Privacy Policy
Upside Financial Technologies Inc. ("Upside," "we," "us," or "our") provides Upside PR, a client portal through which businesses submit draft press releases and receive analysis, comments, and rewritten drafts (the "Service"). This Privacy Policy explains how we collect, use, disclose, and protect personal information in connection with the Service and its associated websites.
Upside is a Canadian company and complies with applicable Canadian privacy legislation, including the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy laws.
A note on scope. Most of what customers submit to the Service is corporate business information (draft press releases, corporate history, market data context), not personal information. Corporate content is protected as confidential information, and frequently as material non-public information, under the Upside PR Terms of Service and the Upside PR Data Handling and Security Policy (the "Data Policy"), which govern its handling, security, retention, and deletion. This Privacy Policy governs personal information: information about identifiable individuals, such as the account holders and authorized users who operate customer accounts, and individuals named in customer materials.
1. Information We Collect
1.1 Information you provide.
- Account and contact information: name, business email address, phone number, title, and company affiliation of account holders and authorized users.
- Onboarding information: company profile details (ticker, exchange, projects) and the names and roles of the individuals who will use the account.
- Billing information: billing contact details and payment card information. Card details are collected and processed by our third-party payment processor; Upside does not store full card numbers.
- Customer content: materials submitted to the Service may incidentally contain personal information, such as the names, titles, and quotes of executives appearing in draft or historical press releases. We process this information as part of the customer's content, on the customer's instructions, and protect it under the Data Policy.
- Communications: records of correspondence, support requests, and feedback.
1.2 Information collected automatically.
- Device and log information: IP address, browser type, operating system, and access timestamps.
- Usage data: pages visited, features used, and job metadata (mode, timing, status). Application logs are designed not to contain draft text or other customer content, as described in the Data Policy.
- Cookies: we use cookies necessary for authentication, session management, and security, and limited first-party analytics cookies on our public marketing pages. We do not run third-party advertising or tracking cookies inside the portal, and screens displaying draft content carry no third-party telemetry. You can control cookies through your browser settings, but the portal requires functional cookies to operate.
2. How We Use Personal Information
We use personal information to:
- provide, operate, secure, and support the Service, including authentication, tenant isolation, and audit logging;
- set up and administer customer accounts and process payments;
- communicate with users about the Service, including service and security notices;
- monitor, analyze, and improve the Service (using aggregated or de-identified data wherever practicable);
- send marketing communications, where permitted and subject to your right to opt out at any time;
- detect, investigate, and prevent fraud, abuse, and security incidents; and
- comply with legal and regulatory obligations.
We do not use customer content, or personal information contained in it, to train or fine-tune machine learning models, and we contractually prohibit our service providers from doing so. We do not sell personal information.
3. How We Share Personal Information
3.1 Service providers (subprocessors). We share information with service providers who help us deliver the Service, under contracts that restrict their use of the information to providing services to us and require appropriate safeguards. Our core providers are:
- Cloud hosting and model infrastructure: Amazon Web Services, including AWS Bedrock, on which model inference runs inside Upside's own AWS environment under zero-data-retention controls (no request or response data is retained by the provider or shared with the model developer), as described in the Data Policy;
- Payment processing: our payment processor, which handles card data under its own PCI-DSS compliant systems and privacy policy;
- Business operations tools: email, support, and document services used to run our business.
The Data Policy contains the current subprocessor list and our mechanism for notifying customers of changes.
3.2 Legal requirements. We may disclose information where required by law, court order, or a regulator with jurisdiction, or where we believe in good faith that disclosure is necessary to protect our rights or the safety of any person. Where legally permitted, we will notify the affected customer before disclosing its information.
3.3 Business transactions. If Upside is involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction, subject to confidentiality protections. We will notify affected customers of any change in ownership or control of their personal information.
3.4 With consent. We may share information for other purposes with your consent.
4. International Transfers
Upside is based in Canada. Portions of the Service, including cloud hosting and model inference, are performed on infrastructure located in the United States. Information processed there is subject to the safeguards described in the Data Policy (including encryption in transit and at rest and zero-data-retention model processing) but may be subject to access by courts, law enforcement, and national security authorities under the laws of that jurisdiction. By using the Service, customers and their users acknowledge this processing.
5. Security
We protect personal information using the administrative, technical, and physical safeguards described in the Data Policy, including TLS 1.2 or higher for data in transit, AES-256 encryption at rest, multi-factor authentication for production access, least-privilege access controls, tenant isolation, and audit logging. No method of transmission or storage is completely secure, and we cannot guarantee absolute security; our responsibility for security incidents is as set out in the Terms of Service and the Data Policy.
6. Retention
We retain personal information only as long as necessary for the purposes described in this Policy or as required by law. Account and billing records are retained for the duration of the customer relationship and for the minimum periods required by tax and commercial law (typically seven years for financial records). Customer content follows the shorter, purpose-built retention and purge schedule in the Data Policy, including default purge of draft materials after the related release becomes public, on-demand deletion, and deletion within 90 days of offboarding.
7. Your Rights
Subject to applicable law, individuals may:
- request access to the personal information we hold about them;
- request correction of inaccurate or incomplete information;
- withdraw consent to processing, subject to legal and contractual restrictions (withdrawing consent required for the Service may prevent us from providing it);
- request deletion of personal information, subject to our legal retention obligations; and
- complain to the Office of the Privacy Commissioner of Canada or the applicable provincial commissioner.
To exercise these rights, contact us at hello@upsidepr.ai. We may need to verify your identity before acting on a request. Where the information at issue is contained in a customer's content, we may refer the request to that customer, who controls that content.
8. Third-Party Sites
Our websites may link to third-party sites. We are not responsible for their privacy practices, and this Policy does not apply to them.
9. Children
The Service is for businesses and their authorized representatives. It is not directed to individuals under 18, and we do not knowingly collect personal information from children.
10. Changes to This Policy
We may update this Policy from time to time. We will post the updated version with a revised date and, for material changes, notify customers through the portal or by email. Continued use of the Service after the effective date constitutes acceptance.
11. Contact
Questions, requests, or complaints about privacy: hello@upsidepr.ai, attention Privacy Officer, Upside Financial Technologies Inc., Toronto, Ontario.