Table of contents
Capturia ("we", "our") operates a sales automation platform for Quebec and Canadian small and medium businesses. This privacy policy describes in detail how we collect, use, store, share, and protect your personal information when you use our services, our website capturia.io, and our subdomains (app.capturia.io, admin.capturia.io, tool.capturia.io). It applies to SMB clients, their internal users (administrators, sales representatives), prospects, website visitors, and to individuals who interact with the pre-suasion tools published by our clients on their own domains.
1. Information We Collect
We collect information in four ways: directly from you, automatically through our platform, through third-party services you voluntarily connect, and indirectly when you interact with a pre-suasion tool that a Capturia client has published on their own website.
- Information you provide directly: first and last name, email address, phone number, company name, website, industry, responses to forms and qualification questionnaires, messages exchanged with our team or AI agents, appointment information (date, time, participants, meeting notes), data entered in the client portal.
- Information collected automatically: IP address, browser type and operating system, pages visited on the platform and time spent, approximate geolocation derived from your IP address, session identifiers, cookies essential to platform operation (see section 16). Our error monitoring tool Sentry also captures execution traces (stack traces) along with your IP address and application context when an error occurs, in order to diagnose bugs.
- Information from third-party integrations you voluntarily activate: Google Calendar data (availability, events, Google account email address) when you connect Google Calendar; Zoom or Microsoft Teams profile (name, email), meeting data, and recordings when you connect Zoom or Teams; transactional and payment data processed by Stripe; call transcriptions generated by our transcription service AssemblyAI.
- Information collected through pre-suasion tools embedded on our clients' websites: responses to quizzes, calculators and diagnostics, email address and contact details voluntarily submitted by visitors. For this flow, the Capturia client is the principal data controller within the meaning of Quebec Law 25 (see section 4); Capturia acts as a processor and stores this data on the client's behalf.
2. Categories of Data Subjects
This policy covers five distinct categories of individuals whose personal information may be processed by Capturia:
- SMB clients: businesses that have subscribed to a Capturia plan. The information processed concerns the company itself (legal name, address), its legal representative, and payment information.
- Internal users of SMB clients: administrators, sales representatives and collaborators invited by a client to use the platform. The information processed includes account credentials, preferences, platform activity, and content produced as part of their work (responses to internal quizzes, funnel configurations).
- Visitors to capturia.io and prospects: individuals who browse our marketing site, fill in a contact form, register for a webinar, or interact with our AI qualification agents.
- Visitors to pre-suasion tools and sites published via the renderer: end consumers who interact with quizzes, calculators or capture pages that a Capturia client has published on their own domain. These individuals have no direct relationship with Capturia; the SMB client is the principal data controller and their own privacy policy applies first.
- Capturia Partners program partners (affiliates): individuals and companies who refer Capturia for a commission. The information processed is their identity and contact details, their commissions and payouts, their GST and QST numbers and, to produce their tax slips, their tax identity: legal or business name, Quebec address, social insurance number or business number.
3. How We Use Your Information
We use your information exclusively to provide, maintain, secure and improve the services you have requested. Each use is directly tied to a feature visible in the platform.
- Synchronize your sales representatives' calendars with Google Calendar to display availability on public booking pages and automatically create events when appointments are confirmed.
- Create and manage video meetings via Zoom or Microsoft Teams (permanent rooms per representative, automatic links in invitations).
- Process payments for your Capturia subscription via Stripe.
- Send SMS (via Twilio) and transactional emails (via Resend) as part of your workflows: appointment confirmations, follow-ups, reminders. For emails sent on behalf of a Capturia client, we automatically provision a dedicated sending subdomain in the form "{client-name}.mail.capturia.io" via Resend.
- Generate content, analyses, summaries and recommendations using our artificial intelligence providers (Anthropic Claude, Google Gemini, OpenAI): conversational agents, funnel builder, sales coaching, post-meeting summaries, lead qualification.
- Answer your questions about how to use the platform through the support assistant built into the dashboard (powered by Anthropic Claude). To personalize its answers, the assistant receives, when each assistance session opens, a snapshot of your account (plan and usage, configuration inventory [pipelines, AI agents, phone numbers, calendars, integrations, team members], account health, and open support tickets), limited to the sections your role already lets you see in the platform. Retention periods specific to the assistant are detailed in section 14.
- Transcribe sales calls via AssemblyAI to power coaching and quality assurance.
- Compile and publish client pre-suasion tools on the Cloudflare infrastructure (Workers, R2, KV) served from tool.capturia.io and from clients' custom domains.
- Measure usage of published tools through our edge function "renderer-track" which collects anonymous usage metrics (page views, conversion events) without persistent identifiers.
- Produce the tax slips of Capturia Partners affiliates (T4A and RL-1), file them with the Canada Revenue Agency and Revenu Québec and give them to the affiliates, as tax laws require; issue on their behalf, under the agreement they accepted, the self-billed statement of each payout of their commissions; verify their GST and QST numbers with the official registries before using them and claiming input tax credits on their commissions. The social insurance number is used for the slips only.
- Ensure platform security, prevent fraud, monitor errors (via Sentry) and diagnose technical issues.
4. Our Role: Capturia as Controller and as Processor
Within the meaning of Quebec Law 25, Capturia does not have a single role. Depending on the data flow concerned, Capturia acts either as a data controller, or as a processor acting on behalf of a client.
- Capturia acts as a data controller for: information collected through capturia.io (visitors, prospects, contact forms), account information of SMB clients (legal name, payment, configuration), and information of internal users of clients (sales representatives, administrators).
- Capturia also acts as a data controller for information collected through booking pages hosted on capturia.io and its subdomains, when a visitor books an appointment with an SMB client. In this flow, Capturia operates the collection system (form, validation, AI agent, preparation emails, calendar) and this policy applies to the visitor. The relevant SMB client, whose identity is displayed on the booking page, becomes a recipient of the visitor's contact details after the booking is confirmed, for its own subsequent commercial follow-up. For any question about the SMB client's use of contact details after the booking (commercial follow-up, addition to a CRM, subsequent communications), the visitor may contact the SMB client directly.
- Capturia acts as a processor for: information about end leads captured through pre-suasion tools that a Capturia client has published on their own site (the client's custom domain, distinct from capturia.io). In this case, the SMB client determines the purposes, and Capturia processes the data strictly according to its instructions, within the scope of the subscription contract.
- For this last flow (pre-suasion tools on the client's custom domain), the SMB client is responsible for providing its own privacy policy to data subjects and for collecting the required consent. A Data Processing Addendum (DPA) is available to SMB clients on request at info@capturia.io. The DPA frames Capturia's obligations as processor and lists the sub-processors used (Anthropic, Google Gemini, Cloudflare, etc.) along with a right of objection.
- Capturia never combines data processed for one client with data processed for another: isolation is enforced at the database level by Row Level Security (see section 10).
5. Integrations and Third-Party Services
Capturia integrates with several third-party services to deliver its features. Each integration is voluntarily activated by you and can be disconnected at any time from the platform settings. Upon disconnection, OAuth access tokens are immediately deleted from our systems. Here is the detail of each integration:
- Google Calendar. Data accessed: calendar (availability and events), Google account email address. Purpose: synchronize sales representatives' availability and create appointment events. OAuth scopes requested: calendar.readonly, calendar.events, userinfo.email. OAuth access and refresh tokens are encrypted with AES-256 before storage. Capturia does not store the detailed content of your existing events: only availability slots are consulted. Revocation: from the Capturia settings or via myaccount.google.com/permissions.
- Zoom. Data accessed: user profile (name, email), meeting creation and management, recordings list. Purpose: automatically create meetings for appointments, generate permanent rooms per representative, access recordings for coaching. OAuth tokens are encrypted with AES-256 before storage. Capturia never stores your Zoom password. Revocation: disconnect from Capturia settings (calls Zoom's OAuth revoke endpoint immediately) or uninstall via marketplace.zoom.us > Manage > Added Apps (Zoom sends us a deauthorization event and we confirm data deletion back to Zoom).
- Microsoft Teams. Data accessed: user profile (name, email), online meeting creation and management with their metadata (participants, dates, identifiers), meeting recordings when available. Purpose: generate permanent rooms per representative and their links in invitations, access recordings for coaching and call analysis of sales representatives who use Teams instead of Zoom. OAuth tokens are encrypted before storage and revocable from the Capturia settings.
- DocuSign. Data processed: signer information (name, email), contract content, electronic signature with timestamp and IP address. Purpose: have DFY contracts signed by SMB clients at the moment of conversion. The DocuSign webhook triggers the transition of the client account from demo to active state. DocuSign policy: docusign.com/company/privacy-policy.
- Stripe. Purpose: processing of Capturia subscription payments. Capturia does not store your credit card numbers; they are processed directly by Stripe (PCI-DSS Level 1 certified). Stripe policy: stripe.com/privacy.
- Stripe Connect. For SMB clients who choose to use it, Stripe Connect allows Capturia to facilitate the processing of their own clients' payments through the platform. The SMB client controls their Connect accounts, products, prices and payment links. Capturia neither sees nor stores card numbers of the SMB client's own customers.
- Anthropic (Claude API). Data processed: content of conversations sent to our AI agents, lead context, content generation prompts for the funnel builder, conversations with the dashboard support assistant, and the account snapshot transmitted at the start of each assistance session (plan and usage, configuration inventory [pipelines, AI agents, phone numbers, calendars, integrations, team members], account health, and open support tickets). Purpose: powering conversational agents, the AI-assisted funnel builder, copy analysis, and the built-in support assistant. API keys, access tokens and other secrets are never transmitted to Anthropic. Under Anthropic's Commercial Terms and DPA effective January 1, 2026, data sent through the API is not used to train its models. Anthropic retains API data by default for 7 days for security and abuse prevention purposes, then deletes it. Policy: privacy.claude.com.
- Google Gemini API. Data processed: prompts sent to the AI-assisted funnel builder and to certain generation features. Purpose: content generation, suggestions, analysis. Under Google Cloud's "Cloud Data Processing Addendum", prompts sent to Gemini for Google Cloud are not used to train its models.
- OpenAI. Data processed: sales conversation content, call transcriptions, lead context data for certain legacy agents. Purpose: powering AI conversational agents and post-meeting summary generation. Under OpenAI's API policy, data submitted via the API is not used to train its models.
- AssemblyAI. Data processed: sales call audio files and video meeting recordings. Purpose: automatic transcription for coaching and quality assurance. Audio files are deleted by AssemblyAI after transcription, and the transcript produced at AssemblyAI is deleted there automatically no later than 30 days after it was created. The copy Capturia keeps follows the periods in section 14.
- Twilio. Data processed: contact phone numbers, SMS message content, call metadata and recordings, voicemails. Purpose: sending and receiving SMS, voice calls and voicemails as part of your workflows. Twilio also handles regulatory STOP/opt-out keyword management. Call recordings, voicemails and media received by text (photos, voice notes) are copied to our infrastructure, then deleted from Twilio once our copy is verified. The trace of a recorded call is deleted from Twilio when its recording reaches the retention deadline chosen by the client; the traces of a contact's calls and texts are deleted from Twilio when their record or the account is deleted. A deletion that fails at Twilio is retried automatically, without ever losing a recording we have not copied yet.
- WhatsApp Business. Data processed: phone numbers, content of inbound and outbound WhatsApp messages. Purpose: WhatsApp conversations in the unified inbox of clients who enable this channel. Opt-out is managed per contact in the database.
- Resend. Data processed: recipient email addresses and content of transactional emails. Purpose: email delivery. For each Capturia client, we automatically provision a dedicated sending subdomain under mail.capturia.io via Resend, which improves deliverability and per-client isolation.
- Meta (Facebook, Instagram). Data accessed: connected Facebook pages, professional Instagram accounts, Facebook Ads campaigns. Purpose: (a) receive leads submitted via Facebook Lead Ads directly into the Capturia platform, (b) send server-to-server conversion events (Conversions API) to measure campaign performance (for example a Lead event on webinar registration, a Purchase event on Blueprint purchase). Meta OAuth tokens are encrypted before storage.
- GoHighLevel. Data processed: for clients who link their own GoHighLevel sub-account to Capturia from their account, contact records, deals, appointments, notes and tasks are synchronized both ways; the contact's qualification and a Capturia summary are shown there, the summary and key moments of each analyzed meeting are added there as a comment on the contact's record, and sent proposals (status, amounts, contract, payments) are reflected there. Conversations (SMS, emails, calls) are reflected there only with the client's explicit consent. For some clients whose primary CRM remains hosted there, leads from their landing pages, forms and pre-suasion tools (name, email, phone, tags, answers) are also sent there. These copies live at GoHighLevel under the client's account rules: the retention periods in section 14 do not apply to them. Purpose: keep the client's GoHighLevel CRM up to date with Capturia.
- Cloudflare. Purpose: hosting of published pre-suasion tools (Workers + R2 storage + KV for routing), CDN, web application firewall (WAF), management of clients' custom domains via Cloudflare for SaaS. Cloudflare may process visitors' IP addresses and HTTP headers to ensure security and content delivery. Capturia also uses Cloudflare Turnstile, a bot detection mechanism that protects our public forms (login, chat assistant, pre-suasion tools), including in invisible mode with no visitor interaction. Turnstile analyzes technical browser signals to distinguish humans from bots, without advertising cookies or cross-site tracking. Its data processing is described in the Cloudflare Turnstile Privacy Addendum, available at https://www.cloudflare.com/turnstile-privacy-policy/.
- ENTRI. Third-party component loaded in the browser inside the client dashboard when adding a custom domain. ENTRI enables one-click DNS configuration with more than 60 registrars. Capturia does not store any registrar credentials and performs no DNS writes from its servers.
6. Google User Data: Google API Services User Data Policy Compliance
Capturia's use of information received from Google APIs adheres to the Google API Services User Data Policy (developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements. Capturia commits to the following restrictions:
- Capturia accesses Google Calendar data only to provide calendar synchronization, appointment management, and meeting room creation features directly visible in the platform user interface.
- Capturia does not use or transfer data received from Google APIs for any of the following purposes prohibited by Google: (1) targeted advertising, (2) selling to data brokers, (3) providing to information resellers, (4) determining credit-worthiness, (5) lending purposes, (6) user advertisements, (7) personalized advertisements, (8) retargeted advertisements, (9) interest-based advertisements, (10) creating databases, (11) training, fine-tuning or improving artificial intelligence models, whether developed internally or by our third-party AI providers (Anthropic, Google Gemini, OpenAI).
- Capturia never sells Google user data to third parties.
- Capturia does not allow humans to read data received from Google APIs unless: (a) you have given explicit and informed consent, (b) it is necessary for security purposes (investigating abuse or a vulnerability), (c) to comply with a legal obligation, or (d) in aggregated and anonymized form for internal operations that do not allow identification.
- Google OAuth access and refresh tokens are encrypted using AES-256 before storage in our database and are never stored in plain text. Tokens are transmitted exclusively over HTTPS encrypted connections. Upon disconnection of a Google integration, tokens are deleted immediately and the associated Google data is no longer accessible to Capturia. Upon termination of your account, all tokens are deleted within 30 days in accordance with the account deletion procedure described in section 14.
7. Information Sharing and Sub-processors
We never sell your personal information. We share your information only with the following categories of recipients, to the extent strictly necessary for the purposes described in this policy:
- SMB clients receiving leads after a booking: when a visitor books an appointment via a booking page hosted on capturia.io, their contact details (name, email, phone, any notes, qualification answers) are transmitted to the relevant SMB client to enable the appointment and its subsequent commercial follow-up.
- Infrastructure providers: Supabase (database, authentication, edge functions; hosted on Amazon Web Services), Vercel (web application hosting), Cloudflare (Workers, R2, KV, WAF, management of clients' custom domains).
- Artificial intelligence providers: Anthropic Claude (conversational agents, funnel builder), Google Gemini (AI content generation), OpenAI (legacy AI agents and coaching).
- Communication providers: Twilio (SMS, voice, voicemails), Resend (transactional emails and per-client sending subdomains), WhatsApp Business (WhatsApp messages for clients who enable this channel).
- Transcription and audio analysis provider: AssemblyAI (phone calls and video meeting recordings).
- Videoconferencing providers: Zoom, Microsoft Teams (depending on the sales representative's choice).
- Payment providers: Stripe (Capturia subscription payments), Stripe Connect (for SMB clients who process their own clients' payments through Capturia).
- Electronic signature provider: DocuSign (DFY contract signing).
- Advertising providers: Meta (Facebook Lead Ads management, server-to-server event delivery via Conversions API to measure campaign performance).
- External CRM synchronization: GoHighLevel (synchronization of records, deals, appointments, notes and tasks for clients who link their sub-account, conversations with their consent; leads from some landing pages and pre-suasion tools sent for clients whose primary CRM remains hosted there).
- Observability provider: Sentry (collection of errors and execution traces with technical context for debugging, including Session Replay).
- Internal notifications: Slack (operational notifications to the Capturia team, for example upon a new webinar registration or a technical incident). No personal data of end leads is externalized to Slack beyond contextual summaries when necessary.
- Third-party components loaded in the browser: ENTRI (one-click DNS configuration in the custom domains wizard).
- Third-party services voluntarily connected by you: Google, Zoom, Microsoft Teams, to the extent necessary for the integration you activated.
- Tax authorities and accountant: the Canada Revenue Agency and Revenu Québec receive the tax slips of Capturia Partners affiliates (legal obligation); our external accountant, bound by professional secrecy, receives the information needed to produce their RL-1 slips in software authorized by Revenu Québec. A partner's QST number is checked with Revenu Québec's official service, which receives that number only.
- Legal authorities: only if required by a valid court order, applicable law, or to protect our legal rights. We challenge any request that appears disproportionate to us.
8. Information Transfers Outside Quebec
Capturia is a company established in Quebec, Canada. In the course of providing our services, some of your personal information may be transferred to and processed outside Canada by our technology sub-processors. Before any transfer, we ensure that the recipient provides an adequate level of protection in accordance with Law 25 requirements and that a data processing agreement is in place. Here is the principal location of our sub-processors:
- Supabase: database and authentication, hosted on Amazon Web Services, United States.
- Vercel: web application hosting, United States.
- Cloudflare: Workers, R2, KV and WAF, multi-region infrastructure with presence in the United States and globally.
- Anthropic (Claude API): United States. API data is not used for training, default retention of 7 days.
- Google (Calendar, Gemini API): United States, subject to the Google API Services User Data Policy and Cloud Data Processing Addendum.
- Microsoft (Teams): United States and other regions, subject to Microsoft standard contractual clauses.
- OpenAI: United States. API data is not used for training.
- Zoom: United States.
- Stripe and Stripe Connect: United States, PCI-DSS Level 1 certified.
- DocuSign: United States, compliant with industry standards eIDAS and SOC 2.
- Sentry: United States, acts as a processor for error collection.
- AssemblyAI: United States.
- Twilio: United States.
- WhatsApp Business (Meta): United States and other Meta regions.
- Meta: United States (Lead Ads and Conversions API).
- Resend: United States.
- GoHighLevel: United States.
- Slack: United States (internal notifications to the Capturia team).
9. Privacy Impact Assessments (PIA)
In accordance with section 3.3 of Quebec Law 25, Capturia conducts a privacy impact assessment for each transfer of personal information outside Quebec as well as for any new high-risk processing project. The PIA examines data sensitivity, purposes, contractual and technical protection measures, the legal framework of the destination country, and remedies available to data subjects. The PIAs conducted by Capturia are available upon reasonable request to B2B clients and to the Commission d'accès à l'information du Québec (CAI). This procedure is reviewed at regular intervals and upon any major change of sub-processor.
10. Information Security
We implement technical and organizational security measures consistent with industry standards to protect your information against unauthorized access, loss, alteration, or disclosure:
- Encryption of all data in transit via HTTPS/TLS between your browser and our servers.
- AES-256 encryption of all OAuth tokens (Google, Zoom, Microsoft Teams) and sensitive authentication credentials before database storage.
- Strict per-client data isolation in the database via Row Level Security (RLS): one client can never access another client's data.
- Role-based access controls (owner, administrator, sales representative) with server-side verification on every request.
- CSRF (Cross-Site Request Forgery) protection on all OAuth authentication flows via single-use httpOnly cookies.
- Authenticated sessions with automatic token refresh and configurable expiration.
- Cloudflare Web Application Firewall (WAF) in front of published tools to block known attacks and rate-limit traffic.
- Logging of access to sensitive data for anomaly detection, and collection of application errors by Sentry to quickly identify vulnerabilities.
- Principle of least privilege for internal access to production data: only strictly necessary personnel have access, which is logged and revocable.
- AES-256-GCM encryption of Capturia Partners affiliates' social insurance numbers before storage: only the last three digits remain readable, the number is decrypted only to produce a slip, and every access to a tax document is logged.
11. Behavioral Analytics and Session Recording
Capturia uses two distinct recording mechanisms, for different purposes. First, on the platform (capturia.io, app.capturia.io, admin.capturia.io), Sentry's "Session Replay" integration records an anonymized visualization of your session only when an application error occurs (no capture under normal conditions, capture triggered by the error). This recording is used exclusively for diagnosing the bug. Sensitive fields (passwords, payment information) are masked automatically by default. Second, on the funnels and pre-suasion tools published by Capturia clients on their own sites, a heatmap mechanism based on the rrweb library collects anonymous clicks, scrolls and movements to help the SMB client optimize their funnel. For this second flow, the SMB client is the data controller within the meaning of Quebec Law 25 (see section 4) and Capturia acts as a processor. None of these recordings is sold or used for advertising purposes. In accordance with section 8.1 of Quebec Law 25 (technologies that may identify, locate or profile), an explicit prior consent mechanism is planned. In the meantime, you can object to these recordings by contacting us at info@capturia.io.
12. Artificial Intelligence
Capturia uses artificial intelligence in several aspects of its platform. We believe in transparency about the use of these technologies:
- AI conversational agents: automated agents (powered primarily by Anthropic Claude, and by OpenAI for some legacy agents) qualify incoming leads, ask qualification questions, and collect relevant information. Conversations are stored in the platform and accessible to sales representatives.
- Support assistant: an assistant built into the dashboard (powered by Anthropic Claude) answers your questions about how to use the platform, reviews your account configuration to diagnose issues (schedules, SMS, AI agents, pipeline), and can prepare a support ticket that you approve before it is sent. It only reads data from your own account, according to your role's permissions, and can never see another client's data. Assistance conversations are transmitted to Anthropic without prior anonymization (the assistant must be able to name your contacts and configurations in order to help you), but personal information is redacted in the internal log of the checks it performs. Only Capturia team members holding a dedicated support role can view a conversation transcript, notably when you escalate it to human support.
- Connector for your own AI assistant (Claude, ChatGPT): an account owner or administrator can connect their own AI assistant to Capturia through the connector, after authorizing access on Capturia's authorization screen, which shows the address of the receiving application. The assistant can then read, in read-only mode, the account's data (records and prospects, pipeline, today's appointments, AI agent conversations, connector usage) and prepare message drafts that the person sends themselves. The data the assistant reads is transmitted to that assistant's provider (Anthropic for Claude, OpenAI for ChatGPT, or the publisher of any other application the person authorizes) through the person's own account with that provider, and is processed under that account's terms and settings, not under Capturia's agreements with its own providers. The token given to the assistant is reserved for the connector: it opens no other access to the account's data. Like any sign-in of the person, Capturia's sign-in service also recognizes it for that person's own sign-in profile (email address, two-factor authentication, sessions): an email address change there must be confirmed from both the old and the new address, and the password cannot be changed there without the current password. Each person sees and cuts off their assistants in My Account, Connected assistants tab; the owner and administrators also see their team's assistants and the connection log there, and the owner can remove the permission to connect an assistant with custom permissions.
- Funnel and copy builder: Anthropic Claude and Google Gemini generate marketing content (titles, sections, copy) from prompts entered by sales representatives. Generated content is always editable by a human before publication.
- Sales coaching: AI analyzes call and conversation transcriptions to provide personalized recommendations to sales representatives: strengths, areas for improvement, follow-up suggestions.
- Post-meeting summaries: after each transcribed call or meeting, AI generates a structured summary with key points, commitments, and next steps.
- Workflow automation: AI may trigger or personalize certain steps in follow-up sequences (SMS and email content, lead prioritization).
- None of these providers (Anthropic, Google, OpenAI) uses data sent through their commercial APIs to train their models, pursuant to their respective DPAs in effect in 2026.
13. Decisions Based Exclusively on Automated Processing
In accordance with section 12.1 of Quebec Law 25, Capturia commits to inform data subjects of any decision made solely through automated processing that would produce a legal effect or significantly affect them. To date, Capturia does not make any such decisions: all analyses, scores, rankings and recommendations generated by AI are decision-support tools intended for a human (sales representative, administrator, Capturia team), who remains the sole final decision-maker. If we were to introduce in the future an exclusively automated decision affecting a person (for example an automatic refusal of service), we would: (a) explicitly inform the person at the time of the decision, (b) communicate to them the personal information used, the principal factors and the general logic of the processing, (c) offer them the right to submit observations and request the review of the decision by a human, at info@capturia.io.
14. Data Retention
We retain your personal information according to the following periods, after which it is deleted or anonymized:
- Active client account data (profile, company, configuration): retained for the duration of the contractual relationship, then 3 years after contract end to meet legal and tax obligations.
- Prospect and lead data (record, answers to pre-suasion tool quizzes and forms, exchanges): kept for as long as the responsible SMB client keeps the record, and deleted with it or with its account; the SMB client decides. A chat conversation is deleted 24 months after its last activity, or 30 days after if it was never linked to a record. The text of meeting analyses follows its own period, below.
- Call recordings, voicemails, meeting recordings and media received by text (photos, voice notes), along with the word-for-word transcript of calls, voicemails and meetings: kept for as long as the contact's record exists. Deleting the record removes the audio and word-for-word transcript of calls and meetings, the analysis and summary of meetings, and deletes voicemails and text conversations with their media; the summary and notes of calls, and the notes of meetings, stay. Deleting the account deletes everything. In both cases, the copies at our phone provider Twilio are deleted too, and a deletion that fails there is retried automatically. A call, voicemail or meeting with no record is kept until the account is deleted, unless automatic deletion applies. The account administrator can turn on automatic deletion of call recordings, voicemails and meeting recordings after 30, 90, 180, 365 or 730 days ("Recording retention" setting, off by default); turning the setting on or shortening it never deletes anything within 7 days. At the deadline, the audio is deleted along with the word-for-word transcript, for calls, voicemails and meetings, as well as the word-for-word quotes reused in a meeting's analysis; the summary, analysis and notes stay. The audio and transcript of a meeting shown as a replay in a proposal that's still active go once that proposal ends. Recordings of a contact under a signed contract, and those the team chose to keep, are never deleted automatically, nor is their transcript.
- Meeting analyses (summary, key moments, objections, next action, coaching comments): their text is erased 24 months after the last contact with the person (activity on their record, exchanges on every channel, meetings, appointments), or 24 months after the meeting when it is linked to no record. The analysis's numeric scores (including those corrected by a manager, without their reason) and costs stay attached to the meeting, without any text drawn from the conversation. Appointment prep notes and handoff notes drawn from these analyses go at the same time, and the morning summary sent to teams is deleted after 24 months.
- Quotes and proposal pages: these are the SMB client's business documents, kept until its account is deleted. Deleting the contact's record does not delete them; they are then detached from it. A proposal page may restate facts retained from meetings with the person: they stay in the page for as long as it is kept, even after the transcript and the analysis are deleted.
- Conversations with the dashboard support assistant: a session inactive for 30 days is automatically archived; transcripts of archived sessions are retained for 12 months after archiving, then deleted. The internal log of checks performed by the assistant is retained for 90 days for reads and 2 years for actions. The account snapshot attached to a session is deleted upon archiving; if the session was escalated to human support, it is retained with the ticket to document its context, until the session itself is deleted (12 months after archiving). Deleting the client account or removing a team member also deletes the associated assistance conversations.
- Payment and billing data: retained as required by applicable Quebec tax regulations (minimum 6 years).
- Connection logs and security data: 12 months.
- Errors, execution traces and Session Replay recordings captured by Sentry: retained according to our Sentry provider's retention policy, typically between 30 and 90 days depending on data category and our plan, then automatically purged.
- Heatmaps and anonymous events collected on published client funnels: retained for a maximum of 24 months to allow the SMB client to analyze funnel performance, then purged.
- Data sent to AI providers (Anthropic, Google Gemini, OpenAI): Anthropic retains API requests for 7 days by default and then deletes them; the other providers apply equivalent policies under their commercial DPAs.
- OAuth tokens from third-party integrations: deleted immediately when the user disconnects the integration. Upon account termination, all tokens are deleted within 30 days.
- AI assistants connected to the connector (Claude, ChatGPT): an assistant's access ends as soon as it is cut off: its sessions and pending authorizations are deleted, and its consent is revoked. The record of that consent (application, authorization and revocation dates) stays attached to the person's sign-in account, and is deleted with it. The connection log (which person connected or cut off which assistant, and when) is kept as long as the account exists, and deleted with it or with the person.
- Tax information of Capturia Partners affiliates (tax identity, encrypted social insurance number, slips, self-billed statements of their payouts, agreement acceptances, tax numbers and their verifications): kept until December 31 of the seventh year after the last tax year concerned, as tax laws require, including after the partner's account is closed, then destroyed.
15. Your Rights: Quebec Law 25
In accordance with Quebec's Act respecting the protection of personal information in the private sector (Law 25, RLRQ c. P-39.1) and the federal Personal Information Protection and Electronic Documents Act (PIPEDA), you have the following rights over your personal information held by Capturia:
- Right of access: You may request a copy of all personal information we hold about you, including its source, the categories of persons who have access to it, and the planned retention period.
- Right of rectification: You may request the correction of inaccurate, incomplete, or ambiguous information.
- Right of deletion and right to de-indexation: You may request the deletion of your information when it is no longer necessary for the purposes for which it was collected, subject to our legal retention obligations.
- Right to withdraw consent: You may withdraw your consent to a specific processing activity at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
- Right to portability: You may request to receive your information in a structured and commonly used technological format, or to have it transmitted to another organization.
- Right to object to profiling and session recording technologies: See section 11 for the objection procedures.
- To exercise any of these rights, send your request to info@capturia.io specifying your identity and the right you wish to exercise. We will acknowledge receipt within 5 business days and process your request within a maximum of 30 days in accordance with Law 25.
- Mechanisms already in place in the platform: (a) SMB clients and their internal users can request account deletion directly from the dashboard settings, which triggers a purge process with a grace period; (b) a complete export of their data, meeting transcripts and analyses included, is available on demand from the dashboard; (c) for contacts managed in the CRM by an SMB client, the right to erasure is exercised by deleting the record from the dashboard or the API: deletion is immediate and takes with it the contact's call and meeting recordings and their word-for-word transcript, the analysis of meetings, voicemails and media received by text; the files are removed from our storage and from our phone provider within the hour; (d) two-factor authentication (2FA) is available for all accounts.
- For rights related specifically to an SMB client's use of your contact details after a booking made on capturia.io (commercial follow-up, addition to a CRM, subsequent communications), you may also contact the relevant SMB client directly, whose identity appears on the booking page. Capturia will facilitate your request if needed and remains your primary contact for the collection phase.
- If we are unable to fulfill your request (for example due to a legal retention obligation), we will inform you in writing with the reasons for the refusal and the available remedies.
17. Confidentiality Incident Notification
In the event of a confidentiality incident presenting a risk of serious harm to data subjects, Capturia commits to: (a) notify without undue delay (targeting a delay of 72 hours after becoming aware) the Commission d'accès à l'information du Québec (CAI) and the affected individuals, (b) maintain an internal register of all confidentiality incidents, kept for at least 5 years, (c) cooperate with the CAI and any other competent authority, (d) take any reasonable measure to contain the incident and reduce its impact. If you suspect an incident involving your information, contact us immediately at info@capturia.io with "Incident" in the subject line.
18. Complaint Procedure
If you believe that Capturia has not respected your rights regarding personal information protection, we invite you first to write to info@capturia.io describing the situation. We will acknowledge receipt within 5 business days and provide a reasoned response within 30 days. If the response does not satisfy you, you may file a complaint with the Commission d'accès à l'information du Québec (CAI) via cai.gouv.qc.ca, or with the Office of the Privacy Commissioner of Canada (OPC) via priv.gc.ca for matters of federal scope. No retaliatory measure will be taken against any person who has exercised their rights or filed a complaint.
19. Person in Charge of the Protection of Personal Information
In accordance with section 3.1 of Quebec Law 25, the person in charge of the protection of personal information at Capturia is, by default and in the absence of a written delegation, the principal officer of Capturia The person in charge can be reached at: info@capturia.io, Capturia, Quebec City (Quebec), Canada. The person in charge oversees the application of this policy, processes requests for the exercise of rights, coordinates the response to confidentiality incidents, and represents Capturia before the CAI. Any written correspondence may be addressed to the attention of the "Person in Charge of the Protection of Personal Information".
20. Changes to This Policy
We may update this privacy policy to reflect changes in our practices, services, or applicable laws. The date of the latest update is shown at the top of the page. In the event of a material change, we will notify you by email or through a prominent notice on the platform before the changes take effect. Your continued use of the services after notification constitutes your acceptance of the changes. We encourage you to review this policy regularly.
21. Contact and Official Version
For any questions regarding this privacy policy, to exercise your rights or to report an incident, contact Capturia's person in charge of the protection of personal information at: info@capturia.io, Capturia, Quebec City (Quebec), Canada. This policy is drafted in French and in English. In case of any divergence of interpretation between the two versions, the French version shall prevail.