HIRVA

HIRVA Consultancy Inc.

Privacy Policy

Last updated: July 28, 2026 · v2.0

This policy explains how HIRVA Consultancy Inc. ("HIRVA", "we", "us") handles personal information across our websites (hirva.ca) and the SimNode platform (simnode.hirva.ca, api.hirva.ca) — what we collect, why, who processes it for us, how long we keep it, and the choices and rights you have. It forms part of our Terms of Service. We are the "organization" responsible under Canada's PIPEDA, and the data controller where that concept applies.

01The short version

  • We collect the minimum needed to run accounts, billing and security — not to profile you.
  • We never see or store card numbers; Stripe processes payments.
  • No advertising, no cross-site tracking, no sale of personal information — one essential sign-in cookie.
  • Your process models are private by default; support can only open a project you explicitly shared, every view is recorded, and sharing is revocable.
  • Customer models are never used to train machine-learning systems.
  • Security activity (sign-ins, exports, simulations, IP address) is logged, and kept for about 6 months.

02What we collect, and why

Account information

  • Email address, and a name if you provide one — to identify the account, verify it, and send service messages (verification, password reset, security alerts).
  • Password — stored only as a bcrypt hash; we cannot read it.
  • Two-factor authentication data — your authenticator (TOTP) secret, and backup codes stored only as hashes. Used solely to verify sign-ins.
  • Plan, role, trial end date, and account status.

Billing information

  • A Stripe customer reference and subscription state — so we know which features to unlock and can route webhook events to the right account.
  • Card details are entered on Stripe's systems and never reach our servers. Stripe also calculates applicable sales taxes from your billing address.

Your projects (Customer Content)

  • Projects you save are stored on servers we control (see Section 6). We keep the model document plus metadata: name, size, device and connection counts, timestamps, archived and sharing status.
  • Projects are private by default — see Section 5 for the only ways a person at HIRVA can open one.

Security and activity logs

  • Authentication events (sign-ins, failures, two-factor events, password changes), project lifecycle events (create, open, update, delete, restore, share/unshare), exports and generated code, simulation and optimization usage, and billing events.
  • Each event may include your IP address and browser (user-agent) string.
  • Purpose: account protection, brute-force and bot defence, plan-limit enforcement, abuse and data-leak detection, support, and aggregate service analytics.
  • Web server logs (IP, request, timestamp) are kept short-term for the same purposes.

Contact and lead information

  • If you use the contact form or email us: your name, contact details and message — used to respond and delivered to our business mailbox.

We collect this information directly from you and from your use of the Services. We do not buy data about you or enrich profiles from third parties.

03Cookies and anti-bot protection

  • One essential cookie: an encrypted, HttpOnly session cookie scoped to hirva.ca, which keeps you signed in across the website and the app. It expires when you close your browser and is not readable by page scripts. It is not used for tracking.
  • No advertising cookies, no analytics trackers, no cross-site tracking.
  • Sign-up and sign-in forms use layered bot protection: an invisible honeypot and timing check (processed by us), and Cloudflare Turnstile, which may process your IP address and browser signals on Cloudflare's systems to distinguish humans from bots. Turnstile is a security control, not advertising technology.

04AI features — what leaves our servers

  • Optional features (such as the AI advisor) send the relevant simulation context — device names, parameters, results — and your question to our AI model provider to generate the response.
  • This happens only when you invoke the feature; nothing is sent in the background.
  • We do not use your models or prompts to train models, and we instruct processing only to provide the response. Avoid including personal or confidential identifiers in prompts.

05When a person at HIRVA can see your project

  • Consent — you press 'Share with HIRVA support' on a specific project. Only that project becomes visible; every support view is recorded on your own account activity, and you can revoke sharing at any time.
  • Security — strictly limited access where necessary to investigate abuse, fraud, or a security incident.
  • Legal — where required by law or binding order; we will tell you unless legally prohibited.
  • Otherwise, staff tooling shows metadata only (name, size, counts, dates) — never the model.
  • Privileged administrative actions on our side are recorded in a tamper-evident, hash-chained audit log.

06Where information is stored and processed

The Services run on virtual servers we operate with our hosting provider (currently Hostinger, on infrastructure in Europe), with application data held in databases on those servers. Our processors — listed in Section 7 — process data in their own regions, which may include the United States and Europe. Wherever information is processed, we apply the safeguards in Section 9, and information may be subject to the laws of the jurisdiction where it is processed.

07Who processes information for us

We do not sell personal information. We share it only with service providers acting on our instructions, each limited to its purpose:

  • Stripe — payment processing, subscription billing, and sales-tax calculation.
  • Cloudflare — Turnstile bot protection on auth forms.
  • Our AI model provider — only for the optional AI features in Section 4.
  • Hostinger — server hosting and our business email/SMTP delivery (verification, reset and notification emails).

We may also disclose information where required by law, to protect our rights or users' safety, or as part of a merger, acquisition or sale of assets — in which case this policy continues to apply to the transferred information and we will notify you of any change in responsibility.

08How long we keep things

  • Account information — while your account exists. After account closure, personal information is deleted or anonymised within a reasonable period, except where longer retention is required (below).
  • Projects — while your account exists, including read-only archived projects. After account closure, or on your verified deletion request, projects are deleted; on request-based deletion we act within 30 days.
  • Security and activity logs — approximately 180 days, then pruned automatically.
  • Daily usage counters — days, not months (rolling cleanup).
  • Email verification and reset tokens — hours to 2 days; they expire and are purged.
  • Billing and tax records — approximately 7 years, as Canadian tax law requires.
  • Backups — rotate on a short schedule; deleted data leaves backups as they rotate.

09How we protect it

  • All traffic is encrypted in transit (TLS).
  • Passwords hashed with bcrypt; backup codes stored hashed; two-factor authentication is mandatory on every account.
  • Sessions use signed, HttpOnly cookies that end with your browser session; password changes and admin action invalidate existing sessions immediately.
  • Repeated failed sign-ins and code attempts trigger temporary lockouts; forms carry layered bot defences.
  • Role-based access control on administrative functions, with privileged actions written to a tamper-evident audit log.
  • Server-side enforcement of plan limits and per-account isolation of project data (requests can only ever reach the signed-in account's rows).

No system is perfectly secure, but these controls are tested and maintained. If a breach creates a real risk of significant harm to you, we will notify you and the Privacy Commissioner as required by law, without unreasonable delay.

10Your rights and choices

Under PIPEDA — and comparable laws such as Quebec's Law 25 and, for visitors from the EEA/UK, the GDPR — you can ask us to:

  • provide access to the personal information we hold about you, and information about how it is used and disclosed;
  • correct inaccurate information;
  • delete your account and associated personal information (subject to the retention requirements in Section 8);
  • withdraw consent for optional processing — for example stop using AI features, or revoke a project share — at any time;
  • receive a copy of your projects (export them from the app at any time on a paid plan, or ask us).

Email info@hirva.ca; we respond within 30 days and may need to verify your identity. If you are unsatisfied, you may complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca) or your local supervisory authority. We do not discriminate against you for exercising your rights, and we do not use automated decision-making that produces legal or similarly significant effects about you.

11Children

The Services are business tools for adults; we do not knowingly collect personal information from anyone under 18. If you believe a minor has created an account, contact us and we will remove it.

12Changes to this policy

If we change how we handle personal information, we will update this page, revise the date and version above, and for material changes notify you by email or in-app before they take effect. Earlier versions are available on request.

13Contact

Privacy questions and requests: info@hirva.ca · HIRVA Consultancy Inc., Greater Toronto Area (GTA), Ontario, Canada. See also the Terms of Service.

Questions about this document? Email info@hirva.ca or write to HIRVA Consultancy Inc., Greater Toronto Area (GTA), Ontario, Canada.