Anexus Technologies Incorporated, an Ontario corporation doing business as Anexus Connect, with its registered office in Ontario, Canada (“Anexus Connect,” “we,” “us,” or “our”) respects your privacy. This Privacy Policy describes how we collect, use, disclose, and protect information when you use:
- Our marketing website (the “Website”), currently served at https://www.anexusconnect.com (including any subdomains), and
- Our related APIs (for example, endpoints under
/api/),
and how that relates to our separate web application at https://app.anexusconnect.com (the “App”).
By accessing or using the Website, you acknowledge that you have read and understood this Privacy Policy.
1. Information We Collect
1.1 Information You Provide Directly
We collect personal information that you voluntarily provide, including:
- First name and last name
- Email address
- Company name and company size
- Country
- CRM platform preferences
- Messages submitted through forms
- Any information included in communications with us
1.2 Information Collected Automatically
When you use the Website, we and our service providers may automatically collect:
- Technical Data: IP address, browser type, language, operating system, device characteristics, screen resolution, and time zone
- Usage Data: pages viewed, referring and exit pages, timestamps, session duration, and navigation patterns
- Interaction Data: clicks, scroll depth, and engagement behavior
- Attribution Data: UTM parameters and referral information
- Approximate Location Data: derived from IP address
- Persistent Identifiers: a randomly generated visitor ID stored in browser local storage
- Browser Fingerprint Signals: limited technical characteristics used to distinguish sessions; not intended to identify individuals
1.3 AI Assistant (Website Chat)
If you interact with our AI assistant:
- We collect the content of messages you submit
- We may retain conversation context to generate responses
This data may be processed by third-party AI providers acting as service providers.
1.4 Information We Do Not Ask For or Store
By design, the Website's contact forms, marketing flows, and AI chat do not ask for and do not store:
- Government-issued identification numbers;
- Full payment card or banking details;
- Health information or other special-category sensitive personal information.
Please don't submit any of the above through forms or chat. If you do submit such information by accident, we will delete it as soon as it is identified.
Exception — Profile Shop onboarding via Stripe: If you choose to sell through Profile Shop, Stripe (not Anexus Connect) may collect government-issued ID, tax identification numbers, and bank-account details directly from you for identity verification, KYC/AML compliance, and payouts. This is described in Section 6 (Profile Shop & Stripe Connect). We do not receive or store those documents.
2. How We Use Information
We use personal information to:
- Operate, maintain, and improve the Website
- Respond to inquiries and support requests
- Communicate with users regarding submitted requests
- Analyze usage patterns and improve performance
- Evaluate marketing effectiveness and conversion metrics
- Provide AI-powered assistance
- Detect, prevent, and investigate security incidents
- Comply with legal and regulatory obligations
Payments and Billing
Payments are processed by third-party payment providers, including Stripe and Stripe Connect. We do not store or process full payment card information on our servers.
We may store limited billing-related information, including:
- Subscription status
- Order history
- Customer details (such as name, email, and billing or shipping information)
- For users who sell through Profile Shop: Stripe Connected Account identifier, payout and account-status capabilities, and transaction metadata (amount, currency, platform fee, timestamps, Buyer email, Offering reference) — described in Section 6 below.
Payment processing is subject to Stripe's privacy practices. For more information, please review: https://stripe.com/privacy
3. Legal Bases for Processing
Where applicable, we rely on:
- Contractual necessity – to respond to requests and inquiries
- Legitimate interests – for analytics, security, and service improvement
- Consent – where required (e.g., cookies or marketing communications)
- Legal obligations – where required by applicable law
4. Cookies, Local Storage, and Similar Technologies
We use:
- Essential technologies required for Website functionality and security
- Browser local storage (e.g., visitor ID)
- Analytics and session-replay tools, including Microsoft Clarity
- Third-party content delivery services such as Google Fonts, jsDelivr, and cdnjs
These services may collect technical data such as IP addresses when resources are requested.
You may control cookies and similar technologies through your browser settings. Disabling them may affect Website functionality.
5. Disclosure of Information
We may disclose personal information to:
- Service providers, including:
- Hosting and infrastructure providers
- Email delivery services
- Analytics providers (e.g., Microsoft Clarity)
- AI processing providers
- Payment processors (e.g., Stripe)
- Professional advisors, including legal and accounting services
- Government or regulatory authorities, where required by law
We may also disclose aggregated or de-identified information that cannot reasonably identify an individual.
6. Profile Shop & Stripe Connect (Payments to and from Users)
Our Profile Shop feature allows Users (each a “Seller”) to sell digital products, services, bookings, or other offerings to other persons (each a “Buyer”). Payments are processed through Stripe Connect, operated by Stripe, Inc. and its affiliates (“Stripe”).
Anexus Connect is not the merchant of record for Profile Shop transactions and does not custody or hold payment funds at any time. Funds flow from the Buyer through Stripe to the Seller's Stripe Connected Account. The Buyer's payment data is collected and processed by Stripe, not by us. Our role is limited to facilitating the connection between you and Stripe and recording metadata about transactions for the purpose of operating the platform and collecting our platform fee.
6.1 What Stripe collects (Sellers)
When you onboard as a Seller, Stripe collects identity-verification information directly from you under the Stripe Connected Account Agreement and the Stripe Services Agreement. This may include, depending on your jurisdiction and business type:
- Legal name, business name, date of birth, and home or business address
- Government-issued identification (e.g., driver's licence, passport) and selfie or document images for identity verification
- Tax identification number (e.g., SIN, BN, EIN, VAT number) where required by law
- Bank account or debit-card details for payouts
- Beneficial-ownership and ownership-structure information for business accounts
- Information needed for KYC (Know-Your-Customer), AML (anti-money-laundering), and sanctions screening
This information is collected, processed, and stored by Stripe under Stripe's Privacy Policy. We do not receive, store, or have access to your full Stripe KYC documents (e.g., government-ID images), bank account numbers, or social-insurance/tax numbers.
6.2 What we receive from Stripe (Sellers)
We receive and store the following Stripe-provided metadata about each Seller, which we use to operate Profile Shop:
- Your Stripe Connected Account identifier and account type (e.g., Express, Standard)
- Account status, capabilities, and onboarding-completion status
- Whether charges and payouts are enabled
- Restriction, suspension, or termination signals from Stripe
- Limited business profile information (legal/business name, business URL, country, default currency)
- Payout schedule and payout history references (we may store the existence and status of payouts, not the underlying bank details)
6.3 What we collect about transactions
For each transaction processed through Profile Shop, we store metadata that may include:
- A unique transaction or charge identifier
- The Offering purchased (product, service, or booking reference; quantity)
- Gross transaction amount, currency, and our platform fee
- Buyer-supplied details necessary for fulfilment and receipts (such as name, email address, and any delivery information collected at checkout)
- Timestamps, IP address (where collected for fraud-prevention purposes), and the source the transaction originated from (e.g., NFC tap, QR scan, shared link)
- Status of the transaction (succeeded, refunded, disputed, reversed)
We do not store full payment-card numbers, CVV codes, full bank-account numbers, or other regulated payment instruments. That data resides with Stripe.
6.4 What Buyers should know
If you purchase an Offering through Profile Shop:
- Your payment is processed by Stripe under Stripe's Privacy Policy; we do not see your full card details.
- We share your name, email address, and any delivery or fulfilment information you provide at checkout with the Seller so the Seller can deliver the Offering and respond to support and warranty inquiries.
- The Seller is an independent business and acts as a separate controller of your personal information once it is shared with them. You should review the Seller's own privacy practices.
- We retain a record of your transaction for tax, accounting, fraud-prevention, dispute-resolution, and platform-operation purposes, as described in Section 11 (Retention).
6.5 Information we share with Sellers and Stripe
- We share Buyer-supplied transaction details with the relevant Seller for fulfilment, support, and post-sale service.
- We share information necessary for Stripe to process payments and comply with its legal obligations (including KYC, AML, sanctions, and tax-reporting obligations).
- We may share Seller-account status information internally and with our service providers to operate, secure, and monitor the platform.
6.6 Cross-border processing
Stripe processes payment and identity information in the United States and other jurisdictions where Stripe operates. By using Profile Shop, you acknowledge that personal information related to your payments will be transferred to and processed by Stripe outside of your country of residence, including in the United States, subject to safeguards required by applicable law.
6.7 Tax-reporting and recordkeeping
Where required by law (for example, certain marketplace-facilitator tax obligations or recipient-reporting obligations such as Form 1099-K equivalents), we and/or Stripe may collect additional Seller tax information and report transaction totals to the relevant tax authority. Sellers are solely responsible for accuracy of the information they provide and for their own tax obligations, as described in our Terms of Use (Section 5).
6.8 Security of payment metadata
We protect transaction and account-status metadata using the same encryption, access controls, and security measures described in Section 12. Sensitive payment instruments themselves are held by Stripe, not by us.
7. The Application (App)
The App (https://app.anexusconnect.com) may collect additional categories of information, including:
- Account credentials
- Profile and business content
- Payment-related data (processed by third-party payment providers such as Stripe)
- Product usage analytics
Separate privacy notices and terms may apply to the App. In case of conflict, App-specific notices will govern App-related processing.
8. International Data Transfers
To run a reliable global service, we and our service providers may process and store personal information in:
- Canada (our primary jurisdiction);
- United States (for hosting, AI processing, email delivery, payments, and several CRM integrations);
- European Economic Area, United Kingdom, India, Australia, Japan, and other regions where specific service providers (for example, Zoho regional data centres) operate.
8.1 Cross-border safeguards
When personal information leaves your home jurisdiction, we apply appropriate safeguards: contractual protections with our service providers (Data Processing Agreements, Standard Contractual Clauses where required for EU/UK data), encryption in transit and at rest, and minimisation of the data shared with each provider to only what is required for the service.
8.2 Notice for residents of Quebec
If you are a resident of Quebec, please note that some of your personal information will be processed outside Quebec, including in the United States and other jurisdictions, by our service providers listed in the Sub-processors section below. These jurisdictions may not offer a level of protection equivalent to that of Quebec. We have assessed the privacy risks of these transfers in accordance with section 17 of Quebec's Act respecting the protection of personal information in the private sector (as amended by Law 25) and have put contractual and technical safeguards in place to mitigate them. You may contact our Privacy Officer (see Section 17) for more information on this assessment or to object to a specific transfer.
8.3 Notice for residents of the EU, EEA, UK, and Switzerland
Transfers of your personal information to Canada are made under the European Commission's adequacy decision for Canada (commercial sector). Transfers to the United States and other non-adequate jurisdictions are made under Standard Contractual Clauses (or the UK International Data Transfer Agreement, where applicable) together with the technical and organisational measures described in Section 12. You may request a copy of the relevant transfer mechanism from our Privacy Officer.
9. Your Privacy Rights
Depending on your jurisdiction, you may have the right to:
- Access your personal information
- Request correction of inaccurate data
- Request deletion of personal data
- Object to or restrict certain processing
- Request data portability
- Withdraw consent where applicable
- Lodge a complaint with a regulatory authority
9.1 Data Export and Portability
You may submit a request to us at any time to receive a copy of the personal information we hold about you in connection with your account, including where applicable in a structured, commonly used, and machine-readable format suitable for transmission to another controller (“data portability”), subject to applicable law and technical feasibility. We may require reasonable steps to verify your identity before fulfilling such requests and may decline requests that are manifestly unfounded, excessive, or otherwise not required or permitted by law.
9.2 Account Deletion
You may request deletion of your account and associated personal information at any time by contacting us using the details in Section 17. Upon receipt of a verifiable request, we will process the request in accordance with applicable law. Please note that we may retain certain information where retention is necessary to comply with legal obligations, resolve disputes, enforce our agreements, or protect legitimate interests (including security and fraud prevention), and we may retain information that has been irreversibly anonymized or aggregated such that it no longer reasonably identifies you.
Where self-service tools are made available within the App, you may also use those tools to initiate export or deletion requests, without limiting your right to contact us directly.
10. U.S. State Privacy Disclosures (Including California)
For residents of applicable U.S. states:
- We may collect identifiers, usage data, and inferred data
- We do not knowingly collect sensitive personal information
- Certain analytics practices may be considered “sharing” under applicable laws
You may exercise your rights by:
- Using browser privacy controls (including Global Privacy Control signals)
- Adjusting cookie preferences
- Contacting us directly
We will not discriminate against users for exercising their rights.
11. Retention
We hold personal information only for as long as we genuinely need it. Our retention is governed by the following principles:
- Fulfilling the purposes described in this policy;
- Complying with our legal, regulatory, and tax-recordkeeping obligations;
- Resolving disputes and enforcing our agreements;
- Protecting the security and integrity of the Services.
11.1 Specific retention periods
To make this concrete, the following table sets out the retention periods we apply by default. Where you exercise a deletion right (Section 9), we apply the shorter of your request or the legal minimum.
| Category | Default retention | Reason |
|---|---|---|
| Active account data (profile, contacts, settings) | For as long as the account is active | To provide the Service to you |
| Deleted-account personal data | Removed within 30 days of verified deletion request | Standard timeline for verified deletion |
| Operational backups containing deleted data | Overwritten within 90 days | Backup rotation; data is restored only in a disaster-recovery scenario |
| Security and access logs | 90 days of detailed logs; aggregated metrics longer | Incident investigation, fraud detection |
| Transaction and tax records (Profile Shop, hardware orders, subscriptions) | 7 years (Canadian and U.S. tax-recordkeeping standard) | Tax and accounting compliance |
| Marketing email contacts (mailing lists) | Until you unsubscribe, then 30 days for suppression-list purposes | CASL / CAN-SPAM compliance |
| Support correspondence | 3 years from last interaction | Pattern detection, dispute reference |
| AI chat transcripts | 90 days, then deleted or irreversibly aggregated | Quality monitoring, abuse prevention |
11.2 Legal holds
If we are required to preserve data due to ongoing litigation, regulatory investigation, or other legal hold, retention may be extended for that specific data set until the hold is released.
11.3 Aggregated and anonymised data
We may retain aggregated or irreversibly de-identified data indefinitely for statistical and product-improvement purposes. Such data does not identify you and is not personal information.
12. Security
Protecting your information is core to what we do. We design, build, and operate Anexus Connect with security as a first-class concern, not an afterthought. In plain language, here's what that means in practice:
- Encrypted in transit: every page you load and every action you take travels between your browser and our servers over an encrypted connection — the same kind of protection your bank uses when you log in.
- Encrypted at rest: the sensitive data we store on your behalf — contact details, integration keys, personal information — is encrypted in our databases using industry-standard, bank-grade encryption (technically: AES-256-GCM, for the curious).
- Hashed passwords: we never store your password as plain text. We store a one-way mathematical fingerprint of it, so even we cannot see what you typed.
- Limited access: only a small number of authorised engineers can reach the production systems, and every action is logged and reviewable.
- Hardened infrastructure: we run on professionally managed cloud infrastructure with firewalls, continuous monitoring, and protection against attacks designed to take websites offline.
- Kept up to date: we apply security updates promptly and monitor the software we rely on for known issues.
- Ongoing review: we review our security regularly and treat reports from researchers and customers as a top priority.
That said, no online service can promise absolute security — this is the honest truth of the internet, not a get-out clause. We cannot guarantee that determined and well-resourced attackers will never breach a system, that no employee will ever make a mistake, or that no third-party dependency will ever be compromised. When an incident occurs, our commitment is in Section 13 (Breach Notification): tell affected users promptly, work to contain and remediate, and learn from it.
If you discover a vulnerability or have a security concern, please contact support@anexustechnologies.com with the subject line "Security." We will acknowledge receipt within one business day.
13. Data-Breach Notification
If we become aware of a personal-data breach that is likely to result in a risk to your rights and freedoms, we will:
- Notify the appropriate supervisory authority without undue delay (and, where required, within 72 hours of becoming aware), in accordance with applicable law (including GDPR, PIPEDA, and applicable U.S. state laws);
- Notify affected users without undue delay where the breach is likely to result in a high risk to their rights and freedoms;
- Document the breach, its effects, and the remedial action taken.
You can help by promptly reporting any suspected unauthorized access to your account or suspicious activity to support@anexustechnologies.com.
14. Children's Privacy
Anexus Connect is a professional networking and CRM tool built for adults. The Website, App, and related services are not directed to children under the age of 13 (or the higher applicable age under your local law — for example, 14 in Quebec under Law 25, and 16 in many European jurisdictions). When you create an account, you represent that you meet the applicable minimum age.
We do not knowingly collect personal information from children below the applicable age. If we discover that we have collected personal information from a child without verified parental consent:
- We will delete the child's personal information within 30 days of discovery;
- Where contact details for a parent or guardian are available, we will notify them;
- We will preserve, where required by law, the minimum record needed to demonstrate the deletion and to prevent recreation of the account.
If you are a parent or guardian who believes a child has provided us with personal information, please contact us at support@anexustechnologies.com with the subject line "Child Account" so we can take action quickly.
15. AI Assistant — Additional Notice
- The AI assistant operates using automated systems and may generate inaccurate or incomplete responses
- It is not intended for legal, financial, medical, or professional advice
- Users must not submit sensitive personal information
- Data may be processed by third-party AI providers under their terms
16. Changes to This Policy
We may update this Privacy Policy periodically. Updates will be reflected by revising the Effective Date.
17. Contact Us — Privacy Officer
For privacy-related inquiries, access or deletion requests, complaints, or any question about this Policy, please contact our Privacy Officer:
Privacy Officer, Anexus Technologies Incorporated
Email: support@anexustechnologies.com (subject line: "Privacy Officer")
You may also reach us through the Website contact form. We aim to respond to all privacy requests within 30 days, and we will tell you in advance if we need an extension allowed by law.
- Mailing address: Anexus Technologies Incorporated, Ontario, Canada (full address available on written request);
- Website: https://www.anexusconnect.com
- App: https://app.anexusconnect.com
If you are not satisfied with our response, you have the right to lodge a complaint with the privacy authority in your jurisdiction — for example, the Office of the Privacy Commissioner of Canada (priv.gc.ca), the Commission d'accès à l'information du Québec (cai.gouv.qc.ca), or your applicable European data-protection authority.
18. Sub-processors and Service Providers
Running Anexus Connect involves a small set of trusted service providers (also called "sub-processors") who help us deliver, secure, and support the Services. We carefully select each one, sign written data-protection agreements with them, and share only the data they need to perform their function.
18.1 Categories of sub-processors we use
| Function | Current provider(s) | Region(s) |
|---|---|---|
| Cloud hosting, database, storage | Professionally managed cloud infrastructure (current provider disclosed on request) | Canada / United States |
| Payments and marketplace facilitation | Stripe, Inc. and Stripe Payments Canada, Ltd. | Canada / United States / global Stripe regions |
| Transactional email delivery | Google (Gmail SMTP) and equivalent transactional-email providers | United States |
| AI features (generation, drafting) | Large-language-model providers such as OpenAI, Anthropic, Groq, or Google (current provider disclosed in the App or on request) | United States and provider's operating regions |
| CRM integrations (only when you connect them) | HubSpot, Pipedrive, monday.com, Freshsales, Copper, Apollo, ActiveCampaign, Close, Salesforce, Zoho | Per the provider's data centre you choose |
| Calendar integrations (only when you connect them) | Google Calendar, Microsoft Outlook, Apple Calendar | Provider-specific |
| Wallet passes | Apple Inc. (Apple Wallet), Google LLC (Google Wallet) | Provider-specific |
| Bot and abuse protection | Google reCAPTCHA | United States |
| Analytics (privacy-respecting, where used) | First-party analytics on our own infrastructure; cookieless metrics where feasible | Canada / United States |
18.2 How we contract with sub-processors
Every sub-processor we engage is subject to a written agreement that obliges them to:
- Process personal information only on our documented instructions;
- Keep the information confidential and apply appropriate technical and organisational security measures;
- Notify us of any security incident affecting our data without undue delay;
- Assist us with privacy rights requests and regulatory cooperation;
- Return or delete the information at the end of the engagement.
18.3 When you connect a CRM, calendar, or other integration
Integrations are entirely under your control — they only activate when you connect them in the App. When you do:
- You authorise us to access specific data via the provider's secure API;
- The connection keys we receive are stored with industry-standard, bank-grade encryption in our database;
- We use the integration only for the functionality you enabled (such as syncing a captured contact, or showing your availability);
- You can disconnect at any time in Settings → CRM Integrations, which revokes our access from our side;
- Your use of an integrated third-party service remains subject to that provider's own terms and privacy policy.
18.4 Changes to sub-processors
If we add or replace a material sub-processor, we will update this list and, where the change has a meaningful impact on how we process your data, give reasonable advance notice through the App, by email, or by a prominent notice on the Website.
19. AI Training and Model Use
Many people, rightly, have questions about how their data is treated by AI systems. Here is our commitment:
- We do not use your data to train AI models. We do not use your account data, contacts, profile content, files, or the content of your AI-assistant conversations to train, fine-tune, develop, evaluate, or improve any artificial-intelligence model — neither our own nor any third party's.
- We require the same of our AI providers. Where we use third-party AI providers (such as OpenAI, Anthropic, or Google) to power AI Features, we use the data-protection settings that prevent your prompts and the resulting output from being used to train their general models. Where a provider offers an enterprise or zero-data-retention tier, we use it.
- This applies after termination. The commitment in this section applies during your use of the Services and survives termination of your account.
- Aggregated, irreversibly de-identified data. We may use information that has been irreversibly aggregated or anonymised — such that it no longer identifies you or any individual — for product analytics and improvement. By design, such data is not personal information.
- Operational telemetry. We may review error logs, sample prompts, or sample outputs in order to investigate a bug, fix a quality issue, or address abuse — but not to train models.
For the current AI provider powering a given AI Feature, see the relevant feature page in the App or contact us at support@anexustechnologies.com.
20. User-Generated Content
You may upload and publish content through the Services — profile information, images, videos, links, AI chat content, and similar material. You retain ownership of that content, subject to the licence you grant us in the Terms of Use.
You are responsible for the content you provide. While we do not pre-screen every piece of user content, we monitor for abuse, respond to credible reports, and act under our Acceptable Use Policy where content violates these rules. Reports can be sent to support@anexustechnologies.com.
Our Terms of Use govern use of the Services.