Privacy Policy

This policy explains in plain language how Automatisations Astrale inc. (“Astrale,” “we”) handles personal information collected on astrale.ca, by email, when an appointment is booked, and through any Astrale digital service that lets a user connect a financial account with Plaid.

Effective September 9, 2026

Responsible organization

Automatisations Astrale inc.
1182337940
Gabriel Gingras
gabriel.gingras@astrale.ca

Scope and accountability

This policy applies to people who visit astrale.ca, use our contact form, book an appointment, contact Astrale directly, or use an Astrale digital service that displays Plaid Link to connect a financial account.

Astrale is accountable for the personal information under its control. The person identified above oversees this policy and receives privacy-related requests.

Information we collect

We limit collection to the information required for the purposes described below.

  • Contact form: first and last name, phone number, email address, company (optional) and message.
  • Appointment booking: first and last name, guest email addresses, company (optional), description of the need (optional), selected date, time and time zone, and Google Calendar invitation and Google Meet link data.
  • Direct communications: information contained in the emails and documents you choose to send us.
  • Financial connection: selected financial institution, connection status and date, technical connection identifiers, and information shown in Plaid’s consent screen.
  • Authorized financial data: depending on the requested feature, account type and name, masked account identifier, balance, transactions, account-holder information, or other data you expressly choose to share. Astrale limits access to the categories required for the service being used.
  • Limited technical data: IP address, browser or device type, date, time and requested resource that may appear in hosting logs to deliver and secure the site.

Why we use it

We use personal information only for the purposes identified at collection or as otherwise permitted by law.

  • respond to an inquiry and communicate with you;
  • understand a business need and prepare a commercial follow-up;
  • create or update your record in our CRM, attach your inquiry, assign the follow-up to a member of our team and create a callback task due within five minutes;
  • promptly notify authorized members of our team in GoHighLevel that a new inquiry was received so that it can be followed up;
  • schedule, confirm and hold a meeting through Google Calendar and Google Meet;
  • connect the financial account you selected and provide the specific feature described before Plaid Link opens;
  • verify that the connection works, prevent fraud, investigate unauthorized access and support your request;
  • operate, protect and improve the reliability of the site;
  • prevent abuse, spam and security incidents;
  • meet our legal, accounting and contractual obligations and defend our rights.

Financial connections with Plaid

Astrale uses Plaid as a financial connectivity provider. Plaid collects and processes certain information directly from you and your financial institution under its own notices, obligations, and the choices shown in Plaid Link. Astrale receives only the authorized data required for the requested feature.

Astrale does not receive or store your online banking username or password. This information is entered in the secure interface of Plaid or your financial institution, depending on the connection method offered.

You may withdraw consent, ask Astrale to disconnect your account, and request deletion of financial data under our control by contacting the person identified at the top of this page. You may also manage certain connections and data held by Plaid through the tools Plaid makes available to end users.

Service providers and disclosure

We do not sell or rent personal information. Only Astrale personnel who require it for their work may access it.

We may disclose the information required to providers that support the site and its functions: Cloudflare for infrastructure hosting, delivery and security, HighLevel Inc. (GoHighLevel and LeadConnector) for managing requests and internal alerts in our CRM, Google Calendar and Google Meet for meetings and invitations, and Plaid for authorized financial connections.

When a feature uses Plaid, Astrale provides Plaid with the technical information and instructions required to start and maintain the connection you request. Plaid may provide Astrale with the financial information you authorized. Plaid also processes information under its End User Privacy Policy, which is linked in the official resources at the bottom of this page.

When you submit the contact form, Astrale sends GoHighLevel your first and last name, phone number, email address, company if provided, and message. GoHighLevel acts as a service provider to Astrale: it creates or updates your contact record, stores the message as a note, assigns the follow-up and creates an internal callback task. Astrale remains responsible for determining the purposes of this processing.

These providers process information through their own infrastructure and contractual commitments. We may also disclose information when required by law, to respond to a valid order, or to protect our rights and the safety of individuals.

Processing outside Quebec

Cloudflare, HighLevel Inc. (GoHighLevel and LeadConnector), Google, and Plaid operate international infrastructure. Some information may therefore be processed or stored outside Quebec, including in Canada, the United States or other territories where these providers operate their services, and local authorities may access it under applicable law.

Connected financial institutions and Plaid may process information under their own policies and applicable laws. Astrale does not determine their independent practices, but limits its requests to the data required for the stated feature.

Before entrusting personal information to a provider outside Quebec, Astrale applies the measures required by law, including a privacy impact assessment and appropriate contractual protections where required.

Retention and destruction

We retain information only for as long as necessary for the purpose for which it was collected. The period depends on the nature of the request, the last interaction, whether a business relationship exists, limitation periods and our legal, tax or contractual obligations.

Financial data and connection tokens under Astrale’s control are retained only while the connection is active and required for the requested feature, or for an additional period required by law. When a connection is withdrawn or a valid deletion request is processed, Astrale stops new collection, revokes the applicable access, and destroys data that no longer needs to be retained.

At the end of the applicable period, information is securely destroyed or anonymized for serious and legitimate purposes in accordance with the law. Providers may retain backup copies for a limited period based on their technical cycles.

Astrale reviews its information categories, purposes, and retention rules at least once a year and after any material change to a service or provider.

Security safeguards

We apply reasonable administrative, technical and physical safeguards based on the sensitivity, quantity, purpose and medium of the information. We document security responsibilities, limit collection, and assess providers that handle sensitive information.

Access to systems and sensitive information is limited to people and services that require it for their responsibilities. Critical systems use stronger authentication where available; access is removed when no longer required and reviewed based on risk.

Connections to our services are protected using modern encrypted transport. Sensitive data stored by our platforms is protected at rest through the encryption and key-management mechanisms provided by the relevant vendors. Application secrets must not be embedded in browser code or published in the source repository.

We monitor exposed assets and software dependencies, assess reported vulnerabilities, and apply patches based on severity and risk. Relevant events may be logged to detect abuse, support investigations, and restore services.

No transmission or storage method is infallible. If you believe information has been compromised, contact the person in charge of personal information without delay.

Privacy incidents

Astrale maintains a procedure to receive reports, contain an incident, preserve relevant evidence, assess consequences, correct the cause, and document decisions. Privacy incidents are recorded in the register required by law where applicable.

When an incident creates a risk of serious injury, Astrale notifies the Commission d’accès à l’information and affected individuals as required by law. Communications provide useful information to reduce the risk without disclosing details that would further compromise security.

Cookies and usage measurement

Only with your consent, PostHog measures your journey across the site: pages and sections viewed, returning visits, referral sources and allowed campaign parameters, clicks, estimated active time, video playback, form interactions, errors, questionnaire answers and confirmations sent by the calendar. Events include technical identifiers, device information and language. Field edits and deletions are measured without sending text entered before submission. After a form is successfully submitted, your name, email and company if provided are sent to PostHog to link collected actions to your profile. Your phone number and free-text message are not sent to PostHog. They remain in our inquiry handling tools; a hashed version of your phone number may be sent to Meta with your consent, as explained below. An identifier stored in the browser recognizes later visits; it does not prove that the same person always uses that device. Approximately 20% of consented sessions may have a visual recording with fields and personal information masked; the external calendar, request payloads and console logs are excluded. PostHog processes this data in our project hosted in the United States. Meta Pixel also measures visits and advertising conversions. With your consent, we also use Meta’s Conversions API to send inquiry milestones: an appointment booked, a won deal with its actual value, or a lost deal. Your email and phone are hashed before this transfer; hashing lets Meta match events to its accounts and does not make the information anonymous. Available click and browser identifiers are also sent. Matching information is retained for up to 90 days in our tracking service; technical deduplication receipts without contact details are retained for 400 days. A secure cookie stores a receipt for 90 days so a withdrawal of consent from this browser can be applied to CRM tracking. After withdrawal, a new form submission with your consent is required to resume this CRM tracking. If you decline, these tracking tools remain disabled and forms work normally. You can withdraw consent using the cookie preferences button. Withdrawal stops new collection; you may also request access to or deletion of previously collected data by contacting our privacy officer.

A separate application that displays Plaid Link may use cookies or technologies that are strictly necessary for authentication, security, and the financial connection. Plaid describes its own technologies and choices in its privacy policy and in the interface shown before connection.

A separate administrative connection used to configure Google Calendar may use one secure, short-lived cookie solely to protect the integrity of authentication. Visitors cannot access this function, the cookie is not used for tracking and it is deleted when the process ends.

Your rights

Subject to the conditions and exceptions provided by law, you may request access to personal information we hold about you, correction of inaccurate or incomplete information, withdrawal of consent, disconnection of a financial account, deletion of data that no longer needs to be retained, cessation of dissemination or de-indexing where applicable, and delivery of certain computerized information in a structured, commonly used technological format.

Email the person identified at the top of this page and describe your request. We may reasonably verify your identity before responding. We will process the request within the legal time limits and explain in writing any refusal permitted by law.

If you are not satisfied with our response, you may file a complaint with the Commission d’accès à l’information du Québec. Depending on the context, the Office of the Privacy Commissioner of Canada may also have jurisdiction.

Minors

Astrale provides services to businesses and does not direct its services to anyone under 14. We do not knowingly seek to collect their personal information through this site. A parent or guardian may contact us to request deletion of information submitted by mistake.

Changes to this policy

We may update this policy to reflect changes in our practices, providers or applicable law. The current version is published on this page with its effective date. We will provide appropriate notice of any material change.