Legal
Subscription Agreement
The terms on which Daybook Technologies Inc. provides the Daybook platform to businesses.
Version 1.0 | October 7, 2026
The Subscription Agreement (together with all Order Forms and Schedules, the “Agreement”) is entered into between Daybook Technologies Inc., a corporation incorporated under the Canada Business Corporations Act with its principal place of business in Prince Edward Island (“Daybook”), and the entity identified in the applicable Order Form (the “Customer”). By clicking “I Agree”, executing an Order Form, or otherwise accessing or using the Platform, the Customer agrees to be bound by this Agreement and Daybook’s Privacy Policy located at https://daybookpro.com/privacy.
1. Definitions
In this Agreement, the following terms have the meanings set out below:
“Agreement” means this Subscription Agreement, including all Order Forms, Schedules and amendments made in accordance with Section 18.
“AI Action” means an action performed or initiated by an AI Feature, including creating or updating a record, drafting or sending a communication, or scheduling an appointment.
“AI Features” means features of the Platform that use artificial intelligence or automated processing services to analyse, extract, classify, transcribe, generate, summarize or otherwise process Customer Content, including the functionality described in Section 8.
“AI Output” means any summary, transcription, extraction, classification, draft, response, recommendation, generated content or other output produced by an AI Feature.
“CASL” means Canada’s Anti-Spam Legislation, S.C. 2010, c. 23, and any regulations made thereunder, as amended from time to time.
“Customer” means the business entity that has accepted this Agreement and is identified in the applicable Order Form.
“Customer Account Information” means information concerning the establishment, administration, commercial status and use of the Customer’s account, including the Customer’s business name, trade or industry, contact information, subscription plan, subscription and payment status, account activity, last-sign-in information, feature usage, engagement information, and account health or engagement indicators. Customer Account Information does not include full payment-card information.
“Customer Content” means all data, information, texts, records, files, and other content uploaded to, stored in, or transmitted through the Platform by or on behalf of the Customer or its Users, including Customer Personal Information.
“Customer Personal Information” means any personal information (as defined under PIPEDA) contained within Customer Content that relates to an identified or identifiable individual.
“Documentation” means the user guides, help articles, and technical specifications for the Platform made available by Daybook from time to time.
“Fees” means the subscription fees and any other amounts payable by the Customer as set out in the applicable Order Form.
“Order Form” means a written or electronic order document (including a web-based sign up form) executed or accepted by both parties that sets out the subscription plan, Fees, Subscription Term, and other commercial terms, and that incorporates this Agreement by reference.
“PIPEDA” means the Personal Information Protection and Electronic Documents Act, S.C. 2000, c. 5, and any regulations made thereunder, as amended from time to time, and includes any substantially similar provincial legislation that applies in lieu of PIPEDA.
“Platform” means Daybook’s proprietary cloud-based business management software, currently marketed under the name “Daybook”, including its modules and functionality relating to client and employee records, appointments and scheduling, invoicing and payments, communications, websites and forms, document and image processing, artificial intelligence and automated processing, and related business workflows, together with any updates, enhancements or new features made available by Daybook during the Subscription Term.
“Service” means Daybook’s provision of access to and use of the Platform, together with any support services described in the Documentation or Order Form.
“Stripe” means Stripe Payments Canada, Ltd. and its affiliates, the third-party payment processor used by Daybook to process subscription payments and, where applicable, to facilitate payment collection by Customers from their own end users.
“Subprocessor” means any third party engaged by Daybook to process Customer Personal Information in connection with the provision of the Service.
“Subscription Term” means the period during which the Customer is licensed to access and use the Platform, as set out in the applicable Order Form, and any renewal periods.
“User” means any individual who accesses or uses the Platform under the Customer’s account, including the Customer’s employees, contractors, and agents.
“Field User” means a User designated or permitted by Daybook to access field-user functionality of the Platform, subject to the features and limitations applicable to that User type.
“Office User” means a User occupying a paid office seat under the Customer’s subscription.
“Sales Partner” means an independent sales representative, referral partner, reseller, agency or other third party authorized by Daybook to market the Service, manage a commercial relationship with a Customer or provide first-line account or support assistance on Daybook’s behalf.
“Third-Party Infrastructure” means hosting, cloud computing, database, storage, communications, artificial intelligence, mapping, payment processing and other infrastructure or technology services supplied to Daybook by a Subprocessor or other third-party provider and used by Daybook in providing the Service.
“Third-Party Service” means any third-party application, account, platform or service that a Customer elects to connect or integrate with the Platform.
“Website Services” means website design, generation, hosting, maintenance or related services provided by Daybook to a Customer through or in connection with the Platform.
2. Subscription and access
2.1 Licence Grant. Subject to the terms of this Agreement and timely payment of all Fees, Daybook grants the Customer a non-exclusive, non-transferable, limited licence to access and use the Platform during the Subscription Term solely for the Customer’s internal business purposes.
2.2 Restrictions. Except as expressly permitted by this Agreement or through functionality made available by Daybook, the Customer must not sublicense, resell or commercially make the Platform available to a third party as a standalone or managed software service, or exceed the number of paid Users or other usage limits set out in the applicable Order Form. For greater certainty, this Section does not prohibit the Customer from permitting third parties to access or interact with the Platform through functionality intended for that purpose, including client, customer or parent portals, quote approval links, appointment booking tools, public forms, Customer websites, or access provided to the Customer’s accountants, subcontractors, employees, clients or other authorized persons. The Customer remains responsible for its configuration and use of such functionality and for access granted under its account.
2.3 Authorized Third-Party Access. Where the Platform includes functionality intended for access by clients, parents, guardians, accountants, subcontractors or other authorized persons, the Customer shall be solely responsible for:
(a) determining whether and to what extent each person should receive access;
(b) configuring access permissions so that each person receives only the access reasonably necessary for the authorized purpose;
(c) verifying the person’s identity and authority where appropriate;
(d) obtaining all consents and other legal authority required to make Customer Content available to that person;
(e) promptly revoking access when it is no longer required or authorized; and
(f) all activity conducted using credentials or access rights issued under the Customer’s account, except to the extent caused by Daybook’s breach of this Agreement.
2.4 Administrative Contact. The Customer must designate at least one individual as its administrative contact (“Admin”) who will be responsible for managing User accounts, receiving notices from Daybook, and ensuring the Customer’s compliance with this Agreement.
2.5 User Responsibility. The Customer is responsible for all acts and omissions of its Users in connection with the Platform. The Customer must ensure that each User complies with this Agreement and must promptly notify Daybook if it becomes aware of any unauthorized access to or use of the Platform.
2.6 Age Requirement. A User must be at least sixteen (16) years of age. A User must be at least eighteen (18) years of age to access, operate or interact directly with an AI Feature, including an AI assistant made available through a portal, website or other Customer-facing interface. The Customer must not authorize or permit a person under eighteen (18) years of age to access or interact directly with an AI Feature. Where a User has not attained the age of majority in the province or territory in which the User resides, the Customer is responsible for authorizing and supervising that User’s permitted access to and use of the Platform and for obtaining any consent or authorization required by applicable law. The Customer is responsible for the acts and omissions of all Users accessing the Platform under its account.
2.7 Acceptance. When an individual accepts this Agreement on behalf of the Customer by clicking “I Agree” or a similar button, that individual represents and warrants that they have the authority to legally bind the Customer. Daybook may record the acceptance date, the version of the Agreement accepted, and the User account associated with the acceptance. Such records constitute prima facie evidence of the Customer’s acceptance.
2.8 User Types and Seats. The Platform may provide different categories of User access, including Office Users and Field Users. Unless otherwise stated in the applicable Order Form:
(a) the Customer’s subscription includes the number of paid Office User seats specified in the Order Form;
(b) each additional Office User seat costs CAD $39.00 per month, which may be subject to change in accordance with this Agreement, billed in accordance with the billing frequency applicable to the Customer’s subscription;
(c) Fees for an Office User seat added during a billing period may be prorated from the date the seat is added;
(d) removal of an Office User seat takes effect for billing purposes at the end of the then-current billing period, and no refund or credit will be provided for the remaining portion of that period;
(e) Field User accounts are not separately charged and may be added without a numerical limit, subject to Daybook’s reasonable technical, security and acceptable-use requirements; and
(f) the features available to Office Users and Field Users may differ, as described in the Documentation.
The Customer must designate each User accurately according to the User’s role and use of the Platform. Daybook may reclassify a Field User as an Office User if that User accesses or uses functionality designated for Office Users, in which case the applicable Office User Fee will apply after notice to the Customer.
2.9 Authority of Sales Partners. A Sales Partner is not authorized to enter into an agreement on behalf of Daybook, amend this Agreement, make a warranty or representation on behalf of Daybook, waive any right of Daybook, incur any liability in Daybook’s name or otherwise bind Daybook, unless Daybook expressly grants that authority in writing. If a statement made by a Sales Partner conflicts with this Agreement, an applicable Order Form or written information issued by an authorized representative of Daybook, this Agreement and the applicable Order Form will prevail.
3. Order forms and fees
3.1 Fees and Subscription Plans. The Fees, Subscription Term, billing frequency, included Office User seats and other applicable commercial terms are set out in the applicable Order Form. Subscription plans may be offered on a monthly, annual, seasonal or other basis agreed between Daybook and the Customer.
3.2 Billing Cycle. Monthly subscriptions are billed monthly in advance. Annual subscriptions are billed as specified in the Order Form and, unless otherwise stated there, Daybook’s standard annual subscription price is equal to ten (10) months of the corresponding standard monthly subscription Fee. Seasonal subscriptions, including camp plans, are billed for the season or period specified in the Order Form. The applicable billing date or schedule is set out in the Order Form.
3.3 Payment. Fees are collected by Stripe on Daybook’s behalf unless otherwise specified in the Order Form. By accepting this Agreement, the Customer authorizes Daybook and Stripe to charge the payment method on file for Fees when due in accordance with the billing schedule applicable to the Customer’s subscription. Payment processing is subject to Section 4.
3.4 Failed Payments. If a payment fails, Daybook will notify the Customer and may retry the charge. If the outstanding amount is not paid within ten (10) days of the failed payment notice, Daybook may suspend the Customer’s access to the Platform without further notice until all outstanding amounts are paid in full.
3.5 Fee Changes. Daybook may change the Fees applicable to a monthly subscription by giving the Customer at least thirty (30) days’ prior written notice. A Fee change for an annual or seasonal subscription will not take effect before the beginning of the next renewal term or season unless the Customer expressly agrees otherwise in writing. Continued use of the Platform after the effective date of a Fee change constitutes acceptance of the changed Fees. The Customer may cancel the affected subscription before the Fee change takes effect in accordance with Section 17.
3.6 No Refunds. Fees are non-refundable. No refunds or credits will be issued for partial months of service, unused User licences, or early termination, unless the applicable Order Form expressly provides otherwise.
3.7 Taxes. The Customer is responsible for all applicable taxes, levies, or duties imposed by any governmental authority on the Fees, other than taxes on Daybook’s net income.
3.8 Free Trial. Daybook may make the Platform available to a prospective Customer for a fourteen (14) day free trial without requiring a payment card. Unless Daybook specifies otherwise, the free trial provides access to the features included in the applicable subscription plan. A free trial does not automatically convert to a paid subscription, and Daybook will not charge the Customer unless the Customer affirmatively selects a paid subscription and provides or authorizes a payment method.
At the end of any free trial, Daybook may suspend the Customer’s access to the Platform unless the Customer begins a paid subscription. If the Customer does not begin a paid subscription, Daybook may make Customer Content available for export for thirty (30) days after the trial expires and may restrict access during that period to read-only access or export functionality. After that thirty (30) day period, Daybook may delete Customer Content from its active systems at any time, subject to Daybook’s documented retention practices and applicable law. The Customer is responsible for exporting any Customer Content it wishes to retain before the export period expires. Residual copies in backup systems may remain until deleted or overwritten in the ordinary course of Daybook’s backup-retention cycle.
Daybook may suspend or terminate a free trial immediately if the Customer breaches this Agreement, misuses the Platform or creates a security or operational risk. Unless Daybook agrees otherwise in writing, a Customer is eligible for only one free trial.
4. Payment processing
4.1 Stripe as Payment Processor. Payment card processing for subscription Fees is performed by Stripe. The Customer’s use of Stripe’s payment services is subject to Stripe’s then current terms of service and privacy policy, which the Customer agrees to as a condition of using the Platform’s payment features. Daybook does not store full payment card numbers, security codes, or other sensitive card data on its own systems.
4.2 Recurring Authorization. By providing or authorizing a payment method, the Customer authorizes Daybook and Stripe to charge that payment method for all Fees when due in accordance with the billing frequency and payment schedule specified in the applicable Order Form, including any recurring monthly, annual or seasonal Fees. This authorization continues until the applicable subscription is cancelled, expires or is terminated in accordance with this Agreement.
4.3 Accurate Billing Information. The Customer must maintain accurate and up to date billing information (including payment card details and billing address) in its account. The Customer is responsible for any failed payments resulting from inaccurate or outdated billing information.
4.4 Chargebacks and Disputes. If the Customer initiates a chargeback or payment dispute with its card issuer or bank in respect of any Fee, the Customer must notify Daybook promptly. Daybook may suspend the Customer’s access to the Platform pending resolution of the dispute. Daybook reserves the right to recover any amounts lost as a result of a chargeback, together with any associated fees charged by Stripe or the card issuer.
4.5 Customer Collected Payments. Where the Platform enables the Customer to collect payments from its own end users (for example, parents paying camp deposits or clients paying invoices), those payments are conducted directly between the Customer and its end users via Stripe. Daybook is not a party to those transactions and is not responsible for any refunds, chargebacks, disputes, or losses arising from them. The Customer is solely responsible for its obligations to its end users in respect of such payments.
4.6 Payment Card Network Compliance. The Customer is solely responsible for complying with all applicable card network rules (including but not limited to those of Visa, Mastercard, and American Express) in respect of payments collected through the Platform.
5. Customer content and data ownership
5.1 Ownership. All Customer Content remains the property of the Customer or, where applicable, the Customer’s end users. Nothing in this Agreement transfers any ownership of Customer Content to Daybook.
5.2 Licence to Daybook. The Customer grants Daybook a limited, non-exclusive, royalty-free licence to access, collect, process, transmit, store, reproduce and otherwise use Customer Content to the extent reasonably necessary to provide, maintain, secure and support the Service, perform Daybook’s obligations under this Agreement, provide export and transition functionality, maintain backup copies in accordance with Daybook’s ordinary backup-retention cycle, and comply with applicable law. This licence continues for as long as Daybook retains Customer Content in accordance with this Agreement.
5.3 Restrictions on Daybook’s Use. Daybook will not use Customer Content for its own commercial purposes, for advertising, or to train general-purpose AI models, without the Customer’s express prior written consent. Daybook may use aggregated, de-identified data derived from Customer Content for product improvement and analytical purposes, provided that such data cannot reasonably be used to identify the Customer or any individual. Daybook will not permit a Sales Partner to use Customer Content for advertising, independent prospecting, sale or disclosure to an unrelated third party, or any purpose unrelated to the Customer’s relationship with Daybook.
5.4 Customer Representations. The Customer represents and warrants that: (a) it has all necessary rights, consents, and authority to upload Customer Content to the Platform and to grant the licence in Section 5.2; (b) Customer Content does not infringe any third-party intellectual property rights; (c) Customer Content does not violate any applicable law.
6. Data processing and privacy
6.1 Roles. As between the parties, the Customer is the organization that determines the purposes and means of collecting and using Customer Personal Information. Daybook acts as a service provider that processes Customer Personal Information on the Customer’s behalf and in accordance with the Customer’s instructions as set out in this Agreement and the applicable Order Form.
Daybook may use Sales Partners and other service providers to perform limited account-management, onboarding, training and support functions on Daybook’s behalf. Where a Sales Partner processes Customer Personal Information on Daybook’s behalf, the Sales Partner acts as a Subprocessor and is subject to the applicable requirements of this Agreement and Schedule B.
Where a Sales Partner processes Customer Account Information for Daybook’s account-administration, sales, commission, relationship-management or support purposes, the Sales Partner acts as a service provider to Daybook and must process that information only for the purposes authorized by Daybook.
6.2 Compliance. Each party must comply with all applicable privacy legislation, including PIPEDA, in connection with its activities under this Agreement.
6.3 Privacy Policy. Daybook’s Privacy Policy, as updated from time to time and available at Daybook’s website, is incorporated into this Agreement by reference and describes Daybook’s data handling practices in detail.
6.4 Data Residency. The primary production database for the Platform is hosted using Google Firebase infrastructure having its primary data location in Toronto, Ontario, Canada. Certain server application code, AI Features, communications services, integrations and other Platform functionality may process Customer Personal Information outside Canada, including in the United States. The particular processing location may depend on the applicable functionality and service provider and may not be selectable by Daybook. The Customer acknowledges and consents to these data flows. Additional information is provided in Daybook’s Privacy Policy and Schedule B.
6.5 Security Safeguards. Daybook will implement and maintain appropriate administrative, technical, and physical safeguards designed to protect Customer Personal Information against unauthorized access, use, disclosure, alteration, or destruction, having regard to the sensitivity of the information and the risks involved.
Where a Sales Partner is permitted to access Customer Account Information, Customer Personal Information or a support request, Daybook will require the Sales Partner to maintain safeguards appropriate to the sensitivity of the information and the nature of the access. Such safeguards may include individual user accounts, role-based access restrictions, confidentiality obligations, access-revocation procedures, security training and incident-reporting requirements.
6.6 Security Incidents. Daybook will notify the Customer promptly upon confirming that a breach of security safeguards has occurred involving Customer Personal Information, to enable the Customer to meet its own notification obligations under PIPEDA or other applicable law. Such notification will include, to the extent then known, a description of the nature of the breach, the information affected, and the steps taken or proposed to address the breach. Where a breach of security safeguards originates with a Subprocessor, Daybook’s notification obligation under this Section shall commence when Daybook receives notice or otherwise becomes aware of information reasonably sufficient to confirm that the breach involves Customer Personal Information.
For greater certainty, where a Sales Partner processes Customer Personal Information on Daybook’s behalf, that Sales Partner is treated as a Subprocessor for purposes of this Section.
6.7 Breach Records. Daybook will maintain a record of every breach of security safeguards involving Customer Personal Information for at least twenty-four (24) months after the day on which Daybook determines that the breach has occurred, as required by the Breach of Security Safeguards Regulations made under PIPEDA.
6.8 Data Return and Deletion. Except for an expired free trial governed by Section 3.8, upon expiry or termination of this Agreement, Daybook will make Customer Content available for export by the Customer for a period of thirty (30) days following the effective date of termination. Following that period, Daybook may delete Customer Content from its active systems. Residual copies of Customer Content that exist in Daybook’s backup systems may be retained and deleted in the ordinary course of Daybook’s backup retention cycle. The Customer is solely responsible for determining the records and information it is required to retain under applicable law, regulation, professional standards or contractual obligations and must export and retain any such Customer Content before expiry of the applicable export period. Daybook is not responsible for maintaining Customer Content following the applicable deletion period solely because the Customer may be subject to a record-retention requirement, unless Daybook expressly agrees otherwise in writing.
6.9 Data Processing Addendum. The parties’ respective obligations with respect to the processing of Customer Personal Information are further described in Schedule B (Data Processing Addendum), which forms part of this Agreement.
6.10 Sales Partners and Customer Account Information. Daybook may appoint a Sales Partner to introduce the Customer to Daybook, administer or support Daybook’s commercial relationship with the Customer, assist with onboarding or training, or provide first-line account or support assistance.
Daybook may provide an assigned Sales Partner with limited Customer Account Information reasonably necessary to:
(a) identify and administer the Customer account;
(b) attribute the Customer or subscription to the applicable Sales Partner;
(c) calculate, verify or administer referral fees or commissions;
(d) monitor the Customer’s subscription and payment status;
(e) monitor adoption, engagement and use of the Platform;
(f) identify whether the Customer may require onboarding, training, support or account-management assistance; and
(g) manage Daybook’s commercial relationship with the Customer.
Customer Account Information made available to a Sales Partner may include the Customer’s business name, trade or industry, subscription plan, subscription and payment status, date of last account activity or sign-in, feature-usage and engagement information, and an account health or engagement score or similar indicator. Daybook will not provide a Sales Partner with full payment-card information.
An account health or engagement score is an internal account-management indicator based on factors such as subscription status, frequency of access, feature usage, adoption and engagement. It is not intended to assess the creditworthiness, professional competence or legal compliance of the Customer or any individual and must not be used to make a decision producing legal or similarly significant effects on an individual.
Daybook will not provide a Sales Partner with general access to the Customer’s client lists, jobs, invoices or other Customer Content solely because the Sales Partner introduced or is assigned to the Customer.
Daybook will require each Sales Partner receiving Customer Account Information, Confidential Information or personal information to use that information only for authorized Daybook purposes and to comply with appropriate confidentiality, privacy, security, access-control and deletion obligations. A Sales Partner is not authorized to use Customer information for its own unrelated purposes.
6.11 Support Requests Reviewed by Sales Partners. Where the Customer has an assigned Sales Partner, Daybook may route a request for assistance, support, training or account management to that Sales Partner for the purpose of receiving, reviewing, responding to or escalating the request. The Sales Partner may read the full contents of the request, including any messages, screenshots, documents, attachments, Customer Content or personal information included in it.
The Customer must not include personal information or Customer Content in a support request unless that information is reasonably necessary to obtain the requested assistance and the Customer has all rights, consents and other legal authority required to disclose the information to Daybook and the assigned Sales Partner for that purpose.
A Sales Partner may access Customer Content only to the extent reasonably necessary to address a support request submitted or authorized by the Customer, or as otherwise expressly directed or authorized by the Customer. Submission of a support request does not authorize the Sales Partner to access unrelated Customer Content.
Daybook will require the Sales Partner to keep the support request and its contents confidential, use them only to provide or coordinate the requested assistance, apply appropriate security safeguards, and delete or return locally retained copies when they are no longer reasonably required for the authorized purpose. These obligations apply whether the information is intentionally or inadvertently included in the support request.
6.12 Sales Partner Access Controls. Daybook will use reasonable administrative and technical controls designed to limit a Sales Partner’s access to:
(a) Customers assigned to that Sales Partner;
(b) the categories of Customer Account Information reasonably necessary for the Sales Partner’s authorized functions; and
(c) Customer Content included in or reasonably necessary to address an authorized support request.
Daybook will not knowingly provide a Sales Partner with unrestricted access to the Customer’s account or Customer Content. Daybook may suspend, restrict or revoke a Sales Partner’s access where reasonably necessary to protect the Customer, Customer Content, the Platform or another person.
6.13 Appointment and Reassignment of Sales Partners. Daybook may appoint, replace or remove a Sales Partner assigned to the Customer. Where reasonably practicable, Daybook will notify the Customer of a change if the Sales Partner will provide ongoing account-management or support services or process Customer Personal Information. Upon reassignment or removal, Daybook will revoke the former Sales Partner’s access to the Customer’s account information and require the former Sales Partner to return or delete Customer Personal Information that is no longer required for an authorized purpose, subject to applicable legal retention requirements.
7. Information about minors
7.1 Service. The Service is supplied to businesses and is not directed or marketed to minors for Daybook’s own purposes. Daybook does not independently solicit personal information from minors for its own purposes. A Customer may use the Platform to collect or process personal information about minors or permit minors to interact with non-AI Platform features, in which case Daybook processes that information on the Customer’s behalf.
7.2 Customer Obligations. Where the Customer’s use of the Platform involves the storage or processing of personal information about minors (for example, in connection with the operation of a day camp, daycare, or similar service), the Customer is solely responsible for:
(a) obtaining all required parental or guardian consents before entering a minor’s personal information into the Platform;
(b) providing appropriate privacy notices to parents and guardians describing the collection, use, and disclosure of their child’s personal information;
(c) ensuring that the collection of minors’ personal information is limited to what is necessary for the identified purpose;
(d) responding to parental or guardian requests for access to, correction of, or deletion of their child’s personal information; and
(e) complying with all applicable laws governing the collection, use, and disclosure of children’s personal information.
7.3 Daybook’s Role. Daybook will process a minor’s personal information only as directed by the Customer and only to the extent necessary to provide the Service.
8. AI features
8.1 Description. The Platform includes AI Features that may use artificial intelligence and automated processing services provided by Google and other service providers to analyse, extract, classify, transcribe, generate, summarize or otherwise process Customer Content. Depending on the functionality used, AI Features may read and analyse emails, text messages and attachments; draft replies and other communications; interpret message threads and assist with or perform appointment scheduling; extract and analyse information from receipts, supplier bills, bank statements, payroll reports, void cheques and other documents; transcribe voice notes; analyse photographs and images; generate website copy and other written content; generate summaries and reports; and respond to questions or requests from Users, Customer personnel, clients and other end users. Some AI Features are initiated by a User, while others may operate automatically or in the background as part of workflows enabled or configured by the Customer.
8.2 Data Transmission. In providing AI Features, relevant Customer Content may be transmitted to and processed by Google or other AI service providers. Such processing may occur outside Canada, including in the United States, and the applicable processing location may not be selectable by Daybook. The Customer acknowledges and consents to such processing and transmission.
8.3 AI Outputs. AI Outputs are generated probabilistically and may be incomplete, inaccurate, outdated or unsuitable for the Customer’s intended purpose. The Customer must independently review AI Outputs before relying on them. Where the Customer enables an AI Feature to perform or initiate an AI Action automatically, the Customer is responsible for configuring, monitoring and reviewing that functionality and for correcting any resulting error. AI Features are not a substitute for professional judgment and must not be used to make decisions producing legal or similarly significant effects on individuals without appropriate human review.
8.4 No Warranty. Daybook does not warrant the accuracy, completeness, or fitness for purpose of any AI Output. AI Features are provided on an “as is” basis.
8.5 Consequential Decisions. AI Features must not be used to make consequential decisions about individuals, including, without limitation, decisions about a minor’s care, health, or safety without independent human review of the underlying source record.
8.6 Customer Compliance. The Customer is responsible for ensuring that its use of AI Features complies with all applicable law, including any obligation to notify individuals that their personal information may be processed by automated means or AI systems.
8.7 AI Model Training. Daybook will configure and use third-party AI services under commercial terms intended to prohibit Customer Content submitted through the Platform from being used to train or improve general-purpose artificial intelligence models. Daybook will not knowingly submit Customer Content to a free or unpaid AI-service tier that permits the provider to use that Customer Content for general-purpose model training or improvement.
8.8 Third-Party Services and Integrations. The Platform may permit the Customer or its Users to connect Third-Party Services, including Google Workspace, Google accounts, Microsoft 365, email accounts, mailboxes, calendars, payment accounts and other business applications. Depending on the integration enabled by the Customer, Daybook may access, retrieve, read, index, analyse, display, store, create, modify, send or delete emails, attachments, calendar events and other information available through the connected account, but only to the extent reasonably necessary to provide the functionality selected, enabled or requested by the Customer or its Users.
By enabling a Third-Party Service, the Customer authorizes Daybook to access the connected account and to transmit Customer Content and other information to, and receive information from, that Third-Party Service to the extent reasonably necessary to provide the requested integration or functionality. The Customer represents that it has the authority and all required consents to connect the account and permit that processing.
The Customer’s use of a Third-Party Service is subject to that provider’s terms and privacy practices. Daybook does not control and is not responsible for the availability, operation, security or data-handling practices of a Third-Party Service, or for the use, disclosure or retention of Customer Content by that Third-Party Service after Customer Content has been transmitted to it at the Customer’s direction, except to the extent required by applicable law.
8.9 Connected-Account Permissions and Disconnection. The Customer is responsible for managing the permissions granted to each connected account and for disconnecting an account when access is no longer required or authorized. Disconnecting a Third-Party Service does not necessarily delete information previously transmitted to, received from or stored by that Third-Party Service or the Platform.
8.10 Age Restrictions for AI Features. AI Features are not intended for direct access or use by persons under eighteen (18) years of age. The Customer must not enable or knowingly permit a person under eighteen (18) years of age to access or interact directly with an AI Feature, including through a client, parent, guardian or other portal. Daybook may use age-screening, account controls or other technical measures to restrict access to AI Features. The Customer must accurately configure and administer any age-related access controls made available through the Platform.
8.11 Google API Services User Data. Daybook’s use and transfer to any other application of information received from Google APIs will comply with the Google API Services User Data Policy, including its Limited Use requirements. Daybook will use information received from Google APIs only to provide or improve user-facing functionality requested or enabled by the Customer or its Users, maintain and secure the applicable integration, comply with applicable law, or as otherwise permitted by the Google API Services User Data Policy.
9. Communications
9.1 Customer Messages. The Platform enables the Customer to send electronic messages, including email, SMS, and similar communications, to the Customer’s own end users (“Customer Messages”). The Customer is the sender of all Customer Messages for the purposes of CASL and all other applicable anti-spam and electronic communication laws.
9.2 Customer Obligations. The Customer is solely responsible for:
(a) determining whether each Customer Message constitutes a commercial electronic message (“CEM”) under CASL;
(b) obtaining and retaining evidence of all legally required consents before sending any CEM;
(c) including accurate sender identification and contact information in each Customer Message;
(d) providing a functional, no-cost unsubscribe mechanism in each CEM;
(e) honouring all unsubscribe requests within ten (10) business days of receipt;
(f) maintaining suppression lists and not overriding suppressions without a documented legal basis; and
(g) ensuring that the content of each Customer Message is accurate and not misleading.
9.3 Daybook’s Role. Daybook will provide technical functionality within the Platform to support the Customer’s compliance with CASL, including unsubscribe mechanisms. Daybook does not review or approve the content of Customer Messages and is not responsible for the Customer’s compliance with CASL.
9.4 Enforcement Rights. Daybook reserves the right to suspend the Customer’s access to the Platform’s messaging features, impose sending limits, require the Customer to provide evidence of consent, or terminate this Agreement if the Customer repeatedly violates CASL or any other applicable anti-spam law.
9.5 No Implied Consent. Acceptance of this Agreement does not constitute consent by the Customer or its Users to receive marketing or promotional communications from Daybook. Any such consent must be obtained separately and in accordance with CASL.
9.6 Message Tracking. Certain Customer Messages, including quotes and invoices, may contain a tracking pixel or similar technology that records whether and when the message is opened and may collect associated technical information, such as an IP address, browser type or device information. The Platform may make that information available to the Customer that sent the Customer Message.
The Customer is responsible for determining whether its use of message-tracking functionality is lawful, providing all required notices and obtaining any required consents. The Customer must not use message-tracking information for an unlawful, misleading or discriminatory purpose. Further information concerning Daybook’s processing of message-tracking information is set out in the Privacy Policy.
10. Acceptable use
10.1 Prohibited Uses. The Customer must not, and must ensure that its Users do not:
(a) reverse engineer, decompile, disassemble, or otherwise attempt to derive the source code of the Platform;
(b) sublicense, resell, rent, lease, or otherwise make the Platform available to any third party except as expressly permitted by this Agreement;
(c) use automated means to access or extract data from the Platform;
(d) upload, transmit, or store any malicious code, viruses, or other harmful software;
(e) attempt to circumvent, disable, or interfere with any security controls, authentication mechanisms, or access restrictions of the Platform;
(f) use the Platform for any unlawful purpose or in violation of any applicable law or regulation;
(g) upload or transmit any content that infringes the intellectual property rights, privacy rights, or rights of any third party;
(h) use the Platform to send unsolicited commercial electronic messages; or
(i) use the Platform to harvest, collect, or compile contact information about individuals without their consent.
10.2 Suspension. Daybook may suspend the Customer’s access to the Platform immediately and without prior notice upon discovering a material breach of this Section 10. Daybook will notify the Customer of the suspension as soon as reasonably practicable.
11. Confidentiality
11.1 Obligations. Each party (as “Receiving Party”) must keep the other party’s Confidential Information strictly confidential and must not disclose it to any third party without the prior written consent of the disclosing party, except as permitted by this Section 11. Each party must use the other’s Confidential Information only for the purposes of performing its obligations or exercising its rights under this Agreement.
11.2 Definition. “Confidential Information” means all non-public information disclosed by one party to the other in connection with this Agreement that is designated as confidential or that reasonably should be understood to be confidential given the nature of the information and the circumstances of disclosure. Customer Content is the Customer’s Confidential Information. Daybook’s pricing, technology, and business plans are Daybook’s Confidential Information.
11.3 Exclusions. Confidential Information does not include information that: (a) is or becomes publicly available through no fault of the Receiving Party; (b) was known to the Receiving Party before disclosure without restriction; (c) is independently developed by the Receiving Party without use of the disclosing party’s Confidential Information; or (d) is lawfully received from a third party without restriction on disclosure.
11.4 Permitted Disclosures. A Receiving Party may disclose Confidential Information to its employees, contractors, Sales Partners, service providers and professional advisors who have a need to know the information for purposes connected with this Agreement and who are bound by confidentiality, privacy and security obligations at least as protective as those applicable to the Receiving Party under this Agreement. A Receiving Party may also disclose Confidential Information to the extent required by applicable law or court order, provided that it gives the disclosing party prompt prior written notice (to the extent permitted by law) and cooperates with the disclosing party in seeking a protective order.
11.5 Survival. Confidentiality obligations under this Section 11 survive termination or expiry of this Agreement for a period of three (3) years, except that obligations with respect to trade secrets continue indefinitely.
11.6 Responsibility for Representatives. Each party is responsible for ensuring that its employees, contractors and service providers comply with the confidentiality obligations applicable to them. Daybook will ensure that its Sales Partners comply with the confidentiality, privacy, security and use restrictions applicable to them under this Agreement. Daybook remains responsible for a Sales Partner’s authorized use or disclosure of the Customer’s Confidential Information to the extent provided by this Agreement, Schedule B and applicable law.
12. Intellectual property
12.1 Daybook’s IP. Daybook retains all intellectual property rights in and to the Platform, the Documentation, and any improvements, enhancements, derivative works, or other developments made to the Platform or Documentation, whether or not made in response to Customer feedback. No rights in the Platform or Documentation are granted to the Customer except as expressly set out in this Agreement.
12.2 Customer’s IP. The Customer retains all intellectual property rights in and to Customer Content. No rights in Customer Content are granted to Daybook except as expressly set out in this Agreement.
12.3 Feedback. If the Customer provides Daybook with any suggestions, ideas, enhancement requests, or other feedback relating to the Platform (“Feedback”), the Customer grants Daybook a perpetual, irrevocable, royalty-free, worldwide licence to use, incorporate, and commercialise such Feedback without restriction or compensation to the Customer.
12.4 No Implied Licences. Except as expressly stated in this Agreement, no licence or right is granted by implication, estoppel, or otherwise.
13. Website services
13.1 Website Services. Where specified in an Order Form or otherwise agreed by Daybook and the Customer, Daybook may design, generate, host, maintain or otherwise provide Website Services for the Customer.
13.2 Customer Content and Approval. The Customer is responsible for reviewing and approving all text, images, pricing, representations, policies and other content displayed on its website before publication and on an ongoing basis. The Customer represents that it has all rights and permissions required to use content supplied by or on behalf of the Customer. Daybook may treat the Customer’s instruction to publish or make the website publicly available as confirmation that the Customer has reviewed and approved the website content.
13.3 AI-Generated Content. Daybook may use AI Features to prepare initial drafts of website copy, descriptions, images or other content. AI-generated content may be inaccurate, incomplete or unsuitable and must be independently reviewed and approved by the Customer before publication. The Customer remains responsible for the accuracy and legality of content published on its website.
13.4 Intellectual Property. The Customer retains ownership of Customer Content supplied for use on the website. Daybook retains ownership of the Platform, its software, templates, components, tools, processes and other pre-existing or generally applicable technology used to create, operate or host the website. Except as expressly agreed in writing, the provision of Website Services does not transfer ownership of the Platform or Daybook’s underlying technology to the Customer.
13.5 Domains. The ownership, registration and administration of any domain name used for a Customer website will be specified in the applicable Order Form. Where reasonably practicable, a domain acquired for the Customer will be registered in the Customer’s legal name, with the Customer identified as the registrant and Daybook authorized to act as the technical or administrative contact. Where Daybook registers or administers a domain on the Customer’s behalf, the Customer is responsible for providing accurate registration information and paying all applicable registration, renewal and transfer fees. Upon termination and payment of all outstanding amounts, Daybook will reasonably cooperate in transferring administrative control of any Customer-owned domain, subject to applicable registrar requirements.
13.6 Hosting and Suspension. Daybook may suspend or remove a Customer website where reasonably necessary to address non-payment, unlawful or infringing content, a security risk, abuse of the Service or a material breach of this Agreement. Where reasonably practicable, Daybook will provide notice and an opportunity to remedy the issue before removing a website, except where immediate action is reasonably necessary.
13.7 Termination and Handover. Upon termination of Website Services and payment of all amounts owing, Daybook will:
(a) reasonably cooperate in transferring any Customer-owned domain administered by Daybook, subject to applicable registrar requirements;
(b) make Customer Content used on the website and reasonably capable of export available to the Customer for thirty (30) days; and
(c) provide reasonable information required to facilitate migration to another service provider.
Unless expressly stated in an Order Form, an export does not include Daybook’s proprietary Platform software, source code, templates, infrastructure, development tools or other technology. The availability and format of an export depend on the technical capabilities of the Platform. Migration, transfer and technical assistance beyond the standard export process may be charged at Daybook’s then-current professional-service rates.
Daybook may discontinue hosting after the effective date of termination. The Customer is responsible for arranging replacement hosting and completing any migration before that date or within any additional transition period agreed in writing.
13.8 Website Compliance. The Customer is responsible for ensuring that its website and business activities comply with all laws and regulatory requirements applicable to the Customer, including requirements concerning privacy notices, consent, electronic communications, accessibility, advertising, consumer protection, pricing, professional services and mandatory business disclosures. Daybook does not warrant that any template, AI-generated content or draft policy supplied through the Website Services satisfies the Customer’s particular legal or regulatory obligations.
13.9 Third-Party Services and Fees. Domain registration, payment processing, email, mapping, plugins, integrations and other third-party products or services used with a Customer website may be subject to separate fees, terms and privacy practices. Unless the applicable Order Form states otherwise, the Customer is responsible for those fees and for maintaining all required third-party accounts, subscriptions and licences.
13.10 Website Availability. Daybook will use commercially reasonable efforts to make hosted Customer websites available, but does not guarantee uninterrupted or error-free availability. Website availability may be affected by maintenance, security incidents, third-party infrastructure failures, internet disruptions and events beyond Daybook’s reasonable control.
14. Warranties and disclaimers
14.1 Daybook’s Warranties. Daybook warrants that:
(a) the Platform will perform materially in accordance with the Documentation during the Subscription Term, subject to scheduled maintenance, failures or interruptions of Subprocessor services or Third-Party Services, internet or telecommunications failures, and other circumstances beyond Daybook’s reasonable control;
(b) Daybook will implement and maintain reasonable administrative, technical, and physical security safeguards to protect Customer Personal Information; and
(c) Daybook has the right to grant the licences set out in this Agreement and that, to Daybook’s knowledge, the Platform does not infringe any Canadian intellectual property right of a third party.
14.2 Disclaimer. EXCEPT AS EXPRESSLY SET OUT IN SECTION 14.1, THE PLATFORM AND ALL AI FEATURES ARE PROVIDED “AS IS” AND “AS AVAILABLE”. DAYBOOK DISCLAIMS ALL OTHER WARRANTIES, CONDITIONS, AND REPRESENTATIONS, EXPRESS OR IMPLIED, INCLUDING ANY IMPLIED WARRANTIES OR CONDITIONS OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, SATISFACTORY QUALITY, TITLE, AND NON-INFRINGEMENT. DAYBOOK DOES NOT WARRANT THAT THE PLATFORM WILL BE UNINTERRUPTED, ERROR-FREE, OR FREE FROM SECURITY VULNERABILITIES, OR THAT ANY DEFECTS WILL BE CORRECTED.
14.3 Customer’s Warranties. The Customer warrants that: (a) it has the authority to enter into this Agreement; (b) its use of the Platform will comply with all applicable laws; and (c) it has obtained all consents required to upload Customer Content to the Platform.
14.4 Third-Party Infrastructure. The Platform depends on hosting, cloud infrastructure, communications, artificial intelligence, payment processing and other services supplied by Subprocessors and other third-party providers. Daybook will use commercially reasonable efforts to select, configure and manage such providers in a manner consistent with Daybook’s obligations under this Agreement. Daybook does not warrant that any such third-party service will be uninterrupted or error-free or will continue to provide particular functionality. Daybook will not be responsible for a failure, interruption, modification or discontinuation of a third-party service that is beyond Daybook’s reasonable control, except to the extent that the resulting liability arises from Daybook’s breach of this Agreement, including its obligations concerning the selection, configuration or management of Subprocessors, or to the extent otherwise required by applicable law.
15. Limitation of liability
15.1 Exclusion of Consequential Loss. TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, NEITHER PARTY WILL BE LIABLE TO THE OTHER FOR ANY INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, PUNITIVE, OR CONSEQUENTIAL DAMAGES, OR FOR ANY LOSS OF PROFITS, REVENUE, DATA, GOODWILL, BUSINESS OPPORTUNITY, OR ANTICIPATED SAVINGS, ARISING OUT OF OR IN CONNECTION WITH THIS AGREEMENT, EVEN IF THAT PARTY HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH LOSS.
15.2 Aggregate Cap. TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, DAYBOOK’S TOTAL AGGREGATE LIABILITY TO THE CUSTOMER FOR ALL CLAIMS ARISING OUT OF OR IN CONNECTION WITH THIS AGREEMENT WILL NOT EXCEED THE TOTAL FEES PAID OR PAYABLE BY THE CUSTOMER IN THE TWELVE (12) MONTHS IMMEDIATELY PRECEDING THE EVENT GIVING RISE TO THE CLAIM.
15.3 Data Processing Cap. Subject to Section 15.4, Daybook’s total aggregate liability arising from or relating to unauthorized access to, use of, loss of, alteration of or disclosure of Customer Content or Customer Personal Information, or from a breach of Daybook’s data-processing, privacy, confidentiality or security obligations relating to Customer Content or Customer Personal Information, will not exceed two times (2x) the total Fees paid or payable by the Customer in the twelve (12) months immediately preceding the first event giving rise to the applicable claim.
The cap in this Section applies regardless of whether the applicable claim is characterized as a breach of privacy, security, confidentiality, contract, warranty or statutory duty, or as negligence or otherwise, and regardless of whether the same act or omission constitutes a breach of both Section 6 and Section 11.
15.4 Exclusions from Limitations. The limitations and exclusions in Sections 15.1, 15.2, and 15.3 do not apply to:
(a) Fees and other amounts owed by the Customer;
(b) fraud or fraudulent misrepresentation by a party;
(c) a party’s wilful misconduct or gross negligence;
(d) death or personal injury caused by a party’s negligence; or
(e) liability that cannot lawfully be limited or excluded.
Except for claims described in paragraphs (b) to (e), a claim arising from unauthorized access to, use of, loss of or disclosure of Customer Content or Customer Personal Information is subject to the special aggregate cap in Section 15.3, notwithstanding that the event may also constitute a breach of Section 11.
15.5 Acknowledgement. The parties acknowledge that the limitations of liability in this Section 15 reflect a reasonable allocation of risk and form an essential basis of the bargain between the parties.
15.6 Application to Indemnification Obligations. Except as expressly stated in this Section:
(a) the Customer’s indemnification obligations under Section 16.1 arising from the Customer’s infringement or misappropriation of a third party’s intellectual property rights, violation of CASL, or unlawful collection, use or disclosure of personal information are not subject to the aggregate liability cap in Section 15.2 or the data and privacy cap in Section 15.3;
(b) the Customer’s other indemnification obligations are subject to the aggregate liability cap in Section 15.2, except to the extent Section 15.4 applies; and
(c) Daybook’s indemnification obligations under Section 16.2 are subject to the aggregate liability cap in Section 15.2, except to the extent Section 15.4 applies.
16. Indemnification
16.1 Customer Indemnity. The Customer will defend, indemnify, and hold harmless Daybook and its officers, directors, employees, and agents from and against any third-party claims, actions, proceedings, losses, damages, costs, and expenses (including reasonable legal fees) arising out of or in connection with:
(a) Customer Content, including any claim that Customer Content infringes a third party's intellectual property rights or violates a third party's privacy rights;
(b) the Customer’s breach of this Agreement;
(c) the Customer’s violation of any applicable law, including CASL and PIPEDA; or
(d) the Customer’s use of this Platform in a manner not permitted by this Agreement.
16.2 Daybook Indemnity. Daybook will defend, indemnify, and hold harmless the Customer and its officers, directors, employees, and agents from and against any third-party claims, actions, proceedings, losses, damages, costs, and expenses (including reasonable legal fees) arising out of or in connection with a claim that the Platform, as provided by Daybook and used in accordance with this Agreement, infringes a Canadian intellectual property right of a third party. This indemnity does not apply to the extent that the alleged infringement arises from: (a) Customer Content; (b) modifications to the Platform made by or on behalf of the Customer; or (c) the Customer’s use of the Platform in combination with products or services not provided by Daybook.
16.3 Indemnification Procedure. The party seeking indemnification (“Indemnified Party”) must: (a) give the indemnifying party prompt written notice of the claim; (b) grant the indemnifying party sole control of the defence and settlement of the claim (provided that the indemnifying party may not settle any claim that imposes liability or obligations on the Indemnified Party without the Indemnified Party’s prior written consent); and (c) provide the indemnifying party with all reasonable assistance, at the indemnifying party’s expense.
17. Term and termination
17.1 Term and Renewal. This Agreement begins on the date the Customer accepts it and continues for the Subscription Term specified in the applicable Order Form unless earlier terminated in accordance with this Agreement.
(a) A monthly subscription automatically renews for successive monthly billing periods unless cancelled. The Customer may cancel a monthly subscription at any time, and the cancellation will take effect at the end of the billing period for which Fees have been paid.
(b) An annual subscription continues for the annual Subscription Term specified in the Order Form and renews only as specified in the Order Form. Unless the Order Form states otherwise, prepaid annual Fees are non-refundable if the Customer cancels during an annual Subscription Term.
(c) A seasonal subscription continues for the season or other period specified in the Order Form. Its renewal, cancellation and payment terms are those set out in the Order Form.
(d) Cancellation does not relieve the Customer of its obligation to pay Fees accrued or committed before the effective date of cancellation.
17.2 Termination for Breach. Either party may terminate this Agreement on thirty (30) days’ written notice to the other party if the other party commits a material breach of this Agreement and fails to cure that breach within the thirty (30) day notice period.
17.3 Immediate Termination by Daybook. Daybook may terminate this Agreement immediately on written notice to the Customer if:
(a) the Customer fails to pay any Fees within ten (10) days of receiving written notice of non-payment from Daybook;
(b) the Customer becomes insolvent, makes an assignment for the benefit of creditors, or is subject to bankruptcy, receivership, or similar proceedings; or
(c) the Customer commits a material breach of Section 9 or Section 10, including conduct that creates a material security, legal, reputational or operational risk to Daybook, the Platform or another person.
17.4 Effect of Termination. Upon expiry or termination of this Agreement for any reason:
(a) except for any limited access expressly provided under Sections 3.8, 6.8 or 13.7 for export or transition purposes, all licences granted to the Customer terminate;
(b) the Customer must cease using the Platform other than through any read-only, export or transition functionality expressly made available by Daybook;
(c) all accrued Fees become immediately due and payable; and
(d) the data export and deletion provisions of Section 6.8 apply.
17.5 Survival. Any provision that by its nature is intended to survive expiry or termination will survive, including Sections 3.6 and 3.7 (Fees and Taxes), 5 (Customer Content and Data Ownership), 6.7 and 6.8 (Breach Records and Data Return and Deletion), 6.10 to 6.13 (Sales Partners, Support Requests, Access Controls and Reassignment), to the extent relating to retained information, confidentiality, access revocation, return or deletion, 8.3 to 8.11 (AI Outputs, Disclaimers, Third-Party Services, Age Restrictions and Google API Services User Data), 11 (Confidentiality), 12 (Intellectual Property), 13.2 to 13.10 (Website Services), 14.2 (Disclaimer), 15 (Limitation of Liability), 16 (Indemnification), 17.4 (Effect of Termination), 19 (Governing Law and Dispute Resolution) and 20 (General).
18. Changes to the service and agreement
18.1 Platform Updates. Daybook may update, modify, or enhance the Platform and Documentation from time to time. Daybook will use reasonable efforts to provide the Customer with at least thirty (30) days’ prior written notice of any material reduction in the functionality of the Platform. Where a change is required by applicable law, security requirements, a Subprocessor or Third-Party Service, or another technical dependency outside Daybook’s reasonable control and thirty (30) days’ prior notice is not reasonably practicable, Daybook may implement the change on shorter notice and will provide the Customer with as much advance notice as is reasonably practicable.
18.2 Agreement Amendments. Daybook may amend this Agreement on not less than thirty (30) days’ written notice to the Customer. The Customer’s continued use of the Platform after the effective date of the amendment constitutes the Customer's acceptance of the amended Agreement. If the Customer does not accept a material amendment, the Customer may terminate the affected Service by giving Daybook written notice before the amendment takes effect. For a prepaid annual or seasonal subscription, Daybook will refund the portion of prepaid Fees attributable to the period after the effective date of termination, unless the amendment is required by applicable law or does not materially diminish the Customer’s rights or materially increase the Customer’s obligations.
18.3 Legally Required Changes. Notwithstanding Sections 18.1 and 18.2, changes required by applicable law may take effect immediately upon notice to the Customer.
19. Governing law and dispute resolution
19.1 Governing Law. This Agreement is governed by and construed in accordance with the laws of the Province of Prince Edward Island and the federal laws of Canada applicable therein, without regard to conflict of law principles.
19.2 Jurisdiction. The parties irrevocably submit to the exclusive jurisdiction of the courts of the Province of Prince Edward Island for the resolution of any dispute arising out of or in connection with this Agreement.
20. General
20.1 Entire Agreement. This Agreement, together with all Order Forms and Schedules, constitutes the entire agreement between the parties with respect to its subject matter and supersedes all prior and contemporaneous representations, warranties, agreements, and understandings, whether written or oral, relating to the subject matter.
20.2 Severability. If any provision of this Agreement is held to be invalid, illegal, or unenforceable, the remaining provisions of this Agreement will continue in full force and effect.
20.3 Waiver. A waiver of any right or remedy under this Agreement is only effective if given in writing. No waiver of a breach constitutes a waiver of any subsequent breach.
20.4 Notices. All notices under this Agreement shall be in writing and delivered by: (a) email with read receipt or confirmation of delivery; (b) courier; or (c) registered mail, to the addresses set out in the applicable Order Form, or such other address as a Party designates in writing. Notices are effective on the date of confirmed delivery.
20.5 Assignment. The Customer may not assign or transfer this Agreement or any of its rights or obligations under it without Daybook’s prior written consent, which may be withheld in Daybook’s sole discretion. Any purported assignment without such consent is void. Daybook may assign this Agreement to any successor entity that acquires control of Daybook.
20.6 Force Majeure. Neither party will be liable for any delay or failure to perform its obligations under this Agreement (other than payment obligations) to the extent that such delay is caused by circumstances beyond that party’s reasonable control, including acts of God, natural disasters, pandemic, war, terrorism, labour disputes, governmental actions, or failures of third-party infrastructure providers. The affected party must notify the other party promptly and use reasonable efforts to resume performance.
20.7 Relationship of Parties. The parties are independent contractors. Nothing in this Agreement creates a partnership, joint venture, agency, franchise, or employment relationship between the parties.
20.8 Counterparts and Electronic Signatures. This Agreement may be executed in counterparts, each of which will be deemed to be an original and all of which together will constitute one and the same instrument. Electronic signatures and clickwrap acceptances are valid and binding.
20.9 Sales Partners. A Sales Partner is an independent contractor of Daybook and is not the Customer’s agent, employee, partner or representative.
Schedule a — order form
The Order Form is the sign-up form, checkout or order document that sets out the Customer’s subscription plan, Fees, Subscription Term and other commercial terms. It is not reproduced here.
Schedule b
Data processing addendum (“dpa”)
This Data Processing Addendum (“DPA”) forms part of the Daybook Technologies Inc. Business-To-Business Software as a Service (“B2B SAAS”) Subscription Agreement (Version 1.0) (the “Agreement”) and applies to the processing of Customer Personal Information by Daybook on behalf of the Customer.
1. Roles of the Parties
1.1 The Customer is the organization that determines the purposes and means of collecting and using Customer Personal Information (“Controller” for the purposes of this DPA).
1.2 Daybook is a service provider that processes Customer Personal Information on the Customer’s behalf and in accordance with the Customer's documented instructions (the “Processor” or “Service Provider” for the purposes of this DPA).
2. Scope and Nature of Processing
2.1 Daybook processes Customer Personal Information solely to provide, maintain, secure and support the Service as described in the Agreement. Depending on the Customer’s use of the Service, the categories of personal information processed may include contact information; appointments, invoices, quotes, job notes, receipts, supplier bills and other business records; emails, email-account and mailbox data, calendar events, meeting details, SMS messages, attachments, voice notes, photographs and other communications or files; employee and contractor information, including dates of birth, home addresses, Social Insurance Numbers, banking or direct-deposit information, compensation and pay rates, TD1 forms and payroll information; information relating to children, including names, dates of birth, health and care information, emergency contacts and authorized pickup information; information submitted by clients and other end users through websites, forms, portals and appointment booking tools; Customer Account Information, including business identity, subscription plan, subscription and payment status, account activity, support and usage information to the extent that such information constitutes Customer Personal Information processed by Daybook on the Customer’s behalf; support requests and any messages, screenshots, documents, attachments or Customer Content included in them; and other personal information contained in Customer Content.
2.2 Sensitive Personal Information. Customer Personal Information may include information of a sensitive nature, including Social Insurance Numbers, banking and direct-deposit information, payroll and compensation information, identity documents, children’s personal information, and health, medical, allergy, care and emergency information. Daybook will apply safeguards appropriate to the sensitivity of the information, the purposes for which it is processed and the reasonably foreseeable risks of unauthorized access, use, disclosure, alteration, loss or destruction.
2.3 Daybook will process Customer Personal Information only in accordance with the Customer’s documented instructions as set out in the Agreement and any applicable Order Form, unless otherwise required by applicable law.
3. Confidentiality of Personnel
3.1 Daybook will ensure that all personnel authorized to process Customer Personal Information are subject to appropriate confidentiality obligations, whether by contract or by operation of law.
4. Security Safeguards
4.1 Daybook will implement and maintain appropriate technical and organizational measures to protect Customer Personal Information against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access, having regard to the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risk to the rights and freedoms of individuals.
4.2 The measures maintained by Daybook may include, as appropriate to the relevant systems and processing activities, access controls, authentication procedures, encryption, logging and monitoring, backup and recovery controls, personnel confidentiality obligations, and security-incident response procedures.
Daybook may modify its security measures from time to time, provided that the modifications do not materially reduce the overall level of protection afforded to Customer Personal Information during the Subscription Term.
5. Subprocessors
5.1 The Customer authorizes Daybook to engage the following Subprocessors, including any Sales Partner acting as a Subprocessor, to process Customer Personal Information in connection with the Service:
| Subprocessor | Purpose | Location |
|---|---|---|
| Google Firebase | Primary database and file storage | Toronto, Ontario, Canada; and Outside Canada, including the United States |
| Google AI Services | AI Features and automated processing | Outside Canada, including the United States |
| Google Cloud Platform / Google Cloud Functions | Server application hosting, server-side processing and related infrastructure | Outside Canada, including the United States |
| Twilio | SMS and communications services | Outside Canada, including the United States |
| Postmark | Incoming email processing | Outside Canada, including the United States |
| Replicate | AI and image/photo analysis | Outside Canada, including the United States |
| Google Maps | Mapping and location-related functionality | Outside Canada, including the United States |
| Google reCAPTCHA | Spam, fraud and automated-abuse prevention | Outside Canada, including the United States |
| Google Workspace and Google APIs | Business productivity and communications services | Outside Canada, including the United States |
| Microsoft Corporation / Microsoft 365 | Connected Microsoft email, mailbox, calendar, productivity and communications services | Outside Canada, including the United States |
| Stripe | Payment processing | Global |
| GitHub | Tracking of support requests (names, email addresses and screenshots are removed before a request is sent) | United States |
| Anthropic | AI-assisted investigation of support requests | United States |
| Apple | Push notifications to Apple devices | Outside Canada, including the United States |
| Meta Platforms | Facebook content embedded in Customer websites, where a Customer adds it | Outside Canada, including the United States |
| Affirm | Pay-over-time payment options, where a Customer offers them | Canada and the United States |
| Klarna | Pay-over-time payment options, where a Customer offers them | Outside Canada, including the United States |
Each Sales Partner that processes Customer Personal Information as a Subprocessor will be identified on Daybook’s current Subprocessor list by legal name, processing purpose and processing location. Daybook will make that list available to the Customer on request and will provide notice of additions or replacements in accordance with Section 5.2.
5.2 Daybook will maintain an up-to-date list of its material Subprocessors and will make that list available to the Customer on request. Daybook will give the Customer reasonable prior notice of any intended material addition or replacement of a Subprocessor. If the Customer objects on reasonable data-protection grounds, the parties will work in good faith to resolve the objection. If the parties cannot resolve the objection and Daybook cannot reasonably provide the Service without the applicable Subprocessor, either party may terminate the affected Service on written notice. Notice of a new Sales Partner is required under this Section where the Sales Partner will process Customer Personal Information as a Subprocessor. No Subprocessor notice is required solely because a Sales Partner receives non-personal corporate or commercial information.
5.3 Before permitting a Subprocessor to process Customer Personal Information, Daybook will enter into a written agreement requiring the Subprocessor to protect Customer Personal Information in a manner appropriate to the nature of the processing and consistent with applicable privacy law. Daybook remains responsible for the Subprocessor’s processing of Customer Personal Information to the extent required by applicable law and this DPA.
5.4 Sales Partners. Where Daybook authorizes a Sales Partner to process Customer Personal Information, Daybook will:
(a) limit the Sales Partner’s access to Customer Personal Information reasonably necessary for the assigned functions;
(b) require the Sales Partner to process Customer Personal Information only on Daybook’s documented instructions;
(c) require the Sales Partner to maintain appropriate confidentiality and security safeguards;
(d) prohibit the Sales Partner from using Customer Personal Information for its own unrelated purposes;
(e) require the Sales Partner to notify Daybook without undue delay of any actual or suspected unauthorized access, use or disclosure;
(f) require the Sales Partner to return or delete Customer Personal Information when access is no longer required, subject to applicable legal retention requirements; and
(g) remain responsible for the Sales Partner’s processing to the extent required by the Agreement, this DPA and applicable law.
6. Assistance with Individual Rights
6.1 Daybook will provide the Customer with reasonable assistance, taking into account the nature of the processing, to enable the Customer to respond to requests from individuals exercising their rights under PIPEDA or other applicable privacy legislation, including requests for access or correction and, where applicable, withdrawal of consent or deletion.
7. Security Incident Notification
7.1 Daybook will notify the Customer without undue delay upon confirming that a breach of security safeguards has occurred involving Customer Personal Information. Such notification will include, to the extent then known: (a) a description of the nature of the breach; (b) the categories and approximate number of individuals and records affected; (c) the likely consequences of the breach; and (d) the measures taken or proposed to address the breach and mitigate its effects. Where the breach originates with a Subprocessor, Daybook will be deemed to have confirmed the breach when Daybook receives notice or otherwise obtains information reasonably sufficient to determine that Customer Personal Information has been affected.
7.2 Daybook will maintain records of breaches of security safeguards in accordance with Section 11.
8. Deletion and Return of Customer Personal Information
8.1 Upon expiry or termination of the Agreement, Daybook will make Customer Personal Information available for export by the Customer for thirty (30) days. After that period, Daybook may delete or cause the deletion of Customer Personal Information from systems under Daybook’s control and may instruct its applicable Subprocessors to delete Customer Personal Information in accordance with their applicable data-processing terms, unless continued retention is required by applicable law. Residual copies maintained in backup systems may be retained and deleted or overwritten in accordance with Daybook’s or the applicable Subprocessor’s ordinary backup-retention cycle, provided that such information remains protected in accordance with this DPA and is not restored to active use except as reasonably necessary for disaster recovery, security or legal purposes.
8.2 The Customer is responsible for exporting and retaining any Customer Personal Information it is required to preserve under applicable law, professional standards or contractual obligations before the export period expires.
8.3 Upon the Customer’s written request, Daybook will confirm in writing that Daybook has completed the deletion actions required of it under this Section and, where applicable, has instructed its Subprocessors to delete Customer Personal Information in accordance with their applicable data-processing terms. Daybook is not required to independently verify deletion from a Subprocessor’s backup, disaster-recovery or other systems beyond the verification or certification made available to Daybook by that Subprocessor.
8.4 Notwithstanding Sections 8.1 to 8.3, Customer Personal Information associated with an expired free trial is governed by Section 3.8 of the Agreement. If the prospective Customer does not begin a paid subscription, Daybook may delete that Customer Personal Information after the applicable export period but is not required by this DPA to complete deletion immediately upon expiry of that period. Any Customer Personal Information retained after the export period remains subject to the confidentiality, security and processing limitations in the Agreement and this DPA.
8.5 Upon termination or reassignment of a Sales Partner, or when a Sales Partner no longer requires access to Customer Personal Information, Daybook will revoke the Sales Partner’s access and require the Sales Partner to return or delete Customer Personal Information in its possession or control, unless continued retention is required by applicable law. Any information retained pursuant to applicable law remains subject to the confidentiality, security and use restrictions in this DPA.
9. Audit Rights
9.1 Daybook will make available to the Customer, on reasonable written request and no more than once per calendar year, information reasonably necessary to demonstrate Daybook’s compliance with this DPA. Such information may be provided in the form of a summary of Daybook's security practices, third-party audit reports, or certifications, at Daybook’s discretion.
9.2 If the Customer requires an on-site audit, the parties will agree in advance on the scope, timing, and cost of such audit. Any audit must be conducted during normal business hours with reasonable prior notice and must not unreasonably disrupt Daybook’s operations.
10. Cross-Border Transfer Safeguards
10.1 Customer Personal Information may be transferred to and processed outside Canada, including in the United States, in connection with server application code, AI Features, communications services, Third-Party Services and other functionality used to provide the Service. The location of processing may depend on the applicable Subprocessor and functionality and may not be selectable by Daybook. The Customer acknowledges and consents to such transfers as described in Section 6.4 of the Agreement and Daybook’s Privacy Policy. The identification of a primary or configured data location for a particular Subprocessor does not constitute a representation that all processing, backups, metadata, support access or ancillary services provided by that Subprocessor occur exclusively in that location.
10.2 Daybook will ensure that any cross-border transfer of Customer Personal Information is subject to appropriate safeguards, which may include contractual protections with Subprocessors, consistent with the requirements of PIPEDA and other applicable law.
11. PIPEDA Breach Record Retention
11.1 Daybook will maintain a record of every breach of security safeguards involving Customer Personal Information for at least twenty-four (24) months after the day on which Daybook determines that the breach has occurred, as required by the Breach of Security Safeguards Regulations made under PIPEDA. Such records will be made available to the Privacy Commissioner of Canada upon request.