# PIPEDA & Québec Law 25 Privacy Addendum

### Canada — Privacy Addendum to the Privacy Policy and Data Processing Agreement

> **Template notice.** This is a starting template, not legal advice. Have it
> reviewed by qualified Canadian privacy counsel before you rely on or sign it.
> Replace every `[BRACKETED]` placeholder. This Addendum supplements the base
> Privacy Policy and Data Processing Agreement; where they conflict on the
> personal information of individuals in Canada, this Addendum controls.

---

This Canada Privacy Addendum (the "Addendum") describes how **[YOUR LEGAL
COMPANY NAME]**, operator of the **[PRODUCT NAME]** math-learning platform
("we," "us"), handles personal information subject to the federal **Personal
Information Protection and Electronic Documents Act ("PIPEDA")** and Québec's
**Act respecting the protection of personal information in the private sector,
as amended by Law 25**, and comparable provincial laws (e.g. BC PIPA, Alberta
PIPA).

---

## 1. Accountability (PIPEDA Principle 1; Law 25 privacy officer)

1.1 We are accountable for personal information under our control. Our
designated **Privacy Officer** is **[PRIVACY OFFICER NAME / TITLE / EMAIL]**,
who is responsible for compliance with this Addendum and Canadian privacy law.

1.2 For school and school-board deployments, the school/board is the
organisation with primary accountability to students and parents; we act as its
service provider (mandatary) and process personal information only to deliver
the service under the Data Processing Agreement.

## 2. Identifying Purposes & Consent (Principles 2–3; Law 25 consent)

2.1 We collect personal information only for these purposes: creating and
operating student accounts, delivering and adapting math instruction, tracking
learning progress, and providing support. We identify these purposes at or
before collection.

2.2 **Consent for minors.** Consistent with Québec Law 25, where a student is
**under 14**, we require consent from a person having parental authority (a
parent or guardian) before creating and operating the account. At 14 and over,
the young person may consent on their own for the educational service. For
school deployments, the school provides or coordinates this consent as part of
the educational relationship.

2.3 Consent may be withdrawn at any time, subject to legal or contractual
limits, by contacting us or (for school accounts) the school.

## 3. Limiting Collection & Data Minimization (Principle 4; Law 25 minimization)

3.1 We collect only what is necessary: a **first name or nickname**, a display
name, grade level, and learning activity. For family accounts we also collect
the managing adult's email.

3.2 We do **not** collect a student's full legal name, home address, phone
number, or exact date of birth. We ask only for **birth month and year** to
determine the applicable consent age, and we do not store even that after the
account type is determined.

## 4. Limiting Use, Disclosure & Retention (Principle 5)

4.1 We use and disclose personal information only for the purposes in Section 2,
or as permitted or required by law. We do **not** sell personal information and
do **not** use student information for advertising or profiling unrelated to
learning.

4.2 **Retention:** active accounts are retained while in use; inactive student
accounts are deleted after **24 months**; support-chat transcripts are deleted
**90 days** after the last message. On request or termination we delete or
return personal information, except where retention is legally required.

## 5. Accuracy & Individual Access (Principles 6, 9; Law 25 access/rectification)

5.1 Signed-in account holders can **export** a machine-readable copy of their
data and **delete** their account directly from Account Settings. School-managed
students exercise access, correction, and deletion through their school, which
we support with tooling.

5.2 We correct personal information shown to be inaccurate and, where
appropriate, notify parties to whom it was disclosed.

## 6. Safeguards (Principle 7; Law 25 security)

We protect personal information with encryption in transit (TLS) and at rest via
a managed database, row-level access controls scoping each user to their own
records, least-privilege administrative access, rate limiting, and automated bot
protection on authentication.

## 7. Cross-Border Transfers & Service Providers (Law 25 s. 17)

7.1 Personal information may be processed or stored **outside Canada**, including
in the United States and the European Union, by us and by our service providers
(listed at **[PRODUCT URL]/subprocessors**). Where information is transferred
outside Québec/Canada, we conduct a privacy impact assessment as required by Law
25 and put contractual and technical protections in place.

7.2 We remain responsible for personal information transferred to service
providers and require each to provide comparable protection.

## 8. Confidentiality Incidents / Breach (Law 25; PIPEDA s. 10.1)

8.1 We maintain a breach-response process. Where a confidentiality incident
presents a **risk of serious injury**, we notify the Commission d'accès à
l'information du Québec (and/or the Office of the Privacy Commissioner of Canada
under PIPEDA) and affected individuals as required, and keep a register of
incidents. For school accounts, we notify the school without undue delay. See
the Breach-Response Runbook.

## 9. Automated Decision-Making (Law 25 s. 12.1)

9.1 The platform adapts exercises to a learner's demonstrated performance. It
does **not** make decisions producing legal or similarly significant effects
about a person based solely on automated processing. If that changes, we will
provide the transparency and review rights Law 25 requires.

## 10. Openness & Complaints (Principles 8, 10)

10.1 This Addendum and our Privacy Policy are available in **English and
French**. Questions or complaints may be directed to our Privacy Officer at
**[PRIVACY OFFICER EMAIL]**. Individuals may also complain to the **Office of the
Privacy Commissioner of Canada** or, in Québec, the **Commission d'accès à
l'information**.

---

## Contacts

- **Privacy Officer:** **[NAME / TITLE / EMAIL]**
- **Mailing address:** **[ADDRESS]**

_Last updated: **[DATE]**_
