Privacy Policy

Last updated: July 22, 2026

This Privacy Policy explains how MITRAS GROUP INC. (“SREDlog”, “we”, “us”) collects, uses, protects and shares information when you use SREDlog (the “Service”). It applies to the information described below and the ways we handle it.

1. Who this applies to

SREDlog is a business tool used by SR&ED consultants, accounting firms and companies to prepare SR&ED claims. “Firm” means the organization that holds an account; “you” means a user of that account.

Where a Firm uploads information about its own clients or employees, the Firm is responsible for having the right to do so; we process that information on the Firm’s behalf.

2. Information we collect

Account information: your name, email address, password (stored only as a secure hash), and the IP address you sign up from.

Workspace data you enter: clients, claims, projects, financial figures, time allocations, and the documents (“evidence”) you upload.

Connected-system data: when a client authorizes a source such as Jira, SREDlog stores the selected project evidence needed for the claim, which can include issue summaries, worklog comments, hours, and display names. Connector OAuth credentials are encrypted at rest.

API keys: any AI key your Firm optionally provides (bring-your-own-key), stored encrypted at rest and used only to make your Firm’s AI requests.

Billing information: handled by our payment processor (Stripe). We do not store full card numbers.

Usage and device data: basic logs needed to operate and secure the Service (for example, request and error logs and session-cookie activity). On public pages, Cloudflare Web Analytics may collect aggregate page-view and performance metrics; Cloudflare describes this service as cookieless and says it does not collect or use visitors’ personal data.

3. How we use information

To provide and operate the Service, store your work, generate drafts, produce forms and the audit binder.

To secure the Service, prevent abuse, and enforce our Terms.

To process subscriptions and send essential service emails (verification, invites, account notices).

We do not sell your information, and we do not use your workspace data for advertising.

4. AI processing

AI features run either on SREDlog AI (the default) or, if your Firm opts in, on an OpenAI key your Firm supplies. The content needed to fulfil a request (for example, a project’s evidence) is sent to the AI provider (OpenAI), under SREDlog’s account for SREDlog AI, or under your Firm’s account for bring-your-own-key, to generate the result.

SREDlog does not pool client data across firms or use it to train models. OpenAI states that API data is not used for training unless the API account explicitly opts in.

SREDlog sends AI chat and response requests with provider-side response storage disabled. OpenAI may still retain API inputs and outputs in abuse-monitoring logs for up to 30 days by default, unless different approved data controls apply to the API account. OpenAI explains these controls on its API data-controls page.

5. Service providers

We use a small set of service providers and subprocessors to run SREDlog: cloud hosting and database infrastructure, cloud object storage for uploaded files, OpenAI for AI features, Stripe for payments, and an email provider for transactional email.

Service providers receive only the information needed to provide their function. Some may process data outside Canada, including in the United States, under their own security, confidentiality and data-processing commitments.

Customers that need vendor review materials or a data processing agreement (DPA) can contact privacy@sredlog.com.

6. Cookies

SREDlog uses essential cookies to keep you signed in, complete two-factor and single-sign-on flows, protect connector authorization, and remember your light/dark preference.

We do not use advertising, analytics or cross-site tracking cookies. Cloudflare Web Analytics is cookieless; see Cloudflare’s Web Analytics documentation for its current description of the service.

7. Data retention and deletion

We keep your data for as long as your account is active. You can delete claims, clients and uploaded files at any time. Those deleted items remain in Recently Deleted for 30 days, so mistakes are recoverable, and are then permanently removed, including the underlying stored files.

A Firm admin can delete the Firm’s account at any time, which permanently removes its workspace data and stored documents. A Firm admin can also export the Firm’s data as a machine-readable file from Settings → Export data.

Some records may be retained as required for legal, tax, security or backup purposes for a limited period, after which they are deleted or anonymized.

For Jira user data, SREDlog participates in Atlassian’s Personal Data Reporting process. We periodically report the Atlassian account identifiers whose personal data remains stored and refresh or erase affected copies when Atlassian tells us an account changed or closed.

8. Security

We protect data with encryption in transit, encryption of sensitive secrets at rest, per-Firm isolation, role-based access control and audit logging. No system is perfectly secure, but we work to safeguard your data. See our Security page for details.

If a confidentiality incident creates a level of serious risk that triggers notice under applicable law, we will notify affected people and the applicable privacy regulator. Depending on the circumstances, that regulator may be the Commission d’accès à l’information or the Office of the Privacy Commissioner of Canada. We keep a register of confidentiality incidents where applicable law requires one.

9. Your rights

Subject to applicable law (including Canada’s PIPEDA and Quebec’s Law 25), you may request access to, correction of, or deletion of your personal information, and may withdraw consent where processing relies on it.

To make a request, contact us at privacy@sredlog.com. If your information was provided by a Firm, we may direct your request to that Firm.

SREDlog’s Privacy Officer is its founder and can be reached at privacy@sredlog.com.

10. Children

SREDlog is a business tool and is not directed to individuals under 18. We do not knowingly collect information from children.

11. Changes to this Policy

We may update this Policy from time to time. We will post the updated version with a new “Last updated” date, and for material changes we will provide reasonable notice.

12. Contact

Questions or privacy requests: privacy@sredlog.com.