1. Who we are
HelionAI is a Law 25 compliance platform operated by LeapVision Technologies Inc. ("LeapVision", "we", "us", "our"), a corporation incorporated in Quebec, Canada (NEQ 1181486631, BN 757702436). HelionAI is the brand and the service; LeapVision Technologies Inc. is the organization responsible for the personal information processed through the service.
- Controller (organization): LeapVision Technologies Inc.
- Address: 206 Rivermere, Saint-Lambert, Quebec, Canada J4R 2G1
- General email: hello@helionai.ca
This policy explains what personal information we collect, why, how we use and protect it, and the rights you have under Quebec's Act respecting the protection of personal information in the private sector ("Law 25") and other applicable laws (including Canada's federal PIPEDA).
2. Person in charge of the protection of personal information
In accordance with Law 25, we have designated a person responsible for the protection of personal information. This person oversees compliance with this policy and handles your requests and complaints.
- Person in charge of personal information protection: JP Bray, Chief Executive Officer, LeapVision Technologies Inc.
- Email: privacy@helionai.ca
Note: where no person is expressly designated, Law 25 provides that the role falls by default to the person with the highest authority in the organization. The CEO of LeapVision Technologies Inc. holds this responsibility until an express delegation is recorded.
3. What we collect and why
We collect only what is necessary for the purposes described below, depending on the surface you interact with.
3.1 Free assessment (public-signals "scan")
- What we collect: your business email and the domain name of the website you ask us to scan.
- Why: to generate and send you your free assessment report, and to follow up with you about HelionAI.
- The scan analyzes the public pages of the website you provide, not you as an individual.
3.2 The platform (customer account)
- What we collect: your account and organization data (name, email, company name, role, login credentials) and the content you enter into the platform (self-assessment answers, registers, incidents, PIAs, access requests, uploaded evidence).
- Why: to provide the service, maintain your compliance record, authenticate you, and support you.
- Some content you enter may itself be personal information (for example, about your own customers or employees). With respect to that content, you act as the responsible organization and we act as a service provider on your behalf, under our Data Processing Agreement.
3.3 The website
- Analytics (Google Analytics 4): only after you consent (see Section 4). Aggregate website usage measurement.
- Server logs: IP address, browser type, pages viewed, timestamps, collected automatically for security, fraud prevention, and proper operation of the site. This is necessary for operation and does not require consent, but is disclosed here for transparency.
We do not sell your personal information.
4. Consent, cookies, and tracking technologies
4.1 Our consent management platform (CMP)
Our site shows a consent banner as soon as you arrive. Until you consent, non-essential technologies are blocked by default. The banner lets you Reject all, Accept all, or Customize your choices, with the reject option presented with the same prominence as the accept option.
4.2 Google Analytics 4 and Consent Mode v2
We use Google Analytics 4 (measurement ID G-NPPLG8B6DG) to understand site usage. We use Google Consent Mode v2, configured to deny by default analytics and advertising storage. No analytics measurement is sent before you consent. If you accept, analytics cookies (for example _ga) are set and measurement is sent to Google.
4.3 Essential cookies
Some cookies are strictly necessary (security, authentication, session, remembering your consent choice). They are not used for profiling and do not require consent.
4.4 Identification, location, and profiling technologies
Law 25 requires that any technology capable of identifying, locating, or profiling an individual be off by default. That is the case here: analytics remains off until you consent. We use no advertising pixels, no retargeting tools, and no behavioural profiling technology.
4.5 How to withdraw or change your consent
You can change or withdraw your consent at any time through our consent management banner (reachable from the site), or by clearing cookies in your browser. Withdrawal of consent is not retroactive. You can also write to privacy@helionai.ca.
5. Your rights and how to exercise them
Under Law 25 (and, depending on your situation, PIPEDA and other laws), you have the following rights regarding your personal information:
- Access: confirm whether we hold information about you and obtain a copy.
- Rectification: have inaccurate, incomplete, or ambiguous information corrected.
- Withdrawal of consent: withdraw a consent you gave (see Section 4.5).
- Deletion / cessation of dissemination: ask us to stop disseminating information about you and, where the law provides, to destroy it.
- De-indexing: request the de-indexing of a hyperlink that gives access to information about you where the conditions of the law are met.
- Portability: obtain, to the extent provided by law, the computerized information you provided to us in a structured, commonly used technological format.
How to exercise these rights: write to privacy@helionai.ca, or use the request form provided on our service. We respond within the timeframes required by law (generally 30 days). We may need to verify your identity before acting. If we refuse a request, we will explain the reasons and the available recourse.
6. Retention and destruction
We keep personal information only as long as necessary for the purposes for which it was collected, or as long as the law requires. When the purposes are fulfilled, we securely destroy or anonymize the information.
Our default retention periods are as follows:
| Category of information | Retention period | Rationale |
|---|---|---|
| Prospect emails (free assessment) | Up to 24 months after last contact, or until you unsubscribe if earlier | Reasonable commercial follow-up, then destruction; unsubscribing ends retention for prospecting purposes. |
| Account and organization data (customer) | For the duration of the subscription, then 90 days after account closure | Allows reactivation, final export, and closing billing, after which the information is destroyed or anonymized. |
| Customer-entered compliance content (self-assessments, registers, incidents, PIAs, access requests, uploaded evidence) | For the duration of the subscription, then deletion within a 30-day grace period after account closure | This content may contain personal information you hold about your own customers or employees; we keep it as a service provider and delete it promptly after the service ends, unless you instruct otherwise or the law requires retention. |
| Server logs (security) | 30 days | A short period sufficient for incident detection, troubleshooting, and fraud prevention. |
| Administrative access logs (who accessed what) | 12 months | Accountability and investigation needs in the event of a confidentiality incident. |
| Proof of consent (consent management platform logs) | 24 months after consent is withdrawn or changed | Demonstrates to the CAI, on request, that valid consent was obtained, without keeping the proof indefinitely. |
| Backup copies | Maximum 35-day backup cycle | Backups are overwritten on a rolling basis; information deleted from active systems ages out of backups by the end of the cycle. |
Where the law imposes a different period (for example, tax rules for billing records), we apply the longest required period and then destroy the information.
7. Hosting, sub-processors, and communication outside Quebec
7.1 Hosting in Canada and AI features (not enabled in production)
We host your data in Canada, in the AWS ca-central-1 (Montreal, Quebec) region.
AI-assisted drafting features are not currently enabled in our production environment. No content is sent to any AI sub-processor today. If we enable them, inference will run in-region in Canada (AWS Bedrock, ca-central-1); we will not enable transport to a United States Anthropic endpoint. Enablement is conditional on prior clearance by our legal function of in-region processing in Canada, and content submitted to these features would not be used to train AI models.
7.2 Sub-processors
We use a small number of carefully selected sub-processors, bound by contract to protection obligations at least equivalent to ours. Our sub-processor list includes, among others:
- Amazon Web Services (AWS): hosting and storage,
ca-central-1region (Canada). - Paddle (Paddle.com, Inc.): billing and payment processing, United States. Paddle handles payment instruments directly; we do not store full card numbers. Bound by Paddle's Data Processing Agreement.
- Resend (Resend, Inc.): transactional email delivery (service notifications, deadline alerts, DSAR confirmations, training links), United States. Bound by Resend's Data Processing Agreement.
- Google Analytics 4 (Google LLC): website usage analytics, United States. Only activated after your explicit consent (see Section 4.2). Bound by Google's Data Processing Terms.
An in-region AI inference sub-processor in Canada (AWS Bedrock ca-central-1) would be added to this list if and only if AI-assisted drafting features are enabled (see Section 7.1). The detailed, up-to-date list is maintained separately.
7.3 Communication outside Quebec
Some supporting sub-processors (for example the payment provider and the email provider) may process certain limited operational information outside Quebec, possibly in the United States. Before any communication of personal information outside Quebec, we conduct and document the privacy impact assessment (PIA / EFVP) required by Law 25, considering the sensitivity of the information, the purposes, the protection measures in place, and the legal framework of the destination jurisdiction. We limit the information shared to what is strictly necessary.
8. Automated decision-making
LeapVision does not make any decision based exclusively on automated processing that would produce a legal effect or a similarly significant effect about an individual. The free assessment scores the public website of an organization according to transparent rules; it is not an automated decision about a natural person. Should we ever introduce such processing, we would inform you and provide the rights the law requires.
9. Security
We maintain security measures that are reasonable given the sensitivity of the information: encryption in transit, access controls, hosting in Canada, logging, and least-privilege practices. No system is perfectly secure, but we work to protect your information appropriately.
10. Confidentiality incidents and complaints
In the event of a confidentiality incident presenting a risk of serious injury, we take reasonable steps to reduce its consequences, record it in our incident register, and notify the Commission d'accès à l'information (CAI) and the individuals concerned, as required by Law 25.
For any question or complaint about the processing of your personal information, write first to our person in charge, at privacy@helionai.ca. If our response does not satisfy you, you may file a complaint with the Commission d'accès à l'information du Québec (CAI) and, depending on your situation, with the Office of the Privacy Commissioner of Canada.
11. Information about minors
Our service is intended for businesses and is not directed at children. We do not knowingly collect personal information from children.
12. Changes to this policy
We may update this policy. Any significant change will be posted on this page with a new effective date.
13. Contact us
LeapVision Technologies Inc. (brand: HelionAI)
206 Rivermere, Saint-Lambert, Quebec, Canada J4R 2G1
Person in charge of personal information protection: privacy@helionai.ca
General questions: hello@helionai.ca