R RapidRAG›Privacy Policy
Proof of Concept Notice: RapidRAG is currently in active development and is provided free of charge as a proof of concept. BCT Infosys Inc. provides no warranties and accepts no liability for any data loss, inaccuracies, security incidents, or damages arising from use of this platform. Use at your own risk.

Privacy Policy

Company: BCT Infosys Inc.Product: RapidRAG — RAG-as-a-ServiceJurisdiction: Ontario, CanadaEffective: June 18, 2026Version: 1.1

1. Introduction

BCT Infosys Inc. (“BCT Infosys,” “we,” “us,” or “our”) is incorporated under the laws of the Province of Ontario, Canada. We are committed to protecting your personal information in accordance with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), Canada's Anti-Spam Legislation (CASL), and applicable Ontario statutes.

This Privacy Policy describes how we collect, use, disclose, and protect personal information in connection with your use of the RapidRAGplatform and all related services (collectively, the “Services”).

By accessing or using the Services, you acknowledge that you have read and understood this Policy and consent to the collection, use, and disclosure of your personal information as described herein.

2. Privacy Officer

BCT Infosys has designated a Privacy Officer who is responsible for our compliance with PIPEDA and this Policy. You may direct any privacy questions, access requests, or complaints to:

BCT Infosys Inc. — Privacy Officer
2 County Ct Blvd, Brampton, ON L6W 3W8, Canada
Email: [email protected]
General: [email protected]

3. What Information We Collect

3.1 Information You Provide

  • Account registration: name, email, organization, role
  • Password (stored as a cryptographic hash — never in plaintext)
  • Knowledge base content you upload (documents, files, URLs)
  • Repository and cloud drive connections you authorize (GitHub, GitLab, Google Drive)
  • Slack/Telegram/WhatsApp messages processed through integrations you enable
  • Support correspondence and feedback

3.2 Information Collected Automatically

  • IP addresses, browser type, operating system, pages visited, timestamps
  • Authentication events (login times, failed attempts — not passwords)
  • Feature usage metrics and API call volumes (anonymized query patterns)
  • Device information (type, screen resolution, timezone)

We do not read the content of your knowledge base for advertising or profiling purposes.

3.3 Third-Party Integration Data

When you connect GitHub, GitLab, Google Drive, Slack, or other platforms, those services send us OAuth tokens and the file/message content you authorize. Tokens are stored in encrypted secrets management (HashiCorp Vault) and are never logged.

4. How We Use Your Information

PurposePIPEDA Basis
Provide and operate the ServicesConsent / Contractual necessity
Account authentication and access controlConsent / Contractual necessity
Process support requestsConsent / Legitimate purpose
Monitor system health and securityLegitimate purpose
Aggregate anonymized usage analyticsLegitimate purpose
Send transactional notificationsContractual necessity
Send marketing/product updatesExpress consent (CASL opt-in)
Comply with legal obligationsLegal obligation

We do NOT sell your personal information, use it to train AI models without explicit written consent, or share it with advertisers.

5. Marketing Emails — CASL Compliance

We only send commercial electronic messages if you have provided express consent or we have implied consent as permitted under CASL. Every marketing email includes a clear unsubscribe link. We process unsubscribe requests within 10 business days as required by CASL. CASL consent records are retained for a minimum of 3 years.

6. How We Share Your Information

BCT Infosys does not sell, rent, or trade your personal information. We share it only with:

  • Sub-processors (cloud hosting, AI inference, email delivery, billing, monitoring) bound by contractual data protection obligations
  • Law enforcement / courts when required by Canadian or Ontario law, court order, or regulatory demand
  • Successors in the event of a merger or acquisition (with advance notice to you)
  • Third parties with your prior express consent

Cross-border transfers: Some sub-processors may be outside Canada. By using the Services you consent to such transfers where necessary. Canada has been recognized by the EU Commission as providing adequate protection under PIPEDA.

7. Data Retention

Data CategoryRetention Period
Account data & Customer DataAccount duration + 30 days after termination
Authentication logs90 days
System logs / telemetry30 days
Support correspondence3 years from ticket closure
Billing records7 years (CRA requirement)
CASL consent records3 years from consent or last transaction
Anonymized analyticsIndefinitely (not personal information)

8. Data Security

We implement a defense-in-depth security architecture including:

  • TLS 1.2+ in transit; AES-256 at rest; mTLS between internal services
  • Secrets stored in HashiCorp Vault
  • Role-based access control (RBAC) via Keycloak; principle of least privilege
  • Automated vulnerability scanning and penetration testing
  • Full audit logging of administrative actions
NO SYSTEM IS COMPLETELY SECURE. BCT INFOSYS CANNOT GUARANTEE ABSOLUTE SECURITY OF YOUR DATA. You are responsible for the security of your credentials, API keys, and OAuth tokens. BCT Infosys is not liable for breaches caused by your failure to maintain credential security, your employees' actions, or third-party integration vulnerabilities.

8.1 Breach Notification

In the event of a breach of security safeguards that creates a real risk of significant harm, BCT Infosys will notify the Office of the Privacy Commissioner of Canada (OPC) and all affected individuals as soon as feasible, and maintain a breach record for a minimum of 24 months, as required under PIPEDA.

9. Your Rights Under PIPEDA

RightHow to Exercise
Access your personal informationEmail [email protected] — response within 30 days
Correct inaccurate dataEdit in-app, or email us
Withdraw consentEmail [email protected] (may affect service access)
Lodge a complaintContact OPC at www.priv.gc.ca or 1-800-282-1376

10. Children's Privacy

The Services are not directed to individuals under 18. We do not knowingly collect personal information from minors. Contact our Privacy Officer immediately if you believe we have collected data from a minor.

11. On-Premises Deployments

For self-hosted deployments, Customer Data never leaves your infrastructure. BCT Infosys has no access to your Customer Data in this configuration. Our Privacy Policy obligations apply only to personal information we actually receive.

12. Changes to This Policy

We will notify registered users by email at least 30 days before material changes take effect. Your continued use of the Services after that date constitutes your consent to the updated Policy.

13. Governing Law

This Policy is governed by the laws of the Province of Ontario and the federal laws of Canada applicable therein, including PIPEDA and CASL. Disputes are subject to the exclusive jurisdiction of the courts of Ontario, sitting in Brampton or Toronto, Ontario, Canada.

14. Contact

BCT Infosys Inc. — Privacy Officer
2 County Ct Blvd, Brampton, ON L6W 3W8, Canada
[email protected] | [email protected]

Office of the Privacy Commissioner of Canada: www.priv.gc.ca | 1-800-282-1376

© 2026 BCT Infosys Inc. — Brampton, Ontario, Canada
HomePrivacy PolicyTerms & Conditions[email protected]