Skip to main content

Data Processing Agreement

Updated October 1, 2026

1. Definitions

In this Data Processing Agreement ("Agreement"), the following terms apply:

  • "Personal data" means any information about an identifiable individual, as defined under the Personal Information Protection and Electronic Documents Act (PIPEDA).
  • "Data controller" means the organization that determines the purposes and means of the processing of personal data. In this Agreement, the data controller is Mymspgoat Inc.
  • "Data processor" (or "sub-processor") means any third party that processes personal data on behalf of the data controller.
  • "Data subject" means the individual whose personal data is being processed.
  • "Processing" means any operation performed on personal data, including collection, recording, storage, use, disclosure, and deletion.
  • "Breach of security safeguards" means the loss of, unauthorized access to, or unauthorized disclosure of personal data resulting from a breach of an organization's security safeguards.

2. Scope and purpose

This Agreement applies to all personal data processed by Mymspgoat Inc. through the website mymspgoat.com, including data collected via contact forms, consultation requests, and email correspondence. The purpose of this Agreement is to establish the obligations of Mymspgoat Inc. and its sub-processors regarding the protection of personal data, and to ensure that all processing is carried out in compliance with applicable Canadian privacy legislation. This Agreement supplements our Privacy Policy and should be read in conjunction with it.

3. PIPEDA framework

Mymspgoat Inc. processes personal data in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA), which governs how private-sector organizations collect, use, and disclose personal information in the course of commercial activities in Canada. We adhere to the ten fair information principles set out in Schedule 1 of PIPEDA: accountability, identifying purposes, consent, limiting collection, limiting use disclosure and retention, accuracy, safeguards, openness, individual access, and challenging compliance. The Office of the Privacy Commissioner of Canada (OPC), located at 30 Victoria Street, Gatineau, QC K1A 1H3, oversees compliance with PIPEDA. Individuals may file a complaint with the OPC if they believe their privacy rights have been violated.

4. Roles and responsibilities

Mymspgoat Inc. acts as the data controller for all personal data collected through mymspgoat.com. As data controller, Mymspgoat Inc. is responsible for determining the purposes for which personal data is collected, ensuring that data collection is limited to what is necessary, obtaining meaningful consent from data subjects, implementing appropriate security safeguards, and ensuring that sub-processors comply with equivalent data protection obligations. The director of Mymspgoat Inc., Marc-Andre Tremblay, is the individual accountable for the organization's compliance with this Agreement and with PIPEDA.

5. Data processing activities

Mymspgoat Inc. processes personal data for the following purposes:

  • Responding to inquiries submitted through the contact form or by email.
  • Scheduling and managing consultation appointments.
  • Sending follow-up communications related to a specific request or service.
  • Maintaining records for tax and legal compliance purposes.
  • Improving the website experience through anonymized analytics (when the visitor has consented to analytics cookies).

The categories of personal data processed may include: name, email address, phone number, message content, and any additional information voluntarily provided by the data subject. We do not collect sensitive personal data such as health information, financial account numbers, or government-issued identification numbers through this website.

6. Sub-processors

Mymspgoat Inc. engages the following sub-processors to assist in delivering its services. Each sub-processor is contractually bound to process personal data only for the purposes specified by Mymspgoat Inc. and to maintain appropriate security measures:

  • Hebergement Web Canada Inc. (WHC.ca) - Web hosting provider. Location: 505 Boulevard Rene-Levesque Ouest, Bureau 270, Montreal, QC H2Z 1Y7, Canada. WHC.ca hosts the website and its associated data on servers located in Canada. Personal data processed: all data transmitted through the website.
  • FormSubmit (formsubmit.co) - Form submission processing service. Location: United States. FormSubmit processes data submitted through the website's contact forms and forwards it to our email. Personal data processed: name, email address, phone number, and message content submitted via forms.

Mymspgoat Inc. will notify data subjects of any changes to its sub-processors by updating this Agreement. We will not engage a new sub-processor without ensuring that it provides adequate data protection guarantees.

7. Data security measures

Mymspgoat Inc. implements appropriate technical and organizational measures to protect personal data against unauthorized access, disclosure, alteration, or destruction. These measures include:

  • Encryption of data in transit using TLS (HTTPS) across all pages of the website.
  • Access to personal data is restricted to authorized personnel only.
  • Regular review of security practices and procedures.
  • Use of strong passwords and secure authentication for administrative access.
  • Selection of sub-processors that demonstrate adequate security safeguards.

While we take reasonable steps to protect your personal data, no method of electronic transmission or storage is completely secure. We cannot guarantee absolute security but are committed to maintaining safeguards that are appropriate to the sensitivity of the data.

8. Data breach notification

In the event of a breach of security safeguards involving personal data that creates a real risk of significant harm to individuals, Mymspgoat Inc. will:

  • Notify the Office of the Privacy Commissioner of Canada as soon as feasible, and in any event within 72 hours of becoming aware of the breach.
  • Notify affected individuals as soon as feasible, providing details about the nature of the breach, the personal data involved, the steps taken to reduce the risk of harm, and what the individual can do to protect themselves.
  • Keep a record of all breaches of security safeguards, as required by PIPEDA, for a minimum period of 24 months.

Sub-processors are contractually required to notify Mymspgoat Inc. without undue delay upon becoming aware of a breach affecting personal data they process on our behalf.

9. Data subject rights

Under PIPEDA, you have the following rights regarding your personal data:

  • Right of access: You may request access to the personal data that Mymspgoat Inc. holds about you.
  • Right of correction: You may request that inaccurate or incomplete personal data be corrected.
  • Right to withdraw consent: You may withdraw your consent for the processing of your personal data at any time, subject to legal or contractual restrictions.
  • Right to deletion: You may request the deletion of your personal data when it is no longer necessary for the purposes for which it was collected.
  • Right to complain: You may file a complaint with the Office of the Privacy Commissioner of Canada if you believe your privacy rights have been violated.

To exercise any of these rights, please contact us using the details provided in Section 14 of this Agreement. We will respond to your request within 30 days, as required by PIPEDA. For more information, see our Privacy Policy.

10. Data retention and deletion

Mymspgoat Inc. retains personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by law. Our retention periods are as follows:

  • Inquiry data (contact form submissions, email correspondence): retained for 12 months from the date of the last interaction, then moved to an archive.
  • Archived data: retained for an additional 36 months in a restricted-access archive, after which it is permanently deleted.
  • Tax and financial records: retained for 6 years, as required by Canadian tax law.
  • Cookie consent preferences: stored in localStorage under the key "mspg_consent" for 365 days.

When personal data is no longer required, it is securely deleted or anonymized so that it can no longer be associated with an identifiable individual.

11. International data transfers

Mymspgoat Inc. primarily processes personal data within Canada. However, certain sub-processors may process data outside of Canada. Specifically, FormSubmit (formsubmit.co) is based in the United States, and personal data submitted through our contact forms may be transferred to and processed in the United States. When personal data is transferred outside of Canada, we ensure that the receiving organization provides a comparable level of protection as required by PIPEDA. We use contractual safeguards and assess the privacy practices of our sub-processors to ensure your data remains protected. For additional information about how your data is handled, please refer to our Terms of Service.

12. Amendments

Mymspgoat Inc. reserves the right to update this Agreement at any time. Changes will be published on this page with an updated revision date. Material changes affecting how personal data is processed will be communicated through a notice on the website. Your continued use of mymspgoat.com after any changes constitutes acceptance of the updated Agreement. We encourage you to review this page periodically. For details about the company publishing this Agreement, please see our Legal Notice.

13. Governing law

This Agreement is governed by and construed in accordance with the laws of the Province of Ontario and the federal laws of Canada applicable therein, including PIPEDA. Any disputes arising out of or in connection with this Agreement shall be submitted to the exclusive jurisdiction of the Ontario Superior Court of Justice, sitting in Ottawa. Nothing in this Agreement limits your right to file a complaint with the Office of the Privacy Commissioner of Canada.

14. Contact

If you have any questions about this Data Processing Agreement, wish to exercise your data subject rights, or need to report a concern about how your personal data is being handled, please contact us:

You may also contact the Office of the Privacy Commissioner of Canada at 30 Victoria Street, Gatineau, QC K1A 1H3, or visit their website for more information about your privacy rights under PIPEDA.