Privacy Policy

Last updated: February 23, 2026

1. Person Responsible for Personal Information Protection

Exoset Inc. ("Exoset", "we") is committed to protecting the personal information it collects and processes in the course of its activities. The person responsible for personal information protection can be reached at:

2. Personal Information Collected

We collect the following personal information, depending on your use of our services:

Contact Form

  • Full name
  • Professional email address
  • Company name (optional)
  • Phone number (optional)
  • Subject and message content

Client Portal

  • Email address
  • Authentication data (session token)
  • Account metadata (organization, role)

Automatically Collected Data (with your consent)

  • IP address
  • Browser type and operating system
  • Pages viewed and visit duration
  • Approximate geolocation data

3. Cookies Used

Our site uses the following cookies:

CookieTypeDurationPurpose
NEXT_LOCALEEssential1 yearRemember your language preference
Supabase cookiesEssentialSessionClient portal authentication
cookie_consentEssential1 yearRemember your cookie consent choice
Google Analytics cookiesAnalyticsUp to 2 yearsAnalyze site usage (loaded only with your consent)

Analytics cookies are only enabled if you click "Accept All". You can change your choice at any time via the "Cookie preferences" link at the bottom of the page.

4. Third-Party Processors

We use the following third-party processors for the operation of our services:

  • Google AnalyticsTraffic and visitor behavior analysis
  • Google reCAPTCHAProtection against automated submissions (contact form)
  • Google MapsDisplay of our office locations
  • ResendSending transactional emails (contact form, magic links)
  • SupabaseDatabase hosting and authentication
  • VercelWebsite hosting

5. Legal Bases for Processing

  • ConsentAnalytics cookies (Google Analytics) — enabled only after your explicit acceptance
  • Legitimate interestAbuse protection (Google reCAPTCHA), site security
  • Contractual necessityClient portal authentication, processing contact requests

6. Data Retention

  • Contact form: data is sent by email and is not stored in our database
  • Client portal accounts: retained as long as the account is active
  • Analytics data: per Google Analytics default settings (up to 26 months)
  • Consent cookies: 12 months

7. Your Rights

In accordance with Quebec's Law 25 and the General Data Protection Regulation (GDPR), you have the following rights:

  • Right to access your personal information
  • Right to rectification of inaccurate data
  • Right to erasure (right to be forgotten)
  • Right to data portability
  • Right to withdraw your consent at any time
  • Right to file a complaint with the Commission d'accès à l'information du Québec (CAI) or the Commission nationale de l'informatique et des libertés (CNIL) in France

To exercise your rights, please write to us at info@exoset.com

8. International Transfers

Some of our third-party processors (Google, Vercel, Supabase, Resend) may process your data in the United States. These transfers are governed by standard contractual clauses and appropriate security measures in accordance with the requirements of Law 25 and the GDPR.

9. Security Measures

We implement appropriate technical and organizational security measures to protect your personal information, including encrypted communications (HTTPS/TLS), rate limiting, data validation, and access control.

10. Changes

We may modify this policy at any time. The last updated date at the top of this page will be updated accordingly. We encourage you to review this page regularly.