Privacy Policy

Last updated: July 23, 2026

1. Introduction & Scope

RapidAccess.ai ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard personal information across everything we do — our public website, our general interactions with you (such as marketing, contact-form submissions, and recruitment), and your use of the RapidAccess.ai application (the signed-in product).

By accessing or using our services, you agree to this Privacy Policy. If you do not agree, please discontinue use of our services.

2. Information We Collect

Website & General Interactions

Information you voluntarily provide:

  • Account information (name, email address, company name)
  • Contact-form submissions
  • Job-application information (name, email, LinkedIn profile)
  • Communications you send to us

We do not run third-party analytics, and we do not set tracking or advertising cookies on our website. As with any website, some limited standard technical data is processed by our hosting and infrastructure providers when you visit — for example, to operate, secure, and troubleshoot the site. We do not use this information to identify you or to build marketing profiles, and we do not sell it.

The RapidAccess.ai Application

When you use the application, we handle three categories of customer data:

  • Account & identity — your name, email, role, and organization membership — to authenticate you and control access to the modules your organization has purchased.
  • AI chat conversations — the full text of your chat messages and the assistant's replies, conversation titles, and timestamps — so you can revisit and continue past conversations, and to support quality assurance and product improvement (see Section 3).
  • Web engagement & usage — which features you access and when, session activity, standard technical information (browser/device type and IP address), and usage counters — to operate and secure the service and measure usage against your plan.

Your application data is isolated to your organization and is not readable by any other customer. The application is not designed to collect patient health information (PHI); please do not submit PHI through the service.

3. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve our services
  • Register your account and manage your subscription
  • Respond to your inquiries and provide customer support
  • Send service-related communications
  • Perform quality assurance and product improvement — we review AI interactions to find where the assistant produced a poor answer and improve the system. This is done by authorized personnel on a read-only basis, and is not used to train any model of our own.
  • Protect against fraud and unauthorized access
  • Comply with legal obligations

4. Artificial Intelligence

The application includes an AI assistant powered by a third-party enterprise AI provider's large language models, which we access under a paid, enterprise agreement. This AI provider is one of the service providers described in Section 5.

What is sent to the AI provider. To answer a question, we send the AI provider the text of your question (and relevant earlier turns in the same conversation) together with the context retrieved to ground the answer. The AI provider returns a generated response. We also send text to the AI provider to generate the vector embeddings used for search.

How the AI provider may use it. Because we use the service under enterprise (paid) terms, the AI provider acts as our data processor: it does not use your prompts or the generated responses to train or improve its models or other products, and inputs and outputs are not made available to its other customers.

We do not use your conversations to train any model of our own. If you would like more detail about our AI provider or the terms that govern our use of it, please contact us (Section 10).

5. How We Share Your Information

We do not sell or rent your personal information, and we do not share it with third parties for their own marketing purposes.

We share information only in the following limited circumstances:

  • Service providers: trusted vendors who help us operate the service (for example, cloud hosting and infrastructure, AI processing, and email delivery), under contractual data-processing terms
  • Legal requirements: when required by law, court order, or governmental authority
  • Business transfers: in connection with a merger, acquisition, or sale of assets

Cross-border processing. Some of our service providers operate outside Canada (primarily in the United States). Where that is the case, your information may be processed and stored in — and subject to the laws of — those jurisdictions, including lawful access by their authorities. We remain accountable for your information and require these providers to protect it under terms that provide a comparable level of protection. A current list of our sub-processors is available to customers on request.

6. Data Security & Safeguards

We apply technical and organizational controls appropriate to the sensitivity of the data:

  • Tenant isolation — application data is partitioned per organization, with no shared, cross-organization records.
  • Enforced access control — access rules are enforced at the data layer. Conversations are readable, editable, and deletable only by the user who created them; privileged operations are server-side only; and internal access is limited to authorized personnel for the purposes described here.
  • Encryption — data is encrypted in transit (TLS/HTTPS) and encrypted at rest.
  • Secrets management — service credentials are held in a managed secret store and never exposed to the browser.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

7. Standards & Compliance

  • Privacy law: we are committed to handling personal information in accordance with the privacy laws that apply to our customers, including Canada's PIPEDA, Quebec's Law 25, and California's CCPA/CPRA.
  • Infrastructure: we build on established cloud providers that maintain their own independent security certifications, such as SOC 2 and ISO 27001.
  • No health information: the application is not designed to collect or process patient health information (PHI).
  • Enterprise assurances: we can provide a Data Processing Agreement (DPA) and additional information about our security practices and sub-processors to enterprise customers on request.

8. Data Retention

  • Conversations are retained until you delete them or your organization's account is closed.
  • Diagnostic and usage records are retained only as long as they are needed for the reliability, billing, and product-improvement purposes described above; usage records are stored in aggregate.
  • Account and organization records are retained for the life of the account and for a reasonable period afterward, as needed to meet legal, accounting, and dispute-resolution obligations.

Default retention periods apply unless a different schedule is agreed in your organization's service agreement. Enterprise customers may request custom data-retention and deletion terms, which we will review on a per-account basis. We will delete or de-identify data sooner on request, subject to Section 9 and to legal retention requirements.

9. Your Privacy Rights & Choices

Depending on your location, you may have the right to:

  • Access the personal information we hold about you
  • Correct inaccurate or incomplete information
  • Request deletion of your personal information
  • Opt out of marketing communications
  • Request a copy of your data in a portable format

In the application, you can permanently delete any conversation at any time. You can also ask us to delete other information associated with your account. We respond to verified requests within 30 days, or tell you if we need more time as permitted by law.

Canadian residents have these rights under PIPEDA and, in Quebec, under Law 25; California residents have additional rights under the CCPA/CPRA. To exercise any of these rights, contact our Privacy Officer (Section 10).

Complaints. If you believe we have mishandled your personal information, please contact our Privacy Officer. If you are not satisfied with our response, Canadian residents may complain to the Office of the Privacy Commissioner of Canada (and, in Quebec, the Commission d'accès à l'information).

10. Privacy Officer & Contact

Our Privacy Officer is accountable for the personal information under our control, including information handled by our service providers. You can reach the Privacy Officer at the address below. The Privacy Officer's identity is disclosed to users within the application and is otherwise available on request.

Privacy Officer: privacy@rapidaccess.ai
General inquiries: contact@rapidaccess.ai

11. Cookies and Tracking

Our website does not use tracking or advertising cookies, and we do not run third-party analytics. If we introduce cookies or analytics in the future, we will update this policy and obtain consent where required.

12. Children's Privacy

Our services are not directed to individuals under 18. We do not knowingly collect personal information from children. If we become aware of such collection, we will delete the information promptly.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page with a revised "Last updated" date. Your continued use of our services constitutes acceptance of the updated policy.