Privacy Policy

This policy applies during your usage of the platform, and data-handling practices may be refined as the service matures.


Version 2026-07-21-tac-v5-priv-v4-aigov-v3-aup-v3

Material changes are versioned and the version you accepted is recorded as you log into your account. See Terms and Conditions Section 1.1.


1. Who we are

SignaVision Solutions Inc. (“SignaVision”, “we”, “us”, or “our”) operates the servers and computing &. distribution topology for special interest purposes and development including   RAG and associated governed retrieval infrastructure.
Jurisdiction : Ontario, Canada
Privacy inquiries and data requests may be directed to:   privacy@signavision.ca.

2. Data we collect


2.1 Account information

We collect and maintain account information necessary to operate the service, including:
  • email address.
  • display name or account identifier.
  • hashed password credentials.
  • account creation timestamps.
  • last-login and authentication metadata.
  • tier and tenant admission status.
  • Passwords are stored only as salted cryptographic hashes and are never stored in plain text.

2.2 Tenant and Tier Metadata For AI / LLM

We maintain governance metadata relating to tenant and tier structure,including:
  • tenant identifiers and slugs.
  • default and assigned tiers.
  • tier-governance requests and decision history.
  • organization and seat membership relationships.
  • tenant life cycle events.
  • governance restrictions, archival state, and tier status metadata.
This metadata is used solely for sovereignty enforcement, governance operations, retrieval scoping, operational integrity, and audibility.

2.3 Uploaded content

Users may upload documents and files for admission into tenant-scoped semantic occupancy which uploading files will pass through an admission gate which may include:
  • quarantine processing.
  • file-type verification.
  • MIME validation.
  • malware scanning (including ClamAV or equivalent tooling).
  • structural integrity checks
  • governance admissibility checks.
Files that successfully pass admission may be transformed into derived semantic occupancy, including extracted text, chunks, embeddings, provenance metadata, and retrieval artifacts. Uploaded content is scoped to the tenant and tier into which it was admitted and is not made cross-tenant accessible.

2.4 Chat and retrieval

We store conversational prompts, retrieval context, generated answers,citation metadata, and retrieval traces necessary to operate the service and maintain governance integrity. Retrieval operations are scoped to the tenant and tier associated with the authenticated session.

2.5 Operational logs

The platform maintains operational and governance logs including:
  • admission provenance records.
  • timestamps.
  • SHA-256 file hashes.
  • MIME and
  • scanner verdicts.
  • retrieval traces.
  • error and stability logs.
  • governance events.
Operational logs are retained only for governance, security, audibility, abuse prevention, debugging, and platform integrity purposes.

3. What We Collect Legally

We collect and process data for the following purposes:
  • to provide and operate the service.
  • to authenticate users and enforce tenant sovereignty.
  • to maintain platform security and governance integrity.
  • to process retrieval and reasoning operations requested by users.
  • to improve operational reliability and platform safety.
  • to comply with legal obligations.
  • Depending on the context, processing is performed on the basis of performance of a contract.
  • legitimate operational and security interests.
  • user consent where required by law.

4. Where Data Lives

Platform infrastructure is operated through internally segmented systems and sovereign processing boundaries. Public access to the platform is mediated through externally exposed gateway infrastructure. Internal reasoning, semantic occupancy, and governance systems operate on segmented infrastructure layers that are not directly publicly accessible.

4.1 What Are Being Used

Certain platform functions may operate across internally connected infrastructure nodes responsible for:
  • semantic occupancy and embeddings.
  • retrieval and reasoning.
  • governance and observability.
  • authentication and public ingress.
Primary infrastructure is currently operated in Canada unless otherwise disclosed.

5. Data Storage and Data Life Cycles

Platform infrastructure is operated through internally segmented systems and sovereign processing boundaries. Public access to the platform is mediated through externally exposed gateway infrastructure. Internal reasoning, semantic occupancy, and governance systems operate on segmented infrastructure layers that are not directly publicly accessible.

5.1 Uploaded files

Uploaded files are retained only for the duration reasonably necessary to:
  • complete admission processing.
  • verify extraction integrity.
  • create semantic occupancy.
  • support short-term operational recovery and validation.
Once extraction and occupancy generation complete successfully, the original uploaded file may be deleted while derived occupancy, embeddings, provenance metadata, and governance records remain subject to this policy. Files rejected by the admission gate are destroyed immediately and do not enter semantic occupancy. Only provenance metadata relating to the rejection event is retained...Deleted files or retired occupancy may temporarily persist within encrypted backups, disaster recovery systems, or immutable governance archives until those systems cycle through their normal retention schedules.

5.2 Tier Archives

A tier may be archived or terminated as part of governance life cycle management.
Archived tiers remain in a read-only state and may preserve:
  • chat history.
  • retrieval lineage.
  • governance trails.
  • occupancy references.
  • historical provenance metadata.
Archived tiers do not permit new admissions or active retrieval operations. Terminated tiers may enter governance retirement procedures resulting in occupancy tombstoning, retrieval revocation, and eventual retirement of associated corpora subject to applicable retention requirements.

5.3 Tenant termination

Upon account closure or tenant termination:
  • retrieval access is revoked.
  • active tiers may be archived or retired.
  • users may request export of eligible uploaded content during a 30-day export window.
  • occupancy retirement and governance tombstoning procedures may begin.
Unless retention is required by law, dispute preservation, fraud prevention,security investigation, or regulatory obligation, personal data is scheduled for deletion within 30 days after the export window closes.

5.4 Audibility

Certain governance records may survive termination for limited operational and lawful purposes, including:
  • audit trails.
  • governance lineage.
  • security and abuse-prevention records.
  • legal-compliance records.
  • retrieval provenance metadata.
Governance and security records may be retained for up to 24 months where reasonably necessary for platform integrity, lawful compliance, dispute resolution, or abuse prevention.

5.5 Provenance And Observability Discoveries

The platform maintains provenance and observability traces for governance,security, audibility, operational integrity, abuse prevention, and lawful compliance purposes.
These records may include:
  • admission provenance logs.
  • scanner verdicts.
  • retrieval traces.
  • governance events.
  • aggregated operational telemetry.
  • anonymity observability metrics.
Aggregated or anonymity metrics that no longer identify an individual or tenant may be retained beyond personal-data deletion timelines. Certain records may also be retained where required by legal hold, dispute preservation, fraud prevention, or regulatory obligation.

5.6 Deletion Mechanics

Deletion requests may be initiated through in-portal governance controls where available or by contacting to   privacy@signavision.ca. We may require reasonable verification of account ownership or tenant authority before processing deletion requests.
Deletion requests are processed within a commercially reasonable timeframe,subject to:
  • governance propagation.
  • backup-retention cycles.
  • security or fraud-prevention obligations.
  • legal or regulatory holds.
Deletion of occupancy is implemented through governance supersession and tombstoning rather than silent mutation of historical provenance records.

6. Your Rights

Subject to applicable law, users may have rights relating to their personal information, including:
  • the right to access personal information we hold about them.
  • the right to request correction of inaccurate information.
  • the right to request deletion of certain personal information.
  • the right to request export or portability of eligible data.
  • the right to object to or restrict certain processing activities where applicable.
  • the right to withdraw consent where processing is based on consent.
  • Users may also have the right to submit complaints to the Office of the Privacy Commissioner of Canada (OPC) or applicable provincial privacy regulators.
Certain rights may be limited where retention is required for governance integrity, legal compliance, fraud prevention, security investigation, dispute resolution, or operational audibility.

7. Sharing and Processors

We do not sell personal data and do not share tenant occupancy across tenants.
Limited third-party processors may be used for infrastructure operations such as:
  • mail delivery.
  • DNS and TLS services.
  • hosting infrastructure.
  • security and abuse prevention.
Processors receive only the minimum data necessary to perform their operational function and are subject to confidentiality and security obligations where applicable.

8. Security

We implement layered security controls designed to support sovereign tenant isolation and governed retrieval operations, including:
  • TLS encryption for external traffic.
  • segmented internal infrastructure.
  • WireGuard-protected internal service communication where applicable.
  • admission-gate quarantine and malware scanning.
  • tenant-scoped retrieval boundaries.
  • authentication and governance enforcement.
  • retrieval provenance and citation grounding mechanisms.
No system can be guaranteed perfectly secure. Users remain responsible for safeguarding account credentials and maintaining endpoint security on their own devices.

9. Cookies

  • The platform primarily uses essential session.
  • The platform will use sessions to track all users usages.
  • The platform primarily uses essential session and security cookies, including authentication and CSRF-protection cookies.

10. Children Under 13 Years Old

The service is not directed toward children under the age of 13 without institutional or parental authorization where required by applicable law. We do not knowingly collect personal information from children except where access is provided through an authorized educational, institutional, organizational relationship.

11. On-Going Updating To All Policies

We may update this policy and other policies. Material changes are versioned. The version in effect when you login into your account as recorded.

12. Contact Information

Privacy inquiries and data requests may be directed to   admin@signavision.ca .

Privacy Policy   ⚙️   Terms & Conditions   ⚙️   Acceptance of Use   ⚙️   Governance