Trust Center

PIPEDA Alignment

How Safe For The Office™ is designed to support organizations operating under Canada's Personal Information Protection and Electronic Documents Act.

Important Note

This page describes how Safe For The Office™ is designed to support PIPEDA-aligned operations. It does not constitute legal advice, and Safe For The Office™ does not claim formal PIPEDA certification or approval. Organizations with specific compliance obligations should consult their own legal and privacy counsel.

Overview

PIPEDA — the Personal Information Protection and Electronic Documents Act — is Canada's federal private-sector privacy law. It governs how organizations collect, use, and disclose personal information in the course of commercial activities.

Safe For The Office™ was designed with PIPEDA principles in mind. The platform's privacy-first architecture — particularly the decision to never persist participant data — directly supports the data minimization and purpose limitation principles at the core of PIPEDA.

Principle 1 — Accountability

Safe For The Office™ maintains an append-only administrative audit log that records all platform management actions. This log supports accountability by creating a durable record of who did what, when, and with what result. The audit log is retained for one year.

Facilitators remain responsible for how they use the platform in their workshops, including how they communicate with participants about data handling.

Principle 2 — Identifying Purposes

The purposes for which information is collected are limited and specific:

  • - Facilitator email address — used for authentication and account communication
  • - Participant display name — used to identify the participant within a live session only
  • - Participant responses — used to operate the live workshop activity only
  • - Room records — used to support facilitator session history

Information is not collected for secondary purposes such as advertising, profiling, or resale.

Principle 3 — Consent

Participants join a workshop session voluntarily by entering a display name. No account, email address, or registration is required. The act of joining constitutes consent to participate in the session.

Facilitators are responsible for informing participants about the nature of the workshop activities and any organizational policies that apply to workshop participation.

Principle 4 — Limiting Collection

Safe For The Office™ collects the minimum information necessary to operate the platform:

  • - Participant email addresses are never collected
  • - Participant IP addresses are not logged
  • - No device identifiers or fingerprints are collected
  • - No behavioural tracking data is collected

The platform does not collect information beyond what is required to run a workshop session.

Principle 5 — Limiting Use, Disclosure, and Retention

Information collected by Safe For The Office™ is used only for the purposes identified above. It is not shared with third parties for commercial purposes, not used for advertising, and not sold.

Participant data is not retained after a session ends — it is cleared from server memory when the session closes. There is no retention period because there is nothing to retain.

Facilitator account data is retained while the account is active. Operational records (audit log, room records) are retained for defined periods as described in the Data Retention policy.

Principle 6 — Accuracy

Facilitators can update their account information through the facilitator portal. Account records reflect the information provided by the facilitator.

Principle 7 — Safeguards

Safe For The Office™ implements technical safeguards appropriate to the sensitivity of the information held:

  • - All connections encrypted in transit using TLS
  • - Passwords stored using scrypt — a memory-hard hashing algorithm
  • - Database credentials stored in AWS Secrets Manager — not in code
  • - Database hosted in a private network — not directly accessible from the internet
  • - Role-based access control with database-authoritative enforcement
  • - All data hosted in Canada (AWS ca-central-1)

For a complete description of security controls, see the Data Security policy.

Principle 8 — Openness

This Trust Center documents Safe For The Office™'s data handling practices in plain language. The policies are publicly accessible and describe what information is collected, how it is used, and how it is protected.

Principle 9 — Individual Access

Facilitators can access their account information through the facilitator portal. Requests to access, correct, or delete account information can be submitted via the contact form. We will respond to access requests within a reasonable timeframe.

Participant data cannot be accessed after a session ends because it is not retained. There is no record to retrieve.

Principle 10 — Challenging Compliance

Questions or concerns about Safe For The Office™'s data handling practices can be directed to us via the contact form. We take privacy concerns seriously and will respond to every inquiry.

For Privacy Officers and Legal Reviewers

If you are completing a Privacy Impact Assessment (PIA) or vendor privacy review and require additional documentation, contact us directly. We can provide written responses to specific questions about our data handling practices.

Contact us for privacy documentation →

Last reviewed: October 2026