Privacy Policy
What personal information we hold, why, and what you can do about it.
1Who is responsible
World Industries Network is responsible for the personal information described here, as the enterprise that decides what is collected and why. This policy takes effect on 9 August 2026. Write to [email protected] about anything in it.
It is written to Quebec's Act respecting the protection of personal information in the private sector, as amended by Act 25, and to the federal Personal Information Protection and Electronic Documents Act. Where the EU or UK General Data Protection Regulation applies to you, the additional statements marked below apply and we act as controller for the processing described.
2The person in charge of personal information
Law 25 requires an enterprise to designate a person in charge of the protection of personal information and to publish that role, with its title and contact details. Unless the role is delegated in writing, it is held by the person exercising the highest authority within the enterprise, and that is the position here.
- Title
- Person in charge of the protection of personal information
- Held by
- The person exercising the highest authority within World Industries Network
- Contact
- [email protected]
Requests reaching that address are handled by the person holding the role, not by general support. If you need to escalate past them, section 13 tells you where.
3What we collect
- Account
- Name, email, password hash, language, and the Companies you belong to.
- Company
- Business name, sector, legal form, description, addresses, logo and cover, and the identity and verification data a payment provider requires to pay you out.
- Content
- What you publish or send: posts, products, messages, files, reviews, and the metadata attached to them.
- Commerce
- Orders, delivery addresses, amounts, fees, refunds, disputes and payout records. Full card numbers never reach our servers; they are handled by our payment provider.
- Technical
- Session and security tokens, a salted hash of your IP address for rate limiting and abuse prevention, and device, operating system and browser for a counted visit.
- Analytics
- Anonymous page counts, and only where you accepted analytics cookies.
- Support
- What you tell us when you write to us, and our reply.
We collect this from you, from your use of the Platform, and from our payment provider where it returns the result of an identity or bank verification you initiated.
4Why we collect it, and on what basis
- To run your account
- Necessary to perform our contract with you. Law 25: necessary for the purposes of the enterprise.
- To operate the marketplace
- Necessary to perform the contract, and to comply with tax, accounting and anti-fraud obligations.
- To secure the Platform
- Our legitimate interest in preventing fraud, abuse and unauthorised access, balanced against your interests.
- To answer you
- Necessary to perform the contract, or our legitimate interest in responding.
- To measure usage
- Your consent, which you may withdraw at any time.
- To meet a legal obligation
- Compliance with a legal obligation to which we are subject.
We do not sell personal information, we do not run third-party advertising or tracking pixels, and we do not use the contents of your private messages for advertising or to profile you.
5Consent, and how to withdraw it
Where we rely on consent, we ask before the collection starts rather than after, and refusing is a single action with the same weight as accepting. You can withdraw consent at any time: for analytics, through the cookie controls; for anything else, by writing to [email protected]. Withdrawal applies going forward and does not make earlier processing unlawful.
Consent for a person under 14 is given by the person having parental authority.
6Who we share it with
We share personal information with service providers who process it on our instructions and under contract, only as needed to deliver the service: payment processing, cloud hosting and databases, object storage and content delivery, transactional email, error monitoring, and product analytics where you consented.
We also disclose where the law requires it, to respond to a valid legal demand, to establish or defend a legal claim, or to protect the rights and safety of a person. If our business is transferred, personal information may transfer with it under the confidentiality obligations Law 25 imposes on such a transaction.
What another user sees is what you publish. Your business email is not shown on a public profile; contact requests are relayed by us so your address stays private.
7Where it is processed
Personal information is processed and stored in Canada, the United States and the European Union, depending on the provider and the service. Communicating personal information outside Quebec requires a privacy impact assessment establishing that the information will receive adequate protection, and a contract recording that assessment. Where the GDPR applies, transfers out of the EEA rely on the European Commission's standard contractual clauses or an adequacy decision.
Every provider, and its assessmentWho processes what, where they do it, and the conclusion of the assessment for each.8How long we keep it
- Account and Company data
- While the account is open, then destroyed or anonymised within a reasonable period after closure, subject to the rows below.
- Orders, invoices and payout records
- Retained for the period required by tax and financial record-keeping law, counted from the end of the relevant fiscal year.
- Security and access logs
- Short retention, sufficient to investigate abuse.
- Moderation records
- Retained so a removal can still be explained and contested, and kept to the minimum needed for that.
- Support correspondence
- Retained while it may still be relevant to a dispute.
When a retention period ends, the information is destroyed or anonymised. Anonymised information is no longer personal information and may be kept as aggregate statistics.
9How it is protected
- At rest
- Sensitive fields are encrypted with AES-256-GCM.
- Passwords
- Hashed with Argon2id. They are never stored or recoverable in clear text.
- In transit
- TLS on every connection, with post-quantum key exchange where the client supports it.
- Access
- Per-module permissions within a Company, and no shared administrative credential.
10Automated processing
Some decisions on the Platform are made or assisted by automated processing, and Law 25 requires that we tell you which:
- Feed ranking orders what you see from the accounts you follow and your sector. It does not decide anything about you.
- Abuse controls, including rate limiting and fraud signals, can restrict an action automatically.
- Content reported by enough distinct members is removed automatically. The owner is notified with the count and the reasons, and the removal is recorded so it can be contested.
- A seller risk tier, derived from account age and settlement history, sets the payout hold and a rolling volume ceiling.
Where a decision about you is based exclusively on automated processing, you may ask what personal information was used, why the decision was reached, and to have it reviewed by a person. Write to [email protected].
11Your rights
You may ask for access to the personal information we hold about you, its rectification, its deletion where the law provides for it, a portable copy in a structured and commonly used technological format, the withdrawal of your consent, and, in the circumstances Law 25 sets out, that we cease disseminating information or de-index a link where dissemination causes you serious injury to reputation or privacy.
How to exercise themWhat to send, how we verify you, and how long we take.12Confidentiality incidents
A confidentiality incident is unauthorised access to, unauthorised use of, unauthorised communication of, or loss of personal information, or any other breach of its protection. It does not require an attacker: a misdirected export or a bug that showed one member data belonging to another is an incident.
Every incident is entered in a register, including one that carries no risk of serious injury. Each entry records the information concerned, the circumstances, when it happened and when we became aware, how many people it concerns, the finding on risk of serious injury and what led to it, the notices given, and the measures taken. Entries are kept for five years from the date we became aware.
Where an incident presents a risk of serious injury, we notify the Commission d'accès à l'information and the persons concerned with diligence, and we take reasonable measures to reduce the risk and to prevent it happening again. Where the GDPR applies, we notify the competent supervisory authority within 72 hours where the incident is likely to result in a risk to individuals.
If you believe an incident has occurred, write to [email protected] or [email protected]. Both reach a person, and a report from outside is entered in the register the same way one we find ourselves is.
13Complaints
Write to [email protected] first. If our answer does not satisfy you, you may complain to the Commission d'accès à l'information du Québec, to the Office of the Privacy Commissioner of Canada, or, if you are in the EEA or the UK, to your national supervisory authority.
14Changes
We publish the current version here with an effective date. Where a change materially affects how we use personal information about you, we give notice before it takes effect and, where the change requires it, ask for consent again.