Privacy Policy
SofiaPulse Robots Inc. ·
1. About this policy
This Privacy Policy has been prepared by SofiaPulse Robots Inc. (“SofiaPulse”) and sets out the manner in which SofiaPulse collects, uses, discloses and otherwise manages personal information.
It covers three distinct matters, which should be kept separate:
- the advertising SofiaPulse delivers on its own behalf or on behalf of its clients through its proprietary SofiaPulse technology (“Ad” or “Ads”), served via an ad tag or a widget hosted on a publisher’s site;
- the client applications operated by SofiaPulse, through which clients and their personnel configure campaigns, review creative, and access reporting (the “Applications”); and
- the SofiaPulse website at sofiapulse.com (the “Website”).
Different practices apply to each. Statements made in this policy in respect of one do not apply to another unless expressly stated. In particular, the Applications require an account and process information that identifies the account holder; the Ads do neither.
“Personal information” means information about an identifiable individual.
2. SofiaPulse advertising in brief
SofiaPulse’s Ads store no information on the user’s device, assign no identifier, and construct no profile. An IP address is used to derive a coarse geographic area and is then discarded.
SofiaPulse does not carry out online behavioural advertising, does not track users across sites or over time, does not combine the information it receives with information from other sources, and retains no record of an individual ad request once it has been served.
SofiaPulse’s Ads contain no forms and do not request a name, email address, or other identifying detail. As no identifier is held, there is no profile to disclose and no opt-out to apply. Section 3 sets out the detail, and section 13 addresses the effect on data subject rights.
3. Viewing or interacting with a SofiaPulse Ad
SofiaPulse’s Ads are displayed through third-party websites and apps. When an Ad is requested, SofiaPulse receives:
- the IP address, transmitted by the device as an inherent part of any internet connection;
- the browser type and version, and device type, as passed in the ad request;
- contextual information about the page or app the Ad appears on, such as the domain and URL;
- delivery and interaction events — that an Ad was served, rendered, viewed, clicked, or that a video reached a given point.
What SofiaPulse does with an IP address
An IP address is necessarily received in order for any content to reach a device. On receipt, it is used to derive a coarse geographic area — country, and in some markets region or designated market area — so that the Ad is appropriate to the market and complies with local advertising rules. The IP address is used for that derivation and for routing the response, and is then discarded. It is not written to storage, not logged, and not available for any later use.
This derivation is performed for SofiaPulse by a cloud infrastructure provider acting on its instructions (see section 9). The resulting geographic value is not sufficient to identify an individual, a household, or a precise location.
SofiaPulse recognises that an IP address is personal information notwithstanding that it is not retained.
What SofiaPulse does with delivery and interaction events
Delivery and interaction events are counted in aggregate so that advertisers can verify what was delivered and publishers can be paid accurately for the inventory they supplied. These counts are not linked to an individual, to a device, or to any identifier, and cannot be traced back to an individual.
What SofiaPulse Ads do not do
- store or read cookies, local storage, or any other information on a device;
- assign, read, or receive any persistent or cross-site identifier;
- retain an IP address after the geographic derivation above;
- link one ad request to another, or to an individual, a household, or a device over time;
- build, use, or contribute to an advertising profile;
- infer or target on the basis of health, political opinion, religion, sexual orientation, or any other sensitive characteristic;
- combine any of the above with information obtained from other sources;
- collect a name, email address, telephone number, or any other information that identifies an individual;
- sell, rent, trade, or otherwise make any of the above available to third parties for their own purposes.
4. Using the SofiaPulse Applications
The Applications are available to personnel of SofiaPulse clients and are reached through an account. They are separate from ad serving. Nothing described in this section applies to the Ads, and nothing described in section 3 limits what is set out here.
Signing in
Access is by single sign-on, handled by Firebase Authentication. The supported identity providers are Google and Microsoft; an account holder signs in with whichever of those holds their existing account. SofiaPulse operates no password store of its own and never receives an account holder’s password. On sign-in, SofiaPulse receives the account holder’s name, email address, and a stable account identifier, and uses these to establish and maintain the session and to determine what the account holder is permitted to see. The identity provider account itself is governed by that provider’s terms and, where an employer administers it, by that employer’s policies.
What is processed
- Account information — name, email address, account identifier, organisation, and assigned permissions;
- Session information — a session identifier stored on the device so that the account holder remains signed in, together with sign-in and sign-out events;
- Usage and technical information — IP address, browser and device type, and records of actions taken within the Applications, such as campaigns created or reports generated;
- Content submitted — creative assets, campaign configuration, and any other material an account holder uploads or enters.
This information is used to operate and secure the Applications, to provide the contracted services, to maintain an audit record of actions taken on a client account, to support account holders, and to meet legal and contractual obligations. It is retained for the duration of the client relationship, and afterwards for as long as is necessary for those purposes or required by law.
Cookies and storage in the Applications
Unlike the Ads, the Applications do store information on the device. This is limited to what is strictly necessary to operate the service: a session cookie or equivalent token to keep an account holder signed in, and any preference the account holder sets. The Applications use no advertising cookies, do not track account holders across other websites, and build no advertising profiles.
Reporting shown in the Applications
Campaign reporting available through the Applications is aggregate. It reports delivery and performance in totals, and does not identify, and cannot be resolved to, any individual who viewed an Ad.
Who provides the infrastructure
The Applications are delivered through Vercel and Cloudflare on the front end and operated on Cloudflare and Google Cloud on the back end, with sign-in handled by Firebase Authentication. Each is a service provider acting on SofiaPulse’s instructions, and each is named in the subprocessor list.
5. Visiting the SofiaPulse Website
The Website can in general be visited without identifying oneself or submitting any personal information.
SofiaPulse collects the IP addresses of visitors to its Website and other information about the visit, such as page requests, browser type, operating system, and average time spent on the Website. SofiaPulse uses this to understand Website activity and to monitor and improve the Website.
Unlike SofiaPulse Ads, the Website does use cookies and similar technologies. See section 7.
6. Contacting SofiaPulse and email communications
Contacting SofiaPulse. Where an individual contacts SofiaPulse with a comment, question or complaint, personal information may be requested — such as a name, email address or phone number — along with any additional information SofiaPulse needs in order to respond. SofiaPulse may retain this to assist that person in future and to improve its customer service.
Email and other communications. From time to time SofiaPulse may obtain consent to send email and other communications about products, services, promotions or events that may be of interest. Recipients can opt out of promotional messages at any time by following the unsubscribe instructions in any email SofiaPulse sends, or by contacting SofiaPulse using the details in section 14.
8. Disclosure of personal information
It is SofiaPulse’s policy not to disclose, trade, rent, sell or otherwise transfer personal information without consent, except as set out in this policy.
Sale of business. SofiaPulse may transfer information it holds as an asset in connection with a merger or sale — including transfers made as part of insolvency or bankruptcy proceedings — involving all or part of SofiaPulse Robots Inc., or as part of a corporate reorganisation, stock sale or other change in corporate control.
Legal. SofiaPulse and its service providers may provide personal information in response to a search warrant or other legally valid inquiry or order, or to an investigative body in the case of a breach of an agreement or contravention of law, or as otherwise required by applicable Canadian, US or other law. SofiaPulse may also disclose personal information where necessary for the establishment, exercise or defence of legal claims, or as otherwise permitted by law.
9. Service providers and international processing
SofiaPulse uses third parties who provide services on its behalf. They are given only the information needed to perform their designated function, they act on SofiaPulse’s documented instructions, and SofiaPulse does not authorise them to use or disclose personal information for their own marketing or any other purpose of their own.
SofiaPulse names every one of them. The complete, current list is at Subprocessors.
| Cloud infrastructure | Hosting and delivery of Ads, and derivation of coarse geographic area from IP address as described in section 3. The IP address is processed in memory and discarded; it is not stored by SofiaPulse or on its behalf. |
|---|---|
| Single sign-on | Authentication of account holders signing in to the Applications, as described in section 4. Sign-in is handled by Firebase Authentication, with Google and Microsoft as supported identity providers. |
| Platform and client applications | Hosting, compute, storage, and analytics for the SofiaPulse platform and the web applications used by SofiaPulse clients. Separate from ad serving; concerns account information of client personnel and aggregate campaign data. |
| Website hosting and analytics | Operation of the Website and measurement of Website usage, as described in sections 5 and 7. |
| Correspondence, and sending communications where these have been requested. |
International processing. SofiaPulse is established in Canada, and its service providers operate globally. Personal information may therefore be processed outside the individual’s country of residence, including in Canada and the United States, and will be subject to the laws of those jurisdictions, including lawful requests for access by public authorities.
Where personal information of individuals in the European Economic Area or the United Kingdom is transferred outside those areas, it is transferred to Canada. SofiaPulse relies on the European Commission’s adequacy decision for Canada (Decision 2002/2/EC), which covers organisations subject to the Personal Information Protection and Electronic Documents Act in their commercial activities, and on the corresponding United Kingdom adequacy regulations. No further transfer mechanism is required for that transfer.
The derivation of coarse geographic area described in section 3 is performed in the Montréal region of its cloud provider’s infrastructure. Where a service provider transfers personal information onward to the United States or elsewhere in the course of operating its own systems, that transfer is governed by the Standard Contractual Clauses approved by the European Commission in Implementing Decision (EU) 2021/914, as incorporated into that provider’s data processing agreement with SofiaPulse.
10. Security of personal information
SofiaPulse maintains reasonable administrative, technical and physical safeguards designed to protect personal information in its custody and control against unauthorised access, use, modification and disclosure.
In respect of its Ads, the principal safeguard is structural rather than procedural. Information capable of identifying or tracking an individual is not retained, and therefore cannot be re-purposed, disclosed, accumulated, or exposed in a security incident. SofiaPulse retains other personal information — such as information sent to it directly — for no longer than necessary for the purposes described here or to meet legal requirements.
11. Third-party links
SofiaPulse’s services may contain links to sites SofiaPulse does not own or operate, and links to its Website may appear on third-party sites where SofiaPulse advertises. Those sites have their own privacy statements and terms, which SofiaPulse recommends be read. SofiaPulse has no control over them and is not responsible for how they collect, use, disclose or secure personal information.
12. Children
SofiaPulse’s services are not intended for children under 13, and SofiaPulse does not intend to collect personal information from children under 13. SofiaPulse does not knowingly direct advertising at children or process personal information for the purpose of advertising to children. A person aged 13 or older but under the age of majority in their place of residence must have the permission of a parent or legal guardian to use SofiaPulse’s services.
13. Rights of individuals
Individuals have the right to access, update, and correct inaccuracies in personal information in SofiaPulse’s custody and control, subject to exceptions prescribed by law. Such a request may be made using the contact details in section 14. SofiaPulse may ask for information to verify the requester’s identity before responding.
Individuals in the European Economic Area or the United Kingdom
Where the General Data Protection Regulation applies, data subjects have the rights of access, rectification, erasure, restriction, portability, and objection, and the right to lodge a complaint with their supervisory authority.
SofiaPulse’s legal basis for delivering, geographically selecting, securing, and measuring its Ads is legitimate interest under Article 6(1)(f). SofiaPulse’s assessment of that basis, and how to object, is set out in full in its Legitimate Interest Claim.
What SofiaPulse can and cannot disclose about its advertising
Because its Ads assign no identifier and retain nothing about any individual request, there is no record tied to an individual for SofiaPulse to retrieve, correct, restrict, or delete. Article 11 GDPR provides that a controller which does not require identification of an individual for its purposes is not obliged to acquire additional information solely in order to identify that person in response to a request. That provision describes SofiaPulse’s position. SofiaPulse does not collect identifying information for the purpose of responding to such requests, as doing so would require establishing the identification capability this policy records the absence of.
SofiaPulse is therefore able to state completely what is done with information of the kind generated by a device, as set out in this policy, but is unable to provide information specific to an individual, as no such information exists in SofiaPulse’s systems.
Where an individual has given SofiaPulse information directly — by contacting SofiaPulse, or by subscribing to communications — that information is identifiable and these rights apply to it in the ordinary way. SofiaPulse’s Ads themselves never collect such information.
Where SofiaPulse acts as a processor on behalf of a client, it may redirect the request to that client as the controller of the information.
14. Changes and how to contact SofiaPulse
This Privacy Policy may be updated to reflect changes in SofiaPulse’s practices. The revised policy will be posted here. If SofiaPulse makes material changes, a notice will be posted on the front page of its Website.
Questions or comments about this policy, requests to opt out of marketing messages, requests to access, update or correct personal information, and complaints about how SofiaPulse treats personal information may all be directed to the contact below.
| [email protected] | |
| SofiaPulse Robots Inc. 415 Rue des Récollets, Suite 101 Montréal, QC H2Y 1W3 Canada |