Skip to main content
DutivaDutivaCANADA
How it worksWorkspacePricingGuidesCareers
FRSign inSee plans
FR
DutivaDutiva
How it worksWorkspacePricingGuidesCareers
Sign inSee plans
DutivaDutiva

Compliance-led workspace for Canadian employers — HR guidance, review-ready documents, and the day-to-day operations around your people.

Dutiva provides practical HR workflow support and compliance-oriented guidance. It does not provide legal, tax, medical, or financial advice.

Built in Ottawa·PIPEDA-conscious·Bilingual EN/FR

Stuck on a workflow? support@dutiva.ca

Review us on Trustpilot
Product
AdvisorWorkflowsDocument StudioPricingWaitlist
Resources
GuidesHelp CentreFAQBlogService statusChangelog
Company
About UsCareersContactDutiva vs Citation CanadaDutiva vs SixFiftyOpen app
Investors
InvestorsClient sign-in
Legal
Privacy PolicyTerms of ServiceCookie PolicyDisclaimerAccessibility
View all policies
© 2026 Dutiva Canada Inc. All rights reserved.
All legal & compliance documents

Privacy Policy

Last updated: August 30, 2026 · Effective date: June 2, 2026

Dutiva Canada Inc. ("Dutiva," "we," "us," or "our") provides HR compliance software for Canadian employers, HR professionals, and business operators. This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information when you use Dutiva, including our website, application, Advisor, document workflows, beta access, support, and related services.

This Policy is designed to support compliance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy laws, including Quebec privacy requirements where they apply. It does not replace any separate Data Processing Agreement, subscription agreement, or organization-specific privacy obligations that may apply to your use of Dutiva.

1. Who We Are

Dutiva Canada Inc. provides HR compliance software built for Canadian employers and HR teams. For account, website, billing, support, and product-usage information that we collect directly from users, Dutiva is responsible for that personal information under applicable Canadian privacy law.

Where an employer, HR professional, or organization enters personal information about employees, candidates, contractors, or other individuals into Dutiva, that organization is generally responsible for ensuring it has the authority, consent, notice, and internal policies required to use Dutiva for that information. Dutiva processes that information to provide the service, subject to this Policy and any applicable agreement with the customer.

Our Privacy Officer handles privacy questions and requests. See Section 10 for your rights and how to contact us.

2. Information We Collect

We collect the categories below to operate Dutiva for the purposes described in Section 3. We disclose them only to the service providers and in the circumstances described in Section 4.

Depending on how you use Dutiva, we may collect the following categories of personal information:

  • Account information — name, work email, authentication details, organization name, province or territory, role, plan, account status, and related account settings.
  • Workspace information — onboarding answers, employer profile details, selected province, territory, or applicable federal regime, organization size, preferred language, workflow preferences, saved settings, and in-app configuration choices.
  • Document information — document titles, template selections, jurisdiction or coverage-context codes, document inputs, saved drafts, generated documents, lifecycle status, export records, and electronic-signature workflow records.
  • Advisor messages — messages you submit to Dutiva Advisor, limited conversation history needed to provide the response, selected province, territory, or applicable federal regime, retrieved guidance context, and limited workspace context needed to make the response useful.
  • Usage, device, and security data — log data, IP address, browser and device information, pages or features used, timestamps, rate-limit signals, error logs, authentication events, and security events generated by our infrastructure.
  • Billing data — subscription status, invoice, payment, tax, and billing portal information processed through Stripe. Dutiva does not store full card numbers or banking credentials.
  • Beta, support, and communications data — beta waitlist submissions, feedback consent, support messages, survey responses, transactional email records, and communication preferences.

3. How We Use Information

We use personal information only for purposes needed to operate, secure, support, and improve Dutiva, including to:

  • provide, authenticate, operate, maintain, and secure the Dutiva service;
  • create accounts, manage access, apply plan limits, and support organization-level administration;
  • generate, save, review, export, and administer HR documents and electronic-signature workflows;
  • deliver Advisor responses, retrieve relevant guidance context, and improve the reliability and safety of HR compliance workflows;
  • process subscriptions, invoices, receipts, account notices, support requests, and service updates;
  • measure aggregate feature usage, troubleshoot errors, prevent abuse, enforce rate limits, and monitor service performance;
  • protect the security, availability, integrity, and lawful operation of Dutiva; and
  • comply with legal, tax, accounting, security, regulatory, dispute-resolution, and audit obligations.

We do not sell personal information. We do not use customer HR documents or Advisor messages for third-party advertising.

4. Service Providers and Disclosure

We disclose personal information only as needed to operate the service, comply with law, complete business transactions, or protect rights, safety, and security.

We use the following categories of service providers. Each receives only the information needed for its role:

  • Infrastructure and hosting — Supabase (database, authentication, storage, and edge functions) and Vercel (hosting, serverless functions, deployment, and operational logs) store and process account, workspace, document, and operational data needed to run Dutiva.
  • AI inference — DigitalOcean Gradient AI processes Advisor message content and limited context to generate responses. Data is sent only as needed for inference. Under Dutiva's arrangement, customer content is not used to train third-party foundation models.
  • Payments — Stripe processes subscription, payment, invoice, tax, and billing portal data. Dutiva does not store full card numbers or banking credentials.
  • Email — Resend (or an equivalent transactional email provider) delivers account, billing, document, and support emails.
  • Network, security, and availability — Cloudflare provides DNS, network security, performance, and availability services, and may provide bot protection on public forms when configured.
  • Website analytics — Google Tag Manager and Google Analytics load only when configured and the visitor has accepted analytics through the consent banner.
  • First-party support analytics — Help Centre searches, article views, helpfulness votes, and support ticket events are optional, off by default, sent to a Dutiva-operated edge function in Canada, and do not use third-party cookies.
  • Trust signals — TrustedSite (Halo Security) loads on the public marketing site only so visitors can see security-scan status. It is not loaded in the signed-in workspace and is not used for advertising.

We may also disclose information where required by law, court order, regulator request, legal process, merger or financing diligence, corporate transaction, or where reasonably necessary to protect the security and integrity of Dutiva, our users, or the public.

See our Subprocessor List for subprocessors, processing locations, and data categories.

5. Consent and Choices

We rely on consent, contract necessity, legitimate service operations, and legal obligations as appropriate under Canadian privacy law. We identify purposes before or at collection unless the purpose is obvious from context or permitted by law.

  • Required processing — account, workspace, document, billing, security, and core product data are needed to provide Dutiva, maintain security, complete billing, preserve audit records, and meet legal obligations. You cannot use the core service without this processing.
  • Optional processing — beta feedback communications, optional marketing communications, third-party website analytics (Google Tag Manager and Google Analytics), and first-party support analytics are optional. These load or run only when you have granted consent through the consent banner or an explicit preference control, except where a communication is transactional and necessary to the service you requested.
  • Customer-controlled data — where an employer or organization enters personal information about employees, candidates, contractors, or other individuals, that organization is responsible for having the authority, consent, notice, and internal policies required to use Dutiva for that information.
  • Withdrawal — you may withdraw optional consent by using unsubscribe or preference controls where available, adjusting consent through the consent banner where applicable, or contacting us at privacy@dutiva.ca. Withdrawing optional consent does not affect processing that is required to provide the service, maintain security, complete billing, or meet legal obligations.
  • Advisor — Dutiva Advisor is a core product feature. You cannot opt out of Advisor processing while using Advisor; you can choose not to use Advisor. See Sections 7 and 8 for AI and automated-processing notices.

6. Cross-Border Processing

Some service providers may process or store information outside Canada, including in the United States. When information is processed outside your province or outside Canada, it may be subject to the laws of that jurisdiction.

We use contractual, technical, and organizational safeguards designed to protect personal information during cross-border processing. For Quebec personal information, transfers outside Quebec are reviewed through a privacy impact assessment process before the transfer is approved, where required by applicable law.

7. AI Advisor Notice

Dutiva Advisor is an AI-powered workflow guidance feature. Advisor messages are sent to our server-side Advisor endpoint and then, where needed, to a third-party AI model provider for inference. We do not include payment details in AI requests, and we limit workspace context to the fields needed to make the response useful.

When you use Advisor, keep the following in mind:

  • Do not submit social insurance numbers, medical records, banking credentials, personal health information, or highly sensitive employee records to the Advisor unless Dutiva expressly provides a controlled workflow for that type of information.
  • Advisor responses are generated by AI and are not reviewed by a lawyer before delivery.
  • Advisor responses provide general HR workflow support and compliance-oriented guidance. They are not legal advice and should not be treated as a substitute for professional review.
  • Dutiva does not make employment decisions for you. Employers, HR professionals, and authorized users remain responsible for reviewing outputs and making workplace decisions.

Dutiva does not use customer Advisor prompts or generated HR documents to train third-party foundation models unless a separate written agreement or explicit opt-in provides otherwise.

See our AI Usage Disclosure, AI & Technology Policy, and Legal Disclaimer for additional detail.

8. Automated Decision-Making

Dutiva may use automated systems to generate drafts, retrieve guidance context, suggest next steps, enforce rate limits, monitor security, and support product functionality. Dutiva is designed to assist employer and HR workflows; it is not designed to make final hiring, discipline, accommodation, termination, compensation, or other employment decisions on behalf of customers.

Where automated processing produces a recommendation, draft, or guidance output, users should review the output before relying on it. Dutiva is not designed to make solely automated decisions that produce legal or similarly significant effects about individuals on behalf of customers.

If you have questions about automated processing associated with your personal information, or want information about how it is used, contact us at privacy@dutiva.ca.

To request human review of a specific AI output where applicable law or our Human Review Escalation Policy provides for it, contact privacy@dutiva.ca or follow the escalation paths described in that policy.

9. Retention and Deletion

We retain personal information only as long as needed for the purposes described in this Policy, unless a longer period is required or permitted for legal, tax, accounting, security, dispute, regulatory, or audit reasons. The periods below describe our current approach. Exact timing may vary based on product configuration, customer instructions, legal requirements, and whether an account remains active.

  • Account and workspace data — retained while the account is active, then deleted or anonymized after account deletion unless retained for legal, billing, security, support, audit, or dispute purposes.
  • Generated documents, inputs, and saved drafts — retained until a user or authorized administrator deletes or archives them, the account is deleted, or a required retention period ends, subject to legal, security, and backup limitations.
  • Advisor messages and AI workflow context — current browser workflows may keep conversation state for the in-session user experience. Server-side calls may process limited context for inference, safety, troubleshooting, rate limiting, and service reliability.
  • First-party support analytics raw event data — retained for 90 days, then deleted. Daily aggregates, which no longer identify an individual in a reasonably foreseeable way, are retained indefinitely.
  • Billing, tax, security, and audit records — retained for required statutory or operational periods.
  • Backups — retained until they expire through the normal backup lifecycle. Backups may not allow selective deletion before expiry, but they are protected by access controls and are not used for ordinary production access.
  • Account deletion — self-initiated account deletion removes owned account rows and generated documents, then records an anonymized deletion audit entry.

See our Data Retention and Deletion Policy for additional detail.

10. Your Privacy Rights

Subject to legal limits, you may request access to personal information we hold about you, correction of inaccurate information, withdrawal of consent for optional processing, account deletion, and information about our privacy practices and how we have used or disclosed your information.

Quebec residents may also have rights to portability, de-indexing or erasure in certain circumstances, and information about automated decision-making that produces legal or similarly significant effects.

To exercise these rights:

  • Email — send privacy requests to privacy@dutiva.ca.
  • Contact form — use dutiva.ca/contact and select the Privacy request category.
  • Identity verification — we may need to verify your identity before responding. Do not attach identity documents to an ordinary support message unless we ask you to.
  • Response timing — we aim to respond within 30 days where required by law, unless an extension is permitted or required.
  • Regulators — you may contact the Office of the Privacy Commissioner of Canada at priv.gc.ca or the Commission d'accès à l'information du Québec at cai.gouv.qc.ca.

Privacy requests are handled separately from ordinary support.

11. Cookies, Local Storage, and Analytics

Dutiva uses strictly necessary authentication storage and local browser storage for settings such as language, theme, onboarding progress, and in-browser workflow state. Optional analytics are only loaded when configured in the application environment.

We do not use third-party advertising cookies or cross-site advertising trackers. See our Cookie Policy for additional detail.

12. Security and Breach Response

We use safeguards appropriate to the sensitivity of the information, including TLS in transit, access controls, authentication, service-role separation, rate limiting, audit-oriented deletion records, and operational monitoring. These safeguards are designed to protect personal information against loss, theft, and unauthorized access, use, or disclosure.

If a privacy breach creates a real risk of significant harm, we will notify affected individuals and report to the Office of the Privacy Commissioner of Canada as soon as feasible, and we will keep required breach records. Quebec confidentiality incidents are handled under Quebec notification and recordkeeping requirements where applicable.

13. Updates to This Policy

We may update this Policy from time to time to reflect changes in our service, providers, legal obligations, or privacy practices. If we make material changes, we will provide notice in a manner appropriate to the change, such as by updating the date above, posting a notice in the service, or sending an account notice where appropriate.

14. Contact

  • Privacy Officer — Dutiva Canada Inc.
  • Email — privacy@dutiva.ca
  • Website — dutiva.ca

For privacy rights and how to submit a request, see Section 10.