EntificLabs.

Entific Labs is a brand of TSV Studios Inc., incorporated in British Columbia, Canada.

Documents

  • Terms of Use
  • Privacy Policy
  • Data Processing Addendum

Version 1.0
Last updated August 21, 2026

Data Processing Addendum

The terms on which Entific processes personal information on your behalf. This Addendum forms part of the Terms of Use.

This Data Processing Addendum (“DPA”) is entered into between TSV Studios Inc., trading as Entific Labs (“Processor,” “Entific,” “we”), and the customer organisation agreeing to the Terms of Use (“Controller,” “you”). It applies whenever we process personal information on your behalf in providing the Service.

1. Definitions

  • “Customer Content” means documents you upload, text and prompts you enter, outputs generated for you, and case records you create — including personal information about your own clients contained in them.
  • “Personal Information” has the meaning given in PIPEDA and, where applicable, “personal data” under the GDPR.
  • “Applicable Privacy Law” means PIPEDA, the BC Personal Information Protection Act, and any other data protection law applicable to your use of the Service, including the GDPR and UK GDPR where you have data subjects in those jurisdictions.
  • “Subprocessor” means a third party engaged by us to process Personal Information on your behalf.

2. Roles of the parties

You are the Controller of Personal Information contained in Customer Content. We are the Processor, and we process it only on your documented instructions.

Your use of the Service constitutes your instruction to process Customer Content for the purposes of providing the Service, and for no other purpose.

Separately, we act as a Controller of account and billing data about your personnel. That processing is governed by our Privacy Policy, not this DPA.

3. Our obligations

We will:

  • process Personal Information only on your documented instructions, unless required otherwise by law — in which case we will notify you before processing, unless the law prohibits it;
  • ensure personnel authorised to process Personal Information are bound by confidentiality obligations;
  • implement the security measures described in Section 6;
  • engage Subprocessors only as permitted in Section 5;
  • assist you, taking into account the nature of the processing, in responding to data subject requests;
  • assist you with data protection impact assessments and consultations with regulators, where reasonably required;
  • notify you of a Personal Data Breach as set out in Section 7; and
  • delete or return Personal Information at the end of the Service as set out in Section 8.

4. No training, no secondary use

We do not use Customer Content to train, fine-tune, or improve any machine learning model, and we contractually require our model providers not to do so either. Our systems are improved using published court decisions and other public legal sources — not the files, prompts, or case records you entrust to us.

Specifically, we will not:

  • use Customer Content to train, fine-tune, or evaluate any machine learning model;
  • permit any Subprocessor — including model providers — to do so;
  • use Customer Content to develop or improve products for other customers;
  • sell, rent, or otherwise disclose Customer Content for commercial gain; or
  • access Customer Content except as necessary to provide the Service, resolve a support request you raise, or comply with law.

We may generate and use aggregate operational metrics — request counts, latency, error rates, and token usage — that contain no Personal Information and cannot be attributed to you or your clients.

5. Your obligations

You are responsible for:

  • having a lawful basis to collect Personal Information and to provide it to us;
  • giving any notice and obtaining any consent your own professional, regulatory, or legal obligations require;
  • the accuracy of Personal Information you provide; and
  • configuring access within your organisation so that only appropriate personnel can see a given case.

If you are a lawyer or regulated consultant, you remain responsible for your own duties of confidentiality and for determining whether use of a cloud service is consistent with them.

6. Subprocessors

You authorise us to engage the Subprocessors listed below. We impose data protection obligations on each of them no less protective than those in this DPA, and we remain liable to you for their performance.

SubprocessorPurposeLocationCustomer Content
Vercel Inc.Application hosting and content deliveryUnited StatesYes
Supabase Inc.Database and file storageCanadaYes
Clerk Inc.Authentication and account identityUnited StatesNo
Stripe, Inc.Payment processing and billingUnited StatesNo
Algolia SASSearch infrastructure for published court decisionsUnited States / European UnionNo
PostHog Inc.Product analytics and session replay. Form inputs are masked before captureUnited StatesNo
Railway Corp.Application hostingCanadaYes
Google LLCAI model processingUnited StatesYes
OpenAI, L.L.C.Language model processingUnited StatesYes
NVIDIA CorporationLanguage model processingUnited StatesYes

Of these, 6 may process Customer Content. The remainder handle only account, billing, or usage metadata.

We will give you notice before adding or replacing a Subprocessor that processes Customer Content. If you reasonably object on data protection grounds within 30 days, you may terminate the affected part of the Service without penalty for the remainder of the term.

7. Security measures

We maintain measures appropriate to the sensitivity of immigration and legal records, including:

  • Encryption — TLS in transit; encryption at rest for stored documents and database records.
  • Access control — role-based access, scoped per organisation and per case; administrative access limited to personnel who require it.
  • Isolation — customer workspaces are logically separated; case records are scoped to the owning organisation.
  • Input masking — form inputs are masked before capture in product analytics, so text entered into the Service is not recorded in session replays.
  • Secrets handling — service credentials are held in managed secret storage and are not committed to source control.
  • Backups — encrypted, with a defined retention and purge cycle.

8. Personal data breaches

We will notify you without undue delay, and in any event within 48 hours, after becoming aware of a Personal Data Breach affecting Customer Content.

We become aware when we have a reasonable degree of certainty that a Personal Data Breach has occurred. Investigating whether an event is a Personal Data Breach happens before that point; an alert, an anomaly, or an unconfirmed report is not by itself awareness.

Notification is not a finished investigation. Where we do not yet have full details, we will notify you with the information available at the time and provide the remainder in phases, without undue further delay, as the investigation progresses. We will not withhold notice while establishing the full picture.

Our notice will describe, to the extent known:

  • the nature of the breach and the categories and approximate number of records concerned;
  • the likely consequences of the breach;
  • the measures taken or proposed to address it and mitigate its effects; and
  • a contact point for further information.

We will cooperate with you in investigating and remediating the breach, and in meeting any obligation you have to notify a regulator or affected individuals. Reports may be sent to and received from legal@thestarkventures.com.

9. Return and deletion

On termination, we will make Customer Content available for export for 30 days. After that, we will delete it from active systems within a further 30 days, and from backups within the ordinary backup purge cycle, unless retention is required by law.

You may request deletion of specific Customer Content at any time through the Service, or by contacting legal@thestarkventures.com.

10. Audits and information

On reasonable written request, and no more than once in any 12-month period unless required by a regulator, we will provide information reasonably necessary to demonstrate compliance with this DPA. Where available, we will provide third-party audit reports or security documentation in place of an on-site audit.

11. International transfers

We are established in British Columbia, Canada. Most Subprocessors are located in the United States, so Customer Content is transferred to and processed there.

Where you have data subjects in the European Economic Area, the United Kingdom, or Switzerland, the applicable standard contractual clauses are incorporated into this DPA by reference, with Entific as data importer and you as data exporter.

12. Annex — details of processing

Subject matter and duration

Provision of legal research, workflow, and application-audit software, for the duration of your subscription plus the retention periods in Section 9.

Nature and purpose

Storage, retrieval, indexing, text extraction, and automated analysis of legal documents and case records, in order to provide the Service to you.

Categories of data subject

  • Your personnel who use the Service.
  • Your clients — the applicants, sponsors, and other individuals who are the subject of the immigration matters you manage.
  • Third parties named in documents you upload, such as family members or representatives.

Categories of Personal Information

  • Identifiers — names, email addresses, and UCI numbers.
  • Immigration matter data — application type, refusal dates, deadlines, and case history.
  • Document contents — the full extracted text of documents you upload.
  • Account and usage data — for your personnel only.

Sensitivity. Immigration and refugee records are among the most sensitive personal information an individual has. They may reveal nationality, family status, medical history, criminal history, and grounds of persecution. Uploaded material may also be subject to solicitor-client privilege. We treat all Customer Content on that basis, regardless of whether a particular record is formally classified as sensitive under a given statute.

13. General

This DPA forms part of the Terms of Use. Where it conflicts with the Terms on the processing of Personal Information, this DPA governs. It is governed by the laws of the Province of British Columbia and the federal laws of Canada applicable therein. Our liability under this DPA is subject to the limitations in the Terms of Use.

14. Contact

TSV Studios Inc. (trading as Entific Labs)
555 Burrard Street, Vancouver, British Columbia V7X 1M8, Canada
Privacy: legal@thestarkventures.com
Security: legal@thestarkventures.com

© 2026 TSV Studios Inc. All rights reserved.

entific.ai