Data Processing Addendum
Last updated: 2026-07-18
This Data Processing Addendum ("DPA") forms part of the ProofChain Terms of Service and Partner Agreement between HKMM Group Inc., an Ontario corporation at 146 Thirtieth Street, Suite 100, Etobicoke, Ontario M8W 3C4, Canada ("HKMM", "Processor"), and the Partner accepting these terms ("Controller"). It governs processing of Personal Information as defined under PIPEDA and, where applicable, the Quebec Act respecting the protection of personal information in the private sector (Law 25).
1. Roles
For homeowner-initiated data (uploads, claims, permit references, warranty registrations), HKMM is the controller. For partner-initiated data submitted through the Issuer Console, Marketplace RFQ responses, Insurance Quote Engine, or Lender API — where the Partner determines the purpose and means — HKMM acts as processor on the Partner's behalf. Both parties operate asindependent controllers for their respective compliance obligations under Canadian privacy law.
2. Scope of processing
- Categories of data subjects: homeowners, occupants, tradespeople, inspection subjects, adjusters and lender contacts.
- Categories of Personal Information: name, email, phone, mailing address, property address, credential numbers, appointment records, warranty serial numbers, IoT telemetry, photographs of premises, chat / event notes.
- Purpose: operate the ProofChain trust ledger; issue and verify attestations; compute Home Score and Risk Grade; enable Marketplace matching; power Insurance Quote and Lender API; deliver ProofReport and Buyer Trust Pack.
- Duration: for the term of the Partner Agreement plus retention periods set out in the Privacy Notice.
3. Processor obligations
- Process Personal Information only on the Controller's documented instructions.
- Ensure personnel with access are bound by confidentiality.
- Implement appropriate technical & organisational measures: TLS in transit, encryption at rest, row-level security in the database, least-privilege access, audit logging on all HQ actions, Merkle-anchored event history, penetration testing on major releases.
- Assist the Controller with data-subject requests (access, correction, deletion, portability) and with notifications under Law 25 §3.5 and PIPEDA breach reporting.
- Notify the Controller without undue delay and no later than 72 hours after becoming aware of a Personal Information breach affecting the Controller's data.
- Return or delete Personal Information at the end of the Agreement, except where retention is required by law or ledger integrity. Attestations may be anonymised instead of deleted.
4. Sub-processors
The Controller authorises HKMM to engage sub-processors listed below. HKMM will notify the Controller of intended additions or replacements at least 30 days in advance; the Controller may object on reasonable data-protection grounds.
| Sub-processor | Purpose | Region |
|---|---|---|
| Lovable Cloud | Managed backend, database, storage | Canada, USA |
| Paddle.com Market Ltd. | Merchant of Record, payments, tax, invoicing | UK, EEA, USA |
| Lovable Emails | Transactional email delivery | USA, EEA |
| Google (Gemini via AI Gateway) | AI Home Coach & AI Verification | USA |
5. Cross-border transfers
Personal Information may be transferred to and processed in the United States and the European Economic Area. HKMM relies on: (a) recognised adequacy decisions where applicable; (b) the European Commission's Standard Contractual Clauses (Module 2 and Module 3 as appropriate) for EEA/UK transfers; and (c) contractual safeguards equivalent to Schedule 1 PIPEDA / Law 25 §17 for outbound transfers from Canada. A Transfer Impact Assessment is available on request.
6. Audits
HKMM makes SOC 2 / ISO 27001 posture information (once available) and security documentation available on written request under NDA. On-site audits are limited to once per calendar year and to material breach investigations.
7. Liability
Liability under this DPA is subject to the liability cap in the Terms of Service and Partner Agreement, save that neither party may cap liability that cannot be limited under Canadian privacy law.
8. Contact
Privacy Officer: privacy@proofchain.world · Legal: legal@proofchain.world · Tel: +1 289-643-9839
