Privacy Policy — Norquay AI Advisory
Last updated: September 4, 2026
1. Who this policy covers
This policy describes how Norquay AI Advisory ("Norquay," "we," "us") collects, uses, stores, and protects information through the Norquay AI Advisory SaaS platform (the "Service"), available at norquayaiadvisory.ca. It applies to the businesses that subscribe to the Service ("clients," "you") and, where relevant, to the customers and contacts whose information a client processes through the Service.
Norquay is based in Alberta, Canada, and this policy is written with reference to Alberta's Personal Information Protection Act (PIPA) and the federal Personal Information Protection and Electronic Documents Act (PIPEDA).
2. What we collect
Account and business information you or your team provide when you sign up and use the Service: company name, your name, email address, and information you enter or upload while using the platform's features (e.g., financial records, quotes, invoices, customer communications, and related business documents, depending on which features you use).
Customer data your business processes. If your business's customers or contacts appear in data you enter into the Service, we process that information as your service provider, on your instructions.
Usage and technical data: log-in activity, IP address, browser/device information, and how you interact with the Service — used for security (rate limiting, fraud/abuse prevention, and detecting anomalous access) and to operate and improve the product.
Payment information: handled entirely by Stripe. We never receive, store, or process raw card numbers ourselves — we only receive a reference to your subscription and payment status from Stripe.
3. How AI is used to process your data
The Service uses Anthropic's Claude AI models to power its features (for example, drafting content, analyzing business data, and generating recommendations within the platform's skills). When you use an AI-powered feature, the relevant data you've entered is sent to Anthropic's API to generate that feature's output.
Data sent to Anthropic through our API integration is not used by Anthropic to train its models, under Anthropic's commercial API terms. We do not use your business or customer data to train any AI model ourselves, build case studies, or share it with other clients.
4. Third parties we share data with
We use the following third-party services to operate the platform:
- Anthropic — AI model access, powering the platform's AI-driven features
- Supabase — database, authentication, and file storage where your account and business data is stored
- Stripe — payment processing and subscription billing
- Twilio — SMS/messaging features, where applicable
- Meta — social media publishing integrations, where you connect a Meta/Facebook/Instagram account
- Google — integrations with Google services, where you connect a Google account
We will update this list, and notify clients, before adding a new subprocessor that would handle client data.
5. How long we keep your data
- Your account and business data is kept for as long as your subscription is active.
- If you cancel, your data remains recoverable for 30 days in case you reactivate, after which it is permanently deleted (also triggered immediately if you request deletion directly).
- Records we're required to keep for our own tax/accounting purposes are kept for 7 years, separately from your business data.
6. Security measures
- All traffic is encrypted in transit (HTTPS/TLS); data is encrypted at rest.
- Every client's data is isolated at the database level (row-level security) so it is structurally unreachable by any other client — this is tested, not just assumed.
- Individual logins per user, with optional two-factor authentication.
- Rate limiting and bot protection on login and signup.
- If a security incident actually exposes your data, we will notify you within 48 hours of becoming aware, in writing, with what's known at the time — even if our investigation isn't finished.
7. Your rights
Under PIPA/PIPEDA, you can request access to the personal information we hold about you, ask us to correct it, or ask us to delete it (subject to what we're legally required to retain). Contact us using the details below to make a request.
8. Cookies
The Service uses a session cookie required for you to stay logged in. We do not use advertising or cross-site tracking cookies.
9. Children's data
The Service is intended for business use and is not directed at children. We do not knowingly collect personal information from children.
10. Changes to this policy
We'll update this page when our practices change and note the date at the top. Material changes affecting how your data is used will be communicated directly, not just posted silently.
11. Contact
Questions about this policy or a data request: hello@norquayaiadvisory.ca