Skip to content
Offra

Personal information

Privacy

We hold very little, for specific reasons, and you can have all of it removed in one click. This page describes what the code actually does.

This is a translation, provided for convenience. The version that governs is the French one, at offra.ca/confidentialite. Where the two differ, the French text governs.

In effect as of September 4, 2026.

Who is responsible

The company responsible for the information described here is Consuly Pte. Ltd., 68 Circular Road, #02-01, Singapore 049422, which operates offra.

The person responsible for the protection of personal information is Philippe Dallaire, fondateur, reachable at confidentialite@offra.ca.

What we hold

  • Business contact details — company name, a publicly published email address, and the web address where we found it. Sometimes the name and role of the person that address belongs to, or a telephone number, when they appear on the same page.

    We keep the URL, an excerpt of the page and the date of consultation for every address. That is the implied-consent basis CASL provides for, and it has to be demonstrable rather than asserted.

  • Public SEAO history — the bids and contracts already published by the Government of Quebec.

    This is open data under CC-BY 4.0. It concerns companies, not people.

  • The emails sent — the subject and the exact text of each message as it was delivered, along with the delivery and bounce notices.

    Written once, never modified. If you ever ask us what we wrote to you, the answer has to be the message and not a reconstruction.

  • Page views — the date, the browser, and a fingerprint of the IP address.

    For those views the IP address is not kept as it is: it is turned into a salted, irreversible fingerprint, in line with Law 25's minimisation principle. We use neither tracking pixels in emails nor advertising cookies. Site analytics is a separate thing, and it is left to you: see below.

  • The consent register, and its exception — every unsubscribe and every express consent: the exact text you were shown, the page, the date, and the IP address in clear.

    This is the only place an IP address is not turned into a fingerprint, and it is deliberate: this register exists to prove that a decision was made, by somebody, at a given moment. An irreversible fingerprint would prove nothing.

  • Appointments — if you book a call: your name, your email and the booking details.

  • Purchases — the billing email address, the amount, the billing address and, if you provide them, your tax numbers.

    Card numbers never pass through our servers: payment is handled by Stripe, which is the controller for that data. We keep Stripe's full response, because in a chargeback it is that response that stands.

  • Account — the email address you sign in with, and a name if you gave one.

  • The documents you upload — the file itself, in private storage; its name; the text we extract from it, page by page; and the findings we draw from it, with their page.

    A public tender document — the specifications, an addendum — is read once and serves the other reports on that same notice; its file name is then never displayed, because it often contains a company or project name. Your past bids are neither shared nor reused that way. Reading a document requires sending it to the providers named below.

Where this information comes from

Three origins, and they do not obey the same rules.

What you give us yourself. The documents you upload, your billing address, the name and email on an account: we hold them from you, at the moment you give them. It is the only category collected directly from the person concerned, and you can always choose to upload nothing — a report is produced entirely without.

What a colleague gives us about you. An administrator opening a seat in their workspace types the address of the person they invite. We then hold only that address and the proposed role, we use it to send one invitation, and the link it contains expires after fourteen days. Declining the invitation, or simply ignoring it, creates no account: write to us and we delete the address without waiting for it to expire.

What we find on the open web. SEAO publishes no bidder contact details. Every address we hold was therefore found elsewhere, and how it may be found is constrained.

  • Published addresses only. An address is recorded only if the exact string appeared on a page we consulted. The URL, an excerpt of that page and the date are kept with it — three mandatory fields, without which the record cannot exist.
  • Never a guessed address. No address reconstructed from a first name and a domain. That is not an internal policy but an impossibility: there would be no page to cite, so no record to create.
  • No purchased lists, no enrichment provider. Including for checking that an address exists: we query the mail server directly rather than uploading our records to a third party.
  • The crawler declares itself and limits itself. It respects robots.txt, identifies itself with a way to reach us, spaces its requests and reads no more than a dozen pages per site.

Who else is involved

Each for one function only. We do not sell, rent or trade any data.

Supabase
Database, accounts and sending sign-in links. Also holds the documents you upload, in private storage where no file is reachable without a link we sign for one minute.
Stripe
Payment, taxes, billing address and tax numbers.
Resend
Sending emails and delivery notices.
Google Workspace
A second sending path, from a named business mailbox, so that you can simply reply.
Cal.com
Booking a call. Receives your name, your email and your company name, to prefill the form.
Mistral AI
Converts the documents you upload to text. Receives the full content of each file — specifications, pricing schedule, past bid — because there is no way to read part of one without sending it. It is the only one of these providers established in the European Union.
OpenRouter (Anthropic, DeepSeek)
Two uses. It writes the plain-language summary of a report, and then receives the notice's figures and company names, no information about a person. It also reads the documents you upload, to draw findings from them: it then receives their text, up to sixty pages per report.
Groq
Reads a person's name and role out of the page excerpt we have already kept. Receives that excerpt and the email address in it. The model reads a page we consulted; it invents no contact details.
Serper.dev
Looks up a company's official website. Receives a company name and a municipality.
Exa
Looks up a company's official website, like the previous service. Receives a company name and a municipality.
Umami
Site analytics, with no cookie and without identifying you. Receives the page viewed, the previous page, your browser and a truncated IP address — never a complete one. The request leaves from our servers and not from your browser, which therefore never contacts it directly.
Google (Tag Manager, Analytics)
Only if you have accepted. It then receives the pages you view and sets cookies in your browser. Nothing from Google is loaded before that click, and you can change your mind at any time.
Railway
Application hosting.

Outside Quebec

Consuly Pte. Ltd. is headquartered in Singapore, and the providers above run their infrastructure outside Quebec, mainly in the United States — with the exception of Mistral AI, established in France. Your information is therefore stored and processed there.

We tell you because Law 25 requires it, and because it is structural rather than accidental: it follows from the choice of providers, not from a hosting detail.

The same holds for analytics. What leaves Quebec for Umami is deliberately thin — a page, a previous page, a browser, a truncated IP address — and leaves from our servers rather than yours. What leaves for Google leaves only with your agreement, and stops when you withdraw it.

For how long

We do not publish a retention period the code does not apply. Here is the real state of it.

  • Nothing is deleted automatically. No scheduled job purges anything. Information is kept as long as it serves the reason it was collected for — or until you ask us to remove it.
  • Three things are kept permanently, and deliberately. The consent register, the unsubscribe list and the text of the messages sent. These are compliance documents: their whole purpose is to prove what was done, and at what moment we stopped.
  • Deleting a document removes it from your view without erasing it. It disappears from your lists, no link can reach it any more and it stops being read — but the file and its record are kept, as is the text we extracted from it. We keep it so we can answer “what exactly had I uploaded” and put it back if need be. The findings already written into a version of a report are not removed either — a sold version never changes, which is the rule that protects you elsewhere and applies here too. For a real erasure, write to us: it is a manual operation, and we do it.
  • The links we send you do not expire. The unsubscribe link stays valid if you change your mind, and the link to a report you bought stays openable. Only the sign-in link to an account expires, after an hour.

What you can require

  • Stop receiving anything. The unsubscribe link at the bottom of every email acts immediately, with no sign-in and no confirmation.

    CASL allows ten business days; handling it in the request itself removes the question. The unsubscribe register accepts neither modification nor deletion — it is a legal document.

  • Access, correction, withdrawal. Write to us and we will send you what we hold about you, correct it or delete it.

    Two exceptions, stated plainly. The consent and unsubscribe register is kept, because its purpose is to prove that we stopped writing to you. And a document's “delete” button hides it rather than erasing it, for the reason explained above — an erasure request addressed here does erase.

  • Portability. You can ask for the information you gave us in a structured, commonly used technological format.

  • Complain.If our answer does not satisfy you, you can take it to the Commission d'accès à l'information du Québec.

Cookies and analytics

There is a banner, and it asks one question: do you accept Google Analytics. Everything else in this section is true whether you answer yes or no.

  • The basic measurement, for everyone. We count page views with Umami, which sets no cookie, writes nothing in your browser and follows you on no other site. A visitor there is a fingerprint recomputed every day from a truncated IP address and your browser: the next day, the same person is somebody else. The script is served from offra.ca, so your browser contacts nobody else to display this page.
  • Google Analytics, only if you accept it. Nothing from Google is loaded before you click “Accept”. If you do, Google Tag Manager and Google Analytics set cookies that recognise you from one visit to the next. Refusing is one click, in the same place, at the same size and in the same words as accepting — and clicking nothing at all counts as refusing.
  • You can change your mind. The “Cookies” link at the bottom of every page reopens the question. If you withdraw your agreement, we withdraw the consent with Google and delete its cookies immediately; the code already loaded in the open tab stops at the next page load. We say so rather than pretending otherwise.
  • A browser that has already answered. If it sends the “Global Privacy Control” signal, we record it as a refusal and do not show you the banner. You have already expressed the choice; asking again would be the opposite of respecting it.
  • The pages that are not measured at all. The ones whose link was sent to you personally: the unsubscribe, the booking, the preview and the report. The address of those pages is itself the key that opens them, so it is passed to nobody — not to Google, not to Umami, even if you accepted everything. The company name you type into the subscription form does not leave either.
  • The other cookies. Your session cookie, set when you sign in to your account and shared with the application so that you do not have to sign in again moving from one to the other. And, since the site became bilingual, your language: it is written only when you click the FR/EN button, never on arriving at a page, and it is shared with the application so that you do not have to choose again after signing in. It contains two letters. Your light or dark theme choice and your answer to the banner stay in your browser and never reach us.
  • No tracking in emails. Our messages are plain text, with no HTML version: a tracking pixel is not even representable in one. Links pass through no redirector, which holds for the unsubscribe link too.
  • No advertising. No ad network, no social network pixel, no advertising cookie, and nothing that serves to profile you. Typefaces are served from our own servers, so your browser does not contact Google to display them.

Privacy incidents

We keep a register of privacy incidents. If an incident presents a risk of serious harm, we notify the Commission d'accès à l'information and the people concerned without delay, as Law 25 requires.

Automated decisions

Our models assess tenders, not people. No decision producing an effect on you is taken exclusively by automated processing — and the decision that matters, whether or not to bid, remains entirely yours.

Contact us

For any question about the protection of personal information, or to exercise one of the rights above, write to confidentialite@offra.ca.

A change to this page takes effect on publication, with a new effective date.

Consuly Pte. Ltd.Offra par Consuly Pte. Ltd - 68 Circular Road, #02-01, 049422, Singapore