Skip to main content
DutivaDutivaCANADA
How it worksWorkspacePricingGuidesCareers
FRSign inSee plans
FR
DutivaDutiva
How it worksWorkspacePricingGuidesCareers
Sign inSee plans
DutivaDutiva

Compliance-led workspace for Canadian employers — HR guidance, review-ready documents, and the day-to-day operations around your people.

Dutiva provides practical HR workflow support and compliance-oriented guidance. It does not provide legal, tax, medical, or financial advice.

Built in Ottawa·PIPEDA-conscious·Bilingual EN/FR

Stuck on a workflow? support@dutiva.ca

Review us on Trustpilot
Product
AdvisorWorkflowsDocument StudioPricingWaitlist
Resources
GuidesHelp CentreFAQBlogService statusChangelog
Company
About UsCareersContactDutiva vs Citation CanadaDutiva vs SixFiftyOpen app
Investors
InvestorsClient sign-in
Legal
Privacy PolicyTerms of ServiceCookie PolicyDisclaimerAccessibility
View all policies
© 2026 Dutiva Canada Inc. All rights reserved.
All legal & compliance documents

AI & Technology Policy

Last updated: August 26, 2026 · Effective date: June 1, 2026

This Policy explains the technology used to operate Dutiva, including the current Advisor model flow, technology providers, data-handling boundaries, retrieval controls, and safeguards around AI-assisted HR workflows.

This Policy should be read together with the Privacy Policy, Terms of Service, Legal Disclaimer, AI Usage Disclosure, Data Processing Agreement, and Data Retention and Deletion Policy.

1. Purpose and Scope

Dutiva is a Canadian HR compliance software-as-a-service platform for employers, HR professionals, and business operators. Some features use artificial intelligence, retrieval, automation, and third-party technology providers to support HR workflows.

This Policy is intended to provide practical transparency about how these technologies are currently used. It does not create service commitments beyond the Terms of Service and does not replace product-specific notices shown in the application.

2. Current Advisor Model Flow

Dutiva Advisor is served through Dutiva’s server-side advisor-chat edge function. The current production configuration routes Advisor messages to DigitalOcean Gradient AI and uses DeepSeek 3.2 (`deepseek-3.2`) to generate responses. The provider and model are resolved at request time from Dutiva’s routing table and can change without a software deploy.

Dutiva may update models, providers, retrieval methods, system instructions, safety controls, and routing logic over time to improve reliability, bilingual performance, latency, cost, security, or responsible-use controls. Material public-facing changes will be reflected in this Policy, the AI Usage Disclosure, or in-product notices where appropriate.

3. What May Be Sent to AI Providers

Advisor requests may include:

  • the user’s message;
  • limited recent conversation turns;
  • the selected province, territory, or federal regime;
  • retrieved HR guidance context;
  • the active workflow ID or template context; and
  • limited workspace context such as organization name, selected jurisdiction or coverage context, role, employer size, language preference, plan, and workflow state.

Dutiva limits context sent to AI providers to what is reasonably needed to generate a useful response. Dutiva does not intentionally include payment card numbers, banking credentials, full account identifiers, or billing portal credentials in AI requests.

Users should not submit social insurance numbers, medical records, personal health information, banking details, protected employee records, collective agreement files, or other highly sensitive employee information to the Advisor unless Dutiva expressly provides a controlled workflow for that information and the customer has a lawful basis to use it.

4. Retrieval and Guidance Context

Dutiva may provide the model with internal HR guidance context from Dutiva’s compliance knowledge pipeline, including jurisdiction-specific notes, workflow checklists, template context, and structured guidance.

The Advisor is instructed to use retrieved guidance where available, avoid inventing citations or statutory references, identify assumptions and uncertainty, and flag high-risk matters for qualified HR, legal, payroll, privacy, or other professional review.

Retrieved guidance improves grounding, but it does not guarantee that a response is complete, current, or suitable for the customer’s facts, workplace, contracts, policies, collective agreements, or industry.

5. Output Controls and Safety Measures

Dutiva applies practical controls around AI-assisted responses, including:

  • server-side provider calls so model provider secrets are not exposed in the browser;
  • prompt and context minimization where reasonably possible;
  • message length limits, limited conversation history, and rate limiting;
  • system instructions that call for jurisdiction notes, risk levels, next steps, legal basis, and professional-review guidance where appropriate;
  • safety, abuse-prevention, and formatting controls; and
  • persistent user-facing reminders that Dutiva provides HR workflow support and compliance-oriented guidance, not legal advice.

These controls reduce risk, but they cannot eliminate AI errors or inappropriate outputs.

6. Technology Providers

Dutiva currently relies on the following core provider categories:

  • Supabase: authentication, database, storage, edge functions, and app data infrastructure.
  • Vercel: hosting, serverless functions, deployment, and operational logs.
  • DigitalOcean Gradient AI: AI model routing and inference for Advisor-related features.
  • Stripe: subscription billing, checkout, invoices, tax, and payment processing.
  • Cloudflare: DNS, traffic routing, performance, availability, and network protection.
  • Google Analytics, if enabled: product or website analytics.
  • React and Vite: frontend application framework and build tooling.

Not every provider receives every category of information. Provider access depends on the feature, configuration, and data required to operate that part of the service.

7. AI Limits and Professional Review

AI systems can produce inaccurate, incomplete, outdated, fabricated, biased, or internally inconsistent content. Dutiva does not guarantee that AI responses reflect all current statutes, regulations, case law, collective agreements, employment contracts, workplace policies, agency guidance, payroll requirements, human rights obligations, or workplace facts.

Dutiva does not make final workplace decisions for customers. Employers, HR professionals, and authorized users remain responsible for reviewing outputs, confirming facts, applying current law and workplace context, documenting decisions, and obtaining qualified professional review where appropriate.

Before acting on terminations, layoffs, accommodations, investigations, privacy incidents, pay equity, unionized workplace issues, executive compensation, cross-border employment arrangements, or other high-risk matters, customers should obtain qualified legal or professional review.

8. Data Retention, Training, and Product Improvement

Dutiva’s current browser workflow may keep Advisor conversation state in-session for user experience and workflow continuity. Dutiva may also process limited operational records, logs, usage signals, and security events to provide, troubleshoot, secure, monitor, and improve the service as described in the Privacy Policy and Data Retention and Deletion Policy.

Dutiva does not use customer Advisor prompts or generated HR documents to train third-party foundation models unless a separate written agreement or explicit opt-in provides otherwise.

Provider-side processing and retention are governed by provider terms, configurations, and Dutiva’s agreements with those providers. Where available, Dutiva uses configuration, contractual, and operational controls intended to limit unnecessary retention and use of customer content.

9. Automated Systems and Human Review

Dutiva uses automation to support draft generation, guidance retrieval, rate limits, security monitoring, and workflow status. Dutiva is designed to assist employer and HR workflows; it is not designed to make final hiring, discipline, accommodation, termination, compensation, or other employment decisions on behalf of customers.

Where an automated or AI-assisted output is used to support a workplace decision, the customer remains responsible for human review, fact-checking, and decision-making. Customers should consider additional privacy, human rights, employment standards, labour relations, and internal governance requirements before using automated outputs in workplace decisions.

10. Changes to This Policy

Dutiva may update this Policy as its service, provider stack, model configuration, retrieval system, security controls, or legal obligations evolve. Material changes will be reflected by updating the date above, publishing a revised Policy, or providing additional notice where appropriate.

11. Questions

Questions about Dutiva’s use of AI, automation, or technology providers can be sent to support@dutiva.ca.

FRANÇAIS