breach and information available to Port 443, Port 443 will provide Customer with reasonable information and assistance necessary for Customer to meet applicable breach-notification obligations.
9.3 Port 443 will take reasonable steps to investigate, contain, mitigate and remediate a Personal Data Breach affecting the Services.
A notification under this section does not constitute an admission of fault or liability by Port 443.
10. Data Protection Impact Assessments and Regulatory Assistance
Taking into account the nature of the Processing and information available to Port 443, Port 443 will provide reasonable assistance to Customer with:
- data protection impact assessments concerning Processing carried out by Port 443 on Customer’s behalf; and
- consultations with competent data-protection authorities,
where such assistance is required under Article 35 or 36 of the EU GDPR, UK GDPR, or equivalent provisions of Applicable Data Protection Laws.
11. Return, Deletion and Backup Retention
11.1 Active Data. Customer may delete individual records through functionality made available within the Services or may request deletion where such functionality is not reasonably available.
11.2 End of Services. Upon termination or expiry of the Services, Port 443 will, at Customer’s choice, return or delete Personal Data Processed on Customer’s behalf and delete remaining copies, unless applicable law requires continued retention.
Customer is responsible for exporting Personal Data it wishes to retain before termination where self-service export functionality is available.
11.3 Backups. Due to the nature of backup and disaster-recovery systems, Personal Data deleted from active production systems may continue to exist temporarily within backup copies.
Port 443 currently retains:
- nightly database backups for up to 35 days; and
- certain longer-term backup snapshots for up to 12 months.
Accordingly, Personal Data that existed in a backup before deletion may remain within backup storage for a maximum period of up to 12 months before deletion through Port 443’s normal backup-retention lifecycle.
11.4 Beyond Use. Personal Data relating to deleted records that remains solely within backup systems will not be used for ordinary business Processing and will be retained only for legitimate backup, security and disaster-recovery purposes until the applicable backup expires.
Any Personal Data restored from backup remains subject to this DPA and applicable deletion obligations.
11.5 Legal Retention. Port 443 may retain Personal Data beyond the periods otherwise specified in this section only where required by applicable law, in which case Port 443 will limit Processing of the retained Personal Data to the purposes required by that law.
12. Demonstrating Compliance and Audits
12.1 Information Requests. Port 443 will make available to Customer, on reasonable request, information reasonably necessary to demonstrate compliance with Port 443’s obligations under this DPA and Article 28 of the EU GDPR or UK GDPR, as applicable.
Port 443 may satisfy such requests by providing relevant security documentation, policies, questionnaires, certifications, third-party audit materials, summaries of testing or assessments, or other information reasonably sufficient to demonstrate compliance.
12.2 Audits. Where the information provided under Section 12.1 is not reasonably sufficient to satisfy Customer’s legitimate compliance requirements, and where required by Applicable Data Protection Laws, Port 443 will allow for and contribute to a reasonable audit or inspection by Customer or an independent auditor appointed by Customer.
An audit or inspection under this section will be subject to the following conditions:
Customer will provide reasonable advance written notice;
- audits will ordinarily occur no more than once in any 12-month period;
- audits will take place during normal business hours;
- Customer and any auditor will be subject to appropriate confidentiality obligations;
- the audit will be limited to systems, records and Processing activities relevant to Customer’s Personal Data and Port 443’s obligations under this DPA;
- the audit will not require Port 443 to disclose information relating to other customers, privileged information, trade secrets, source code, penetration-testing details that could reasonably create a security risk, or information that Port 443 is prohibited from disclosing;
- audits will be conducted in a manner designed to minimize disruption to Port 443’s operations; and
- where reasonably practicable, remote review of documentation will be used before an on-site inspection is requested.
12.3 Exceptional Circumstances. The limitations on audit frequency in Section 12.2 will not apply where an additional audit is reasonably required:
- by a competent data-protection authority;
- following a Personal Data Breach materially affecting Customer’s Personal Data; or
- because Customer has reasonable grounds to believe that Port 443 is materially failing to comply with this DPA.
12.4 Costs. Customer will bear its own costs associated with an audit. Where an audit or related assistance requires material time or resources beyond Port 443’s ordinary compliance obligations, Port 443 may charge Customer reasonable fees based on the resources required, provided that Port 443 informs Customer of those anticipated fees in advance.
Port 443 will not charge such additional fees where the audit establishes a material breach of this DPA by Port 443.
12.5 Cooperation. Port 443 and Customer will cooperate in good faith to determine the most efficient and proportionate means of satisfying Customer’s reasonable audit and compliance requirements.
13. Relationship of the Parties
13.1 With respect to Personal Data that Customer submits to or Processes through the Services, Customer acts as Controller and Port 443 acts as Processor except where Applicable Data Protection Laws require a different characterization for a particular Processing activity.
13.2 This DPA does not apply to Personal Data for which Port 443 acts independently as a Controller, such as certain information concerning Customer’s own account relationship with Port 443. Such Processing is governed by Port 443’s Privacy Policy and Applicable Data Protection Laws.
13.3 Third-party services that act as independent controllers of Personal Data are not Subprocessors under this DPA and may be subject to their own privacy terms.
14. General Terms
14.1 Except as modified by this DPA, the Terms of Service remain in full force and effect.
14.2 Port 443 may update this DPA from time to time to reflect changes in Applicable Data Protection Laws, the Services or Port 443’s data-protection practices. Port 443 will not materially reduce the level of protection afforded to Personal Data under this DPA during the term of Customer’s use of the Services.
Where an update materially affects Customer’s rights or Port 443’s obligations concerning the Processing of Personal Data, Port 443 will provide reasonable notice in accordance with the Terms of Service or through the Services.
14.3 The governing law and dispute-resolution provisions of the Terms of Service apply to this DPA except where Applicable Data Protection Laws require otherwise.
14.4 If any provision of this DPA is determined to be invalid or unenforceable, the remaining provisions will remain in effect. The invalid or unenforceable provision will be interpreted or amended to the minimum extent necessary to make it valid and enforceable while preserving its intended effect as closely as possible.
14.5 Nothing in this DPA limits any rights or obligations that cannot lawfully be limited under Applicable Data Protection Laws.
SCHEDULE 1 — PROCESSING DETAILS
Controller: The Port 443 customer using the applicable Service.
Processor: Port 443 Inc., Ontario, Canada.
Subject matter: Processing of Personal Data in connection with the provision, hosting, operation, maintenance, security and support of the Services.
Duration: For the duration of Customer’s use of the Services, together with any limited post-termination period required for return, deletion, backups, legal compliance or other obligations described in this DPA.
Nature of Processing: Collection, receipt, organization, storage, retrieval, consultation, use, transmission, making available, modification, restriction, backup, deletion and other Processing reasonably necessary to provide the Services.
Purpose: To provide, operate, maintain, secure and support the Services at Customer’s direction.
Categories of Data Subjects: Students, prospective students, parents and guardians, customers and prospective customers, instructors, tutors, teachers, coaches, employees, contractors, authorized users and other contacts whose Personal Data Customer submits to the Services.
Types of Personal Data: Names, contact details, address information, account information, scheduling and attendance information, student/customer information, billing and transaction-related information, communications, notes, technical and usage information, and other information submitted by Customer through the Services.
Controller’s rights and obligations: As described in the Terms of Service, this DPA and Applicable Data Protection Laws.


Contact
Address
Drop us a line
