What we build

Consent, language and where the data lives, before a Canadian business hires

Wobble works from Karachi and has no Canadian office. The items worth writing down early are consent, language, where the data lives, and how few hours the two working days genuinely share.

Consent decides the design, so it comes first

Hiring an AI automation agency for a Canadian business is mostly a question of four settled items. Consent, because CASL decides how outbound can be built. Language, because bilingual delivery is a cost line. Where the data is stored, because Quebec runs its own privacy regime. And the working window, which between Canada and Karachi is short and has to be planned around.

Canada's anti-spam law, usually called CASL, governs commercial electronic messages, which covers the email and SMS an automation sends to a Canadian recipient. The obligations in plain terms are that you need consent, either express or implied in defined circumstances, that you identify yourself and provide contact details, and that you give an unsubscribe path that works and is acted on promptly. Confirm the current detail with your own adviser rather than with any automation supplier.

The reason this section is first rather than last is that it changes the data model, not just the copy. Consent has to be a stored field with a timestamp, a source and a type, attached to the person rather than to a campaign. A list that arrives as a spreadsheet from a previous agency, with no record of where the addresses came from, cannot responsibly be messaged, and no automation resolves that.

The second consequence is that an unsubscribe has to propagate everywhere. The classic failure is a person opting out of one sequence while a different workflow keeps sending, because it reads a different table that nobody remembered to connect. That is a design fault, and it is worth asking a supplier to explain how they prevent it before anything sends.

Privacy sits at two levels, and Quebec runs its own

Federally, private sector handling of personal information sits under PIPEDA. Several provinces have their own legislation covering some or all of it, and Quebec operates a distinctly stricter regime of its own. Which applies to you depends on where you operate and what you are doing, which is a question for your adviser rather than for a supplier.

The build consequences are much the same whichever applies. Collect only what the process needs. Be able to say where a person's information is held. Be able to produce or delete it on request. And know who else can see it, including the AI model providers a workflow sends text to, because that is a disclosure most businesses have never written down.

There is also a breach reporting obligation to plan for. From an automation point of view that means logs exist, are retained, and are readable by somebody who is not the person who built the system, so that a question about who accessed what has a factual answer rather than a reconstruction.

Bilingual is a cost line, not a checkbox

Quebec has language requirements affecting customer-facing communication, and plenty of national businesses serve customers in both official languages regardless of any legal trigger. Either way, bilingual support changes an automation build in ways that should be costed at the start rather than discovered in testing.

Every customer-facing string exists twice. Message templates, automated replies, the knowledge base an assistant answers from, transactional emails, and the error messages a customer might actually see. Each French version needs a reviewer who is genuinely fluent, because a machine-translated support reply reads as carelessness to the person receiving it, and that impression is expensive to undo.

There is also a routing decision that sounds obvious and is one of the more common defects in bilingual automation. The system has to detect or record a language preference and then keep using it. A customer writes in French, gets a French reply, and then receives the three-day follow-up in English because a different workflow never checked the field.

Ask for the template count

Ask any supplier to state how many customer-facing strings and templates are in scope, then plan the bilingual timeline around review rather than around build. The building is not twice the work. The review, approval and testing genuinely are.

Voice, messaging and the WhatsApp exclusion

Business-initiated WhatsApp calling is not available for Canadian recipients. Meta's exclusion list currently covers Canada, the United States, Egypt, Vietnam and Nigeria. This is Meta setting rules for its own platform, the list can change, and it should be confirmed in Meta's documentation rather than in anybody's proposal.

So a voice-first WhatsApp pattern that works in some markets does not transfer here. Canadian customer contact runs mostly on email, SMS and the telephone, each governed by the consent rules above and each with its own expectations about tone and timing.

This matters less than it first appears. The valuable part of a lead response system is the speed and completeness of the first reply and the reliability of the follow-up, not the channel it happens to arrive on. Design for the channel your customers already use with you, then measure whether a second one adds anything.

The working day you actually share

Karachi is UTC+5 with no daylight saving. Toronto sits nine or ten hours behind depending on the season, and Vancouver twelve or thirteen. A Karachi day extended to seven in the evening reaches Toronto at about ten in the morning eastern, which is a narrow window, and reaches Vancouver barely at all without somebody working very late.

The arrangement that works is asynchronous by default with one fixed synchronous hour a week. Blockers get posted at the end of the Karachi day so the Canadian morning can clear them, decisions are written down where both sides can find them later, and a demonstration is a five minute recording watched with coffee rather than a live call at an unkind hour for somebody.

Get the covered hours written into the agreement in Canadian time rather than the supplier's. It removes an entire category of misunderstanding for the cost of one sentence.

When to rule this out early

If your own policy, or a rule specific to your sector, puts personal information under a Canadian residency requirement, a team working from Karachi cannot sit inside the part of the system that touches it. Establish that in week one rather than in a security review three months later.

If your customer base is mostly French-speaking and nobody on your side can review French copy, the bottleneck will sit with you rather than with the supplier, and the project will move at the speed of that review. Line up a reviewer before the build starts.

If the work needs somebody physically present, hire locally for that part. A remote team can cover a great deal and cannot cover being in the room this afternoon.

And if your outbound lists have no record of where the contacts came from, fix that before automating anything that sends. Automation makes a consent problem faster, not smaller.

Who you would deal with, how soon the four items are settled, and what stays yours

The published work nearest to a Canadian arrangement is Zavcom, a United States internet, television and telephone provider, where AI-powered Google Search and call-only campaigns produced 89 conversions in ninety days at $1.54 a click, delivered alongside Wembly Studios. There is no Canadian engagement on the work page, and saying that is more use to you than a map with a pin in it. Wobble works from Karachi, bills month to month and is answerable for what it operates across 25 engagements in six countries. Moiz Khan owns automation architecture and decides what gets built and how it runs.

The four items above are settled in the first week, which is also the audit. Consent takes the longest, not because the rule is complicated but because the answer is usually that an existing list has no recorded provenance, and that finding changes the plan before anything is built rather than after. One named system is live inside a fortnight. Bilingual delivery is scoped in that same week rather than discovered in month two, because it is a cost line and treating it as a checkbox is how a Quebec engagement goes wrong.

Outbound is where the stop matters most in this market. One suppression list is checked by every workflow before anything sends, and where a consent position is ambiguous the system does not send at all. It hands it to a person to resolve. Anything published in your name, any change to spend and any complaint wait for human approval. A machine that resolves an ambiguous consent record in the sending direction is not a feature, it is a liability with a timestamp on it.

What stays yours is the consent record, and it is the most valuable thing this build produces. Consent per person with a timestamp, a source and a type, the single suppression list, and logs that let a position be evidenced rather than argued about, all sitting in accounts under your own logins, so you own the system and can answer a question about a message sent last year. Building the consent field with your own team is realistic and worth doing first, because it is a data model decision rather than an automation, and getting it wrong in-house is a great deal cheaper than getting it wrong at scale.

Common questions

How does CASL change the way messaging automation is built?

It moves consent into the data model. Consent becomes a stored field per person with a timestamp, a source and a type, every outbound workflow checks one suppression list before sending, sender identification lives inside the templates, and records are kept so a consent position can be evidenced. Confirm the current requirements with your own adviser rather than with a supplier.

Does Canadian privacy law apply to a supplier outside Canada?

Your obligations to your customers stay yours regardless of where a supplier sits, which is why the practical answer is written processor terms plus a clear record of where data is held and who can see it. Federally that sits under PIPEDA, some provinces have their own legislation, and Quebec runs a stricter regime. Your adviser should confirm which applies to you.

Can WhatsApp be used to call customers in Canada?

No. Meta's exclusion list for business-initiated WhatsApp calling currently covers Canada, the United States, Egypt, Vietnam and Nigeria. Meta sets that rule for its own platform and the list can change, so confirm it in Meta's documentation rather than in a proposal. Canadian contact mostly runs on email, SMS and the phone.

What does bilingual support actually cost in an automation build?

Less in build time than people expect and more in review time. Every customer-facing string exists twice, including templates, automated replies, knowledge base content, transactional emails and visible error messages, and each French version needs a genuinely fluent reviewer. The other cost is the language preference field, which every workflow has to read, not just the first one.

What working hours do we share with a team in Karachi?

A narrow window. Karachi is nine or ten hours ahead of Toronto and twelve or thirteen ahead of Vancouver, so a Karachi evening reaches the Toronto morning and barely touches Vancouver. The workable pattern is asynchronous by default, one fixed call a week, blockers posted at the end of the Karachi day, and covered hours written into the agreement in Canadian time.

When is a remote overseas partner wrong for a Canadian business?

When a Canadian residency requirement applies to the data in question, when the work needs somebody physically present, when your customer base is mostly French-speaking and no internal reviewer is available, or when existing lists carry no record of where the contacts came from. That last one needs fixing before automating anything that sends.

See where this applies to your business

The AI Readiness Call is a short, free conversation about where automation would actually pay back in your business. The call is free. The diagnosis is not.

Book AI Readiness Call