Impact OS is built to handle sensitive client information responsibly, with PIPEDA in mind.
Data is encrypted in transit (TLS) and at rest.
Every organization’s data is isolated at the database level with row-level security (RLS), not just in the application layer.
We rely on a small set of vetted sub-processors: Supabase (database & storage), Stripe (payment processing), and Resend (transactional email).
If an incident affects your data, we notify affected organizations without undue delay, consistent with PIPEDA.
Read the full Privacy Policy for details on data residency, retention, and your rights.