Privacy Policy — DREAM
Department Resource & Equipment Asset Management
Contact: admin@egregius.tech
1. Introduction
Egregius Digital ("we", "us", or "our") operates DREAM (Department Resource & Equipment Asset Management), a software platform that helps organizations manage assets, equipment, assignments, inventory records, and lifecycle planning.
We respect privacy and are committed to handling personal information in accordance with applicable Canadian privacy laws, including the federal Personal Information Protection and Electronic Documents Act (PIPEDA) and Alberta's Personal Information Protection Act (PIPA), as applicable to the personal information we handle.
This Privacy Policy explains how information is collected, used, disclosed, stored, and protected when DREAM websites or services are used.
2. Scope
This Privacy Policy applies to:
- Public Website Visitors: Visitors to public-facing DREAM pages such as marketing, pricing, or support pages.
- Account Users: Administrators, Editors, Viewers, and other authorized users of the DREAM platform.
- Customer Data: Information entered into DREAM by customer organizations relating to employees, departments, locations, assets, and operational records.
3. Role of Customer Organizations
DREAM is business software used by organizations. Customer organizations determine what information they upload to the platform and are responsible for ensuring they have lawful authority to collect, use, and provide that information to DREAM. Customer organizations are also responsible for managing user accounts within their organization, including assigning appropriate permissions and promptly disabling access for users who no longer require it.
Egregius Digital provides and operates the software platform and processes information as necessary to deliver, secure, maintain, and support the service.
4. Information We Collect
A. Account Information
We may collect:
- Email address
- User role and access permissions
- Organization name
- Authentication identifiers provided through Firebase Authentication
- Login timestamps
- Technical telemetry related to security, fraud prevention, and service reliability
Users who sign in using Google OAuth may provide their Google account email address and a unique authentication identifier.
B. Employee / Workforce Information Entered by Customers
Customer organizations may store:
- First and last name
- Employee ID or badge number
- Work email address
- Work telephone number
- Department or cost centre
- Employment status (active / inactive)
We do not request or require highly sensitive employee information such as Social Insurance Numbers, dates of birth, home addresses, or personal banking information.
C. Asset and Operational Information
Customer organizations may store:
- Asset categories, descriptions, makes and models
- Serial numbers or internal asset tags
- Purchase prices and estimated replacement values
- Assignment history to employees or locations
- Lifecycle planning data
- Audit logs of changes and assignments
D. Uploaded Content
Organizations may upload branding images such as organization logos.
E. Website Analytics
DREAM may use cookies or similar technologies on public-facing marketing pages, including Google Analytics 4, to understand website traffic and improve our website. These technologies are not intentionally deployed inside authenticated customer dashboard areas.
5. How We Use Information
We may use information to:
- Provide and operate DREAM
- Authenticate users and manage permissions
- Maintain subscriptions and account access
- Enable asset management, assignment tracking, forecasting, and reporting
- Facilitate audits or verification of assigned assets
- Improve functionality and user experience
- Detect abuse, fraud, or unauthorized access
- Maintain audit trails and system integrity
- Respond to support requests
- Comply with legal obligations
We do not sell personal information.
6. Payments
DREAM uses Paddle as its payment processor and Merchant of Record. We do not collect, process, or store payment card numbers or billing addresses on our own systems.
Payment transactions are handled directly by Paddle under Paddle's own terms and privacy practices. We may retain limited subscription metadata such as plan type, status, expiry dates, and anonymous subscription identifiers.
7. Hosting and International Processing
DREAM uses Google Firebase and Google Cloud services.
Primary application data is hosted in Canada in the Toronto region (northamerica-northeast2).
Some authentication or supporting service functions may be processed through systems located outside Canada, including the United States.
Where personal information is processed outside Canada, it may be accessible to courts, law enforcement, or government authorities in those jurisdictions under their laws. Questions about our use of service providers located outside Canada, including the purposes of that processing, may be directed to our Privacy Officer using the contact details below.
8. Disclosure to Third Parties
We may disclose limited information to service providers who help operate DREAM, including:
- Google Firebase / Google Cloud (Database and Hosting)
- Paddle (Merchant of Record and Subscription Management)
- Website analytics providers used on public pages
We require these service providers, by contract, to protect personal information to a standard comparable to that described in this Privacy Policy, and to use it only as needed to provide services to us.
We may also disclose information where required by law, court order, lawful authority, or where reasonably necessary to protect users, customers, or the public. We do not sell customer data to advertisers or data brokers.
9. Retention
We retain personal information only as long as reasonably necessary for the purposes described in this policy or as required by law.
When a customer organization's subscription ends, it may request an export of its data within 30 days. After that period, personal information is deleted, anonymized, or archived in accordance with our policies and applicable legal obligations, except where longer retention is required for legal, accounting, audit-integrity, or security reasons.
Customer organizations remain responsible for their own records-retention and destruction obligations under the laws that apply to them.
10. Security
We use reasonable administrative, technical, and organizational safeguards designed to protect information, including: encryption of data in transit and at rest, authentication controls, role-based access controls, logging and monitoring, and reputable cloud infrastructure providers.
No system can guarantee absolute security.
11. Breach Notification
If we determine that a privacy or security incident involving personal information creates a real risk of significant harm, we will take the steps required by applicable law. This may include notifying the appropriate privacy regulator — such as the Office of the Privacy Commissioner of Canada and/or the Office of the Information and Privacy Commissioner of Alberta — as well as affected organizations and individuals.
We maintain records of breaches of security safeguards as required by law.
12. Access and Correction Requests
Individuals may request access to or correction of personal information we control, subject to applicable law.
We will respond to access and correction requests within the time required by applicable law (generally within 30 days), at little or no cost to the individual. If we are unable to provide access, we will explain why, as permitted by law.
Where information was entered by a customer organization, requests may need to be directed first to that organization.
Requests may be sent to: admin@egregius.tech
13. Challenging Compliance & Complaints
We have policies and procedures to receive and respond to questions or complaints about our handling of personal information.
If you have a privacy concern, please contact our Privacy Officer at admin@egregius.tech
We will investigate and respond. If you are not satisfied with our response, you have the right to contact the relevant privacy regulator:
- Office of the Privacy Commissioner of Canada — priv.gc.ca
- Office of the Information and Privacy Commissioner of Alberta — oipc.ab.ca
14. Children
DREAM is a business-oriented platform and is not intended for children.
15. Changes to This Policy
We may update this Privacy Policy from time to time. Updated versions will be posted on the applicable DREAM website and the Effective Date will be revised.
When we make material changes, we may require you to review and accept the updated policy before you continue to use signed-in areas of the Service.
16. Contact
For privacy questions, access or correction requests, or complaints, you may contact our Privacy Officer:
Privacy Officer, Egregius Digital
Alberta, Canada
admin@egregius.tech