Skip to main content
DutivaDutivaCANADA
How it worksWorkspacePricingGuidesCareers
FRSign inSee plans
FR
DutivaDutiva
How it worksWorkspacePricingGuidesCareers
Sign inSee plans
DutivaDutiva

Compliance-led workspace for Canadian employers — HR guidance, review-ready documents, and the day-to-day operations around your people.

Dutiva provides practical HR workflow support and compliance-oriented guidance. It does not provide legal, tax, medical, or financial advice.

Built in Ottawa·PIPEDA-conscious·Bilingual EN/FR

Stuck on a workflow? support@dutiva.ca

Review us on Trustpilot
Product
AdvisorWorkflowsDocument StudioPricingWaitlist
Resources
GuidesHelp CentreFAQBlogService statusChangelog
Company
About UsCareersContactDutiva vs Citation CanadaDutiva vs SixFiftyOpen app
Investors
InvestorsClient sign-in
Legal
Privacy PolicyTerms of ServiceCookie PolicyDisclaimerAccessibility
View all policies
© 2026 Dutiva Canada Inc. All rights reserved.
All legal & compliance documents

Subprocessor List

Last updated: August 26, 2026 · Effective date: June 1, 2026

Dutiva Canada Inc. ("Dutiva") uses third-party service providers ("subprocessors") to operate and improve the platform. This page lists the subprocessors we currently use, their purpose, the location of their data processing operations, and the categories of data they may access. This list is updated when we add or change subprocessors.

1. Infrastructure and Hosting

Supabase Inc. — Purpose: Database, authentication, file storage, and backend API infrastructure. Data processed: Account data, workspace data, generated documents, usage logs. Processing location: United States (AWS infrastructure; Canada region available and used where configured).

Vercel Inc. — Purpose: Frontend hosting, edge network delivery, and deployment infrastructure. Data processed: Web traffic, request metadata, static assets. Processing location: United States and global CDN edge nodes.

2. AI and Language Model Services

DigitalOcean Gradient AI — Purpose: AI model routing and inference services powering Dutiva Advisor responses and document generation. Data processed: Advisor message text, jurisdiction context, selected template inputs, retrieved guidance context. Processing location: Canada, the United States, or the Netherlands (serverless inference; the provider routes each request to the nearest available region and does not offer region selection on serverless). Data submitted for inference is subject to the provider's data processing terms and is not used to train third-party foundation models under Dutiva's arrangement.

3. Payment Processing

Stripe, Inc. — Purpose: Payment processing, subscription management, and billing portal. Data processed: Payment card data (stored and processed by Stripe; Dutiva does not store full card numbers), billing address, transaction records, subscription status. Processing location: United States.

4. Email and Transactional Communication

Resend Inc. (or equivalent transactional email provider) — Purpose: Transactional email delivery including account verification, password reset, document notifications, billing receipts, and support communications. Data processed: Email address, message content, delivery metadata. Processing location: United States.

5. Error Monitoring

Dutiva does not use a third-party error-tracking subprocessor (such as Sentry or Datadog). When the application encounters an error, a minimized report is sent to a Dutiva-operated function and stored in Dutiva's own database (Supabase, listed in Section 1). Each report is limited to a coarse error message, the route pattern, a release identifier, coarse browser and operating-system family, and locale — it carries no user, session, or authentication identifiers and no input content. Processing and storage follow the Supabase entry above.

6. Analytics

First-party analytics are processed in-house. Help Centre and support-funnel events (searches, article views, helpfulness votes, and support ticket events) are sent to a Dutiva-operated edge function pinned to the Canada (ca-central-1) region and stored in Dutiva's own database (Supabase, Section 1). They carry a daily-rotated anonymous identifier or a workspace (organization) identifier, never an individual user identifier, and are not shared with any third-party analytics provider. These events are collected only after the visitor consents through the consent banner.

Optional third-party website analytics: Google Tag Manager and Google Analytics 4 (Google LLC — United States). Where used, they load only after the visitor has granted consent through the consent banner. Tag Manager is the loader; GA4 may fire from that container, or from a measurement ID with IP anonymization enabled when Tag Manager is not configured.

7. Bot Protection and CAPTCHA

To protect public forms (such as beta-signup and support requests) from spam and automated abuse, Dutiva may use a CAPTCHA / bot-protection provider: Cloudflare, Inc. (Cloudflare Turnstile) by default, or Intuition Machines, Inc. (hCaptcha) where configured. When enabled, the provider evaluates technical signals from the visitor's browser — including IP address and interaction signals — to distinguish humans from automated clients. This protection is engaged only on public submission forms and only when bot-protection keys are configured. Cloudflare may also provide DNS, network-security, and availability services where used. Processing location: United States and global edge network.

TrustedSite (Halo Security) — Purpose: public-website security-scan trustmark. Data processed: visitor IP address and browser or device signals when the trustmark script loads on marketing pages. The signed-in workspace does not load this script. Processing location: United States.

8. Cross-Border Data Transfers

Most of Dutiva's subprocessors are based in the United States. Personal data transferred to U.S.-based subprocessors is subject to U.S. law, including potential access by U.S. government authorities under applicable surveillance laws. We select subprocessors that maintain appropriate technical and contractual safeguards, including data processing agreements aligned with PIPEDA requirements.

For Quebec residents: cross-border transfers of personal information are subject to requirements under Quebec Law 25 (Act Respecting the Protection of Personal Information in the Private Sector). We conduct privacy impact assessments for cross-border transfers where required and maintain documentation of transfer safeguards.

9. Subprocessor Changes

Dutiva will update this list when subprocessors are added, changed, or removed. We aim to provide reasonable notice of material changes to our subprocessor list. Enterprise customers with data processing agreements may be entitled to specific notice periods as set out in their agreement.

For questions about subprocessors or data transfers, contact privacy@dutiva.ca.