Privacy

Privacy Policy

How GreenHat Security Inc. collects, uses, protects, and retains personal information across our website and SR&D Claim OS.

Effective

Who we are and what this policy covers

GreenHat Security Inc. is a cybersecurity company based in Vancouver, British Columbia, Canada. This policy explains how we handle personal information through the GreenHat Security website, our contact and support channels, and the SR&D Claim OS service.

It does not replace the privacy terms of a third-party service that you choose to connect or visit. Those services have their own privacy practices.

Information we collect

The information we handle depends on how you use our website and services:

  • Contact and support information: your name, email, organization, inquiry topic, message, and related correspondence.
  • Access and account information: your verified work email, authentication context, assigned role, and access activity. For protected services, Cloudflare Access uses Google Workspace sign-in to verify that an email is authorized.
  • Claim and project information: projects, experiments, dates, narratives, evidence files, review states, and other records you add to SR&D Claim OS.
  • Optional AI document-processing information: when an organization administrator enables AI processing and the separate document-content setting, extracted document text and task instructions are sent through OpenRouter to the model provider selected by that administrator. When this option is off, the service uses local OCR and deterministic rules instead.
  • Authorized QuickBooks information: supported accounting records from a company you choose to connect, currently Bills (Bill), Purchases (Purchase), Vendor Credits (VendorCredit), Journal Entries (JournalEntry), and optional Time Activities (TimeActivity). These records may include dates, amounts, descriptions, and names associated with a transaction. GreenHat receives OAuth authorization tokens for the connection, not your QuickBooks password.
  • Integration and audit information: the connected QuickBooks company identifier, connection and synchronization timestamps, audit events, error details, and encrypted OAuth tokens used to maintain the authorized connection.
  • Technical and analytics information: IP address, browser and device information, requested pages, referral information, interaction events, and cookie or similar identifiers collected through our services and, when you accept optional analytics, our analytics tools.

How we use information

We use information only for purposes connected to operating our business and services, including to:

  • respond to inquiries, provide support, and communicate about a requested service;
  • authenticate authorized users and apply role-based access controls;
  • provide, secure, troubleshoot, and maintain the website and SR&D Claim OS;
  • retrieve and synchronize accounting records that an authorized user requests;
  • when enabled by an organization administrator, classify documents and extract proposed fields using the configured AI provider for human review;
  • maintain audit history, investigate errors, and prevent misuse or security incidents;
  • understand aggregate website use and improve site performance and navigation; and
  • meet legal, regulatory, contractual, and recordkeeping obligations.

We do not use an authorized QuickBooks connection to change source accounting records. The current integration is read-only.

Service providers and disclosures

We use service providers to operate and secure our services. Depending on the feature, these providers include Cloudflare for hosting and access security; Google for Workspace authentication and Google Analytics 4; Microsoft Clarity for website interaction analytics; Resend for contact-form email delivery; Intuit for an authorized QuickBooks Online connection; and, only when optional AI document processing is enabled, OpenRouter and the model provider selected through it.

We may also disclose information when reasonably necessary to comply with law, respond to valid legal process, protect users or our services, investigate misuse, or complete a business transaction subject to appropriate safeguards. We do not disclose more information than is reasonably necessary for the relevant purpose.

Analytics, consent, and your choices

Google Analytics 4 and Microsoft Clarity help us understand how visitors use the public website. These optional tools do not load unless you select “Accept optional analytics” in our on-site preference control. If you decline, the website's core features continue to work without those analytics tools. We store your choice in your browser and you can change it at any time through “Analytics choices” in the site footer.

You choose whether to submit a contact form, upload claim evidence, or authorize a QuickBooks connection. An organization administrator controls whether AI processing is enabled and whether extracted document text may be sent to the configured provider. An authorized user can disconnect QuickBooks to stop future synchronization. Where consent is the basis for optional processing, you may withdraw it subject to legal, contractual, security, and recordkeeping requirements.

Retention and deletion

We keep personal information only as long as reasonably necessary for the purposes described in this policy, to provide an active service, maintain appropriate audit and security records, resolve disputes, and meet legal or contractual obligations. Retention varies with the record type and context.

Disconnecting QuickBooks clears the stored OAuth tokens and stops future synchronization. It does not automatically delete accounting records already synchronized into SR&D Claim OS or associated audit history. Those records are handled separately under applicable legal, contractual, security, and recordkeeping requirements. You may ask us to assess a deletion request through the process below.

Safeguards and processing locations

We use administrative, technical, and organizational safeguards appropriate to the sensitivity of the information. These include authenticated access, role-based authorization, encryption for stored OAuth tokens, access logging, and service monitoring. No system or transmission method can be guaranteed completely secure.

GreenHat is based in Canada, but we and our service providers may process information in Canada, the United States, or other locations where they operate. Information processed outside Canada, or outside your province or country, may be subject to the laws of that jurisdiction.

Access, correction, deletion, and questions

You may ask to access or correct personal information we hold about you, request deletion where applicable, withdraw consent to optional processing, or raise a concern about our handling of personal information. We may need to verify your identity and authority before acting on a request, and legal exceptions may apply.

GreenHat Security Inc. has designated a Privacy Officer. Contact the Privacy Officer at anthony@greenhatsec.com, through our support page or the contact form. Please do not send passwords, OAuth tokens, or unnecessary financial information through the public form.

If we do not resolve a privacy concern, you may contact the Office of the Information and Privacy Commissioner for British Columbia or the Office of the Privacy Commissioner of Canada, as appropriate to the matter.

Changes to this policy

We may update this policy as our services or legal obligations change. We will post the updated version on this page and revise the effective date. Material changes may also be communicated through the relevant service when appropriate.

Have a privacy question or request?

Contact our Privacy Officer through the support path. We will verify the request and explain any legal or operational limits that apply.