Draft for counsel review — not legal advice. This document describes how ATLAS OS (Smart Buildings Inc.) intends to handle personal information. It must be reviewed and finalized by qualified Canadian privacy counsel before reliance.
Last updated: draft. Governing law: Ontario, Canada.
Who we are
ATLAS OS is a building-operations platform operated by Smart Buildings Inc. ("we", "us"). We act as a service provider to building operators and, for certain telemetry, as a processor on their behalf. This policy covers the ATLAS OS web application, APIs, and connected habitat services.
Information we collect
- Account & operator data: names, work emails, role, and authentication identifiers for operators who access the console.
- Building telemetry: per-floor sensor readings (energy, water, air, food, occupancy) ingested through the platform's tagged-point model.
- Presence & wellness signals: privacy-by-design WiFi-CSI presence (RuView) — occupancy counts and, on health/clinic floors, optional vital-sign estimates. No cameras and no wearables are used.
- Usage data: log and diagnostic information needed to operate the service.
How we use information
We process personal information to operate the digital twin, triage incidents, deliver resident broadcasts, compute building KPIs, and maintain security. We do not sell personal information.
Legal bases & Canadian law
We handle personal information consistent with PIPEDA and applicable provincial privacy legislation. Where a building uses health-related signals (e.g., clinic vitals), we apply PHIPA-aligned safeguards and process such data only as a service provider under the operator's direction and with appropriate consent.
Sensing and consent
Presence and vital-sign sensing in dwellings is deployed only with resident notice and consent, and subject to a privacy-law review for the specific deployment. Residents may request information about, or object to, such sensing through their building operator.
Sharing & subprocessors
We share information with infrastructure subprocessors (hosting, database) under contract, and with the building operator who controls the deployment. A current list of subprocessors is available on request.
Retention
We retain personal information only as long as necessary for the purposes above or as required by law, after which it is deleted or de-identified.
Security
We use administrative, technical, and physical safeguards appropriate to the sensitivity of the information, including access controls and encryption in transit.
Your rights
Subject to applicable law, you may request access to, correction of, or deletion of your personal information, and may withdraw consent where processing relies on it. Requests are routed through your building operator or to us directly.
Contact
Privacy questions: privacy@smartbuildings.example (placeholder — replace with the official contact before publication).