Privacy Policy
In force from 1 August 2026
1. Who we are
This policy describes how EAG solutions, with its registered office at 925, Boul. de Maisonneuve Ouest, Suite 354, Montréal QC Canada H3A 0A5, protects personal information on the dypsia.com platform.
Officer responsible for the protection of personal information: the person holding the highest authority within Dypsia, or the person to whom this role has been delegated in writing. Reachable at info@dypsia.com.
2. Who it applies to
This policy covers three groups of people:
- visitors to the dypsia.com website;
- customers and their administrators: the organizations that create a space, and the people who represent them;
- the members and customers of our customers: for them, see section 4. It is the organization, not Dypsia, that decides what is collected about them and how it is used.
3. What we collect and why
| Information | Why |
|---|---|
| Organization name, country, address, city, postal code | Create and identify the space, issue the invoices |
| Administrator's name and email address | Manage the account, send service notifications, verify the address |
| Password | Authentication. It is stored hashed: we can neither read it nor recover it |
| Billing data | Billing, accounting, taxes |
| Technical logs: IP addresses, connection timestamps, security events | Security, abuse prevention, proof that the contract was accepted, diagnosis |
| Emails exchanged with support | Answering requests |
We do not collect payment card numbers: payments are handled by certified providers, under their own policies.
4. The data our customers host
Each customer manages its own data in its space: members, donors, customers, suppliers, accounting entries, documents. For that information:
- the customer is responsible for it: it is the customer who decides what is collected and why;
- Dypsia acts on its behalf: we host and back up that data on its instructions, without consulting it or using it for other purposes;
- each space rests on an isolated database, with no cross-access between customers;
- if someone writes to us about data held by a customer, we direct them to that customer and let the customer know.
5. Who we share it with
We neither sell nor rent any personal information. We disclose it only:
- to our hosting provider, which supplies the servers where your data is stored, without accessing or using it;
- to the payment providers, for the paid plans;
- to the authorities, where a law or a valid order requires it. We tell the person concerned where the law allows;
- to a possible buyer, in the event of a sale or a reorganization, the commitments of this policy being kept.
The current list of our providers is available on request at info@dypsia.com.
6. Where it is kept
Data is hosted on servers located in the European Union.
For people in Canada, it is therefore kept outside the country. We frame this communication with a written agreement with our host, guaranteeing a comparable level of protection.
For people in the European Union, the data stays in the Union. Where it is consulted from Canada for administration or support, that transfer rests on the European Commission's adequacy decision covering Canada.
7. For how long
| Category | Period |
|---|---|
| Active account and space | For as long as the contractual relationship lasts |
| Terminated space | 30 days, then permanent deletion and progressive erasure from the backups |
| Inactive free space | Deleted after 120 days without a connection, warning at 90 days |
| Billing data | For the period required by the tax and accounting rules of the country where the Customer is established. These data cannot be erased before that term, even on request. |
| Technical logs | 12 months, except for a security incident being analyzed |
| Unconfirmed sign-up | Nothing kept: nothing is recorded until the email address is confirmed |
8. How we protect it
- encrypted communications;
- a separate database for each space, with no cross-access;
- passwords stored hashed, never in clear;
- encrypted configuration secrets;
- administrative access controlled and logged;
- regular backups with rotation;
- the email address verified before any account is created.
In the event of a breach carrying a serious risk, we notify the competent authorities and the people concerned, and keep the register the law requires.
9. Your rights
You may see the information we hold about you, have it corrected, withdraw your consent subject to legal and contractual obligations, and challenge our compliance with our officer.
If you are in the European Union, you also have the rights to erasure, restriction, objection and portability.
To exercise them, write to info@dypsia.com. We answer within thirty days, and within one month for requests falling under the European regulation.
You may also complain to the competent authority: in Canada, the Office of the Privacy Commissioner; in the European Union, the supervisory authority of your country.
If your information is held in the space of a customer organization because you are a member, a donor or a customer of it, send your request straight to that organization: it alone decides on the processing. We assist it as far as our technical means allow.
10. Minors
The Dypsia account and the Spaces are meant for organizations and professionals. We do not knowingly collect information about minors in order to create an account.
11. Changes
We may change this policy at any time. The version in force is the one published on this page, with its update date. On a paid plan, changes take effect at the next renewal of the subscription; a customer who refuses them may terminate before that renewal. On the Free plan, they take effect as soon as they are published.
12. Reaching us
For any question about this policy or about your personal information: info@dypsia.com, or by post to 925, Boul. de Maisonneuve Ouest, Suite 354, Montréal QC Canada H3A 0A5.
The French version of this policy prevails over any translation given for information.