Data Processing Agreement
Last updated: August 15, 2026
Between: MarketPadHQ Corp. (the "Processor") and Customer (the "Controller")
1. Scope
This DPA applies to all personal data processed by MarketPadHQ on behalf of Customer in connection with the use of the MarketPadHQ platform.
2. Roles
- Customer is the Data Controller and determines the purposes and means of processing.
- MarketPadHQ is the Data Processor and processes data only on Customer's instructions.
3. Purpose of Processing
MarketPadHQ processes personal data solely to provide the services outlined in the Terms of Service, including:
- Account management
- Email delivery and automation
- Lead scoring and analytics
- Payment processing
- Customer support and communication
4. Data Subject Categories
Customer may submit personal data of:
- Employees and contractors
- Customers and prospects
- End users of Customer's products or services
5. Types of Data Processed
- Name, email, phone number, job title
- Company, industry, location
- Interaction data (opens, clicks, form submissions)
- IP address and browser information
- Payment information (processed via Stripe)
6. Data Processing Locations
Data is processed in:
- Canada (primary)
- United States (Stripe, SendGrid, hosting)
7. Subprocessors
MarketPadHQ uses the following subprocessors:
- Stripe (payment processing)
- SendGrid (email delivery)
- Meta (advertising and analytics)
- DigitalOcean (hosting)
Customer may object to the use of a subprocessor by providing written notice within 10 business days.
The integrations behind these subprocessors, and what each one receives, are described in our Third-Party Integrations policy.
8. Data Security
MarketPadHQ implements reasonable technical and organizational measures to protect personal data, including:
- Encryption in transit and at rest
- Access controls and authentication
- Regular security reviews
- Incident response procedures
Further detail is set out in our Security policy.
9. Data Subject Rights
MarketPadHQ will assist Customer in responding to data subject requests (access, correction, deletion, portability) within a reasonable timeframe.
10. Data Breach Notification
MarketPadHQ will notify Customer without undue delay of any data breach affecting Customer's data and will provide information to assist with compliance obligations.
11. Data Retention
Personal data is retained for as long as Customer's account is active, plus a reasonable period for backups and legal compliance. Data can be deleted upon Customer's request.
12. Audit Rights
Customer may request a security audit of MarketPadHQ's data processing practices once per year, subject to reasonable notice and confidentiality.
13. Governing Law
This DPA is governed by the laws of Canada and the United States, as applicable.
14. Contact
For any questions or data subject requests, contact:
MarketPadHQ Corp.
support@marketpadhq.com
This DPA supplements our Terms of Service and Privacy Policy. Where this DPA and those documents differ on the processing of personal data, this DPA governs.