Appearance
Requests & Contact v3.9
Last updated: September 30, 2026
Available on Request
The following documents are available to prospective and current partners. Contact your AI4Love implementation partner or email privacy@ai4love.ca to request access.
| Document | Description | Access |
|---|---|---|
| Data Processing Agreement (DPA) | Standard DPA template covering data handling, retention, sub-processors, and breach notification obligations. Customizable per organization. | Available to all prospective partners |
| Sub-Processor List | Published on the Sub-Processors page: every third-party provider with role, data touched, region, and certification. | Public. No request needed |
| Removal and erasure procedure | Source-system deletions and merges are removed from the AI4Love base on request, completed within 5 business days with written confirmation during pilot phase. Erasure requests received directly by AI4Love are routed to the client as data controller. See Data Handling. | Public. No request needed |
| SOC 2 Type II Reports | Reports from infrastructure providers (Airtable, Vercel, Axiom, Nango, Doppler). AI4Love can facilitate access to provider reports relevant to your compliance review. | Available under NDA |
| Vendor Security Questionnaire | Responses to standard vendor assessment frameworks (SIG Lite, CAIQ, HECVAT), completed on request. | Available to all prospective partners |
Penetration testing is on our security roadmap. Results will be shared with partner organizations upon completion. We welcome scoping input from partner security and privacy teams.
What Is Never Gated
The following information is always publicly available in this Trust Center:
- System architecture and data flow
- Data handling principles and retention model
- Sub-processor list
- AI behavior model and decision boundaries
- Security controls and access model
- Failure modes and incident response procedures
- Changelog of system updates
We believe transparency about how the system works builds more trust than NDAs around how it doesn't.
Compliance Frameworks
AI4Love's architecture is designed to support compliance with:
- PIPEDA (Personal Information Protection and Electronic Documents Act)
- Provincial health privacy legislation (e.g., BC PIPA, Ontario PHIPA). subject to your privacy assessment of US-hosted processing; Canadian data residency is not currently available
- CRA requirements for charitable organizations
- CASL (Canadian Anti-Spam Legislation) — AI4Love does not send communications, but insight data can inform CASL-compliant outreach by your team
AI4Love does not currently hold its own SOC 2 Type II certification. All data storage and processing is delegated to SOC 2 Type II certified providers (see Infrastructure Providers).
Contact
- General inquiries: hello@ai4love.ca
- Privacy, DPA, and security questionnaire requests: privacy@ai4love.ca
- Security concerns: privacy@ai4love.ca
- Implementation partner: Contact your assigned partner directly
For urgent security matters, email privacy@ai4love.ca with "URGENT" in the subject line. We commit to acknowledging security reports within 24 hours.