Legal
Privacy Policy
Last updated: July 19, 2026
This Privacy Policy explains how Laurier AI [insert full legal name if different] ("Laurier AI," "we," "us," or "our") collects, uses, discloses, and safeguards personal information when you visit our website, communicate with us, request or receive a proposal, or use services that we design, build, configure, integrate, host, support, or manage (collectively, the "Services").
Our Services may include AI and automation consulting, workflow automation, AI agents, customer-support systems, voice agents, sales and lead-handling systems, document processing, reporting and knowledge systems, websites, internal tools, system integrations, and other custom AI or software solutions.
Please read this Privacy Policy in full. The following points provide a short overview:
- We collect information needed to understand your needs, deliver and support the Services, secure our systems, communicate with you, and meet our legal obligations.
- Many of our Services connect to tools selected or used by our business customers. Data may move between Laurier AI, the customer, those connected tools, and approved service providers as necessary to operate the solution.
- When we process personal information for a business customer, we generally act as that customer's service provider or processor. The customer remains responsible for its own notices, permissions, lawful instructions, and use of the solution.
- We do not sell personal information for money. Certain advertising or analytics activities may be considered a "sale," "sharing," or targeted advertising under some privacy laws. Available choices are described in Your Privacy Choices.
- We do not use Customer Data to train general-purpose AI models for our own benefit unless the customer expressly agrees in writing. Third-party AI providers process data under their own agreements and configured data terms.
- AI output can be inaccurate or incomplete. Customers should use appropriate human review, especially before decisions or actions that may significantly affect a person.
- To ask a question or exercise an available privacy right, contact us using the information in Section 15.
1. SCOPE AND OUR ROLE
This Privacy Policy applies to personal information that Laurier AI controls in connection with our website, sales process, business operations, and Services.
It does not replace the privacy policy of a business customer whose data we process. If you interact with an AI agent, voice agent, workflow, website, form, or other system that we operate for one of our customers, that customer normally decides why and how your personal information is used. Please direct requests to that customer first. We will assist the customer as required by our agreement and applicable law.
A proposal, statement of work, order form, services agreement, data processing addendum, or other written agreement may include additional privacy and security terms. If those terms conflict with this Privacy Policy, the signed agreement controls for the relevant Services.
2. INFORMATION WE COLLECT
We may collect the following categories of information.
2.1 Information you provide to us
Contact and business information. Your name, business name, job title, email address, telephone number, mailing address, and other details you provide when you contact us, submit a form, book a meeting, or request a proposal.
Account and authentication information. Usernames, account identifiers, permissions, and authentication information used to provide access to a system. We may receive security tokens or credentials needed to connect approved tools. We seek to store credentials using appropriate secure methods and use them only to provide the Services.
Project and configuration information. Business requirements, workflows, process descriptions, policies, knowledge materials, system settings, integration details, test data, and instructions provided to design, configure, test, operate, or support a solution.
Customer Data. Information, documents, records, messages, prompts, files, images, audio, transcripts, database entries, contact records, customer-service conversations, lead information, and other content submitted by or on behalf of a customer or processed through a customer solution.
Communications. Emails, meeting notes, support requests, survey responses, feedback, and other communications with us.
Call and voice information. If a voice feature is used, the system may process audio, call metadata, transcriptions, summaries, and actions taken during or after the call. Where calls are recorded, the business deploying the system must provide any notice and obtain any consent required by law. Recording and retention settings may differ by project.
Billing information. Billing contacts, invoices, transaction records, tax information, and related payment details. Payment card information is normally processed directly by a payment provider and is not stored by Laurier AI unless expressly stated.
2.2 Information collected automatically
Device and technical information. Internet Protocol address, browser type, device type, operating system, referring pages, language, approximate location derived from IP address, and similar technical information.
Website and service usage information. Pages viewed, links clicked, session dates and times, form interactions, feature use, error reports, automation events, audit logs, and performance information.
Cookies and similar technologies. We and our providers may use cookies, pixels, local storage, tags, and similar technologies for essential functionality, security, preferences, analytics, and, where enabled, advertising measurement. See Section 6 and Your Privacy Choices.
2.3 Information from customers, integrations, and third parties
We may receive information from:
- customers that authorize us to process information on their behalf;
- connected tools such as customer relationship management systems, calendars, email platforms, phone systems, help desks, document stores, databases, accounting tools, analytics systems, and other business applications;
- AI, cloud, hosting, communications, automation, security, and software providers used to deliver the Services;
- referral partners, public business sources, social networks, and other parties that direct you to us; and
- public sources where collection and use are permitted by law.
2.4 Sensitive information
Unless Laurier AI has expressly agreed in writing and appropriate safeguards have been configured, you must not provide highly sensitive personal information, including payment card numbers, bank account credentials, government identifiers, biometric templates, precise health records, or other information requiring enhanced protection.
Healthcare and other regulated customers must not allow a solution to process personal health information or similarly regulated data until the parties have completed appropriate privacy, security, and contractual review. A project involving such data may require a data processing addendum, additional access controls, approved providers, specific retention settings, and other safeguards.
3. HOW WE USE INFORMATION
We may use personal information to:
- respond to inquiries, assess business needs, prepare proposals, and manage our relationship with you;
- design, build, configure, test, deploy, host, operate, monitor, maintain, and improve the Services;
- connect approved systems and allow information and actions to move between them;
- generate responses, summaries, classifications, reports, recommendations, documents, tasks, appointments, notifications, and other outputs requested through the Services;
- provide support, troubleshoot errors, investigate incidents, and maintain service continuity;
- authenticate users, manage permissions, prevent misuse, and protect the security and integrity of our website, systems, customers, and Services;
- process payments, administer accounts, maintain business records, and enforce agreements;
- send service messages and, where permitted, marketing communications;
- understand website and Service performance and improve usability and reliability;
- create de-identified or aggregated information that is not reasonably capable of identifying an individual;
- comply with law, respond to lawful requests, establish or defend legal claims, and protect rights, safety, and property; and
- carry out other purposes disclosed when information is collected or with consent.
Where applicable law requires a legal basis, we rely on one or more of the following: performance of a contract, consent, compliance with legal obligations, and our legitimate interests or those of a customer, provided those interests are not overridden by applicable privacy rights.
4. AI AND AUTOMATION-SPECIFIC PROCESSING
Our Services may use machine learning models, generative AI, rules-based automation, APIs, and connected software. Depending on the project, information submitted to a solution may be transmitted to one or more providers to generate an output or complete an authorized action.
We select and configure providers based on project needs, customer instructions, availability, security, privacy, capability, and cost. Providers may change over time. Customers may request information about material providers used for their project, subject to confidentiality and security limitations.
Laurier AI does not use Customer Data to train general-purpose AI models for our own benefit unless the customer expressly authorizes that use in writing. We seek to use business or enterprise provider settings that limit provider training where appropriate and commercially available. A customer's own provider account, selected model, or requested configuration may be governed by different terms.
AI and automated systems may produce inaccurate, incomplete, biased, outdated, or unexpected results. They may also take incorrect actions if instructions, source data, integrations, or system conditions are incomplete or wrong. We may maintain logs, test records, evaluations, and human-review steps to improve reliability and investigate problems.
Unless expressly agreed in writing following appropriate review, our Services are not designed to make solely automated decisions that create legal effects or similarly significant effects concerning an individual. Customers are responsible for deciding where human approval, escalation, review, or an alternative non-automated process is required.
5. HOW AND WHY WE DISCLOSE INFORMATION
We may disclose personal information to the following categories of recipients.
Service providers and subprocessors. Providers that support hosting, cloud infrastructure, AI models, automation, databases, communications, telephony, email delivery, analytics, security, identity, payments, project management, and professional services. They may process information only for permitted purposes and subject to applicable agreements.
Business customers and their authorized users. Information processed through a customer solution may be made available to the customer, its administrators, and people it authorizes. An administrator may be able to access conversations, records, reports, logs, and other content associated with the customer's solution.
Connected services. When a customer requests an integration, we disclose information to and receive information from the connected service as necessary to perform the requested workflow. The connected service's own terms and privacy practices also apply.
Professional advisers. Lawyers, accountants, insurers, auditors, and other advisers where reasonably necessary to operate our business, protect our interests, or comply with law.
Authorities and legal recipients. Courts, regulators, law enforcement, government agencies, and other parties where disclosure is required or permitted by law or reasonably necessary to prevent fraud, address security issues, protect rights and safety, or establish, exercise, or defend legal claims.
Business transfers. A buyer, investor, lender, adviser, or successor in connection with an actual or proposed financing, merger, acquisition, reorganization, sale of assets, insolvency, or similar transaction, subject to appropriate protections.
At your direction or with consent. Other recipients when you or the relevant customer directs us to disclose information or provides consent.
We do not sell personal information for money. Some disclosures involving advertising cookies or similar tools may be defined as "selling," "sharing," or targeted advertising under certain laws. See Your Privacy Choices.
6. COOKIES, ANALYTICS, AND ADVERTISING
We may use the following categories of cookies and similar technologies:
Strictly necessary. Required for core website functions, security, network management, fraud prevention, accessibility, and saving privacy choices. These technologies cannot always be disabled through our website.
Functional. Remember choices and provide enhanced features.
Analytics. Help us understand website traffic, interactions, and performance.
Advertising and measurement. Measure campaigns, limit repeated ads, create audiences, or support advertising on other services, where enabled.
Available controls may include a cookie banner, a settings panel, browser controls, an advertising opt-out, and Global Privacy Control. Blocking cookies through your browser may affect website functionality. See Your Privacy Choices for more information.
7. COMMUNICATIONS AND MARKETING
We may send operational messages about proposals, projects, security, support, invoices, and changes to the Services. These messages are part of our business relationship and may not offer an unsubscribe option where they are not marketing.
We send marketing emails, texts, or similar electronic messages only as permitted by applicable law. You may unsubscribe using the method included in a message or by contacting us. We may keep limited information on a suppression list so that we can respect your choice.
8. INTERNATIONAL AND CROSS-BORDER PROCESSING
Laurier AI is based in Canada, but we and our service providers may process or store information in Canada, the United States, and other countries. Privacy and data-access laws in those locations may differ from those in your jurisdiction, and courts, law enforcement, or national-security authorities may be able to access information as permitted by local law.
Where required, we use contractual and other measures intended to provide an appropriate or comparable level of protection for information transferred to a service provider or another country.
9. DATA RETENTION
We retain personal information only for as long as reasonably necessary for the purposes described in this Privacy Policy, including to deliver and support the Services, maintain business and security records, comply with legal obligations, resolve disputes, and enforce agreements.
Retention depends on the type of information, the project configuration, customer instructions, legal requirements, risk, and the capabilities of connected providers. Customer Data may be subject to a project-specific retention schedule. Backup copies and security logs may remain for a limited period after deletion from active systems.
When information is no longer required, we delete it, de-identify it, or securely isolate it until deletion is reasonably possible, subject to legal and technical limitations.
10. SECURITY
We use reasonable administrative, technical, and organizational safeguards designed to protect personal information against loss, theft, misuse, and unauthorized access, use, alteration, or disclosure. Safeguards may include access controls, least-privilege permissions, encryption, credential-management practices, logging, monitoring, backups, vendor review, and incident-response procedures, as appropriate to the Services.
No system or transmission method is completely secure. Customers are responsible for securing their own accounts, devices, networks, permissions, source data, and connected services, and for promptly reporting suspected unauthorized access.
11. YOUR PRIVACY RIGHTS AND CHOICES
Depending on where you live and subject to exceptions, you may have the right to:
- request access to or information about personal information we hold about you;
- request correction of inaccurate or incomplete information;
- request deletion or erasure;
- receive a portable copy of certain information;
- withdraw consent where processing is based on consent;
- object to or request restriction of certain processing;
- opt out of certain targeted advertising, sale, sharing, profiling, or marketing activities;
- ask about the use of service providers outside Canada;
- appeal a decision on a privacy request where applicable; and
- make a complaint to the applicable privacy or data-protection regulator.
See Your Privacy Choices for available website and communication controls. You may also submit a request using the contact information in Section 15.
We may need to verify your identity and authority before completing a request. We will not discriminate against you for exercising a right provided by law. Rights are not absolute, and we may retain or refuse to disclose information where permitted or required by law. If Laurier AI processes the information only for a business customer, we may direct your request to that customer.
Authorized agents may submit requests where permitted by law. We may ask for proof of authorization and may need to verify your identity directly.
12. CHILDREN'S INFORMATION
Our website and Services are intended for businesses and are not directed to children under 16. We do not knowingly collect personal information directly from children under 16 through our website. If you believe a child has provided personal information to us without appropriate authorization, please contact us.
A customer must not use a Laurier AI solution to collect or process children's information unless the use has been expressly reviewed and authorized in writing and the customer has implemented all notices, consents, age controls, and safeguards required by law.
13. THIRD-PARTY SERVICES AND LINKS
Our website and Services may link to or integrate with services that Laurier AI does not control. Their privacy policies and terms govern their handling of information. We encourage you and our customers to review those policies before enabling an integration or providing information.
14. CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy to reflect changes to our practices, Services, providers, or legal obligations. We will post the updated version and change the "Last updated" date. Where required, we will provide additional notice or obtain consent for material changes.
15. CONTACT US
Questions, concerns, complaints, and privacy requests may be sent to:
Privacy Officer
Laurier AI [insert full legal name if different]
Email: [insert monitored privacy email]
Mailing address: [insert business mailing address]
If we do not resolve your concern, you may have the right to contact the Office of the Privacy Commissioner of Canada or another privacy or data-protection authority with jurisdiction over the matter.