— Working across Canada

A technology partner for Canadian businesses, coast to coast.

SetKernel Digital Inc. is a Canadian engineering firm based in Halifax. We build websites and software, run IT and Microsoft 365, secure and migrate infrastructure, and put AI to work for businesses from St. John’s to Victoria. Most of the work is remote. What makes it Canadian is the context we bring to it: which privacy law applies to you, where your data should live, and what your insurer, your lender, and your largest customer are starting to ask for.

— Privacy law, province by province

One country, several privacy regimes.

Canada does not have a single private-sector privacy law. Which rules apply depends on where you operate, what kind of data you hold, and who you serve. We design systems to the regime that actually governs you, and we document the choices so your lawyer and your auditor can check them. We are engineers, not lawyers — for your specific obligations, confirm with counsel.

Federal — PIPEDA, and what may replace it

PIPEDA covers private-sector organizations in most provinces, plus federally regulated businesses everywhere. It already requires reporting breaches that create a real risk of significant harm, and keeping a record of every breach. A proposed replacement, Bill C-36, is before Parliament; until it passes, PIPEDA is the law, and we build to it while watching what changes.

Quebec — Law 25, fully in force

Quebec’s modernized private-sector law is in force: a named person in charge of personal information, confidentiality-incident reporting, privacy by default, and a privacy impact assessment before personal information leaves Quebec. That last point includes transfers to servers in other provinces — so “it is hosted in Toronto” is not automatically enough for a Quebec business.

British Columbia and Alberta — PIPA

Both provinces have their own Personal Information Protection Acts, recognized as substantially similar to PIPEDA, which govern most private-sector organizations there. Alberta has required notifying its commissioner of breaches that pose a real risk of significant harm for years. The mechanics differ enough from PIPEDA that incident plans should name the right regulator.

Nova Scotia — PHIA and PIIDPA

Health custodians in Nova Scotia work under PHIA. Public bodies — and the service providers that handle their personal information — are covered by PIIDPA, which requires that information be stored and accessed in Canada, with limited exceptions. If you supply a Nova Scotia public body, that requirement flows down to your systems.

— Data residency

Where your data lives, and who can be compelled to hand it over.

Residency and sovereignty are different questions. Residency is where the servers are. Sovereignty is whose law can reach the data. A Canadian region run by a US-headquartered provider keeps data physically in Canada, but that provider may still be subject to the US CLOUD Act, which lets US authorities compel a US company to produce data in its control wherever it is stored. For most businesses a Canadian region is a sensible, sufficient answer. For some contracts it is not, and it is better to know which one you have before you sign.

Canadian cloud regions

AWS, Microsoft Azure, and Google Cloud all run Canadian regions (in Montreal, Toronto, Quebec City, or Calgary depending on the provider). We pin primary storage, backups, and logs to them deliberately — the defaults are often elsewhere.

Cloudflare, with care

We build heavily on Cloudflare, a US company with a global network that includes Canadian data centres. Some plans offer controls over where data is processed and stored; where a requirement exceeds what the plan supports, we say so rather than pretend.

Canadian hardware you control

When a contract demands sovereignty, not just residency, the answer is infrastructure you own — Proxmox VE on hardware in your office or a Canadian data centre, run by a Canadian firm. More work to operate, and beyond doubt on location.

A written data map

Every architecture document we produce lists each system that holds personal information, where it is stored, and who can reach it. It is what you hand a procurement reviewer, and what catches the analytics or AI tool that would quietly send data offshore.

— What is changing

Pressures Canadian businesses are feeling right now.

Bill C-8 and your largest customers

Bill C-8 carries the federal critical cyber systems legislation for designated operators in federally regulated sectors such as telecommunications, banking, energy, and transportation. Those operators have to manage supply-chain and third-party risk, which means their suppliers — often small firms — start receiving security questionnaires, contract clauses, and requests for evidence. We help you answer them honestly and close the gaps they expose.

Cybersecurity

Cyber insurance wants evidence

Renewal forms now ask whether you enforce multi-factor authentication, run endpoint detection, keep backups that ransomware cannot reach, and patch on a schedule. A “no” can mean higher premiums, exclusions, or no cover. We put those controls in place and keep the evidence ready for the form.

The insurance readiness checklist

VMware licensing under Broadcom

Broadcom ended perpetual VMware licences and moved customers to subscription bundles, and many Canadian businesses with a handful of hosts saw renewal quotes jump. Proxmox VE is a credible exit for a lot of them. We plan and run the migration with rollback at each step.

VMware to Proxmox migration

BDC’s LIFT program

BDC launched LIFT in April 2026 to pair financing with advisory support for businesses adopting AI, digital, and cyber-security technology. It is BDC’s program: BDC sets the terms and decides eligibility, and we do not administer it. If you apply, we can supply the written scope and architecture document that turn an idea into a fundable project.

The AI readiness sprint

— Working with us from anywhere in Canada

Remote by design, and specific about it.

Time zones

Our working day runs on Atlantic time, which puts us half an hour behind Newfoundland and one to four hours ahead of the rest of the country. We schedule calls into the part of your day that overlaps ours, keep a written trail so work does not stall between calls, and agree at the start how urgent issues reach us.

English and French

We work in English primarily, with French available for written deliverables and meetings on request. This site is published in French, and engagement memos and architecture documents can be produced in the language you brief us in.

How a remote engagement runs

You send a short written brief. We reply in writing within one business day with a fit or no-fit answer. From there it is our five-step method — Brief, Architect, Sprint, Ship, Operate — with a written artefact at each step, video calls where they help, and remote access to the systems we manage.

When we travel

On-site support and break-fix stay in Atlantic Canada. Elsewhere, the work is remote. If a project genuinely needs someone in the room — a data-centre cutover, for example — we say so in the scope and agree the trip in writing before it happens.

— Questions

What Canadian businesses ask first.

Do you work with businesses outside Atlantic Canada?

Yes. We are based in Halifax and serve businesses across Canada remotely — websites, software, AI, cloud, cybersecurity, and managed IT for Windows and Microsoft 365 environments. On-site support is limited to Atlantic Canada; everywhere else, the work runs remotely with travel agreed in writing when a project needs it.

Can you keep our data in Canada?

Yes, and we document it. We pin storage, backups, and logs to Canadian cloud regions, or build on hardware in Canada that you control when a contract requires more than residency. We are candid about the limits: a Canadian region operated by a US-headquartered provider keeps data in Canada, but does not remove that provider’s exposure to US law.

We are in Quebec. Does Law 25 change how you work?

It changes what we document. Law 25 expects a privacy impact assessment before personal information is communicated outside Quebec, including to another province, so we make hosting locations explicit in the architecture document and flag every transfer. We can also work and deliver documents in French on request.

Is PIPEDA being replaced?

A replacement has been proposed — Bill C-36 — but it is not law yet. PIPEDA remains in force, and in Quebec, British Columbia, and Alberta provincial laws govern most private-sector organizations. We build to the rules in force today and design so that tighter consent and transparency requirements are a configuration change, not a rebuild.

Can you help us use BDC’s LIFT program?

BDC runs LIFT and decides who qualifies, so talk to BDC about eligibility and terms. What we can do is scope the AI, digital, or cyber-security project clearly in writing — the problem, the approach, the deliverables, and what it will take to run afterwards — which is the kind of document a financing conversation needs.

How do we start?

Send a short written brief: where you are, what you run or want built, and any constraints such as data residency, Law 25, or an insurance renewal date. We reply in writing within one business day with a fit or no-fit answer and, if it is a fit, the next step.

— Engage

Anywhere in Canada. Tell us what you need.

Two paragraphs is enough — where you are, what you run or want built, and what is in the way. We reply in writing within one business day.

Esc