Data Processing Agreement โ Enterprise / Institutional Users
Effective: June 25, 2026 ยท Version: 1.0
This Data Processing Agreement (DPA) is a legally required document that governs how Piero Corradetti Consulting processes personal data on behalf of an Institution when the Institution deploys Unrelenting Resilience to its cohort. It defines who is responsible for what, what security measures are in place, what happens in a data breach, how long data is kept, and what happens to data when the agreement ends. This DPA must be executed before any Operative personal data is collected through the Platform. It forms part of the overall legal framework alongside the Enterprise Terms of Service and Enterprise Agreement.
PARTIES
Data Processor:
Piero Corradetti Consulting
Operating as Unrelenting Resilience
Ontario, Canada
unrelenting-resilience.ca
Data Controller (Institution):
Institution Name: ________________________________
Registered Address: ________________________________
Jurisdiction: ________________________________
Administrator Name: ________________________________
Administrator Title: ________________________________
Administrator Email: ________________________________
RECITALS
A. The Institution has entered into or is entering into an Enterprise Agreement and Enterprise Terms of Service with Piero Corradetti Consulting for the deployment of the Unrelenting Resilience platform to the Institution's defined cohort of Operatives.
B. In the course of providing the Platform services, Piero Corradetti Consulting will process personal data of the Institution's Operatives on behalf of the Institution.
C. Applicable privacy law โ including the Personal Information Protection and Electronic Documents Act (PIPEDA), Quebec's Act Respecting the Protection of Personal Information in the Private Sector (Law 25), the General Data Protection Regulation (GDPR), and the California Consumer Privacy Act (CCPA) โ requires that data processing activities carried out by a processor on behalf of a controller be governed by a written agreement setting out the subject matter, duration, nature, and purpose of the processing.
D. The parties wish to enter into this Data Processing Agreement to ensure that the processing of Operative personal data is carried out in compliance with applicable law and with appropriate protections for the rights and interests of Operative data subjects.
The parties therefore agree as follows:
1. Definitions
In this Agreement, the following terms have the meanings set out below. Where a term is not defined here, the definitions in the Enterprise Terms of Service and Privacy Policy apply.
- "Agreement" means this Data Processing Agreement, including all Schedules.
- "Applicable Privacy Law" means all privacy and data protection legislation applicable to the processing of Operative Personal Data under this Agreement, including without limitation PIPEDA, Law 25, GDPR, CCPA, and any other applicable federal, provincial, state, or national data protection legislation.
- "Controller" means the Institution, which determines the purposes and means of processing Operative Personal Data.
- "Processor" means Piero Corradetti Consulting, which processes Operative Personal Data on behalf of the Controller.
- "Data Subject" means an identified or identifiable natural person whose personal data is processed under this Agreement โ primarily, individual Operatives enrolled in the Institution's cohort.
- "Operative Personal Data" means any personal data relating to Operatives that is processed by the Processor on behalf of the Controller through the Platform. The categories of Operative Personal Data are set out in Schedule 1.
- "Processing" has the meaning given to it under Applicable Privacy Law and includes collecting, recording, storing, organizing, structuring, using, disclosing, transmitting, deleting, or destroying personal data.
- "Personal Data Breach" means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Operative Personal Data.
- "Sub-Processor" means any third party engaged by the Processor to carry out processing activities on Operative Personal Data on behalf of the Controller. Sub-Processors are listed in Schedule 2.
- "Cohort Data" means the full body of data generated by or relating to the Institution's Operatives within the Platform, as further described in Schedule 1.
- "Restricted Transfer" means a transfer of Operative Personal Data to a jurisdiction that does not provide an equivalent level of data protection under Applicable Privacy Law.
- "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses for the transfer of personal data to third countries adopted by the European Commission under GDPR Article 46(2)(c), as updated from time to time.
2. Roles of the Parties
2.1 Controller and Processor
For the purposes of this Agreement and Applicable Privacy Law:
- The Institution is the Controller with respect to Operative Personal Data. The Institution determines the purposes for which Operative Personal Data is collected (i.e., participation in the Unrelenting Resilience program) and the means by which it is collected (i.e., through the Platform under the Institution's enterprise account).
- Piero Corradetti Consulting is the Processor with respect to Operative Personal Data. Piero Corradetti Consulting processes Operative Personal Data only on the Controller's behalf and only as described in this Agreement and the Platform's Privacy Policy.
2.2 Independent Controller Activities
Piero Corradetti Consulting also processes certain personal data as an independent Controller โ for example, Administrator contact information used to manage the enterprise account and aggregated, anonymized platform usage data used for research and development. These activities are governed by the Privacy Policy and are not subject to this Agreement.
3. Processing Instructions
3.1 Documented Instructions
The Processor shall process Operative Personal Data only on the documented instructions of the Controller. The Controller's instructions are set out in this Agreement and the Enterprise Terms of Service and include:
- Processing Operative Personal Data to provide the Platform services described in the Enterprise Agreement.
- Storing Operative Personal Data in accordance with the retention periods set out in Section 8.
- Making Operative Personal Data accessible to the Controller's authorized Administrators through the Master Command Dashboard.
- Using anonymized and aggregated Operative Personal Data for platform improvement and research, as described in the Privacy Policy.
3.2 Changes to Instructions
The Controller may issue additional or amended processing instructions by written notice to the Processor. The Processor will implement compliant instructions within a reasonable timeframe. Where the Processor considers that an instruction infringes Applicable Privacy Law, the Processor shall promptly inform the Controller.
3.3 Processing Outside Instructions
If the Processor is required by applicable law to process Operative Personal Data other than in accordance with the Controller's instructions, the Processor shall notify the Controller before such processing unless prohibited from doing so by law.
4. Purpose and Nature of Processing
4.1 Purpose
The Processor processes Operative Personal Data solely for the purpose of providing the Unrelenting Resilience platform services to the Controller's enrolled Cohort, including:
- Account creation and authentication for Operative accounts.
- Delivery of the 8 Pillar daily mission program, gamification features, and XP tracking.
- Operation of The Eye AI mentor feature.
- Operation of the Comm-Link messaging system within the Controller's isolated Cohort.
- Delivery of structured courses and assessments through the Curriculum Forge.
- Making Cohort Data available to the Controller's Administrators through the Master Command Dashboard.
- Sending platform communications and re-engagement notifications to Operatives.
4.2 Prohibition on Independent Use
The Processor shall not process Operative Personal Data for its own purposes, for the benefit of any third party, or for any purpose not described in this Agreement or authorized in writing by the Controller โ with the exception of anonymized and aggregated data used for platform improvement, which cannot be linked to individual Operatives.
5. Data Subject Rights
5.1 Cooperation
The Processor shall provide reasonable assistance to the Controller in responding to Data Subject requests to exercise rights under Applicable Privacy Law, including rights of access, correction, erasure, restriction, portability, and objection.
5.2 Routing of Requests
Where a Data Subject submits a rights request directly to the Processor, the Processor shall:
- Notify the Controller within five (5) business days of receiving the request.
- Not respond to the request on the Controller's behalf without the Controller's written authorization, except where required by Applicable Privacy Law.
5.3 Controller Responsibility
The Controller is responsible for determining whether a Data Subject's rights request is valid and for directing the Processor's response. The Processor shall implement the Controller's instructions within a reasonable timeframe and in any event within the response period required by Applicable Privacy Law.
5.4 Deletion and Erasure
Where the Controller instructs the Processor to delete or erase an Operative's personal data in response to a Data Subject erasure request, the Processor shall:
- Delete the Operative's identifiable personal data from active systems within thirty (30) days of receiving the instruction.
- Certify completion of the deletion in writing to the Controller.
- Retain only anonymized data that cannot be linked to the individual Operative.
- Note that deletion may affect the Operative's ability to access the Platform.
6. Confidentiality
6.1 Personnel Confidentiality
The Processor shall ensure that all personnel authorized to process Operative Personal Data:
- Are bound by appropriate confidentiality obligations (whether contractual or statutory).
- Are informed of the confidential nature of the Operative Personal Data and their obligations under this Agreement.
- Access Operative Personal Data only to the extent necessary to perform their functions.
6.2 Processor Confidentiality
The Processor shall treat all Operative Personal Data as confidential and shall not disclose it to any person except:
- To authorized personnel for the purposes described in this Agreement.
- To Sub-Processors as described in Section 7.
- As required by Applicable Privacy Law or a lawful order, in which case the Processor shall notify the Controller as early as practicable before disclosure unless prohibited by law.
7. Sub-Processors
7.1 Authorized Sub-Processors
The Controller authorizes the Processor to engage the Sub-Processors listed in Schedule 2 to carry out specific processing activities on Operative Personal Data on the Controller's behalf.
7.2 Sub-Processor Obligations
The Processor shall ensure that each Sub-Processor is bound by written data processing obligations that are no less protective than those set out in this Agreement, including obligations with respect to confidentiality, security, and compliance with Applicable Privacy Law.
7.3 Processor Liability for Sub-Processors
The Processor remains fully liable to the Controller for the acts and omissions of its Sub-Processors to the same extent as if the Processor had carried out the processing directly.
7.4 Changes to Sub-Processors
The Processor shall notify the Controller at least thirty (30) days before adding or replacing a Sub-Processor that will process Operative Personal Data. The Controller may object to the addition or replacement within fifteen (15) days of notification on reasonable data protection grounds. If the parties cannot resolve the objection, the Controller may terminate the Enterprise Agreement on thirty (30) days' written notice without penalty.
8. Data Retention and Deletion
8.1 Retention During the Term
The Processor shall retain Operative Personal Data for the duration of the Enterprise Agreement and for any additional period required by Applicable Privacy Law or as specified in the Privacy Policy.
8.2 Retention After Termination
Upon termination or expiry of the Enterprise Agreement, the Processor shall, at the Controller's election:
- Return: Provide the Controller with a complete export of all Operative Personal Data in a structured, commonly used, machine-readable format within thirty (30) days of termination.
- Delete: Securely delete or anonymize all Operative Personal Data within sixty (60) days of termination, and provide the Controller with written certification of deletion.
The Processor may retain Operative Personal Data beyond these periods only where retention is required by Applicable Privacy Law, in which case the Processor shall notify the Controller of the retention obligation and the legal basis for it.
8.3 Anonymized Data
The Processor may retain anonymized and aggregated data derived from Operative Personal Data indefinitely for research and platform improvement purposes, provided that such data cannot reasonably be used to identify any individual Operative.
9. Security Measures
9.1 Technical and Organizational Measures
The Processor shall implement and maintain appropriate technical and organizational measures to protect Operative Personal Data against Personal Data Breaches and against unauthorized or unlawful processing. These measures are described in Schedule 3 and include at minimum:
- Encryption of Operative Personal Data in transit using TLS 1.2 or higher.
- Encryption of Operative Personal Data at rest using AES-256 or equivalent.
- Role-based access controls limiting access to Operative Personal Data to authorized personnel only.
- Multi-factor authentication for all administrative access to systems processing Operative Personal Data.
- Regular security assessments, vulnerability scanning, and penetration testing.
- Secure software development lifecycle practices.
- Physical security controls at data centre facilities.
- Business continuity and disaster recovery procedures.
9.2 Review and Updates
The Processor shall review and update the security measures described in Schedule 3 on at least an annual basis and promptly following any material change to the Platform's architecture or any Personal Data Breach.
9.3 Controller's Security Obligations
The Controller is responsible for maintaining the security of its own systems and for ensuring that its Administrators access the Master Command Dashboard using appropriately secured devices and credentials. The Processor's security obligations under this Agreement do not extend to the Controller's own systems, networks, or devices.
10. Personal Data Breach Notification
10.1 Processor Notification to Controller
In the event of a Personal Data Breach affecting Operative Personal Data, the Processor shall:
- Notify the Controller without undue delay and in any event within forty-eight (48) hours of becoming aware of the breach.
- Provide the Controller with the following information as soon as it is available:
- The nature of the Personal Data Breach, including the categories and approximate number of Data Subjects and personal data records affected.
- The name and contact details of the Processor's data protection contact point.
- The likely consequences of the breach.
- The measures taken or proposed to address the breach and mitigate its effects.
- Provide further information to the Controller as it becomes available.
10.2 Controller Notification to Regulators and Data Subjects
The Controller is responsible for notifying applicable regulatory authorities and affected Data Subjects of a Personal Data Breach in accordance with Applicable Privacy Law and within the timelines required by that law. The Processor shall cooperate fully with the Controller in preparing and delivering any required notifications.
10.3 Breach Remediation
The Processor shall take prompt and appropriate steps to contain, investigate, and remediate any Personal Data Breach and shall keep the Controller informed of progress throughout.
11. Data Protection Impact Assessments and Prior Consultation
Where required by Applicable Privacy Law โ including under GDPR Article 35 and Law 25's privacy impact assessment requirements โ the Processor shall provide reasonable assistance to the Controller in conducting data protection impact assessments relating to the processing of Operative Personal Data through the Platform.
Where prior consultation with a supervisory authority is required following a data protection impact assessment, the Processor shall cooperate with the Controller in preparing the required submissions.
12. International Data Transfers
12.1 Processing Location
The Processor primarily processes Operative Personal Data in Canada. Canada is recognized by the European Commission as providing an adequate level of data protection for commercial organizations under PIPEDA.
12.2 Sub-Processor Transfers
Where Sub-Processors process Operative Personal Data outside Canada or the EEA, the Processor shall ensure that appropriate transfer mechanisms are in place, including:
- Standard Contractual Clauses (SCCs) where required under GDPR.
- Contractual protections equivalent to those required under Applicable Privacy Law for transfers from Canadian jurisdiction.
12.3 Controller Transfers
The Controller is responsible for ensuring that its transfer of Operative Personal Data to the Processor (including through enrollment of Operatives on the Platform) is lawfully authorized under Applicable Privacy Law in the Controller's jurisdiction.
13. Audit Rights
13.1 Controller Audit Rights
The Controller has the right, on reasonable written notice of not less than thirty (30) days, to:
- Request and receive from the Processor documentation evidencing the Processor's compliance with this Agreement, including security certifications, audit reports, and records of processing activities.
- Conduct or commission an audit of the Processor's data processing activities relating to Operative Personal Data, at the Controller's expense, provided that:
- Audits are conducted no more than once per year unless a Personal Data Breach has occurred.
- Audits are conducted during normal business hours and in a manner that minimizes disruption to the Processor's operations.
- The Controller's auditors are bound by appropriate confidentiality obligations.
13.2 Processor Cooperation
The Processor shall cooperate fully with audits conducted under Section 13.1 and shall provide access to relevant systems, records, and personnel as reasonably required.
14. Records of Processing Activities
The Processor shall maintain records of its processing activities relating to Operative Personal Data as required by Applicable Privacy Law, including under GDPR Article 30. These records shall include:
- The name and contact details of the Processor and any Sub-Processors.
- The categories of processing carried out on behalf of the Controller.
- International transfers of Operative Personal Data and the safeguards in place.
- A general description of the technical and organizational security measures in place.
These records shall be made available to the Controller and to applicable supervisory authorities on request.
15. Term and Termination
15.1 Term
This Agreement commences on the date of execution and continues for the duration of the Enterprise Agreement, unless earlier terminated in accordance with this Section.
15.2 Termination
This Agreement terminates automatically upon termination or expiry of the Enterprise Agreement. Either party may also terminate this Agreement on written notice if the other party commits a material breach of this Agreement that is not remedied within fourteen (14) days of written notice.
15.3 Effect of Termination
Upon termination, the data return and deletion obligations in Section 8.2 apply. Sections 6 (Confidentiality), 9 (Security Measures), 12 (International Data Transfers), and 13 (Audit Rights) survive termination for a period of three (3) years or such longer period as required by Applicable Privacy Law.
16. Limitation of Liability
The liability of each party under this Agreement is subject to the limitation of liability provisions in the Enterprise Agreement and Enterprise Terms of Service. Nothing in this Agreement excludes or limits liability that cannot be excluded or limited under Applicable Privacy Law, including liability for fines or penalties imposed by a supervisory authority.
17. General Provisions
- Precedence: In the event of any conflict between this Agreement and the Enterprise Terms of Service or Enterprise Agreement, this Agreement prevails with respect to the processing of Operative Personal Data.
- Entire Agreement: This Agreement, together with its Schedules, constitutes the entire agreement between the parties with respect to the processing of Operative Personal Data.
- Amendment: This Agreement may only be amended by a written instrument signed by both parties, except that the Processor may update Schedule 2 (Sub-Processors) in accordance with Section 7.4.
- Severability: If any provision is found to be invalid or unenforceable, the remaining provisions continue in full force and effect.
- Governing Law: This Agreement is governed by the laws of the Province of Ontario and the federal laws of Canada applicable therein.
- Jurisdiction: The parties submit to the exclusive jurisdiction of the courts of Ontario, Canada.
18. Contact and Data Protection Inquiries
Piero Corradetti โ Data Protection Contact
Operating as Unrelenting Resilience
Website: unrelenting-resilience.ca
Jurisdiction: Ontario, Canada
For data protection inquiries, breach notifications, or Data Subject rights requests relating to this Agreement, please contact us through the website above.
Execution
By signing below (or executing electronically), the parties agree to be bound by the terms of this Agreement.
PROCESSOR โ Piero Corradetti Consulting
Signature: ________________________________
Name: Piero Corradetti
Title: Principal, Piero Corradetti Consulting
Date: ________________________________
CONTROLLER โ Institution
Signature: ________________________________
Full Legal Name: ________________________________
Title: ________________________________
Institution: ________________________________
Date: ________________________________
(Electronic execution via DocuSign or equivalent is accepted. A countersigned PDF will be provided to both parties following execution.)
SCHEDULE 1 โ Description of Processing Activities
To be completed for each Institution at time of execution.
| Field | Detail |
|---|---|
| Subject matter of processing | Delivery of the Unrelenting Resilience mental fitness training program to the Institution's enrolled Cohort |
| Duration of processing | For the term of the Enterprise Agreement and as required by applicable law thereafter |
| Nature of processing | Collection, storage, organization, use, disclosure, and deletion of Operative Personal Data through the Platform |
| Purpose of processing | Program delivery, engagement monitoring, course assessment, facilitator oversight, and platform improvement (anonymized only) |
| Categories of Data Subjects | Operatives enrolled in the Institution's cohort, including students, employees, members, or participants as applicable |
| Categories of Personal Data | Registration data (name, email, password hash); Activity data (XP, pillar scores, micro-action completions); Reflection log and journal content; Course assessment responses; Comm-Link messages; The Eye conversation logs; Engagement and usage analytics; Device and browser technical data; IP addresses and session logs |
| Special categories of data | No special categories of personal data (as defined under GDPR Article 9) are intentionally collected. Reflection log and The Eye conversation content may incidentally contain sensitive personal information. The Controller is responsible for advising its Operatives not to submit special category data through the Platform. |
| Maximum Cohort Size | As specified in the Enterprise Agreement Schedule A |
| Retention period | As set out in Section 8 of this Agreement and the Privacy Policy |
SCHEDULE 2 โ Authorized Sub-Processors
Current as of the effective date. Updated in accordance with Section 7.4.
| Sub-Processor | Location | Processing Activity | Safeguards |
|---|---|---|---|
| Cloud infrastructure / hosting provider (Supabase, Inc. / Vercel, Inc.) | USA | Hosting Platform infrastructure and storing Operative Personal Data at rest | DPA in place; encryption at rest and in transit |
| Payment processor (Stripe, Inc.) | USA | Processing subscription and license fee payments (billing data only โ no Operative activity data) | PCI-DSS compliant; DPA in place |
| Email delivery provider (Resend, Inc.) | USA | Delivering transactional emails, onboarding communications, and re-engagement notifications | DPA in place; data minimization |
| AI model provider (Google LLC - Gemini API) | USA | Processing conversation inputs to generate The Eye responses in real time | DPA in place; data not used for model training; no retention beyond response generation |
The Processor will notify the Controller of any changes to this Schedule in accordance with Section 7.4.
SCHEDULE 3 โ Technical and Organizational Security Measures
The Processor implements and maintains the following security measures with respect to Operative Personal Data:
Encryption
- All Operative Personal Data transmitted between the user's device and the Platform is encrypted using TLS 1.2 or higher.
- All Operative Personal Data stored at rest is encrypted using AES-256 or equivalent.
- Database backups containing Operative Personal Data are encrypted using the same standard.
Access Controls
- Access to systems processing Operative Personal Data is restricted to authorized personnel on a need-to-know basis using role-based access controls.
- Multi-factor authentication (MFA) is required for all administrative access to production systems.
- Access privileges are reviewed quarterly and revoked promptly upon personnel departure.
- The Processor maintains an access log for all administrative access to systems containing Operative Personal Data.
Network Security
- Production systems are isolated behind firewalls and network segmentation controls.
- Intrusion detection and prevention systems are in place.
- Regular vulnerability scanning is conducted on externally accessible systems.
Application Security
- The Platform is developed following secure software development lifecycle (SSDLC) practices.
- Third-party dependencies are monitored for known vulnerabilities.
- Penetration testing is conducted at least annually by qualified security personnel.
Physical Security
- Operative Personal Data is processed in data centres with appropriate physical access controls, including badge access, CCTV, and 24/7 monitoring.
- The Processor does not maintain on-premises data storage containing Operative Personal Data.
Incident Response
- The Processor maintains a documented Personal Data Breach response procedure.
- A designated contact is responsible for receiving and acting on breach notifications.
- The Processor's 48-hour notification obligation to the Controller under Section 10.1 is operationalized through this procedure.
Business Continuity
- Regular backups of Operative Personal Data are maintained and tested.
- A business continuity and disaster recovery plan is in place and reviewed annually.
Personnel
- All personnel with access to Operative Personal Data receive data protection training on joining and annually thereafter.
- All personnel are bound by contractual confidentiality obligations.