This policy explains what personal information The Defense Brief (“we”, “us”) collects, why, who receives it, how long we keep it, and the choices and rights you have. It applies to our website, applications, email and services.
1. Who Is Responsible
The Defense Brief, Toronto, Ontario, Canada, is responsible for the personal information described here. Our privacy contact can be reached at info@defensebrief.ca (subject line “Privacy”).
2. What We Collect
- Account information: your email address, sign-in identifiers, verification status and role.
- Membership and payments: your plan, subscription status, the version of the Membership Agreement you accepted and when, and Stripe customer and subscription identifiers. Card details are collected by Stripe, not by us.
- Settings and saved work: email preferences, watchlists, followed programmes and companies, saved searches and views, company profiles, bid workspaces, certification registrations, research partner lists and preparation tasks.
- Questions you ask our AI tools: the text you enter in the Market Assistant or Scenario tool, the countries, keywords, sectors and tickers you choose for My Brief, and the answers generated.
- Screening searches: the names and notes you enter in restricted-party screening.
- DB Wire purchases: the licences you buy, the licence version accepted, and payment references.
- Pilot requests: the organization, name, email, role, country, team size and scope you give us, and the IP address, browser type and referring page sent with the form.
- Site analytics: pages viewed, referring site, device and browser type, approximate country (derived from your IP address, which is not stored), and a random visitor identifier held in a cookie.
- Messages you send us: the content of emails and requests.
3. Why We Use It
- to provide the Service, including accounts, membership, saved work, alerts and briefs you ask for;
- to take payment, keep financial records and send the notices a purchase requires;
- to generate AI-assisted answers and briefings you request;
- to answer enquiries and pilot requests;
- to understand how the site is used in aggregate and improve it;
- to show ads to non-members on a few pages, only if you accept advertising cookies;
- to secure the Service, prevent abuse, and meet legal obligations.
We do not sell personal information. We do not use your data to train AI models. Topics you follow — including sensitive subjects — are treated as coverage preferences only; we do not infer anything about your identity, beliefs or characteristics from them.
4. Consent and Your Choices
We ask for your express consent where it matters most: to receive optional email, and before any advertising cookies are set. Other uses described in this policy are those a reasonable person would expect when using the Service, and you can withdraw consent to optional uses at any time:
- Email: every optional email has an unsubscribe link, and you can switch each kind off in your account settings. Unsubscribing takes effect immediately. Account, billing and security notices are still sent.
- Advertising cookies: off unless you accept them. Change your choice any time from Cookie settings at the bottom of every page.
- Site analytics: on by default; switch it off in Cookie settings. We also treat a browser’s Global Privacy Control or Do Not Track signal as switching it off.
Withdrawing consent may mean a feature that depends on it (for example, emailed alerts) stops working.
5. Who Receives Personal Information
We share personal information only with service providers who process it for us under contract, and as the law requires. Current providers:
- Supabase — sign-in, database and file storage.
- Stripe — payments and billing records.
- Resend — email delivery, with SendGrid or our mail host used only if Resend is unavailable.
- OpenAI — generating AI-assisted answers, summaries and briefings. We send the text needed for the request. Under OpenAI’s API terms this data is not used to train its models, and OpenAI may keep it for up to 30 days for abuse monitoring.
- Google AdSense — ads for non-members on a few pages, only after you accept advertising cookies.
- Google Fonts, jsDelivr and unpkg — deliver fonts and code libraries; your browser’s IP address and page address reach them when a page loads.
- Our hosting provider — runs the servers the Service operates on.
If you are a member of an organization that uses The Defense Brief, the organization’s administrators can manage your membership of it, and the organization’s weekly brief is built from the items its members follow. You can opt out of receiving that brief in your account settings.
We may disclose information where required by law, to protect the rights and safety of others, or as part of a sale or reorganization of our business, subject to this policy.
6. Where Information Is Processed
Our service providers may store or process personal information outside Canada, including in the United States. Information held in another country is subject to that country’s laws and may be accessible to its authorities. We require providers to protect it in line with this policy.
7. Cookies and Similar Technologies
- Sign-in and security (necessary): stored in your browser so you stay signed in.
- Preferences (necessary): language and theme, stored in your browser.
- db_consent (necessary): remembers your cookie choices, 395 days.
- db_vid (analytics): random visitor identifier, 395 days. db_sid (analytics): session identifier, 30 minutes of inactivity. Not set if you switch analytics off.
- Google AdSense (advertising): set by Google only after you accept advertising cookies.
- Stripe (necessary for payment): set on the payment page.
8. How Long We Keep It
- Account information and saved work: while your account is open.
- Site analytics: 395 days.
- IP address, browser and referrer sent with a pilot request: 90 days. Pilot request details: 2 years, unless they become a customer relationship.
- Market Assistant questions and answers: 365 days.
- Screening searches: 2 years.
- My Brief runs and PDFs: 365 days.
- Payment, purchase and licence records: as long as tax and contract law require (generally at least six years).
- Email unsubscribe records: kept so we do not email you again.
- Records of privacy requests: 3 years after completion.
9. Accessing, Correcting and Deleting Your Information
You can download a copy of your data and close your account at any time from your account settings. Closing your account deletes your saved work and settings and removes your sign-in; we keep only the records described in section 8 that the law or our contracts require, with your email address removed from your account record.
You may also ask us for access to, or correction of, the personal information we hold about you by writing to info@defensebrief.ca. We may need to confirm your identity. We will respond within thirty (30) days. If we need more time, we will tell you within those thirty days why and when to expect a response, which will be no more than thirty (30) further days. Requests are free.
10. Security and Breaches
We protect personal information with measures appropriate to its sensitivity, including encryption in transit, access controls and limiting access to those who need it. No system is perfectly secure. If a breach of our safeguards creates a real risk of significant harm to you, we will notify you and the Office of the Privacy Commissioner of Canada as soon as feasible, and we keep a record of every breach.
11. Children
The Service is not intended for anyone under 18, and we do not knowingly collect their personal information.
12. Changes to This Policy
We will post changes here with a new date. If a change significantly affects how we use information we already hold, we will tell you by email and ask for consent where required.
13. Questions and Complaints
Contact info@defensebrief.ca. If you are not satisfied with our response, you may complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca).