// LEGAL DOCUMENT
Data Processing Addendum
Effective August 8, 2026 · Version 1.1
This document is provided for general information and to govern your use of the service. It is not legal advice. If you have questions about how it applies to you, please contact us.
01Applicability & Parties
This Data Processing Addendum (the “DPA”) forms part of, and is incorporated by reference into, the Terms of Use (the “Terms”) between The Gig App, operator of the GIG platform available at thegigapp.ca (“GIG”, “we”, “us” or the “Processor”), and the organization customer that has accepted the Terms (“you”, the “Customer” or the “Controller”). Capitalized terms used but not defined in this DPA have the meanings given to them in the Terms.
This DPA applies only where, and to the extent that, the Customer is an Organization (a subscribing entity or account holder that operates a workspace within GIG, the “Organization”) that uploads, submits, or otherwise causes GIG to Process Personal Information about identifiable third parties through the Service. Such third parties include, without limitation, the Organization’s contractors, staff, employees, gig workers, event attendees, contacts, businesses, and end clients (collectively, “Data Subjects”). The data so handled is the “Customer Personal Information”.
This DPA does not apply to, and does not govern, Personal Information for which GIGis itself the controller — namely the account, registration, billing, payment, usage, log, security, and support information that GIG collects about the Customer and its authorized users in order to operate, secure, bill for, and improve the Service. GIGProcesses that information as an independent controller in accordance with its Privacy Policy, and not under the documented instructions of the Customer. Where this DPA and the Privacy Policy both speak to a given dataset, the characterization in Section 3 governs which instrument applies.
By accepting the Terms, the Customer (acting through an individual representing that they have authority to bind the Organization) enters into this DPA on behalf of the Organization. If the individual accepting does not have that authority, they must not use the Service.
02Definitions
The following definitions apply to this DPA. They are framed by reference to the federal Personal Information Protection and Electronic Documents Act (“PIPEDA”) and applicable provincial privacy law in Canada, and they also recognize the equivalent concepts used in international data-protection frameworks (such as the European General Data Protection Regulation, “GDPR”) for the benefit of Customers and Data Subjects located outside Canada.
- Controller means the Organization (the Customer), being the party that alone or jointly determines the purposes and means of the Processing of Customer Personal Information. Under PIPEDA the Controller is the “organization” accountable for the Personal Information under its control; under the GDPR it is the “controller”.
- Processor means The Gig App (GIG), being the party that Processes Customer Personal Information on behalf of, and on the documented instructions of, the Controller. This corresponds to a “third party to whom an organization transfers personal information for processing” under PIPEDA and to a “processor” under the GDPR.
- Sub-processor means any third party engaged by GIG that Processes Customer Personal Information in connection with providing the Service (for example, infrastructure, hosting, payment, or monitoring providers).
- Personal Information means information about an identifiable individual, consistent with PIPEDA, and includes any “personal data” within the meaning of the GDPR. “Customer Personal Information” means Personal Information about Data Subjects that the Customer Processes through the Service as described in Section 1.
- Data Subject means the identifiable individual to whom Customer Personal Information relates.
- Processing (and “Process”) means any operation performed on Personal Information, including collection, recording, organization, storage, retrieval, consultation, use, disclosure, transmission, hosting, encryption, anonymization, retention, deletion, or destruction.
- Service means the GIG software-as-a-service platform and related features made available under the Terms, including the Entity, Architect, Finance, Data, Forms, Gigs/Events, Profile, Notifications, Settings, and administrative modules.
- Content means the data, records, files, and materials the Customer and its authorized users submit to or generate within the Service, which may contain Customer Personal Information.
03Roles & Scope of Processing
As between the parties, the Customer is the Controller of Customer Personal Information and determines the purposes and means of its Processing; GIG is the Processor and Processes Customer Personal Information only to provide, secure, maintain, and support the Service in accordance with the documented instructions of the Customer, the Terms, this DPA, and applicable law. The Customer’s configuration and use of the Service, together with the Terms and this DPA, constitute the Customer’s complete and final documented instructions for Processing. GIG will not Process Customer Personal Information for its own purposes, will not sell it, and will not use it for advertising.
Subject matter, nature and purpose. The subject matter of the Processing is the provision of the Service. The nature and purpose is the hosting, storage, organization, transmission, and display of Customer Personal Information so that the Customer can operate its gig-economy and event-management workflows. The duration of the Processing is the term of the Customer’s subscription and the period thereafter described in Section 11.
Categories of Data Subjects and Personal Information, by module. The categories vary with how the Customer configures and uses the Service:
- Entity (contacts, businesses, contractor pipeline). Data Subjects: contacts, businesses, prospective and engaged contractors. Personal Information: names, email addresses, phone numbers, mailing and billing addresses, photographs, biographies, designations, and Customer-defined custom fields.
- Architect (projects and info-card blocks). Data Subjects: any individual referenced in a project or block, including where a project is published read-only to a public share-link page (
/p/[slug], no-index). Personal Information: whatever the Customer places in project blocks. - Finance (budgets, invoices, payments, payouts, disputes, memberships, approvals). Data Subjects: the Customer’s own clients, payees, members, and approvers. Personal Information: billing and line-item detail, invoice and payment records, payout references, and — for magic-link approvals at
/approve/[token]— the approver’s email address, IP address, and user-agent captured in an immutable approvals audit log. Card data is handled by Stripe; GIG does not store full card numbers (only brand, last four digits, and expiry). - Data (custom tables and charts). Data Subjects and Personal Information: whatever the Customer chooses to record in custom tables.
- Forms (public forms at
/f/[id]). Data Subjects: any person — including unauthenticated members of the public — who submits a published form. Personal Information: the submitter’s answers and email address. - Gigs/Events (day-sheets at
/gig/[token], intake at/gig/join). Data Subjects: event attendees and self-registrants. Personal Information: attendee name, email, role, RSVP status, plus-ones, dietary requirements, travel details (flights and hotels), call times, and uploaded rider files. - Profile and gig profiles (
/profile, updates at/update-profile/[token]). Data Subjects: individual gig workers and profile holders. Personal Information: designation, biography, headshot, social links, rate cards, contractor agreements, and a private e-transfer email. The public discovery view exposes designation, biography, logo, and social links, but not the private e-transfer email. - Notifications and Settings. Data Subjects: members and account administrators. Personal Information: in-app inbox messages, organization name, logo, and address, and member roles.
04Customer (Controller) Obligations
The Customer is responsible, as Controller, for the lawfulness of the Customer Personal Information it Processes through the Service. In particular, the Customer represents, warrants, and undertakes that it will:
- establish and maintain a valid legal basis — including, where required, the knowledge and consent of the relevant Data Subjects under PIPEDA (or other applicable law) — for the collection, use, and disclosure of Customer Personal Information through the Service, including its upload to, and Processing by, GIG and its Sub-processors;
- provide the Data Subjects with all notices, and obtain all consents, required by applicable privacy law regarding the Processing contemplated by this DPA, including the cross-border transfer described in Section 8 and the lawful-access risk described there;
- ensure that the Customer Personal Information is accurate, complete, and current to the extent necessary for the purposes for which it is Processed, and promptly correct or update it through the Service as needed;
- issue instructions to GIG only where doing so complies with applicable law, and not instruct GIG to Process Customer Personal Information in a manner that would cause either party to breach applicable law;
- comply with its obligations under the Acceptable Use Policy, including not uploading Personal Information about others without lawful authority; and
- respond, as the first point of contact, to requests from its own Data Subjects to access, correct, or delete the Customer Personal Information held in its workspace, with the assistance described in Section 9.
05GIG (Processor) Obligations
GIG, as Processor, undertakes that it will:
- Documented instructions. Process Customer Personal Information only on the documented instructions of the Customer (as expressed in the Terms, this DPA, and the Customer’s configuration and use of the Service), and as required by applicable law. IfGIG is required by law to Process Customer Personal Information otherwise, it will, where legally permitted, inform the Customer before doing so. If GIG believes an instruction infringes applicable privacy law, it will notify the Customer.
- Confidentiality of personnel. Ensure that the personnel authorized to Process Customer Personal Information are bound by appropriate obligations of confidentiality and are made aware of the confidential nature of the data, and limit access to those personnel who need it to provide, secure, or support the Service.
- Security. Implement and maintain the technical and organizational measures described in Section 6.
- Sub-processors. Engage Sub-processors only as described in Section 7.
- Assistance. Taking into account the nature of the Processing and the information available to it, provide reasonable assistance to the Customer in meeting the Customer’s own obligations under applicable privacy law, including with respect to Data Subject requests (Section 9), personal data breaches (Section 10), and regulator inquiries.
- No independent use. Not Process the Customer Personal Information for any purpose other than providing the Service, and not retain, use, or disclose it for its own commercial purposes.
06Security Measures
GIG will implement and maintain technical and organizational security measures designed to protect Customer Personal Information against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, appropriate to the sensitivity of the information. These measures currently include the following, whichGIG may update from time to time provided that it does not materially reduce the overall level of protection:
- Tenant isolation. Per-organization data isolation enforced at the database layer through row-level security, so that each Organization’s workspace is logically segregated from others.
- Encryption at rest of sensitive tokens. AES-256-GCM encryption of sensitive tokens and similar secrets within the application, using a managed encryption key.
- Encryption in transit. Encryption of data in transit over public networks using current transport-layer security.
- Access controls. Role-based access within the Service (owner, admin, employee, staff, and contractor roles), administrative access limited to authorized personnel, and scoped, time-limited magic-link tokens for approval, profile-update, and gig day-sheet and intake flows (for example, profile-update links expiring after 48 hours, and gig day-sheet links expiring seven days after the gig end), with session-binding on approval links.
- Immutable audit logs. Append-only, immutable audit logging of sensitive administrative and approval actions — including, for external approvals, capture of the approver’s email, IP address, and user-agent — which cannot be altered or deleted.
- File storage controls. Storage of uploaded files (such as headshots, organization logos, and gig rider files) in storage buckets served by public or signed URLs as configured for the relevant feature, with applicable upload-size limits.
- Vendor diligence. Reliance on reputable infrastructure Sub-processors (Section 7) that maintain their own recognized security programs.
The Customer is responsible for the security of credentials issued to its users, for configuring access roles appropriately, and for its decisions about which features and public-facing pages (for example, public project pages, public forms, public gig profiles, and day-sheet links) to enable and how widely to distribute share-links. No method of transmission or storage is perfectly secure.
07Sub-processors
The Customer provides GIG with a general authorization to engage Sub-processors to Process Customer Personal Information in connection with providing the Service. GIGwill impose on each Sub-processor, by written contract, data-protection obligations that are substantially equivalent to those set out in this DPA, and GIG remains responsible to the Customer for the performance of its Sub-processors’ obligations in respect of Customer Personal Information.
As of the effective date of this DPA, the authorized Sub-processors are:
- Supabase — managed Postgres database, authentication, and file storage, and the sending of authentication and magic-link emails. Processing locations include the United States (regions us-east-2 and us-west-2).
- Stripe (including Stripe Connect) — payment processing, subscriptions, invoicing, and platform payment facilitation. Card data is handled by Stripe; GIGdoes not store full card numbers.
- Vercel — application hosting and content delivery via United States and global edge infrastructure.
GIG will give the Customer reasonable prior notice (which may be given by updating this DPA, posting a sub-processor list, or notifying account administrators) before adding or replacing a Sub-processor that Processes Customer Personal Information. If the Customer has a reasonable, good-faith objection to a new Sub-processor on data-protection grounds, the Customer may notify GIG of the objection within a reasonable period after notice; the parties will discuss the objection in good faith, and if it cannot be resolved, the Customer’s sole remedy is to terminate the affected subscription in accordance with the Terms.
08International / Cross-border Transfers
GIG operates from Ontario, Canada. However, by virtue of the Sub-processors listed in Section 7, Customer Personal Information is stored and Processed outside Canada, including in the United States. The Customer acknowledges and authorizes this transfer for processing.
Consistent with PIPEDA’s accountability principle and the guidance of the Office of the Privacy Commissioner of Canada on transfers for processing, GIG uses contractual and other means to require each Sub-processor to provide a comparable level of protection for Customer Personal Information while it is being Processed on GIG’s behalf, wherever located.
Lawful-access risk. The Customer acknowledges that, while Customer Personal Information is stored or Processed outside Canada, it may be accessible to the courts, law enforcement, and governmental or regulatory authorities of the foreign jurisdiction under the laws of that jurisdiction (including United States legal process), regardless of the safeguards GIG or its Sub-processors put in place. The Customer is responsible for informing its Data Subjects of this possibility where required by applicable law.
Quebec and other provincial requirements. Where the Customer or any Data Subject is located in Quebec, the parties acknowledge that the Customer may be required to conduct a privacy impact assessment before communicating Personal Information outside Quebec under Quebec’s private-sector privacy law; GIG will, on reasonable request, provide information reasonably available to it about the nature, locations, and safeguards of the Processing to assist the Customer with such an assessment. Nothing in this DPA relieves the Customer of its own obligations under applicable provincial law.
09Data Subject Requests
The Customer, as Controller, is responsible for responding to requests from its Data Subjects to exercise their rights under applicable privacy law, including rights of access, correction, deletion, withdrawal of consent, and — where applicable under Quebec or other law — data portability.
Taking into account the nature of the Processing, GIG will provide the Customer with reasonable assistance, through appropriate technical and organizational measures and the self-service tools available in the Service, to enable the Customer to respond to such requests in relation to Customer Personal Information held in its workspace. Where the Customer cannot accomplish a request using the self-service tools, GIG will provide reasonable assistance on request.
If GIG receives a request directly from a Data Subject that relates to Customer Personal Information, GIG will, unless legally prohibited, promptly direct the Data Subject to the relevant Customer and will not respond to the substance of the request except on the Customer’s documented instructions or as required by law.
10Personal Data Breach
GIG will notify the Customer without undue delay after becoming aware of a breach of security safeguards affecting Customer Personal Information (a “Personal Data Breach”). The notification will include, to the extent then known and to the extent GIG is lawfully able to disclose it, a description of the nature of the breach, the categories and approximate volume of Customer Personal Information and Data Subjects affected, the likely consequences, and the measures taken or proposed to address it.
GIG will provide the Customer with information reasonably available to it, and reasonable cooperation, to enable the Customer to meet its own legal obligations as Controller — including, under PIPEDA, assessing whether the breach creates a real risk of significant harm to an individual and, where it does, reporting to the Office of the Privacy Commissioner of Canada, notifying affected individuals and any organization that can reduce the risk of harm, and maintaining records of the breach for the prescribed period. Where any Data Subject is located in Quebec, GIG will likewise assist the Customer with its confidentiality-incident obligations under applicable Quebec law.
The obligation to report a Personal Data Breach to a regulator or to notify affected individuals rests with the Customer as Controller, and GIG’s notification to the Customer is not an acknowledgment of fault or liability. GIG’s independent breach obligations relating to data for which it is the controller are addressed in its Privacy Policy.
11Return & Deletion
During the subscription term, the Customer may access and export its Content, including Customer Personal Information, using the features available in the Service. On expiry, cancellation, or other termination of the subscription, the Customer will have a reasonable window — as described in the Terms — to export its Content before it becomes unavailable.
Following that window, GIG will delete or return Customer Personal Information in accordance with the Customer’s instructions and the operation of the Service, subject to the following:
- certain records are subject to soft-deletion by status (for example, subscription and membership records), while organization deletion by a platform administrator and account deletion trigger a cascading hard deletion of associated records;
- immutable, append-only audit logs are retained as required for integrity and recordkeeping and are not deletable;
- form submissions and notifications are retained until deleted by the Organization;
- residual copies may persist for a limited period in routine, time-limited backups managed by GIG’s infrastructure Sub-processors before being overwritten in the ordinary backup cycle; and
- GIG may retain Customer Personal Information to the extent, and for as long as, required by applicable law, in which case it will continue to protect it in accordance with this DPA.
On the Customer’s written request, GIG will confirm in writing that it has deleted Customer Personal Information in accordance with this Section, save for copies retained as permitted above.
12Audits
On the Customer’s reasonable written request, and no more than once in any twelve-month period unless required by a regulator or following a Personal Data Breach, GIG will make available to the Customer information reasonably necessary to demonstrate its compliance with this DPA. GIG may satisfy this obligation by providing summary documentation of its security measures or relevant third-party attestations or certifications (such as a SOC 2 report or equivalent), where available, in lieu of granting direct access to systems.
Any audit or information request must: be conducted during normal business hours and on reasonable advance notice; not unreasonably interfere with GIG’s operations; be subject to strict confidentiality obligations; not access the data or systems of other customers or any information whose disclosure would compromise the security of the Service; and be at the Customer’s expense. The auditor must not be a competitor of GIG.
13Liability
Each party’s liability arising out of or related to this DPA, whether in contract, tort (including negligence), or otherwise, is subject to, and counts toward, the exclusions and limitations of liability set out in the Terms. The aggregate liability of either party under this DPA and the Terms, taken together, is governed by the limitation-of-liability provisions of the Terms and is not increased by this DPA. Nothing in this DPA limits any liability that cannot be limited or excluded under applicable law.
14Governing Law & Precedence
This DPA is governed by the laws of the Province of Ontario and the federal laws of Canada applicable therein, without regard to conflict-of-laws principles, consistent with the governing-law and dispute-resolution provisions of the Terms(including any statutory rights of consumer or sole-proprietor Customers that cannot be waived under Ontario’s Consumer Protection Act, 2002).
This DPA forms part of the Terms. In the event of any conflict or inconsistency between this DPA and the remainder of the Terms with respect to the Processing of Customer Personal Information, this DPA prevails. In all other respects, the Terms continue in full force and effect. The Acceptable Use Policy and Cookie Policy continue to apply in accordance with the Terms.
15Contact
Questions about this DPA, or requests relating to the Processing of Customer Personal Information, may be directed to GIG’s privacy contact at Admin@thegigapp.ca. General enquiries may be sent to Admin@thegigapp.ca. For information about how GIG handles Personal Information as a controller, and about complaints to the Office of the Privacy Commissioner of Canada, see the Privacy Policy.
