Compliance
Law 25 and GDPR
Quebec's Law 25 modernized the province's private-sector privacy rules. The European Union's GDPR sets separate obligations for organizations that process personal data covered by the regulation. Epistolē is being built with both frameworks in mind, but each customer remains responsible for how they collect and use personal data.
Subscriber data is stored in Canada
Epistolē stores subscriber records, campaigns, and consent records in a Canadian data centre. Messages still travel to each recipient's email provider, which may operate in another country. The residency commitment applies to the subscriber data stored by Epistolē.
Consent, tracked
Epistolē records consent status and supporting timestamps for each contact. Unsubscribe and complaint signals create suppression records that block future sends. These controls help customers demonstrate and honour consent choices, but they do not replace a customer's responsibility to establish a lawful basis for every list.
Privacy by design
We collect only the data needed to operate the service and do not sell customer or subscriber data. Epistolē does not use open-tracking pixels. Optional click tracking is off by default and uses signed Epistolē redirects. Unsubscribes, complaints, and hard bounces create suppression records that block future sends.
Individual rights
Law 25 generally requires a written response to an access or correction request within 30 days. Under the GDPR, organizations generally must respond to rights requests without undue delay and within one month. Epistolē is building the export, correction, deletion, and request-tracking workflows needed to help customers meet those duties. These workflows must be completed and verified before launch.
Questions
For compliance and privacy questions, use our contact form.