Privacy Notice
This Privacy Notice describes how NorthQuinn Inc. d/b/a CanvasrIQ ("CanvasrIQ," "we," "our," or "us") collects, uses, discloses, retains, and protects personal information in connection with our website located at canvasriq.com and our lead generation platform (collectively, the "Service"). Please read this notice carefully. If you do not agree with the practices described herein, you should not use the Service.
- Scope and Applicability
- Information We Collect
- How We Collect Information
- Purposes and Legal Bases for Processing
- How We Disclose Information
- Data Retention
- Security
- Cookies and Tracking Technologies
- AI Voice Agent — Additional Privacy Disclosures
- Third-Party Services and Links
- California Privacy Rights (CCPA/CPRA)
- Nevada Privacy Rights
- Children's Privacy
- Email Communications and CAN-SPAM
- Transfers of Personal Information
- Changes to This Privacy Notice
- Contact and Data Subject Requests
1. Scope and Applicability
This Privacy Notice applies to personal information collected through the CanvasrIQ website (canvasriq.com), our waitlist and early access registration forms, our Voice Agent inquiry form, and any other interactions you have with us in connection with the Service. It does not apply to information collected by third parties whose websites may be linked to or accessible from our Service, or to information collected by our customers in connection with their own use of leads or data obtained through the Service.
CanvasrIQ is operated by NorthQuinn Inc., a Delaware corporation with its principal place of business in New York, New York. NorthQuinn Inc. is the data controller with respect to personal information collected through the Service.
2. Information We Collect
2.1 Information You Provide Directly
We collect personal information that you voluntarily provide when you interact with our Service, including:
- Identity information: First name, last name
- Contact information: Email address, telephone number
- Professional information: State of licensure, insurance line(s) of practice, agency or company name, team or organization size
- Communications: The content of any messages, inquiries, or other free-text information you submit through our contact forms
2.2 Information Collected Automatically
When you access our Service, certain information is automatically collected through our hosting infrastructure, including:
- Usage data: Pages visited, time and date of access, referring URLs, session duration, and navigation patterns
- Device and technical data: IP address, browser type and version, operating system, device identifiers, and screen resolution
- Network data: Internet service provider and approximate geolocation derived from IP address at the country and region level only
This automatically collected information is processed by Cloudflare, Inc., which provides our web hosting, content delivery, and security infrastructure. Please review Cloudflare's privacy policy at cloudflare.com/privacypolicy for more information.
2.3 Information We Do Not Collect
We do not collect sensitive categories of personal information such as Social Security numbers, government-issued identification numbers, financial account information, health or medical information, precise geolocation data, biometric data, or information about racial or ethnic origin, religious beliefs, or sexual orientation.
3. How We Collect Information
We collect personal information through the following channels:
- Waitlist and registration forms: When you complete our signup form to join the CanvasrIQ waitlist or early access program
- Voice Agent inquiry form: When you submit an inquiry through our Voice Agent module contact form
- Direct communications: When you contact us by email at hello@canvasriq.com
- Automatic collection: Through our hosting and security infrastructure as described in Section 2.2 above
Form submissions are processed through Web3Forms (web3forms.com), a third-party form handling service that transmits your submission to us via secure channels. Web3Forms processes your data solely to facilitate delivery of your submission and does not retain or use your personal information for its own purposes beyond the transmission period.
4. Purposes and Legal Bases for Processing
We process your personal information for the following purposes:
| Purpose | Categories of Data Used | Legal Basis |
|---|---|---|
| To add you to our waitlist and notify you of the CanvasrIQ launch | Identity, contact, professional information | Performance of a contract / your consent |
| To fulfill the 50 free leads offer to waitlist members at launch | Identity, contact, professional information | Performance of a contract |
| To respond to Voice Agent or general inquiries | Identity, contact, professional information, communications | Legitimate interests / your consent |
| To send product updates, launch announcements, and marketing communications | Identity, contact information | Your consent (with opt-out right) |
| To operate, maintain, and improve the security and performance of the Service | Usage data, device and technical data | Legitimate interests |
| To comply with applicable legal obligations | All categories as required | Legal obligation |
| To enforce our Terms of Service and protect our legal rights | All categories as relevant | Legitimate interests |
Where we rely on consent as the legal basis for processing, you have the right to withdraw your consent at any time by contacting us at hello@canvasriq.com. Withdrawal of consent does not affect the lawfulness of processing that occurred prior to withdrawal.
5. How We Disclose Information
5.1 Service Providers
We disclose personal information to third-party service providers that perform services on our behalf, including form processing (Web3Forms) and web hosting and security (Cloudflare). These providers are authorized to use your personal information only to the extent necessary to perform their obligations to us and are bound by confidentiality and data protection obligations.
5.2 Business Transfers
In the event of a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or substantially all of our assets, personal information held by us may be transferred to the successor entity. We will notify you of any such change in ownership or control of your personal information in accordance with applicable law.
5.3 Legal Requirements and Protection of Rights
We may disclose personal information if we believe in good faith that disclosure is necessary to: (a) comply with applicable law, regulation, legal process, or governmental request; (b) enforce our Terms of Service or other applicable agreements; (c) detect, prevent, or address fraud, security vulnerabilities, or technical issues; or (d) protect the rights, property, or safety of CanvasrIQ, our users, or the public.
5.4 With Your Consent
We may disclose personal information for any other purpose with your prior written consent.
5.5 No Sale of Personal Information
We do not sell, rent, trade, or otherwise transfer your personal information to third parties for their own marketing or commercial purposes. We do not engage in the sale of personal information as defined under the California Consumer Privacy Act or any comparable state statute.
6. Data Retention
We retain personal information for as long as necessary to fulfill the purposes for which it was collected, to provide the Service, to comply with our legal obligations, to resolve disputes, and to enforce our agreements. The following general retention periods apply:
- Waitlist and registration data: Retained until the earlier of (i) your request for deletion, (ii) two years following the date of collection if no active account or subscription relationship has been established, or (iii) such longer period as may be required by applicable law
- Voice Agent inquiry data: Retained for the duration of any active sales relationship and for a period of two years thereafter
- Communications and correspondence: Retained for a period of three years from the date of last communication
- Automatically collected usage data: Retained in accordance with Cloudflare's data retention practices
Upon expiration of the applicable retention period, we will securely delete or anonymize your personal information. Deletion requests will be processed as described in Section 16 below, subject to applicable legal exceptions.
7. Security
We implement and maintain commercially reasonable administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, use, disclosure, alteration, and destruction, including:
- Encrypted HTTPS connections with TLS for all data transmission
- Deployment of HTTP security headers including Content Security Policy, HTTP Strict Transport Security with preload, X-Frame-Options, and Cross-Origin policies
- API key management through server-side environment secrets, ensuring no credentials are exposed in client-facing code
- Rate limiting and bot detection on all data submission endpoints
- Infrastructure hosted on Cloudflare's globally distributed, SOC 2-certified network
No security system is impenetrable. In the event of a data breach reasonably likely to result in risk to your rights and freedoms, we will notify you and any applicable regulatory authorities as required by applicable law.
8. Cookies and Tracking Technologies
CanvasrIQ does not currently deploy first-party cookies, tracking pixels, web beacons, or behavioral advertising technologies on canvasriq.com. We do not use cookies to track your activity across third-party websites, serve targeted advertisements, or build behavioral profiles.
Our hosting provider, Cloudflare, may set strictly necessary cookies for security, performance, and functionality purposes. These cookies are not used for advertising or tracking. Google Fonts may log your IP address as a result of loading font files from Google's servers, processed in accordance with Google's Privacy Policy at policies.google.com/privacy.
If we introduce first-party cookies or third-party tracking technologies in the future, we will update this Privacy Notice and provide appropriate notice and consent mechanisms.
9. AI Voice Agent — Additional Privacy Disclosures
This section applies specifically to subscribers who have purchased and enabled the CanvasrIQ AI Voice Agent module (the "Voice Agent"). The Voice Agent involves the collection, processing, and retention of personal information categories not present in the standard CanvasrIQ lead generation service. If you are not a Voice Agent subscriber, this section does not apply to your use of the Service.
9.1 Categories of Personal Information Collected Through the Voice Agent
In connection with the operation of the Voice Agent module, CanvasrIQ and its subprocessors collect the following additional categories of personal information:
- Call audio recordings: The Voice Agent records all outbound calls placed on behalf of subscribing agents. Call audio is captured in its entirety from the initiation of the call through termination, including any periods during which a called party is placed on hold or transferred
- Call transcripts: Full text transcripts are generated from call audio through automated speech recognition processing. Transcripts contain the verbatim content of all statements made by both the Voice Agent and the called party during the call
- Call metadata: Date, time, duration, originating number, destination number, call outcome classification, and disposition data associated with each call attempt and completed call
- Called party information: Name, telephone number, and any other information disclosed by or about the called party during the course of the call, including responses to qualification questions, expressions of interest or disinterest, appointment preferences, and any other information elicited by the Voice Agent's conversational logic
- Consent records: Records documenting the basis on which each outbound call was placed, including the source and date of any prior express written consent, Do Not Call registry check timestamps, and applicable safe harbor documentation
- Appointment and calendar data: Information collected in connection with the Voice Agent's appointment booking functionality, including proposed and confirmed appointment times, calendar identifiers, and associated contact details
- AI interaction data: Data generated by the AI processing layer, including confidence scores, intent classifications, sentiment analysis outputs, and model inference logs associated with each call
9.2 Call Recording and All-Party Consent Requirements
The recording of telephone conversations is governed by a complex patchwork of federal and state laws. Under federal law, the Electronic Communications Privacy Act (18 U.S.C. § 2511) permits recording of telephone calls with the consent of at least one party to the call. However, numerous states impose more stringent requirements, mandating the consent of all parties to a call before it may be lawfully recorded. As of the effective date of this Privacy Notice, states that require all-party consent for telephone recording include, without limitation, California, Connecticut, Delaware, Florida, Illinois, Maryland, Massachusetts, Michigan, Montana, Nevada, New Hampshire, Oregon, Pennsylvania, and Washington.
CanvasrIQ's Voice Agent is designed to provide a disclosure to called parties at the outset of each call indicating that the call may be recorded. However, the sufficiency of this disclosure to constitute legally valid consent under the applicable law of each state in which you conduct outreach is a legal question that CanvasrIQ cannot answer on your behalf. You are solely and exclusively responsible for ensuring that your use of the Voice Agent's call recording functionality complies with applicable federal and state wiretapping, eavesdropping, and recording consent laws in every jurisdiction in which you conduct outreach activities.
Prior to activating the Voice Agent in any state requiring all-party consent, you are strongly advised to consult with qualified legal counsel regarding the consent disclosure language, the delivery mechanism, and the recordkeeping requirements applicable to your use case.
9.3 Processing of Called Party Personal Information
Personal information collected about called parties (i.e., the prospects you contact using the Voice Agent) through call recordings, transcripts, and AI interaction data is processed by CanvasrIQ and its subprocessors as follows:
- Primary processing: Call audio is transmitted to and processed by our telephony infrastructure provider, Twilio Inc. ("Twilio"), and our AI processing infrastructure for the purpose of generating call transcripts, outcome classifications, and appointment booking data
- Delivery to subscriber: Call recordings, transcripts, and metadata are made available to the subscribing agent through the Voice Agent dashboard and are associated with the applicable lead record
- Quality assurance: Aggregated and anonymized call data may be used internally to monitor and improve the performance of the Voice Agent's conversational logic and qualification accuracy
- Compliance logging: Consent records, DNC check timestamps, and call disposition data are retained for compliance documentation purposes
CanvasrIQ does not use called party personal information collected through the Voice Agent to build consumer profiles, serve advertising, or for any purpose beyond the provision of the Voice Agent service to the subscribing agent. CanvasrIQ does not sell called party personal information.
9.4 AI Processing and Automated Decision-Making
The Voice Agent employs artificial intelligence and machine learning technologies to conduct natural language conversations, assess prospect qualification, and make real-time decisions regarding call routing, objection handling, and appointment scheduling. You acknowledge and agree that:
- The Voice Agent's conversational responses are generated by AI and do not constitute statements or representations of CanvasrIQ, NorthQuinn Inc., or any human employee or agent
- AI-generated qualification assessments and lead scoring outputs are probabilistic in nature and are not guaranteed to be accurate
- You remain solely responsible for verifying AI-generated qualification data before making business decisions in reliance thereon
- You are responsible for ensuring that any automated decision-making conducted through the Voice Agent in connection with your insurance practice complies with applicable fair lending, anti-discrimination, and insurance regulatory requirements
9.5 Telephony Subprocessors
The Voice Agent relies on the following key subprocessors for the delivery of telephony and AI processing services:
- Twilio Inc.: Provides cloud communications infrastructure, including telephone number provisioning, outbound call routing, call recording storage, and real-time audio streaming. Twilio processes call audio and metadata in connection with the provision of its services. Twilio's privacy practices are governed by Twilio's Privacy Statement, available at twilio.com/en-us/legal/privacy. Twilio is certified under applicable data protection frameworks and maintains SOC 2 Type II compliance
- Calendly (or successor scheduling integration): Provides appointment booking and calendar integration functionality. When the Voice Agent successfully books an appointment, relevant appointment details are transmitted to Calendly or your integrated scheduling platform. Calendly's privacy practices are governed by Calendly's Privacy Notice, available at calendly.com/legal/privacy-notice
We maintain data processing agreements with each subprocessor that obligate them to process personal information only as directed by CanvasrIQ and in accordance with applicable data protection laws. A current list of Voice Agent subprocessors is available upon request at hello@canvasriq.com.
9.6 Retention of Voice Agent Data
The following retention periods apply to personal information collected through the Voice Agent module, in addition to the general retention schedules set forth in Section 6:
- Call audio recordings: Retained for a period of two (2) years from the date of the call, unless a longer retention period is required by applicable law, regulatory obligation, or pending legal proceeding
- Call transcripts: Retained for a period of two (2) years from the date of the call
- Call metadata and disposition data: Retained for a period of three (3) years from the date of the call for compliance documentation purposes
- Consent records and DNC check logs: Retained for a minimum of four (4) years from the date of the applicable call or consent record, in accordance with FTC Telemarketing Sales Rule recordkeeping requirements
- AI interaction and model inference logs: Retained in anonymized or aggregated form for system improvement purposes; identifiable AI interaction data is retained for a period of ninety (90) days from the date of the call
9.7 Called Party Rights and Requests
Individuals who have been contacted by the Voice Agent on behalf of a CanvasrIQ subscriber and who wish to exercise rights with respect to recordings or transcripts of calls involving them may submit a request to hello@canvasriq.com. CanvasrIQ will coordinate with the applicable subscriber to respond to such requests in accordance with applicable law. Note that certain call recordings and transcripts may be subject to retention obligations that limit our ability to delete such records prior to the expiration of the applicable mandatory retention period.
10. Third-Party Services and Links
Our Service may contain links to third-party websites, platforms, or services, including LinkedIn and Google Maps. These third-party services operate under their own privacy policies, which we do not control. We encourage you to review the privacy policies of any third-party services you access in connection with our Service. CanvasrIQ is not responsible for the privacy practices of third-party services.
11. California Privacy Rights (CCPA/CPRA)
If you are a resident of the State of California, the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act of 2020 (collectively, "CCPA") affords you specific rights with respect to your personal information.
10.1 Categories of Personal Information Collected
In the preceding twelve months, we have collected the following CCPA categories of personal information: Identifiers (name, email address, IP address); personal information described in California Civil Code Section 1798.80(e) (name, telephone number); professional or employment-related information (insurance line, agency name); and internet or other electronic network activity information (usage and device data).
10.2 Your CCPA Rights
Subject to certain exceptions, California residents have the following rights:
- Right to Know: Request disclosure of the categories and specific pieces of personal information we have collected about you, the sources, the purposes, and the categories of third parties with whom we share it
- Right to Delete: Request deletion of personal information we have collected about you, subject to certain exceptions permitted by law
- Right to Correct: Request correction of inaccurate personal information we maintain about you
- Right to Opt-Out of Sale or Sharing: We do not sell or share personal information as defined under the CCPA
- Right to Limit Use of Sensitive Personal Information: We do not process sensitive personal information beyond CCPA-permitted purposes
- Right to Non-Discrimination: We will not discriminate against you for exercising any CCPA rights
10.3 Submitting a CCPA Request
To exercise your CCPA rights, submit a verifiable consumer request to hello@canvasriq.com with the subject line "California Privacy Request." We will respond within 45 days of receipt, with an optional 45-day extension where reasonably necessary. You may designate an authorized agent to submit requests on your behalf, subject to verification requirements.
10.4 Shine the Light
We do not disclose personal information to third parties for their direct marketing purposes. To submit a Shine the Light request under California Civil Code Section 1798.83, contact us at hello@canvasriq.com.
12. Nevada Privacy Rights
We do not sell personal information as defined under Nevada Revised Statutes Chapter 603A. Nevada residents with questions about our privacy practices may contact us at hello@canvasriq.com.
13. Children's Privacy
The Service is directed exclusively to adults aged 18 and older and is intended for use by licensed insurance professionals. We do not knowingly collect personal information from children under the age of 13, or under the age of 16 for purposes of sale or sharing. If we discover that we have inadvertently collected personal information from a child under the applicable age threshold, we will promptly delete such information. If you believe a child has provided us with personal information without appropriate consent, please contact us immediately at hello@canvasriq.com.
14. Email Communications and CAN-SPAM
We may send you commercial email communications regarding the CanvasrIQ launch, product updates, promotional offers, and related content. All commercial email communications will comply with the CAN-SPAM Act of 2003, including clearly identifying CanvasrIQ as the sender, including an accurate subject line and our physical mailing address, providing a clear opt-out mechanism, and honoring opt-out requests within 10 business days of receipt.
To opt out of commercial email communications at any time, use the unsubscribe mechanism in any commercial email we send, or contact us at hello@canvasriq.com with the subject line "Unsubscribe."
15. Transfers of Personal Information
CanvasrIQ is headquartered in the United States. If you access the Service from outside the United States, your personal information will be transferred to, processed, and stored in the United States, where data protection laws may differ from those in your jurisdiction. By using the Service, you consent to such transfer. The Service is currently directed solely to U.S.-based insurance professionals and is not intended for residents of the European Economic Area or the United Kingdom.
16. Changes to This Privacy Notice
We reserve the right to modify this Privacy Notice at any time. If we make material changes, we will provide notice by updating the "Last Updated" date at the top of this page and, where feasible, by email notification. Your continued use of the Service following notice of any changes constitutes your acceptance of those changes.
17. Contact and Data Subject Requests
For questions, concerns, or data subject rights requests relating to this Privacy Notice, please contact us at:
NorthQuinn Inc. d/b/a CanvasrIQ
Attn: Privacy
New York, New York
Email: hello@canvasriq.com
We will acknowledge receipt of all privacy-related inquiries within five business days and respond substantively within the timeframes required by applicable law.