Netrasya AI Inc. (“Netrasya”, “we”, “us”)
Kitchener, Ontario, Canada
This policy explains what information we handle, why, where it is stored, and the choices you have. It covers two things: our public website at netrasyaai.ca, and the Netrasya Lens application we provide to client firms and their authorized users.
Netrasya Lens is a business-to-business service. Two relationships matter:
If you are an individual whose personal information appears inside a client firm’s documents, please direct access or deletion requests to that firm; we will assist the firm in responding.
The marketing site is static. We do not set advertising or analytics cookies and we do not run third-party trackers. Standard server and access logs (for example IP address, browser type, pages requested, timestamp) may be generated by our hosting provider for security and reliability. Web fonts are served from our own origin, so no font provider receives your IP address.
To create and secure an account we process:
We use passwordless sign-in: we email you a one-time code rather than storing a password.
On your firm’s instructions we process:
This content, and any personal information it happens to contain, is processed only to provide search, retrieval, and cited answers to your firm’s authorized users.
To run, secure, bill, and improve the service we record usage events — for example which actions occurred (sign-in, ingest, query), document and chunk counts, processing latency per stage, and token counts for billing. We also keep application and infrastructure logs and metrics. We do not build advertising profiles from this data.
We rely on your firm’s instructions and our agreement with the firm, on consent (for example when you request a sign-in code), and on our legitimate business interests in operating a secure, reliable service, as permitted under Canadian privacy law.
Netrasya Lens answers questions using a language model we host ourselves on our own infrastructure in Canada. Your documents and questions:
Application data is stored and processed in Canada, in Amazon Web Services’ Canada (Central) region (ca-central-1). This includes documents, search indexes, account data, email delivery, and logs.
Our infrastructure provider, Amazon Web Services, is a global company. While we configure the service to keep your data in the Canadian region, AWS as an organization may be subject to laws of other jurisdictions. We therefore describe our commitment as “stored and processed in Canada” — we do not claim your data can never, under any legal process, leave Canada.
The public marketing website is served by a hosting and CDN provider (see sub-processors) that operates globally; it handles no customer documents or account data, only ordinary web traffic.
We use a small number of providers to deliver the service. Each is bound to protect the information it handles and to use it only to provide services to us.
| Provider | Role | Data involved | Location |
|---|---|---|---|
| Amazon Web Services | Compute, document storage, database, email delivery (SES), logging | All application data: documents, indexes, account data, sign-in emails, logs | Canada (Central) |
| Netlify | Hosting and CDN for the public marketing website only | Website request logs (e.g. IP, browser) | Global edge · US-based |
| Porkbun | Domain registration, DNS, and business email | Domain records; email sent to our business inbox | US-based |
We will update this list before adding a sub-processor that handles customer content, as required by your firm’s agreement.
We do not sell personal information and we do not share it for advertising. We disclose information only:
We protect information with measures including encryption in transit; access restricted to a small team on a need-to-know basis; permission-aware retrieval so users only see documents their firm has granted them; passwordless authentication with revocable sessions; parameterized database access; and segregation of customer environments. No system is perfectly secure, but we work to protect your data and to limit and respond to any incident. We will notify affected firms of a security breach involving their data as required by law.
Where your firm’s agreement with us sets different or shorter periods, that agreement governs.
Under Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial law, you may:
To exercise these rights, contact us using the details below. For information held inside a client firm’s documents, we will route your request to that firm, who controls it. We respond to verified requests within the timelines required by law.
The marketing website uses no advertising or analytics cookies and no third-party trackers.
The application uses your browser’s local storage strictly to operate: it stores your sign-in token so you stay logged in, and a small flag noting when a session has expired. These are necessary for the service to function and are not used for tracking or advertising. Clearing them signs you out.
Netrasya Lens is a workplace tool intended for businesses and their staff. It is not directed to children and we do not knowingly collect information from children.
We may update this policy as the service evolves. We will revise the “last updated” date and, for material changes affecting client firms, provide notice as required by the applicable agreement.
Email: privacy@netrasyaai.ca
Fallback: info@netrasyaai.ca
Kitchener, Ontario, Canada
You may also contact the Office of the Privacy Commissioner of Canada at www.priv.gc.ca.