Essai

Why Host Your Data in Canada? Sovereignty, Privacy, and Legal Obligations for Condo Associations

14 min read
Why Host Your Data in Canada? Sovereignty, Privacy, and Legal Obligations for Condo Associations

When a condo association picks a management software, the question of where the data is hosted usually comes last: you look at the features, the price, the ease of use. Yet the geographic and legal location of the servers has concrete implications for confidentiality, legal compliance, the board's liability and even the resale value of the units. This is not a technical detail: it is a decision that commits the condo association for several years. Here, in plain terms, is what every board member should understand before signing with a SaaS provider.

The problem: where does your condo data go?

Most property management SaaS used in Quebec are American. Buildium, AppFolio and Yardi come to mind, all leaders of the North American market. Their servers are operated by American companies, which places them under United States jurisdiction even when the data is physically stored in Canada through a local hosting partner. That nuance is crucial: "stored in Canada" and "operated by a Canadian company" do not mean the same thing legally.

And the problem does not stop at management software. Most of the peripheral tools condo boards use day to day are American too: Google Workspace for email and shared calendars, Dropbox or Google Drive for documents, DocuSign for electronic signatures, Zoom for virtual meetings, Slack or WhatsApp for board discussions. All operated by companies subject to the CLOUD Act, regardless of where their servers physically sit.

What this means concretely for a condo association: resident emails, general meeting minutes, detailed financial statements, the contingency fund's banking details, property tax notices, co-owner names and addresses, all of it may be stored on legally American infrastructure, accessible to foreign authorities under certain conditions. For a 12-unit building, the volume of personal data accumulated over three or four years is considerable.

What is the American CLOUD Act?

The Clarifying Lawful Overseas Use of Data Act (CLOUD Act) was passed in March 2018 by the United States Congress under the Trump administration, and has been in force ever since. Its principle is simple but heavy with consequences: it lets the American government compel access to data held by any American company, no matter where that data is physically stored in the world. The statute grew out of the well-known Microsoft Ireland dispute of 2013 to 2018, in which Microsoft refused to hand the FBI emails stored in Ireland. The CLOUD Act settled it: wherever the servers are, the American company must comply.

The law applies notably to Google (Google Cloud, Gmail, Drive, Workspace), Amazon (AWS, the largest cloud provider in the world), Microsoft (Azure, OneDrive, Outlook, Teams), Apple (iCloud), Meta (WhatsApp, Messenger), and to every SaaS hosted on those infrastructures. Even a small Canadian SaaS hosted on AWS is technically exposed: its infrastructure provider is American.

In practice, a CLOUD Act request follows American judicial procedure: a federal prosecutor presents a warrant to the company, which may try to challenge it before an American judge. The end client is generally not notified, except under strict conditions. For a Quebec condo association, that means its data could be examined without it ever finding out.

Concretely, a Quebec condo association that uses Gmail for its communications, Dropbox for its documents and an American management software: its data is potentially accessible to American federal agencies, with no notice to the owner and no practical recourse under Canadian law. The risk is diffuse but structural.

To go further, the official text of the CLOUD Act is available on the United States Congress website: congress.gov/bill/115th-congress/senate-bill/2383.

Since September 2022, Quebec applies Law 25 (An Act to modernize legislative provisions as regards the protection of personal information). It imposes several obligations that bear directly on condo associations, treated as "organizations" within the meaning of the Act:

  • Minimal collection: collect only the data strictly necessary for the purpose of the processing
  • Explicit consent from the people concerned, manifest, free and informed
  • Right of access and rectification of the data by the people concerned
  • Localization requirement or privacy impact assessment for certain categories of sensitive information transferred outside Quebec
  • Mandatory notification to the Commission d'accès à l'information (CAI) and to the people concerned in the event of a confidentiality incident presenting a serious risk

Law 25 provides for two sanction regimes, and the distinction matters. Administrative monetary penalties, imposed directly by the Commission d'accès à l'information without going through the courts, can reach 10 million dollars or 2 percent of worldwide turnover. Penal sanctions go up to 25 million dollars or 4 percent. That makes it one of the most severe data protection laws in the world. For a condo association, the immediate risk is more measured: a complaint from an unhappy co-owner to the CAI, which can trigger an investigation and impose corrective measures. The reputational and trust stakes, though, are considerable.

The full text of Law 25 is available on LégisQuébec: legisquebec.gouv.qc.ca/en/document/lc/P-39.1.

At the federal level, PIPEDA (Personal Information Protection and Electronic Documents Act) imposes similar rules on the Canadian private sector across the country. The two regimes complement each other and apply simultaneously to Quebec condo associations. PIPEDA is generally less strict than Law 25 on consent, but it enshrines the same fundamental principles: transparency, purpose, security, access.

A concrete case: what can go wrong

Picture a plausible scenario. An eight-unit condo association in Montreal has used an American SaaS for three years to handle its charges, its budget and its minutes. The provider stores the names, addresses, phone numbers and payment histories of every co-owner, plus the association's banking details. One day, following an American investigation with no direct connection to the association (say, an inquiry into another of the provider's clients, or a generic administrative demand), a CLOUD Act warrant compels the handover of large volumes of data. The association is not informed, because the provider is under no obligation to inform it, and its data is examined without its consent.

An even likelier case: a data breach at the American SaaS provider exposes the contact details and payment histories of hundreds of thousands of North American co-owners, including those of the association. Under Law 25, the association is responsible for notifying the CAI and its co-owners "with diligence." But the American provider may take weeks or months to supply the details of the breach, and may never clearly confirm the exposure. The association ends up in a legal grey zone, without reliable information, exposed to complaints.

These scenarios are not theoretical: massive data breaches at SaaS providers have become routine (LastPass, Okta, MOVEit, and others). And every time, downstream clients discover the exposure long after the fact.

How to assess your current provider

Before signing or renewing with a SaaS provider, here are the concrete questions to ask. The absence of a clear answer is itself an answer.

  • Where are the servers that store our data physically located? A vague answer along the lines of "North America" is not good enough.
  • Who is the legal operator of the servers? A Canadian subsidiary is not enough if the parent company is American.
  • Are you subject to the CLOUD Act? The honest answer is almost always yes for American SaaS, even through a Canadian subsidiary.
  • What is your notification policy for foreign government requests? Look for a contractual commitment, not a mere best-effort promise.
  • How do you guarantee compliance with Law 25 and PIPEDA? Ask for the technical detail, not a marketing page.
  • What is your export procedure on termination? Check the format, the timeline, and the absence of hidden fees.

These questions may feel intrusive, but they should be routine for any serious provider. A provider that refuses to answer in writing is a warning sign.

The hidden cost of moving to a Canadian solution

Many condo associations hesitate to migrate for fear of the cost and the disruption. That is understandable but usually overestimated. For a small association (4 to 20 units), moving to a Canadian solution typically takes between 3 and 8 hours of work spread over a few weeks: exporting the data from the old tool, importing it into the new one, checking consistency, and telling the co-owners.

The direct financial cost is nil or low: most Canadian providers (Kohabit among them) offer free access during the migration phase and then charge rates comparable to American SaaS, and lower for small associations. For reference, Kohabit charges 2.99 CAD per unit per month, which is under 30 dollars a month for a ten-unit building, with every feature included.

The hidden cost is actually elsewhere: it is the cost of doing nothing. As long as the data stays on an American SaaS, exposure to the CLOUD Act and the risk of Law 25 non-compliance persist. That risk does not materialize every day, but when it does, the consequences are out of proportion.

Comparison: data in Canada vs. in the United States

CriterionCanadian hosting (Kohabit)American hosting (American SaaS)
Applicable lawPIPEDA + Law 25CLOUD Act + local law
Access by the US governmentNoPossible without notification
Law 25 complianceNativeTo be checked case by case
Right to portabilityGuaranteedVaries by contract
Confirmed locationPlatform in QuebecOften multi-region
Recourse in a disputeCanadian courtsOften American jurisdiction
Third-party trackersNone (self-hosted Umami)Varies (often Google Analytics)

What "hosted in Canada" concretely means at Kohabit

When Kohabit says "hosted in Canada," here is what that covers technically:

  • Physical location of the servers: Beauharnois, Quebec, with OVH Hosting Inc., the Canadian entity of the French group OVHcloud. Platform data, database, documents and media, stays in Quebec. Only notification emails travel through our sending provider, whose current region is American (see the FAQ below).
  • No American subcontractor for the storage of sensitive data: neither AWS, nor Google Cloud, nor Azure for the main databases
  • Data subject to Canadian law only: Quebec's Law 25 and federal PIPEDA
  • No exposure to the CLOUD Act: that law reaches American companies, which OVHcloud is not. No American procedure can therefore compel access to this data
  • Right to portability: your data belongs to you. On request it is returned to you in an exportable format, and deleted from our servers within 30 days of the account being closed (see our privacy policy)
  • No third-party trackers: no Google Analytics, Facebook Pixel, Hotjar or anything similar. Usage statistics are produced by Umami, self-hosted in Canada

This approach is not just a marketing choice: it is an architectural decision with operational consequences. It narrows the pool of available infrastructure providers and forces us to favour solutions that are sometimes less mature than their American equivalents. It is a trade-off we accept in favour of digital sovereignty.

Frequently asked questions

Is my data really in Canada? How can I check?

The best practice is to ask the provider for a written attestation of where the servers are and what is subcontracted. Kohabit provides that information on request, with the names of the data centers used and the applicable certifications. To check technically, you can use an IP traceroute tool (free online) to identify the network route to the main server and confirm that it stays in Canada.

Can the CLOUD Act really affect my six-unit condo association?

Yes, in principle. The CLOUD Act draws no distinction by size: it applies to all data held by an American company. In practice, American authorities are obviously not interested in a six-unit condo association specifically, it is a question of proportionality. But the legal principle stands: your data is not under the exclusive protection of Canadian law, and a breach at the provider can expose you indirectly.

Are there exceptions to the CLOUD Act?

The CLOUD Act provides for a mechanism of bilateral agreements ("Executive Agreements") with certain allied countries to limit cross-border requests. No such agreement exists between the United States and Canada to date (May 2026). So in practice, for data held by American companies operating in Canada, the CLOUD Act applies with no formal diplomatic safeguard.

Are the outgoing emails sent by the platform also under the CLOUD Act?

Good question, and one that is rarely asked. A notification email often copies an excerpt of the content, an announcement title or a maintenance request description: the exposure is real, even when the main platform is Canadian. If your provider routes its email through an American service such as SendGrid (Twilio group) or Amazon SES, those excerpts travel through infrastructure subject to the CLOUD Act.

Our own answer, in full transparency: the domain's mail goes through ProtonMail, in Switzerland. Transactional email goes through Mailgun, which has belonged to the Swedish group Sinch since 2022, but whose American sending region we currently use. The content of our notifications is therefore processed in the United States, and that is the only part of our chain that leaves Canada. Mailgun offers a European region, sealed off from the American one, and that is where we are heading. We would rather write it down than let you find it out: this is exactly the question to ask any provider, including us.

What happens if Kohabit is acquired by an American company?

That is a legitimate question, and the honest answer is that no contractual clause fully protects you from a change of shareholder. What protects you in practice is being able to leave: your data belongs to you, it is returned on request in an exportable format, and nothing binds you beyond your current subscription period. A tool you can walk away from with your data is a tool whose acquisition matters less to you.

What are the Canadian alternatives to the common American tools?

For email: ProtonMail (Switzerland, outside US jurisdiction), Hey (Canada, via Basecamp), Tutanota (Germany, subject to strict GDPR). For file storage: Sync.com (Canada), pCloud (Switzerland). For electronic signatures: DocuSign has a Canadian residency option if you explicitly ask for it, otherwise Signéo (Quebec). For video conferencing: self-hosted Jitsi, or Whereby (Norway, GDPR).

Does Kohabit use any American third-party services?

Kohabit's principle is to keep American dependencies to the strict minimum. No American third-party tracker (Google Analytics, Facebook Pixel, Hotjar) is used on the platform. For internal usage statistics, Kohabit uses Umami, a privacy-respecting analytics tool, self-hosted on the Canadian infrastructure, with no cookies and no profiling.

Going further

For more on the regulatory compliance of condo associations, see our page on the Bill 16 maintenance log in Quebec, which details the specific obligations around the maintenance log and the contingency fund.

Want to see concretely how a tool guarantees this sovereignty? See how Kohabit keeps your data in Canada: Canadian operator hosting, encryption, audit log and an Law 25 compliance file provided. Choosing a tool is only one decision among many: our guide to self-managing a small condo association covers the whole of a volunteer board's work.

Kohabit is built to be a credible Canadian alternative to the American tools: create your account and try it free for a month, with no credit card, and keep your data under Quebec jurisdiction from day one.

Sources

  • CLOUD Act (2018), full text on congress.gov
  • Law 25 on the protection of personal information, on LégisQuébec
  • PIPEDA, Office of the Privacy Commissioner of Canada
  • Microsoft Corp. v. United States (Microsoft Ireland), United States Supreme Court

Written by Ben, founder of Kohabit and volunteer board member of his own condo association. This article is informational and does not replace legal advice: for a specific compliance situation, consult a lawyer specializing in privacy law.

Published on May 8, 2026 updated on August 23, 2026

Ready to simplify your condo management?

Try Kohabit free for 1 month, no credit card required. Create your account in minutes.

No credit card required · Cancel anytime