Nord Paradigm Inc. (“Nord Paradigm,” “we,” “us”) is committed to protecting your personal information. This policy explains what data we collect, why we collect it, how we use it, and your rights under Quebec’s Act respecting the protection of personal information in the private sector (Loi 25) and the Personal Information Protection and Electronic Documents Act (PIPEDA).

Who We Are

Nord Paradigm Inc. is an AI advisory and governance consultancy federally incorporated in Canada and registered in Quebec (NEQ 1181998668). Our principal place of business is at 393, rue Racine E, 4e étage, Chicoutimi, QC G7H 1T2, Canada.

Person Responsible for the Protection of Personal Information

In accordance with Loi 25, Nord Paradigm has designated the following person as responsible for the protection of personal information:

Dominic-André Leclerc, Founder
Nord Paradigm Inc.
Email: dominic@nordparadigm.com

You may contact this person to exercise your rights under Loi 25 or PIPEDA, ask questions about this policy, or file a privacy complaint.

What We Collect and Why

When You Use Breach (Free)

We collect the company name or URL you submit, your email address (to deliver your report), and information inferred from publicly available sources about the company (such as industry and location). The generated report includes business-identifying information needed to make the analysis useful. Separately, our internal product analytics use a report reference, industry, language, and risk level rather than the company name or email address. Reports used for internal research purposes are stripped of business-identifying information.

When You Subscribe to Signal (Newsletter)

We collect your email address to send you our newsletter. Newsletter signup is always separate from product consent. You can unsubscribe at any time.

When You Book a Meeting

The exact fields depend on the booking path. The public discovery-call form asks for your name, email address, optional organization, selected conversation topic, team size, the process that costs you the most time each week, the AI tool you use most often, and any optional note. A private direct-booking link may ask only for your name, email address, and an optional note.

We collect your name, email address, optional organization, selected conversation topic, meeting time, and any additional context you choose to provide. We use this information to check availability, create a calendar invitation and video meeting, send the invitation, and prepare for the conversation. Calendar availability checks return busy periods only and do not expose event names or details to visitors.

When Breach Pro is used through an agency partner

Breach Pro may be used through marketing, communications, web, SEO, and content agency partners. Agency partners use Breach Pro to produce co-branded strategic AI audits on behalf of their own clients. In this flow, we collect the company URL and intake form responses the agency partner submits (competitor names, business software, employee count range, and a description of current challenges), and where a paid engagement applies, payment and billing information through our payment provider (see Third-Party Services below). In addition:

  • The agency partner submits their client’s company URL and intake form responses. No end-customer email address is collected by Nord Paradigm.
  • The generated report is delivered to the agency partner’s dashboard. The agency partner is responsible for transmitting it to the end customer through their own communication channels.
  • The agency partner acts as data controller with respect to the customer relationship; Nord Paradigm acts as data processor for the end-customer data, and as data controller for the agency partner’s account data.
  • The end customer’s rights under Quebec’s Law 25 and PIPEDA (access, correction, deletion, portability, complaint) remain fully applicable and can be exercised either through the agency partner or directly with Nord Paradigm at dominic@nordparadigm.com.
  • A data processing agreement governs the relationship between Nord Paradigm and each agency partner, in accordance with Section 18.3 of Law 25.

Website Analytics

We use cookieless, aggregated site measurement to understand basic page traffic. We also offer optional audience analytics, but load that service only after you choose “Accept analytics” in our consent banner.

If you opt in, the audience analytics service may collect the pages you visit, approximate location, browser and device details, referral source, and engagement events. We use these measurements to improve our content, site performance, and visitor journeys. We do not send names, email addresses, form contents, or report contents to this service, and advertising features are disabled.

You may decline without affecting the website. You can review or change your choice at any time using the “Analytics preferences” button.

Automated Processing and AI-Generated Analysis

Our products use artificial intelligence to analyze publicly available information about the company URL you submit and generate a written report.

In accordance with Article 12.1 of Loi 25, we inform you that:

  • Your report is generated through automated processing involving large language models and structured analysis pipelines.
  • The report constitutes informational analysis, not a binding decision affecting your legal rights, employment, credit, insurance, or eligibility for any service.
  • You have the right to request the principal factors and parameters used in producing your report and to submit observations to a person responsible at Nord Paradigm.
  • To exercise this right, contact dominic@nordparadigm.com.

Third-Party Services

We use the following service providers to operate our products. We limit the data sent to each service to what is needed for its function. Several providers process data in the United States. Their own retention, security, and backup practices may also apply while they process data for us.

Service Provider Purpose Location
Stripe, Inc. Payment processing United States
Anthropic, PBC AI model inference for report generation and visibility measurement United States
OpenAI, L.L.C. AI model inference for conversational assistant visibility measurement United States
Google LLC (Gemini) AI model inference for conversational assistant visibility measurement United States
Google LLC (Places API) Public business profile lookups for visibility analysis United States
Firecrawl Web scraping infrastructure United States
Serper Search results infrastructure United States
Resend, Inc. Sends report and operational emails; receives the recipient address, the company and report excerpts included in the email, and the report access link United States
Beehiiv, Inc. Newsletter delivery (Signal) United States
Vercel, Inc. Web hosting and content delivery United States
Website analytics provider Optional audience measurement after consent, including pages visited, approximate location, device and browser details, referral source, and engagement events United States
Neon, Inc. Database hosting United States
Upstash, Inc. (Redis and QStash) Redis stores generated Breach Free report data, public and internal access state, and limited operational records. QStash routes Breach Pro pipeline messages that can include report identifiers, company names, and visibility queries. United States
Cloudflare, Inc. DNS, CDN, and tunnel infrastructure United States
Google LLC (Workspace) Business email, calendar scheduling, and video meetings United States
Notion Labs, Inc. Stores Breach lead contact details, report references, feedback, and non-identifying product analytics used by authorized Nord Ops personnel United States

Important privacy commitments:

  • Your payment and billing information is handled entirely by our PCI-DSS compliant payment processor. We never see or store your full card number.
  • Your name and email address are never sent to the AI provider.
  • No personal identifying information is shared with web scraping or search providers; they receive only company URLs and industry-related search queries.
  • The transactional email provider receives your email address and the report-email content, including the company name, a short report excerpt, and the access link. The newsletter provider receives your email address and subscription preferences only when you separately consent.

We do not sell, rent, or share your personal information with third parties for their marketing purposes.

How Long We Keep Your Data

Data Retention
Email address Until deletion request
Intake form responses 12 months after report generation
Ordinary public access to a generated report 30 days after generation
Generated reports (structured data in the internal Nord Ops archive) Up to 12 months (365 days) after generation, unless deleted earlier upon request
Payment records 6 years (Canada Revenue Agency requirement)
Competitor website data Not retained after report generation
Newsletter subscription Until unsubscribe
Meeting booking details and calendar invitation Until deletion request or according to the connected calendar account’s retention settings
Server logs and error logs 30 days

Public access and internal retention are separate: the ordinary report link expires automatically after 30 days. This ends ordinary public access but does not immediately erase the report. The report’s structured data remains in an internal archive available through authenticated Nord Ops tools for up to 12 months so we can respond when a client follows up. Authorized Nord Ops personnel may create a new time-limited access link during that period; doing so does not extend the report’s original 12-month archive deadline.

Note on generated reports: PDF reports are not stored persistently on our servers. Each PDF is regenerated on demand from the report’s structured data (JSON) held in our database. The structured data constitutes the record of reference; deleting this data deletes the report.

Your Rights

Under Loi 25 and PIPEDA, you have the right to:

  • Access a copy of all personal information we hold about you
  • Correct any inaccurate or incomplete information
  • Delete your personal information (we will complete deletion within 30 days)
  • Withdraw consent at any time (your delivered reports remain yours; we delete the source data)
  • Data portability: receive your personal information in a structured, commonly used technological format (Loi 25, in force since September 2024)
  • Be informed of automated decisions as described above
  • Know what data we collect and how we use it (this policy)
  • File a complaint with the Commission d’accès à l’information du Québec (CAI) at cai.gouv.qc.ca, or with the Office of the Privacy Commissioner of Canada at priv.gc.ca

To exercise any of these rights, email dominic@nordparadigm.com. We will respond within 30 days. If we cannot accommodate your request, we will explain why and inform you of your right to file a complaint with the CAI.

For a report-deletion request, include the email address used to receive the report and, if available, the company URL or report link so we can identify the correct record. After verifying the request, we revoke active public access and remove the structured report and related operational records under our control, subject to records we must retain by law and service-provider backup cycles.

Data Security

  • All data transmitted to and from our services is encrypted (HTTPS/TLS)
  • Payment processing is handled entirely by a PCI-DSS compliant provider
  • Ordinary public report links expire after 30 days; any replacement access link is also time-limited
  • The longer report archive is accessed through authenticated Nord Ops tools restricted to authorized personnel
  • In the event of a confidentiality incident presenting a risk of serious injury, we will notify the CAI and affected individuals as required by Loi 25

Report links: Treat a report link with the same care as a confidential file shared by email. Ordinary client access ends after 30 days. After that point, only authorized Nord Ops personnel can open the internal archive or create a new short-lived client link. A verified deletion request removes the report and its active access records from our application storage.

Cookies

Our products use strictly necessary cookies for functions such as session management, security, and payment processing. These do not require consent under Loi 25 or PIPEDA.

Audience analytics cookies are optional and are not placed unless you choose “Accept analytics”. Advertising storage, advertising personalization, and advertising signals remain disabled. Your analytics preference is stored locally in your browser so the site can remember it.

You may refuse or withdraw consent without affecting the website. Use the “Analytics preferences” button at the bottom of the page to change your choice.

Competitor Data

Breach Pro analyzes publicly available information from competitor websites that you identify. The free Breach diagnostic does not perform competitor analysis. We access only data that any person could view in a web browser. We do not access login-protected content, scrape social media profiles, or collect personal information about individuals at competitor businesses. Competitor data is used solely within your Pro report and is not retained after generation.

Minors

Our products are intended for businesses and adults. We do not knowingly collect personal information from individuals under 14 years of age. If you believe we have collected information from a minor, contact us immediately.

Changes to This Policy

We may update this policy as our products and legal requirements evolve. The “last updated” date at the top reflects the most recent revision. For material changes, we will provide additional notice (such as a notice on our website or, where appropriate, by email).

Contact

For any questions about this policy or your personal information:

Dominic-André Leclerc
Person responsible for the protection of personal information
Nord Paradigm Inc.
393, rue Racine E, 4e étage, Chicoutimi, QC G7H 1T2, Canada
Email: dominic@nordparadigm.com
Website: nordparadigm.com