Privacy Policy
Effective Date: July 10, 2026 Last Updated: July 10, 2026
1. Scope, Legal Basis, and Privacy Roles
This Privacy Policy explains how 1001551995 Ontario Inc., operating as SmartBizAssist ("SmartBizAssist", "we", "us", or "our"), collects, uses, discloses, retains, and protects personal information in connection with SmartBizAssist.ai and the Services.
For our own business operations (billing, support, website), SmartBizAssist determines purposes and methods of processing. When customers use the Services to manage their own end users, the customer acts as the Data Controller and SmartBizAssist processes information on the customer's instructions as a Data Processor.
This Policy supports compliance with Canadian privacy principles (accountability, purpose-limitation, consent, data minimization, safeguards, openness, and individual access). It does not replace customer-facing privacy notices or third-party platform policies.
2. Information We Collect and Why
| Category | Examples | Purpose |
|---|---|---|
| Account & Business Data | Name, business name, role, email, phone, settings | Create accounts, administer platform, provide support |
| Authentication & Security Data | Credentials, MFA records, IP, device data, logs | Secure accounts, detect abuse, troubleshoot |
| Billing & Transaction Data | Plan, invoices, tax status, billing contact | Process subscriptions, calculate taxes, comply with accounting obligations |
| Configuration & Knowledge Data | Hours, pricing, FAQs, scripts, escalation rules | Configure AI agents and workflows |
| Customer-Controlled End-User Data | Names, contacts, transcripts, recordings, bookings | Operate customer-configured workflows: chat, voice, SMS, scheduling |
| Website, Cookie & Analytics Data | Cookies, referral, performance, error logs, approx. location | Run website, improve performance, support marketing where permitted |
3. Consent, Collection Methods, and Communications Compliance
We collect information directly from users, automatically through the Services, via customer-authorized integrations, from service providers, and from public sources where permitted. We collect only what is reasonably necessary for identified purposes.
Consent may be express or implied depending on context. Users may withdraw consent for optional processing (marketing, non-essential cookies) without affecting administrative or legally required communications.
Customers are responsible for providing notices and obtaining consents from their end users for voice recording, transcription, SMS messaging, marketing, and other workflows (including CASL and Do Not Call rules). We use strictly necessary cookies for login and platform operation; analytics or marketing cookies are used only with consent.
4. AI Processing, Automated Decisions, and Customer Responsibilities
The Services may use AI, LLMs, speech-to-text, text-to-speech, and automation rules to generate responses, summaries, recommendations, routing, and follow-up tasks. AI outputs are probabilistic and may be inaccurate or incomplete.
Customers must test configurations, review knowledge inputs, monitor agent performance, and maintain human oversight. The platform is not a substitute for professional, regulated, or emergency decision-making.
We do not use identifiable customer or end-user data to train generalized AI models for other customers; aggregated and de-identified metadata may be used for monitoring and optimization.
5. Service Providers, Sub-Processors, Sharing, and Cross-Border Transfers
We do not sell personal information. We disclose data only where necessary to deliver services, where customers authorize integrations, for billing or legal reasons, or in connection with business transactions under confidentiality obligations.
Service providers may include hosting, telecom carriers, AI infrastructure providers, payment processors, analytics tools, and support systems. We aim to apply contractual and technical safeguards to sub processors.
Data may be processed or stored outside Canada, including the United States. Where required, we perform transfer impact assessments and contractual protections.
6. Retention, Deletion, Security, and Sensitive Information
We retain data only as long as necessary to provide Services, meet legal obligations, and resolve disputes.
- Account & Billing Records: Retained during the account relationship and per legal requirements.
- Customer-Controlled Workflow Data: Retained per customer settings; default deletion/ de-identification within 30–60 days after account cancellation unless otherwise specified.
- Security & Technical Logs: Retained for a limited period for investigation and platform integrity.
We apply safeguards including access controls, encryption in transit and at rest, role-based permissions, logging, employee confidentiality, and vendor reviews. Breaches that present significant harm will be notified to affected parties and regulators as required.
The platform is not pre-configured for regulated health or highly sensitive use cases; do not submit PHI or similar data without a written agreement and security addendum.
7. Individual Rights, Policy Updates, and Contact
Depending on applicable law, you may have rights to access, correct, delete, or obtain your personal information, withdraw consent for optional processing, request human review of automated decisions, and challenge our practices.
If your information was collected through a customer workflow, we may direct you to that customer for requests. We may require identity verification before responding to requests.
We may update this Policy; material changes will be communicated by website notice, dashboard alert, or email where appropriate.
For support: Support@smartbizassist.ai
For privacy inquiries or deletion/access requests: Privacy Officer — hello@smartbizassist.ai
Phone: +1-647-800-8403