CASL Compliance Policy
Last updated: · Effective date:
Dutiva Canada Inc. ("Dutiva," "we," "us," or "our") designs its commercial electronic message practices around Canada's Anti-Spam Legislation (CASL): consent, clear sender identification, truthful content, and a working unsubscribe mechanism.
This Policy explains how Dutiva manages commercial electronic messages sent by or on behalf of Dutiva, including beta access communications, product updates, lifecycle campaigns, promotional messages, customer announcements, partner communications, and event-related outreach.
This Policy should be read with Dutiva's Privacy Policy, Cookie Policy, Terms of Service, AI Usage Disclosure, and related legal pages. It is a public-facing operational policy and does not replace legal review for specific campaigns, channels, jurisdictions, or partner arrangements.
1. Scope
This Policy applies to electronic messages sent by or on behalf of Dutiva that encourage participation in a commercial activity and are sent to an electronic address, to the extent those messages are subject to CASL.
Covered messages may include email, SMS or text messages, direct electronic messages, in-app direct messages where applicable, and similar electronic communications used for beta access, product marketing, feature updates, events, promotions, customer lifecycle campaigns, and partner communications.
Some service, account, billing, security, legal, support, or transactional messages may be handled differently under CASL depending on their content and purpose. Dutiva separates operational service communications from optional marketing where practical.
2. Core CASL Requirements
Dutiva's commercial electronic message practices are designed around CASL's three core requirements: obtain a valid consent basis or permitted exception, clearly identify the sender and any person on whose behalf the message is sent, and include a working unsubscribe mechanism.
Dutiva also aims to ensure that commercial message content is accurate, not misleading, and consistent with Dutiva's public product, legal, privacy, AI, and compliance statements.
If a message cannot be confidently categorized as transactional, exempt, or supported by a documented consent basis, Dutiva should treat it as a commercial electronic message requiring CASL review before sending.
3. Consent Standards
Dutiva sends commercial electronic messages only where it has express consent, implied consent, or another CASL-permitted basis.
Express consent should be obtained through a clear positive action, such as submitting a signup form, selecting an unchecked checkbox, or otherwise affirmatively requesting to receive commercial communications. Consent requests should state the purpose of the communications, identify Dutiva and any other relevant sender, include required contact information, and explain that consent can be withdrawn.
Express consent must not be bundled into general terms of service, hidden in unrelated consent language, or obtained through a pre-checked box. Where multiple types of optional communications are offered, preference choices should be reasonably clear.
Implied consent may apply where CASL permits it, such as certain existing business relationships, certain inquiries or applications, business contact information that is conspicuously published without a no-solicitation statement and is relevant to the recipient's role, or other circumstances recognized by CASL. When Dutiva relies on implied consent, the basis and any review or expiry date should be documented.
Withdrawal of consent must be respected. A recipient who unsubscribes or otherwise withdraws consent must not be re-added to commercial sends unless a new valid consent basis is obtained or another CASL-permitted basis clearly applies.
4. Transactional, Service, and Exempt Messages
Dutiva may send service, account, billing, security, legal, support, or transactional messages where permitted and reasonably necessary to provide the service, maintain account security, complete billing, deliver beta access, communicate legal updates, or administer an existing customer relationship.
Transactional or service messages should not include promotional content unless Dutiva has an appropriate CASL basis for that promotional content or the message otherwise qualifies under an applicable CASL rule or exception.
Examples of operational messages may include account verification, magic-link authentication, security alerts, payment receipts, billing notices, service-impact notices, legally required updates, support responses, and beta access instructions.
5. Consent Records and Preference Management
Dutiva maintains records intended to show when and how consent was obtained, the source of the electronic address, the communication purpose, the consent language presented, the subscription or preference category, the unsubscribe status, and related timestamps.
Where technically available and appropriate, consent records may include form source, campaign source, IP address, user agent, account identifier, workflow identifier, preference category, and the version of the consent copy used at the time.
When relying on implied consent, Dutiva should document the basis, supporting facts, review date, and expiry date where applicable. Suppression and unsubscribe records should be retained as needed to honour opt-out requests and demonstrate compliance.
6. Identification Requirements
Commercial electronic messages must clearly identify Dutiva Canada Inc. and, where applicable, any person or organization on whose behalf the message is sent.
Messages must include contact information that remains valid for at least 60 days after the message is sent. Depending on the channel and format, contact information may include a mailing address and at least one additional method such as an email address, web address, or telephone number.
Where message format is constrained, such as in SMS or short-form electronic messages, Dutiva may use a clear and prominent link to a web page containing the required identification, contact, and unsubscribe information, where legally appropriate.
7. Unsubscribe and Suppression Controls
Each commercial electronic message must include a working unsubscribe mechanism that is clear, prominent, simple, quick, and available at no cost to the recipient.
Unsubscribe mechanisms should be readily performed. For email, this may include a direct unsubscribe link or preference centre. For SMS, this may include a recognized reply command such as STOP or a link to a preference page.
Unsubscribe requests must be processed without delay and no later than 10 business days after receipt. The unsubscribe mechanism must remain functional for at least 60 days after the message is sent.
Dutiva should check suppression lists and unsubscribe records before sending future commercial messages. Where technically feasible, recipients should be able to unsubscribe from all commercial messages or manage categories of optional communications.
8. Beta, Waitlist, and Product Communications
Beta waitlist forms, early-access forms, and product-interest forms should use clear consent language for optional commercial communications. Where consent is requested, the consent action should be affirmative, visible, and not pre-selected.
Operational beta access messages may be sent as service or account communications where they are reasonably necessary to administer access, authentication, onboarding, support, or security. Promotional beta messages, launch announcements, newsletters, upsell messages, partner offers, and event invitations must follow this Policy.
Product updates that are primarily operational, security-related, legal, or service-administration notices should be kept separate from optional marketing where practical. If an update message includes promotional content, Dutiva should confirm the CASL basis before sending.
9. Third-Party, Partner, and Vendor Sends
Dutiva must not upload, purchase, rent, or use third-party contact lists unless the source, consent basis, permitted purpose, data provenance, unsubscribe responsibility, and privacy implications have been reviewed.
Partner campaigns must clearly identify the sender and any party on whose behalf the message is sent. The parties should define who is responsible for consent records, message approval, unsubscribe processing, suppression-list management, complaint handling, and record production if requested.
Vendors or service providers sending commercial electronic messages for Dutiva must be required to follow CASL-aligned practices, maintain appropriate suppression records, process unsubscribes within required timelines, and provide send, consent, and unsubscribe records on request.
10. Content and Claim Controls
Commercial messages must not include false or misleading sender information, subject lines, claims, offers, pricing, urgency statements, endorsements, product capabilities, legal-compliance claims, AI claims, privacy claims, or employment-law support claims.
Claims about Dutiva's HR compliance support, legal boundaries, AI use, privacy posture, Quebec Law 25 readiness, PIPEDA alignment, or document-generation capabilities should be accurate, reviewable, and consistent with Dutiva's public legal pages.
Messages should avoid dark patterns, hidden conditions, unclear trial or pricing claims, false scarcity, or language that could mislead a recipient about whether a message is promotional or required for service administration.
11. Campaign Review Before Sending
Before launching a new marketing channel, lifecycle campaign, partner send, event campaign, SMS workflow, or other commercial message type, Dutiva should confirm the following:
- The message has been categorized as commercial, transactional, service-related, exempt, or otherwise CASL-permitted.
- The consent basis or permitted exception is documented.
- The identification block, sender name, and contact information are present and accurate.
- The unsubscribe mechanism works, is readily performed, and updates suppression records.
- The send list excludes unsubscribed recipients and suppressed addresses.
- The message content is accurate, not misleading, and consistent with Dutiva's legal, privacy, AI, and product positioning.
- Any partner, vendor, or third-party data source has been reviewed before use.
12. Monitoring, Training, and Recordkeeping
Dutiva should maintain internal ownership for commercial-message compliance, including consent language, campaign review, suppression-list hygiene, unsubscribe testing, vendor oversight, and complaint handling.
Personnel or contractors involved in marketing, beta access, lifecycle messaging, customer communications, or partner campaigns should receive reasonable guidance on CASL basics and Dutiva's internal approval process.
Dutiva may periodically review sample messages, forms, consent records, unsubscribe workflows, and suppression-list operation to confirm that commercial-message practices remain aligned with this Policy and applicable law.
13. Changes to This Policy
Dutiva may update this Policy from time to time to reflect changes in CASL guidance, communication channels, product flows, marketing practices, service providers, or internal controls. Material changes to Dutiva's commercial electronic message practices should be reflected in this Policy or related public-facing materials.
14. Official References
Reference points include the text of Canada's Anti-Spam Legislation, CRTC guidance and FAQs on commercial electronic messages, consent, identification, unsubscribe mechanisms, and CRTC guidance on information to be included in commercial electronic messages and requests for consent.
15. Contact
Questions about Dutiva's commercial electronic message practices can be sent to:
Dutiva Canada Inc.
Email: privacy@dutiva.ca
Website: dutiva.ca
You may also use the unsubscribe or preference controls included in Dutiva commercial messages where available.
