eave Privacy Policy
Effective date: 26 September 2026
northLo Software Consulting, operating as “eave” (“northLo,” “we,” “us,” or “our”), respects your privacy. This Privacy Policy explains how we collect, use, disclose, protect, and retain personal information in connection with:
- eave Puck;
- eave Clip;
- eave Line;
- the eave iOS and Android application;
- the eave website and public marketing or landing pages;
- eave accounts and related services; and
- the eave developer platform and application programming interface.
Our mailing address is Moncton, New Brunswick, Canada E1G 0B3. Our Privacy Officer and privacy contact is:
Privacy Officer
northLo Software Consulting
Moncton, New Brunswick, Canada E1G 0B3
Email: support@eaveapp.ca
This Privacy Policy is written in plain language. If you are a Quebec resident, you may request a French version by contacting support@eaveapp.ca.
1. The eave service
eave is a real-time scam-detection product family. Depending on the device and configuration, eave captures audio when a telephone call or conversation begins and streams the audio live to the eave AI backend.
- eave Puck and eave Clip stream audio through Bluetooth to the eave application and backend.
- eave Line streams audio through Wi-Fi to the eave backend.
- The eave AI analyzes the conversation in real time for scam patterns, including gift-card requests, fake bank, government, grandchild, or technical-support impersonation, urgency and pressure tactics, and claims that an account has been compromised.
- When the analysis indicates a potential scam, the eave application may trigger a vibration, voice warning, or optional notification to trusted safety contacts designated by the user.
Audio is not saved as a recording
The audio stream is processed transiently and in real time. eave does not save the audio as a recording, and does not maintain a library of audio recordings or conversation transcripts.
The real-time stream is used to provide scam detection and alerts. Detection results, alert history, device information, account information, and related service records may be retained as described in this Privacy Policy, but those records are not an audio recording or transcript library.
Each eave device includes privacy controls:
- a physical hardware mute switch that physically cuts the microphone; and
- a status LED indicating when the device is actively listening.
eave Line also includes a hardware-gated “Listen” LED and a privacy switch. Users should rely on the physical controls and visible LED indicators when deciding whether to enable or disable listening.
2. Personal information we collect
The information we collect depends on how you use eave.
Account and contact information
When you create or use an eave account, we may collect:
- your name;
- email address;
- account credentials or authentication information;
- account preferences;
- device registrations and identifiers;
- subscription status;
- customer-service history; and
- information you provide when contacting us.
Device and application information
We may collect information needed to operate, secure, troubleshoot, and improve the service, including:
- device type and model;
- device serial number or other device identifier;
- application version;
- operating system;
- connectivity and configuration information;
- battery and device-status information;
- mute and listening-state information;
- service logs;
- error reports; and
- information about the operation of eave devices and the application.
Apple App Store and Google Play may independently collect information relating to app distribution, app-store analytics, crash reporting, device operation, and app use. Their collection and use of information are governed by their own privacy policies and terms.
Audio and detection information
When listening is enabled, eave processes the live audio stream captured by the device. The audio is analyzed for scam patterns and is not saved as a recording or transcript library.
The system may generate information such as:
- whether an alert was triggered;
- the type or category of suspected scam pattern;
- a scam-risk score or classification;
- the time and duration of a detection event;
- device and connection information associated with the event; and
- alert-delivery information.
Voice and conversation audio can contain personal information about the user and other people present or participating in a call. It may also reveal sensitive information. Users must use eave lawfully and are responsible for providing any notices and obtaining any consents required before capturing or processing conversations under the laws that apply to them.
Trusted safety contacts
eave allows a user to designate trusted safety contacts to receive optional scam alerts. The user may provide a contact’s name, telephone number, email address, or other delivery information needed to send the alert.
By designating a trusted safety contact, the user represents that they have the authority or consent needed to provide that person’s information and authorizes eave to contact that person for the selected safety-alert purpose. The designated contact may receive an alert and information needed to understand that an eave alert was sent.
A user may remove or change trusted safety contacts through the application or by contacting support@eaveapp.ca.
Payment information
When devices or subscriptions are purchased through the eave website, payment processing is provided by Stripe. We do not store full payment-card numbers. Stripe receives and processes payment information under Stripe’s own terms and privacy practices.
We may receive limited payment-related information from Stripe, such as:
- payment status;
- transaction or invoice information;
- subscription status;
- payment method type;
- partial payment details used for identification or customer support; and
- fraud-prevention or transaction information provided by Stripe.
Support information
If you contact support@eaveapp.ca, we may collect the information you provide, including:
- your name and contact details;
- account or device information;
- the content of your request;
- troubleshooting information;
- attachments or other information you voluntarily provide; and
- records of our communications with you.
A third-party email or helpdesk provider is used to operate the support@eaveapp.ca inbox and may process support information on our behalf.
Website and landing-page information
Our website and public marketing or landing pages may collect information such as:
- browser and device information;
- IP address;
- approximate location inferred from IP address;
- pages viewed;
- referral information;
- interaction and usage information; and
- information submitted through forms.
The public marketing or landing page is hosted on the Marblism platform. The Marblism-hosted landing page may set its own cookies or similar technologies. Marblism’s handling of information and cookies may be governed by Marblism’s own terms and privacy practices.
Developer platform information
Developers and hardware or telephony companies may integrate the eave scam-detection engine into their own products through the eave developer platform or application programming interface.
Where a developer customer submits information to eave for processing:
- the developer customer is generally the controller or organization responsible for its end users’ personal information;
- eave processes that information on the developer customer’s instructions and under the applicable developer agreement;
- the developer customer is responsible for providing its own privacy notices and obtaining any required consents; and
- the developer customer’s end users should generally direct privacy requests to that developer customer first.
We may also process developer account, billing, authentication, technical-support, usage, and security information as an organization providing the developer platform.
3. How we use personal information
We use personal information for the following purposes:
- providing, operating, and maintaining eave;
- processing live audio for real-time scam detection;
- generating scam-risk alerts and delivering them to the user;
- sending optional alerts to trusted safety contacts selected by the user;
- pairing, authenticating, configuring, and securing eave devices and applications;
- providing customer support and responding to inquiries;
- processing purchases, payments, subscriptions, refunds, and returns;
- preventing fraud, abuse, unauthorized access, and security incidents;
- diagnosing errors and improving reliability;
- maintaining service records and account history;
- complying with legal, tax, accounting, regulatory, and law-enforcement obligations;
- enforcing our agreements and protecting our rights, users, and property;
- operating and securing the developer platform;
- understanding service performance and improving our products; and
- sending service-related communications.
We do not use live audio to create a permanent recording or transcript library.
We do not sell or monetize personal information. We do not use personal information for cross-context behavioural advertising.
Where consent is required, we obtain consent before collecting, using, or disclosing personal information. For voice or audio processing, consent is express and purpose-specific where required by law and is obtained separately from acceptance of the Terms of Service where required.
4. Legal bases and consent
Depending on the jurisdiction and circumstances, we rely on one or more of the following bases for processing personal information:
- your meaningful, informed, and express consent;
- providing the service you requested;
- performing a purchase, subscription, or other agreement with you;
- complying with legal obligations;
- protecting users, systems, and the public from fraud or security threats; and
- other lawful purposes permitted by applicable privacy law.
Before asking for consent, we aim to explain:
- what information will be collected;
- why it will be collected;
- how it will be used;
- with whom it may be disclosed;
- whether it may be processed outside the jurisdiction where it was collected;
- the consequences of refusing or withdrawing consent; and
- how consent may be withdrawn.
Consent requests for audio processing are separate from the Terms of Service where required. Consent for optional trusted safety contacts and optional marketing communications is also separate from consent necessary to provide core service functionality.
You may withdraw consent at any time, subject to legal or contractual restrictions. You can stop audio processing by using the applicable physical mute switch or privacy switch, by disabling the relevant feature in the application, by deleting your account, or by contacting support@eaveapp.ca. Stopping audio processing may prevent eave from providing real-time scam detection.
Withdrawal does not affect processing that occurred before withdrawal or processing that we are permitted or required to continue under law.
5. Disclosure of personal information
We may disclose personal information to the following categories of recipients for the purposes described in this Privacy Policy.
Microsoft Azure
Microsoft Azure hosts our backend processing and storage. The eave backend and customer data are hosted in the Microsoft Azure Canada Central region in Canada. Azure may process live audio, detection information, account information, technical information, and other data needed to provide eave.
Stripe
Stripe processes payments for device purchases and subscriptions. We do not store full payment-card numbers. Stripe may process payment information, transaction information, billing information, and fraud-prevention information.
Apple App Store and Google Play
Apple App Store and Google Play distribute the eave application and may process app-distribution, app-store analytics, and crash-reporting information. Their processing is governed by their own terms and privacy practices.
Email and helpdesk provider
A third-party email or helpdesk provider operates the support@eaveapp.ca inbox and may process support communications, contact information, account information, and information included in support requests.
Marblism
The public marketing or landing page is hosted on the Marblism platform. Marblism may process information collected through that page and may set its own cookies or similar technologies.
Trusted safety contacts
If a user chooses to use the trusted safety contacts feature, we disclose the alert and information needed to deliver it to the contacts selected by that user.
Legal, safety, and business disclosures
We may disclose personal information where reasonably necessary to:
- comply with a court order, law, legal process, or regulatory request;
- respond to a lawful government or law-enforcement request;
- investigate fraud, abuse, security incidents, or suspected unlawful activity;
- protect the rights, safety, and property of eave, our users, or others;
- establish, exercise, or defend legal claims;
- enforce our agreements; or
- support a financing, restructuring, reorganization, merger, acquisition, sale of assets, or similar business transaction, subject to applicable privacy requirements.
We require service providers that process information for us to use it only for authorized purposes, protect it appropriately, and comply with applicable contractual and legal obligations.
6. Storage location and international processing
Customer data for the eave backend is hosted and stored in Microsoft Azure’s Canada Central region in Canada.
Some limited information may be processed outside Canada by third parties involved in operating the service, including:
- Apple App Store;
- Google Play;
- Stripe; and
- the third-party email or helpdesk provider used for support@eaveapp.ca.
These providers may process information in the jurisdictions where they or their service providers operate. Their processing is governed by their own terms, privacy policies, contractual obligations, and applicable transfer safeguards.
We may be required to disclose information to courts, law-enforcement agencies, regulators, or other authorities in Canada or another jurisdiction where we are legally required to do so.
7. Retention and deletion
We retain personal information only for as long as reasonably necessary for the purposes described in this Privacy Policy, including legal, tax, accounting, security, fraud-prevention, dispute-resolution, and service-management purposes.
Audio
Live audio is processed transiently for real-time detection. Audio is not retained as a recording and is not maintained in a transcript library.
Detection events and alert history
Detection events, alert history, scam-risk results, and related technical records may be retained while an account is active and for a limited period afterward to meet legal, tax, security, fraud-prevention, accounting, and dispute-resolution obligations. After the applicable need ends, the information is deleted or anonymized.
Users may delete alert history in the application where that functionality is available or by contacting support@eaveapp.ca.
Account and device records
Account, device, subscription, and transaction records are retained while needed to provide the service and for a limited period after account closure where necessary for legal, tax, accounting, fraud-prevention, security, or dispute-resolution purposes. They are then deleted or anonymized in accordance with our retention practices.
Support communications
Support emails and helpdesk records are retained as needed to respond to the request, provide support, maintain an appropriate service record, address disputes, and meet legal or security obligations. They are deleted or anonymized when those purposes no longer require retention.
Backups
Information may remain temporarily in routine backups until those backups are securely overwritten or otherwise deleted in the ordinary course of our backup and security processes.
Users may close their account in the application where available or by emailing support@eaveapp.ca. Closing an account does not require us to delete information that we must retain under law or that is reasonably necessary to establish, exercise, or defend legal claims, prevent fraud, or maintain security.
8. Security safeguards
We use safeguards appropriate to the sensitivity and nature of the information we process. These safeguards include, as appropriate:
- encryption in transit;
- encryption at rest;
- access controls;
- least-privilege internal access;
- authentication and authorization controls;
- monitoring and logging;
- security processes for service providers;
- physical and technical device privacy controls; and
- hosting and backend storage in Microsoft Azure Canada Central.
No method of transmission, storage, or processing is completely secure. We cannot guarantee absolute security. If we determine that a privacy or security incident requires notice under applicable law, we will provide notice as required.
9. Artificial intelligence, profiling, and automated decisions
eave uses artificial intelligence to analyze conversations in real time for patterns associated with scams. The system may generate a scam-risk score, classification, or alert.
The AI generates a scam-risk alert only. An eave alert is advisory and may be inaccurate, incomplete, delayed, or unavailable. eave does not guarantee that it will detect any particular scam.
No automated decision made by eave produces legal effects or similarly significant effects about a person. eave does not use scam-risk alerts to determine a person’s eligibility for credit, employment, insurance, housing, education, government benefits, or other comparable opportunities.
Users remain responsible for deciding how to respond to an alert. An alert is not a determination that a person is dishonest or that a conversation is fraudulent.
10. Cookies and similar technologies
Our website and public marketing or landing pages may use cookies, pixels, local storage, and similar technologies.
Essential technologies
Essential cookies and similar technologies may be used to:
- operate and secure the website;
- remember basic preferences;
- support forms or requested functionality; and
- prevent fraud or misuse.
These technologies may be necessary for the website to function.
Non-essential technologies
Where used, non-essential cookies or similar technologies may help us understand website traffic, measure performance, or improve the website. We do not use cookies for cross-context behavioural advertising.
The Marblism-hosted landing page may set its own cookies or similar technologies. We do not control all cookies that Marblism may use. You should review Marblism’s applicable privacy information for details about its practices.
You can control or restrict cookies through your browser settings and, where available, through cookie-preference tools provided on the website. Disabling cookies may affect website functionality. Because browser settings differ, the available controls depend on the browser and device you use.
11. Electronic communications and CASL
We may send service-related electronic messages, including account notices, security messages, purchase confirmations, subscription notices, device information, support responses, and important changes to the service.
Where we send commercial electronic messages under Canada’s Anti-Spam Legislation, we obtain the required consent, identify the sender, and provide a readily usable unsubscribe mechanism.
The sender is:
northLo Software Consulting, operating as eave
Moncton, New Brunswick, Canada E1G 0B3
support@eaveapp.ca
You may unsubscribe from commercial or marketing communications by using the unsubscribe mechanism in the message or by contacting support@eaveapp.ca. Unsubscribing from marketing communications does not necessarily stop service, security, transactional, or legally required communications.
12. Your privacy rights
Depending on where you live and subject to applicable legal exceptions, you may have the right to:
- request access to personal information we hold about you;
- request information about how we collect, use, and disclose your personal information;
- request correction of inaccurate or incomplete information;
- request deletion of personal information;
- withdraw consent;
- request a copy of certain information in a structured, commonly used, and machine-readable format;
- object to or restrict certain processing;
- request cessation of dissemination of personal information in circumstances provided by law;
- request de-indexing or removal of links to personal information in circumstances provided by law;
- opt out of targeted or cross-context behavioural advertising;
- appeal a decision concerning a privacy request where applicable; and
- make a complaint about our privacy practices.
We will consider requests in accordance with applicable law. Some information may be exempt from access or deletion, including information we must retain for legal, security, fraud-prevention, accounting, tax, or dispute-resolution purposes.
How to make a request
Send a privacy request to support@eaveapp.ca and include:
- your name;
- the email address associated with your account, if applicable;
- the nature of your request;
- enough information for us to understand and process it; and
- any information needed to communicate with you securely.
We may need to verify your identity before providing information, making changes, or completing a deletion request. We will request only information reasonably necessary for verification and will not use verification information for unrelated purposes.
We generally respond to access and correction requests within the time required by applicable law. Where PIPEDA applies, requests are generally handled within 30 days, subject to lawful extensions. California requests are generally handled within the periods required by the CCPA and CPRA, subject to permitted extensions and exceptions.
You will not be denied goods or services, charged a different price, or otherwise discriminated against for exercising privacy rights, except where a difference is permitted by applicable law.
13. Quebec residents and Law 25
For Quebec residents, we provide this Privacy Policy in clear and simple language and explain:
- the categories of information we collect;
- the purposes for collection, use, and disclosure;
- the means by which information is collected;
- the third parties that may process information;
- the possibility that limited information may be processed outside Canada;
- retention and destruction practices;
- security safeguards;
- how consent may be withdrawn;
- access and correction rights;
- deletion and destruction requests;
- portability requests;
- requests for cessation of dissemination;
- requests for de-indexing; and
- how to contact our Privacy Officer.
Where required by Quebec law, we obtain express, informed, specific, and separate consent before collecting, using, or disclosing sensitive personal information, including voice or audio information. Consent is separate from acceptance of the Terms of Service where required.
Quebec residents may request:
- access to their personal information;
- rectification or correction;
- deletion where permitted;
- portability in a structured, commonly used, and technological format where required;
- cessation of dissemination where provided by law; and
- de-indexing or removal of links to personal information where provided by law.
We will assess requests for cessation of dissemination or de-indexing under applicable law. We cannot control search engines, websites, or third parties that independently publish or index information, but we will take reasonable steps concerning information within our control where a request is legally valid.
Quebec residents may request a French version of this Privacy Policy by contacting support@eaveapp.ca.
14. California residents
This section applies to California residents to the extent the California Consumer Privacy Act, as amended by the California Privacy Rights Act, applies to our processing.
Categories of personal information
During the preceding 12 months, we may have collected the following categories of personal information:
- identifiers, such as name, email address, device identifier, account identifier, and IP address;
- commercial information, such as purchase, subscription, transaction, and payment-status information;
- internet or electronic network activity information, such as application, device, browser, connectivity, and website interaction information;
- audio or sensory information, consisting of live audio processed for real-time scam detection and not retained as a recording;
- geolocation information, such as approximate location inferred from IP address where available;
- professional or business information for developer customers;
- inferences, such as scam-risk scores, classifications, or alert results generated by the eave service; and
- other information reasonably capable of being associated with you that you provide to us.
Voice data may constitute sensitive personal information under California law. We use voice data to provide real-time scam detection and related security and service functions. We do not sell or share voice data for advertising or unrelated purposes.
Sources
We collect information:
- directly from users;
- from eave devices and the eave application;
- from payment and app-store providers;
- from support communications;
- from developer customers; and
- automatically through websites, applications, devices, cookies, and similar technologies.
Purposes
We collect and use these categories for the purposes described in this Privacy Policy, including providing eave, processing audio in real time, generating alerts, processing payments, providing support, maintaining security, preventing fraud, improving reliability, and complying with law.
Sale and sharing
We do not sell personal information for monetary or other valuable consideration. We do not share personal information for cross-context behavioural advertising or targeted advertising.
Accordingly, we do not sell or share personal information as those terms are defined under the CCPA and CPRA. Service providers and contractors that process information on our instructions for hosting, payment processing, app distribution, analytics, crash reporting, or support are not permitted to use the information for independent purposes beyond their authorized services.
California rights
Subject to legal exceptions and verification requirements, California residents may have the right to:
- know the categories and specific pieces of personal information collected;
- know the sources, purposes, and categories of recipients;
- request deletion;
- request correction of inaccurate information;
- opt out of the sale or sharing of personal information;
- limit the use and disclosure of sensitive personal information;
- receive equal treatment for exercising privacy rights; and
- use an authorized agent to submit a request where permitted.
Because we do not sell or share personal information as defined by the CCPA and CPRA, there is no sale or sharing to opt out of. We also do not use sensitive personal information for purposes requiring a California right to limit its use beyond the purposes described in this Privacy Policy.
Requests may be submitted to support@eaveapp.ca. We verify identity before acting on requests to know, delete, or correct, using procedures appropriate to the sensitivity of the request and the potential risk of unauthorized disclosure. We will not require you to create an account to make a request, although we may require reasonable information to verify your identity.
We generally respond to verified California requests within 45 days, subject to permitted extensions and exceptions. If we deny a request, we will explain the reason where required and provide information about available appeal rights.
15. Residents of other United States states
Residents of other US states may have rights under applicable state privacy laws, including rights to:
- access or confirm whether personal information is processed;
- obtain a copy of personal information;
- correct inaccurate personal information;
- delete personal information;
- opt out of targeted advertising;
- opt out of certain profiling or automated decisions;
- opt out of the sale of personal information;
- appeal the denial of a privacy request; and
- exercise privacy rights without unlawful discrimination.
We do not sell personal information or use personal information for targeted or cross-context behavioural advertising. We will honour applicable state privacy rights and appeals processes. Requests may be made by contacting support@eaveapp.ca.
16. Children
eave is intended for people who are 18 years of age or older. The service is not directed to or intended for minors.
We do not knowingly collect personal information from anyone under 18. If we learn that an account belongs to a person under 18, we will close the account and take reasonable steps to delete the associated personal information, subject to information we are required or permitted to retain under applicable law.
If you believe that a person under 18 has provided personal information to us, please contact support@eaveapp.ca.
17. Developer and API customers
Developer customers are responsible for determining the lawful basis for processing their end users’ information and for providing appropriate privacy notices, consent requests, audio notices, and rights mechanisms.
When acting as a processor or service provider for a developer customer, eave:
- processes information on the developer customer’s documented instructions;
- uses the information to provide the contracted developer services;
- applies appropriate contractual and technical safeguards;
- does not sell or monetize the developer customer’s end-user information; and
- assists the developer customer with privacy obligations where required by the applicable agreement and law.
An end user whose information is submitted through a developer integration should generally contact the relevant developer customer to exercise privacy rights. We may direct requests to the responsible developer customer where that customer controls the relevant information.
18. Privacy accountability and PIPEDA principles
We are accountable for personal information under our control. Our Privacy Officer is responsible for overseeing this Privacy Policy, privacy inquiries, access and correction requests, consent practices, complaints, and privacy compliance.
Our privacy program is based on the ten fair information principles recognized under Canada’s Personal Information Protection and Electronic Documents Act:
- Accountability. We identify the Privacy Officer responsible for privacy compliance and maintain responsibility for information processed by service providers on our behalf.
- Identifying purposes. We identify the purposes for collecting, using, and disclosing personal information before or when it is collected.
- Consent. We seek meaningful, informed consent. We obtain express, purpose-specific consent for voice and audio processing where required and obtain consent separately from the Terms of Service where required.
- Limiting collection. We collect information that is reasonably necessary for the purposes described in this Privacy Policy and do not collect live audio for a permanent recording or transcript library.
- Limiting use, disclosure, and retention. We use and disclose personal information only for identified purposes, permitted related purposes, legal purposes, or other purposes authorized by law. We retain information only as long as reasonably necessary.
- Accuracy. We take reasonable steps to keep account, transaction, support, and other information accurate, complete, and current for the purposes for which it is used. Users may request correction.
- Safeguards. We use physical, technical, and organizational safeguards appropriate to the sensitivity of the information, including encryption, access controls, least-privilege access, and secure hosting.
- Openness. We make our privacy practices available through this Privacy Policy and identify our Privacy Officer and contact information.
- Individual access. Individuals may request access to their personal information and information about its use and disclosure, subject to lawful exceptions.
- Challenging compliance. Individuals may raise a privacy concern or complaint with our Privacy Officer. We will investigate complaints and respond as required by applicable law.
19. Complaints and regulatory recourse
Please first contact our Privacy Officer at support@eaveapp.ca so that we can investigate and attempt to resolve your concern.
If you are not satisfied with our response, you may have the right to contact the privacy regulator with jurisdiction over your concern, including:
- the Office of the Privacy Commissioner of Canada for matters within its jurisdiction;
- the Commission d’accès à l’information du Québec for matters within its jurisdiction; or
- the applicable state privacy regulator or attorney general in the United States.
20. No emergency service or guarantee
eave is not an emergency service. It does not contact emergency services, banks, police, medical providers, or other authorities on your behalf unless a separate service explicitly states otherwise.
eave is not a substitute for professional, legal, financial, medical, safety, or law-enforcement advice. Users should independently assess calls, conversations, and alerts and contact appropriate professionals or authorities when necessary.
Because scam methods change and technology can fail, eave does not guarantee detection of any particular scam, fraud, impersonation, or unsafe conversation. Alerts may be delayed, inaccurate, incomplete, or unavailable because of device settings, mute status, connectivity, power, background noise, language, speech, system failures, or other circumstances.
21. Changes to this Privacy Policy
We may update this Privacy Policy to reflect changes in our services, technology, legal obligations, vendors, or privacy practices.
When we make material changes, we may provide notice through the eave application, website, email, account notifications, or another appropriate method. Where applicable law requires renewed consent, we will request it.
The effective date appears at the beginning of this Privacy Policy. The current version will be made available through the eave website or application.
22. Contact us
For privacy questions, access requests, correction requests, deletion requests, consent withdrawals, complaints, or other privacy concerns, contact:
Privacy Officer
northLo Software Consulting, operating as eave
Moncton, New Brunswick, Canada E1G 0B3
support@eaveapp.ca
New Brunswick, Canada is the governing jurisdiction for this Privacy Policy to the extent permitted by applicable law. Mandatory privacy rights and protections in the jurisdiction where you live continue to apply.