Privacy Policy
Last updated: July 1, 2026
Draft for review
This document is provided for transparency and is under review by legal counsel. It is not legal advice. For questions, contact our Privacy Officer at privacy@embaylms.com.
This Privacy Policy explains how Embay Consulting Inc. (“Embay”, “we”, “us”) collects, uses, discloses, and protects personal information in connection with the EmbayLMS platform, our website at embaylms.com, and the application at app.embaylms.com. We are committed to handling personal information in accordance with Quebec’s Act respecting the protection of personal information in the private sector (Law 25, CQLR c. P-39.1), Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA), and, where applicable, the EU and UK General Data Protection Regulation (GDPR).
Who we are and our role
EmbayLMS is a multi-tenant Software-as-a-Service learning management system. Our customers are organizations (employers and institutions) that use EmbayLMS to deliver training to their learners.
- For personal information about a customer’s learners and administrators processed inside that customer’s workspace, the customer (the tenant/employer) is the controller (the “responsible” person under Law 25) and EmbayLMS acts as its service provider (processor). We process that information only on the customer’s documented instructions.
- For personal information we collect for our own purposes — platform account data, billing and tax records, and information about prospects who contact us through our website — EmbayLMS is the controller.
Information we collect
Depending on your relationship with us, we may process the following categories:
- Identity and directory: name, email, employee ID, manager, group or department.
- Optional profile: preferred language (EN / FR-CA), timezone, and custom fields configured by your organization.
- Learning records: enrollments, completions (including imported historical completions), scores, attempts, attendance, and certificates.
- Authentication: bcrypt password hashes, TOTP (MFA) secrets, single sign-on identifiers, and session data.
- Usage and technical: audit-log entries (including IP address and user agent), login events, and non-identifying application logs.
- Billing: billing contact, invoices, GST/HST numbers, and purchase orders. We do not store payment-card data — card details are captured and held by Stripe through Stripe-served payment UI (hosted pages or embedded Stripe iframes).
- Content-embedded: virtual instructor-led training (VILT) recordings, assignment uploads, and discussion posts.
We do not collect Social Insurance Numbers or other government IDs, health data, biometrics, precise geolocation, or payment-card numbers.
How and why we use information, and our lawful bases
- To provide, secure, and support the service under our contract with the tenant.
- To help the tenant meet its own legal training and record-keeping obligations.
- To operate optional features (for example, marketing communications) on a consent basis.
- To maintain security, prevent abuse, and keep an append-only audit trail.
Where GDPR applies, our lawful bases are: performance of a contract, compliance with a legal obligation, our legitimate interests (such as securing the platform), and consent for optional features.
Where your data is stored (data residency)
Core learning records and the user directory are stored at rest in Canada — on AWS in the ca-central-1 (Montreal) region and on Supabase’s Canadian region. Some sub-processors process limited or transient data outside Canada, as described below and on our Sub-processors page.
Sub-processors
We engage a small set of vetted sub-processors to help deliver the service. The current list, with each provider’s purpose, data, location, and safeguards, is published on our Sub-processors page. Each is bound by a data processing agreement.
International transfers (Law 25 s.17)
Before any transfer of personal information outside Quebec, we assess the transfer as required by section 17 of Law 25. Limited transfers to sub-processors outside Canada (for example, Vercel edge compute, Zoom, Stripe, HubSpot, and Railway) are covered by data processing agreements, encryption in transit, and data minimization. Sensitive core data — learning records and the user directory — stays in Canada.
How long we keep it
- Training completion records: retained 7 years using an “anonymize-don’t-delete” approach — identity is replaced with an irreversible pseudonym while the completion fact, date, and score are preserved — then hard-deleted.
- Audit logs: 3 years (append-only).
- Account personal information: for the life of the account plus 90 days after deactivation; deleted on a verified Law 25 request, except fields embedded in records under legal retention, which are anonymized instead.
- Authentication secrets: destroyed on rotation or deletion.
- VILT recordings: tenant-configurable; default 1 year.
- Quiz item-level detail: 2 years.
- Application logs: 13 months.
- Billing records: 7 years (tax law).
- Backups: 35-day rolling window.
- Tenant data after a contract ends: read-only at 30 days, purged at 90 days.
- Prospect / marketing data: 24 months.
Your rights
Subject to applicable law, you may exercise the following rights, and we aim to respond within 30 days:
- Access to your personal information;
- Rectification of inaccurate or incomplete information;
- Deletion or de-indexation;
- Data portability (available under Law 25 since September 2024);
- Withdrawal of consent (for example, marketing communications under CASL);
- Escalation of a complaint.
You can exercise most rights directly in your profile, through your organization’s administrator, via our privacy request form, or by emailing privacy@embaylms.com. Because your employer is the controller of learner data held on its behalf, requests about that data are routed to your employer.
How to complain
If you are not satisfied with our response, you may escalate to the Commission d’accès à l’information du Québec (CAI), the Office of the Privacy Commissioner of Canada (OPC), or, for EU/UK data subjects, your local supervisory authority.
Cookies
Our website uses only strictly necessary cookies today, and any future analytics or marketing cookies are gated behind consent. See our Cookie Policy for details.
Security
We protect personal information with technical and organizational measures including TLS 1.2+ in transit, AWS KMS encryption at rest, bcrypt password hashing, multi-factor authentication, role-based access control, schema isolation between tenants, and append-only audit logging. Payment-card processing is handled by Stripe: card data is entered only into Stripe-served payment UI (hosted pages or embedded Stripe iframes) and never touches EmbayLMS servers; our PCI DSS scope is SAQ A / A-EP, pending QSA determination. Our SOC 2 controls operate from day one; a SOC 2 Type II report is targeted as our audit history matures.
Breach notification
We maintain a confidentiality-incident procedure and a confidentiality incident register (Law 25 s.3.8). Where a confidentiality incident presents a risk of serious injury, we notify the CAI or OPC and affected persons, targeting notification within 72 hours of detection.
Children
EmbayLMS is a workplace training platform used by employers for their adult workforce. The service is not directed to children under 14 (Quebec) or 16, and we do not knowingly collect personal information directly from children.
GDPR / EU-UK notice
Where the GDPR or UK GDPR applies, EmbayLMS generally acts as a processor for personal data in a tenant workspace, and the tenant is the controller. Our lawful bases are contract, legal obligation, legitimate interests, and consent. Data subjects in the EEA or UK have rights of access, rectification, erasure, restriction, portability, and objection, and may lodge a complaint with their supervisory authority. Transfers outside the EEA/UK rely on appropriate safeguards such as Standard Contractual Clauses where required.
Changes to this policy
We may update this policy from time to time. Material changes will be reflected by the “last updated” date above and, where appropriate, communicated to affected customers.
Contact
For any privacy question or to exercise a right, contact our Privacy Officer, Mathieu Brillon, at privacy@embaylms.com.
Privacy Officer
Mathieu Brillon, acting Privacy Officer, Embay Consulting Inc. — privacy@embaylms.com