Which privacy laws does Corpshore operate under by default?+
PIPEDA, Canada's federal private-sector privacy law, applies by default to Canadian delivery, and Quebec Law 25, the most demanding privacy law in the country, applies to Quebec engagements. Provincial laws in Alberta and British Columbia, and Ontario PHIPA for health data, apply according to scope, which we confirm for your engagement rather than assume.
Does Corpshore comply with GDPR?+
Where an engagement involves the personal data of European Union data subjects, processing is aligned to GDPR principles, with the controller and processor roles, lawful basis and international transfer safeguards set out in the contract and its data processing terms. GDPR is applied according to scope rather than claimed universally, and your counsel should confirm the arrangement.
How does Corpshore handle accessibility obligations?+
Customer-facing delivery follows accessible service practices and digital deliverables follow WCAG 2.1 AA aligned practices, which support your obligations under AODA in Ontario and the Accessible Canada Act federally. Accessibility is treated as a design requirement rather than an afterthought, so the work supports rather than undermines your own accessibility position.
What compliance documentation can we request during due diligence?+
You can request the data processing terms, a description of safeguards and access controls, the cross-border transfer position for your engagement, the breach notification process and the roles accountable for compliance. Regime-specific items, such as the Law 25 posture or the GDPR processor commitments, are available for the frameworks your engagement engages.
Does CASL affect outsourced marketing and outreach?+
Yes, where delivery includes commercial electronic messaging on your behalf. The work is run to your consent records and CASL obligations, with sender identification and a functioning unsubscribe mechanism built into the process. You can request the consent-handling approach and the record-keeping method used for messaging performed on your behalf.
Do you hold specific security certifications?+
This page describes our posture in terms of governance and process rather than listing certifications we cannot substantiate here. Where an engagement requires a specific attestation or audit, that is addressed directly in the contract and its schedules. We would rather commit to what we can document than claim a badge we cannot stand behind.
Is this page legal advice we can rely on?+
No. It is general information about the compliance frameworks a Canadian engagement may touch, not legal advice. The specific commitments for your engagement are set out in the contract and its schedules and should be reviewed by your own counsel. What we commit to here is that the applicable position is documented and shared before go-live.