Skip to content
FFACET

PRIVACY / QUEBEC LAW 25

Privacy policy

This policy explains in plain language how Lumiro Studio, which operates Facet, handles personal information on the marketing website and in the Facet application.

Last updated: August 24, 2026

1. Scope and roles

Facet is a proposal creation, sharing and acceptance service for agencies. This policy covers website visitors, account holders, agency members and proposal recipients.

For account, billing and service operations data, Facet determines the purposes of processing. For information an agency uploads about its own clients, the agency remains responsible for collection and instructions; Facet acts as its service provider.

2. Information we process

  • Account and organization: name, email, agency, role, language preference and security settings.
  • Clients and proposals: business contact details, scope, rates, comments, attachments, selected options and document history.
  • Acceptance: signer name and email, consent text, date and time, IP address, browser, document fingerprint and, depending on the method, signature evidence or certificate.
  • Use and security: session identifiers, technical logs, IP address or derived fingerprint, browser, views, access attempts and events needed to prevent abuse.
  • Billing and communications: selected plan, subscription status, transaction identifiers and email delivery logs. Facet does not receive your full payment card number.
  • Audience measurement: only after consent, pages viewed, navigation events, device, approximate source and measurement identifiers generated by Google Analytics.

3. Why we use it

  • Create and secure accounts and agency workspaces.
  • Produce, send, display, version and accept proposals.
  • Send requested access codes, invitations, notifications and documents.
  • Administer subscriptions, prevent fraud and resolve incidents.
  • Provide support, maintain service quality and meet legal obligations.
  • Measure use of the marketing site with Google Analytics when authorized.

5. Providers and sharing

We limit access to people and providers that need it to deliver the service. Depending on the features used, this may include our hosting, database and storage providers, as well as Resend for email, Polar for billing, DocuSign for signatures and Google for consented audience measurement.

Some providers may process information outside Quebec or Canada. Before such a transfer, we assess sensitivity, purpose, contractual safeguards and the applicable legal framework. We do not sell personal information.

6. Retention and disposal

We retain information during the active relationship and afterwards according to our retention schedule, security needs, contractual commitments and applicable legal periods. Acceptance evidence, billing records and incident logs may need to be retained longer than ordinary account data.

At the applicable deadline, information is deleted, anonymized or securely destroyed. A copy may remain temporarily in protected backups until rotation. You may ask the person in charge for the period applying to a specific category.

7. Security and incidents

We use administrative, technical and physical safeguards proportionate to the information, including agency-workspace separation, access controls, secret encryption, attempt limits, logging and backups. No system can offer absolute security.

We maintain an incident-management process. When an incident presents a risk of serious harm, we notify the Commission d’accès à l’information and affected individuals as required by law.

8. Your rights

  • Request access to personal information we hold about you.
  • Correct inaccurate or incomplete information.
  • Withdraw consent where processing depends on it.
  • Where provided by law, request computerized personal information in a structured, commonly used technological format.
  • Ask a question or make a complaint to the person in charge, and contact the Commission d’accès à l’information if you remain dissatisfied.

Some rights may be limited by law, the rights of others or the need to preserve contractual evidence.

9. Governance and changes

Our internal practices cover responsibilities, access, retention, disposal, providers, privacy impact assessments, complaints and incidents. They are reviewed as the service or its risks evolve.

We will publish material changes on this page and update the date above. We will provide an additional notice when the nature of a change calls for one.

PERSON IN CHARGE OF THE PROTECTION OF PERSONAL INFORMATION

A question, request or complaint?

Write to the person in charge of the protection of personal information. We will acknowledge your request and may verify your identity before responding.

bonjour@lumiro.studio