Back to home

Privacy Policy

Denis Bellerose Services-Conseils inc. — Last updated: 2026-05-08Version: v3.0

The data controller for your personal information is:


Denis Bellerose Services-Conseils inc.

*Doing business as SoiWISE*

Quebec Business Number (NEQ): 1164931223


Registered office address:

145A rue du Coutelier

Saint-Augustin-de-Desmaures (Quebec) G3A 2J7

Canada


Privacy Officer:

privacy@soiwise.com


Under Quebec's Act respecting the protection of personal information in the private sector (hereinafter "Law 25"), Denis Bellerose Services-Conseils inc. (operating the SoiWISE brand) is committed to ensuring the protection, confidentiality and security of your personal information.

We collect the following information:


2.1 Identification Information

- First and last name
- Email address
- Password (stored as bcrypt hash, never in plain text)
- IP address and user agent upon login
- Login history (date, time, IP, device)

2.2 Professional Information

- Professional title and industry
- Work experiences (title, company, dates, description, achievements)
- Technical and professional skills
- Education and degrees (institution, program, dates)
- Career preferences (position type, location, salary, work mode)
- Career aspirations and work values
- Phone number (optional)
- Location (city, province/state, country)

2.3 Usage-Generated Information

- AI analysis results (tags, scores, extracted skills)
- AI-generated professional biography
- Light references received (confirmation and appreciation from a former colleague or supervisor)
- Consent log (type, date, document version, status)
- Security audit log (sensitive account actions)

2.4 Technical Information

- IP address (partially masked in display, fully retained in security logs)
- User agent (browser type and operating system)
- Pages visited and Platform interactions
- Language and notification preferences

2.5 Payment and Billing Information

For Users subscribing to a SoiWISE Premium subscription:

- Stripe Customer ID
- Subscription status (active, canceled, suspended)
- Subscription date and next renewal date
- Transaction and invoice history
- Billing address
- Last four digits of credit card (provided by Stripe for display purposes only)
- Applicable tax amounts (GST and QST for Quebec residents)

Important: SoiWISE does not store or directly process your full credit card information. The entire payment process is handled by Stripe Payments Canada, Ltd., a payment service provider certified PCI-DSS Level 1.

Your personal information is collected and processed for the following purposes:


3.1 Delivery of Platform Services

- Creation and management of your P6 Profile (structured professional profile based on 6 pillars)
- Import and AI analysis of your CV
- Skill extraction and categorization with scoring
- Professional biography generation
- Management of light reference requests and responses

3.2 Artificial Intelligence Analysis

- Analysis of professional experiences for skill and keyword extraction
- Assignment of skill scores to enrich your P6 Profile
- Profile improvement suggestions
- Personalized career coaching

Details of this processing are described in our Data Usage and AI Policy.


3.3 Platform Security and Integrity

- Identity verification upon registration (6-digit email code)
- Two-factor authentication (2FA) by email
- Protection against fraud and unauthorized access
- Detection of suspicious activities
- Audit logging for regulatory compliance

3.4 Communications

- Account-related notifications (light references, profile alerts)
- Security alerts (login from new device, password change)
- Commercial and promotional communications (only with your express consent, in accordance with CASL C-28)

3.5 Legal Compliance

- Compliance with obligations under Quebec's Law 25
- Retention of audit and consent logs for 5 years
- Response to access, rectification or deletion requests
- Evidence in case of security incidents (reporting obligation)

3.6 Subscription and Billing Management

For Users subscribing to a SoiWISE Premium subscription:

- Payment processing via Stripe Payments Canada, Ltd.
- Issuance of invoices compliant with Quebec tax requirements (GST and QST)
- Subscription lifecycle management (subscription, renewal, cancellation)
- Application of the launch offer (first 250 Users at 30% discount for 6 months until October 31, 2026)
- Communication of billing-related notifications (successful payment, failed payment, cancellation)
- Processing of refund requests during the 7-day guarantee period

5.1 With Reference Persons

When a light reference request is made, the reference person receives only the information necessary to complete the validation: candidate name, period and description of the relevant experience. The candidate declares they have obtained the reference person's consent before submitting the request.


5.2 With Technical Service Providers

We use the following service providers for Platform operations:

- Stripe Payments Canada, Ltd. (British Columbia, Canada) — Payment processing for SoiWISE Premium subscriptions. Provider certified PCI-DSS Level 1. Data processed: payment information (credit card, billing address), transaction history, Stripe Customer ID. SoiWISE does not store or directly process your full credit card information. Policy: stripe.com/privacy.
- Anthropic (Claude API) — AI analysis of professional experiences. Only anonymized descriptions (no name, email or direct identifier) are transmitted.
- Resend — Transactional email service (verification, notifications, security alerts, light reference invitations). Your email address is transmitted for delivery.
- Neon.tech — PostgreSQL database hosting.
- Render — Backend server hosting (Node.js/Express).
- Vercel — Frontend hosting (React/Vite).

5.3 Transfer Outside Quebec

In accordance with section 17 of Law 25, we inform you that some of your personal information may be transferred and processed outside Quebec, notably in the United States, by the following providers:

- Render (backend) — United States
- Neon.tech (database) — United States
- Resend (emails) — United States
- Anthropic (AI) — United States

These transfers are governed by appropriate contracts and these providers commit to ensuring an adequate level of protection for your personal information.


5.4 No Sale of Data

SoiWISE never sells, rents or commercializes your personal information to third parties. Your data is used exclusively for the purposes described in this policy.


5.5 Legal Disclosure

We may disclose your information if required by law, in response to a court order, subpoena or legitimate request from a government authority.

6.1 Active Data Retention

Your personal information is retained for as long as your account is active and you use the Platform.


6.2 After Deletion Request

When you request account deletion:

- Grace period (30 days) — Your data remains intact, you can cancel the deletion.
- After deletion — All your personally identifiable data is permanently deleted (profile, skills, experiences, education, preferences, aspirations, light references).

6.3 Data Retained After Deletion (Law 25)

In accordance with our legal obligations, the following data is retained for 5 years after account deletion, in anonymized form (SHA-256 hash of email address):

- Security audit log (AuditLog) — Sensitive actions (password changes, data exports, deletion requests)
- Consent log (ConsentLog) — Complete history of consents given and withdrawn, with dates and document versions
- Login history (LoginHistory) — Dates, times, IP addresses and devices used

This anonymized data allows SoiWISE to demonstrate compliance in case of audit or security incident, without possibility of direct re-identification.


6.4 Sessions

Active sessions (JWT) are cascade-deleted upon account deletion. Expired sessions are automatically cleaned up.

Under Quebec's Law 25, you have the following rights:


7.1 Right of Access

You have the right to access all personal information we hold about you. You can exercise this right directly from the "My Account" section of the Platform.


7.2 Right to Rectification

You can correct any inaccurate or incomplete information in your profile at any time through the Platform's interface.


7.3 Right to Deletion

You can request the deletion of your account and all your personal data at any time, subject to the 30-day grace period and retention obligations required by law (see section 6).


7.4 Right to Portability (art. 27)

You can export all your personal data in structured JSON format from the "My Account" section. This feature includes all collected data: profile, skills, experiences, education, preferences, aspirations, light references, AI analyses and consent history.


7.5 Right to Withdraw Consent

You can withdraw your consent to data processing at any time:

- Marketing consent — Withdrawable from the "My Consents" section in "My Account," without affecting your account.
- Mandatory consents (Terms of Use, Privacy Policy, Data Processing) — Withdrawing these consents requires account deletion, as these processes are essential for service delivery.

Each withdrawal of consent is recorded in our consent log with date, time and version of the relevant document.


7.6 Right to File a Complaint

If you believe your rights have not been respected, you may file a complaint with the Commission d'accès à l'information du Québec (CAI):

- Website: www.cai.gouv.qc.ca
- Phone: 1-888-528-7741

7.7 Exercising Your Rights

To exercise your rights, you can:

- Use the self-service features of the Platform (My Account)
- Contact us at privacy@soiwise.com

We will respond to your request within 30 days, in accordance with Law 25.

In accordance with section 10 of Law 25, SoiWISE implements reasonable and appropriate security measures to protect your personal information:


8.1 Technical Measures

- Password encryption — bcrypt hashing with random salt (passwords are never stored in plain text)
- Token authentication — JWT (JSON Web Token) with expiration
- Two-factor authentication (2FA) — 6-digit code sent by email, user-activatable
- Encrypted communications — HTTPS (TLS) for all communications between your browser and our servers
- Verification codes — 6-digit codes hashed with bcrypt, 15-minute expiration, attempt limits
- IP masking — IP addresses partially masked in user display
- Audit data hashing — SHA-256 to anonymize logs after account deletion

8.2 Organizational Measures

- Restricted access to personal data (least privilege principle)
- Logging of all sensitive actions (AuditLog)
- Consent log retention for compliance evidence
- Regular security measures review

8.3 Incident Notification

In the event of a confidentiality incident likely to cause serious harm, SoiWISE commits to:

- Taking reasonable measures to reduce risks
- Notifying the Commission d'accès à l'information du Québec (CAI)
- Notifying affected individuals, in accordance with section 3.5 of Law 25
- Recording the incident in a register maintained for this purpose

9.1 Cookies Used

The Platform uses a minimal number of cookies, strictly necessary for operation:

- Authentication cookie — Stores your session token (JWT) to maintain your connection
- Language cookie — Stores your language preference (French/English)

9.2 Third-Party Cookies

As of the date of this policy, the Platform uses no advertising tracking cookies and no third-party analytics tools (no Google Analytics, Facebook Pixel or equivalent).


9.3 Cookie Management

You can configure your browser to reject cookies. However, rejecting essential cookies may prevent the Platform from functioning properly (inability to log in).


9.4 Local Storage

The Platform may use your browser's local storage (localStorage) to store interface preferences (theme, menu state). This data does not leave your device and is not transmitted to our servers.

The Platform is intended for professionals aged 18 and over. We do not knowingly collect personal information from minors. If we learn that a minor has registered on the Platform, we will delete their account and data as soon as possible.


If you are a parent or guardian and believe that a minor has provided personal information on the Platform, please contact us at privacy@soiwise.com.

11.1 Right to Modify

SoiWISE reserves the right to modify this policy at any time. The date of the last update is indicated at the top of the document.


11.2 Notification of Changes

In the event of substantial changes, we will inform you:

- By email to the address associated with your account, at least 30 days before the effective date
- By a visible notice on the Platform

11.3 New Consent

If changes affect the purposes of processing or the nature of data collected, a new consent will be requested. This new consent will be recorded in our consent log with the new document version.


11.4 Version

Each version of this policy is identified by a version number and date. Version history is maintained in our consent log.

For any questions regarding the protection of your personal information:


Privacy Officer

Denis Bellerose Services-Conseils inc.

*Doing business as SoiWISE*

Quebec Business Number (NEQ): 1164931223

145A rue du Coutelier, Saint-Augustin-de-Desmaures (Quebec) G3A 2J7, Canada


Privacy email: privacy@soiwise.com

Legal email: legal@soiwise.com

Billing email: billing@soiwise.com


Commission d'accès à l'information du Québec (CAI)

www.cai.gouv.qc.ca

1-888-528-7741


We commit to responding to any request within 30 days, in accordance with Quebec's Law 25.

For any questions regarding the protection of your data, contact us at privacy@soiwise.com