Privacy Policy
This Privacy Policy is issued by the Company. The Company's full identity, address, and legal contact details appear at the bottom of this page. It describes how we collect, use, share, and protect personal information when you use the Platform, whether as a Customer (the organization that subscribes to the Service) or as a User acting on a Customer's behalf. It applies to the entire Service, including its artificial-intelligence-powered features (text and voice conversational agents). By using the Service, you acknowledge that you have reviewed this policy.
Table of Contents
- Definitions
- What data we collect
- Why we use it
- Our legal basis
- How data flows to third parties
- Cookies and similar technologies
- How long we keep your data
- How we protect your data
- International transfers
- Your rights and how to exercise them
- Minors
- Changes to this policy
1. Definitions
> In short: a few terms recur throughout this document; here they are, defined once.
"Service" means the multi-tenant cloud platform operated by the Company, including its artificial-intelligence-powered text and voice conversational agents, its web interfaces, and any related functionality.
"Customer" means the organization that subscribes to the Service and on whose behalf Users act.
"User", "you" means any natural person who accesses the Service, whether acting on their own behalf or on behalf of a Customer.
"Personal information" means any information relating to a natural person that allows that person to be identified, directly or indirectly.
"Subprocessor" means a third party to whom the Company entrusts the processing of personal information on the Company's behalf, in connection with the provision of the Service.
2. What data we collect
> In short: account data you provide to us, content generated when you or your contacts interact with our conversational agents, and technical data collected automatically.
We collect three broad categories of information:
2.1 Account data. Name, business email address, job title, login credentials, and any information provided when creating an account, registering a Customer, or managing an organization's members.
2.2 Content generated through conversations and artificial intelligence. The content of exchanges held with the Service's conversational agents — text, voice transcripts, associated metadata (timestamp, channel used, outcome of the exchange) — as well as the outputs produced by artificial intelligence features when activated by the Customer.
2.3 Usage and technical data. Information generated automatically by your use of the Service: IP address, device and browser type, pages viewed, actions taken within the interface, technical and connection logs, and the information described in the Cookies and similar technologies section.
When the Customer voluntarily connects a third-party account (business messaging, instant messaging, email, calendar), information from that third-party account may also be processed as part of the Service, to the extent permitted by that third-party account and in accordance with the authorizations granted by the Customer.
3. Why we use it
> In short: we use your data to run the Service, secure it, bill for it, and improve it — never beyond those purposes.
We use the information described above for the following purposes:
- Providing the Service: creating and managing accounts, enabling access to subscribed features, ensuring the day-to-day operation of the Platform.
- Artificial intelligence features: processing text and voice conversations through the conversational agents, generating responses and, where applicable, voice synthesis or video avatars, when these features are activated by the Customer.
- Security and fraud prevention: detecting unauthorized access, preventing abuse, maintaining the integrity and availability of the Service, including through audit logging of sensitive actions.
- Billing: processing payments for Customers with a paid subscription.
- Improving the Service: analyzing aggregated usage to fix defects, prioritize features, and improve the Platform's performance and usability.
We do not use your personal information for purposes incompatible with those set out above without obtaining your additional consent, where such consent is required.
4. Our legal basis
> In short: consistent with applicable Quebec privacy law, we process your data either because the contract between us requires it, because we have a properly scoped legitimate interest, or because you consented to it.
In accordance with the Act respecting the protection of personal information in the private sector (Quebec, commonly known as "Law 25") and the Personal Information Protection and Electronic Documents Act (PIPEDA, federal), each processing of personal information we carry out relies on one of the following bases:
- Performance of the contract binding us to the Customer or to you, where processing is necessary to provide the subscribed Service.
- Our legitimate interests, properly scoped and proportionate, in particular to secure the Platform, prevent fraud, and improve the Service, to the extent such interests do not unjustifiably override your rights and freedoms.
- Your consent, in particular for non-essential cookies (analytics and marketing) described in the Cookies and similar technologies section, and for any other purpose that legally requires it.
- Compliance with legal obligations, where the law requires us to retain or disclose certain information.
5. How data flows to third parties
> In short: we rely on providers to operate the Service; the complete list of those providers and the contractual safeguards governing them appear in two separate documents in our legal catalog.
In the normal course of operating the Service, certain information is disclosed to third-party providers acting as subprocessors of the Company, in particular for infrastructure hosting, payment processing, artificial-intelligence-based language and voice processing, or the integration of third-party accounts the Customer chooses to connect. These providers act only on our instructions and solely for purposes necessary to provide the Service.
The detailed, category-by-category list of providers we rely on appears in our Subprocessor List, maintained separately and kept up to date. The contractual safeguards governing these transfers — including the obligations imposed on our subprocessors regarding the protection of personal information — appear in our Data Processing Agreement. We never sell your personal information.
6. Cookies and similar technologies
> In short: the Service uses essential, analytics, and marketing cookies; you can manage and withdraw your consent for the latter two categories.
The Service uses cookies and similar technologies grouped into three categories: essential (necessary for the Platform to function), analytics (aggregated usage measurement), and marketing (personalization of communications). You can review, manage, and withdraw your consent for the analytics and marketing categories at any time through the cookie settings built into the Service. The detail of each category, the technologies used, and your management options appear in our Cookie Policy.
7. How long we keep your data
> In short: we keep your data only as long as necessary for its purpose; automated retention periods already apply to several technical categories, and the complete detail lives in a dedicated document.
We retain personal information only for as long as necessary for the purposes described in this policy, or as required by applicable legal obligations, after which it is deleted or anonymized. For example, connection and technical verification logs are automatically purged after 30 days by default, and audit logs are automatically purged according to a duration defined per category. Other technical categories are subject to dedicated automated retention policies. Exports of personal data produced in response to an access request are provided via a download link with a limited lifetime, which expires automatically. The complete, category-by-category detail appears in our Data Retention Policy.
8. How we protect your data
> In short: isolation of data by client organization, encryption, role-based access control, and audit logging — a security program under continuous improvement, not a label we've obtained.
We implement administrative, technical, and organizational security measures proportionate to the sensitivity of the information processed, including in particular:
- isolation of data by client organization at the database level, through a row-level security policy applied systematically;
- encryption of data in transit (TLS) and encryption at rest provided by our hosting infrastructure;
- role-based access control for administration of the Platform;
- timestamped audit logging of sensitive actions.
Our security program is under continuous improvement. As no security measure is infallible, we cannot guarantee absolute protection against every incident. The detail of our security practices appears in our Security Overview.
9. International transfers
> In short: your data may be hosted and processed in North America by our cloud infrastructure providers; the detail of processing locations appears in a dedicated document.
The Service's core infrastructure (database, authentication, storage, application hosting) is hosted, and personal information is processed there, in North America, through our cloud infrastructure providers. Certain specialized subprocessors — in particular those related to artificial intelligence, voice synthesis, video avatar generation, or the third-party messaging gateway — may nonetheless process data outside this zone, or even outside Canada. When personal information crosses a provincial or national border, we take reasonable measures to ensure it receives adequate protection, having regard to applicable requirements. The detail of processing jurisdictions, provider by provider, appears in our Data Residency & Transfers document.
10. Your rights and how to exercise them
> In short: you can request access, correction, deletion, or export of your personal information, and withdraw your consent, through a built-in request system that tracks each request through to resolution.
In accordance with Law 25 and PIPEDA, you have the following rights over your personal information:
- Right of access: obtain confirmation that we hold information about you and obtain a copy of it.
- Right of rectification: have inaccurate, incomplete, or ambiguous information corrected.
- Right to erasure: request deletion of your personal information, subject to our legal retention obligations.
- Right to portability: receive your information in a structured, commonly used format.
- Right to object and to withdraw consent: object to certain processing or withdraw consent already given, in particular for analytics and marketing cookies.
- Right to lodge a complaint with the Commission d'accès à l'information du Québec, or with the competent data protection authority.
How to exercise these rights. The Service includes a built-in system for requesting data export, deletion, and correction, accessible directly within the Platform. Each request you submit receives a tracked status (pending, in progress, completed, or refused) along with a processing history specifying who handled it, when, and the reason for any refusal. Data exports are provided via a download link with a limited lifetime, which expires automatically after a set period. If you are unable to use this system or wish to exercise your rights otherwise, you may contact us using the details below.
Additional rights depending on your jurisdiction. If you reside in the European Union, the European Economic Area, the United Kingdom, or California, you may have additional rights under the General Data Protection Regulation (GDPR) or the California Consumer Privacy Act/California Privacy Rights Act (CCPA/CPRA), including rights of access, portability, objection to profiling or to the sale of information, and the right to designate an authorized agent to exercise these rights on your behalf. We process such requests to the best of our ability, taking into account the requirements specific to each regime, without this policy asserting full compliance with or certification under these foreign frameworks.
11. Minors
> In short: the Service is not intended for children; it is the Customer's responsibility to ensure its Users meet the required age.
The Service is intended for professional use by organizations and their Users, and is not designed or intended for use by children. Where a Customer's end-contact data is processed as part of the Service, it is the Customer's responsibility to ensure that the processing of such data, including that of minors where applicable, complies with applicable law and to obtain any consent required for that purpose.
12. Changes to this policy
> In short: we may change this policy; material changes will be communicated to you before they take effect.
We may modify this Privacy Policy from time to time, in particular to reflect changes in our practices, in the Service, or in applicable law. Any material modification will be communicated to you through reasonable notice, in particular by email or by a notice displayed within the Service, before it takes effect. The date of the last update appears at the bottom of this page. We encourage you to review this policy periodically. Your continued use of the Service after a modification takes effect constitutes your acceptance of the revised policy.