B2B SaaS vendor track

A B2B SaaS vendor plays two roles: responsible party for its own data (employees, prospects, metrics) and service provider for the information its customers put in the product (s. 18.3: written contract, use limited to the mandate, notice in case of incident).

Multi-tenancy and isolation

A leak between customers is a confidentiality incident. Enforce isolation at the database level:

ALTER TABLE documents ENABLE ROW LEVEL SECURITY;
CREATE POLICY tenant_isolation ON documents
  USING (tenant_id = current_setting('app.tenant_id')::uuid);

Test isolation automatically (cross-tenant integration tests) with every release.

Service data vs telemetry

Separate the data needed to perform the contract from telemetry and marketing: distinct schemas or databases, opt-in for analytics, traced consent (immutable log).

AI and LLMs

Do not train a model (internal or third-party) on customer data without the customers' explicit written consent; check AI providers' retention and training clauses.

Location and subprocessors

Hosting in a Canadian region (e.g. ca-central-1) simplifies the assessment; a US region triggers a PIA (s. 17). Every new supplier (payments, email, analytics, AI) goes through RPRP validation, and the subprocessor catalogue is kept up to date.

When a customer leaves

At contract end: final data export, then deletion (including backups on their cycle) and written confirmation.