Where your data lives.
Your exposures, forward contracts, policy, and reports are stored in Canada, in Supabase region ca-central-1 (Montreal). They do not leave Canadian soil in the normal course of running the platform.
How it is protected.
- TLS 1.2 or higher for all data in transit.
- AES-256 encryption at rest.
- Row-level security at the database layer, so no tenant can read another tenant's data.
- Multi-factor authentication available on every account.
- Audit logging on every administrative action.
Compliance posture.
PolicyFX is built to PIPEDA. We follow the ten fair information principles: accountability, identifying purposes, consent, limiting collection, limiting use, accuracy, safeguards, openness, individual access, and challenging compliance.
Sub-processors outside Canada.
A few supporting services operate in the United States: Stripe for billing, Resend for email, and Google Workspace for PolicyFX staff email and documents. The data each one touches is limited to what its function requires.
The book of record, meaning your ledger, your policy, and your reports, stays in ca-central-1.
Breach notification.
If a breach creates a real risk of significant harm, we notify affected customers and the Office of the Privacy Commissioner of Canada under PIPEDA section 10.1.
Your rights.
Access, correction, and withdrawal-of-consent requests are answered within thirty days. Send them to info@policyfx.ca.
The one line for your vendor file.
"Tenant data hosted in Canada (ca-central-1). PIPEDA compliant. Row-level security at the database layer."