Privacy policy
How ShieldAI collects, uses, discloses and protects personal information, and the rights you have over it under Canadian privacy law.
1. Who we are and what this covers
This policy is issued by CONFIRM: exact registered legal entity name, e.g. "ShieldAI Inc.", a company incorporated in CONFIRM: jurisdiction of incorporation with its registered office at CONFIRM: registered address ("ShieldAI", "we", "us").
We are subject to the federal Personal Information Protection and Electronic Documents Act (PIPEDA), and, where we handle personal information about residents of Quebec, to the Act respecting the protection of personal information in the private sector as amended by Law 25. Where we act as a service provider to a public body, additional obligations under provincial access and privacy legislation such as FIPPA or PHIPA may apply through our contract with that body.
This policy covers two distinct things, and the distinction matters:
- This website — shield-ai.ca, including the interactive tools published on it. Covered in §2.
- Our services — ShieldAI Gateway, Terminova, Elpista, WorkCohorts and the Ontario Energy Assistant. Covered in §3.
For our services, our customer is usually the organisation that engages us, and that organisation determines what personal information is processed and why. In those engagements we generally act as a service provider processing information on the customer's instructions, and the customer's own privacy policy governs the relationship with the individuals concerned. Where you are an individual using one of our services through such an organisation, contact that organisation first; we will support them in responding to you.
2. Information collected through this website
This site is deliberately built to collect as little as possible. As published, it:
- sets no cookies, and uses no browser local or session storage;
- contains no analytics, advertising or tracking scripts of any kind;
- contains no forms that transmit anything to us — the sizing calculator and eligibility tools run entirely in your browser, and the values you enter are never sent anywhere or seen by us;
- offers contact only through
mailto:links, which open your own email client. We receive that message only if you choose to send it.
Two things are nonetheless collected as a technical consequence of the site being on the internet, and we would rather state them plainly than imply the site is invisible:
- Server logs. This site is hosted on GitHub Pages. GitHub records request data including IP address, user agent and requested URL, and retains it under its own policies. We do not receive, query or store these logs.
- Web fonts. CONFIRM: remove this bullet once fonts are self-hosted Typefaces are currently requested from Google Fonts, so your browser discloses your IP address to Google when loading a page. We are moving these to self-hosted files to eliminate this.
If you email us, we hold your message and contact details for as long as needed to deal with your enquiry and to keep a record of our correspondence.
3. Information processed in our services
What we process depends entirely on which service and which customer engagement is involved. Categories may include:
- Account and contact data for the individuals authorised to use a service.
- Content submitted for processing — prompts and documents sent through ShieldAI Gateway, source text in Terminova, application material in WorkCohorts, enquiries to the Ontario Energy Assistant. This content may itself contain personal information, and in some deployments sensitive information such as health or financial details.
- Audit and log data recording who did what and when, which is a core function of our products rather than an incidental by-product.
CONFIRM: for each product, whether personal information is used to train, fine-tune or improve any model. If it is not — which we believe to be the case — state that explicitly here, because customers will ask and it is a material commitment.
4. Why we collect it
We identify our purposes before or at the time of collection. Those purposes are:
- to provide, operate, secure and support the services;
- to authenticate users and administer access;
- to maintain the audit records our customers rely on to demonstrate compliance;
- to respond to enquiries and provide customer support;
- to meet legal, regulatory and contractual obligations.
We do not sell personal information, and we do not use it for advertising or for profiling unrelated to delivering the service.
5. Consent
We collect, use and disclose personal information with your knowledge and consent, except where PIPEDA permits or requires otherwise. Consent may be express or implied depending on the sensitivity of the information and the reasonable expectations of the individual; sensitive information calls for express consent.
You may withdraw consent at any time, subject to legal and contractual restrictions and on reasonable notice. Withdrawing consent may mean we can no longer provide a service. Where we process information on behalf of a customer organisation, consent is managed by that organisation.
6. Disclosure and service providers
We disclose personal information only:
- to service providers who process it on our behalf under contract, bound to protections comparable to those in this policy and permitted to use it only for the purposes we specify;
- where required or permitted by law, including in response to a valid legal demand;
- with your consent.
CONFIRM: list the actual sub-processors — cloud providers and regions, any model or inference providers, email, support and payment systems. Public-sector procurement will require this list, and an inaccurate one is worse than none.
A demand from a law-enforcement or government body does not automatically compel disclosure. Where we are lawfully able to, we notify the affected customer before responding so they can seek to contest it.
7. Where information is stored
Our services are designed to keep customer data in Canadian regions, and residency is a deployment constraint we architect for rather than a contractual promise about infrastructure we do not control.
CONFIRM: state the actual regions per product — e.g. Terminova on Azure Canada East — and identify any processing, support access or backup that occurs outside Canada. If any does, say so: while information is outside Canada it is subject to the laws of that jurisdiction and may be accessible to its courts and authorities. PIPEDA requires transparency about this, not its absence.
8. Retention
We keep personal information only as long as necessary to fulfil the purposes for which it was collected, or as required by law or contract. Information that has served its purpose is destroyed, erased or anonymised.
CONFIRM: actual retention periods — customer content, audit logs, backups, and correspondence. A stated schedule is required to answer a PIA and is one of the first things a public-sector reviewer will ask for.
Audit records exist precisely so they cannot be quietly altered or removed, and are retained for the period agreed with the customer even where other data has been deleted.
9. Safeguards
We protect personal information with safeguards appropriate to its sensitivity, including encryption in transit and at rest, role-based access control on a need-to-know basis, network segmentation, logging and monitoring, and tamper-evident audit trails.
CONFIRM: certification status. Say "aligned with ISO 27001 and SOC 2" unless you hold current certificates, in which case name the certificate, scope and auditor. Claiming certification you do not hold is the single most damaging error available on this page.
No safeguard is absolute, and we do not claim our systems cannot be breached.
10. Automated processing
Our services use artificial intelligence, so we state our position on automated decisions directly.
Our products are built so that a person makes any decision carrying consequences for an individual. Models triage, rank, extract and draft; they do not approve, reject or determine eligibility on their own. Each routing decision is logged with the reasoning that produced it, so a decision can be reviewed and explained after the fact.
Where a decision is nonetheless based exclusively on automated processing, Quebec's Law 25 requires that the individual be informed of that fact and be able to submit observations to a person able to review the decision. Where that applies to a deployment, we support the customer in meeting it.
CONFIRM: whether any deployment makes fully automated decisions without human review. If any does, it must be described specifically here.
11. Your rights
Subject to the exceptions in applicable law, you may:
- Access the personal information we hold about you, and be told how it has been used and to whom it has been disclosed.
- Correct information that is inaccurate or incomplete.
- Withdraw consent, subject to §5.
- Request deletion where we no longer have a lawful basis to keep it. Quebec residents have a right to de-indexing and erasure in defined circumstances.
- Receive a portable copy of computerised personal information you provided to us, in a structured, commonly used technological format — a right available to Quebec residents since 22 September 2024.
Write to the contact in §15. We will respond within 30 days as PIPEDA requires, or tell you within that period why we need an extension. We may need to verify your identity first, and we will not charge for a routine request without telling you in advance.
12. Breach response
If a breach of security safeguards creates a real risk of significant harm to an individual, PIPEDA requires us to report it to the Privacy Commissioner of Canada and to notify the affected individuals as soon as feasible. We maintain records of every breach of security safeguards for at least 24 months, whether or not it met the reporting threshold, and will make those records available to the Commissioner on request.
Where we act as a service provider, we notify the affected customer without undue delay so that they can meet their own obligations.
13. Complaints
Raise any concern with our Privacy Officer first — see §15. We will investigate and respond in writing. If a complaint is justified we will take appropriate steps, including amending our practices.
If you are not satisfied with our response, you may complain to the Office of the Privacy Commissioner of Canada at priv.gc.ca, or 1-800-282-1376. Quebec residents may instead contact the Commission d'accès à l'information du Québec at cai.gouv.qc.ca. You do not need our permission to do so.
14. Changes
We may update this policy. The effective date above always reflects the current version. Where a change materially affects how we handle personal information we already hold, we will take reasonable steps to notify affected individuals or our customers directly rather than relying on this page alone.
Canadian federal privacy law is under active reform. Bill C-27, which would have replaced PIPEDA with the Consumer Privacy Protection Act, died on the order paper when Parliament was prorogued in January 2025. PIPEDA remains in force. We will revise this policy if successor legislation is enacted.
15. Contact
PIPEDA requires us to designate an individual accountable for our compliance. Direct any question, access request or complaint to:
- Privacy Officer: CONFIRM: named individual — PIPEDA Principle 1 and Law 25 both require a designated person, by name
- Email: privacy@shield-ai.ca CONFIRM: create this mailbox, or change to info@shield-ai.ca
- Post: CONFIRM: mailing address