DOCSCOPE AI INC.
Privacy Policy
English (Canada) • Authoritative English version. Translations are provided subject to mandatory applicable law.
Effective date: August 28, 2026
1. Who we are and what this Policy covers
Docscope AI Inc. ("Docscope," "we," "us," or "our") is located in Richmond, British Columbia, Canada. We provide AI solutions and Docscope Sites fully managed website services to businesses and organizations.
This Policy applies when Docscope collects, uses, or discloses personal information in connection with:
- docscope.ai and other Docscope-operated websites or service interfaces that link to this Policy;
- communications with prospective, current, or former customers;
- personalized Concept pages prepared for prospective customers;
- proposals, subscriptions, accounts, billing, service delivery, support, and administration;
- Docscope-hosted customer websites where Docscope determines the purpose of a particular processing activity; and
- information processed by Docscope as a service provider for a customer, subject to Section 11.
This Policy does not replace a customer business's own privacy notice for visitors to that customer's website. Where Docscope processes visitor information only on a customer's instructions, the customer determines why the information is collected and is primarily responsible for its notice and lawful instructions.
"Personal information" generally means information about an identifiable individual. Business information that is not about an identifiable individual is not personal information, although business contact information may still be handled with appropriate care and may be protected by applicable law depending on the context.
2. Privacy accountability
Docscope is responsible for personal information under its control, including information processed by a service provider on Docscope's behalf.
Docscope designates a Privacy Officer to oversee privacy compliance, respond to questions and complaints, coordinate access or correction requests, and maintain appropriate privacy policies and practices. The Privacy Officer can be contacted at [email protected].
Employees, contractors, and service providers are given access only where reasonably needed for their role and are expected to protect confidential and personal information.
3. Information we may collect
The information collected depends on how a person or business interacts with Docscope and which services are used.
3.1 Identity and contact information
This may include:
- name;
- work title or role;
- business name;
- business email address;
- telephone number;
- mailing or business address; and
- preferred language or communication method.
3.2 Business and website information
This may include:
- company description, industry, locations, hours, products, services, menus, prices, promotions, and contact details;
- current website address, domain name, social-media links, and public listings;
- branding, logos, photographs, videos, and other business materials;
- website goals, requested pages, features, integrations, and content instructions;
- information used to prepare a personalized Concept page or personalized service proposal; and
- approvals, revisions, publishing decisions, and service configuration.
Some of this information may not be personal information, but it may be connected to an identifiable owner, employee, representative, or sole proprietor.
3.3 Proposal, subscription, and account information
This may include:
- proposal version, acceptance date, electronic acceptance record, and authorized representative;
- selected plan, service scope, start date, renewal date, and subscription status;
- account identifiers, login records, authentication events, access permissions, and security history;
- service changes, cancellations, suspensions, and termination records; and
- records needed to administer the customer relationship.
3.4 Payment and billing information
This may include:
- billing name, business, address, and email;
- invoices, receipts, amounts, taxes, discounts, and payment status;
- transaction and payment-processor identifiers;
- failed-payment, chargeback, dispute, and collection records; and
- limited card details made available by the payment processor, such as card brand, expiry status, or the last four digits.
Docscope does not store the complete payment-card number or card security code. Those details are handled by the payment processor under its own privacy and security practices.
3.5 Communications and support information
This may include:
- emails, messages, call notes, meeting notes, and contact-form submissions;
- support requests, troubleshooting information, screenshots, attachments, and resolution history;
- preferences, complaints, feedback, survey responses, and service discussions; and
- records of notices sent or received.
3.6 Domain, DNS, and technical administration information
This may include:
- domain name, registrar, renewal status, nameservers, DNS records, and configuration history;
- registrar or hosting account identifiers and delegated-access records;
- technical contacts and authorization records;
- website deployment, certificate, monitoring, backup, and incident information; and
- credentials or access tokens where a customer chooses to provide them for an agreed task.
Customers should use secure methods requested by Docscope and should not send passwords or sensitive credentials through an unsecured channel.
3.7 Website forms, content, and service data
Depending on the service configuration, this may include:
- information entered into a Docscope-operated form;
- information submitted through a customer website hosted by Docscope;
- content, documents, prompts, instructions, or files submitted for an AI-enabled service;
- website content and revision history; and
- operational data needed to deliver, troubleshoot, secure, or support a service.
Customers should not submit highly sensitive or regulated personal information unless Docscope has expressly agreed in writing to process it with appropriate safeguards.
3.8 Technical, usage, and analytics information
This may include:
- IP address;
- browser, device, and operating-system information;
- date and time of access;
- pages, links, or features viewed or used;
- referring or exit page;
- approximate location inferred from an IP address;
- server, application, security, and error logs;
- session, authentication, and diagnostic events; and
- aggregated website or service performance information.
On Docscope-operated websites, and on customer websites where the feature is enabled, Docscope may use privacy-focused, cookie-free analytics to understand aggregate traffic and service performance. The analytics system may record page views, referrer URLs, browser, operating system, device type, and country-level location. It may transiently process an IP address and user-agent information to generate a session identifier that is not intended to identify a person.
Docscope does not use this analytics function for cross-site tracking or targeted advertising, and the current configuration does not set analytics cookies. If a website later enables cookies, session recording, logged-in user identification, advertising pixels, or other similar technologies, that website will provide any additional notice or obtain any consent required for the technologies actually enabled.
3.9 Marketing and communication preferences
This may include:
- consent or implied-consent records where applicable;
- subscription or unsubscribe status;
- preferred topics or communication channel; and
- delivery status, bounce information, unsubscribe actions, or responses where generated by an email service.
4. Where information comes from
Docscope may collect information:
- directly from the individual or business representative;
- from another authorized person within the same business or organization;
- through a website, form, account, support channel, meeting, proposal, or payment process;
- from a customer that asks Docscope to provide a service involving other individuals' information;
- automatically from systems, logs, security tools, or service interactions;
- from payment processors, domain or DNS providers, hosting providers, email services, analytics services, or other service providers;
- from public business websites, professional or business directories, public registries, social-media business pages, or other lawful public sources; and
- from a referral partner or other person who has a lawful basis to provide the information.
When Docscope uses public business information to identify a prospective customer or prepare a personalized Concept page, Docscope limits the information to what is reasonably relevant to the business purpose and uses commercial electronic messages only as permitted by applicable anti-spam law.
5. Why we collect, use, and disclose information
Docscope may handle personal information for the following purposes.
5.1 To communicate and evaluate a possible service
We may use information to:
- respond to an inquiry or referral;
- identify and communicate with an appropriate business contact;
- understand an existing website and business requirements;
- prepare or deliver a personalized Concept page;
- prepare, explain, revise, and administer a personalized service proposal; and
- schedule a meeting or demonstration.
A person does not need to open an account or provide payment-card information merely to view a personalized Concept page.
5.2 To form and administer the customer agreement
We may use information to:
- verify authority to act for a business;
- record electronic acceptance;
- create and manage an account or subscription;
- establish the service start date, term, renewal, cancellation, or termination status;
- issue invoices, receipts, notices, and service records; and
- maintain an accurate history of the customer relationship.
5.3 To build, host, operate, and support services
We may use information to:
- design, configure, build, publish, and update websites;
- connect domains and configure DNS, SSL/TLS, hosting, monitoring, and deployment;
- provide AI-enabled functions, automation, analysis, or integrations described in the accepted service proposal;
- process support requests, diagnose issues, and restore service;
- manage content changes and approvals; and
- provide maintenance, monitoring, and basic support.
5.4 To process payments and manage accounts receivable
We may use and disclose billing information to:
- initiate and reconcile charges through the payment processor;
- manage recurring billing;
- identify failed or overdue payments;
- send payment notices;
- address chargebacks or payment disputes; and
- collect amounts lawfully owed.
5.5 To secure the service and prevent misuse
We may use information to:
- authenticate users and control access;
- monitor system health, suspicious activity, abuse, malware, spam, phishing, and fraud;
- investigate incidents or policy violations;
- maintain logs and evidence; and
- protect Docscope, customers, website visitors, service providers, and the public.
5.6 To operate and improve the business
We may use appropriate information to:
- understand service performance and reliability;
- measure general website or feature usage;
- improve workflows, documentation, support, templates, and service quality;
- train staff or contractors using appropriately limited information;
- plan capacity and business operations; and
- create aggregated or de-identified information where permitted by law.
Docscope will not treat information as de-identified if it can reasonably be linked back to an individual using information available to Docscope.
5.7 To send service and marketing communications
We may send operational communications about proposals, payments, security, service changes, renewals, support, and the customer relationship.
We may send commercial electronic messages only where permitted by Canada's Anti-Spam Legislation or other applicable law. Messages will include required identification and unsubscribe information. An unsubscribe request does not stop necessary transactional, security, billing, or service communications.
5.8 To meet legal and professional obligations
We may use or disclose information to:
- comply with applicable law, tax, accounting, corporate, and record-keeping duties;
- respond to lawful demands, court orders, warrants, or regulatory requirements;
- obtain legal, accounting, insurance, security, or other professional advice;
- establish, exercise, or defend legal rights; and
- complete a proposed or completed financing, reorganization, merger, acquisition, or sale, subject to applicable privacy law and appropriate safeguards.
6. Consent and other authority under Canadian privacy law
Canadian private-sector privacy law generally requires meaningful consent for the collection, use, or disclosure of personal information, subject to statutory exceptions.
Depending on the sensitivity, purpose, and circumstances, consent may be express or implied. For example, when a person voluntarily provides a work email address and asks Docscope to prepare a proposal, consent to use that information for the request may be implied. Express consent may be requested for a new, non-obvious, or sensitive purpose.
Docscope will not require consent to collect, use, or disclose personal information beyond what is reasonably necessary to provide a requested product or service, except where the person has a meaningful choice.
Docscope may also collect, use, or disclose information without consent where a law permits or requires it, including in certain situations involving fraud prevention, debt collection, investigations, legal demands, emergencies, publicly available information, or a business transaction.
A person may withdraw consent, subject to reasonable notice and legal or contractual restrictions. Withdrawal may limit Docscope's ability to provide a requested service. Withdrawal of marketing consent does not affect service, security, billing, legal, or other communications that do not require marketing consent.
7. Service providers and other disclosures
Docscope may provide personal information to service providers that perform functions for Docscope or help deliver the service, including providers of:
- payment processing and recurring billing;
- cloud infrastructure, hosting, storage, content delivery, backup, and deployment;
- domain registration, DNS, certificates, and internet infrastructure;
- email, communications, customer support, and document services;
- security, monitoring, logging, fraud prevention, and incident response;
- privacy-focused website analytics and service diagnostics;
- AI models, AI infrastructure, automation, or data-processing services where an AI-enabled function is used;
- accounting, legal, insurance, audit, and other professional services; and
- business continuity, corporate transactions, or asset transfers.
Service providers may process information only for authorized purposes and are expected to use safeguards appropriate to the information and service. Docscope remains accountable for personal information under its control, subject to applicable law.
Docscope may also disclose information:
- to a customer or its authorized users where the information relates to that customer's service;
- to a person the individual directs or authorizes;
- to protect rights, safety, systems, or property;
- in connection with a legal process or regulatory requirement; or
- as otherwise permitted or required by law.
8. AI service providers and submitted content
Where an accepted service includes an AI-enabled function, content, prompts, files, or other data may be processed by Docscope systems or an AI service provider to perform the requested function.
The particular data flow may differ by service. Docscope will use the information for the agreed service, security, support, and lawful operational purposes. A customer that expects personal information, confidential information, or regulated data to be processed through an AI function should confirm the permitted data, provider requirements, retention settings, and safeguards in the accepted proposal or a separate written addendum.
Individuals and customers should not submit highly sensitive personal information to a general AI-enabled feature unless Docscope has expressly approved that use in writing.
AI processing may produce inaccurate or unexpected output. Privacy rights and decisions should not be based solely on an unreviewed AI output.
9. Processing outside British Columbia or Canada
Docscope and its service providers may process or store information in British Columbia, elsewhere in Canada, the United States, or another jurisdiction where a provider operates.
When information is processed in another jurisdiction, it may be subject to that jurisdiction's laws and may be accessible to courts, law-enforcement agencies, national-security authorities, or regulators in accordance with those laws.
Canadian privacy law does not generally prohibit using an out-of-country service provider, but Docscope remains responsible for personal information under its control. Docscope uses contractual, organizational, and technical measures that are reasonable for the sensitivity and circumstances and considers provider privacy and security practices when selecting and managing material service providers.
A person may contact the Privacy Officer for general information about material cross-border processing relevant to that person's information.
10. Security safeguards
Docscope uses reasonable administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, collection, use, disclosure, copying, modification, loss, disposal, or similar risks.
Safeguards may include, as appropriate to the service and information:
- access controls and least-privilege practices;
- authentication and account-management controls;
- encryption in transit and other encryption where appropriate;
- secure hosting and network configuration;
- software updates, monitoring, logging, and incident-response procedures;
- confidentiality obligations for personnel and service providers;
- backup, recovery, and continuity measures; and
- secure deletion or de-identification processes.
No safeguard can eliminate every risk. Docscope does not claim that its systems or any third-party system are absolutely secure.
Customers are responsible for protecting their own accounts, email, devices, domain registrar access, credentials, and authorized-user lists, and for promptly reporting suspected compromise.
11. Information processed for customer websites
A customer may use a Docscope-hosted website to receive inquiries, form submissions, or analytics information from its own visitors.
Where the customer determines why and how that visitor information is collected and Docscope processes it only to provide hosting, transmission, storage, security, troubleshooting, or support, Docscope acts as a service provider for the customer. In that situation:
- the customer is responsible for giving visitors an appropriate privacy notice and obtaining required consent;
- the customer must give Docscope lawful instructions;
- Docscope may process the information to provide, secure, maintain, and support the service and as required by law;
- a visitor should usually direct a privacy request first to the customer business shown on the website; and
- Docscope may forward a request to the customer or assist the customer as reasonably required by the agreement and applicable law.
Docscope may separately control limited technical, billing, security, or business-administration information needed for Docscope's own lawful purposes, as described in this Policy.
Customers must not configure general website forms to collect highly sensitive or regulated information without prior written agreement on the necessary safeguards and responsibilities.
12. Retention and disposal
Docscope retains personal information only as long as reasonably necessary for the identified purposes, including to provide service, maintain security and business records, comply with legal, tax, accounting, and contractual obligations, resolve disputes, collect amounts owed, and establish or defend legal rights.
Retention depends on the type of information, sensitivity, service relationship, legal obligations, operational need, and whether the information is contained in an active system, archive, log, or backup.
Where British Columbia's Personal Information Protection Act requires information used to make a decision that directly affects an individual to be retained for at least one year, Docscope will retain it for the required period so the individual has a reasonable opportunity to request access.
When information is no longer reasonably required for a legal or business purpose, Docscope will use reasonable processes to delete it, destroy the record, or remove the means by which it can be associated with an individual. Residual copies may remain temporarily in secure backups, system logs, legal holds, or disaster-recovery systems until they are overwritten or deleted through normal processes.
This Policy does not promise a single fixed retention period for every category of information.
13. Access, correction, and deletion requests
An individual may request access to personal information about that individual under Docscope's control and may ask how it has been used or disclosed, subject to exceptions in applicable law.
An individual may also ask Docscope to correct inaccurate or incomplete personal information. Docscope may ask for reasonable information to verify identity and locate the relevant records.
Requests should be sent in writing to [email protected] with enough detail to identify the person, the relationship with Docscope, and the information requested.
Docscope will respond within the time required by applicable law. Under British Columbia's PIPA and federal PIPEDA, the ordinary response period is generally 30 days, subject to permitted extensions and exceptions.
Access may be limited or refused where required or permitted by law, including where disclosure would reveal another person's personal information, confidential commercial information, privileged information, security-sensitive information, or information connected to an incomplete investigation. Where appropriate, Docscope will explain the reason and available complaint process.
An individual may ask Docscope to delete personal information. Canadian privacy law does not create an unlimited deletion right in every circumstance. Docscope will assess the request and will delete or de-identify information where reasonably required or appropriate, but may retain information needed for an active contract, security, fraud prevention, legal compliance, record-keeping, debt collection, dispute resolution, backup integrity, or legal claims.
Where information is processed only for a customer, Docscope may refer the request to that customer or act on the customer's lawful instructions.
14. Privacy incidents
Docscope maintains processes to assess and respond to suspected loss of, unauthorized access to, or unauthorized disclosure of personal information.
Docscope will investigate a confirmed incident, take reasonable containment and remediation steps, document the incident as required, and notify affected individuals, customers, privacy regulators, or other authorities where notification is required by applicable law.
15. Marketing choices
A person may unsubscribe from marketing emails using the unsubscribe method in the message or by contacting [email protected].
Docscope will process unsubscribe requests as required by applicable law. Docscope may continue to send non-marketing communications that are reasonably necessary for a proposal requested by the person, an active service, billing, security, legal notice, support, or the administration of a customer relationship.
16. Privacy complaints
A person who has a privacy concern should contact the Privacy Officer first so Docscope can investigate and respond.
If the concern is not resolved, the person may have the right to complain to the Office of the Information and Privacy Commissioner for British Columbia, the Office of the Privacy Commissioner of Canada, or another privacy regulator with jurisdiction.
Docscope will not retaliate against a person for raising a privacy concern or exercising a lawful privacy right.
17. Changes to this Policy
Docscope may update this Policy to reflect changes in law, services, technology, providers, or practices. The current version will show its effective date.
If a change is material, Docscope will use reasonable methods to provide additional notice. Where applicable law requires new consent for a new purpose, Docscope will seek that consent before using information for the new purpose.
18. Language and controlling version
This Policy may be made available in English, Simplified Chinese, and Canadian French. The English version is the authoritative version and controls in the event of a conflict or inconsistency, to the fullest extent permitted by mandatory applicable law.
Nothing in this language clause limits a right that mandatory applicable law gives a person to receive, rely on, or invoke another language version.
19. Contact the Privacy Officer
Privacy questions, consent withdrawals, access requests, correction requests, deletion requests, or complaints may be sent to:
Privacy Officer
Docscope AI Inc.
Richmond, British Columbia, Canada
Email: [email protected]
A mailing address for formal privacy correspondence is available on request through this email.