# ETP Foundry — Privacy notice **Draft v0.1 — pending counsel review · 28 September 2026** This notice explains what personal information ETP Foundry collects through etpfoundry.com, the signed-in desk, the public API and the hosted MCP, why, where it is kept, and what your rights are. It is written for Canada's *Personal Information Protection and Electronic Documents Act* (PIPEDA). ## 1. Who we are **Lucilla, Inc., federal corporation no. 16699448, Toronto, Ontario, trading as ETP Foundry** ("we"). We are responsible for the personal information described here. Privacy contact: **hello@etpfoundry.com** (subject line "Privacy"). ## 2. What we collect | Data | Where it comes from | Why we hold it | |---|---|---| | **Access requests**: name, e-mail, firm, optional seat and message | The form at /request-access | To reply to you and decide whether to grant access. It is written to the desk's append-only event log so that a request is not lost in a mailbox | | **Sign-in identity**: Google account e-mail, a Firebase user id, e-mail verification status, provider metadata | Google sign-in through Firebase Authentication (the only way to sign in) | To check your e-mail against the desk's roster of invited users. An address not on the roster is refused, and the refusal is logged | | **Account settings**: role, seat, per-user settings, signer webhook URLs | Set by us when you are invited, or by you in the console | To run the desk for you | | **API keys**: a SHA-256 hash of each `ck_` key (never the key itself) and when it was last used | Created by you in the console | To authenticate calls to the API and the hosted MCP | | **Assistant conversations**: what you type to the in-console assistant, its replies, the steps it took, and your approvals or rejections; a daily usage count | The "Ask the desk" assistant | To show you your history and keep the assistant within its limits. See the AI-use disclosure | | **Audit events**: actions you take in the desk (for example confirming a fixing or creating an API key), with your identity | The desk | Benchmark records must be attributable and kept (rulebook §10) | | **Server logs**: request metadata, IP address, errors, authentication refusals | Google Cloud Logging | Security and operations | | **E-mail** you send us | Google Workspace | To reply | We do **not** use analytics, advertising or tracking cookies. The site keeps sign-in state and a few display preferences in your browser's own storage. Nothing is shared with third parties for marketing. We do not collect payment card data or identity documents through the site. ## 3. Where it is kept and who processes it All desk data is held in Google Cloud, in region `us-central1` (United States). The assistant's messages are processed by Google Vertex AI (location `global`, which may route processing outside the United States). Our service providers are listed in the sub-processor list at etpfoundry.com/documents/subprocessors-v0.1.md. We do not sell personal information. ## 4. How long we keep it | Data | Retention | |---|---| | Access requests and audit events | Kept in the desk's event log, to which the rulebook's 7-year record rule applies | | Sign-in identity and account settings | While you have access; deleted on request after that | | API key hashes | Until the key is revoked | | Assistant conversations | Deleted automatically **90 days after the last message** in the conversation. You can delete any conversation yourself before then ("Delete this conversation" in the console's conversation history), and we delete any conversation on request. Each deletion, and each automatic purge, is recorded in the audit log by conversation id, never its content | | Server logs | Google Cloud Logging default (30 days) | Records written to the Canton ledger (for example, who confirmed a fixing) are permanent by design and cannot be erased. We keep personal information off the ledger: ledger records identify parties by their Canton party identifier. ## 5. Your rights You may ask to access or correct the personal information we hold about you, or withdraw consent and ask us to delete it, subject to the records we must keep. Write to hello@etpfoundry.com. We answer within 30 days. If you are not satisfied, you may complain to the Office of the Privacy Commissioner of Canada. ## 6. Security See the security overview (etpfoundry.com/documents/security-overview-v0.1.md). If a breach creates a real risk of significant harm, we will notify the affected individuals and the Privacy Commissioner as PIPEDA requires. ## 7. Changes We publish every version of this notice. The date above shows which one is current.