Privacy Policy
Last updated: July 25, 2026. Version: 2026-07-25-v1.56.1.
Plain English summary: Bridge To AI uses your intake answers to prepare your private AI opportunity report and related service materials. This first intake is designed for directional business information, not private financials, recipes, customer lists, supplier contracts, payroll details, invoices, or confidential operating data. Intake records are encrypted before storage, email is notification-only by default, and your browser stores only a session reference. Where practical, identifying details may be tokenized before AI processing. Partner organizations may receive anonymized aggregate insights only, not raw member interviews or individual answers.
1. Who We Are And Who Is Accountable
This policy applies to the Bridge To AI intake interview and related report-generation process operated by Bridge To AI / Kandar Consulting in Alberta, Canada.
Privacy Officer: Darren Randles, Bridge To AI / Kandar Consulting. Privacy requests, questions, or complaints can be sent to team@bridgetoai.ca.
2. Scope Of This Policy
This policy covers the first-stage directional intake, private AI opportunity report generation, secure storage, administrative retrieval, and anonymized aggregate partner reporting connected to the intake.
Deeper implementation work, paid scoping, custom workbench builds, file uploads, financial review, supplier/customer analysis, grant paperwork, invoice/PO review, or other sensitive operational work require a separate agreement and separate consent for that more detailed data handling.
3. Information We Collect
We may collect information you provide before and during the intake, including:
- your name and email address;
- business name, website, industry category, niche, role, team size, and department/function information;
- your comfort level for sharing detail in this first intake;
- directional answers about business model, customers, sales, operations, systems, risks, AI readiness, and desired support;
- voice and tone examples based on a short business scenario;
- technical records needed to save, resume, process, secure, troubleshoot, and verify the intake.
We do not ask for passwords, banking credentials, payment card numbers, private government IDs, private financial records, recipes, supplier contracts, payroll details, invoices, customer lists, or confidential formulas in this first intake.
4. How We Use Your Information
We use your information to:
- save and resume your intake session;
- generate private AI opportunity reports, advisor notes, and preliminary action recommendations;
- send report links, status notices, or service-related follow-up;
- record whether you asked Bridge To AI to follow up, maybe follow up later, or only send the free report;
- identify practical AI opportunities, readiness gaps, and risks for your business;
- maintain system reliability, security, data integrity, and troubleshooting records;
- create anonymized aggregate insights for approved partner programs.
We do not sell your interview answers, publish your raw interview record, or use your raw interview answers for unrelated marketing.
5. Partner Programs And Aggregate Reporting
Some intake links may be offered through a partner organization, such as an association, training provider, or member program. In those cases, Bridge To AI may share anonymized and aggregated insights with the partner to help with education, course planning, member-support strategy, and program improvement.
Partner aggregate reports may include trends such as completion rates, readiness patterns, common AI education needs, sector-level pain points, adoption barriers, broad opportunity categories, and preferred support areas. They do not include raw interview files, individual member answers, direct contact details, or named business records unless you separately agree.
To reduce re-identification risk in small groups, Bridge To AI will avoid reporting a partner segment or category where the group is too small to reasonably protect member identity. As a working standard, segment-level trends should generally require at least five participating businesses before being shared with a partner.
6. Encryption And Secure Storage
Your intake answers are processed through secure server-side systems and stored in encrypted form. Bridge To AI uses application-level encryption before storing sensitive intake content in Supabase. Supabase also provides platform security for data at rest and in transit.
The browser is not intended to store your full raw intake. It stores only what is needed to identify or resume the secure session.
7. Pseudonymization / Tokenization For AI Processing
When your answers are processed by AI, Bridge To AI uses a secure processing layer to reduce unnecessary exposure of identifying details where practical.
The secure processing layer may replace identifying information such as names, emails, phone numbers, websites, and similar details with placeholders before AI analysis. If the placeholders need to be restored so the correct report can be delivered, the re-identification map is kept separately and encrypted.
Because this process can be reversible when a re-identification map exists, it is more accurately described as pseudonymization or tokenization, not permanent anonymization. Anonymized aggregate reporting is used for partner-level insights where raw identities and re-identification maps are not shared with the partner.
Pseudonymization reduces exposure, but it may not remove every possible business-identifying detail, especially if you provide highly specific or recognizable business information.
8. Human Access
Bridge To AI does not casually review raw interview records. A Bridge To AI team member may access the raw intake record only when needed to:
- deliver the requested service;
- prepare, verify, or improve client reports and recommendations;
- recover a failed submission;
- investigate a technical, security, or data integrity issue;
- respond to a lawful request or required compliance obligation.
9. Service Providers And Cross-Border Processing
Bridge To AI uses trusted third-party platforms to operate the intake system:
- Vercel hosts the intake application and server-side API processing.
- Supabase stores encrypted intake sessions, outputs, logs, and related records.
- Resend sends notification emails and report-related email communication.
- Selected AI providers, such as Anthropic/Claude and other approved AI services, process minimized or tokenized prompts to generate reports and recommendations.
- GitHub stores and manages application source code. GitHub is not intended to store client interview records.
- BTAI secure processing layer supports privacy, logging, minimization, validation, and workflow-control functions.
These providers may process data only as needed to provide their services to Bridge To AI, subject to their own terms, privacy policies, security practices, and data processing agreements.
Some providers may process or store information in Canada, the United States, or other jurisdictions where they or their subprocessors operate. While information is in another jurisdiction, it may be subject to the laws of that jurisdiction, including lawful access by courts, law enforcement, or national security authorities.
Bridge To AI remains accountable for personal information under its control and uses contractual, technical, and organizational measures intended to provide a comparable level of protection while service providers process information for Bridge To AI.
10. AI Provider Data Use
Bridge To AI uses AI provider API services for report generation, adaptive follow-up support, and related processing. We do not intentionally submit intake data to consumer chat products for public model training. AI providers process submitted data according to their API terms, privacy policies, and data processing practices. Bridge To AI's intent is to use provider settings and API services that do not use customer-submitted API data to train public models by default, where available.
11. Email And Report Delivery
By providing your email address, you allow Bridge To AI to send you report links, status notices, and service-related follow-up. Raw interview files are not emailed by default. Email is primarily used for notifications and secure delivery links.
12. Data Retention And Deletion
Bridge To AI keeps personal information only as long as reasonably needed for the purposes described in this policy, unless a longer period is required or permitted by law.
- Incomplete intake drafts are normally deleted or made inaccessible after 30 days of inactivity.
- Completed first-stage intake records are normally retained for up to 12 months after report delivery to support retrieval, correction, follow-up, quality review, and service continuity.
- Records connected to a paid engagement may be retained under the separate agreement for that engagement.
- Security, audit, and KPI logs may be retained longer where they do not contain raw answer text or are needed for security, compliance, troubleshooting, or aggregate reporting.
- Anonymized aggregate insights may be retained for trend analysis, education planning, and service improvement.
You may request deletion of your personal information by contacting Bridge To AI. Some information may be retained where needed for legal obligations, dispute resolution, security, backups, or legitimate business records.
13. Access, Correction, Deletion, And Complaints
You may request access to personal information Bridge To AI holds about you, ask for a correction, request deletion where appropriate, or ask questions about how your information has been used or disclosed.
To make a request, contact team@bridgetoai.ca with the subject line "Privacy Request." Bridge To AI will aim to respond within 30 days. If more time is needed, we will explain why.
If you believe Bridge To AI has not addressed your privacy concern, you may contact the Office of the Privacy Commissioner of Canada at priv.gc.ca.
14. Incident And Breach Response
If Bridge To AI becomes aware of a privacy or security incident involving personal information, we will investigate and take steps to contain, assess, and remediate the issue. Where required by Canadian privacy law, Bridge To AI will notify affected individuals and the Office of the Privacy Commissioner of Canada of any breach that creates a real risk of significant harm.
15. Cookies, Analytics, And Tracking
The intake currently uses local browser storage only to keep a secure session reference for save/resume. It is not intended to store the full raw intake in your browser. If Bridge To AI adds analytics, cookies, pixels, or similar tracking tools in the future, this policy will be updated to describe what is used and why.
16. Age And Intended Users
The intake is intended for business users who are at or above the age of majority in their province, territory, state, or country. It is not directed to children.
17. Security Limits
No internet-based system can be guaranteed 100% secure. Bridge To AI uses reasonable technical and organizational safeguards, including encryption, access control, tokenization where practical, secure server-side processing, minimized email exposure, and data integrity checks.
18. Changes To This Policy
Bridge To AI may update this policy as the service, technology, legal requirements, or provider stack changes. The version shown at the top of this page identifies the policy version used for consent records. If we make material changes, we will provide notice through the intake site, by email where appropriate, or through another reasonable method before the new version applies to future intake submissions.