Legal
Privacy Policy
Effective date: July 5, 2026
This policy explains how ParsenLog handles personal data. It covers two distinct situations: (1) data about you as a website visitor or account user, where we are the controller; and (2) the documents our customers submit to the service, which we process on their behalf as a processor.
1. Who we are
ParsenLog Inc. is a corporation incorporated in 2026, with its head office located in Toronto, Ontario, Canada. It provides a contract intelligence and management Software as a Service (SaaS) platform.
2. Two roles: controller and processor
As a controller, we determine how we handle personal data about website visitors, prospects, and the individual users of our customers’ accounts (for example, account and contact details). This policy governs that data.
As a processor, we handle the documents and contract data that our business customers upload to the service. We process that data only on the customer’s instructions, under our Data Processing Agreement (DPA). If you are an individual whose information appears in a document a customer uploaded, that customer is the controller — please direct your request to them.
3. Data we collect
- Account data — name, work email, organization, and authentication data (managed by our authentication provider).
- Contact data — information you submit through our contact form or by emailing us (name, email, company, message).
- Usage & device data — log data such as IP address, browser type, and interactions with the service, used to operate, secure, and improve it.
- Customer-submitted documents — contracts and files uploaded by our customers, which may contain personal data. We process these as a processor (see Section 2), not for our own purposes.
4. How we use personal data
- To provide, maintain, secure, and improve the service.
- To respond to enquiries and provide support.
- To manage accounts, authentication, and billing.
- To comply with legal obligations and enforce our terms.
We do not sell personal data, and we do not use customer-submitted documents to train general-purpose or foundation AI models.
5. Legal bases
We currently operate in Canada, and our handling of personal data is governed by applicable Canadian privacy law (including PIPEDA and applicable provincial laws). We collect and use personal data to provide and secure the service, for business communications, with your consent where required (e.g. certain cookies or marketing), and to meet our legal obligations. Where the EU or UK GDPR applies, we rely on the corresponding legal bases — performance of a contract, legitimate interests, consent, and legal obligation.
6. Sharing with service providers
We share personal data with third-party service providers who process it on our behalf — for hosting, storage, document processing (OCR), AI extraction, authentication, and email — each bound by contract to protect it and use it only for those purposes. We will provide the current list on request, and it is set out in our data-processing agreement. We may also disclose data where the law requires it, or as part of a merger or acquisition, subject to appropriate safeguards.
7. International transfers
We host and store customer data on Microsoft Azure in Canada. The AI extraction step is performed on Microsoft Azure infrastructure in the United States; prompts and outputs are processed only to provide the service and are not used to train AI models. Where personal data is transferred across borders (for example, for that processing or to another service provider), we rely on appropriate safeguards such as Standard Contractual Clauses where required by law.
8. Retention
We keep personal data only as long as needed for the purposes above or as required by law. Customer-submitted documents are retained for the customer’s subscription term and then returned or deleted under the DPA. Account and contact data is retained while your account or relationship with us is active, and for a reasonable period afterward.
9. Security
We use administrative, technical, and organizational measures designed to protect personal data, including encryption in transit and at rest, per-organization isolation, and access controls. See our Security page for more.
10. Your rights
Depending on your location, you may have rights to access, correct, delete, restrict, or object to the processing of your personal data, and to data portability. To exercise a right, reach us through our Contact page. If your information appears in a document uploaded by one of our customers, please contact that customer, who is the controller of that data. You may also have the right to complain to a supervisory authority.
11. Cookies
We use only necessary cookies to operate the site and keep you signed in (for example, authentication and session cookies set by our login provider). We do not currently use analytics, advertising, or other tracking cookies. If that changes, we will update this policy and obtain your consent where required.
12. Children
The service is intended for business use and is not directed to individuals under 16. We do not knowingly collect personal data from children.
13. Changes to this policy
We may update this policy from time to time. We will post the updated version here and revise the effective date above. Material changes will be communicated as required by law.
14. Contact us
Questions or requests: reach us through our Contact page.