Nitide / Privacy

Privacy policy

What Nitide does with personal information, in plain terms. Our pages set no cookies until you open the booking window (only our host may set one, for security) and the site has no forms. When you write to us, we keep only what we need to answer you.

Version of September 22, 2026

This is an English translation of the French version, which is the original. If the two differ, you may rely on whichever version is more favourable to you.

Who is responsible

Nitide is a business based in Montreal, Quebec. The person in charge of the protection of personal information is Matteo Jam, Nitide's founder. Write to him with any question, access request or complaint.

Matteo Jam, person in charge of the protection of personal information
Nitide, Montreal, Quebec
contact@nitide.ca

This page also describes our internal rules: who has access to personal information, how long we keep it, how we destroy it and how we handle a complaint. Matteo Jam has approved them.

When you visit the site

The site has no forms, no accounts, no ads and no social media buttons, and our pages set no cookies until you open the booking window (see "Booking a call"). Three things still happen during a visit.

Preferences kept in your browser

The site remembers a few display settings in your browser's storage: the language you picked on a demo product page, the colour theme if you chose one, and the fact that you have already seen the opening animation during this visit. This data stays on your device. It is never sent to us and is not used to recognize you. To erase it, clear this site's data in your browser settings.

Hosting

The site is hosted by Cloudflare. Like any host, Cloudflare receives your IP address and the technical details of each request (the page requested, your browser, the time). It needs them to send you the page and to protect the site against attacks. We do not use this data to find out who you are.

If Cloudflare needs to check that a visit is not coming from a bot, it may set a security cookie. Cloudflare describes it as strictly necessary and says it does not track users from site to site or from session to session.

Audience measurement

If we measure the site's audience, we do it without cookies and in totals only. The tool we plan to use is Cloudflare Web Analytics. It stores nothing in your browser and reads no cookies or stored data from it. It sends the page viewed, the referring site and technical measurements of how the page loads (timings, memory used). According to Cloudflare, your IP address is discarded at the nearest data centre and is not kept in its core databases or logs. We see totals: page views, countries, device types, browsers, the sites visits come from. We never see one person's path through the site.

The site uses no technology that can identify you, locate you or build a profile of you. If we ever added one, it would be turned off by default and this page would explain how to turn it on.

Scanning a demo QR code simply opens a page on this site. We collect nothing more than for any other page.

When you write to us

To reach us, you write to contact@nitide.ca. We then receive your email address, your name if it appears, and whatever you choose to tell us: your business, your products, your questions.

We use it to answer you, set up a call and, if you ask, prepare a proposal. By writing to us, you consent to that use. For anything else, we ask you first. You can withdraw your consent at any time by writing to us; we then stop using your information, except what the law requires us to keep.

Today, only Matteo Jam has access to this mailbox. If anyone else ever does, this policy will say so.

If we write to you first

Sometimes we write to a brand that does not know us yet. We only do so at a business address the company published itself, on its website for example, with no statement refusing commercial messages, and about a subject related to its business. That is what Canada's Anti-Spam Legislation allows.

Every message says who we are, how to reach us and how to stop receiving our messages. If you ask us to stop, we stop, no later than the 10 business days the law allows. We then keep your address on a do-not-contact list so we do not write to you again by mistake.

For this outreach we keep only business contact information (the company's name, the person's name and role, their work address and phone number) and the history of our exchanges. We have no newsletter. If we start one, it will go only to people who sign up for it.

If you become a client

To do the work, we keep the contact details of the people we work with and what we need for invoicing. We also handle your product data (ingredients, sizes, GTINs): it describes your products, not people.

If we need to pass personal information to a third party to carry out the engagement, for example to GS1 Canada for your ECCnet records, your contract says so.

Our providers, and what leaves Quebec

ProviderWhat it does for usWhere the data is
Cloudflare (a US company)Hosts the site, routes email sent to contact@nitide.ca to our mailbox, and measures audience without cookies if we turn it on.Global network. Cloudflare says it stores its data mainly in the United States and the European Economic Area.
Google (Gmail)Hosts the mailbox that receives your email.Servers in several countries. Data may be processed outside Canada.
Cal.com (a US company)Runs the booking window, once you click "Book 15 minutes". It then receives your name, email, the slot you pick, your timezone and any notes you add.Servers in the United States.

Your information may therefore be processed outside Quebec, including in the United States, where other laws apply. Before entrusting personal information to a provider outside Quebec, Quebec law requires us to assess whether it will be adequately protected there and to sign a written agreement. We do this for every provider on this list, and we update the list when we add one.

We do not sell, rent or trade any personal information.

How long we keep it

After that, we destroy the information securely, or we make it anonymous.

How we protect it

We collect little, one person has access, and our accounts are protected by two-factor authentication. The site is served over an encrypted connection (HTTPS).

If a confidentiality incident happens (unauthorized access, use or disclosure, or a loss), we take steps to reduce the risk. If it presents a risk of serious injury, we promptly notify the Commission d'accès à l'information du Québec and the people concerned. Every incident is recorded in a register.

Your rights

To exercise a right, write to contact@nitide.ca. We may ask you to confirm your identity so that we do not hand your information to someone else. We answer in writing within 30 days of receiving your request.

If you are not satisfied

Start by writing to Matteo Jam at contact@nitide.ca and explain what happened. We acknowledge receipt, look into it and answer in writing within 30 days.

You can also turn to the Commission d'accès à l'information du Québec (page in French). It receives complaints about a business's practices. If we refuse an access or correction request, or do not answer in time, you can file an application for the examination of a disagreement within 30 days of the refusal or of the end of the response period.

If you are outside Quebec, or if your information crossed a provincial or national border, the federal law (PIPEDA) may also apply. You can then turn to the Office of the Privacy Commissioner of Canada.

Booking a call

The "Book 15 minutes" buttons open Cal.com, a US booking tool. Nothing from Cal.com loads before your click: until you click, Cal.com sets no cookies and receives no data. When you book, Cal.com collects your name, email, the slot, your timezone and any notes you add, hosts all of it in the United States, and sets its own cookies to run its window. We receive the booking in our Google calendar and keep it for as long as the file is open, then three years. The call happens on Google Meet, or by phone if you prefer. You can also simply write to contact@nitide.ca and skip Cal.com.

If this policy changes

We publish the new version on this page, with its date. If a change affects how we use information you have already given us, we also tell you directly.

The rules for using the site are in our terms of use.

References

  1. Act respecting the protection of personal information in the private sector, CQLR, c. P-39.1, in particular ss. 1, 3.1, 3.2, 3.5, 3.8, 8, 8.1, 8.2, 8.3, 17, 22, 23, 27, 28, 30, 32, 33, 42 and 43. LégisQuébec, up to date as of June 10, 2026, consulted September 22, 2026.
  2. Rédiger une politique de confidentialité : guide explicatif pour les entreprises (in French), Commission d'accès à l'information, December 2023.
  3. Responsabilité des entreprises (in French), Commission d'accès à l'information, consulted September 22, 2026.
  4. Entrée en vigueur des dispositions sur la portabilité (in French), Commission d'accès à l'information, September 22, 2024.
  5. Vos recours (in French), Commission d'accès à l'information, consulted September 22, 2026.
  6. PIPEDA requirements in brief, Office of the Privacy Commissioner of Canada, modified May 1, 2024. See also the Personal Information Protection and Electronic Documents Act, S.C. 2000, c. 5, current to July 21, 2026.
  7. Canada's Anti-Spam Legislation, S.C. 2010, c. 23, ss. 6, 10 and 11, current to July 21, 2026.
  8. RUM beacon for Web Analytics (collection, IP address, browser storage), Cloudflare, modified June 30, 2026, and Cloudflare Cookies, updated May 5, 2026.
  9. Cloudflare Privacy Policy, effective November 4, 2025.
  10. Google Privacy Policy, effective May 26, 2026.
  11. Charter of the French language, CQLR, c. C-11, s. 91 (differences between the French version and another version). LégisQuébec, up to date as of June 10, 2026, consulted September 22, 2026.