Skip to main content
Effective Date: 2026-08-06
Last Updated: 2026-08-06

Purpose of This Page

Quebec’s Act Respecting the Protection of Personal Information in the Private Sector (Bill 25) requires businesses to publish, in simple and clear terms, information about the policies and practices they have adopted to govern personal information. This page is that summary for Dimedove Technologies Inc. (“Dimedove”). It summarizes how we govern personal information across its lifecycle: collection, use, retention, destruction, security, incidents, and complaints. It complements, and does not replace, our Privacy Policy, Terms of Service, Security Policy, and Cookie Policy.

Person in Charge of the Protection of Personal Information

Bill 25 requires every business to designate a person in charge of the protection of personal information (privacy officer). Privacy Officer: Felix Simard, CEO Dimedove Technologies Inc. Email: security@dimedove.com The Privacy Officer is responsible for ensuring compliance with applicable privacy laws, approving governance rules, overseeing Privacy Impact Assessments, managing confidentiality incidents, and handling privacy complaints and requests.

What We Collect and Why

We collect personal information only for the purposes described in our Privacy Policy, which include operating our AI agent platform, managing customer accounts and billing, securing the Services, and complying with legal obligations. The categories of information we collect, the purposes for each, and the parties it may be shared with are described in Sections 3 through 5 of the Privacy Policy. When we process personal information from AI agent conversations on a business customer’s behalf, that business customer determines the purposes of the processing and we act as its service provider. The roles are explained in Section 13.3 of the Privacy Policy.

Retention and Destruction

We keep personal information only as long as necessary for the purposes it was collected for, or as required by law. Our specific retention periods are published in Section 6.2 of the Privacy Policy. In summary:
  • Account and transaction records are kept for the duration of the business relationship and up to 7 years afterward for legal and tax purposes
  • Conversation data is kept for the duration of the business relationship
  • Usage analytics and support communications are kept for up to 3 years
  • Security logs are kept for up to 2 years
When a retention period expires, personal information is securely deleted or destroyed, or anonymized in accordance with recognized best practices. Individuals and business customers may also request deletion earlier, as described in Section 8 of the Privacy Policy.

Security Measures

We protect personal information with technical and organizational safeguards, including encryption of personal information in transit and at rest using commercially reasonable, industry-standard controls, role-based access controls with the principle of least privilege, multi-factor authentication, network monitoring, and logging of access to production systems. Staff receive security awareness training, and access to personal information is limited to personnel who need it for their role. Our security practices are described in detail in the Security Policy.

Privacy Impact Assessments

We conduct Privacy Impact Assessments (PIAs) for projects involving the collection, use, communication, or cross-border transfer of personal information, including transfers to service providers outside Quebec. We may provide appropriate information or summaries concerning relevant PIAs to regulators, business customers, or other appropriate parties where appropriate, subject to confidentiality, privilege, security considerations, and applicable law.

Confidentiality Incidents

We maintain a register of confidentiality incidents involving personal information, as required by Bill 25. If an incident presents a real risk of serious harm, we notify the Commission d’acces a l’information du Quebec and affected individuals with diligence and within the time required by applicable law, and we take reasonable measures to reduce the risk of harm and prevent recurrence. Our incident response process is described in the Security Policy.

Complaints Process

Anyone may file a complaint about how we handle personal information.
  1. Submit the complaint to our Privacy Officer at security@dimedove.com (or legal@dimedove.com), describing the concern and, where relevant, the personal information involved.
  2. Acknowledgement: we acknowledge receipt of the complaint promptly.
  3. Review: the Privacy Officer reviews the complaint, may request additional information to verify identity or clarify the concern, and investigates.
  4. Response: we respond in writing within the timeframes required by applicable law, explaining our conclusions and any corrective measures taken.
If you are not satisfied with our response, you may contact the Commission d’acces a l’information du Quebec or the privacy regulator in your jurisdiction.

Your Rights

Individuals may request access to their personal information, correction of inaccurate information, deletion, cessation of dissemination, and the other rights described in Sections 8 and 12 of the Privacy Policy. Requests may be sent to the Privacy Officer at the contact details above, and we respond within the timeframes required by applicable law.

Review of These Rules

Our governance rules and this summary are reviewed and updated when our practices, technology, or legal obligations change. Material changes are communicated as described in Section 14 of the Privacy Policy.

Contact

Privacy Officer: Felix Simard, CEO
Email: security@dimedove.com
Support: support@dimedove.com
Legal: legal@dimedove.com
Dimedove Technologies Inc. 4 Pl. Ville-Marie #300 Montréal, QC H3B 2E7 Canada