Privacy Policy
Privacy Policy
1. Introduction
Web Inventix AI is a registered business name of BRANTVENTURES INC., an Ontario corporation. BRANTVENTURES INC. owns and operates webinventix.ai and conducts business under the name Web Inventix AI.
This Privacy Policy explains how Web Inventix AI collects, uses, discloses, retains, and protects personal information. It also explains how you can request access to your personal information, ask for a correction, withdraw consent where applicable, or raise a privacy concern.
We handle personal information in accordance with the Personal Information Protection and Electronic Documents Act, commonly called PIPEDA, and other privacy laws that apply to our activities.
In this policy, Web Inventix AI, we, us, and our refer to BRANTVENTURES INC. operating as Web Inventix AI.
2. Scope
This policy applies to personal information we control in connection with:
- Visitors to our website
- Prospective, current, and former clients
- Suppliers, contractors, referral partners, and business partners
- People who contact us by email, telephone, website form, social media, or at an event
- Job applicants
- Users of a Web Inventix AI product or service where we control the personal information
This policy does not apply to:
- Third-party websites, platforms, or services that have their own privacy policies
- Personal information that we process solely for a client under the client’s instructions, except as described in Section 9
- Employee information outside the scope of an applicable privacy law
- Information that is not personal information under applicable law
3. Accountability
Web Inventix AI is responsible for personal information under its control. We have designated a Privacy Officer to oversee privacy practices, requests, questions, and complaints.
Privacy Officer contact information appears in Section 18.
4. Personal Information We Collect
The personal information we collect depends on how you interact with us and the service involved.
4.1 Information You Provide
We may collect:
- Name, company, job title, and business contact information
- Email address, telephone number, and mailing address
- Information submitted through a contact, booking, newsletter, application, or project form
- Project requirements, workflow information, files, technical records, and other materials you provide
- Contract, billing, transaction, and account information
- Communications, support requests, meeting notes, and feedback
- Resumes, cover letters, work history, references, and other application materials
- Consent and communication preferences
- Other information you choose to provide
Please do not send sensitive personal information unless we request it for a defined purpose and provide an approved transfer method.
4.2 Information Collected Automatically
When you visit our website or use an online service, we or our service providers may collect:
- IP address and broad geographic location
- Device type, operating system, and browser type
- Pages viewed, links selected, referring page, and navigation path
- Date, time, and duration of a visit
- Cookie, analytics, security, and similar technical identifiers
- Diagnostic, performance, and security logs
4.3 Telephone, Meeting, and Voice Information
If you contact us by telephone or join an online meeting, we may collect contact details, call or meeting metadata, notes, transcripts, or recordings. If a call or meeting will be recorded or transcribed, we will provide notice and obtain consent when required by law.
4.4 Information From Third Parties
We may receive personal information from:
- Clients, suppliers, and business partners
- Referrals
- Public business websites and professional directories
- Professional networks such as LinkedIn
- Business-to-business data providers
- Event organizers
- Advertising, analytics, security, and fraud-prevention services
- Government, regulatory, or public records where permitted by law
When information comes from another organization, we expect that organization to have authority to provide it to us for the stated purpose.
5. How We Collect Information and Obtain Consent
We collect personal information directly from you, automatically through our website and systems, from our clients when we act as a service provider, or from third parties where permitted by law.
We seek meaningful consent when consent is required. The form of consent may depend on the sensitivity of the information, the context, and your reasonable expectations. Consent may be express or implied where permitted by law.
We may collect, use, or disclose personal information without consent where a law permits or requires it. You may withdraw consent at any time, subject to legal or contractual limits and reasonable notice. Withdrawal may affect our ability to provide a requested product or service.
6. How We Use Personal Information
We may use personal information to:
- Respond to inquiries and assess proposed projects
- Provide proposals, products, software development, consulting, implementation, and support
- Create and manage client, supplier, contractor, and partner relationships
- Process contracts, invoices, payments, and business records
- Schedule calls, meetings, demonstrations, and project work
- Configure, operate, test, secure, maintain, and improve our website, systems, and services
- Authenticate users and manage access permissions
- Diagnose technical problems and prevent fraud, misuse, and security threats
- Communicate about service changes, security, support, and account matters
- Send marketing communications where permitted by law
- Measure website, campaign, and service performance
- Recruit and assess job applicants
- Train personnel and manage internal quality, subject to appropriate privacy controls
- Establish, exercise, or defend legal rights
- Meet tax, accounting, regulatory, legal, insurance, and recordkeeping requirements
- Complete a business transaction such as a financing, merger, reorganization, or sale
- Carry out another purpose that we explain when collecting the information or that you authorize
We limit collection, use, and disclosure to purposes that a reasonable person would consider appropriate in the circumstances.
7. Artificial Intelligence and Automated Tools
Web Inventix AI develops and uses artificial intelligence, automation, analytics, voice, chatbot, computer vision, and related software systems. Depending on the service, these systems may process text, documents, images, audio, video, technical records, or other information that contains personal information.
We may use automated tools to:
- Classify and route inquiries
- Detect spam, fraud, misuse, or security events
- Transcribe or summarize approved calls and meetings
- Extract information from approved documents
- Generate drafts, recommendations, reports, or software outputs
- Support customer service, lead handling, scheduling, and workflow automation
- Test, monitor, and improve an authorized client solution
When we use personal information with an AI system, we apply the same privacy obligations that apply to other processing. This includes defining the purpose, limiting the information used, controlling access, assessing service providers, applying retention rules, and adding human review where the context calls for it.
We do not use client content containing personal information to train a general-purpose model for our own independent purposes unless the client has authorized that use and the required legal authority has been established.
If an AI system contributes to a decision that could materially affect a person, the applicable project terms, notices, and controls should describe the system’s role, material limitations, and available human review. We do not represent automated output as error-free.
Third-party AI providers may process information on our behalf or on behalf of a client. Their processing location, retention options, and contractual terms may vary. We assess these factors based on the project, information sensitivity, and client requirements.
8. How We Disclose Personal Information
We do not sell or rent personal information.
We may disclose personal information to:
- Hosting, cloud, email, communications, analytics, security, payment, customer-management, scheduling, and support providers
- Software developers, engineers, technical contractors, and project partners working under confidentiality and data-protection obligations
- AI, data-processing, transcription, and automation providers used for an approved purpose
- A client or a party the client directs us to work with
- Accountants, auditors, insurers, lawyers, and other professional advisers
- Government, regulatory, court, law-enforcement, or other authorities where permitted or required by law
- A buyer, investor, lender, adviser, or successor involved in a proposed or completed business transaction, subject to appropriate confidentiality controls
- Other parties with your consent or as permitted by law
We limit service-provider access to the information reasonably required for the assigned service. Our contracts, due-diligence process, access controls, and security requirements vary according to the information and risk involved.
9. Client-Controlled Information
In some projects, Web Inventix AI processes personal information for a client and under that client’s instructions. The client determines the purposes for the processing and is generally responsible for notices, consent, legal authority, individual requests, and instructions about the data.
When we act in this role, we process the information under the applicable contract, data-processing terms, documented client instructions, and law. We use it to provide, secure, maintain, troubleshoot, and support the contracted service.
If your information is held in a system operated for one of our clients, direct your privacy request to that client. We will support the client as required by our contract and applicable law.
10. Service Providers and Processing Outside Canada
We may use service providers, contractors, and technical teams located in Canada and other countries. As a result, personal information may be processed or stored outside your province or outside Canada, including in the United States and other jurisdictions used for an approved project.
Personal information processed in another country may be subject to that country’s laws and may be accessible to courts, law-enforcement agencies, national-security authorities, or regulators in that country.
When personal information is transferred to a service provider for processing, Web Inventix AI remains accountable for personal information under its control.
We use measures suited to the sensitivity and context, which may include:
- Vendor and service review
- Contractual privacy and confidentiality terms
- Purpose and use restrictions
- Access controls and least-privilege permissions
- Security requirements
- Retention and deletion instructions
- Incident reporting obligations
- Client-approved data locations or providers where required by contract
Contact the Privacy Officer if you have questions about service providers or processing locations relevant to your information.
11. Security Safeguards
We use administrative, technical, and physical safeguards appropriate to the sensitivity, amount, format, location, and purpose of the personal information under our control.
Measures may include:
- Access controls and role-based permissions
- Authentication and credential management
- Encryption in transit and, where supported and appropriate, at rest
- Confidentiality and data-protection terms
- Security logging, monitoring, backup, and recovery controls
- Software maintenance, vulnerability management, and testing
- Staff and contractor privacy and security requirements
- Incident-response procedures
- Secure deletion or de-identification methods
No system, transmission method, or storage method is completely secure. We cannot guarantee absolute security.
12. Retention and Disposal
We retain personal information only for as long as reasonably required for the identified purpose, a legal or contractual requirement, dispute handling, security, or legitimate recordkeeping.
Our general retention periods are:
| Record Category | General Period |
|---|---|
| Inquiries that do not become a client engagement | Up to 24 months after the last meaningful contact |
| Client contracts, project administration, and core business records | Generally up to 7 years after the engagement ends |
| Financial, invoice, and tax records | Generally 7 years or the period required by law |
| Job applicant information | Generally up to 24 months after the application process ends, unless hired or a longer period is authorized |
| Marketing consent and unsubscribe records | For as long as reasonably required to document consent and honour communication preferences |
| Security incident and breach records | At least the period required by law. PIPEDA breach records are retained for at least 24 months |
| Client-controlled information | As stated in the client agreement or documented client instructions |
Specific systems, contracts, legal holds, backup cycles, or project requirements may require a different period. When information is no longer required, we delete it, de-identify it, or place it beyond routine use using methods appropriate to the information and system.
13. Cookies and Similar Technologies
Our website may use cookies, pixels, local storage, and similar technologies for:
- Core site operation and security
- Form, session, and preference functions
- Performance measurement and analytics
- Marketing attribution or advertising, if enabled
Some technologies are set by third-party providers. Those providers may collect device, browser, usage, and technical information under their own privacy terms.
Where required, we request consent before using non-essential cookies or similar technologies. You can use available cookie controls or browser settings to block or delete cookies. Blocking some cookies may affect site functions.
The website’s cookie notice or preference tool should identify the current non-essential cookie categories and available choices.
14. Marketing Communications
We may send business updates, offers, invitations, or other commercial electronic messages where permitted by Canada’s Anti-Spam Legislation, commonly called CASL, or another applicable law.
For commercial electronic messages sent under CASL, we use express consent, valid implied consent, or another lawful basis. Messages identify the sender, provide required contact information, and include a working unsubscribe method where required.
You may unsubscribe by using the link in a message or by contacting support@webinventix.ai. We process CASL unsubscribe requests without delay and no later than 10 business days after receipt.
We may retain limited suppression-list information after an unsubscribe request so we can respect the request and document compliance.
15. Your Privacy Rights
Subject to applicable law, you may ask us to:
- Confirm if we hold personal information about you
- Provide access to your personal information and an account of its use and disclosure
- Correct information that is inaccurate or incomplete
- Explain our privacy practices
- Withdraw consent where processing relies on consent
- Delete information that is no longer required, subject to legal, contractual, security, and recordkeeping limits
- Address a concern about our handling of personal information
Additional rights may apply under the law of your province, state, country, or the context in which the information was collected.
To make a request, contact the Privacy Officer using the information in Section 18. We may ask for information needed to verify your identity and locate the requested records. Do not send identity documents until we provide instructions.
Under PIPEDA, we respond to an access request with due diligence and generally within 30 days. A permitted extension may apply. We will explain an extension or a lawful refusal as required.
If we cannot resolve your concern, you may contact the Office of the Privacy Commissioner of Canada.
16. Children
Our website and general business services are not directed to children under 16. We do not knowingly collect personal information directly from a child under 16 through the general website.
A client project involving children requires project-specific privacy requirements, consent or other legal authority, age-appropriate notices, limited collection, access controls, retention rules, and safeguards suited to the use case.
Contact the Privacy Officer if you believe a child has provided personal information to us without proper authority.
17. Security Incidents and Privacy Breaches
We assess suspected or confirmed privacy and security incidents involving personal information under our control. We take reasonable steps to contain the incident, investigate its cause and scope, reduce harm, and address identified control gaps.
Where PIPEDA applies, we report a breach to the Office of the Privacy Commissioner of Canada and notify affected individuals when it is reasonable to believe the breach creates a real risk of significant harm. We may also notify another organization or government institution when required or permitted by law to reduce or address the risk of harm.
We maintain records of breaches as required by law.
18. Contact the Privacy Officer
Privacy Officer
Web Inventix AI
A registered business name of BRANTVENTURES INC.
Toronto, Ontario, Canada
Email: support@webinventix.ai
Website: https://webinventix.ai/
Include Privacy Request in the email subject line. Do not include sensitive personal information in the first message.
19. Changes to This Policy
We may update this Privacy Policy to reflect changes in law, technology, service providers, products, or business operations. The revised policy will be posted on this page with a new effective date or last-updated date.
If a change materially affects how we use personal information already collected, we will provide additional notice or obtain consent when required by law.