Privacy Policy
THE SHORT VERSION
- Tacillon records who did a procedure, what they confirmed, and when. It stores the display name you choose for a worker, the steps they confirm, the time and method of each confirmation, and any video or photo the guide's author recorded. That is personal information about the worker.
- Your employer, not Sequonyx, decides why Tacillon is used and who uses it. Questions about your own information go to your employer first; we help them answer within ten business days.
- The data is stored in the United States by named hosting providers listed below, and is protected there by contract and by technical controls.
- We never sell it, never advertise with it, and never use it to train AI. We keep anonymous statistics about how the app is used, built from structure and counts, never from video, audio, text or names.
- Voice callouts: when you speak a confirmation, your browser's speech service (Google, on Chrome) turns the audio into text. We receive the text, never the audio.
- No advertising cookies, no trackers. The app keeps your sign-in and an offline copy of your guides on your device so it works without reception.
This summary is a courtesy. The numbered sections below are the policy.
1. Who this policy covers and who is responsible
1.1 This policy describes how Sequonyx Inc. ("Sequonyx", "we") handles personal information in the Tacillon service (the "Service"). It is written for three kinds of people:
- Account holders: the person at an organisation (the "Enterprise") who creates and manages the Enterprise account.
- Workers: people who run or author procedures under a profile on a device signed into an Enterprise account. They are the Enterprise's employees or contractors, not our customers.
- Readers: members of the public who open a published Product User Guide and may register a warranty or acknowledge a safety protocol.
1.2 Roles under Canadian privacy law. The Enterprise decides what the Service is used for, which workers use it, and what the guides contain. It is accountable to its workers and readers for those decisions under the privacy and employment law that applies to it. Sequonyx processes the information on the Enterprise's behalf and instructions, and is independently accountable under the Personal Information Protection and Electronic Documents Act (Canada) ("PIPEDA") for safeguarding it while it is in our systems and for the information we collect about account holders directly.
1.3 We are based in Ontario, Canada. Ontario has no general private-sector privacy statute, so PIPEDA is the law that governs our handling of personal information. Where an Enterprise or a worker is in Quebec, Alberta or British Columbia, that province's private-sector privacy law also applies to the Enterprise's handling, and we support the Enterprise in meeting it.
2. What personal information the Service handles
| Information | About whom | Where it comes from | Why it exists |
|---|---|---|---|
| Email address and password (hashed), or Google account identity | Account holder | Typed at sign-up, or supplied by Google if you choose Google sign-in | To create and secure the Enterprise login and to send confirmation and password-reset messages |
| Enterprise name | The organisation | Typed at sign-up or renamed later | To label the account and its records |
| Worker display name (a profile) | Worker | Typed by the Enterprise on the device | To record who performed a procedure in the audit record |
| Videos, photographs and any spoken narration in them | Whoever appears or speaks | Recorded by the Enterprise's author on a phone while building a guide, or as an equipment photograph | To show a worker exactly how a step is done; to help identify equipment by sight |
| Audit record: each step presented and confirmed, the method (tap or voice), the time, gate results, pauses, aborts and their reasons, the guide and version used, the device app version | Worker | Generated by the app as a procedure is run | To give the Enterprise a sequence-locked record of what was confirmed, when, and by whom |
| Voice callout text | Worker | Produced by the browser's speech-recognition service from the worker's spoken words (see section 5) | To confirm a step by voice instead of touch |
| Reader email address, and for a worker-reader the employer's name; the exact protocol text agreed to; date; app version | Reader | Typed by the reader on a published Product User Guide | To record a warranty activation or safety acknowledgement for the manufacturer that published the guide |
| Terms acceptance record: version, date, account email, method, document fingerprint | Account holder | Generated when the account holder agrees to the Terms | To prove which terms the Enterprise agreed to |
| Technical logs: IP address, browser type, request times | Anyone using the Service | Recorded automatically by our hosting providers | Security, abuse prevention and diagnosing faults; kept by the providers for their standard periods |
2.1 What we do not collect. The Service has no advertising, no analytics trackers, and no third-party cookies. It does not collect precise location, contacts, or anything from the device beyond what the features above require. The camera and microphone are used only when a worker or author actively starts a recording, a QR scan or a voice callout.
2.2 What the Enterprise should not put in. The Terms ask Enterprises not to enter health information, government identifiers, financial information, or personal information beyond a display name and, for readers, an email address. If you see such information in a guide, tell your Enterprise.
3. Why we use personal information, and on what basis
3.1 We use personal information only to provide, secure, support and improve the Service as described in the table above, to keep the records the Enterprise has asked the Service to keep, to communicate with account holders about the Service, and to comply with law.
3.2 Consent. Under PIPEDA we rely on consent. Account holders consent when they agree to the Terms and this policy. Workers' and readers' information is collected by the Enterprise for its own purposes; the Enterprise is responsible for informing them, and the Terms require it to do so before a worker first uses the Service or appears in a recording. Readers consent when they submit a registration; the screen tells them what is recorded and why.
3.3 What we will never do. We do not sell personal information. We do not use it for advertising or profiling. We do not use any customer content, or any personal information in it, to train, fine-tune or evaluate artificial-intelligence or machine-learning models, ours or anyone else's. See section 6 of the Terms of Service for the anonymous statistics we do keep, and section 7 for how any future research use would require a separate agreement and express consent.
4. Where the information is stored, and who can reach it
4.1 Location. The Service's database, authentication system and media storage are hosted in the United States (Amazon Web Services region us-east-1, Northern Virginia). Information stored there is subject to United States law, including lawful access by United States authorities, while it is there. We chose this provider for its security model and are transparent about the location so that Enterprises can make their own decision; an Enterprise may ask us about Canadian hosting before its pilot begins.
4.2 Our providers. These organisations process information for us, only on our instructions and under their published data-protection terms. We do not use any others.
| Provider | What it does for the Service | Where | What it sees |
|---|---|---|---|
| Supabase, Inc. | Database, sign-in and password handling, private video and photo storage | United States (AWS us-east-1) | All stored customer content and account data |
| Cloudflare, Inc. | Serves the app's files to your browser and protects the site | Global edge network, incorporated in the United States | IP address and request logs; not the contents of your database or videos |
| Google LLC | (a) Google sign-in, if the account holder chooses it. (b) Speech recognition for voice callouts, performed by the Chrome browser's built-in service | United States and global | (a) Account holder's Google identity. (b) The audio of a voice callout, sent by the browser directly to Google and converted to text; we receive only the text and never store the audio |
| Email delivery (Web Hosting Canada, or Resend, Inc.) | Sends account-confirmation and password-reset messages | Canada (Web Hosting Canada) or United States (Resend) | The account holder's email address and the message |
4.3 Who inside Sequonyx can reach it. Access to production systems is limited to the people who operate the Service. We do not open an Enterprise's guides, videos or records except to give support the Enterprise has asked for, to investigate a security incident or a suspected breach of the Terms, or when the law requires it, and we tell the Enterprise when we have done so unless the law forbids it.
4.4 Other Enterprises cannot see your data. Every record is tied to one Enterprise account and the database enforces that boundary on every request. A published Product User Guide is the one deliberate exception: the Enterprise chooses to make that guide readable by anyone with its link.
4.5 Legal demands. If we receive a demand from a court or authority for an Enterprise's information, we will tell the Enterprise before complying unless the law forbids it, and we will disclose only what the demand requires.
5. Voice, video and the device
5.1 Voice callouts use the speech-recognition service built into the browser. On Chrome, that service is operated by Google and the audio is sent to Google to be converted to text, under Google's own privacy terms. The Service receives the text, checks it against the required phrase, and records the result and the text. We never receive or store the audio. A worker who prefers not to use voice can confirm every step by touch instead.
5.2 Video and photographs are recorded only when a guide's author starts a recording. They are stored privately, and can be viewed only by devices signed into the Enterprise account, or by anyone with the link if they are part of a published Product User Guide. People who appear in a recording should be told and should agree before it is made; the Terms make this the Enterprise's responsibility.
5.3 On the device. The app keeps the sign-in token, a copy of the Enterprise's guides and equipment list, the recently used profile, and the device's own copy of the audit record in the browser's local storage so the app works without reception. Signing out clears the cached guides and profiles. The device's audit record is kept until the Enterprise clears it from the Audit Trail screen or clears the site's data; the server archive is unaffected by either.
6. How long we keep it
| Information | Kept for |
|---|---|
| Account, enterprise, profiles, guides, equipment, media | The life of the Enterprise account, then deleted within 30 days after the 60-day export window described in the Terms, and from backups as they rotate (currently within a further 30 days) |
| Audit archive | The same as above. The archive is append-only while the account exists; individual entries are never edited or removed |
| Reader registrations | The same as above; the Enterprise may export them at any time |
| Terms acceptance records | The life of the account plus seven years, as evidence of the agreement |
| Provider technical logs | The provider's standard period, typically 7 to 30 days |
7. How we protect it
Information travels encrypted between your device and our providers. The database enforces, on every query, that an account can read and write only its own Enterprise's rows. Videos and photographs are stored in a private bucket and are reachable only through short-lived signed links or the published-guide exception. The audit archive is append-only and each entry carries a digital fingerprint of the one before it, so tampering is detectable. Safety-critical behaviour of the app is checked by an automated self-test before each release. No system is perfectly secure; if we learn of unauthorised access to personal information we will notify the affected Enterprise within 72 hours of confirming it, and the Enterprise will notify affected individuals and regulators as the law requires, with our help.
8. Anonymous statistics (Performance Data)
We keep aggregated and anonymized statistics about how the Service is used, called Performance Data in the Terms of Service. They are built only from the structure of use (counts, durations, sequences, outcomes, and categories from a fixed list) and never from video, audio, images, text, names, identifiers or the name of any Enterprise or site. We apply the standard set by the Office of the Privacy Commissioner of Canada for information "made anonymous", including aggregation thresholds and suppression of rare values, and we will never attempt to re-identify anyone from them. Because they are anonymous, they are not personal information; we describe them here so that nothing about the Service is hidden. Section 6 of the Terms of Service is the full description.
9. Your rights and how to use them
9.1 Workers: you have the right to know what information about you your employer holds in the Service, to see it, and to have it corrected if it is wrong. Ask your employer; the Terms oblige the Enterprise to answer and oblige us to help within ten business days. If you contact us directly we will point you to your Enterprise unless the law requires us to act ourselves. Note that the audit record cannot be edited; a correction is recorded as a new entry alongside the original.
9.2 Account holders: you may see, correct or delete the information about you and your Enterprise at any time, export your Enterprise's data, and close the account, by contacting us (section 12).
9.3 Readers: your registration belongs to the manufacturer that published the guide. Contact them to see or correct it; we will help them do so.
9.4 Withdrawing consent. A worker may withdraw consent to further recording by telling their employer; the Enterprise can stop using their profile at any time. Records already made remain part of the Enterprise's audit archive.
9.5 Complaints. If you are not satisfied with how we have handled your information, you may complain to the Office of the Privacy Commissioner of Canada. Residents of Quebec may also contact the Commission d'accès à l'information du Québec. We would welcome the chance to resolve the matter first.
10. Children
The Service is a workplace tool and is not directed at anyone under 16. Enterprises must not create profiles for, or record, anyone below the legal working age in their jurisdiction without the consents that jurisdiction requires.
11. Changes to this policy
When we change this policy we publish a new version with a new date, and the app asks the account holder to read and agree to it before continuing past sign-in. Enterprises are expected to pass material changes on to their workers. Earlier versions are available on request.
12. Contact
Sequonyx Inc., Ontario, Canada.
Privacy contact: sequonyx@proton.me, subject line "Privacy".
We acknowledge every privacy request within five business days.
Pilot-stage document
This policy was prepared by Sequonyx for its pilot program and has not yet been reviewed by Ontario legal counsel. It will be reviewed before the Service is offered commercially. If anything in it is unclear, ask us.