Privacy Policy
Hexagen Technologies Inc. ("we", "us") provides a transportation management system. This policy explains what personal information we handle, why, and what you can do about it.
It is written for Canada. We handle personal information under the Personal Information Protection and Electronic Documents Act (PIPEDA) and the substantially similar provincial laws of Alberta and British Columbia.
The product is available across Canada, including Quebec, and is offered in English and French. Which language you read it in is your own setting.
1. Read this first: two very different situations
The product is available two ways, and which one applies to you changes almost everything in this policy.
| We host it (subscription) | You host it (licence) | |
|---|---|---|
| Where your operational data lives | Our infrastructure in Canada | Your infrastructure |
| Who we are, for that data | Your service provider, handling it on your instructions | Nobody — we never receive it |
| What we hold about you | Account, billing, support, and the data you load | Account, licence, billing, support only |
Sections 2 to 13 describe the hosted service. If you run the Software on your own infrastructure, read section 14 — it is short, and most of this policy does not apply to you.
2. Whose personal information this is about
Three groups, and the third is the one we take most care with:
- Our customers — the transport companies who subscribe, and the people at those companies who use the product
- People in our customers' records — contacts at their customers and carriers, and other individuals whose details a customer enters
- Drivers — who did not sign up for anything, and whose information is the most sensitive here. Section 5 is about drivers specifically
3. What we collect, and why
When you sign up and pay us
Your name, work email, phone number, company details, and your role. Where you pay by card, payment is handled by our payment processor — we do not store your full card number. We keep the subscription record, invoices and payment status. Where we set up an account for your organisation under an order, your organisation gives us the work email address of the person who will administer it, and their name if it gives one, and we use them to send that person their invitation.
We use this to give you access, bill you, provide support, and send service messages about your account.
When you use the product
Your operational records: loads, quotes, invoices, customers, carriers, drivers, equipment, documents, and the messages you send through the product. Much of this contains other people's personal information, which you entered.
We handle this on your instructions, to run the service for you. We do not sell it, and we do not use it to train machine-learning models. If you switch on the optional AI features, section 7 sets out exactly what they send and where it goes.
Automatically
Sign-in records, IP address, and application logs needed to run the service securely and diagnose problems — including a log of each request made to our web addresses, which section 8 describes.
When you connect another service
If you connect a telematics provider, an email mailbox, or an accounting system, we hold the credentials for that connection and the data it returns — vehicle positions, email messages and attachments, and accounting records.
Connecting an email mailbox means we sync message content and attachment metadata into the product. That is the point of the feature, and it is worth stating plainly.
4. Cookies
We use a small number of cookies, all of them necessary for the product to work. We do not use advertising cookies, and we have no analytics or tracking vendor.
| Cookie | Purpose |
|---|---|
p26-access-token | Keeps you signed in. Not readable by scripts |
p26-refresh-token | Renews your session. Not readable by scripts |
p26-brand-company | Remembers which company's branding to show on the sign-in page |
p26-return-to | Returns you to the page you were on after your session refreshes |
p26-render | Tells the page it is being rendered into a PDF, so it does not try to refresh a session it does not have |
p26-locale | Remembers whether to show the product in English or French. Readable by scripts, and kept for a year |
We also remember a few preferences in your browser's local storage — whether you dismissed the welcome tour, whether you collapsed the navigation or the mailbox rail, and when to next remind you about two-factor authentication. These never leave your browser and are not sent to us. Clearing your site data removes them.
5. Drivers
If you are a driver and your carrier uses this product, your carrier decides what information about you is collected and why. They are responsible for it; we handle it for them. Ask them first — but you can also contact us and we will help route your request.
What the product can hold about you: your name and contact details, your licence number, class, province of issue and endorsements, your assignments, photographs and documents you upload (such as proof of delivery), trip reports you file, your position while you are running a load, and — if your carrier switches on AI live tracking — the latest AI reading of your trip.
About location tracking, which is the part that matters most:
- Position is recorded only while a load is assigned to you or in transit, and stops when it is delivered. Off-duty tracking is not a supported use of this product
- Position can come from your truck's telematics device, from the mobile app, or from both. If you use the app and have given consent, it records your phone's position for those loads whether or not the truck also has a device
- The app asks for your consent before using your phone's location, and you can withdraw it. While tracking is on, the app shows that it is on
- Your carrier can share a tracking page with its customer that shows the truck's current position while that customer's freight is on it. That position comes only from the truck's telematics device, never from your phone, it is shown without your name or any other detail about you, and it stops at delivery
- Position history is kept for 90 days on our hosted service and then permanently deleted
- If your carrier switches on AI live tracking (section 7), every five minutes the product compares the sources reporting for your trip — the truck's device, your phone and, once the trip is in transit, the truck's last known position — and sends our AI provider, which may process it outside Canada, how many minutes old each one's latest position is, the speed it reported, and how many miles apart they are. It does not send your coordinates, any address, your name or your load number, and it does not store your position. That is still information about you: it can show that your phone has stopped reporting, has stopped moving, or is not where the truck is. The provider's reading of it — which source to believe, an arrival estimate, a status and a short note — is shown to your carrier's dispatchers and deleted once the trip is delivered or cancelled. It changes nothing on your trip and sends you nothing
Messages: we send you WhatsApp messages only if you have opted in, and your opt-in is recorded and can be withdrawn — replying STOP withdraws it. Your replies are recorded for 90 days on our hosted service and then deleted. If your carrier switches on the WhatsApp assistant (section 7), a question you type that is not an answer to something we asked you is sent to our AI provider, along with what the product reads from your own trips to answer it, and that provider may process it outside Canada. It is not shown your pay, another driver, or a trip that is not yours, and it cannot change anything on your trip or file anything for you.
Reports: a report your carrier runs can include you — your name, your trips and stops, your worked hours, whether you were on time and, for the people at your carrier allowed to see it, your pay. If your carrier switches on Hena AI or the scheduled report summary (section 7), rows of such a report can be sent to our AI provider, which may process them outside Canada. Neither can change anything on your trip or your pay.
This product is not an electronic logging device. It does not record your duty status or hours of service. Where your carrier's telematics provider reports them, the product reads your current duty status and remaining driving, on-duty and cycle time from that provider to show your carrier's dispatchers when they choose a driver, and saves none of it to its database; if your carrier switches on the dispatch features in section 7, these figures can be part of what is sent to our AI provider. A trip report you file is your own record of distance and expenses — it is not a logbook.
6. Who we share information with
We do not sell personal information.
We share it with service providers who help us run the product, and only for that purpose. Some of them support every account, whatever you use — hosting, the relay for our outbound email, and Google's address lookup among them. Others apply only if you switch on the feature or connect the integration that their line names:
- Cloud hosting and infrastructure — Microsoft Azure: our servers and your stored data in Canada, and the network edge that every connection to the product passes through, which is not confined to Canada (section 8)
- Payment processing — Stripe
- Email delivery — Apple, which relays our outbound mail
- Push notifications to the driver app, if your drivers use it — Expo, and then Apple's or Google's push service
- AI processing, only if you enable the AI features — Microsoft Azure AI Foundry. Section 7 explains what is sent and where it runs
- Telematics providers, if you connect one — Samsara, Motive, Geotab
- Email and productivity providers, if you connect a mailbox — Google, Microsoft
- Accounting providers, if you connect one — Intuit QuickBooks, Xero, Zoho Books
- Fuel card providers, if you connect one — WEX, Comdata, EFS
- Messaging providers, if you connect one — Twilio, Meta (WhatsApp), Bird (formerly MessageBird), Slack
- Address lookup and maps — Google, for every account: what is entered in an address field is sent to Google for suggestions, and the place picked is looked up and shown on a preview map. Road routes, and an interactive map that your browser loads directly from Google, are added where your account has the Google routing add-on
Maps your browser loads directly. Some maps are drawn from map images that the reader's browser fetches straight from a map provider, which then receives that reader's IP address and the area of the map being shown — our servers are not involved. On accounts with the Google routing add-on, that provider is Google. The tracking page a carrier can share with its customer, which anyone with the link can open, uses the OpenStreetMap Foundation's map service instead, as do the map screens of accounts on self-hosted routing, and those of any account when the product cannot confirm which routing add-on it has as the screen loads. The OpenStreetMap Foundation is an independent not-for-profit organisation based in the United Kingdom; our servers send it nothing, and where its servers answer a given request is not something we control. On a tracking page, the area shown is the one around the pickup and delivery points and, where the page shows it, the truck's current position.
The current list is maintained in our subprocessor list.
We may also disclose information where the law requires it, or to establish or defend a legal claim.
7. AI features
The AI features are an optional paid add-on. They are off by default, and each one has its own switch that an administrator of your company turns on. If nobody turns them on, nothing described in this section happens.
When a feature is on, the relevant information is sent to Microsoft Azure AI Foundry and a model produces a result — a suggestion, a reading or a summary for someone in your company in every case but one, the driver WhatsApp assistant, whose short reply is sent to the driver who asked. What gets sent depends on the feature:
| Feature | What is sent |
|---|---|
| Mailbox triage | For each conversation in a connected mailbox whose newest received message the product's own rules cannot sort: that message's sender name and address, its subject, whether it has attachments and the first 2,000 characters of its body, with — where it applies — a note that your company already corresponds with the sender, or that the conversation is filed against one of your records |
| Compose assist | The draft you typed and its subject line; for a draft written from scratch, what you said the email should do; and, where the message is linked to a load, that load's number, its lane as origin and destination city and province, the equipment, the pickup and delivery windows, the rate and the customer name |
| Hena AI — what you ask it | Your question (up to 400 characters), up to 12 earlier messages of the same conversation so that a follow-up makes sense, today's date in your company's time zone, and which screen you asked from |
| Hena AI — what it looks up to answer you | Your own company's records — whatever it looks up to answer, and nothing it did not look up. One list look-up sends up to 20 rows: for trips and orders, the number, the customer name, pickup and delivery dates, status, amount and currency, the lane as origin and destination city and province, the equipment type and the assigned driver's name; for invoices, the number, customer, issue and due dates, status, total, amount paid and balance; for customers, the name, status, city and province; for drivers, the name, whether they are free or on the road, how many open trips they hold, and where and when they last delivered; for trucks, the unit number, status, the trip it is on, the driver's name, how long ago its last position was reported, the kind and city of the stop it is heading to, and its estimated arrival. Opening one record sends each stop's city and province, scheduled time and window, whether it is an appointment, and any instructions typed on it — plus notes, reference numbers, invoice lines and payment totals. It can also send delivered orders that are not yet invoiced with what they come to, and up to 20 rows of a report. That can be one of the product's built-in reports — lists of trips, orders and invoices with their numbers, customer names, lanes, equipment, statuses, dates, amounts, amounts paid, balances, margins and carrier pay, or totals by driver, carrier, truck, customer, lane, status, charge type, expense category or jurisdiction, such as each driver's trips, stops, hours worked (first arrival to last departure — not hours of service) and on-time rate — or a report Hena groups itself by any column your role can read in the report catalogue. A report of that kind can make the group labels any such value, including a customer's billing email address or phone number, a carrier's or vendor's name, or a typed description or reference, and for the roles allowed to see driver pay it can total what each driver was paid. Counts and money totals are worked out over the whole set and sent as figures. Street addresses and GPS coordinates are not sent: a truck reaches the model as an age and a city, never as a position. Notes and stop instructions are sent as they were typed. Extracts of the product's own help pages may also be sent; they contain no personal information |
| Report drafting | The report you described (up to 2,000 characters); the list of report datasets and columns your role is allowed to use — names and descriptions, not your records; and, when you ask for a change to a report already in the builder, that report as it stands, including its name and any filter values typed into it, such as a customer name. No rows from your records are read or sent |
| Scheduled report summary | Nothing anyone typed, and no request from a person: when a report schedule you have set to send a CSV file also asks for a summary, each time that schedule runs the product computes a one-page summary of the report and asks the model for a short narrative over it. The report is read under the role of the person who last saved the schedule, and only a report of at most 2,000 rows is summarised. What is sent: the report's name, its date range and row count, and each column's label and type; for each numeric column, its total, average, lowest and highest value and how many rows held a value; money totals per currency; up to three breakdowns of a text, status or yes/no column, each naming the eight largest values in it with their row counts, shares and totals and one folded "Other" row — those values are the report's own cells, so they can be a customer's name, a carrier's or vendor's name, a driver's name, a status, a city, a typed description or reference or, in a customer report, a billing email address or phone number; a trend by day, week or month on the report's first date column; and the first 40 rows of the report as they appear in the CSV, every column included — which, depending on the report, can be trip, order and invoice numbers, customer names, driver names, lanes, dates, amounts, margins, carrier pay, worked hours and, for the roles allowed to see it, what each driver was paid. Text cells are cut at 120 characters. The report catalogue has no street-address, GPS-coordinate or licence-number column, so none is sent. The model answers with a headline, up to six highlights and up to four things to check; those sentences are printed at the top of the PDF, marked as written by AI, above charts and tables computed from the report, and the PDF is emailed with the CSV to the schedule's recipients, who are members of your company. The narrative is kept only inside that PDF, which is cleared a day after the run (section 9) |
| Explaining a dispatch suggestion | For one suggested driver and load: the driver's name, the load number and up to 12 of the reasons the product's own ranking gave for the suggestion. Those reasons can include the driver's availability and working pattern, approved time off, how long since their last load, where and when they come free, how far they are from the pickup, whether they hold a hazmat endorsement, whether their standing trailer fits and any truck or trailer paperwork lapsing, and the duty status and remaining driving time their telematics provider reports |
| Checking the dispatch plan | For each of up to 10 suggestions on the plan: the load's number, status, customer name, lane as origin and destination city and province, equipment, rate (unless your company has set the dispatch board to hide money), stated requirements and notes as typed; each stop's city and province, scheduled time and window, whether it is an appointment, and instructions as typed; and the suggested driver's name, licence class, hazmat endorsement and driver type, their availability and open loads, their standing truck and trailer unit numbers with whether each is ready and any registration, insurance or inspection lapsing before the pickup, the duty status and remaining driving, on-duty and cycle time their telematics provider reports, where and when they come free, their distance and drive time to the pickup, and the reasons the product's own ranking gave. No street addresses, coordinates or phone numbers |
| Autonomous dispatching | Nothing |
| Suggesting a response to a late load | When someone asks for a suggested response on a load that is late or at risk: the load number, how late it is expected to be and, where known, the assigned driver's name and how many minutes ago the load's position was last reported |
| Trip planner | What you typed into the planner's request box (up to 300 characters). For the "why this set" line on one proposed trip: order numbers, customer names, pickup and delivery city names, pallet position counts, whether a delivery is an appointment, the trailer type, the rule engine's verdicts, the spread in minutes between pickups, and the name of the driver ranked first to reach the first pickup, with whether they can reach it and the estimated distance. For the review of a whole day's plan: the day being planned, the off-route tolerance in miles you set, and, for each proposed trip, its order numbers, customer names, pickup and delivery city names, trailer type and rule verdicts, the pallet positions used against the trailer's capacity, the name of the driver the planner chose for that trip with whether they can reach its first pickup and the estimated distance, and the planner's own estimates for the trip — its miles, its minutes and how many of its stops the estimate reaches late — plus the order numbers the plan could not place with a reason code, and which of the plan's checks passed or failed. A day with nothing planned on it is not sent. No addresses, coordinates, phone numbers, prices or position history are sent |
| AI live tracking on the Power board | Nothing anyone typed, and no request from a person: a scheduled check every five minutes. For each trip that is assigned or in transit and has a driver or carrier assigned or a location source reporting, up to 40 trips in one request: a number that stands in for the trip within that request (not its load number); the trip's status; the product's own rule-based reading of the trip, such as on track, at risk, late or stale; for each location source that has reported — the truck's telematics device, the driver's phone, and, only once the trip is in transit, the truck's last known position — how many minutes old its latest position is and the speed it reported; how many miles apart each pair of those sources is; how many stops remain and the straight-line miles through them; the rule-based arrival estimate in minutes from now; and how many minutes that estimate falls after the delivery window, or before it. A trip checked in the last 10 minutes with no newer position from any source is not sent again that round. No GPS coordinates, no addresses, and no driver name, customer name or load number are sent. Where one of the sources is the driver's phone, those ages, speeds and distances are still information about that driver — section 5 tells drivers so |
| Driver questions on WhatsApp | The driver's typed WhatsApp message, as they wrote it, and what the product reads from that driver's own trips to answer it — the same trips the driver app shows them. That can include the trip's number, the customer name, the status, the dates and any typed notes; the equipment and unit numbers; for each of the driver's own stops the full street address, the scheduled time and window, whether it is an appointment, the stop reference and any instructions typed on it; and the paperwork still owed, with its labels and instructions. No money of any kind, no other driver, and no trip that is not that driver's — the answer is built from the driver's own trip view, which carries no rate, charge or pay, and a trip number that is not theirs is refused rather than looked up. Pay, hire and termination dates, and licence and medical-card expiry, are not part of it. No GPS coordinates are sent — a stop reaches the model as an address, never as a position. The driver's message itself is also recorded with their other WhatsApp replies, up to 4,096 characters of it, for 90 days — which happens whether or not this feature is on |
| Reading a quotation reply | When someone opens a mailbox conversation already filed against an order still awaiting the customer's answer: the order number, the total that was quoted, and the plain text of the customer's latest reply, up to 8,000 characters |
| Suggesting a price | Only when no lane rate or customer base fare is on file: the lane as origin and destination city and province, the equipment, the distance where known, the currency, and up to 8 of your delivered loads on the same lane with the same equipment in the last six months, each with its load number, total and delivery date |
| Expense statement import | For up to 300 of the statement's charges: each line's description as printed on the statement, and its amount. No dates are sent |
| Matching spreadsheet columns | When you import customers, carriers, drivers, trucks or trailers from a spreadsheet: the headings of the columns the product could not match itself, up to five example values from each of those columns, and the list of fields they might fill. The examples are whatever those columns hold — in a driver spreadsheet, they can be names, phone numbers or licence numbers |
| Branding suggestion | The logo or sample document you uploaded, as an image — the first page, where it is a PDF |
Mailbox triage is the one to read twice. It reads newly received mail in a connected mailbox on a schedule, rather than only what someone opens. If the mailbox you connect also carries personal correspondence, that correspondence is read too.
AI live tracking also runs on a schedule rather than when someone asks. Once it is on, the check runs every five minutes whether or not anyone has the board open, and every request it makes is metered like any other.
So does the scheduled report summary. Once a schedule asks for one, the summary is made each time that schedule runs, on the cadence set for it, whether or not anyone is signed in, under the role of the person who last saved the schedule — if that person leaves your company or loses that role, nothing is sent. Turning the feature off afterwards stops the summary and leaves the CSV going out as before.
Five things we commit to:
- Your data is not used to train models. We do not do it, and Microsoft's terms for this service commit that your prompts, responses and embeddings are not made available to the model's provider, are not used by that provider to improve its models, and are not used to train any foundation model or to improve Microsoft or third-party products or services without our explicit instruction. The models themselves are stateless — nothing you send is retained inside them.
- We do not keep the text we send. The prompt is not stored. What we record about each request is metering — which feature ran, whether it worked, how many tokens it used and how long it took.
- We keep an AI answer only where the answer is the feature. There are three such cases. Mailbox triage's label and its one-line summary of a thread are saved, because an inbox that had to re-read every message to show them would be both slower and more expensive. AI live tracking keeps one reading per trip — the source it chose, its arrival estimate and how far that falls from the delivery window, a status, a note of up to 280 characters and when the reading was made — replaced each time the trip is checked, so the board can show it without asking again. It holds no position, no speed and no source's reporting time, and section 9 says how long it stays. The scheduled report summary's narrative is kept only inside the PDF made for that run — the same file its recipients receive — while it waits to be emailed, and that file is cleared a day after the run (section 9); it is not saved anywhere else. Every other feature's answer is shown to you and not stored — a rewritten draft, an answer from Hena AI, an explanation of a suggestion.
- Microsoft screens requests for abuse of its service, and this is the one route by which someone outside our company could see one. Prompts and responses are checked automatically as they are processed. Where a pattern suggests the service is being misused, a sample may be selected for review — normally by automated systems that retain nothing, and in some cases by authorized Microsoft employees working under time-limited, individually approved access. Microsoft does not publish how long that review data is kept.
- No AI result changes your records by itself. Nothing an AI feature produces writes to a load, a trip, an invoice or any other record of your business, and almost every AI result is a proposal that a person accepts, edits or discards. AI live tracking is not a proposal: its reading is shown on the Power board, marked "AI", without anyone accepting it. It is checked against the evidence before it is stored and discarded if it does not fit, and it is shown only while the feature is still on and the reading is no more than 15 minutes old — otherwise the board shows the product's own reading, marked "Rule". It changes no status, records no arrival or delivery, and sends no notification. And two features' words reach people without being read first. The driver WhatsApp assistant's reply goes straight to the driver who asked it; it cannot mark a stop, file a document or change a trip, and when it cannot answer, the driver gets a fixed line pointing them at their trip message buttons and at dispatch. The scheduled report summary's narrative is emailed to the schedule's recipients, marked as written by AI, above charts and tables computed from the report; it changes nothing in the report and nothing in your records, and when the model cannot answer, the PDF goes out with the figures and a line saying no narrative was written.
Where the processing happens, honestly. Our AI provider account is in Canada, but the models run on a Global deployment, which means Microsoft may perform the processing in any of its regions worldwide. A Canada-only option is not currently offered for these models.
What does stay in Canada is anything stored. Under Microsoft's terms for a Global deployment, data held at rest — including the store used for the abuse review described above — remains in the region we designated, which is Canada. It is the live handling of a request that may happen elsewhere. We state both halves plainly rather than let section 8's statement that we store your data in Canada imply something it does not cover, and it is one of the reasons these features are off until you choose them.
8. Where your information is
Our hosted service stores your data in Canada (Azure Canada Central), and the servers that run it are there too. The route your connection takes to reach them is not confined to Canada, and neither are the few things described after it.
How your connection reaches us. Every request to our web addresses, tms.hexagen.ca and api.tms.hexagen.ca, reaches Microsoft's global network edge (Azure Front Door) first, rather than going straight to our servers — whoever or whatever makes it, and including the requests that carry your data when you use the product under your own company's web address. Microsoft answers each connection at one of its edge locations, normally one near the person connecting, and we cannot restrict those locations to Canada: someone connecting from outside Canada, or a request Microsoft routes around a fault or heavy traffic, can be handled at a location in another country. At that location the encrypted connection from your browser ends, and the request and its response are decrypted — so everything that passes between you and the product, including what you type and what the product shows you, is handled there — before being encrypted again and sent on to our servers in Canada. The edge counts the requests each IP address makes, to protect the service from abuse, and records those over its limit. It keeps cached copies of the product's own program files — the scripts, styles and images built into the product, which contain no personal information — and caches nothing else. Microsoft is already our hosting provider: the edge is the same provider handling the connection somewhere that may not be Canada, not a new one. We keep a log of each request that passes through it — the IP address it came from, the web address requested, what the browser reports about itself, the time and the result — in our log store in Canada, for 30 days (section 9).
Three more things sit outside Canada, and we disclose them rather than hide them. The AI features in section 7 run on a global model deployment, so Microsoft may process those requests in any of its regions. The service providers in section 6, and the map services a browser loads directly, operate wherever they operate. And a photograph or document a driver captures in the driver app, or through an upload link sent to them on WhatsApp, is uploaded first to DropWire, our own capture service, which runs separately from this hosted service. The product also stores its own copy in Canada — sent by the driver's phone, or fetched from DropWire for a WhatsApp upload — but DropWire keeps its copy as well, until it deletes it on its own retention schedule, and until the product's copy arrives, DropWire's is the only one. This section's statement about Canada does not cover DropWire's copy.
Most of those providers are outside Canada, mainly in the United States, and information shared with them is processed there and is subject to the laws of that country. This is unavoidable for a payment processor, for the provider that relays our email, for Google's address lookup, which every account uses, and for any integration you choose to connect. The OpenStreetMap Foundation, whose map service a browser can load directly (section 6), is based in the United Kingdom. We tell you this rather than claiming your data never leaves Canada, because that claim would not be true.
9. How long we keep it
| Information | Kept for |
|---|---|
| Driver position history | 90 days, then permanently deleted |
| AI live tracking's reading of a trip | Replaced each time the trip is checked while it is assigned or in transit, and deleted by the next five-minute check after the trip is delivered or cancelled — whether or not the feature is still on. Also deleted with the trip, and with the rest of your account data after you cancel. It holds no position |
| The files a scheduled report sends — its CSV and, where switched on, the summary PDF with its AI narrative | Held for delivery and cleared a day after the run. The copies in recipients' mailboxes are outside the product |
| Logs of requests to our web addresses, recorded at Microsoft's network edge (section 8) | 30 days, then deleted |
| Your account data after you cancel | 90 days, then eligible for permanent deletion |
| Financial and tax records | As long as tax and accounting law requires, which is longer |
| Records of security breaches | 24 months, as PIPEDA requires |
Deletion is a real deletion, not a hidden flag — with one exception: deleting a driver's capture here does not delete the copy DropWire keeps, which goes only on DropWire's own retention schedule (section 8).
One honest caveat: data deleted from our live systems remains in encrypted backups until those backups expire on their normal schedule. We cannot reach into a backup to remove a single record.
10. Your rights
Under Canadian privacy law you can:
- Ask what we hold about you and get a copy
- Correct information that is wrong or incomplete
- Withdraw consent, subject to legal and contractual limits — withdrawing some consent may mean we cannot provide part of the service
- Complain about how we handled your information
If your information is in a customer's records — you are a driver, or a contact at one of their customers — that company decides what happens to it, so ask them first. We will help route your request and support them in answering it.
To make a request, contact us at support@hexagen.ca. We respond within 30 days, as PIPEDA requires. We may need to verify your identity first.
If you are not satisfied, you can complain to the Office of the Privacy Commissioner of Canada — priv.gc.ca.
11. Security
We protect information with access controls, encryption in transit, isolation between customers, and restricted staff access. Encryption in transit covers the connection from your browser to Microsoft's network edge and from the edge to our servers; at the edge itself the connection is decrypted and encrypted again, as section 8 explains. Staff access customer data only where needed to run the service, resolve a support request, or comply with the law.
No system is perfectly secure and we do not claim otherwise.
12. If something goes wrong
If a breach of our security safeguards creates a real risk of significant harm, we notify the affected people and the Office of the Privacy Commissioner of Canada as the law requires, and we notify our customer so they can meet their own obligations. We keep a record of every breach for 24 months, including ones we assess as harmless.
13. Children
The product is business software and is not directed at children. We do not knowingly collect information from anyone under the age of majority in their province.
14. When you host the Software
If your organisation licences the Software and runs it on its own infrastructure, this is the section that applies to you.
We do not receive your operational data. Your loads, customers, drivers, documents, position history and mail stay on your infrastructure and never reach us, with the two exceptions below. We are the supplier of the software, not the handler of that data — your organisation is responsible for it, and for its own privacy obligations.
What we do hold: your account and licence record, your billing relationship with us, and any support correspondence. Sections 3 ("When you sign up and pay us"), 6, 8, 9, 10 and 12 apply to that information.
The AI features work the same way on your installation, and the choice is yours. If you configure an AI provider and switch a feature on, the text in section 7's table goes to your provider under your agreement with them. If you do not configure one, the features stay off and nothing is sent anywhere.
Support access is one exception. If you ask us to help with a problem and grant us access to your installation, we may see your data while doing so. That access is at your invitation, limited to your request, and recorded. Without it, we have no access.
Driver captures are the other, if you use DropWire. If your installation is configured to send driver captures through DropWire, our capture service, each photograph or document a driver captures passes through DropWire, which keeps a copy on its own retention schedule.
The retention periods in section 9 describe our hosted service. On your own installation, retention is whatever your administrator configures — the Software's position-history retention defaults to 90 days but is a setting you control, and the deletion job runs when your operator runs it.
Your privacy obligations to your own drivers and customers are yours. We supply software capable of supporting them — configurable retention, a deletion path, data export, and consent capture for location and messaging — but operating them, and answering to the people whose information you hold, is your organisation's responsibility.
15. Changes to this policy
We publish a new version rather than editing the current one, and previous versions stay available. If a change materially affects how we handle your information, we give notice before it takes effect.
16. Contact
Privacy Officer: the Director, support@hexagen.ca
Quebec's Law 25 requires an organisation to designate a person responsible for the protection of personal information, and to publish that person's title and contact details. That is the role above, and it is the person to write to about anything in this policy. Hexagen Technologies Inc., Brampton, Ontario, Canada