1. Scope
This Privacy Policy applies to personal information processed by Palvexa Technologies (“Palvexa,” “we,” “us”) through our website, dashboards, business communications, support activities and technology services, including automated reception, telephony, messaging, appointment, integration and artificial-intelligence solutions.
When Palvexa processes personal information on behalf of a business customer, that customer generally determines the purposes and instructions for the processing. In that context, some requests should be directed to the business with which you have a relationship.
2. Information we may collect
Depending on your relationship with Palvexa and the features used, we may process:
- Professional identity and contact information: name, title, organization, email address, telephone number and communication language.
- Account information: credentials, settings, roles, access history and authentication-related information.
- Business and operational information: locations, operating hours, services, calendars, availability, routing rules, preferences and work instructions.
- Calls and communications: telephone numbers, date, time, duration, metadata, recordings where permitted, transcripts, summaries, messages, requests, appointments and interaction outcomes.
- Our customers’ end-customer information: contact details, service requests, appointment details and other information provided during an interaction with a Palvexa-powered system.
- Billing information: payment status, amounts, taxes and transaction identifiers. Full card details are normally processed directly by our payment provider.
- Support and security information: support requests, technical logs, IP address, device and browser information, security events and diagnostics.
- Information submitted voluntarily: content sent through email, forms, calls, demonstrations, meetings or other channels.
- Public-site usage data: aggregate technical events such as a page visit, approximate scroll progress, contact-form visibility or submission state, and a general device category. This mechanism is not designed to receive names, email addresses, company names or contact-request content.
3. Sources
We may collect information directly from you, your employer or organization, a Palvexa customer, a system integrated at the customer’s request, technology providers, or automatically when our websites and services are used.
4. Purposes
We use personal information only for identified and reasonable purposes, including to:
- provide, configure, secure and improve our services;
- answer calls and messages, respond to requests and route information;
- book, modify or cancel appointments and perform requested automations;
- manage accounts, authentication, billing and support;
- detect errors, abuse, security incidents and fraud;
- evaluate system quality and reliability, subject to applicable settings and agreements;
- measure aggregate public-site usage and the reliability of the contact journey;
- meet legal, regulatory, contractual and accounting obligations; and
- communicate about our services where permitted by law.
We do not reuse personal information for an incompatible new purpose without obtaining required consent or relying on another basis permitted by law.
5. Consent and choices
We obtain consent where required. Consent may be provided by you, by the business customer responsible for the interaction, or by another authorized person. You may withdraw consent where permitted by law, subject to reasonable consequences and our legal or contractual obligations.
Business customers are responsible for ensuring that they have the notices, authority and consents required for the information they ask us to process, including requirements related to call recording, automated communications and artificial-intelligence systems.
6. Providers and disclosures
We may disclose information to providers that help operate our services, including hosting, security, authentication, database, telephony, messaging, artificial intelligence, payment, email, monitoring and support providers. They may process information only for agreed services and subject to applicable protections.
Depending on enabled features, providers may include Cloudflare, Supabase, Neon, Telnyx, Vapi, OpenAI, Anthropic, Stripe, Google and Resend. This list may evolve without changing the nature of the purposes described in this policy.
We may also disclose information where required by law, to protect the rights or safety of Palvexa or others, as part of a properly managed business transaction, or with your consent. We do not sell personal information.
7. Processing outside Québec
Some providers and systems may process or store information outside Québec or Canada. Information may then be subject to the laws of the relevant jurisdiction. Before communicating information outside Québec, Palvexa evaluates relevant factors and applies contractual, organizational and technical measures proportionate to the risk.
8. Retention and disposal
We retain information only as long as needed for the purposes described, customer requirements and legal, security, evidentiary and billing obligations. Retention periods vary by information category, sensitivity and service. When no longer required, information is reasonably deleted, destroyed or anonymized, subject to backups and applicable obligations.
9. Security
We use administrative, technical and physical safeguards proportionate to the sensitivity of the information, including access controls, authentication, encryption where appropriate, logging, environment separation, least-privilege controls and incident-management procedures. No system is completely risk-free, so we cannot guarantee absolute security.
10. Cookies, logs and similar technologies
The public website does not use advertising cookies or a persistent identifier for its traffic measurements. It may send first-party aggregate events such as a page visit, approximate scroll progress, contact-form visibility, and the technical success or failure of a submission. Names, email addresses, company names, request content and advertising identifiers are not intentionally sent to this measurement mechanism.
Our hosting and security systems may still process essential technical logs such as IP address, date, requested resource and browser information to deliver the site and prevent abuse. Dashboards may use cookies or local storage strictly necessary for authentication and operation.
If we add non-essential technologies that enable identification, location, profiling or advertising, we will update this policy and implement required choices or consent before activating them.
11. Your rights
Depending on applicable law and subject to exceptions, you may request access, correction, information about use and disclosure, withdrawal of consent where possible, deletion or de-indexation where legally available, or submit a question or complaint about our practices.
We may need to verify your identity. When information is processed for a business customer, we may forward the request to that customer or ask you to contact it directly.
12. Minors
Our services are intended for businesses and are not designed for children under 14. We do not knowingly seek to collect their information directly without required authorization.
13. Changes
We may update this policy to reflect changes to our services, providers or laws. The updated date will appear at the top. Where required, we will provide appropriate notice of material changes.
14. Privacy Officer and contact
Privacy Officer
Executive Management, Palvexa Technologies
Québec, Canada
[email protected]
Please use “Privacy request” in the subject line and provide enough detail for us to process your request.