AINOW SolutionsAINOW
Legal

AINOW Mobile Privacy Policy

Effective date: September 1, 2026

This policy applies to the AINOW mobile application (“the App”) published by AINOW Solutions Inc. (“AINOW”, “we”). Our general privacy policy is at ainowsolutions.ca/privacy.

1. Who this policy is for

The App is a workplace tool. You use it with an account your organization (“your organization”) provides through Microsoft Entra ID — there are no personal sign-ups. Your organization holds the AINOW subscription, controls the environment (“tenant”) your data lives in, decides which business systems are connected to it, and administers your access. AINOW processes your data to operate that tenant on your organization’s behalf, under our agreement with them. For questions about how your organization uses AINOW, contact your administrator; for questions about this policy, contact us (section 11).

2. What the App collects

Account and identity. When you sign in, Microsoft Entra ID confirms who you are to us. We receive your organizational identifier (an opaque directory object ID), and your name and work email address from your Microsoft profile. We use the identifier to key your memberships, conversations, and preferences; we cache your display name to show it in the App. Your password is never seen, transmitted, or stored by the App — sign-in happens with Microsoft directly.

Content you create. Chat messages you type, and — during voice calls — what you say. Voice audio is streamed for real-time processing and is not recorded or stored; the call’s transcript is kept as ordinary conversation messages. Conversations, transcripts, and any drafts the assistant prepares are stored in your organization’s tenant.

Device push token. If you allow notifications, the App registers your device’s push token so your tenant can notify you when something needs your approval or a workflow finishes. This is optional: if you decline the notification permission, the App works fully without it. The token is deleted when you sign out and expires automatically after 90 days without use. Notifications themselves are deliberately content-free — they carry a short title and a link into the App, never the content of a record or conversation.

Service diagnostics. Like any networked application, requests to our service carry standard metadata (IP address, user agent, timing). We keep it in our service telemetry to operate, secure, and troubleshoot the platform. The App contains no advertising SDK, no third-party analytics SDK, and no tracking.

3. How your content is used

The assistant processes your messages and voice to answer you and to prepare draft actions. No change to a business system happens without your explicit approval in the App — drafts wait for you to approve or decline, and expire if you do neither. AI processing runs on Microsoft Azure (Azure OpenAI Service) under your organization’s tenant configuration; per Microsoft’s Azure OpenAI terms, your inputs are not used to train foundation models. We do not use your content for advertising, and we do not sell it.

4. Where data goes

  • Your organization’s tenant (Microsoft Azure, Canada Central region): conversations, transcripts, drafts, memberships, preferences, device registrations.
  • Systems your organization connected (for example, its own ServiceNow instance): only when you approve a draft action that writes to them, or when the assistant reads from them to answer you. These systems belong to your organization and are governed by its policies.
  • Notification delivery: push messages are delivered through Microsoft Azure Notification Hubs and Google Firebase Cloud Messaging (Android) or Apple Push Notification service (iOS). Because notifications are content-free by design, these carriers transport titles and links only.
  • We use no other third-party recipients, and we do not sell or rent personal information to anyone.

5. Retention and deletion

Your organization controls retention of tenant content (conversations, transcripts, drafts) and can administer or delete it through its AINOW environment. On your side: signing out deletes your device’s push registration; unused push registrations are pruned after 90 days; pending drafts expire automatically (typically within 24 hours). To request deletion of your content or account, contact your organization’s administrator, who can action it directly — or write to us at privacy@ainowsolutions.ca and we will action or redirect the request with your organization.

6. Security

Data in transit is encrypted (TLS). Tenant data is stored in Microsoft Azure (Canada Central) with per-organization isolation. Sign-in tokens are kept in the operating system’s secure storage on your device. The App’s human-approval design is itself a safeguard: the assistant cannot change your organization’s systems without your explicit, recorded approval.

7. Your rights

Depending on where you live (including under Canada’s PIPEDA and Quebec’s Law 25), you may have rights to access, correct, or delete personal information about you. Because your organization controls the tenant, the fastest path is your administrator; you can also contact us (section 11) and we will assist or redirect the request to your organization as required by our role as its service provider.

8. Children

The App is a workplace tool provisioned by organizations and is not directed to children.

9. International users

The service is hosted in Canada (Microsoft Azure, Canada Central). If you use the App from elsewhere, your data is processed in Canada under this policy and our agreement with your organization.

10. Changes to this policy

We will post updates at this address and update the effective date. Material changes will be communicated to your organization.

11. Contact

AINOW Solutions Inc.
3433 Sandpiper St, Colwood, BC V9C 0R5, Canada
privacy@ainowsolutions.ca