Privacy Policy

Pending legal review. This is default placeholder content. Sections covering AI-generated content and AI data processing have not yet been reviewed by a qualified legal professional. An administrator should replace this text with approved legal content before this page is made available to users in a live environment.

Last updated: May 15, 2026

1. Introduction

Cardwatch Licensing (2023) Limited ("Company", "we", "us", or "our"), located at 16610 Bayview Avenue Suite 209, Newmarket, Ontario L3X 3B1, is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our recipe management system ("the Service").

2. Information We Collect

We may collect the following types of information:

  • Account Information: Name, email address, username, organization name, and password when you register for an account.
  • Usage Data: Information about how you use the Service, including pages visited, features used, and actions taken.
  • Content Data: Recipes, ingredients, menus, production schedules, and other content you create within the Service.
  • Device Information: Browser type, operating system, IP address, and other technical information collected automatically.

3. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve the Service
  • Create and manage your account
  • Process and respond to your requests
  • Send you technical notices and support messages
  • Monitor and analyze usage trends to improve user experience
  • Detect, prevent, and address technical issues and security threats

4. AI Processing and Third-Party AI Services

The Service uses third-party artificial intelligence services to power certain features. When you use AI-assisted features, some of your data may be transmitted to these external services for processing:

  • Data sent to AI services may include recipe names and content, ingredient names and descriptions, nutritional data, menu planning inputs, conversational messages submitted to the dietary assistant, and images uploaded for OCR-based ingredient import.
  • AI providers used: We use Microsoft Azure OpenAI Service for recipe generation, nutritional analysis, menu cycle planning, and the conversational assistant, and Microsoft Azure Computer Vision for OCR-based ingredient import. Semantic search within the Service is powered by vector embeddings generated via Azure OpenAI Service.
  • Third-party data handling. Data transmitted to Microsoft Azure services is processed in accordance with Microsoft's Privacy Statement and the applicable Azure service terms. Cardwatch does not control how Microsoft processes data under its own policies.
  • Retention. Cardwatch does not store AI model inputs or outputs beyond what is necessary to deliver the Service (for example, saving a generated recipe you explicitly choose to keep). We do not use your data to train AI models.
  • Opting out. AI-assisted features are optional. You may choose not to use recipe generation, the conversational assistant, OCR import, or other AI-powered tools. Core Service functionality remains available without engaging these features.

5. HIPAA and US Healthcare Data (US Clients)

This section applies to clients located in the United States whose use of the Service may involve Protected Health Information ("PHI") as defined under HIPAA.

  • Business Associate obligations. When the Company processes PHI on behalf of a HIPAA Covered Entity (such as a hospital, nursing facility, or long-term care provider), the Company acts as a Business Associate. An executed Business Associate Agreement ("BAA") is required before any PHI is processed through the Service. Contact us to request a BAA prior to use.
  • What may constitute PHI. Depending on how you configure and use the Service, data such as resident dietary restrictions, allergen profiles, meal records, and POS-integrated resident information may constitute PHI when linked to an identifiable individual in a healthcare context. You are responsible for determining whether PHI is involved in your use of the Service.
  • Safeguards. The Company implements administrative, physical, and technical safeguards consistent with HIPAA Security Rule requirements for any PHI processed under an executed BAA. These include access controls, audit logging, encryption in transit, and personnel training.
  • Breach notification. In the event of a breach of unsecured PHI, the Company will notify affected Covered Entities in accordance with the HIPAA Breach Notification Rule and the terms of the applicable BAA.
  • Minimum necessary. The Company uses and discloses PHI only to the minimum extent necessary to fulfill its obligations under the BAA and to provide the Service.

6. Data Storage and Security

We implement appropriate technical and organizational security measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction. Your data is stored on secure servers and we use encryption for data in transit. However, no method of transmission over the Internet or electronic storage is 100% secure.

7. Data Sharing and Disclosure

We do not sell your personal information. We may share your information in the following circumstances:

  • With your consent or at your direction
  • With service providers who assist us in operating the Service
  • To comply with legal obligations or valid legal processes
  • To protect the rights, privacy, safety, or property of our users or the public
  • In connection with a merger, acquisition, or sale of assets

8. Data Retention

We retain your personal information for as long as your account is active or as needed to provide the Service. We may also retain and use your information to comply with legal obligations, resolve disputes, and enforce our agreements. You may request deletion of your account and associated data by contacting us.

9. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal information:

  • Access and receive a copy of your personal data
  • Correct inaccurate or incomplete personal data
  • Request deletion of your personal data
  • Object to or restrict processing of your personal data
  • Data portability
  • Withdraw consent at any time

10. US State Privacy Rights

If you are a resident of a US state with applicable privacy legislation, you have additional rights regarding your personal information. These rights currently apply to residents of California, Colorado, Connecticut, Virginia, Texas, Oregon, Montana, and other states that have enacted comprehensive consumer privacy laws.

California Residents (CCPA/CPRA)

Under the California Consumer Privacy Act ("CCPA") as amended by the California Privacy Rights Act ("CPRA"), California residents have the following rights:

  • Right to know. You may request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources from which it was collected, our business or commercial purpose for collecting it, and the categories of third parties with whom we share it.
  • Right to delete. You may request that we delete personal information we have collected about you, subject to certain exceptions permitted by law.
  • Right to correct. You may request that we correct inaccurate personal information we maintain about you.
  • Right to opt out of sale or sharing. We do not sell your personal information, nor do we share it for cross-context behavioral advertising purposes.
  • Right to limit use of sensitive personal information. To the extent we process sensitive personal information (such as health-related data), you have the right to limit our use to purposes permitted under the CPRA.
  • Right to non-discrimination. We will not discriminate against you for exercising any of your CCPA/CPRA rights.

Other US State Residents

Residents of other US states with applicable privacy laws have similar rights, including the right to access, correct, delete, and obtain a portable copy of your personal data, and the right to opt out of certain processing. The specific rights available to you depend on the laws of your state.

To exercise any of the above rights, please contact us using the details in Section 13. We will respond to verifiable requests within the timeframe required by applicable law (typically 45 days, with a possible extension of an additional 45 days where reasonably necessary).

11. Cookies and Tracking

We use cookies and similar tracking technologies to maintain your session, remember your preferences, and improve the Service. You can control cookie settings through your browser preferences, though disabling cookies may affect the functionality of the Service.

12. Children's Privacy

The Service is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child, we will take steps to delete that information.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date. Your continued use of the Service after any changes constitutes your acceptance of the updated policy.

14. Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us at:

Cardwatch Licensing (2023) Limited
16610 Bayview Avenue Suite 209
Newmarket, Ontario L3X 3B1
Canada