Privacy · Transparency
Privacy Statement
This statement covers maplespire.ca, its contact form, and the app.maplespire.ca demo. MapleSpire does not sell personal information and currently uses no advertising, behavioural analytics, or profiling.
The demo is not intended for sensitive or confidential information. Offline browser storage may keep data on your device until you clear the site’s data.
1. Accountable person and scope
Olivier Albertini, individual operator of MapleSpire, Québec, Canada is accountable for personal information under his control. The published role of the Privacy Officer is “Privacy Officer.” Contact: support@maplespire.ca.
This Statement covers the landing site, contact form, demo, accounts, architecture workspaces, collaboration, share links, support, and transactional email.
2. Information and purposes
- Account: email, name or alias, language, identity-provider identifier, and organization membership—to create, authenticate, authorize, and personalize the account.
- Local account: irreversibly hashed password, email-verification status, and hashed verification tokens—to secure sign-in.
- Service content: diagrams, objects, relationships, comments, decisions, files, permissions, invitations, and collaboration history—to save, synchronize, share, and display work.
- Contact and support: name, email, optional organization, subject, message, consent, and correspondence—to respond, send a receipt, and resolve the request.
- Technical information: IP address, time, requested route, security events, errors, device or browser type, and session identifiers—to deliver, secure, diagnose, and prevent abuse.
- Optional AI configuration: provider, model, service address, and encrypted API key; selected prompts and context are sent to the configured provider only when an AI feature is used.
3. Sources and consent
We collect information from you, your organization, your browser, or the identity provider you choose. Processing needed for account creation, security, synchronization, and support is integral to the requested Service. Optional future uses will have a separate choice where required.
An email address and authentication data are required for an account; without them, sign-in is unavailable. In the contact form, name, email, subject, message, and the processing confirmation are required to receive a response; organization is optional. Architecture content is voluntary, but features cannot operate without the content you choose to create or share.
You may withdraw optional consent, subject to legal limits and consequences explained at withdrawal. Withdrawing processing essential to the Service may require closing the account.
4. Cookies and device storage
The landing site stores only language and theme preferences in local storage. The demo uses an essential HTTP-only session cookie, normally lasting no more than 30 days, and a 10-minute essential OIDC cookie during external sign-in. Offline features use IndexedDB and local storage for models, caches, language, theme, and preferences on your device.
These are necessary for the requested service or an explicit preference, not advertising or profiling. We therefore do not currently show an advertising consent banner. If we add analytics, behavioural measurement, or other non-essential technology, it will be off by default until valid, revocable consent.
5. Communications
We send messages necessary for an account or request: email verification, invitations, security, support, and receipts. Users are not automatically subscribed to promotions. Any optional newsletter or commercial message will have separate consent and an unsubscribe method.
6. Providers and disclosures
Access is limited to people and providers that need it to provide or protect the Service. Current categories include Cloudflare (DNS, network, tunnel, security), Amazon Web Services (CloudFront, contact handling, queue, SES), Microsoft Entra ID or Google when chosen for sign-in, email providers, and an AI provider selected by your organization.
We may also disclose information when law requires, to protect rights and safety, investigate fraud or an incident, or during a reorganization with appropriate safeguards. We do not sell or rent personal information.
7. Processing location and transfers
Core demo data is currently operated on infrastructure controlled by the operator in Canada. Cloudflare, AWS, Microsoft, Google, or a chosen AI provider may process some information in Québec, elsewhere in Canada, the United States, or other countries where they operate. Local law may permit government access.
Before a new transfer outside Québec, we assess privacy factors and use contractual commitments and safeguards proportionate to risk.
8. Retention and destruction
- Account and content: while the account is used, then until closure, a demo reset, or completion of a valid request, subject to legal and security needs.
- Verification tokens: valid for 24 hours; raw values are not stored and expired records are removed during maintenance.
- Session: the normal cookie expires within 30 days; the OIDC cookie within 10 minutes or on return.
- Contact and support correspondence: during handling and generally no more than 24 months after the last exchange, unless needed for a dispute or law.
- Ordinary technical logs are bounded and rotated; security events, acceptance evidence, incidents, and audit trails may be retained longer where needed for security, accountability, or law.
- Offline storage: until you clear site data in your browser or delete synchronized content.
9. Security and incidents
Safeguards appropriate to a demo include encryption in transit, HTTP-only cookies, password hashing, AI-key encryption, access controls, rate limits, and audit records. No safeguard offers absolute security.
We maintain an incident register and assess risk. We notify regulators and affected people where required. Report a suspected incident promptly to support@maplespire.ca.
10. Your rights
Depending on applicable law, you may ask what information is held and how it is used, access or correct it, withdraw optional consent, obtain portability of eligible information, or request deletion. You may also ask about retention and who can access it.
Email support@maplespire.ca with your name, account email, the request, and relevant facts. We handle requests and complaints confidentially and may verify identity. We respond within legal time limits—normally the 30 days provided in Québec—or explain a permitted refusal. You may complain to the Privacy Officer, Québec’s Commission d’accès à l’information, or the Office of the Privacy Commissioner of Canada.
11. Minors, automated decisions, and profiling
The Service is for people 18 or older and we do not knowingly seek minors’ information. Contact us if you believe a minor created an account.
MapleSpire currently collects no precise geolocation, makes no decision with legal or similarly important effects solely by automated processing, and performs no advertising profiling. AI suggestions, if enabled, remain tools that users must review.
12. Changes and questions
We post the update date. If a material change introduces a new purpose, disclosure, or risk, we provide prominent notice and obtain new consent where required.
Questions, requests, or complaints: Privacy Officer, support@maplespire.ca.