Legal

    Privacy Policy

    Effective Date: May 15, 2026 • Last Updated: September 20, 2026

    1. Introduction

    Canada Compliance AI Inc. ("we", "our", "us") operates the website canadacomplianceai.ca and provides compliance management software to Canadian businesses.

    This Privacy Policy explains how we collect, use, store, and disclose your personal information in compliance with:

    • Personal Information Protection and Electronic Documents Act (PIPEDA)
    • Quebec Law 25 (An Act to modernize legislative provisions as regards the protection of personal information)
    • Provincial privacy legislation where applicable

    Data Controller:
    Canada Compliance AI Inc.
    c/o Brainfy AI Inc.
    Edmonton, AB, Canada
    Email: privacy@canadacomplianceai.ca

    2. What Personal Information We Collect

    Account Information

    • Full name
    • Email address
    • Company name
    • Phone number (if provided)
    • Billing address

    Payment Information

    Processed by our payment processor Stripe. We do not store full credit card numbers — only last 4 digits and card brand for display purposes.

    Usage Data

    • IP address (Canada location only)
    • Browser type and version
    • Pages visited, time spent, links clicked
    • Compliance scan results and configurations
    • Audit log entries
    • Support tickets and email correspondence

    Cookies and Tracking

    See our Cookie Policy for full details.

    3. How We Use Your Information

    We use personal information only for the purposes for which it was collected:

    • Provide the Service: Account management, compliance scanning, audit logs, reports
    • Billing: Process payments, issue invoices, handle refunds
    • Support: Respond to questions, troubleshoot issues
    • Product Improvement: Analyze usage patterns to improve features (aggregated data only)
    • Legal Compliance: Respond to regulatory inquiries, enforce Terms of Service
    • Marketing (with consent): Send product updates, compliance tips, feature announcements

    We do not sell, rent, or trade your personal information to third parties.

    4. Where We Store Your Data

    Your compliance records, account data, files and backups are stored in Canada:

    • Application Database: Supabase (Montreal, Canada region)
    • File Storage: Supabase Storage (Montreal, Canada)
    • Backups: Supabase automated backups (Canada region)

    Some service providers process limited personal information outside Canada, under Standard Contractual Clauses or equivalent safeguards. These are the only transfers outside Canada:

    • Stripe (payment processing — US/EU, PIPEDA-compliant DPA)
    • Resend (transactional email — US, GDPR/PIPEDA-compliant)
    • Vercel (hosting — global CDN, edge caching in Canada when possible)
    • Anthropic (AI-assisted compliance features — US; receives the text you submit to an AI feature, and does not train on API inputs or outputs)
    • Google Analytics (optional, only if you consent to analytics cookies — US)

    See our Subprocessors List for full details.

    5. How Long We Retain Your Data

    Data TypeRetention PeriodReason
    Account dataAccount lifetime + 7 yearsPIPEDA audit requirement
    Compliance audit logs7 yearsRegulatory requirement
    Payment records7 yearsCRA requirement
    Support tickets3 yearsLegal defense, quality assurance
    Usage analytics (anonymized)2 yearsProduct improvement

    You may request deletion at any time. We will comply within 30 days unless legal obligations require retention.

    6. Your Rights Under PIPEDA and Quebec Law 25

    You have the right to:

    • Access: Request a copy of all personal information we hold about you
    • Correction: Request correction of inaccurate or incomplete information
    • Deletion: Request deletion of your personal information (subject to legal retention requirements)
    • Portability: Receive your data in a structured, machine-readable format
    • Withdraw Consent: Opt out of marketing emails or analytics tracking
    • Lodge a Complaint: File a complaint with the Office of the Privacy Commissioner of Canada (OPC)

    To exercise your rights, email privacy@canadacomplianceai.ca. We will respond within 30 days.

    7. Security Measures

    We implement industry-standard security practices:

    • Encryption in Transit: TLS 1.3 for all connections
    • Encryption at Rest: AES-256 for database and file storage
    • Access Controls: Role-based access control (RBAC), multi-factor authentication (MFA) required for admin accounts
    • Row-Level Security (RLS): Database policies ensure users can only access their own data
    • Audit Logging: All data access and modifications logged
    • Penetration Testing: Third-party testing is planned — see our Security page for current status
    • Incident Response Plan: we aim to notify affected individuals and the Privacy Commissioner within 72 hours of determining that a breach creates a real risk of significant harm — faster than PIPEDA's "as soon as feasible" requirement (s. 10.1)

    8. Contact Us

    For privacy questions, data access requests, or complaints:

    Email: privacy@canadacomplianceai.ca

    Mailing Address:
    Canada Compliance AI Inc.
    c/o Brainfy AI Inc.
    Edmonton, AB, Canada

    Office of the Privacy Commissioner of Canada:
    https://www.priv.gc.ca/en/report-a-concern/file-a-formal-privacy-complaint/