Privacy Policy
How Nord Paradigm collects, uses, and protects your information. Last updated: July 30, 2026.
Nord Paradigm Inc. (“Nord Paradigm,” “we,” “us”) is committed to protecting your personal information. This policy explains what data we collect, why we collect it, how we use it, and your rights under Quebec’s Act respecting the protection of personal information in the private sector (Loi 25) and the Personal Information Protection and Electronic Documents Act (PIPEDA).
Who We Are
Nord Paradigm Inc. is an AI advisory and governance consultancy federally incorporated in Canada and registered in Quebec (NEQ 1181998668). Our principal place of business is at 393, rue Racine E, 4e étage, Chicoutimi, QC G7H 1T2, Canada.
Person Responsible for the Protection of Personal Information
In accordance with Loi 25, Nord Paradigm has designated the following person as responsible for the protection of personal information:
Dominic-André Leclerc, Founder
Nord Paradigm Inc.
Email: dominic@nordparadigm.com
You may contact this person to exercise your rights under Loi 25 or PIPEDA, ask questions about this policy, or file a privacy complaint.
What We Collect and Why
When You Use Breach (Free)
We collect the company name or URL you submit, your email address (to deliver your report), and information inferred from publicly available sources about the company (such as industry and location). The generated report includes business-identifying information needed to make the analysis useful. Separately, our internal product analytics use a report reference, industry, language, and risk level rather than the company name or email address. Reports used for internal research purposes are stripped of business-identifying information.
When You Subscribe to Signal (Newsletter)
We collect your email address to send you our newsletter. Newsletter signup is always separate from product consent. You can unsubscribe at any time.
When You Book a Meeting
The exact fields depend on the booking path. The public discovery-call form asks for your name, email address, optional organization, selected conversation topic, team size, the process that costs you the most time each week, the AI tool you use most often, and any optional note. A private direct-booking link may ask only for your name, email address, and an optional note.
We collect your name, email address, optional organization, selected conversation topic, meeting time, and any additional context you choose to provide. We use this information to check availability, create a calendar invitation and video meeting, send the invitation, and prepare for the conversation. Calendar availability checks return busy periods only and do not expose event names or details to visitors.
When Breach Pro is used through an agency partner
Breach Pro may be used through marketing, communications, web, SEO, and content agency partners. Agency partners use Breach Pro to produce co-branded strategic AI audits on behalf of their own clients. In this flow, we collect the company URL and intake form responses the agency partner submits (competitor names, business software, employee count range, and a description of current challenges), and where a paid engagement applies, payment and billing information through our payment provider (see Third-Party Services below). In addition:
- The agency partner submits their client’s company URL and intake form responses. No end-customer email address is collected by Nord Paradigm.
- The generated report is delivered to the agency partner’s dashboard. The agency partner is responsible for transmitting it to the end customer through their own communication channels.
- The agency partner acts as data controller with respect to the customer relationship; Nord Paradigm acts as data processor for the end-customer data, and as data controller for the agency partner’s account data.
- The end customer’s rights under Quebec’s Law 25 and PIPEDA (access, correction, deletion, portability, complaint) remain fully applicable and can be exercised either through the agency partner or directly with Nord Paradigm at dominic@nordparadigm.com.
- A data processing agreement governs the relationship between Nord Paradigm and each agency partner, in accordance with Section 18.3 of Law 25.
Website Analytics
We use cookieless, aggregated site measurement to understand basic page traffic. We also offer optional audience analytics, but load that service only after you choose “Accept analytics” in our consent banner.
If you opt in, the audience analytics service may collect the pages you visit, approximate location, browser and device details, referral source, and engagement events. We use these measurements to improve our content, site performance, and visitor journeys. We do not send names, email addresses, form contents, or report contents to this service, and advertising features are disabled.
You may decline without affecting the website. You can review or change your choice at any time using the “Analytics preferences” button.
Automated Processing and AI-Generated Analysis
Our products use artificial intelligence to analyze publicly available information about the company URL you submit and generate a written report.
In accordance with Article 12.1 of Loi 25, we inform you that:
- Your report is generated through automated processing involving large language models and structured analysis pipelines.
- The report constitutes informational analysis, not a binding decision affecting your legal rights, employment, credit, insurance, or eligibility for any service.
- You have the right to request the principal factors and parameters used in producing your report and to submit observations to a person responsible at Nord Paradigm.
- To exercise this right, contact dominic@nordparadigm.com.
Third-Party Services
We use the following service providers to operate our products. We limit the data sent to each service to what is needed for its function. Several providers process data in the United States. Their own retention, security, and backup practices may also apply while they process data for us.
| Service Provider | Purpose | Location |
|---|---|---|
| Stripe, Inc. | Payment processing | United States |
| Anthropic, PBC | AI model inference for report generation and visibility measurement | United States |
| OpenAI, L.L.C. | AI model inference for conversational assistant visibility measurement | United States |
| Google LLC (Gemini) | AI model inference for conversational assistant visibility measurement | United States |
| Google LLC (Places API) | Public business profile lookups for visibility analysis | United States |
| Firecrawl | Web scraping infrastructure | United States |
| Serper | Search results infrastructure | United States |
| Resend, Inc. | Sends report and operational emails; receives the recipient address, the company and report excerpts included in the email, and the report access link | United States |
| Beehiiv, Inc. | Newsletter delivery (Signal) | United States |
| Vercel, Inc. | Web hosting and content delivery | United States |
| Website analytics provider | Optional audience measurement after consent, including pages visited, approximate location, device and browser details, referral source, and engagement events | United States |
| Neon, Inc. | Database hosting | United States |
| Upstash, Inc. (Redis and QStash) | Redis stores generated Breach Free report data, public and internal access state, and limited operational records. QStash routes Breach Pro pipeline messages that can include report identifiers, company names, and visibility queries. | United States |
| Cloudflare, Inc. | DNS, CDN, and tunnel infrastructure | United States |
| Google LLC (Workspace) | Business email, calendar scheduling, and video meetings | United States |
| Notion Labs, Inc. | Stores Breach lead contact details, report references, feedback, and non-identifying product analytics used by authorized Nord Ops personnel | United States |
Important privacy commitments:
- Your payment and billing information is handled entirely by our PCI-DSS compliant payment processor. We never see or store your full card number.
- Your name and email address are never sent to the AI provider.
- No personal identifying information is shared with web scraping or search providers; they receive only company URLs and industry-related search queries.
- The transactional email provider receives your email address and the report-email content, including the company name, a short report excerpt, and the access link. The newsletter provider receives your email address and subscription preferences only when you separately consent.
We do not sell, rent, or share your personal information with third parties for their marketing purposes.
How Long We Keep Your Data
| Data | Retention |
|---|---|
| Email address | Until deletion request |
| Intake form responses | 12 months after report generation |
| Ordinary public access to a generated report | 30 days after generation |
| Generated reports (structured data in the internal Nord Ops archive) | Up to 12 months (365 days) after generation, unless deleted earlier upon request |
| Payment records | 6 years (Canada Revenue Agency requirement) |
| Competitor website data | Not retained after report generation |
| Newsletter subscription | Until unsubscribe |
| Meeting booking details and calendar invitation | Until deletion request or according to the connected calendar account’s retention settings |
| Server logs and error logs | 30 days |
Public access and internal retention are separate: the ordinary report link expires automatically after 30 days. This ends ordinary public access but does not immediately erase the report. The report’s structured data remains in an internal archive available through authenticated Nord Ops tools for up to 12 months so we can respond when a client follows up. Authorized Nord Ops personnel may create a new time-limited access link during that period; doing so does not extend the report’s original 12-month archive deadline.
Note on generated reports: PDF reports are not stored persistently on our servers. Each PDF is regenerated on demand from the report’s structured data (JSON) held in our database. The structured data constitutes the record of reference; deleting this data deletes the report.
Your Rights
Under Loi 25 and PIPEDA, you have the right to:
- Access a copy of all personal information we hold about you
- Correct any inaccurate or incomplete information
- Delete your personal information (we will complete deletion within 30 days)
- Withdraw consent at any time (your delivered reports remain yours; we delete the source data)
- Data portability: receive your personal information in a structured, commonly used technological format (Loi 25, in force since September 2024)
- Be informed of automated decisions as described above
- Know what data we collect and how we use it (this policy)
- File a complaint with the Commission d’accès à l’information du Québec (CAI) at cai.gouv.qc.ca, or with the Office of the Privacy Commissioner of Canada at priv.gc.ca
To exercise any of these rights, email dominic@nordparadigm.com. We will respond within 30 days. If we cannot accommodate your request, we will explain why and inform you of your right to file a complaint with the CAI.
For a report-deletion request, include the email address used to receive the report and, if available, the company URL or report link so we can identify the correct record. After verifying the request, we revoke active public access and remove the structured report and related operational records under our control, subject to records we must retain by law and service-provider backup cycles.
Data Security
- All data transmitted to and from our services is encrypted (HTTPS/TLS)
- Payment processing is handled entirely by a PCI-DSS compliant provider
- Ordinary public report links expire after 30 days; any replacement access link is also time-limited
- The longer report archive is accessed through authenticated Nord Ops tools restricted to authorized personnel
- In the event of a confidentiality incident presenting a risk of serious injury, we will notify the CAI and affected individuals as required by Loi 25
Report links: Treat a report link with the same care as a confidential file shared by email. Ordinary client access ends after 30 days. After that point, only authorized Nord Ops personnel can open the internal archive or create a new short-lived client link. A verified deletion request removes the report and its active access records from our application storage.
Cookies
Our products use strictly necessary cookies for functions such as session management, security, and payment processing. These do not require consent under Loi 25 or PIPEDA.
Audience analytics cookies are optional and are not placed unless you choose “Accept analytics”. Advertising storage, advertising personalization, and advertising signals remain disabled. Your analytics preference is stored locally in your browser so the site can remember it.
You may refuse or withdraw consent without affecting the website. Use the “Analytics preferences” button at the bottom of the page to change your choice.
Competitor Data
Breach Pro analyzes publicly available information from competitor websites that you identify. The free Breach diagnostic does not perform competitor analysis. We access only data that any person could view in a web browser. We do not access login-protected content, scrape social media profiles, or collect personal information about individuals at competitor businesses. Competitor data is used solely within your Pro report and is not retained after generation.
Minors
Our products are intended for businesses and adults. We do not knowingly collect personal information from individuals under 14 years of age. If you believe we have collected information from a minor, contact us immediately.
Changes to This Policy
We may update this policy as our products and legal requirements evolve. The “last updated” date at the top reflects the most recent revision. For material changes, we will provide additional notice (such as a notice on our website or, where appropriate, by email).
Contact
For any questions about this policy or your personal information:
Dominic-André Leclerc
Person responsible for the protection of personal information
Nord Paradigm Inc.
393, rue Racine E, 4e étage, Chicoutimi, QC G7H 1T2, Canada
Email: dominic@nordparadigm.com
Website: nordparadigm.com