Legal
Privacy Policy
This policy explains how PrivateAccess collects, uses, protects and retains personal information.
1. Who is responsible
BQMP operates PrivateAccess from 330 Avro, Pointe-Claire, QC, H9R 5W5 CANADA and is responsible for the service’s personal-information practices.
2. Information collected
Account data includes your chosen username, recovery email, password hash, account status and security records. Where a sending allowance applies, PrivateAccess records a technical message identifier, reservation status and the number of successfully sent emails to enforce the account’s sending limit; this counter does not add a separate copy of the message content. Billing data includes Stripe customer, checkout and subscription identifiers; PrivateAccess does not need to store complete card details. Mail-service data may include message routing information, mailbox usage, login records and abuse signals. For protected external delivery, the destination address, sender, expiry and access records are stored with an encrypted payload containing the subject, message and attachments.
3. Why information is used
Information is used to register and secure accounts, verify ownership, process subscriptions, provision mailboxes, route mail, prevent abuse, provide support, comply with law and maintain service reliability.
4. Legal grounds
Processing is used to perform the service contract, comply with legal obligations, protect legitimate security and abuse-prevention interests, and act on consent where consent is required.
5. Service providers
PrivateAccess uses service providers for payment processing, hosting, email infrastructure, monitoring and customer support. Stripe processes payment information under its own privacy terms. Providers receive only the access needed for their role.
6. International transfers
Hosting and service providers may process information outside your province or country. PrivateAccess uses contractual, organizational and technical safeguards appropriate to the information and applicable law.
7. Retention
Mailbox content is retained while the account is active and is scheduled for deletion within 30 days after final account closure. Protected external messages expire after 30 days and may be revoked earlier by the sender. Backup copies may remain for up to 90 days. Billing, fraud-prevention and legal records may be retained for up to seven years where required.
8. Security
PrivateAccess uses password hashing, protected sessions, optional two-factor authentication, one-use tokens, access controls, audit records, encrypted transport, encrypted protected-message storage, backups and mail-security controls.
9. Your choices and rights
Subject to applicable law, you may request access, correction, export, restriction or deletion of personal information, withdraw consent where applicable, or complain to a privacy regulator. Requests must be verified to protect the account.
PA group rooms
PA and E65 group administrators can manage all group rooms, membership and reply settings, and read or delete room messages. PA stores group names, member identifiers, join times, administrator audit records and message read receipts. Added members see only messages sent after they join; removal revokes access immediately. Group administrators choose 24-hour, 3-day, 7-day or 30-day expiry for new messages. Group messages and files use the same server encryption, backup retention and download rules as PA Chat.
Chat email notifications
New unread direct and group chats generate a notification to the recipient’s verified contact email. The email contains no chat text, group name or attachments. Its link requires normal PA sign-in and current conversation access. Notification records store recipient and message identifiers, delivery state and a random link locator until the message expiry. Deleted, expired, opened or inaccessible messages are skipped before sending.
PA Chat — added 9 September 2026
PA Chat stores approved contact relationships, message sender and recipient identifiers, timestamps, expiry times, read receipts and recent chat presence. Message text, attachment names and files are encrypted on the PA server; this is not end-to-end encryption. Either participant can choose 24-hour or 30-day expiry for new messages. Expired content becomes inaccessible immediately and is removed by scheduled cleanup. Current encrypted PA backups may retain copies for up to 30 additional days. Device exports and downloaded files remain with their recipients. Blocking a contact removes the conversation from active chat storage.
10. Cookies
PrivateAccess uses an essential session cookie for authentication and security. It does not use advertising cookies. See the Cookie Policy for details.
11. Children
PrivateAccess accounts are available only to people who are at least 18 years old.
12. Contact and changes
Privacy questions and verified rights requests may be directed to privacy@privateaccess.space. Material policy changes will be dated and communicated through appropriate account channels.
