Compliance & your rights
Last updated: July 2026 (Beta)
SOC 2
A SOC 2 examination is on our roadmap. We are not SOC 2 certified today and do not claim to be. Our current controls — self-hosted AI in Canada, encryption in transit, restricted database access, hash-chained review audit logs — are described across these Trust pages. We will state the examination status here honestly as it progresses.
Privacy Impact Assessments
Every external processor we send data to has a completed baseline privacy assessment before it goes live, and any new processor must pass a privacy-impact assessment — including a cross-border transfer assessment (Québec Law 25 s.17) where personal information would leave Canada — before it is switched on. The current processors, with their region and data class, are on our Subprocessors page.
Data governance high-watermark
Because your data is hosted in Québec, it is governed to the Québec Law 25 standard regardless of your matter’s province — Canada’s strictest provincial privacy regime. Our substantive templates cover Alberta and Ontario common law; Québec is our data region, not a supported drafting jurisdiction.
Your rights (access, correction, deletion)
Under PIPEDA, Alberta’s PIPA, and Québec’s Law 25 you may ask us to access, correct, or delete your personal information. You can delete documents and AI reviews from your account directly; for a full data-subject request, email support@docica.ca and we will respond within the statutory timeframe. When you delete an item it is removed from active systems promptly; see the Privacy Policy for how deletion propagates to encrypted backups.
Reporting a concern
To raise a privacy concern or reach our privacy contact, email support@docica.ca. You also have the right to contact your provincial or federal privacy commissioner.