Skip to content

Requests & Contact v3.9 ​

Last updated: September 30, 2026

Available on Request ​

The following documents are available to prospective and current partners. Contact your AI4Love implementation partner or email privacy@ai4love.ca to request access.

DocumentDescriptionAccess
Data Processing Agreement (DPA)Standard DPA template covering data handling, retention, sub-processors, and breach notification obligations. Customizable per organization.Available to all prospective partners
Sub-Processor ListPublished on the Sub-Processors page: every third-party provider with role, data touched, region, and certification.Public. No request needed
Removal and erasure procedureSource-system deletions and merges are removed from the AI4Love base on request, completed within 5 business days with written confirmation during pilot phase. Erasure requests received directly by AI4Love are routed to the client as data controller. See Data Handling.Public. No request needed
SOC 2 Type II ReportsReports from infrastructure providers (Airtable, Vercel, Axiom, Nango, Doppler). AI4Love can facilitate access to provider reports relevant to your compliance review.Available under NDA
Vendor Security QuestionnaireResponses to standard vendor assessment frameworks (SIG Lite, CAIQ, HECVAT), completed on request.Available to all prospective partners

Penetration testing is on our security roadmap. Results will be shared with partner organizations upon completion. We welcome scoping input from partner security and privacy teams.


What Is Never Gated ​

The following information is always publicly available in this Trust Center:

  • System architecture and data flow
  • Data handling principles and retention model
  • Sub-processor list
  • AI behavior model and decision boundaries
  • Security controls and access model
  • Failure modes and incident response procedures
  • Changelog of system updates

We believe transparency about how the system works builds more trust than NDAs around how it doesn't.


Compliance Frameworks ​

AI4Love's architecture is designed to support compliance with:

  • PIPEDA (Personal Information Protection and Electronic Documents Act)
  • Provincial health privacy legislation (e.g., BC PIPA, Ontario PHIPA). subject to your privacy assessment of US-hosted processing; Canadian data residency is not currently available
  • CRA requirements for charitable organizations
  • CASL (Canadian Anti-Spam Legislation) — AI4Love does not send communications, but insight data can inform CASL-compliant outreach by your team

AI4Love does not currently hold its own SOC 2 Type II certification. All data storage and processing is delegated to SOC 2 Type II certified providers (see Infrastructure Providers).


Contact ​

For urgent security matters, email privacy@ai4love.ca with "URGENT" in the subject line. We commit to acknowledging security reports within 24 hours.

AI4Love Trust Center v3.9