Privacy policy

We protect your personal information with the same care we bring to helping our customers protect their visitors' information. This policy explains what we collect, why, and what your rights are.

Last updated: July 18, 2026

1. Scope

This privacy policy describes how Oriana Solutions Inc., publisher of the Consorm platform, collects, uses, communicates and protects personal information in connection with its site, its application and its service (the "Service").

It applies to the information of customers and users of the Service, as well as to the information of visitors of our customers' sites that we process on their behalf. It should be read together with our terms and conditions.

2. Identity and contact details

The person responsible for the processing of personal information covered by this policy is Oriana Solutions Inc., with its head office in Montreal, Quebec, Canada.

In accordance with Law 25, we have designated a person in charge of the protection of personal information. You can reach them, for any question or to exercise your rights, at allo@consorm.ca.

3. Our dual role: controller and processor

Depending on the context, we act in one of the following two capacities:

As a controller
with respect to the information of customers and users who create an account, subscribe to a plan or communicate with us. We determine the purposes and means of that processing, described in this policy.
As a processor
with respect to the information of visitors of our customers' sites (the consent data), which we process only on behalf of and under the instructions of the customer concerned. For that information, the customer is the controller and their own privacy policy applies.

4. Information we collect

Account and billing information

When you create an account or subscribe to a plan, we collect your name, your email address, the profile picture associated with your sign-in method, your organization's name, and the billing information required. Payment information (card numbers) is processed directly by our payment provider and is not stored on our servers.

Usage and technical information

We collect technical information related to your use of the Service, such as access logs, IP address, browser type, session identifiers, the configurations you create and diagnostic data, for security, troubleshooting and improvement purposes.

Consent data processed on behalf of our customers

When a visitor interacts with a customer's consent banner, the Service records their expressed choice. For data minimization, that record relies on a pseudonymous identifier and does not contain the visitor's name. It may include:

  • a pseudonymous consent identifier and the nature of the decision (acceptance, refusal, withdrawal, saved preferences);
  • the cookie categories concerned and the version of the policy presented;
  • context data such as language, country and region (province or state), and the Global Privacy Control (GPC) signal;
  • a timestamp, a browser fingerprint (user agent) and a one-way hash of the IP address, the plain IP address not being stored.

5. Purposes for which we use information

We use the information for which we are the controller for the following purposes:

  • provide, operate, maintain and secure the Service and manage your account;
  • process payments, billing and subscription administration;
  • answer your requests, provide support and send you communications about the Service;
  • prevent fraud, abuse and security incidents, and enforce our terms;
  • improve the Service, including through aggregated statistics that cannot identify you;
  • comply with our legal and regulatory obligations.

We do not sell your personal information and do not use it for purposes to which you have not consented where such consent is required.

6. Cookies and tracking technologies on our platforms

Our own application uses only the cookies strictly necessary for it to work, in particular to maintain your authentication session and your preferences (such as language). We do not use advertising cookies on the application. You can review and manage cookies from your browser settings.

7. Communication and use of subcontractors

We do not sell or rent your personal information. We may communicate it to service providers (subcontractors) who act on our behalf and under our instructions, only to the extent necessary to provide the Service, and who are bound by confidentiality and security obligations. Our main subcontractors are the following:

SubcontractorFunctionProcessing location
SupabaseAuthentication and database hostingCanada / United States
CloudflareEdge delivery, storage, bot protectionGlobal network
StripePayment processing and billingUnited States
ResendTransactional email deliveryUnited States
GoogleSign-in and Google Tag Manager integrationUnited States
Microsoft AzureTechnical monitoring and loggingCanada / United States

We may also communicate information where the law requires it, to answer a request from a competent authority, to protect our rights or the safety of others, or in connection with a business transaction such as a merger or acquisition, in which case the information remains protected by this policy.

8. Transfers outside Quebec

We favor hosting your information in Canada. However, some of our subcontractors may process information outside Quebec, notably in the United States. Before proceeding with such a communication, we carry out a privacy impact assessment, in accordance with Law 25, and we govern these transfers with contractual commitments ensuring adequate protection of the information.

9. Retention period

We keep personal information only for as long as necessary to fulfill the purposes for which it was collected, or as long as the law requires. Account information is kept for the duration of the contractual relationship and for a reasonable period afterwards.

Consent data is kept on behalf of the customer concerned, according to their instructions and the purpose of proving consent. When an erasure is requested, we delete the record and keep only a proof of erasure based on a one-way hash, without keeping the erased identifier.

10. Security and protection measures

We take reasonable technical and organizational security measures to protect personal information against loss, unauthorized access, communication, copying, use or modification. These measures include encryption of data in transit, role-based access control, encryption of sensitive tokens and data minimization.

By design, the Service applies strict minimization of visitor information: the IP address is stored as a one-way hash rather than in plain form, visitor requests rely on a hash of the email address, and erasure leaves only a proof stripped of any identifier. No system can however guarantee absolute security.

11. Your rights

Subject to the conditions and exceptions provided by law, you have the following rights with respect to your personal information:

  • the right to access your information and obtain a copy of it;
  • the right to have inaccurate, incomplete or ambiguous information corrected;
  • the right to withdraw your consent or object to a processing, where applicable;
  • the right to deletion or to the cessation of dissemination of your information, in the cases provided by law;
  • the right to portability, that is, to receive the computerized information you provided to us in a structured, commonly used technological format;
  • the right to be informed of, and to submit observations regarding, a decision based exclusively on automated processing.

12. How to exercise your rights

To exercise your rights, write to our person in charge of the protection of personal information at allo@consorm.ca. We may need to verify your identity before acting on your request, and we answer within the deadlines provided by law.

If you are a visitor of one of our customers' sites and wish to exercise your rights with respect to your consent data, you must address your request to the operator of the site concerned, who is its controller. As a processor, we assist that customer in acting on your request.

13. Information about minors

The Service is intended for organizations and professionals and is not directed at minors. We do not knowingly collect personal information from minors through our application. If you believe such information has been transmitted to us, please notify us so we can delete it.

14. Confidentiality incidents

In case of a confidentiality incident presenting a risk of serious harm, we take reasonable measures to reduce its consequences and prevent its recurrence, keep an incident register and issue the required notices to the people concerned and to the Commission d'accès à l'information, in accordance with Law 25.

15. Changes to this policy

We may modify this policy from time to time to reflect the evolution of the Service or of our legal obligations. The version in force is the one published on this page, with its update date. In case of an important change, we take reasonable means to inform you.

16. Contact details and complaints

For any question, concern or complaint about this policy or the processing of your personal information, contact our person in charge at allo@consorm.ca. We commit to handling your request diligently.

If you believe your request has not been handled satisfactorily, you can file a complaint with the Commission d'accès à l'information du Québec (cai.gouv.qc.ca).