Data processing and confidentiality
Last updated: June 21, 2026
This page summarizes commitments expected in a Data Processing Addendum ("DPA") between DrivingOps and a school customer. It does not replace a signed DPA and does not by itself create additional contractual obligations.
1. Parties and roles
For data a school enters into the service, the school is normally the organization responsible for the information or the controller, and DrivingOps acts as a service provider or processor. The exact legal characterization depends on the law and processing activity.
2. Subject matter, duration, and instructions
We process data during the service term and agreed return, deletion, or retention period, only to provide, secure, maintain, and support DrivingOps under the agreement, customer configuration, and documented instructions. We will inform the customer if an instruction appears to violate applicable law.
3. People and data categories
People may include owners, employees, instructors, learners, parents, guardians, prospects, and support contacts. Data may include identity, contact, account, enrolment, schedule, attendance, progress, communications, invoices, documents, consent, necessary notes, logs, and technical identifiers.
4. Confidentiality
We treat customer data as confidential. Access is limited to personnel and providers who need it for their duties and are bound by confidentiality. We do not sell customer data, use it for behavioural advertising, or use learner records to train third-party general-purpose models.
5. Security measures
Measures are proportionate to risk and, depending on the environment, include encryption in transit and at rest, logical tenant isolation, roles and permissions, managed identity, secrets management, logging, backups, monitoring, change control, and incident response. See the Security overview.
6. Sub-processors
We may use sub-processors to provide the service. We remain responsible for contractual oversight and impose relevant obligations. The current list is on the Sub-processor page. Notice and objection mechanics are defined in the signed DPA.
7. Transfers outside Quebec or Canada
Core workloads are designed for Canada, but some providers or optional features may process data elsewhere. We provide information reasonably needed for the customer's privacy impact assessment and put required contractual safeguards in place.
8. Individual requests
If we receive a request about data controlled by a school, we forward it to the school unless legally prohibited. We reasonably assist with access, correction, withdrawal, portability, deletion, or information about an automated decision.
9. Security incidents
After confirming an incident affecting customer data, we notify the customer without undue delay under the DPA and provide available information to help assess risk, maintain records, notify people or regulators, and mitigate effects. We do not make a public statement on the customer's behalf without authorization unless legally required.
10. Compliance assistance
Taking account of the service and information available to us, we reasonably assist with privacy impact assessments, security, incidents, and applicable regulatory consultations. Extraordinary requests may be subject to agreed fees.
11. Audit and information
We provide reasonable information demonstrating DPA compliance, such as policies, control summaries, or available reports. Audit terms, including confidentiality, notice, scope, frequency, and cost, are defined in the signed DPA.
12. Return and deletion
At the end of service, the customer can export data under the agreement. We then delete or anonymize it, except data retained by law, for a dispute, or through the normal backup lifecycle. Retained data remains protected and is not used for other purposes.
13. Customer duties
The customer must have authority and a lawful basis, provide notices, manage consent, configure access, minimize data, and define applicable retention schedules. It remains responsible for its decisions and obligations to individuals.
14. Requesting the DPA
To request the full DPA, technical measures, or the list applicable to your environment, email hello@drivingops.ca.
These are pre-launch documents provided for transparency and legal review. A signed agreement or order form may contain additional terms and will control if there is a conflict. Questions? Contact us.