Privacy Policy — Ekorra
Version 1.3 — September 12, 2026 · Effective date: September 12, 2026
This document is a translation of the French original. In case of discrepancy, the French version prevails.
Neural North (the "Operator", "Ekorra", "we") operates the Ekorra platform for collecting, checking and exchanging documents. This policy describes how we collect, use, retain and protect personal information, in accordance with Law 25 (Quebec) and PIPEDA (Canada).
1. Who this policy is for
- Customers: the entrepreneurs, firms and businesses holding an Ekorra account.
- Uploaders: the end clients who upload documents through an Ekorra portal at a Customer's request, or who view there the documents that Customer sends them. For this information, the Customer is the person in charge (controller); Ekorra acts as a service provider under the Data Processing Agreement.
2. Information collected
Customer accounts: name, business name and logo, email, contact address, language, Google account identifier when you sign in with Google, usage logs (sign-ins, IP addresses), API keys and webhook addresses, workspace settings (including whether document sharing is enabled), the questions you ask about your files through the question-answering feature and the answers provided, the plan recorded on your account and the status of your trial period (account creation date, trial end date and status: trial under way, grace period, trial expired, plan agreed or "no plan"), the suspension status of the account where applicable, the internal notes on support and billing that our team records on your account (never displayed in the Service, but subject to your rights — section 9), the log of our team's actions on your account (author, action, target and date — never the text of a note) and, where applicable, billing information.
Uploaders and documents:
- the Uploader's name, email and language, recorded by the Customer in its client list;
- the uploaded documents (which may contain sensitive information: financial statements, notices of assessment, bank statements, identity documents), together with the description of the file (profile or transcript) provided by the Customer to build the request;
- the verification results produced by the AI (notes, confidence levels, and fields extracted from documents — amounts, dates, years, issuer — stored outside the file, destroyed with the document and replaced upon a new upload);
- the search index derived from the documents (text transcribed page by page and vector representations), stored outside the file and destroyed with it (section 3);
- messages exchanged with the assistant, including questions asked about the file and the answers provided; messages addressed to the Customer from the portal;
- where the Customer has enabled document sharing: the documents the Customer sends to the Uploader and the viewing receipts for those documents (date and time of the first viewing and of the last download, visible to the Customer);
- code verification data: one-time code stored in hashed form only, time sent and time verified, number of failed attempts, and a device-specific session token;
- after the documents of a request are deleted (section 7), an archive record without content: status of the request, dates and stages, purpose, names of the documents requested and check rules set by the Customer, a count of what was deleted and the date of deletion.
Feedback: the comments you voluntarily send us from the Service to improve it — category, message text, date, identifier of the workspace or request it was sent from and, once the comment has been dealt with, the date it was handled. Ekorra is the person in charge of this information, which it processes on its own behalf. The text is read by our team in its administration tool, and an internal notice alerts the team to each piece of feedback by email (section 6): do not include sensitive information or information about other people.
Technical email log: for each email sent, the template, language, delivery status, timestamp and the identifiers of the workspace and request concerned — never the recipient's address or the content.
We do not collect biometric information and do not perform any identity verification based on identity documents: uploaded identity documents are treated as ordinary documents. The verification code described above only confirms access to the Uploader's email address.
3. Purposes
Providing the Service: collection, AI-assisted checking, review by the Customer, notifications and reminders, relaying messages to the Customer; delivering to the Uploader the documents the Customer intends for them and confirming that they have been viewed; verifying, by one-time code, access to the Uploader's email address before those documents are viewed; indexing documents and answering questions asked by the Uploader about their own request and by the Customer about the active files in its own workspace (its own Uploaders only — internal use, by the person in charge, of information it already holds), solely for the purposes of processing the request and serving the Uploader. Operating, securing and supporting the Service — our team then accesses metadata and counters only (section 8) — and preventing fraud; billing; improving the Service through de-identified statistics; complying with our legal obligations. Uploaders' documents and information — including the search index — are never used to train AI models or for advertising purposes.
The search index is created when a document is checked, processed in Canada, segregated by Customer and by request at search time, and deleted as soon as the document is replaced or removed, and at the latest with the request (section 7). It does not constitute a durable document base.
4. Automated decisions
Document checks are AI-assisted — including field extraction (amounts, dates, issuer), which remains a mere aid to review — but no final decision is fully automated: every verdict is made by a person at the requesting Customer. The assistant's answers to questions about documents cite the document and page they come from (or state that no source was found); they are a reading aid and replace neither the verification of the document nor the Customer's decision. Uploaders are informed of the automatic check and of the indexing at the time of upload and may ask questions or object through the portal or with the Customer.
5. Disclosure and service providers
We do not sell any personal information. We disclose it only: to the requesting Customer (for the documents, messages and viewing receipts of its Uploaders); to our technical service providers, contractually bound by equivalent obligations; or where the law requires it.
Service providers (list maintained in Schedule A of the Data Processing Agreement):
- Hosting, storage, backups and search index: Google Cloud (Montreal region, Canada)
- AI model provider: Google Cloud Vertex AI (Gemini models and a multilingual vector representation model — text-multilingual-embedding-002 as of this version —, processed in a Canadian region; enterprise terms: no use of data for training)
- Transactional email delivery: Resend (Plus Five Five, Inc., United States)
Our team's internal tools: Ekorra's business mailbox (Google Workspace) receives the internal feedback notice described in section 6; no Uploader information is otherwise processed there.
6. Transfers outside Quebec and Canada
Uploaders' documents and information are hosted and processed in Canada (Google Cloud, Montreal region, including AI processing, indexing, search and backups).
Only one category of information leaves Canada: transactional emails, delivered by our provider Resend (Plus Five Five, Inc.), established in the United States, where it keeps a copy of sent emails for a limited period (thirty (30) days as of this version). These are the portal invitation, reminders, the review return, the notice that a document has been sent to you, one-time verification codes, Customers' sign-in links, the relaying to the Customer of the messages you write to it from the portal, and the internal notice that alerts our team to feedback. Each email contains only the data specific to its category: your email address and, except in the verification code email (which carries no greeting), your first name (your full name in the relaying of your messages, so that the Customer knows who is writing), the Customer's email address for its sign-in link, the name of the requesting Customer, the purpose of the request, the names of the documents requested, to be fixed, still needed or sent, the brief review note accompanying a document to be fixed, the portal access link (valid thirty (30) days) and, where applicable, a verification code (valid ten (10) minutes) or a sign-in link (valid fifteen (15) minutes); the contact relay and feedback reproduce the text you wrote yourself — we invite you not to include any sensitive information in it and to upload a document in the portal instead. These emails never contain any document, attachment, AI-extracted field or description of a sent document. They are encrypted in transit between Ekorra and the provider; final delivery to your email server is encrypted where that server supports it, as with any email.
The internal feedback notice is received in our team's business mailbox (Google Workspace), whose hosting is not fixed in Canada: for as long as that notice reproduces the text of the feedback, a copy of that text resides there — with no Uploader information other than what the author wrote — until it is deleted (section 7). That mailbox is an Ekorra tool, covered by the assessment described below.
This transfer has been the subject of a privacy impact assessment in accordance with section 17 of Law 25 (sensitivity and purpose, contractual measures with the provider, minimization of the data transmitted, time-limited access elements, legal regime of the destination State); we review it at least once a year and upon any change of email category or provider. Any new transfer outside Quebec would be subject to an equivalent prior assessment and an update of this policy.
7. Retention and destruction
Uploaders' documents are kept while the request is being processed and are deleted twelve (12) months after it is closed — closing being the end of the Customer's review (request marked complete) —, unless the Customer instructs otherwise or the law requires otherwise. The following follow the same retention and deletion: the documents the Customer sends to the Uploader, viewing receipts, the messages and questions and answers attached to the request, the document suggestions and the description (profile or transcript) the request was built from, code verification data, the portal access link, the entries of the technical email log attached to the request and the search index — the latter being also deleted as soon as a document is replaced or removed. A request the Customer has not closed (draft, request sent or under review) is not covered by this deletion until it is; you may request its deletion (section 9).
Deletion is carried out by a daily process, in calendar months; it is secure and irreversible in our systems, and takes effect in our encrypted backup copies no later than forty (40) days afterwards. Backups serve only to restore the Service; after a restoration, the daily process re-applies the deletion to data whose retention has elapsed. An archive record without content remains (section 2), which the Customer may view.
A verification code expires after ten (10) minutes; the expired code is deleted at the next daily run. A verified session on the Uploader's device expires after thirty (30) days. The Uploader's name, email and language recorded in the Customer's client list follow that Customer's account data, unless deletion is requested (section 9). Customers' account data — including the questions asked across all of their files, the internal notes and the log of our team's actions — is kept for the duration of the contractual relationship and for 12 months after it ends, unless a legal obligation requires otherwise. Feedback is de-identified twelve (12) months after it is handled and at the latest twenty-four (24) months after it is received: the text is deleted by the same daily process, and only the category, origin and dates are kept for statistical purposes; the copy of the internal notice received in our team's mailbox is deleted no later than the same deadline (section 6). Copies of documents that the Customer downloads into its own files are subject to the Customer's retention obligations, not ours.
8. Security
Encryption in transit (TLS) and at rest, need-to-know access control, logging, segregation by Customer — including of the search index, whose filtering by Customer and by request is applied in every search —, encrypted backups, signed and time-limited access links, one-time verification codes that are hashed, time-limited and attempt-limited. Our team's administration tools expose metadata and counters only — never the content of a document, an extracted field, a detailed check note, a portal message or an access link to a file — and every action of the team on an account is logged. In case of a confidentiality incident presenting a risk of serious injury: notification to the Commission d'accès à l'information (CAI), to the Office of the Privacy Commissioner of Canada where applicable, to the persons concerned and to the affected Customers; an incident register is kept.
9. Your rights
Access, correction, withdrawal of consent, deletion, portability (communication in a structured technological format) and complaint to the CAI or the Privacy Commissioner. For documents requested by a Customer, we redirect the request to that Customer and assist it.
10. Person in charge of the protection of personal information
Julien Mercier, Founder — vie-privee@ekorra.com — Neural North, 4432, rue Saint-Michel, Montréal (Québec) H1Y 3J7. Response within thirty (30) days.
11. Storage in your browser (cookies) and minors
The Service uses no advertising cookies or third-party analytics tools, and no technology allowing you to be identified, located or profiled within the meaning of section 8.1 of Law 25. It relies solely on your browser's local storage, for what is strictly necessary to its operation — data read by the Service in your browser and never transmitted to a third party:
- `smartbox_session`: the Customer's sign-in token (workspace session), sent to our servers to authenticate your requests;
- `ekorra_portal_session:<request>`: the Uploader's verified session token, specific to one request, after a verification code is entered (thirty (30) days), sent to our servers to authorize viewing of sent documents;
- `ekorra_lang`: interface language (French or English);
- `ekorra_theme`: display theme (light or dark);
- `ekorra_docs_view`: display mode of the document list;
- `ekorra_flags`: experimental features you have enabled yourself in the settings;
- `ekorra_consent_hidden`: remembers that you collapsed the portal's privacy notice; the notice remains one click away.
You may clear this data at any time through your browser settings; the Service then asks you to sign in or enter a code again and returns to its default settings. The Service is not intended for minors.
12. Changes and language
Any material change is announced with reasonable notice within the Service or by email. The version in force and its date appear at the top of the document. Document drafted in French; this English version is provided for convenience and, in case of discrepancy, the French version prevails.
Operator: Neural North · 4432, rue Saint-Michel, Montréal (Québec) H1Y 3J7 · contact@ekorra.com · vie-privee@ekorra.com
Version history: 1.3 (September 12, 2026) — account data (plan, trial, suspension, internal notes, action log), archive record, deletion mechanism and backup copies, team access to metadata, team mailbox, browser storage (sections 2, 3, 5 to 8 and 11) · 1.2 (September 11, 2026) — alignment with the privacy impact assessment of the email provider · 1.1 (September 10, 2026) — document sharing, one-time code, indexing and question answering · 1.0 (September 10, 2026) — first published version.