Privacy policy
How we handle personal information, written to be read rather than skipped.
Last updated:
Who we are
Built by AI ([Legal entity name]) is a software and consulting business based in Toronto, Ontario, Canada. In this policy, "we" and "us" mean Built by AI, and "you" means anyone who visits this website or contacts us.
We are the organisation responsible for the personal information described below. You can reach our privacy contact at hello@builtbyai.ca or by writing to [business address].
What we collect
Information you give us
When you submit the contact form or email us, we collect the details you provide: your name, email address, and — if you choose to include them — your phone number, company, budget range, timeline, and description of your project.
Information collected automatically
Our website host records standard server logs (IP address, browser type, pages requested, timestamps) for security and reliability. If we use analytics, we use a privacy-respecting, cookieless product that does not track you across other websites and does not build an advertising profile of you.
This site sets no advertising or tracking cookies. The only browser storage we use is a single local preference remembering whether you chose the light or dark theme — it never leaves your device.
Client project information
During an engagement, we may be given access to your business systems and data, which can include personal information about your customers or staff. We handle that strictly under the terms of our client agreement, use it only to deliver the agreed work, and return or delete it on request at the end of the engagement.
Why we collect it, and your consent
We use personal information only for these purposes:
- To respond to your enquiry and discuss a possible project.
- To prepare quotes, contracts, and invoices.
- To deliver and support work you have engaged us for.
- To keep the website secure and working properly.
- To meet our legal, tax, and accounting obligations.
We do not sell personal information, rent it, or share it for advertising. We do not add you to a marketing list because you contacted us. If we ever start a newsletter, you will have to opt in deliberately.
Who else touches your information
We use a small number of service providers to run the business. Each has access only to what it needs:
- Website hosting and CDN — serving this site and keeping server logs.
- Form processing — delivering contact form submissions to our inbox.
- Email — receiving and replying to your messages.
- Accounting and payments — issuing invoices and processing payment.
- Project and document tools — managing work in progress.
Some of these providers store data outside Canada, including in the United States. While information is in another country it may be accessible to that country's courts and law enforcement under their laws. We choose providers with appropriate safeguards and contractual protections. If your project requires Canadian data residency, tell us during scoping and we will build to that constraint.
We will otherwise only disclose personal information where the law requires it, or where it is necessary to establish or defend a legal claim.
Artificial intelligence
We use AI tools in our own development and consulting work. Where a project involves sending your data to a third-party AI provider, we will tell you which provider, what is sent, and what they retain — before it happens, in writing, as part of scoping.
We disable training on customer data wherever a provider offers that setting, and we do not feed client information into consumer AI products. Where a workload is too sensitive to leave your environment, we can build using models that run inside your own cloud tenancy or on your own hardware.
How long we keep it
Enquiries that do not become projects are kept for up to 24 months, in case you come back, and then deleted. Client records, contracts, and invoices are kept for seven years to satisfy Canadian tax and record-keeping requirements. Server logs are kept for a short period — typically 30 days.
How we protect it
This site is served over HTTPS. Access to accounts and client systems is protected by strong, unique credentials and multi-factor authentication. We apply least-privilege access, keep dependencies patched, and limit who can see client data to the people working on that engagement.
No system is perfectly secure, but if a breach ever affected your personal information in a way that creates a real risk of significant harm, we would notify you and the Office of the Privacy Commissioner of Canada as PIPEDA requires.
Your rights
Under PIPEDA you can, at any time:
- Ask what personal information we hold about you and get a copy.
- Ask us to correct anything inaccurate or incomplete.
- Withdraw consent and ask us to delete your information, subject to our legal retention obligations.
- Ask how we use it and who we have shared it with.
- Complain about how we handled it.
Email hello@builtbyai.ca and we will respond within 30 days at the outside — usually much sooner. There is no charge for a reasonable request.
If you are not satisfied with our answer, you can contact the Office of the Privacy Commissioner of Canada.
Children
This is a business-to-business website. We do not knowingly collect personal information from anyone under 16. If you believe we have, contact us and we will delete it.
Links to other sites
Where we link to another website, that site's own privacy practices apply once you leave ours. We are not responsible for how they handle your information.
Changes to this policy
If we change how we handle personal information, we will update this page and change the date at the top. Material changes will be flagged to active clients directly rather than only posted here.
Contact
Questions about this policy, or about anything we hold on you:
hello@builtbyai.ca
Built by AI — [Legal entity name], [business address], Toronto, Ontario, Canada.