1. Who is responsible

BQMP operates PrivateAccess from 330 Avro, Pointe-Claire, QC, H9R 5W5 CANADA and is responsible for the service’s personal-information practices.

2. Information collected

Account data includes your chosen username, recovery email, password hash, account status and security records. Billing data includes Stripe customer, checkout and subscription identifiers; PrivateAccess does not need to store complete card details. Mail-service data may include message routing information, mailbox usage, login records and abuse signals. For protected external delivery, the destination address, sender, expiry and access records are stored with an encrypted payload containing the subject, message and attachments.

3. Why information is used

Information is used to register and secure accounts, verify ownership, process subscriptions, provision mailboxes, route mail, prevent abuse, provide support, comply with law and maintain service reliability.

4. Legal grounds

Processing is used to perform the service contract, comply with legal obligations, protect legitimate security and abuse-prevention interests, and act on consent where consent is required.

5. Service providers

PrivateAccess uses service providers for payment processing, hosting, email infrastructure, monitoring and customer support. Stripe processes payment information under its own privacy terms. Providers receive only the access needed for their role.

6. International transfers

Hosting and service providers may process information outside your province or country. PrivateAccess uses contractual, organizational and technical safeguards appropriate to the information and applicable law.

7. Retention

Mailbox content is retained while the account is active and is scheduled for deletion within 30 days after final account closure. Protected external messages expire after 30 days and may be revoked earlier by the sender. Backup copies may remain for up to 90 days. Billing, fraud-prevention and legal records may be retained for up to seven years where required.

8. Security

PrivateAccess uses password hashing, protected sessions, optional two-factor authentication, one-use tokens, access controls, audit records, encrypted transport, encrypted protected-message storage, backups and mail-security controls.

9. Your choices and rights

Subject to applicable law, you may request access, correction, export, restriction or deletion of personal information, withdraw consent where applicable, or complain to a privacy regulator. Requests must be verified to protect the account.

10. Cookies

PrivateAccess uses an essential session cookie for authentication and security. It does not use advertising cookies. See the Cookie Policy for details.

11. Children

PrivateAccess accounts are available only to people who are at least 18 years old.

12. Contact and changes

Privacy questions and verified rights requests may be directed to privacy@privateaccess.space. Material policy changes will be dated and communicated through appropriate account channels.