Suivo Privacy Policy
Effective date: August 16, 2026
Last updated: August 23, 2026
This Privacy Policy explains how Suivo Technologies Inc., federal corporation number 1001698079, a corporation incorporated under the Canada Business Corporations Act (“Suivo,” “we,” “us,” or “our”) collects, uses, discloses, stores, and protects personal information through the Suivo website, web application, mobile application, APIs, support, and related services (collectively, the “Services”). Suivo's Québec enterprise number is pending and will be added once issued.
It also explains how Suivo handles personal information on behalf of real estate teams that use the Services (“Customers”), including information about their employees, agents, contacts, leads, clients, prospective clients, household members, service providers, and other people.
1. Key points
- Suivo is a business platform for real estate professionals, not a consumer social network or advertising platform.
- Customers decide which people and business records to place in Suivo and are responsible for their own privacy notices, consent, and legal authority.
- The Services may process contact details, property and transaction interests, emails, text messages, calendar events, files, call audio, transcripts, CRM notes, and AI-derived information, depending on enabled features.
- Suivo does not sell personal information and does not share it for cross-context behavioural advertising.
- Connected Gmail, Outlook, and calendar features are optional and use scoped provider authorization.
- AI, speech, telephony, authentication, notification, and scheduling providers may process information outside Québec and outside Canada.
- Primary production hosting is currently designed for a Canadian Google Cloud region, but this is not complete Canadian data residency.
- Disconnecting a connected service, deleting Google data, deleting an individual User, and terminating a Customer account are different actions with different effects.
- No system is completely secure. We use safeguards designed to reduce risk and respond to incidents as required by law.
- Individuals may have rights of access, correction, deletion or withdrawal, portability, and complaint, subject to legal exceptions and the role of the Customer that controls the record.
This summary is not a substitute for the full Policy.
2. Who is responsible for personal information
2.1 Suivo's direct activities
Suivo is responsible for personal information it collects for its own purposes, such as website inquiries, contracting, account administration, authentication, security, support, service communications, provider management, and legal compliance.
2.2 Customer-controlled records
Customers generally decide why and how personal information in their CRM records, connected communications, calendars, files, tasks, appointments, and voice workflows is processed. For that information, Suivo generally acts as a service provider following Customer instructions and the applicable agreement.
The exact legal roles depend on the activity and jurisdiction. Terms such as “controller,” “processor,” or “service provider” do not override applicable law.
If you are a contact, lead, client, employee, or other person whose information a Customer placed in Suivo, the Customer is usually the first point of contact for your request. We will assist the Customer as required by law and contract.
3. Privacy contact
The person responsible for the protection of personal information at Suivo is:
Privacy Officer — Person Responsible for the Protection of Personal Information
Suivo Technologies Inc.
Federal corporation number: 1001698079
Québec enterprise number (NEQ): Pending
Email: <contact@suivo.ca>
Website: https://suivo.ca
Use this contact to ask a privacy question, exercise a privacy right, challenge compliance, or make a complaint. Security vulnerabilities should be reported through the Security page, not through an ordinary privacy request.
4. Scope
This Policy applies to:
- the public website at
suivo.ca; - the authenticated web application at
app.suivo.ca; - Suivo's iOS, Android, and supported web clients;
- the Suivo API and background processing;
- demos, onboarding, support, and business communications; and
- optional connected mailbox, calendar, messaging, notification, AI, file, and voice features.
This Policy does not govern a third-party website, application, Connected Service, or Customer's independent privacy practices. Their policies apply to their processing.
5. Personal information we collect and process
What we process depends on how you and the Customer use the Services.
5.1 Account, identity, and profile information
We may process:
- name, display name, email address, telephone number, and profile photograph;
- Customer, brokerage, team, title, role, professional details, languages, service areas, specialties, biography, and availability notes;
- authentication-provider identifiers, account state, sign-in method, session information, and recovery or verification state;
- User ID, Customer or team ID, role, permissions, membership, assignments, and access-grant information;
- notification preferences, language, time zone, theme, and application settings; and
- device push tokens and registered device information.
Suivo uses an external identity provider. We do not receive or store your Google, Apple, Gmail, or Microsoft password.
5.2 CRM, contact, and real estate information
Customers and connected sources may provide:
- names, aliases, contact methods, preferred method, physical or property addresses, and language;
- employer, profession, brokerage, agent, vendor, cooperating-professional, household, participant, and other relationship information;
- lead or inquiry source, assignment, ownership, collaborators, team, and routing history;
- buyer, seller, renter, landlord, investor, referral, or other real estate intent;
- property type, location, listing or property identifiers, price, budget, financing or pre-approval status, timeline, preferences, constraints, and showing interest;
- opportunity stage, status, health, qualification details, milestones, transaction state, and outcome;
- notes, tasks, goals, follow-ups, reminders, appointments, activity, audit history, and internal decisions;
- consent, unsubscribe, do-not-email, do-not-text, do-not-call, suppression, and compliance evidence; and
- information about other participants, household members, co-buyers, co-sellers, agents, lawyers, lenders, inspectors, vendors, and service providers.
Some of this information may be sensitive because it reveals finances, housing plans, family or household circumstances, location, professional relationships, or private communications.
5.3 Email, messages, and internal communications
When a Customer connects or uses communication features, we may process:
- message bodies in text or HTML;
- sender, recipient, reply-to, carbon-copy, and blind-carbon-copy addresses;
- subject, timestamp, message and thread identifiers, mailbox folders or labels, history identifiers, delivery and read state, and provider metadata;
- attachments, filenames, file types, sizes, content hashes, storage references, and malware-scan state;
- SMS content, sender and recipient phone numbers, delivery events, and provider identifiers;
- internal direct or group messages and their membership; and
- drafts, quick replies, sent messages, notification previews, and conversation associations.
Email content is treated as untrusted. Supported viewers sanitize HTML, isolate it from the surrounding application, and block remote images by default. If a User chooses to load permitted remote images or open a link, the remote host may receive the User's IP address, browser information, request time, and URL data under that host's policy.
5.4 Connected mailbox and provider credentials
For Gmail and Outlook connections, we may process:
- connected email address and basic provider profile;
- OAuth access and refresh tokens, scopes, token expiry, refresh state, and connection generation;
- mailbox type, delegation information, connection status, subscription or watch identifiers, and synchronization cursors;
- authorized mailbox messages, metadata, attachments, and history; and
- message sending instructions and provider delivery evidence.
Tokens and selected raw content are encrypted. Tokens are credentials and are not displayed in ordinary product views.
5.5 Calendar and appointment information
If a calendar feature is enabled, we may process:
- connected calendar identity, calendar names, permissions, provider IDs, tokens, sync cursors, and subscription state;
- event title, description, date, time, time zone, location, recurrence, status, organizer, attendees, responses, and provider event identifiers;
- privacy-reduced busy periods for authorized team availability; and
- appointment requests, proposals, confirmations, rescheduling, cancellation, and audit history.
Creating or updating an event may cause Google or Microsoft to send invitations or updates to attendees.
5.6 Calls, voice, recordings, and transcripts
If voice, calling, voicemail, dictation, or transcription features are enabled, we may process:
- caller and recipient telephone numbers, routing information, provider call IDs, timestamps, duration, status, and call events;
- live audio streams needed to carry, transcribe, synthesize, or analyze the call;
- call recordings where recording is enabled and lawful;
- interim and final transcripts, transcript turns, confidence or quality information, language, and timing;
- limited raw-audio or speech-to-text diagnostic samples when a separately controlled audit feature is enabled;
- synthesized assistant audio and conversation state;
- consent, recording disclosure, opt-out, do-not-call, and transfer state;
- call summaries, qualification facts, contact details, requests, callbacks, appointment requests, and follow-up actions; and
- failures, quality evidence, and bounded technical diagnostics.
Transcription and recording are different. Live audio may be transmitted to a speech provider and converted into text even if a durable call recording is not saved. A call may be recorded only when the applicable feature and Customer configuration permit it.
Suivo does not intentionally use call audio to create biometric voiceprints or identify a person by unique voice characteristics. If that changes, we will conduct the required review and provide additional notice and consent before the new use.
Customers are responsible for telling participants about AI, transcription, monitoring, or recording and obtaining consent where required. Participants may ask the Customer to stop recording or contacting them. Technical support for an objection does not determine the legal effect of the request.
5.7 Files and attachments
We may process files a User uploads or that arrive through a connected mailbox, including file content, filename, size, MIME type, content hash, uploader, associated record, storage object version, and malware-scan result.
Supported files are quarantined until the configured scanner returns a clean decision for the exact stored bytes. A blocked or failed file may remain unavailable. Malware signatures and detailed scanner output are not intended for ordinary User display.
Do not upload government identification numbers, payment-card data, health records, highly sensitive legal documents, or other information not necessary for the configured real estate workflow.
5.8 AI prompts, output, and derived information
Depending on the feature, we may process authorized Customer Data to create:
- inquiry relevance or classification decisions;
- structured contact, property, relationship, opportunity, and timeline facts;
- summaries, note titles, response drafts, and quick replies;
- suggested next actions, workflow priorities, and routing or assignment evidence;
- speech transcripts and conversation responses;
- confidence, validation, failure, retry, and model metadata; and
- versioned snapshots needed to prevent stale AI output from overwriting newer records.
These are inferences or generated information and can be inaccurate. Customers and Users must review consequential information. Suivo is not designed to make a legally significant decision about an individual solely through automated processing.
5.9 Technical, usage, and security information
We may collect:
- IP address, request time, request method, route, response status, latency, and bounded correlation identifiers;
- browser, operating system, device type, app version, build, platform, contract version, and network state;
- session, authentication, authorization, role, and security-event information;
- feature interactions, page state, error state, queue state, provider health, performance, and aggregate metrics;
- notification delivery and receipt status;
- storage, database, cache, and service health information; and
- logs needed to prevent abuse, debug faults, reconcile provider activity, and respond to incidents.
Ordinary telemetry is designed not to contain message bodies, call transcripts, raw audio, file bytes, full storage keys, passwords, OAuth tokens, API keys, or arbitrary provider error text. Accidental inclusion can still occur, so logs are access restricted and subject to review and retention controls.
5.10 Website, demo, sales, and support information
If you visit the website, request a demo, schedule a meeting, or contact support, we may process:
- name, business email, phone number, company, team size, job title, and inquiry;
- meeting preferences and scheduling information;
- correspondence, support messages, screenshots, files, and troubleshooting details you choose to send; and
- basic website request logs and theme preference.
6. Where information comes from
We collect information:
- directly from Users, website visitors, Customers, and people who communicate with us;
- from a Customer's administrators, agents, staff, imports, records, and instructions;
- from connected Google, Microsoft, Apple, telephony, messaging, calendar, and identity accounts authorized by a User or Customer;
- from emails, texts, calls, forms, listing portals, referrals, and other inquiry sources routed to a Customer;
- from devices, browsers, applications, network requests, and security systems;
- from service providers acting for Suivo;
- from other participants in a communication or transaction; and
- through AI-assisted or deterministic derivation from authorized source information.
Customers must not treat information as “public” unless applicable privacy law actually permits the intended collection and use.
7. Why we collect and use information
We process personal information to:
7.1 Provide and operate the Services
- create and administer accounts and Customer workspaces;
- authenticate Users and enforce roles, team membership, record authority, and permissions;
- create, display, search, update, archive, assign, and relate CRM records;
- synchronize and display authorized email, messages, calendars, attachments, and communication history;
- send Customer-approved email, SMS, calendar updates, notifications, and calls;
- route inquiries, create tasks, manage appointments, and support collaboration;
- scan files and make authorized clean files available;
- process User requests, save settings, and maintain continuity; and
- provide mobile, web, API, and support functions.
7.2 Provide AI and voice features
- transcribe dictation and calls;
- understand and classify inquiries;
- generate summaries, drafts, titles, suggested actions, and structured CRM facts;
- conduct configured AI-assisted voice interactions;
- validate output, prevent unsupported actions, and reauthorize before disclosure; and
- measure feature quality using permitted, access-controlled evidence.
7.3 Protect the Services and people
- prevent unauthorized access, fraud, abuse, spam, malware, duplication, and security incidents;
- validate webhooks, credentials, device registrations, and runtime identities;
- troubleshoot failures and provider ambiguity;
- preserve audit evidence, enforce suppression, and investigate complaints;
- monitor availability, performance, and safe operation; and
- exercise or defend legal claims.
7.4 Communicate and support
- answer inquiries and provide onboarding, support, security, privacy, and administrative communications;
- send service, account, security, task, appointment, and notification messages according to preferences; and
- schedule and manage demos or meetings.
7.5 Improve and govern the Services
- fix defects and improve usability, reliability, safety, and accessibility;
- test changes using synthetic, de-identified, or specifically authorized information;
- understand aggregate feature health and capacity; and
- conduct privacy, security, legal, and provider compliance reviews.
Google Workspace data and data derived from it are used only as permitted by the Google API Services User Data Policy, including its Limited Use requirements. They are not used for unrelated product improvement, advertising, creditworthiness, or training shared/general-purpose models.
7.6 Comply with law
- respond to lawful process;
- meet privacy, tax, accounting, corporate, security-incident, and recordkeeping obligations;
- maintain do-not-contact and suppression evidence;
- cooperate with regulators and enforce our agreements; and
- complete a corporate transaction subject to the restrictions below.
Depending on the activity and jurisdiction, processing may be based on consent, performance of a contract, compliance with law, protection of legitimate interests that do not override individual rights, or another lawful basis. Where consent is required, it may be withdrawn subject to legal and contractual restrictions and reasonable notice.
8. Google Workspace API data
This section applies when a User connects Gmail or Google Calendar.
8.1 Data accessed
For Gmail, the reviewed application requests gmail.readonly and gmail.send scopes. Suivo may access the connected email address, basic authorized profile, message and thread lists, headers, sender and recipient addresses, subjects, bodies, timestamps, identifiers, history, and attachments, and may send messages the authorized User initiates or approves.
For Google Calendar, the reviewed application requests calendar.calendarlist.readonly to let a User discover and select subscribed calendars and calendar.events to provide two-way event synchronization. Suivo may read authorized events and may create, update, reschedule, synchronize, or delete events as instructed by the User and configured workflow. Suivo does not use these scopes to change calendar sharing, manage calendar access-control lists, add or remove calendar subscriptions, or delete calendars.
8.2 How Google data is used
Suivo uses Google Workspace data to provide prominent user-facing features, including:
- synchronizing the connected inbox or calendar;
- displaying authorized communication and event history;
- associating messages with contacts, conversations, opportunities, tasks, and appointments;
- identifying and routing real estate inquiries;
- generating visible summaries, classifications, structured facts, suggested actions, and response drafts;
- sending messages and calendar updates initiated or approved by an authorized User; and
- protecting, debugging, and supporting those features.
8.3 Storage and sharing
Suivo stores encrypted OAuth credentials, synchronized content, provider identifiers, and derived workflow information in protected systems. Relevant Google data may be sent to contracted hosting, AI, or security providers only when needed to provide or improve the visible feature, with the User's consent, or for another purpose permitted by Google's Limited Use requirements.
We do not:
- sell Google Workspace data;
- transfer it to advertising platforms, data brokers, or information resellers;
- use it for advertising, retargeting, lending, or creditworthiness;
- use it for unrelated surveillance;
- use it to train a shared or general-purpose AI model; or
- allow ordinary human review.
Human access is limited to: the User's affirmative agreement to view specific data for support; a necessary security or abuse investigation; legal compliance; or permitted aggregated internal operations.
8.4 Disconnecting and deleting Google data
Disconnecting Google: Disconnecting stops future access and synchronization and removes or invalidates Suivo's usable mailbox credentials. Previously created CRM records and synchronized communication history may remain under the Customer's retention instructions.
Deleting Google data: The separate Google-data deletion control is intended to:
- stop new synchronization;
- remove usable OAuth credentials and attempt provider revocation;
- delete stored Gmail message payloads and provider identifiers from live application records;
- delete Gmail intake and intake-audit records;
- delete associated stored attachment bytes and attachment records;
- delete mailbox backfill state and cancel pending derived notifications; and
- replace message content in surviving workflow events with a limited marker showing that provider data was deleted.
The deletion flow may retain:
- sanitized event anchors needed for workflow integrity and audit history;
- canonical CRM facts, contacts, opportunities, tasks, appointments, or other business records that no longer contain the deleted Gmail payload and are controlled by the Customer;
- de-identified or aggregate operational information;
- legally required security or incident evidence; and
- keyed cryptographic tombstones representing deleted provider message identifiers so that the same deleted message is not re-ingested. Tombstones do not contain the original message identifier in readable form.
If provider token revocation temporarily fails, encrypted revocation material may be retained only to retry revocation. The live content purge is designed not to wait on that provider result.
The current implementation does not support a public promise that every Contact or Opportunity originally created from Gmail will be deleted automatically. Contact the Customer and <contact@suivo.ca> if a remaining CRM fact must be reviewed.
8.5 Google policy
Suivo's use and transfer of information received from Google APIs must comply with the Google API Services User Data Policy, including the Limited Use requirements.
9. Microsoft 365 data
If a User connects Outlook, the reviewed application may request Mail.ReadWrite, Mail.Send, and User.Read. This allows Suivo to read and synchronize mailbox content, create and send messages, maintain subscriptions, and access the connected account's basic email identity.
If a User connects Microsoft Calendar, Suivo may access authorized calendars and events and may create, update, synchronize, or delete events as instructed.
Disconnecting Microsoft stops future access and removes usable credentials. Unless a Customer uses another deletion process or makes a valid request, previously synchronized messages, event history, derived CRM facts, and business records may remain under Customer retention rules. Suivo must not claim a Microsoft-specific purge identical to the Gmail purge unless one is implemented and verified.
10. AI, profiling, and automated processing
Suivo uses automated rules and AI to organize records, extract or infer information, prioritize or route work, generate drafts and summaries, and support voice interactions. This can create a profile of a contact's apparent real estate intent, preferences, budget, financing state, timeline, communication history, engagement, and follow-up needs.
The Services are designed as professional decision-support tools. A Customer or authorized User remains responsible for consequential action. Customers must not configure Suivo as the sole decision-maker for credit, housing eligibility, employment, insurance, legal rights, or another decision producing legal or similarly significant effects.
If an applicable law gives you a right to information about a decision based exclusively on automated processing, to provide observations, or to request correction, contact the Customer responsible for the decision and <contact@suivo.ca>. We may need information from the Customer to respond.
AI input and Output may be processed by providers outside Canada. The active provider may vary by feature, language, quality, configuration, and availability. Provider contracts and settings—not merely the use of an API—determine provider retention and training treatment.
11. Technologies on the website and in the applications
11.1 Authentication and essential storage
The authenticated application uses essential cookies, tokens, secure device storage, or similar technologies to sign Users in, maintain sessions, prevent fraud, store necessary settings, and route requests. Disabling them may prevent the application from working.
11.2 Public website browser storage and analytics
The public website stores a suivo-consent value in local storage to remember the visitor's cookie-notice choice and may store suivo-demo-email in session storage after a visitor enters an email in the homepage demo field. If a visitor accepts analytics cookies, Suivo loads Google Analytics 4 in basic consent mode to measure page views and limited demo, scheduling, and contact-link interactions. The Google tag is not requested before acceptance or after refusal. Advertising storage, advertising user data, advertising personalization, Google Signals, and ad-personalization signals are disabled, and Suivo does not intentionally send names, email addresses, Calendly answers, CRM information, or form contents to Google Analytics. Details and withdrawal controls are available in the Cookies and Website Storage notice.
11.3 Calendly
Suivo uses Calendly for optional demo scheduling. The inline scheduler on the Contact page loads Calendly resources when a visitor selects “View available times”; elsewhere, the shared “Book a demo” dialog loads Calendly resources when a visitor opens it. Calendly may receive the visitor's IP address, browser and device information, referring or page context, cookies or similar identifiers, and—if the visitor schedules a meeting—the name, contact details, availability, answers, and other meeting information submitted. Calendly handles information under its own privacy terms.
11.4 Remote email content
Remote images in email are blocked by default. Loading them can contact the sender's or another third party's server and may reveal that a message was opened. Invisible and suspicious trackers remain blocked by the supported viewer even after visible images are allowed.
11.5 Advertising and analytics
The reviewed public website does not include third-party advertising trackers or a general analytics SDK. Suivo does not use personal information for cross-context behavioural advertising. If we add non-essential analytics, advertising, fingerprinting, precise-location, or profiling technology, we will update this Policy and provide the notice and choices required by law before activating it.
11.6 Mobile permissions
The mobile application may request:
- microphone access to dictate messages or use an enabled voice feature;
- photo-library or file access when a User chooses an attachment;
- notification permission for enabled push notifications; and
- secure local storage for session or app state.
The reviewed mobile configuration does not request precise device location. Property addresses and service areas entered into CRM records are not the same as GPS location. If location access is added, we will provide feature-specific notice and a device permission control.
11.7 App marketplace disclosures
Apple App Store and Google Play privacy labels or data-safety forms are summaries and do not replace this Policy. Depending on the enabled features and the final production build, those filings may need to identify account and contact information, user content, messages, photos or files, audio, identifiers, product interaction or usage data, crash or diagnostic data, and data used for application functionality, authentication, security, support, and analytics. Suivo must keep the filings consistent with the production application, this Policy, and the relevant platform definitions. The reviewed mobile configuration did not contain an advertising SDK or request permission for precise location.
12. When we disclose personal information
We may disclose personal information as follows.
12.1 Within the Customer organization
Information may be available to Customer administrators, Team Managers, Agents, collaborators, assignees, or other authorized Users based on team membership, role, record authority, ownership, assignment, participation, integration ownership, and workspace configuration.
Customer administrators may reassign organization-controlled work when a User leaves. A Team Manager role should not automatically disclose another User's private record where the configured authority model protects it.
12.2 At the Customer's or User's direction
We disclose information when an authorized User sends a message, places or accepts a call, invites an attendee, connects a provider, loads remote email content, shares a record, exports data, or otherwise instructs the Services to interact with another person or system.
12.3 Service providers and subprocessors
We use providers to operate the Services. They may process information only for the contracted purpose, subject to their agreements, applicable law, and the limits below.
12.4 Connected Services
Google, Microsoft, Apple, telecommunications carriers, email providers, calendar providers, and other Connected Services receive information needed to perform the action the User requests. They may independently process account and service data under their own terms.
12.5 Legal, safety, and security reasons
We may preserve or disclose information when we reasonably believe it is necessary to comply with valid legal process, enforce an agreement, investigate fraud or abuse, protect rights and safety, respond to a security incident, or establish or defend a legal claim.
Where lawful and appropriate, we will assess the request, seek to narrow it, and notify the affected Customer before disclosure. We may be prohibited from giving notice.
12.6 Professional advisers
We may disclose necessary information to lawyers, auditors, insurers, accountants, security specialists, and other professional advisers under confidentiality duties.
12.7 Corporate transactions
Information may be disclosed under confidentiality in connection with financing, due diligence, merger, acquisition, restructuring, insolvency, or sale of assets. Google Workspace data will be transferred as part of a merger, acquisition, or asset sale only after the explicit prior consent required by Google's Limited Use policy.
12.8 De-identified information
We may use and disclose information that has been de-identified so that it cannot reasonably identify an individual or Customer, subject to contractual and legal restrictions. We will not attempt to re-identify it except to test whether de-identification is effective or as permitted by law.
13. Providers and processing locations
The following table reflects providers found in the reviewed application. A provider may be inactive, optional, or limited to a particular feature. The final published list must match production and the current subprocessor register.
| Provider/category | Purpose | Information that may be processed | Likely processing location |
|---|---|---|---|
| Google Cloud Platform | Cloud Run hosting, PostgreSQL database, object storage, KMS, cache/queue infrastructure, logs, and optional speech services | Most Service data, encrypted content, files, keys, technical logs, and audio sent to Speech | Primary Suivo resources configured in Canada; Google operations/subprocessors may involve other countries |
| Clerk | Authentication, session management, account administration, and social sign-in orchestration | Account identity, email, authentication IDs, sessions, device/network data | Canada, United States, or other provider locations |
| Google Workspace APIs | User-connected Gmail and Calendar functions | Authorized mailbox, profile, messages, attachments, calendars, events, tokens, and provider metadata | Google-controlled locations |
| Microsoft 365 / Microsoft Graph | User-connected Outlook and Calendar functions | Authorized profile, mailbox, messages, attachments, calendars, events, tokens, and provider metadata | Microsoft-controlled locations |
| OpenAI | AI drafts, summaries, classifications, extraction, transcription, realtime voice, or other configured model features | Relevant prompts, message/call content, audio, Output, and technical metadata | United States and/or other provider locations |
| Deepgram | Speech-to-text when selected | Live call audio, transcripts, language, timing, and technical metadata | United States and/or other provider locations |
| ElevenLabs | Speech-to-text and text-to-speech when selected | Audio, transcript text, synthesized-response text, voice settings, and technical metadata | United States, European Union, and/or other provider locations |
| Cartesia | Text-to-speech when selected | Response text, voice configuration, synthesized audio, and technical metadata | United States and/or other provider locations |
| Telnyx | Telephone numbers, calls, media streaming, SMS, transfer, and delivery webhooks | Phone numbers, call/SMS content and metadata, audio streams, provider identifiers, and delivery events | Canada, United States, and/or global telecommunications networks—verify service configuration |
| Postmark | Transactional service email and delivery webhooks | User email, message subject/body, template variables, delivery and bounce information | Provider-controlled locations |
| Expo, Apple Push Notification service, and Firebase Cloud Messaging | Push notification delivery | Push token, app/project identifiers, limited notification payload, delivery receipts, and device/platform data | Provider-controlled global locations |
| Apple and Google | Optional social sign-in and app distribution | Account identity selected by User, app/device, purchase or store metadata controlled by the store | Provider-controlled global locations |
| Calendly | Optional demo scheduling | IP/browser data and meeting details submitted by the visitor | United States and/or other provider locations |
ClamAV malware scanning in the reviewed deployment runs as a Suivo-controlled sidecar rather than sending file bytes to an external scanning API.
A current subprocessor list and available contractual transfer information may be requested at <contact@suivo.ca>.
14. International and out-of-Québec processing
Suivo is founded in Québec and primary application infrastructure is designed for a Canadian Google Cloud region. However, service providers and Connected Services may process information outside Québec and outside Canada.
Before Suivo entrusts personal information to a provider outside Québec, we will perform the privacy assessment required by applicable law and use a written agreement with appropriate protections. Factors include sensitivity, purpose, quantity, safeguards, provider practices, location, and the legal regime where information may be accessible.
Information processed abroad can be accessed by courts, law enforcement, national-security authorities, or regulators under local law. Contractual and technical safeguards reduce but cannot eliminate that possibility.
Customers must assess their own instructions and professional requirements, especially before enabling AI or voice providers for client communications.
15. Retention and destruction
We keep personal information only as long as reasonably necessary for the identified purpose, Customer instructions, security, legal obligations, disputes, and legitimate business continuity. We then delete, anonymize, or securely destroy it, subject to backups and lawful exceptions.
The following is Suivo's standard retention schedule. A shorter period applies when the purpose ends sooner or a valid deletion request can be honoured. A longer period applies only for a documented Customer instruction, professional recordkeeping duty, legal hold, security investigation, dispute, or other legal requirement.
| Record category | Standard retention rule |
|---|---|
| Website demo and sales inquiries | 24 months after the last substantive interaction, unless a Customer relationship begins, consent supports a longer relationship, or the person asks for deletion sooner |
| Support records | 24 months after ticket closure; unnecessary support attachments are deleted within 90 days after closure |
| User account and profile | While the account is active; User-specific account information is deleted or de-identified within 30 days after a valid deletion or offboarding request, subject to Customer-controlled record continuity and legal exceptions |
| Authentication/security events and ordinary application logs | Readily accessible for up to 90 days and retained in restricted archives for up to 12 months; incident evidence follows the incident or legal-hold period |
| Customer CRM records, tasks, notes, appointments, and audit history | For the Customer subscription, followed by a 30-day export window; live Customer Data is deleted or de-identified within the following 30 days unless Customer requests earlier deletion or law requires retention |
| Synchronized Gmail/Outlook content | While connection and Customer workflow require it; then under Customer schedule or provider-specific deletion request |
| OAuth tokens and integration credentials | Until disconnect, revocation, account deletion, expiry without renewal, or provider purge; unusable credentials are deleted promptly, and encrypted failed-revocation material is retained for no more than 7 days solely to retry revocation |
| Calendar replicas and sync metadata | While connected; provider replicas and sync-only metadata are deleted within 30 days after disconnect, while business appointment history follows the Customer-record schedule |
| Call recordings | Only if enabled and lawfully disclosed; 30 days after the call unless Customer selects a shorter period or a documented legal hold applies |
| Call transcripts, call events, and derived CRM facts | The Customer-record schedule: subscription term, 30-day export window, then deletion or de-identification within 30 days, unless Customer or law requires another documented period |
| Raw-audio and STT diagnostic audit samples | Disabled by default; if specifically enabled for diagnosis, no more than 7 days with purpose-bound access |
| Attachments and stored files | The same period as the authorized parent record; rejected, blocked, orphaned, or quarantined files are deleted within 30 days unless retained as documented security evidence |
| AI prompts, Output, and model trace metadata stored by Suivo | The same period as the owning record; separate diagnostic copies containing content are retained no more than 30 days, and provider-side retention is governed separately by the applicable provider contract and configuration |
| Push tokens | Until logout, invalidation, User deletion, or 180 days without successful use, whichever occurs first |
| Notification delivery and transactional-email evidence | 12 months for delivery reconciliation, suppression, security, and complaint handling |
| Internal do-not-call and communication suppression records | At least 3 years and 14 days after the request, and longer where necessary to continue honouring it; suppression is not erased merely because marketing records are deleted |
| Privacy requests and complaints | Substantive request and response records for 3 years after closure; unnecessary identity-verification documents are deleted within 90 days after verification or closure |
| Québec confidentiality-incident register | At least five years after Suivo learns of the incident |
| Backups | Overwritten on a 35-day cycle; restored data is re-subjected to active deletion and suppression records before ordinary use |
We may retain information longer when required by law, court order, legal hold, regulator, taxation, accounting, insurance, security, fraud prevention, professional recordkeeping, or to establish or defend claims. Access during extended retention is restricted to the retention purpose.
Deleting live information may not immediately remove it from encrypted, access-restricted backups. Backup copies are not returned to active use except for recovery and are overwritten on the approved cycle.
16. Account deletion and Customer offboarding
16.1 Deleting an individual User
The reviewed application provides an authenticated individual account-deletion route. It is designed to remove the local User, profile, routing profile, push tokens, read state, mailbox connections, Gmail message payloads owned through the User's Gmail mailbox, and User-authored internal messages, and to request deletion from the identity provider where configured.
Customer-controlled contacts, opportunities, tasks, active work, voice sessions, and thread ownership may be reassigned to another Team Manager for continuity. If no replacement Team Manager exists where required, deletion may be blocked until the Customer appoints one. Historical assignment and audit evidence may remain.
Deleting an individual User is therefore not the same as deleting the Customer organization or every business record the User worked on.
16.2 Leaving a team
Leaving a team removes the User's membership through a related offboarding flow but does not necessarily delete the identity-provider account. Customer-controlled work may be reassigned and retained.
16.3 Terminating a Customer organization
Customer offboarding, export, and deletion follow the applicable Order, DPA, approved retention schedule, legal holds, and professional recordkeeping responsibilities. Customer should export required records before access ends. Not every provider payload, internal security record, model trace, or system field is part of a standard export.
17. Security safeguards
We use administrative, technical, and organizational safeguards designed for the sensitivity and context of the information, including:
- encrypted transport for supported production connections;
- managed encryption at rest and field-level AES-256-GCM envelope encryption for selected raw content and credentials;
- production key management through Google Cloud KMS;
- authenticated access, scoped OAuth, roles, team scoping, record authority, and PostgreSQL row-level security;
- purpose-specific runtime identities and deployment checks;
- malware quarantine and scanning for supported attachments;
- sanitization and isolation of untrusted email HTML and default blocking of remote images;
- bounded provider calls, idempotency, retry controls, use-time authorization, and stale-work protection;
- webhook verification for supported providers;
- logging, monitoring, audit evidence, and incident response; and
- testing and review of security-sensitive changes.
No safeguard is perfect. Users must protect devices and credentials, use multifactor authentication where available, and report suspected unauthorized access promptly. More detail is available on the Security page.
18. Confidentiality incidents
If Suivo has reason to believe a confidentiality or security incident involving personal information occurred, we will take reasonable steps to contain it, reduce harm, investigate, remediate, preserve required evidence, and prevent recurrence.
We will assess the sensitivity of the information, foreseeable consequences, and probability of harmful use. We will notify affected individuals, Customers, the Commission d'accès à l'information du Québec, the Office of the Privacy Commissioner of Canada, or other authorities when required by law or contract.
We maintain a confidentiality-incident register for the period required by law. Notice may be delayed or limited when law enforcement, a regulator, security needs, or incomplete facts require it.
19. Your privacy rights
Depending on the law and Suivo's role, you may have the right to:
- know whether we hold personal information about you;
- access that information and information about its use and disclosure;
- correct inaccurate, incomplete, or ambiguous information;
- withdraw consent, subject to legal or contractual restrictions and reasonable notice;
- request deletion or destruction where retention is no longer lawful or necessary;
- request that dissemination stop or that a link be de-indexed or re-indexed where legal conditions are met;
- receive computerized personal information collected from you in a structured, commonly used technological format and request transfer to an authorized person where legally required and practically possible;
- obtain information and make observations about a decision based exclusively on automated processing where applicable;
- object to or opt out of non-essential communications or processing; and
- challenge compliance and make a complaint without retaliation.
Rights are not absolute. Access or deletion may be limited to protect another person, preserve legal privilege, comply with law, maintain suppression, prevent fraud, honour a legal hold, protect security, or preserve Customer-controlled regulated records.
20. How to make a request
Send a written request to <contact@suivo.ca> and include:
- your name and contact information;
- the Customer or team connected to the record, if known;
- the right you want to exercise;
- enough information to locate the record; and
- your preferred language and response method.
Do not email a password, OAuth token, government identifier, or unnecessary sensitive document. We may request proportionate identity and authority verification. An authorized representative must provide proof of authority.
If a Customer controls the record, we may refer the request to that Customer or need its instructions. We will respond within the period required by applicable law, explain any lawful refusal, and provide information about available review or complaint procedures.
21. Choices and controls
Depending on the feature, Users may:
- disconnect Gmail, Outlook, Google Calendar, or Microsoft Calendar;
- use the separate Gmail Google-data deletion control;
- delete an individual Suivo account, subject to Customer continuity rules;
- remove a push token or change notification preferences;
- decline microphone, photo-library, or notification permissions in device settings;
- avoid loading remote email images;
- choose whether to invoke a draft, dictation, attachment, calendar, or other optional feature;
- ask a Customer to correct, suppress, or delete a contact record; and
- unsubscribe or request no further email, text, or calls.
Withdrawing consent may prevent a feature from working. We may retain minimal suppression evidence to ensure the person is not contacted again.
22. Complaints and regulators
Contact the Privacy Officer first so we can investigate and respond. If you are not satisfied, you may have the right to complain to:
- the Commission d'accès à l'information du Québec;
- the Office of the Privacy Commissioner of Canada; or
- another privacy, consumer, telecommunications, or professional regulator with jurisdiction.
This Policy does not limit a right to contact a regulator.
23. Children and minors
Suivo accounts are for adults using the Services for business. We do not knowingly allow anyone under 18 to create an account.
Customer records may incidentally refer to a minor—for example, a household member or property occupant. Customers must avoid collecting unnecessary information about minors and must obtain consent from a parent, guardian, or other authorized person where required. Do not use Suivo to build profiles of children or market directly to them.
If you believe a child created an account or unnecessary information about a child was submitted, contact <contact@suivo.ca>.
24. Changes to this Policy
We may update this Policy when our practices, providers, Services, or legal requirements change. We will post the new date and provide additional notice when a change is material.
Where required, we will obtain new consent before using personal information for a materially new purpose or disclosing it to a new category of recipient. For Google API data, we will update the disclosure and obtain the User consent required by Google's policy before a new use.
We retain prior versions of this Policy so that Customers and Users can identify the terms that applied at a particular time. Until a public version archive is available, a prior version may be requested at <contact@suivo.ca>.
25. Contact us
Suivo Technologies Inc.
Federal corporation number: 1001698079
Québec enterprise number (NEQ): Pending
Attn: Privacy Officer — Person Responsible for the Protection of Personal Information
Email: <contact@suivo.ca>
Website: https://suivo.ca