Compliance without compromise.
Meeting our regulatory obligations means documenting the applicable scope, data locations, and controls for each product and connected service. Ask us to confirm the details for your planned setup.
Last updated: December 2024
Compliance frameworks
Where we stand today, stated plainly.
PIPEDA
Personal Information Protection and Electronic Documents Act. Canada's federal privacy law governing how private sector organizations collect, use, and disclose personal information.
Access to confirmGDPR
General Data Protection Regulation. European Union regulation on data protection and privacy. Applicability and readiness depend on the product and customer setup.
Access to confirmContinuous monitoring
24/7 security monitoring. Monitoring and threat-detection controls depend on the applicable product and environment.
Access to confirmProduct-specific data locations
Storage and processing locations depend on the product and connected services. We review the full workflow before making a residency or compliance commitment.
Hosting location
Confirmed by product and planned setup.
Connected services
Included in the location review.
Privacy obligations
Scope confirmed for the applicable workflow.
Encrypted
In transit & at rest.
Data handling principles
Best practices, applied to every byte we hold.
Data minimization
We only collect data that's essential for providing our services. No excessive data collection.
Purpose limitation
Your data is used only for the purposes you agreed to. No surprise uses.
Storage limitation
Data retained only as long as necessary. Automatic deletion policies in place.
Accuracy
Tools to update and correct your data anytime. Keep your information current.
Audit & reporting
Transparent compliance monitoring and reporting, on a fixed cadence.
Daily
Automated security scans.
Weekly
Access log reviews.
Monthly
Compliance assessments.
Always
Every sensitive action logged, with 7-year audit trail retention.
Our commitments, your rights
Our commitments
- Keep our compliance practices current as privacy laws evolve
- Run security audits on a fixed internal cadence — daily, weekly, and monthly
- Provide transparent data processing information
- Respond to data subject requests within 30 days
- Notify of breaches within 72 hours
- Appoint a dedicated Data Protection Officer
Your rights
- Access all personal data we hold about you
- Request correction of inaccurate information
- Request deletion of your data (right to be forgotten)
- Export your data in a portable format
- Object to certain types of processing
- Withdraw consent at any time
Incident response plan
In the unlikely event of a security incident, we work to a documented plan with these internal targets.
- Under 1 hour. Detection & containment.
- Under 24 hours. Investigation.
- Under 72 hours. Notification.
Compliance documents
Our privacy policy, terms of service, and security overview are published on this site. For our Data Processing Agreement or Security Whitepaper, contact us and we'll send them over.
Questions about this?
A person answers, not a form. We respond within 48 hours.
compliance@omgsystems.caOMGsystems Inc. · Durham, Ontario, Canada