1. Definitions
1.1 “Customer Data” means data the Customer makes available to Frank from its DMS, CRM, or otherwise — including customer records, deal records, inventory, and trade information.
1.2 “De-Identified Data” means Customer Data from which all direct and indirect identifiers have been removed such that it can no longer reasonably identify an individual or the Customer.
1.3 “Services” means the Frank tools the Customer has purchased under its Dealer Terms of Service or a signed Order Form.
1.4 “Subprocessor” means a third party Frank engages to process Customer Data in order to provide the Services, listed in our List of Subprocessors.
1.5 “Security Incident” means a confirmed breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Customer Data.
2. Roles
When a Customer shares Customer Data with 18009619 Canada Inc., operating as Frank ("Frank", "we", "us") to use the Services, Frank acts as a service provider processing that data on the Customer’s behalf and instructions, for the purpose of providing the Services the Customer has purchased. The Customer remains responsible for the data it submits and for its own compliance obligations toward the individuals whose information appears in Customer Data.
3. Details of processing
The table below describes the processing carried out under this DPA, consistent with standard data-processing-agreement practice:
| Category | Detail |
|---|---|
| Subject matter | Provision of Frank’s Tools (Equity, Private Sale, Trade, and F&I) to the Customer. |
| Duration | For the term of the Customer’s agreement with Frank, plus any post-termination retention described in §12. |
| Nature and purpose | Collection, storage, and use of Customer Data to operate the Tools, provide support, detect and prevent fraud and abuse, and, where the Customer’s agreement grants it, create De-Identified Data. |
| Categories of data subjects | The Customer’s customers, employees, and other individuals whose information appears in Customer Data. |
| Categories of personal data | Contact information, vehicle and deal records, trade-in and inventory information, and other data the Customer submits through the Services. |
| Special categories | Frank does not knowingly process government identification numbers, full financial account numbers, or health information as Customer Data — the Customer should not submit these through the Services. |
4. Processing on instructions
Frank processes Customer Data only on the Customer’s documented instructions — which include the instructions built into the ordinary operation of the Services the Customer has purchased, this DPA, and the Customer’s signed agreement — unless required to do otherwise by law, in which case Frank will inform the Customer of that legal requirement first, unless the law prohibits it.
5. Scope of processing
Frank processes Customer Data only to: (a) operate the Tools the Customer has purchased; (b) provide support; (c) detect, prevent, and respond to fraud, abuse, and security incidents; and (d) comply with law. Frank does not sell Customer Data.
6. Confidentiality of personnel
Frank ensures that personnel authorized to process Customer Data are subject to a confidentiality obligation, whether contractual or statutory, and that access to Customer Data is limited to personnel who need it to provide the Services.
7. Security measures
Frank maintains technical and organizational measures appropriate to the sensitivity of the data processed, including:
- Encryption of Customer Data in transit.
- Scoped, role-based access controls to production systems.
- Audit logging of access to Customer Data.
- Vendor security review before onboarding a new Subprocessor.
- Regular review of access permissions and prompt revocation on personnel offboarding.
8. Subprocessors
8.1 Frank uses the Subprocessors listed in our List of Subprocessors to provide the Services. The Customer consents to Frank’s use of these Subprocessors.
8.2 Frank remains responsible for a Subprocessor’s handling of Customer Data under its agreement with that Subprocessor, to the same standard this DPA requires of Frank.
8.3 If Frank adds a new Subprocessor, we’ll update our List of Subprocessors. A Customer whose signed agreement requires advance notice of a new Subprocessor should contact privacy@drivefrank.ca or call 647-360-8580 to confirm the notice period and objection process that applies to them.
9. Assistance with data subject requests
Where an individual exercises a privacy right (for example, access or deletion) directly against the Customer regarding Customer Data, Frank will provide reasonable assistance to help the Customer respond, taking into account the nature of the processing and the information available to Frank.
10. Security incident notification
If Frank becomes aware of a Security Incident affecting Customer Data, Frank will notify the affected Customer without undue delay after becoming aware of it, and will provide the information reasonably available at the time — including, as it becomes known, the nature of the incident, the categories and approximate number of individuals and records affected, and the steps Frank is taking in response.
11. International transfers
Some Subprocessors process Customer Data outside Canada, principally in the United States — see our List of Subprocessors for locations. Where that happens, Frank takes contractual and technical steps to ensure a comparable level of protection to what applies in Canada.
12. Data on termination
On termination of a Customer’s agreement, Frank’s license to use the Services ends and Frank stops collecting new Customer Data from the Customer. Frank does not automatically delete Customer Data already collected — Frank continues to hold and use it under the data-license terms in the Customer’s signed agreement (including any De-Identified Data rights described in §13), unless that agreement or applicable law requires deletion. A Customer whose agreement requires return or deletion of data on termination should refer to that agreement’s terms, which control over this page.
13. De-identified & aggregated data
Where a Customer’s signed agreement grants it, Frank may create and use De-Identified Data derived from Customer Data to operate and improve Frank’s own products (for example, market pricing insights). This use is described in the Customer’s signed data-license schedule; where no such schedule exists, Frank does not exercise this right over that Customer’s data.
14. Consumer consent
Where Customer Data includes personal information about a Customer’s own consumers, the Customer is responsible for having the lawful basis (including any required consent under PIPEDA/CASL) to share that data with Frank in the first place. Frank’s own handling of that personal information once shared is governed by this addendum and, for Frank’s direct consumer users, by our Privacy Policy.
15. Audit
On reasonable written notice, and no more than once per year unless required by a regulator or in response to a Security Incident, Frank will make available the information reasonably necessary to demonstrate compliance with this DPA, which may take the form of a summary of Frank’s security practices rather than an on-site audit.
16. Liability
Liability for a breach of this DPA is governed by the limitation of liability in the Customer’s Dealer Terms of Service or signed agreement — this DPA does not create separate or additional liability.
17. Order of precedence
This page is Frank’s standard reference DPA. Where a Customer has a signed Master Subscription & Services Agreement or data-sharing schedule with 18009619 Canada Inc., that signed agreement governs and prevails over this page on any conflict.
18. Changes to this addendum
We may update this addendum from time to time. Material changes will be posted here with an updated date.
19. Contact us
Questions from a current or prospective dealer/business customer about this addendum? Contact privacy@drivefrank.ca or call 647-360-8580.