WeDisplay · Legal
Data Processing Addendum
This Data Processing Addendum ("DPA") forms part of, and is incorporated by reference into, the WeDisplay Terms of Service(the "Terms") between the customer entity that has agreed to the Terms ("Customer", "you", or "your") and EN6IA (Québec enterprise number (NEQ) 2266497173), operating as "WeDisplay" ("WeDisplay", "we", "us", or "our"). It applies whenever WeDisplay processes Customer Personal Data (as defined below) on Customer's behalf in connection with the digital signage platform described in the Terms, including our dashboard, applications, player software, APIs, and related services (collectively, the "Service"). Capitalized terms not defined in this DPA have the meaning given to them in the Terms.
This DPA is entered into automatically, without further action by either party, upon Customer's acceptance of the Terms and continued use of the Service to process Customer Personal Data. A countersigned copy is available on request to [email protected] for Customers who require one for their own records or third-party diligence.
1. Definitions
- "Controller"means the natural or legal person which, alone or jointly with others, determines the purposes and means of the processing of personal data (or, under Law 25, the "person or body responsible for personal information"). For Customer Personal Data, Customer is the controller.
- "Processor"means the natural or legal person which processes personal data on behalf of a controller (or, under Law 25, a "person or body to whom personal information is communicated to carry out an act on behalf of" the controller). For Customer Personal Data, WeDisplay is the processor.
- "Personal data"(or "personal information") means any information relating to an identified or identifiable natural person.
- "Customer Personal Data"means personal data that WeDisplay processes on Customer's behalf and on Customer's documented instructions in the course of providing the Service, including (a) personal data about Customer's team members that Customer or its team members submit to the Service to administer their account, screens, sources, and permissions, and (b) any personal data that Customer or its team members choose to include within Customer Content (for example, in uploaded media, layouts, schedules, or data-widget configurations). It does not include personal data for which WeDisplay is itself the controller, such as account, billing, website-visitor, and marketing data, which is instead governed by our Privacy Policy.
- "Data subject" means the identified or identifiable natural person to whom Customer Personal Data relates.
- "Sub-processor" means a third party engaged by WeDisplay to process Customer Personal Data in order to provide the Service, as listed in Annex III.
- "Law 25" means Québec's Act respecting the protection of personal information in the private sector, and "GDPR" means the General Data Protection Regulation (EU) 2016/679, in each case as amended from time to time.
2. Roles of the Parties
As between Customer and WeDisplay, and with respect to Customer Personal Data, Customer is the controller and WeDisplay is the processor. WeDisplay processes Customer Personal Data solely to provide, secure, support, and maintain the Service in accordance with the Terms and this DPA, and does not determine the purposes or means of that processing.
Where Customer itself acts as a processor on behalf of a third party (for example, where Customer provides signage services to its own clients), Customer represents that it has all rights and authorizations necessary to instruct WeDisplay to process the related personal data as set out in this DPA, and WeDisplay will process such data solely as a sub-processor of Customer under those instructions.
3. Scope, Duration, Nature and Purpose of Processing
Subject matter. The provision of the Service by WeDisplay to Customer, to the extent that provision involves the processing of Customer Personal Data.
Duration. WeDisplay will process Customer Personal Data for the duration of the Terms, and thereafter only for the wind-down period described in Section 9 (Deletion or Return of Data) or as otherwise required by applicable law.
Nature and purpose of processing.WeDisplay processes Customer Personal Data as necessary to operate the digital signage Service Customer has subscribed to — including storing, transmitting, displaying, and organizing Customer Content; authenticating Customer's team members, screens, players, and sources; enforcing the access permissions Customer configures; providing customer support; and maintaining the security, availability, and reliability of the Service — and for no other purpose.
Types of Customer Personal Data and categories of data subjects.The specific types of Customer Personal Data processed, and the categories of data subjects to whom it relates, are determined and controlled solely by Customer through its use of the Service. Typically, this consists of (a) the names, email addresses, and role/permission assignments of Customer's own team members who are given access to the Service, and (b) any personal data that Customer or its team members choose to include within Customer Content displayed through the Service (for example, images, video, or documents that depict or reference identifiable individuals, or personal data pulled into a data widget Customer configures). Customer is solely responsible for ensuring it has a lawful basis to submit any such personal data to the Service, consistent with Section 4 (Customer Content & Responsibility) of the Terms. WeDisplay does not intend for, and asks Customer not to use, the Service to process special categories of personal data (such as health, biometric, or precise geolocation data relating to identified individuals) unless Customer has independently assessed and accepts responsibility for the heightened risk of doing so.
4. Processor Obligations
WeDisplay will, with respect to Customer Personal Data:
- Process only on documented instructions.Process Customer Personal Data only on Customer's documented instructions, which consist of the Terms, this DPA, and Customer's configuration and use of the Service's features (for example, uploading Customer Content or inviting a team member), unless otherwise required by applicable law, in which case WeDisplay will inform Customer of that legal requirement before processing, unless the law prohibits such disclosure on important grounds of public interest. WeDisplay will promptly notify Customer if, in its opinion, an instruction infringes applicable data protection law.
- Confidentiality. Ensure that personnel authorized to process Customer Personal Data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality, and access Customer Personal Data only to the extent necessary to perform their duties in providing the Service.
- No sale of Customer Personal Data.Not sell Customer Personal Data, and not use it for WeDisplay's own independent marketing or advertising purposes, or for any purpose other than providing the Service as instructed by Customer.
- Security. Implement and maintain the technical and organizational security measures described in Annex II.
- Sub-processing. Engage sub-processors only as permitted by Section 6 (Sub-Processors) of this DPA.
5. Security Measures (Annex II)
WeDisplay maintains administrative, technical, and organizational security measures designed to protect Customer Personal Data appropriate to its sensitivity, including:
- Organization-scoped data isolation— every query and record in the Service is scoped to Customer's organization, so one customer's data is not visible to another.
- Encryption of sensitive secrets at rest — credentials such as connected-calendar tokens and AI-provider API keys are encrypted before storage.
- Encryption in transit — connections to the Service, its APIs, and its player software are protected using TLS.
- Upload and media-serving controls — uploaded files are validated by their actual file signature (magic bytes), and media is served only when it corresponds to a registered upload tracked in our database (never an arbitrary filesystem path), with protection against path-traversal.
- SSRF-guarded outbound proxy— where the Service fetches external content on Customer's behalf (for example, for data widgets), outbound requests are routed through a proxy that blocks requests to internal or unauthorized network destinations.
- Role-based access control — access within an organization is governed by a set of granular, individually assignable permissions, so team members receive only the access their role requires.
- Rate limiting — sensitive endpoints such as account registration, password reset, and device pairing are rate-limited to reduce the risk of automated abuse.
- Audit logging — sensitive account and administrative actions are logged for accountability and investigation.
- Boot-time secret safeguard — production systems refuse to start if configured with a default or insufficiently strong authentication secret.
- Backups — the production database is backed up on a regular schedule and stored with an infrastructure provider that encrypts data at rest.
These measures are reviewed and updated from time to time to reflect changes in the Service and in good security practice; any change will maintain or improve, and will not materially diminish, the overall level of protection during the term of the Terms. WeDisplay does not currently hold any third-party security certification (such as SOC 2, ISO 27001, PCI DSS, or HIPAA attestation), and makes no representation that it does; Customer should take this into account when assessing whether the Service is suitable for its intended use of Customer Personal Data.
6. Sub-Processors (Annex III)
Customer authorizes WeDisplay to engage the following sub-processors to provide the Service. Each is bound by contractual confidentiality and data-protection obligations appropriate to the personal data it may process:
| Sub-processor | Purpose |
|---|---|
| Stripe | Payment and billing processing |
| Authentication/OAuth sign-in; Google Calendar integration (where Customer connects it) | |
| Microsoft | Authentication/OAuth sign-in; Outlook/Exchange calendar integration (where Customer connects it) |
| GitHub | Authentication/OAuth sign-in |
| Resend | Transactional email delivery (invites, receipts, notifications) |
| Anthropic | Optional AI Assistant feature, when enabled by Customer |
| Cloudflare | Content delivery network, web-application firewall, and object storage |
| OVH | Cloud infrastructure hosting |
WeDisplay's WebRTC relay (TURN/coturn) infrastructure, used to help live-streaming sources and players connect across networks, is self-hosted on WeDisplay's own servers and is not operated by a third-party sub-processor.
WeDisplay remains responsible for each sub-processor's compliance with obligations materially equivalent to those set out in this DPA. If WeDisplay intends to add or replace a sub-processor that will process Customer Personal Data, we will provide reasonable advance notice by posting an updated version of this page with a revised effective date, or by direct notice (email or in-app) for material changes. Customer may object to a new sub-processor on reasonable data-protection grounds by contacting [email protected]within 15 days of notice; if the parties cannot resolve the objection, Customer's exclusive remedy is to terminate the affected part of the Service in accordance with the Terms.
7. Assistance with Data Subject Requests and Compliance Obligations
Taking into account the nature of the processing, WeDisplay will provide Customer with reasonable assistance, by appropriate technical and organizational measures, to enable Customer to respond to requests from data subjects seeking to exercise their rights under applicable data protection law (such as access, rectification, deletion, or portability requests) with respect to Customer Personal Data. Where WeDisplay itself receives such a request directly from a data subject in relation to Customer Personal Data, WeDisplay will not respond directly (except to confirm receipt or direct the individual to Customer) and will instead promptly forward the request to Customer, unless legally prohibited from doing so.
WeDisplay will also provide Customer with reasonable assistance in meeting its obligations relating to the security of processing, notification of personal-data breaches to supervisory authorities and data subjects, and, where applicable, data protection impact assessments and related prior consultation with supervisory authorities, taking into account the information available to WeDisplay and the nature of the processing.
8. Personal-Data Breach Notification
If WeDisplay becomes aware of a confidentiality incident or personal-data breach affecting Customer Personal Data, WeDisplay will notify Customer without undue delay after becoming aware of it, and will provide the information reasonably available to WeDisplay to assist Customer in meeting its own breach-notification obligations to regulators and affected data subjects. WeDisplay will also take reasonable steps to contain, investigate, and mitigate the impact of the incident.
9. Deletion or Return of Data
On termination or expiry of the Terms, WeDisplay will make Customer Personal Data available for export and, following the Retention Period described in Section 13 (Suspension and Termination) of the Terms, will delete Customer Personal Data from its production systems, except to the extent WeDisplay is required or permitted by applicable law to retain it (for example, for legal, tax, security, or dispute-resolution purposes), in which case WeDisplay will continue to protect that data in accordance with this DPA for as long as it is retained.
10. Audit and Information Rights
WeDisplay will make available to Customer the information reasonably necessary to demonstrate compliance with this DPA, and will allow for and contribute to audits, including inspections, conducted by Customer or an independent auditor mandated by Customer, subject to reasonable advance written notice, confidentiality protections for WeDisplay's and its other customers' information, and no more than once per 12-month period unless required by a supervisory authority or conducted following a confirmed personal-data breach. Where reasonably practicable, WeDisplay may satisfy an audit request by providing relevant documentation describing its security measures in lieu of an on-site inspection.
11. International Transfers
WeDisplay is based in Québec, Canada, and processes Customer Personal Data on infrastructure located in Canada, the United States, and the European Union, including through the sub-processors listed in Section 6. Where a transfer of Customer Personal Data outside Québec is required by that processing, WeDisplay has conducted, or will conduct on request, a transfer impact assessment consistent with the requirement under Law 25 to ensure the recipient jurisdiction or organization provides a level of protection for personal information that is equivalent to that required in Québec. Where the GDPR applies to Customer Personal Data and it is transferred outside the European Economic Area or United Kingdom to a jurisdiction that has not received an applicable adequacy decision, WeDisplay relies on the European Commission's Standard Contractual Clauses (or the UK International Data Transfer Addendum, as applicable) with the relevant sub-processor, or another legally recognized transfer mechanism, as the safeguard for that transfer.
12. Order of Precedence; Governing Law; General
In the event of a conflict between the terms of this DPA and the Terms with respect to the processing of Customer Personal Data, this DPA prevails to the extent of the conflict. In all other respects, the Terms continue to apply, including its provisions on liability, indemnification, and dispute resolution, which apply to this DPA as if fully set out here.
This DPA is governed by the same governing law as the Terms — the laws of the Province of Québec and the federal laws of Canada applicable therein — without regard to conflict-of-law principles that would apply the law of another jurisdiction. This DPA is entered into automatically upon Customer's acceptance of the Terms and use of the Service to process Customer Personal Data, and remains in effect for as long as WeDisplay processes Customer Personal Data on Customer's behalf. Customers who require a manually executed copy, or who have questions about this DPA, may contact [email protected].
Questions about this document? Contact [email protected]. See all policies in the Legal Center.