Data Processing Agreement (DPA) — Ekorra
Version 1.4 — September 18, 2026 · Effective date: September 18, 2026 · Schedule forming an integral part of the Terms of Use.
This document is a translation of the French original. In case of discrepancy, the French version prevails.
This agreement governs the processing of personal information that Neural North (the "Operator", "Ekorra", the service provider) carries out on behalf of the Customer (the entrepreneur, firm or business holding the account, the person in charge or controller) as part of the Service, with respect to its end clients (the "Uploaders").
1. Roles and instructions
1.1. The Customer is in charge of its Uploaders' personal information: it determines the purposes (which documents, why, which documents it sends them) and warrants that it has a valid basis for collecting and communicating them.
1.2. Ekorra processes this information solely: (a) to provide the Service as documented (collection, AI-assisted checking, review, notifications, relaying of Uploaders' messages, sharing of documents from the Customer to its Uploaders and code verification, indexing and question answering on documents, API/webhooks, operations and support — processing operations detailed in Schedule B); (b) in accordance with the Customer's reasonable instructions; (c) as required by law. No use for its own purposes, no sale, no training of AI models on the Customer's data.
1.3. Suspension. Where Ekorra suspends the Customer's account for a serious breach (Terms of Use, section 8.4), collection stops: the Uploaders' portals become read-only (viewing of the request status and of documents already sent; no upload, no submission, no message) and every action of the Customer is refused. No data is deleted by a suspension; this agreement continues to apply to the data retained, including the deletion provided for in section 9.
2. Categories of data processed
Identity and contact details of Uploaders; uploaded documents (which may contain financial and tax data and identity documents), whether requested by the Customer or added by the Uploader, and the description of the file (profile or transcript) provided by the Customer; documents sent by the Customer to the Uploader and viewing receipts (date and time of the first viewing and of the last download); verification results and notes, including fields extracted from documents by the AI (amounts, dates, years, issuer), stored outside the file and destroyed with it; search index derived from the documents (text transcribed page by page and vector representations), stored outside the file and destroyed with it; portal messages (assistant, questions asked about documents and answers, messages addressed to the Customer); code verification data (hashed code, timestamps, failed attempts, device session token); technical metadata, including the log of emails sent (template, language, delivery status, timestamp, workspace and request identifiers — never the recipient's address or the content); after a request is deleted (section 9), its archive record without content (status, dates, stages, purpose, names of the documents requested and the Customer's check rules, a count of what was deleted, date of deletion).
3. Confidentiality
Ekorra personnel and service providers with access to the data are bound by confidentiality obligations and trained accordingly. Access is limited to a need-to-know basis. Ekorra personnel access the Customer's data through administration tools that expose metadata and counters only — the Customer's account information, statuses, dates, counts of requests, documents and emails, technical log — and never the content of a document, an extracted field, a detailed check note, a portal message or an access link to a file; every action of personnel on the Customer's workspace is logged (author, action, target, date). Direct access to the hosting systems is reserved to authorized personnel, on a need-to-know basis.
4. Security measures
Encryption in transit (TLS 1.2+) and at rest; access control and authentication; signed access links with a limited scope and lifetime; for viewing documents sent by the Customer, one-time code verification (valid ten (10) minutes, code stored in hashed form only, limited number of attempts) followed by a device-specific session token, distinct from the access link, valid thirty (30) days; logical segregation by Customer, including for webhook delivery and for the search index, whose filtering by Customer and, for Uploaders, by request is applied in the search query itself; assistant answers limited to retrieved and cited sources; access logging; encrypted backups; periodic security tests and reviews; HMAC signing of webhooks. Ekorra makes its security documentation available to the Customer and shares, where they exist, the independent audit reports concerning it.
5. Sub-processors
5.1. The Customer authorizes the sub-processors listed in Schedule A. Ekorra imposes on each of them obligations equivalent to this agreement and remains responsible for their performance. Where a sub-processor contracts only on its standard terms, Ekorra assesses their adequacy before entrusting it with data (section 6), offsets any gaps through its own measures (minimization of the data transmitted, time-limited access elements) and informs the Customer in Schedule A.
5.2. Any addition or replacement is notified to the Customer at least thirty (30) days in advance; the Customer may object on reasonable grounds, in which case the parties seek a solution (including termination of the affected service without penalty). If an urgent replacement becomes necessary because of a sub-processor's failure, the end of its services or a change to its terms that Ekorra considers unacceptable, Ekorra notifies the Customer as soon as it itself becomes aware of it, with as much notice as circumstances allow; the Customer's right to object remains.
6. Data location
Hosting, storage, backups, AI processing, indexing and search in Canada (Google Cloud, Montreal region — northamerica-northeast1). Only transactional emails pass through the United States-based email provider described in Schedule A, with only the data listed there: the recipient's contact details, the Customer's name, the purpose of the request, document names, the count of documents received and requested, brief review notes, the text of relayed messages and time-limited access elements — never any document, attachment, AI-extracted field or description of a sent document. These emails are encrypted in transit from Ekorra to the provider; final delivery to the recipient's email server is encrypted where that server supports it. This transfer has been the subject of a privacy impact assessment in accordance with section 17 of Law 25 (sensitivity, purpose, contractual and technical measures, legal regime of the destination State); Ekorra shares its conclusions with the Customer upon request (section 8) and reviews it at least once a year, upon any change of email category or provider, and upon any reasoned objection by the Customer (section 5.2). No other transfer outside Canada takes place without prior notice to the Customer and, for data subject to Law 25, without a prior privacy impact assessment.
7. Confidentiality incidents
Ekorra notifies the Customer without undue delay and no later than 72 hours after becoming aware of a confidentiality incident affecting its data. This period runs from the moment Ekorra itself becomes aware of it, including where it is informed by a sub-processor. The notification includes the relevant information (nature of the incident, data and persons concerned, measures taken or planned) and is supplemented as further information becomes available where not all of it is available within that period. Ekorra keeps the incident register required by Law 25 and cooperates with the regulatory notifications (CAI, Privacy Commissioner) that fall to the Customer.
8. Assistance to the person in charge
Ekorra reasonably assists the Customer with: Uploaders' requests for access, correction, deletion or portability; assessments (PIAs) and security questionnaires; requests from authorities.
9. Deletion and return
9.1. The documents of a request — including those sent by the Customer to the Uploader, the search index derived from them, viewing receipts, the messages and questions and answers attached to the request, the document suggestions and the description of the file, code verification data, the portal access link and the email log entries attached to the request — are securely and irreversibly deleted twelve (12) months after the request is closed, closing being the end of the Customer's review (request marked complete), unless the Customer instructs otherwise or the law requires otherwise; the Customer and the Uploader may request earlier deletion. A request that is not closed (draft, sent or under review) is not covered by this rule until it is. Deletion is carried out by a daily process, in calendar months, idempotent and logged (run date, counts — never content). The archive record described in section 2 remains, viewable by the Customer. Expired verification codes are deleted by the same daily process.
9.2. At the end of the contract, the Customer has thirty (30) days to export its data; Ekorra then securely deletes all personal information within thirty (30) days, except where a legal retention obligation applies, and certifies it upon request. The Uploaders' contact details recorded in the Customer's client list (name, email, language) are deleted at that time, or earlier upon request.
9.3. Copies of documents that the Customer views, downloads or exports outside the Service fall outside these deletion mechanisms; their retention and protection are the Customer's responsibility as the person in charge.
9.4. The search index of a document is also deleted as soon as that document is replaced or removed, without waiting for the deletion of the request.
9.5. Backup copies. Encrypted backups (daily database export kept thirty (30) days; object storage recovery window of seven (7) days), all in the Montreal region, are overwritten by rotation: deleted data disappears from every copy no later than forty (40) days after its deletion. Backups serve only to restore the Service; after a restoration, the daily process re-applies the deletion to data whose retention has elapsed.
10. Verification
Upon reasonable request (at most once per year), Ekorra provides the information necessary to demonstrate its compliance: security documentation, independent audit reports where they exist, answers to questionnaires, the log of the deletion process runs. On-site audits are limited to cases required by law, at the Customer's expense and under a confidentiality agreement.
11. Acceptance, term, precedence and language
11.1. This agreement is accepted by the Customer together with the Terms of Use, expressly within the Service, when the account is created and then at each new version of either document (Terms of Use, section 9). Ekorra records the email address of the session that accepted, the version accepted and the date — no IP address and no device information. This record of acceptances is kept by Ekorra on its own behalf, for evidentiary purposes (Privacy Policy, sections 2 and 7); it is not covered by section 9 of this agreement.
11.2. This agreement is amended in accordance with section 9 of the Terms of Use: any new version is presented to the Customer for acceptance, and the last version accepted continues to govern the processing until then. The addition or replacement of a sub-processor is, in addition, governed by section 5.2. The addition of a category of email delivered by a sub-processor already authorized, to the same country, is neither an addition nor a replacement of a sub-processor: it is preceded by the review of the assessment provided for in section 6 and recorded in Schedule A in a new version of this agreement.
11.3. This agreement applies for as long as Ekorra processes data for the Customer and prevails over the Terms of Use in case of conflict regarding personal information. Drafted in French; this English version is provided for convenience and, in case of discrepancy, the French version prevails.
Schedule A — Authorized sub-processors
- Google Cloud (Cloud Run, Firestore — including the vector search index —, Cloud Storage, backups — Montreal region, northamerica-northeast1) — hosting, storage, backups and search index — Canada.
- Google Cloud Vertex AI (Gemini models and a multilingual vector representation model — text-multilingual-embedding-002 as of this version; a change of model within the same service and the same region is not a change of sub-processor and is recorded in Schedule B.8) — document suggestion and checking, field extraction, text transcription and indexing, portal assistant and answers to questions about documents; no training on Customers' data — Canada (northamerica-northeast1, processing residency confirmed for the Gemini models and for the vector representation model).
- Resend (Plus Five Five, Inc.) — delivery of transactional emails — United States (the provider keeps a copy of sent emails there for a limited period: thirty (30) days as of this version). Categories: (1) portal invitation and access link; (2) reminders; (3) review return; (4) notice of a document sent by the Customer; (5) one-time verification code; (6) Customer sign-in link; (7) relaying of the Uploader's messages to the Customer; (8) internal feedback notice addressed to the Ekorra team (Ekorra's own processing, described in the Privacy Policy); (9) submission notice addressed to the Customer, at its contact address (failing that, at its account address), at each submission by an Uploader — which the Customer can turn off in its settings. Data transmitted, depending on the category: the Uploader's email address and first name (no first name in the code email; full name and reply address in the contact relay; first name only, without address, in the submission notice); the Customer's email address (sign-in link, relay, submission notice); the Customer's name; the purpose of the request; the names of the documents requested, to be fixed, still needed or sent; the count of documents received and requested and whether the submission is partial or complete (submission notice); the brief review note accompanying a document to be fixed (written by the AI or by the Customer); text written by the sender (contact relay, feedback); portal access link (thirty (30) days), verification code (ten (10) minutes) or sign-in link (fifteen (15) minutes). Never: document, attachment, AI-extracted field, description of a sent document, assistant thread message; in the submission notice, in addition: surname, Uploader's address, file or document name, verification note, access element (its link opens the Customer's workspace, where sign-in is required). Measures: encryption in transit from Ekorra to the provider (final delivery encrypted where the recipient's server supports it), data minimization, time-limited access elements, provider access secrets kept in Canada, the provider's contractual commitments (data processing addendum, SOC 2 Type II certification declared by the provider, public list of its own sub-processors); transfer assessed in accordance with section 17 of Law 25, reassessed at least once a year (section 6).
Schedule B — Processing operations carried out on behalf of the Customer
Each processing operation below is carried out in Canada (except email delivery, Schedule A), without use for Ekorra's own purposes or training of AI models, and ends with the deletion described in section 9.
- B.1 Document collection — Creation of the request and of the document list (AI suggestions based on the profile or transcript provided by the Customer), sending of the personal link to the Uploader, upload through the portal, including documents added by the Uploader where the Customer allows it. Data: identity and contact details of the Uploader, documents, metadata. Purpose: assembling the file requested by the Customer.
- B.2 AI-assisted checking and field extraction — Analysis of each file upon receipt (type, period, readability, Customer's rules); notes, confidence levels and extracted fields (amounts, dates, years, issuer), stored outside the file and replaced upon each new upload. Purpose: flagging problems to the Uploader immediately and preparing the Customer's review. Verdict: human (B.3).
- B.3 Review and decision by the Customer — Viewing, approval, rejection, removal and notes by a person at the Customer; partial submission possible. No fully automated decision. Closing the review (request marked complete) starts the deletion clock (section 9).
- B.4 Portal assistant — Answers to the Uploader's questions in the portal, forwarded to the Customer where necessary; messages kept with the request. The assistant relies on the index described in B.8, limited to the Uploader's request.
- B.5 Notifications, reminders and relaying — Transactional emails (invitation and access link, reminders, review return, sign-in links, notice of a sent document, verification codes, relaying of the Uploader's messages to the Customer, submission notice to the Customer — sent at each submission, partial or complete, unless the Customer has turned it off): minimal data listed in Schedule A, never any document (Schedule A, Resend); technical log of each send without recipient or content (section 2).
- B.6 Sharing of documents from the Customer to the Uploader (feature enabled by the Customer in its settings, disabled by default) — Upload by the Customer of a document intended for the Uploader, email notice without content, viewing and download by the Uploader after code verification (B.7), viewing receipt (date and time of the first viewing and of the last download, visible to the Customer), withdrawal possible by the Customer. Data: the sent document, viewing timestamps. Purpose: delivering to the Uploader the documents useful to their file and confirming that they have taken note of them. Retention: that of the request (section 9).
- B.7 Code verification and verified session — Sending of a one-time code to the Uploader's email address (valid ten (10) minutes), stored in hashed form only; time sent and time verified, failed-attempt counter, limit on the number of attempts; upon success, a device-specific session token, distinct from the access link, valid thirty (30) days. Purpose: ensuring that the person viewing the sent documents has access to the Uploader's email address. Not an identity verification. Uploading remains accessible through the signed link alone. Expired codes are deleted by the daily process (section 9.1).
- B.8 Indexing and question answering on documents — During checking (B.2), the text of each document is transcribed page by page by the same Gemini model that performs the check, split into segments and converted into vector representations by a Vertex AI model served in the Montreal region (text-multilingual-embedding-002 as of this version); segments and vectors are stored in an index (Firestore, Montreal region) tied to the Customer, the Uploader, the request, the document and the upload. For each question, the search is filtered, in the query itself, on the Customer's workspace and, for the Uploader, on their request; a Gemini model (Montreal region) then formulates an answer citing the document and page, or states that no source was found. Scopes: the Uploader, on their own request; the Customer, on one file or on all the active files (requests sent or under review) in its workspace (its own Uploaders only — internal use, by the person in charge, of information it already holds). Purpose: processing the request and serving the Uploader; no new purpose, no profiling, no training. Retention: the index of a document is deleted upon replacement or removal of that document and, at the latest, with the request (section 9). If the vector representation model changes, the index is re-encoded server-side, without the content being exposed to Ekorra personnel. Answers are a reading aid; the decision remains human.
- B.9 API and webhooks — Programmatic access by the Customer to its own data and signed event notifications (HMAC), segregated by workspace.
- B.10 Export and download — Copies provided to the Customer at its request (file or ZIP archive), outside the scope of automatic deletion (section 9.3).
- B.11 Deletion — Daily process that securely deletes, twelve (12) calendar months after each request is closed, the files (current and previous uploads, sent documents), extracted fields, index, messages, suggestions and file description, viewing receipts, verification data, access link and email log entries of the request, and leaves the archive record without content (section 2); deletes expired verification codes; logs each run (date, counts). Effective in backup copies no later than forty (40) days afterwards (section 9.5). Earlier upon instruction, and at the end of the contract (section 9).
- B.12 Operations and support — Access by Ekorra personnel, through its administration tools, to the metadata and counters described in section 3 (never to content), recording of the Customer's plan and options, suspension for a serious breach (section 1.3), execution and supervision of the deletion process (B.11). Every action is logged (author, action, target, date). Purpose: operation, security and support of the Service.
Operator: Neural North · 4432, rue Saint-Michel, Montréal (Québec) H1Y 3J7 · contact@ekorra.com Person in charge of the protection of personal information: Julien Mercier, Founder — vie-privee@ekorra.com
Version history: 1.4 (September 18, 2026) — express, recorded acceptance of this agreement, amendments (section 11), submission notice to the Customer: ninth category of email (section 6, Schedule A, Schedule B.5) — neither a new sub-processor nor a new country · 1.3 (September 12, 2026) — suspension (section 1.3), archive record (section 2), personnel access to metadata (section 3), deletion mechanism and backup copies (sections 9.1, 9.2, 9.5, 10), Schedule A (vector representation model, backups, code without first name), Schedule B (B.3, B.6, B.7, B.8, B.11, new B.12) · 1.2 (September 11, 2026) — alignment with the privacy impact assessment of the email provider · 1.1 (September 10, 2026) — document sharing, one-time code, indexing and question answering, Schedule B · 1.0 (September 10, 2026) — first published version.