Skip to content
Security & Compliance — Québec

Security & Law 25 Compliance

How BatiCore protects your data and helps you comply with Law 25 — Last updated: July 15, 2026

Trust first

BatiCore handles your estimates, your job sites and your clients' information. Here is concretely what protects that data — and, transparently, what is still to come.

Measures in place

🏢
Per-company isolation
Each company is partitioned: every query is filtered by your organization's identifier, taken from your session. Your data never crosses another company's.
🔑
Role-based access control
Seven roles (owner, admin, commercial manager, finance, estimator, site foreman, field worker) with fine-grained permissions. Each member only accesses what they need.
🧾
Tamper-evident audit log
Sensitive actions are recorded in a hash-chained log, designed to make any alteration detectable — a key Law 25 expectation.
🔒
Encryption of sensitive data
The most sensitive information, such as employees' social insurance numbers, is encrypted at rest (AES-256-GCM).
🛡️
Hardened authentication
Temporary lockout after repeated failures, two-factor authentication (TOTP) with backup codes, and controlled "remember me" sessions.
✍️
LCCJTI electronic signature
Estimates signed in the client portal carry legal value in Quebec (LCCJTI): timestamped consent, traceability and a locked document.
💾
Backups & restore
Regular database backups, with a tested restore procedure to limit any data loss.
📈
Monitoring & alerts
Continuous server-error detection and alerts, to react quickly to a technical incident.

What is Law 25?

The Act to modernize legislative provisions as regards the protection of personal information (Law 25, formerly Bill 64) has come into force progressively since 2022 in Québec. It applies to every business that collects, uses or discloses the personal information of Québec residents.

As a general contractor, you collect personal information (names, addresses, phone numbers, emails, banking details) from your clients and employees. Law 25 imposes obligations on you.

What BatiCore does for you

🔐
TLS encryption + AES-256 secrets
Data is encrypted in transit (TLS/HTTPS). At rest, the most sensitive secrets (SIN, MFA secrets) are AES-256 encrypted; client data is isolated per company (RBAC + multi-tenant isolation). Encryption at rest for the remaining client data is planned.
📋
Processing register
BatiCore provides a Compliance → Law 25 space to document and review your personal-data processing activities.
Retention periods
Configure the retention periods for your client data. BatiCore alerts you before automatic deletion.
🤖
AI anonymization
The AI Copilot automatically anonymizes personal data before sending it to the Anthropic API.
📥
Access requests
BatiCore helps you handle your clients' access or rectification requests within 30 days (the legal deadline).
🔔
Incident notification
In the event of a privacy incident, BatiCore provides a report template to submit to the Commission d'accès à l'information.

Your obligations as a business

ObligationStatusHow BatiCore helps
Designate a privacy officer (RPRP)In effectCompliance module → Law 25 → Configure the RPRP
Register of privacy incidentsIn effectDedicated space under Compliance → Law 25
Privacy impact assessment (PIA)In effectPIA template provided under Compliance → Law 25
Explicit consent for sensitive dataIn effectClient portal: consent recorded at each signature
Right to erasure on requestIn effectOn request to privacy@baticore.ca — handled within 30 days (deletion or anonymization)
Transparency of automated decisionsIn effectDetailed in the Privacy Policy (Automated decisions section)
Transfers outside Québec covered (PIA)In effectHosting (application, API, database, files) in Canada — Amazon Web Services, Montréal region (ca-central-1). Transfers outside Quebec limited to U.S. subcontractors (Stripe, Resend, Anthropic) and a European one (Geoapify — address geocoding), covered by s. 17 of Law 25 / PIA (see Privacy Policy).

BatiCore acts as a processor

Within the meaning of Law 25, BatiCore acts as a processor — you are the controller of your client data. BatiCore processes your data only on your instructions and to provide the service.

BatiCore undertakes to:

  • Never sell your data to third parties
  • Use your data only to provide the BatiCore service
  • Notify you within 72 hours of any security incident
  • Provide you with a full export of your data on request
  • Permanently delete your data within 30 days of termination

Full transparency

We would rather be honest about what is not yet in place than over-promise:

  • Encryption at rest of client contact details (email, phone, address): planned, in addition to the encryption already applied to the most sensitive data.
  • External penetration test (pentest) and OWASP review: planned before scaling up.
See our full Privacy Policy →
A question about security?

Write to us at support@baticore.ca

This content is provided for informational purposes only and does not constitute legal advice. To assess your compliance, consult the Commission d'accès à l'information or a legal advisor.

Questions about Law 25 compliance: privacy@baticore.ca

Privacy officer (RPRP): Cliford Saint-Natus, founder · privacy@baticore.ca · Solutions BatiCore Inc. · Saint-Basile-le-Grand, Québec, Canada