Legal

Privacy Policy

Effective Date: July 6, 2026

This Privacy Policy explains how LOD Technologies Inc., a British Columbia corporation operating the CLōD platform at clod.io (“CLōD,” “we,” “us”), collects, uses, discloses, and protects personal information when you use our websites, API, and dashboard (the “Services”). It applies alongside our Terms of Service. We are the “organization” responsible for personal information under Canada's PIPEDA and, where applicable, Québec's private-sector privacy law (as amended by Law 25). Where the EU or UK GDPR applies, we act as the controller of account and billing information, and as a processor of the content you submit through the API.

1. Information We Collect

Account information. Name, email address, and password when you create an account. If you sign up via a third-party provider (e.g., Google), we receive basic profile information from that provider.

Usage data. Information about how you use the Services: API requests made, models used, token counts, request timestamps, latency metrics, error rates, and cost data. This generates your activity logs and billing statements.

Request content (Inputs and Outputs). The prompts you submit and the responses returned. You control whether and how long this content is retained — see Section 4 (Your Retention Controls).

Technical data. IP address, browser type, operating system, and device identifiers, collected for security and functionality.

Payment information. Payment details are processed by our third-party payment processors; we never store full card numbers. We retain billing records (amounts, dates, transaction IDs, last four digits) for accounting, fraud prevention, and compliance.

2. How We Use Your Information (and Our Legal Bases)

We use personal information to: provide, maintain, and improve the Services, including processing API requests, routing across data centers, calculating pricing, and generating activity logs (performance of contract); send service communications such as billing receipts, usage alerts, and security notices (performance of contract / legitimate interests); detect and prevent abuse, fraud, and unauthorized access (legitimate interests / legal obligation); send marketing communications you can opt out of at any time (consent / legitimate interests); and comply with legal obligations, including tax, accounting, and sanctions laws.

We do not use your Inputs or Outputs to train, fine-tune, or improve AI models. Aggregated, de-identified usage data (never the content of your requests) helps us improve performance, pricing, routing, and the model catalog. We do not attempt to re-identify de-identified data.

We do not make decisions producing legal or similarly significant effects about you based solely on automated processing.

3. Sharing and Disclosure

Service providers. Trusted vendors who help us operate the platform (cloud infrastructure, payment processing, analytics, support tooling), contractually bound to handle data securely and only for the purposes we specify. A current list of subprocessors is available on request at privacy@clod.io.

Legal requirements. We may disclose data when required by law, court order, or governmental authority, or where we believe disclosure is necessary to protect the rights, property, or safety of CLōD, our users, or the public. Where lawful, we will notify you of demands for your data.

Business transfers. In connection with a merger, acquisition, financing, or sale of assets, personal information may be transferred subject to this Policy's protections.

No sale. We do not sell, rent, or trade your personal information, and we do not "sell" or "share" personal information as those terms are defined under the California Consumer Privacy Act (CCPA/CPRA).

4. Your Retention Controls

Activity logs. Request logs are retained according to your project settings. You choose the retention window, including turning content logging off.

Log encryption. You may enable per-project log encryption. Encrypted logs are readable only by you as the holder of the private key — CLōD cannot decrypt them.

Zero Data Retention (ZDR). Where you enable ZDR for a project, we do not persist the content of your Inputs or Outputs after the request completes: content is processed in memory solely to route the request and return the response. Usage metadata (token counts, model selection, timestamps, status codes) is still retained for billing, security, and abuse prevention. ZDR projects may lose access to features that depend on stored content, such as activity logs.

5. Data Retention

Account data. Retained for as long as your account is active. If you delete your account, we delete or anonymize your personal data within 30 days, except where retention is required for legal, accounting, or fraud-prevention purposes (billing records are typically retained for seven years under Canadian tax law).

Request content. Retained per your project settings, log-encryption, and ZDR choices (Section 4).

Technical and security data. Retained for up to 12 months for security and abuse investigation, then deleted or aggregated.

6. International Data Transfers

We are based in Vancouver, Canada, and route requests across data centers that may be located in other jurisdictions, including the United States; energy-aware routing means the processing location may vary per request. Where we transfer personal information internationally, we do so in accordance with applicable law, including contractual safeguards, and — where the EU or UK GDPR applies — EU Standard Contractual Clauses and the UK Addendum. Customers requiring a data processing agreement (DPA) may request one at privacy@clod.io. We conduct the assessments required by Québec Law 25 for communications of personal information outside Québec.

7. Security

We maintain administrative, physical, and technical safeguards including encryption in transit (TLS) and at rest, access controls on a least-privilege basis, logging and monitoring, and periodic security assessments. No method of transmission or storage is completely secure; we will notify you and applicable regulators of breaches of security safeguards as required by law (including PIPEDA's breach-reporting requirements and Law 25's confidentiality-incident regime).

API key security. API keys are sensitive credentials. Never share them publicly or embed them in client-side code. CLōD will never ask for your API key by email or chat. If you believe a key is compromised, revoke it immediately from your dashboard.

8. Cookies and Tracking

Essential cookies maintain your session and authenticate you on the dashboard; these cannot be disabled without breaking core functionality. Analytics cookies are used only with your consent to understand how visitors interact with our website; you can withdraw consent at any time via cookie settings. We honour Global Privacy Control (GPC) signals where required by law. We do not use third-party advertising cookies.

9. Your Rights

Depending on your jurisdiction, you may have the right to: access a copy of the personal information we hold about you and information about how it is used (and, under Law 25, to whom it has been communicated); correct inaccurate or incomplete information; delete your personal information; receive your information in a portable, structured format; withdraw consent where processing is based on consent; object to or restrict certain processing (GDPR); and not receive discriminatory treatment for exercising your rights (CCPA).

To exercise any right, contact privacy@clod.io or use your dashboard settings. We respond within 30 days. We may need to verify your identity before acting on a request. If you are dissatisfied with our response, you may complain to your supervisory authority — in Canada, the Office of the Privacy Commissioner of Canada; in Québec, the Commission d'accès à l'information; in the EU/UK, your local data protection authority; in California, the California Privacy Protection Agency.

Marketing opt-out. Unsubscribe via any marketing email or your notification preferences. Service and billing communications are sent regardless, as they are necessary to operate your account.

10. Children's Privacy

The Services are not intended for anyone under 16, and we do not knowingly collect personal information from children under 16. If you believe a child has provided us personal information, contact privacy@clod.io and we will delete it promptly.

11. Privacy Officer and Contact

Our Privacy Officer (responsible for personal information protection, including for Law 25 purposes) can be reached at:

LOD Technologies Inc. (CLōD) Vancouver, British Columbia, Canada privacy@clod.io

12. Changes to This Policy

We may update this Policy from time to time; the Effective Date above reflects the latest version. Continued use of the Services after changes take effect constitutes acceptance; prior versions are available on request.