Transparency

Privacy policy

How Dossio handles the personal information of users, visitors and anyone who contacts us — and what we do not do with it.

Draft — this document is not in force

This text is a draft under review and binds no one. Some of its sentences describe in the present tense measures that are still to be put in place. Still missing:

  • incorporating the company and recording its legal name, its NEQ and its head office
  • the privacy impact assessment for each communication outside Quebec (s. 17)
  • the written processing agreements with each of the processors
  • opening the confidentiality incident register

1. Two very different roles — read the one that concerns you

Dossio holds two categories of information that do not follow the same rules. Confusing the two is the first thing a lawyer will check, so it leads this policy rather than sitting in a footnote.

  • Your own information, as our user. Your account, your communications with us, the billing of your subscription, your beta signup. We are the person in charge (controller) of it. This entire policy applies to it, and you exercise your rights with us.
  • The information your firm records in its matters. The names, contact details and circumstances of the lawyer’s clients, of opposing parties, of witnesses. The firm is the person in charge of it; we are only its mandatary (processor) within the meaning of section 18.3 of the Act respecting the protection of personal information in the private sector. We handle it solely on the firm’s instructions, to provide it the service, and for nothing else.

If you are a firm’s client and you wish to consult, correct or destroy what concerns you in a matter, speak to your lawyer. We are not permitted to answer you directly: that matter is covered by professional secrecy, and we are not its master. We will forward your request to the firm concerned if you write to us.

2. Who is in charge, and how to reach them

Dossio is operated by [legal name to be completed]. In accordance with section 3.1 of the Act, the person having the responsibility for the protection of personal information is Gabriel Siles, person in charge of the protection of personal information. You can reach them at bonjour@dossio.ca, with “personal information” in the subject line.

3. The information we collect

As the person in charge, we handle:

  • Your account — name, professional email address, password in hashed form, authentication factors, the firm you belong to, your role and your access rights.
  • Your subscription — billing details, payment history. Card numbers are handled by our payment provider and never pass through our servers.
  • Your communications with us — support requests, emails, reports.
  • Your beta signup, where applicable — name, email, profession, firm size, and the software you currently use (optional). The date of your consent is recorded, and so is the date of its withdrawal if you withdraw it.
  • Technical and security logs — sign-ins, access attempts, document views and downloads, with the timestamp and the identity of the user. They serve to detect unauthorized access and to answer for a contested access.
  • An anti-abuse counter on the public form. We record no IP address: only a cryptographic fingerprint computed with a secret key, from which the address cannot be recovered. It serves solely to stop a script from flooding the form, and it is destroyed automatically after seven days.

4. Why we use it

Each purpose is distinct, and we do not take information collected for one purpose and put it to another without asking you:

  • to provide the service, authenticate users and carry out the functions requested;
  • to secure the service, detect and prevent unauthorized access and abuse;
  • to administer the subscription, bill and collect;
  • to offer support and answer your requests;
  • to give you access to the beta and tell you how it is progressing;
  • to meet our legal obligations.

We do not sell or rent personal information. We do not use it to train, fine-tune or evaluate an artificial intelligence model. We do no targeted advertising and no profiling.

5. Consent, and how to withdraw it

Where we rely on your consent — the beta signup and our communications, in particular — it is requested for a specific purpose, in plain terms, at the moment of collection. You may withdraw it at any time by writing to bonjour@dossio.ca. We then stop writing to you. We do keep a record that consent existed and of the date it was withdrawn: that is what lets us demonstrate we respected your choice. The processing needed to perform your subscription rests not on consent but on the contract, and ends with it.

6. Cookies and analytics

Dossio uses only the cookies strictly necessary for sign-in, security and keeping your session alive. We use no advertising cookies, no third-party trackers and no analytics tool — neither Google Analytics nor any equivalent. That is why you see no cookie consent banner on this site: there is nothing to consent to. Before adding any non-essential analytics, we will publish the required information and seek the applicable consent.

7. Providers, and processing outside Quebec

We rely on providers for hosting, authentication, storage, sending email, billing and error detection. Each one is named on the Where your data lives page, with its country of incorporation, the region where it hosts, and the categories of data it handles. That page is the complete list, not a summary, and we keep it current with every addition.

Some of these providers are American companies even when the data remains hosted in Montreal, and are on that basis subject to the CLOUD Act. Section 17 of the Act requires that any communication outside Quebec be the subject of a privacy impact assessment before it is put into service. We carry out that assessment for each provider and keep it current; its content must match the Where your data lives page exactly, and if one changes, the other changes the same day.

Each provider is bound by a written agreement limiting the use of the information to what we ask of it. None has the right to use it for its own purposes.

8. How long we keep it

Section 23 of the Act requires that information be destroyed or anonymized once the purpose of its collection is accomplished. Here are our schedules, rather than a vague formula:

  • Anti-abuse counter fingerprints: seven days, destroyed by an automatic task that runs every night. It is the only schedule on this list that already runs without human intervention.
  • Account and firm data: 90 days after closure, a window during which you can still recover your data, then destruction or anonymization.
  • Beta signups: up to 12 months after the programme ends, or sooner if you withdraw your consent, except for the proof of consent and of its withdrawal.
  • Audit and security logs: seven years. They are append-only — they can be neither modified nor deleted, not even by us. That is what gives them evidentiary value the day an access is contested, and it is also why they outlive the closure of the account.
  • Billing data: seven years, per tax requirements.
  • Backups: up to 30 days. Data destroyed from the live database may survive in a backup until its cycle expires. We never restore a backup to recreate data destroyed at someone’s request.

9. Your rights

As regards the information for which we are the person in charge, you may:

  • access it and obtain communication of it;
  • have it corrected if it is inaccurate, incomplete or equivocal;
  • withdraw your consent, where the processing rests on it;
  • obtain its portability — receive it in a structured, commonly used technological format, or ask us to transfer it to a third party (s. 27);
  • request its destruction, or the cessation of its dissemination and the de-indexing of a hyperlink, in the cases provided for by law (s. 28.1).

Write to bonjour@dossio.ca. We answer with diligence and no later than within 30 days. We will need to verify your identity before answering — that is a protection for you, not an obstacle. Our answers are free of charge; a refusal is given in writing with reasons, and with the available recourses.

If our answer does not satisfy you, you may apply to the Commission d’accès à l’information du Québec, which can examine a disagreement and receive a complaint.

10. Automated decisions and artificial intelligence

Dossio makes no decision today based exclusively on automated processing, and includes no artificial intelligence feature. The deadline calculator applies public, verifiable rules of the Code of Civil Procedure: that is not a decision about you, and its result remains subject to the lawyer’s verification. Should we ever introduce such a feature, we will update this policy the very day it goes into service, naming the provider, the processing region and what becomes of the data sent. Section 12.1 of the Act then gives you the right to be informed of it, to know the principal factors behind the decision, and to submit observations to a person.

11. Security

We apply, among other things, mandatory two-factor authentication — enforced by the database itself and not only by the interface —, encryption in transit and at rest, strict isolation of firms at the database level, entirely private document storage reachable only through a short-lived signed link, limited access rights and an append-only audit log. No measure removes risk entirely; we revisit these controls as the service evolves.

12. Confidentiality incidents

We keep a register of confidentiality incidents. In the event of an incident presenting a risk of serious injury, we notify the Commission d’accès à l’information and the persons concerned with diligence, and we take measures to reduce its consequences and prevent it recurring. If the incident touches a firm’s data, we notify the firm — it is the person in charge towards its own clients, and the decision to inform them is its own.

13. Changes to this policy

We will publish any change on this page, with a new version number and a new date. A significant change will be announced to you by email before it takes effect. Earlier versions remain available on request: knowing what changed and when is worth as much as the current text.

This policy applies together with the terms of use and the Where your data lives page, which names each of our providers.

Version 2.0 — last updated: August 13, 2026.