Official DAC websitedeliveryaccountability.ca
Privacy & Data Handling

Consumer case records are not ordinary website data.

Delivery Accountability Canada is designed around separation: case information, security/audit records, public contact enquiries, voluntary project-support records and optional website analytics serve different purposes and should not be treated as one data pool.

Privacy Enquiry
Record separation

Different records have different purposes.

01

Consumer case records

Reports, incident details, evidence, case messages, status history, outcomes and referrals belong to the authenticated case-management system.

02

Security & audit records

Authentication events, administrator actions, evidence access, anti-abuse assessments and operational security events support platform integrity and accountability.

03

Public contact enquiries

General contact messages receive separate DAC-CON references. Case evidence should remain in the secure case workspace rather than the public contact form.

04

Project-support records

Interac e-Transfer and PayPal support records exist for financial reconciliation and transparency and are kept separate from consumer case priority and decisions.

05

Launch email subscribers

The pre-launch form stores the submitted name, email address, consent record and operational delivery status only for confirming the request and sending essential launch information. Confirmation and unsubscribe links are provided.

06

Optional analytics

Website analytics is a separate measurement layer. Analytics should not receive case numbers, narratives, evidence filenames, order numbers, contact messages or financial account information.

07

AI-assisted review

Where enabled, AI inputs should be minimized and redacted. AI assistance does not replace human responsibility for consequential case decisions.

Evidence protection

Evidence needs stronger handling than an ordinary attachment.

  • Private storageEvidence should be kept outside the public web root and served only through authenticated access.
  • File screeningUploads are designed for server-side type validation, malware scanning and review-state tracking.
  • Integrity checksSHA-256 file hashes can help detect unexpected modification of stored evidence.
  • Access historyEvidence access should be attributable so sensitive records are not viewed without accountability.
What not to submit

Only provide information necessary to understand the issue.

Passwords

Never send account or banking passwords.

Complete card numbers

Mask payment-card information before uploading screenshots.

Government ID

Do not submit identification unless specifically required through an approved process.

Unrelated private data

Remove information about other people that is not necessary for the consumer issue.

Your choices

Privacy controls should be understandable and revisitable.

Account holders can manage notification and consent-related settings in the secure portal. Formal access, correction, deletion or privacy requests may require identity verification before records can be disclosed or changed.

Account controls

Signed-in consumers can manage notification preferences and review account information.

Launch email choice

Launch messages require email confirmation. Every launch message includes a one-click unsubscribe link; unsubscribed addresses are suppressed from future launch sends. DAC retains the minimum suppression record needed to honour that choice and avoid resending.

Analytics choice

Optional analytics can be accepted or declined independently from necessary security and case functions.

Privacy enquiries

Use the Contact & Support Centre and select Privacy / data handling for general privacy questions.

Contact Privacy Support →

Public transparency

Aggregate public reporting is separated from individual consumer records and should not expose individual cases.

View Public Transparency →
AI Assistant privacy

Public questions and signed-in account questions follow different data boundaries.

The DAC AI Assistant is designed as an internal-knowledge assistant rather than an unrestricted web chatbot. Public mode has no client/account data access. Signed-in mode can receive only server-authorized information belonging to the current account when it is actually relevant to the question.

Public mode

Answers use indexed public DAC pages, verified DAC policy records and approved navigation. No case, evidence, contact, Network-member or account record is available.

Secure account mode

For relevant questions, DAC may provide minimal summaries from the signed-in user's own permitted records. The general assistant does not receive evidence-file contents or secure case-message bodies.

Chat continuity

DAC stores assistant conversation records for continuity, security and operational review under the configured retention period. Do not enter passwords, banking credentials or unnecessary sensitive information into chat.

Human handoff

If you request a human, DAC creates a Contact & Support request only after you confirm and submit the handoff form. Including the recent AI transcript is optional and off by default.

AI boundary: an AI answer is informational assistance, not a case decision, legal finding or promise of an outcome. When approved DAC information is insufficient, the assistant should say so and can route you to a human.

Language processing

Google Cloud Translation

Interface text

When a visitor selects a supported non-English language, DAC may send eligible interface text to Google Cloud Translation so the page controls, instructions and public information can be displayed in that language. Translation requests are proxied through the DAC server; the Google API key is not exposed to the browser.

Private records

DAC does not automatically send case narratives, uploaded evidence, case messages, names, email addresses, account identifiers or professional credentials to Google for interface translation. Private-content translation is disabled by default and would require a separate controlled workflow.

Original-record rule: machine-translated text is an accessibility aid. The original submitted record remains authoritative. Translation does not change consent, evidence, case status, audit history or legal meaning.