Transparency
Privacy policy
How Dossio handles the personal information of users, visitors and anyone who contacts us — and what we do not do with it.
Draft — this document is not in force
This text is a draft under review and binds no one. Some of its sentences describe in the present tense measures that are still to be put in place. Still missing:
- incorporating the company and recording its legal name, its NEQ and its head office
- the privacy impact assessment for each communication outside Quebec (s. 17)
- the written processing agreements with each of the processors
- opening the confidentiality incident register
1. Two very different roles — read the one that concerns you
Dossio holds two categories of information that do not follow the same rules. Confusing the two is the first thing a lawyer will check, so it leads this policy rather than sitting in a footnote.
- Your own information, as our user. Your account, your communications with us, the billing of your subscription, your beta signup. We are the person in charge (controller) of it. This entire policy applies to it, and you exercise your rights with us.
- The information your firm records in its matters. The names, contact details and circumstances of the lawyer’s clients, of opposing parties, of witnesses. The firm is the person in charge of it; we are only its mandatary (processor) within the meaning of section 18.3 of the Act respecting the protection of personal information in the private sector. We handle it solely on the firm’s instructions, to provide it the service, and for nothing else.
If you are a firm’s client and you wish to consult, correct or destroy what concerns you in a matter, speak to your lawyer. We are not permitted to answer you directly: that matter is covered by professional secrecy, and we are not its master. We will forward your request to the firm concerned if you write to us.
2. Who is in charge, and how to reach them
Dossio is operated by [legal name to be completed]. In accordance with section 3.1 of the Act, the person having the responsibility for the protection of personal information is Gabriel Siles, person in charge of the protection of personal information. You can reach them at info@dossio.ca, with “personal information” in the subject line.
3. The information we collect
As the person in charge, we handle:
- Your account — name, professional email address, password in hashed form, authentication factors, the firm you belong to, your role and your access rights.
- Your subscription — billing details, payment history. Card numbers are handled by our payment provider and never pass through our servers.
- Your communications with us — support requests, emails, reports.
- Your beta signup, where applicable — name, email, profession, firm size, and the software you currently use (optional). The date of your consent is recorded, and so is the date of its withdrawal if you withdraw it.
- Technical and security logs — sign-ins, access attempts, document views and downloads, with the timestamp and the identity of the user. They serve to detect unauthorized access and to answer for a contested access.
- An anti-abuse counter on the public form. We record no IP address: only a cryptographic fingerprint computed with a secret key, from which the address cannot be recovered. It serves solely to stop a script from flooding the form, and it is destroyed automatically after seven days.
4. Why we use it
Each purpose is distinct, and we do not take information collected for one purpose and put it to another without asking you:
- to provide the service, authenticate users and carry out the functions requested;
- to secure the service, detect and prevent unauthorized access and abuse;
- to administer the subscription, bill and collect;
- to offer support and answer your requests;
- to give you access to the beta and tell you how it is progressing;
- to meet our legal obligations.
We do not sell or rent personal information. We do not use it — and our processing provider has no right to use it — to train, fine-tune or evaluate an artificial intelligence model. We do no targeted advertising and no profiling. The matter-summary feature is covered in section 11.
5. Consent, and how to withdraw it
Where we rely on your consent — the beta signup and our communications, in particular — it is requested for a specific purpose, in plain terms, at the moment of collection. You may withdraw it at any time by writing to info@dossio.ca. We then stop writing to you. We do keep a record that consent existed and of the date it was withdrawn: that is what lets us demonstrate we respected your choice. The processing needed to perform your subscription rests not on consent but on the contract, and ends with it.
6. Cookies and analytics
Dossio uses only the cookies strictly necessary for sign-in, security and keeping your session alive. We use no advertising cookies, and no tracker that would follow you from one site to another. We use neither Google Analytics, nor Microsoft Clarity, nor any tool of that kind.
The public pages — the home page, the terms, this page and "Where your data lives" — count their visits with Vercel Web Analytics, provided by our host. That measurement sets no cookie, writes no persistent identifier on your device and builds no profile: it aggregates page views and referrers, without telling you apart from any other visitor.
It runs nowhere else. The pages behind sign-in — your matters, your contacts, your invoices, your documents — are not measured, and their addresses are transmitted to no one. That limit is written into the code, not set by a toggle.
That is why you see no cookie consent banner on this site: there is no non-essential cookie to consent to. The day we add a measurement that sets one, we will publish the required information and seek the applicable consent before putting it into service.
7. Providers, and processing outside Quebec
We rely on providers for hosting, authentication, storage, sending email, billing and error detection. Each one is named on the Where your data lives page, with its country of incorporation, the region where it hosts, and the categories of data it handles. That page is the complete list, not a summary, and we keep it current with every addition.
Some of these providers are American companies even when the data remains hosted in Montreal, and are on that basis subject to the CLOUD Act. Section 17 of the Act requires that any communication outside Quebec be the subject of a privacy impact assessment before it is put into service. We carry out that assessment for each provider and keep it current; its content must match the Where your data lives page exactly, and if one changes, the other changes the same day.
Each provider is bound by a written agreement limiting the use of the information to what we ask of it. None has the right to use it for its own purposes.
8. External calendars: what Google and Microsoft receive
This section applies only to firms that connect an Outlook or Google Calendar account inside Dossio. Connecting is optional, it is done account by account, and nothing leaves until a lawyer has authorised it with their own provider.
It is the only feature of Dossio that sends information outside Canada, so we describe it in detail rather than in principle.
- What we ask for. A single authorisation: to read and write the events of your calendar (“calendar.events” at Google). We do not ask to manage your calendars, nor for your contacts, your email or your files. We also read your account address, for one purpose only: showing on screen which account is connected.
- What we send. Entries created in Dossio. Depending on your firm’s setting, they leave with their title, matter number, location and note — or under a fixed title, “Dossio — busy”, which reveals only a time slot. That setting is on screen, applies to the whole firm, and a partner changes it in one click.
- What we keep from YOUR calendar, and this is the important part. The time slot only. An appointment read at Google or Microsoft is stored in Dossio under a fixed title — “Busy (external calendar)” — with no real title, no location, no description and no attendees. This is not a setting anyone could change: the function that writes those entries takes no title parameter at all. Your dentist, the school run or a family dinner never enter the firm’s database.
- How access tokens are held. Encrypted with AES-256-GCM using a key that is not in the database, and stored in a sealed table: no access policy, no privilege granted to anyone. Three server functions touch them, and nothing else.
- What we do with it. Show your scheduling conflicts, and keep your two calendars in agreement. Nothing more.
- What we share: nothing. No calendar data is passed to a third party, sold, used for advertising, or used to build a profile or train an artificial-intelligence model.
- How to end it. Disconnecting the account destroys the tokens — the row is deleted from the database, not merely flagged. You can also remove Dossio’s access from your Google or Microsoft account settings. When a firm closes, the connections, the tokens and the mirrored entries are purged with everything else.
Dossio’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
9. How long we keep it
Section 23 of the Act requires that information be destroyed or anonymized once the purpose of its collection is accomplished. Here are our schedules, rather than a vague formula:
- Anti-abuse counter fingerprints: seven days, destroyed by an automatic task that runs every night. It is the only schedule on this list that already runs without human intervention.
- Account and firm data: 90 days after closure, a window during which you can still recover your data, then destruction or anonymization.
- Beta signups: up to 12 months after the programme ends, or sooner if you withdraw your consent, except for the proof of consent and of its withdrawal.
- Audit and security logs: seven years. They are append-only — they can be neither modified nor deleted, not even by us. That is what gives them evidentiary value the day an access is contested, and it is also why they outlive the closure of the account.
- Billing data: seven years, per tax requirements.
- Backups: up to 30 days. Data destroyed from the live database may survive in a backup until its cycle expires. We never restore a backup to recreate data destroyed at someone’s request.
10. Your rights
As regards the information for which we are the person in charge, you may:
- access it and obtain communication of it;
- have it corrected if it is inaccurate, incomplete or equivocal;
- withdraw your consent, where the processing rests on it;
- obtain its portability — receive it in a structured, commonly used technological format, or ask us to transfer it to a third party (s. 27);
- request its destruction, or the cessation of its dissemination and the de-indexing of a hyperlink, in the cases provided for by law (s. 28.1).
Write to info@dossio.ca. We answer with diligence and no later than within 30 days. We will need to verify your identity before answering — that is a protection for you, not an obstacle. Our answers are free of charge; a refusal is given in writing with reasons, and with the available recourses.
If our answer does not satisfy you, you may apply to the Commission d’accès à l’information du Québec, which can examine a disagreement and receive a complaint.
11. Automated decisions and artificial intelligence
Dossio makes no decision based exclusively on automated processing. The deadline calculator applies public, verifiable rules of the Code of Civil Procedure: that is not a decision about you, and its result remains subject to the lawyer’s verification. Section 12.1 of the Act therefore does not apply; were it to apply, you would have the right to be informed of it, to know the principal factors behind the decision, and to submit observations to a person.
Since 23 August 2026, Dossio includes an AI matter-summary feature. It is a feature of the software, described in the contract you accept when you sign up — not an option your firm turns on: it exists for every subscriber. An individual matter can be kept out of it, from that matter’s own page, by any lawyer in the firm — and none of its content is then transmitted. Until a summary has been requested and a document has been uploaded, nothing has been transmitted: those two acts send text, not the existence of the feature. A summary makes no decision: it produces text that a lawyer reads, verifies document by document, and chooses whether or not to keep.
Here is what happens then, and nothing else. The text of the matter’s documents — extracted from them, or recognized if they are scans — is sent for reading to Amazon Web Services, region ca-central-1 (Montreal), through the Amazon Bedrock service. That is the same processor and the same region as our email and our text recognition: no provider is added to the list on the [Where your data lives](/en/where-your-data-lives) page, and processing stays in Canada. The provider does not keep the text after answering and has no right to use it to train, fine-tune or evaluate a model. Invocation logging, which would retain the text sent, is disabled.
Before sending, your client’s name and those of the parties recorded on the matter are replaced by labels, then restored on receipt. This is not anonymization: a name written in a document but not recorded on the matter goes out with the text, and we say so rather than let you believe otherwise. Never sent: fees, invoices, time entries, the firm’s internal notes, or any document from another matter.
Every request is written to the firm’s audit log — who made it, for which matter, how many documents, when — and that log is available to the firm itself.
12. Security
We apply, among other things, mandatory two-factor authentication — enforced by the database itself and not only by the interface —, encryption in transit and at rest, strict isolation of firms at the database level, entirely private document storage reachable only through a short-lived signed link, limited access rights and an append-only audit log. No measure removes risk entirely; we revisit these controls as the service evolves.
13. Confidentiality incidents
We keep a register of confidentiality incidents. In the event of an incident presenting a risk of serious injury, we notify the Commission d’accès à l’information and the persons concerned with diligence, and we take measures to reduce its consequences and prevent it recurring. If the incident touches a firm’s data, we notify the firm — it is the person in charge towards its own clients, and the decision to inform them is its own.
14. Changes to this policy
We will publish any change on this page, with a new version number and a new date. A significant change will be announced to you by email before it takes effect. Earlier versions remain available on request: knowing what changed and when is worth as much as the current text.
This policy applies together with the terms of use and the Where your data lives page, which names each of our providers.
Version 2.0 — last updated: .