Privacy Policy

Last updated: June 2026

Mediavore Interactif inc., operating the Planivore platform (hereinafter “Planivore” or “we”), is committed to protecting the personal information of the individuals and organizations that use our services. This Privacy Policy (the “Policy”) describes what information we collect, how we use it, how long we keep it, and the rights available to you.

This Policy applies to the Planivore website, the planivore.app platform, and all associated services (the “Service”). It should be read alongside our Terms of Use. Terms defined in the Terms of Use, including “Client”, “Primary Administrator”, “Authorized User”, “Client Content”, “AI Feature”, and “Third-Party Provider”, have the same meaning in this Policy.

1. Scope

This Policy applies in particular to:

  • visitors to our website;
  • individuals who communicate with us;
  • representatives of our clients, prospects, partners, and suppliers;
  • administrators and Authorized Users of client accounts;
  • individuals whose personal information may be included in Client Content processed in our Service.

2. Role of Planivore and of the Client

Depending on the context, Planivore may act:

  • as a company or organization responsible for its own personal information, for example to manage its website, sales, billing, marketing, recruitment, or support;
  • as a service provider or technology processor on behalf of a Client that uses the platform for its own organizational purposes.

When the Client uses the platform to manage its plans, projects, notes, assessments, reports, users, or other content, the Client generally remains responsible for determining what data it enters into the platform, for what purposes, and on what legal basis. In this context, requests relating to the content of a Client’s account may first need to be addressed to that Client.

3. Categories of Personal Information Collected

Depending on the context, we may collect the following categories of personal information:

  • identification and contact information, such as last name, first name, title, organization, email address, phone number, and business address;
  • account information, such as username, internal identifier, role, preferences, settings, and access logs;
  • transaction and billing information, such as billing address, billing history, certain payment details, and the information required to process a subscription; payments are handled directly by our payment processor and we do not store complete payment card data;
  • technical and usage information, such as IP address, device type, operating system, browser, pages visited, timestamps, technical logs, application events, and usage statistics;
  • information contained in communications you send us, including by email, form, chat, videoconference, phone call, or support request;
  • information included in Client Content when the Client or its Authorized Users choose to enter, import, or upload it into the platform;
  • information related to the AI Feature when activated, including text excerpts submitted for translation, correction, rephrasing, improvement, or other writing assistance, and the outputs generated;
  • content of messages submitted through the online support channel (support chat or ticketing system) when you communicate with Planivore’s support team; this data does not include Client Content or account-specific data.

We do not need you to provide sensitive personal information, unless it is necessary in a specific and authorized context. We ask Clients and Authorized Users to avoid entering sensitive or unnecessary information in free-text fields, particularly in fields used with the AI Feature.

4. How We Collect Information

We collect personal information:

  • directly from you, when you fill out a form, request a demo, create an account, contact us, subscribe, attend an event, or use our services;
  • automatically, through cookies, logs, pixels, similar technologies, and analytics tools;
  • from our Clients, partners, integrators, resellers, payment providers, authentication providers, or other authorized third parties;
  • indirectly, when an Authorized User or administrator enters information into the platform in the normal course of using the Service.

5. How We Use Your Information

We use personal information, as applicable, to:

  • provide, operate, administer, support, and improve our services;
  • create and manage accounts, permissions, settings, and access;
  • process orders, subscriptions, payments, renewals, and invoices;
  • respond to requests, comments, incidents, audits, and support or training needs;
  • ensure security, integrity, availability, fraud prevention, and compliance with our policies;
  • communicate with you about the Service, updates, changes, new features, events, newsletters, or offers, where permitted;
  • produce aggregated, anonymized, or de-identified statistics, where permitted;
  • comply with our legal, regulatory, contractual, or governance obligations;
  • enable the use of the AI Feature when it has been activated by the Client’s Primary Administrator.

6. AI Feature and Third-Party Processing

The Service includes two distinct AI-powered components, each with different data flows.

6.1 Optional AI Feature (writing assistance)

When the AI Feature is activated for a Client account, certain text excerpts voluntarily entered in compatible fields may be transmitted to a third-party artificial intelligence service provider, notably OpenAI, in order to perform the requested function, for example to translate, correct, rephrase, or improve a text.

In this context:

  • we seek to limit the data transmitted to what is reasonably necessary to provide the requested feature;
  • transmitted data is processed in accordance with our technical architecture and our applicable agreements with our providers;
  • generated outputs may be retained in the platform depending on how the user chooses to use or save them;
  • the Client remains responsible for determining whether the use of this feature is appropriate for its own legal, regulatory, contractual, and internal obligations.

Depending on the technical configuration, the nature of the provider used, and the applicable contractual settings, certain data associated with the AI Feature may be processed by a third-party provider outside the Service’s primary hosting environment. OpenAI states in its official documentation that data sent through its API is not used to train its models by default, unless the customer explicitly opts in to data sharing, and that limited retention may apply for abuse monitoring.

6.2 Online Support Channel and AI Support Assistant

Planivore provides all its clients with an online support channel (support chat or ticketing system) for submitting help requests to the support team. This channel uses an AI assistant to process requests and generate responses based on Planivore’s internal knowledge base.

In this context:

  • messages submitted via the support channel may be transmitted to a third-party artificial intelligence service provider — Planivore uses Anthropic’s models for this purpose — to generate a contextual response based on the knowledge base;
  • the support assistant does not access Client Content, account data, documents uploaded to the platform, or personal information in the strategic plan;
  • support chat exchanges may be temporarily retained for service quality and knowledge base improvement purposes;
  • Anthropic states in its official documentation that data submitted via API is not used by default to train its models;
  • at the start of each support chat session, users receive a notification indicating that responses may be generated with the assistance of artificial intelligence.

7. Legal Basis for Processing

Where required by applicable law, we rely in particular on one or more of the following legal bases:

  • your consent;
  • the performance of a contract or of pre-contractual measures;
  • compliance with a legal obligation;
  • our legitimate interests, to the extent they do not override your rights;
  • any other basis recognized by applicable law.

8. Disclosure to Third Parties

We may disclose personal information to the following categories of recipients, where necessary:

  • hosting, infrastructure, authentication, security, analytics, and support providers;
  • payment processors and billing tools;
  • communication, messaging, CRM, marketing, or automation providers;
  • artificial intelligence service providers, when the AI Feature is activated or to operate the support assistant;
  • professional advisors, auditors, insurers, and financial institutions;
  • public authorities, regulatory bodies, or courts, where required or permitted by law.

We do not sell your personal information, and we do not use Client Content for commercial purposes other than providing the Service.

9. Cookies and Similar Technologies

We use cookies, logs, pixels, and similar technologies to:

  • operate the website and the Service;
  • remember certain preferences;
  • measure audience and usage;
  • improve performance, security, and user experience;
  • support certain communication or analytics campaigns.

You can manage certain cookies in your browser settings or, where available, through our cookie management tool. Refusing certain cookies may affect some features.

10. Data Retention

We retain personal information only for as long as necessary to fulfill the purposes described, subject to:

  • our legal, accounting, tax, regulatory, or contractual obligations;
  • security, fraud prevention, evidence, audit, continuity, or dispute resolution needs;
  • retention settings agreed with our Clients.

Unless otherwise provided in the applicable contract:

  • account data is retained for the duration of the subscription and for a reasonable period following termination (generally 60 days) to allow for account recovery or data export;
  • Client Content is retained for the term of the contract; following termination, the Client has 60 days to request an export in structured format (CSV or SQL), after which the data may be permanently deleted;
  • technical and access logs may be retained for up to 12 months for security and diagnostic purposes.

Certain information related to billing, the contractual relationship, security, or compliance obligations may be retained longer where required or justified.

11. Hosting, Transfers, and Cross-Border Access

The primary environment of our Service and our client data is organized to favour hosting in Canada. However, certain Third-Party Providers, subcontractors, communication tools, analytics services, support services, or specialized features, including the AI Feature, may involve access to, processing, disclosure, or transit of data outside Québec or Canada.

For clients located in the United States or in the European Union, Planivore also offers hosting on servers located in their respective region (United States or Europe), allowing the client’s data to remain within the relevant jurisdiction. This option is specified in the quote accepted by the client. Unless otherwise stated in the quote, hosting is in Canada by default.

Where such transfers or cross-border access are necessary, we seek to implement reasonable and appropriate contractual, technical, and organizational measures based on the sensitivity of the data and applicable legal requirements.

For transfers to countries that do not offer an adequate level of protection recognized by the competent supervisory authorities (in particular under the European Union’s General Data Protection Regulation (GDPR)), we seek to implement recognized transfer mechanisms, such as the standard contractual clauses (SCCs) adopted or approved by the European Commission, or any other equivalent mechanism accepted by applicable law. Clients or suppliers located in the European Union may request a copy of the applicable transfer mechanisms by contacting our privacy officer.

12. Security

We implement reasonable administrative, organizational, contractual, physical, and technological security measures to protect personal information against loss, theft, unauthorized access, disclosure, copying, misuse, alteration, or destruction. These measures include data encryption in transit (TLS), access controls, audit logging, and periodic security reviews.

However, no security measure offers an absolute guarantee. In the event of a confidentiality incident presenting a real risk of serious harm, we will take the measures required by applicable law, including:

  • notifying the competent supervisory authority within the required timeframes (no later than 72 hours after becoming aware of it under the GDPR, or within the timeframes prescribed by Québec’s Act 25 and other applicable laws);
  • where we act as a processor on behalf of a Client, notifying that Client without undue delay so that it can meet its own obligations;
  • notifying the individuals concerned where required by law and where the risk is high;
  • documenting the incident in accordance with our legal and regulatory obligations.

13. Your Rights

Depending on applicable law and subject to permitted exceptions, you may request:

  • access to your personal information;
  • rectification of inaccurate or incomplete information;
  • withdrawal of your consent where processing is based on it;
  • deletion or anonymization of certain information;
  • portability, where such a right exists;
  • restriction of, or objection to, certain processing;
  • not to be subject to a decision based solely on automated processing that produces legal effects or significantly affects you, subject to legal exceptions, in accordance with Article 22 of the GDPR and the applicable provisions of Act 25.

To exercise these rights, contact us at [email protected]. We will respond within the timeframes required by applicable law and may need to verify your identity before processing your request. For information contained in a client account administered by an organization, we may redirect you to that organization where appropriate.

14. Third-Party Information and Minors

The Client and Authorized Users must only enter into the platform information they are authorized to process. The Service is not intended for independent use by children. If you believe that personal information concerning a minor has been collected inappropriately, please contact us.

15. Changes to This Policy

We may amend this Policy from time to time to reflect changes in our practices, providers, features, applicable laws, or service offering. The most recent version will be posted on our website with its update date. In the case of material changes, we will notify you by email or via a prominent notice within the Service.

16. Contact Information and Privacy Officer

For any question, request, or complaint regarding this Policy or the protection of personal information, please contact us:

Company: Mediavore Interactif inc. (Planivore)
Person in charge of the protection of personal information: Alexandre Jalbert
General email: [email protected]
Privacy email: [email protected]
Phone: +1 514-248-2228
Website: https://planivore.app/

If you believe your rights have not been respected, you may also file a complaint with the Commission d’accès à l’information du Québec or, depending on where you reside, with the competent supervisory authority.

17. Provisions for Individuals Located in the European Union (GDPR)

Where the European Union’s General Data Protection Regulation (GDPR) applies to the processing of your personal information, the following provisions supplement this Policy.

17.1 Controller and processor

Depending on the context, Planivore acts as a data controller (for its own customer management, marketing, and platform operation activities) or as a data processor (when it processes data on behalf of a Client in connection with the Service). Where Planivore acts as a processor within the meaning of Article 28 of the GDPR, the contractual provisions applicable between Planivore and the Client (including Section 23 of the Terms of Use and the annexes to the subscription agreement) constitute the required Data Processing Agreement.

17.2 Additional rights under the GDPR

In addition to the rights set out in Section 13, individuals whose data is processed under the GDPR have, in particular, the right to lodge a complaint with the competent supervisory authority of their Member State (for example, the CNIL in France). To exercise your rights or obtain information about our processing mechanisms, please contact our privacy officer at [email protected].

17.3 Privacy impact assessment (PIA / DPIA)

Where a feature likely to result in a high risk to the rights and freedoms of individuals is implemented (in particular artificial intelligence features), Planivore undertakes to carry out, or have carried out, a data protection impact assessment (DPIA) in accordance with applicable requirements, before its deployment.

18. Provisions for United States Residents

Depending on your state of residence, local privacy laws may apply and grant you additional rights. This section applies in particular to residents of California (CCPA/CPRA), Virginia (CDPA), Colorado (CPA), Connecticut (CTDPA), Texas (TDPSA), and any other state that has adopted a comparable law.

18.1 Categories of personal information collected

In accordance with applicable laws, Planivore may collect the following categories of personal information: identifiers (name, email address, phone number); commercial information (billing history, subscriptions); internet and network activity information (IP addresses, access logs, usage data); approximate geolocation data (inferred from the IP address). We do not collect biometric data, health data, or sensitive financial information.

18.2 Rights of U.S. residents

Depending on the law applicable in your state of residence, you may have the following rights:

  • the right to know which categories of personal information have been collected and for what purposes;
  • the right to access and obtain a copy of your personal information;
  • the right to correction;
  • the right to deletion, subject to legal exceptions;
  • the right to portability in a structured, readable format;
  • the right to opt out of profiling for targeted advertising;
  • the right not to be discriminated against for exercising these rights.

18.3 Sale and sharing of information

Planivore does not sell your personal information and does not share it for cross-context behavioral advertising within the meaning of the CCPA/CPRA. You therefore do not need to exercise a right to opt out of sale. To exercise any other applicable right, please contact us at [email protected]. We will respond to your request within the timeframes prescribed by applicable law (45 days under the CCPA, which may be extended by an additional 45 days).

18.4 Children (COPPA)

Our Service is not intended for children under 13, and we do not knowingly collect personal information from children under 13, in accordance with the Children’s Online Privacy Protection Act (COPPA). If you become aware that a child has provided us with personal information without parental consent, please contact us at [email protected].