Personal information governance
Version 2026-09-10.1 · 2026-09-10
Keep a copy. Agreement acceptance, acknowledgment of this notice and optional processing choices are recorded separately.
Scope and responsibility
This notice describes Preuve en main and Case in Hand. Contact the person responsible for privacy at vieprivee@preuveenmain.ca, or use equipe@preuveenmain.ca if delivery fails. Postal contact: Preuve en main / Case in Hand · 6801, route Transcanadienne, Pointe-Claire (Québec), Canada H9R 5J2 · +1 514-695-1610 · equipe@preuveenmain.ca. This notice is information about processing, not an unlimited consent or a release from our duties. Optional processing choices are separate from the service agreement.
Local records and accounts
Drafts, case notes and evidence are stored in your browser. Someone with access to your device or browser profile may read them. Clearing browser storage can remove them. Account creation transmits your email, chosen username, password for hashing, and agreement choices. The server stores a salted password hash, account dates, email-verification state, device-bound sessions and subscription state. A password is not stored in readable form. Existing accounts may already have synchronized records from earlier versions.
Optional case-text synchronization
If you enable synchronization in Agreement & data controls, case text, names, dates, case type, notes, and document drafts may be uploaded to Cloudflare Workers KV so that you can retrieve them on another device. This content is readable by the server; it is not end-to-end encrypted. It may contain sensitive family, health, financial or legal information about you and others. The encrypted evidence vault is separate. Declining synchronization keeps new case text local and does not prevent account or billing use. Disabling it stops new uploads; it does not delete existing server copies. Request deletion separately, or delete the relevant synchronized cases. Account access lets you retrieve previously uploaded material.
Evidence vault, transcription and document export
Vault: when you request backup, files are encrypted in your browser before upload to Cloudflare R2, with a passphrase that is not sent to us. We receive encrypted bytes, size, technical identifiers, account association and upload dates. Loss of the passphrase can make recovery impossible. Transcription: selected audio and language/context are sent to Cloudflare Workers AI to return a draft transcript. Studio: selected document text and formatting fields are sent to our Cloudflare Worker to render the requested file. Our application does not intentionally persist those raw processing requests or generated output; drafts may still be synchronized if you enabled synchronization. Infrastructure processing and retention follow provider arrangements; we do not promise that no provider logs exist or that every copy disappears instantaneously. Review the separate confirmation before each processing request.
Payments, support and optional audience measurement
Stripe receives card and billing details directly; we receive order references, product, amount, currency and billing state, without full card numbers. Support and pricing-assistance forms send contact details and the message to our internal records and email services. Assistance is discretionary after individual review, with no guaranteed discount; do not send sensitive evidence. Optional audience measurement counts daily page views only by Canadian or US site, without page paths, referrers, clicks, visitor IDs, device IDs or case content. It is off unless you choose it, the essential-only choice is equally available, its local preference lasts 180 days, and daily totals expire after 90 days. Essential hosting and security requests still process IP addresses, URLs, browser information and errors. Optional analytics and necessary security processing are different systems. Newsletter and testimonial choices are separate.
Agreement evidence and authorized access
We keep separate records of affirmative agreement and processing choices: account identifier, document version and SHA-256 digests, language, server timestamp, purpose, checkbox assertions and receipt ID. We do not include case text, password, raw IP address or browser fingerprint in those receipts. Authorized administrators can view account and acceptance records through protected controls; administrative access is logged. Administrative screens do not display synchronized case content, but technical access to readable server data remains possible for authorized operational work. Receipts demonstrate an action associated with a session; they are not proof of identity, comprehension or a legal waiver.
Recipients and international processing
Cloudflare provides hosting, security, KV, R2 and AI processing; Stripe processes payments; the configured transactional email service delivers messages. Google receives information if Google sign-in is enabled and chosen. Data can be processed outside Québec, Canada or your US state, including in the United States, and can be subject to lawful access there. We do not promise exclusive Canadian or US storage. We limit disclosures to requested services, necessary operations and legally required purposes. We do not use case content for advertising, sell it, or give ourselves permission to train models on it. Provider contractual protections and transfer assessments must support each enabled flow.
Business contacts and correspondence
For professional outreach and support, our restricted CRM can hold business contact details, public sources and evidence of contact eligibility, message drafts, sent messages, replies, assistance requests and staff notes. These records are removed after 24 months without an update; suppression records are retained to honor refusals. When configured, a dedicated Gmail business mailbox sends approved messages and retrieves replies to tracked conversations. Brave Search can discover public business sources; optional Cloudflare Workers AI can draft messages or summarize public sources for human review. These functions do not authorize uploading user case files to the outreach tools. We use no email tracking pixels. A publicly listed address is not blanket permission for marketing. Refuse further outreach through the unsubscribe method or by contacting equipe@preuveenmain.ca. We respect applicable consent, identification and opt-out requirements.
Retention and deletion
Local data remains until you delete it or your browser removes it. Accounts, synchronized cases and encrypted files remain until removed or a closure request is completed; no unimplemented automatic inactivity purge is promised. Sessions expire after 30 days; rate-limit and security counters use shorter technical expiry periods. Administrative access logs expire after one year. Acceptance and withdrawal receipts are retained while the account exists to evidence the current and prior choices. At closure we review and remove records no longer needed; limited transaction, fraud, legal-hold or dispute records may need longer retention under applicable law. Stripe, mail and infrastructure retention may differ. Ask us for the applicable retention and deletion status for your request. Deleting a local copy, cancelling billing and deleting server data are different actions.
Your choices and privacy rights
Use Agreement & data controls to inspect your acceptance receipts and switch case-text synchronization off or on. For access, correction, a portable copy, deletion, account closure, withdrawal of consent or a complaint, email vieprivee@preuveenmain.ca. Requests are free; we use proportionate verification and do not ask for unnecessary identity documents. We target a response within 30 days, or the applicable legal deadline, and explain lawful exceptions or extensions. Withdrawal applies prospectively and does not erase a previous lawful processing action. If a requested feature needs the processing, withdrawal stops that feature. Québec residents may complain to the Commission d’accès à l’information; other Canadians may contact their provincial commissioner or the Office of the Privacy Commissioner of Canada as applicable. US residents may have rights to know/access, correct, delete, obtain a copy, opt out of sale/sharing/targeted advertising and appeal a denial, depending on the statute and its applicability. Send an appeal to the same privacy contact with “Privacy appeal” in the subject; we provide a reasoned response and available regulator route within the applicable deadline. We do not penalize lawful rights requests.
Sensitive information, children and security incidents
This service is for adults of legal majority, not for children to create accounts. If you believe a child has provided account information, contact us so we can address it. A user’s own agreement does not supply permission for all information about other people. Do not upload unnecessary health records, identification numbers or privileged information. We do not make solely automated decisions about your legal rights, score you, or predict court outcomes; AI output is a draft for human review. No security measure is absolute. We investigate privacy incidents and give affected people and authorities notices when applicable law requires them. We publish material changes with a new version and request a new choice when required.
Newsletter records, connected mail and older records
Newsletter subscription and consent evidence is kept in the newsletter register independently of the CRM. Unsubscribing stops promotional use; a limited refusal/consent record may remain to demonstrate and honor the choice. A connected business Gmail mailbox’s authorization credentials remain stored until the operator disconnects it; Gmail mailbox messages follow the mailbox’s own retention settings, so removing a CRM copy does not itself erase the mailbox. Older analytics counters from the previous system can remain until their former expiry of up to 400 days, unless removed sooner. Older support/testimonial/report copies not yet migrated may also require cleanup; migrated non-newsletter source copies receive a 730-day expiry. We distinguish this transition from the new 90-day aggregate analytics and 24-month CRM policies, and will assess legacy copies when handling deletion requests.