This Privacy Policy explains how Nametech Canada Ltd. ("Nametech", "we", "us") collects, uses, discloses and protects personal information in connection with the NameCRM application, its client portals, its phone assistant and its website (together, the "Service").
Nametech Canada Ltd. is a company based in Surrey, British Columbia, and the Service is offered to businesses in Canada. Our handling of personal information in British Columbia is governed by BC's Personal Information Protection Act (PIPA). When personal information crosses a provincial or national border in the course of our business, including when a service provider outside Canada processes it for us, Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) also applies. We follow both. Commercial email and text messages sent through the Service are subject to Canada's Anti-Spam Legislation (CASL).
We handle two kinds of personal information, and our role is different for each.
If you are a client or contact of a business that uses NameCRM and you have a question about your information, please contact that business first. If you contact us instead, we will pass your request to the business and help it respond.
We use personal information only for purposes a reasonable person would consider appropriate in the circumstances, and we tell you those purposes at or before the time we collect it. We use it to:
We do not sell personal information, and we do not use Customer Data to advertise to anyone.
We collect, use and disclose personal information with the knowledge and consent of the person it is about, except where the law permits or requires otherwise. Depending on the sensitivity of the information and the situation, consent may be express or implied. You may withdraw consent at any time, subject to legal or contractual restrictions and reasonable notice, by contacting our Privacy Officer (Section 18). We will tell you what withdrawing consent means for you; for example, we may no longer be able to provide part or all of the Service.
For Customer Data, the business that uses NameCRM is responsible for obtaining any consent its contacts must give.
NameCRM lets a business send commercial electronic messages, such as newsletters and promotional emails or text messages, to its contacts. The business is responsible for having the consent CASL requires before it sends them. The Service supports CASL compliance by:
The messages we send to account holders about their own account (such as security, billing and service notices) are sent to provide the Service. If we send you marketing about our own products, we will do so only with your consent, and every such message will let you unsubscribe.
A business can use NameCRM's AI phone assistant to answer its calls. The assistant tells callers at the start of the call that the call is recorded. The call audio is recorded and transcribed so the business has a record of what was said and can follow up. Speech is transcribed by Deepgram, and the assistant's spoken voice is produced by ElevenLabs. Calls are carried by Twilio.
A business can also record and transcribe its own meetings and calls through the Service. When it does, the business is responsible for telling the other participants and for obtaining any consent the law requires.
Recordings and transcripts are Customer Data. They are kept and deleted under the rules in Section 11.
Some features of the Service use artificial intelligence: drafting messages, assistants that answer questions or carry out tasks inside the Service, the AI phone assistant, and transcription of calls and meetings. To provide these features, the content needed for the task (for example, a contact record, a message thread or call audio) is sent to the AI provider that performs it: Anthropic for drafting and assistants, Deepgram for speech to text, and ElevenLabs for the phone assistant's voice. These providers process that content to return a result to the Service. We have set each of these AI providers so that the content we send them is not used to train their models.
AI output can be wrong or incomplete. A business using these features is responsible for checking what it sends to its own clients.
We do not sell or rent personal information. We disclose it only as follows.
We use the service providers below to run the Service. They process personal information on our behalf, under contracts that limit their use of it to providing their service to us. We remain responsible for personal information we transfer to them for processing.
When a business connects its own account with one of these providers (for example its Microsoft 365 mailbox, Google Calendar or QuickBooks), the provider's own terms and privacy policy also apply to that account.
Our database and file storage are located in Canada. However, the servers that run the application are provided by Vercel and operate in the United States, and several of the service providers listed in Section 9 operate in the United States or other countries. This means personal information is processed outside Canada, including in the United States.
While personal information is outside Canada, it is subject to the laws of the country where it is processed, and the courts, law enforcement and national security authorities of that country may be able to access it. We remain accountable for personal information we transfer to service providers for processing, and we use contractual and other means to require a comparable level of protection while they process it.
We keep personal information only as long as it is needed for the purposes described in this policy, or longer where the law requires it.
When personal information is no longer needed, we delete it or make it anonymous.
We protect personal information with security safeguards appropriate to its sensitivity, including encryption in transit, access controls and authentication, and row-level access rules in the database so that one account cannot read another account's data. Our service providers are required to protect the information they process for us. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
If a breach of security safeguards involving personal information under our control creates a real risk of significant harm to anyone, we will report it to the Office of the Privacy Commissioner of Canada and notify the affected individuals as soon as feasible, as PIPEDA requires. We keep a record of every breach of security safeguards, whether or not it must be reported.
If a breach affects Customer Data, we will tell the affected business without undue delay and give it the information we have, so it can meet its own obligations to its contacts.
Subject to the limited exceptions in PIPA and PIPEDA, you may:
Send your request to our Privacy Officer (Section 18). We may need to confirm your identity first. We will respond in writing within 30 days. If we need more time, as the law allows in some cases, we will tell you within those 30 days, explain why and say when you can expect a response. If we refuse a request, we will tell you why. If you are a contact of a business that uses NameCRM, see Section 2.
If you are not satisfied with our response, you may complain to the Office of the Information and Privacy Commissioner for British Columbia or the Office of the Privacy Commissioner of Canada.
The Service uses only the cookies and browser storage it needs to work: to keep you signed in and to remember preferences such as your theme. We do not use third-party advertising cookies or cross-site tracking.
Client portal analytics. When a business shares a client portal, the portal records which pages its visitors view and what they click, and shows this to that business so it can see what its client has opened. The portal also records failed password attempts, together with a scrambled (hashed) form of the network address, to stop password guessing. This information stays with the business that owns the portal and is not shared with advertisers.
Some pages load fonts or code libraries from public content delivery networks, such as Google Fonts and jsDelivr. As with any web request, those networks receive your device's IP address and browser details when the page loads.
The Service is intended for businesses and is not directed to individuals under the age of 19. We do not knowingly collect personal information from children. If you believe a child has given us personal information, contact our Privacy Officer and we will delete it.
We may update this Privacy Policy from time to time. We will post the updated version here and change the "last updated" date. If we make a material change, we will notify account holders by email or in the Service before it takes effect, and where a change means using personal information for a new purpose, we will ask for consent where the law requires it.
For questions, access or correction requests, or privacy concerns, contact our Privacy Officer: