Draft templates pending review by legal counsel — not legal advice. The sub-processor list is current and accurate.
How WeShield collects, uses, and protects personal information, consistent with PIPEDA. Draft template pending review by counsel.
Account information (name, email), the workspace data your organization enters (grant prospects, applications, documents, team members), and operational metadata (audit logs, usage counts) needed to run and secure the service.
Tenant data is stored and processed in Canada (Supabase ca-central-1 and Vercel yul1, both in Montréal). The one processing step that may leave Canada is AI inference: when AI features are enabled for a workspace, redacted prompts are sent to the configured AI provider. The current production provider is DeepSeek (People’s Republic of China jurisdiction); Anthropic (United States) is the supported alternative. AI features are opt-in, and high-risk identifiers are redacted before any prompt leaves the platform. The active provider is always disclosed on the sub-processor list and in the AI-use registry.
WeShield is designed for Canadian privacy law. Personal information is handled consistent with PIPEDA and, for organizations and individuals in Québec, the Act respecting the protection of personal information in the private sector (Law 25), including data-residency in Québec, breach recording, and transparency about any transfer outside Canada (see Data residency). A privacy point of contact and the formal Law 25 program details are provided to workspace administrators on request.
To provide the platform, isolate each tenant, maintain a tamper-evident audit trail, enforce security and rate limits, and — where enabled — produce AI assistance. We do not sell personal information.
Workspace administrators can export a full copy of their data and permanently erase the workspace from Settings (right to access and erasure). For other requests about personal information, contact us.
Tenant isolation is enforced at the database with row-level security; every privileged action passes a single audited gateway; the audit trail is hash-chained and tamper-evident. High-risk identifiers are redacted before any outbound AI call.
A workspace administrator can choose to connect Google services (Gmail, Google Drive, Google Sheets, Google Calendar) to their workspace. Connecting is always initiated and approved by a human through Google’s own consent screen; WeShield requests read-only access, and only the scopes shown on that screen.
What we access and why: with your permission, WeShield reads email (gmail.readonly), files (drive.readonly), spreadsheets (spreadsheets.readonly), and calendar events (calendar.readonly) solely to provide workspace features you invoke — for example grounding grant drafts in your own documents or surfacing deadlines. We access only what the feature you use requires.
How it is stored and protected: OAuth tokens are encrypted (AES-256-GCM) in the application layer before they reach our Canadian-resident database, which additionally enforces per-workspace row-level isolation; a database record alone cannot yield a usable token. Content read from Google services is processed to serve your request and is not retained beyond what the feature stores in your own workspace.
What we never do with Google user data: we do not sell it; we do not use it for advertising; we do not allow humans to read it except with your explicit consent for support, for security investigation, or where required by law; we do not transfer it except as needed to provide the features you invoke. Disconnecting a Google account (a human-only action, audited) deletes the stored tokens and revokes WeShield’s access with Google.
WeShield’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy (developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.