Security & Data Protection

Connexxia Inc. — Last updated: August 23, 2026

Where your data lives

The Connexxia platform stores customer data in Canada. Data residency is a design property of the platform, not an add-on: hosting, databases, and AI inference are provisioned on Canadian infrastructure, under Canadian jurisdiction.

PIPEDA alignment

Connexxia's data-handling practices are built around the ten principles of Canada's Personal Information Protection and Electronic Documents Act (PIPEDA): accountability, identified purposes, consent, limited collection, limited use and retention, accuracy, safeguards, openness, individual access, and challenging compliance. Purposes are disclosed at the point of collection, consent is recorded and revocable, and audit trails cover data access.

Minimal collection

Integrations collect only the metadata needed for their stated purpose. For example, the Salesforce security analysis collects user IDs, profiles, roles, permission sets, and sharing rules — and does not collect record data, attachments, notes, email content, financial data, or health data.

Safeguards

Data is encrypted in transit (TLS) and at rest. Access is authenticated per user, with OAuth-scoped connections to third-party services that customers can revoke at any time. Tenant isolation is enforced at the platform layer, and state-changing requests are protected against cross-site request forgery.

Questions and reports

To ask about these practices, request details of the safeguards applicable to your organization, or report a suspected vulnerability, contact info@connexxia.ca. See also the Privacy Policy and License Agreement.

We use one analytics tool to count visits and clicks — no ads, no resale. Your choice stays on your device. / Un seul outil d'analyse, sans publicité ni revente.