Introduction
The Same Page Solutions Inc. ("TSP", "we", "us") is committed to operationalizing workplace inclusion with a strict "Privacy-First" and "Privacy by Design" architecture. We understand that our platform handles sensitive conversations about health, neurodiversity, and workplace needs.
This Privacy Policy applies to our platform (AdaptAbility), our AI agent (Your Digital Advocate), and our consulting services. We comply with:
- Canada: The Personal Information Protection and Electronic Documents Act (PIPEDA) and Law 25 (Quebec).
- United Kingdom: The UK General Data Protection Regulation (UK-GDPR) and the Data Protection Act 2018.
Data Residency & Sovereignty
Plain English: Your data lives in a highly secure, encrypted vault in Canada.
- Primary Storage: All data is encrypted at rest and stored exclusively in Canada (AWS ca-central-1 region), ensuring strict compliance with Canadian data residency and PIPEDA requirements.
- UK Transfers: For UK customers, data is processed in accordance with the UK-Canada "Adequacy Decision," ensuring Canadian privacy standards are recognized as sufficient for UK-GDPR compliance.
Cookies & Session Management
Plain English: We only use the essential background technology needed to keep you securely logged in. We do not use tracking cookies to follow you around the internet.
AdaptAbility only uses "Strictly Necessary" functional cookies and secure local storage tokens. These are required to authenticate your login session, maintain the state of the Digital Advocate, and ensure platform security. We do not use third-party marketing, advertising, or cross-site tracking cookies.
The Data We Collect & Our Legal Basis
Plain English: We separate your business login info from your private health chats. We never sell your data, and we don't use it for marketing.
Under UK-GDPR and PIPEDA, we must establish a "Legal Basis" for processing your data. We distinguish between three types of data:
Account Data (Business Information)
- Who: Employers and Authorized Users.
- What: Name, business email, job title, department, and login credentials.
- Legal Basis: Performance of a Contract. We need this data to provide the service your employer purchased.
- The Pseudonymization Layer: To protect your identity, every employee is assigned a unique, 8-character pseudonym. The AI never knows your real name or email.
Advocacy Data (Sensitive Information)
- Who: Individual Employees (Members).
- What: Chat logs with the Digital Advocate, self-disclosed health information, and drafted accommodation requests.
- Legal Basis: Explicit Consent. Because this involves special category health data, we only process it with your direct consent.
- Strict Limit: We strictly do not use this data for advertising or marketing.
Telemetry and Feedback Data (System Health)
- Legal Basis: Legitimate Interest. To keep the platform secure and functional.
- Protection: Passive error logs are completely stripped of Personally Identifiable Information (PII). If you report a bug, we explicitly sever the relational link between you and your feedback using a salted, one-way cryptographic hash (SHA-256) of your user ID, ensuring total anonymity.
How We Use Artificial Intelligence (AI)
Plain English: We use AI to help you, not to learn from you. Your private chats are never used to train the public AI models. We use strict math rules to ensure your employer can never guess who you are from our anonymous reports.
We use Generative AI to power our platform. To maintain your trust, we adhere to the following:
- Zero-Day Retention (No-Training Promise): Your data is NEVER used to train the public models of our AI providers. AWS Bedrock "Model Invocation Logging" is strictly disabled.
- RAG Architecture: We use Retrieval-Augmented Generation (RAG) to ground the AI's answers in verified legislation (e.g., Equality Act 2010, Accessible Canada Act) rather than learning from your personal story.
- Low Volume Suppression (The Rule of 7): When providing anonymous, aggregated insights to Employers, we use a strict privacy lock. It requires a minimum of 7 active users within a company or department before rendering data, mathematically preventing HR from reverse-engineering individual identities.
The Digital Advocate does not engage in automated decision-making or profiling. It provides information, drafting assistance, and recommendations, but all final decisions regarding accommodations are made by human HR administrators.
Data Sharing & The "Privacy Firewall"
Plain English: You control what your boss sees. They cannot view your private brainstorming. If you are in severe distress, we have a safety protocol to get you human help.
We act as a "Privacy Firewall" between the Employee and the Employer.
- You (The User): See your full chat history and drafted documents.
- Your Employer: Sees nothing by default. They only see specific Accommodation Requests after you explicitly submit them. Once submitted, that document becomes part of the employer's official HR records.
- Safeguarding & The "Break Glass" Protocol: Our system monitors conversations for crisis keywords on a 0-10 distress scale. If language indicates an immediate risk of harm (Levels 9-10), the AI intercepts the conversation. A trained Admin may execute a secure "Break Glass" protocol to reveal your pseudonymized details and escalate the situation to HR or emergency services. This triggers an immutable Privacy Audit Log.
- Translation Firewall: If you brainstorm with the Digital Advocate in a language other than English or French, the AI will translate the professional meaning of your request for your employer, ensuring your raw, native-language notes remain entirely private.
- Service Providers: We use trusted Sub-Processors, including Amazon Web Services (AWS) for cloud hosting/storage and Anthropic (via AWS Bedrock) for AI inference.
Data Retention & Deletion
Plain English: We don't keep your data forever. If you delete your account, or if your company stops using our software, we wipe your records from our systems.
- Active Users: We retain your Advocacy Data only as long as you maintain an active account to provide you with ongoing support.
- Account Deletion: If you choose to delete your account, we implement a 30-day "soft delete" grace period, after which an automated job permanently hard-deletes your data.
- Employer Offboarding: If your employer terminates their contract with us, all associated employee Sandbox data is scheduled for secure deletion in accordance with our overarching data retention schedules.
- Volatile Document Uploads: Any personal documents you upload into the Discovery Space for AI analysis are temporarily processed via secure AWS S3 buckets and immediately destroyed from our servers when your session ends. They are never saved to our long-term relational databases.
Your Rights
Plain English: You own your data. You can ask to see it, change it, or have us delete it completely. You also have the right to complain if you think we are doing a bad job.
Under PIPEDA and UK-GDPR, you have the following rights:
- Right to Access & Correction: You may request a copy of your personal data or update inaccurate information.
- Right to Erasure ("Right to be Forgotten"): You may ask us to permanently delete your account and chat history.
- Right to Withdraw Consent: You can stop using the platform at any time.
- Right to Complain: If you reside in the UK, you have the right to lodge a complaint with the Information Commissioner's Office (ICO). If you reside in Canada, you may contact the Office of the Privacy Commissioner (OPC).
We will acknowledge and respond to all data rights requests within 30 days, free of charge.
Security Measures & Breach Notification
Plain English: We use high-level security to protect your chats. If a hacker ever did manage to break in, we would tell you immediately.
- Encryption: AES-256 encryption for data at rest and TLS 1.3 for data in transit. Documents are accessed strictly via short-lived AWS presigned URLs; we never store PII on local filesystems.
- Access Control: Every high-privilege administrative action is recorded in an immutable dual-table Audit Log.
- Breach Notification: In the unlikely event of a security breach that poses a real risk of significant harm, we will notify you and the relevant regulatory authorities without undue delay, as required by law.
- Internal Access (RBAC): We employ strict Role-Based Access Control. Only the Privacy Officer and designated Senior Engineers have access to production environments for debugging, and every high-privilege action is logged. Customer Service teams or Sales teams cannot view your unencrypted Advocacy Data.
Children's Privacy
AdaptAbility is a professional workplace tool. You must be at least 18 years old to create an account and use the Service. We do not knowingly collect personal information from individuals under the age of 18.
Changes to this Policy
We may update this Privacy Policy from time to time to reflect changes in our technology or legal requirements. If we make material changes, we will notify you by email or through a prominent notice on your platform dashboard before the changes take effect.
Contact Us
If you have questions about this policy or wish to exercise your data rights, please contact our Privacy Officer/Data Protection Officer:
Privacy Officer: Mike Clarke
Email: mike@samepagesolutions.ca
Address: 111, Peter Street, Suite 902, Toronto, Canada, ON M5V 2H1