Compliance without compromise.
Meeting our regulatory obligations so you can focus on your business. Canadian data residency, a fixed audit cadence, and transparent practices — because compliance is more than checking boxes.
Last updated: December 2024
Compliance frameworks
Where we stand today, stated plainly.
PIPEDA
Personal Information Protection and Electronic Documents Act. Canada's federal privacy law governing how private sector organizations collect, use, and disclose personal information.
CompliantGDPR
General Data Protection Regulation. European Union regulation on data protection and privacy. We're ready to serve EU customers.
ReadyContinuous monitoring
24/7 security monitoring. Round-the-clock security monitoring and threat detection to protect your data.
ActiveCanadian data residency
Your data is stored exclusively in Canadian data centers. We comply with all Canadian privacy laws and never transfer data outside the country without explicit consent.
AWS Canada Central
Primary infrastructure.
Backups
Encrypted, stored in Canada.
PIPEDA
Full compliance.
Encrypted
In transit & at rest.
Data handling principles
Best practices, applied to every byte we hold.
Data minimization
We only collect data that's essential for providing our services. No excessive data collection.
Purpose limitation
Your data is used only for the purposes you agreed to. No surprise uses.
Storage limitation
Data retained only as long as necessary. Automatic deletion policies in place.
Accuracy
Tools to update and correct your data anytime. Keep your information current.
Audit & reporting
Transparent compliance monitoring and reporting, on a fixed cadence.
Daily
Automated security scans.
Weekly
Access log reviews.
Monthly
Compliance assessments.
Always
Every sensitive action logged, with 7-year audit trail retention.
Our commitments, your rights
Our commitments
- Keep our compliance practices current as privacy laws evolve
- Run security audits on a fixed internal cadence — daily, weekly, and monthly
- Provide transparent data processing information
- Respond to data subject requests within 30 days
- Notify of breaches within 72 hours
- Appoint a dedicated Data Protection Officer
Your rights
- Access all personal data we hold about you
- Request correction of inaccurate information
- Request deletion of your data (right to be forgotten)
- Export your data in a portable format
- Object to certain types of processing
- Withdraw consent at any time
Incident response plan
In the unlikely event of a security incident, we work to a documented plan with these internal targets.
- Under 1 hour. Detection & containment.
- Under 24 hours. Investigation.
- Under 72 hours. Notification.
Compliance documents
Our privacy policy, terms of service, and security overview are published on this site. For our Data Processing Agreement or Security Whitepaper, contact us and we'll send them over.
Questions about this?
A person answers, not a form. We respond within 48 hours.
compliance@omgsystems.caOMGsystems Inc. · Durham, Ontario, Canada