Privacy Policy

    Last Updated: February 2026

    1. Introduction

    This Privacy Policy explains how personal data is collected, used, stored, transferred internationally, and protected when you use our AI-assisted software designed for architecture firms. It applies to all website, application and system users and customers who interact with our services. The policy is governed by Canadian Personal Information Protection and Electronic Documents Act (PIPEDA) and United States state privacy laws.

    2. Scope and Application

    This Privacy Policy applies to all website, application and system users and customers of our AI-assisted software for architecture firms. It covers the collection, use, storage, international transfer, and protection of personal data in accordance with Canadian PIPEDA and United States state privacy laws, and United Arab Emirates data protection requirements.

    3. Definitions

    Set out defined terms used in this Privacy Policy and their meanings, including but not limited to: "Personal Data", "Processing", "Data Controller", "Data Processor", "User", "Customer", "Service", "AI-assisted Software", "Architecture Firm", "International Transfer", "Applicable Laws".

    4. Data Controller and Contact Details

    The data controller for personal data processed under this Privacy Policy is Project Rayder Inc., located at 1366, Creekside Dr., Oakville, ON, L6H 4Z3, Canada. For privacy-related queries, requests, or concerns, please contact our Data Protection Officer at [email protected] or +1 (647) 676-7886. Where required by applicable law, we have appointed a representative in the relevant jurisdiction. Contact details for our representative are: Shezan Mukadam, #2404, 15, Legion Road, Toronto, [email protected].

    5. Personal Data We Collect

    We collect personal data including account information (such as name, email address, organisation, and role), usage data (such as log-in records, device and browser details, IP address, and activity logs), communications data (such as messages, support requests, and feedback), and any other information provided through our AI-assisted software for architecture firms. Additional categories may include payment details, professional credentials, and project-related content submitted by users or customers.

    6. Sources of Personal Data

    We collect personal data from multiple sources, including directly from users when they register, interact with our software, or communicate with us; from customers who provide information about their authorised users or project teams; staff members and from third party sources such as service providers, business partners, or publicly available databases, where permitted by applicable law.

    7. Purposes of Processing

    We process personal data for the following purposes: to deliver and operate our AI-assisted software for architecture firms; to improve and develop our services and user experience; to comply with applicable laws and regulatory requirements; to manage customer accounts and relationships; to respond to support requests and communications; to analyse usage and performance; to ensure data security and integrity; and to facilitate international transfers and lawful disclosures. Additional purposes may include research, product enhancement, and fraud prevention, as permitted by law.

    8. Legal Bases for Processing

    We process personal data on the following legal bases, as required by applicable laws in each jurisdiction: (a) with the consent of the data subject; (b) for the performance of a contract with the user or customer; (c) to comply with legal obligations under Canadian PIPEDA and United States state privacy laws; (d) for our legitimate business interests, including improving and securing our AI-assisted software for architecture firms, provided such interests are not overridden by the rights and freedoms of data subjects; and (e) where necessary to protect vital interests or for the establishment, exercise, or defence of legal claims. Where consent is required, users and customers may withdraw consent at any time by contacting us at [email protected].

    9. Use of AI and Automated Decision Making

    Our AI-assisted software for architecture firms uses artificial intelligence and automated decision-making to analyse RFP-related information and past proposal content. Automated processing may include profiling to suggest relevant proposals, optimise workflows, and enhance user experience. No decisions with significant legal or similar effects are made solely by automated means without human review. Safeguards are implemented to ensure transparency, fairness, and accuracy, including regular audits and the opportunity for users to request human intervention or clarification regarding automated outcomes. If you have questions about our use of AI or wish to object to automated decisions, please contact us at [email protected].

    10. Cookies and Similar Technologies

    We use cookies, analytics, and similar technologies to enhance user experience, analyse website usage, and improve our AI-assisted software for architecture firms. Cookies may be essential for site functionality, performance, or personalisation. Analytics tools help us understand how users interact with our services. You may manage or disable cookies through your browser settings; however, some features may not function properly if cookies are disabled. For more information about the types of cookies and technologies used, and your options, please refer to our Cookie Notice or contact us at [email protected].

    11. Retention of Personal Data

    We retain personal data for as long as necessary to fulfil the purposes for which it was collected, including to comply with legal, regulatory, and contractual obligations. Account information and usage data are retained while your account is active and for twelve (12) months after account closure, unless a longer retention period is required by law. Communications data and project-related content are retained for twenty-four (24) months or as required to resolve disputes or enforce agreements. Criteria for determining retention periods include the nature of the data, applicable legal requirements, and business needs. Upon expiry of the retention period, personal data is securely deleted or anonymised.

    12. International Data Transfers

    Personal data may be transferred to and processed in jurisdictions outside your country of residence, including Canada, the United States and other locations where our service providers, infrastructure, or business partners operate. Such transfers are conducted in compliance with applicable laws and subject to appropriate safeguards, including contractual clauses, data protection agreements, and technical measures designed to ensure the security and lawfulness of processing. Where required, you may request a copy of the relevant safeguards by contacting us at [email protected].

    13. Disclosure of Personal Data to Third Parties

    We disclose personal data to third parties in accordance with applicable laws and for specified purposes. Categories of third parties may include service providers (such as cloud hosting, analytics, and payment processors), business partners, professional advisors, regulatory authorities, and law enforcement agencies. Disclosures are made to facilitate service delivery, comply with legal obligations, manage business operations, protect rights and interests, and support fraud prevention or security measures. Where required, we enter into data protection agreements with third parties to ensure appropriate safeguards for personal data. Further details regarding third party disclosures are available upon request.

    14. Data Security Measures

    We implement technical and organisational measures to protect personal data against unauthorised access, loss, alteration, or disclosure. These measures include encryption of data in transit and at rest, access controls, regular security audits, staff training, and secure infrastructure provided by reputable third-party providers. Our systems are monitored for vulnerabilities and incidents, and we maintain policies for incident response and data breach notification in accordance with Canadian and US requirements. Users and customers are encouraged to use strong passwords and safeguard their account credentials. Further details regarding our security practices are available upon request.

    15. Your Rights Under Canadian Privacy Law

    Individuals have the right under Canadian privacy law, including PIPEDA, to access their personal data, request corrections, and withdraw consent for processing where applicable. You may also request information about how your data is used, challenge the accuracy of your data, and file complaints with the Office of the Privacy Commissioner of Canada. To exercise these rights, please contact us at [email protected] or follow the procedures outlined in this Privacy Policy. We will respond to requests within thirty (30) days or sooner, as required by law. If you are dissatisfied with our response, you may escalate your concern to the relevant privacy authority.

    16. Your Rights Under United States Privacy Laws

    Individuals have rights under United States privacy laws, including the right to access personal data, request correction or deletion, and opt out of certain data processing activities. State-specific laws, such as the California Consumer Privacy Act (CCPA), may provide additional rights, including the right to know what personal data is collected, the right to request deletion, and the right to opt out of the sale or sharing of personal data. To exercise these rights, please contact us at [email protected]. We will respond to requests within forty-five (45) days or sooner, as required by law. If you are dissatisfied with our response, you may contact the relevant state privacy authority.

    17. Exercising Your Privacy Rights

    Individuals may exercise their privacy rights by submitting a written request to our Data Protection Officer at [email protected] or via the online portal at www.myarchfp.com. Upon receipt, we will verify your identity by matching account details and/or requesting supporting documentation. We aim to respond to all requests within thirty (30) days or sooner, subject to applicable law. If additional information is required to process your request, we will notify you promptly. Requests may be denied where permitted by law, including where compliance would compromise the rights of others or conflict with legal obligations.

    18. Children's Privacy

    Our AI-assisted software and related services are not directed to children under the age of thirteen (13) and we do not knowingly collect personal data from children. If we become aware that personal data from a child has been collected without appropriate parental consent, we will take steps to delete such information promptly. Parents or guardians who believe their child has provided personal data may contact us at [email protected] to request removal. Where applicable, we comply with relevant laws regarding children's privacy, including the Children's Online Privacy Protection Act (COPPA) in the United States and similar requirements in other jurisdictions.

    19. Direct Marketing and Communications

    We may send direct marketing communications, including updates about our AI-assisted software for architecture firms, service announcements, and promotional offers, to users and customers who have provided consent or as permitted by applicable law. You may manage your communication preferences or withdraw consent at any time by following the unsubscribe instructions in our emails or by contacting us at [email protected]. Opting out will not affect essential service-related communications. For further details on managing marketing preferences, please refer to our website or contact our Data Protection Officer.

    20. Enterprise Customers and Authorised Users

    Enterprise customers are responsible for ensuring that authorised users comply with this Privacy Policy and applicable data protection laws. Authorised users may include employees, contractors, or other individuals designated by the enterprise customer to access and use our AI-assisted software for architecture firms. Enterprise customers must provide accurate information about authorised users, obtain any necessary consents, and communicate relevant privacy notices. We process personal data of authorised users on behalf of enterprise customers, who act as data controllers for such data. Our obligations as a data processor are governed by applicable agreements and laws. Enterprise customers must promptly notify us of any changes to authorised user status or data subject requests relating to personal data processed through our services.

    21. Data Storage Location and Infrastructure Providers

    Personal data is primarily stored on secure servers located in Canada and the United States, depending on user location and applicable legal requirements. Our key infrastructure and hosting providers include reputable third-party cloud service providers who maintain robust security and compliance standards. Data may also be processed or backed up in additional jurisdictions as required for redundancy and business continuity. Details regarding specific storage locations and infrastructure partners are available upon request.

    22. Data Protection by Design and Default

    We integrate privacy and data protection principles into the design, development, and operation of our AI-assisted software for architecture firms. By default, personal data is collected and processed only to the extent necessary for specified purposes, with access restricted to authorised personnel. Technical and organisational measures, such as data minimisation, pseudonymisation, and secure default settings, are implemented to ensure compliance with Canadian and US data protection laws. Regular reviews and assessments are conducted to maintain privacy by design and default, and to address emerging risks. Users and customers are provided with clear options to manage privacy settings and exercise their rights under applicable law.

    23. Data Breach Response

    We maintain internal procedures to promptly identify, contain, and assess any suspected or confirmed data breach involving personal data. Upon detection, our incident response team investigates the breach, mitigates risks, and documents findings. Where required by Canadian PIPEDA or United States state privacy laws, we will notify affected individuals and relevant authorities without undue delay, providing details of the breach, potential impacts, and remedial actions. Notifications will be made in accordance with applicable legal timeframes and may include guidance for individuals to protect themselves. For further information about our breach response process, or to report a suspected breach, please contact our Data Protection Officer at [email protected].

    24. Links to Third Party Sites and Services

    Our AI-assisted software for architecture firms may contain links to third party websites, platforms, or services. Such third party sites and services operate independently and are subject to their own privacy policies and practices, which are not controlled, endorsed, or governed by us. We are not responsible for the privacy, security, or content of any third party sites or services. Users and customers are encouraged to review the privacy policies of any third party sites or services before providing personal data or engaging with them. Accessing third party links is at your own risk.

    25. Changes to This Privacy Policy

    We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or the features of our AI-assisted software for architecture firms. Any material changes will be communicated by posting the revised Privacy Policy on our website and, where required by law, by providing direct notice to users and customers via email or other appropriate means. The effective date of the updated Privacy Policy will be indicated at the top of the document. Continued use of our services after the effective date of any changes constitutes acceptance of the revised Privacy Policy. We encourage you to review this Privacy Policy periodically to stay informed about how your personal data is handled.

    26. Governing Law and Complaints

    This Privacy Policy is governed by the laws of Canada (PIPEDA) and applicable United States state privacy laws. Individuals may lodge complaints regarding personal data handling by contacting our Data Protection Officer at [email protected], or by submitting a complaint to the relevant privacy authority in their jurisdiction, such as the Office of the Privacy Commissioner of Canada or the appropriate US state privacy regulator. We encourage individuals to contact us directly with any concerns before escalating to a regulatory authority. Complaints will be investigated promptly and addressed in accordance with applicable legal requirements.

    27. Contact Information

    For privacy queries, rights requests, and complaints, please contact our Data Protection Officer at [email protected], or write to Project Rayder Inc. at 1366, Creekside Dr., Oakville, ON, L6H 4Z3, Canada.

    Phone: +1 (647) 676-7886

    Online: www.myarchfp.com