| Field | Value |
|---|---|
| Company | Domilia Inc. |
| Effective Date | July 15, 2026 |
| Version | 1.0 |
| Next scheduled review | July 15, 2027 |
| Status | Approved |
| Document owner | Privacy Officer — Domilia Inc. |
This Privacy Statement is published to meet the requirements of Québec's Act respecting the protection of personal information in the private sector (as modernized by Law 25, CQLR c. P-39.1), the Personal Information Protection and Electronic Documents Act (PIPEDA, Canada) and, where applicable to individuals located in the European Economic Area, the General Data Protection Regulation (GDPR). The authoritative French version of Domilia's privacy policy is available at docs/legal/privacy-policy.md and on https://domilia.ca.
Domilia Inc. (« Domilia ») is a Québec-based software company that develops and operates the Domilia Super App, a multi-tenant SaaS platform serving healthcare, education, government and enterprise organizations. Its modules include learning management (LMS), human resources, beneficiary care, hygiene and maintenance, telephony, Internet of Things (IoT), and indoor location / desk booking.
We understand that you are aware of and care about your own personal privacy interests, and we take that seriously. This Privacy Statement describes Domilia's policies and practices regarding its collection and use of your personal data, and sets forth your privacy rights. We recognize that information privacy is an ongoing responsibility, and so we will from time to time update this Privacy Statement as we undertake new personal data practices or adopt new privacy policies.
Domilia is headquartered in Longueuil, Québec, in Canada. Domilia has appointed an internal privacy officer (the « Agent de protection des renseignements personnels » required by section 3.1 of Québec's Law 25, acting as data protection officer) for you to contact if you have any questions or concerns about Domilia's personal data policies or practices. If you would like to exercise your privacy rights, please direct your query to Domilia's privacy officer. The privacy officer's name and contact information are as follows:
Vincent Gendreau — Privacy Officer
Domilia Inc.
769, rue Maple
Longueuil (Québec) J4J 4M8, Canada
info@domilia.ca
Domilia collects personal information about its website visitors and customers. With a few exceptions, this information is generally limited to:
We use this information to provide prospects and customers with services.
When an institutional customer (for example a school service centre, a healthcare establishment or a public body) deploys the Domilia Super App for its own users, Domilia processes the personal data described in the customer's service agreement — such as user accounts, training and certification records, schedules, and, for specific modules only, health-related or background-check information — acting as a service provider (processor) on documented instructions from that customer. Domilia collects only the personal information strictly necessary to deliver the contracted services.
We do not sell personal information to anyone and only share it with third parties who are facilitating the delivery of our services.
From time to time, Domilia receives personal information about individuals from third parties. Typically, information collected from third parties will include further details on your employer or industry, or — where an institutional customer has enabled the background verification module and the individual has consented — verification results returned by our specialized provider.
As is true of most other websites, Domilia's website collects certain information automatically and stores it in log files. The information may include internet protocol (IP) addresses, the region or general location where your computer or device is accessing the internet, browser type, operating system and other usage information about the use of Domilia's website, including a history of the pages you view. We use this information to help us design our site to better suit our users' needs. We may also use your IP address to help diagnose problems with our server and to administer our website, analyze trends, and gather broad demographic information that assists us in identifying visitor preferences.
Domilia has a legitimate interest in understanding how customers and potential customers use its website. This assists Domilia with providing more relevant products and services and with providing appropriate staffing to meet customer needs.
Domilia uses only cookies that are strictly necessary for the operation of the platform:
accessToken, refreshToken) — HTTP-only, Secure, SameSite=StrictThese strictly necessary cookies do not require prior consent. Domilia does not use advertising or cross-site tracking cookies. Analytics cookies are not enabled by default on institutional customer environments; where they are enabled (for example on a public marketing site), they are configured for data minimization and presented behind a consent banner.
Personal data processed within the Domilia Super App on behalf of an institutional customer is used exclusively to deliver the contracted services: account creation and authentication, learning and certification management, scheduling and HR workflows, audit trails required by law, technical support, and administrative communications related to the account. Product improvement relies solely on aggregated and anonymized telemetry. No commercial profiling and no advertising use is made of service data.
The personal information Domilia collects from you is stored in one or more databases hosted by Microsoft Azure, in the Canada Central (Toronto, Ontario) and Canada East (Québec City, Québec) regions. These third parties do not use or have access to your personal information for any purpose other than cloud storage and retrieval.
Domilia engages a limited number of sub-processors to deliver its services, all bound by contractual confidentiality, security and data protection obligations:
| Sub-processor | Role | Processing location |
|---|---|---|
| Microsoft Azure | Cloud hosting (compute, database, storage) | Canada Central + Canada East |
| Microsoft Entra ID | Federated authentication (only if SSO is enabled by the customer) | Microsoft global services |
| SendGrid | Transactional email delivery | Configurable; Canadian relay available on request |
| Anthropic (Claude API) | Optional AI assistance features | Outside Canada — optional, can be disabled per customer |
| Certn | Criminal background verification (VAJ module only) | Canada |
| Stripe | Payment processing (modules billing end users) | Canada + United States depending on flow |
The current list of sub-processors active for a given customer is available on request from info@domilia.ca.
We do not otherwise reveal your personal data to non-Domilia persons or businesses for their independent use unless: (1) you request or authorize it; (2) the information is provided to comply with the law (for example, compelled by law enforcement to comply with a search warrant, subpoena, or court order), enforce an agreement we have with you, or to protect our rights, property or safety, or the rights, property or safety of our employees or others; (3) the information is provided to our agents, vendors or service providers who perform functions on our behalf; (4) to address emergencies or acts of God; or (5) to address disputes, claims, or to persons demonstrating legal authority to act on your behalf. We may also gather aggregated data about our services and website visitors and disclose the results of such aggregated (but not personally identifiable) information to our partners and service providers.
Domilia has its headquarters in Canada, and customer data — including PostgreSQL databases, Azure Blob storage and Redis caches — resides exclusively in the Canadian Azure regions listed above. No replication outside Canada is configured on production environments of customers requiring Canadian data residency.
A limited number of ancillary services may process or transit data outside Canada (optional AI assistance features via Anthropic, and certain payment flows via Stripe). These are identified explicitly, are optional or replaceable on contractual request, and are governed by written agreements imposing appropriate safeguards. In accordance with section 17 of Québec's Law 25, any communication of personal information outside Québec is subject to a prior assessment covering the sensitivity of the information, the purpose of the processing, the protection measures applied and the legal regime of the receiving jurisdiction; these assessments are documented and retained by the privacy officer.
For individuals located in the European Economic Area: Canada benefits from an adequacy decision of the European Commission for personal data transferred to recipients subject to PIPEDA, and Domilia enters into data processing agreements with its vendors whenever feasible and appropriate.
For more information or if you have any questions, please contact us at info@domilia.ca.
Québec's Law 25, PIPEDA, the European Union's GDPR and other privacy laws provide certain rights for data subjects. These rights include the following:
This Privacy Statement is intended to provide you with information about what personal data Domilia collects about you and how it is used. If you wish to confirm that Domilia is processing your personal data, or to have access to the personal data Domilia may have about you, please contact us at info@domilia.ca.
You may also request information about: the purpose of the processing; the categories of personal data concerned; who else outside Domilia might have received the data from Domilia; what the source of the information was (if you didn't provide it directly to Domilia); and how long it will be stored. You have a right to correct (rectify) the record of your personal data maintained by Domilia if it is inaccurate. You may request that Domilia erase that data or cease processing it, subject to certain exceptions. When your personal data is processed by Domilia on behalf of an institutional customer, your request may be redirected to that organization, which remains responsible for the data; Domilia provides its customers with the technical means (export, rectification, anonymization, and irreversible deletion endpoints) to respond within the legal deadlines.
Reasonable access to your personal data will be provided at no cost. Domilia responds to any request within a maximum of thirty (30) days. If access cannot be provided within a reasonable time frame, Domilia will provide you with a date when the information will be provided. If for some reason access is denied, Domilia will provide an explanation as to why access has been denied, together with the applicable remedies.
For questions or complaints concerning the processing of your personal data, you can email us at info@domilia.ca. You may also lodge a complaint with the Commission d'accès à l'information du Québec (CAI), with the Office of the Privacy Commissioner of Canada (OPC), or, if you are located in the European Union, with your national data protection authority.
Domilia implements technical and organizational measures proportionate to the sensitivity of the information processed, including: TLS 1.2+ encryption in transit (TLS 1.3 recommended), AES-256 encryption at rest, secrets management through Azure Key Vault, HTTP-only cookie-based authentication with MFA available, granular role-based access control, parameterized queries, structured audit logging, rate limiting on sensitive routes, hardened HTTP security headers, and mobile protections (screen-capture blocking on sensitive pages, device integrity detection). Access to production data is restricted to authorized personnel and access rights are reviewed quarterly.
Your personal data is stored by Domilia on the servers of the cloud-based database management services Domilia engages, located in Canada (Microsoft Azure — Canada Central and Canada East). Domilia retains service data for the duration of the customer's business relationship with Domilia and for the period required by law or contract thereafter, as detailed in Domilia's Data Retention Policy. Typical retention periods include: active user accounts for the duration of the service contract plus five (5) years (traceability obligations); learning and certification records for the contract duration plus a minimum of five (5) years; audit logs for a minimum of seven (7) years. At the end of the retention period, personal information is either irreversibly anonymized or securely deleted, in accordance with section 23 of Québec's Law 25. All personal data that Domilia controls may be deleted upon verified request from data subjects or their authorized agents, subject to legal retention obligations. For more information on where and how long your personal data is stored, and for more information on your rights of erasure and portability, please contact us at info@domilia.ca.
The Domilia platform is intended for institutional use (employees, managers). Certain educational modules (school LMS) may process information concerning minors strictly under a mandate entrusted by a legally competent school organization; in such cases the institutional customer remains responsible for parental consent where applicable, interfaces intended for minors apply reinforced data minimization, and no profiling mechanisms are integrated. We do not knowingly attempt to solicit or receive information directly from children.
If you have questions, concerns, complaints, or would like to exercise your rights, please contact us at:
Domilia Inc.
c/o Vincent Gendreau — Privacy Officer
769, rue Maple
Longueuil (Québec) J4J 4M8, Canada
info@domilia.ca
https://domilia.ca