Privacy Policy

Last updated: August 10, 2026

This Privacy Policy explains how SYSMOTIX ('we', 'our', or 'us') collects, uses, discloses, and protects personal information in the course of its activities, in accordance with applicable laws in Quebec, including Law 25.

By using our website, our forms, our automation solutions, or by communicating with us, you agree that your personal information will be treated in accordance with this policy.

Who are we?

SYSMOTIX is a company located in Quebec, Canada, that helps SMEs optimize their operations through automation solutions, web development, and intelligent integrations (chatbots, voice bots, CRM, automated flows, etc.).

This policy applies to all our activities in Quebec and elsewhere, to the extent required by applicable laws.

Scope of the Policy

This Privacy Policy applies to personal information that we collect:

  • via our website (including contact and demo request forms);
  • via our exchanges by email, telephone, SMS, instant messaging (e.g., Slack);
  • via our automation, web development, CRM, and integration solutions that we implement for our clients;
  • via our prospecting, marketing, and customer service activities.

It does not apply to third-party sites to which our site may redirect (e.g., social networks, partner tools). We invite you to consult their own privacy policies.

What personal information do we collect?

We may collect the following categories of information, depending on the context:

Identification Information

  • First name, last name;
  • Company name;
  • Position or function within the company.

Contact Information

  • Professional email address;
  • Phone number;
  • Professional account identifiers (e.g., company name on certain tools used in the implementation).

Information related to your request or project

  • Content of forms (description of your needs, information on your internal processes, business constraints);
  • Information necessary for the configuration and integration of our solutions (e.g., opening hours, types of services, customer categories, response scripts, etc.).

Information on the use of our solutions and our site

  • IP address, browser type, pages viewed, time spent, traffic origin (via cookies and analytics tools);
  • Technical and functional logs of the systems we implement (e.g., interactions with a bot, call statistics, response rate).

Information on our clients' end users

In the context of certain mandates (for example, when a bot or system manages calls or requests from a clientele), we may process information concerning our clients' customers, such as:

  • first name, last name (if applicable);
  • contact information (email, phone);
  • content of exchanges (messages, requests, questions);
  • information necessary for follow-up (e.g., appointments, communication preferences).

When this information is considered 'personal information' within the meaning of the law, we process it in accordance with this policy and the contract binding us to the client.

Sensitive Information (special cases)

In certain sectors (health, legal, finance, etc.), exchanges may contain more sensitive information (e.g., health data, financial information, specific files).

In these contexts, we implement enhanced protection measures, and the processing of this data is always done in compliance with applicable legal and contractual requirements.

Meta Lead Ads and Facebook Login for Business integration

This section describes specifically what we do with information that comes from Meta advertising forms (Facebook and Instagram), when a business client enables this integration in our CRM.

Where this information comes from

This information comes from a Meta Lead Ads form that you voluntarily filled out on Facebook or Instagram, in response to a company's advertisement. That company is our client: it uses our CRM to receive and manage its enquiries.

  • For the integration to work, the business client must first connect its Meta portfolio and select for itself the Pages it authorizes us to use, through Facebook Login for Business.
  • We do not access any Page, advertising account or form that has not been explicitly authorized to us.
  • The business client can withdraw this authorization at any time from its Meta settings or from our CRM. Access then ends, and no new enquiry is imported.

What information is processed

Depending on how the business client has configured its form, we may process:

  • your name;
  • your email address;
  • your phone number;
  • your answers to the form's questions and custom fields, according to the configuration chosen by the business client;
  • the technical identifiers attached to your enquiry: lead, form, Page and ad identifiers;
  • the date and time of your submission;
  • the metadata needed to route your enquiry to the correct business and to attribute the campaign;
  • advertising performance data, only where that feature is enabled and authorized by the business client.

We do not request from Meta any information beyond what appears in the form you filled out, and we do not access your Facebook or Instagram profile.

What this information is used for

  • importing your enquiry into the CRM of the business concerned;
  • associating it with the correct organization, so that it is visible only to that business;
  • enabling that business to carry out the commercial follow-up you requested;
  • avoiding duplicates when the same enquiry is sent more than once by Meta;
  • ensuring the operation, reliability and security of the integration;
  • producing the advertising performance reports authorized by the business client, where applicable.

What we do not do

Information obtained through Meta is never sold, rented or traded. We do not use it to build advertising profiles for our own benefit, nor to feed other business clients, nor to send you our own commercial communications.

Who has access

Access is limited to authorized users of the business client concerned, and to SYSMOTIX personnel who need it to operate, troubleshoot or support the service. The providers actually involved in the handling of this information are:

  • Meta Platforms, the source of the form and of the enquiry;
  • Hostinger, host of the automation infrastructure we operate and on which the n8n software runs, which receives the enquiry and normalizes it;
  • Supabase, provider of the CRM database;
  • Vercel, host of the CRM application;
  • Twilio (text messages) and Resend (emails), only where the business client enables automated follow-up.

Some of these providers may be located outside Quebec or Canada. In that case, we take reasonable steps to ensure the information benefits from adequate protection, in particular through appropriate contractual agreements and, where needed, a privacy impact assessment (PIA).

How long it is kept

Information from Meta Lead Ads follows the rules described in the section "How long do we keep your information?" of this policy. It is kept for as long as the business concerned needs it to follow up on your enquiry, and is then securely destroyed or anonymized, subject to legal retention obligations. You may request its deletion at any time.

How to request deletion of your information

You may request access to your information, its correction, its deletion, or the withdrawal of your consent where processing is based on it.

A dedicated page sets out the steps to follow, the information needed to verify your identity, what will be deleted and how confirmation will be sent to you: Meta Lead Ads data deletion.

You may also write directly to support@sysmotix.com, or contact the advertising business that collected your enquiry.

The business client may also disconnect the Meta integration at any time, which ends any new import of enquiries.

We act on valid requests, except for what we must retain under a legal, accounting or tax obligation, or in order to document the deletion itself.

How this information is protected

The following measures are in place for this integration:

  • role-based access control, limiting what each user can view;
  • strict isolation of each organization's data, enforced directly at the database level, so that one business client cannot access another's data;
  • logging of activity carried out on enquiries and of communications sent;
  • verification of the cryptographic signature of data transmitted by Meta, at the entry point of our automation infrastructure;
  • encryption of communications in transit (HTTPS/TLS);
  • storage of Meta access credentials in an encrypted server-side secrets vault, never exposed in a browser or to a user.

No system is entirely free of risk. In the event of a privacy incident, we apply the procedures described in the section "Privacy Incidents".

How do we collect your information?

We collect personal information:

1) Directly from you, when:

  • you fill out a form on our site;
  • you contact us (email, phone, SMS, social networks, etc.);
  • you participate in a meeting, demonstration, or call with us;
  • you sign a contract or quote with us.

2) Indirectly, via:

  • analytics, performance tracking, or support tools used on our site or in our solutions (e.g., tracking tools, server logs);
  • our clients' systems, platforms, or software, when our solutions are integrated into them;
  • certain technology providers or partners (hosts, telephony providers, AI APIs, CRM, etc.), to the extent necessary for the provision of our services.

For what purposes do we use your information?

We use personal information for the following purposes:

Provision of our services

  • analyze your business needs;
  • design, configure, and deploy our automation, web development, and integration solutions;
  • manage user accounts, access, and permissions;
  • provide technical support, after-sales service, and project follow-up.

Improvement of our solutions and our offering

  • analyze the use of our systems (statistics, logs, performance);
  • improve the quality, relevance, and efficiency of automations (scripts, flows, responses, interfaces);
  • develop new features, products, or services.

When possible, we use aggregated or anonymized data for analysis purposes.

Customer relationship management and internal operations

  • billing and accounting management;
  • management of contracts, proposals, and renewals;
  • communication with you to inform you of changes, updates, or improvements.

Compliance with our legal obligations

  • comply with applicable laws, particularly regarding the protection of personal information, document retention, and taxation;
  • respond to requests from competent authorities when required by law.

On what basis do we process your information?

Depending on the context, the processing of your personal information is mainly based on:

  • the performance of a contract or pre-contractual measures (for example, when we analyze a project for a client or implement a solution for their business);
  • your consent, when required by law (e.g., newsletter subscription, collection of certain types of data, use of non-essential cookies);
  • our legitimate interests, when processing is necessary for the management and improvement of our services, and respects your rights and reasonable expectations.

When processing is based on your consent, you can withdraw it at any time, subject to legal or contractual constraints, by contacting us using the contact details set out in the section "How to Contact Us".

Cookies and similar technologies

We may use cookies and similar technologies to:

  • facilitate navigation on our site;
  • analyze traffic and use of our pages;
  • improve user experience and site performance.

You can configure your browser to refuse all or some cookies, or to be alerted when a cookie is sent. However, some site features may be limited if you disable certain cookies.

If we use specific analytical or advertising cookies, we may detail them in a dedicated section or banner.

With whom do we share your information?

We do not sell your personal information.

However, we may communicate them to the following categories of third parties, when necessary:

  • Technology service providers: hosting, servers, cloud solutions, telephony/SMS/voice, AI platforms, analytics tools, support tools, or CRM. The main providers we currently use are Meta Platforms, Hostinger, Supabase, Vercel, Twilio and Resend;
  • Partners or subcontractors who help us deliver our projects (developers, integrators, consultants), subject to confidentiality obligations;
  • External professionals (e.g., accountants, legal advisors), when necessary for the management of our business;
  • Competent authorities, if the law requires us to or to protect our rights.

Some of these third parties may be located outside Quebec or Canada. In this case, we take reasonable measures to ensure that the transferred information benefits from an adequate level of protection, particularly through appropriate contractual agreements and, if necessary, a privacy impact assessment (PIA).

How long do we keep your information?

We keep personal information for as long as necessary for the purposes for which it was collected, and then securely destroy or anonymize it.

Because a single period does not suit every type of information, we determine the applicable period using the following criteria:

  • the nature of the information and how sensitive it is;
  • the purpose for which it was collected, and whether that purpose is still current;
  • whether there is an active business relationship or an ongoing exchange with you, or with the business client concerned;
  • the legal, accounting, tax and regulatory obligations that require us to keep certain records;
  • the need to establish, exercise or defend a right, in particular in the event of a claim or dispute;
  • security, logging and fraud-prevention needs.

Where a law sets a retention period, that period applies.

Our retention rules are recorded internally and are subject to periodic review, under the responsibility of the Privacy Officer, whose contact details appear in the section "How to Contact Us".

You may at any time request the deletion of information concerning you, as set out in the section "Your Rights".

How do we protect your information?

We implement reasonable security measures, proportionate to the sensitivity of the personal information we hold, including:

  • limiting access to information to only those persons who need it to perform their duties, through role-based access control;
  • strict isolation of each client organization's data, enforced directly at the database level, so that one business client cannot access another's data;
  • logging of activity carried out on files and of communications sent from our systems;
  • verification of the cryptographic signature of data transmitted by third-party platforms at the entry point of our automation infrastructure;
  • use of strong passwords and, where possible, two-factor authentication on our systems;
  • use of secure connections (HTTPS/TLS) for our online services;
  • storage of third-party service credentials in encrypted server-side secrets vaults;
  • regular backups and restoration procedures in case of incident;
  • confidentiality agreements with our employees, collaborators, and subcontractors;
  • regular updates of our software and systems to reduce vulnerability risks.

However, no system is completely risk-free. In the event of a privacy incident affecting your information, we will apply the procedures described in the section "Privacy Incidents".

Privacy Incidents

A 'privacy incident' is, for example, unauthorized access, use, communication, or loss of personal information.

In the event of a privacy incident:

  • we will quickly take measures to limit the impacts and secure the information concerned;
  • we will analyze the situation and keep a register of incidents in accordance with applicable laws;
  • when the incident presents a risk of serious harm, we will notify the persons concerned and, when required, the Commission d'accès à l'information du Québec (CAI).

Your Rights

Subject to the limits provided by law, you have the following rights regarding your personal information:

  • Right of access: know what personal information we hold about you and obtain a copy;
  • Right of rectification: request the correction of inaccurate, incomplete, or ambiguous information;
  • Right of deletion: request that your information be deleted where keeping it is no longer justified;
  • Right of withdrawal of consent: when processing is based on your consent, request to withdraw it (for example, for marketing);
  • Right to portability, when this right is applicable and provided by law, for certain types of information.

To exercise any of these rights, please contact us as set out in the section "How to Contact Us". We may ask you for certain information to verify your identity before responding to your request.

If your request concerns a Meta advertising form you filled out on Facebook or Instagram, the detailed steps are set out on the Meta Lead Ads data deletion page.

You also have the right to file a complaint with the Commission d'accès à l'information du Québec (CAI) if you believe that your rights regarding the protection of personal information have not been respected.

Changes to this Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, our services, or applicable laws.

When we make significant changes, we will update the 'Last updated' date at the top of this page and, when required, we will inform you of these changes (for example via a notice on our site or by email).

We invite you to regularly consult this page to stay informed about how we protect your personal information.

How to Contact Us

For any question regarding this Privacy Policy, to exercise your rights or to raise a concern, you can contact the Privacy Officer of Technologies SYSMOTIX inc. at support@sysmotix.com.

For requests concerning a Meta advertising form specifically, see the Meta Lead Ads data deletion page.

Privacy Officer: Loading...