Privacy Policy
Draft — pending legal review. This document is a working draft and may change before it takes effect.
This Privacy Policy explains how Evolved Tech Group Inc. (“we”, “us”) handles personal information in connection with LeaderSync, our AI leadership coach and operating partner for leadership teams, and the leadersync.ai website. We wrote it to be read, not skimmed past. If anything is unclear, ask us.
1. Who we are
LeaderSync is operated by Evolved Tech Group Inc., a company based in Alberta, Canada. We are responsible for personal information under our control and have appointed a Privacy Officer who is accountable for our compliance with this policy and with applicable Canadian privacy law, including the Personal Information Protection and Electronic Documents Act (PIPEDA) and, where it applies, Alberta’s Personal Information Protection Act (PIPA).
2. What this policy covers
This policy covers two kinds of information:
- Customer Data — the information a customer organization and its people put into LeaderSync or that LeaderSync collects on the customer’s behalf: messages to the agent, emails, meeting transcripts, priorities, numbers, issues, action items and similar records. For Customer Data, our customer decides what goes in and who can see it, and we process it on the customer’s behalf under our Terms of Service.
- Account, billing and website information — information about the people who sign up, administer and pay for LeaderSync, and about visitors to our website. We are responsible for this information.
If you use LeaderSync through your employer, your employer controls your Customer Data. Please contact them first with questions about it; we will help them respond.
3. Information we collect
Information you give us
- Account and contact details: name, work email address, job title, company name and time zone.
- Your team: the names, work email addresses, titles and roles of the people you add, and which of them are on your leadership team.
- Conversations with your agent: messages you and your team send by email, in the web app or (when available) in Microsoft Teams, and the agent’s replies.
- Your operating system: the records the agent keeps for your team, such as your Vision Plan, Seat Map, Quarterly Priorities, Weekly Numbers, issues, action items, meeting notes, Core Processes, Health Check results, and confidential Quarterly Check-ins and Fit Reviews.
- Support requests: what you tell us when you contact us.
Information we collect on your behalf
- Email content: emails sent to or from your workspace address and agent threads, including the sender, recipients, subject, body text and dates. We remove quoted earlier messages and do not accept attachments.
- Microsoft 365 information: with your administrator’s approval, directory details (names, email addresses, job titles and Microsoft identifiers) for people you search for or add, and calendar events needed to find and schedule your meetings.
- Meeting recordings and transcripts: see section 6.
Information collected automatically
- Service logs: IP address, browser type, pages and actions requested, timestamps and error details, used to run, secure and troubleshoot LeaderSync.
- Sign-in cookie: the web app uses a cookie to keep you signed in.
Information from payment providers
Payments are processed by Stripe. We receive limited billing details, such as the billing contact, billing address, card brand, last four digits and subscription status. We do not receive or store full card numbers.
4. How we use information
We use personal information to:
- provide LeaderSync, including running your agent, sending and receiving its messages, joining and transcribing the meetings you set up, and keeping your team’s records;
- set up and manage accounts, subscriptions, billing and free trials;
- respond to support requests and send service messages (for example, about your trial, billing or changes to the service);
- keep LeaderSync secure, prevent abuse and investigate problems;
- understand, in aggregate, how LeaderSync is used so we can improve it; and
- meet legal, tax and accounting obligations.
We do not sell personal information. We do not use Customer Data for advertising. We do not use Customer Data to train AI models.
We collect, use and disclose personal information with consent, which may be express or implied depending on the sensitivity of the information and the reasonable expectations of the individual, or as otherwise permitted or required by law. A customer organization that adds people to LeaderSync is responsible for having the authority and providing the notices needed to do so.
5. AI processing
Your agent is powered by Claude, a large language model provided by Anthropic. To respond to a message, prepare an agenda or process a transcript, we send Anthropic the content the agent needs for that task, which can include Customer Data. Anthropic processes it as our subprocessor under commercial terms that do not permit it to use that content to train its models.
AI-generated content can be wrong or incomplete. LeaderSync is designed so that people stay in charge: the agent records what people tell it, and anyone can correct it by replying.
6. Meeting recordings and transcripts
When a customer sets up a meeting in LeaderSync, a notetaker provided by our subprocessor Recall.ai joins that meeting from its link and appears in the participant list. It records the meeting’s audio (and may receive video and the meeting chat) to produce a transcript that attributes what was said to each speaker. We store the transcript in the customer’s workspace and use it to create action items, issues, priority updates and a recap.
The customer is responsible for telling participants that the meeting is being recorded and transcribed and for obtaining any consent the law requires, including from participants outside their organization. Participants who do not want to be recorded should raise it with the meeting organizer, who can remove the notetaker.
7. Subprocessors and sharing
We use the following subprocessors to provide LeaderSync. Each receives only what it needs for its role and is bound by contract to protect it.
| Subprocessor | Purpose | Location |
|---|---|---|
| Amazon Web Services | Application hosting and database | Canada (ca-central-1) |
| Anthropic | AI processing (Claude) for your agent | United States |
| Recall.ai | Meeting notetaker: recording and transcription | United States |
| Postmark | Sending and receiving email | United States |
| Stripe | Billing and payments | United States |
| Microsoft | Sign-in, team directory, calendars and Microsoft Teams | Per your Microsoft 365 tenant |
We will update this list before adding or replacing a subprocessor. We may also disclose personal information:
- within a customer’s workspace, to the people that customer has authorized — for example, the agent posts recaps to the leadership team, while confidential people records are limited to owners, admins and the person’s manager;
- to professional advisers, such as lawyers and accountants, under confidentiality obligations;
- if required by law, court order or a lawful request from a public authority, or to protect the rights, property or safety of our users, the public or us; and
- in connection with a merger, financing or sale of all or part of our business, subject to equivalent protections.
8. Where information is stored
The LeaderSync application and its database are hosted by Amazon Web Services in Canada (the ca-central-1 region), and database backups are kept in the same region.
Some subprocessors process information outside Canada, mainly in the United States — including Anthropic (AI processing), Recall.ai (meeting recording and transcription), Postmark (email) and Stripe (billing). While information is outside Canada, it is subject to the laws of that jurisdiction and may be accessible to its courts, law enforcement and national security authorities. We use contracts and other measures to protect it.
9. How long we keep information
- Customer Data is kept while the customer’s subscription or trial is active, so the agent can keep the team’s history.
- If a trial ends without a subscription, or a subscription is cancelled or unpaid, the workspace is paused and its Customer Data is kept for 90 days so the customer can reactivate or export it. After that, we delete it.
- When a customer asks us to delete their workspace, we delete Customer Data from our active systems within 30 days. Copies in encrypted backups expire within a further 30 days.
- Service logs are kept for up to 30 days, unless needed longer to investigate a security issue.
- Billing and tax records are kept for as long as Canadian tax law requires, generally six years.
10. Export and deletion
Customers can export their whole operating system at any time from the web app, as a zip of plain Markdown files. Owners can ask us to delete their workspace by emailing support@leadersync.ai. We will confirm the request before acting on it and let them know when deletion is complete.
11. Security
We protect personal information with safeguards appropriate to its sensitivity, including encryption in transit (TLS) and at rest, per-company isolation of data and agent access, an additional per-company encryption key for connection secrets, single sign-on or one-time sign-in links instead of passwords, restricted staff access with audit logging, and a private network for our database. No method of transmission or storage is perfectly secure; if a breach of security safeguards creates a real risk of significant harm, we will notify affected customers, individuals and regulators as the law requires.
12. Your choices and rights
Subject to the law, you can ask to access the personal information we hold about you, ask us to correct it, and withdraw your consent to our use of it (which may mean we can no longer provide some or all of LeaderSync). To make a request, email our Privacy Officer at support@leadersync.ai. We will respond within 30 days, or tell you if we need more time as the law allows.
If your request is about Customer Data held for your employer, we may refer it to them and help them respond.
If you are not satisfied with our response, you can contact the Office of the Privacy Commissioner of Canada or, in Alberta, the Office of the Information and Privacy Commissioner of Alberta.
13. Cookies and analytics
The leadersync.ai marketing website does not use advertising or analytics cookies, and it serves its fonts itself rather than loading them from third parties. The LeaderSync web app uses a necessary cookie to keep you signed in. If we add analytics in the future, we will update this policy first.
14. Children
LeaderSync is a business service. It is not intended for anyone under 18, and we do not knowingly collect their personal information.
15. Changes to this policy
We may update this policy as LeaderSync changes. We will post the new version here with a new “last updated” date and, for material changes, notify customer owners by email before the changes take effect.
16. Contact us
Privacy Officer
Evolved Tech Group Inc.
Alberta, Canada
support@leadersync.ai (subject: “Privacy”)