Legal document

Privacy Policy

How we protect the personal information captured on your sites.

Issued by
Aquilix Technologies Inc.
Last updated
August 25, 2026
Sections
17
Privacy officer
Simon Roy, Chief Technology Officer
Related document
Terms of use

01Who this policy is for

Technologies Aquilix inc. (“Aquilix”) designs and operates an AI video analytics system for occupational health and safety (OHS) prevention on construction sites. This work involves processing images of people, and therefore personal information within the meaning of Quebec's Law 25.

This policy is addressed to:

  • workers, subcontractors and visitors filmed on a site where Aquilix is deployed;
  • the client companies that use the platform;
  • anyone who visits our website or uses the client portal.

This is the public version of our internal personal information governance policy, which governs all of our practices and binds our staff, officers, consultants and subcontractors.

02What we collect

We capture and keep only the images and metadata needed to detect the health and safety events defined with the client:

  • images from the site cameras, framed on hazard zones; break areas, changing rooms and private spaces are excluded;
  • the technical metadata needed to operate the service (camera identifier, timestamp, IP address, session data);
  • the configuration defined with the client (detection zones, types of events to detect);
  • for the website and client portal: account data, connection logs, cookies and analytics tools. Non-essential tools can be declined.

The cameras do not capture sound. Any audio capture is prohibited without a written decision by the privacy officer.

Before each deployment, we document a necessity and proportionality test in writing with the client: the concrete risk specific to the site, the minimum scope and duration of the collection, and the less intrusive alternatives considered together with the reasons they were set aside.

03Why we collect it

A single purpose justifies the collection: occupational health and safety.

  • preventing accidents, injuries and occupational illnesses;
  • investigating after an accident;
  • supporting health and safety training.

Performance evaluation, productivity monitoring and general discipline of a worker are excluded from this purpose. That exclusion is written into the client contract.

04What we do not do

  • No facial recognition. We neither create nor keep biometric templates — that is, a measurement of a face, gait or body shape converted into data that can be used to recognize a person.
  • No audio recording.
  • No sale, rental or disclosure of personal information for advertising purposes.
  • No use of images to assess a worker's performance, productivity or discipline.

No feature that relies, or could reasonably rely, on biometric measurements is developed in real conditions, activated or offered on a trial basis until four conditions are all met: a written and reasoned decision by the privacy officer, a privacy impact assessment, the express consent of the people concerned, and a written declaration to the Commission d'accès à l'information filed at least 60 days before the feature goes live.

When the system has to recognize that a person seen by one camera is the same as the one seen by another — otherwise it would count two workers where there is only one — it relies solely on non-biometric attributes: clothing, hard hat, high-visibility vest, silhouette, position, trajectory and timestamp. The tracking identifier is temporary and cannot be linked to a name, an employee number or any other identifier. This feature ships disabled by default, and turning it on requires a documented decision and prior notice to the people concerned.

05Blurring and minimization

Detection runs on the image in memory. Only a version that has gone through the following measures is kept, displayed or disclosed:

  • irreversible blurring of faces;
  • dynamic masking of the full silhouette when the detection does not require the body to be visible;
  • anonymization of clip timestamps.

These measures apply to retained clips, to images used for training, instruction or demonstration, and to any content disclosed to a third party. Detecting personal protective equipment and presence in a hazard zone does not require facial features to be visible.

The client cannot require these measures to be turned off. Only a written, reasoned and time-limited decision by the privacy officer can lift them, and that decision is recorded.

Deployment status: face blurring is applied to retained clips and to training images. Enabling it by default across the entire camera fleet, without client intervention, along with real-time anonymization at capture, will be deployed no later than December 1, 2026.

06Who can view the images

Access to images and clips is closed by default and granted individually. Aquilix maintains a controlled list of authorized people and requires every client to maintain one as well. Each authorized person signs a confidentiality undertaking beforehand, and that undertaking survives the end of their employment or mandate.

Only people who hold an occupational health and safety role and who act as neutral observers may be added to the list:

  • health and safety coordinators, advisors and officers of the site or of the client company;
  • members of the health and safety committee, where the committee's mandate warrants it;
  • investigators appointed after an accident, for the duration of the investigation and for the relevant clips only;
  • Aquilix staff strictly required for operations, technical support and annotation;
  • the monitoring station, for intrusion alerts only and under a written agreement.

People who exercise authority over the organization, supervision or evaluation of work — site managers and superintendents, foremen, crew leads, production managers and human resources managers — cannot view the images. This exclusion is structural and is not a judgment on individuals: it keeps the prevention purpose from drifting toward performance assessment. If a client asks for such access, we refuse and document the refusal in writing.

When a manager needs to be informed of an event, they receive a written report describing the hazardous situation and the corrective action required, with no image and no identification of the worker, unless the law or an accident investigation requires otherwise.

07Human review

Analyses are produced automatically, but authorized people do view images in three situations: technical support and maintenance, annotation of the images used to train our models, and investigation following an accident.

Anyone who views images is on the controlled list described in section 6 and bound by a confidentiality undertaking requiring them to consult images only for the health and safety purpose, to disclose their content to no one, and to keep no copy or screenshot.

08Improving our models

Using site images to train or improve our models is a purpose distinct from delivering the service. We state it as such, here and in our client contracts.

  • no identifiable raw image goes into the training set: faces are blurred and timestamps anonymized before any annotation;
  • a dataset log records the origin, content and retention period of each set;
  • training images assembled before our policy was adopted are subject to a sorting, anonymization or destruction plan approved by the privacy officer;
  • anyone taking part in annotation is on the controlled list and signs a confidentiality undertaking.

09How long we keep the images

The periods below are maximums set by our retention schedule:

  • continuous video streams: 30 days by default from capture, then automatic deletion; the period can be adjusted in the client contract;
  • health and safety event clips: the period set in the client contract, failing which three years from the event;
  • intrusion clips sent to the monitoring station or to police: until the file is closed; the transmission log is kept for three years;
  • blurred training images: for as long as they remain useful for improving the models, with an annual review;
  • system access logs: 24 months. Confidentiality incident register: at least five years.

Information is destroyed or anonymized as soon as the purposes of its collection are fulfilled, even before the deadline. Destruction is suspended for information covered by ongoing litigation, an investigation, a confidentiality incident or an access request, and resumes when the file is closed.

10What we share, and with whom

We do not sell personal information. There are three cases of disclosure, all governed in writing:

  • Monitoring station: when an anomaly is detected, a short clip of the event is sent to it for validation. The camera stream is viewed only once an intrusion has been validated, for the purpose of dispatching a response. A written agreement limits use to those two purposes and every transmission is logged.
  • Police: under the exceptions provided by law. Every transmission is logged.
  • Suppliers: only where their involvement is necessary to deliver the service, and under a written contract providing for purpose limitation, confidentiality, prompt incident notification, an audit right and certified destruction of the data at the end of the contract.

Clips sent in an intrusion context may, strictly to the extent necessary to identify an intruder, not be anonymized. That exception is set out in the written agreement with the monitoring station, limited to the sequences concerned and recorded in the transmission log.

Any other disclosure requires the consent of the person concerned or a legal obligation.

11Security

Our security measures are proportionate to the sensitivity of the images:

  • encryption of data in transit and at rest;
  • environments partitioned per client;
  • multi-factor authentication and least-privilege access;
  • access to images limited to the people on the controlled list described in section 6.

We hold no SOC 2 or ISO/IEC 27001 certification to date. Those attestations, along with systematic logging of image consultations and periodic backup restoration testing, are part of our governance roadmap and are not yet in force.

12Where the data is hosted

The images entrusted to us are hosted in Quebec, in environments partitioned per client. No personal information is disclosed outside Quebec.

Before any future disclosure outside Quebec, we would carry out a privacy impact assessment taking into account the legal regime of the destination jurisdiction, and enter into a written agreement. We take into account that a supplier incorporated in the United States, or whose parent company is, can be compelled by U.S. law to disclose information even when it is stored in Canada: the decisive factor is the supplier's legal ties, not the location of the server.

13Alerts and automated decisions

The alerts produced by the system are flags meant to be validated by a person. No decision adverse to a worker is based exclusively on automated processing.

Were such a decision to be made, the person concerned would be informed and could submit their observations.

14Your rights

Anyone concerned may request:

  • access to the personal information that concerns them;
  • its correction;
  • its communication in a structured technological format (portability);
  • the withdrawal of their consent.

Requests are addressed to the privacy officer, who answers in writing within a maximum of 30 days and records the handling of each request.

Where a sequence shows other people, we mask those third parties rather than refuse the request. A request may be refused in whole or in part where it runs into a legitimate obstacle, in particular a person's safety or confidential commercial information. Any refusal is given in writing with reasons and can be challenged before the Commission d'accès à l'information.

15Confidentiality incidents

Any unauthorized access, use, disclosure or loss is recorded in our incident register. The privacy officer assesses the risk of serious injury and, where applicable, promptly notifies the Commission d'accès à l'information and the people concerned, then documents the corrective measures.

Viewing images by someone who is not on the controlled list, or by an authorized person for a purpose other than occupational health and safety, is a confidentiality incident.

16Contact us

To exercise your rights, report an incident or ask a question about this policy, write to the privacy officer:

  • Simon Roy, Chief Technology Officer
  • info@aquilix.ca
  • Technologies Aquilix inc.

You can also write to us from the Contact us.

17Changes to this policy

This policy is reviewed at least once a year, and on every significant change: a new feature, a new market or a legislative amendment. The date of the last update appears at the top of the page.

Any change is published on this page. By continuing to use our services, you accept the version in force.