Sidian Technologies Corp.
Privacy Policy
Last updated September 28, 2026
Contents 14 sections
1. Who we are and what this covers#
Sidian Technologies Corp. ("Sidian", "we", "us") is a company organized in British Columbia, Canada. This policy covers the sidian.io website and our products and services, including the DataGuard web application, admin portal, Outlook add-in, API and AI Vault connector (together, the "Services").
If your organization has signed an agreement with us that covers how we handle its data, that agreement takes precedence over this policy where the two differ.
2. Two kinds of data, two roles#
Account and website data. Information about you as a visitor, a user, or a customer contact. We decide how it is used and we answer requests about it directly.
Customer Content. The documents, emails, files, messages and other material your organization puts through the Services, the sensitive values we detect in them, and everything we produce from them. We process Customer Content on behalf of the organization that holds the account and according to its settings and instructions.
If you are named in a document that a law firm or other customer processed with the Services, that organization is responsible for your information. Please contact it directly. If you contact us, we will pass your request to the organization and help it respond.
3. What we collect#
When you visit sidian.io
- Pages you view, the page that referred you, your browser and device type, and an approximate location derived from your IP address, collected through the analytics and advertising tools described in section 7.
- If you book a demo, the details you enter into Calendly, such as your name, email address and answers to its questions.
- If you request access to our investor materials, your email address and, if you give them, your name and firm.
- If you fill in a form on one of our pages, the details you enter (such as name, email address, company and role) and the campaign parameters in the link that brought you there.
When you have an account
- Your name, email address, organization and role, and the identifiers your sign-in provider gives us (for example, a Microsoft account ID and tenant ID).
- Billing information: plan, seat count, billing contact and subscription identifiers. Card details are handled by our payment provider or by Microsoft Marketplace; we do not receive card numbers.
- A record that you accepted our terms, including your name, email address, IP address, browser details and the time.
Customer Content
- Files you upload, and files you connect from Microsoft OneDrive, SharePoint or Google Drive. We read connected files where they already live and do not keep a copy of them. We hold a file only while we process it, including while we produce the versions your organization asks for: redacted copies, protected copies, and synthetic versions in which detected values are replaced with stand-ins.
- Emails the Outlook add-in checks, including the subject, sender, recipients, body and attachments.
- The sensitive values we detect, such as names, identifiers and account numbers, together with the stand-in (pseudonym) we assign to each one, so that the same value is always replaced the same way.
- Messages you write in review sessions, and policies you upload to configure the Services.
Connected accounts
When you connect Microsoft 365 or Google Drive, we store an encrypted authorization token so the Services can fetch the files you connected when you are not signed in. We ask only for the permissions shown on the consent screen. You can revoke access at any time in your Microsoft or Google account settings, or ask your administrator to disconnect it.
Security and service records
- Records of actions taken in the Services, such as who opened, approved, shared or changed a file, and the IP address and browser used to open a shared folder.
- Error reports and service logs. We remove request bodies and attached data from error reports. Service logs can include file names, and the logs of the model services that analyze documents can include document content.
4. How we use it#
- To provide the Services: detecting sensitive content, redacting or replacing it, producing the copies your organization asks for, and sending what your settings allow.
- To keep the Services secure, investigate problems, and prevent misuse.
- To provide support. See section 9 for how support access to Customer Content is limited.
- To bill for the Services and send service messages, such as invitations, sign-in links and notices about your files.
- To understand how people use sidian.io and to measure our advertising.
- To meet legal obligations and enforce our terms.
We do not use Customer Content to train or fine-tune machine-learning models, and we do not permit our service providers to do so. We may use aggregate operational measurements that contain no Customer Content, such as processing times and error rates, to run and improve the Services.
5. How detection and AI processing work, and their limits#
Detection runs on models we operate on dedicated cloud infrastructure. To find sensitive content, those models read the original content.
Every model in the Services, including the ones that analyze your policies and answer in review sessions, is one we operate. We do not send your content to Anthropic, OpenAI or any other third-party AI model provider. The only way your content reaches an outside AI tool is if your organization connects one through AI Vault.
When your organization connects an AI tool such as Claude, ChatGPT or Copilot to a folder through AI Vault, that tool receives synthetic versions of your files in which detected values are replaced with stand-ins. Please understand the limits of this:
- Detection is automated and can miss things. It is less reliable on scanned pages, handwriting, images and complex tables. Anything it misses is passed through unchanged.
- Your settings decide what is replaced. Protection presets and label settings chosen by your organization can let some categories pass unchanged. For example, the standard presets pass amounts, dates and the substance of legal text so that AI tools can reason about them.
- Stand-ins are not anonymization. Replacing names and identifiers reduces what an AI tool learns, but the remaining context can still identify a person or matter.
- The AI tool's own terms govern what it receives. Once a connected tool has read a file, its provider's terms and privacy policy apply to that copy.
- Changes can apply automatically. By default, edits a connected AI tool makes to files in an AI Vault folder are applied without a person approving them. An administrator or folder owner can require approval.
8. Where your data is stored#
Sidian is based in Canada. The Services are hosted in the United States: our database and backups are in the western US and our web application runs in the eastern US. Some of the providers in section 6 may process data in other countries.
Information stored or processed outside your country is subject to the laws of the country where it is held, and courts, law enforcement and national security authorities there may be able to access it.
9. How we protect it#
- Connections to the Services are encrypted in transit using HTTPS.
- Our hosting providers state that they encrypt stored data at rest. We additionally encrypt some data ourselves: the store that maps each stand-in back to its original value uses a separate key for each organization, and we encrypt connected-account tokens and the email bodies and attachments recorded by the Outlook add-in.
- Other data, including files while we process them and copies of detected values kept in analysis and audit records, relies on our hosting providers' encryption rather than ours.
- Access within the Services is limited to members of your organization according to the roles your administrators assign.
- Sidian support staff who access your organization through the Services cannot view document content, and their actions there are recorded.
- A small number of Sidian engineers who operate our infrastructure can technically access stored data, including Customer Content. We limit this to what is needed to run, secure and repair the Services.
No system is perfectly secure, and we cannot guarantee that information will never be accessed, disclosed or lost. If a breach of security leads to the accidental or unlawful destruction, loss, alteration or unauthorized disclosure of, or access to, Customer Content, we will notify the affected customer without undue delay and within 72 hours of becoming aware of it. We will notify regulators and individuals where the law requires.
10. How long we keep it#
- Files are held only while we process them. We do not keep copies of your files.
- Other Customer Content, such as detected values, their stand-ins, review messages and uploaded policies, is kept while your organization's account is active, until your organization deletes it. Deleting a folder or review session deletes its records.
- When an account closes, the organization has 30 days to export its Customer Content. Within a further 30 days we delete the organization's data, including Customer Content, detected values and connected-account tokens, or sooner if it asks us to. Deleted data remains in our backups for about four weeks before the backups expire.
- Records we keep longer: billing records, records of terms acceptance and security audit records are kept as long as we need them for legal, tax, accounting and security purposes, including after an account closes.
- Users removed from an organization by an administrator have their user account deleted.
- Website analytics are kept by each provider according to its own retention settings.
11. Your rights and choices#
Depending on where you live, you may have the right to ask for access to the personal information we hold about you, to have it corrected or deleted, to receive a copy of it, to object to or limit certain uses of it, and to withdraw consent you have given. You will not be treated differently for exercising these rights.
To make a request, email [email protected]. We will confirm your identity before acting and respond within 30 days, or tell you if we need longer and why. Requests about Customer Content are handled with the organization responsible for it (see section 2). Some information may be kept where the law requires it or allows it, for example billing records.
If you are not satisfied with our response, you can complain to a privacy regulator: in Canada, the Office of the Privacy Commissioner of Canada or the Office of the Information and Privacy Commissioner for British Columbia; in the EU or UK, your local data protection authority.
12. Children#
The Services are for businesses and professionals and are not intended for anyone under 18. We do not knowingly collect personal information from children.
13. Changes to this policy#
We will update this policy as the Services change, and change the date at the top of the page when we do. If a change materially affects how we handle Customer Content, we will tell account administrators by email or in the Services before it takes effect.
14. Contact us#
Sidian Technologies Corp. is responsible for the personal information described in this policy. For questions, requests or complaints, contact our privacy contact at [email protected], or write to us at Sidian Technologies Corp., 1824 Store Street, Second Floor, Victoria, BC V8T 4R4, Canada.
See also Terms of Service