PRIVACY POLICY
FutureVault Privacy Policy
(Effective July 20, 2026)
At a glance
- FutureVault is a secure digital vault for your documents. You control your documents and who you share them with.
- We do not sell your personal information, and we do not use your documents to train AI models.
- We collect only what we need to run the Service, keep it secure, and delete it when it is no longer needed.
- You have rights to access, correct, delete, and port your information. See “Your rights and choices.”
- Questions: privacy@futurevaultinc.com.
This summary is for convenience only and does not replace the full policy below.
1. Who we are and who is responsible for your information
FutureVault Inc. (“FutureVault,” “we,” “us”) provides a digital document vault delivered through our website, mobile application, and white-label platforms we operate for our business clients (each a “Client”). Together these are the “Service.”
Who is responsible for your personal information depends on how you use the Service:
- Where a Client provides the Service to you (white-label): the Client is generally responsible for your information (the “controller” / “person in charge”), and FutureVault acts as its service provider (“processor”). The Client’s own privacy policy governs, and you should direct rights requests to the Client. We will assist the Client in responding.
- Where you use FutureVault directly: FutureVault is responsible for your information and this policy governs.
This policy explains our practices in both roles.
2. Information we collect
- Account information: your name, email, and login credentials when you register.
- Your documents: the files and data you upload, store, and share (“Your Documents”). You decide what to add and who may access it.
- Contacts: the names and emails of people you choose to share with. You are responsible for having their consent before adding them. Because this information is collected indirectly (from you rather than from the contact), please ensure they are aware their details have been provided to us.
- Support and communications: information you provide when you contact us.
- Device and usage data: device and browser identifiers, IP address, operating system, access logs, and how you use the Service — used for security, performance, and administration.
- Cookies and similar technologies: strictly-necessary cookies to run the Service. Some strictly-necessary functions are provided by third-party services embedded in the Service for fraud and bot prevention and for customer support. These set cookies and receive limited device and technical data solely to perform those functions, and may process it outside Quebec and Canada. We do not use cookies for cross-site tracking or advertising.
3. How and why we use your information
We use personal information to provide and secure the Service, support you, run our business, and comply with law. Where the EU/UK GDPR applies, our legal bases are:
Purpose | Legal basis (GDPR) |
Provide, maintain, and secure the Service | Performance of a contract |
Protect against fraud, abuse, and security threats | Legitimate interests |
Comply with legal, regulatory, and audit obligations | Legal obligation |
Improve and develop the Service (aggregated/de-identified) | Legitimate interests |
We will not use your information for materially different purposes without notice or, where required, your consent.
For users in Canada, we collect, use, and disclose personal information with your consent, which may be express or implied depending on the sensitivity of the information and the purpose. You may withdraw consent at any time, subject to legal and contractual limits, and we will explain the consequences of doing so. Where we use technology that identifies, locates, or profiles you, we will inform you and, where required, obtain your consent.
4. How we share your information
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We disclose information only:
- To service providers (e.g., hosting, cloud) bound by contract to protect it and use it only to deliver the Service to us — they make no independent use of it.
- To comply with law or a valid legal request, or to investigate fraud, abuse, or violations of our terms.
- In a business transfer (merger, acquisition, or reorganization); affected users will be notified.
- With your direction — when you share Your Documents with Contacts, they can view, download, and (where permitted) modify what you share. Choose carefully.
5. Artificial intelligence and automated decisions
- No training on your content: we do not use Your Documents or personal information to train our own or third parties’ AI or machine-learning models, and any AI service providers are contractually prohibited from doing so.
- AI features: where the Service offers AI-assisted features (such as search, classification, or summarization), they operate only on your own content to serve you and are subject to the safeguards in this policy.
- Automated decisions: we do not make decisions that produce legal or similarly significant effects about you by automated means.
6. How long we keep your information
We keep personal information only as long as needed for the purposes above and to meet legal, regulatory, and audit obligations. Indicative periods:
Category | Retention |
Your Documents | Until you delete them or close your account. |
Account information | Life of the account, then 5 years for legal/audit. |
Support and access logs | Deleted within 60 days of account closure. |
After deletion, residual copies may persist briefly in secure backups. We may also de-identify or anonymize data; once anonymized it is no longer treated as personal information.
7. How we protect your information
We maintain physical, technical, and organizational safeguards designed to protect personal information, including encryption in transit and at rest, access controls, and multi-factor authentication. FutureVault is SOC 2 Type 2 audited and PCI-DSS compliant, and our security program is overseen by our Chief Information Security Officer. No method of transmission is perfectly secure, but we work continuously to protect your information and require comparable safeguards from our providers.
If a breach creates a real risk of significant harm, we will notify affected individuals and the appropriate regulators as required by law. Where we act as a processor for a Client, we notify the Client without undue delay, and the Client is responsible for notifying individuals and regulators.
8. Your rights and choices
Subject to applicable law and identity verification, you can access, correct, delete, and receive a portable copy of your personal information, withdraw consent and close your account. To make a request, contact privacy@futurevaultinc.com. We do not discriminate against you for exercising your rights.
If FutureVault provides your Service through a Client, please direct requests to that Client; we will support them in responding.
Canada (including Quebec)
You may access and correct your information and ask about its use and disclosure. Quebec residents also have rights to data portability and to information about automated decisions. You can send a notice to FutureVault’s privacy officer and, if unsatisfied, to the Office of the Privacy Commissioner of Canada or the Commission d’accès à l’information du Québec.
United States (California and other states)
If you are a resident of a U.S. state with a comprehensive privacy law — including California, Colorado, Connecticut, Texas, and Virginia, among others — you may have the right to access, correct, delete, and obtain a portable copy of your personal information, and to limit the use of sensitive personal information. We do not sell your personal information or share it for cross-context behavioral advertising. California residents may also designate an authorized agent to submit requests on their behalf. To exercise any of these rights, contact us with “State Privacy Rights” in the subject line. If we deny your request, you may appeal by contacting us at the same address, and we will respond within the time required by applicable law.
European Union and United Kingdom
Where the Service is provided to you through a Client, the Client is the controller of your personal information and FutureVault acts only as its processor. Your GDPR rights — access, rectification, erasure, restriction, objection, withdrawal of consent, and data portability — are exercised through the Client, whose privacy notice governs; please direct requests to the Client, and FutureVault will assist as required. You may also lodge a complaint with your local supervisory authority.
9. International data transfers
We are based in Canada and may process information in Canada and other countries where we or our providers operate. Where we transfer personal information across borders, we use appropriate safeguards — including European Commission Standard Contractual Clauses and the UK IDTA/Addendum where applicable — and, for Quebec data, we assess transfers before they occur. By using the Service you understand your information may be processed outside your jurisdiction.
10. Children’s privacy
The Service is for adults 18 and over. We do not knowingly collect information from anyone under 18. If you believe a child has provided us information, contact us and we will delete it.
11. Changes to this policy
We may update this policy from time to time. We will post the new version with an updated effective date. A summary of changes is kept below.
Version | Date | Summary |
2.0 | July 20, 2026 | Full modernization: data-role clarity, AI section, updated US/Quebec/EU-UK rights, retention schedule, breach commitment. |
1.0 | Jun 23, 2022 | Prior version. |
12. How to contact us
Privacy Officer, FutureVault Inc.
154 University Ave, Suite 601, Toronto, ON M5H 3Y9, Canada
privacy@futurevaultinc.com · 1-844-538-2858
