PIPEDA Compliance Statement
Last updated: · Effective date:
This PIPEDA Compliance Statement explains how Dutiva Canada Inc. ("Dutiva," "we," "us," or "our") designs its privacy program around the 10 fair information principles under the Personal Information Protection and Electronic Documents Act (PIPEDA).
This Statement summarizes program controls, public commitments, and operating practices that support responsible handling of personal information in Dutiva’s website, application, Advisor, document workflows, beta access, support, and related services.
This Statement should be read with Dutiva’s Privacy Policy, Data Processing Agreement, Data Retention and Deletion Policy, Incident and Breach Response Policy, Cookie Policy, AI Usage Disclosure, AI & Technology Policy, and any applicable subscription or order terms. It is not an independent audit, certification, or legal opinion.
1. Scope and Role
This Statement applies to Dutiva’s privacy program where PIPEDA applies to Dutiva’s collection, use, disclosure, retention, and safeguarding of personal information in the course of commercial activity.
For account, website, billing, support, security, and product-operations information that Dutiva collects directly from users, Dutiva is responsible for that personal information under applicable Canadian privacy law.
Where a customer submits personal information about employees, candidates, contractors, or other individuals into Dutiva for HR workflows, generated documents, Advisor context, electronic-signature workflows, or saved records, the customer generally determines the purposes for that processing and Dutiva processes the information as a service provider or processor, subject to the Data Processing Agreement and applicable customer instructions.
Some activities may also be subject to provincial privacy laws, including Quebec privacy requirements, or to customer-specific legal obligations. This Statement supports Dutiva’s PIPEDA-oriented controls but does not replace customer obligations, organization-specific policies, or legal review.
2. Principle 1 - Accountability
Dutiva designates a Privacy Officer for privacy inquiries, access and correction requests, deletion requests, policy ownership, provider privacy review, privacy-impacting product changes, and privacy-breach assessment. The Privacy Officer can be contacted at privacy@dutiva.ca.
Dutiva uses internal ownership and documented procedures for privacy-impacting changes, service providers and subprocessors, cross-border processing, AI and model-provider processing, data retention and deletion workflows, incident response, breach records, and public privacy-policy updates.
Customers remain responsible for ensuring that they have the authority, consent, notices, internal policies, and lawful basis required to submit employee, candidate, contractor, or other third-party personal information into Dutiva.
3. Principle 2 - Identifying Purposes
Dutiva identifies the purposes for collecting personal information in the Privacy Policy, product flows, support interactions, contractual materials, and related legal pages.
Core purposes include account access, authentication, HR document workflows, Advisor responses, employer-profile context, billing, support, product security, usage metering, service reliability, legal compliance, tax and accounting records, incident response, and audit needs.
Where Dutiva introduces materially different personal-information practices, Dutiva updates the relevant public-facing policy, in-app notice, contractual term, or product explanation as appropriate to the change.
4. Principle 3 - Consent
Dutiva seeks consent appropriate to the sensitivity of the information, the product context, and the user’s reasonable expectations. Some processing is necessary to provide the service, maintain security, complete billing, preserve audit records, or meet legal obligations.
Optional communications, beta feedback communications, optional analytics, or marketing communications are handled through appropriate consent, unsubscribe, or preference controls where required or appropriate.
Users may withdraw optional consent by using available unsubscribe or preference controls or by contacting Dutiva. Withdrawal may not affect processing that is required to provide the service, maintain security, complete billing, preserve legal records, or comply with law.
5. Principle 4 - Limiting Collection
Dutiva designs product workflows to collect personal information needed for defined HR compliance, document, account, billing, security, support, and product-operations purposes.
Dutiva limits Advisor context and AI requests to the message content and workspace context reasonably needed to produce useful workflow guidance. Product guidance warns users not to enter social insurance numbers, payment card numbers, banking credentials, medical records, protected health information, or highly sensitive employee records unless a specific Dutiva workflow expressly supports that data type.
Dutiva may adjust forms, prompts, fields, and workflow requirements over time to reduce unnecessary collection while preserving product usefulness, legal recordkeeping, and service reliability.
6. Principle 5 - Limiting Use, Disclosure, and Retention
Dutiva uses and discloses personal information for the purposes described in the Privacy Policy, Data Processing Agreement, Terms of Service, Cookie Policy, AI Usage Disclosure, and other applicable legal pages or customer instructions.
Dutiva does not sell personal information. Dutiva does not use customer HR documents or Advisor messages for third-party advertising.
Dutiva uses service providers and subprocessors only as needed to operate, secure, support, process payments for, analyze where enabled, and improve the service. Current core provider categories are described in the Privacy Policy and Data Processing Agreement.
The Data Retention and Deletion Policy describes retention principles, account deletion workflows, customer-controlled deletion, backup limits, legal holds, and exceptions for legal, tax, billing, dispute, security, incident, and anonymized audit purposes.
7. Principle 6 - Accuracy
Dutiva relies on users and customers to provide accurate account, organization, province, territory, federal-regime, role, workflow, document, and employer-profile information.
Product settings, profile flows, workspace configuration, and support channels allow users to update information used by the dashboard, Advisor, document generator, workspace, billing, and related workflows where applicable.
Individuals may request correction of inaccurate personal information by contacting privacy@dutiva.ca, subject to legal limits and customer-control considerations where the information was submitted by a customer organization.
8. Principle 7 - Safeguards
Dutiva uses safeguards appropriate to the sensitivity of the information, including administrative, technical, and organizational measures designed to protect personal information against loss, theft, unauthorized access, disclosure, copying, use, modification, disposal, or other compromise.
Safeguards may include TLS encryption in transit, authentication controls, restricted administrative access, row ownership controls, service-role separation, API secret isolation, rate limits, input limits, provider security controls, operational monitoring, secure development practices, deletion audit hashing, and incident-response procedures.
Dutiva maintains an Incident and Breach Response Policy for suspected or confirmed privacy and security incidents. No safeguard can eliminate all risk, but Dutiva aims to apply safeguards proportionate to the sensitivity, volume, and use of the information involved.
9. Principle 8 - Openness
Dutiva publishes public-facing privacy and legal documents that describe its privacy practices, service terms, cookies and browser storage, AI usage, technology providers, data processing, retention and deletion, incident response, accessibility, CASL, and Quebec Law 25 practices.
Dutiva’s Privacy Policy describes information categories, purposes, service providers, cross-border processing, AI Advisor processing, automated processing, retention, individual rights, cookies, security, and contact information.
Privacy inquiries can be directed to Dutiva’s Privacy Officer at privacy@dutiva.ca.
10. Principle 9 - Individual Access
Subject to legal limits, individuals may request access to personal information Dutiva holds about them and may request information about how it has been used or disclosed.
Dutiva aims to respond to access requests within 30 days where required by law, unless an extension is permitted or required.
Where Dutiva processes Customer Personal Information on behalf of a customer organization, Dutiva may direct the request to the relevant customer or provide reasonable assistance to the customer through existing product functionality, support channels, and account or record deletion workflows.
11. Principle 10 - Challenging Compliance
Individuals may challenge Dutiva’s compliance with this Statement, the Privacy Policy, or applicable privacy law by contacting the Privacy Officer at privacy@dutiva.ca.
Dutiva will review privacy complaints, investigate where appropriate, document relevant findings, and respond in a manner proportionate to the issue and applicable legal requirements.
Individuals may also contact the Office of the Privacy Commissioner of Canada at priv.gc.ca.
12. Breach Reporting and Records
Dutiva assesses privacy breaches and breaches of security safeguards involving personal information under Dutiva’s control to determine whether the breach creates a real risk of significant harm. The assessment considers the sensitivity of the information, the probability of misuse, and other relevant factors.
Where PIPEDA reporting applies, Dutiva reports to the Office of the Privacy Commissioner of Canada and notifies affected individuals as soon as feasible after determining that the breach creates a real risk of significant harm, unless prohibited by law. Dutiva may also notify other organizations or government institutions that may be able to reduce or mitigate harm where appropriate.
Dutiva keeps records of every breach of security safeguards involving personal information under its control for at least two years, including records for breaches that are not reportable. Quebec confidentiality incidents are handled under Quebec notification and recordkeeping requirements where applicable.
When Dutiva processes Customer Personal Information on behalf of a customer, customer notification and breach-support responsibilities are also described in the Data Processing Agreement and Incident and Breach Response Policy.
13. Privacy Program Review and Improvement
Dutiva reviews privacy practices as its product, providers, AI workflows, data flows, and legal obligations evolve. Reviews may include provider privacy review, privacy-impacting product review, cross-border transfer review, deletion workflow review, security-control review, and policy updates.
Dutiva may update this Statement to reflect changes in the service, provider stack, privacy practices, applicable law, regulator guidance, or internal privacy controls.
14. Official References
This Statement is anchored to the Office of the Privacy Commissioner of Canada’s explanation of PIPEDA’s fair information principles and mandatory breach reporting guidance. It is also informed by the text of PIPEDA, including Schedule 1 and breach-of-security-safeguards provisions.
15. Contact
Dutiva Canada Inc. - Privacy Officer
Email: privacy@dutiva.ca
Website: dutiva.ca
