All legal documents

Legal

Privacy Policy

Last updated: 2026-06-29

This Privacy Policy explains how Resonix Labs (Canada) Inc. ("Resonix", "we", "us") collects, uses, discloses, and protects personal information when you visit our websites, request or use our investor data room, or otherwise interact with us. It is written to address both Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and, where applicable, the EU/UK General Data Protection Regulation (GDPR).

Scope note. Our downloadable software (SolvScout, SolvTune, SolvSRK) runs entirely on your own machine and, as shipped, does not collect personal information or transmit data to us (no telemetry, no phone-home). This Policy therefore concerns mainly our websites and business interactions. See the Software License Agreement (04) and Free EULA (05) for software terms.

1. Who we are (controller & contacts)

2. The personal information we collect

(a) Information you give us

  • Access requests (investor data room): name, email, firm, job title, and any message you submit.
  • Account data (investors granted access): name, email, company, access tier, account status, and a securely hashed password (we never store passwords in plaintext).
  • Correspondence: anything you send us by email or contact form.

(b) Information collected automatically

  • Authentication/session: a session cookie (resx_session) and related login records.
  • Access & audit logs: IP address, browser user-agent, pages/resources accessed, document views/downloads, login events, and timestamps. We keep these for security, access control, and to show document engagement to authorized administrators.
  • Site analytics: aggregate usage and performance metrics via Vercel Analytics and Vercel Speed Insights.
  • Cookies/similar technologies: see our Cookie Policy (07).

We do not intentionally collect special-category/sensitive data, and our sites are not directed to children.

3. Why we use it, and our legal bases (GDPR Art. 6)

PurposeExamplesGDPR legal basis
Provide & secure the data room/accountsauthenticate logins, enforce access tiers, audit accessContract (Art. 6(1)(b)); Legitimate interests (Art. 6(1)(f)) — security
Review access requestsevaluate and respond to requestsLegitimate interests; steps prior to a contract
Communicate with youreply to enquiries, send service emails (invites, password resets)Legitimate interests; steps prior to a contract (Art. 6(1)(b))
Improve & measure our sitesanalytics, performanceConsent (where required) or Legitimate interests
Comply with lawrecords, securityLegal obligation (Art. 6(1)(c)); Legitimate interests

Under PIPEDA, we collect, use, and disclose personal information for purposes a reasonable person would consider appropriate in the circumstances, with your knowledge and consent (express or implied) except where the law permits otherwise.

Where we rely on legitimate interests, we have balanced those interests against your rights; you may object (see §8).

4. Cookies & analytics

We use a strictly-necessary session cookie and a theme-preference setting, plus Vercel Analytics/Speed Insights. Where required (e.g., for EU/UK users), non-essential analytics will be used only with your consent. Full details and how to control them are in the Cookie Policy (07).

5. How we share information (processors & disclosures)

We do not sell your personal information. We share it only with:

  • Service providers (processors/sub-processors) who host and operate our infrastructure under contract and our instructions:
  • Vercel — website hosting, analytics, performance;
  • Neon (hosted on AWS) — database;
  • Cloudflare R2 — document/object storage;
  • our email-delivery provider — transactional email. A current list (with locations and roles) is maintained in the DPA (08).
  • Professional advisors (lawyers, auditors) under confidentiality.
  • Authorities where required by law, or to establish/exercise/defend legal claims, or for export-control/sanctions compliance (see Policy 09).
  • Corporate transactions — in connection with a merger, financing, or sale, subject to confidentiality and this Policy.

6. International transfers

We are based in Canada and use service providers that may process data in Canada, the United States, and/or the EU depending on configuration. Where personal data of EU/UK individuals is transferred outside the EEA/UK, we rely on an appropriate transfer mechanism (e.g., Standard Contractual Clauses, adequacy decisions, or the UK IDTA), and Canada benefits from an EU adequacy decision for commercial organizations subject to PIPEDA. Confirm region configuration with us via the privacy contact.

7. How long we keep it (retention)

We keep personal information only as long as necessary for the purposes above:

DataIndicative retention
Account dataLife of the account + 12–24 months after closure
Access requests (not approved)12 months
Access & audit logs12–24 months
Password set/reset tokensExpire automatically (set: 48h; reset: 1h), single-use
Session cookie7 days
Correspondence24 months

We then delete or irreversibly anonymize the data, unless a longer period is required by law.

8. Your rights

Under GDPR/UK GDPR (for individuals in the EU/UK), you may request: access; rectification; erasure; restriction; portability; and to object to processing based on legitimate interests or to direct marketing. Where we rely on consent, you may withdraw it at any time. You also have the right to lodge a complaint with your supervisory authority.

Under PIPEDA (Canada), you may request access to and correction of your personal information and may withdraw consent (subject to legal/contractual limits). You may complain to the Office of the Privacy Commissioner of Canada.

To exercise any right, contact privacy@resonixlabs.io. We will respond within the timeframes required by law (generally 30 days under PIPEDA; one month under GDPR). We may need to verify your identity.

9. How we protect information

We use technical and organizational measures appropriate to the risk, including: password hashing (bcrypt, cost factor 12), encrypted transport (HTTPS/TLS), database SSL, access controls and tiered authorization, audit logging, rate limiting, and least-privilege access. No method is 100% secure; we maintain processes to respond to incidents and will notify you and regulators of breaches where required by law.

10. Automated decision-making

We do not make decisions producing legal or similarly significant effects about you based solely on automated processing.

11. Changes to this Policy

We may update this Policy from time to time. The "Last updated" date shows the latest version; material changes will be notified as required by law.

12. Contact

Questions or requests: privacy@resonixlabs.io / Resonix Labs (Canada) Inc.

13. Notice to California residents (CCPA/CPRA)

In the preceding 12 months we have collected the following categories of personal information (as defined by the CPRA):

CategoryExamples we collectSold / Shared?
Identifiersname, email, company, IP address, account identifiersNo
Commercial informationdata-room access requests, documents viewed/downloadedNo
Internet/network activitylog data, pages/resources accessed, performance metricsNo
Professional / employment informationfirm, job title submitted in an access requestNo

We do not sell and do not share (as "sell" and "share" are defined under the CPRA, including for cross-context behavioral advertising) personal information, and have not done so in the preceding 12 months. We do not use or disclose sensitive personal information for purposes that would trigger the right to limit. Our purposes for collection are described in §3; we retain information per §7.

Your California rights: to know/access the personal information we hold; to delete it; to correct it; to opt out of sale/sharing (not applicable — we do neither); to limit use of sensitive personal information (not applicable); and to non-discrimination for exercising your rights. To exercise a right, contact privacy@resonixlabs.io; we will verify your identity and may honor an authorized agent's request with proof of authorization.

"Do Not Sell or Share My Personal Information": because we do not sell or share personal information, no opt-out is required; this statement serves as our disclosure. We honor Global Privacy Control (GPC) browser signals as a valid opt-out of any future sale/sharing.

14. Notice to Quebec residents (Law 25)

our designated Privacy Officer, reachable at privacy@resonixlabs.io. This person oversees our compliance with Quebec's Act respecting the protection of personal information in the private sector (Law 25).

  • Transfers outside Quebec: before disclosing personal information outside Quebec, we conduct a privacy-impact assessment of the transfer and rely on appropriate safeguards (see §6).
  • Automated decisions: we do not make decisions based exclusively on automated processing of your personal information (see §10); if that changes, we will inform you and provide the rights Law 25 requires.
  • Your rights include access, correction, withdrawal of consent, and de-indexing/cessation of dissemination in the circumstances the law provides.
  • French language: a French-language version of this Policy is available on request for Quebec residents, consistent with the Charter of the French Language.