01Who we are
SynapTIQ Inc. (“AvisPilot”, “we”, “our”) is the controller of the personal data collected through the AvisPilot service.
Controller's contact details:
SynapTIQ Inc. — NEQ 1180925183
7777 Avenue du Château-de-Chambord, Québec (Québec) G1H 4G9, Canada
Email: contact@synaptic-inc.ca
In accordance with Law 25, SynapTIQ Inc. has appointed a person responsible for the protection of personal information, reachable at the same email address for any request about your data.
02What data do we collect?
We collect only the data necessary to operate the service, in 4 categories:
2.1 Account data
Last name, first name, email address, password (stored as a bcrypt hash — never in clear text), role (owner, administrator, editor), phone number (optional).
2.2 Organization and location data
Legal name, industry, postal address, website, phone, logo, time zone, language. For each attached location: name, category, city, address, connected platforms.
2.3 Review and reply data
Customer reviews imported from the connected platforms (Google Business Profile, and others to come): author, rating, content, publication date, source. Replies written by users or generated by our AI assistance, drafts, internal notes.
2.4 Technical and billing data
Encrypted OAuth credentials (AES-256-GCM) for the connected platforms, Stripe customer identifier, subscription status, period dates, payment methods (handled directly by Stripe — we never store a card number). Minimal technical logs (sign-in date, aggregated browser) for security.
03Why do we collect it?
| Purpose | Legal basis (GDPR) | Data categories |
|---|---|---|
| Creating and managing your account | Performance of the contract (art. 6.1.b) | Account |
| Providing the service (review sync, AI reply generation) | Performance of the contract (art. 6.1.b) | Org, reviews, replies, technical |
| Billing and subscription management | Performance of the contract + legal obligation (art. 6.1.b and c) | Billing |
| Sending transactional emails (welcome, review alerts, reports) | Performance of the contract (art. 6.1.b) | Account |
| Service security, fraud prevention, logging | Legitimate interest (art. 6.1.f) | Technical |
| Service improvement (anonymised aggregated statistics) | Legitimate interest (art. 6.1.f) | Aggregated technical |
04How long do we keep your data?
We apply a retention policy proportionate to each purpose:
- Account and organization data: for the whole duration of your subscription, then 30 days after cancellation (cooling-off period and possible recovery), before permanent deletion.
- Reviews and replies: for the duration of the subscription + 30 days, then deleted. The Excel and PDF exports you have downloaded remain in your possession.
- Billing data: kept for 10 years after the last transaction, in accordance with the accounting and tax obligations applicable in Canada and in France.
- Technical security logs: 12 months maximum.
- Platform OAuth tokens: revoked automatically when a location is disconnected or the account is cancelled.
05Who do we share your data with?
We never sell your data. We use carefully selected processors, bound by contract (GDPR standard contractual clauses), solely for the purposes above.
| Processor | Role | Location |
|---|---|---|
| Stripe | Payment and subscription processing | Ireland (EU) / United States |
| Brevo (formerly Sendinblue) | Sending transactional emails | France / European Union |
| Anthropic | Claude AI model for reply generation | United States |
| Google (Business Profile API) | Syncing Google reviews and publishing replies | United States / Ireland |
06International transfers
As a Canadian company processing the data of European users, we carry out framed international transfers:
- Canada benefits from a partial adequacy decision from the European Commission for organisations subject to PIPEDA, which is our case.
- Transfers to the United States(Stripe, Anthropic, Google) are framed by the European Commission's Standard Contractual Clauses or by the EU-US Data Privacy Framework where the processor is certified under it.
08Your rights
In accordance with the GDPR, Law 25 and PIPEDA, you have the following rights over your personal data:
- Right of access: obtain confirmation that data concerning you is processed, and receive a copy of it.
- Right to rectification: correct inaccurate or incomplete data.
- Right to erasure (“right to be forgotten”): request the deletion of your data, subject to legal retention obligations.
- Right to restriction: temporarily suspend processing.
- Right to portability: receive your data in a structured, machine-readable format (CSV/JSON) or have it transferred to another service.
- Right to object: object to processing based on legitimate interest.
- Right to withdraw your consent at any time, where consent is the legal basis for the processing.
- Right to de-indexing (Law 25, s. 113): have the dissemination of publicly accessible personal information stopped.
- Post-mortem instructions (French GDPR / Law 25): arrange what happens to your data after your death.
To exercise one of these rights, write to contact@synaptic-inc.ca stating the right invoked and your identity. We reply within a maximum of 30 days (GDPR) or 30 business days (Law 25).
If you believe your rights are not respected, you may lodge a complaint with:
- EU: your data protection authority (CNIL in France: cnil.fr).
- Québec: Commission d'accès à l'information (CAI) — cai.gouv.qc.ca.
- Canada (federal): Office of the Privacy Commissioner — priv.gc.ca.
09Security
We apply technical and organisational measures to protect your data:
- Encryption of communications (HTTPS / TLS 1.3).
- Encryption at rest of sensitive OAuth tokens (AES-256-GCM).
- Passwords stored with bcrypt and a unique salt per user.
- Multi-factor authentication available through Google OAuth.
- Database access restricted to authorised staff and logged.
- Regular encrypted backups.
In the event of a data breach likely to result in a high risk to your rights, we will inform you within 72 hours of becoming aware of it, in accordance with article 33 of the GDPR.
10Changes to this policy
We may amend this policy to reflect changes to the service, or legal or regulatory changes. Any material change will be notified to you by email at least 30 days before it takes effect. The date of the last update is shown at the top of this page.
11Contact
For any question about this policy or about your personal data:
contact@synaptic-inc.ca
or through our contact form.