Privacy Policy
Operated by Canadian Procurement Exchange Inc. — Canadian procurement intelligence for EU businesses
Effective 16 June 2026 • Version v1.2 (draft)
Draft — Legal Review Required

This is a v1.0 draft dated 11 June 2026. Bracketed items marked [confirm] are placeholders. Have EU counsel review this document before relying on it.

This Privacy Policy explains how we collect, use, disclose, and protect personal data when you visit the CanProcX EU service or use it to access Canadian government procurement intelligence (the “Service”). The Service is offered to business customers located in the European Union and European Economic Area who subscribe in euros (EUR). Because our customers and the individuals whose data we process are located in the EU/EEA, this Policy is designed first and foremost to meet our obligations under the General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”). Where Canadian privacy law (the Personal Information Protection and Electronic Documents Act, “PIPEDA”) applies to our operations in Canada, we comply with that as well.

1. Who We Are (Controller, Representative, DPO)

1.1   The Service is operated by Canadian Procurement Exchange Inc. (operating as “CanProcX”, “we”, “us”), a corporation incorporated under the Canada Business Corporations Act (CBCA) with its registered office in Ontario, Canada. For the purposes of GDPR and UK GDPR, Canadian Procurement Exchange Inc. acts as the data controller for personal data collected through your registration and use of the Service.

1.2   Where we process personal data on behalf of a business or defence customer under a service contract, we may act as a data processor; those activities are governed by our Data Processing Agreement rather than this Policy.

1.3   Privacy contact / officer. We have designated a privacy contact accountable for our compliance with this Policy and applicable data-protection law. Reach our privacy contact at privacy@canprocx.ca (or ai.help@canprocx.ca) for any access request, complaint, or question. We do not sell your personal data, and we do not share it for cross-context behavioural advertising.

Controller & Contacts

Data controller: Canadian Procurement Exchange Inc. (operating as CanProcX) [confirm registered address]

Privacy / Data Protection contact: ai.help@canprocx.ca

Data Protection Officer (DPO): [DPO name & contact — confirm whether a DPO is required under GDPR Art. 37]

EU/EEA representative (GDPR Art. 27): [representative name & EU address — required where the controller is established outside the EU; confirm and appoint]

2. Personal Data We Collect

2.1   We collect the following categories of personal data about you, our EU business customers and your users:

2.2   Canadian public procurement data. The intelligence the Service surfaces is drawn from open Canadian government data, principally CanadaBuys (canadabuys.canada.ca), which is licensed under the Open Government Licence – Canada. This data is mostly about organisations, contracts, and tenders, but may incidentally contain the names or contact details of public officials published by Canadian contracting authorities. We process such data only to provide procurement intelligence to you; it is sourced from a public dataset, not collected from you.

3. Purposes & Lawful Bases (GDPR Art. 6)

3.1   We process personal data for the purposes below. For each, the lawful basis under GDPR Article 6(1) is indicated.

PurposeLawful Basis (GDPR Art. 6)
Create and manage your account; deliver the Service to you(b) Performance of a contract
Process subscription payments in EUR via Stripe(b) Performance of a contract
Provide Canadian procurement intelligence from public sources(b) Contract / (f) legitimate interests (delivering the requested business service)
Secure, maintain, and improve the Service; analytics(f) Legitimate interests
Service emails and account notifications(b) Contract / (f) legitimate interests
Marketing emails (where sent)(a) Consent
Comply with legal, tax, and regulatory obligations(c) Legal obligation

3.2   Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms. You may object at any time (see Section 8). Where we rely on consent, you may withdraw it at any time without affecting processing already carried out.

3.3   Artificial intelligence (AI) processing. We use AI and machine-learning techniques to (a) match your profile to relevant tenders and (b) assemble draft bid/submission packages from the information you provide. These tools support decision-making and are not used to make decisions producing legal or similarly significant effects about you without human involvement (GDPR/UK GDPR Art. 22). AI-assembled output is a drafting aid that you review and control. Human-review and contestation: you may at any time request that a human review, explain, or reconsider any AI-assisted output or matching that affects you, and you may contest it, by contacting ai.help@canprocx.ca or privacy@canprocx.ca. We do not use your confidential bid content to train third-party public AI models. [confirm AI sub-processors & training terms]

4. Sharing & Sub-Processors

4.1   We do not sell personal data. We share it only with the service providers (sub-processors) needed to run the Service, and where required by law:

RecipientPurposeLocation
StripePayment processing in EUR (Stripe Checkout)EU / USA [confirm]
Google FirebaseUser authentication (sign-in) & application data storage (Firestore)USA / global
NetlifyWebsite & application hosting / deliveryUSA / global CDN
CanadaBuys (Government of Canada)Public-data source for tender intelligence (Open Government Licence – Canada)Canada
[Analytics provider]Usage analytics (where enabled)[confirm]
[Email provider]Transactional & account emails[confirm]

4.2   We may also disclose data to professional advisers, to comply with a legal obligation or lawful request, to enforce our terms, or in connection with a corporate transaction (e.g., merger or sale), in which case this Policy will continue to apply to the transferred data.

5. International Data Transfers (Canada ↔ EU)

5.1   Operating the Service involves data flows between the European Union and Canada, and some sub-processors (e.g., Netlify, Stripe, Google Firebase) operate in the United States or other countries. Canada benefits from a partial EU adequacy decision for commercial organisations subject to PIPEDA, which supports EU→Canada transfers to such organisations.

5.2   Where transfers are made to countries without an adequacy decision (for example, the United States), we rely on appropriate safeguards under GDPR Articles 44–49, principally the European Commission’s Standard Contractual Clauses (SCCs), supplemented by additional measures where necessary. You may request a copy of the relevant safeguards by contacting ai.help@canprocx.ca.

5.3   Where your data is processed. Personal data may be stored or processed in Canada, the United States, and the European Union, depending on the sub-processor (for example, certain Google Firebase, Stripe, and Netlify infrastructure operates in the United States or other regions).

5.4   Foreign-access caveat. When data is stored or processed outside your home jurisdiction, it may be subject to access by foreign courts, law-enforcement, or governmental authorities under those countries’ laws. We take reasonable steps to limit and protect against such access but cannot exclude it entirely.

6. Data Retention

6.1   We retain personal data only for as long as necessary for the purposes set out in this Policy:

Data typeRetention periodTrigger / basis
Account & profile dataLife of account + 24 months after closure, then deleted/anonymisedService delivery; reactivation; disputes
Billing & transaction records7 years from the transactionTax, accounting & audit obligations
Usage & security logs12 monthsSecurity, fraud prevention, analytics
Support communications24 months from last contactService quality & disputes
Marketing-consent recordsUntil withdrawn + 24 monthsConsent evidence
Cookie / analytics identifiersPer cookie lifetime (max 13 months)Consent & analytics

6.2   Canadian public procurement data sourced from CanadaBuys is retained as part of the Service’s reference dataset and refreshed periodically; it is not retained against an individual user. [confirm final periods with counsel]

7. How We Protect Personal Data

7.1   We apply technical and organisational measures appropriate to the risk, including: encryption in transit (HTTPS/TLS), hashed and salted passwords, role-based access controls, restriction of payment-card handling to Stripe (PCI-DSS compliant), hosting on a reputable provider (Netlify), and least-privilege access to systems. SAFE Defence customers may be subject to additional controls described in their agreement.

7.2   No system is perfectly secure. While we take reasonable steps to protect personal data, we cannot guarantee absolute security.

7.3   Breach-notification procedure. If we become aware of a personal-data breach, we will: (a) contain and assess it without undue delay; (b) where it is likely to result in a risk to individuals, notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware (GDPR/UK GDPR Art. 33); (c) notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms (Art. 34); and (d) keep records of breaches as required. Where Canadian law applies, we will also notify the Office of the Privacy Commissioner of Canada and affected individuals where there is a real risk of significant harm under PIPEDA.

8. Your Rights as a Data Subject

8.1   Subject to applicable law, you have the following rights regarding your personal data under the GDPR:

8.2   How to exercise your rights. Contact our privacy contact at privacy@canprocx.ca (or ai.help@canprocx.ca). We will respond within the timeframe required by the GDPR/UK GDPR — generally within one month, extendable by two further months for complex requests, with notice — free of charge in most cases. We may need to verify your identity before acting on a request, and we will tell you if we cannot fully comply and why.

9. Cookies & Consent

9.1   We use cookies and similar technologies to operate the Service, remember preferences, maintain secure sessions, and (where enabled) measure usage. Categories include strictly necessary cookies (always active), and, where applicable, analytics cookies.

9.2   For visitors in the EU/EEA and UK, non-essential cookies are set only with your prior consent via our cookie banner, consistent with the ePrivacy Directive, GDPR, and UK PECR. You can manage or withdraw cookie consent at any time through the cookie-preferences control on the site or your browser settings. We do not use cookies for cross-context behavioural advertising. [confirm cookie-preferences control & whether a separate Cookie Notice is published]

10. Children’s Privacy

10.1   CanProcX EU is a business-to-business service intended for use by professionals. It is not directed to children, and we do not knowingly collect personal data from individuals under the age of 16 (or the applicable EU member-state age of digital consent). If you believe a child has provided us data, please contact ai.help@canprocx.ca and we will delete it.

11. Changes to This Policy

11.1   We may update this Policy from time to time. The “Effective” date and version above indicate when it was last revised. For material changes, we will provide reasonable advance notice — by email to your account address or a prominent in-product notice — at least 14 days before the change takes effect, and we will seek fresh consent where required. We keep prior versions available on request.

12. How to Complain

12.1   If you have a concern about how we handle your personal data, please contact us first at ai.help@canprocx.ca so we can try to resolve it.

12.2   You also have the right to lodge a complaint with your local EU/EEA data protection supervisory authority (a list is maintained by the European Data Protection Board, edpb.europa.eu). Where Canadian law applies to our operations, you may also contact the Office of the Privacy Commissioner of Canada (priv.gc.ca).

12.3   This Policy is governed by [confirm governing law], without prejudice to mandatory data-protection rights you have under the GDPR.