1. Introduction

AI Connect, developed by How Ai Connects Inc., is committed to protecting the privacy of every individual who interacts with our website, applications, and professional services. This Privacy Policy explains in clear and thorough terms what personal information we collect, why we collect it, how we use it, with whom we share it, and what rights you have regarding your data. We have drafted this policy to comply with applicable privacy legislation including Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA), the European Union’s General Data Protection Regulation (GDPR), and the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), to the extent each regime applies to our operations.

By accessing our website at www.aiconnect.buzz, using any of our services, or communicating with us through any channel, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with any provision contained herein, you should discontinue use of our website and services immediately. We encourage you to review this policy periodically, as it may be updated from time to time to reflect changes in our data practices, legal obligations, or service offerings. Your continued engagement with AI Connect following any modification constitutes your acceptance of the revised terms.

How Ai Connects Inc. operates as a computer systems design and integration consultancy headquartered in Mississauga, Ontario, Canada. Our work involves architecting technology systems, integrating artificial intelligence capabilities, and providing strategic advisory services to enterprises across North America. In the course of these activities, we may process limited categories of personal information, primarily related to business contacts, prospective clients, website visitors, and service providers. This policy describes our comprehensive approach to safeguarding that information.

2. Information We Collect

We collect information that you voluntarily provide to us when you interact with our website, submit inquiries through our contact form, send us emails, schedule consultations, or otherwise engage with our business development channels. The categories of personal information we may collect include: your full name, email address, phone number, company name, job title, and the content of any message or inquiry you submit. When you use our contact form, we also record the timestamp of your submission and your IP address for security and anti-spam purposes.

In addition to the information you actively provide, our website automatically collects certain technical data through standard internet protocols. This includes your browser type and version, operating system, referring URL, pages visited, time spent on each page, and coarse geographic location derived from your IP address at the country or city level. We also collect device-level information such as screen resolution, preferred language settings, and whether JavaScript is enabled. This automatically collected data helps us understand how visitors interact with our website, identify performance issues, and improve the overall user experience. None of this automatically collected data is used to identify individual users by name or to build personal profiles.

We do not collect sensitive personal information as defined under applicable privacy laws, such as government-issued identification numbers, financial account credentials, health or biometric data, racial or ethnic origin information, political opinions, religious beliefs, trade union membership, genetic data, or data concerning a person’s sex life or sexual orientation. If we ever have a legitimate business need to collect such categories of information, we will do so only with your explicit, informed, and freely given consent, and only after providing you with a specific notice detailing the purpose and legal basis for such collection.

3. How We Use Your Information

The personal information we collect serves several defined business purposes, each grounded in a lawful basis under applicable privacy legislation. We use your contact details to respond to inquiries, provide information about our services, schedule consultations, and maintain ongoing business communications. When you reach out through our contact form with a project brief or integration challenge, we use the information you provide to assess whether and how our services might address your needs. This preliminary assessment allows us to prepare meaningful, context-aware responses rather than generic replies, which we believe serves both your interests and our operational efficiency.

We also use aggregated, de-identified technical data derived from website analytics to monitor site performance, detect and diagnose technical errors, analyze traffic patterns, and inform decisions about content and design improvements. This analytical use does not involve identifying individual visitors and is processed strictly in aggregate form. Additionally, we may use your contact information to send you occasional updates about our services, industry insights, or relevant developments in systems integration and artificial intelligence, but only if you have explicitly opted in to receive such communications. You may withdraw your consent to marketing communications at any time by clicking the unsubscribe link in any email or by contacting us directly at chat@aiconnect.buzz.

In certain circumstances, we may need to use your personal information to comply with legal obligations, respond to lawful requests from regulatory authorities or law enforcement agencies, enforce our contractual agreements, protect our legal rights, or defend against legal claims. Any such use will be limited to what is strictly necessary for the specific legal purpose and will be documented in accordance with our internal data processing records. We do not use personal information for automated decision-making, profiling that produces legal effects, or any form of artificial intelligence training involving individual-level data.

4. Data Sharing and Disclosure

How Ai Connects Inc. does not sell, rent, lease, trade, or otherwise commercially exploit your personal information. We do not share your data with third parties for their own independent marketing purposes, and we never have. The limited sharing that does occur is strictly for operational purposes necessary to deliver our services and maintain our business infrastructure. Specifically, we may share personal information with trusted service providers who perform functions on our behalf, including website hosting providers, email delivery services, analytics platforms, and cloud storage providers. Each of these service providers is contractually bound to process your data only in accordance with our documented instructions and to implement appropriate technical and organizational security measures.

We may also disclose personal information if required to do so by law, court order, subpoena, or other legal process, or if we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others, to investigate fraud, or to respond to a government request. In the unlikely event that How Ai Connects Inc. undergoes a merger, acquisition, reorganization, or sale of all or substantially all of its assets, personal information held by us may be among the assets transferred to the successor entity, provided that the successor agrees to honor the terms of this Privacy Policy with respect to such information. You will be notified via email or a prominent notice on our website of any such change in ownership or control of your personal data.

We do not share, disclose, or transfer personal information to any third party located in a jurisdiction that does not provide an adequate level of protection as determined by the relevant data protection authority, unless appropriate safeguards such as Standard Contractual Clauses, Binding Corporate Rules, or equivalent mechanisms have been put in place. A current list of our subprocessors and the safeguards governing any international data transfers is available upon request by emailing chat@aiconnect.buzz.

5. Data Retention

We retain personal information only for as long as is reasonably necessary to fulfill the purposes for which it was collected, or as required by applicable law, whichever period is longer. Contact form submissions and related correspondence are retained for a period of twenty-four months following the most recent interaction, unless an ongoing business relationship is established, in which case the information is retained for the duration of the relationship plus an additional seven years to comply with Canadian tax and commercial record-keeping obligations. Automatically collected technical data, including server logs and analytics data, is retained in identifiable form for a maximum of fourteen months before being permanently anonymized or deleted.

When personal information is no longer required for its original purpose and no legal or regulatory obligation mandates its continued retention, we securely delete or irreversibly anonymize it using methods appropriate to the sensitivity and format of the data. Paper records, if any, are shredded using cross-cut shredders. Digital records are deleted through secure overwrite procedures that render the data unrecoverable. Backups containing personal data are retained pursuant to our standard backup rotation policy and are purged no later than ninety days after the source data is deleted from production systems. We conduct periodic reviews of our data inventory to identify and purge information that has exceeded its defined retention period.

6. Security Measures

The security of your personal information is a foundational priority for How Ai Connects Inc. We have implemented and continuously maintain a comprehensive information security program that encompasses administrative, technical, and physical safeguards designed to protect personal data against unauthorized access, disclosure, alteration, and destruction. Our security posture is informed by industry-standard frameworks including the National Institute of Standards and Technology (NIST) Cybersecurity Framework and the Center for Internet Security (CIS) Critical Security Controls. Below we detail seven specific security measures that form the backbone of our data protection infrastructure.

01

Transport Layer Encryption

All data transmitted between your browser and our servers is protected using TLS 1.3 with strong cipher suites. We enforce HTTPS across all pages and resources, and we employ HTTP Strict Transport Security (HSTS) with a minimum max-age directive of one year to prevent downgrade attacks and cookie hijacking.

02

Encryption at Rest

Personal information stored on our servers and cloud infrastructure is encrypted at rest using AES-256 encryption. Database volumes, backup snapshots, and log storage are all covered by our at-rest encryption policy, with encryption keys managed through a dedicated key management service with strict access controls and regular key rotation.

03

Access Control and Authentication

Access to personal data is restricted to authorized personnel on a strict need-to-know basis. We enforce multi-factor authentication (MFA) for all administrative accounts, implement role-based access controls (RBAC) with least-privilege principles, and maintain comprehensive access logs that are reviewed regularly for anomalous activity.

04

Network Security Architecture

Our production environment is segmented using virtual private cloud configurations with security groups, network access control lists, and web application firewalls. Intrusion detection and prevention systems monitor network traffic for malicious patterns, and all administrative access is routed through a bastion host with session recording enabled.

05

Vulnerability Management

We perform regular vulnerability scanning of our infrastructure and applications using automated tools supplemented by periodic manual penetration testing conducted by qualified independent security professionals. Critical and high-severity vulnerabilities are addressed within a defined remediation window, and all software dependencies are monitored for known vulnerabilities through continuous software composition analysis.

06

Security Monitoring and Incident Response

Our systems generate comprehensive security logs that are aggregated into a centralized security information and event management (SIEM) platform. Automated alerts are configured for indicators of compromise, and we maintain a documented incident response plan with defined escalation paths, containment procedures, and notification protocols. Any confirmed data breach that poses a risk to individual privacy will be reported to the relevant supervisory authority within the legally mandated timeframe, and affected individuals will be notified without undue delay.

07

Employee Training and Governance

All employees and contractors with access to personal data undergo mandatory data protection and security awareness training upon onboarding and on an annual basis thereafter. Training covers secure data handling practices, phishing recognition, password hygiene, social engineering defense, and the specific requirements of applicable privacy laws. Compliance with our security policies is monitored, and violations are subject to disciplinary action up to and including termination of employment or contract.

While we implement robust security measures, no method of electronic transmission or storage is absolutely impenetrable. We cannot guarantee that unauthorized third parties will never defeat our safeguards or misuse your information. We encourage you to take appropriate precautions to protect your own devices and credentials when interacting with online services. If you have reason to believe that your interaction with our website is no longer secure, please notify us immediately at chat@aiconnect.buzz.

7. International Data Transfers

How Ai Connects Inc. is headquartered in Canada, and our primary data processing activities occur on servers located in Canada and the United States. If you are accessing our website or services from outside Canada or the United States, please be aware that your personal information may be transferred to, stored in, and processed in these countries, whose data protection laws may differ from those in your country of residence. By providing us with your personal information, you expressly consent to such transfer, storage, and processing.

Where we transfer personal data from the European Economic Area, the United Kingdom, or Switzerland to a country that has not been deemed to provide an adequate level of data protection by the relevant authority, we rely on appropriate safeguards recognized under applicable data protection law. These safeguards include the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Agreement, and/or adequacy decisions issued by the competent regulatory bodies. We conduct transfer impact assessments to evaluate the laws and practices of the destination country and implement supplementary measures where necessary to ensure that the transferred data receives a level of protection essentially equivalent to that guaranteed within the originating jurisdiction. You may request a copy of the relevant safeguards by contacting us at chat@aiconnect.buzz.

8. Your Rights

Depending on your jurisdiction of residence, you may have certain rights regarding the personal information we hold about you. We respect these rights and have established processes to facilitate their exercise. Below we outline seven specific rights that may apply to you, along with a description of how you can exercise each one. We will respond to all verified requests within the timeframes prescribed by applicable law, typically within thirty to forty-five calendar days. Where a request is particularly complex, we may extend this period by an additional thirty days and will notify you of the extension and the reasons for the delay.

Right of Access

You have the right to request confirmation of whether we process your personal data, and if so, to obtain a copy of that data along with information about the purposes of processing, categories of data concerned, recipients to whom the data has been disclosed, the envisaged retention period, and the source of the data if it was not collected directly from you. The first copy will be provided free of charge; we may charge a reasonable fee for additional copies.

Right to Rectification

You have the right to request that we correct inaccurate personal data concerning you and to have incomplete personal data completed, including by means of providing a supplementary statement. We will make reasonable efforts to verify the accuracy of the corrected data before implementing the change. If we have disclosed the inaccurate data to third parties, we will inform them of the rectification where feasible and legally permissible.

Right to Erasure (Right to be Forgotten)

You have the right to request the deletion of your personal data in certain circumstances, including where the data is no longer necessary for the purposes for which it was collected, where you withdraw consent and no other legal ground for processing exists, where you object to processing and there are no overriding legitimate grounds, or where the data has been unlawfully processed. This right is not absolute and may be limited by legal obligations requiring us to retain certain records.

Right to Restriction of Processing

You have the right to request that we restrict the processing of your personal data where you contest the accuracy of the data, the processing is unlawful and you oppose erasure, we no longer need the data but you require it for the establishment, exercise, or defense of legal claims, or you have objected to processing pending verification of whether our legitimate grounds override your interests.

Right to Data Portability

You have the right to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format, and to transmit that data to another controller without hindrance from us, where the processing is based on consent or a contract and is carried out by automated means. Where technically feasible, you may request that we transmit the data directly to another organization.

Right to Object

You have the right to object at any time to the processing of your personal data for direct marketing purposes, including profiling related to such direct marketing. You also have the right to object to processing based on our legitimate interests or the performance of a task in the public interest, unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.

Right to Withdraw Consent

Where processing is based on your consent, you have the right to withdraw that consent at any time without affecting the lawfulness of processing carried out prior to the withdrawal. Withdrawal of consent does not affect processing based on other lawful grounds. You may exercise this right by contacting us using the details provided in the Contact Information section below.

Right to Lodge a Complaint

You have the right to lodge a complaint with the competent supervisory authority in your jurisdiction if you believe that our processing of your personal data violates applicable data protection law. In Canada, this is the Office of the Privacy Commissioner of Canada. In the European Union, this is the supervisory authority in your member state of residence. We encourage you to contact us first so that we may attempt to resolve your concern directly.

How to Exercise Your Rights

To exercise any of the rights described above, please send a written request to chat@aiconnect.buzz with the subject line —Data Subject Request.— We may need to verify your identity before processing your request, which may involve asking you to confirm details we already hold about you or requesting a copy of government-issued identification. We will not discriminate against you for exercising any of your privacy rights.

9. Cookies and Tracking Technologies

Our website uses cookies and similar tracking technologies to enhance your browsing experience, analyze site traffic, and understand where our visitors come from. A cookie is a small text file that a website stores on your device through your web browser. Cookies may be session-based, meaning they expire when you close your browser, or persistent, meaning they remain on your device for a predetermined duration or until you manually delete them. The cookies we use fall into three categories: essential cookies that are necessary for the website to function properly and cannot be disabled, performance and analytics cookies that help us understand how visitors interact with our site, and functional cookies that remember your preferences to improve your experience on return visits.

You have control over cookies through your browser settings. Most modern browsers allow you to view, manage, delete, and block cookies on a site-by-site basis or globally. You can also configure your browser to send a Do Not Track signal, although there is currently no consensus on how websites should respond to such signals and we do not currently alter our data collection practices in response to Do Not Track headers. Please note that disabling certain categories of cookies may affect the functionality of our website. For detailed guidance on managing cookies in your specific browser, we recommend consulting the browser’s help documentation or visiting www.allaboutcookies.org.

10. Analytics

We use privacy-respecting analytics tools to collect aggregated, non-personally-identifiable information about website traffic and usage patterns. Our analytics implementation is configured to anonymize IP addresses by truncating the last octet before any processing or storage occurs, meaning that full IP addresses are never logged to disk or retained in any analytical dataset. We do not use analytics data to track individual users across sessions, build user profiles, or serve targeted advertising. The analytics data we collect includes page view counts, referrer sources, browser types, device categories, session duration metrics, and coarse geographic distribution at the country level.

The analytics processing is performed by our own infrastructure or by service providers who are contractually prohibited from using the data for their own purposes. We do not integrate our analytics with any advertising networks, data brokers, or third-party data enrichment services. The aggregate insights derived from our analytics help us identify which pages and content resonate with our audience, detect technical issues that degrade the user experience, and make informed decisions about how to structure and present information on our website. No individual visitor can be identified from our analytics reports, and we have configured our tools to minimize data collection to only what is necessary for these operational purposes.

11. Third-Party Services

Our website may contain links to third-party websites, plugins, and services that are not owned or controlled by How Ai Connects Inc. This Privacy Policy does not apply to any third-party website, service, or application, even if you access it through a link on our website. We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services. We strongly encourage you to review the privacy policy of every website you visit before providing any personal information.

In the course of delivering our professional services, we may integrate or interface with third-party platforms and tools at the direction of our clients. In such cases, the client remains the data controller and we act as a data processor, handling personal data strictly in accordance with the client’s documented instructions and the terms of our service agreements. We conduct due diligence on major third-party service providers before engaging them, evaluating their security practices, privacy certifications, and compliance with applicable data protection laws. A current list of subprocessors engaged in the delivery of our services is maintained and updated regularly, and is available to our clients upon request.

12. Children’s Privacy

Our website and services are not directed to individuals under the age of sixteen, and we do not knowingly collect, use, or disclose personal information from children under sixteen years of age. If we become aware that we have inadvertently collected personal data from a child under sixteen without verified parental consent, we will take immediate steps to delete such information from our records. We encourage parents and legal guardians to monitor their children’s internet usage and to instruct them never to provide personal information through websites or online forms without parental permission.

If you are a parent or guardian and believe that your child has provided us with personal information, please contact us at chat@aiconnect.buzz with the subject line —Children’s Privacy Concern.— We will promptly investigate the matter and, upon verification, delete the relevant data from our systems. We take the protection of minors’ privacy very seriously and have designed our data collection practices accordingly, with age-gating mechanisms where appropriate and no features designed to appeal specifically to children or teenagers.

13. Changes to This Privacy Policy

We reserve the right to update or modify this Privacy Policy at any time to reflect changes in our data practices, legal obligations, service offerings, or industry standards. When we make material changes to this policy, we will update the —Effective Date— and —Last Updated— date at the top of this page and, where the changes are significant in nature, we will provide a prominent notice on our website for a period of at least thirty days following the update. For changes that materially affect the rights of individuals whose data we already hold, we may also send a direct notification via email where we have a valid email address on file.

We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting your information. Your continued use of our website and services after any modification to this policy constitutes your acknowledgment and acceptance of the updated terms. If a change requires your consent under applicable law, we will obtain your consent before applying the change to your data. The version history of this Privacy Policy is maintained in our internal records and previous versions are available upon request by emailing chat@aiconnect.buzz.

14. Contact Information

If you have any questions, concerns, or requests regarding this Privacy Policy or our data protection practices, or if you wish to exercise any of your privacy rights as described in this document, we encourage you to reach out to us using the contact details provided below. We take privacy matters seriously and are committed to addressing your concerns in a timely, transparent, and thorough manner. Please direct all privacy-related communications to our designated privacy contact point.

How Ai Connects Inc.
805-1355 Silver Spear Rd
Mississauga, Ontario L4Y 2W9
Canada

Email: chat@aiconnect.buzz
Website: www.aiconnect.buzz

We will acknowledge receipt of your inquiry within five business days and provide a substantive response within thirty calendar days, or sooner where required by applicable law. If your concern involves a matter that you believe we have not adequately addressed, you have the right to contact the Office of the Privacy Commissioner of Canada or the data protection authority in your jurisdiction of residence, as described in the Your Rights section above.