Privacy · Law 25
Law 25 and the app.sentrix.ca platform
How the app.sentrix.ca platform applies Québec's Law 25: who is accountable, Azure hosting in Canada, sub-processors, PIA, incidents, retention and your rights.
Last updated on 2026-10-02. This section explains how Sentrisques Cybersécurité Inc. applies Québec's Act respecting the protection of personal information in the private sector, as amended by Law 25, to the app.sentrix.ca platform. It complements our privacy policy, which covers the public website, and our data processing agreement.
Who is accountable
Our person in charge of the protection of personal information is William Georges Khouri, President and Chief Executive Officer of Sentrix. He ensures compliance with the law and the implementation of our policies. You can reach him at privacy@sentrix.ca.
Two roles coexist in the platform, and they decide who answers for what:
- Sentrix is the accountable enterprise for the information needed to manage your subscription: name, business email address, organization and role of the people who sign in, and the application's security logs.
- Your organization remains accountable for the information it places in the platform for its compliance programme: its users' accounts, evidence drawn from its systems, uploaded documents. Sentrix then acts as its service provider, only on your instructions and to deliver the service.
What the platform processes, and why
| Category | Examples | Purpose |
|---|---|---|
| User accounts | Name, business email, organization, role | Sign in, manage access, contact you about the service |
| Compliance evidence | Information drawn from your systems connected read-only, uploaded documents | Assess your controls and produce your audit deliverables |
| Security logs | IP address, browser, timestamp, actions taken | Protect the platform, detect abuse, investigate an incident |
| Support | Exchanges with our support team | Answer your requests |
We collect only what these purposes require. We do not sell personal information, and we do not use a customer's compliance data for any purpose other than providing the service.
Where the data is hosted
The platform is hosted on Microsoft Azure, in the Canada Central region, in Toronto. Databases, files, encryption keys and backup copies stay in Canada.
Because Toronto is outside Québec, Law 25 treats this hosting as a communication of personal information outside Québec. Before making it, we assessed whether the information receives adequate protection, taking into account its sensitivity, the purposes of its use, the protection measures and the applicable legal framework. This assessment is recorded in our privacy impact assessment.
Our sub-processors
We entrust some tasks to providers bound by a written contract that governs confidentiality, security and the use of the information. They may use it only for the purposes of the mandate.
| Provider or category | Role | Location |
|---|---|---|
| Microsoft Azure | Platform hosting, databases, storage, identity and key management, AI-assisted features | Canada (Canada Central region) |
| Network protection | Web application firewall, attack filtering and DNS in front of the application | Global network, requests may transit outside Canada |
| Customer relationship and support | Customer account management and support requests | Canada |
| Email and collaboration | Correspondence with our customers | Cloud |
Customers are notified at least 30 days before a new sub-processor is added to the platform. The named list is provided to our customers with their data processing agreement and on request at privacy@sentrix.ca.
Privacy impact assessment
A privacy impact assessment was carried out for the platform, including its hosting outside Québec. We update it when a significant change affects how the platform processes personal information, such as a new sub-processor, a new hosting region or a feature that uses new information.
Security and privacy by default
Data is encrypted in transit and at rest, and keys are held in a managed vault. Access to customer data is limited to team members whose role requires it, logged and reviewed. Our staff are bound by confidentiality commitments and take security awareness training.
The platform uses no Google Analytics, no advertising cookies and no profiling tool. Where the platform offers a privacy setting, it is set to its most protective level by default.
Artificial intelligence and automated decisions
AI-assisted features run on Microsoft Azure services, under the same contractual framework as the hosting. They serve to deliver the service to you; your data is not used for any other purpose.
Should a platform feature base a decision exclusively on automated processing of your information, we would inform you no later than at the time of the decision, and you could learn the information and the main factors used, have the information corrected, and submit your observations to a person able to review the decision.
Confidentiality incidents
We keep a register of confidentiality incidents. When an incident presents a risk of serious injury, we promptly notify the Commission d'accès à l'information and the persons concerned, as the law requires.
When an incident affects information your organization is accountable for, we notify it without undue delay and give it the information it needs to assess the risk and meet its own obligations.
Retention and destruction
| Information | Period |
|---|---|
| Your programme data in the platform | Term of the subscription, then 30 days to export it |
| Active data after the subscription ends | Deleted within 90 days |
| Backup copies | Encrypted and isolated, they expire on their cycle, at most seven years, and are restored only if the law requires it |
| Account and billing information | Term of the subscription, plus seven years for tax obligations |
| Security logs | A limited period, set by our logging policy |
At the end of the period, the information is securely destroyed, or anonymized according to generally accepted practices where the law allows it.
Your rights
You may request access to the personal information that concerns you, its correction, or withdraw your consent where processing depends on it. You may also ask that computerized information you provided be communicated to you, or to a person you designate, in a structured, commonly used technological format.
Write to privacy@sentrix.ca. We verify your identity, then answer within 30 days. If your request concerns information your employer is accountable for in the platform, we pass it on and help them answer.
Complaints
A complaint about how we handle your personal information goes first to our person in charge, at privacy@sentrix.ca. We acknowledge it and answer in writing within 30 days. If the answer does not satisfy you, you may contact the Commission d'accès à l'information du Québec.
Platform users
The platform is a service offered to organizations. It is not intended for people under 14 and does not knowingly collect information about them.
Frequently asked questions
- Where is platform data hosted?
- The app.sentrix.ca platform is hosted on Microsoft Azure, in the Canada Central region, in Toronto. Your account data and compliance programme data are stored and processed there. Because Toronto is outside Québec, Law 25 treats this hosting as a communication of personal information outside Québec, and a privacy impact assessment was carried out for it.
- Is Sentrix accountable for my employees' information?
- For the information your organization places in the platform, such as your users' accounts or evidence drawn from your systems, your organization remains the accountable enterprise and Sentrix acts as its service provider, on your instructions. For the information needed to manage your subscription, Sentrix is the accountable enterprise.
- Does the platform use Google Analytics or advertising cookies?
- No. The app.sentrix.ca platform uses neither Google Analytics nor advertising cookies. Only the cookies needed to sign in, to secure the session and to run the application are used. The public website sentrix.ca has its own cookie policy, which describes the analytics loaded only after you consent.
- What happens to our data when the subscription ends?
- You have 30 days after the subscription ends to export your data. Active data is then deleted within 90 days. Backup copies, encrypted and isolated, expire on their cycle, at most seven years, and are not restored unless the law requires it. They are destroyed when they expire.
- How do I exercise a right of access or portability?
- Write to privacy@sentrix.ca. If the request concerns information your employer manages in the platform, we pass it on and help them answer, since they are accountable for it. For information Sentrix is accountable for, we answer within 30 days, after verifying your identity, in a structured and commonly used format.
Related pages
Privacy
Privacy center
All of Sentrix's policies in one place: the sentrix.ca website, the app.sentrix.ca platform and Law 25, the processing agreement, cookies, security, disclosure.
Privacy · DPA
Data processing agreement (DPA)
Sentrix's commitments as the service provider for your data in app.sentrix.ca: instructions, security, sub-processors, hosting in Canada, incidents and exit.
Legal
Privacy Policy
How Sentrix collects, uses and protects personal information on sentrix.ca and in the platform, your rights under Law 25, PIPEDA, GDPR and CCPA.
Last updated: 2026-10-02
