1. Introduction
Canada Compliance AI Inc. ("we", "our", "us") operates the website canadacomplianceai.ca and provides compliance management software to Canadian businesses.
This Privacy Policy explains how we collect, use, store, and disclose your personal information in compliance with:
- Personal Information Protection and Electronic Documents Act (PIPEDA)
- Quebec Law 25 (An Act to modernize legislative provisions as regards the protection of personal information)
- Provincial privacy legislation where applicable
2. What Personal Information We Collect
Account Information
- Full name
- Email address
- Company name
- Phone number (if provided)
- Billing address
Payment Information
Processed by our payment processor Stripe. We do not store full credit card numbers — only last 4 digits and card brand for display purposes.
Usage Data
- IP address (Canada location only)
- Browser type and version
- Pages visited, time spent, links clicked
- Compliance scan results and configurations
- Audit log entries
- Support tickets and email correspondence
Cookies and Tracking
See our Cookie Policy for full details.
3. How We Use Your Information
We use personal information only for the purposes for which it was collected:
- Provide the Service: Account management, compliance scanning, audit logs, reports
- Billing: Process payments, issue invoices, handle refunds
- Support: Respond to questions, troubleshoot issues
- Product Improvement: Analyze usage patterns to improve features (aggregated data only)
- Legal Compliance: Respond to regulatory inquiries, enforce Terms of Service
- Marketing (with consent): Send product updates, compliance tips, feature announcements
We do not sell, rent, or trade your personal information to third parties.
4. Where We Store Your Data
Your compliance records, account data, files and backups are stored in Canada:
- Application Database: Supabase (Montreal, Canada region)
- File Storage: Supabase Storage (Montreal, Canada)
- Backups: Supabase automated backups (Canada region)
Some service providers process limited personal information outside Canada, under Standard Contractual Clauses or equivalent safeguards. These are the only transfers outside Canada:
- Stripe (payment processing — US/EU, PIPEDA-compliant DPA)
- Resend (transactional email — US, GDPR/PIPEDA-compliant)
- Vercel (hosting — global CDN, edge caching in Canada when possible)
- Anthropic (AI-assisted compliance features — US; receives the text you submit to an AI feature, and does not train on API inputs or outputs)
- Google Analytics (optional, only if you consent to analytics cookies — US)
See our Subprocessors List for full details.
5. How Long We Retain Your Data
| Data Type | Retention Period | Reason |
|---|
| Account data | Account lifetime + 7 years | PIPEDA audit requirement |
| Compliance audit logs | 7 years | Regulatory requirement |
| Payment records | 7 years | CRA requirement |
| Support tickets | 3 years | Legal defense, quality assurance |
| Usage analytics (anonymized) | 2 years | Product improvement |
You may request deletion at any time. We will comply within 30 days unless legal obligations require retention.
6. Your Rights Under PIPEDA and Quebec Law 25
You have the right to:
- Access: Request a copy of all personal information we hold about you
- Correction: Request correction of inaccurate or incomplete information
- Deletion: Request deletion of your personal information (subject to legal retention requirements)
- Portability: Receive your data in a structured, machine-readable format
- Withdraw Consent: Opt out of marketing emails or analytics tracking
- Lodge a Complaint: File a complaint with the Office of the Privacy Commissioner of Canada (OPC)
To exercise your rights, email privacy@canadacomplianceai.ca. We will respond within 30 days.
7. Security Measures
We implement industry-standard security practices:
- Encryption in Transit: TLS 1.3 for all connections
- Encryption at Rest: AES-256 for database and file storage
- Access Controls: Role-based access control (RBAC), multi-factor authentication (MFA) required for admin accounts
- Row-Level Security (RLS): Database policies ensure users can only access their own data
- Audit Logging: All data access and modifications logged
- Penetration Testing: Third-party testing is planned — see our Security page for current status
- Incident Response Plan: we aim to notify affected individuals and the Privacy Commissioner within 72 hours of determining that a breach creates a real risk of significant harm — faster than PIPEDA's "as soon as feasible" requirement (s. 10.1)
8. Contact Us
For privacy questions, data access requests, or complaints: