Global policy, with Canada, EEA and UK, and United States addenda
Version 3.0
Effective upon January 1, 2023
Last updated August 8, 2026
Applies to genieai.io, runbos.ai, the BOS platform and all Genie AI products and services
Privacy Officer privacy@genieai.ca
This policy explains what Genie AI collects, why we collect it, who we share it with, how long we keep it, and the rights you can exercise. Where Genie AI processes personal information on behalf of a business customer, the customer agreement and Data Processing Addendum govern, and this policy is descriptive only.
1. Who we are and what this policy covers
GENIE AI, Inc. ("Genie AI", "we", "us", "our") is a corporation incorporated federally in Canada under the Canada Business Corporations Act, with its principal place of business in Ontario, Canada. We build BOS, the Business Orchestration System, an AI native platform that orchestrates people and AI agents to run business operations, together with the vertical solutions and applications built on it.
This Privacy Policy applies to personal information we handle through our websites, applications, platform, agents, APIs, events, support channels, sales and marketing activities, and any other product, service, program or feature we provide, online or offline (together, the "Services").
This policy does not apply to third party products or websites that link to or integrate with our Services, or to the internal privacy practices of our customers. Those are governed by their own policies.
1.1 Our two roles
Genie AI handles personal information in two distinct roles. Understanding which one applies to you determines how this policy operates.
+--------------+-------------------------------+-----------------------+ | Role | When it applies | What governs | +==============+===============================+=======================+ | Controller | We decide why and how | This Privacy Policy. | | | information is processed. | | | ("or | This covers visitors to our | | | ganization" | websites, prospects and | | | under | marketing contacts, users who | | | Canadian | create accounts directly with | | | law) | us, billing contacts, | | | | applicants, and partners. | | +--------------+-------------------------------+-----------------------+ | Processor | A business, enterprise or | The customer | | | government customer uses BOS | agreement and our | | ("service | and submits information about | Data Processing | | provider" | its own employees, | Addendum. The | | or | contractors, customers or | customer is the | | "agent") | citizens. We process that | controller and is | | | Customer Content only on the | responsible for | | | customer's documented | notice and consent to | | | instructions. | its own individuals. | +--------------+-------------------------------+-----------------------+
If you are an individual whose information was placed into BOS by an organization, please direct access, correction and deletion requests to that organization. We will support them in responding, and we will refer your request to them if you contact us directly.
1.2 Acceptance
By using our Services you accept this policy. If you do not agree with it, please do not use the Services. If anything here is unclear, contact our Privacy Officer before you continue.
2. Definitions
- Personal information means information about an identifiable individual. It does not include aggregated, de-identified or anonymous information that cannot reasonably be attributed to an individual, which we refer to as non personal information.
- Customer Content means data, documents, records, prompts, workflows, files and other material that a customer or its authorized users submit to, or generate within, the Services.
- Service Data means account, configuration, billing, telemetry, log, diagnostic and usage information generated by operating the Services.
- Sub processor means a third party we engage to process personal information in the course of providing the Services.
- Sensitive personal information means categories treated as sensitive under applicable law, including government identifiers, financial account credentials, precise geolocation, biometric identifiers, health information, and account login credentials.
3. Personal information we collect
We collect only what we need for the purposes described in this policy. The categories below describe what we collect as a controller.
-------------------------------------------------------------------------
Category Examples Source
---------------- --------------------------------------- ---------------- Identity and First and last name, business email, You, directly. contact mailing address, phone number, job title, employer, preferred language.
Account and Username, hashed credentials, single You, or your access sign on identifiers, multi factor administrator. enrolment, role and permission assignments, organization membership.
Billing and Billing contact and address, plan and You, and payment transaction licence tier, invoice and payment processors. history, tax identifiers, purchase orders. Card numbers are handled by our payment processors and are not stored on our systems.
Usage and Features used, agents invoked, workflow Automatically. telemetry and task events, session duration, performance and error data, API call metadata.
Device and IP address, browser and device type, Automatically. network operating system, language, referring page, approximate region derived from IP.
Support and Messages, tickets, call and meeting You, directly. communications notes, feedback, survey responses, recordings where you are notified and consent applies.
Marketing and Subscription preferences, campaign You, and event engagement, event registration and partners. attendance, content downloads.
Recruitment Resume, work history, references, right You, and to work confirmation, assessment recruiters. results, where you apply for a role.
Customer Content Whatever a customer chooses to place Our customers. into BOS. This may include personal information about that customer's own people. We do not control what is submitted. -------------------------------------------------------------------------
3.1 Sensitive information
We do not seek sensitive personal information for our own purposes, and we ask that you do not send it to us in support tickets, emails or free text fields. Where a customer configures BOS to process sensitive categories, that processing happens under the customer agreement, on the customer's instructions, and with the additional controls described in section 9.
3.2 Information about children
Our Services are built for business, enterprise and government use. They are not directed to children, and we do not knowingly collect personal information from anyone under the age of majority in their province, state or country. If we learn we have collected such information without valid consent, we will delete it promptly. Contact our Privacy Officer if you believe a child has provided us with personal information.
4. Why we use personal information
We use personal information only for the purposes identified when it was collected, for purposes a reasonable person would consider appropriate in the circumstances, or as otherwise permitted or required by law.
----------------------------------------------------------------------- Purpose Legal basis in the Canadian consent EEA and UK model --------------------------- --------------------- --------------------- Provide, operate, secure Performance of a Express or implied and support the Services, contract. consent at the point including provisioning of collection. accounts and running agents and workflows.
Bill, collect payment, Contract and legal Express consent and manage licences, and meet obligation. legal requirement. tax and accounting obligations.
Maintain, troubleshoot, Legitimate interests. Implied consent, monitor, and improve consistent with reliability, quality and reasonable performance of the expectations. Services.
Protect against fraud, Legitimate interests Permitted use and abuse, unauthorized access and legal obligation. implied consent. and security incidents, and enforce our terms.
Develop new features, Legitimate interests. Implied consent for models, integrations and non personal and de products, using Service identified data. Data and de identified or aggregated data.
Send service and Contract and Implied consent, and administrative notices, legitimate interests. required notice. including security, availability and policy change notices.
Send marketing Consent, or Express or implied communications, legitimate interests consent under CASL, invitations, newsletters for existing business with unsubscribe in and offers. relationships. every message.
Respond to lawful demands Legal obligation. Permitted disclosure from law enforcement, without consent where regulators, courts and required by law. government authorities.
Evaluate candidates and Steps prior to Express consent. manage recruitment. entering a contract and legitimate interests.
Support corporate Legitimate interests. Permitted use, with transactions, financing, the safeguards in due diligence, and business section 8. continuity. -----------------------------------------------------------------------
We may use and disclose non personal information, including aggregated and de identified data, for any lawful business purpose. Where we de identify data we maintain the technical and organizational measures to keep it de identified, and we do not attempt to re identify it.
4.1 If we want to use information for something new
If we intend to use personal information for a purpose that was not identified when we collected it and that you would not reasonably expect, we will identify the new purpose and obtain your consent first, unless the law permits or requires us to proceed without it.
5. Consent, and how to withdraw it
We obtain express consent where the information is sensitive, where the purpose is not obvious, or where the law requires it. We rely on implied consent only where the information is less sensitive, the purpose is clear from the context, and your reasonable expectations support it.
You can refuse to provide personal information, and you can withdraw consent at any time, subject to legal and contractual restrictions and reasonable notice. Withdrawing consent may mean we can no longer provide part or all of the Services to you. Withdrawal does not affect processing that already occurred, and it does not apply to information we are required to retain by law.
To withdraw consent, contact privacy@genieai.ca, or use the unsubscribe link in any marketing message. Service and security notices are not marketing and will continue while your account is active.
6. Cookies, analytics and tracking
We use cookies, local storage, pixels, web beacons and similar technologies on our websites and, in limited form, in the product.
------------------------------------------------------------------------ Type What it does Can you turn it off ---------------- ------------------------------------ ------------------ Strictly Authentication, session integrity, No. The Services necessary load balancing, security and fraud will not function prevention. without these.
Functional Remembers language, region, Yes, with reduced interface and workspace preferences. convenience.
Analytics and Measures traffic, feature adoption, Yes. performance errors and page performance so we can improve the Services.
Marketing and Measures campaign performance and Yes. attribution attributes sign ups to sources. ------------------------------------------------------------------------
Where required by law we present a consent banner and set non essential cookies only after you opt in. You can also control cookies through your browser or device settings, and you can withdraw consent at any time through the cookie preferences link on our website. Blocking cookies may break parts of the Services.
We use third party analytics providers, including Google Analytics. These providers may collect IP address, timestamps, referring pages and return visitor status, and process that information under their own privacy terms. We configure IP anonymization and data retention limits where the provider supports them.
We honour Global Privacy Control and similar recognized opt out preference signals where applicable law requires it. Beyond that, our Services do not currently alter behaviour in response to browser do not track signals, because no common standard for them has been adopted.
7. Artificial intelligence, agents and automated processing
BOS orchestrates AI agents that read, generate, route and act on information. Because that is the core of what we build, we set out our commitments explicitly.
7.1 Model training
- We do not use Customer Content to train, fine tune or improve foundation models for the benefit of other customers or for general model development.
- We contractually require our AI model sub processors not to train their models on Customer Content submitted through our Services, and we use zero retention or limited retention configurations where the provider offers them.
- We may use Service Data, and Customer Content that has been aggregated or irreversibly de identified, to measure quality, tune orchestration logic, evaluate performance and improve reliability.
- Where a customer expressly opts in under a separate written agreement, we may use its Customer Content for that customer's own dedicated models. That opt in is specific, revocable and never assumed.
7.2 Inputs, outputs and retention
Prompts and outputs may be retained for a limited period to deliver the feature, support debugging, maintain audit trails, and detect abuse. Retention periods are set out in section 11 and can be shortened by contract for enterprise and government deployments.
7.3 Accuracy and human oversight
AI generated output can be incomplete, out of date or wrong. Outputs are decision support, not professional advice, and should be reviewed by a person before they are relied on for legal, financial, medical, employment or safety related decisions. Customers configure the approval gates, escalation paths and human in the loop checkpoints appropriate to their use case, and are responsible for doing so.
7.4 Automated decision making
Genie AI does not use automated decision making, including profiling, to make decisions about individuals that produce legal or similarly significant effects on them, without human involvement. Where a customer configures BOS to support such decisions in its own operations, the customer is responsible for the lawful basis, the disclosure, and the individual's right to an explanation and to human review. On request we will provide customers with information about the principal factors and parameters a configured workflow uses, so they can meet those obligations, including under Quebec's Law 25 and Articles 13, 14 and 22 of the GDPR.
7.5 Prohibited uses
Our terms prohibit using the Services to conduct unlawful surveillance, to infer sensitive characteristics for discriminatory purposes, to generate biometric identification of individuals without a lawful basis, or to make consequential decisions about people without meaningful human review.
8. Disclosure and sub processors
We do not sell your personal information, and we do not rent it, trade it, or share it for cross context behavioural advertising.
We disclose personal information only in the circumstances below.
- Sub processors and service providers who help us deliver the Services, under written contracts that limit them to our instructions, impose confidentiality and security obligations at least as protective as ours, and prohibit any independent use.
- Affiliates and our own personnel, advisors and contractors who need the information to do their jobs, on a least privilege basis.
- Your organization, where you use the Services through a workspace administered by an employer or other customer. Administrators can access account, usage and content within their workspace.
- Authorities and third parties where we are legally required to disclose, including in response to a valid court order, subpoena, regulatory demand or lawful investigative request. We assess every demand, require it to be legally valid and appropriately scoped, and notify the affected customer unless we are prohibited from doing so.
- To establish, exercise or defend legal claims, enforce our terms, prevent fraud, or protect the rights, property or safety of Genie AI, our customers or the public.
- In a corporate transaction, including a merger, amalgamation, financing, reorganization, or sale of all or substantially all of our assets. We will require the counterparty to be bound by this policy or by substantially similar protections, and we will act reasonably to ensure continuity of protection, though we cannot guarantee the counterparty's future compliance.
8.1 Categories of sub processors
We engage sub processors in the categories below. The current list of named sub processors, their function and their processing location is published at genieai.io/subprocessors and is updated when it changes.
------------------------------------------------------------------------ Category Function Typical processing region ----------------------- -------------------------------- --------------- Cloud infrastructure Compute, storage, networking, Canada, United and hosting managed databases. States
AI model and inference Language model inference and United States, providers embedding generation. Canada
Identity and access Authentication, single sign on, United States multi factor enrolment.
Payments and billing Payment processing, invoicing, United States, tax calculation. Canada
Communications Transactional email, United States notifications, in product messaging.
Support and ticketing Customer support, knowledge United States, base, session diagnostics. Canada
Analytics and Product analytics, error United States, monitoring tracking, uptime and performance European Union monitoring.
Business operations CRM, contract execution, United States, accounting, collaboration Canada tooling. ------------------------------------------------------------------------
Enterprise and government customers can subscribe to advance notice of new sub processors and, where their agreement provides for it, object on reasonable data protection grounds.
9. Security
We maintain an information security program with administrative, technical and physical safeguards proportionate to the sensitivity of the information we hold. Our program is aligned to recognized frameworks, and our current certification and attestation status is available on request under NDA.
9.1 Controls
- Encryption of personal information in transit using TLS 1.2 or higher, and at rest using AES 256 or equivalent.
- Role based access control, least privilege provisioning, mandatory multi factor authentication for internal systems, and single sign on and SCIM provisioning for customer workspaces.
- Logical tenant isolation so one customer's Customer Content is not accessible to another.
- Centralized audit logging, monitoring and alerting across production systems.
- Secure development lifecycle including code review, dependency scanning, static analysis and change management.
- Independent penetration testing and regular vulnerability scanning, with tracked remediation timelines by severity.
- Background checks where permitted by law, confidentiality agreements, and mandatory privacy and security training for personnel at onboarding and annually.
- Vendor due diligence and security review before a sub processor is engaged, and periodically afterward.
- Documented backup, disaster recovery and business continuity plans, with defined recovery objectives and periodic testing.
9.2 Incident response and breach notification
We maintain a documented incident response plan with defined severity levels, escalation paths and post incident review. If a breach of security safeguards occurs:
- Where we act as a processor, we notify the affected customer without undue delay after becoming aware, and provide the information the customer needs to meet its own notification obligations.
- Where we act as a controller and the breach creates a real risk of significant harm, we notify the Office of the Privacy Commissioner of Canada, the Commission d'acces a l'information du Quebec where applicable, and affected individuals as soon as feasible, and we maintain breach records for the period required by law.
- Where the GDPR or UK GDPR applies, we notify the competent supervisory authority within 72 hours of becoming aware, unless the breach is unlikely to result in a risk to individuals, and we notify affected individuals where the risk is high.
No method of transmission or storage is completely secure. We work hard to protect your information but cannot guarantee absolute security. If you suspect unauthorized access to your account or a security issue in our Services, contact security@genieai.ca immediately. We operate a responsible disclosure process and will not pursue good faith security research conducted within its terms.
10. International transfers and data residency
Genie AI is based in Canada. Personal information we collect may be stored and processed in Canada, the United States, and other jurisdictions where we or our sub processors operate. Those jurisdictions may have data protection laws that differ from those where you live, and information located there may be accessible to local courts, law enforcement and national security authorities under the laws of that jurisdiction.
We take the following steps to protect information that crosses borders.
- We contractually require every recipient to provide a comparable level of protection to the one required in the originating jurisdiction, and we remain accountable for information transferred to a third party for processing.
- For transfers from the EEA we rely on the European Commission's Standard Contractual Clauses, and we complete transfer impact assessments and apply supplementary measures where the assessment indicates they are needed.
- For transfers from the United Kingdom we rely on the UK International Data Transfer Addendum or the IDTA, as applicable.
- For transfers out of Quebec we conduct the privacy impact assessment required by Law 25 before the transfer, and confirm the information will receive adequate protection.
Data residency options are available for enterprise and government deployments, including Canadian region hosting for Canadian public sector workloads. Residency commitments are made in the customer agreement, not by this policy. Contact privacy@genieai.ca to confirm what is available for a specific deployment.
11. Retention
We keep personal information only as long as it is needed for the purposes it was collected for, or as long as required by law, contract, or the resolution of a dispute. When the retention period ends we delete the information, or irreversibly de identify or anonymize it. Our default schedule follows. Customer agreements may specify shorter or longer periods, and where they do, they prevail.
-----------------------------------------------------------------------
Information Default retention
--------------------------- ------------------------------------------- Customer Content in BOS For the term of the agreement. On termination, available for export for 30 days, then deleted from production within 90 days.
Account and profile data For the term of the agreement, plus 12 months, unless earlier deletion is requested.
Prompt and output logs 12 months, configurable down to 30 days for enterprise and government deployments.
Billing, invoicing and tax 7 years from the end of the relevant fiscal records year, to meet Canadian tax and corporate record requirements.
Support tickets and 24 months from closure. correspondence
Security, audit and access 12 to 24 months, depending on system and logs regulatory requirement.
Website analytics data 14 months.
Marketing contacts Until consent is withdrawn, or after 24 months of no engagement, whichever comes first. Unsubscribe records are kept indefinitely so we do not contact you again.
Recruitment records 12 months after the competition closes, or longer with the candidate's consent.
Encrypted backups Rolling 35 days, after which deleted records age out. Deletion requests are applied to production immediately and to backups as they cycle. -----------------------------------------------------------------------
12. Your rights
Subject to the exceptions in section 12.3, you can exercise the following rights over personal information we hold about you as a controller.
-----------------------------------------------------------------------
Right What it means
---------------- ------------------------------------------------------ Access Obtain confirmation that we hold personal information about you, a copy of it, and an account of the parties to whom, and the circumstances in which, it has been disclosed.
Correction Have inaccurate or incomplete information corrected or completed. If we decline, we annotate the record to show a correction was requested and not made.
Deletion Have information deleted where it is no longer needed, where consent is withdrawn and no other basis applies, or where required by law.
Portability Receive computerized personal information you provided to us in a structured, commonly used technological format, and have it transmitted to another organization where technically feasible.
Withdraw consent Withdraw consent at any time, on reasonable notice, subject to legal and contractual restrictions.
Object and Object to processing based on legitimate interests, or restrict ask us to restrict processing while a dispute about accuracy or legal basis is resolved.
De indexing Ask us to cease disseminating information, or de index a link, where dissemination contravenes the law or a court order, or causes serious injury to reputation or privacy.
Human review Ask for human review of, and an explanation of the factors behind, a decision based exclusively on automated processing.
Non Exercise your rights without being denied service, discrimination charged a different price, or given a lower quality of service.
Complain Lodge a complaint with your privacy regulator. Our response will tell you which one and how to reach it. -----------------------------------------------------------------------
12.1 How to make a request
Send your request to privacy@genieai.ca with the subject line Privacy Request. Include enough detail for us to locate the information and verify your identity. We may ask for proof of identity proportionate to the sensitivity of the information requested, and we use that proof only to verify the request. An authorized agent may act for you with written authorization and proof of their own identity.
12.2 How we respond
- We acknowledge requests promptly and respond no later than 30 days from receipt, or within any different period required by applicable law.
- We may extend the period where the law allows, and where we do we will tell you before the original deadline and explain why.
- Access requests are answered free of charge, except that minimal cost recovery may apply where permitted by applicable privacy legislation, and we will tell you the estimated cost before proceeding.
- Where we correct information, and it is reasonable to do so, we notify third parties to whom we disclosed the incorrect information.
12.3 When we may refuse
We may withhold information, in whole or in part, where the law permits or requires it, including where:
- the information is subject to solicitor client or litigation privilege;
- disclosure would reveal confidential commercial information;
- disclosure could reasonably be expected to threaten the life, safety, or physical or mental health of another individual;
- the information was generated in a formal dispute resolution process;
- the information relates to another identifiable individual and cannot be severed;
- the information was collected without knowledge or consent for purposes related to investigating a breach of an agreement or a contravention of the laws of Canada or a province, or in the course of a lawful investigation.
If we refuse, we will tell you the reasons, the provision of the applicable legislation we rely on, how to reach the Privacy Officer to discuss it, and how to ask for a review by the relevant regulator.
13. Regional addenda
The following terms supplement this policy for individuals in the identified regions. Where an addendum conflicts with the main body, the addendum prevails for those individuals.
13.1 Canada
We handle personal information in accordance with the Personal Information Protection and Electronic Documents Act, Quebec's Law 25 and the Act respecting the protection of personal information in the private sector, and the substantially similar provincial legislation of Alberta and British Columbia.
- Accountability. We have designated a Privacy Officer who is accountable for our compliance and reachable at privacy@genieai.ca.
- Quebec. Privacy settings for any product feature that collects personal information are set to the highest level of confidentiality by default. We conduct privacy impact assessments for projects involving the acquisition, development or overhaul of information systems handling personal information, and before communicating personal information outside Quebec.
- Commercial electronic messages. We comply with Canada's Anti Spam Legislation. Every commercial message identifies us, gives our contact information, and includes a working unsubscribe mechanism that we action within 10 business days.
- Complaints. You may complain to the Office of the Privacy Commissioner of Canada at priv.gc.ca, or to the Commission d'acces a l'information du Quebec, the Office of the Information and Privacy Commissioner of Alberta, or the Office of the Information and Privacy Commissioner for British Columbia, as applicable. We ask that you contact us first so we can try to resolve it directly.
13.2 European Economic Area, United Kingdom and Switzerland
- Controller. GENIE AI, Inc. is the controller for the processing described in this policy, except where we act as a processor for a customer.
- Legal bases. Our legal bases are set out in the table in section 4. Where we rely on legitimate interests, we have carried out a balancing assessment and will provide a summary on request.
- Transfers. We rely on Standard Contractual Clauses, the UK Addendum or the IDTA, and supplementary measures identified by transfer impact assessment. A copy of the relevant safeguards is available on request.
- Rights. In addition to the rights in section 12, you have the right to lodge a complaint with your local supervisory authority, including the Information Commissioner's Office in the United Kingdom and the Federal Data Protection and Information Commissioner in Switzerland.
- Representative. Our representative under Article 27 of the GDPR and the UK GDPR, where required, is identified at genieai.io/legal.
13.3 United States
This section applies to residents of California, Colorado, Connecticut, Virginia, Utah, Texas and other states with comprehensive privacy legislation, to the extent that legislation applies to us.
- Sale and sharing. We have not sold personal information, and we have not shared it for cross context behavioural advertising or targeted advertising, in the preceding 12 months. We do not sell or share the personal information of minors.
- Categories. The categories of personal information we collect, the sources, the purposes, and the categories of recipients are described in sections 3, 4 and 8. We disclose personal information to sub processors for business purposes only.
- Sensitive personal information. We do not use or disclose sensitive personal information for purposes other than those permitted without a right to limit, including providing the Services, security, and legal compliance.
- Rights. California, Colorado, Connecticut and Virginia residents may request to know, access, correct, delete, obtain a portable copy, opt out of targeted advertising, profiling and sale, and appeal a refusal. To appeal, reply to our decision with the subject line Privacy Appeal, and we will respond within the period your state's law requires and tell you how to contact your Attorney General.
- Shine the Light. California residents may request information about disclosures of personal information to third parties for their own direct marketing purposes. We make no such disclosures.
14. Third party links and integrations
Our Services link to and integrate with third party sites, platforms and applications, including social media, identity providers and business tools that customers connect to BOS. When you follow a link or authorize an integration, that third party collects and handles information under its own privacy policy and security practices. We do not control those practices. Review them before connecting anything, and be aware that social media plug ins can connect your browser directly to the provider's servers when the page loads.
15. Changes to this policy
We may update this policy as our Services, our legal obligations, or our practices change. The date at the top shows when it was last revised. If a change materially affects your rights, we will provide notice by posting it prominently on our website, by email, or both, before it takes effect. Continued use of the Services after a change takes effect means you accept it. We maintain prior versions and will provide one on request.
16. Contact us
Direct any question, concern, access request or complaint to our Privacy Officer. We take every complaint seriously, investigate it, and respond in writing with the outcome and the steps you can take if you remain unsatisfied.
-----------------------------------------------------------------------
Reason Contact
--------------------------- ------------------------------------------- Privacy questions, requests privacy@genieai.ca, attention Privacy and complaints Officer
Security issues and security@genieai.ca vulnerability reports
General customer service hello@genieai.io
Mail GENIE AI, Inc., attention Privacy Officer, Suite 400, 77 King Street West, Toronto, Ontario M5K 2A1, Canada -----------------------------------------------------------------------
GENIE AI, Inc. Federally incorporated in Canada under the Canada Business Corporations Act. This policy is published in English. Une version francaise est disponible sur demande.