Privacy Policy

SofiaPulse Robots Inc. ·

1. About this policy

This Privacy Policy has been prepared by SofiaPulse Robots Inc. (“SofiaPulse”) and sets out the manner in which SofiaPulse collects, uses, discloses and otherwise manages personal information.

It covers three distinct matters, which should be kept separate:

Different practices apply to each. Statements made in this policy in respect of one do not apply to another unless expressly stated. In particular, the Applications require an account and process information that identifies the account holder; the Ads do neither.

“Personal information” means information about an identifiable individual. Where the General Data Protection Regulation applies, “personal information” should be read as “personal data”.

2. SofiaPulse advertising in brief

SofiaPulse’s Ads store no information on the user’s device, assign no identifier, and construct no profile. An IP address is used to derive a geographic area — country, region and city, and nothing finer — and is then discarded.

SofiaPulse does not carry out online behavioural advertising, does not track users across sites or over time, and does not combine the information it receives with information from other sources. A record of each delivery and interaction event is retained for reporting, containing no identifier and no personal information, as described in section 3.

SofiaPulse’s Ads contain no forms and do not request a name, email address, or other identifying detail. As no identifier is held, there is no profile to disclose. A recorded objection to processing carried out on the basis of legitimate interest is honoured, as described in the SofiaPulse Legitimate Interest Claim. Section 3 sets out the detail, section 4 describes how SofiaPulse handles objection and preference signals, and section 14 addresses the effect on data subject rights.

3. Viewing or interacting with a SofiaPulse Ad

SofiaPulse’s Ads are displayed through third-party websites and apps. When an Ad is requested, SofiaPulse receives:

What SofiaPulse does with an IP address

An IP address is necessarily received in order for any content to reach a device. On receipt, it is used to derive a geographic area — country, region and city — so that the Ad is appropriate to the market in which it is served, including advertising for businesses that trade in a particular city, and complies with local advertising rules. Nothing finer is derived: no postal code, no coordinates and no accuracy radius, notwithstanding that the geolocation database returns such values in the same lookup, and no location signal is read from the device. The IP address is used for that derivation and for routing the response, and is then discarded. It is not written to SofiaPulse’s storage and not present in SofiaPulse’s application logs, and SofiaPulse does not access, query or use it after the derivation.

This derivation happens at two points, and in two places:

In both cases the derivation is performed by SofiaPulse’s own software against a licensed geolocation database held locally on that infrastructure. The IP address is used in memory and discarded at each point; it is not passed from one to the other. No IP address is sent to any third-party geolocation service. The database supplier receives no personal information and is not a processor. The resulting value names a city; it is not a precise location, not a household, and not sufficient to identify an individual.

As with any internet service, SofiaPulse’s infrastructure providers necessarily see IP addresses in order to route traffic, and process them in their own operational and security logs under the agreements described in section 10. SofiaPulse does not retain those addresses, does not use those logs for advertising purposes, and does not join them to any SofiaPulse dataset.

SofiaPulse recognises that an IP address is personal information notwithstanding that it is not retained by SofiaPulse.

What SofiaPulse does with the page address

SofiaPulse does not receive the full address of the page. The party serving the creative — in practice the demand-side platform — supplies it in sanitised form, from which the query string is expected to have been removed before transmission. SofiaPulse uses that value as received, does not request a fuller one and has no other route to it.

From it SofiaPulse takes the domain, and uses it for one purpose: as a dimension of the aggregate delivery and performance counts described below, so that an advertiser can see how a campaign performed across the publishers it ran on. It is not used to select the advertisement, which is selected on geographic area alone. It is not used to identify or recognise any individual, and it is not retained against any request.

What SofiaPulse does with browser and device information

The user-agent string is parsed at the moment of the request into device type, device brand and model, and browser. These are used only as dimensions of the aggregate performance counts described below — for example, impressions and clicks by device type, by browser and by country on a given day. They are not used to select the advertisement, which is selected as described above.

The string itself is used in memory for that parsing and is not retained. No individual request can be recovered from the resulting counts.

SofiaPulse does not combine browser or device information with an IP address, a timestamp, or a page URL in order to construct a fingerprint or a probabilistic identifier. Its systems are not designed or configured to do so, and no code path performs such a combination.

What SofiaPulse does for security and fraud prevention

SofiaPulse works to ensure that advertisers are not billed for invalid, duplicate or fraudulent impressions and that publishers are not credited for them. It is worth being exact about when this happens, because it is not what the phrase usually implies.

SofiaPulse does not assess a request for fraud as it is handled. Nothing is scored, blocked or refused in real time on that basis, and an invalid request is served and recorded like any other. The work is done afterwards, on the delivery and interaction records described above: when those records are aggregated into the counts advertisers and publishers see, records judged duplicative or fraudulent are excluded from the counts.

This means no additional information is collected for this purpose and no additional record is written for it. The input is the same set of records, already described, that SofiaPulse writes for reporting. Separately, and independently of SofiaPulse, the infrastructure providers named in section 10 operate their own network-level protections against automated and abusive traffic, as any hosting provider does.

What SofiaPulse does with delivery and interaction events

When an Ad is served, rendered, viewed or clicked, or a video reaches a given point, SofiaPulse writes a record of that event. The record holds the campaign, creative and format, the publisher domain, the geographic area (country, region and city), the device type, brand, model and browser, and the type of event. It holds no identifier for any person, no IP address and no user-agent string, and nothing in it identifies or relates to an identifiable individual.

Each record also carries the identifier of the client on whose behalf the advertisement was served — the advertiser or agency, not any person. Records are therefore segregated by client rather than pooled: they are never combined across clients, and every record relating to a given client’s campaigns can be located and deleted on that client’s instruction.

These records are the basis of the aggregate reporting supplied to advertisers and publishers — verifying what was delivered, and paying accurately for the inventory supplied. They are retained so that reporting can be recompiled in new forms as advertisers ask different questions of the same campaigns, and are kept for as long as that reporting remains useful.

Because the records contain no identifier, they cannot be linked to one another, to a person, to a household or to a device, and SofiaPulse cannot use them to recognise anyone on a later occasion.

What SofiaPulse Ads do not do

4. Objection and preference signals

SofiaPulse relies on legitimate interest under Article 6(1)(f) for everything it declares in connection with advertising, and does not itself ask any user for consent. Whether the ePrivacy rules on terminal equipment additionally require consent for an ad call is not a question SofiaPulse seeks to settle in its own favour: it stores nothing on and reads nothing from the device, and where a publisher’s consent management platform applies a consent model rather than a legitimate interest one, the record it transmits reflects that.

SofiaPulse acts on that record either way. It does not need the point resolved, because it proceeds only where the record establishes it, and serves nothing where it does not.

The publisher’s consent management platform records the user’s choices and transmits them to SofiaPulse with the ad request, in the standard IAB Europe Transparency and Consent Framework parameters. SofiaPulse reads whether it is established as a vendor for legitimate interest, for the purposes it declares, before any processing described in section 3 takes place.

Where SofiaPulse is established as a vendor for legitimate interest in that record, it processes on its own basis as a controller, as described in section 3, and the advertisement is served and counted.

Where it is not established, SofiaPulse distinguishes two situations, and treats them differently.

Where an objection has been recorded. SofiaPulse was disclosed to the user and the user declined it. SofiaPulse serves no advertisement: nothing is selected, no geographic area is derived, and no record is written. It does not deliver on any other basis, and an instruction from an advertiser does not displace a person’s objection to SofiaPulse.

Where there is no record of SofiaPulse at all — the publisher has not disclosed SofiaPulse, or no valid record was transmitted. Nobody was asked about SofiaPulse and nothing was declined. SofiaPulse does not process on its own basis and applies none of the purposes it declares as a controller. It acts solely on the documented instructions of the advertiser or agency whose campaign is being delivered, as that party’s processor and under the legal basis that party has established. The advertisement is delivered, because delivering it is what SofiaPulse has been instructed to do.

SofiaPulse does not treat the absence of a record as permission to process for its own purposes, and records against each event which of these positions applied.

Where an advertiser’s tracking URL is delivered within a creative, the consent parameters in it are relayed unchanged.

SofiaPulse keeps no record of any user’s choices and no identifier against which one could be stored. The behaviour described here is enforced in code, which SofiaPulse will make available for inspection by a partner or a supervisory authority on request, under appropriate confidentiality terms.

5. Using the SofiaPulse Applications

The Applications are available to personnel of SofiaPulse clients and are reached through an account. They are separate from ad serving. Nothing described in this section applies to the Ads, and nothing described in section 3 limits what is set out here.

Signing in

Access is by single sign-on, handled by Firebase Authentication. The supported identity providers are Google and Microsoft; an account holder signs in with whichever of those holds their existing account. SofiaPulse operates no password store of its own and never receives an account holder’s password. On sign-in, SofiaPulse receives the account holder’s name, email address, and a stable account identifier, and uses these to establish and maintain the session and to determine what the account holder is permitted to see. The identity provider account itself is governed by that provider’s terms and, where an employer administers it, by that employer’s policies.

What is processed

This information is used to operate and secure the Applications, to provide the contracted services, to maintain an audit record of actions taken on a client account, to support account holders, and to meet legal and contractual obligations. The legal basis is the performance of SofiaPulse’s contract with the client and SofiaPulse’s legitimate interest in operating and securing the service.

How long it is kept

Account, usage, audit and submitted content are ordinary business records. They are kept for the duration of the client relationship and afterwards only for as long as is necessary for the purposes described above or required by law, and are then deleted or returned at the client’s election.

No equivalent statement is needed for the Ads. SofiaPulse’s ad serving has no retention: once an Ad has been served, no record of that request exists to be kept, and there is therefore no retention period to state.

Cookies and storage in the Applications

Unlike the Ads, the Applications do store information on the device. This is limited to what is strictly necessary to operate the service: a session cookie or equivalent token to keep an account holder signed in, and any preference the account holder sets. The Applications use no advertising cookies, do not track account holders across other websites, and build no advertising profiles.

Reporting shown in the Applications

Campaign reporting available through the Applications is aggregate. It reports delivery and performance in totals, and does not identify, and cannot be resolved to, any individual who viewed an Ad.

Who provides the infrastructure

The Applications are delivered through Vercel and Cloudflare on the front end and operated on Cloudflare and Google Cloud on the back end, with sign-in handled by Firebase Authentication. Each is a service provider acting on SofiaPulse’s instructions, and each is named in the processor list.

6. Visiting the SofiaPulse Website

The Website can in general be visited without identifying oneself or submitting any personal information.

SofiaPulse collects the IP addresses of visitors to its Website and other information about the visit, such as page requests, browser type, operating system, and average time spent on the Website. SofiaPulse uses this to understand Website activity and to monitor and improve the Website.

Unlike SofiaPulse Ads, the Website does use cookies and similar technologies. See section 8.

7. Contacting SofiaPulse and email communications

Contacting SofiaPulse. Where an individual contacts SofiaPulse with a comment, question or complaint, personal information may be requested — such as a name, email address or phone number — along with any additional information SofiaPulse needs in order to respond. SofiaPulse may retain this to assist that person in future and to improve its customer service.

Email and other communications. From time to time SofiaPulse may obtain consent to send email and other communications about products, services, promotions or events that may be of interest. Recipients can opt out of promotional messages at any time by following the unsubscribe instructions in any email SofiaPulse sends, or by contacting SofiaPulse using the details in section 16.

8. Cookies and similar technologies

SofiaPulse’s Ads. SofiaPulse’s Ads do not use cookies, local storage, or any other technology that stores or reads information on a device. SofiaPulse publishes a machine-readable disclosure of this at vendor-device-storage-disclosure.json; its storage list is empty because there is nothing to declare. SofiaPulse additionally disables cache validators, including entity tags, on its ad, tag, and event endpoints, so that no value is written to or returned from a browser cache in a form capable of re-identifying a device.

SofiaPulse’s Website. SofiaPulse’s Website uses cookies. A cookie is a small piece of data a website can send to a browser and store on a device, so that the site can recognise that browser on a later visit.

SofiaPulse uses Google Analytics on the Website to understand which areas visitors use, so that SofiaPulse can evaluate and improve the experience. Google Analytics sets cookies on the device and processes the IP address on SofiaPulse’s behalf. To opt out of Google Analytics across all websites, Google makes a browser add-on available for that purpose. Most browsers can also be configured to give notice when a cookie is received, or to reject cookies entirely; where cookies from the Website are declined, some features may not work as intended.

This applies to the Website only. SofiaPulse’s Ads use no analytics of this kind and set nothing on any device. The Applications store only the strictly necessary session and preference information described in section 5.

SofiaPulse’s Website may also use tracking pixels and web beacons to understand which pages are visited, so that SofiaPulse can improve the Website for future visitors. SofiaPulse may also engage third parties to serve its own advertisements on other websites; those companies may use such technologies to report on visits to its Website in order to measure the effectiveness of its advertising. These practices relate to its Website and its own marketing only, and are entirely separate from the Ads SofiaPulse delivers for clients.

9. Disclosure of personal information

It is SofiaPulse’s policy not to disclose, trade, rent, sell or otherwise transfer personal information without consent, except as set out in this policy.

Sale of business. SofiaPulse may transfer information it holds as an asset in connection with a merger or sale — including transfers made as part of insolvency or bankruptcy proceedings — involving all or part of SofiaPulse Robots Inc., or as part of a corporate reorganisation, stock sale or other change in corporate control.

Legal. SofiaPulse and its service providers may provide personal information in response to a search warrant or other legally valid inquiry or order, or to an investigative body in the case of a breach of an agreement or contravention of law, or as otherwise required by applicable Canadian, US or other law. SofiaPulse may also disclose personal information where necessary for the establishment, exercise or defence of legal claims, or as otherwise permitted by law.

Government access requests. SofiaPulse reviews every such request for validity and scope, requires that it be properly served and legally binding, challenges requests that are overbroad or improperly made, and discloses only the minimum the request compels. SofiaPulse notifies the affected client where it is legally permitted to do so. In respect of the Ads, the event records described in section 3 contain no identifier and cannot be searched for or attributed to any individual, so there is nothing to produce in respect of a particular person.

10. Service providers and international processing

SofiaPulse uses third parties who provide services on its behalf. They are given only the information needed to perform their designated function, they act on SofiaPulse’s documented instructions, and SofiaPulse does not authorise them to use or disclose personal information for their own marketing or any other purpose of their own.

SofiaPulse names every one of them. The complete, current list, with the location and transfer mechanism for each, is at Processors and subprocessors. That list covers providers processing personal information on SofiaPulse’s behalf. It does not cover the advertising platforms SofiaPulse itself buys media from to promote its own business, described in section 8, which act as controllers in their own right under their own notices.

Cloud infrastructure Edge delivery, creative and asset storage for the Ads, and the compute on which SofiaPulse’s own software performs the two geographic derivations described in section 3 — at the edge when the Ad is selected and when its creative assets are returned, and in the Montréal region when an event is recorded. The IP address is processed in memory by SofiaPulse’s software and discarded at each point; it is not stored by SofiaPulse or on its behalf. The processor list states which provider does which.
Single sign-on Authentication of account holders signing in to the Applications, as described in section 5. Sign-in is handled by Firebase Authentication, with Google and Microsoft as supported identity providers.
Platform and client applications Hosting, compute, storage, and analytics for the SofiaPulse platform and the web applications used by SofiaPulse clients. Separate from ad serving; concerns account information of client personnel and aggregate campaign data.
Website hosting and analytics Operation of the Website and measurement of Website usage, as described in sections 6 and 8.
Email Correspondence, and sending communications where these have been requested.

International processing

SofiaPulse is established in Canada, and its service providers operate globally. Personal information may therefore be processed outside the individual’s country of residence, including in Canada and the United States, and will be subject to the laws of those jurisdictions, including lawful requests for access by public authorities.

How Chapter V of the GDPR applies

Where the GDPR applies to SofiaPulse under Article 3(2), two situations must be distinguished.

Information reaching SofiaPulse from a device in the EEA or the UK. Where a user’s device transmits an ad request to SofiaPulse, the information is disclosed by the data subject’s own device and not by an exporter established in, or otherwise subject to, the GDPR in respect of that disclosure. Following the European Data Protection Board’s guidance on the interplay between Article 3 and Chapter V, that is not a transfer within the meaning of Chapter V, and no transfer mechanism is required for it. The processing remains subject to the GDPR in full.

Information SofiaPulse discloses to a service provider outside the EEA or the UK. Where SofiaPulse, as a controller subject to Article 3(2), makes personal information available to a service provider established in a third country, that is a transfer and Chapter V applies. SofiaPulse is the exporter. SofiaPulse relies on the following, per provider and by reference to the provider’s own legal entity rather than the location of its data centres:

SofiaPulse notes that the Standard Contractual Clauses were drafted for exporters established in the European Union, and that a dedicated set of clauses for exporters subject to the GDPR under Article 3(2) has been announced by the European Commission but not yet adopted. Pending their adoption SofiaPulse applies the existing clauses as the closest available safeguard under Article 46, disapplying those provisions that duplicate obligations SofiaPulse already owes directly under the GDPR.

The transfers described above are of the categories set out in section 3 and section 5. In respect of the Ads, the information transferred is an IP address that is discarded on receipt and retained in no jurisdiction.

Transfers by SofiaPulse’s clients to SofiaPulse

Separately, a client established in the EEA or the UK that transfers personal information to SofiaPulse in Canada may rely on the European Commission’s adequacy decision for Canada (Decision 2002/2/EC), which covers organisations subject to the Personal Information Protection and Electronic Documents Act in the course of their commercial activities, and on the corresponding United Kingdom adequacy regulations. SofiaPulse is such an organisation in respect of the personal information it receives in the course of its commercial activities across provincial and national borders. No Article 46 safeguard is required for that transfer.

11. Security of personal information

SofiaPulse maintains administrative, technical and physical safeguards designed to protect personal information in its custody and control against unauthorised access, use, modification and disclosure. These include encryption of personal information in transit using current TLS versions and at rest, role-based access control with access granted on a least-privilege basis, multi-factor authentication for all administrative access, segregation of the Applications from ad-serving infrastructure, logging and review of administrative access, and periodic review of provider security posture.

In respect of its Ads, the principal safeguard is structural rather than procedural. Information capable of identifying or tracking an individual is not retained — the event records described in section 3 carry no identifier — and therefore cannot be re-purposed, disclosed, or exposed in a security incident. SofiaPulse retains other personal information — such as information sent to it directly — for no longer than necessary for the purposes described here or to meet legal requirements.

SofiaPulse maintains a register of security incidents affecting personal information and will notify affected supervisory authorities and individuals where the applicable law requires it.

13. Children

SofiaPulse’s services are not directed to children, and SofiaPulse does not knowingly direct advertising at children or process personal information for the purpose of advertising to children. SofiaPulse’s Ads assign no identifier and construct no profile, and so cannot be used to target any individual, including a child.

Under Article 8 GDPR, where processing is based on consent, a child must be at least 16 years old for that consent to be valid, unless the member state concerned has set a lower age, which may not be below 13. SofiaPulse does not rely on consent as its legal basis for the Ads, and its Applications are business tools available only to personnel of its clients. SofiaPulse does not intend to collect personal information from children through any of its services.

14. Rights of individuals

Individuals have the right to access, update, and correct inaccuracies in personal information in SofiaPulse’s custody and control, subject to exceptions prescribed by law. Such a request may be made using the contact details in section 16. SofiaPulse may ask for information to verify the requester’s identity before responding.

Individuals in the European Economic Area or the United Kingdom

Where the General Data Protection Regulation applies, data subjects have the rights of access, rectification, erasure, restriction, portability, and objection, and the right to lodge a complaint with their supervisory authority.

SofiaPulse’s legal basis for delivering, geographically selecting, securing, and measuring its Ads is legitimate interest under Article 6(1)(f). SofiaPulse’s assessment of that basis, and how to object, is set out in full in its Legitimate Interest Claim.

What SofiaPulse can and cannot disclose about its advertising

Because its Ads assign no identifier and retain nothing about any individual request, there is no record tied to an individual for SofiaPulse to retrieve, correct, restrict, or delete. Article 11 GDPR provides that a controller which does not require identification of an individual for its purposes is not obliged to acquire additional information solely in order to identify that person in response to a request. That provision describes SofiaPulse’s position. SofiaPulse does not collect identifying information for the purpose of responding to such requests, as doing so would require establishing the identification capability this policy records the absence of.

In accordance with Article 11(2), SofiaPulse informs any individual making such a request that it is not in a position to identify them. Where an individual is able to provide additional information enabling their identification, SofiaPulse will act on it; in respect of the Ads there is no such information, because nothing SofiaPulse holds is capable of being linked to a person.

SofiaPulse is therefore able to state completely what is done with information of the kind generated by a device, as set out in this policy, but is unable to provide information specific to an individual, as no such information exists in SofiaPulse’s systems.

Where an individual has given SofiaPulse information directly — by contacting SofiaPulse, or by subscribing to communications — that information is identifiable and these rights apply to it in the ordinary way. SofiaPulse’s Ads themselves never collect such information.

Where SofiaPulse acts as a processor on behalf of a client, it may redirect the request to that client as the controller of the information.

15. Quebec and Canadian requirements

SofiaPulse is established in Quebec and is subject to the Personal Information Protection and Electronic Documents Act and to the Act respecting the protection of personal information in the private sector, as amended.

Person in charge of the protection of personal informationYousef Younes, Chief Executive Officer — [email protected]
AssessmentsSofiaPulse conducts a privacy impact assessment before communicating personal information outside Quebec and before implementing any new system involving personal information.
Automated decisionsSofiaPulse makes no decision about any individual based exclusively on automated processing. Its Ads do not differentiate treatment between individuals.
Identification and profiling technologySofiaPulse’s Ads use no technology that identifies or profiles an individual. A geographic area — country, region and city, and nothing finer — is derived from the IP address as described in section 3, and that address is discarded. The derived area appears on the delivery and interaction records described in section 3, which carry no identifier for any person. It is not capable of locating an individual and no location signal is read from the device. Its Applications use strictly necessary session storage only, as described in section 5.

16. Changes and how to contact SofiaPulse

This Privacy Policy may be updated to reflect changes in SofiaPulse’s practices. The revised policy will be posted here. If SofiaPulse makes material changes, a notice will be posted on the front page of its Website.

Questions or comments about this policy, requests to opt out of marketing messages, requests to access, update or correct personal information, and complaints about how SofiaPulse treats personal information may all be directed to the contacts below.

Email[email protected]
MailSofiaPulse Robots Inc.
415 Rue des Récollets, Suite 101
Montréal, QC H2Y 1W3
Canada
Representative in the European Union
Article 27 GDPR
Cloudkasten GmbH
Seestraße 20 G
50374 Erftstadt
Germany
[email protected]

Pursuant to Article 27 of the EU General Data Protection Regulation (GDPR), SofiaPulse Robots Inc. has appointed Cloudkasten GmbH as the above representative in the European Union. Individuals located in the EU may contact our EU Representative on any matter relating to the processing of their personal data or to the exercise of their rights under the GDPR.

A data subject may contact either SofiaPulse directly or its representative, and may lodge a complaint with the supervisory authority of their habitual residence, place of work, or place of the alleged infringement.