Privacy Policy
Privacy Policy
Unionsuite holds the personal information your union entrusts to it. This policy explains what we process, why, where it lives, who we share it with, and the rights you and your members have. A signed Data Processing Agreement governs the specifics; this page is the standard form.
Updated June 11, 2026.
Security & compliance
Data Security & Compliance Report
Our full security architecture and control environment — single-tenant isolation, encryption in transit and at rest, passwordless access control, per-record audit trails, and the complete data lifecycle — mapped control-by-control to the SOC 2 Trust Services Criteria and ISO/IEC 27001:2022, on certified Canadian infrastructure.
SOC 2-aligned ISO 27001-aligned Hosted in Canada
Who we are and our role
- Unionsuite Ltd. ("Unionsuite", "we") builds and operates the Unionsuite platform from Ottawa, Canada.
- For the member personal data inside your union's workspace, your union is the data controller and we are the data processor: we process that data only on your union's documented instructions, to provide and support the service. Your union decides what is collected and why, and is responsible for the lawful basis to collect it and for informing its members.
- For a small amount of data we determine ourselves, the account and contact details of the staff who administer your workspace, and our own billing records, we act as the controller.
- We never sell personal data, and we never use member data for advertising or to train third-party AI models.
What we process and why
- Member and union records your union enters: names, contact details, employment and classification, seniority, dues status, grievance histories, attached documents, and the custom fields your workspace defines. We process these solely so your union can run on Unionsuite.
- Account data for the people who administer the workspace: email address, role and permissions, and sign-in activity. We use this to authenticate users and secure the service.
- Operational and diagnostic data needed to run the platform: audit logs of actions taken, and error reports (see subprocessors). We use this to keep the service reliable and to investigate problems.
- We collect only what the service needs. We do not build advertising or behavioural profiles of members.
Legal basis and PIPEDA alignment
- Our handling is aligned with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy law.
- As processor, we rely on your union's instructions and the lawful basis your union holds for its members' data (typically the union's legitimate representation and administration of its members, and consent where required).
- Where we act as controller (administrator accounts, billing), we rely on the contract with your union and our legitimate interest in operating and securing the service.
Single-tenant isolation
- Every union gets its own isolated database, file storage, and web address. Your data is never co-mingled in a shared table or bucket with another union's. This separation is built into the architecture, not just a policy setting.
- Because workspaces are separate, another union's configuration, import, or error can never reach your data.
Subprocessors we rely on
- Supabase, managed Postgres database, file storage, and authentication. Member data is hosted in a Canadian region. Supabase runs on SOC 2 / ISO 27001-certified infrastructure.
- Vercel, application hosting and content delivery (CDN) for the website and app. Vercel runs on SOC 2-certified infrastructure.
- Resend, delivery of transactional and bulk email (sign-in codes, notifications, mass mailings your union sends).
- Sentry, error and performance monitoring, so we detect and fix problems quickly.
- Anthropic (Claude), powers the optional in-app and website AI assistant. The assistant answers from the product manual and offer documents; it does not read your member records, and member data is never used to train Anthropic's models.
- Each subprocessor is bound by a written agreement with confidentiality and security obligations and may use your union's data only to provide its service to us. We give advance notice before adding or changing a subprocessor that handles member data.
Where your data lives
- Member personal data is stored in Canada, in a Canadian data centre, on every plan.
- Some operational data (for example error diagnostics and email-delivery metadata) may be processed by subprocessors outside Canada. Where that happens, the transfer is covered by the subprocessor's contractual safeguards, and member personal records remain hosted in Canada.
How we secure it
- Encryption in transit and at rest, passwordless sign-in with rate-limited one-time email codes, row-level security in the database, and role-based permissions (47 granular capabilities across 4 roles).
- Per-record audit logs, automatic backups, a manually saved copy before every bulk operation, and signed, time-limited links for file access.
- A fuller description is on our security page at /security.
Retention and deletion
- We keep member data for as long as your union maintains its workspace and instructs us to.
- You can export everything yourself at any time, members, grievance histories, audit logs, and files, to CSV, Excel, or PDF.
- When you leave, the order is deliberate: export first, revoke access, then delete on an agreed schedule, confirmed in writing. Your data is never held hostage.
- Backups are rotated and expire on a normal cycle after deletion.
Member rights, handled through your union
- Members' rights to access, correct, or delete their personal data are exercised through their union, which is the controller of that data.
- When your union asks, we help it find, export, correct, or delete a member's records, and we act on your union's instructions promptly.
- If a member contacts us directly, we refer them to their union and assist the union in responding.
AI and automated processing
- The AI assistant is optional. It answers questions from the product manual and our offer documents, not from member records, and it does not make automated decisions about members.
- Member personal data is never used to train Anthropic's or any other third party's models.
Cookies and analytics
- The marketing site uses Vercel Analytics, which is privacy-friendly: it measures page views and performance without cookies and without collecting member personal information.
- The application uses only the cookies needed to keep you signed in securely. We do not run advertising trackers.
Changes and contact
- We give reasonable advance notice of material changes to this policy or to our subprocessors.
- Privacy questions, a security questionnaire, or a request for our signed DPA, write to security@unionsuite.net, or support@unionsuite.net for everything else. A real person answers.
Questions? Email us, a real person answers.