The client SMB
The business remains responsible for personal information it holds, even when Yeevy or a cloud or AI provider processes it. Its privacy officer approves the purpose, necessary data, EFVP/PIA, residual risk, and production use.
Last updated: August 5, 2026
Quebec SMBs should be able to improve their operations with AI without losing control of customer, employee, or business data. “Law 25” is the common name for the Quebec privacy reform whose obligations are now reflected in the Act respecting the protection of personal information in the private sector. Here is how we turn those obligations into project decisions. This page complements our privacy policy and is not legal advice.
Law 25 does not regulate every piece of business information or every use of AI. It applies when a private-sector organization collects, uses, shares, keeps, or destroys personal information: information that identifies a person directly or indirectly. An AI project that uses customer records, employee information, emails, recordings, support messages, identifiers, or inferred profiles can therefore be covered. The Commission d’accès à l’information expressly lists an artificial intelligence system as a system that can require a privacy impact assessment when personal information is involved.
The business remains responsible for personal information it holds, even when Yeevy or a cloud or AI provider processes it. Its privacy officer approves the purpose, necessary data, EFVP/PIA, residual risk, and production use.
Yeevy is directly responsible for information it collects for its own business. In a client mandate, we process only the information required by the written agreement, protect its confidentiality, report any confidentiality breach without delay, and do not keep it after the mandate unless the agreement and law permit it.
An AI or cloud provider is assessed as another service provider. Its location, subprocessors, training use, retention, access, security, incident notice, export, and deletion terms must be known. Processing outside Quebec requires an EFVP/PIA, adequate protection, and a written agreement.
For a typical Quebec SMB project involving personal information, the business should be able to show all of the following:
If a project uses only synthetic data or information anonymized according to law, some personal-information obligations may not apply. De-identified information is different: it remains protected, and the business must take reasonable measures against re-identification.
By default, prototypes use synthetic, redacted, or de-identified data. No sensitive personal information, client record, trade secret, or access credential is sent to an external AI service until the need, approved data, provider, applicable privacy impact assessment, contractual safeguards, and client authorization are documented. If the risk cannot be reduced to an acceptable level, we redesign or stop that use of data.
Law 25 protects information about an identifiable person. For an SMB, that can include customer and employee files, emails, recordings, support conversations, financial information, health information, identifiers, and information inferred by an AI system. De-identifying information reduces risk but does not automatically make it anonymous or remove it from privacy obligations.
Contracts, pricing, processes, source code, forecasts, and business strategy may be confidential even when they do not identify a person. Law 25 may not apply to that information in the same way, but we still protect it through the project agreement, access restrictions, provider controls, and an explicit list of information that is allowed or prohibited in the AI system.
Each project passes the following gates before production data is enabled. A failed gate means the data stays out while we change the design, choose another provider, or stop that part of the project.
We identify each source, field, data owner, affected group, destination, user, and retention need. We classify personal, sensitive, regulated, and confidential business information and identify credentials or secrets that must never be included in prompts or training material.
What you receive: a data-flow map and a permitted/prohibited data register.
We test whether the objective can be achieved without personal or confidential information, with fewer fields, or with synthetic, aggregated, redacted, or locally processed data. Consent does not replace the requirement that personal information be necessary for the stated purpose.
What you receive: a documented purpose, minimum dataset, and lawful-use assumptions for the client to confirm.
The client’s privacy officer is involved from the beginning. For an acquisition, development, or redesign of an information system involving personal information—including an AI system—a privacy impact assessment (PIA; EFVP in French) documents legal compliance, the data flow, affected people, risks, severity and likelihood, safeguards, residual risk, and approval. The assessment is also completed before personal information is communicated outside Quebec or entrusted to a person or organization outside Quebec to collect, use, communicate, or retain it. It is updated if the purpose, data, model, provider, or location changes.
What you receive: an EFVP/PIA decision record stating proceed, modify, or stop, with risks, owners, safeguards, and review dates.
We verify hosting and processing locations, subprocessors, model-training terms, prompt and output retention, security controls, access, incident notice, export, and deletion. Shared-model training is disabled by configuration and contract unless the client expressly authorizes it in writing and has a lawful basis. Any applicable transfer outside Quebec must provide adequate protection and be governed by a written agreement reflecting the EFVP.
What you receive: a provider assessment, required settings, and contractual control checklist.
We begin with synthetic or redacted data in an isolated environment. Access follows least privilege. Depending on the risk, controls include encryption, separation of environments, pseudonymization, audit logs, output filtering, and testing for data leakage, prompt injection, incorrect results, and inappropriate bias. Production data is enabled only after the controls are verified and approved.
What you receive: test evidence, an access matrix, and a production-readiness decision.
In production, we monitor access, failures, data leakage, and changes to the provider or model. Human review remains in the workflow for decisions that can significantly affect a person. Inputs, outputs, logs, provider copies, and backups follow the approved retention schedule, then are returned, deleted, or lawfully anonymized. The incident plan identifies who contains, assesses, records, and gives required notices for a privacy incident.
What you receive: a retention and deletion schedule, monitoring plan, incident procedure, and handover documentation.
Our default is that AI assists a person; it does not replace accountable human judgment for a decision that significantly affects someone.
If a client chooses a decision based exclusively on automated processing of personal information, we design the workflow so the client can give the required notice, explain on request the information and main factors used, correct inaccurate information, receive the person’s observations, and provide meaningful human review.
The SMB remains responsible for the personal information it holds and approves the purpose, data, residual risk, and production use through its privacy officer. Yeevy supplies the technical facts, performs the agreed controls, documents recommendations, and supports access, correction, consent-withdrawal, and incident obligations as a service provider. Legal counsel should validate novel, sensitive, regulated, or high-impact uses.
For information collected directly by Yeevy, contact Oleg Hmelevschi, Yeevy’s Privacy Officer — info@yeevy.ai · 514 346-2956.