MECHANUS IQ · LEGAL All agreements

MIQ Data Processing Agreement

Schedule B to Master Services Agreement

Field Value
Document ID MIQ-DPA-001
Version 2026-09-02 (published version; instrument form 2026-06-22 founder-use form)
Provider Mechanus IQ Ltd.
Client [Client legal name]
Effective date [Date]

This Data Processing Agreement is entered into by Mechanus IQ Ltd. ("MIQ" or "Provider") and the client named above ("Client"). It forms part of the Master Services Agreement, pilot agreement, diagnostic engagement letter, statement of work, order form, or other written agreement that incorporates it (the "Agreement").

1. Purpose

1.1 Purpose. This DPA defines the parties' data handling obligations for MIQ's forensic operational intelligence services.

1.2 Service boundary. MIQ analyzes dealership operational data to identify patterns, exceptions, leakage indicators, process variance, evidence gaps, and operational-control issues. MIQ does not provide legal, tax, accounting, audit, insurance, investment, employment, lending, regulatory, or compliance-certification advice.

1.3 Client responsibility. Client remains responsible for the legal basis, notices, consents, internal authorizations, professional-advisor review, and business decisions connected to Client Data and MIQ outputs.

2. Definitions

2.1 Agreement means the written agreement, statement of work, order form, schedule, addendum, or engagement instrument that incorporates this DPA.

2.2 Anonymized Aggregate Data means data derived from Client Data only where it has been transformed so that it cannot reasonably identify, link to, or be attributed to any individual, Client, dealership, rooftop, transaction, staff code, lender, OEM, stock number, deal number, repair order, VIN, or other operational identifier, whether directly or through combination with other available information. DPA execution alone does not authorize MIQ to create or use Anonymized Aggregate Data for cross-client products or aggregate participation.

2.3 Authorized Personnel means MIQ personnel, contractors, and service providers who need access to Client Data to provide the services and who are subject to confidentiality and security obligations.

2.4 Breach means unauthorized access to, acquisition of, disclosure of, alteration of, loss of, or compromise of Client Data in MIQ's custody or control.

2.5 Client Data means data provided by or on behalf of Client to MIQ, or generated by MIQ from that data, for the services. Client Data includes raw operational imports, normalized operational records, analytical outputs, dashboard data, audit logs, and evidence records.

2.6 Evidence Integrity Hash means a cryptographic hash, hash-chain value, Merkle root, or equivalent integrity value derived from evidence records. Evidence Integrity Hashes must not contain Client Data values, personal information, prompt content, or operational row contents.

2.7 Operational Data means PII-stripped dealership data such as dollar amounts, dates, categorical codes, counts, ratios, product categories, lender codes, department codes, stock numbers, deal numbers, repair order numbers, and Client-assigned staff codes or other pseudonymous identifiers approved in writing for the engagement.

2.8 Personal Information means information about an identifiable individual under applicable privacy law.

2.9 Processing means any collection, receipt, validation, storage, normalization, analysis, use, disclosure, transmission, return, deletion, or destruction of Client Data.

2.10 Subprocessor means a third party engaged by MIQ to process Client Data or support the services on MIQ's behalf.

3. Roles And Instructions

3.1 Client as decision authority. Client determines the business purpose for providing Client Data to MIQ and is responsible for ensuring that the data may be provided to MIQ.

3.2 MIQ as processor/service provider. MIQ processes Client Data only to provide the services, follow documented Client instructions, comply with this DPA, comply with the Agreement, protect the security and integrity of the services, satisfy legal obligations, and exercise rights expressly permitted by the Agreement.

3.3 Documented instructions. Client's documented instructions include this DPA, the Agreement, the applicable statement of work or order form, and written instructions from Client's authorized contact.

3.4 Conflicting instructions. If MIQ believes an instruction is unlawful, unsafe, inconsistent with this DPA, or inconsistent with MIQ's two-layer personal-information minimization architecture, MIQ may pause the affected processing and request clarification before continuing.

4. Personal Information Minimization and Two-Layer Intake Boundary

4.1 No Customer Personal Information Intake and Independent Intake Screen. Client must remove customer personal information before transferring data to MIQ. MIQ will not ask Client to provide customer names, addresses, telephone numbers, email addresses, Social Insurance Numbers, driver's licence numbers, credit bureau data, bank account numbers, credit card numbers, or other direct customer identifiers. In addition to Client's stripping, MIQ operates an independent, fail-closed intake screen that rejects detectable customer personal information before the export is accepted into storage. Personal information identified at intake is not retained.

4.2 Staff-coded analysis. If personnel analysis is selected, Client must use Client-assigned staff codes, role labels, department labels, or other pseudonymous identifiers approved in writing for the engagement. Client must not provide employee names, personal addresses, personal phone numbers, Social Insurance Numbers, payroll account numbers, or unnecessary employee personal information under this DPA. Any future exception requires explicit founder-approved constitutional authority and a separate written handling instrument that states the purpose, field scope, minimization, retention, masking, access, and approval controls.

4.3 No full VIN or raw partial VIN in v1. Client must not provide full VINs, short VINs, last-eight VINs, raw partial VINs, or raw VIN hashes under this DPA. Any future exception requires explicit founder-approved constitutional authority and a separate written handling instrument that states the field scope, purpose, minimization, retention, masking, access, and approval controls.

4.4 No credentials, scraping, or unauthorized access. Client must not provide DMS credentials, lender portal credentials, OEM credentials, or other third-party system credentials to MIQ under this DPA. This DPA does not authorize scraping, RPA, stealth browser automation, credential sharing, or unauthorized access.

4.5 PII discovery procedure. If MIQ discovers or reasonably suspects that Client Data contains customer PII or unnecessary employee PII, MIQ may quarantine or stop processing the affected data, notify Client's designated contact, securely delete or return the affected data as appropriate, and request replacement PII-stripped data.

4.6 Operational sensitivity. Even where data is PII-stripped, Client Data may remain confidential, commercially sensitive, or indirectly linkable by Client. MIQ will handle all Client Data under this DPA whether or not a specific data element is ultimately treated as Personal Information.

5. Permitted And Prohibited Use

5.1 Permitted processing. MIQ may process Client Data to:

(a) validate, normalize, and quality-check authorized operational exports;

(b) perform deterministic analysis, anomaly detection, exception monitoring, pattern intelligence, and operational-control analysis;

(c) generate reports, dashboards, alerts, recommendations, method notes, and evidence records;

(d) support Client-requested correction, dispute, export, retention, or destruction workflows;

(e) maintain security, audit logs, access controls, and evidence integrity; and

(f) perform other processing expressly authorized by the Agreement or written Client instruction.

5.2 Prohibited processing. MIQ must not:

(a) sell, rent, lease, or commercially exploit Client Data in identifiable, pseudonymous, transaction-level, rooftop-level, staff-level, or dealer-attributable form;

(b) combine Client Data with another client's data except where a signed or versioned Data Participation Addendum, statement of work, order form, product schedule, or successor written instrument expressly authorizes the specific use;

(c) use Client Data to train, fine-tune, tune, calibrate, evaluate, select features for, benchmark, improve, or contribute to AI or machine-learning models except under a signed or versioned Data Participation Addendum, statement of work, product schedule, order form, or successor written instrument that satisfies MIQ's controlled-learning requirements;

(d) disclose Client Data to Singularity or any MIQ affiliate except under a separate client-signed data contribution or affiliate-use agreement;

(e) disclose Client Data to public AI tools or unauthorized developer tools;

(f) publish or disclose dealer-identifiable, customer-identifiable, staff-identifiable, lender-identifiable, OEM-identifiable, rooftop-identifiable, or transaction-identifiable outputs outside Client's authorized recipient group; or

(g) use MIQ outputs to accuse any individual or business of fraud, criminal conduct, illegality, dishonesty, intent, or personal culpability.

5.3 DPA execution is not data-participation authority. Signing this DPA does not authorize cross-client benchmarking, aggregate anomaly intelligence, commercial aggregate products, lender-facing aggregate products, model training, controlled learning, federated learning, model-weight aggregation, contribution of model updates, or affiliate data contribution.

5.4 Controlled-learning lane requirements. Any controlled-learning or federated-learning use must be separately documented inside a signed or versioned Data Participation Addendum, statement of work, order form, product schedule, or successor written instrument, and must identify the model family, eligible signal scope, opt-out mechanism, opt-out effect, cohort and concentration gates, privacy-budget controls, revocation rule, runtime boundary, and evidence requirements.

6. Subprocessors And MIQ-Controlled Components

6.1 Approved subprocessors. Client authorizes MIQ to use the following subprocessors for the stated purposes, subject to this DPA and the applicable Agreement.

Subprocessor Purpose Processing location or boundary Data processed
Amazon Web Services, Inc. Hosting, storage, databases, object storage, compute, backups, and infrastructure services AWS ca-central-1 for storage, backups, databases, logs, evidence records, and non-LLM application processing Client Data required to provide the services
Amazon Web Services, Inc. - Amazon Bedrock Model-assisted summarization or analysis only if the Agreement or statement of work expressly elects this path Cross-region profile may route prompt content to United States regions as well as Canada. Not a Canada-only inference path PII-stripped Operational Data and MIQ-generated analytical text only, if separately authorized
Auth0 or successor identity provider Authentication and identity management, if enabled for Client's tenant Identity-provider processing location and metadata treatment must be disclosed in the applicable subprocessor register or security packet Authentication metadata, access tokens, user account metadata; no raw operational Client Data content
Stripe or successor payment processor Payment, invoicing, and billing support, if used Payment processor systems and applicable payment records Billing and payment records, not raw operational Client Data

6.2 Subprocessor obligations. MIQ will maintain written obligations with subprocessors that are appropriate to the service and the data involved. MIQ remains responsible for subprocessors' handling of Client Data to the extent required by the Agreement.

6.3 New subprocessors. MIQ will provide prior notice before adding a subprocessor that will process operational Client Data in a materially new way. Client may object on reasonable privacy, security, confidentiality, or residency grounds. If the parties cannot resolve the objection, Client may terminate the affected service or statement of work.

6.4 Subprocessor register. MIQ will maintain a canonical subprocessor register and provide the then-current client-facing extract or security packet under the applicable Agreement. The register is the source of truth for each service's purpose, data class, processing or storage region/boundary, contractual role, change-notice posture, and evidence status. This Section 6.4 does not duplicate those facts or expand the approved list in Section 6.1; the current client-authorized list remains controlled by Section 6.1 and any applicable written election or amendment.

6.5 MIQ-controlled monitoring components. MIQ may operate self-hosted monitoring and error-tracking components for error detection, operational monitoring, and incident response. These components are MIQ-controlled service components rather than third-party subprocessors where they are not operated by an external provider. Application error context, system logs, and operational diagnostics must minimize or exclude Client Data values.

7. Security Measures

7.1 Administrative and technical safeguards. MIQ will maintain administrative, technical, and organizational safeguards designed to protect Client Data against unauthorized access, disclosure, alteration, loss, and destruction.

7.2 Minimum control set. The safeguard program will include:

(a) encryption at rest for databases, object storage, and backups that hold Client Data;

(b) encryption in transit for transfers between Client and MIQ and between MIQ systems;

(c) tenant isolation using tenant-scoped access controls and forced row-level security or successor controls approved by MIQ;

(d) least-privilege access controls for Authorized Personnel;

(e) multi-factor authentication for administrative access to systems containing Client Data;

(f) audit logging for access to, changes to, and operations on Client Data;

(g) secure software-change practices for systems that process Client Data;

(h) incident response procedures;

(i) vulnerability management and patching procedures; and

(j) self-hosted or MIQ-controlled operational monitoring for systems that process Client Data.

7.3 No third-party analytics. MIQ must not deploy third-party analytics, session replay, behavioral tracking, advertising pixels, fingerprinting, or telemetry tools on systems that process or display Client Data.

7.4 Access limitation. MIQ will limit Client Data access to Authorized Personnel who need access for the services, security, support, incident response, legal hold, audit, or compliance with the Agreement.

8. Model Inference Boundary

8.1 Default exclusion. Model-assisted inference over Client Data is excluded unless the Agreement, statement of work, order form, or processing schedule expressly authorizes it.

8.2 Election required. Where model-assisted inference is selected, the authorizing instrument must identify the model provider or model family, the data allowed in prompts, the redaction or minimization controls, the processing location or cross-region posture, output use limits, retention treatment, and whether the path is excluded, disclosed cross-border, or verified Canada-resident.

8.3 Hosted model cross-region disclosure. If a hosted model profile with disclosed cross-region inference is selected, Client acknowledges that PII-stripped prompt content and MIQ-generated analytical text may be routed outside Canada, including to United States regions. MIQ must not describe that path as Canada-resident or Canada-only.

8.4 No public AI tooling for Client Data. Developer-assistant tooling, public chat tools, and general-purpose AI tools are not authorized production subprocessors for Client Data under this DPA unless a later written amendment expressly authorizes the specific tool, data category, processing location, security boundary, and Client consent or approval path.

8.5 No model-training by default. Model-assisted inference, if authorized, does not authorize model training, fine-tuning, tuning, calibration, feature selection, model evaluation, benchmarking, model improvement, controlled learning, federated learning, or contribution of model updates.

9. Cross-Border Transfer And Residency

9.1 Canada-first storage and primary processing. MIQ's service commitment is that Client source uploads, normalized operational data, databases, object storage, logs, evidence records, backups, and non-LLM application processing remain in Canada. The only permitted non-Canada processing under this DPA is separately elected model inference under Sections 8.2 and 8.3 and the authentication metadata and billing or payment records processed by the identity and payment subprocessors approved in Section 6.1; a generic later instrument cannot broaden this commitment.

9.2 Separate inference treatment. Model inference is treated separately from storage and primary non-LLM processing. A model-inference path may not be represented as Canada-only unless that specific path has been verified and recorded in the applicable Agreement or processing schedule.

9.3 Prior written approval for non-Canada Client Data processing. MIQ will not intentionally transfer, store, or process Client Data outside Canada except for (a) model inference expressly authorized under Sections 8.2 and 8.3 and the applicable signed election, and (b) authentication metadata and billing or payment records processed by the identity and payment subprocessors approved in Section 6.1. No statement of work, order form, generic instruction, or later instrument can authorize other non-Canada Client Data processing unless it expressly amends this DPA and is at least as protective.

9.4 Remote access. Authorized Personnel may access systems remotely only through secure channels, logged access, and device controls. MIQ must not store Client Data on unmanaged personal devices.

10. Retention And Destruction

10.1 Retention schedule. Unless the Agreement states a shorter period, MIQ's baseline retention schedule is:

Data category Retention period
Raw operational imports Active engagement plus 90 calendar days
Analytical outputs Active engagement plus 365 calendar days
Dashboard data Active engagement plus 180 calendar days
Evidence records other than override records Active engagement plus 1,095 calendar days
Durable finding records 2,555 calendar days (7 years) from record date; archive, then destroy
Override records and SOP gate override records 7 years from record date
Audit logs 2 years from entry date
Billing and financial records 7 years from transaction date

10.2 Engagement termination event. Engagement termination, offboarding, or early-destruction request must be recorded in writing or through an authenticated workflow. MIQ will not infer termination solely from inactivity, missed uploads, low usage, stale dashboard activity, or absence of recent data.

10.3 Destruction method. MIQ may use secure deletion, cryptographic erasure, deletion of tenant-scoped records, object-storage lifecycle deletion, cache flushes, and backup-expiry procedures appropriate to the data category and storage class.

10.4 Destruction notice. After termination or upon written request where applicable, MIQ will provide a data destruction notice or schedule identifying retained categories, expected destruction dates, and applicable exceptions.

10.5 Destruction confirmation. MIQ will provide reasonable confirmation after destruction milestones are complete. Any timestamp, hash-chain, or evidence-rail proof must accurately state whether it is active, placeholder, internal-only, or independently verifiable.

10.6 Legal hold and required retention. MIQ may suspend destruction where required by law, legal hold, preservation instruction, dispute, investigation, professional-advisor instruction confirmed by Client, or obligations that survive termination.

10.7 Backup destruction. Backup copies will be destroyed, expired, or rendered inaccessible according to MIQ's backup and retention procedures, subject to technical feasibility, legal hold, and required retention.

11. Evidence Integrity And Hash Anchoring

11.1 Evidence records. MIQ may create evidence records for uploads, findings, reports, dashboard events, access events, overrides, actions, configuration changes, destruction events, and related service events. Override records and SOP gate override records follow the 7-year retention period in Section 10.1.

11.2 Hash-only integrity. Evidence Integrity Hashes, hash chains, or public root anchors must not contain Client Data values, Personal Information, prompt content, operational row contents, tenant identifiers in public form, raw CSV content, staff codes, stock numbers, deal numbers, repair order numbers, or dealer-identifying information.

11.3 Optional evidence rail activation. Permissioned-ledger anchoring, public-chain root anchoring, and RFC 3161 timestamping are active only if the applicable statement of work or evidence schedule expressly activates the selected rail and MIQ has recorded verified production availability for that rail in the delivery environment. Contractual selection alone does not make an evidence rail live or available.

11.4 No legal-status guarantee. Evidence integrity tools support provenance, sequencing, tamper detection, and auditability. MIQ does not represent any evidence rail, public root anchor, or timestamp as court-admissible, regulator-approved, or legally sufficient unless the applicable proof is attached to the Agreement or the specific artifact.

12. Breach Notification And Incident Response

12.1 Client notice. If MIQ confirms a Breach that affects or may affect Client Data, MIQ will notify Client's designated privacy or security contact without undue delay after confirmation and as soon as feasible in the circumstances.

12.2 Operational target. MIQ's internal operational goal is to provide initial Client notice within 72 hours where feasible and legally appropriate. This is an operational target, not a representation of a fixed statutory deadline.

12.3 Notice content. Initial notice will include, to the extent known, the nature of the Breach, affected data categories, affected systems or tenants, approximate timing, steps taken, mitigation steps planned, and MIQ contact information for follow-up.

12.4 Cooperation. MIQ will cooperate reasonably with Client in assessing legal notice duties, regulator communications, individual communications, containment, remediation, and post-incident reporting.

12.5 Breach records. MIQ will maintain incident and breach records for at least 24 months, or longer where required by law, legal hold, the Agreement, or MIQ policy.

13. Data Subject And Individual Requests

13.1 Routing. If MIQ receives a data subject, employee, customer, regulator, or privacy request relating to Client Data, MIQ will redirect the request to Client or notify Client unless legally prohibited.

13.2 Client-led response. Client is responsible for determining how to respond to requests from individuals because Client controls the source relationship and any re-identification keys for staff codes or operational identifiers.

13.3 Reasonable assistance. MIQ will provide reasonable assistance to locate, export, correct, restrict, or delete responsive Client Data in MIQ's custody, subject to this DPA, legal hold, evidence-integrity limits, retention obligations, and the Agreement.

13.4 Identifier limits. MIQ will not ask Client to provide customer PII to respond to a request unless a separate written and minimized handling path is approved. Where personnel-code lookup is required, Client should provide only the minimum operational identifiers needed for the response.

14. Aggregate, De-Identified, And Controlled-Learning Uses

14.1 No implied consent. DPA execution, account creation, upload attestation, public Terms of Use, privacy-policy acknowledgement, Auth0 invite acceptance, mini-audit consent, dealer setup submission, continued use, or dashboard access does not authorize aggregate intelligence, controlled learning, model training, affiliate contribution, lender-facing products, or public disclosure.

14.2 Aggregate intelligence. Any cross-client aggregate anomaly intelligence, benchmarking, commercial aggregate product, lender-facing product, OEM-facing product, insurer-facing product, investor-facing product, or public aggregate disclosure requires authenticated signup or website legal terms presented during account creation, a signed Data Participation Addendum, SOW, order form, or product schedule that expressly activates the aggregate-intelligence lane, provides an opt-out path where aggregate participation is default-on, and defines permitted use, suppression rules, cohort floors, revocation treatment, recipient limits, and no-reidentification obligations.

14.3 Controlled learning. Any controlled learning or federated learning requires a signed or versioned Data Participation Addendum, SOW, order form, product schedule, or successor written instrument that satisfies the requirements in Section 5.4.

14.4 Affiliate and Singularity boundary. No Client Data, Anonymized Aggregate Data, aggregate intelligence, controlled-learning artifact, model output, model update, model weight, gradient, metric, benchmark, or client-derived data may be contributed, transferred, licensed, pooled, or disclosed to Singularity or any other affiliate unless a separate client-signed data contribution or affiliate-use agreement expressly authorizes it.

14.5 No re-identification. Neither party may attempt to re-identify, reverse engineer, single out, link, or infer any individual, Client, rooftop, staff member, customer, transaction, lender, OEM, or business partner from aggregate or anonymized outputs.

15. Audit And Information Rights

15.1 Information requests. Client may request reasonable information about MIQ's controls, subprocessors, retention schedule, breach procedures, and evidence exports applicable to Client Data.

15.2 Audit path. Client may request an audit or third-party review of MIQ's compliance with this DPA on reasonable written notice. The parties will agree on scope, timing, confidentiality, security, personnel access, and cost before the audit begins.

15.3 Audit limits. Audits must not compromise another client's data, MIQ's confidential security architecture, production availability, privileged material, trade secrets, or unrelated corporate records.

15.4 Remediation. If an audit identifies material non-compliance with this DPA, MIQ will prepare a reasonable remediation plan and timeline.

16. Return, Export, And Offboarding

16.1 Return or export. Upon termination or Client request, MIQ will provide a reasonable export of Client's available analytical outputs, dashboard data, and evidence records in a machine-readable format where technically feasible and subject to the Agreement.

16.2 Export contents. Exports may include reports, structured analytical outputs, evidence records, hash-chain references, method notes, and manifests. Exports must not include another client's data.

16.3 Destruction after export. Return or export does not prevent MIQ from retaining records that survive under the retention schedule, legal hold, billing duties, evidence integrity, incident records, or other Agreement terms.

16.4 Irrevocable destruction. Once Client Data is destroyed according to this DPA and applicable procedures, MIQ has no obligation to reconstruct it.

17. Confidentiality

17.1 Confidential treatment. Each party will treat the other party's confidential information with reasonable care and will use it only for the Agreement.

17.2 Permitted disclosure. A party may disclose confidential information to personnel, contractors, subprocessors, professional advisors, insurers, auditors, or legal authorities only where the disclosure is necessary, authorized, subject to appropriate confidentiality obligations where practical, or required by law.

17.3 Compelled disclosure. If a party is legally required to disclose the other party's confidential information, it will provide prior notice where legally permitted and will reasonably cooperate to limit the disclosure.

18. Survival

18.1 Surviving terms. The following survive expiry or termination of this DPA and the Agreement to the extent applicable: Sections 2, 4, 5.2, 5.3, 5.4, 8.5, 10, 11, 12.5, 13, 14, 16, 17, 18, and any other provision that by its nature should survive.

18.2 Aggregate and no-reidentification survival. No-reidentification, affiliate-transfer restrictions, confidentiality, and any surviving aggregate or controlled-learning restrictions continue after termination.

19. General

19.1 Conflict. If this DPA conflicts with the Agreement, this DPA controls for data processing, privacy, data security, retention, and Client Data handling matters, unless the conflicting term is more protective of Client Data and expressly states that it overrides this DPA.

19.2 Amendments. This DPA may be amended only by a written instrument signed or otherwise accepted by both parties.

19.3 Governing law and regulatory responsibility. This DPA is governed by the laws of the Province in which the Client's principal place of business is located and the federal laws of Canada applicable therein. Client is responsible for its dealership operations and business decisions under applicable dealer regulation. MIQ remains responsible for legal and regulatory obligations applicable to MIQ's own conduct, services, systems, and data handling. MIQ provides operational intelligence only and does not act as Client's regulator or legal adviser. Nothing in this Section transfers or excludes a party's non-waivable obligations under applicable law.

19.4 No external approval representation. This DPA does not state or imply that any regulator, lender, insurer, accountant, tax advisor, external legal reviewer, or other external professional has approved MIQ's services, controls, evidence architecture, model-inference path, aggregate-intelligence path, or controlled-learning path.

20. Signatures

Mechanus IQ Ltd.

Name: ______

Title: ______

Date: ______

Signature: _______

Client

Legal name: ______

Name: ______

Title: ______

Date: ______

Signature: _______

Schedule B-1: Processing Details

Item Detail
Nature of processing Automated and semi-automated analysis of dealership Operational Data for forensic operational intelligence, anomaly detection, exception monitoring, operational-control review, reporting, dashboards, and evidence records
Purpose of processing The services described in the Agreement and applicable statement of work
Categories of data Dollar amounts, dates, categorical codes, counts, ratios, lender codes, department codes, product categories, selected operational identifiers, stock numbers, deal numbers, repair order numbers, and Client-assigned staff codes or other pseudonymous identifiers
Excluded data Customer names, addresses, phone numbers, emails, SINs, driver's licence numbers, credit bureau data, bank or payment card numbers, full VINs, raw partial VINs in v1, employee names, unnecessary employee PII, credentials, free-text PII, and any field not authorized for the engagement
Categories of individuals indirectly reflected Dealership personnel where Client uses approved staff codes or similar pseudonymous identifiers. Customer direct identifiers are prohibited: Client must strip them before transfer, and MIQ's independent intake screen rejects detectable instances before accepted storage. Approved staff codes are pseudonymous, not anonymous, and remain subject to this DPA. Transaction facts may relate to customer transactions without identifying the customer.
Processing duration The Agreement term plus the retention periods in Section 10
Primary processing location Canada for storage, backups, databases, logs, evidence records, and non-LLM application processing
Model inference location Excluded by default. If elected, location and cross-border posture must be stated in the applicable model-inference election, statement of work, or processing schedule

Schedule B-2: Model Inference Election

Select one option in the Agreement, statement of work, order form, or processing schedule. If no option is selected, Option A applies.

Option Treatment
Option A - Excluded No model-assisted inference over Client Data. Deterministic and rule-based processing only
Option B - Disclosed cross-border Bedrock inference Amazon Bedrock model-assisted inference may be used for PII-stripped Operational Data and MIQ-generated analytical text. Client acknowledges cross-region routing may include United States regions and is not Canada-only
Option C - Verified Canada-resident inference Model-assisted inference may be used only after MIQ verifies and records a Canada-resident path in the applicable instrument

Reliance Record

This is the client signature copy of the MIQ Data Processing Agreement. No statement in this agreement represents outside legal, tax, accounting, insurance, lender, regulator, privacy, or professional approval.

Version 2026-09-02 · Published at mechanusiq.com/legal/data-processing-agreement/ · This published version is the operative text referenced by the Mechanus IQ onboarding acceptance record. Questions: legal@mechanusiq.com