Legal
Privacy Policy
This policy explains how PrivateAccess collects, uses, protects and retains personal information.
1. Who is responsible
BQMP operates PrivateAccess from 330 Avro, Pointe-Claire, QC, H9R 5W5 CANADA and is responsible for the service’s personal-information practices.
2. Information collected
Account data includes your chosen username, recovery email, password hash, account status and security records. Billing data includes Stripe customer, checkout and subscription identifiers; PrivateAccess does not need to store complete card details. Mail-service data may include message routing information, mailbox usage, login records and abuse signals. For protected external delivery, the destination address, sender, expiry and access records are stored with an encrypted payload containing the subject, message and attachments.
3. Why information is used
Information is used to register and secure accounts, verify ownership, process subscriptions, provision mailboxes, route mail, prevent abuse, provide support, comply with law and maintain service reliability.
4. Legal grounds
Processing is used to perform the service contract, comply with legal obligations, protect legitimate security and abuse-prevention interests, and act on consent where consent is required.
5. Service providers
PrivateAccess uses service providers for payment processing, hosting, email infrastructure, monitoring and customer support. Stripe processes payment information under its own privacy terms. Providers receive only the access needed for their role.
6. International transfers
Hosting and service providers may process information outside your province or country. PrivateAccess uses contractual, organizational and technical safeguards appropriate to the information and applicable law.
7. Retention
Mailbox content is retained while the account is active and is scheduled for deletion within 30 days after final account closure. Protected external messages expire after 30 days and may be revoked earlier by the sender. Backup copies may remain for up to 90 days. Billing, fraud-prevention and legal records may be retained for up to seven years where required.
8. Security
PrivateAccess uses password hashing, protected sessions, optional two-factor authentication, one-use tokens, access controls, audit records, encrypted transport, encrypted protected-message storage, backups and mail-security controls.
9. Your choices and rights
Subject to applicable law, you may request access, correction, export, restriction or deletion of personal information, withdraw consent where applicable, or complain to a privacy regulator. Requests must be verified to protect the account.
10. Cookies
PrivateAccess uses an essential session cookie for authentication and security. It does not use advertising cookies. See the Cookie Policy for details.
11. Children
PrivateAccess accounts are available only to people who are at least 18 years old.
12. Contact and changes
Privacy questions and verified rights requests may be directed to privacy@privateaccess.space. Material policy changes will be dated and communicated through appropriate account channels.
