Privacy Policy
Last updated: March 15, 2026
Your privacy is important to us. This policy explains how InvestAssist collects, uses, and protects your personal information.
1. Introduction
InvestAssist ("we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our investment deal management platform.
By using InvestAssist, you consent to the data practices described in this policy. If you do not agree with the terms of this Privacy Policy, please do not access or use the Service.
This policy applies to:
• The InvestAssist web application at investassist.ai
• Our mobile applications (when available)
• All related services and communications
2. Information We Collect
INFORMATION YOU PROVIDE:
• Account Information: Name, email address, phone number, company name, job title
• Profile Information: Photo, biography, professional credentials
• Financial Information: Payment card details (processed by our payment provider)
• Deal Information: Property details, financial models, investor data, documents
• Communications: Messages, emails, support requests, and feedback
AUTOMATICALLY COLLECTED INFORMATION:
• Device Information: IP address, browser type, operating system, device identifiers
• Usage Data: Pages visited, features used, time spent, clicks, navigation patterns
• Location Data: General geographic location based on IP address
• Cookies: Session cookies, preference cookies, and analytics cookies
INFORMATION FROM THIRD PARTIES:
• Authentication providers (Google, Microsoft) when you use social sign-in
• Integrated services (CRM, property management systems) when you connect them
• Market data providers for deal analysis features
3. How We Use Your Information
We use collected information for the following purposes:
SERVICE DELIVERY:
• Provide, maintain, and improve the Service
• Process transactions and manage your account
• Enable deal management, collaboration, and investor communications
• Generate AI-powered analysis and insights
COMMUNICATIONS:
• Send service-related notifications and updates
• Respond to your inquiries and support requests
• Send marketing communications (with your consent)
ANALYTICS & IMPROVEMENT:
• Analyze usage patterns to improve user experience
• Develop new features and services
• Conduct research and analysis
SECURITY & COMPLIANCE:
• Detect and prevent fraud, abuse, and security incidents
• Comply with legal obligations and enforce our terms
• Protect the rights and safety of our users
4. How We Share Your Information
We do NOT sell your personal information. We may share your information in the following circumstances:
WITH YOUR CONSENT:
• When you invite team members or investors to access your deals
• When you connect third-party integrations
• When you explicitly authorize sharing
SERVICE PROVIDERS:
• Cloud hosting providers (AWS, Vercel)
• Payment processors (Stripe)
• Analytics providers (with anonymized data)
• Customer support tools
BUSINESS PURPOSES:
• To comply with legal obligations, subpoenas, or court orders
• To protect our rights, privacy, safety, or property
• In connection with a merger, acquisition, or sale of assets
• To enforce our terms and policies
AGGREGATED DATA:
• We may share aggregated, de-identified data for research, industry analysis, or marketing purposes. This data cannot be used to identify you.
5. Data Security
We implement robust security measures to protect your information:
ENCRYPTION:
• Data in transit: TLS 1.3 encryption for all communications
• Data at rest: AES-256 encryption for stored data
• Database encryption for sensitive fields
ACCESS CONTROLS:
• Role-based access control (RBAC)
• Multi-factor authentication available
• Regular access reviews and audit logs
INFRASTRUCTURE:
• SOC 2 Type II certified infrastructure
• Regular security assessments and penetration testing
• Automated threat detection and monitoring
• Secure backup and disaster recovery procedures
INCIDENT RESPONSE:
• Dedicated security team for incident response
• Breach notification within 72 hours as required by law
• Post-incident analysis and remediation
While we strive to protect your information, no method of transmission or storage is 100% secure. We cannot guarantee absolute security.
6. Data Retention
We retain your information for as long as necessary to provide the Service and fulfill the purposes outlined in this policy:
ACTIVE ACCOUNTS:
• Account information: Retained while your account is active
• Deal data: Retained until you delete the deal or close your account
• Usage logs: Retained for 12 months
DELETED CONTENT:
• Deleted items: Moved to trash for 30 days, then permanently deleted
• Closed accounts: Data retained for 90 days, then permanently deleted
• Backups: May contain deleted data for up to 30 additional days
LEGAL REQUIREMENTS:
• Financial records: Retained for 7 years for tax/audit purposes
• Legal holds: Data may be retained longer if required by law
You may request deletion of your data at any time through your account settings or by contacting privacy@investassist.ai.
7. Your Privacy Rights
Depending on your location, you may have the following rights regarding your personal information:
ACCESS: Request a copy of the personal information we hold about you.
CORRECTION: Request correction of inaccurate or incomplete information.
DELETION: Request deletion of your personal information, subject to legal retention requirements.
PORTABILITY: Request your data in a portable, machine-readable format.
OBJECTION: Object to certain processing activities, including marketing.
RESTRICTION: Request limitation of how we process your data.
WITHDRAWAL: Withdraw consent for processing based on consent.
To exercise these rights, contact privacy@investassist.ai or use the tools in your account settings. We will respond to requests within 30 days.
FOR CALIFORNIA RESIDENTS (CCPA):
• You have the right to know what personal information is collected
• You have the right to request deletion of your information
• You have the right to opt-out of the sale of personal information (we do not sell data)
• You have the right to non-discrimination for exercising your rights
8. Cookies and Tracking
We use cookies and similar technologies to enhance your experience:
ESSENTIAL COOKIES:
• Authentication and session management
• Security features
• Core functionality
PREFERENCE COOKIES:
• Remember your settings and preferences
• Language and display preferences
ANALYTICS COOKIES:
• Understand how users interact with the Service
• Identify areas for improvement
• Track feature adoption
MANAGING COOKIES:
• Most browsers allow you to control cookies through settings
• Disabling essential cookies may prevent you from using certain features
• We honor Do Not Track (DNT) browser signals
THIRD-PARTY TRACKING:
• We use analytics services that may set their own cookies
• We do not allow third-party advertising cookies
9. International Data Transfers
InvestAssist is based in Ontario, Canada. Your information may be transferred to and processed in countries other than your own.
DATA TRANSFERS:
• We use cloud infrastructure in North America
• Some service providers may process data in other regions
• We ensure appropriate safeguards are in place for transfers
SAFEGUARDS:
• Standard Contractual Clauses (SCCs) for transfers outside Canada
• Data Processing Agreements with all processors
• Compliance with applicable data protection laws
FOR EU/EEA USERS:
• We comply with GDPR requirements
• EU-based users can exercise rights under GDPR
• Contact our Data Protection Officer at dpo@investassist.ai
FOR CANADIAN USERS:
• We comply with PIPEDA and applicable provincial laws
• You have rights under Canadian privacy legislation
10. Children's Privacy
InvestAssist is not intended for use by children under 18 years of age. We do not knowingly collect personal information from children.
If you are a parent or guardian and believe your child has provided us with personal information, please contact us at privacy@investassist.ai. If we discover that we have collected personal information from a child without verification of parental consent, we will take steps to delete that information.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.
NOTIFICATION:
• Material changes will be communicated via email or prominent notice in the Service
• The "Last Updated" date will be revised
• Continued use after changes constitutes acceptance
REVIEW:
• We encourage you to review this policy periodically
• Historical versions are available upon request
12. Contact Us
If you have questions or concerns about this Privacy Policy or our data practices, please contact us:
EMAIL: privacy@investassist.ai
PHONE: +1-647-999-5515
MAIL:
InvestAssist
Attn: Privacy Team
325 Front Street West, Suite 400
Toronto, ON M5V 2Y1
Canada
DATA PROTECTION OFFICER:
For GDPR-related inquiries: dpo@investassist.ai
We will respond to your inquiry within 30 days.
