Operant360 is a job management platform for restoration, remediation and construction contractors. Contractors use it to run projects, build scopes and estimates, manage inventory and contents, issue work orders and purchase orders, track time, invoice their clients and take payment.
This policy explains what personal information we handle, why we handle it, who we share it with and what choices you have. It applies to the Operant360 website at operant360.com, the Operant360 web application, and the emails and documents the platform sends on a contractor’s behalf.
In this policy, “we” and “us” mean Purenvironmental Restoration Services Ltd., a Canadian corporation with its operating address at 679 Norfolk St. N, Simcoe, Ontario N3Y 3R2, operating under the name Operant360. “Operant360” refers to the software platform described in this policy. “You” means the person reading this, whether you are a customer, a customer’s employee, a customer’s client, or a visitor to our website.
This is the most important thing to understand about how your information is handled, so it comes first.
When we decide how information is used, we are responsible for it. This covers our own website visitors, people who sign up for accounts, billing contacts and anyone who contacts our support team. Canadian law calls us the organization responsible for that information; European law calls us the controller; California law calls us a business.
When a contractor decides how information is used, they are responsible for it and we act on their instructions. Everything a contractor puts into their Operant360 workspace falls into this category: their project records, the names and contact details of the property owners and insurance adjusters they work with, photographs of insured properties, scope notes, estimates, invoices and time entries. We store and process that information so the contractor can run their business. We do not decide what it is used for. European law calls us the processor here; California law calls us a service provider.
If you are a property owner, adjuster, subcontractor or employee and a contractor has entered your details into Operant360, that contractor is the organization accountable to you. Ask them for their privacy policy. If you contact us directly we will help, but in most cases we will refer your request to the contractor and support them in answering it, because the information is theirs to explain.
Subcontractors and suppliers whose information is entered into the platform should be aware that their data is controlled by the contractor who entered it. It is the contractor’s responsibility to notify you of this processing and to direct you to this policy.
When you create an account we collect your name, email address, a password (stored only as a cryptographic hash, never in readable form), and your organization’s name. If you turn on two-factor authentication we store the information needed to verify your codes. If you upload a profile photo we store that.
When you subscribe we collect billing contact details, your billing address and tax information. Card numbers go directly to Stripe and never touch our servers. We receive only the last four digits, the card brand and the expiry date so we can show you which card is on file.
When you contact support we keep the message and our reply.
Contractors enter and upload a great deal of information in the course of running jobs. Depending on how they use the platform, this can include:
We do not go looking for particularly sensitive categories of information, and the platform is not designed to hold health records, government identifiers or financial account numbers. Contractors should not put them into free-text fields.
When you use the application we record standard technical information: IP address, browser and device type, operating system, the pages you visited, timestamps, and the referring page. We keep server logs for security and troubleshooting.
When something breaks, our error monitoring tool captures a diagnostic record: the error, the page it happened on, browser details and the account identifier involved. We configure it to strip out request bodies, tokens and passwords.
We also measure how the product is used, so we know which features earn their keep and where people get stuck. This covers pages viewed, features opened, actions taken and rough timings. By default it is anonymous and nothing is stored on your device. If you are signed in, we ask whether we may go further and connect it to your account. Section 13 explains how it works and how to change it. We have switched off IP storage in our analytics tool, so it keeps no IP address and collects no location data.
We do not use advertising cookies, tracking pixels or social media trackers, and we do not build advertising profiles.
If you connect your QuickBooks Online account, we receive customer records, invoices, payments and chart-of-accounts data from Intuit so the two systems stay in sync. You control the connection and can revoke it at any time.
If your organization takes payment through the platform, Stripe sends us the payment status, the amount, the last four digits of the card and any dispute or refund events. Stripe also collects identity and banking information directly from your organization during onboarding, under Stripe’s own privacy policy.
| What we do | Why | Legal basis where GDPR applies |
|---|---|---|
| Create and secure accounts, authenticate sign-ins, enforce roles and permissions | To let you use the platform and keep other people out of your data | Performance of a contract |
| Run the platform: store projects, generate estimates, send documents, sync integrations | To deliver what the contractor signed up for | Performance of a contract |
| Bill subscriptions, collect payment, handle taxes and dunning | To get paid | Performance of a contract; legal obligation for tax records |
| Provide support and respond to questions | To help you | Performance of a contract; legitimate interests |
| Monitor errors, investigate abuse, prevent fraud, maintain backups | To keep the service working and secure | Legitimate interests; legal obligation |
| Send service notices about outages, security and material changes | To keep you informed. You cannot opt out of these while you hold an account | Performance of a contract |
| Send product news and marketing email | To tell you about the product. Every message has an unsubscribe link | Consent, or legitimate interests where permitted |
| Measure how features are used, through product analytics | To find where the product is failing people and decide what to build next | Consent where a non-essential cookie or similar technology is involved; otherwise legitimate interests |
| Improve the platform using aggregated, de-identified usage statistics | To decide what to build next | Legitimate interests |
We do not sell personal information, and we do not share it for cross-context behavioural advertising. We have never done so.
Marketing communications: If you unsubscribe from marketing emails, this will not affect transactional emails such as invoices, security alerts, or important service notices. You will continue to receive those as long as you hold an account.
Operant360 generates draft estimates, suggested line items, cost figures and document text automatically. These are drafts. Every one of them is presented to a person who reviews, edits and approves it before it goes anywhere. Nothing the platform generates produces a legal or similarly significant effect on anyone without a human deciding to act on it.
If you are in Quebec and you want to know more about how a particular automated recommendation was produced, or you want to submit observations about it, write to our Privacy Officer at the address in section 16.
Several parts of the platform use AI models: drafting estimates from scope notes, matching descriptions to price-code library entries, transcribing dictated voice notes, summarizing room notes, drafting work orders and reading uploaded photographs.
Three commitments govern this:
We do not train models on your content. Not our own models, not anyone else’s. Your projects, photos, notes and documents are never used as training data.
Our AI vendors do not train on your content either. We use them under commercial terms that prohibit training on submitted data and that either disable retention or limit it to a short abuse-monitoring window.
Voice recordings are transitory. Audio is sent for transcription, the text comes back, and the audio file is discarded. We do not keep a library of recordings.
Where technically feasible, we anonymize or de-identify data before sending it to AI models. For example, personal identifiers are not required to transcribe audio or generate a draft estimate from a scope description. We strip or mask this information to the extent the model does not need it to perform the task.
Output is a draft. Estimates, cost figures and generated text can be wrong, and it is the contractor’s responsibility to review them. Nothing the platform produces is professional advice, and it is not a substitute for a qualified estimator, adjuster, engineer or hygienist.
A user can connect their own Google Calendar or Outlook account so that jobs they are booked on appear in their personal calendar, and so their personal events appear alongside the work schedule inside the platform. This is optional, per person, and can be disconnected at any time from the calendar settings page. Disconnecting deletes the dedicated calendar we created in the connected account and stops all syncing.
When a calendar is connected we access only what the feature needs: the list of calendars in the account (so the user can choose which ones to show), events from the calendars the user picks, and the ability to create and update events in the one dedicated calendar we make for their bookings. Personal events pulled in this way are visible only to the person who connected the account — never to their employer, their colleagues, or us in the ordinary course of operating the service.
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular: we use Google Workspace API data only to provide the calendar sync feature described above; we do not transfer it to anyone except as needed to provide that feature, to comply with law, or as part of a merger or acquisition with prior notice; we do not use it for advertising; and humans at Operant360 do not read it except with the user’s permission for support, for security purposes, or where the law requires it.
We do not use data obtained through Google Workspace APIs to develop, improve, or train generalized artificial intelligence or machine learning models. Calendar data is not fed to the AI features described in the previous section, and it is never used as training data — ours or anyone else’s.
Your data is stored in Canada, and the application that reads and writes it runs in Canada. The database, the files you upload and the application code all sit in Montréal. We chose that deliberately.
Some things still leave the country, and we would rather tell you plainly than bury it:
Where information does leave Canada, it can be accessed by that provider’s staff abroad and can be subject to lawful access requests by courts and government authorities in that country. This is true of any cloud platform. We limit it by contract, we send each provider only what it needs, and we keep the core of your data at home.
We remain accountable for your information under PIPEDA wherever it is processed. For transfers out of the European Economic Area or the United Kingdom we rely on the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum. Where Quebec’s Law 25 applies, we conduct a privacy impact assessment (PIA) and transfer impact assessment (TIA) for any new processing activity or service provider that involves a cross-border transfer. We maintain records of these assessments and make them available to supervisory authorities on request.
While your organization’s subscription is active, we keep its data so the platform works.
When a subscription ends, the workspace stays available in read-only form for 30 days so you can export what you need. After that we begin deletion, and data is removed from live systems within 60 days of termination.
Encrypted backups roll off on a 35-day cycle. Deleted data can persist in a backup until that cycle completes, and it is not restored into live systems.
Some things we keep longer because we have to. Invoices, payment records and tax documentation are retained for seven years under Canadian tax law. Security and audit logs are retained for 12 months. Records connected to an actual or threatened legal claim are retained until the matter is resolved.
An individual user account that is deleted is removed within 30 days, though records of that person’s actions inside a customer’s workspace (who approved an estimate, who logged the hours) remain, because they belong to the contractor’s business records. Where these records remain, they are associated with a unique, non-identifiable user identifier (or a “deleted user” placeholder) rather than the individual’s name, so the data cannot be trivially re-associated with the individual’s identity.
Everything moves over TLS and sits encrypted at rest. Passwords are hashed. Access to production systems is restricted to the small number of people who need it, protected by multi-factor authentication and reviewed periodically. The platform enforces role-based permissions so people see only what their role allows, and it isolates each organization’s data at the database layer. We take encrypted backups, monitor for errors and abuse, and run security review over changes to the codebase.
No system is perfectly secure, and we will not pretend otherwise. If a breach occurs that creates a real risk of significant harm, we will notify affected customers and the Office of the Privacy Commissioner of Canada without unreasonable delay, along with the Commission d’accès à l’information du Québec, supervisory authorities in the EEA or UK, and state attorneys general, wherever those obligations apply. We maintain the breach records the law requires.
Everyone, wherever they live, can ask us to:
Write to privacy@operant360.com. We will confirm receipt promptly and respond within 30 days. If a request is complex we may take longer, and we will tell you why before the 30 days are up. We will ask you to verify your identity first, and we will not charge you unless a request is repetitive or excessive, in which case we will tell you the cost before doing the work.
If your request concerns information a contractor entered about you, we will route it to that contractor and support them in responding, because it is their record. Contact them directly for the fastest result.
You can complain to the Office of the Privacy Commissioner of Canada at priv.gc.ca. We would rather hear from you first.
Law 25 gives you the additional right to ask that information about you stop being disseminated, and to ask for a hyperlink to it to be de-indexed, where the dissemination contravenes the law or a court order. Our Privacy Officer is named in section 16. You can complain to the Commission d’accès à l’information du Québec.
In addition to the rights above you can object to processing based on legitimate interests, ask us to restrict processing, and complain to your national supervisory authority or, in the UK, the Information Commissioner’s Office.
See section 12.
Under the California Consumer Privacy Act as amended by the CPRA, California residents have the rights set out below. These apply to information we handle in our own right. Where a contractor is the business and we act as their service provider, direct your request to that contractor.
What we collect and why. In the past 12 months we have collected identifiers (name, email, IP address, account ID), commercial information (subscription and payment records), internet activity (log and usage data), professional information (your role and employer), audio and visual information (photographs and voice notes uploaded by contractors), and inferences drawn from usage. We collect it for the purposes in section 4, from the sources in section 3, and we disclose it to the service providers in section 7.
We do not sell personal information, and we do not share it for cross-context behavioural advertising. We have not done so in the past 12 months, and we do not sell or share the personal information of anyone under 16.
Sensitive personal information. We do not use or disclose sensitive personal information for any purpose beyond those permitted without an opt-out under section 7027(m) of the CCPA regulations.
Your rights. To know, to access a copy, to delete, to correct, to opt out of sale or sharing (which does not apply, since we do neither), to limit use of sensitive personal information, and not to be discriminated against for exercising any of them. You may use an authorized agent, who must provide written proof of authorization.
Make a request at privacy@operant360.com. We will verify you by confirming control of the account email, or by matching identifying details you provide against our records.
If you live in Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Florida, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Minnesota, Maryland, Tennessee, Indiana, Kentucky, Rhode Island or any other state with a comprehensive consumer privacy law in force, you have rights to confirm, access, correct, delete, obtain a portable copy, and opt out of targeted advertising, sale and profiling with legal effects. We do not conduct targeted advertising, sell personal data, or profile people in ways that produce legal effects.
Appeals. If we refuse your request, you can appeal by replying to our decision or writing to privacy@operant360.com with “Appeal” in the subject line. We aim to respond to all appeals within 30 days. If we need more time due to the complexity of the appeal, we will inform you within the initial 30-day period. If we deny the appeal, we will give you a link or a means to complain to your state Attorney General.
Note that most state privacy laws other than California’s apply only to individuals acting in a personal or household capacity, and exclude information about people acting in a commercial or employment context. Much of the information in Operant360 is commercial. We will not use that as a reason to refuse a request we can reasonably honour.
Operant360 is a business tool. It is not directed at children and we do not knowingly collect information from anyone under 16. If you believe a child’s information has ended up in the platform, write to privacy@operant360.com and we will delete it.
We will update this policy when the platform or the law changes. The effective date at the top always reflects the current version.
If a change materially affects how we handle personal information, we will notify account holders by email and post a notice in the application at least 30 days before it takes effect. Continuing to use Operant360 after that date means the new version applies to you.
Privacy Officer: J. Bowyer
Purenvironmental Restoration Services Ltd. (operating as Operant360)
679 Norfolk St. N
Simcoe, Ontario N3Y 3R2
Email: privacy@operant360.com
For general questions: support@operant360.com
We will acknowledge privacy enquiries within five business days.
A Data Processing Addendum (DPA) incorporating the European Commission’s Standard Contractual Clauses and the UK International Data Transfer Addendum is available on request. Please contact us at privacy@operant360.com to request a copy.