Privacy Policy
Last updated: 2026-09-07
1. Introduction
Domly, operated by BAKA Real Estate, Inc ("Domly," "we," "us," or "our"), respects your privacy and is committed to protecting your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our platform, website, and related services (the "Service").
This policy is designed to comply with the Personal Information Protection and Electronic Documents Act (PIPEDA), Quebec's Act respecting the protection of personal information in the private sector (Law 25), and other applicable Canadian federal and provincial privacy legislation.
2. Information We Collect
a. Information You Provide
Account data: name, email address, phone number, and password when you register with an email address. If you register using Sign in with Google, we receive your name, email address, Google account identifier and language preference from Google instead of a password — see section 4 below. Billing data: payment method and billing address, processed securely via Stripe (we do not store credit card numbers). Tenant data you upload: tenant names, phone numbers, and property assignments. Knowledge Base content: building rules, bylaws, FAQ entries, and uploaded documents (PDF, Word, text). Support requests: information you provide when contacting our team.
b. Information Collected Automatically
SMS message content: the full text of messages exchanged between tenants and the AI Agent, including metadata (timestamps, phone numbers, delivery status). Tenant-submitted media: photos sent by tenants via SMS for maintenance assessment, stored securely on Cloudflare R2. Device and usage data: browser type, IP address, operating system, pages visited, and feature usage. Server logs: requests to our servers and edge functions, which may include identifiers such as email, phone, or tenant IDs.
c. Information Generated by Our Service
AI-generated responses and conversation summaries. Maintenance triage assessments and priority classifications. Photo analysis results (e.g., identification of water damage, mold, or broken fixtures). Message categorization data (category, priority, confidence scores).
3. How We Use Your Information
We process data for the following purposes: to provide the Service (managing tenant communications, generating AI responses, delivering notifications); to contact tenants on your behalf (sending maintenance updates, responding to inquiries, and providing troubleshooting guidance via SMS — subject to consent); to manage billing and subscriptions (processing payments, tracking usage, enforcing free-tier limits); to improve our Service (troubleshooting, analytics, AI model performance monitoring — we do not use your data to train AI models); to comply with legal obligations (tax, regulatory, CASL compliance, fraud prevention); and for security purposes (detecting abuse, preventing unauthorized access).
4. Sign in with Google and Google User Data
Domly offers Sign in with Google as an optional alternative to an email-and-password account. This section describes exactly what Google user data we access, how we use it, who it is shared with, how it is protected, and how long we keep it. If you never use the Google button, none of this applies to you.
What we access
We request only the openid, email and profile scopes. From the identity token Google returns, we read and store four values: your Google account identifier (the stable "sub" claim), your email address, your name, and your locale (used only to decide whether to show you the product in English or French). We do not request or store your Google profile photo, your contacts, your calendar, your files, or any other Google service data. We never receive your Google password, and we are never given access to your Google account itself.
How we use it
Solely to create and operate your Domly account: to sign you in, to recognise you on return visits, to link a Google sign-in to an existing Domly account when the email address matches and Google confirms it is verified, to address you by name in the product, and to set your initial language. We use the Google account identifier rather than your email address as the link to your account so that your account keeps working if your Google email address later changes.
Who it is shared with
Your Google account identifier is never shared with anyone. It is stored only in our own database (see the sub-processor table in section 7). Your name and email address are shared only in the limited circumstances that apply to every account regardless of how it was created: with Stripe if and when you subscribe to a paid plan, in order to create a billing customer record. Your Google account identifier and email address are never sent to our AI provider. Your name may appear in messages Lucie sends on your behalf — for example when introducing herself to a contractor as your assistant — because that is the service you asked her to perform. We do not sell your information, and we do not disclose it to data brokers or any other third party.
What we will never do with it
We do not use Google user data for targeted or personalised advertising. We do not sell it or transfer it to data brokers, information resellers, or advertising networks. We do not use it to train, fine-tune, or improve any artificial-intelligence or machine-learning model, whether our own or a third party's. Domly uses AI to help answer your tenants' messages, and no data obtained through Sign in with Google is ever part of that processing. We do not use it for any purpose other than providing and improving the Domly features you signed up for, or where required by law.
Domly's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
How it is protected
Google identity tokens are verified against Google's published signing keys over TLS and are discarded immediately after verification — we never store them. The four values we keep are held under the same controls described in section 9: encrypted in transit (TLS 1.2+) and at rest, behind role-based access controls and row-level security.
How long we keep it, and how to remove it
For as long as your account is active, and then on the schedule in section 8: deleted from our active systems 30 days after you close your account, with encrypted backups purged within 90 days. You can revoke Domly's access at any time from your Google Account under Security → Your connections to third-party apps and services; doing so stops future Google sign-ins but does not by itself delete your Domly account. To delete the account and the data with it, contact our Privacy Officer using the details in section 15.
5. AI Data Processing
Domly uses Anthropic's Claude AI to power its conversational AI Agent. When a tenant sends an SMS, the message content, relevant Knowledge Base entries, and conversation history are sent to Anthropic's API for processing. Anthropic processes this data solely to generate a response and does not use it to train its models.
Photo analysis: when tenants send images, these are transmitted to Anthropic's Claude Vision API for analysis (identifying maintenance issues such as water damage, mold, broken fixtures, or pest signs). Images are not retained by Anthropic after processing.
We do not sell or license any personal data to AI providers. Data sent to Anthropic is governed by our Data Processing Agreement with them and is subject to their enterprise data handling commitments.
6. Legal Basis for Processing (PIPEDA)
Under PIPEDA, we rely on the following bases for processing personal information: consent — we obtain meaningful consent before collecting, using, or disclosing personal information (for SMS communications, this is obtained through an explicit opt-in process); contractual necessity — processing is necessary to provide the Service you have requested; legitimate interest — we may process data for security, fraud prevention, and service improvement where this does not override your privacy rights; and legal obligation — we process data as required by Canadian law, including tax and anti-spam regulations.
7. Data Sharing & Sub-Processors
We share personal information only with the sub-processors necessary to deliver the Service. Each sub-processor is bound by data processing agreements that require them to protect your data. We do not sell, rent, or share tenant phone numbers or personal data with third parties for their own marketing purposes.
| Provider | Purpose | Data Location |
|---|---|---|
| Anthropic | AI processing — message classification, response generation, photo analysis, conversation summaries | United States |
| Twilio | SMS delivery, phone number provisioning, message routing | United States / Canada |
| Stripe | Payment processing, subscription management, invoicing | United States |
| Cloudflare | Website hosting (Cloudflare Pages), media storage (R2), edge computing | Global CDN (nearest edge) |
| PostgreSQL (Neon / Supabase) | Primary data storage — accounts, tenants, messages, knowledge base | Canada / United States |
We may also disclose information where required by law, court order, or government request; to protect the rights, safety, or property of Domly, our users, or others; or in connection with a merger, acquisition, or sale of assets (with notice to affected users).
8. Data Retention
Account data is retained for as long as your account is active. Tenant data is retained until you delete it or close your account. SMS messages, conversation logs, and media are retained for up to 24 months, unless you delete them sooner. Billing records are retained as required by Canadian tax law (generally 6 years).
Upon account closure, we retain your data for 30 days to allow for reactivation, after which it is permanently deleted from our active systems. Encrypted backups may persist for up to 90 days before automatic purge.
9. Data Security
We implement appropriate technical and organizational measures to protect your personal information, including: encryption of data in transit (TLS 1.2+) and at rest; role-based access controls and row-level security in our database; secure token storage for authentication; regular security monitoring and logging; and sub-processor security assessments. No system is 100% secure. In the event of a data breach that poses a real risk of significant harm, we will notify affected users and the Office of the Privacy Commissioner of Canada as required by PIPEDA's breach notification provisions.
10. Your Rights Under PIPEDA
As a Canadian resident, you have the right to: access the personal information we hold about you; correct any inaccurate or incomplete information; withdraw consent for data processing (for SMS messages, reply STOP at any time); request deletion of your personal information, subject to legal retention requirements; and file a complaint with the Office of the Privacy Commissioner of Canada if you believe your privacy rights have been violated.
To exercise any of these rights, contact us at admin@bakaventures.com. We will respond within 30 days as required by PIPEDA. If you have uploaded third-party data (e.g., tenant information), you are responsible for honouring their privacy rights requests. Domly will assist where possible.
11. Cookies & Analytics
Our website uses strictly necessary cookies to maintain your session and language preference. Our public marketing pages — the landing page, blog, and legal pages — also load three third-party measurement and advertising tools: Google Analytics (aggregate traffic and usage measurement), Google Ads conversion tracking, and the Meta (Facebook) pixel. These are advertising and analytics technologies: they set cookies, and they allow Google and Meta to measure the performance of our advertising and, in Meta's case, to build advertising audiences. They are loaded on our own marketing pages only, and never inside the signed-in application. No data obtained through Sign in with Google is passed to any of them. You can block these through your browser's cookie and tracking settings, through an ad blocker, or via Google's and Meta's own advertising controls.
12. Children's Privacy
Our Service is designed for landlords and property managers and is not directed to individuals under 18 years of age. We do not knowingly collect personal information from children. If we become aware that data has been provided about a minor without proper authority, we will delete it promptly.
13. International Data Transfers
Some of our sub-processors are located in the United States. When personal information is transferred outside Canada, we ensure comparable protection through contractual safeguards (Data Processing Agreements) with each sub-processor. By using the Service, you acknowledge that some data processing may occur outside Canada, subject to these protections.
14. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated by email or in-app notification at least 30 days before they take effect. The "Last updated" date at the top of this page reflects the most recent revision. Continued use after updates indicates acceptance.
15. Contact & Privacy Officer
If you have questions about this Privacy Policy or wish to exercise your privacy rights, contact our designated Privacy Officer at: BAKA Real Estate, Inc, Canada. Email: admin@bakaventures.com
You may also file a complaint with the Office of the Privacy Commissioner of Canada at www.priv.gc.ca or, for Quebec residents, the Commission d'accès à l'information du Québec at www.cai.gouv.qc.ca.