Plain English Summary

When you upload a document, PID Intelligence processes it using cloud OCR and AI services to extract structured data.

Files are not intended for permanent storage unless a storage feature is explicitly enabled. Temporary copies, logs, or cached processing data may exist briefly to support system operation and reliability. Where data is retained, it is stored at rest in Canada.

PID Intelligence does not use customer documents to train its own AI models. Third-party AI providers (Anthropic, Google Cloud) process data under their own published terms.

Contents
  1. 01What we collect
  2. 02Temporary processing & background storage
  3. 03Third-party services & sub-processors
  4. 04Cross-border data processing
  5. 05AI training & model use
  6. 06How your documents flow
  7. 07How we use your information
  8. 08Email communications (CASL)
  9. 09Your rights (PIPEDA)
  10. 10Data retention
  11. 11Security
  12. 12ISO/IEC 27001-aligned practices
  13. 13Contact

PID Intelligence is a product of AdaptIQ Solutions Inc. (operating as PID Intelligence), a British Columbia corporation, which is the data controller responsible for the personal information described in this policy. References to "PID Intelligence", "we", "us", and "our" mean AdaptIQ Solutions Inc.

PID Intelligence is committed to protecting the privacy of its users. This policy explains what information we collect, how we use it, and your rights under applicable Canadian privacy law (PIPEDA — the Personal Information Protection and Electronic Documents Act).

01What we collect

Data typeWhat it includesWhy we collect it
Registration dataName, work email, firm name, roleTo manage Design Partner access and communicate with you
Usage logsTimestamps, file sizes, extraction method usedTo operate the service and improve extraction quality
Feedback dataResponses to in-tool feedback formsTo improve the product
Document contentProcessed temporarily — see Section 02For extraction; not retained as primary user data

02Temporary processing and background storage

To provide document extraction and AI-assisted processing services, PID Intelligence may temporarily process, cache, transmit, or store uploaded documents and extracted content within secure infrastructure systems and third-party processing services.

This may include:

  • encrypted upload handling
  • OCR preprocessing
  • temporary image or text extraction buffers
  • structured extraction outputs
  • API request and response logging
  • monitoring and error logs
  • infrastructure backups
  • processing through third-party AI providers

Uploaded documents are not intended for long-term storage unless explicitly enabled as part of a feature. However, temporary processing artifacts, logs, cached data, or extracted outputs may persist for limited periods within infrastructure systems or third-party environments.

PID Intelligence does not use customer documents to train its own AI models. See Section 05.

03Third-party services and sub-processors

PID Intelligence uses third-party service providers to operate the platform. The following sub-processors are explicitly named:

AI vendor

Anthropic (Claude API)

  • Document extraction and reasoning
  • Image and text understanding via the Claude API
  • API-based processing — PID Intelligence does not host Anthropic models
  • Retention governed by Anthropic's API terms and PID Intelligence's API configuration
AI & OCR vendor

Google Cloud (Vision AI)

  • OCR and text detection on engineering drawings
  • Image processing for P&ID and document drawings
  • API-based processing — PID Intelligence does not host Google models
  • Retention governed by Google Cloud API terms and PID Intelligence's API configuration
Email delivery

Brevo

  • Transactional email delivery (access codes, onboarding)
  • Newsletter delivery (opt-in only)
  • Only name and email address are shared
Payments

Stripe

  • Subscription billing and payment processing
  • Checkout sessions and payment method handling
  • Name, email, and payment details — payment details are handled by Stripe and not stored by PID Intelligence
Storage

Amazon Web Services (S3)

  • Cloud object storage for application data at rest
  • Extracted drawing data, crops, and review records
  • Usage and account profile records
  • Stored in Canada (ca-central-1), encrypted at rest (AES-256)
Infrastructure

Netlify

  • Website hosting and serverless functions (compute)
  • User account creation and authentication (Netlify Identity)
  • Form submissions
  • Application data is stored in Amazon S3 (above), not on Netlify
Development

GitHub

  • Source code hosting and version control (private repository)
  • Development infrastructure only, not part of the extraction pipeline
  • The platform transmits no customer account or document data to GitHub. No document you upload, and no account record, is sent there by the service
  • Separately from that: the source code repository has historically contained engineering identifiers (such as tag and line numbers) taken from drawings processed during early development. These are in the repository's version history, not in the running service, and are being scoped for removal

A current list of sub-processors and their privacy policies is maintained at pidintelligence.com/pages/sub-processors.

PID Intelligence does not use advertising networks, analytics tracking, social media pixels, or any other data collection services beyond those listed above.

04Cross-border data processing

Persistent client data — extracted drawing data, crops, review records, and account/usage profiles — is stored at rest in Canada (Amazon Web Services, region ca-central-1). Transient processing still crosses the border: rasterized drawing images are sent to Anthropic and Google Cloud Vision, both in the United States, for extraction, and are not retained by those processors beyond the request.

By using PID Intelligence, you consent to this transient transfer of data to the United States for the purpose of operating the extraction service. Each sub-processor named in Section 03 operates under their own published data-handling and regional infrastructure policies. Where supported, PID Intelligence selects regional endpoints or configurations that minimize cross-border transfer; complete confinement of all processing (including transient AI/OCR calls) within Canada is not currently offered.

05AI training and model use

PID Intelligence does not use customer documents to train its own AI models.

Third-party providers (Anthropic, Google Cloud) may process data according to their own policies and configured API terms. PID Intelligence selects API configurations designed to minimize retention and prevent model training on customer content where supported by the provider. We cannot, however, override the underlying terms of those providers — please review their published policies if model-training behavior is material to your decision to use PID Intelligence.

06How your documents flow through the system

For transparency, here is the typical data flow for a P&ID extraction:

  1. You upload a PDF in your browser.
  2. For vector PDFs, geometric symbol detection runs locally in your browser. No drawing data leaves your device for this step.
  3. The PDF is rasterized (converted to an image) and transmitted to PID Intelligence's server over an encrypted connection.
  4. The rasterized image is sent to Google Cloud (Vision / Gemini) for OCR and multimodal text/symbol detection.
  5. The rasterized image is sent to Anthropic (Claude API) for AI vision analysis, symbol interpretation, and cross-validation.
  6. Structured extraction results are formatted and returned to you.
  7. Uploaded files, intermediate processing artifacts, and logs are subject to the temporary-processing terms in Section 02. They are not intended for long-term storage, but may persist briefly in infrastructure systems or third-party environments.

07How we use your information

  • To send your access code and onboarding information
  • To communicate updates, changes, or issues with the tool
  • To aggregate anonymised, non-identifiable usage patterns to improve the service
  • To respond to support requests

We will never sell, rent, or share your personal information with third parties for marketing or commercial purposes.

By using PID Intelligence, you consent to the collection and use of information as described in this policy.

08Email communications (CASL)

Account emails (always sent): PID Intelligence will send you emails related to your account — welcome message, password reset, usage notifications, payment confirmations, and feedback requests after your first extraction. These are transactional messages and are not optional while you have an active account.

Newsletter (opt-in only): At signup you can choose to subscribe to the PID Intelligence newsletter — occasional product updates, P&ID extraction tips, and early-access offers. Canada's Anti-Spam Legislation (CASL) requires your express consent before we send these, so the newsletter checkbox is unchecked by default. We record the date, source, and wording of your consent.

Unsubscribe: Every newsletter message includes an unsubscribe link. You can also unsubscribe at any time by emailing hello@pidintelligence.com with "Unsubscribe" in the subject line. Unsubscribing stops marketing emails only — account emails will continue as long as you have an active account.

09Your rights

Under PIPEDA, you have the right to:

  • Access the personal information we hold about you
  • Request correction of inaccurate information
  • Request deletion of your registration data
  • Withdraw consent for processing (this will end your platform access)

To exercise any of these rights, email hello@pidintelligence.com. We will respond within 30 days.

10Data retention

Registration data: retained for the duration of your Design Partner program membership plus 12 months.

Usage logs: retained for 24 months. Usage logs do not contain document content; they contain operational metadata such as timestamps, file sizes, and extraction methods used.

Documents and extraction outputs: Drawing images (valve crops, thumbnails) are deleted within 7 days. Structured extraction outputs and review records are deleted within 90 days. No drawing content is retained beyond these windows.

You may request earlier deletion of registration data at any time by emailing hello@pidintelligence.com.

11Security

PID Intelligence uses HTTPS encryption for all data in transit. Access to registration and usage data is restricted to PID Intelligence's operator. We follow reasonable security practices appropriate for a small SaaS business. While we take reasonable measures to protect your information, no system can be guaranteed to be 100% secure.

12ISO/IEC 27001-aligned practices

PID Intelligence is not currently ISO/IEC 27001 certified. We structure our internal information-security program — risk assessment, sub-processor management, retention, and incident response — in alignment with the ISO/IEC 27001 framework. This section describes controls that are implemented today, not a certification claim.

Controls currently in place:

  • Encryption in transit: all traffic to and from PID Intelligence is served over HTTPS/TLS.
  • Encryption at rest: stored application data (Amazon S3) is encrypted using AES-256.
  • Canadian data residency: persistent client data is stored at rest in Canada (see Section 04).
  • Automated retention enforcement: the deletion windows in Section 10 are enforced by infrastructure-level lifecycle rules and a scheduled purge process, not by manual cleanup.
  • Access hardening: Content Security Policy headers on all pages; no-store cache directives on API responses so extraction results aren't cached downstream.
  • Endpoint protection: full-disk encryption is required on any workstation used to handle client documents.
  • Administrative logging: access by PID Intelligence staff to administrative functions is recorded in an access log.
  • Authenticated processing endpoints: document extraction requests require a verified account identity; unauthenticated requests are rejected at the endpoint.
  • Documented incident response: we maintain a written incident response procedure covering breach detection, assessment, and notification.
  • Sub-processor governance: sub-processors are named and reviewed (Section 03 and the sub-processors page); we track data processing agreements with each.

Some controls in our internal information security management system are still in progress and not yet fully implemented — for example, enforced multi-factor authentication across every administrative account. We don't claim that as complete here. If you need more detail for a vendor security review, contact us at hello@pidintelligence.com.

13Contact

The data controller is AdaptIQ Solutions Inc. (operating as PID Intelligence).

Privacy questions or requests: hello@pidintelligence.com