Privacy Policy
Operated by Canadian Procurement Exchange Inc. (operating as CanProcX) · canprocx.ca
Effective 16 June 2026 • Version v1.2 (draft)
Draft: Not Legal Advice

This is an AI-prepared v1.2 draft. It is not legal advice. Have qualified privacy counsel review this document before relying on it. Items in [square brackets] are placeholders to be confirmed (e.g., registered address, EU/UK representative, DPO).

This Privacy Policy explains how we collect, use, disclose, and protect personal information when you visit canprocx.ca or use the CanProcX service (the “Service”), including the Standard and SAFE Defence tiers. It is designed to meet our obligations under Canadian privacy law (the Personal Information Protection and Electronic Documents Act (PIPEDA) and, where applicable, Quebec’s Law 25) and, for users and data subjects located in the European Union and United Kingdom, the EU General Data Protection Regulation (GDPR, Regulation (EU) 2016/679) and the UK GDPR.

We Do Not Sell Your Personal Information

CanProcX does not sell your personal information, and we do not share it for cross-context behavioural advertising. We share personal information only with the service providers needed to run the Service and where required by law, as described in Section 4.

1. Who We Are

1.1   The Service is operated by Canadian Procurement Exchange Inc. (operating as “CanProcX”, “we”, “us”), a corporation incorporated under the Canada Business Corporations Act (CBCA) with its registered office in Ontario, Canada. For the purposes of GDPR and UK GDPR, Canadian Procurement Exchange Inc. acts as the data controller for personal information collected through public use of the Service and this website.

1.2   Where we process personal data on behalf of a business or defence customer under a service contract, we act as a data processor; those activities are governed by our Data Processing Agreement rather than this Policy.

1.3   Privacy contact / officer. We have designated a privacy contact accountable for our compliance with this Policy and applicable privacy law. You can reach our privacy contact at privacy@canprocx.ca (or ai.help@canprocx.ca) for any access request, complaint, or question about how we handle your personal information.

Contact & Privacy Enquiries

Controller: Canadian Procurement Exchange Inc. (operating as CanProcX)

Privacy contact / officer: privacy@canprocx.ca • ai.help@canprocx.ca

Postal address: [Canadian Procurement Exchange Inc., registered address, Ontario, Canada]

EU/UK representative (GDPR Art. 27 / UK Art. 27): [name and contact; confirm whether a representative must be appointed]

Data Protection Officer (if appointed): [name and contact; confirm whether a DPO is required]

2. Information We Collect

2.1   We collect the following categories of personal information:

2.2   Public procurement data. The Service surfaces tender and procurement information drawn from largely public, third-party government sources such as TED (tenders.ted.europa.eu), the UK’s Find a Tender service, Canada’s CanadaBuys, and other national or regional procurement portals. This data is mostly about organisations and contracts, but may incidentally contain names of public officials or contact persons published by contracting authorities. We process such data as part of providing procurement intelligence.

2.3   The table below summarises, by category, the personal information we process, its source, why we process it, and the categories of recipients we share it with.

CategorySourcePurposeShared with
Account & contact data (name, business email, company, role, password)Provided by you at registrationCreate and operate your account; authenticate sign-in; provide the Service; supportGoogle Firebase (auth/storage); email provider; hosting (Netlify)
Company & bid-profile dataProvided by youMatch you to relevant tenders; assemble AI bid packagesGoogle Firebase; AI processing provider(s)
Usage & device data (logs, IP, browser, pages, searches)Collected automaticallyOperate, secure, and improve the Service; analyticsHosting/CDN; analytics provider (where enabled)
Payment & billing data (status, last 4 digits, billing name/country)From Stripe (you provide card data directly to Stripe)Process subscriptions; tax/accounting; fraud preventionStripe; accounting/tax advisers as required
Communications (support messages, records)Provided by youRespond to and document support and enquiriesEmail/support provider
Procurement / tender data (incidental official contact names)Third-party government feeds (TED, Find a Tender, CanadaBuys, etc.)Provide procurement intelligence and matchingNot shared as personal data; presented within the Service

2.4   Sources of information. We collect personal information (a) directly from you; (b) automatically through your use of the Service; and (c) from third-party sources, namely our payment processor (Stripe) and the public/government procurement feeds described above.

3. Purposes & Legal Bases for Processing

3.1   We process personal information for the purposes below. For GDPR-covered processing, the relevant legal basis under Article 6(1) is indicated; under PIPEDA, processing relies on your knowledge and consent and on reasonable, identified business purposes.

PurposeGDPR Legal Basis (Art. 6)PIPEDA Basis
Create and manage your account; deliver the Service(b) Performance of a contractConsent / contractual necessity
Process subscription payments via Stripe(b) Performance of a contractConsent / contractual necessity
Provide procurement intelligence from public sources(f) Legitimate interests (delivering the requested business service)Reasonable business purpose
Secure, maintain, and improve the Service; analytics(f) Legitimate interestsReasonable business purpose
Service emails and account notifications(b) Contract / (f) legitimate interestsConsent / reasonable purpose
Marketing emails (where sent)(a) ConsentExpress or implied consent (CASL)
Comply with legal, tax, and regulatory obligations(c) Legal obligationRequired by law

3.2   Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms. You may object at any time (see Section 8). Where we rely on consent, you may withdraw it at any time without affecting processing already carried out.

3.3   Artificial intelligence (AI) processing. We use AI and machine-learning techniques to (a) match your company and bid profile to relevant tenders, and (b) assemble draft bid/submission packages from the information you provide and the data available to us. These tools support our team and your decision-making; they are not used to make decisions producing legal or similarly significant effects about you without human involvement. AI-assembled output is a drafting aid that you review and control. Human-review and contestation right: you may at any time request that a human review, explain, or reconsider any AI-assisted output or matching that affects you, and you may contest it, by contacting ai.help@canprocx.ca or privacy@canprocx.ca. We do not use your confidential bid content to train third-party public AI models. [confirm AI sub-processors & training terms]

4. How We Share & Disclose Information

4.1   We do not sell personal information. We share it only with the service providers (sub-processors) needed to run the Service, and where required by law:

RecipientPurposeLocation
StripePayment processing (Stripe Checkout)USA / EU [confirm]
Google FirebaseUser authentication (sign-in) & application data storage (Firestore)USA / global
NetlifyWebsite & application hosting / deliveryUSA / global CDN
[Analytics provider]Usage analytics (where enabled)[confirm]
[Email provider]Transactional & account emails[confirm]

4.2   We may also disclose information to professional advisers, to comply with a legal obligation or lawful request, to enforce our terms, or in connection with a corporate transaction (e.g., merger or sale), in which case this Policy will continue to apply to the transferred information.

5. International Data Transfers

5.1   The Service involves data flows between Canada and the European Union, and some sub-processors (e.g., Netlify, Stripe) operate in the United States or other countries. Canada benefits from a partial EU adequacy decision for commercial organisations subject to PIPEDA, which supports EU–Canada transfers.

5.2   Where transfers are made to countries without an adequacy decision, we rely on appropriate safeguards under GDPR Articles 44–49 (and the equivalent UK GDPR mechanisms), principally the European Commission’s Standard Contractual Clauses (SCCs) and the UK International Data Transfer Agreement (IDTA) / Addendum, supplemented by additional measures where necessary. You may request a copy of the relevant safeguards by contacting privacy@canprocx.ca.

5.3   Where your data is processed. Personal information may be stored or processed in Canada, the United States, and the European Union, depending on the sub-processor (for example, certain Google Firebase, Stripe, and Netlify infrastructure operates in the United States or other regions).

5.4   Foreign-access caveat. When personal information is stored or processed outside your home jurisdiction, it may be subject to access by foreign courts, law-enforcement, or governmental authorities under the laws of those countries. We take reasonable steps to limit and protect against such access, but we cannot exclude it entirely.

6. Data Retention

6.1   We retain personal information only for as long as necessary for the purposes set out in this Policy. Our standard retention schedule is set out below. Where a longer period is required by law (for example, tax or limitation-period requirements), we retain the data for that longer period.

Data typeRetention periodTrigger / basis
Account & profile dataLife of account + 24 months after closure, then deleted or anonymisedProvide Service; reactivation; dispute window
Company & bid-profile dataLife of account + 24 months after closureService delivery; matching history
Billing & transaction records7 years from the transactionTax, accounting & audit obligations
Usage & security logs12 monthsSecurity, fraud prevention, analytics
Support communications24 months from last contactService quality & dispute handling
Marketing-consent recordsUntil consent withdrawn + 24 months (proof of consent)CASL / GDPR consent evidence
Cookie / analytics identifiersPer cookie lifetime (see Section 9), max 13 monthsConsent & analytics

6.2   Public procurement data sourced from TED, Find a Tender, CanadaBuys, and similar portals is retained as part of the Service’s reference dataset and refreshed periodically; it is not retained against an individual user. [confirm final periods with counsel]

7. How We Protect Information

7.1   We apply technical and organisational measures appropriate to the risk, including: encryption in transit (HTTPS/TLS), hashed and salted passwords, role-based access controls, restriction of payment-card handling to Stripe (PCI-DSS compliant), hosting on a reputable provider (Netlify), and least-privilege access to systems. SAFE Defence customers may be subject to additional controls described in their agreement.

7.2   No system is perfectly secure. While we take reasonable steps to protect personal information, we cannot guarantee absolute security.

7.3   Breach-notification procedure. If we become aware of a personal-data breach (a “breach of security safeguards” under PIPEDA), we will: (a) contain and assess the breach without undue delay; (b) where the breach is likely to result in a risk to affected individuals, notify the competent supervisory authority (under GDPR/UK GDPR, without undue delay and, where feasible, within 72 hours of becoming aware (Art. 33)); under PIPEDA, the Office of the Privacy Commissioner of Canada as soon as feasible where there is a real risk of significant harm; (c) notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms (GDPR/UK GDPR Art. 34) or a real risk of significant harm (PIPEDA), describing the breach, likely consequences, and steps we and they can take; and (d) keep records of breaches as required by law. Where applicable, we will also notify Quebec’s CAI under Law 25.

8. Your Rights

8.1   Subject to applicable law, you may exercise the following rights regarding your personal information:

8.2   How to exercise your rights. Contact our privacy contact at privacy@canprocx.ca (or ai.help@canprocx.ca). We will respond within the timeframes required by law (generally within one month under GDPR/UK GDPR (extendable by two further months for complex requests, with notice)) and within 30 days under PIPEDA (subject to permitted extensions). We provide our response free of charge in most cases. We may need to verify your identity before acting on a request, and we will tell you if we cannot fully comply and why.

9. Cookies & Similar Technologies

9.1   We use cookies and similar technologies to operate the Service, remember preferences, maintain secure sessions, and (where enabled) measure usage. Categories include strictly necessary cookies (always active), and, where applicable, analytics cookies.

9.2   For visitors in the EU/EEA and UK, non-essential cookies are set only with your consent via our cookie banner, consistent with the ePrivacy Directive and UK PECR. You can manage or withdraw cookie consent at any time through the cookie-preferences control on the site or your browser settings. We do not use cookies for cross-context behavioural advertising. [confirm cookie-preferences control & whether a separate Cookie Notice is published]

10. Children’s Privacy

10.1   CanProcX is a business-to-business service intended for use by professionals. It is not directed to children, and we do not knowingly collect personal information from individuals under the age of 16 (or the applicable age of digital consent). If you believe a child has provided us information, please contact privacy@canprocx.ca and we will delete it.

11. Changes to This Policy

11.1   We may update this Policy from time to time. The “Effective” date and version shown above indicate when it was last revised. For material changes, we will provide reasonable advance notice (for example, by email to your account address or a prominent in-product notice) at least 14 days before the change takes effect, and, where the change requires it, we will seek your fresh consent. Other changes take effect when posted. We keep prior versions available on request.

12. How to Complain

12.1   If you have a concern about how we handle your personal information, please contact us first at privacy@canprocx.ca so we can try to resolve it.

12.2   You also have the right to lodge a complaint with a supervisory authority:

12.3   This Policy is governed by the laws of [confirm: Ontario, Canada], without prejudice to mandatory data-protection rights you may have under GDPR or other applicable law.