Privacy Policy
Last updated: September 11, 2026(view August 2026)
This document is published in French and in English. In case of any discrepancy between the two versions, the French version prevails.
Introduction
This privacy policy of 9553-6785 Québec Inc. (“Meo”, “we”) describes how Meo collects, uses, discloses, retains and protects personal information through its website and software. It applies to the activities described below, subject to applicable Canadian privacy laws.
For the purposes of this policy, personal information is any information that makes it possible to identify a person, directly or indirectly. When Meo processes information about visitors, prospects or account holders for its own activities, Meo determines the purposes of that processing. When a customer uploads or manages information in Meo about its own clients, employees or other individuals, that customer determines the purposes of the processing and Meo processes the information on its instructions and under our Data Processing Agreement. This policy does not describe each customer's own privacy practices.
Effective date: September 11, 2026
1. Privacy officer
We have designated a privacy officer. If you have questions about how we handle your personal information, or if you wish to exercise your rights, you may contact our privacy officer:
2. What personal information do we collect?
We may collect personal information directly from you, automatically when you use our Services, or from a customer that uses Meo to manage information on its own instructions, including through:
- Creating an account in the software
- Documents, forms and records that a customer uploads or manages in Meo
- Booking an appointment through our website
- The contact form and support exchanges, including through Intercom
- The exposure calculator, our privacy-practice assessments and related report requests
- Cookies, pixels and similar technologies used on the website
Types of information collected:
- Account information: Name, email address, phone number, company
- Customer-managed content: Documents, forms and other personal information that a customer uploads or manages in Meo
- Requests and assessments: Email address, sector, answers, results, representative client count, and operational indicators supplied or calculated through our tools
- Payment information: Processed by Stripe. We do not store your credit card data
- Technical and usage data: IP address, browser, operating system, pages visited, referral source, date and time, usage events, cookie or device identifiers, and consent choices
- Communications: Name, contact details and content of contact, sales or support requests and emails
3. Why do we collect your information?
We collect and use your personal information solely for the following purposes:
| Purpose | Information used |
|---|---|
| Provide and improve our Services | Account information, customer-managed content, technical and usage data |
| Create and manage your account | Name, email, phone, company |
| Produce and send requested reports | Email, sector, answers and results from calculators and assessments |
| Respond to contact, sales and support requests | Name, contact details, company and content of the request |
| Manage prospects and provide requested follow-up | Contact details, sector, request source, results and communication preferences |
| Measure website use and the effectiveness of our communications | Technical data, usage events and identifiers, according to your consent choices |
| Maintain performance and security and prevent abuse | IP address, technical browsing data and automated verification signals |
| Billing and payment processing | Payment information (via Stripe) |
| Meet our legal obligations | Data required under applicable law |
4. Consent
We seek valid consent where required by law. The form of consent depends on factors including the sensitivity of the information, reasonable expectations and the context. Certain processing necessary to provide the Services, maintain security, process billing, or otherwise permitted or required by law may occur without separate express consent. Using the Services is not blanket consent to every activity described in this policy.
Withdrawal of consent: Where processing is based on your consent, you may withdraw it for future activities by contacting us at conformite@documeo.ca, subject to applicable legal or contractual restrictions and reasonable notice. Withdrawal may limit or prevent the delivery of certain Services.
Minors: Our Services are not intended for persons under 14 years of age. Where applicable law requires consent or authorization from a parent or guardian, the person providing the information must obtain it.
5. Retention of your personal information
We retain your personal information only for the period necessary for the purposes for which it was collected, or as required or permitted by law.
| Situation | Retention period |
|---|---|
| Active account | For the entire duration of your subscription |
| After a deletion request | Deleted within 60 days |
| Backups | Purged within 90 days following deletion |
| Requests, communications and assessment data | For the time needed to respond, provide the report, deliver requested follow-up and meet our obligations, then deleted or anonymized under our retention schedule |
| Legal and billing documents | Retained in accordance with applicable legal requirements |
6. Who has access to your personal information?
Access to your personal information is strictly limited to authorized personnel of 9553-6785 Québec Inc. who need it to carry out their duties. We apply the principle of least privilege: each person has access only to the data necessary to carry out their responsibilities.
We do not sell your personal information. Any disclosure to analytics or advertising providers is limited to the purposes, technical measures, and consent choices described in this policy.
We may disclose your personal information in the following circumstances:
- Vendors: Our service providers (see section 8) who help us deliver the Services, subject to applicable contractual terms and safeguards.
- Analytics and advertising: Providers may receive technical, usage or attribution data as described in section 10, including according to your consent choices where consent is required.
- Authorities: Where the law requires it, for example to respond to subpoenas, warrants or court orders.
- Business transactions: In the event of an acquisition, reorganization or financing of our business, in compliance with applicable laws.
7. Processing locations and transfers
Documents managed by our customers and primary account data are stored in Canada, in the AWS Canada (Central) region (ca-central-1).
Some of our providers (see section 8) may process personal information elsewhere in Canada or outside Canada, including in the United States. When a transfer is considered:
- We put in place appropriate contractual and security measures based on the service and information involved. See our Data Processing Agreement
- We assess the nature and sensitivity of the information, the purpose, destination and safeguards, and carry out a privacy impact assessment where required by law
- Information processed in another jurisdiction may be subject to that jurisdiction's laws and legally valid access requests
To keep our services secure, web requests pass through Cloudflare, a global security network. Cloudflare may process requests at points of presence in North America before routing them to our primary infrastructure in Canada. All data remains encrypted in transit (TLS 1.3).
To see our practices, the controls we have in place, and to submit a privacy request, visit our public privacy portal.
8. Our vendors
The following principal providers may process limited personal information to help us deliver, secure, support and measure our Services. We limit disclosed information to what is needed for their function and apply appropriate contractual or security measures based on the context.
| Category | Provider | Region | Purpose |
|---|---|---|---|
| Hosting | AWS | Canada (Central) | Data storage and deployment |
| Database | Supabase | Canada (Montreal) | Database and authentication |
| Payments | Stripe | Outside Canada | Payment processing (not stored by us) |
| Postmark | Outside Canada | Transactional emails and requested reports | |
| Security | Cloudflare and Turnstile | Global (transit) | Firewall, DDoS protection, content delivery and automated abuse prevention |
| Content delivery | Google Fonts | Global | Loading web fonts |
| Content delivery | jsDelivr | Global | Loading the Lenis interface library |
| Analytics | PostHog | United States | Website use and journey measurement |
| Analytics | Google Analytics | Global | Audience and performance measurement |
| Advertising | Meta | Global | Advertising measurement and attribution, with marketing consent |
| Lead management | ActiveCampaign | Outside Canada | Requested reports and related follow-up, with unsubscribe controls |
| Support | Intercom | Outside Canada | Contact form and support communications |
| Integration | Google (Google Tasks API) | Global | Optional task synchronization, enabled by the user |
Providers and their processing locations may change. More detailed documentation about our security measures and providers is available on request.
Google Tasks connection (optional)
If you connect your Google account to Meo, we access your Google Tasks lists and tasks through the Google Tasks API for the sole purpose of synchronizing tasks you already have in Meo. Meo creates a list named Meo in your account, adds your open tasks to it, updates their title, due date and status, and brings back the completion state you change on the Google side. Meo does not read your other lists for any other purpose, creates no calendar events, and shares no Google data with third parties.
The authorization token is stored encrypted in our database hosted in Canada and is never sent to your browser. You can disconnect at any time under Settings, Account, Integrations. Meo then revokes the authorization with Google and deletes the token along with the identifiers that map your Meo tasks to your Google tasks.
Meo’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
9. Your privacy rights
Depending on the applicable law and context, you may have the following rights. Their availability, scope, conditions and exceptions may vary:
| Right | Description |
|---|---|
| Right of access | You have the right to be informed of how we collect, use and disclose your personal information. You also have the right to access the personal information we hold about you. |
| Right to rectification | If you believe that any personal information we hold about you is incorrect or incomplete, you have the right to request that it be corrected. |
| Right to portability | Where provided by law and subject to its conditions, you may request certain eligible personal information in a structured, commonly used technological format, or ask that it be disclosed to another authorized person or organization. |
| Right to withdraw consent | Where processing is based on your consent, you may withdraw it for future activities, subject to applicable legal or contractual restrictions and reasonable notice. |
| Right to erasure | Where applicable law permits, you may request deletion of certain personal information, subject to our legal, contractual, security and retention obligations. |
| Right to de-indexation | Where provided by applicable law and subject to its conditions, you may request that certain information cease to be disseminated or that a hyperlink attached to your name be de-indexed. |
| Right to file a complaint | You may file a complaint with the privacy authority responsible under applicable law. |
How do you exercise your rights?
Send an email to conformite@documeo.ca. We will respond within the period required by applicable law.
10. Cookies and tracking
Our website uses cookies (called “témoins” in French), pixels, local storage and similar technologies to operate the site, protect forms, analyze use and measure the effectiveness of our communications.
These technologies may store or read information on your device, or transmit technical signals such as your IP address, the page viewed, usage events, and browser or device identifiers.
No non-essential cookie is enabled before you make a choice. Persistent analytics cookies and advertising features require your consent. Some providers may receive limited technical signals without placing an analytics cookie, including for security, consent management, and cookieless measurement of pages and events. Meta loads only with marketing consent.
You may change your cookie preferences at any time by clicking the button below or through the “Manage cookies” link in the site footer.
11. Automated decisions
Meo currently uses no fully automated decision-making process that would produce legal or significant effects on the persons concerned.
If we implemented such a process, we would update this policy and provide the information and mechanisms required by applicable law.
12. Data security
We have put in place physical, technical and administrative measures to protect your personal information against destruction, loss, unauthorized modification, disclosure and unauthorized access.
Encryption in transit
All communications are protected by TLS 1.3
Encryption at rest
Stored data is encrypted with AES-256
Access controls
Multi-factor authentication, principle of least privilege
SOC 2 readiness
We are preparing our controls for an independent SOC 2 examination
When we disclose personal information to our providers, we require safeguards appropriate to the nature of the information and the service provided.
13. Notification in the event of a confidentiality incident
We maintain the privacy incident records required by applicable laws and assess each incident against the relevant notification thresholds.
When a notification threshold under applicable law is met:
- We notify the responsible privacy authority within the required period
- We inform affected individuals where required by law
- We communicate the measures taken to reduce the risks and the steps you can take to protect yourself
14. Changes to this policy
We may change this privacy policy from time to time, for example to reflect new laws or changes in the way we handle personal information.
In the event of a significant change, we will inform you by email or through a notice in our software. The last-updated date and, where different, the effective date are shown on this page. Superseded versions remain available in our archives.
15. Contact
For any question about this privacy policy, or to exercise your personal information rights:
Olivier Beaulieu
Privacy officer
Email: conformite@documeo.ca
1779 rue Careau, Québec, Canada, G1M 0C9
If you believe your rights have not been respected, you may file a complaint with the privacy authority responsible under applicable law.