Contact us

Trust Center · Privacy & Law 25

Privacy & Law 25

For privacy officers, legal counsel, and compliance teams. Law 25 alignment as concrete obligations, not a badge.

Residency & routing

Canadian data residency is standard for all customer content. Cross-border routing controls are configurable and auditable. Model providers and their processing regions are listed by name on the legal page, and enterprise deployments can pin providers to approved regions or run self-hosted.

Law 25, as obligations we meet

Quebec's Law 25 is treated as engineering requirements, not marketing:

  • Privacy impact assessments: PIA support is shipped in-product, not offered as consulting
  • Data minimization: no tracking cookies on this site; one functional cookie for language
  • Retention: scan results deleted after 30 days unless an account is created; backups bounded and stated
  • Rights: access, rectification, and deletion are product features (the Trust Ledger), not ticket queues
  • Incident notification: contractual commitments aligned to Law 25 timelines

The deletion cascade, with a receipt

When a person withdraws a contribution, everything derived solely from it is removed with it, claims, embeddings, derived documents, and they receive a deletion receipt. Backup retention is bounded and the bound is stated in the DPA. A downloadable DPA is available on the legal page; for Quebec customers, the French version of legal documents takes precedence.

Employee rights are architectural

Access and rectification aren't policies we promise to follow, they're screens in the product that employees use directly. See the Trust Ledger and the employee page.

A question this page didn't answer?

Security reports: [email protected] · Employee concerns: [email protected] · Everything else: [email protected]