Data Processing Agreement
Effective Date: October 8, 2026
This Data Processing Agreement ("DPA") is part of the Terms of Service between Visionary Creations Inc. ("Cortana") and the customer that uses Cortana ("Customer"). It applies to the personal information Cortana processes on the Customer's behalf ("Customer Personal Data") and takes effect when the Customer accepts the Terms. Where this DPA and the Terms differ on the protection of personal information, this DPA governs.
1. Roles
The Customer decides why and how Customer Personal Data is processed and is the controller (or "business"). Cortana processes it on the Customer's behalf as a processor (or "service provider"). The details of the processing are in Annex 1.
Written to: GDPR Art. 28(1), (3); CCPA Cal. Civ. Code § 1798.140(ag), 11 CCR § 7051; PIPEDA Sch. 1, Principle 4.1.3; Quebec Private Sector Act s. 18.3.
2. Cortana's Obligations
- Instructions. Cortana processes Customer Personal Data only on the Customer's documented instructions: the Terms, this DPA and the settings and configuration the Customer chooses in Cortana. Cortana will tell the Customer if it believes an instruction breaks the law.
- Confidentiality. Cortana staff and contractors who can access Customer Personal Data are bound to keep it confidential.
- Security. Cortana maintains the measures in Annex 2.
- Assistance. Cortana helps the Customer answer requests from people exercising their rights, and with impact assessments and consultations with authorities, as far as the nature of the processing allows. A request Cortana receives directly about Customer Personal Data is passed to the Customer.
- Incidents. Cortana tells the Customer without undue delay after becoming aware of a breach affecting Customer Personal Data, with the information it has, and keeps updating it.
- Deletion. Tracking data is deleted 60 days after the Customer's Ad Tracking subscription ends when no other plan is active. Other Customer Personal Data is deleted from Cortana on the Customer's request, within the times the law sets; copies held by subprocessors follow their own retention. The Customer may ask Cortana for a copy of its data before deletion.
- Information and audits. Cortana makes available the information reasonably needed to show compliance with this DPA, and allows audits by the Customer or an auditor it appoints, on reasonable notice, at the Customer's cost, no more than once a year unless an authority requires it.
Written to: GDPR Art. 28(3)(a)–(h), 32–36; CCPA § 1798.100(d), 11 CCR § 7051(a); PIPEDA Principles 4.1.3, 4.7, s. 10.1; Quebec Private Sector Act ss. 3.5–3.8, 18.3, 23.
3. Subprocessors
The Customer authorizes Cortana to use subprocessors for hosting, databases, storage, messaging, AI models, analytics and support. Each one processes Customer Personal Data under its own data processing terms with Cortana, and Cortana remains responsible for them. Cortana provides the current list to the Customer on request, and tells a Customer that asks for notice before adding or replacing a subprocessor that processes its data; the Customer may object within 30 days on reasonable data-protection grounds, and if Cortana cannot address the objection, the Customer may end the affected service.
Written to: GDPR Art. 28(2), (4); 11 CCR § 7051(a)(8); PIPEDA Principle 4.1.3; Quebec Private Sector Act s. 18.3.
4. International Transfers
Cortana and its main subprocessors process Customer Personal Data in the United States. Where a transfer of personal data from the European Economic Area, the United Kingdom or Switzerland needs a transfer mechanism, the Standard Contractual Clauses adopted by the European Commission (Module Two, controller to processor, or Module Three, processor to processor), with the UK Addendum and the Swiss amendments where they apply, are incorporated into this DPA by reference.
Written to: GDPR Arts. 44–46, Commission Implementing Decision (EU) 2021/914; UK GDPR Art. 46 and the UK International Data Transfer Addendum; Swiss FADP Art. 16; Quebec Private Sector Act s. 17.
5. U.S. State Privacy Laws
As the Customer's service provider or processor, Cortana:
- does not sell or share Customer Personal Data;
- does not retain, use or disclose it outside the direct business relationship with the Customer, or for any purpose other than providing Cortana as described in the Terms;
- does not combine it with personal information from other sources, except as the law allows a service provider to do in providing the service;
- complies with the laws that apply to it and gives the same level of protection they require;
- tells the Customer if it can no longer meet these obligations; and
- allows the Customer to take reasonable steps to stop and remedy unauthorized use.
Written to: CCPA Cal. Civ. Code § 1798.100(d), § 1798.140(ag), 11 CCR § 7051; Va. Code § 59.1-579; Colo. Rev. Stat. § 6-1-1305; Conn. Gen. Stat. § 42-521.
6. The Customer's Obligations
- The Customer has a lawful basis for the processing and gives people the notices, and obtains the consents, the law requires — including for the Cortana pixel and cookies on its websites, for messages and calls its AI agents make, and for call recording.
- The Customer's instructions comply with the law.
- The Customer answers requests from people about their personal information, with Cortana's help under Section 2.
Written to: GDPR Arts. 6, 13–14, 24; PIPEDA Principle 4.3; Quebec Private Sector Act ss. 8, 8.1; CCPA § 1798.100(b); Cal. Penal Code § 632; TCPA 47 U.S.C. § 227.
7. Liability and Term
The limitations of liability in the Terms apply to this DPA. This DPA lasts as long as Cortana processes Customer Personal Data.
Annex 1 — Details of the Processing
- Subject matter and purpose: providing Cortana — attributing leads and sales to their source, running the Customer's AI agents and messaging, syncing the Customer's CRM and calendars, sending conversions to the ad platforms the Customer connects, and supporting the Customer.
- Duration: while the Customer uses Cortana, then until deleted as described in Section 2.
- People concerned: the Customer's website visitors, leads, contacts, buyers and callers, and the Customer's own team members.
- Types of personal information: names, email addresses, phone numbers and addresses; online identifiers (cookie IDs, IP addresses, user agents, ad click IDs) and device signals; browsing activity and approximate location; form answers and signatures; messages, call recordings and transcripts; bookings, purchases and payments; and any custom fields the Customer adds.
- Sensitive information: Cortana is not designed to process sensitive personal information; the Customer should not configure it to collect such information.
Annex 2 — Security Measures
- Encryption of personal information in transit (TLS).
- Restricted access to the credentials of the services the Customer connects, which are being moved to encrypted storage.
- Access to a business's data limited to that business's authorized users, and to Cortana staff who need it to provide support.
- Authentication for every user of the app; signature or token verification on incoming webhooks, being completed across every integration.
- Logging of sensitive operations.
- Security review of changes before they ship, and a remediation record kept against SOC 2 and ISO 27001 controls.
Questions about this DPA: [email protected] (Privacy Officer: Matei Parvu).
