Cohvia
    ProductPricingAbout
    Sign InSign Up

    Legal

    Terms of ServiceConditions d'utilisation (FR)Privacy PolicyPolitique de confidentialité (FR)Cookie PolicyData Processing AgreementSubprocessorsAcceptable Use Policy

    Data Processing Agreement

    Last updated: May 31, 2026

    This Data Processing Agreement ("DPA") forms part of, and is incorporated into, the Terms of Service (the "Agreement") between SACS Ecommerce Stores Inc., operating as "Cohvia" ("Cohvia," "Processor") and the customer that accepts the Agreement ("Customer," "Controller"). It applies where and to the extent Cohvia processes Customer Personal Data on Customer's behalf in providing the Service. By accepting the Agreement, Customer accepts this DPA. Where the Agreement and this DPA conflict on matters of personal-data processing, this DPA controls.


    1. Definitions

    "Applicable Data Protection Law" means all laws governing the processing of personal data applicable to a party, including the EU General Data Protection Regulation (Regulation (EU) 2016/679) ("EU GDPR"), the UK GDPR and Data Protection Act 2018 ("UK GDPR"), the Swiss Federal Act on Data Protection, the California Consumer Privacy Act as amended ("CCPA") and other US state privacy laws, Canada's PIPEDA, and Quebec's Law 25.

    "Customer Personal Data" means personal data within Customer Data that Cohvia processes on Customer's behalf under the Agreement.

    "Controller," "Processor," "Data Subject," "Personal Data," "Processing," "Personal Data Breach" have the meanings in the EU GDPR (and equivalent terms such as "business," "service provider," and "consumer" under the CCPA apply correspondingly).

    "Subprocessor" means a third party engaged by Cohvia to process Customer Personal Data.

    "Standard Contractual Clauses" / "SCCs" means the clauses in Commission Implementing Decision (EU) 2021/914, Module Two (Controller-to-Processor).


    2. Roles and scope

    2.1 Customer is the Controller (or a processor acting on behalf of a third-party controller) of Customer Personal Data; Cohvia is the Processor. Where Customer is itself a processor, Cohvia is a subprocessor, and Customer warrants it has the controller's authority to engage Cohvia on these terms.

    2.2 Cohvia will process Customer Personal Data only as a Processor, in accordance with this DPA and Customer's documented instructions.

    2.3 The subject matter, duration, nature and purpose of processing, types of personal data, and categories of data subjects are set out in Exhibit A.


    3. Processing instructions

    3.1 Cohvia will process Customer Personal Data only on Customer's documented instructions, including regarding international transfers, unless required by law (in which case Cohvia will inform Customer first, unless legally prohibited). The Agreement, this DPA, and Customer's configuration and use of the Service constitute Customer's complete instructions.

    3.2 Cohvia will inform Customer if, in its opinion, an instruction infringes Applicable Data Protection Law (without obligation to provide legal advice).

    3.3 No training; purpose limitation. Cohvia will not use Customer Personal Data to train, fine-tune, or improve any AI or machine-learning model, and will not process Customer Personal Data for any purpose other than providing the Service and as instructed. Cohvia routes AI processing to commercial model providers contractually committed not to train on submitted data.

    3.4 CCPA service-provider terms. With respect to personal information under the CCPA, Cohvia is a "service provider." Cohvia will not (a) sell or share such personal information; (b) retain, use, or disclose it for any purpose other than the business purposes specified in the Agreement, or outside the direct business relationship; or (c) combine it with personal information from other sources except as permitted by the CCPA. Cohvia certifies it understands and will comply with these restrictions.


    4. Confidentiality

    Cohvia ensures that personnel authorized to process Customer Personal Data are bound by appropriate confidentiality obligations and access it only as needed to provide the Service.


    5. Security

    5.1 Cohvia will implement and maintain appropriate technical and organizational measures to protect Customer Personal Data against unauthorized or unlawful processing and accidental loss, destruction, or damage, taking into account the state of the art, costs, and the nature and risk of processing. Current measures are described in Exhibit B.

    5.2 Cohvia may update its security measures provided they do not materially reduce the overall level of protection.


    6. Subprocessors

    6.1 General authorization. Customer provides general written authorization for Cohvia to engage Subprocessors. The current list is at Subprocessors list.

    6.2 Changes and right to object. Cohvia will give Customer at least 30 days' notice (for example by updating the subprocessors page and offering a subscription to notifications) before adding or replacing a Subprocessor. Customer may object on reasonable data-protection grounds within that period; the parties will work in good faith to resolve the objection, and if they cannot, Customer may terminate the affected part of the Service.

    6.3 Flow-down and liability. Cohvia will impose data-protection obligations on each Subprocessor that are no less protective than this DPA and will remain liable for each Subprocessor's performance.


    7. Data subject requests

    7.1 Taking into account the nature of the processing, Cohvia will assist Customer by appropriate technical and organizational measures, insofar as possible, to respond to requests from Data Subjects exercising their rights.

    7.2 The Service provides functionality enabling Customer to access, correct, export, and delete Customer Personal Data. If Cohvia receives a request directly from a Data Subject, it will (unless legally required to respond) refer the request to Customer.

    7.3 Cohvia will provide reasonable assistance beyond standard self-service functionality; significant additional assistance may be subject to reasonable fees, communicated in advance.


    8. Personal data breaches

    8.1 Cohvia will notify Customer without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach affecting Customer Personal Data.

    8.2 The notice will describe, to the extent known, the nature of the breach, the categories and approximate number of data subjects and records affected, likely consequences, and measures taken or proposed. Where the information is not all available at once, Cohvia may provide it in phases without undue further delay.

    8.3 Cohvia will take reasonable steps to mitigate and will cooperate with Customer's breach-notification obligations to authorities and data subjects. Cohvia's notification is not an acknowledgment of fault.


    9. DPIAs and prior consultation

    Cohvia will provide reasonable assistance to Customer with data protection impact assessments and prior consultations with supervisory authorities, taking into account the nature of processing and information available to Cohvia.


    10. Return and deletion of data

    10.1 On termination or expiry of the Agreement, Cohvia will, at Customer's choice, return or delete Customer Personal Data.

    10.2 Cohvia will make Customer Personal Data available for export for 30 days after termination (the "export window"), after which Cohvia will delete it within 60 days, including from active systems and (within its standard cycles) backups.

    10.3 Deletion cascades to derived data, including embeddings and AI-generated outputs created from the deleted data. Cohvia may retain data where required by law, kept only for that purpose and protected.

    10.4 On Customer's written request, Cohvia will certify deletion.


    11. Audits and information

    11.1 Cohvia will make available information reasonably necessary to demonstrate compliance with this DPA, including third-party audit reports or certifications where available (such as SOC 2 reports, once obtained).

    11.2 Where Applicable Data Protection Law grants an audit right, Customer may, on reasonable prior notice, no more than once per year (except where required by a supervisory authority or following a breach), conduct an audit limited to relevant information and conducted so as not to disrupt Cohvia's operations or compromise other customers' confidentiality. The parties will agree on scope, timing, and cost in advance.


    12. International transfers

    12.1 To the extent Cohvia processes Customer Personal Data subject to EU GDPR, UK GDPR, or Swiss law in a country without an adequacy decision, the Standard Contractual Clauses (Module Two) are incorporated into this DPA by reference and apply, with:

    (a) Clause 7 (docking) included; Clause 9 option 2 (general subprocessor authorization, 30 days) applies; Clause 11 optional language excluded; Clause 17 governed by the law of Ireland; Clause 18 forum the courts of Ireland;

    (b) Annexes populated by Exhibits A, B, and C of this DPA.

    12.2 For UK transfers, the UK International Data Transfer Addendum to the SCCs applies, with Tables completed using this DPA's Exhibits. For Swiss transfers, the SCCs apply with references adapted to Swiss law and the Swiss Federal Data Protection and Information Commissioner as supervisory authority.

    12.3 Where a Subprocessor is certified under the EU-US Data Privacy Framework (and UK/Swiss extensions), transfers to it may also rely on that certification.

    12.4 If the chosen transfer mechanism is invalidated, the parties will work in good faith to implement an alternative lawful mechanism.


    13. Liability

    13.1 Each party's liability under this DPA is subject to the limitations and exclusions in the Agreement, except where Applicable Data Protection Law (including the SCCs) requires otherwise. Liability of the data importer toward data subjects under the SCCs is not limited by this Section.


    14. General

    14.1 This DPA takes effect on acceptance of the Agreement and remains in force while Cohvia processes Customer Personal Data. Terms that should survive (including Sections 10–13) survive termination.

    14.2 If any part of this DPA conflicts with the SCCs, the SCCs prevail for transfers they govern.

    14.3 This DPA is governed by the law stated in the Agreement, except where Applicable Data Protection Law or the SCCs require a specific governing law.


    Exhibit A — Details of Processing

    Parties. Data exporter: Customer (Controller). Data importer: SACS Ecommerce Stores Inc. (operating as Cohvia) (Processor), 620 King Street North, Suite 1004, Waterloo, Ontario N2J 4G8, Canada.

    Subject matter: Provision of the Cohvia AI customer-success platform.

    Duration: The term of the Agreement, plus the export and deletion periods in Section 10.

    Nature and purpose: Hosting, storage, organization, retrieval, and AI-assisted analysis of business communications and records to generate account narratives, insights, and plans for Customer.

    Types of Personal Data: Business contact details (name, email, job title, employer); identifiers and account/authentication data; content of communications (call transcripts, emails, support tickets) and CRM records, which may contain personal data about Customer's personnel and Customer's customers/prospects; usage data. Customer controls what data it submits and should not submit special categories of personal data except as agreed under the Agreement.

    Categories of Data Subjects: Customer's authorized users and personnel; individuals at Customer's customer/prospect accounts who appear in ingested communications and records.

    Frequency of transfer: Continuous, for the duration of the Agreement.

    Supervisory authority (SCCs Annex): The Irish Data Protection Commission (DPC), or, where the data exporter is established in another EEA member state, the supervisory authority of that member state.


    Exhibit B — Technical and Organizational Measures

    Cohvia maintains measures including, as applicable:

    • Encryption: TLS for data in transit; encryption at rest for stored data.
    • Access control: role-based access; least-privilege; unique credentials; multi-factor authentication for administrative access; logical tenant isolation between customers.
    • Network and application security: hardened cloud infrastructure, firewalls, and secure development practices.
    • Subprocessor management: AI processing routed to providers committed to zero data retention / no training where available.
    • Logging and monitoring: audit logging of administrative and security-relevant events.
    • Resilience: backups and recovery procedures.
    • Personnel: confidentiality obligations and security awareness.
    • Incident response: documented breach detection and response process, including notification under Section 8.
    • Data lifecycle: deletion procedures that cascade to derived data (embeddings and AI outputs).

    [Update this Exhibit as your security posture matures — e.g., add SOC 2 Type II, ISO 27001, penetration-testing cadence once obtained.]


    Exhibit C — Subprocessors

    The current list of Subprocessors, including each Subprocessor's name, role/processing activity, and location, is maintained at Subprocessors list, which is incorporated into this DPA by reference. The list currently includes providers for cloud hosting, database, authentication, data integration, AI model routing, payments, and analytics.


    Contact for data-protection matters: privacy@cohvia.com — SACS Ecommerce Stores Inc. (operating as Cohvia), 620 King Street North, Suite 1004, Waterloo, Ontario N2J 4G8, Canada.

    Cohvia

    Customer Context Platform

    Product

    • Overview
    • Relationship intelligence
    • Handovers
    • Planning & execution
    • Book health
    • Scaling & leverage
    • Pricing

    Solutions

    • CS leaders
    • CSMs
    • Account executives
    • Team of one
    • For customers

    Company

    • About
    • Contact

    Resources

    • Customer Context Platform
    • Customer Narrative
    • AI Success Plans
    • Security
    • Privacy
    • Cookie preferences
    • Do Not Sell or Share My Personal Information
    • Cookie Policy
    • Terms
    • DPA
    • Subprocessors

    © 2026 Cohvia. All rights reserved.

    TwitterLinkedIn