Legal
Privacy Policy
Last updated: August 16, 2026
1. Who We Are
Studio Signal is a web design and marketing agency based in Quebec, Canada, serving clients primarily in Quebec and Ontario.
Privacy Officer / Person Responsible for Personal Information: Seb Molgat, [email protected]
For the purposes of Quebec's Act respecting the protection of personal information in the private sector (Law 25), Seb Molgat is the designated person responsible for personal information.
2. What This Policy Covers
This policy describes how we collect, use, and protect personal information on studiosignal.ca, our agency website. It also explains your rights under applicable law.
If you are a Studio Signal client, see Section 3.5 for how we handle your own account data in our client portal. If you are a visitor to a website we host or maintain on behalf of one of our clients, see Section 9 for how we handle personal information in that separate context.
3. Information We Collect
3.1 Contact Form
When you submit our contact form (site diagnostic request, general inquiry, or call request), we collect: full name, email address, website URL (if provided), and your message.
How it's handled: your submission is sent directly to us by email via Resend (see 3.6). We do not store contact form submissions in a database; the only retained copy is the email itself, subject to our normal mailbox retention.
3.2 Appointment Booking (Cal.diy)
When you book a call through our website, we collect: full name, email address, selected date and time, and any notes you provide.
Stored in: Cal.diy, our self-hosted scheduling application, running on our own server infrastructure hosted by Oracle Cloud in Montreal, Quebec, Canada. No booking data is sent to third-party scheduling platforms.
3.3 Website Analytics (Umami)
We use Umami, a privacy-focused analytics tool, self-hosted on our own server in Montreal, Quebec, Canada. Umami collects: page views and navigation paths, referral source, browser type and operating system (aggregated), and approximate country (derived from anonymized IP; the full IP is not stored).
Umami does not use cookies and does not share data with any third party.
3.4 Cookies
| Cookie | Purpose | Duration |
|---|---|---|
| theme | Remembers your light/dark mode preference | 1 year |
| payload-token | Keeps you signed in to the client portal (clients only) | 2 hours, or until you sign out |
| NEXT_LOCALE | Remembers your preferred language (English or French) | 1 year |
We do not use advertising cookies, cross-site tracking cookies, or analytics cookies.
3.5 Client Portal (For Our Clients)
If you become a Studio Signal client, we create an account for you in our client portal. We collect and store your name, company name, email address, and the project-related information you provide there — support tickets, intake form responses, and any files or notes exchanged as part of your project.
Stored in: our self-hosted client portal application, running on our own server infrastructure in Montreal, Quebec, Canada.
Payments: invoices are processed through Helcim Inc., a Canadian payment processor. We do not store your payment card details ourselves; Helcim handles and secures that information directly under its own security standards.
Contracts: signed agreements are handled through DocuSeal, a document-signing tool we self-host on our own infrastructure in Montreal, Quebec, Canada — not a third-party service.
Billing history: project billing and invoicing records are also kept in our internal time-tracking and invoicing system, on the same self-hosted infrastructure.
3.6 Transactional Email
We use Resend (Resend Inc., United States) to deliver transactional email. This includes contact form submissions, and, for clients, portal emails such as account setup, password resets, support ticket updates, and invoice notifications. Resend processes the relevant name, email address, and message content in transit. Resend does not retain email content beyond delivery. Resend maintains a Data Processing Agreement and is GDPR-compliant. Their privacy policy is available at resend.com/legal/privacy-policy.
3.7 Server Logs
Our web server automatically records standard technical data including IP addresses, timestamps, and requested URLs. Logs are retained for 30 days and used only for security and troubleshooting.
4. Why We Collect This Information
| Data | Quebec Law 25 Basis | GDPR Basis (if applicable) |
|---|---|---|
| Contact form | Consent via voluntary submission | Legitimate interest (pre-contractual communication) |
| Cal.diy bookings | Necessary to deliver requested service | Performance of a contract / pre-contractual steps |
| Client portal account | Necessary to deliver a contracted service | Performance of a contract |
| Analytics | Consent (anonymized, non-identifying) | Legitimate interest (improving our website) |
| Server logs | Necessary for system security | Legitimate interest (security) |
We do not sell, rent, or trade your personal information.
5. Who Has Access to Your Information
- Studio Signal personnel (currently: Seb Molgat)
- Resend Inc., for transactional email delivery only (see 3.6)
- Helcim Inc., for payment processing only, and only for clients (see 3.5)
- Infrastructure providers (Oracle Cloud) for routine hosting operations
Our client portal, e-signature (DocuSeal), and invoicing tools are self-hosted by us — not operated by, or shared with, any outside company.
We do not use third-party email marketing, CRM platforms, or advertising networks.
International Transfers
Contact form submissions and, for clients, portal-related emails, are relayed through Resend's infrastructure in the United States. Resend maintains GDPR-compliant data processing agreements. Payment processing (Helcim) is handled by a Canadian company and does not involve a cross-border transfer by us. All other data (bookings, client portal accounts, contracts, analytics, logs) stays on our own infrastructure in Montreal, Quebec, Canada.
6. Your Rights
All visitors (Quebec Law 25 / PIPEDA)
- Access: Request a copy of the personal information we hold about you
- Correction: Request that we correct inaccurate or incomplete information
- Withdrawal of consent: Withdraw consent for non-essential processing at any time
- Complaint: File a complaint with the Commission d'accès à l'information (CAI) at cai.gouv.qc.ca
EU/EEA visitors (GDPR, included as a courtesy for any international visitors)
In addition to the above:
- Erasure: Request deletion of your personal information
- Portability: Receive your data in a structured, machine-readable format
- Restriction: Ask us to limit how we process your data
- Objection: Object to processing based on legitimate interest
- Supervisory authority: Lodge a complaint with your local data protection authority
To exercise any of these rights, contact: [email protected]. We will respond within 30 days. Identity verification may be required.
7. Data Security
Personal information is stored on a self-hosted, hardened server in Montreal, Quebec, Canada, protected by:
- Encrypted HTTPS connections (TLS 1.2/1.3)
- Network firewalls and access controls
- Automated backups stored in encrypted cloud storage
- No unnecessary third-party access
In the event of a breach that poses a serious risk of harm, we will notify affected individuals and the appropriate regulatory authority within 72 hours, as required by Law 25.
8. Data Retention
| Data type | Retention period |
|---|---|
| Contact form submissions | Not stored; transmitted by email only, retained per our own mailbox policy |
| Booking records | 3 years (business records) |
| Client portal account data | 2 years after your account is deactivated |
| Signed contracts and invoices | 6 years after the end of the tax year they relate to |
| Analytics data | 13 months (rolling) |
| Server logs | 30 days |
9. Our Role as a Data Processor
As a web design and marketing agency, we build and maintain websites that collect personal information from your visitors and customers. In this capacity, we act as a data processor on your behalf, and you (our client) are the data controller.
We process your end-users’ data only according to your documented instructions. Clients are responsible for:
- Maintaining their own privacy policy on their website
- Obtaining required consents from their users
- Notifying us of any data subject rights requests we need to fulfill
Clients who require a Data Processing Agreement (DPA) may request one at [email protected].
10. Children's Privacy
Our website is not directed at children under the age of 14 (or 16 for EU visitors). We do not knowingly collect personal information from minors. If we discover we have inadvertently collected such data, we will delete it promptly.
11. Changes to This Policy
We may update this policy periodically. The "Last updated" date at the top will reflect any changes. For material changes, we will post a notice on our website.