CorralData Provincial Health Addendum
Last Updated
September 26, 2026
This Provincial Health Addendum (“PHA”) is the Provincial Health Addendum referenced in the CorralData Data Processing Agreement available at /data-processing-agreement/. It applies to Canadian Personal Information, including Personal Health Information, that Corral Data, Inc. (“CorralData”) handles on behalf of a customer (“Customer”) under the CorralData SaaS Services Agreement available at /saas/, the applicable Services Order Form, and the Data Processing Agreement (together, the “Agreement”). This PHA is incorporated into the Agreement by reference. If this PHA conflicts with the Agreement with respect to Canadian Personal Information, this PHA controls.
1. Definitions
“Canadian Privacy Laws” means the Personal Information Protection and Electronic Documents Act (S.C. 2000, c. 5) (“PIPEDA”) and any applicable provincial privacy or health information law, including Ontario’s Personal Health Information Protection Act, 2004 (“PHIPA”), Alberta’s Health Information Act (“HIA”) and Personal Information Protection Act, and Québec’s Act respecting the protection of personal information in the private sector (CQLR c P-39.1), as amended by S.Q. 2021, c. 25 (the “Québec Privacy Act”), each as amended, together with their regulations.
“Canadian Personal Information” means personal information or personal health information, as defined in the applicable Canadian Privacy Law, about individuals in Canada that CorralData handles on Customer’s behalf. “Québec Personal Information” means Canadian Personal Information about individuals in Québec.
2. Role
CorralData acts as Customer’s service provider and processes Canadian Personal Information on Customer’s behalf. Where Customer is a health information custodian under PHIPA or a custodian under the HIA, CorralData acts as Customer’s agent or information manager under that law and will comply with the obligations that law places on agents and information managers.
3. Use of Canadian Personal Information
CorralData will use Canadian Personal Information to provide, support, and improve the services described in the Agreement, according to Customer’s documented instructions, and as permitted in Section 4. CorralData will not sell Canadian Personal Information.
4. Anonymized and De-Identified Data
Customer authorizes CorralData to anonymize or de-identify Canadian Personal Information to the extent permitted by Canadian Privacy Laws, and to use, commercialize, and disclose the resulting data, alone or combined with other data, in aggregate or record-level form, for serious and legitimate purposes, including benchmarking, research, analytics, product development, and industry insights.
For Québec Personal Information, CorralData will anonymize in accordance with section 23 of the Québec Privacy Act and the Regulation respecting the anonymization of personal information, including: (a) supervision by a person qualified in the field; (b) a documented re-identification risk analysis before release, reassessed periodically; and (c) the register required by that regulation.
For all Canadian Personal Information, CorralData will not attempt to re-identify anonymized or de-identified data and will contractually prohibit recipients from attempting to re-identify it. Anonymized data is not Canadian Personal Information and is owned by CorralData as described in Section 7 of the SaaS Services Agreement.
5. Confidentiality and Security
CorralData will limit access to Canadian Personal Information to personnel and sub-processors who need it, all of whom are bound by written confidentiality obligations, and will protect it with the measures described in Annex 1 of the Data Processing Agreement, including encryption in transit and at rest, role-based access controls, and audit logging.
6. Storage Location and Transfers Outside the Province
Customer data is hosted on Amazon Web Services in data centers located in the United States. The specific AWS region used for Customer’s data is available on request. CorralData’s sub-processors are listed at /sub-processors/.
Within fifteen (15) business days of Customer’s request, CorralData will provide the information Customer reasonably needs to complete any privacy impact assessment required by Canadian Privacy Laws, including under section 17 of the Québec Privacy Act. CorralData will give at least thirty (30) days’ written notice before moving Customer data outside the United States or adding a sub-processor that will access Canadian Personal Information.
7. Incidents
CorralData will notify Customer without undue delay, and no later than seventy-two (72) hours after becoming aware, of any theft, loss, or unauthorized access, use, or disclosure of Canadian Personal Information, and of any violation or attempted violation of its obligations under this PHA.
CorralData will provide the information Customer needs to assess the risk of significant harm or serious injury, to notify regulators (including the Commission d’accès à l’information, the Information and Privacy Commissioner of Ontario, and the Office of the Information and Privacy Commissioner of Alberta) and affected individuals where required, and to maintain any required incident records. CorralData will take reasonable steps to contain the incident and reduce the risk of harm.
8. Individual Rights Requests
Within ten (10) business days of Customer’s request, CorralData will help Customer respond to requests for access, correction, deletion, or portability, including by exporting data in a structured, commonly used technological format. CorralData will redirect requests it receives directly from individuals to Customer.
9. Verification
CorralData will provide its available security reports and answer reasonable written questionnaires about its compliance with this PHA. Customer may conduct an audit once per year on thirty (30) days’ written notice, at its own cost, or at any time following an incident described in Section 7.
10. Return and Destruction
When the Agreement ends, or earlier at Customer’s written request, CorralData will return or securely destroy Canadian Personal Information within thirty (30) days and confirm this in writing. Backup copies remain protected under this PHA and are deleted on CorralData’s normal backup cycle. This Section does not apply to anonymized or de-identified data.
11. Updates
CorralData may update this PHA by posting a new version on its website. CorralData will give Customer at least thirty (30) days’ written notice of any update that materially reduces the protection of Canadian Personal Information.
12. Language
The parties have expressly required that this PHA and all related documents be drawn up in English. Les parties ont expressément exigé que le présent addenda et tous les documents connexes soient rédigés en anglais.
" alt="">