Policies Internal operating policies

AI Vendor Policy

Standards that AI vendors must meet to handle Map.ca traffic — data handling, training restrictions, audit requirements.

Version
0.1.0
Effective
May 20, 2026
Last reviewed
May 20, 2026
Review cycle
every 6 months
Master Policy Index entry
§4 #34

Policy text

Map.ca uses AI vendors. The AI Vendor Policy is how Map.ca makes sure that using a vendor does not silently undo the AI Use Policy. It defines the contractual exclusions (no Map.ca data used to train the vendor’s models), the data-handling tier each vendor is bound to, the data-residency requirements, the sub-processor disclosure cadence, the audit-log requirements, and the termination rights Map.ca preserves when a vendor changes its practices.

It applies to every AI vendor handling Map.ca traffic, Map.ca’s procurement and AI teams, and the security reviewers who evaluate vendor changes.

Principles this policy enforces

  • AI assists, people remain responsible
  • Consent must be meaningful
  • Collect less, protect more
  • Public data and personal data are not the same thing

What it requires

  • Contractually exclude Map.ca data from any vendor training pipeline.
  • Bind vendors to a documented data-handling tier.
  • Require sub-processor disclosure and a meaningful notice period for changes.
  • Preserve audit-log access on demand.

What it forbids

  • Do not allow vendor use of Map.ca data for training without separate, explicit permission.
  • Do not allow sub-processor changes without notice.
  • Do not allow data exfiltration to unauthorized jurisdictions.
  • Do not waive audit rights for commercial convenience.

How it applies

References