Get Started

Privacy Policy

Version: 1.1

Effective Date: April 18, 2026

Last Updated: April 28, 2026

1 Introduction and Scope

Poardal Software Inc. ("Poardal Software," "we," "us," or "our") provides Innovique Studio (the "Service") — an AI-powered marketing intelligence software-as-a-service platform — and operates the related marketing website. This Privacy Policy describes how we collect, use, share, and otherwise process personal information in connection with: (a) our marketing website at innoviquestudio.com; and (b) our application at app.innoviquestudio.com, including when you create an account, administer a workspace, or use any of the features of the Service (AI agents, analytics dashboards, creative tools, social publishing, agency tools, and related functionality).

Innovique Studio is a product of Poardal Software Inc. References to "Innovique Studio" in this policy mean the Service and related offerings described above.

SaaS and Customer Relationship. The Service is provided to Customers under a commercial agreement. When we process Customer Data to provide the Service (including hosting, authentication, AI-assisted content generation, analytics integrations, collaboration features, and support), we do so on behalf of and under the instructions of the applicable Customer, and we act as a service provider (and, where applicable, a "processor"). In those cases, the Customer is responsible for determining what Customer Data is submitted to the Service and for providing required notices and obtaining any necessary consents from its Authorized Users. Poardal Software acts as an independent controller for personal information we process for our own commercial relationship purposes (for example, sales communications, account administration, billing, security, fraud prevention, and marketing website interactions).

Commercial Relationship Notice. This Privacy Policy is written primarily for our business contacts and Customer organizations that purchase or evaluate the Service (a "commercial relationship"). If you are an employee, contractor, freelancer, or other representative of a Customer or prospective Customer, we may collect and use your personal information to manage our relationship with your organization (for example, to provide demos, set up accounts, administer subscriptions, provide support, and send service-related communications).

Key Definitions (summary). "Business Contact" means an individual acting in a business capacity for a Customer, partner, supplier, or prospective Customer. "Authorized User" means an individual authorized by a Customer to use the Service under that Customer's subscription (including owners, admins, managers, and members of a workspace). "Customer Data" means content and information (including personal information) submitted to, generated within, or processed through the Service by or on behalf of a Customer or its Authorized Users. "Workspace" means a tenant within the Service; workspaces can be organized into parent/child hierarchies (for example, agencies with client sub-workspaces) and share a single subscription at the parent level.

If you use the Service through a Customer (for example, your employer, agency, or the organization that invited you), please note that the Customer's own privacy practices may also apply. Our handling of Customer Data may also be governed by a separate agreement with the Customer (including data processing terms, where applicable).

Please read this Privacy Policy carefully. By accessing or using the Service, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree with the terms of this Privacy Policy, please do not access or use the Service.

Applicable Laws. We design our privacy practices to comply with applicable privacy and data protection laws where we operate, including Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and Quebec's Act Respecting the Protection of Personal Information in the Private Sector (Law 25). Depending on how you use the Service and where you are located, additional laws (such as the GDPR, UK GDPR, and certain U.S. state privacy laws including the CCPA/CPRA) may also apply.

We reserve the right to make changes to this Privacy Policy at any time and for any reason. We will alert you about any material changes by updating the "Last Updated" date of this Privacy Policy and notifying you via email. You are encouraged to periodically review this Privacy Policy to stay informed of updates.

2 Information We Collect

We collect personal information in several ways in the context of our commercial relationship with Customers and prospective Customers (including sales, contracting, billing, and support), when Authorized Users access and use the Service, and when visitors interact with our marketing website.

2.1 Business Contacts and Commercial Relationship Information

If you are a Business Contact (for example, you request a demo, negotiate or administer a subscription, or contact us for support), you may provide personal information such as your name, business email address, job title, organization, billing country, and the content of your communications with us.

2.2 Authorized Users and Customer Data (Service)

If you are an Authorized User, we collect and process Customer Data that you or your organization submits to the Service, and information associated with your account. Your organization's workspace owner or admin may also provide your details (for example, name and email address) when inviting you to a workspace.

· Name and email address

· Avatar image (optional)

· Time-zone preference

· Password (stored in hashed form using Supabase's managed bcrypt implementation) and multi-factor authentication (TOTP) configuration, if enabled

· Workspace name, slug, role (owner, admin, manager, or member), and membership history (including invitations sent, accepted, or revoked)

· Parent/child workspace relationships (for agency customers)

· Connected third-party credentials and metadata:

· Google Analytics 4 (GA4) and Google Search Console (GSC) OAuth access and refresh tokens, along with the connected Google account email address and selected property/site identifiers

· Access tokens, profile identifiers, display names, and avatar URLs for connected social media platforms (Twitter/X, Instagram, Facebook, LinkedIn, TikTok, YouTube, Pinterest, Reddit, Bluesky, Threads, Google Business Profile, Telegram, Snapchat, WhatsApp)

· WordPress site URLs, usernames, and Application Passwords

· Conversation content and files: your prompts, the AI-generated responses, attached documents (PDFs, Word documents, images, video, audio), extracted text from uploaded files, chat session titles, and model/usage metadata (input and output token counts, model identifiers, timestamps)

· Content you create or generate in the Service, including:

· Workshop (content library) items

· Presentations (slides, themes, charts, data tables, published deck URLs, and deck view analytics)

· Websites built with the Website Builder (pages, sections, SEO metadata, custom domain configuration, and contact-form submissions)

· Design Studio projects (canvases, layers, assets)

· Social Graphics Generator cards

· Blog HTML generations and their publication history

· Generated images (and their prompts, providers, and credit usage) and generated audio tracks

· Persona profiles and focus-group panel transcripts

· Brand Guidelines: brand name, tagline, voice and tone, language style, target audience, key messages, key personnel, contact information, social profile links, brand colors, fonts, industry, services, unique selling propositions, content guidelines, boilerplate copy, emoji preferences, logos, and image style guides (including material extracted from any URL you ask us to crawl or documents you upload)

· Agent Knowledge Base entries

· Agency data: URLs and names of prospects you submit for SEO audits, accessibility (WCAG) audits, or sales reports, and the resulting audit and report content

· Scheduled report configurations (recipient email addresses, schedule, included data sources)

· Usage records: token consumption per agent, chat counts, image and audio credit consumption, social post counts, Workshop and Knowledge Base item counts, monthly rollovers, and workspace-level storage usage

· Audit log entries: your name and actions related to member role changes, member additions or removals, workspace creation, team invitation acceptance, and plan/subscription changes

2.3 Website Visitors (Marketing Website)

If you visit innoviquestudio.com, we may collect information you submit through the site (for example, demo requests or contact-form messages) and information collected via cookies and similar technologies, including:

· Your name, email address, organization, and message content if you submit a form

·  Analytics data about your visit (pages viewed, session duration, traffic source, device and browser information, approximate geographic location) collected via Google Analytics

· IP address and connection metadata used for bot detection and regional currency display

2.4 Information Collected Automatically (Service and Website)

When you access or use the Service or visit our website, we (and our service providers) automatically collect certain information, such as:

· Device information: device type, operating system, browser type and version (user-agent string)

· Usage data: pages visited, features used, time spent on pages, and navigation patterns within the Service

· Log data: IP address (which may be truncated or masked in certain logs where feasible), access times, request paths, and referring URLs

· Session data: session identifiers, authentication tokens, session creation and expiration times, and last-activity timestamps (managed by Supabase)

· Performance and diagnostic data: application performance metrics, page-load times, long tasks, resource-loading events, error reports, crash logs, stack traces, and sampled session replays. Our performance-monitoring and error-tracking tools may receive identifiers (such as user ID and, where necessary, email address) to help us triage issues affecting specific accounts, and are configured to limit the collection of personal information where feasible; sensitive form inputs are masked by default.

· Geographic indicator for billing: the country associated with your connection at checkout (derived from our bot-protection provider's country header) is used to display pricing in CAD (for Canadian customers) or USD (for all other customers)

· Local storage and similar technologies. The Service uses browser cookies, local storage, and session storage to support essential functionality such as authentication, remembering your selected workspace, storing theme preferences, preserving in-progress editor state (for example, the SVG editor), and detecting stale application chunks after deploys. Authentication cookies are managed by Supabase as secure, HTTP-only cookies.

2.5 Information from Third Parties

We may receive personal information from third parties in a commercial-relationship context or to provide the Service, including from Customers, payment processors, connected third-party platforms, and our sub-processors.

· Workspace owners and administrators may provide your name and email address when inviting you to a workspace

· Stripe (our payment processor) provides subscription status, invoice events, billing country, and customer/subscription identifiers; we do not receive or store your full payment card number

· Google (GA4 and GSC), connected social media platforms, and connected WordPress sites return the analytics, content, and publishing data you have authorized us to access on your behalf

· DataForSEO returns business-listing, review, and search-result data in response to queries made by the Scout agent at your direction

· Unsplash returns stock-photo search results and download metadata when you search for images within the Presentation Builder or related tools

3 How We Use Your Information

We use personal information for the purposes described below. These purposes vary depending on whether you are a Business Contact, an Authorized User, or a website visitor, and whether we are acting as a controller (for our commercial-relationship purposes) or as a processor/service provider (for Customer Data).

3.1 Provide the Service (Customer Data)

· Create and manage your account, workspace profile, and parent/child workspace hierarchy

· Authenticate you (including multi-factor authentication where enabled) and maintain secure sessions

· Enable collaboration among workspace members based on their assigned roles

· Operate the Analytics Dashboard by calling the Google Analytics 4 and Google Search Console APIs on your behalf using read-only scopes

· Operate our AI agents (Nala, Maven, Quill, Echo, Pulse, Compass, Pixel, Scout, Nexus, Envoy, Nova, Sonic, and the Atlas orchestrator) and related features by sending your prompts, files, brand guidelines, and knowledge-base entries to third-party AI providers.

· Generate images, SVG graphics, and audio assets via the Pixel and Sonic agents and their underlying providers

· Publish content on your behalf to connected social media platforms, WordPress sites, and (for published presentations and websites) to our publishing infrastructure

· Run SEO audits, accessibility (WCAG) audits, and landing-page analyses against URLs you submit

· Crawl websites, process uploaded brand briefs, and store the resulting brand guidelines for later reference by agents

· Process payments and manage subscriptions through Stripe, including add-on purchases (for example, audio and token credit packs)

· Send transactional emails (account setup, password resets, team invitations, scheduled reports, contact-form deliveries, and other service notifications) via our transactional email provider

· Maintain audit logs for accountability, security, and compliance purposes

3.2 Commercial Relationship Administration

· Respond to inquiries, provide demos, and communicate with you about the Service

· Negotiate, enter into, and administer our contracts with Customers and partners

· Process payments, manage subscriptions, and maintain related records

· Provide support, manage support tickets, and communicate service-related updates

3.3 Security, Integrity, and Operations

· Verify your identity and prevent unauthorized access

· Protect against automated abuse and credential-stuffing via CAPTCHA challenges at sign-up

· Monitor application performance, availability, and error rates via our monitoring and error-tracking tools

· Detect, prevent, and respond to security threats, fraud, or technical issues

· Enforce tenant isolation via row-level security (RLS) and role-based access controls

· Maintain audit logs of significant workspace events (member changes, role changes, plan changes, workspace creation)

· Enforce our Terms of Use and subscription limits (including monthly token, chat, image, and audio credit allowances)

3.4 Product Improvement and Analytics

· Analyze usage and performance to maintain, support, and improve the Service (including troubleshooting and debugging)

· Develop and improve features, including based on aggregated trends and feedback

· Understand how visitors use innoviquestudio.com and measure marketing effectiveness (for example, via Google Analytics)

3.5 Communications (Service, Support, and Marketing)

· Respond to your inquiries and support requests via the in-app help assistant and email

· Send service communications and administrative notices (for example, onboarding, account updates, scheduled reports, and security alerts)

· Where permitted by law, send information about features, updates, and events related to the Service; you can opt out of non-essential communications.

3.6 Legal Compliance

· Comply with applicable laws, regulations, and legal processes

· Respond to lawful requests from public authorities

· Maintain records required by applicable law (for example, tax and accounting records)

3.7 Unauthorized Use

We do not:

· Sell your personal information in exchange for money

· Share personal information for cross-context behavioral advertising

· Share your personal information with third parties for their own direct marketing purposes

· Use Customer Data (including your prompts, files, brand guidelines, analytics data, or generated content) to train general-purpose AI models.

4 How We Share Your Information

We may share personal information in the following circumstances, including to provide the Service, manage our commercial relationship, and comply with legal requirements. Where we process Customer Data, we share it with service providers and other parties only as needed to provide and secure the Service and consistent with our agreements with Customers.

4.1 Within a Workspace

Your information is visible to other members of your workspace based on your role and permissions. Owners, admins, and managers can see membership lists, roles, and (where relevant) audit-log entries attributable to your name. Content you create in a workspace (chat sessions, Workshop items, Knowledge Base entries, Brand Guidelines, presentations, websites, designs, audit reports, and sales reports) may be visible to other workspace members according to the Service's access model. Owners and admins of a parent workspace automatically inherit access to child workspaces. This sharing is fundamental to the collaborative purpose of the Service.

4.2 Service Providers and Sub-Processors

We share information with trusted third-party service providers who process data on our behalf. These providers are contractually obligated to protect your information and may only use it to provide their services to us, consistent with applicable data protection requirements.

4.3 Infrastructure and Hosting

· Supabase — managed PostgreSQL database, authentication, file storage (including the buckets used for AI-generated images, brand guides, social media galleries, and audio), and edge-function runtime. Our primary Supabase project is hosted in a United States region.

· Netlify - hosting for the Innovique Studio application front-end

· Vercel - hosting for user-published presentations and websites (content published from the Presentation Builder and Website Builder is served from Vercel's infrastructure)

· Upstash (Redis) - short-lived caching of analytics query responses (GA4 and GSC) and business-listing/SERP responses to reduce third-party API usage and improve performance

4.4 Payment Processing

· Stripe - payment processing, subscription management, and secure storage of payment credentials. All payment transactions are conducted directly through Stripe's platform. We receive only Stripe customer and subscription identifiers, billing country, and transaction events; we never access or store your payment card details.

4.5 Email Communications

· Resend - transactional email delivery (account notifications, team invitations, scheduled reports, contact-form submissions, and other service notifications). Resend receives recipient names, email addresses, and message content for this purpose.

4.6 AI and Generative Model Providers

When you interact with our AI agents or creative tools, the content you submit (including your prompts, uploaded files, chat history, brand guidelines, and knowledge-base entries, as applicable) is sent to one or more of the following providers to generate responses, images, or audio.

· Anthropic - Claude models, used as the large-language-model provider

· OpenAI - used for image generation and as a text model

· Google (Gemini) - used for image generation, editing, and search-and-replace

· Replicate - used for image generation, editing, upscaling, vectorization, and background removal

· Recraft - used for photorealistic image generation and AI vector/SVG output

· FAL - used for image generation, upscale, STT and TTS models

· Deepgram - used for STT services

· BFL - used for image generation

· Stability AI - used for music and sound-effect generation

4.7 Third-Party Data APIs

· DataForSEO - provides business-listing, review, and search-result data

· Google - YouTube search API

· Unsplash - provides stock-photo search results when you use the built-in photo picker; attribution is displayed automatically on published decks that include an Unsplash image

· Cloudmersive - used for virus scanning uploaded files

· Upstash - caching for SEO results, reviews, Youtube searches

· Vercel - website hosting

4.8 Connected Customer Integrations (at your direction)

When you connect a third-party account, we transmit data between the Service and that third party on your behalf and under your authorization:

· Google (Google Analytics 4 and Google Search Console) - read-only access to the GA4 properties and GSC sites you connect, subject to Google's API terms

· Self-hosted WordPress sites - for browsing and publishing content using Application Passwords you provide

4.9 Security and Performance Monitoring

· Sentry - error tracking and crash reporting. Sentry receives error details, stack traces, and browser/device information and may receive identifiers (such as user ID and, where necessary, email address) and sampled session replays when errors occur, so we can triage issues affecting specific accounts; we configure Sentry to reduce the amount of personal information captured where feasible.

· Datadog (Real User Monitoring) - application performance monitoring and user-experience analytics, including a 20% sample of session replays, long-task events, and resource-load metrics. Identifiers (such as user ID and, where necessary, email address) may be attached to sessions to support debugging; we configure Datadog to limit the collection of personal information where feasible.

· Cloudflare Turnstile - bot-protection CAPTCHA presented during account sign-up/login; Cloudflare processes connection metadata (including IP address) as part of challenge evaluation and provides a geographic country indicator that we use to determine whether to display prices in CAD or USD.

4.10 Website Analytics (Marketing Website Only)

· Google Analytics - visitor behaviour analysis and traffic measurement on innoviquestudio.com. Subject to Google's Privacy Policy. You may opt out using the Google Analytics Opt-out Browser Add-on (https://tools.google.com/dlpage/gaoptout).

5 Commercial Relationship Disclosures

In a commercial-relationship context, we may share Business Contact information with the applicable Customer workspace administrators and with our professional advisors (such as legal, audit, tax, and accounting advisors) where necessary for contracting, billing, compliance, or relationship management. We may also share information as needed to facilitate a transaction you request (for example, coordinating a demo or support engagement). We do not share personal information with third parties for their own direct-marketing purposes.

5.1 Legal and Compliance

We may disclose your information if required to do so by law or in response to valid legal requests, including court orders, subpoenas, government or regulatory agency requests, or to protect our legal rights, defend against legal claims, or prevent fraud or security threats.

5.2 Business Transfers

In the event of a merger, acquisition, reorganization, or sale of all or a portion of our assets, your information may be transferred as part of that transaction. We will notify you via email and/or a prominent notice in the Service of any change in ownership or data-handling practices.

5.3 With Your Consent

We may share your information for other purposes with your explicit, informed consent.

6 Data Storage and Location

6.1 Primary Infrastructure.

· Application database and file storage: Supabase (managed PostgreSQL with row-level security), hosted in a United States region. Supabase storage buckets hold AI-generated images, uploaded brand assets, social-media gallery media, generated audio files, and other user-uploaded files.

· Application front-end: hosted by Netlify

· Published presentations and websites: hosted by Vercel (content that you elect to publish from the Presentation Builder or Website Builder is served from Vercel's infrastructure)

· Marketing website (innoviquestudio.com): hosted on a standard web-hosting provider; analytics via Google Analytics

· Media Files: stored in Cloudflare R2 storage buckets, including image, video and audio generations.

Because the primary application database is hosted in the United States, your personal information will be stored and processed in the United States and may be accessed from other jurisdictions where our service providers operate. If you are located outside the United States (for example, in Canada, the European Economic Area, the United Kingdom, or Switzerland), the use of the Service necessarily involves a transfer of your personal information to the United States and, where applicable, to other jurisdictions where our sub-processors operate.

6.2 Data in Transit. All data transmitted between your device and our servers is encrypted using TLS (Transport Layer Security). Data transmitted between our edge functions and third-party sub-processors is likewise transmitted over TLS.

6.3 Tenant Data Isolation. Each workspace on the platform is logically isolated via a Tenant ID and row-level security (RLS) policies enforced at the database level. Access-control (including support for parent-to-child workspace role inheritance for agency accounts) ensure that users can only access data belonging to workspaces to which they have been authorized.

6.4 Data Retention

We retain your personal information for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law.

6.4.1 Active Accounts. We retain your account and workspace information for as long as your account is active or as needed to provide the Service.

6.4.2 Account Deletion - What Is Deleted. When you delete your account through the Service:

· Your name, email address, password hash, avatar, MFA configuration, and other profile fields are deleted

· Your workspace memberships are removed, and chat sessions, uploaded files, generated content, brand guidelines, knowledge-base entries, and other personal Customer Data that you own are deleted on a cascading basis

· Your encrypted OAuth tokens for Google (GA4/GSC), connected social media platforms, and WordPress sites are deleted

· Your notification and communication preferences are deleted

6.4.3 Workspace Deletion. When a workspace owner deletes a workspace, all associated data - chat sessions, analytics connections, generated content, audit reports, team membership records, and related assets - is deleted on a cascading basis.

6.4.4 What Is Retained. Even after account or workspace deletion, certain records may be retained where necessary for legal, regulatory, accounting, or legitimate business purposes, including:

· Billing and tax records: Stripe customer and subscription identifiers, invoices, and related records, retained as required by applicable tax and accounting laws (typically up to 7 years)

· Audit log entries: entries created by database triggers for membership, plan, and workspace events may be retained as part of the workspace's audit trail for security and compliance purposes

· Security and abuse-prevention records: logs used to investigate and respond to security incidents or abuse

· Published content: presentations, websites, and other content that you published to a live URL before deletion will remain accessible at that URL until you unpublish it through the Service; published content may also remain cached by third parties (search engines, link previewers, content delivery networks)

6.4.5 Specific Retention Periods

· Error and performance logs: retained for up to 90 days in Sentry and Datadog before being purged

· Cached third-party responses: GA4 responses are cached for up to 4 hours, GSC responses for up to 6 hours, and DataForSEO responses for up to 24 hours in Upstash Redis before being evicted

· Database backups: encrypted backups are retained for approximately 30 days before being securely deleted; deleted data may persist in these backups until the backup is purged

· Financial records: retained as required by tax and accounting laws (typically 7 years)

· Session records: active session data is retained for the duration of the session; session metadata used for security review is retained for up to 12 months

6.4.6 Archived and Anonymized Data. Data that has been de-identified or aggregated so that it cannot reasonably be used to identify you may be retained indefinitely for product improvement purposes.

 

7 Data Security

We implement comprehensive technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction.

7.1 Technical Safeguards

· Encryption of data in transit using TLS

· Encryption of sensitive fields at rest, including OAuth access and refresh tokens and WordPress Application Passwords, using AES-256-GCM with keys derived via HKDF

· Encryption of Supabase-managed database backups at rest

· Password hashing using industry-standard cryptographic algorithms (bcrypt, managed by Supabase)

· Multi-factor authentication (MFA) via time-based one-time passwords (TOTP) available on all accounts

· Row-Level Security (RLS) policies enforced at the database level, with helper functions that correctly honor parent-to-child workspace role inheritance

· CORS origin allowlisting on all edge functions (no wildcard origins)

· Server-Side Request Forgery (SSRF) protection on any feature that fetches user-provided URLs (for example, brand-guidelines website crawling and audit tools) - private IP ranges, loopback addresses, cloud metadata endpoints, and non-HTTP schemes are blocked

· Magic-byte validation on uploaded files (in addition to MIME-type checking) before processing

· Strict Content Security Policy and additional HTTP security headers (HSTS, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy) on the application

· Input sanitization and DOMPurify-based output encoding to mitigate cross-site scripting

· Generic error responses to clients (no internal error details, stack traces, or database errors are returned)

· HMAC-signed, time-limited tokens for OAuth state validation

· Automated error detection and tracking

· Real-time application performance monitoring

· CAPTCHA (Cloudflare Turnstile) on account sign-up to mitigate automated abuse

· Immutable audit log entries for significant workspace events

7.2 Organizational Safeguards

· Access controls based on the principle of least privilege

· Documented incident-response procedures

· Regular security reviews and testing of the Service

· Due-diligence reviews of our sub-processors

7.3 Infrastructure Security

· Enterprise-grade cloud infrastructure (Supabase, Netlify, Vercel)

· Primary application database hosted in the United States with managed backups

While we strive to protect your personal information using industry-leading security measures, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security but are committed to maintaining the highest standards of data protection. If you believe your account has been compromised, please contact us immediately at privacy@innoviquestudio.com.

8 Your Privacy Rights

Depending on your location and your relationship with us (for example, Business Contact versus Authorized User), you may have certain rights regarding your personal information. Where we process Customer Data on behalf of a Customer, privacy requests about that Customer Data should generally be directed to the Customer (your organization) because the Customer controls the data and Poardal Software Inc. processes it as a service provider/processor. Where we act as a controller (for example, for Business Contact information, billing, and marketing website interactions), you may submit requests directly to us as described below.

8.1 Right to Access and Portability

You have the right to request a copy of the personal information we hold about you. Account holders can view and export much of their personal data (including chat history, Workshop content, and brand guidelines) directly from within the Service. For additional access or portability requests, contact us at privacy@innoviquestudio.com.

8.2 Right to Correction

You have the right to request correction of inaccurate personal information we hold about you. You can update most information (including your name, avatar, timezone, notification preferences, MFA configuration, and workspace metadata) directly through your account and workspace settings.

8.3 Right to Deletion.

· Authorized Users: You can delete your account at any time from within the Service. If your deletion request relates to Customer Data inside a workspace that is controlled by your organization (for example, a client workspace at an agency), please contact your workspace owner or the Customer directly, as they control that data and may have retention obligations.

· Business Contacts and website visitors: You may submit a deletion request to privacy@innoviquestudio.com.

Certain records may be retained after deletion where required or permitted by law and for legitimate business purposes (for example, billing records, audit logs, and backups pending the scheduled purge).

8.4 Right to Restriction

You have the right to request that we restrict the processing of your personal information in certain circumstances.

8.5 Right to Object

You have the right to object to the processing of your personal information for certain purposes, including direct marketing.

8.6 Right to Withdraw Consent

Where processing is based on your consent (for example, optional analytics or marketing communications where required by law), you may withdraw your consent at any time. Much of our processing in a commercial-relationship context is not consent-based (for example, processing necessary to provide the Service, administer accounts, provide support, and maintain security) and will continue after consent is withdrawn where another lawful basis applies.

8.7 Revoking Third-Party Connections

You may disconnect any Google (GA4/GSC), social media, or WordPress integration at any time from within the Service. When you do so, we delete the corresponding tokens from our systems and attempt to revoke them with the upstream provider. You can also revoke Google OAuth permissions at any time from your Google Account permissions page (https://myaccount.google.com/permissions).

8.8 Opt-Out of Non-Essential Communications

You can opt out of non-essential email notifications through your notification preferences. Transactional emails related to account security, password resets, team invitations, and critical service notifications cannot be opted out of while your account remains active.

8.9 How to Exercise Your Rights

If you are a Business Contact or your request relates to information we control, contact us at privacy@innoviquestudio.com. If you are an Authorized User and your request relates to Customer Data in the Service, please contact your workspace owner or the Customer first.

We will respond to your request within 30 days (or 45 days for requests under the CCPA/CPRA). We may need to verify your identity before processing your request.

9 Cookies and Tracking Technologies

We use cookies, browser local storage, session storage, and similar technologies to collect and store information when you use the Service and visit our website.

9.1 Essential Cookies and Storage (Application).

These are necessary for the Service to function properly. They enable core functionality including authentication, secure session management, workspace selection, and in-editor state preservation. You cannot opt out of these without preventing use of the Service.

· Authentication cookies: managed by Supabase; used to maintain your authenticated session (HTTP-only, secure)

· Local Storage - selected workspace: remembers your last-active workspace between visits

· Local Storage - theme preference: remembers your light/dark theme choice

· Local Storage - editor state: preserves in-progress state for the SVG Editor and certain other editors

· Local storage - invitation flow: stores transient state required to complete team-invitation acceptance

· Session Storage - chunk-reload timestamp: detects stale application code after a deploy and prompts a refresh

9.2 Bot Protection (Application).

Cloudflare Turnstile is used on the sign-up and login form to mitigate automated abuse. Turnstile may set cookies and read limited device characteristics solely to evaluate whether a challenge should be presented.

9.3 Analytics and Performance Monitoring (Application).

· Sentry collects error events (including stack traces, browser and device information, and a session replay captured when an error occurs) and may include identifiers (such as user ID and, where necessary, email address) so we can triage issues affecting specific accounts; we configure Sentry to reduce the amount of personal information captured where feasible.

· Datadog Real User Monitoring collects performance metrics, long-task events, resource-loading events, user interactions, and a 20% sample of session replays. Identifiers (such as user ID and, where necessary, email address) may be attached to sessions; sensitive inputs are masked by default and media is blocked in replays.

9.4 Analytics Cookies (Marketing Website — innoviquestudio.com).

We use Google Analytics on our marketing website to understand how visitors interact with the site. Google Analytics collects information such as:

· Pages visited and time spent on each page

· Traffic sources and referring websites

· Device and browser information

· Approximate geographic location (city/country level)

Google Analytics uses cookies stored in your browser. This analytics is applied only to the innoviquestudio.com marketing website, not to the Service itself.

9.5 Your Cookie Choices

· Most web browsers are set to accept cookies by default

· You can configure your browser to remove or reject cookies, but doing so may affect functionality of the Service

· You can opt out of Google Analytics tracking on our marketing website using the Google Analytics Opt-out Browser Add-on (https://tools.google.com/dlpage/gaoptout)

· We do not use third-party advertising cookies, retargeting tools, or cross-site behavioral tracking technologies on the Service or the marketing website

 

10 International Data Transfers

Our primary application database is hosted in the United States. In addition, many of our sub-processors — including most of our AI providers, monitoring tools, and payment and email providers — are headquartered in or process data in the United States and, in some cases, the European Union. As a result, personal information we collect may be transferred to, stored, and processed in countries outside your country of residence, including the United States.

Where personal information is transferred internationally, we take steps designed to provide an appropriate level of protection in the circumstances, which may include contractual protections (such as data processing terms and, where applicable, Standard Contractual Clauses approved by the European Commission or equivalent mechanisms), vendor due diligence, and technical measures such as encryption to protect data in transit and at rest.

Service Provider Locations (non-exhaustive)

· Supabase — primary database hosted in the United States

· Netlify — United States

· Vercel — United States

· Stripe — United States and Europe

· Anthropic, OpenAI, Google (Gemini), Replicate, Recraft, FAL, Stability AI — primarily United States

· Upstash — United States

· Resend — United States

· Sentry — United States

· Datadog — United States and Europe

· Cloudflare (Turnstile) — global edge network, United States-headquartered

· DataForSEO — primarily the European Union

· Unsplash — primarily the United States

· Google Analytics — United States

· Google (GA4/GSC APIs) — United States (subject to Google's data-processing infrastructure)

· Social media platforms and WordPress sites you connect — various jurisdictions determined by the third-party provider or site owner

These providers maintain SOC 2, ISO 27001, or equivalent certifications where applicable and comply with applicable data-protection frameworks. By using the Service, you acknowledge the transfer of your information to countries outside your country of residence as necessary to provide the Service.

 

11 Children's Privacy

The Service is intended for use by professionals in a business context. It is not directed to, and we do not knowingly collect personal information from, individuals under the age of 16. Our Terms of Use require that you be at least 16 years of age to use the Service.

If you are a parent or guardian and believe that your child has provided us with personal information, please contact us at privacy@innoviquestudio.com. If we become aware that we have collected personal information from a child under the age of 16 without appropriate consent, we will take steps to delete that information promptly.

12 California Privacy Rights (CCPA / CPRA)

If you are a California resident, you have specific rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act (collectively, "CCPA"):

Right to Know. You have the right to request information about the categories and specific pieces of personal information we have collected about you, the sources, our business purpose, and the third parties with whom we share it.

Right to Delete. You have the right to request deletion of your personal information, subject to certain exceptions.

Right to Correct. You have the right to request correction of inaccurate personal information.

Right to Opt-Out of Sale or Sharing. You have the right to opt out of the "sale" or "sharing" of your personal information. We do not sell your personal information, and we do not share your personal information for cross-context behavioral advertising.

Right to Limit Use of Sensitive Personal Information. We do not use sensitive personal information for purposes that require you to be offered a right to limit such use.

Right to Non-Discrimination. We will not discriminate against you for exercising your privacy rights.

Shine the Light. We do not share personal information with third parties for their direct-marketing purposes.

Authorized Agent. You may designate an authorized agent to make a request on your behalf. We may require verification that you have authorized the agent.

Response Time. We will respond to verifiable consumer requests within 45 days.

To exercise your CCPA rights, please contact us at privacy@innoviquestudio.com.

13 European Privacy Rights (GDPR / UK GDPR)

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have additional rights under the General Data Protection Regulation ("GDPR") and the UK GDPR.

Legal Basis for Processing. We process your personal information based on one or more of the following legal bases:

· Contract: processing necessary to perform our contract with you or your organization (for example, providing the Service and maintaining your account)

· Legitimate Interests: processing necessary for our legitimate business interests (for example, fraud prevention, security monitoring, audit logging, product improvement, and direct marketing to business contacts) and balanced against your rights and freedoms

· Consent: processing based on your explicit consent (for example, certain optional analytics or marketing communications, which you may withdraw at any time)

· Legal Obligation: processing necessary to comply with legal requirements

Data Controller. Depending on the context, Poardal Software Inc. may act as a controller (for example, for account administration, billing, marketing website interactions, and security) or as a processor/service provider (for example, when processing Customer Data within the Service on a Customer's instructions). Where Poardal Software Inc. acts as a controller, Poardal Software Inc. is the data controller for that processing.

Data Protection Officer. For questions about our data-protection practices, please contact our Privacy Officer at privacy@innoviquestudio.com.

Your GDPR Rights. In addition to the rights listed in the privacy rights described in this policy, you have the right to:

· Receive information about our processing activities in a concise and transparent manner

· Object to processing based on legitimate interests

· Lodge a complaint with your local data-protection supervisory authority if you are not satisfied with our response

14 Canadian Privacy Rights (PIPEDA and Quebec Law 25)

If you are located in Canada, your personal information is protected under the Personal Information Protection and Electronic Documents Act ("PIPEDA") and applicable provincial privacy legislation, including Quebec's Act Respecting the Protection of Personal Information in the Private Sector ("Law 25," formerly Bill 64). Poardal Software Inc. is committed to full compliance with these requirements.

14.1 Filing a Complaint.

If you have concerns about our privacy practices, please contact our Privacy Officer at privacy@innoviquestudio.com. We will investigate and respond within 30 days.

If you are not satisfied with our response, you may file a complaint with:

Office of the Privacy Commissioner of Canada

30 Victoria Street

Gatineau, Quebec K1A 1H3

Phone: 1-800-282-1376

Website: www.priv.gc.ca

Commission d'accès à l'information du Québec (CAI) (for Quebec residents)

Phone: 1-888-528-7741

Website: www.cai.gouv.qc.ca

15 AI Processing Notice

Innovique Studio is an AI-powered platform, and many of its core features rely on third-party AI service providers to generate text, images, audio, and other outputs in response to your prompts and inputs.

· AI providers currently used. Anthropic (Claude), OpenAI, Google (Gemini), Replicate, Recraft, FAL, Black Forest Labs, and Stability AI. We may add, replace, or remove providers from time to time and will update this policy accordingly.

· Use of your data for model training. We do not use Customer Data to train our own AI models, and we rely on contractual commitments with our AI providers that prevent them from using Customer Data submitted through our API integrations to train their foundation or public models. Each provider's data-handling commitments are set out in their own terms, which we review as part of our vendor due diligence.

· Retention by AI providers. AI providers may retain inputs and outputs temporarily for limited operational purposes (for example, abuse monitoring and service reliability). Retention periods are governed by each provider's terms.

· Human review of AI outputs. AI outputs can be inaccurate, incomplete, or inappropriate for your intended use. You remain responsible for reviewing and validating any AI-generated content before you rely on it, publish it, or share it externally. Do not submit content to an AI agent that you are not authorized to share.

· Automated decision-making. We do not use your personal information for automated decision-making that produces legal or similarly significant effects for you.

16 Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:

General Privacy Inquiries

Email: privacy@innoviquestudio.com

Data Protection Officer / Privacy Officer

Email: privacy@innoviquestudio.com

Mailing Address

Poardal Software Inc.

Attn: Privacy Officer - Innovique Studio

1463 Ontario St

Burlington, ON L7S 1G6

Canada