Privacy notice
How we handle your personal information
Version 2.0. Effective 22 September 2026. Replaces the version of 14 September 2026.
Who is responsible
BEXAI Consulting Inc., a Canadian corporation incorporated under the Canada Business Corporations Act, 1032A Clarence Avenue, Winnipeg, Manitoba R3T 1S4, Canada, is responsible for the personal information described here. Our privacy officer and person in charge of the protection of personal information is Benjamin Akinteye, Founder and Principal Consultant, privacy@bexai.ca.
The laws we follow
The Personal Information Protection and Electronic Documents Act (PIPEDA) and Canada’s Anti-Spam Legislation (CASL). Where we serve people elsewhere, we also apply the law that protects them. We do not currently offer our services to people in the European Union, the United Kingdom or Nigeria.
What we collect and why
| What | Why | How long we keep it |
|---|---|---|
| Diagnostic and calculator answers, organisation name, role, email | To produce your result and let you return to it | 12 months from creation for a free diagnostic, then deleted or anonymised; longer if it becomes part of an engagement |
| Contact and booking form details and your message | To reply to you and arrange the conversation you asked for | While we are in contact, then 24 months after the last contact |
| What you type to the website assistant, when it is switched on | To answer you. A person at BEXAI reads questions to write new approved answers, and no AI model is trained on them | 90 days if you do not leave your details; if you do, kept with your enquiry, then 24 months after the last contact |
| Consent records: the words you agreed to, the notice version, the time and the page | To prove we had your permission, which the law puts on us | For as long as we contact you on that consent, then 3 years |
| Withdrawals and unsubscribes | So that we never contact you again by mistake | A hashed entry, which cannot be read back as your address, kept permanently, because it is the thing that stops us contacting you |
| Rate-limit data: keyed hashes of your IP address and browser, times, pages requested | To limit abuse | 12 months |
| Audit log: actions taken in accounts, holding hashed identifiers only | To show who did what, and to investigate security incidents | 7 years; breach records at least 24 months, and 5 years where a Quebec resident is affected |
| Account data: name, email, second-factor enrolment | To run your account securely | While the account is open, then 90 days |
| Records of payments, when payments open | Tax law (Income Tax Act s.230; Excise Tax Act s.286) | 6 years after the end of the tax year they relate to |
We use each item only for the purpose stated. We do not sell, rent or trade personal information, we do not use it to train AI models, and we do not make decisions about you by automated means alone.
What we do not collect
We run no third-party advertising or analytics trackers. No advertising script, tag manager or pixel is loaded on any page, our fonts are served from our own domain rather than a font provider, and the site’s Content Security Policy permits the browser to contact only our own domain, our database provider and our error monitoring provider. Our application stores only keyed hashes of your IP address and browser, never the raw values.
Our hosting, database and rate-limit providers keep raw IP addresses in their own short-lived operational logs, for security. We are confirming the exact retention period each of them applies and will state the periods here once they are confirmed rather than estimate them.
Cookies
We use only the cookies needed to keep you signed in and to protect forms from abuse. We use no advertising or tracking cookies, so there is nothing to opt out of.
Where your information is stored and processed
Our database is in Montréal, Canada, and our web functions are pinned to Montréal. Some service providers process information outside Canada, mainly in the United States, and it may then be accessible to courts and authorities there under their law. Our service providers are:
- Supabase: database and sign-in. Data stored in Canada.
- Vercel: website hosting. Our functions are pinned to Montréal. Pages and static files are served through its global content delivery network, so a copy of a public page may be cached near you.
- Anthropic, PBC: AI model provider, United States. Processes AI requests as our processor under its commercial terms and data processing addendum. It does not train its models on what we send. It deletes inputs and outputs within 30 days, except where its terms allow longer retention, such as content flagged for misuse.
- Resend: transactional email.
- Inngest: background jobs.
- Sentry: error monitoring, United States. Receives error reports from the browser and the server, which can include the page you were on and technical details of the failure.
- Upstash: rate-limit store. Holds the keyed hashes described above, never a raw address.
- GoHighLevel: customer relationship mirror. Where it is configured, an enquiry you send us is copied to it so that we can follow up.
- Stripe: payments, when payments open.
A current list is available on request from privacy@bexai.ca.
AI features
Before a diagnostic is sent to the AI model, we replace your name, organisation and email with neutral tokens and restore them only in your finished report. AI-generated content is marked on screen. The website assistant tells you it is an AI at the start of every conversation, answers only from entries a person at BEXAI has approved, and hands anything else to a person.
Email and other messages
We send marketing email only with your consent, and every commercial email says who we are and carries an unsubscribe link that works in one step. Messages that deliver something you asked for, such as your result or a reply to your enquiry, also carry our identification and an unsubscribe link. An unsubscribe takes effect at once, and in any case within 10 business days. We do not currently send marketing text messages; if you ever receive a text from us, replying STOP ends texts from us. Details are on our CASL page.
Your rights
You may ask for access to your personal information, for a correction, or for deletion, and you may withdraw consent or object to a use. Write to privacy@bexai.ca. We reply within 30 days. If we need more time, which the law allows in limited cases, we will tell you within the first 30 days, give you the new date, and remind you of your right to complain to the Privacy Commissioner about the extension.
Deletion covers everything except: the records we keep to prove consent and the hashed entry that stops us contacting you again; payment records, which tax law requires; and security, breach and audit log records. We keep each only for the period in the table above.
If you are not satisfied with our answer, you may complain to the Office of the Privacy Commissioner of Canada at priv.gc.ca.
Security
Row-level security on every table, a second factor for all account access, and an append-only audit log. Report a security issue to security@bexai.ca. If a breach creates a real risk of significant harm to you, we will tell you and the Privacy Commissioner as the law requires.
Automated handling of replies
If our system reads your reply as a request to stop, it stops our messages to you automatically. If it got that wrong, write to privacy@bexai.ca and a person will look at it.
Children
Our services are for adults and organisations. We do not knowingly collect information from anyone under 18.
Changes
We will post any change here with a new version number and effective date. For a material change we will also tell account holders by email.
Privacy notice, BEXAI Consulting Inc. Version 2.0. Effective 22 September 2026. Replaces the version of 14 September 2026. When you give consent on this site, the consent record names version 2.0, so the evidence names the notice you were shown.