Passer au contenu

Ce contenu français est une version de travail en attente d'une révision par un locuteur natif du français québécois avant le lancement.

Corpshore Canada

Mentions légales

Data governance and cross-border transfers

How Corpshore Canada governs personal information across the group, the providers that process it, where it flows, and the safeguards that apply, including for EU and UK data subjects.

Dernière mise à jour:

Ce document est rédigé selon une norme professionnelle canadienne. Il doit être révisé par le conseiller juridique de l'organisation avant d'être invoqué et ne constitue pas un avis juridique.

1. Purpose of this notice

This notice explains how Corpshore Canada, the Canadian operation of Corpshore Solutions Corporation, governs personal information, where that information flows, and the safeguards we apply when it is processed outside Canada. It supports the transparency that PIPEDA requires about the use of service providers and about cross-border processing, and it addresses the position of individuals in the European Union and the United Kingdom whose data we handle on our own account. It supplements our privacy policy and candidate privacy notice. Our Privacy Officer can be reached at privacy@corpshore.ca, and our head office is at The Exchange Tower, 130 King Street West, Suite 1900, Toronto, Ontario M5X 2A2, Canada.

1a. Who is responsible

Corpshore Canada is the Canadian operation of Corpshore Solutions Corporation. It is the organisation accountable for the personal information it collects through this site, and our Privacy Officer is accountable for our compliance with privacy law and for the governance described here. This notice concerns the personal information we handle on our own account, not personal information we process for a client under a service engagement.

2. Accountability and governance

We are accountable for personal information in our custody or control, including information we transfer to a service provider for processing. Our Privacy Officer oversees our privacy programme, which includes this notice and the related policies, a record of the providers we use, contractual data-protection terms with those providers, security safeguards, an intake process for access and correction requests, and a breach-response process. Where Quebec Law 25 applies, our Privacy Officer also carries the function of the person in charge of the protection of personal information.

3. Privacy by design and privacy impact assessments

We consider privacy at the design stage of new features and integrations, collecting the minimum personal information needed and defaulting to the most protective settings. Where a project involves the acquisition, development or overhaul of a system that processes personal information, or a transfer of personal information outside Quebec that engages Quebec Law 25, we conduct a privacy impact assessment proportionate to the sensitivity of the information and the purpose, and we take its findings into account before proceeding. A privacy impact assessment considers the personal information involved, the purposes and necessity of the processing, the parties who will have access, the safeguards that apply, the risks to individuals, and the measures needed to reduce those risks to an acceptable level.

3a. Controller and processor roles

We are clear about the capacity in which we handle personal information. When we collect personal information through this site for our own purposes, such as responding to an enquiry or evaluating an application, we are the organisation accountable for it and we decide how it is used. When we handle personal information on behalf of a client as part of a service engagement, we act as a service provider under the client's instructions, and our contract with the client, not this notice, governs that processing. This notice concerns the personal information we handle on our own account.

4. The providers that process personal information for us

We use the following service providers, each of which processes personal information on our behalf under contractual terms that restrict use to our instructions and require appropriate security and confidentiality:

  • Zoho CRM (records of client and prospective-client enquiries, proposal requests and discovery-call bookings), operated by Zoho Corporation.
  • Zoho Recruit (records of candidates and members of our talent community), operated by Zoho Corporation.
  • Zoho Campaigns (delivery of newsletters and marketing email you have expressly asked to receive, and the related consent and unsubscribe records), operated by Zoho Corporation.
  • Vercel (hosting, content delivery and privacy-respecting traffic measurement), operated by Vercel, Inc.
  • Cloudflare Turnstile (bot and abuse protection on our forms), operated by Cloudflare, Inc.
  • Resend (transactional email such as confirmation and acknowledgement messages), operated by Resend when enabled.
  • Calendly (scheduling of discovery calls), operated by Calendly, LLC, when you choose to book a call.
  • Google Analytics and Microsoft Clarity (aggregate usage and interaction measurement), loaded only after you accept analytics cookies.

5. Where personal information is processed

Several of these providers store or process personal information outside Canada. Zoho stores data in the region configured for our account and may process it in other regions for support and continuity. Vercel, Cloudflare, Resend, Calendly and the analytics providers operate globally and may process data in the United States and elsewhere. This means that personal information you provide to us may be processed outside Canada, and while it is in another country it may be accessible to the courts, law enforcement and national security authorities of that country under that country's laws, which may differ from Canadian law.

6. Safeguards for cross-border processing

We remain accountable for personal information we transfer to a provider for processing, regardless of where the provider operates. We use contractual and technical safeguards to require a comparable level of protection, including data-processing agreements, confidentiality and security commitments, and, where personal information originates in the European Union or the United Kingdom, the European Commission's Standard Contractual Clauses and the United Kingdom International Data Transfer Addendum, supported by additional measures where needed. We assess a provider's safeguards before we engage it and we monitor them during the relationship.

Consistent with PIPEDA, using a provider in another country to process personal information does not require your separate consent, because we remain accountable and the transfer is for processing on our behalf. We are transparent about it instead, which is the purpose of this notice. Where Quebec Law 25 applies to a transfer of personal information outside Quebec, we assess, before the transfer, whether the information would receive adequate protection having regard to the sensitivity of the information, the purposes, the safeguards in place and the legal framework of the destination, and we proceed only where that assessment supports it.

6a. Security safeguards

Across the group we protect personal information with physical, organisational and technical safeguards proportionate to its sensitivity. These include encryption of personal information in transit, access on a least-privilege and need-to-know basis, authentication controls, logging and monitoring, secure software development and delivery, rate limiting and bot protection on public forms, and a process for managing providers and their sub-processors. We keep these safeguards under review and improve them as risks and technology change.

7. European Union and United Kingdom data subjects

Where we process the personal data of individuals in the European Union or the United Kingdom on our own account, for example when an individual in those regions contacts us or applies for a role, we do so in accordance with the General Data Protection Regulation and the United Kingdom GDPR. Our lawful bases are: the taking of steps at your request before entering into a contract; our legitimate interests in operating, securing and growing our business, balanced against your rights; your consent for analytics and marketing; and compliance with a legal obligation. You have the rights of access, rectification, erasure, restriction, objection and portability, and the right to withdraw consent, as those regulations provide. You may exercise them by contacting privacy@corpshore.ca, and you may complain to your local supervisory authority.

8. Canada's adequacy position

The European Commission recognises PIPEDA as providing an adequate level of protection for personal data transferred from the European Union to organisations in Canada that are subject to it, which supports the lawful transfer of personal data from the European Union to us in Canada. We monitor developments in this area, including any review of that adequacy status, and will update our safeguards if the position changes. Where personal data reaches us in Canada under this adequacy recognition and is then processed by a provider outside Canada, we apply the transfer safeguards described in section 6 for that onward processing, so that the protection travels with the data.

9. Retention and disposal across the group

We keep personal information only for the periods set out in our privacy policy and candidate privacy notice, and we require our providers to delete or return personal information at the end of our engagement with them, subject to any retention the law requires. When personal information is no longer needed we destroy, erase or anonymise it using methods appropriate to its sensitivity and the medium on which it is held.

9a. Confidentiality incidents and breach response

We maintain a process to detect, contain, assess and respond to confidentiality incidents and breaches of security safeguards. Where a breach creates a real risk of significant harm, we notify the Office of the Privacy Commissioner of Canada and the affected individuals, and we keep the records PIPEDA requires. Where Quebec Law 25 applies, we notify the Commission d'acces a l'information du Quebec and the individuals concerned where the incident presents a risk of serious injury, and we maintain a register of confidentiality incidents. We require our providers to tell us promptly of any incident affecting personal information they process for us so that we can meet these obligations.

9b. Records and accountability documents

We keep the documents that demonstrate our accountability, including this notice and the related policies, our record of providers and the categories of personal information each one processes, our contractual data-protection terms, our privacy impact assessments, and our records of access, correction and rights requests. These records let us show, on request, how we govern personal information and meet our obligations.

10. Sub-processors and changes

Our providers may use their own sub-processors to deliver their services. We require them to impose equivalent data-protection obligations on those sub-processors and to remain responsible for them. We may add or change providers as our site and services evolve. When we do, we assess the new provider's safeguards and, where a change materially affects how your personal information is processed, we update this notice.

10a. Group-wide governance and consistency

Corpshore Canada is part of a group headquartered in Toronto, and we apply consistent governance across the group so that personal information receives a comparable standard of protection wherever a group entity handles it on our behalf. Where personal information moves within the group to respond to your request or to deliver a service, it does so under that consistent governance and only where it is necessary. Group entities that process personal information for us are subject to the same expectations we set for external providers, including on purpose limitation, security, retention and cross-border safeguards.

11. Contact and complaints

For any question about our data governance or cross-border processing, or to exercise your rights, contact our Privacy Officer at privacy@corpshore.ca. You may complain to the Office of the Privacy Commissioner of Canada, to the Commission d'acces a l'information du Quebec if you are in Quebec, to the Office of the Information and Privacy Commissioner of Alberta or British Columbia where that province's law applies, or to your local supervisory authority in the European Union or the United Kingdom. We would welcome the opportunity to resolve your concern first.