Subspace Logo
PlatformASTRIADocumentationPricingServices

Privacy Policy

Last updated: September 2026

This policy explains how Subspace Computing (“Subspace”, “we”, “our”) collects, uses, discloses, retains and protects personal information in connection with its websites, its console, its APIs, its SDKs, Astria, the Registry and its associated services (the “Services”).

It does not replace a data processing agreement entered into with a Customer. In the event of a conflict, that agreement prevails with respect to the information processed on behalf of that Customer.

1. Privacy officer

The person in charge of the protection of personal information at Subspace is:

Richard Beauregard

President and Privacy Officer

richard.beauregard@subspacecomputing.com

He receives questions, requests to exercise rights and complaints relating to privacy.

2. Respective roles of Subspace and its Customers

Subspace determines the purposes and means of the processing of information relating in particular to its visitors, prospects, account holders, authorized users, commercial communications, billing, security and operation of the platform. Subspace is responsible for that information in accordance with applicable laws.

Where a Customer transmits to Astria or to the other Services information concerning its own clients, employees, insureds, borrowers, users or other individuals, the Customer generally determines the purposes of that processing. In that context, Subspace processes the information on behalf of the Customer, following its instructions and the applicable agreement.

Individuals concerned by data submitted by a Customer should first address their request to that Customer. Subspace will provide the Customer with the assistance reasonably required under the law and the applicable agreement.

3. Information we may collect

Depending on your relationship with Subspace and your use of the Services, we may collect the following categories.

We limit collection to the information necessary for the purposes determined before collection. The fact that information may be useful does not necessarily mean that it is necessary; we avoid collecting information where a reasonably less intrusive solution can achieve the same purpose.

3.1 Account and contact information

  • last name, first name, title, organization and business contact information;
  • email address, language preferences and communication preferences;
  • account identifiers and information associated with authentication;
  • roles, permissions, team membership and account status.

3.2 Technical, usage and security information

  • IP address, device type, browser, operating system and technical identifiers;
  • dates, times, duration, frequency and features used;
  • identifiers and metadata associated with projects, models, versions, requests and API keys;
  • access, error, performance, security and abuse prevention logs;
  • information necessary to calculate quotas, usage and billing.

3.3 Content submitted to the Services

Depending on the features and the retention mode selected:

  • models, rules, formulas, parameters, assumptions and specifications;
  • input data, scenarios, files and instructions;
  • results, artifacts, validations and replay information;
  • data or personal information included by the Customer in those items.

The Customer controls the content it transmits and must avoid including unnecessary personal information.

3.4 Billing and transactions

  • billing name and contact information;
  • organization, address, tax number and transaction history;
  • payment status, plan, credits, consumption and transaction identifiers.

Full payment card data is normally collected and processed directly by our payment provider. Subspace should not receive a full card number in the normal course of the Services.

3.5 Communications and support

  • the content of emails, forms, demonstration requests and support tickets;
  • information provided during calls, demonstrations, surveys or commercial exchanges;
  • comments and preferences communicated voluntarily.

3.6 Website and cookies

  • pages visited, approximate origin, interactions, links viewed and usage events;
  • cookies necessary for operation, security and the retention of preferences;
  • non-essential cookies or analytics technologies, where permitted and after obtaining the required consent.

4. Means and sources of collection

We collect information:

  • directly from you when you create an account, contact us, purchase a service or submit content;
  • automatically when you visit the website or use the Services;
  • from your employer or the organization that gives you access;
  • from Customers that ask us to process data on their behalf;
  • from authentication, payment, hosting, analytics or integration providers;
  • from public sources or partners, where permitted by law.

5. Purposes of processing

We process information only to the extent necessary or permitted in order to:

  • create, administer and authenticate accounts;
  • provide, run, host, maintain and improve the Services;
  • receive, technically validate, execute and return the Customer’s requests;
  • manage models, versions, projects, permissions and environments;
  • measure usage, apply quotas and bill for the Services;
  • provide support and communicate about the Services;
  • monitor performance, diagnose errors and ensure continuity;
  • detect, prevent and investigate abuse, fraud, incidents and unauthorized access;
  • comply with legal, tax, accounting, contractual and regulatory obligations;
  • establish, exercise or defend our rights;
  • produce aggregated and lawfully anonymized technical statistics;
  • send commercial communications where permitted by law and honour unsubscribe choices.

We do not sell or rent personal information. We do not use content submitted by a Customer to train a general or shared artificial intelligence model without its express written authorization.

6. Consent and other authorizations

Where consent is required, we seek valid consent appropriate to the nature and sensitivity of the information. You may withdraw your consent, subject to legal and contractual restrictions and to a reasonable implementation period.

Withdrawal may prevent Subspace from providing a feature that requires the information concerned. Certain processing may also be permitted or required without consent by law, in particular to provide a requested service, prevent fraud, ensure security, comply with an obligation or defend a right.

7. Automated decisions

Subspace does not, for its own purposes, make any decision producing legal or otherwise significant effects with respect to an individual based solely on the content of a Customer Model.

A Customer may, however, use the Services to execute its own model or to support an automated decision. That Customer remains responsible for determining whether its use is permitted, for informing the individuals concerned, for providing them with the required information and review mechanisms and for ensuring appropriate oversight.

If Subspace implements, for its own purposes, a decision based exclusively on the automated processing of personal information, Subspace will provide the notices and information required by law.

8. Cookies, analytics and choices

We use strictly necessary cookies to operate and secure our websites and Services. They may, among other things, maintain a session, remember a preference or prevent abuse.

With the required consent, we may use Google Analytics or a comparable technology in order to understand use of the website. These tools may collect identifiers, device information, the IP address or an approximate location, and browsing events.

You may refuse non-essential cookies through the consent mechanism presented on the website and may later change your choice by deleting cookies in your browser settings. Refusing non-essential cookies does not prevent access to the main features; blocking necessary cookies may, however, prevent authentication or certain features.

9. Who has access to information at Subspace

Access is limited to the officers, employees and contractors who need it for their duties, in particular operations, security, support, billing, compliance and the authorized development of the Services. Access is subject to confidentiality obligations and to controls proportionate to the sensitivity of the information.

10. Disclosures to third parties

We may disclose the necessary information to the following categories of suppliers:

  • cloud hosting, storage, network and monitoring;
  • authentication and identity management;
  • payment, billing, accounting and fraud prevention;
  • messaging, support and communications;
  • analytics and usage measurement, subject to the required consents;
  • legal advisors, accountants, insurers and auditors;
  • integration partners authorized by the Customer.

An up-to-date list of the main categories of suppliers and, where required, of their names, may be requested from the person in charge of the protection of personal information.

We may also disclose information:

  • where required by law, by an order or by a competent authority;
  • to detect or prevent fraud, an incident or a threat;
  • to protect the rights, safety or property of Subspace, its users or the public;
  • in connection with a financing, due diligence, merger, reorganization, sale or business transfer, subject to appropriate safeguards.

Suppliers may use the information only for the authorized services and must protect it in accordance with their contractual and legal obligations.

11. Processing outside Quebec and outside Canada

Certain suppliers may process information in Canada, in the United States or in other jurisdictions. The laws and authorities of those jurisdictions may then apply.

Before disclosing personal information outside Quebec where the law requires it, Subspace conducts a privacy impact assessment, taking into account in particular the sensitivity of the information, the purposes, the contractual protections and the applicable legal regime. Subspace proceeds with the disclosure only if its assessment concludes that the information will receive adequate protection, and enters into an appropriate written agreement.

12. Execution processing and retention modes

The Customer’s configuration, its plan, its order form or a Specific Agreement determines the applicable mode.

Minimal mode

The content of the execution request, including the inputs and Results, is processed transiently in order to respond to the request and is not retained as a replayable record after processing. Subspace may retain the technical metadata strictly necessary for security, diagnostics, abuse prevention and billing, without retaining the business content of the execution.

A model saved voluntarily in the Registry or through a storage feature remains retained separately according to the Customer’s settings. If the Customer instead transmits the model with each request in Minimal mode, that transient copy is not retained after processing, subject to the temporary and security mechanisms described in the Documentation.

Metadata mode

Subspace retains selected execution metadata, such as the model and version identifier, the timestamp, the status, the duration, the volume and billing information. Unless otherwise configured, the business inputs and full Results are not retained as a replayable record.

Full mode

Subspace may retain the model, the inputs, the Results, the validations and the artifacts necessary for history, audit or replay, for the period configured or agreed with the Customer.

The Customer is responsible for selecting an appropriate mode, configuring the retention periods and informing the individuals concerned where required.

13. Retention periods

We retain information only for the period necessary for the purposes described, for the provision of the Services and for compliance with our legal obligations. The period may be extended where information is reasonably necessary for security, abuse prevention, billing, an audit, a dispute or the exercise of rights.

CategoryRetention criterion
Account, organization and permissionsFor the life of the account, then for the period reasonably necessary for its closure, for security and for the settlement of residual obligations
Technical metadata and security logsFor the period necessary for operations, diagnostics, security, abuse prevention and the establishment of rights
Execution contentAccording to the selected mode, the configuration and the Specific Agreement
Saved models and versionsUntil deleted by the Customer, the end of the applicable recovery period or the end of the account
Communications and supportFor the period necessary to handle the request and to retain a reasonable record of the exchanges
Billing, tax and transactionsFor at least six years or any other period required by law
Website analytics dataAccording to the period configured in the analytics tool and only for as long as they are necessary for the purposes described
Residual backupsUntil deleted or overwritten according to the normal backup cycle

Once the purpose has been achieved and no obligation requires retention, the information is securely destroyed or anonymized in accordance with the law for a serious and legitimate purpose.

14. Security

Subspace applies reasonable administrative, technical and organizational measures proportionate to the nature of the information, including access controls, separation of environments where appropriate, logging, secrets management, encryption mechanisms where appropriate and secure development and monitoring practices.

Where required by law, Subspace conducts a privacy impact assessment before a project to acquire, develop or overhaul an information system or an electronic service delivery involving personal information.

The privacy functions and settings offered to the public are configured by default at the highest level of privacy required by law.

No system can guarantee absolute security. The Customer remains responsible for the security of its devices, Customer Applications, credentials, API keys, configurations, backups and users.

15. Privacy incidents

Subspace maintains an incident management process. Where an incident involving personal information presents a risk of serious injury, Subspace will notify the Commission d’accès à l’information du Québec and the individuals concerned where the law requires it. Where Subspace processes information on behalf of a Customer, Subspace will notify that Customer in accordance with the applicable agreement and provide it with the reasonably necessary information.

Subspace maintains the register of incidents required by law.

16. Your rights and requests

Subject to the conditions and exceptions provided by law, you may request:

  • confirmation that Subspace holds information about you;
  • access to that information;
  • its rectification if it is inaccurate, incomplete or equivocal;
  • its deletion or the cessation of its dissemination in the cases provided for;
  • the withdrawal of a consent;
  • the communication of certain computerized information in a structured, commonly used technological format;
  • information about the use or disclosure of your information;
  • the review of an automated decision made by Subspace, if applicable;
  • to file a complaint about our practices.

Send your request to the person identified in section 1. We may verify your identity before responding. We will respond within the period provided by law, generally within thirty days of receiving a complete request. A request may be refused or limited where the law permits; we will then explain the reasons and the applicable recourses.

You may also contact the Commission d’accès à l’information du Québec regarding your rights.

17. Commercial communications

You may unsubscribe from commercial communications using the link provided in the message or by writing to us. We may continue to send the operational, security, billing or legal communications necessary for the Services.

18. Minors

The Services are intended for businesses and professionals and are not designed to be used directly by minors. We do not knowingly seek to collect their information for our own purposes. A Customer that uses the Services in relation to a minor remains responsible for obtaining the required authorizations and for complying with the applicable specific protections.

19. Changes to the policy

We may modify this policy to reflect legal, technical or operational developments. The date at the top indicates the version in effect. Where a change is significant, we will give appropriate notice before it takes effect where the law requires it.

A change to the policy does not by itself permit information to be used retroactively for a new, incompatible purpose without the required consent.

20. Contact and complaints

For any question, request or complaint:

Richard Beauregard

President and Privacy Officer

richard.beauregard@subspacecomputing.com

We will acknowledge receipt of complaints and handle them impartially, confidentially and within a reasonable time. A person who is dissatisfied may exercise the recourses provided by law before the competent authority.

Contact
Subspace Logo

Compute infrastructure for modern organizations.

ASTRIA

Compute engine

ASTRIA

Product

  • Platform
  • Pricing
  • OEM integration
  • Product examples

Resources

  • Developer guide
  • Python SDK
  • TypeScript SDK
  • API reference
  • n8n integration
  • MCP integration
  • Investor one-pager (FR)
  • Investor one-pager (EN)

Company

  • Team
  • Services
  • Pilot program

Support

  • Contact
  • Privacy
  • Terms

© 2026 Subspace Computing. All rights reserved.·Powered byASTRIAASTRIA