Scope and our role

Privacy Requests is operated by Brandon Axtmann, carrying on business as Jumpstart Innovation Labs, a sole proprietorship in Ontario, Canada. Our mailing address is 75 Compass Trail, Port Stanley, Ontario, N5L 0B4, Canada. Our privacy officer is Brandon, reachable at privacy@privacyrequests.co.

This notice covers visitors, account users, prospective customers and people contacting our team. It also explains our role when customers use portals and workspaces to handle information about requesters and other people.

For our own account administration, billing, security and support, we determine why and how information is used (often called acting as a controller). For personal information customers put into their workflows, we generally process information on their behalf (as a processor or service provider). The customer determines the purpose; its privacy notice applies to its handling of your request.

Direct questions about a request submitted through a customer portal to that customer. We may refer requests about its data to it and assist as appropriate. This notice is not a data processing agreement. Confirm any required contractual processing terms before uploading data that requires them. Our terms of service describe the service relationship.

Information and sources

  • Accounts and workspaces: names, email addresses, organization details, roles, invitations, settings, authentication records and security preferences, supplied by you or your administrator.
  • Customer content: requester contact details, request descriptions, verification records, correspondence, notes, tasks, files, response packets, approvals, delivery events and audit history. Customers, authorized users, requesters and connected systems supply it. It may include sensitive information or information about other people.
  • Billing: billing contacts, subscriptions, transaction references and payment records from you and our payment provider. Payment details are entered on Stripe-hosted pages; our checkout does not collect full card numbers in the app.
  • Support and sales: contact details, organization name, messages, feature requests and related workspace context supplied through forms, email or support interactions.
  • Technical activity: IP addresses, browser and device information, dates and times, authentication and access events, errors, service usage and, with your analytics choice, website visits and interactions.
  • Assistant activity: messages, conversation history, workspace context, tool results, generated responses, action records and usage information when the assistant is used.

Account and authentication details are needed for account access; payment information is needed for a paid purchase. Other information depends on the features used. Without relevant information, we may be unable to provide a feature or respond to a request. Avoid sending unnecessary identity documents or requester records to support.

Purposes and legal bases

We use information to operate accounts, process subscriptions, provide intake and response workflows, deliver files, respond to support, send service notices, detect abuse, troubleshoot faults, and maintain security and audit records. We use service usage information and feedback to understand and improve the product. Customer content is processed to provide and secure the service, carry out authorized instructions and meet legal requirements.

Where a law requires a legal basis for our own processing, we rely on performance of a contract when dealing with an individual customer; our legitimate interests in administering business relationships and running a secure, reliable service; compliance with legal obligations such as accounting requirements; or consent where required. Our interests include preventing fraud, resolving support issues and understanding product reliability. Optional website analytics relies on consent. These bases do not replace the customer's responsibility to establish a lawful basis for requester data.

Customers decide what to collect, who may access it, whether identity is sufficiently verified, and what to disclose, correct, delete or retain. Authorized workspace users can access content according to their permissions.

AI and integrations

When an enabled assistant is used, messages and relevant workspace information retrieved for the conversation may be sent through Cloudflare AI Gateway to OpenAI to generate responses and proposed actions. Conversation and action records are also stored in the service. Do not include information your organization has not authorized for this use. Workspace controls govern availability and access.

We do not use customer content, assistant inputs or outputs to train AI models. OpenAI does not use the API data we send to train its models. AI processing may generate abuse-monitoring logs retained for up to 30 days, unless a longer period is legally required. This is separate from conversation history stored in your workspace, which is described under retention below.

AI output can be inaccurate or incomplete. Customers remain responsible for reviewing it and making consequential privacy decisions. The assistant does not independently determine a person's legal rights.

Customers may authorize API clients, MCP clients, webhooks or other integrations to access information or receive events. Data made available to them is subject to customer configuration and the connected provider's handling. Review permissions and provider terms before connecting; revoking access cannot recall copies already received.

Cookies and analytics

Essential cookies and browser storage support sign-in, security and preferences. With your permission, we also use Google Analytics 4 and Matomo to measure page usage, campaign referrals, calls to action, signups, inquiries and subscription activity on the marketing website and staff app. Google receives Google Analytics data; Matomo data is sent to our installation at analytics.jumpstartlabs.co. Both providers are controlled by the analytics choice in our cookie banner and settings.

Neither analytics provider loads before acceptance. Rejecting analytics or withdrawing consent stops further collection by our integration; it does not erase data already sent. We do not enable cookieless analytics pings before consent. The website and app remember your choices separately and ask again after 180 days or a material configuration change.

Our events omit arbitrary query strings, fragments and referrer paths and replace case and task identifiers with generic route names. With consent, we retain limited campaign labels and referring site origins and use first-party analytics identifiers across our website and app. We send confirmed subscription purchases, renewals, refunds and cancellation events from our server using a consenting billing administrator’s analytics identifiers, transaction references, currency and amounts. We keep this consent association for no longer than the original 180-day consent period. Withdrawing analytics while signed in also removes that account’s pending subscription analytics and stops future delivery. Failed deliveries are retried for up to 71 hours; duplicate-prevention records are removed when the consent association expires or is withdrawn. We do not intentionally send request contents, uploaded files, names or email addresses in these events. Providers receive network information, including your IP address, when the browser connects. Requester intake, status, verification and secure delivery pages are excluded. No advertising or session-recording integration is included. See our cookie policy for cookies, lifetimes and how to change your choice.

Sharing and transfers

We disclose information as needed to provide the service, including to:

  • Cloudflare for hosting, storage, databases, security, background processing, service email and AI Gateway; Stripe for payments; Google for consented analytics; and OpenAI for assistant requests when used.
  • Support and communications systems used to manage enquiries, and personnel or professional advisers who need information to perform their work.
  • Authorized customer users, delivery recipients and connected services, according to customer actions and configuration.
  • Authorities or other parties when legally required, or where necessary to investigate abuse, protect people and the service, or establish, exercise or defend legal claims.
  • Parties involved in a merger, acquisition or business transfer, subject to appropriate confidentiality and applicable privacy requirements.

Providers operate internationally. Information may be processed outside your country, where privacy laws and authority access may differ. Cloudflare use does not itself guarantee processing in a particular country. Where law requires a transfer mechanism or additional safeguards, the relevant arrangements must cover that processing. Contact us for applicable locations, safeguards and how to obtain relevant contractual information; do not assume a residency arrangement or transfer agreement exists without confirmation.

This is not a contractual subprocessor schedule. See service facts and review materials and contact us for provider information needed for your assessment.

Retention and security

We retain personal information for the purposes described in this notice, taking account of the type and sensitivity of the information, customer instructions, the duration of the relationship, and applicable accounting, security and legal requirements. We delete or anonymize information when it is no longer needed for those purposes.

  • Accounts and workspace profiles: kept to provide access and administer the relationship. Contact us to request account or workspace closure. Removing one user's account does not delete an organization's shared case records.
  • Customer cases, files and audit records: retained under the customer's instructions. Closing a case or cancelling a subscription does not erase these records. Authorized workspace administrators can contact us to arrange export and deletion; we confirm scope, timing and any required preservation before carrying out the request.
  • Assistant conversations: stored as workspace history until deleted by an authorized user or through a verified deletion request. There is currently no automatic age-based deletion of conversation history. Deleting a conversation does not undo actions or erase the associated case audit records.
  • Billing, support, security and contract records: retained as needed to complete transactions, respond to enquiries, investigate abuse, document the relationship and meet applicable legal requirements. We limit retained records to what is needed for the relevant purpose.
  • Consented analytics: Google Analytics event-level data is retained for two months and user-level data for fourteen months, with the user-level period reset by new activity. These settings do not limit most aggregated reports. Our Matomo installation currently has no automatic age-based deletion of analytics records. Contact our privacy officer about access or deletion of analytics data. We review continued retention against the purposes described in this notice.
  • Recovery copies: some information may remain in provider recovery systems after deletion from active systems until the applicable recovery window expires. Contact us for the recovery window applicable to your data. Information in those systems is restricted to recovery and security purposes; any restoration must account for prior deletion instructions.

Customer content and assistant history support the customer's workflow, subject to applicable instructions and legal requirements. Closing a case, cancelling a subscription or reaching a retention review date does not automatically erase records. Retention settings identify cases for review; legal holds may affect deletion decisions.

Deletion requests are subject to identity and authority checks. Where information must be preserved for a legal obligation, hold, fraud investigation or specific dispute, we restrict its use, retain only what is necessary and delete it when that reason ends. We explain applicable exceptions where lawful. Customer-directed requests about case data must be authorized by the organization responsible for it. Expiring or revoking a delivery link cannot remove downloaded copies.

We use technical and organizational safeguards designed to protect information, including access controls and recorded workflow activity. No system is completely secure. Customers should protect credentials, limit access, review recipients and attachments, and configure delivery safeguards. See our security information for the controls described today.

Your rights and choices

Depending on your location and applicable law, you may have rights to access or obtain a copy of information, correct it, request deletion, restrict processing, receive portable data or withdraw consent. Withdrawal does not affect processing lawful before withdrawal. Rights may be subject to conditions and exceptions.

Right to object: where applicable, you may object to processing based on legitimate interests, and to use of your information for direct marketing. Contact us to exercise these rights. Use any unsubscribe mechanism provided to opt out of promotional messages; necessary account, security and billing communications may continue.

Email privacy@privacyrequests.co with your request. We may ask for proportionate information to verify identity or a representative's authority. We will respond within the period required by law. For customer-controlled case data, contact the organization handling the case.

You may complain to the regulator with jurisdiction, including the Office of the Privacy Commissioner of Canada, the UK Information Commissioner's Office, or your local data protection authority. You do not need to contact us first to exercise a right to complain.

Children, changes and contact

The service is intended for organizational users, not for children to create business accounts. A customer's request may concern a child or representative; the customer is responsible for appropriate authority, notices and safeguards. Contact us if a child has created an account or supplied information to us inappropriately.

We may update this notice as practices change. We will update its date and provide additional notice or seek consent where required by law. Questions can be sent to privacy@privacyrequests.co.