Trust & Compliance
Trust Center
Safe For The Office™ is designed using privacy-first principles, Canadian infrastructure, and minimal data collection. This section documents our practices for procurement reviewers, privacy officers, IT teams, and legal reviewers.
At A Glance
- Participant answers are never stored — not in a database, not in logs
- Participant identities are never persisted after a session ends
- All data is hosted in Canada (AWS ca-central-1)
- All connections are encrypted in transit (TLS)
- No advertising networks, no behavioural tracking, no third-party analytics
- Designed to support organizations operating under PIPEDA requirements
Policy Documents
Data Handling
What information is collected, what is not collected, and how participant data is handled during live sessions.
Read policy →
Data Retention
How long different categories of data are retained, our data minimization approach, and retention periods for operational records.
Read policy →
Data Security
Encryption, authentication controls, authorization model, secrets management, and audit logging practices.
Read policy →
Data Residency
Canadian hosting strategy, AWS ca-central-1 infrastructure, and what data remains within Canada.
Read policy →
Security Overview
High-level security posture for IT reviewers — authentication, access controls, deployment security, and responsible disclosure.
Read overview →
PIPEDA Alignment
How Safe For The Office™ is designed to support organizations operating under Canada's Personal Information Protection and Electronic Documents Act.
Read alignment →
Cookie Policy
What cookies are used, why they are used, and what is explicitly not used — including advertising and tracking cookies.
Read policy →
AI Policy
How AI is and is not used within Safe For The Office™, including participant data handling expectations and human oversight commitments.
Read policy →
Procurement Center
If you are completing a vendor assessment, security questionnaire, or privacy impact assessment, visit the Procurement Center for vendor information, pre-answered questionnaire responses, data flow documentation, and direct contact.
Procurement Questions
If you are completing a vendor assessment, security questionnaire, or privacy impact assessment and need information not covered here, contact us directly. We respond to every message personally.