Data Residency & Transfers
This Data Residency & Transfers document is published by the Company. The Company's full identity, address, and legal contact details appear at the bottom of this page.
This policy explains where your data is hosted, the circumstances under which certain subprocessors may process it outside Québec, and the safeguards that govern such transfers. It is addressed to our organizational Customers as well as to users who interact with the Service. It complements our Privacy Policy and our Data Processing Agreement, both of which are referenced throughout this text.
> In short — Your data is hosted in North America. Certain specialized providers (notably those related to artificial intelligence) may process data elsewhere in the world, always under contracts governing its protection. You retain your rights at all times, regardless of where a given piece of data transits.
Table of Contents
- Where Your Data Is Hosted
- Transfers to Subprocessors Located Elsewhere
- Safeguards Governing These Transfers
- Your Rights Regarding International Transfers
- Changes to This Policy
1. Where Your Data Is Hosted
> In short — The Service's core infrastructure — database, authentication, storage, and application hosting — is located in North America, with recognized cloud infrastructure providers.
The core infrastructure underlying the Service, including the database, authentication mechanisms, file storage, and application hosting, is operated in North America, through our cloud infrastructure providers.
These providers operate data centers distributed according to their own engineering practices, notably for purposes of redundancy and service continuity. The Company does not publicly confirm a precise hosting region (for example, a specific geographic zone within North America), as this information pertains to the internal technical architecture of its providers and may change over time without affecting the general location described above.
The choice of our infrastructure providers is based on reliability, security, and performance criteria recognized within the industry. We encourage Customers with particular data-location requirements to raise them with us before entering into an agreement, so that we can clarify what can reasonably be confirmed given their context.
2. Transfers to Subprocessors Located Elsewhere
> In short — To offer certain features, particularly those relying on artificial intelligence, we engage specialized subprocessors, some of which may process data outside Québec, or even outside Canada.
For certain specific features, the Service integrates specialized subprocessors whose infrastructure is not necessarily limited to North America. This is notably the case for the following categories:
- providers of artificial intelligence models used for text and voice processing within conversational agents;
- text-to-speech providers;
- video avatar generation providers;
- the third-party messaging gateway, when the Customer chooses to connect an external messaging account to the Service.
These categories of subprocessors may, depending on their own architecture and operations, process data outside the province of Québec, or even outside Canada. This is a general reality of data processing by specialized providers on an international scale, not a practice specific to any particular provider. The Company does not disclose, in this policy, the list of specific countries involved, as this information evolves with the technologies used.
The current list of subprocessors that may process personal data on the Company's behalf, including their respective roles, is available in our Subprocessor List. We invite you to consult it to learn which categories of providers are involved in processing outside Québec or outside Canada.
3. Safeguards Governing These Transfers
> In short — Before any transfer, each subprocessor undergoes a contractual assessment, and data protection clauses are imposed on it, in accordance with the requirements of Law 25 and PIPEDA.
In accordance with An Act respecting the protection of personal information in the private sector (Law 25, Québec) and the Personal Information Protection and Electronic Documents Act (PIPEDA, federal), any transfer of personal data to a third party located outside Québec, or to a third party that could itself process data outside Canada, is subject to a prior assessment.
This assessment aims to ensure that personal information will receive, at the recipient's location, protection considered equivalent to what it would receive if it remained processed in Québec. In practice, this means that:
- each subprocessor undergoes a contractual assessment before any data transfer;
- appropriate data protection clauses are incorporated into the agreements entered into with these subprocessors, governing in particular the use, retention, security, and any subsequent subprocessing of the data;
- each subprocessor is bound by specific obligations regarding confidentiality, the technical and organizational security of the data, and notification in the event of an incident affecting the data it processes on our behalf;
- these obligations apply regardless of the physical location where the subprocessor carries out its activities.
The entirety of this contractual framework is detailed in our Data Processing Agreement, which governs the relationship between the Company and its organizational Customers acting as controllers of the data of their own contacts, and which requires the Company to have substantially equivalent obligations enforced, by separate contract, against each of its own subprocessors.
4. Your Rights Regarding International Transfers
> In short — The fact that a piece of data is processed by a subprocessor located elsewhere in no way reduces your rights. These remain described in detail in our Privacy Policy.
The fact that a category of subprocessors may process data outside Québec or Canada does not diminish the rights you hold with respect to your personal information. These rights — notably the rights of access, rectification, withdrawal of consent, and, where applicable, portability — are exercised in the same manner, regardless of where a particular piece of data was processed at a given time.
The details of these rights, as well as the procedure for exercising them, are described in our Privacy Policy.
Furthermore, when the Customer uses the Service to interact with its own contacts or end users (for example, through a conversational agent), the Customer may itself be considered a controller of the data of those individuals. It is then up to the Customer to ensure that its own data-transfer practices, including those arising from its use of the Service, comply with the obligations incumbent upon it under applicable laws. This policy describes the framework put in place by the Company with respect to its own infrastructure and its own subprocessors; it does not replace the assessment the Customer must carry out regarding its own obligations.
5. Changes to This Policy
> In short — This policy may be updated from time to time. The version in force is always the one published on this page.
We may modify this policy from time to time, notably to reflect the evolution of our infrastructure, the addition or replacement of subprocessors, or changes to the applicable regulatory framework. The version in force is the one published on this page, which indicates its last update date.
In the event of a significant change affecting the general location where your data is processed or the categories of subprocessors involved, we will make reasonable efforts to bring this change to the attention of affected Customers, through the usual means of communication provided for in our agreements. We invite you to consult this page periodically.