Legal
Privacy Policy
Version 3.1 — Effective September 18, 2026
This Privacy Policy explains how Nomaxion Inc. ("Nomaxion", "we", "us", or "our") collects, uses, discloses, stores, and protects personal information when you and your organization access or use the Nomaxion platform, including our web application and installable mobile (progressive web) application (collectively, the "Platform"). Nomaxion is a digital record-keeping, workflow, and verification tool for industrial, construction, and pipeline operations. It is a record-keeping tool only — it does not approve work, authorize anyone to work, monitor field conditions in real time, or certify any site, person, or activity as safe or compliant.
Nomaxion is operated from Alberta, Canada, and serves organizations across Canada and the United States. We handle personal information in a manner consistent with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), Alberta's Personal Information Protection Act (PIPA), Quebec's Act respecting the protection of personal information in the private sector (as amended by Law 25), the personal information laws of the other provinces, and, for U.S. residents, applicable U.S. state privacy laws such as the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA) and comparable laws in other states (see Section 13). This Policy works together with our Terms of Service and the Data Accuracy, Liability & Hold-Harmless Agreement accepted at sign-up.
1.Roles: who controls your information
In most cases your employer or contracting organization ("your Organization") determines what data is entered into the Platform and the purposes for which it is used. For that data, your Organization is the controlling party (in some laws, the "controller") and Nomaxion acts as a processor / service provider that stores and processes the information on your Organization's behalf and on its instructions.
Nomaxion is the controlling party for a limited set of information we collect directly to create accounts, secure the Platform, bill for the service, and meet our own legal obligations (for example account, authentication, security-log, and device information described below). Where your request concerns data your Organization controls, we may direct you to your Organization or act on its instructions.
2.Information we collect
We collect the following categories of personal information:
Some field and safety records may incidentally contain sensitive information (for example details relating to an injury in an incident report, or your image and voice in captured media). We treat such information with a correspondingly higher standard of care and collect it only for the safety and record-keeping purposes described here.
Voice and image data. Voice recordings and photographs are collected only when you actively use a feature that captures them. We do not use facial-recognition or voiceprint biometric identification, and we do not use your media to identify you biometrically.
Biometric sign-in (Face ID, Touch ID and device biometrics). Nomaxion offers optional biometric sign-in and passkeys purely as a convenience for unlocking the app. When you turn this on, the biometric check — Face ID, Touch ID, or your device’s fingerprint sensor — is performed entirely by your device’s own operating system and secure hardware. Nomaxion does not collect, receive, access, store, transmit, or share face data or any other biometric identifier. We never see your face or fingerprint data; it never leaves your device. All that Nomaxion receives is a yes/no confirmation from your device that the check succeeded, together with a device-generated public key (for passkeys) or an encrypted credential reference held in your device’s own secure keychain. This biometric data is not shared with us or with any third party, and there is nothing for us to retain or delete because we never hold it.
3.How we use information
We use personal information to:
- create, administer, and secure user accounts and verify identity;
- record, cross-reference, and display safety and compliance documentation;
- attach accurate time, place, and authorship to records;
- deliver notifications, reminders, and safety-related alerts;
- maintain a tamper-evident, cryptographically chained audit trail of key actions;
- provide AI-assisted features such as transcription and summarization;
- operate, maintain, troubleshoot, secure, and improve the Platform;
- bill for the service and manage the customer relationship; and
- comply with legal, regulatory, and safety record-keeping obligations.
We do not sell personal information, and we do not use it for third-party advertising or for cross-context behavioural advertising.
4.Legal basis & consent
We collect and use personal information with consent and as reasonably required to deliver the Platform to your Organization and to meet legal and safety record-keeping obligations. By using the Platform and granting device permissions (such as location, camera, or microphone), you consent to the collection and use described here. Where the Platform is provided to you through your Organization, your Organization is responsible for establishing the appropriate authority and notice for the data it enters.
You may withdraw consent for optional collection — for example by disabling location, camera, or microphone permissions, or turning off push notifications — subject to the effect this has on features and on records that rely on that information. Withdrawing consent does not affect records already created or the lawfulness of prior processing.
5.Cookies, local storage & similar technologies
The Platform uses strictly necessary cookies and browser local storage to keep you signed in, remember your session and preferences, protect against fraud and abuse, and enable offline and installable-app functionality. As a progressive web app, the Platform may cache data on your device and register a service worker so it can function with limited or intermittent connectivity.
We do not use third-party advertising cookies or cross-site tracking. Any usage or diagnostic measurement we perform is limited to operating and improving the Platform. Because we do not track you across other websites, we do not respond to browser "Do Not Track" signals differently; we simply do not engage in such tracking. You can clear cookies and local storage through your browser or device settings, though doing so may sign you out and remove cached offline data.
6.How information is shared
Within your Organization. Records are visible to authorized users in your Organization according to their role and project access.
Between collaborating organizations. Where your Organization works with an asset owner, prime contractor, or subcontractor on a shared project, relevant records may be visible to authorized users of those organizations to the extent required for that project.
Service providers & sub-processors. We use trusted infrastructure and processing providers to host the Platform and deliver features such as cloud storage, notifications, and AI-assisted summaries. These providers may process information only on our instructions, under contractual confidentiality and security obligations, and only as needed to provide their service.
Legal & safety. We may disclose information where required by law, regulation, subpoena, or legal process, to enforce our agreements, or to protect the rights, property, or health and safety of any person.
Business transfers. If Nomaxion is involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction, subject to this Policy.
We do not sell personal information to third parties.
7.Artificial intelligence & automated processing
Certain features use artificial intelligence to transcribe voice recordings, summarize field conversations, and extract or suggest content. When you use these features, the relevant input (such as a voice recording or document) is processed by our AI service providers to produce the output. This processing is used to provide the feature you requested; it is not used to build advertising profiles.
AI output is advisory and may contain errors. The Platform does not make automated decisions that produce legal or similarly significant effects about you without human involvement — a qualified user is always responsible for reviewing and validating AI-assisted output before relying on it.
8.Where information is stored (data residency & international transfer)
Platform data is hosted on managed cloud infrastructure. Depending on the hosting region, information may be stored or processed in Canada and/or the United States and handled by our infrastructure and sub-processors. Where information is processed outside your province or country, it may be subject to the laws of the jurisdiction in which it is held, and may be accessible to courts, law-enforcement, and regulatory authorities in that jurisdiction under their laws.
Where we transfer personal information to a service provider in another jurisdiction, we use contractual and other safeguards intended to provide a comparable level of protection. Contact us for current data-residency details applicable to your deployment.
9.Data retention
Safety and compliance records — including work orders, permits, hazard assessments, inspections, incidents, signatures, legal-acceptance records, and their audit history — are retained for the period required to meet your Organization's legal, regulatory, and record-keeping obligations, and to preserve the integrity of the audit trail. When such records are removed from active views they are generally soft-deleted (retained but hidden) rather than erased, and their tamper-evident audit history is preserved.
Voice and audio recordings (Field Talks, group discussions, and site assessments) are kept only as long as needed to produce the written safety record. The original audio is automatically deleted 14 days after it is recorded, while the transcript and summary generated from it are retained as part of the safety record above.
Transient or convenience data — for example in-app notifications, draft entries, certain maintenance or line-item logs, cached offline data, and demo/test data — may be permanently deleted when no longer needed or on request. Security and access logs are retained for a period appropriate to detect and investigate misuse. Where you ask us to delete information, we will do so unless we (or your Organization) are required or permitted to retain it for legal, safety, or compliance reasons, in which case we will retain only what is necessary.
10.How we protect information
We use administrative, technical, and physical safeguards designed to protect personal information, including: role- and project-based access controls; encryption of data in transit; hashed and salted credentials and signing PINs; optional multi-factor authentication and passkeys; breached-password screening; per-request rate limiting to blunt automated brute-force attempts; and a cryptographically chained, tamper-evident audit log for key records. We restrict access to personal information to those who need it to operate the Platform. For a fuller description of these controls, see our Security & Trust page.
No system can be guaranteed perfectly secure. You are responsible for keeping your credentials, signing PIN, and devices confidential and secure, and for notifying us promptly if you suspect unauthorized access to your account.
11.Breach notification
We maintain procedures to detect, investigate, and respond to security incidents. In the event of a breach of security safeguards involving personal information that creates a real risk of significant harm, we will notify affected individuals and the applicable privacy regulator(s), and keep records of breaches, as required by PIPEDA and other applicable law. Where we act as a service provider to your Organization, we will notify your Organization without undue delay so it can meet its own notification obligations.
12.Your privacy rights
Subject to applicable law (including PIPEDA, Alberta PIPA, and Quebec's Law 25), you may:
- request access to the personal information we hold about you;
- request correction of inaccurate or incomplete information;
- ask how your information is collected, used, and disclosed;
- request a copy of the computerized personal information you provided to us in a structured, commonly used technological format (data portability), where required by law;
- request that we cease disseminating your personal information, or de-index a link to it, where its dissemination contravenes the law or a court order (for example under Quebec's Law 25);
- withdraw consent for optional collection (subject to the effect on the service); and
- make a complaint about our handling of your information.
Because your Organization controls much of the data entered into the Platform, some requests (for example to correct or delete a safety record) may be directed to, or require the involvement of, your Organization. To exercise a right, contact us using the details below. We may need to verify your identity before responding. We will respond within the timeframe required by applicable law (generally within 30 days under PIPEDA and Alberta PIPA), and will tell you if we need more time or cannot fulfill a request, along with the reason.
13.United States residents — your state privacy rights
If you are a resident of a U.S. state that has enacted a consumer or personal-data privacy law — including California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, and Montana — you may have additional rights with respect to your personal information, subject to the exceptions and limits in the applicable law. Because much of the data in the Platform is controlled by your Organization, some requests may be directed to, or require the involvement of, your Organization.
California (CCPA/CPRA). Since January 1, 2023, the California Consumer Privacy Act, as amended by the California Privacy Rights Act, applies to personal information collected in an employment and business-to-business context. Subject to the statute, California residents may: (i) know and access the categories and specific pieces of personal information we collect, use, and disclose; (ii) request correction of inaccurate personal information; (iii) request deletion of personal information; and (iv) limit the use and disclosure of sensitive personal information. Nomaxion does not sell or share personal information as those terms are defined under the CCPA/CPRA, we do not use sensitive personal information to infer characteristics about you, and we do not engage in cross-context behavioural advertising — so there is no "sale" or "sharing" to opt out of. We will not discriminate or retaliate against you for exercising your privacy rights.
How to exercise these rights. Contact us using the details in the "Contact us" section below. We will verify your identity before responding and will generally respond within the timeframe required by the applicable law (for California, within 45 days, with one permitted extension where reasonably necessary). You may use an authorized agent to submit a request on your behalf where the law allows, and you may have the right to appeal our decision or to contact your state's attorney general or privacy regulator if you are not satisfied with our response.
14.Mobile app & device permissions
When you install the Platform as a mobile app or use it in your browser, it may request device permissions such as location, camera, microphone, and notifications. These permissions are used only for the features described in this Policy — for example attaching a location or photo to a record, capturing a voice note, or delivering an alert. You can grant or revoke each permission through your device or browser settings at any time. Where the Platform is distributed through an app store, the app store's own data-collection and privacy disclosures also apply to your download and use of the app.
15.Children
The Platform is intended for use by qualified workers and authorized representatives and is not directed to individuals under the age of majority. We do not knowingly collect personal information from children.
16.Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be communicated through the Platform or by email. The "Effective" date above reflects the current version. Your continued use of the Platform after a change takes effect constitutes acceptance of the updated Policy.
17.Contact us & how to complain
Questions, access or correction requests, or privacy complaints can be directed to Nomaxion Inc.'s designated Privacy Officer at [email protected]. Our Privacy Officer is responsible for our compliance with applicable privacy law. We will acknowledge and work in good faith to resolve your concern.
If you are not satisfied with our response, you may contact the Office of the Privacy Commissioner of Canada (priv.gc.ca); in Alberta, the Office of the Information and Privacy Commissioner of Alberta (oipc.ab.ca); or, in Quebec, the Commission d'accès à l'information (cai.gouv.qc.ca). Residents of other Canadian provinces or U.S. states may have the right to contact their local privacy authority or state attorney general.