Privacy Policy

SynapTIQ INC. · Last updated August 30, 2026

Last updated: August 30, 2026

Data controller: SynapTIQ INC., Quebec City (Quebec), Canada

SynapTIQ INC. designs and operates IT solutions for businesses, organizations and self-employed professionals, primarily in Quebec. This policy explains what personal data we collect, why we collect it, how long we keep it and what your rights are. It covers both the synaptic-inc.ca website and the business messaging services we operate on behalf of our clients.

1. Identity of the data controller

The controller of the personal data described in this policy is:

SynapTIQ INC.
7777 Avenue du Château de Chambord
Québec, QC, G1H 4G9
Canada

Any privacy-related question, as well as any request to exercise your rights, may be sent to the contact details above. We have not appointed an external data protection officer: requests are handled directly by SynapTIQ INC. management.


2. Data collected through the website

Contact form

The form on the Contact page collects the information you enter yourself:

  • Full name (required)
  • Email address (required)
  • Subject and message content (required)
  • Company name (optional)
  • Phone number (optional)

This information reaches us by email and is used solely to respond to your enquiry and to carry out the commercial follow-up arising from it. It is never sold, rented or disclosed for advertising purposes.

Browsing data

We measure website traffic using Umami, an analytics solution we host ourselves on our own infrastructure. Measurement data never leaves our servers and is never shared with any advertising network. The following is recorded:

  • The page visited and the referring page
  • Device type, browser and operating system
  • Approximate country of origin, derived from the IP address
  • Date and time of the visit

The full IP address is not retained: it is converted into a non-reversible anonymous identifier and then discarded. We therefore cannot link a visit to an identified individual.

Cookies

This website sets no advertising cookies and no cross-site tracking cookies. Our analytics tool operates without cookies. Only strictly technical cookies necessary for the website to function may be used, such as remembering your language preference. These cookies do not require prior consent and are not used for any profiling.


3. Data processed through our business messaging services

SynapTIQ INC. designs, deploys and operates business messaging solutions built on Meta's WhatsApp Business Platform on behalf of its business clients. In this capacity we act exclusively as a processor (service provider): the business client remains the data controller and determines the purposes and means of processing.

Categories of data processed

  • Phone numbers of individuals who communicate with our client through its messaging channel
  • Message content exchanged in the conversation: text, images, documents, audio files and other attachments
  • Account identifiers: WhatsApp Business account ID, sender phone number ID, and technical identifiers assigned by the platform
  • Conversation metadata: send and receive timestamps, delivery and read status, declared language, message template used, and conversation window status

Our commitments

With respect to this data, SynapTIQ INC. unreservedly undertakes to:

  • Process it solely for the purpose of providing the service ordered by the client
  • Act only on behalf of the client and on its documented instructions
  • Never sell, rent, transfer or monetize this data, in any form whatsoever
  • Not use it to train models, build advertising files or support any data brokerage activity
  • Not combine it with another client's data: each client environment is kept separate
  • Return or destroy this data at the end of the contract, as instructed by the client

If you have communicated with a business through a channel we operate and wish to exercise your rights over that data, please contact that business first, as it is the controller. We assist it in handling your request, and you may also write to us directly to be directed to the right party.


4. Legal bases, purposes and retention periods

ProcessingPurposeLegal basisRetention
Contact formRespond to the enquiry and follow up on itPre-contractual steps taken at the individual's request24 months after the last exchange
Client relationship and billingPerform the contract and meet our accounting obligationsPerformance of the contract and legal obligation7 years (Canadian tax obligations)
Website analyticsUnderstand traffic and improve the websiteLegitimate interest (cookieless measurement, no profiling)24 months, in aggregated form
Business messagingProvide the service ordered by the business clientProcessing agreement with the client acting as controllerAs instructed by the client, at most 12 months after the contract ends
Technical and security logsDetect incidents and ensure availabilityLegitimate interest (information system security)12 months

Once these periods expire, the data is permanently deleted or irreversibly anonymized.


5. Processors and transfers

We rely on a deliberately limited number of suppliers. Each is bound by a confidentiality undertaking and may process the data only as required for the service it provides to us.

SupplierRoleLocation
Meta Platforms, Inc.Provider of the WhatsApp Business messaging platform on which our business messaging solutions are builtUnited States and Meta's global infrastructure
Hostinger International Ltd.Hosting of the website and our applications on a virtual private serverData centres in North America and Europe
Sendinblue SAS (Brevo)Delivery of transactional emails from the contact formEuropean Union

Some of these operations involve transferring data outside Quebec and outside Canada, in particular to the United States and the European Union. Before any transfer, we carry out a privacy impact assessment in accordance with Law 25, and we govern such transfers through the contractual clauses and safeguards provided by each supplier.

We do not disclose your data to any other party, except where legally required by a valid request from a competent authority.


6. Your rights

Depending on where you live and which framework applies, you have the following rights over your personal data:

  • Access — obtain confirmation that we hold data about you and receive a copy of it
  • Rectification — have inaccurate, incomplete or ambiguous data corrected
  • Erasure — request deletion of your data where its retention is no longer justified
  • Objection — object to processing based on our legitimate interest, and withdraw consent already given at any time
  • Portability — receive the data you provided to us in a structured, commonly used technological format, or request its transfer to a third party
  • De-indexing and cessation of dissemination— a right provided under Quebec's Law 25

How to proceed

Send your request by email to contact@synaptic-inc.cawith the subject line “Request regarding my personal information”, or by post to the address given in section 1. State which right you wish to exercise and, if you know them, the data concerned. We may ask you for something confirming your identity, solely to avoid disclosing data to the wrong person; that item is destroyed as soon as verification is complete.

Response time

We respond to any request within a maximum of 30 days from receipt, in accordance with Law 25 and PIPEDA. If the request is complex, we will inform you within that same period, stating the reason and the new expected timeframe. Our response is free of charge. If we decline to act on your request, we will set out in writing the reasons and the remedies available to you.

Remedies

If our response does not satisfy you, you may refer the matter to the Commission d'accès à l'information du Québec, the Office of the Privacy Commissioner of Canada, or — for individuals residing in the European Economic Area — the supervisory authority of your country of residence.


7. Data security

We implement technical and organizational measures appropriate to the sensitivity of the data processed:

  • End-to-end encryption of traffic with the website and our applications via TLS, with automatically renewed certificates
  • Encryption of credentials, access tokens and secrets at rest; passwords stored only as hashes
  • Access to production systems restricted to those who need it, with strong authentication and access logging
  • Strict separation of environments and of data between clients
  • Regular encrypted backups, with a tested restoration procedure
  • Consistent application of security patches across our estate

No system offers absolute security. In the event of a confidentiality incident presenting a risk of serious injury, we notify the individuals concerned and the competent authorities without delay, and we maintain the incident register required by Law 25.



9. Contact and updates

For any question about privacy, this policy or the exercise of your rights:

SynapTIQ INC.
7777 Avenue du Château de Chambord
Québec, QC, G1H 4G9
Canada
Phone: +1 (418) 456-5168
Email: contact@synaptic-inc.ca

We may amend this policy to reflect changes in our services or in the legal framework. The last updated date appears at the top of the page. In the event of a substantial change affecting your rights, we will inform the individuals concerned by appropriate means before it takes effect.

Last updated: August 30, 2026.