Privacy Policy — Clairgest
1. Who we are
Les Logiciels Cygsoft Inc. ("Cygsoft", "we", "us"), a Canadian company registered in Quebec (NEQ 1182033127), operates the Clairgest platform ("the Service"), management software (POS, appointment booking, invoicing, communications) for esthetics, hairstyling and massage therapy professionals across Canada.
Address: PO Box 1281, Sept-Îles (Quebec) G4R 4X7, Canada.
For any questions regarding this policy or to exercise your privacy rights, please contact our Personal Information Protection Officer (PIPO) by email at privacy@clairgest.ca.
2. Who this policy applies to
This policy covers personal information we collect from:
- Tenants: professionals and businesses who subscribe to Clairgest to run their operations.
- End clients of Tenants: individuals who book appointments, purchase products or receive services through the Clairgest platform.
- Visitors: people who visit Clairgest's public pages without creating an account.
Important note: for End clients, the Tenant who registers them is the primary point of contact regarding their data. Cygsoft acts as a service provider (processor under Law 25), and the Tenant acts as the data controller for the data they collected from their own clients.
3. Personal information we collect
3.1 From Tenants
- Identity: first name, last name, business name, NEQ or business number.
- Contact information: mailing address, email, phone number.
- Login data: username, password (hashed), login history, IP address.
- Billing data: payment information processed by our provider (card numbers are never stored on our servers).
- Usage data: event logs, aggregated usage statistics.
3.2 From End clients of Tenants
The following information is collected and managed by the Tenant through the platform:
- Identity and contact information (name, email, phone).
- Appointment and transaction history with that Tenant.
- Notes added by the Tenant (free-text field — see section 3.3).
3.3 Sensitive information
Clairgest does not request and does not actively collect health information, allergies or medical conditions. However, in the course of practising their profession, a Tenant may record such information in the "notes" field of a client record. When this happens:
- This data remains under the exclusive responsibility of the Tenant (who must obtain informed consent from their End client).
- Cygsoft applies the same technical safeguards as for any other personal data.
- Cygsoft does not analyze, aggregate or consult this data for any purpose other than the technical delivery of the Service.
4. Purposes of collection
We use personal information to:
- Provide, maintain and improve the Service.
- Authenticate users and secure accounts.
- Issue invoices and process subscription payments.
- Communicate with Tenants about the Service (technical notifications, support, contract changes).
- Provide technical support and resolve incidents.
- Meet our legal obligations (accounting, mandatory legal disclosures).
- Protect our rights, the rights of our Tenants and the public (fraud prevention, security).
Commercial communications (CASL): we send no commercial electronic messages to a Tenant or End client without their prior explicit consent. Every commercial email includes an unsubscribe option processed within 10 days.
5. Legal bases
Depending on the context, the collection and use of personal information rests on:
- Performance of the contract between Cygsoft and the Tenant (terms of service).
- Explicit consent from the individual concerned (notably for commercial communications and sensitive information).
- Legal obligation (accounting and tax obligations, court orders).
- Cygsoft's legitimate interest in security, fraud prevention and improving the Service, where this does not infringe on the rights of the individuals concerned.
6. Service providers and data sharing
To deliver the Service, Cygsoft relies on carefully selected service providers:
| Category | Type of data processed | Location |
|---|---|---|
| SaaS infrastructure hosting | All Service data | Canada (OVH Canada) |
| Email infrastructure (admin mailboxes) | Emails received and sent | Canada (VD Informatique) |
| Transactional email delivery | Email addresses, notification content | United States (SendGrid) |
| Transactional SMS delivery | Phone numbers, message content | United States (Twilio) |
| Payment processing (upcoming) | Payment information, transaction identifiers | United States and/or Canada |
Transfers outside Quebec: some service providers (SMS, transactional emails, payments) are based in the United States. In accordance with Law 25, we conduct a privacy impact assessment for these transfers and ensure that providers offer equivalent protection. An up-to-date detailed list of our service providers is available on request at privacy@clairgest.ca.
Cygsoft never sells personal information to third parties for marketing purposes.
7. Data retention
| Data | Retention |
|---|---|
| Active Tenant account | For the entire duration of the subscription |
| Tenant account after termination | 30 days in "read-only" access for retrieval, then soft delete |
| Permanent deletion (hard delete) | 90 days after soft delete |
| Billing and tax data | 6 years (Quebec and federal accounting requirements) |
| Technical logs (server logs, access audit) | 90 days |
| Backups | 30-day rolling rotation |
| Information for ongoing incident resolution | Until resolution + 30 days |
At the request of a Tenant or an End client exercising their right to be forgotten, we proceed with permanent deletion within the timeframes set out in Law 25, subject to our legal retention obligations.
8. Security
We implement technical and organizational measures to protect personal information:
- TLS encryption for all client-server communications.
- Cryptographic password hashing (bcrypt).
- Strict multi-tenant isolation (each Tenant only sees their own data).
- Two-factor authentication (2FA) available and recommended.
- Encrypted off-site backups.
- Logging of administrative access and periodic review.
- Training and confidentiality obligations for our staff.
No system is completely foolproof. In the event of a privacy incident affecting your personal information and presenting a risk of serious harm, we will notify you without undue delay, and no later than 72 hours after becoming aware of the incident, in accordance with Law 25.
9. Your rights
In accordance with Quebec's Law 25 and Canada's PIPEDA, you have the following rights:
- Access: obtain a copy of the personal information we hold about you.
- Rectification: have inaccurate or incomplete information corrected.
- Erasure ("right to be forgotten"): request deletion of your information, subject to our retention obligations.
- Portability: receive your information in a structured, commonly used format (JSON or CSV export).
- Objection: object to the processing of your information for legitimate reasons.
- De-indexing: request that a link to your information no longer be accessible through a search engine, where applicable.
- Withdrawal of consent: withdraw consent previously given for commercial electronic communications.
To exercise these rights, contact privacy@clairgest.ca. We respond within 30 days of receiving a complete request. No fee is charged unless the request is manifestly unfounded or excessive.
If you feel we have not responded adequately, you may file a complaint with:
- the Commission d'accès à l'information du Québec: https://www.cai.gouv.qc.ca
- or the Office of the Privacy Commissioner of Canada: https://www.priv.gc.ca
10. Cookies and similar technologies
Clairgest uses cookies strictly necessary to operate the Service (authentication, session, security). These cookies do not require your prior consent.
No profiling, advertising or third-party tracking cookies are placed on the Service's pages.
You may configure your browser to refuse cookies, but this may impair the proper functioning of the Service.
11. Minors
Use of Clairgest by a Tenant requires that they be at least 18 years of age (contractual capacity).
When a Tenant registers a minor End client in the platform:
- For End clients under 14 years of age: parental consent or consent from the holder of parental authority is required and must be obtained by the Tenant before any data entry.
- For End clients aged 14 and older: they may personally consent to the collection of their information for services provided to them.
The Tenant is responsible for obtaining and keeping consents for their own End clients.
12. Updates to this policy
We may update this policy to reflect changes to the Service or to applicable regulations. The date of the latest revision is shown at the top of the document.
For substantive changes, we will notify Tenants by email and require their explicit acceptance at their next login.
Version history is available on request.
13. Contact us
For any question, request or complaint:
Les Logiciels Cygsoft Inc.
Attn: Personal Information Protection Officer
PO Box 1281
Sept-Îles (Quebec) G4R 4X7
Canada
Email: privacy@clairgest.ca
This policy was originally drafted in French. The French version prevails in case of any discrepancy with this translation.