DocGlance Privacy Policy

Effective date: October 6, 2026

DocGlance Software Inc., a Saskatchewan corporation, registered office NW 23-06-11-W2, RM of Cymri No. 36, Midale, Saskatchewan S0C 1S0; mailing address Box 455, Midale, SK S0C 1S0


1. Introduction

This Privacy Policy explains how DocGlance ("DocGlance," "we," "us," or "our") collects, uses, discloses, and protects information in connection with the DocGlance platform, a multi-tenant software-as-a-service document management product supporting a range of use cases — including tracking document expiration and renewal dates, and, as one common use case among others, helping an organization collect and manage documents from its own vendors — (docglance.com and any related applications, the "Service").

DocGlance is operated by DocGlance Software Inc., a corporation incorporated under the laws of the Province of Saskatchewan, Canada, with its registered office at NW 23-06-11-W2, RM of Cymri No. 36, Midale, Saskatchewan S0C 1S0 (mailing address: Box 455, Midale, SK S0C 1S0).

This Policy applies to two distinct groups of people whose information the Service handles, and it is written to explain how each is treated:

If you are a Vendor invited onto DocGlance by one of our Customers, please also see Section 2 ("Two roles DocGlance plays") and Section 8 below, which explain who actually controls the information you submit and who to contact about it.

By using the Service, you agree to the practices described in this Policy. If you do not agree, please do not use the Service.


2. Two roles DocGlance plays: when we're the decision-maker, and when we're not

This is the single most important thing to understand about how DocGlance handles personal information, and it comes directly from how the product works: a Customer decides what documents it needs from its Vendors; a Vendor uploads those documents; DocGlance stores, organizes, and extracts metadata from them.

a) Where DocGlance is the controller (decision-maker) of personal information. For information we collect directly to run our own business relationship with a Customer or Vendor — account registration details, login credentials, billing information, support communications, product analytics, and similar account/administrative data — DocGlance decides why and how that information is used. We are directly accountable for this data under Canadian privacy law, in the same way any ordinary online service is accountable for its own users' account data.

b) Where DocGlance acts on a Customer's instructions (as a service provider / processor) for the content of uploaded documents. The actual documents a Vendor uploads — insurance certificates, licenses, tax forms, security evidence, and the personal information they may contain about Vendor employees or other individuals (e.g., a named individual's role, signature, certification number, or, depending on the document type, a Social Insurance Number or business number) — are not information DocGlance decided to collect for its own purposes. DocGlance processes that content on behalf of, and under the direction of, the Customer that required the document, in order to provide the Service the Customer subscribed to (storage, metadata extraction, expiration tracking, renewal reminders). In this role, DocGlance is best understood as a service provider processing data under the Customer's instructions, not as the party that decides why that information is collected in the first place — the Customer does.

What this means in practice:


3. Information we collect

3.1 Information Customers provide directly

3.2 Information Vendors provide directly

3.3 Information collected automatically

3.4 Information from third parties

3.5 Special categories of information

Because uploaded documents can include tax forms, licenses, insurance certificates, and security evidence, they may incidentally contain sensitive personal information about individuals other than the Vendor account holder — for example, a Social Insurance Number, a business registration/tax number, or a named individual's professional certification details. DocGlance does not request or require any particular category of sensitive information; what appears in a document is determined entirely by the Customer's own document requirements and what the Vendor chooses to upload in response. See Section 2(b) — this content is handled as Customer-controlled data, and Customers are responsible for ensuring their own document requirements and vendor instructions are lawful and appropriate for the personal information they solicit.

Because the Service is open to personal as well as business use, documents uploaded by an individual can also contain more sensitive personal information than a typical vendor document — for example a government-issued ID, a passport or driver's licence, or a health, insurance, or financial record. We treat all uploaded content as confidential regardless of type, and apply the same safeguards to it (Section 11); PIPEDA scales what counts as appropriate protection to the sensitivity of the information, so this widens what "appropriate" has to cover. Please consider whether the Service is the right place to store particularly sensitive records before uploading them.


4. How we use information

We use the information described above to:

We do not sell personal information, and we do not share the content of your documents with any other Customer. We do improve the Service's document recognition over time using non-identifying information about document types and field structures — never the substantive content of your documents (see Section 5).


5. AI-assisted document processing

A core part of the Service uses AI to extract metadata from uploaded documents (document type, parties, dates, identifiers) so Customers and Vendors do not have to enter it manually. We currently use OpenAI for this processing, and we may add or change AI providers, including Anthropic (Claude) and Google (Gemini) as fallback or replacement providers. The providers we use are listed in Section 6.2.


6. How information is shared

We do not sell personal information. We share information only as described below.

6.1 Within the Service, between a Customer and its Vendors

By design, a Customer sees the documents and metadata its own Vendors submit in response to that Customer's requirements. A Vendor's information is not visible to any other Customer; each Customer's data is separated from every other Customer's within the Service.

6.2 Service providers we use to run DocGlance

ProviderPurposeLocationData involved
CreemMerchant of record / payment processingTallinn, EstoniaBilling/payment information; Creem is the merchant of record and is the party a Customer's payment appears against on their statement (see Section 6.4 for what this means)
SupabaseDatabase, authentication, file storageUnited States (US East) — Customer data is stored in the United States, not CanadaAccount data, organization/vendor/document records, uploaded document files
CloudflareApplication hosting (Workers)See the provider's privacy termsApplication traffic; no independent copy of document content beyond ordinary request handling
OpenAI (currently); Anthropic (Claude) and Google (Gemini) (may be added as fallback or replacement providers)AI-assisted document metadata extractionSee each provider's privacy termsDocument content submitted for extraction (see Section 5)
ResendTransactional email (reminders, notifications)See the provider's privacy termsRecipient email address and message content needed to send the notification
SentryError monitoring / observabilitySee the provider's privacy termsTechnical and error data. We aim to keep personal information and document content out of error reports where feasible, but we cannot guarantee that no personal information will ever appear in one
Google (sign-in)"Sign in with Google" for organization usersGoogle's own infrastructure (United States and elsewhere)Name and email address of the person signing in; Google acts as an independent controller of that sign-in under its own terms and privacy policy, and we never receive your Google password (Section 3.1)
Google Analytics (GA4)Traffic measurement on the docglance.com marketing site (Section 9)Google's own infrastructure (United States and elsewhere)Site-usage data from marketing-site visitors (such as pages viewed, device and browser information, and approximate location), processed by Google under its own terms and privacy policy
GitHubSource-code hosting and automated build/test (private repository)United StatesSource code only; no Customer documents or Customer personal information are intended to be stored there
Domain registrar, DNS, and business-email providersdocglance.com domain registration and DNS, and the mailboxes behind our public contact addresses (e.g., support@docglance.com)See each provider's privacy termsContents and sender details of emails you send us; domain contact details
Metabase (internal, self-hosted)Internal analytics dashboards used by DocGlance staff onlyA computer on DocGlance's own network in Saskatchewan, CanadaUsage and business metrics used by DocGlance staff

We select reputable providers and generally rely on each provider's published security and data-processing terms rather than separately negotiated contracts. We review each provider's terms, region and settings from time to time. We do not represent that any provider is contractually bound to use information only for services to us beyond what its own published terms provide.

6.3 Cross-border transfers

Because DocGlance is based in Saskatchewan, Canada, but uses service providers located outside Canada — notably Creem (Estonia) and one or more AI and infrastructure providers that may process data in the United States or elsewhere — personal information may be transferred to, stored in, and processed in countries other than the country where you are located. In particular, our primary database and uploaded-document storage (Supabase) are hosted in the United States (US East), so Customer data, including uploaded documents, is stored and processed in the United States, including countries that may have different data protection laws than your own.

Where we transfer personal information outside Canada, we rely on the security and data-protection terms of our providers' published agreements and take steps intended to ensure that it continues to be protected in a manner consistent with this Policy and applicable Canadian privacy law (PIPEDA does not prohibit cross-border transfers outright, but requires organizations to use contractual or other means to provide a comparable level of protection while the information is being processed by a third party — see Section 11). Information held in another country is subject to the laws of that country and may be accessible to its courts, law enforcement, or national security authorities.

6.4 Payment processing disclosure (Creem)

DocGlance uses Creem (creem.io), based in Tallinn, Estonia, as its merchant of record for payment processing. Under this arrangement, a Customer's purchase is structured as a transaction with Creem directly — Creem's name appears on the Customer's payment statement, Creem issues the customer-facing invoice, and Creem is the party responsible for payment-related compliance (e.g., card processing, chargebacks). Creem then remits payment to DocGlance. Payment card details are collected and held by Creem, not DocGlance, under Creem's own privacy policy, which we encourage Customers to review at creem.io/privacy.

6.5 Legal disclosures

We may disclose information where required to comply with applicable law, regulation, legal process, or governmental request; to protect the rights, property, or safety of DocGlance, our Customers, Vendors, or others; or in connection with a merger, acquisition, financing, or sale of assets.


7. Data retention

Account, organization, and document data is retained for 90 days after a Customer's account is cancelled or closed, then deleted (subject to the legally-mandated exceptions below; this matches Terms of Service §14.2), with export available to the Customer on request during that window. If database backups exist at the time, deleted data may persist in them for up to a further 30 days at most before being permanently purged (Terms of Service §14.3); at launch we run on a database plan that does not include scheduled backups. Billing and transaction records DocGlance itself holds (invoices, payout reports, and related bookkeeping) are not covered by the 90-day window: they are kept for 7 years from the end of the tax year to which they relate, to meet tax record-keeping duties.

Deleting an individual document while an account is active. Deleting a document in the Service is a "soft delete": the document is hidden from the Service's views but is not immediately erased, and DocGlance operators (not users) can restore it on request during that time. A deleted document is permanently removed 30 days after it was deleted; until then it is stored like any other Content.

Audit events and logs.

Earlier versions of a document that has been replaced are kept while the account is active and are deleted with the account's other data. Requests to delete information relating to a Vendor user are handled through the process in Section 8.


8. Your rights and choices

Depending on your role (Customer or Vendor) and location, you may have rights to access, correct, or request deletion of your personal information, and to withdraw consent for certain uses, subject to legal and contractual limitations.

Requests are handled by DocGlance's Privacy Officer (Section 11). We aim to acknowledge a request within 5 business days and will respond to a verified request within 30 days of receiving it. If we need more time, as PIPEDA allows in limited cases, we will tell you in writing before the 30 days end, with our reasons and your right to complain to the Office of the Privacy Commissioner of Canada. If your request concerns the content of a document a Customer collected, we aim to forward it to that Customer within 5 business days and tell you we have done so (Section 2). We may need to verify your identity first, and where we must keep a record by law (for example billing records) we will tell you what we are keeping and why.


9. Cookies and similar technologies

The Service uses two categories of cookies/similar technologies, and no third:

The marketing site does not currently show a cookie-consent banner. If we begin to market to visitors in the European Union or add advertising or retargeting cookies of any kind, we will update this section and, where required, ask for your consent first.


10. Children's information

The Service is not directed to, and we do not knowingly collect personal information from, children. If we become aware that we have collected personal information from a child without appropriate consent, we will take steps to delete it.

The Service is not intended for use by anyone under the age of 18, or under the age of majority where they live if that is higher. This matches Terms of Service §4. Eighteen is the age of majority in Saskatchewan (The Age of Majority Act); some other provinces set it at 19, which is why this statement also defers to the law where you live when that age is higher.


11. Our legal basis and framework: PIPEDA

DocGlance is based in Saskatchewan, Canada. Saskatchewan does not have its own private-sector privacy statute; only Alberta, British Columbia, and Quebec currently have private-sector privacy laws recognized by the federal government as "substantially similar" to the federal law, which exempts organizations in those provinces from PIPEDA for information handled within that province. Saskatchewan is not among them, so the federal Personal Information Protection and Electronic Documents Act (PIPEDA) governs how DocGlance collects, uses, and discloses personal information in the course of its commercial activities.

PIPEDA is built around 10 fair information principles, which this Policy is organized to reflect: accountability, identifying purposes, consent, limiting collection, limiting use/disclosure/retention, accuracy, safeguards, openness, individual access, and challenging compliance.

Accountability. DocGlance is responsible for personal information under its control. DocGlance's designated Privacy Officer is Anthony Thompson, CEO and sole director of DocGlance Software Inc., reachable at support@docglance.com; he is also DocGlance's security contact, and security vulnerabilities or suspected security incidents can be reported to security@docglance.com. No deputy or delegate is named. Requests and complaints are handled by the Privacy Officer; see Sections 8 and 12 for how to make one and the timelines. This is also the designated privacy officer required under Quebec's Law 25 for any Quebec-based Customer or Vendor user — see Section 11.1 below.

Breach notification. Personal information DocGlance controls (account, billing, and usage data — Section 2(a)): if DocGlance experiences a breach of security safeguards involving that information that creates a real risk of significant harm to an individual, DocGlance will notify the affected individual(s) and report the breach to the Office of the Privacy Commissioner of Canada, as required by PIPEDA's mandatory breach reporting requirements (in effect since November 1, 2018). Customer-uploaded document content (Section 2(b)): DocGlance handles this as a service provider on the Customer's instructions, so if a breach of security safeguards affects it, DocGlance will notify the affected Customer's account administrators without undue delay after becoming aware of it, with what happened, what information was involved, and what DocGlance is doing, and will cooperate with the Customer. The Customer, as the organization in control of that information, decides on and performs any report to the Office of the Privacy Commissioner of Canada and any notification of affected individuals. Where the Customer cannot be reached, DocGlance may make that report and notify individuals itself if DocGlance determines a real risk of significant harm exists. DocGlance will also keep a record of every breach of security safeguards it becomes aware of, regardless of whether it meets the "real risk of significant harm" threshold, for at least 24 months, as PIPEDA requires. Other laws (for example Quebec's, Section 11.1) can add reporting duties and deadlines. The matching Customer-notice commitment is in Terms of Service §13.

11.1 Quebec's Law 25

If you are located in Quebec, Quebec's Act respecting the protection of personal information in the private sector ("Law 25") may apply to your personal information in addition to PIPEDA. Law 25 requires, among other things, a designated person responsible for the protection of personal information (DocGlance's is the Privacy Officer named in Section 11 above), specific consent in certain cases, and its own breach-reporting obligation to Quebec's data protection authority, the Commission d'accès à l'information (CAI), in addition to the federal reporting described above. DocGlance is not marketed to Quebec; if you are in Quebec and use the Service, please contact us (Section 12) with any question about how Law 25 applies to your information, and note that you may complain to the CAI (Section 12).

11.2 CASL — Canada's Anti-Spam Law

Canada's anti-spam law (CASL) governs every "commercial electronic message" (an email, text, or similar message that has encouraging participation in a commercial activity as one of its purposes) sent to a recipient with a computer system located in Canada. We send commercial electronic messages only with consent — either your express consent or implied consent where CASL permits it — and each such message identifies DocGlance, includes our mailing address and a way to contact us, and includes a working unsubscribe mechanism that we honour within 10 business days. Marketing communications (opt-in, unsubscribable) are kept separate from transactional communications (renewal reminders, billing and security notices), as described in Sections 4 and 8.


12. Contact us

If you have questions about this Policy or wish to exercise a right described above, contact us at:

support@docglance.com

Security and vulnerability reports: security@docglance.com (read by Anthony Thompson, DocGlance's Privacy Officer and security contact — Section 11).

Mailing address: Box 455, Midale, SK S0C 1S0.

Complaints. You can complain to us about how we handle personal information. We aim to acknowledge a complaint within 5 business days and to reply in writing within 30 days with the outcome and any change we are making.

If you are not satisfied with our response, you have the right to file a complaint with the Office of the Privacy Commissioner of Canada: https://www.priv.gc.ca — and, if you are located in Quebec, with Quebec's Commission d'accès à l'information (see Section 11.1). You may do so at any time, and our replies will remind you of this right.


13. If DocGlance has customers or vendors located outside Canada

DocGlance is not currently marketed or sold outside Canada. If that changes, other privacy laws may apply to our handling of your personal information, and we will update this Policy to reflect them.

13.1 European Union — GDPR

The EU's General Data Protection Regulation can apply to an organization outside the EU, such as DocGlance, if it offers goods or services to individuals in the EU or monitors the behaviour of individuals in the EU. If GDPR applies to our processing of your personal information, we will update this Policy to describe the lawful bases for our processing, the additional rights you have (including erasure and data portability), and the mechanism we rely on for transferring your personal information outside the EU.

13.2 United States — California (CCPA/CPRA) and other state laws

California's Consumer Privacy Act (as amended by the CPRA), and similar laws in a number of other U.S. states, apply only to businesses that meet certain size or data-volume thresholds. We do not currently believe DocGlance meets those thresholds, and we do not sell personal information. If that changes, we will update this Policy and provide the rights those laws require.


14. Changes to this Policy

We may update this Policy from time to time by posting the updated Policy with a new effective date. For a material change, we will post the updated Policy at least 30 days before the change takes effect (consistent with Terms of Service §25's Terms-change notice period), and may also notify account administrators by email. A change required to reflect a change in applicable law or to address an imminent security risk may take effect on shorter notice.