Skip to main content
PiutrO
FRContactBack to home

Legal

PiutrO Privacy Policy

Effective date:
July 27, 2026
Last updated:
July 27, 2026
Version:
1.0

On this page

  1. 1. Who is responsible
  2. 2. Information we collect
  3. 3. Purposes and legal bases
  4. 4. Artificial intelligence
  5. 5. Disclosure of information
  6. 6. International processing and transfers
  7. 7. Retention and deletion
  8. 8. Security
  9. 9. Cookies, analytics, and advertising
  10. 10. Communications
  11. 11. Your privacy rights
  12. 12. Children and restricted data
  13. 13. Changes to this policy
  14. 14. Language
  15. 15. Contact and complaints

PiutrO Labs Inc. (“PiutrO,” “we,” “us,” or “our”) respects privacy and is accountable for personal information processed through PiutrO services that link to this policy (the “Service”). This policy explains what we collect, why we use it, how we disclose and protect it, and the choices and rights available to individuals.

1. Who is responsible

PiutrO Labs Inc. is a Canadian federal corporation (1741934-1), registered in Québec (NEQ 1181927782), with its registered office at 103-5282 Rue du Sureau, Pierrefonds, Québec H8Z 0A5, Canada.

The CEO and Privacy Officer is responsible for PiutrO’s privacy program and can be reached at legal@piutro.com.

For personal accounts, website visitors, billing contacts, marketing recipients, and PiutrO’s own operational data, PiutrO generally acts as controller or organization responsible for processing. For content placed in an organizational workspace, the customer organization generally determines the purposes and means of processing and PiutrO acts as its processor or service provider under the DPA. Users should direct workspace-content requests to their organization first.

2. Information we collect

Information provided directly

  • Account and profile data: name, email, organization, role, language, profile settings, authentication identifiers, and account credentials or tokens.
  • Customer Content: product records, written content, files, attachments, imports, prompts, AI-assisted results, personal-project information, comments, configurations, and audit events.
  • Billing and transaction data: plan, subscription status, billing contact, transaction identifiers, tax location, and limited payment metadata. Stripe processes payment credentials; PiutrO does not intend to store full payment-card numbers.
  • Communications: support requests, legal or privacy requests, feedback, survey responses, and other correspondence.
  • Marketing choices: subscription preferences, campaign interactions, consent records, and withdrawal or opt-out status.

Information collected automatically

  • Device and log data: IP address, browser and device type, operating system, timestamps, referring pages, diagnostic events, authentication and security logs, and approximate location inferred from IP.
  • Usage data: pages and features used, actions taken, workspace and permission events, performance measurements, and interaction patterns.
  • Cookies and similar technologies: essential identifiers and, on the public marketing website after valid consent, analytics and advertising identifiers. See the Cookie Policy.
  • Error data: technical traces and diagnostic context processed through Sentry or similar monitoring, configured to minimize and scrub Customer Content and sensitive fields.

Information received from others

We may receive information from an organization administrator, an approved integration, Microsoft authentication, imported files, fraud and security providers, payment providers, or advertising and analytics partners. Customers must have authority to import third-party personal information and provide required notices.

3. Purposes and legal bases

We process personal information to:

  • create and administer accounts, workspaces, permissions, subscriptions, trials, payments, tax, and support;
  • provide, personalize, maintain, secure, troubleshoot, and improve the Service;
  • process Customer Content on an organization’s documented instructions;
  • provide configurable AI summaries, drafts, recommendations, scoring, ranking, pattern detection, duplicate detection, and risk signals;
  • authenticate users, prevent fraud and abuse, enforce terms, and protect users and the public;
  • communicate operational, security, billing, legal, and service notices;
  • send promotional communications where separate consent or another lawful basis permits, and honour unsubscribe requests;
  • measure marketing-site performance and advertising after consent;
  • comply with law, lawful process, tax, accounting, and regulatory duties; and
  • establish, exercise, or defend legal claims and manage corporate transactions.

Depending on the context, our legal bases include performance of a contract, steps requested before a contract, consent, compliance with legal obligations, and legitimate interests such as security, service improvement, fraud prevention, and business administration after balancing individual rights. Where Québec law requires valid consent for a use or disclosure, we obtain it or rely on a lawful exception.

4. Artificial intelligence

OpenAI may process selected Customer Content and related instructions to provide AI features, including automatic background analysis. Organization administrators can disable AI or limit the features or records it processes. AI recommendations do not change records without user approval.

PiutrO does not use identifiable or de-identified Customer Content to train PiutrO or third-party AI models. OpenAI API data is not used to train OpenAI models by default. Provider retention varies by endpoint and approved data-control configuration. See the AI Transparency Notice for limitations, safeguards, and rights.

PiutrO does not use personal information to make fully automated decisions that produce legal or similarly significant effects. Users make final product-management decisions.

5. Disclosure of information

We disclose information only as reasonably necessary:

  • Customer administrators and authorized users: according to workspace roles, permissions, and organization control.
  • Service providers and subprocessors: hosting, database, storage, authentication, email, AI, payments, security, monitoring, analytics, and consent management providers listed in the Subprocessor List.
  • Advertising and analytics partners: Google Analytics, Meta Pixel, and LinkedIn Insight Tag may receive limited marketing-site identifiers and activity only after valid consent. PiutrO does not place advertising pixels in the authenticated application.
  • Approved integrations: when a user or administrator authorizes an integration.
  • Professional advisers and authorities: lawyers, auditors, insurers, regulators, courts, or law enforcement when authorized or required by law.
  • Corporate transactions: prospective or actual investors, acquirers, successors, or financing parties under confidentiality and legal safeguards.
  • Protection and enforcement: where reasonably necessary to investigate abuse, protect rights and safety, or enforce agreements.

PiutrO does not sell personal information or Customer Content for money. Some laws define disclosure for cross-context behavioural advertising as “sharing.” PiutrO engages in such sharing only on the marketing site after consent and honours applicable opt-outs, including recognized Global Privacy Control signals.

6. International processing and transfers

PiutrO and its providers process information in Canada, the United States, and other countries where they or their subprocessors operate. Those countries may have different privacy laws, and lawful authorities may access information under local law.

Where required, PiutrO uses contractual and organizational safeguards, including DPAs, adequacy decisions, European Commission Standard Contractual Clauses, the UK International Data Transfer Addendum or other approved mechanisms, and transfer risk assessments.

PiutrO’s production infrastructure currently uses Supabase in the AWS US West (Oregon) region (us-west-2) and Render in Ohio, United States (US East). PiutrO does not promise a specific data-residency country under standard plans. A signed enterprise agreement may provide additional commitments.

7. Retention and deletion

We retain personal information only as long as reasonably necessary for the purposes described, including account operation, contractual obligations, security, dispute resolution, and law.

After access ends, organizational Customer Content may remain recoverable or exportable on request for up to 90 days, subject to administrator authorization and technical feasibility. It is then scheduled for deletion from active systems. Residual copies may remain in encrypted backups for up to an additional 90 days and are isolated from ordinary use until overwritten, unless a legal hold, security incident, dispute, or law requires longer retention.

Billing, tax, consent, audit, fraud-prevention, legal, and security records may be retained for longer periods required by law or reasonably necessary. Marketing suppression records may be retained to ensure that an opt-out continues to be honoured. De-identified information may be retained if PiutrO maintains it in de-identified form and does not attempt to re-identify it.

8. Security

PiutrO uses risk-based administrative, technical, and physical safeguards, including access controls, tenant and permission controls, encryption in transit and at rest where supported, logging, backups, secure development practices, and vendor review. Access is limited to authorized persons with a business need.

No security system is perfect. Individuals should use unique credentials, protect authentication factors, and report suspected compromise. PiutrO plans to pursue SOC 2 but is not currently SOC 2 certified or attested.

When a privacy incident creates a legally reportable risk, PiutrO will investigate, maintain required records, and notify affected organizations, individuals, and regulators as required.

9. Cookies, analytics, and advertising

The authenticated application uses essential operational cookies and logs, privacy-conscious product analytics, and scrubbed error monitoring. It does not use advertising pixels.

The public marketing site may use Vercel Analytics or Speed Insights, Google Analytics, Meta Pixel, and LinkedIn Insight Tag according to Cookiebot consent choices. Non-essential technologies are blocked until the required consent is obtained. Users can change preferences at any time through the cookie settings link. PiutrO honours recognized Global Privacy Control signals as required.

10. Communications

Operational messages about accounts, security, billing, legal changes, and service availability are necessary and cannot always be opted out of while an account remains active.

Promotional email requires a separate optional consent where required. Consent is not a condition of service. Each marketing message identifies the sender and provides an unsubscribe mechanism. We keep consent and suppression records and process withdrawals as required by law.

11. Your privacy rights

Subject to identity verification, organizational control, lawful exceptions, and technical feasibility, PiutrO provides individuals worldwide a baseline ability to:

  • access and receive a copy of personal information;
  • correct inaccurate information;
  • request deletion;
  • request a portable export where applicable;
  • withdraw consent without affecting earlier lawful processing;
  • object to or restrict certain processing;
  • opt out of marketing and consented advertising sharing; and
  • complain to PiutrO or a competent privacy regulator.

Requests may be submitted to legal@piutro.com. We will respond within the period required by applicable law, generally within 30 days where practicable. We may request proportionate verification and may deny or limit a request where law permits, explaining the reason and available appeal or complaint route.

Organizational users should first contact their administrator for workspace content. PiutrO will assist the organization under the DPA.

12. Children and restricted data

The Service is not intended for anyone under 18 or below the legal age of majority. We do not knowingly collect children’s personal information. If we learn that such information was submitted, we may suspend processing and delete it.

Users must not submit health, biometric, payment-card, authentication-secret, government-identifier, or children’s data without PiutrO’s express written approval and an appropriate agreement.

13. Changes to this policy

PiutrO will provide at least 30 days’ advance notice of material changes and request renewed consent where law requires. Urgent legal or security changes may take effect sooner with prompt notice. Non-material clarifications may take effect when published. The version and update date appear above.

14. Language

A French version is available and will be presented as required by Québec law. If versions differ, the French version prevails for Québec consumers where required; otherwise, the English version prevails to the extent permitted.

15. Contact and complaints

PiutrO Labs Inc. — CEO and Privacy Officer
Email: legal@piutro.com
Support: support@piutro.com

Individuals may also complain to the Commission d’accès à l’information du Québec, the Office of the Privacy Commissioner of Canada where applicable, their provincial, state, national, EU, or UK supervisory authority, or another regulator with jurisdiction.

© 2026 PiutrO Labs Inc. · Something powerful is taking shape.

PrivacyTerms of ServiceContact Us