PID Intelligence is a product of AdaptIQ Solutions Inc. (operating as PID Intelligence), a British Columbia corporation, which is the data controller responsible for the personal information described in this policy. References to "PID Intelligence", "we", "us", and "our" mean AdaptIQ Solutions Inc.
PID Intelligence is committed to protecting the privacy of its users. This policy explains what information we collect, how we use it, and your rights under applicable Canadian privacy law (PIPEDA — the Personal Information Protection and Electronic Documents Act).
01What we collect
| Data type | What it includes | Why we collect it |
|---|---|---|
| Registration data | Name, work email, firm name, role | To manage Design Partner access and communicate with you |
| Usage logs | Timestamps, file sizes, extraction method used | To operate the service and improve extraction quality |
| Feedback data | Responses to in-tool feedback forms | To improve the product |
| Document content | Processed temporarily — see Section 02 | For extraction; not retained as primary user data |
02Temporary processing and background storage
To provide document extraction and AI-assisted processing services, PID Intelligence may temporarily process, cache, transmit, or store uploaded documents and extracted content within secure infrastructure systems and third-party processing services.
This may include:
- encrypted upload handling
- OCR preprocessing
- temporary image or text extraction buffers
- structured extraction outputs
- API request and response logging
- monitoring and error logs
- infrastructure backups
- processing through third-party AI providers
Uploaded documents are not intended for long-term storage unless explicitly enabled as part of a feature. However, temporary processing artifacts, logs, cached data, or extracted outputs may persist for limited periods within infrastructure systems or third-party environments.
PID Intelligence does not use customer documents to train its own AI models. See Section 05.
03Third-party services and sub-processors
PID Intelligence uses third-party service providers to operate the platform. The following sub-processors are explicitly named:
Anthropic (Claude API)
- Document extraction and reasoning
- Image and text understanding via the Claude API
- API-based processing — PID Intelligence does not host Anthropic models
- Retention governed by Anthropic's API terms and PID Intelligence's API configuration
Google Cloud (Vision AI)
- OCR and text detection on engineering drawings
- Image processing for P&ID and document drawings
- API-based processing — PID Intelligence does not host Google models
- Retention governed by Google Cloud API terms and PID Intelligence's API configuration
Brevo
- Transactional email delivery (access codes, onboarding)
- Newsletter delivery (opt-in only)
- Only name and email address are shared
Stripe
- Subscription billing and payment processing
- Checkout sessions and payment method handling
- Name, email, and payment details — payment details are handled by Stripe and not stored by PID Intelligence
Amazon Web Services (S3)
- Cloud object storage for application data at rest
- Extracted drawing data, crops, and review records
- Usage and account profile records
- Stored in Canada (ca-central-1), encrypted at rest (AES-256)
Netlify
- Website hosting and serverless functions (compute)
- User account creation and authentication (Netlify Identity)
- Form submissions
- Application data is stored in Amazon S3 (above), not on Netlify
GitHub
- Source code hosting and version control (private repository)
- Development infrastructure only, not part of the extraction pipeline
- The platform transmits no customer account or document data to GitHub. No document you upload, and no account record, is sent there by the service
- Separately from that: the source code repository has historically contained engineering identifiers (such as tag and line numbers) taken from drawings processed during early development. These are in the repository's version history, not in the running service, and are being scoped for removal
A current list of sub-processors and their privacy policies is maintained at pidintelligence.com/pages/sub-processors.
PID Intelligence does not use advertising networks, analytics tracking, social media pixels, or any other data collection services beyond those listed above.
04Cross-border data processing
Persistent client data — extracted drawing data, crops, review records, and account/usage profiles — is stored at rest in Canada (Amazon Web Services, region ca-central-1). Transient processing still crosses the border: rasterized drawing images are sent to Anthropic and Google Cloud Vision, both in the United States, for extraction, and are not retained by those processors beyond the request.
By using PID Intelligence, you consent to this transient transfer of data to the United States for the purpose of operating the extraction service. Each sub-processor named in Section 03 operates under their own published data-handling and regional infrastructure policies. Where supported, PID Intelligence selects regional endpoints or configurations that minimize cross-border transfer; complete confinement of all processing (including transient AI/OCR calls) within Canada is not currently offered.
05AI training and model use
PID Intelligence does not use customer documents to train its own AI models.
Third-party providers (Anthropic, Google Cloud) may process data according to their own policies and configured API terms. PID Intelligence selects API configurations designed to minimize retention and prevent model training on customer content where supported by the provider. We cannot, however, override the underlying terms of those providers — please review their published policies if model-training behavior is material to your decision to use PID Intelligence.
06How your documents flow through the system
For transparency, here is the typical data flow for a P&ID extraction:
- You upload a PDF in your browser.
- For vector PDFs, geometric symbol detection runs locally in your browser. No drawing data leaves your device for this step.
- The PDF is rasterized (converted to an image) and transmitted to PID Intelligence's server over an encrypted connection.
- The rasterized image is sent to Google Cloud (Vision / Gemini) for OCR and multimodal text/symbol detection.
- The rasterized image is sent to Anthropic (Claude API) for AI vision analysis, symbol interpretation, and cross-validation.
- Structured extraction results are formatted and returned to you.
- Uploaded files, intermediate processing artifacts, and logs are subject to the temporary-processing terms in Section 02. They are not intended for long-term storage, but may persist briefly in infrastructure systems or third-party environments.
07How we use your information
- To send your access code and onboarding information
- To communicate updates, changes, or issues with the tool
- To aggregate anonymised, non-identifiable usage patterns to improve the service
- To respond to support requests
We will never sell, rent, or share your personal information with third parties for marketing or commercial purposes.
By using PID Intelligence, you consent to the collection and use of information as described in this policy.
08Email communications (CASL)
Account emails (always sent): PID Intelligence will send you emails related to your account — welcome message, password reset, usage notifications, payment confirmations, and feedback requests after your first extraction. These are transactional messages and are not optional while you have an active account.
Newsletter (opt-in only): At signup you can choose to subscribe to the PID Intelligence newsletter — occasional product updates, P&ID extraction tips, and early-access offers. Canada's Anti-Spam Legislation (CASL) requires your express consent before we send these, so the newsletter checkbox is unchecked by default. We record the date, source, and wording of your consent.
Unsubscribe: Every newsletter message includes an unsubscribe link. You can also unsubscribe at any time by emailing hello@pidintelligence.com with "Unsubscribe" in the subject line. Unsubscribing stops marketing emails only — account emails will continue as long as you have an active account.
09Your rights
Under PIPEDA, you have the right to:
- Access the personal information we hold about you
- Request correction of inaccurate information
- Request deletion of your registration data
- Withdraw consent for processing (this will end your platform access)
To exercise any of these rights, email hello@pidintelligence.com. We will respond within 30 days.
10Data retention
Registration data: retained for the duration of your Design Partner program membership plus 12 months.
Usage logs: retained for 24 months. Usage logs do not contain document content; they contain operational metadata such as timestamps, file sizes, and extraction methods used.
Documents and extraction outputs: Drawing images (valve crops, thumbnails) are deleted within 7 days. Structured extraction outputs and review records are deleted within 90 days. No drawing content is retained beyond these windows.
You may request earlier deletion of registration data at any time by emailing hello@pidintelligence.com.
11Security
PID Intelligence uses HTTPS encryption for all data in transit. Access to registration and usage data is restricted to PID Intelligence's operator. We follow reasonable security practices appropriate for a small SaaS business. While we take reasonable measures to protect your information, no system can be guaranteed to be 100% secure.
12ISO/IEC 27001-aligned practices
PID Intelligence is not currently ISO/IEC 27001 certified. We structure our internal information-security program — risk assessment, sub-processor management, retention, and incident response — in alignment with the ISO/IEC 27001 framework. This section describes controls that are implemented today, not a certification claim.
Controls currently in place:
- Encryption in transit: all traffic to and from PID Intelligence is served over HTTPS/TLS.
- Encryption at rest: stored application data (Amazon S3) is encrypted using AES-256.
- Canadian data residency: persistent client data is stored at rest in Canada (see Section 04).
- Automated retention enforcement: the deletion windows in Section 10 are enforced by infrastructure-level lifecycle rules and a scheduled purge process, not by manual cleanup.
- Access hardening: Content Security Policy headers on all pages; no-store cache directives on API responses so extraction results aren't cached downstream.
- Endpoint protection: full-disk encryption is required on any workstation used to handle client documents.
- Administrative logging: access by PID Intelligence staff to administrative functions is recorded in an access log.
- Authenticated processing endpoints: document extraction requests require a verified account identity; unauthenticated requests are rejected at the endpoint.
- Documented incident response: we maintain a written incident response procedure covering breach detection, assessment, and notification.
- Sub-processor governance: sub-processors are named and reviewed (Section 03 and the sub-processors page); we track data processing agreements with each.
Some controls in our internal information security management system are still in progress and not yet fully implemented — for example, enforced multi-factor authentication across every administrative account. We don't claim that as complete here. If you need more detail for a vendor security review, contact us at hello@pidintelligence.com.
13Contact
The data controller is AdaptIQ Solutions Inc. (operating as PID Intelligence).
Privacy questions or requests: hello@pidintelligence.com