Privacy and personal information protection policy
This policy explains what personal information we collect, why, with whom we share it, where it is hosted, how long we keep it and what rights you can exercise.
Preliminary version of 11 August 2026. This document was drafted from a technical inventory of the website and the application. It has not yet been reviewed by legal counsel. The passages in square brackets must be completed by the publisher. Until that review has taken place, this text cannot be relied upon as a contractual commitment.
1. Who is responsible for your information
SupplyCore Software is a brand of 9550-5582 Québec Inc., a company incorporated in Quebec (Canada) and presented on this site under the Anmaer Software banner. In this document, “SupplyCore”, “we” and “our” refer to that company.
- Mailing address: [ADDRESS TO BE COMPLETED]
- Sales: ventes@supplycoresoftware.com
- Support: support@supplycoresoftware.com
- Telephone: +1-450-328-8448
2. Person in charge of the protection of personal information
Quebec law (Act respecting the protection of personal information in the private sector, section 3.1, as amended by Law 25 (Quebec)) requires that a person within the company be responsible for the protection of personal information, and that their title and contact details be published.
- Person in charge: [TO BE DESIGNATED — NAME AND TITLE]
- Dedicated contact address: [TO BE DESIGNATED — FOR EXAMPLE confidentialite@supplycoresoftware.com]
This designation is a legal obligation and has not yet been fulfilled. It must be completed before this policy goes definitively live.
3. Information we collect
3.1 Website contact form
When you fill in the contact form, we collect: first name, last name, business email, telephone, company, country or province, industry, number of warehouses, planned go-live timeframe, plan of interest, the message you write and, where applicable, your consent to receive our communications. This information is encrypted (AES-256-GCM) and then delivered to an internal mailbox.
3.2 Data processed in the application by our clients
When a client company uses the platform, it may contain information about its employees (including, depending on the configuration, social insurance numbers and banking details, encrypted at rest), its business customers, its contacts, its drivers, its portal users, documents and a tamper-proof audit log.
For this data, the client company is the data controller and SupplyCore acts as a service provider: we process this information only on its instructions and in order to provide it with the platform.
3.3 Website audience measurement
We measure website traffic with Plausible, which produces aggregate statistics without placing a cookie and without any persistent individual identifier.
3.4 Technical logs
Like any web service, our hosting keeps technical logs (IP address, timestamp, page requested, user agent) needed for security, fault diagnosis and abuse prevention. Retention period: [PERIOD TO BE CONFIRMED].
4. Why we use this information
| Purpose | Information used | Basis |
|---|---|---|
| Responding to a request for information, a demonstration or a proposal | Contact form | Steps taken at your request before entering into a contract |
| Sending you marketing communications | Name, email | Your consent (checkbox), withdrawable at any time |
| Providing, operating and developing the platform | Client account data | Performance of the subscription agreement |
| Security, abuse prevention, audit log | Technical logs, audit log | Legitimate interest and legal obligations |
| Billing and keeping accounting records | Billing data | Legal obligation |
| Understanding how the site is used | Aggregate statistics without cookies | Legitimate interest |
5. What we do not do
We do not sell or rent your personal information. We do not use it for targeted advertising and we do not pass it on to data brokers.
6. Who has access to your information
We use the following providers, each for a specific function:
| Provider | Role | Place of processing |
|---|---|---|
| Hetzner | Hosting of the server that runs the website and the application | Helsinki, Finland |
| Cloudflare | DNS resolution and site delivery | Global network |
| Plausible | Aggregate audience measurement, without cookies | [TO BE CONFIRMED] |
| n0c | Email service | [TO BE CONFIRMED] |
| Stripe | Payment processing (planned, not yet enabled) | [TO BE CONFIRMED] |
| Provider of the support widget embedded in the website | Live support messaging | [TO BE CONFIRMED — PROVIDER NAME AND LOCATION] |
| Provider of the artificial intelligence model | Operational agents within the application | [TO BE CONFIRMED — PROVIDER NAME AND LOCATION] |
We may also disclose information where the law requires it (court order, request from a competent authority) or in order to assert our rights.
7. Hosting and disclosure outside Quebec
Important point: our servers are located in Helsinki, Finland. Your information is therefore stored and processed outside Quebec and Canada.
Section 17 of the Act respecting the protection of personal information in the private sector requires, before disclosing personal information outside Quebec, a privacy impact assessment establishing that the information would receive adequate protection. Status of that assessment: [ASSESSMENT TO BE CARRIED OUT AND DOCUMENTED].
For people residing in the European Union or the European Economic Area: the data is hosted in Finland, therefore within the EEA. Administrative access carried out from Canada does, however, constitute a transfer to a third country; the applicable safeguard mechanism remains to be confirmed: [MECHANISM TO BE CONFIRMED — ADEQUACY DECISION APPLICABLE TO CANADA OR STANDARD CONTRACTUAL CLAUSES].
8. How long we keep your information
The platform applies a retention policy structured around 14 data categories, together with minimum periods imposed by law that cannot be shortened. For example: six years for accounting records and seventy-two months for payroll registers, under section 230 of the Income Tax Act.
| Type of information | Retention period |
|---|---|
| Requests received through the contact form | [PERIOD TO BE CONFIRMED] |
| Technical server logs | [PERIOD TO BE CONFIRMED] |
| Client account data after the end of the contract | [PERIOD TO BE CONFIRMED], subject to the legal minimums |
| Accounting records and payroll registers | Six years / seventy-two months, legal minimums that cannot be changed |
| Register of confidentiality incidents | Five years after the date of the incident, in accordance with Law 25 (Quebec) |
At the end of these periods, the information is deleted or irreversibly anonymised.
9. Your rights
Depending on where you live, you have all or some of the following rights, which are technically implemented in the platform:
- Access: obtain confirmation that we hold information about you and receive a copy of it.
- Correction: have inaccurate, incomplete or ambiguous information corrected.
- Portability: receive your information in a structured, commonly used technological format.
- Erasure or anonymisation: request the deletion of your information, subject to the retention periods imposed by law.
- Withdrawal of consent: stop receiving our marketing communications at any time, including through the unsubscribe link.
- Objection and restriction: object to certain processing activities or ask that they be restricted.
- Automated decisions: be informed when a decision concerning you is made solely by automated processing, submit your observations and ask for a review by a person.
To exercise a right, write to the person in charge of the protection of personal information (section 2). We reply within the thirty days provided for by Quebec law; for people covered by the GDPR, the time limit is one month, extendable in complex cases.
10. Filing a complaint
If our answer does not satisfy you, you may refer the matter to the Commission d'accès à l'information du Québec (Quebec's access to information and privacy authority, cai.gouv.qc.ca). If you reside in the European Union or the European Economic Area, you may refer the matter to the data protection supervisory authority of your country of residence.
11. Automated decisions and artificial intelligence
The platform uses an artificial intelligence model to power agents that assist with certain operational tasks for our clients. Where a decision producing an effect on you is based exclusively on automated processing, you are informed of it at the time of the decision or before, you may submit your observations and ask that a person review the decision. These information and human review mechanisms are implemented in the product.
12. Security
The measures we apply include: encryption of communications in transit, encryption at rest of sensitive information (social insurance numbers, banking details, the content of requests sent through the form) using the AES-256-GCM algorithm, access control, a tamper-proof audit log, a consent register and a register of confidentiality incidents.
To date we hold no ISO 27001 certification and no SOC 2 attestation, and the service is operated from a single hosting site, without multi-region redundancy. No security measure can guarantee zero risk.
13. Confidentiality incidents
The platform maintains a register of confidentiality incidents. In the event of an incident presenting a risk of serious injury, we promptly notify the Commission d'accès à l'information and the individuals concerned, and we take reasonable measures to reduce the risk. The internal incident management procedure has yet to be formalised: [PROCEDURE TO BE FORMALISED AND DOCUMENTED].
14. Cookies
The public website places no advertising cookies and no third-party tracking cookies. Details of the cookies used are set out in our cookie policy.
15. Minors
Our services are intended for businesses and their professional representatives. We do not knowingly collect information from minors. If you notice that such information has been sent to us, write to us and we will delete it.
16. Changes to this policy
We may amend this policy to reflect legal, technical or organisational developments. The date of the last update appears at the top of the page. In the event of a significant change, we will inform the individuals concerned by reasonable means.
17. Contact us
For any question about this policy or about your personal information: [TO BE DESIGNATED — ADDRESS OF THE PERSON IN CHARGE], or support@supplycoresoftware.com, or by telephone at +1-450-328-8448. Mailing address: [ADDRESS TO BE COMPLETED].