smrtware

Privacy Policy

Effective 6 September 2026 · Version 1.0

Draft pending legal review. This policy was prepared to cover the requirements of the GDPR, Canada's PIPEDA, the Saudi PDPL and the CCPA/CPRA. It has not yet been reviewed by a qualified lawyer in any of those jurisdictions. Do not rely on it as legal advice, and have it reviewed before SmrtWare is offered publicly.

SmrtWare is business software for construction and trades companies, published by SMRTQ SOLUTIONS LIMITED (Ontario, Canada), which trades as smrtQ. In this policy "we" means SMRTQ SOLUTIONS LIMITED and "you" means the person reading it.

1. The two different things this policy covers

SmrtWare is sold as an isolated instance per company. That makes our responsibilities genuinely different in two situations, and the distinction decides who you should contact about what.

SituationWhose personal informationOur role
This website, smrtware.ai Yours, as a visitor or enquirer Controller. We decide why and how it is handled. Sections 2 to 4 apply.
A SmrtWare instance run by a customer company That company's own employees, customers, suppliers and staff Processor. The customer company is the controller. Section 5 applies.

2. What this website collects

This site is a static set of pages. It sets no advertising or analytics cookies, embeds no third-party trackers, and has no login.

We do not sell or share personal information for cross-context behavioural advertising, and we do not profile visitors or make automated decisions about them.

3. Why we may lawfully use it

Where the GDPR or a comparable law applies, our lawful bases are:

Under PIPEDA we rely on your implied consent for the ordinary operation of this site, and express consent where the law requires it.

4. How long we keep it, and who else sees it

We disclose personal information only to service providers who help us run the site and our business, under contract and only as needed; and where we are legally required to, for example by a court order or a regulator. We do not sell personal information.

5. Data inside a SmrtWare instance

If you are an employee, customer or supplier of a company that uses SmrtWare, contact that company, not us. They decide what is recorded, why, and for how long. They are the controller of that information; we are only the processor.

A SmrtWare instance holds the business records the customer company puts into it — customers and suppliers, invoices and bills, jobs and budgets, timesheets and payroll figures. Where the customer runs the instance on their own hardware, we hold none of it at all and have no access to it.

Where we host an instance for a customer, we act only on that customer's documented instructions. Our commitments are:

Where the GDPR applies, these terms are set out in a data processing agreement under Article 28, available to customers on request.

6. Where data is held, and international transfers

This website and any instance we host run on servers in the European Union (Germany). Our business email and office systems are provided by Microsoft and may be processed in Canada, the European Union and the United States.

Where personal information moves between countries we rely on the appropriate safeguard for that route, such as the European Commission's Standard Contractual Clauses, or an adequacy decision where one exists.

For Saudi customers, stated plainly. The Saudi Personal Data Protection Law restricts transferring personal data outside the Kingdom. Hosting a Saudi company's instance on a European server is such a transfer. A Saudi customer who needs their data to remain in the Kingdom should tell us before deployment: an instance can be run on the customer's own hardware in Saudi Arabia, or on a Saudi region of a cloud provider. Do not assume the default European hosting satisfies your PDPL obligations.

7. Your rights

These rights apply to the information we hold as controller — that is, this website and your correspondence with us. For information held inside a customer's SmrtWare instance, contact that company.

If you are in the European Economic Area or the United Kingdom (GDPR)

You may ask us to give you access to your personal data; correct it; erase it; restrict how we use it; or provide it in a portable form. You may object to processing we base on legitimate interests. You may withdraw consent at any time. You may complain to your national supervisory authority — in Ireland the Data Protection Commission, in Germany your state authority, in the United Kingdom the Information Commissioner's Office.

If you are in Canada (PIPEDA)

You may ask what personal information we hold about you, how we have used it and to whom we have disclosed it; ask us to correct it; and withdraw consent, subject to legal and contractual limits. You may challenge our compliance with us first, and then complain to the Office of the Privacy Commissioner of Canada. If a breach of our security safeguards creates a real risk of significant harm to you, we will report it to the Commissioner and notify you.

If you are in Saudi Arabia (PDPL)

You may be informed of the legal basis for collecting your personal data; access it; request a copy in a readable format; ask us to correct, complete or update it; and ask us to destroy it where it is no longer needed. You may complain to the Saudi Data and Artificial Intelligence Authority.

If you are in California (CCPA/CPRA)

You may request the categories and specific pieces of personal information we have collected, the sources, the purpose and the categories of recipients; request deletion; request correction; and opt out of any sale or sharing. We do not sell or share personal information, and we do not use or disclose sensitive personal information beyond what is necessary to provide our service. We will not discriminate against you for exercising a right.

How to exercise any of them

Email the address in section 10. We will respond within the time the applicable law allows — one month under the GDPR, 30 days under PIPEDA, 45 days under the CCPA — and we may need to verify who you are before we act. There is no charge unless a request is manifestly unfounded or excessive, and we will say so before charging anything.

8. Security

We protect personal information with measures appropriate to its sensitivity: encryption in transit, access control and authentication, per-tenant isolation of hosted instances, logged administrative access, and regular backups whose restoration we test. No system is perfectly secure, and we do not claim otherwise.

9. Children

SmrtWare is business software. It is not directed at children, and we do not knowingly collect personal information from anyone under 16. If you believe a child has given us personal information, contact us and we will delete it.

10. Contact, and who is responsible

SMRTQ SOLUTIONS LIMITED, Ontario, Canada.
Privacy enquiries and rights requests: privacy@smrtq.ca
General contact: contact@smrtq.ca

We have not appointed a Data Protection Officer, and on our current scale we do not believe the GDPR requires one. If we appoint one, or an EU or UK representative, we will name them here.

11. Changes to this policy

If we change this policy we will update the effective date above and, where the change is significant and we have a way to reach you, tell you directly.