Privacy Policy
Updated August 16, 2026
The short version
Our software runs inside our customers' own infrastructure. We do not host their AI workloads and we never see the content they process: no models, weights, prompts, inference inputs or outputs, or datasets. What the software sends us is an operational log of how our own optimization engine behaved, and the exclusion of customer content is built into the software's design, not set by a configuration option.
We do not sell personal information and never have. We do not use anyone's personal information to train our models. We keep the amount of personal information we hold deliberately small.
This policy covers our website, our customer portal, our sales and support relationships, and job applications. It follows Québec's Act (Law 25) and Canada's PIPEDA first, and explains below what changes if the EU or UK GDPR applies to you.
What we collect, why, and for how long
Each line below gives what we collect, why, and how long we keep it.
- Website visits: IP address, browser and device, pages viewed, cookies. To operate and secure the site, and to measure our audience if you consent. Kept 13 months.
- Forms: name, work email, company, role, your message. To answer contact and demo requests. Kept 24 months after the last interaction.
- Newsletter: email address. To send our newsletter, about monthly, to people who subscribed. Kept until you unsubscribe.
- Sales and CRM: business contacts, correspondence, meeting notes. To manage sales relationships. Kept 36 months after the last interaction.
- Portal accounts: names, work emails and roles of the users a customer authorizes; credentials, stored hashed or encrypted; sign-in and administration logs. To run customer accounts, licences, and access keys. Kept for the contract, then 12 months.
- Billing: billing contacts, invoicing details. To perform the contract and meet tax obligations. Kept for the contract, then 7 years.
- Support: your contact details, your request, the diagnostic files your team sends us. To answer support requests. Kept for the contract, then 12 months.
- Job applications: CV, application materials, references. To recruit for the role you applied to. Kept 12 months after the process ends.
- Product telemetry: random instance ID, hardware model, driver and runtime versions, summary timing and energy measurements, recipe metadata, quality-check results, error events. To support the software, verify licence scope, and improve our energy models. Kept 12 months linked to an instance, then only as aggregated, de-identified signals.
Our legal grounds under Québec law and PIPEDA are your consent (express for the newsletter and for any tracking technology), the necessity of performing a contract, and compliance with legal obligations. Newsletter messages identify us and carry a working unsubscribe link, honoured within ten days, as CASL requires.
Product telemetry is designed to contain no personal information. If an error log nevertheless contains something that identifies a person, we treat it as personal information, delete it within fifteen days of learning about it, and fix the logging. Customers can also run our software in restricted or air-gapped modes, where less, or nothing, leaves their environment.
Who receives it
We use these service providers, each bound by a written agreement:
- HubSpot: website hosting, forms, CRM, newsletter. Stored in Canada.
- Google Workspace: business email and documents. Stored in Canada.
- Google Analytics: audience measurement, only if you consent. Stored in Canada.
- Amazon Web Services and Google Cloud Platform: customer portal, telemetry endpoint, internal systems. Stored in Canada.
- Intuit QuickBooks: invoicing and accounting.
Each provider is bound by a written agreement and receives only what it needs. We may also disclose personal information where a law of Québec or of Canada requires it, to our professional advisers under confidentiality obligations, or in a corporate transaction.
Where it goes
Our providers store personal information in their Canadian regions. Storage in Canada is not the same as storage in Québec, and our providers' staff may access data from other countries, including the United States, for support and maintenance. Before communicating personal information outside Québec we carry out the assessment required by section 17 of the Québec Act and bind the provider by written agreement. Using our site or portal informs you that this may happen; it does not by itself constitute your consent to it.
Cookies
Cookies that identify, locate, or profile you, our HubSpot tracking cookie and Google Analytics, are off by default and run only if you turn them on. Strictly necessary cookies (security, load balancing, remembering your choice) run without consent. You can see the current list of cookies, with their purpose and duration, and change your choice at any time, in Cookie preferences. Google Search Console, which we also use, measures how our pages appear in search results and sets no cookie on this site.
Your rights
In Québec and elsewhere in Canada: access, rectification, withdrawal of consent, de-indexation where the law provides, and, since September 22, 2024, portability of the computerized information you gave us. Write to privacy@carbonforge.ai. We acknowledge within two business days and answer within thirty days. You can also complain to the Commission d'accès à l'information (Québec) or the Office of the Privacy Commissioner of Canada.
If the EU or UK GDPR applies to you: our bases are consent (newsletter, non-essential cookies), performance of a contract or pre-contractual steps, and legitimate interests (B2B prospecting, site security). You also have rights to erasure, restriction, objection (including to direct marketing at any time), and portability, and you may complain to your supervisory authority. For transfers to Canada we rely on the European Commission's adequacy decision for Canadian organizations subject to PIPEDA, and on Standard Contractual Clauses where it does not apply. Where we process personal data on a customer's behalf, our Data Protection Addendum applies once signed; customers can request it at legal@carbonforge.ai.
We do not profile individuals and do not make automated decisions producing legal or similarly significant effects.
How we protect it
Access is limited by role. Portal authentication secrets are stored hashed or encrypted, and access keys are revocable and rotatable. Traffic is encrypted in transit using TLS 1.2 or higher, and we use multi-factor authentication on our core systems. We are an early-stage company and hold no third-party security certification such as SOC 2 or ISO/IEC 27001; we describe our practices as they are rather than warranting standards we have not certified.
If a confidentiality incident occurs, we log it in our incident register, assess the risk of serious injury, and where that risk exists we notify the Commission d'accès à l'information and the people affected, as sections 3.5 to 3.8 of the Québec Act require. If an incident affects a customer's portal account, access keys, or telemetry, we notify that customer within seventy-two hours of confirming it.
Children, changes, contact
Our site and services are for businesses. We do not knowingly collect personal information from anyone under 14; tell us if you think we have, and we will delete it.
We may update this policy by posting a new version here with a new date and version number. We do not publish earlier versions; if you need the version that was in effect on a given date, write to privacy@carbonforge.ai and we will send it to you. If a change materially affects how we handle information already collected, we will seek consent where the law requires it and flag the change on this page.
Questions or requests: privacy@carbonforge.ai. Privacy Officer, the person in charge of the protection of personal information designated under section 3.1 of the Québec Act. CarbonForge Systems Inc., 6666, rue Saint-Urbain, Montréal (Québec) H2S 3H1, Canada. Email reaches us fastest and most privately; our postal address is a shared reception.