Metered Video

Metered Turn Servers

Get Started with Detailed Documentation

Quick Start Guide

Get up and running in minutes

User Auth Guide

Secure private rooms & access tokens

JavaScript SDK

Complete SDK documentation

Rest API Documentation

Easy to use interface with code samples

Best Practices Guide

Tips to save cost and avoid pitfalls

Video Calling Quick Start Application

Open Source Starter sample app

Why Metered? support@metered.ca | +1 (647) 483-3172

Video Calling

1:1 and group video calls

Voice Calling

Audio-only communication

Interactive Live Streaming

Up to 10,000 participants

Real-Time Streaming

Sub-300ms latency

Recording

Cloud & composite recording

Composition

Mix audio/video streams

Embed Video Chat

One-line integration

C++ SDK

Embedded & IoT devices

Metered Global STUN TURN Servers

99.999% uptime with geo-routing across 31+ regions

DocuScout

AI-powered documentation search

Pricing
TURN Servers
Education
Remote Work
Virtual Events
Telemedicine
Sales & E-commerce
Contact Us
Support Try Demo
Sign in Sign up
Metered Video

Products

Video Calling
Voice Calling
Live Streaming
Recording
TURN Servers

Use Cases

Education Remote Work Virtual Events Telemedicine Sales & E-commerce

Resources

Pricing Documentation Support
Sign up Sign in
GDPR Compliant

Data Processing Agreement — Next Path Software Consulting Inc. (Metered)

Last updated: April 17, 2025
EU Regulation 2016/679

On this page

  • 01 Definitions
  • 02 Data Processing
  • 03 Security Measures
  • 04 Data Subject Rights
  • 05 Audit Rights
  • 06 Sub-processors
  • 01 Definitions
  • 02 Data Processing
  • 03 Security Measures
  • 04 Data Subject Rights
  • 05 Audit Rights
  • 06 Sub-processors

This Data Processing Agreement ("Agreement") forms part of the Contract for Services ("Principal Agreement") and complies with Regulation (EU) 2016/679 (General Data Protection Regulation).

The Parties seek to implement a data processing agreement that complies with the requirements of the current legal framework in relation to data processing and with the GDPR on the protection of natural persons with regard to the processing of personal data.

Agreement Between

Data Controller

The Customer

AND

Data Processor

Next Path Software Consulting Inc.

The Customer ("Controller") and Next Path Software Consulting Inc. (the "Data Processor") are together the "Parties".

WHEREAS

(A) The Customer acts as a Data Controller or can act as a Data Processor.

(B) The Customer wishes to subcontract certain Services, which imply the processing of personal data, to the Data Processor.

(C) The Parties seek to implement a data processing agreement that complies with the requirements of the current legal framework in relation to data processing and with the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation).

(D) The Parties wish to lay down their rights and obligations.

IT IS AGREED AS FOLLOWS:

01

Definitions

Unless otherwise defined herein, capitalized terms and expressions used in this Agreement shall have the following meanings:

  • Agreement

    "Agreement" means this Data Processing Agreement and all Schedules.

  • Customer Content

    Any Personal Data Processed by a Contracted Processor on behalf of Customer including video, audio, text messages, Customer Account Data, Usage data and sensitive data.

  • Contracted Processor

    "Contracted Processor" means a Subprocessor.

  • Data Protection Laws

    EU Data Protection Laws and, to the extent applicable, the data protection or privacy laws of Canada.

  • EEA

    "EEA" means the European Economic Area.

  • EU Data Protection Laws

    "EU Data Protection Laws" means EU Directive 95/46/EC, as transposed into domestic legislation of each Member State and as amended, replaced or superseded from time to time, including by the GDPR and laws implementing or supplementing the GDPR.

  • GDPR

    EU General Data Protection Regulation 2016/679.

  • Data Transfer

    "Data Transfer" means: (a) a transfer of Customer Personal Data from the Customer to a Contracted Processor; or (b) an onward transfer of Customer Personal Data from a Contracted Processor to a Subcontracted Processor, or between two establishments of a Contracted Processor, in each case, where such transfer would be prohibited by Data Protection Laws.

  • Services

    "Services" means the Online Group Chat and other services the Customer provides.

  • Subprocessor

    Any person appointed by or on behalf of Processor to process Personal Data on behalf of the Customer in connection with the Agreement.

The terms "Commission", "Controller", "Data Subject", "Member State", "Personal Data", "Personal Data Breach", "Processing" and "Supervisory Authority" shall have the same meaning as in the GDPR, and their cognate terms shall be construed accordingly.

02

Data Processing

The data processor shall only store, copy or use Customer Data (including email addresses, telephone numbers, names of Users, IP address, geo-location data, log-in information, etc.) to the extent necessary to perform its obligations under the Agreement and/or for maintenance.

1.3 If the Customer processes personal data, it will only process general personal data. In no circumstance will the data processor accept any responsibility or liability for the processing of sensitive personal data.

The data processor does not have any control over the purposes and means of the processing of personal data. Nothing in the Agreement is intended to transfer control over personal data to the data processor in any way.

03

Security Measures

The data processor shall take appropriate technical and organizational measures to ensure an appropriate level of security on the data processor Services to protect personal data against destruction, loss, alteration, unauthorized disclosure or access.

In determining the measures to be taken, the data processor shall take account of implementation costs as well as of the nature, scope, context and purposes of the processing operation concerned and the various risks, in terms of probability and severity, for the rights and freedoms of individuals.

1.8 The data processor shall inform the Customer immediately, but in any case within 48 hours, as soon as it finds that there has been any breach with respect to the personal data. This information must enable the Customer to fulfil its obligations under Articles 33 and 34 of the GDPR.

1.9 The data processor is under no obligation to perform assessments as described under Article 35 and/or 36 of the GDPR.

1.11 The data processor agrees to maintain confidentiality over personal data it processes and ensures that persons authorized to process the Personal Data undertake to maintain confidentiality.

04

Data Subject Rights

At the first request of the Customer, the data processor may cooperate with the parties concerned to exercise their rights with regard to the processing of Personal Data in accordance with Articles 12 to 23 of the GDPR, including:

  • Right to Information & Access

    Data subjects may request information about their data and access to it.

  • Right to Erasure ("Right to be Forgotten")

    Data subjects may request deletion of their personal data.

  • Right to Rectification & Portability

    Data subjects may request correction of inaccurate data and transfer to another controller.

  • Right to Object

    Data subjects may object to processing and automated decision-making, including profiling.

This cooperation will in principle be assessed as Additional Services.

1.12 Upon termination of the Agreement, the data processor shall, at request of the Customer, delete all personally identifiable data.

1.13 The customer can ask the data processor to delete personally identifiable information.

1.14 The Customer warrants that the data processing will be carried out in accordance with the law. This means in any case that the Customer warrants that it is entitled to collect data or have data collected and that it is entitled to process these data and have these collected.

1.15 The Customer shall indemnify the data processor for any loss or damage of personal data and costs resulting from any claims by third parties, expressly including the data subjects and supervisory authorities, relating to or arising from any unlawful processing operation and/or any other violation of the GDPR or the Agreement that can be attributed to the Customer.

05

Audit Rights

Metered shall make available to the Customer the information necessary to demonstrate compliance with its obligations under this Agreement and Article 28 of the GDPR, including its current security documentation and its responses to reasonable security questionnaires.

Where the Customer can demonstrate that the information made available under the preceding paragraph is insufficient to demonstrate such compliance, the Customer may, on at least thirty (30) days' prior written notice, engage an independent third-party auditor to audit Metered's processing of the Customer's Personal Data, subject to the following:

(a) the auditor shall be an independent third party approved by Metered in advance, such approval not to be unreasonably withheld, and shall not be a competitor of Metered;

(b) before any audit begins, the Customer and the auditor shall each execute confidentiality and non-competition undertakings in favour of Metered, in a form provided or approved by Metered;

(c) audits shall take place no more than once in any twelve (12) month period, except where required by a supervisory authority with jurisdiction over the Customer or following a confirmed Personal Data Breach affecting the Customer's Personal Data;

(d) the audit shall be limited in scope to Metered's processing of the Customer's Personal Data, and shall not extend to the data of other customers, to Metered's other systems, or to information belonging to third parties;

(e) audits shall be conducted during normal business hours and in a manner that does not disrupt Metered's operations or compromise the security or confidentiality of any other customer;

(f) the Customer shall bear all costs of the audit, including Metered's reasonable costs of participation;

(g) Metered shall cooperate with the audit and make available the information within its control that is reasonably relevant to the agreed scope of the audit; and

(h) the audit report and all findings are Confidential Information of Metered and shall not be disclosed to any third party.

Where Metered holds a current third-party audit report or certification covering the relevant processing, provision of that report satisfies the Customer's audit rights for the period it covers.

06

Sub-processors

The data processor shall be entitled to make use of sub-processors. In case the data processor engages a new sub-processor, it will notify the Customer. The Customer may object against this engagement in writing. If the data processor persists in engaging a sub-processor after objection, the Customer may terminate the agreement with immediate effect.

Current Sub-processors

Sub-processor Purpose Location
AWS Cloud storage and computing services US, Canada
Google Cloud Cloud hosting and infrastructure Middle East
Hetzner Cloud hosting and infrastructure Germany, Finland, US
Digital Ocean Cloud hosting and infrastructure Global
Akamai / Linode Cloud hosting and infrastructure Global
Helpscout Customer support and helpdesk United States
Microsoft Azure Cloud hosting, edge and traffic management Global
Vultr Cloud hosting and infrastructure Global
ClouDNS DNS resolution services Global
Postmark Transactional email delivery United States
Stripe Payment processing services Global

1.16 Relay processing takes place in the regions from which the Customer's traffic is served. The Customer may restrict the regions from which relay capacity is provided, using the setting available in the Metered dashboard; where the Customer has done so, relay processing is confined to the selected regions. Where the Customer has not configured a restriction, relay processing may take place in regions outside the European Economic Area that are not the subject of an adequacy decision.

Personal data processed by relay infrastructure is limited to connection metadata, including IP addresses. Media relayed through the Service is encrypted end to end between the Customer's endpoints and is not accessible to the data processor.

Customers subject to the GDPR who require processing to remain within the European Economic Area should configure the regional restriction accordingly.

1.17 The Customer consents to Metered having its primary processing facilities located in Canada.

Questions about GDPR compliance?

Our team can help you understand how we protect your data.

Contact Compliance Team View Privacy Policy
Metered

Real-time communication infrastructure for developers. Build video, voice, and streaming experiences.

Based in Ontario, Canada

+1 (647) 483-3172

support@metered.ca

Products

  • Video Calling
  • Voice Calling
  • Live Streaming
  • Recording
  • Composition
  • TURN Servers
  • Embed Video Chat
  • C++ SDK

Use Cases

  • Education
  • Remote Work
  • Virtual Events
  • Telemedicine
  • Sales & E-commerce

Developers

  • Quick Start Guide
  • User Auth Guide
  • JavaScript SDK
  • REST API
  • Best Practices
  • Blog
  • Status

Company

  • Why Metered?
  • Pricing
  • Pricing Calculator
  • Contact Us
  • Legal
  • Privacy Policy
  • Terms of Service
  • GDPR

Free Tools

Open Relay Project | tsocket | TURN Server Testing Tool

© 2026 Next Path Software Consulting Inc. All rights reserved.

Made in Canada

By using this website, you agree to our use of cookies.