The short answer
Usually yes, but not the way most owners assume. Your host's redundancy protects its hardware, not your decisions. Real backup means a second copy you control that the credential which can delete the original cannot reach. In Canada the record-keeping duty sits with you, so "the host lost it" is not a defence.
Ask a small business owner whether their email is backed up and you will usually get some version of "well, it's in the cloud." That answer is not stupid. It is just answering a different question than the one that matters.
Your email provider does keep copies. It has to, because disks fail and servers catch fire and a provider that loses a customer's mailbox to a hardware fault does not stay a provider for long. That machinery is real and it works. But it is built to protect the provider's service from the provider's failures. Almost none of it is built to protect you from yours.
The three ways business email actually disappears
In practice, mail is almost never lost the way people picture it. Nobody's ten years of correspondence evaporates because a drive died. Here is what really happens.
Somebody deletes it. An employee clears out what they think is old clutter and takes a client folder with it. A departing staff member tidies their mailbox on the way out. Someone sets up a rule that quietly files four years of supplier invoices into a folder, then deletes the folder. Every one of these actions is performed with a valid password by a person who is allowed to do it. As far as the mail server is concerned, nothing has gone wrong at all.
The account gets compromised. An attacker who gets into a mailbox often does not just read it. Emptying folders and deleting sent items is standard practice for hiding an invoice-redirection scam, because the victim cannot see what was sent in their name. Again: valid credentials, ordinary commands, no failure for the provider to detect.
The bill lapses. A card expires while the owner is on vacation. Renewal notices go to a mailbox nobody watches, or to the mailbox that is about to be suspended. Services close accounts for non-payment, and closure eventually means deletion. This one is entirely preventable and it still happens constantly, usually to the business least able to absorb it.
Notice the pattern. In all three cases the provider's redundancy performs exactly as designed - it faithfully replicates the deletion. Redundancy answers "what if our hardware fails." Backup answers "what if the data is destroyed on purpose." They are different problems, and buying one does not get you the other.
Why the duty lands on you, not your host
This is where Canadian small businesses have a sharper problem than the general "you should have backups" advice suggests.
The Income Tax Act says every person carrying on business, and every person required to pay or collect taxes, shall keep records and books of account in such form and containing such information as will enable the taxes payable to be determined [1]. Those records must be retained, with every account and voucher necessary to verify the information in them, until the expiration of six years from the end of the last taxation year to which they relate [1]. If a return was never filed for a year, the six years runs from the day it is eventually filed [1]. If you object or appeal, you must keep everything relevant until that is finally disposed of [1].
The GST/HST side is parallel. The Excise Tax Act requires every person who carries on business or is engaged in commercial activity in Canada to keep all records necessary to determine their liabilities and obligations, and to retain them until six years after the end of the year to which they relate [2]. Those records are to be kept in Canada, in English or French, unless the Minister authorizes otherwise [2]. You may dispose of them earlier only with written permission [2].
Both statutes address electronic form directly: a person who keeps records electronically must retain them in an electronically readable format for the retention period [1][2]. So the fact that your quotes and invoices live in a mailbox rather than a filing cabinet changes nothing about the obligation.
Read the subject of those sentences. The obligation is on the person carrying on the business. There is no clause anywhere that says the duty passes to whoever you hired to run your mail. If the records are gone, the Act's remedy is aimed at you: where a person has failed to keep adequate records, the Minister may require that person to keep such records as the Minister specifies from then on [1]. "Our email host lost it" is an explanation, not a defence.
The privacy angle, which cuts both ways
PIPEDA's safeguards principle is worth reading closely, because most people remember only half of it. Security safeguards must protect personal information against loss or theft, as well as unauthorized access, disclosure, copying, use, or modification, and organizations must protect it regardless of the format in which it is held [3]. Loss is right there in the text, listed first. A mailbox full of customer correspondence that vanishes is not only an operational problem.
And if the loss came with an intrusion, there is a second document to produce. The Breach of Security Safeguards Regulations require an organization to maintain a record of every breach of security safeguards for 24 months after the day it determines the breach occurred [4]. Writing that record is dramatically easier when you still have a copy of what was in the mailbox.
Now the counterweight, which matters just as much. The same schedule says personal information shall be retained only as long as necessary for the fulfilment of the purposes it was collected for, that organizations should set minimum and maximum retention periods, and that information no longer required should be destroyed, erased, or made anonymous [3]. Backups are cheap; that is not a reason to hoard customer data indefinitely. A ten-year archive of every message anyone ever sent you is a bigger breach when it eventually leaks. Keep what the tax statutes oblige you to keep, keep what you actually use, and let the rest go on a schedule.
What makes a copy a backup
Here is the line, and it is the part nearly everyone gets wrong: a copy is only a backup if the credential that can destroy the original cannot destroy the copy.
This is why a synchronized second device is not automatically protection. IMAP exists precisely to keep a client and a server in agreement - the protocol allows a client to access and manipulate mail on a server, treating remote folders in a way that is functionally equivalent to local ones, and it provides for an offline client to resynchronize with the server [5]. Synchronization is the feature. DELETE permanently removes a mailbox [5], and EXPUNGE permanently removes every message flagged as deleted from the selected mailbox [5]. A well-behaved client is supposed to reflect all of that. Two laptops and a phone all showing the same account are not three backups; they are three windows onto one copy.
So the test to apply is a single question: if someone signed in right now with the office password and deleted everything, what would still exist an hour later? If the honest answer is "nothing", you do not have a backup no matter how many devices are involved.
What passes the test is unglamorous. A mail client configured to keep a genuine local store, on a machine that is itself backed up somewhere the mail password does not reach. A periodic export of key folders to a file on a drive under your control. An archive account that receives a copy and whose password nobody uses day to day. The mechanism matters far less than the separation.
When you honestly do not need to buy anything
Plenty of businesses are already covered and are about to be sold something they do not need.
If you are two or three people, each of you runs a desktop mail program that keeps a full local copy of every folder, and those computers get backed up - to an external drive, a household backup service, whatever - then you already have a second copy under a second credential. That is a backup. It is not elegant, the restore would be fiddly, and it depends on someone actually confirming the machine backup still runs. But it meets the test, and adding a paid backup service on top is paying twice for the same outcome.
The same goes the other way, and it is worth being blunt about it. If your staff all work in a browser, nothing is stored locally, and everyone shares one login, then no amount of provider redundancy is protecting you and you should fix that before anything else on your technology list.
Do this this week
Pick the mailbox that would hurt most to lose - usually the one that receives quotes, invoices, or client instructions. Sit down and answer one question in writing: if that account were emptied this afternoon, where is the other copy, and what password protects it? If you cannot name a copy that survives, the fix is one afternoon's work: turn on a full local copy in a mail program on one machine, confirm that machine is backed up somewhere the mail password cannot reach, and put a calendar reminder every quarter to open the local archive and check that a message from last year is still there. Then note the retention rules you are actually subject to, so you know what has to survive six years and what should be deleted long before that.