Cargizon Privacy Policy
Last updated: July 18, 2026
Pending review by qualified privacy counsel (PIPEDA / Quebec Law 25 / GDPR). The factual details are completed.
This Privacy Policy explains how 9485-2068 Québec Inc. ("Cargizon", "we", "us") collects, uses, discloses, and protects personal information in connection with the Cargizon platform, websites, and related services (the "Service"). The Service is business-to-business; most personal information we handle relates to employees and representatives of our business customers and their trading partners.
1. Our Roles: Controller and Processor
1.1 Controller. We act as a controller (GDPR) / organization responsible for personal information (PIPEDA, Quebec Law 25) / business (CCPA) for information about: account users and administrators; website visitors; prospective customers; and people who correspond with us.
1.2 Processor. We act as a processor / service provider for personal information contained in Customer Data — content our customers submit to the Service, such as contact details of their vendors, brokers, carriers, and consignees appearing in shipment records and documents. In that role, our customer decides the purposes of processing; our handling is governed by our Data Processing Agreement ("DPA") at /dpa. Individuals whose information appears in Customer Data should direct requests to the relevant customer; we will assist that customer as described in the DPA.
1.3 This Policy primarily describes our controller-role practices.
2. Who We Are
- Entity: 9485-2068 Québec Inc., incorporated in Quebec, Canada
- Address: 1433 Rue de l'Everest, Montréal (Saint-Laurent), Québec H4R 2R3, Canada
- Privacy Officer (PIPEDA / Law 25 "person in charge of the protection of personal information"): Chris Lemieux, CEO, privacy@cargizon.com
- EU/UK Representative (GDPR Art. 27 / UK GDPR, if applicable): Not appointed — the Service is offered on a business-to-business basis to organizations in Canada and is not directed to individuals in the EU or UK.
3. Information We Collect
3.1 You provide directly:
- Account information: name, business email, employer/organization, role, hashed password (or SSO identifiers)
- Billing information: billing contact and address; payment card details are collected and processed by Stripe — we do not store full card numbers
- Content and communications: support requests, feedback, messages
- External participant information: name/email where a customer invites a vendor, broker, or other third party to interact via token-based links
3.2 Collected automatically:
- Log and device data: IP address, browser/OS, timestamps, pages and features used, referring URLs
- Cookies and similar technologies (see our Cookie Policy at /cookies): strictly necessary cookies for authentication and security; analytics as described there
- Error and diagnostic data (via Sentry): stack traces and technical context when the Service encounters an error, which may incidentally include identifiers such as user ID or IP
3.3 From third parties:
- Payment status and subscription events from Stripe
- Email delivery events from Resend
- Publicly available or licensed logistics data (vessel positions, carrier/terminal milestones) — generally about vessels and shipments, not individuals
3.4 Customer Data (processor role): shipment, order, invoice, and document content submitted by customers, including via file upload and customer-specific email import addresses. This may contain personal information of third parties determined by the customer.
4. How We Use Personal Information (and Legal Bases)
| Purpose | Examples | Legal basis (GDPR) |
|---|---|---|
| Provide the Service | accounts, authentication, features, support | Contract |
| Billing | subscriptions, invoicing, collections | Contract; legal obligation |
| Security & integrity | fraud/abuse prevention, rate limiting, access logs, error monitoring | Legitimate interests |
| Communications | service notices, responses to inquiries | Contract; legitimate interests |
| Marketing (own services) | product news to business contacts, subject to consent where required (incl. CASL) | Consent; legitimate interests |
| Improvement & analytics | usage measurement, de-identified/aggregated statistics | Legitimate interests |
| Legal compliance | tax, accounting, responding to lawful requests | Legal obligation |
We do not sell personal information and do not use it for cross-context behavioural advertising.
5. AI Processing
5.1 The Service uses AI models (provided by Anthropic) to extract structured data from documents, classify emails and attachments, answer questions about a customer's own data, and generate analytics.
5.2 AI processing of Customer Data occurs on the relevant customer's instructions (processor role). Extracted results are presented to users for review before saving.
5.3 Our agreements with AI providers prohibit use of data submitted through our integration to train their generalized models.
5.4 Automated decision-making. The Service does not make decisions producing legal or similarly significant effects about individuals without human involvement. AI outputs are decision-support and subject to user review.
6. Disclosure of Personal Information
We disclose personal information only to:
- Service providers (sub-processors) performing services for us — hosting, database, payments, email, AI processing, error monitoring, analytics. Current list: /subprocessors (includes, as of July 18, 2026: Vercel, Supabase, Stripe, Resend, Anthropic, Sentry, AISStream, PostHog, and Google Workspace for business email)
- Advisors and authorities where required by law, to protect rights and safety, or in connection with legal process (with notice to affected customers where lawful)
- Successors in a merger, financing, or sale of assets, subject to confidentiality and continued protection
- At your direction — e.g., when a user shares a document link with an external participant
7. International Transfers
We are based in Canada, and our service providers process data in Canada, the United States, and other jurisdictions. Where personal information subject to GDPR/UK GDPR is transferred to countries without an adequacy decision, we rely on the EU Standard Contractual Clauses (and UK Addendum/IDTA) and supplementary measures as appropriate. Quebec Law 25 note: transfers of personal information outside Quebec are preceded by a privacy assessment considering sensitivity, purposes, and protections. Details are available from the Privacy Officer.
8. Retention
We retain personal information only as long as necessary for the purposes above: account data for the life of the account and a limited period after closure; billing records per tax law (generally 7 years); logs and diagnostics for shorter operational windows; Customer Data per the customer's instructions and the DPA (export available for 30 days post-termination, then deletion from active systems, with backups aging out on schedule).
9. Security
We apply administrative, technical, and physical safeguards appropriate to sensitivity, including encryption in transit and at rest, organization-level data isolation with row-level security, role-based access, private document storage with expiring signed URLs, API key hashing and scoping, rate limiting, logging, and error monitoring. No system is perfectly secure; we cannot guarantee absolute security.
Breach response. We maintain an incident response process. Where a breach creates a real risk of significant harm (PIPEDA) or a risk of serious injury (Law 25), we notify affected individuals and the applicable regulators (including the OPC and the CAI) as required, and we notify controller customers without undue delay per the DPA (and in any case within the timeline needed for their GDPR 72-hour obligations).
10. Your Rights
Depending on your jurisdiction, you may have rights to access, correct, delete, or receive a copy of your personal information; to withdraw consent; to object to or restrict certain processing; to de-indexing (Quebec); and to lodge a complaint with a supervisory authority (e.g., the Office of the Privacy Commissioner of Canada, the Commission d'accès à l'information du Québec, or your local EU/UK authority). Exercise rights by contacting privacy@cargizon.com. We respond within the time required by law (generally 30 days). If your information is in Customer Data, we will refer your request to the responsible customer and assist them.
California residents: we do not sell or share personal information as defined by the CCPA/CPRA; you may exercise access, deletion, and correction rights via privacy@cargizon.com without discrimination.
11. Marketing Communications and CASL
Commercial electronic messages are sent in compliance with Canada's Anti-Spam Legislation: with consent (express or implied, e.g., existing business relationship or conspicuously published business contact information relevant to the recipient's role), with identification of the sender, and with a functioning unsubscribe honoured promptly. Transactional and service messages are not marketing.
12. Children
The Service is not directed to children and we do not knowingly collect personal information from anyone under 18. If you believe a minor has provided information, contact privacy@cargizon.com.
13. Changes to This Policy
We will post updates here and revise the "Last updated" date; material changes will be notified via the Service or email. Continued use after the effective date indicates acknowledgment.
14. Contact
9485-2068 Québec Inc. — Privacy Officer 1433 Rue de l'Everest, Montréal (Saint-Laurent), Québec H4R 2R3, Canada privacy@cargizon.com