Privacy Policy
VX-N Privacy Policy — how we collect, use, and protect personal information under PIPEDA.
Privacy, on the record.
How VX-N collects, uses, and protects personal information — written plainly, held to Canadian law, and applied to every system we deploy.
Canada · PIPEDA · Effective Feb 22, 2026
VX-N provides custom AI automation and solutions, including AI agents, that help our clients streamline and manage their operations. We operate under Canadian law and are committed to protecting personal information in compliance with the Personal Information Protection and Electronic Documents Act (PIPEDA).
Security · Availability · Processing Integrity · Confidentiality · Privacy
Scope and Our Role
This policy applies to all personal information collected, used, or disclosed by VX-N when providing our AI automation and agent services to our clients and through our websites or business operations. It covers data collected via telephone, SMS, email, chat, documents, CRM integrations, and other channels used to deliver our services.
Controller vs. Processor
Website Visitors & Direct Contacts — VX-N acts as a data controller, determining the purposes and means of processing your personal information.
Services on Behalf of Clients — VX-N acts as a data processor, processing personal information only in accordance with the documented instructions of our client.
Where VX-N acts as a processor, individuals whose data is processed through the services VX-N delivers on behalf of a client should direct their privacy inquiries to that client organization in the first instance.
Definitions
Personal Information — Any factual or subjective information about an identifiable individual, including names, contact details, identification numbers, financial information, opinions, and device identifiers.
Sensitive Personal Information — A subset that warrants heightened protection — government IDs, financial accounts, health data, biometric data. Collected only when strictly necessary, with explicit consent.
Communications Data — Audio recordings, call transcripts, chat and SMS logs, interaction metadata generated through voice, messaging, or communication channels.
Usage Data — Information collected automatically — IP addresses, browser type, pages visited, timestamps, and device identifiers.
Processing — Any operation performed on personal information: collection, use, storage, transmission, analysis, or disposal.
Sub-processor — A third party engaged by VX-N to process personal information in connection with delivering our services.
Control Environment — Documented policies, procedures, and operational practices VX-N maintains to protect personal information.
Personal Information We Collect
VX-N collects personal information only to the extent necessary to provide our services. Not all categories apply in every context.
Identity & Contact — Full legal name; Date of birth; Address (home/mailing); Phone numbers; Email address; Government-issued IDs; SIN (where required)
Business Information — Business name & entity type; Registration/incorporation number; Address & locations; Industry/sector; Years in operation & employees
Financial Information — Annual/monthly revenue; Net income & profitability; Debts, liabilities & credit; Bank account details (verification only); Financial statements
Communications Data — Call recordings & transcripts; Chat & SMS logs; Documents provided; Interaction timestamps & metadata
Application & Service Data — Application details & status; Confirmation & consent records; Notes, assessments & routing decisions
Usage & Technical Data — IP addresses & device IDs; Browser type & OS; Pages accessed & timestamps; Cookies & tracking tech; Diagnostic & performance data
Note on sensitive categories: SINs, government-issued IDs, and bank account details are not collected from website visitors or by default. They are collected only in specific deployments where a client has configured VX-N's services to do so and only where strictly necessary. Express consent is required for any collection of sensitive personal information.
Communications Data and AI Processing
How Communications Data Is Used
To deliver the specific service features configured by our client (e.g., call handling, transcription, document extraction, conversation routing).
To generate interaction logs and audit trails required for compliance and quality assurance.
In aggregated and de-identified form, to monitor and improve the safety, accuracy, and reliability of our services.
Processing Integrity
VX-N is committed to ensuring that Communications Data is processed completely, accurately, in a timely manner, and only as authorized by the applicable client instructions. Our systems are designed to detect processing errors, incomplete transactions, and unauthorized processing events.
AI Model Training
VX-N does not use identifiable personal information or client-specific Communications Data to train, fine-tune, or improve generalized AI or machine learning models without explicit consent.
Shared Responsibility for Consent
Because VX-N operates AI agents directly on behalf of our clients — including conducting calls, sending messages, and engaging with individuals — VX-N and its clients work together to ensure that appropriate notices and consent mechanisms are established prior to deployment.
Purposes for Collection
Inbound Handling — Receiving, routing, and recording inbound calls, messages, and inquiries.
Lead Engagement — Capturing prospect information and re-engaging contacts across channels.
Verification — Verifying identity, confirming terms, and recording consent.
Document Processing — Analysing and extracting information from submitted documents.
Service & Support — Fulfilling contractual obligations and providing customer support.
Audit & Compliance — Maintaining interaction records for quality assurance and audit.
Security — Detecting, preventing, and addressing security incidents and fraud.
Analytics — Aggregated data for improving safety, accuracy, and efficiency.
Legal Compliance — Meeting obligations under applicable law and enforcing agreements.
Legal Bases for Processing
Express consent — Sensitive personal information; marketing communications; secondary or non-obvious uses.
Implied consent — Routine service delivery where collection and use are obvious from the context.
Contractual necessity — Fulfilling obligations under a client service agreement.
Permitted by law — Where legislation permits without consent — legal obligations, investigative authorities, or accuracy requirements.
Consent and Meaningful Consent
We obtain individuals' knowledge and consent for the collection, use, or disclosure of personal information, except where otherwise permitted by law. Our consent process is guided by six principles:
1. Highlight Key Points — Clearly explain what, how, who, and risks.
2. Layered Detail — Basic explanations or full policy details.
3. Clear Choices — Voluntary consent, not tied to other purposes.
4. Innovative Presentation — Modern interfaces and just-in-time notices.
5. Individual's Perspective — Clear, understandable language.
6. Updated Mechanisms — Periodic review and notification of changes.
Individuals may withdraw consent at any time by contacting us at dev@vx-n.com, subject to legal or contractual restrictions.
Disclosure, Sub-processors & Retention
Disclosure
We may disclose personal information:
To our clients, to fulfil service obligations.
To sub-processors under contractual safeguards.
To legal or regulatory authorities when required by law.
In connection with a merger, acquisition, or asset sale.
To protect rights, property, or safety of VX-N, clients, or others.
With your consent, for any other purpose disclosed at collection.
VX-N does not sell, rent, or lease personal information to third parties.
Sub-processors & Vendor Risk
All sub-processors are contractually bound to:
1. Process personal information only for specified purposes under VX-N's instructions;
2. Maintain appropriate technical and organizational safeguards;
3. Notify VX-N promptly of any security incidents; and
4. Not use customer data to train their own AI models without explicit consent.
Clients may request our current sub-processor list by contacting dev@vx-n.com.
Client Responsibilities
Clients are responsible for: managing user access to credentials, ensuring accuracy of instructions, obtaining end-user consents, and notifying VX-N of suspected security incidents.
Retention
Call recordings & transcripts — Contract duration + 12 months — Contract; compliance
Application & service data — Engagement + as required by law — Legal obligation
Interaction & usage logs — Up to 24 months — Internal operations; security
Client & business contacts — Engagement + 3 years — Contract; legal obligation
Incident & audit records — Minimum 5 years — Legal obligation; audit
Cross-Border Transfers
Some service providers and infrastructure are located outside Canada, including in the United States. Before any transfer, we implement contractual safeguards ensuring protection substantially similar to PIPEDA. Transfers are limited to minimum necessary data, encrypted in transit and at rest.
Individuals may contact our Privacy Officer at dev@vx-n.com to understand which jurisdictions their data may flow to.
Security Safeguards
VX-N maintains a formal security program designed to protect the confidentiality, integrity, and availability of personal information.
Risk Management — Periodic assessments to identify threats. Findings inform control priorities.
Access Controls — Least-privilege, role-based permissions, multi-factor authentication.
Physical Security — Restricted physical access to authorized personnel only.
Encryption — In transit and at rest using industry-standard protocols.
Network Monitoring — Segmentation, intrusion detection, continuous security monitoring.
Change Management — Formal process with testing, authorization, and post-deployment review.
Audit Logging — Immutable logs of system access and key processing events.
Business Continuity — Documented availability commitments with disaster recovery procedures.
Confidentiality — Information classified and handled under binding confidentiality obligations.
Vendor Management — Security assessment of sub-processors before engagement.
Personnel Training — Security and privacy awareness training at onboarding and recurring.
Independent Assessment — Third-party vulnerability assessments and penetration testing.
No method of transmission over the internet or electronic storage is 100% secure. While we strive to apply commercially reasonable means to protect your personal information, we cannot guarantee absolute security.
Cookies and Tracking
Strictly Necessary — Required for the website to function. Cannot be disabled.
Performance / Analytics — Anonymized usage data to improve the site.
Preference — Remember your settings and preferences.
Security — Support authentication and detect malicious activity.
You can configure your browser to refuse all cookies; however, some features may not function correctly.
Automated Decision-Making
VX-N's AI solutions play an active role in processes that may influence client decisions — including qualifying leads, verifying information, and routing inquiries. While our solutions do not make final determinations autonomously, their outputs may materially affect those decisions.
Individuals have the right to request human review of any AI-assisted assessment that has a significant effect on them.
Accuracy and Data Quality
We rely on clients and individuals to provide accurate information. When we learn information is inaccurate, incomplete, or outdated, we will correct or update it. Individuals may request corrections by contacting us or through the client organization.
Individual Rights
Right to Access — Request a copy of personal information and how it's used.
Right to Rectification — Request correction of inaccurate or outdated information.
Right to Erasure — Request deletion when no longer required, subject to legal retention.
Right to Restrict Processing — Request limits on how we use your information.
Right to Data Portability — Receive your data in a structured, machine-readable format.
Right to Object — Object to particular uses including analytics.
Right to Withdraw Consent — Withdraw previously given consent at any time.
Right to Human Review — Request human review of AI-assisted assessments.
How to Submit a Request
Email dev@vx-n.com with the subject "Personal Information Request." Include your full name, a description of your request, and any details to help locate relevant records.
What Happens Next
1. Acknowledgement — within 5 business days.
2. Identity Verification — before releasing or acting on information.
3. Response — within 30 calendar days (never exceeding 60 days without notice).
Children's Data
VX-N's services are not directed at children. We do not knowingly collect personal information from individuals under 13 (or 16 where required) without parental consent. If we learn we have collected such information, we will delete it promptly.
Jurisdiction-Specific Rights
CCPA/CPRA — California Residents
VX-N does not sell personal information and does not share it for cross-context behavioral advertising. To exercise California privacy rights, contact dev@vx-n.com with subject "California Privacy Request."
CalOPPA
Users may visit our site anonymously. When Do Not Track (DNT) or Global Privacy Control (GPC) signals are detected, we disable non-essential tracking.
Breach Notification
VX-N maintains a formal incident response program. In the event of a breach creating a real risk of significant harm, we will notify affected clients and individuals as soon as feasible and report to authorities within required timeframes (targeting 72 hours where feasible).
Marketing Communications
You may opt out of marketing communications at any time via the "unsubscribe" link in any email or by contacting dev@vx-n.com.
Challenging Compliance & Contact
Complaints, questions, or requests should be directed to our Privacy Officer:
Email — dev@vx-n.com
Mail — VX-N, 465 Rue Bibeau, Suite 120, Saint-Eustache, QC J7R 0C8
If concerns remain unresolved, individuals may contact the Office of the Privacy Commissioner of Canada.
Policy Updates
We may update this policy to reflect changes in our practices, applicable laws, or technology. Material changes will be communicated through our website, client communications, or other channels, and new consent obtained where required by law.