Privacy Policy

Effective date: August 22, 2026

This Privacy Policy describes how Infrenta Technologies Inc. handles information on the Infrenta websites and software services. It is a factual description of current practices, not a marketing page.

1. Scope and who we are

This Privacy Policy explains how Infrenta Technologies Inc. (“Infrenta,” “we,” or “us”) collects, uses, and discloses information when you use our websites, applications, and related software services (the “Services”). It should be read with our Terms of Service.

The Services are business software used by organizations and their Authorized Users. This Policy covers the public marketing site, demo and support communications, and the authenticated product.

2. Our role and business customers

We distinguish two practical kinds of information.

  • Website and account information that you give us directly, such as a demo request or a user profile we maintain to operate your login. We decide how that information is used to run our site and accounts.
  • Customer Data that an organization stores in the Services—project records, files, prompts, and similar content. We process that information to provide the Services to that organization.

Formal “controller” and “processor” labels depend on the law that applies. This Policy describes the practical split without claiming a full compliance program for every jurisdiction.

3. Information we collect

Not all Customer Data is personal information. Project quantities, steel prices, supplier pricing, and similar commercial figures often identify a project or company, not a person. Customer Data may still include personal information when a record names people or when files contain contact details, signatures, or other identifiers.

Depending on how the Services are used, we may process:

  • Account and identity information: name, email address, organization, role, and authentication or account identifiers.
  • Project and business records: projects, estimates, quantities, rates, cost information, vendor and RFQ records, quotations, procurement records, and project-controls records.
  • Uploaded files: PDFs, drawings, spreadsheets, geotechnical or engineering documents, and other attachments.
  • AI inputs: prompts, attachments, source documents, and related tool requests when a user uses an AI-assisted feature.
  • Execution and Quality and Safety records: daily reports, production or logistics notes, incidents, and other operational records that may identify workers or other individuals if the customer enters that information.
  • Website and device information: browser or device type, IP address, pages viewed, and analytics events.
  • Support and sales communications: name, work email, company, and message content from demo or support contacts.

Self-service checkout is not generally available. If a payment feature is used, a payment processor may collect billing details. We do not intend to store raw payment-card numbers in the Services.

4. How we collect information

We collect information from:

  • you, when you create or use an account, upload files, enter records, or send a prompt;
  • organization administrators, when they manage membership or roles;
  • documents and other Customer Data uploaded to the Services;
  • integrations, where Infrenta has provisioned them;
  • the marketing site, including analytics events;
  • demo, sales, and support messages, including walkthrough requests submitted through the public demo form;
  • service providers that help us operate the Services.

We do not buy marketing lists from data brokers as part of the current product.

5. How we use information

We use information to:

  • provide, operate, and maintain the Services;
  • authenticate users and manage organizations and accounts;
  • process Customer Data and generate requested Outputs;
  • provide AI-assisted features when they are used;
  • support, troubleshoot, and communicate about accounts or the Services;
  • secure the Services and detect abuse;
  • understand website and product usage through analytics and operational metrics;
  • respond to demo and sales requests;
  • comply with law and keep necessary business records.

We may use operational logs, error data, and usage metrics to operate, secure, and improve the reliability and usability of the Services. We do not use Customer Data to train general-purpose or public foundation AI models. This Policy does not grant a general right to use raw confidential Customer Data for unrelated product development.

6. Customer Data and uploaded content

As described in the Terms, Customer retains ownership of Customer Data. This Policy does not transfer ownership of Customer Data to Infrenta.

Users may upload documents, reports, drawings, spreadsheets, and attachments. Those files may be stored, processed, displayed, and transformed as needed to provide the requested workflow. Not every file is sent to an AI provider. External processing happens when a feature is invoked that requires it, or when a service provider must host or transmit the file to operate the Services.

Customer Data can include information about employees, subcontractors, supplier contacts, workers, and other project stakeholders. The business customer is responsible for having the authority to provide that information to Infrenta through the Services. Do not store health, medical, or other sensitive personal information unless the workflow requires it and you are authorized to do so. Quality and Safety fields are operational records, not a designed medical-data system.

7. AI-assisted features

Some features use machine learning, large language models, extraction, classification, or similar tools. When a user invokes those features, prompts, attachments, or other Customer Data may be sent to third-party AI providers so we can return the requested result.

Assisted features may send requested content to third-party AI providers when a user invokes them. We may change providers. Those providers process information under their arrangements with us. We do not promise their retention or deletion timelines beyond what those arrangements and applicable law require.

Infrenta will not use Customer Data to train general-purpose or public foundation AI models. That does not mean Customer Data stays only on Infrenta systems. Users should not submit information they are not authorized to process.

8. Cookies and analytics

The marketing site may load Google Analytics (gtag.js) to measure page use and events such as demo clicks. Analytics may set cookies or similar identifiers and may collect IP address, device or browser information, and pages viewed. There is no separate cookie-settings tool on the site today.

The authenticated product uses session and authentication storage as needed to keep you signed in (including cookies or similar tokens from our application and identity infrastructure). We also store limited local state for the marketing analytics event queue before the analytics script loads; that queue is not a persistent customer database.

We do not operate a marketing-pixel or advertising-network stack beyond this analytics implementation.

9. How we share information

We share information only as needed for the purposes in this Policy, including with:

  • service providers that host, store, send messages, process payments when used, or provide analytics;
  • AI providers when a user uses an AI-assisted feature;
  • Authorized Users and administrators in the same organization, according to permissions in the Services;
  • parties you ask us to connect through a supported integration;
  • professional advisers or authorities when law or a legal process requires it, or to protect rights and security;
  • a buyer or successor in a business transaction, as described below.

We do not sell personal information or rent contact lists. We do not share Customer Data with advertisers for cross-context behavioral advertising.

10. Service providers and third parties

The Services rely on third-party infrastructure. Verified categories and examples in the current architecture include:

  • application database, authentication, and file storage (Supabase);
  • AI model providers (third-party AI providers, when those features are used);
  • website analytics (Google Analytics);
  • subscription checkout, if enabled (Stripe);
  • email, when you send a demo or support message to a published Infrenta address.

Providers may change. This list is not a live subprocessors register. Mapping, monitoring, or other utilities may also process limited technical data when those features are used.

11. Organization administrators and Authorized Users

Where an account belongs to an organization, administrators may manage access and roles using the permissions available in the Services. Authorized Users can see Customer Data they are permitted to see. The organization generally controls membership. Individual requests about workplace records may need to go through that organization.

12. Data security

We use administrative, technical, and organizational safeguards designed to protect information. No method of transmission or storage is completely secure. This Policy does not promise a particular certification, guaranteed isolation, or a specific encryption implementation except as separately agreed in writing.

13. Retention and deletion

We retain information for as long as reasonably necessary to provide the Services, comply with contractual and legal obligations, resolve disputes, maintain security, and enforce agreements. After an engagement ends, Customer Data is handled according to the applicable agreement, this Policy, applicable law, and our then-current documented retention practices. This Policy does not set a fixed deletion period.

Deletion or export requests are handled subject to the customer agreement, organization instructions, applicable law, and technical or legal retention requirements. We do not promise a self-service account-purge workflow in this Policy. Authorized Users whose information is held for an organization should start with that organization.

14. International processing

We and our service providers may process information in countries other than the country where you or your organization are located. Those countries may have different data-protection laws. We do not represent that all information remains in Canada. We do not publish a hosting-region map in this Policy because regions can change.

15. Privacy rights and choices

Subject to applicable law and exceptions, you may have rights to access, correct, or delete personal information, to withdraw consent where consent is the basis for processing, or to lodge a complaint with a supervisory authority. This Policy does not guarantee that every listed right applies in every jurisdiction.

To make a request about information Infrenta holds as a business, contact privacy@infrenta.com. We may need to verify the request and, where the information is Customer Data, we may refer you to the organization customer.

16. Business-customer requests

If we process personal information on behalf of a business customer, individuals should usually contact that organization. We may assist the customer as appropriate and as the agreement allows.

17. Service and marketing communications

We send service, security, and account messages that are needed to operate the Services. You may not be able to opt out of those messages while you have an account.

Demo and sales contacts may receive follow-up about the Services. To stop non-transactional marketing email, reply to the message or write to privacy@infrenta.com or support@infrenta.com. We do not operate a self-serve email preference page.

18. Children

The Services are business software and are not directed to children. We do not knowingly collect personal information from children for the Services.

19. Business transfers

If we are involved in a merger, acquisition, financing, reorganization, or sale of assets, information may be transferred as part of that transaction, subject to applicable law.

21. Changes to this Policy

We may update this Policy. The effective date at the top of the page will change when we publish a new version. We may provide additional notice where required by law. Continued use of the Services after an update means the updated Policy applies, except where law or an agreement requires a different process.

22. Contact

Infrenta Technologies Inc.

privacy@infrenta.com