Skip to main content

Privacy Policy

Last updated: September 6, 2026

This Privacy Policy describes the practices of MITRAS GROUP INC. (“SREDlog”, “we”, “us” or “our”) concerning personal information collected through the SREDlog website, applications and related services (collectively, the “Service”). It explains the categories of personal information we collect, the purposes for which it is used, the circumstances in which it may be disclosed, and the rights available to individuals under applicable law.

1. Scope and accountability

This Privacy Policy applies to personal information under SREDlog’s control. It does not apply to information handled independently by a customer organization or by a third party under its own authority.

SREDlog is designed for business use. An organization that subscribes to or administers a SREDlog workspace (the “Customer”) determines which authorized users may access that workspace and which information is submitted to the Service. Where SREDlog processes personal information on the Customer’s behalf, the Customer remains responsible for its collection and use of that information, and SREDlog acts in accordance with the Customer’s lawful instructions and the parties’ agreement.

SREDlog has designated a Privacy Officer who is accountable for its privacy program and may be contacted at privacy@sredlog.com.

2. Categories of personal information

Depending on the manner in which the Service is used, SREDlog may collect account and contact information; authentication and security information; billing and transaction records; communications and support records; technical and usage information; and information submitted to a workspace by or on behalf of a Customer.

Workspace information may include business, technical, financial, employment or other records selected by the Customer for claim-preparation and related purposes. Customers must not submit personal information that is unnecessary for their authorized use of the Service.

SREDlog may also receive information from services that a Customer elects to connect or from individuals whom the Customer authorizes to contribute information to its workspace.

3. Purposes of collection and use

SREDlog collects and uses personal information only for identified and legitimate purposes, including providing, administering and supporting the Service; establishing and authenticating accounts; processing subscriptions and transactions; communicating service, security and account information; responding to requests; maintaining security and reliability; preventing misuse; enforcing agreements; complying with legal obligations; and protecting legal rights.

Where a user requests an AI-enabled function, the information submitted or selected for that function may be processed by SREDlog AI to produce the requested draft, analysis or assistance.

SREDlog does not sell personal information and does not use Customer workspace information for third-party advertising.

5. Disclosure and service providers

SREDlog may disclose personal information to service providers that perform functions on its behalf, including infrastructure and data storage, payment processing, communications, customer support, security, scheduling and SREDlog AI processing. These organizations are authorized to process information only for the services they provide and are subject to appropriate contractual, confidentiality and security requirements.

Personal information may be processed in jurisdictions outside Québec or Canada when a supporting service requires it. In those circumstances, the information may be subject to the laws of the jurisdiction in which it is processed. SREDlog assesses relevant privacy considerations and applies contractual or other safeguards appropriate to the circumstances.

SREDlog may also disclose personal information where required or permitted by law, to protect the rights or safety of SREDlog or others, in connection with a proposed or completed corporate transaction, or with the individual’s direction or consent.

Customers seeking additional information about service-provider categories, cross-border processing or contractual privacy terms may contact privacy@sredlog.com.

6. SREDlog AI

SREDlog AI processes only the information submitted or selected for the requested function. AI-generated material is provided as a draft or assistance and must be reviewed by an appropriately qualified person before it is relied upon.

SREDlog does not pool Customer workspace information across firms or use Customer workspace information to train SREDlog AI for purposes unrelated to providing the Service.

A Customer administrator may control whether SREDlog AI features are available within the Customer’s workspace.

7. Cookies and measurement

SREDlog uses technologies that are necessary to authenticate users, maintain security, preserve user preferences and operate requested features. Public pages may also use limited, aggregate measurement to understand performance and general use of the website.

With your permission, public website pages use Google Analytics cookies to measure visits, referring websites and general actions such as opening a trial, demo or sample link. Google receives cookie identifiers, public page paths and browser/device information. We exclude URL query strings and fragments, form entries, and Customer workspace, claim and evidence information. Google may process analytics information outside Quebec and Canada. Google Analytics is not enabled in authenticated workspaces.

Analytics is off until you select Accept analytics. Reject analytics keeps it off. You can withdraw consent through Cookie preferences in the public website footer. The preference and analytics cookies expire after up to 180 days. Withdrawal stops future collection and removes this website’s analytics cookies; it does not erase previously collected reports. Google explains its processing in How Google uses information from sites that use its services.

SREDlog does not use advertising cookies or cross-site behavioural advertising on the Service.

8. Retention and deletion

Personal information is retained only for as long as reasonably necessary to fulfil the purposes for which it was collected, provide the Service, satisfy contractual obligations, protect legitimate business and security interests, and comply with legal, accounting or reporting requirements.

Retention periods vary according to the nature and sensitivity of the information, the context in which it was collected, Customer instructions and applicable legal requirements. When information is no longer required, SREDlog deletes, anonymizes or otherwise disposes of it in accordance with established procedures.

Authorized Customer administrators may use available account controls to export or delete Customer workspace information, subject to applicable retention requirements and technical processing periods.

9. Safeguards and confidentiality incidents

SREDlog maintains administrative, technical and organizational safeguards designed to protect personal information against unauthorized access, use, disclosure, alteration or loss. Safeguards are selected having regard to the sensitivity, amount, format and location of the information and include access restrictions, security controls, monitoring and incident-response procedures.

SREDlog investigates suspected confidentiality incidents and maintains records or provides notifications to affected individuals and regulatory authorities where required by applicable law.

10. Access, correction and other rights

Subject to applicable law, an individual may request access to or correction of personal information under SREDlog’s control, withdraw consent where processing is based on consent, request information about applicable retention periods, or exercise portability and other statutory rights where available. Requests may be submitted to privacy@sredlog.com and may require verification of identity.

Where personal information was submitted by or on behalf of a Customer, SREDlog may refer the request to that Customer or assist the Customer in responding. Access or other requests may be limited by legal exceptions, the rights of other individuals or applicable contractual obligations.

An individual may also direct a question or complaint concerning SREDlog’s privacy practices to the Privacy Officer at privacy@sredlog.com. SREDlog will review and respond to complaints in accordance with its privacy procedures and applicable law.

11. Minors

The Service is intended for business users and is not directed to minors. SREDlog does not knowingly collect personal information directly from children through the Service.

12. Changes to this Privacy Policy

SREDlog may amend this Privacy Policy to reflect changes to the Service, its practices or applicable requirements. The revised policy will be posted with an updated effective date. SREDlog will provide additional notice of material changes where required by law.

13. Contact

Privacy Officer, MITRAS GROUP INC.: privacy@sredlog.com.

Opening chat…

Open the help centre