Data Processing Addendum
Pluragon IT Inc.
Data-processing terms for organizational customers
PluraSpace™ by Pluragon™
Effective date
August 29, 2026
Version
1.0
1. Parties and Scope
This Data Processing Addendum ("DPA") forms part of the agreement between Pluragon IT Inc. ("Pluragon") and the organizational customer using PluraSpace ("Customer") to the extent Pluragon processes personal information on Customer's behalf in providing PluraSpace.
2. Definitions
"Personal Data" means personal information, personal data, or comparable information relating to an identified or identifiable individual that is protected by applicable privacy or data-protection law. "Applicable Data Protection Law" means privacy or data-protection law applicable to the processing under the agreement. "Subprocessor" means a third party engaged by Pluragon to process Personal Data on behalf of Customer.
3. Roles of the Parties
Customer determines the purposes and means of processing Customer Personal Data submitted to or made available through PluraSpace, except where Pluragon independently determines processing for its own account administration, security, legal, billing-reference, support, analytics, or compliance purposes. For processing performed on Customer's documented instructions, Customer acts as controller or comparable responsible organization and Pluragon acts as processor or service provider, as applicable.
4. Processing Instructions
Pluragon will process Customer Personal Data only as necessary to provide, secure, maintain, support, and improve PluraSpace in accordance with the agreement and Customer's documented instructions, unless processing is required by law. Customer is responsible for ensuring that its instructions, permissions, Microsoft 365 configuration, and use of PluraSpace comply with Applicable Data Protection Law.
5. Confidentiality
Pluragon will ensure that personnel authorized to process Customer Personal Data are subject to appropriate confidentiality obligations.
6. Security
Pluragon will maintain reasonable administrative, technical, and organizational safeguards appropriate to the nature of PluraSpace and the Customer Personal Data processed. The current high-level controls are summarized in Schedule 2 and in the PluraSpace Security Overview.
7. Subprocessors and Service Providers
Customer authorizes Pluragon to use the providers identified on the PluraSpace Subprocessor and Service Provider List where necessary to provide the service. Pluragon will use contractual and operational measures appropriate to the provider's role and the information processed.
8. International Processing
The primary PluraSpace production environment, production database, and backups are hosted in Microsoft Azure in Canada Central and Canada East. Some service providers may process Personal Data outside Canada. Where Applicable Data Protection Law requires a specific international-transfer mechanism, the parties will cooperate in good faith to enter into the required contractual mechanism or other lawful safeguard.
9. Assistance With Individual Rights
Taking into account the nature of the processing and information available to Pluragon, Pluragon will provide reasonable assistance to Customer with requests from individuals concerning Customer Personal Data where Customer cannot reasonably fulfill the request without Pluragon's assistance. Pluragon may require verification of the request and Customer's authority.
10. Security Incidents
Pluragon will notify Customer without undue delay after confirming a security incident involving Customer Personal Data where notification is required by Applicable Data Protection Law or the agreement. Pluragon will provide reasonably available information necessary for Customer to assess and respond to the incident.
11. Return and Deletion
If a subscription lapses or a renewal payment fails, Customer Personal Data may be retained for up to 90 days to allow reactivation. If an administrator intentionally deletes a space, Customer Personal Data may be retained for up to 30 days to allow recovery. After the applicable period, active service data is scheduled for deletion unless retention is required by law or reasonably necessary for security, fraud prevention, tax, or dispute-resolution purposes. Residual backup copies may remain until expiration through the normal backup lifecycle.
12. Restricted Sensitive Data
Customer will not use PluraSpace to process highly sensitive regulated data, including health records, complete payment-card data, government identification documents, or similar information requiring specialized controls, unless Pluragon expressly agrees in writing to support that processing.
13. Audit and Compliance Information
Upon reasonable request, Pluragon will provide information reasonably necessary to demonstrate compliance with this DPA, taking into account confidentiality, security, operational burden, and the availability of existing security documentation. Any broader audit rights must be agreed in writing and conducted in a manner that does not compromise other customers, systems, or confidential information.
14. Liability and Priority
Liability arising under this DPA is subject to the limitations and exclusions of liability in the agreement unless Applicable Data Protection Law requires otherwise. If this DPA conflicts with the agreement on the processing of Customer Personal Data, this DPA controls to the extent of that conflict.
Schedule 1 - Processing Details
Item
Description
Subject matter
Operation of the PluraSpace room-booking and space-management service.
Duration
For the term of the customer relationship plus the applicable retention and deletion periods.
Purpose
Provide room booking, Microsoft 365 integration, administration, support, security, diagnostics, and subscription entitlement.
Data subjects
Customer administrators, authorized users, organizers, and attendees whose information is included in a booking.
Personal Data
Name, email address, organization, optional role/title, booking details, organizer/attendee details, optional booking notes, space configuration, administrative audit records, and support information where submitted.
Special categories / highly sensitive data
Not intended for processing unless Pluragon expressly agrees in writing.
Schedule 2 - High-Level Security Measures
• Production hosting, production database, and backups in Microsoft Azure Canada Central and Canada East.
• Microsoft 365 / Microsoft Graph integration designed to retrieve information necessary for PluraSpace functionality.
• Microsoft authentication credentials and tokens are not stored in the PluraSpace application database.
• Administrative audit logging for key administrative actions.
• Standard Microsoft Azure monitoring and diagnostic tooling for service operations and troubleshooting.
• Payment-card and billing-address processing delegated to Stripe rather than stored in the PluraSpace application.
• Data-retention and deletion procedures aligned with the subscription and account-deletion lifecycle.
Schedule 3 - Providers
The current providers are identified in the PluraSpace Subprocessor and Service Provider List available through PluraSpace legal documentation.
Contact Information
Pluragon IT Inc.
Email
info@pluragon.com
Phone
+1 902 707-0987
Location
171 John Savage Avenue, 2nd Floor, Dartmouth, Nova Scotia B3B 0A5, Canada

