Merci Sam
S

Privacy Policy

MerciSam Privacy Policy

 

Effective Date: March 01, 2026

This Privacy Policy (hereinafter the « Policy ») describes how MerciSam, a corporation (inc.) duly incorporated under the laws of Quebec, Canada (hereinafter « MerciSam, » « We, » « Our, » or « Us »), collects, uses, communicates, retains, and protects the personal information of its users (hereinafter the « User » or « You ») in connection with the use of the MerciSam platform (hereinafter the « Platform » or the « Service »).

 

We are committed to protecting the confidentiality and security of Your personal information in accordance with applicable data protection laws in Quebec and Canada, notably the Act respecting the protection of personal information in the private sector (Law 25).

 

  1. Person Responsible for the Protection of Personal Information

 

The Person Responsible for the Protection of Personal Information at MerciSam is:

  • Name: Mathias Le Brun
  • Title: Person Responsible for the Protection of Personal Information
  • Email: mathias@mercisam.ca

For any questions or requests concerning this Policy or the management of Your personal information, You may contact Mathias Le Brun at the coordinates indicated above.

 

  1. Definitions

 

For the purposes of this Policy, the following terms shall have the meaning defined below:

  • Personal Information: Any information that concerns a physical person and allows them to be identified, directly or indirectly. This includes, but is not limited to, name, address, email address, phone number, date of birth, financial information, etc.
  • Processing: Any operation or set of operations which is performed on personal information, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
  • Platform / Service: Refers to the MerciSam intelligent virtual assistant platform, accessible via its web interface.
  • User: Any physical person who accesses the Platform, creates an account thereon, or uses the services offered by MerciSam.
  1. Collection of Personal Information

 

We collect different types of personal information in various ways, in order to continuously provide and improve Our services.

 

3.1. Categories of Personal Information Collected

 

We collect the following categories of personal information:

  • Identification and contact data: Name, first name, email address, phone number, primary residence address, date of birth.
  • Account and authentication data: Username, password (encrypted), login information.
  • Data related to managed real estate: Full addresses of properties, property types (e.g., apartment, duplex), number of units, acquisition dates, lease information (start/end dates, initial rent, specific clauses).
  • Data related to tenants: Names, first names, contact information (email, phone), information provided in applications (e.g., credit history, references, employment), and, if the User uploads them, copies of tenants’ identification documents (e.g., driver’s license) or other supporting documents.
  • Financial data: Banking information (account number, credit card information – processed by trusted third parties), transaction history related to rent and expenses (receipts, invoices), income and expense statements associated with properties.
  • Usage and activity data: Activity logs on the Platform (connections, actions performed, features used), interactions with the AI assistant Sam (queries, responses), messages exchanged via the Platform’s internal messaging system.
  • Technical and navigation data: IP address, browser type, operating system, unique device identifiers, pages visited, duration of visit, navigation paths, approximate location data (deduced from the IP address). This data is often collected via cookies and similar technologies (see our Cookie Policy).

3.2. Collection Methods

 

We collect Your personal information in several ways:

  • Directly from You: When You create an account, fill out forms on the Platform, upload documents, communicate with Our customer support, or interact directly with Sam (the AI).
  • Automatically: During Your navigation on the Platform, via cookies, web beacons, and other tracking technologies (see our Cookie Policy for more details).
  • From third parties (with Your consent or if permitted by law): For example, via credit investigation service providers if You use this feature, or technology partners.
  1. Purposes of Personal Information Processing

 

We process Your personal information only for the following specific, explicit, and legitimate purposes:

  • Provision and management of the Service:
    • Creation and management of Your user account.
    • Authentication and securing Your access to the Platform.
    • Access to the Platform’s functionalities (listing, daily management, administrative automation, financial steering).
    • Processing of subscription payments and one-time fees.
    • Sending of essential notifications and alerts for the operation of the Service (e.g., rent reminders, legal alerts, transaction confirmations).
    • Allowing the sharing of property management in co-ownership between distinct accounts.
  • Product Improvement and Development:
    • Analysis of Service usage to identify User needs, develop new features, and optimize the user experience.
    • Improvement of the performance of the AI assistant Sam and its recommendations through machine learning on anonymized and aggregated data.
    • Conducting tests and diagnostics to ensure the stability and performance of the Platform.
  • User Support:
    • Responding to Your technical support, assistance, and information requests.
    • Resolving technical or functional problems You may encounter.
  • Experience Personalization:
    • Adapting the content, recommendations, and AI features to the specific needs of Your real estate portfolio and Your User profile.
  • Analysis and Optimization:
    • Conducting anonymized and aggregated statistical analyses on usage trends, property performance, and rental markets, in order to identify optimization levers (e.g., reducing vacancies, adjusting rents, anticipating charges).
  • Security and Fraud Prevention:
    • Monitoring activity on the Platform to detect and prevent abusive, fraudulent, or illegal uses.
    • Protecting systems and data against unauthorized access, cyberattacks, and other threats.
  • Legal and Regulatory Compliance:
    • Complying with Our legal, regulatory, and contractual obligations, notably in tax matters, anti-money laundering, and personal information protection (Law 25).
    • Responding to legal requests from competent authorities.
  • Communication and Marketing (with Your consent):
    • Sending marketing communications, newsletters, promotional offers, or information about new features, if You have given Your prior consent. You have the right to withdraw this consent at any time.
  1. Legal Bases for Processing

 

We process Your personal information on the following legal bases:

  • Execution of a contract: Processing is necessary for the performance of the General Terms of Use (GTU) and the General Terms of Service (GTS) that You accepted by using Our Platform.
  • Your consent: For certain specific purposes (e.g., sending marketing communications, use of certain non-essential cookies), We obtain Your explicit and prior consent. You have the right to withdraw Your consent at any time.
  • Legitimate interest: Processing is necessary for the purposes of the legitimate interests pursued by MerciSam, such as improving Our services, preventing fraud, Platform security, performance analysis, provided that these interests do not override Your interests or Your fundamental rights and freedoms.
  • Legal obligation: Processing is necessary for Us to comply with a legal or regulatory obligation to which We are subject (e.g., tax obligations, anti-money laundering, compliance with Law 25).
  1. Communication and Sharing of Personal Information

 

We do not sell or rent Your personal information to third parties. However, We may disclose Your personal information to third parties in the following circumstances, and always in compliance with applicable laws:

  • To Our subcontractors and service providers:
    We use third-party companies to perform certain functions on Our behalf (e.g., hosting, payment processing, email sending, customer support, audience analysis). These subcontractors only have access to the personal information necessary for the performance of their services and are contractually bound to maintain the confidentiality and security of this data, and to process it in accordance with Our instructions and Law 25.

    • List of Our main subcontractors:
      • PorkBun: For hosting the Platform and data.
      • Stripe: For secure processing of credit card payments and automatic debits.
      • MailChimp: For sending transactional emails and marketing communications (if consented).
      • Zendesk: For managing customer support and online chat service.
      • Google Analytics: For collecting anonymized and aggregated usage statistics of the Platform.
  • To professional partners (with Your consent): If You use Platform features that involve connecting with third-party professionals (e.g., tradespeople, lawyers), We may share the necessary information for this connection, only with Your explicit consent.
  • In the event of a corporate transaction: As part of a merger, acquisition, asset sale, or any other transaction involving all or part of MerciSam, Your personal information could be transferred to the acquiring party, provided that the latter undertakes to respect this Privacy Policy.
  • To legal and regulatory authorities: When required or permitted by law, We may disclose Your personal information in response to a court order, a request from a governmental authority, a subpoena, or to protect Our rights, Our property or Our safety, as well as those of Our Users or the public.
  1. Retention of Personal Information

 

We retain Your personal information only for the duration necessary to achieve the purposes for which it was collected, as well as to comply with Our legal and regulatory obligations (e.g., tax obligations, retention of evidence in the event of a dispute).

 

The retention period varies depending on the nature of the information and the purposes of processing:

  • Account Data: Retained as long as Your account is active. After the deletion of Your account, certain data may be retained for thirty (30) days to allow for User recovery (in accordance with Law 25), and then securely deleted, unless a longer legal retention obligation applies.
  • Financial and Transaction Data: Retained for the legal duration required by tax and accounting laws (generally 7 years in Canada).
  • Activity Logs and Technical Data: Retained for shorter periods for security and analysis purposes (e.g., 12 to 24 months).
  • Anonymized and Aggregated Data: Data that has been irreversibly anonymized may be retained indefinitely for statistical purposes and Service improvement, as it no longer allows the identification of a person.

Once the retention period has expired, personal information is securely destroyed or anonymized.

 

  1. Security of Personal Information

 

We implement rigorous physical, technical, and administrative security measures in accordance with industry best practices to protect Your personal information against loss, theft, unauthorized access, disclosure, copying, unauthorized use, or modification.

 

Our security measures include, without being limited to:

  • Encryption: Use of AES-256 (Advanced Encryption Standard 256-bit) encryption for sensitive data, both in transit (via TLS/SSL protocols) and at rest on Our servers.
  • Strict access controls: Access to personal information limited to authorized MerciSam personnel who need it for the performance of their duties, based on the principle of least privilege.
  • Strong authentication: Requirement of complex passwords and, eventually, implementation of two-factor authentication (2FA) for user account access.
  • Infrastructure security: Hosting of data on secure PorkBun servers in Montreal (Quebec), benefiting from their advanced security measures (physical security of data centers, firewalls, intrusion detection).
  • Regular backups: Conducting regular data backups to ensure resilience and recovery in the event of a major incident.
  • Monitoring and incident detection: Implementation of monitoring systems to detect suspicious activity and a plan for responding to data security incidents.
  • Staff awareness: Regular training of Our personnel on best practices in personal information protection and information security.

Despite these measures, no method of transmission over the Internet or electronic storage is completely secure. Therefore, We cannot guarantee absolute security of Your personal information.

 

  1. User Rights (Law 25 Compliance)

 

In accordance with Quebec’s Law 25, You have specific rights regarding Your personal information. To exercise these rights, please contact Our Person Responsible for the Protection of Personal Information (coordinates in section 1). We will respond to Your request within the deadlines prescribed by law.

 

Your rights include:

  • Right of access: You have the right to obtain confirmation that personal information concerning You is being processed by MerciSam, and to obtain a copy thereof.
  • Right of rectification: You have the right to request the correction of inaccurate, incomplete, or ambiguous personal information concerning You.
  • Right to portability: You have the right to receive the personal information You have provided to Us, in a structured, commonly used, and machine-readable format, and to transmit it to another organization without hindrance from Us.
  • Right to erasure (right to be forgotten): You have the right to request the deletion of Your personal information, subject to any legal retention obligations that may be incumbent upon Us.
  • Right to withdraw Your consent: Where the processing of Your personal information is based on Your consent, You have the right to withdraw this consent at any time, without affecting the lawfulness of the processing based on consent carried out before such withdrawal.
  • Right to be informed of the use of artificial intelligence technology: You have the right to be informed when Your personal information is used to make a decision based exclusively on automated processing (e.g., by the AI Sam), and to be informed of the main factors that led to this decision, as well as the possibility of having the decision rectified.
  • Right to file a complaint: You have the right to file a complaint with the Commission d’accès à l’information du Québec (CAI) if You believe that Your rights regarding the protection of personal information have not been respected.

We commit to responding to any request for access, rectification, or portability within 48 business hours for the initial response, and to carry out the necessary actions within an additional 72 business hours, in accordance with the requirements of Law 25.

 

  1. Transfers of Personal Information Abroad

 

We confirm that all personal information collected by MerciSam is exclusively hosted and processed in Canada, on servers located in Montreal (Quebec). We do not transfer Your personal information outside of Canada. If, in the future, a data transfer outside Quebec were envisaged, We would ensure that adequate protection measures are in place and that You would be informed and, where applicable, Your consent would be collected, in accordance with Law 25.

 

  1. Modifications to the Privacy Policy

 

We reserve the right to modify this Privacy Policy at any time. Any substantial modification will be brought to Your attention by a notice on the Platform and/or by email, at least thirty (30) days before its entry into force. We encourage You to consult this Policy regularly to stay informed of Our practices regarding the protection of personal information. The date of the last update will be indicated at the top of the document.

 

  1. Contact Us

 

For any questions, comments, or requests concerning this Privacy Policy or Our practices regarding the protection of personal information, please contact Our Person Responsible for the Protection of Personal Information:

 

Mathias Le Brun

Email: mathias@mercisam.ca

Phone: 438-800-8798