Where your data goes, and under what safeguards.
Last updated: August 3, 2026
An agency that deploys AI agents processes personal information on behalf of its clients. You should be able to verify how, where, and under what safeguards before you sign. This page answers those questions. For data collected by the alivro.ca site itself, see the privacy policy.
01. Who owns what
The rule is simple: you own your data and your systems; Alivro operates the delivery infrastructure that runs the agents.
- You keep: your CRM or system of record (Jobber, HubSpot, QuickBooks, other), your domain and DNS, your accounting, your business identity. Agents integrate with them; they never replace them.
- Alivro operates: the infrastructure that runs the agents (hosting, telephony, observability), under its accounts, covered by the monthly operating fee. One invoice, not five subscriptions to manage.
- Exit is structural, not promised: the A2P sender brand and phone number are registered under your legal entity and move with you if you leave; verified email domains stay under your DNS, revocable; code and data are exported in full on termination.
02. The processing stack
Here is who processes what in a typical agent deployment. The exact list for your deployment appears in the privacy page published on your domain (see section 05).
Transfers outside Québec are covered by a privacy impact assessment before each deployment, as required by Law 25.
03. What the AI sees, and does not
- The agent accesses only the data its task requires: a scoped mirror, not open access to your CRM.
- Every interaction is traced in a reviewable audit log. No black box.
- Data submitted to Anthropic’s API is not used to train models, per current commercial terms.
- No sale of data. No sharing for advertising purposes.
- Human supervision is included in the monthly operation: conversations are reviewed, drift is corrected.
04. Technical controls in place
Real controls, in production today, not a list of intentions:
- Consent presented at the first interaction, in the user’s language, and logged per user.
- On this very site: no pixel or measurement tool activates before your granular consent.
- Signed and verified webhooks (HMAC) between systems.
- Key-protected internal dashboards.
- Least privilege: when an agent reads a Microsoft 365 mailbox, an application access policy restricts access to that single mailbox, with certificate authentication.
- Continuous monitoring with an out-of-band alert: if an agent goes silent, we learn it through a channel other than the agent itself.
05. The Law 25 compliance kit, included with every agent
Your company's compliance cannot be a brochure promise. Every Alivro deployment includes, at no extra charge:
- A privacy page published on your domain, covering every subprocessor in your deployment.
- A consent disclosure at each user’s first interaction with the agent, logged per user.
- A reviewable consent register in case of an audit.
- CASL alignment for commercial communications: clear identification, functional unsubscribe.
No agent goes to production without this kit. It is a delivery condition, not an option.
06. Retention and exit
- Retention periods are defined per deployment and documented in your company’s privacy page.
- Cancel anytime: you leave with a full export of code and data, and we assist the transition.
07. Incidents
In the event of a privacy incident presenting a risk of serious harm, we notify the affected persons and the relevant authorities without undue delay, and we maintain an incident register, as required by Law 25.
08. Your rights and contact
Privacy officer: Matt Ruyssers, President. For any question about this page or your rights of access, rectification, or withdrawal: privacy@alivro.ca. The full detail of your rights is in the privacy policy.