Privacy
Privacy Policy
Last updated: March 2026
1. Data We Collect
This document is a draft that will be reviewed by legal counsel before its final version.
We collect the data necessary to operate the platform. When you create an account, we collect your name, email address, and organization name. During platform use, we record usage data such as pages visited, actions taken, and session preferences.
Payments are processed by Stripe, our PCI DSS-certified payment processor. Observantia does not store your credit card numbers or banking information directly on its servers.
2. How We Process Your Data
Your data is processed exclusively to provide the Law 25 compliance management service. We do not use your data for advertising purposes and we do not sell it to third parties.
The platform infrastructure relies on Supabase (database hosted on AWS) and Vercel (application delivery). These providers process your data solely to perform the requested services and are bound by data processing agreements consistent with applicable requirements. We commit to processing your personal information only with your consent or where permitted by law.
4. Third Parties We Work With
The following third-party providers process data as part of the Observantia service:
Supabase — database and authentication (AWS infrastructure). Stripe — payment processing (PCI DSS certified). Vercel — hosting and content delivery network. Resend — transactional email delivery (confirmations, alerts, reminders). Loops — subscriber newsletter communications. PostHog EU — platform usage analytics, data processed in Europe.
Each provider is selected based on its security and compliance practices. We share only the data necessary for them to perform their respective services.
5. Your Rights (Law 25)
Under Quebec's Act respecting the protection of personal information in the private sector (Law 25, P-39.1), you have the following rights: access to your personal information held by Observantia; rectification of inaccurate or incomplete information; deletion of your data in cases provided for by law; portability of your data in a structured and commonly used format; withdrawal of your consent at any time, without penalty.
To exercise any of these rights, contact our privacy officer by email at info@observantia.ca. We will process your request within the timeframes prescribed by law.
6. Data Retention
Account data is retained for as long as your account is active. After account deletion, your data is retained for an additional 90 days to allow recovery in the event of accidental deletion, then permanently erased.
Payment records are retained in accordance with applicable accounting and tax obligations, generally seven years. Usage analytics data is retained for a maximum of 12 months.
7. Privacy Officer
Elite Consultation has designated a privacy officer in accordance with the requirements of Law 25.
For any questions about this policy, the use of your data, or the exercise of your rights, you may contact us by email at info@observantia.ca. We commit to responding to your request within 30 days of receipt.
8. Changes to This Policy
We may update this privacy policy from time to time to reflect changes in our practices or applicable legislation. The last updated date is always shown at the top of this page.
For significant changes affecting your rights or how we process your data, we will notify you by email with reasonable advance notice before the changes take effect. Continued use of the platform after notification constitutes acceptance of the revised policy.