Privacy policy

This policy explains what personal data AvisPilot collects, why, how long it is kept and what rights you have to control it. It complies with the GDPR (EU), Québec's Law 25 and Canada's federal PIPEDA.

Last updated25 mai 2026
Contents · 11 sections
  1. 01Who we are
  2. 02What data do we collect?
  3. 03Why do we collect it?
  4. 04Retention periods
  5. 05Who do we share it with?
  6. 06International transfers
  7. 07Cookies
  8. 08Your rights
  9. 09Security
  10. 10Changes to this policy
  11. 11Contact

01Who we are

SynapTIQ Inc. (“AvisPilot”, “we”, “our”) is the controller of the personal data collected through the AvisPilot service.

Controller's contact details:
SynapTIQ Inc. — NEQ 1180925183
7777 Avenue du Château-de-Chambord, Québec (Québec) G1H 4G9, Canada
Email: contact@synaptic-inc.ca

In accordance with Law 25, SynapTIQ Inc. has appointed a person responsible for the protection of personal information, reachable at the same email address for any request about your data.

02What data do we collect?

We collect only the data necessary to operate the service, in 4 categories:

2.1 Account data

Last name, first name, email address, password (stored as a bcrypt hash — never in clear text), role (owner, administrator, editor), phone number (optional).

2.2 Organization and location data

Legal name, industry, postal address, website, phone, logo, time zone, language. For each attached location: name, category, city, address, connected platforms.

2.3 Review and reply data

Customer reviews imported from the connected platforms (Google Business Profile, and others to come): author, rating, content, publication date, source. Replies written by users or generated by our AI assistance, drafts, internal notes.

2.4 Technical and billing data

Encrypted OAuth credentials (AES-256-GCM) for the connected platforms, Stripe customer identifier, subscription status, period dates, payment methods (handled directly by Stripe — we never store a card number). Minimal technical logs (sign-in date, aggregated browser) for security.

03Why do we collect it?

PurposeLegal basis (GDPR)Data categories
Creating and managing your accountPerformance of the contract (art. 6.1.b)Account
Providing the service (review sync, AI reply generation)Performance of the contract (art. 6.1.b)Org, reviews, replies, technical
Billing and subscription managementPerformance of the contract + legal obligation (art. 6.1.b and c)Billing
Sending transactional emails (welcome, review alerts, reports)Performance of the contract (art. 6.1.b)Account
Service security, fraud prevention, loggingLegitimate interest (art. 6.1.f)Technical
Service improvement (anonymised aggregated statistics)Legitimate interest (art. 6.1.f)Aggregated technical

04How long do we keep your data?

We apply a retention policy proportionate to each purpose:

  • Account and organization data: for the whole duration of your subscription, then 30 days after cancellation (cooling-off period and possible recovery), before permanent deletion.
  • Reviews and replies: for the duration of the subscription + 30 days, then deleted. The Excel and PDF exports you have downloaded remain in your possession.
  • Billing data: kept for 10 years after the last transaction, in accordance with the accounting and tax obligations applicable in Canada and in France.
  • Technical security logs: 12 months maximum.
  • Platform OAuth tokens: revoked automatically when a location is disconnected or the account is cancelled.

05Who do we share your data with?

We never sell your data. We use carefully selected processors, bound by contract (GDPR standard contractual clauses), solely for the purposes above.

ProcessorRoleLocation
StripePayment and subscription processingIreland (EU) / United States
Brevo (formerly Sendinblue)Sending transactional emailsFrance / European Union
AnthropicClaude AI model for reply generationUnited States
Google (Business Profile API)Syncing Google reviews and publishing repliesUnited States / Ireland

06International transfers

As a Canadian company processing the data of European users, we carry out framed international transfers:

  • Canada benefits from a partial adequacy decision from the European Commission for organisations subject to PIPEDA, which is our case.
  • Transfers to the United States(Stripe, Anthropic, Google) are framed by the European Commission's Standard Contractual Clauses or by the EU-US Data Privacy Framework where the processor is certified under it.

07Cookies

AvisPilot uses only cookies strictly necessary to the technical operation of the service:

  • Authentication session cookie (NextAuth.js) — maximum duration 30 days.
  • Language preference cookie (next-intl) — duration 1 year.

These cookies are exempt from prior consent (CNIL FR, Law 25 QC) as they are essential to the service. No third-party analytics, advertising or marketing tracking cookie is placed.

08Your rights

In accordance with the GDPR, Law 25 and PIPEDA, you have the following rights over your personal data:

  • Right of access: obtain confirmation that data concerning you is processed, and receive a copy of it.
  • Right to rectification: correct inaccurate or incomplete data.
  • Right to erasure (“right to be forgotten”): request the deletion of your data, subject to legal retention obligations.
  • Right to restriction: temporarily suspend processing.
  • Right to portability: receive your data in a structured, machine-readable format (CSV/JSON) or have it transferred to another service.
  • Right to object: object to processing based on legitimate interest.
  • Right to withdraw your consent at any time, where consent is the legal basis for the processing.
  • Right to de-indexing (Law 25, s. 113): have the dissemination of publicly accessible personal information stopped.
  • Post-mortem instructions (French GDPR / Law 25): arrange what happens to your data after your death.

To exercise one of these rights, write to contact@synaptic-inc.ca stating the right invoked and your identity. We reply within a maximum of 30 days (GDPR) or 30 business days (Law 25).

If you believe your rights are not respected, you may lodge a complaint with:

  • EU: your data protection authority (CNIL in France: cnil.fr).
  • Québec: Commission d'accès à l'information (CAI) — cai.gouv.qc.ca.
  • Canada (federal): Office of the Privacy Commissioner — priv.gc.ca.

09Security

We apply technical and organisational measures to protect your data:

  • Encryption of communications (HTTPS / TLS 1.3).
  • Encryption at rest of sensitive OAuth tokens (AES-256-GCM).
  • Passwords stored with bcrypt and a unique salt per user.
  • Multi-factor authentication available through Google OAuth.
  • Database access restricted to authorised staff and logged.
  • Regular encrypted backups.

In the event of a data breach likely to result in a high risk to your rights, we will inform you within 72 hours of becoming aware of it, in accordance with article 33 of the GDPR.

10Changes to this policy

We may amend this policy to reflect changes to the service, or legal or regulatory changes. Any material change will be notified to you by email at least 30 days before it takes effect. The date of the last update is shown at the top of this page.

11Contact

For any question about this policy or about your personal data:

contact@synaptic-inc.ca
or through our contact form.