Meadowlark / Legal

Data Processing Agreement

Last updated: August 2026  ·  GDPR Article 28 compliant

This Data Processing Agreement ("DPA") forms part of the Terms of Service between Tenon ("Processor") and the customer ("Controller") using the Meadowlark platform. This DPA applies where the Controller's use of the platform involves processing personal data subject to GDPR or applicable Canadian privacy law.

1. Definitions

2. Roles and Responsibilities

The Controller determines what personal data is entered into the Meadowlark platform and for what purpose. The Processor (Meadowlark) processes this data solely on the instructions of the Controller, as set out in the Terms of Service and this DPA.

The Processor shall:

3. Nature and Purpose of Processing

4. Security Measures

The Processor implements the following technical and organizational security measures:

5. Sub-Processors

The Processor uses the following approved sub-processors. The Controller hereby provides general authorization for the use of these sub-processors, subject to the conditions below:

DigitalOcean, LLC

Stripe, Inc.

Resend, Inc.

PostHog (self-hosted)

Anthropic, PBC (and/or OpenRouter, Inc.)

Intuit Inc. (QuickBooks Online)

Cloudflare, Inc.

The Processor will inform the Controller of any intended changes to sub-processors (addition or replacement) and give the Controller the opportunity to object to such changes before they take effect.

6. Data Subject Rights

The Processor shall assist the Controller in fulfilling its obligations to respond to data subject requests. Where a data subject contacts the Processor directly, the Processor will promptly refer the request to the Controller.

The Processor will provide reasonable technical assistance to the Controller to enable the Controller to:

7. Personal Data Breach Notification

In the event of a personal data breach, the Processor will:

Breach notifications will be sent to the account owner's registered email address and, if critical, by phone to the contact on file.

8. Audit Rights

Upon reasonable written notice (minimum 30 days), the Controller may conduct an audit of the Processor's data processing activities relevant to this DPA, or request a summary of third-party audit reports. Audits will be conducted at the Controller's expense and in a manner that minimizes disruption to the Processor's operations.

9. Data Return and Deletion

Upon termination of the service agreement, at the Controller's written request, the Processor will:

10. Governing Law

This DPA is governed by the laws of the Province of Quebec, Canada. It forms part of and is subject to the Terms of Service between the parties.

11. Contact

For questions about this DPA or data processing practices:
Joe Meadows, Privacy Officer
joe@meadowlarkconstruction.ca