Skip to content

Privacy Notice

Last updated: July 17, 2026

1. Scope

This Privacy Notice applies to buy.attestlayer.com, the request-fit check, Buyer Review Pack checkout, Buyer Console, and direct-buyer delivery flows. It does not govern other AttestLayer domains that publish their own notices.

2. Information we collect

We collect the following categories of information:

  • business contact information, including name, work email address, company name, billing contact details, and support messages;
  • order and payment information, including order identifiers, payment status, invoice references, receipts, and subscription or access status;
  • buyer-request information, including the buyer request file, due date, request type, and record inventory submitted during the request-fit check;
  • commercial qualification and capacity-preference information, including active-review count, deal-blocking status, opportunity-value band, incumbent tooling, and payment preference;
  • source records submitted after purchase, including the files your organization authorizes for processing;
  • generated service information, including requirement matrices, source-linked response statements, gap reports, manifests, receipts, verification results, and processing metadata;
  • email-verification information, including verification challenge, verified-session, expiry, attempt, and cancellation metadata;
  • transactional-delivery information, including message status, retry, provider message identifier, bounce, complaint, and delivery metadata; and
  • technical and security information, including IP address, browser information, device information, referrer information, session data, CAPTCHA or abuse-prevention results, and security logs.

3. Why we use information

We use information to:

  • operate the request-fit check, checkout, Buyer Console, and Buyer Review Pack;
  • recommend review capacity and provide billing support without changing evidence strictness or pricing based on deal value;
  • process payments, invoices, refunds, and tax records;
  • send transactional invoice, payment confirmation, order access, billing, and support emails;
  • create, deliver, verify, and protect Buyer Review Pack output;
  • authenticate users and secure the Service;
  • detect fraud, abuse, security incidents, and prohibited use;
  • respond to support, privacy, billing, and security requests;
  • comply with legal obligations; and
  • understand limited website and product usage through PostHog without sending uploaded buyer requests or source records to PostHog.

4. Automated processing

The Buyer Review Pack uses automated processing to classify submitted records against versioned request-profile rules and to generate the service output described in the Terms. These operational service results are not legal, employment, credit, insurance, medical, regulatory, or certification decisions.

5. How information is shared

We share information only with service providers required to operate the direct-buyer workflow, including:

  • Google Cloud Platform for hosting, storage, compute, database, and security infrastructure;
  • Stripe for payments, invoices, receipts, and payment status;
  • transactional email providers for invoice, payment confirmation, order access, billing, and support messages; and
  • PostHog for limited website and product analytics.

The current subprocessor list is available on the Subprocessors page. We do not sell personal information. We do not use uploaded buyer requests or source records for advertising.

6. Location of processing

Buyer request and source-file bytes are processed in Google Cloud's Montréal region for this direct-buyer workflow. Generated private package objects are stored there during the applicable access window. Payment, invoice, transactional email, website analytics, and limited operational metadata may be processed in Canada, the United States, or other locations where the listed subprocessors operate.

Before communicating personal information outside Québec, AttestLayer assesses the sensitivity and purpose of the information, the safeguards and contractual measures, and the legal framework in the destination. A transfer is authorized only when the assessment concludes that the information will receive adequate protection and a written agreement governs the transfer. The protected production release process requires approved evidence for each listed cross-border service provider; policy text alone is not treated as proof.

7. Retention

  • Email-verification challenges: automatically deleted after seven days.
  • Verified sessions and unused Fit Check authorities: expire automatically and are deleted approximately 30 days after expiry when they are not linked to a purchase.
  • Request-fit, buyer-request, and source-file bytes: handled in the processing request and not intentionally persisted as separate working-upload objects; the application does not retain those bytes for reuse after the request ends.
  • Generated private ZIP access: ends at the earlier of the order's 30-day access expiry or 30 days after generation; storage lifecycle deletion is asynchronous and includes a seven-day operator-only soft-delete window.
  • Paid Fit Check, commercial-qualification, capacity-preference, and order metadata, purchase intents, Stripe event references, entitlements, transactional outbox records, resolved operational alerts, and provider delivery metadata: ordinarily retained for seven years for billing, accounting, fraud prevention, service integrity, support, and dispute handling. They may be retained longer where a legal obligation or preserved legal hold requires it.
  • Confirmation and access email delivery: delivery may be retried after a temporary failure and, in an unusual ambiguous provider response, a duplicate transactional message may arrive. Provider delivery metadata follows the paid-order retention period above.
  • Security and abuse-prevention logs: retained for up to 90 days unless a longer period is required to investigate a security incident or comply with law.
  • Registry commitments: current Buyer Review Pack issuance does not add one; historical public cryptographic commitments may remain indefinitely and do not contain submitted files or recoverable source content.

8. Your choices and requests

You may request access to, correction of, or deletion of personal information by emailing privacy@attestlayer.com. Include your company name and the work email address associated with the request. We may ask for reasonable information to verify your identity and protect against unauthorized access or deletion.

Deletion requests do not require us to delete information we must retain for legal, accounting, security, fraud-prevention, or dispute-resolution purposes.

9. Security

We use technical and organizational safeguards designed for the sensitivity of the information we handle. No internet service can guarantee absolute security. You are responsible for submitting only information you are permitted to provide and for protecting your own account credentials.

10. Privacy governance and impact assessments

AttestLayer maintains privacy governance practices covering responsibility and approval, least-privilege access, data inventories and retention, service-provider review, privacy impact assessments, incident response and the privacy-incident register, personnel confidentiality, complaint handling, and periodic control review. Access to customer and buyer information is limited to authorized roles with a business need.

A privacy impact assessment is required before a new or materially refitted electronic service involving personal information is approved for production and before personal information is communicated outside Québec. Supporting assessments, agreements, officer delegation, and the incident register are controlled records and are not published because they may contain confidential security, legal, or incident information. Their exact document hashes and protected approval evidence must be bound to the production release.

11. Privacy Officer and complaints

Privacy Officer (person in charge of protection of personal information): Rabie-Abdollah Macbahi, Services AttestLayer. Contact: privacy@attestlayer.com.

To make a privacy complaint, use that email address with the subject “Privacy complaint” and describe the service, date, people or records involved, and requested resolution. Do not email passwords, payment-card data, private keys, or unnecessary sensitive records. The Privacy Officer records the complaint, confirms the requester's authority where needed, investigates with access limited to relevant personnel, records the outcome and corrective action, and provides a written response. If you disagree with the response, you may ask for reconsideration and may contact the competent privacy regulator.

12. Children

The Service is for business use and is not directed to children. Do not submit personal information about children to the Service.

13. Changes

We may update this Privacy Notice by posting a revised version on this page. The effective date appears at the top of the page.

14. Contact

Privacy requests: privacy@attestlayer.com
Security reports: security@attestlayer.com
Mailing address: Services AttestLayer, operating as AttestLayer, 360 Saint-Jacques Street, Suite G101, Montreal, Quebec H2Y 1P5, Canada