Privacy policy

Last updated : 2026-08-27 · Version 2026-08-27.1

This policy describes what this site actually does: what it collects, why, who receives it, where it is processed, how long it is kept, and what you can demand. It covers hstech.ca and the client area within it. It is written to be read, not skimmed.

Write to the person responsible for the protection of personal information

The privacy address is not yet published on this site. In the meantime, use the contact form and write "privacy" in your message: it reaches the same person.

Who is responsible for your information

H&S Technologies inc. is responsible for the personal information collected by this site. One person is responsible for the protection of personal information: absent a written delegation, the law assigns that responsibility to the person with the highest authority in the company. The law requires publishing that person's TITLE and CONTACT DETAILS — that is what is done here. Their identity is provided on request.

  • Title: Person responsible for the protection of personal information, H&S Technologies inc.
  • Contact: by email, at the privacy address shown at the top of this policy and on the "Legal notice" page. It is a SEPARATE address from the site's commercial one: it serves only the requests covered here, which makes the date your request arrived demonstrable. If no address appears there yet, the site's contact form — available at all times — reaches the same person: write "privacy" in your message.
  • Every request for access, correction, withdrawal of consent, deletion or portability, and every complaint, reaches them at that address.

What we collect, and where

We collect nothing that does not come from a form you fill in yourself, except the visit measurement described below. Each entry point of the site collects the following:

  • Audit form: business name, website, industry, team size, current tools, main challenge and its free-text description, monthly request volume, email, phone, contact name.
  • Contact form: name, email, phone, company, and the free text of your message.
  • Online tools (calculator, configurator): email, name, company, phone, the values you enter and the result shown.
  • Estimator, guided questionnaire and chat: first name, last name, company, email, phone, your answers and the free text you write.
  • Client area: your sign-in address, a session token, and the tracking of your orders and documents.
  • Visit measurement: an anonymous session identifier created in your browser, the pages viewed, the landing page, the referring site, the language, and any campaign parameters and ad click identifiers present in the address you arrived through.
  • Missed phone call: if you call an H&S number and the call does not connect, your number and the number called are recorded so we can call you back or send you a follow-up text. ⚠️ These numbers are kept in clear text, because they ARE the means of replying to you.
  • Voice assistant: if you open "H&S Liaison" and speak to it, your voice is processed by our voice-agent provider to be transcribed and understood. On our side we record only what is useful to your request — company, need, urgency, contact details you volunteer — never the full transcript, and never a payment method, social insurance number or banking details, which are redacted before anything is stored.
  • Abuse protection: a SHA-256 fingerprint computed from your IP address and your browser. Your IP address is not stored in clear text.

Why we collect each of these categories

One purpose per category, and nothing beyond it. We do not reuse information collected for one reason for another purpose without telling you.

  • Contact details and form answers: to prepare your diagnosis or estimate, then to reply to you and follow up commercially.
  • Free text of your messages: to understand your request and answer it.
  • Client area: to authenticate you and give you access to your file and project tracking.
  • Visit measurement and campaign parameters: to know which pages and which ads bring real requests, and to fix the ones that do not.
  • Technical fingerprint: to limit requests per origin and prevent automated abuse of our forms and our cloud costs.

How your consent is obtained

Consent to process a request is separate from consent to advertising cookies: these are two different purposes, and they are never bundled into one checkbox. No optional box is pre-checked.

  • Forms that collect contact details require an explicitly checked box. The server refuses to record anything if it is not checked — the check is strict and fails closed.
  • The EXACT text you accepted is stored with the date, and frozen, for the forms that open a file: audit, online tools, estimator, guided questionnaire, chat, voice assistant and order. A policy reworded later does not rewrite what you consented to that day.
  • ⚠️ The contact form is an exception: the box is mandatory and the server refuses to record your message without it, but the stored message carries no copy of the text you accepted. We say so rather than let you believe otherwise.
  • Checking a form box authorises neither cookies nor advertising measurement.
  • You may withdraw your consent at any time, at the same contact address.

Cookies, measurement and tracking technologies

This site installs no social network pixel and no separate third-party analytics tool. ⚠️ One nuance that matters: if you accept advertising measurement, the Google tag is loaded, and it then also grants the analytics signal — so the pages you view become known to Google, as with any Google tag. Only two mechanisms collect information during your visit, and each is controlled separately. The full detail, and the means to turn them off, are on the "Cookies and tracking" page.

  • Internal audience measurement: an anonymous session identifier, created by your browser, that DIES with your tab. No cookie is set, nothing is sent to a third party. You can turn it off from the "Cookies and tracking" page; your choice is kept on your device.
  • Google Ads measurement: it only runs if you accept it. Until you have chosen, no Google script is loaded and nothing goes to Google. After acceptance two distinct things are sent: the conversion EVENT — the fact that a request was submitted, and an internal technical identifier; and, as with any Google tag, the ordinary data of a page view — the page address, the referring site and your IP address. Never your name, your email, your number, or the content of your message. You can change your mind at any time through the "Cookies" link at the bottom of every page.
  • A strictly necessary session cookie is set when you sign in to the client area. It only keeps you signed in and measures nothing.
  • The site uses NO geolocation technology. That permission is denied site-wide by a permissions policy served on every page.

Artificial intelligence processing

Some of your form answers may be sent to an artificial intelligence provider in order to restate, in your trade's vocabulary, a diagnosis that has ALREADY been computed by a deterministic engine. The model computes no score, ranks nothing and decides nothing: it restates.

  • Provider for that restatement: Anthropic, PBC (United States), through its application programming interface.
  • ⚠️ The voice assistant relies on a DIFFERENT artificial intelligence provider, ElevenLabs Inc. (United States), which processes your voice. It is described in the recipients section.
  • What may be sent: the business name, industry, team size, monthly volume, the stated challenge and its free-text description, and the already-computed diagnosis.
  • For that restatement, what is never sent: your email, your phone number and the contact person's name — they are not part of the message sent.
  • ⚠️ CHAT IS DIFFERENT, and worth knowing before you type. The chat assistant is also powered by Anthropic, and it receives YOUR MESSAGES AS WRITTEN, together with the history of the current conversation. There is no redaction on that path: if you type your email or your number into the conversation, they are sent with the rest. It is also a model that WRITES an answer, rather than restating an already-computed result.
  • This step is optional in the product: with no provider key configured, the diagnosis remains complete and no data leaves our systems on this account.
  • Because the text you write is free-form, avoid entering sensitive information or information about third parties.

No decision made solely by a machine

The automation score and the diagnosis shown at the end of a questionnaire are produced by an explicit rules engine. They are commercial information meant to prepare a conversation: they produce no legal effect on you and deprive you of no right. No decision concerning you is made exclusively on the basis of automated processing. Any follow-up to your request goes through a person at H&S.

Who your information is shared with

We do not sell, rent or trade your information with anyone. It is shared only with the providers listed below, each for a specific function, and according to the functions actually enabled on the site. This list is maintained from the site's code, not from a generic template.

  • Vercel Inc. (United States) — hosting of the site, execution of pages and programming interfaces, application logs. Always active.
  • Neon Inc. (United States) — managed PostgreSQL database where requests are stored. Always active.
  • Resend (United States) — electronic mail. Two uses: the notification that alerts US to a new request, so that none is lost if the database is unavailable; and the emails addressed to YOU from the client area — welcome message and replies — which carry your address and a personal access link. Active when a sending key is configured.
  • Anthropic, PBC (United States) — the diagnosis restatement described above. Active when a provider key is configured.
  • Google LLC (United States) — Google Ads conversion measurement. Active only after your explicit acceptance, and only if a real conversion identifier is configured.
  • Stripe, Inc. (United States, with processing in Ireland) — online payment, when that function is open. Payment happens on a page hosted by Stripe: no card data passes through our servers or is stored by us.
  • Twilio Inc. (United States) — telephony and text messaging: receiving the missed-call notice, sending the follow-up text, and transferring a call to a person. Your phone number is disclosed to it. Active when the text transport is configured with Twilio credentials; failing that, nothing is dialled and nothing is sent.
  • ElevenLabs Inc. (United States) — the "H&S Liaison" voice agent: your voice is sent to it to be transcribed and understood during the conversation. ⚠️ The full conversation stays with that provider, under ITS retention policy, which we do not control. Active only when the voice assistant is open on the site AND you start the conversation.
  • Our internal management system — operated by H&S on its own machine, with no third-party host. It is the one that comes to fetch requests; it is not reachable from any public address.

Information sent outside Québec

Yes, and we say so plainly rather than leaving it to be guessed. The providers named above — hosting, database, email delivery, artificial intelligence, advertising measurement, payment, telephony and voice agent — are established in the United States, and Stripe also processes data in Ireland. Your information may therefore be stored or processed outside Québec, where it is subject to the laws of those jurisdictions and may, in some cases, be accessible to local authorities.

  • The measures actually in place: encrypted communications, minimisation of what is sent to each provider, a fingerprint rather than a clear-text IP address, and reliance on the data protection contractual terms offered by each provider.
  • We do not claim that a formal privacy impact assessment has been completed for each of these transfers. Where the law requires one, that assessment is H&S's responsibility and is carried out before the transfer takes place.
  • If you want to know which providers were active at the time of your request, write to us and we will tell you.

What we do not do

Each of these statements is watched by an automated test: if the site started doing any of these things, the matching test would fail in continuous integration and the defect would be flagged.

  • We do not sell, rent or trade your information with anyone.
  • We use no social network pixel and no data broker.
  • We do not sign you up to any newsletter you did not ask for.
  • We deliberately collect no sensitive information, no banking data and no social insurance number. If you write any into a free-text field, tell us and we will delete it.
  • We do not track your browsing from one visit to the next: the measurement identifier dies with the tab.

How long we keep it

Information is kept for as long as the purpose it was collected for lasts, then destroyed. We publish here the CRITERIA that determine that duration rather than a number of months that would be more reassuring than true.

  • Requests and messages with no follow-up: kept for a reasonable commercial cycle allowing contact to resume, then destroyed. The free text of a contact message, unpredictable by nature, carries the shortest duration.
  • Files that became client files: kept for the duration of the contractual relationship, then for the period required by applicable accounting, tax and legal obligations.
  • Visit measurement: kept long enough to analyse the effectiveness of pages and campaigns, then destroyed.
  • Anti-abuse counters: destroyed automatically once their window expires. That destruction is already automatic in the code.
  • You may request deletion of your information at any time, with no need to justify yourself. We keep only what a legal, accounting or security obligation requires us to keep, and we tell you which.

How we protect it

The measures below are in place in this site's code and verifiable. We claim no certification and no standard that we have not obtained.

  • Encrypted communications, enforced by a strict transport policy across the whole domain.
  • A content security policy served on every page, including error pages, and verified by tests.
  • Display in a third-party frame refused, content types not sniffed, camera, microphone and geolocation denied site-wide.
  • The client area session is carried by an opaque cookie, revocable server-side, marked httpOnly and sent only over HTTPS.
  • Sign-in error messages are identical whatever the cause, so as not to reveal whether an account exists.
  • IP addresses reduced to a SHA-256 fingerprint; invitation tokens stored as a fingerprint and never in clear text.
  • Request rate limiting and spending caps on provider calls, to contain automated abuse.
  • Automatic redaction of payment methods, banking details and social insurance numbers before any dictated text is stored.
  • Strict separation between the development database and the production database, enforced by a start-up guard.

Your rights

Québec law grants you the following rights over the personal information we hold about you. They are exercised free of charge.

  • Access: obtain confirmation that we hold information about you and receive a copy of it.
  • Correction: have inaccurate, incomplete or ambiguous information corrected.
  • Deletion: have information deleted once its purpose is fulfilled, or where its collection was not necessary.
  • Withdrawal of consent: withdraw at any time a consent already given, for the future.
  • Portability: receive, in a structured and commonly used technological format, the computerised information you yourself provided to us.
  • Complaint: complain to us and, if our answer does not satisfy you, to the Commission d'accès à l'information du Québec.

How to exercise your rights, and how long it takes

Write to the person responsible for the protection of personal information, at the privacy address shown at the top of this policy — or, if no address appears there yet, through the site's contact form, which is always available. Do not use the site's commercial address for a request covered here: it is not monitored for that, and the clock would run without anyone seeing it. The procedure is deliberately simple:

  • State what you are asking for: access, correction, deletion, withdrawal of consent, portability or complaint.
  • Give the email address or phone number you had provided to us: that is what lets us find your file.
  • We may ask for reasonable elements to confirm your identity, so that we never disclose your file to someone else. Those elements are used solely for that verification and are not kept beyond it.
  • We answer in writing within 30 days of receiving your request, as the law requires.
  • A refusal, should there be one, is given in writing with reasons, and states the recourse available to you before the Commission d'accès à l'information du Québec.

Confidentiality incidents

A confidentiality incident is unauthorised access to, use, disclosure or loss of personal information. How H&S must handle one is set out in a written procedure, and the rules below apply to any incident.

  • Every incident, even one with no apparent risk, must be recorded in the confidentiality incident register kept by the person responsible for the protection of personal information.
  • We assess the risk of serious injury taking into account the sensitivity of the information, the anticipated consequences and the likelihood that it will be used for a harmful purpose.
  • Where an incident presents a risk of serious injury, we promptly notify the Commission d'accès à l'information du Québec and the persons concerned, and we take reasonable measures to reduce the risk and prevent recurrence.

Our personal information governance

The law requires our governance policies and practices to be published in simple terms. Here they are, as they actually apply to this site.

  • Roles: the person with the highest authority at H&S answers for the protection of personal information; the responsible person named above handles requests, complaints and incidents.
  • Retention and destruction: each category is tied to a purpose; once the purpose is fulfilled, destruction is the expected behaviour, not an exception.
  • Internal access: information is accessible only to the people who need it to answer your request or deliver your project.
  • Subcontracting: we use only the providers named in this policy, each for the stated function.
  • Minimisation: forms ask only for what is necessary for the stated purpose; the site's default settings enable no advertising measurement until you have consented to it.
  • Review: this policy is reviewed whenever a function of the site changes, and its update date is published at the top of the page.

Commercial communications

In accordance with Canada's anti-spam legislation, we send you a commercial electronic message only if you have given your consent or if an exemption applies. Each consent is recorded with its date. Each message identifies H&S Technologies inc. and carries a way to unsubscribe.

Changes to this policy

We update this page when a practice of the site changes, not on a schedule. The last update date and the version number appear at the top of the page. The exact text you accepted at the time of a form remains stored as it was: a new version never retroactively rewrites what you consented to.