Legal

WarmLoop Privacy Policy

Version: 2026-10-04 · Effective: October 4, 2026, except that a change of which section 20 requires notice takes effect for a Customer as that section provides

In brief

This summary points to the sections below, which give the detail.

1. About this policy

This policy describes how WarmLoop Ltd. ("WarmLoop"), a corporation incorporated under the Canada Business Corporations Act with its registered office at 2100 Scarth Street, Regina, Saskatchewan S4P 2H6, collects, uses, discloses and keeps personal information in connection with:

In this policy, "the Service" means the research service and the records service together, as the Terms of Service define it. A "Customer" is the law firm, legal department, business or government body that subscribes to the Service, and an "Authorized User" is an individual a Customer permits to use the Service under one of its accounts. An individual account has one Authorized User. An organization account has several, each in a seat, and is managed by its owner and its administrators, as the Terms of Service describe in section 6. This policy does not cover any other WarmLoop product, and it does not cover the AI assistant you use, which its own vendor's terms and policies govern.

This policy is written for Authorized Users, for people who are invited to an organization account, for people who read a Record or ask for access to one, for visitors to the website, for people who make a submission, and for people whose personal information appears in the court decisions and legislation WarmLoop holds or in material a Customer sends to the Service. The Service is sold only for business, professional or governmental use. It is not offered to individuals for personal use, and it is not directed to children.

This policy is WarmLoop's notice, under privacy law, of how it handles personal information. It describes WarmLoop's practices. It is not a contract and does not form part of the Terms of Service. WarmLoop's contractual commitments to its Customers about their content and data are in the Terms of Service at https://warmloop.com/terms, principally in section 10 (data), section 3 (Records), section 20 (confidentiality), section 27 (rights materials) and section 28 (submissions). Section 8 of this policy lists the email messages the Service sends, and the page at https://warmloop.com/email describes them.

WarmLoop handles personal information in accordance with the Personal Information Protection and Electronic Documents Act, which governs the personal information WarmLoop collects, uses and discloses in the course of its commercial activities.

A Customer that sends WarmLoop personal information about its own clients or about other people, in a query, a Record or an exhibit, remains responsible for that information under privacy law, and WarmLoop processes it on the Customer's behalf and on its instructions. The Customer remains responsible for its own obligations in collecting that information and in sending it to WarmLoop.

2. The Privacy Officer

WarmLoop is responsible for the personal information under its control, including information it transfers to a service provider for processing. It has designated a Privacy Officer who is accountable for WarmLoop's compliance with the privacy principles of the Personal Information Protection and Electronic Documents Act, and to whom questions, requests and complaints can be sent:

Privacy Officer, WarmLoop Ltd.

Email: privacy@warmloop.com

Mail: 2100 Scarth Street, Regina, Saskatchewan S4P 2H6

The name of the individual currently designated as Privacy Officer is available on request. Questions about the Service that do not concern personal information go to info@warmloop.com.

3. Information about Authorized Users and accounts

WarmLoop uses the information in this section to create and secure accounts, to let an organization manage its account and its Authorized Users, to record certifications of rights, to sign users in, to apply the device rules and usage limits, to record acceptance of the Terms of Service, to bill, to provide support, and to investigate faults and misuse.

Sign-in and account details

An account is created the first time an approved person signs in. WarmLoop keeps the email address, the display name, the sign-in method used (Google, Microsoft, or email and password), the identifier the sign-in provider assigns, when the account was created, whether it has been disabled, and any further sign-in methods linked to it. An account is named with the email address of the person who created it, and the owner or an administrator of an organization account may give the organization account another name.

Sign-in with email and password, and the connection to Google sign-in, are handled by Amazon Cognito in Amazon Web Services' Canada (Central) region. Amazon Cognito keeps a sign-in record, with the email address, for each person who signs up that way, including a person whose sign-up WarmLoop then refuses because the email address is not approved. A Google sign-in is processed by Google, and a Microsoft sign-in (work, school or personal Microsoft account) is processed by Microsoft; each confirms to WarmLoop who you are.

After a Google sign-in, and after a Microsoft sign-in that does not show that a second factor was used, WarmLoop's system emails a six-digit code to the account's email address, and the sign-in completes only when that code is entered, in the same browser, within 10 minutes. WarmLoop keeps a record of each such code, with the account, the sign-in provider, a one-way hash of the code and of a token held in the browser, the number of codes sent and of attempts made, and the times. Each time it sends a code, it deletes the records of codes made more than a day before. After 5 wrong codes, the Service stops sending and accepting codes for the account for 15 minutes, and after every 3 more wrong codes it does so again, for longer each time, up to 24 hours at a time, and 7 days without a wrong code start this again from the beginning; WarmLoop keeps a count of the account's wrong codes and pauses for that purpose, and its system emails WarmLoop's operator, with the account's identifier, its email address partly hidden and the sign-in provider, when an account is paused for the second time and when it is first paused for 24 hours.

Until WarmLoop opens sign-up more widely, it approves email addresses or email domains before an account can be created. It keeps its approvals of email addresses, with its notes on them, and it records whether an account is provided without charge. An invitation to an organization account (below) is an approval of the invited email address.

Organization accounts and invitations

For an organization account, WarmLoop keeps the account's name and kind, the role of each of its Authorized Users (owner, administrator or member), when each joined and whether each has been removed, the number of seats, and any email domains WarmLoop has recorded for the organization.

When the owner or an administrator invites a person, WarmLoop keeps the invited email address, the role offered, who sent the invitation, when it was sent, resent, accepted or revoked, when it expires, and which account accepted it. Its database keeps only a one-way hash of the link in the invitation, although the link can appear in the logs of requests described below. WarmLoop's system emails the invitation to the invited address, naming the person who sent it and the organization. If the invited person uses the link in the invitation to stop further invitations, WarmLoop records that address, with the date and the invitation, and refuses any later invitation to it (section 14).

The owner and the administrators of an organization account can see, in the account portal, the email address, role, date joined and status of each of its Authorized Users, the invitations that are pending, and the account's seats and subscription, and they may see the usage counts described below for each of its Authorized Users. Every Authorized User of an organization account can list the account's Records and their readers through the Service. On the Records page of the Service the owner and the administrators see every Record of the account, and a member sees only the Records he or she published (section 5).

When a person with an individual account joins an organization account, the account moves to the organization. The Records published under the individual account stay with it, and the person can no longer list or manage them through the Service.

Certifications of rights

Some documents WarmLoop holds are licensed by their publishers, and an organization's owner or an administrator may certify that the organization holds the rights to read them (Terms of Service, section 27). For each certification WarmLoop keeps the collection and the documents it contains when the certification is made, the legal name of the organization given, the text and version of the statement accepted and a hash of that text, the certifier's account, whether the certifier acted as owner or administrator, and the name the certifier typed, the Authorized Users it covers, any licence reference and any evidence of the rights given with it, the time, and the network address and browser identification from which it was made, together with each later change, suspension or revocation and the reason given. It emails the certifier, and the owner where the certifier is an administrator, a confirmation with the statement, the provisions of the Terms of Service that govern it and a link to revoke the certification. The owner and the administrators of the organization account can see the organization's certifications. When WarmLoop accepts evidence of rights, it is scanned for malware, is kept encrypted in Amazon Web Services' Canada (Central) region, and can be seen at WarmLoop only by the individuals who administer the Service. WarmLoop also keeps a record of each grant of access it makes to an account or a user, with a note of the reason.

The Service's sign-in and account pages accept requests only from Canada or from the network addresses WarmLoop uses to administer the Service, and limit the number of requests from any one address. Requests to the Service, to Records and to the sign-in pages pass through web application firewalls that WarmLoop runs in Amazon Web Services' Canada (Central) region, and requests to the Service and to Records also pass through a load balancer there. A firewall refuses a request that does not meet WarmLoop's rules, such as a request to the sign-in or account pages from outside Canada, and WarmLoop keeps a log of each refused request, with the network address and its country, the page requested without its query string, the request's headers other than cookies and credentials, and the time, for 30 days. When WarmLoop tests a new firewall rule, the firewall also logs each request that the rule would have refused but let through, with the same details as a refused request, and that log is deleted after 30 days. Records can be opened only from network addresses WarmLoop has approved, and WarmLoop keeps the list of approved addresses. A request to a Record from any other address is refused. WarmLoop's system keeps a list of the addresses it refuses, with the site and page requested and the times, in memory for up to 24 hours, so that WarmLoop can recognize and approve an address it expects; the list is lost when the system restarts.

When an account is created, when a sign-up is refused because the email address is not approved, and when an email address already in use signs in through a different sign-in provider, WarmLoop's system emails WarmLoop's operator the person's email address and sign-in provider, and records the event in the audit log.

Devices and connections

Each connection of an AI assistant to the Service is a device. For each one, WarmLoop records the name and identifier the assistant's software registered, when the connection was made, when it last obtained access and last made a request, whether and why it was disconnected, and the version of any setup files installed through it. It also keeps a record of each authorization attempt, with the connecting software and the user. WarmLoop detects, from each connection, the name and version of the AI assistant software, uses it to give setup instructions suited to that software, and records the software and platform detected when setup is run.

Acceptance of the Terms

Each time an Authorized User accepts a version of the Terms of Service, WarmLoop records the user, the version, the time and the network address from which it was accepted.

Usage counts

WarmLoop counts, for each user, tool and day, the requests made, the errors returned and the full documents retrieved, and on its corpus server it counts searches, reranking work and documents retrieved for each user and day. These counts contain no query text. WarmLoop uses them to apply usage limits and to monitor the Service. An hourly count of requests, used to apply the hourly limit, is deleted after 6 hours.

The audit log

WarmLoop keeps an administrative audit log of events on the platform. It records account creation (with the email address, sign-in provider and provider identifier), refused sign-ups (with the email address, sign-in provider and provider identifier), linked sign-in methods, whether each Google or Microsoft sign-in showed that a second factor was used, each emailed sign-in code sent, sent again or that could not be sent, entered correctly or wrongly, expired or refused, and each pause of an account's codes (with the sign-in provider), approvals of email addresses and their withdrawal, accounts disabled or enabled (with the email address), changes to the list of approved network addresses, devices connected, disconnected or refused under the device limit, requests refused for exceeding a limit (with the network address, where the refusal was at the registration or sign-in endpoint), setup runs (with the assistant software and platform detected and the setup option chosen), the version of guidance served, changes in subscription status, invitations to an organization account sent, resent, revoked and accepted, changes of an Authorized User's role, removals, changes in the number of seats and of an organization account's name, certifications made, changed, suspended and revoked, grants of access to rights material, and Record events such as publication, readers added or removed through WarmLoop's operator console, which can do so only for the Records of the operator's own account (with the reader's email address), malware found in an upload, and the deletion, restoration and erasure of a Record. WarmLoop uses it for security and to establish what happened on the platform.

Cookies on the account pages

The Service's sign-in and account pages at https://account.warmloop.com set a cookie that keeps you signed in to those pages for up to 30 minutes, and cookies that hold the state of a sign-in while it completes, for up to 10 minutes, or for up to 30 minutes while an emailed sign-in code is awaited. A Record sets the access cookie described in section 5.

Server and network logs

The research service's web application records a line for each web request it receives, with the method and the address requested, including part or all of any query string in that address, but without the codes, tokens and email addresses that the Service's links and sign-in steps carry in an address. The content of the requests your assistant makes to the Service's tools is not in those lines. The corpus server keeps request logs too, which section 4 describes. Server logs are held on the servers that write them, in Canada. WarmLoop has set no period after which the web application's logs are deleted; the corpus server's request logs are deleted within 12 months (section 4).

WarmLoop's web server also keeps an access log of each request to the Service and to Records, with the time, the network address, the address requested with its query string, the request's headers other than cookies, credentials and the address of the previous page, and the response's status, size and headers other than cookies and the address to which it redirects. The codes, tokens and email addresses that the Service's links and sign-in steps carry in an address, and the words searched for on the Records page, are removed from the address before it is logged. In entries written before that change took effect on September 28, 2026, only the codes and state values that a sign-in passes were removed, and the address of the previous page and of a redirect were kept, so those entries could hold the one-time code and email address in the link sent to a Record's reader (section 5), the link in an invitation to an organization account, and other codes and tokens; all of them were deleted on September 28, 2026. That log is held on the web server, in Canada, and each entry in it is deleted within about a month of being written.

WarmLoop's web database keeps a log of its errors, which can include the text of a database instruction that failed and, in rare cases, a value such as an email address, with the time and the database account. That log is stored in Amazon Web Services' Canada (Central) region, encrypted, and is deleted after 14 days.

WarmLoop's network in Amazon Web Services keeps a record of each connection that its firewall rules refuse, with the network addresses and ports at each end, the protocol, the number of packets and bytes, and the times, but no content. Those records are stored in Amazon Web Services' Canada (Central) region, encrypted, and are deleted after 30 days.

4. Research queries and results

When you search or research through the Service, WarmLoop stores the text of each search or research query ("query text") with the identifier of the Authorized User who sent it and of the assistant software registration it came through, together with the time, the surface used, the kind of search, and operational measurements such as the number of results and how long the search took. This query log is kept on WarmLoop's own server in Saskatchewan. WarmLoop uses it to operate and monitor the Service, including its speed and reliability, and to investigate faults and misuse.

Query text is deleted from the query log 30 days after it is recorded, by a deletion that runs daily. WarmLoop stopped copying the query log into its backups on September 28, 2026, and query text recorded up to that day can remain for a further period, of about 12 months, in WarmLoop's encrypted backups (section 14).

The text of some searches also appears in the request logs of WarmLoop's corpus server. That server records the address of each request it receives. Up to September 28, 2026 it recorded the whole address: for some kinds of search that address includes the search text, and for a citation lookup or a document request it includes the citation looked up and any passage sent to be located in a decision. Since then it records the address without its query string, which keeps the citation looked up or the document requested but leaves out the search text and any passage. A citation looked up and a passage sent to be located are not query text. Those request logs are deleted no later than 12 months after they are written, so the query text and the citations and passages in them are not deleted at 30 days, but are deleted within 12 months, except so far as section 14 requires WarmLoop to keep them because of a request for access.

Where a citation you look up resolves to a decision WarmLoop holds, the form of the citation you sent may be kept as a permanent alias for that decision, so that the same form is recognized in future.

To rank results, the text of each search or research query, with the candidate passages, is sent to a reranking model (Cohere Rerank) hosted by Amazon Web Services in its Canada (Central) region. The query is converted into a search vector on WarmLoop's own server, and that step sends nothing outside it.

WarmLoop does not keep a copy of the results the Service returns to you, beyond the counts and measurements described in this policy, except for a short time in one case: so that your assistant can read the full answer to a citation check page by page, the Service may hold that answer, including the quotations and propositions your assistant sent with the check, in its working memory for up to 30 minutes from the check. That answer is never written to storage, can be read only by the user whose assistant made the check, and is discarded when the 30 minutes end or the Service restarts.

WarmLoop does not use your content to train or fine-tune artificial-intelligence models, and it does not use your query text to develop the Service or send it to an artificial-intelligence tool outside Canada. Where WarmLoop records a detailed trace of a search for the purpose of improving retrieval, it does so only for its own development accounts, which are not Customer accounts. Feedback you choose to send is used as section 6 describes.

Two things keep that promise. First, the Service sends query text to no artificial-intelligence model other than the reranking model in Canada, and the features that could send a request to such a model when a user asks for it are switched off. Second, WarmLoop's development tools run on WarmLoop's own computers and servers, including the corpus server that holds the query log and the request logs, and send what they read to Anthropic's Claude, which is hosted outside Canada (section 11), so WarmLoop's rule for its own development work is that those tools are not used to read a Customer's query text, whether in the query log, in the request logs or in a backup. That rule is kept by WarmLoop's own practice, not by a technical control.

Queries often concern a Customer's matters and can contain personal information about its clients or about other people. That information is the Customer's responsibility, as section 1 explains.

5. Records

What the publishing Customer provides

When an Authorized User publishes a Record, WarmLoop stores the source text of the document for every version, the verified document built from it and the results of verification, each exhibit as uploaded and a viewing copy made from it, the matter reference and title, and the readers named for it by its author, by the owner of the account under which it was published or, for an organization account, by one of its administrators. Readers are named by email address, by email domain, or by reference to WarmLoop's list of court email domains. An exhibit is stored once for the Customer's account and can be reused by later Records of that account.

Each new exhibit is scanned for malware on WarmLoop's own systems before it is processed. An infected upload is deleted and the author is told; the deleted copy stays in the Record store for 90 days, as "Keeping and removing Records" below describes.

Exhibits are kept in WarmLoop's Record store, and the rest of a Record in WarmLoop's web database, both in Amazon Web Services' Canada (Central) region and both encrypted. Public access to the Record store is blocked, and every read passes through WarmLoop's access-controlled viewer.

Records often contain personal information about clients, witnesses and other people. The Customer that publishes a Record decides what it contains and who may read it, and is responsible for having the right to publish it. WarmLoop does not review, approve or endorse a Record, and it accesses a Record's content only so far as is needed to operate, secure, support and troubleshoot the Service, to act on a notice of the kind described at the end of this section, or where the law requires. The checks it runs are mechanical, for example that cited cases resolve and that quoted passages are located where the document says they are.

Publications that are not completed

WarmLoop also stores the source text submitted to start a publication. The source text of a trial run is deleted about 2 hours after it is sent, and a publication plan that is never carried out is deleted about 2 hours after it is made, together with any upload that was not completed. Where a publication fails, or stops short of publishing because the checks found a problem, WarmLoop keeps the source text submitted for it and the exhibits already uploaded for it, other than an infected one, with no set period, although nothing was published. The planned title and matter reference of a Record that was never published are kept with no set period.

Readers

A Record is restricted by default. A reader proves control of an email address named for the Record, or one within an email domain named for it, by entering a one-time code sent to that address, or by following the link sent with it. The code expires 10 minutes after it is sent and works once, and WarmLoop's database stores only a one-way hash of it. The link sent with the code carries the code and the email address. The web server's access log no longer records either, and the entries that held both for a visit made through the link before September 28, 2026 were deleted that day (section 3). Once the code is accepted, the reader's browser receives a signed cookie for that Record, which lasts 90 days from the code, unless the reader signs out of the Record sooner, and is not extended by later visits. The reader's access is checked again on each view, so a revoked reader loses access within about a minute. A reader's access carries over to new versions of the Record and lasts until it is revoked. A reader other than the Record's author sees only the current version.

The access page tells a reader, below the form in which the email address is entered, and again where a reader who is not on the list can ask for access, that WarmLoop records the email address entered, with the reader's network address, browser and the time, to control access to the Record, and that the publishing Customer can see who read it, with a link to this policy. The email that carries the one-time code says the same. While WarmLoop restricts Records to approved network addresses, as it does at the date of this policy, a reader can open a Record, whether restricted or public, only from a network address WarmLoop has approved (section 3). A reader who cannot open a Record for that reason may ask the Customer that published it, or WarmLoop at info@warmloop.com, to have the address approved.

A person without access may ask for it on the Record's access page. The request, with the requester's email address and the Record's title, is stored and emailed to the Record's author, or to a WarmLoop address if no author address is found. The author, the owner of the account and, for an organization account, its administrators may approve or refuse it, and if it is approved the requester is told by email.

Exhibits a reader opens may be kept in that reader's own browser cache for up to 90 days.

Public Records

The owner of the account under which a Record was published or, for an organization account, one of its administrators may make it public, so that anyone with its address can read it and every exhibit it cites, with no email gate, subject to the network-address restriction described above while it applies. WarmLoop still records each view of a public Record, with the viewer's network address and browser identification, but not the viewer's identity. Returning a Record to restricted access does not recall a copy made while it was public. Every Record, public or restricted, carries an instruction to search engines not to index it.

The access log

For each Record, WarmLoop keeps a log of views, of each exhibit opened, of one-time codes sent, accepted and failed, of attempts to open the Record, including by an email address that is not on its list of readers, of access requests and the decisions on them, of readers added and revoked, and of changes between restricted and public access. Each entry records the time and, where they are available, an email address, a network address and a browser identification, and an entry for a view records the version viewed. WarmLoop also keeps a record of each change between restricted and public access, with the Authorized User who made it and the reason given.

The access log is part of the Record's audit trail and is available to the Customer. The Customer can list its latest entries, with readers' email addresses and network addresses, through its own AI assistant, whose vendor then receives them (section 12).

Keeping and removing Records

A Record and each hosted document is kept until it is removed, and does not expire on its own. On the Records page of the Service, the owner and the administrators of an organization account may delete any Record of the account, and an Authorized User may delete a Record he or she published. From the moment a Record is deleted no one can read it, and 30 days later its text, the exhibits it cites that no other Record of the account cites, and its list of readers are erased; until then WarmLoop restores it, with its readers, as a restricted Record, at the written request of the owner of the account. A Customer may also ask for removal at info@warmloop.com, and WarmLoop acts on the request within 30 days, except so far as it must keep information by law. Removal does not recall a copy a reader has already made.

A Record's access log, the records of the one-time codes sent to its readers and the requests made for access to it are kept while the Record is kept and for 6 months after it is erased, and are then deleted. The record of each change between restricted and public access, and the audit entries for a Record, are kept as section 14 describes. When a Record is erased, WarmLoop keeps a record of it that holds none of its content: the Record's identifier, its account, its author's identifier, its address, its dates and the one-way hashes of what was erased. Copies of the Record's database entries, including the source text of the document, remain in WarmLoop's encrypted database backups for up to about 120 days after they are deleted. When an exhibit, or the viewing copy made from it, is deleted or replaced, including an infected upload, an exhibit removed at a Customer's request and an exhibit erased with a deleted Record, the Record store keeps the earlier copy for 90 days, encrypted, served to no one and open only to the individuals who administer the Service for WarmLoop, and then deletes it.

If a Record contains your personal information, a request for access or correction should be directed to the Customer that published it, and WarmLoop will assist that Customer in responding. A request about what WarmLoop records when you open a Record or ask for access to one goes to the Privacy Officer (section 17). WarmLoop may restrict access to a Record on receiving a notice that credibly asserts that it breaches the publishing Customer's obligations under the Terms of Service (for example a publication ban, a sealing order, a confidentiality obligation or privacy law), infringes someone's rights, or breaches an order of a court or tribunal.

When two accounts are merged

If an account is merged into another at the written request of the owners of both accounts (Terms of Service, clause 6.12), its Records, their reader lists, the requests made for access to them and their access logs are then held by the receiving account, whose owner and administrators can see them. The files the Records cite stay where they were stored and are still served with them.

6. Feedback

You can send feedback about the Service through your assistant. Your assistant is instructed to send feedback only when you ask it to and have approved the text, and to leave out client and party names, court file numbers and confidential facts, but WarmLoop cannot check that it has done so.

WarmLoop stores feedback on its own server in Saskatchewan, as it was sent, with your user identifier, the assistant software registration and platform it came from, and the version of the setup files. WarmLoop's review of an item may be recorded with it. WarmLoop does not remove identifying detail from the feedback it stores.

Feedback is kept indefinitely. WarmLoop reviews it and uses it to evaluate and improve the retrieval quality of the Service, including by deriving test queries from it. WarmLoop reviews feedback, as it was sent, using artificial-intelligence development tools that run on WarmLoop's own computers and servers and send what they read to Anthropic's Claude, which is hosted outside Canada (section 11). Summaries of feedback, WarmLoop's records of its review, and test queries derived from feedback are kept in private code repositories hosted by GitHub.

Do not put client-confidential or privileged information in feedback. Sending feedback is optional.

7. Billing

When a Customer subscribes, payment is taken on Stripe's payment page. Card details are entered there and held by Stripe; they do not reach WarmLoop's systems, and WarmLoop never receives or keeps a card's number, expiry date or security code. Stripe's payment page may ask for the card's country and postal code, which Stripe collects under its own policy.

Before Stripe's payment page, the owner or an administrator gives the billing name and address on WarmLoop's own page. WarmLoop keeps them in its own database, uses the province or territory of the address to choose the tax charged, and does not give the address to Stripe. To change that name or address, the Customer writes to info@warmloop.com.

WarmLoop gives Stripe the account's email address, the billing name and WarmLoop's identifier for the account, and, for each payment, the amount as lines (the seats and each tax), WarmLoop's identifier for the charge and a fixed description.

WarmLoop records:

WarmLoop keeps a monthly export of its sales in its own books, which its accountant receives (section 13). On request, WarmLoop's operator sends a copy of an invoice of an account that has been joined to or merged into another by email to the person who was the owner of that account when the invoice was issued, at the address the invoice was issued to. Stripe processes what it receives under its own terms, in locations WarmLoop does not control.

8. Email the Service sends

The Service sends these messages about Records through Amazon Simple Email Service in Amazon Web Services' Canadian regions, from no-reply@mail.warmloop.com, each to one recipient, without attachments, as plain text with an HTML version:

WarmLoop's system sends these messages about organization accounts, rights materials and submissions in the same way:

WarmLoop's system sends these messages about billing in the same way, to the owner and the administrators of the account, each with a link to the invoice where there is one and none with an attachment or a card detail:

WarmLoop's system also emails, in the same way, the sign-in code described in section 3 to the account's email address, and emails WarmLoop's operator the account alerts described in section 3. Amazon Simple Email Service keeps a list of the addresses to which a message could not be delivered or whose recipient complained about a message, so that no further message is sent to them, and it tells WarmLoop's operator of each such event. WarmLoop uses the account email address to send legal, account, billing, security and service notices. WarmLoop sends no marketing email (section 15).

9. The website, and submissions made through it

Pages on warmloop.com load their fonts, styles and images from warmloop.com itself. They contain no analytics, advertising or tracking code. Except for the suggestion page described below, they contain no code that sets a cookie or stores information in your browser, and they make no request to another site. A link to another site loads nothing until you follow it. The suggestion page, when it is open, is the website's only form. To contact WarmLoop otherwise you use an email link, and your own email program sends the message.

The website is delivered by Cloudflare, which receives each request, including your network address, the page requested and your browser's identification, in order to deliver the page. Cloudflare processes that information in locations WarmLoop does not control. WarmLoop has turned on Cloudflare's logging feature for the website; what that feature records, and for how long, is set by Cloudflare.

Email you send to WarmLoop is held in WarmLoop's mailboxes, which are hosted by Microsoft 365, and is used to answer you.

The suggestion page

When the suggestion page at https://warmloop.com/suggest is open, it loads Cloudflare's Turnstile challenge from Cloudflare. Turnstile runs in your browser and collects information about your browser and device in order to tell a person from an automated program, and Cloudflare processes that information under its own terms, in locations WarmLoop does not control. To check the result, WarmLoop's intake service sends Cloudflare the response the challenge produced and may send your network address, and it keeps the result with the submission.

What WarmLoop keeps about a submission

A submission is sent to WarmLoop's intake service at https://intake.warmloop.com, on WarmLoop's web server in Amazon Web Services' Canada (Central) region. WarmLoop keeps the kind of submission; the name, email address, organization, and role and authority the submitter gives; the jurisdiction, the description of the document, the reason given and any addresses; for a consent, the scope chosen, and the version and text of the consent accepted with a hash of that text; the network address and browser identification from which the submission was sent; the result of the Turnstile check; the times the submission was made, verified and decided; and WarmLoop's decision, its notes, its check of the email domain of a consent and its countersignature. Files are kept in a separate storage area in Amazon Web Services' Canada (Central) region, encrypted, closed to public access and stored under random names.

How submitted files are handled

Nothing sent with a submission is scanned or read until the email address is verified (section 8). WarmLoop then treats each file as potentially harmful. It opens a file only inside an isolated environment on its web server that has no access to WarmLoop's other systems. There the file is checked for malware, any active content, such as scripts, is removed into a sanitized copy, or the file is turned into page images, and text is extracted from the sanitized copy and checked for hidden text and for instructions aimed at artificial-intelligence systems. The malware check may use Amazon Web Services' malware scanning or an open-source scanner run inside that environment. When WarmLoop enables it, the extracted text may also be sent to an artificial-intelligence model provided by Anthropic, which may process it outside Canada, only to classify whether it contains such instructions. That feature is off at the date of this policy. A person at WarmLoop reviews every submission before anything is done with it, and sees the extracted text and page images of the sanitized copy, never the file as it was sent.

An address given in a submission is stored as text and is not visited when it is submitted. If WarmLoop decides to obtain a document from it, WarmLoop fetches it later from the publisher's site, and the file goes through the same checks.

Submitted documents in the corpus

If WarmLoop adds a submitted document to the corpus, it keeps the sanitized copy with a record of where the document came from: the submission's identifier, the verified email address of the submitter and, for a consent, the consent. It keeps that copy only outside its write-once archive: on its own computers and its own server in Saskatchewan and, if it copies it to Amazon Web Services, only in encrypted storage in that provider's Canada (Central) region from which WarmLoop can delete it. It deletes the copy within 30 days after a consent under which it holds the copy is revoked or the rights holder demands its deletion in writing, and as an order of a court requires; a copy in its backups is deleted as section 14 describes. The Service serves the document with a label that names the organization that supplied it. A countersigned consent is kept as the record of WarmLoop's licence to use the document.

10. Personal information in court decisions and legislation

The Service searches and serves court and tribunal decisions and legislation. Decisions name parties, witnesses, lawyers, judges and others, and can contain other personal information about them.

WarmLoop acquires decisions as their sources publish them, including in anonymized form where the court or tribunal anonymized them. It keeps what it acquires in a write-once archive in Amazon Web Services' Canada (Central) region, from which it does not delete, and in further copies on its own server and backup drives. If a source later withdraws a decision or replaces it with an anonymized version, the copy WarmLoop acquired earlier remains in the archive. Where WarmLoop has identified a decision as one whose source withholds its text, for example because of a publication ban, the Service serves only information the source published about it, such as its style of cause, date and court, or nothing at all, and not its text.

WarmLoop collects, uses and discloses this information for one purpose: legal research and the verification of legal authority by the law firms, lawyers, legal departments, businesses and government bodies that use the Service. The Personal Information Protection and Electronic Documents Act, with the Regulations Specifying Publicly Available Information made under it, permits an organization to collect, use and disclose, without consent, personal information that appears in a record or document of a court or tribunal that is available to the public, where the collection, use and disclosure relate directly to the purpose for which the information appears there. WarmLoop relies on that permission for the corpus.

To prepare the Service's stored analysis of how decisions have been treated, WarmLoop processes the text of decisions with artificial-intelligence models, including Anthropic's Claude, hosted outside Canada. That work is done by WarmLoop in advance, never at a user's request. WarmLoop computes search vectors for decisions and legislation on its own server and on Amazon Web Services computing in Canada. This work uses the published decisions and legislation, not your content.

WarmLoop makes the corpus available through the Service to its users, and uses it to build and test the Service. It does not publish the corpus on the open web or make it available to search engines.

If you are named in a decision WarmLoop holds and have a question or a concern, write to the Privacy Officer.

11. Service providers, and where information is processed

WarmLoop remains responsible for personal information it transfers to a service provider for processing. These run in Canada:

WarmLoop's encrypted backup drives are rotated off its premises.

These providers process information in locations WarmLoop does not control:

Some of these providers process information outside Canada, including in the United States. Information held outside Canada is subject to the laws of the country where it is held, and may be disclosed to that country's courts and authorities under those laws.

Before WarmLoop adds a service provider to whom a Customer's content, or personal information under WarmLoop's control, may be disclosed, it gives Customers notice as section 20 describes.

12. Your own AI assistant

Every query you send and every result the Service returns, including the full text of documents and the content of Records, passes through the artificial-intelligence assistant and the vendor you have chosen. That vendor handles them under your agreement with it and outside WarmLoop's control. It is not WarmLoop's service provider, and this policy does not govern what it does. If you choose WarmLoop's guided setup and your assistant has a remote-control feature, the setup asks you whether you want it on for WarmLoop sessions; it stays off unless you say on, and the instructions the setup adds to your assistant record your answer. That feature is your vendor's, and whether to use it is your choice. Your assistant reads the files on your computer itself, and WarmLoop does not receive them: it receives only what your assistant sends in a request to the Service, such as a search, a passage sent to be checked or a document you choose to publish as a Record. The method WarmLoop serves tells your assistant to read, for a piece of work, only inside the folder the work runs in and the other folders you name when the work starts, and not to list or search anything above or beside that folder. You are responsible for satisfying yourself that using that assistant is consistent with your own confidentiality and privacy obligations.

13. Other disclosures

Apart from its service providers, which receive information only as section 11 describes, WarmLoop discloses personal information only:

Where a lawful demand concerns a Customer's content, WarmLoop will tell the Customer, unless it is legally prevented from doing so, so that the Customer can assert privilege or object.

WarmLoop makes no personal information of its users available to Phillips & Co. or to any other related organization, other than what any Customer receives about its own account and its own Records. WarmLoop's owner also practises law with Phillips & Co., and his access to WarmLoop's data is on WarmLoop's behalf only. Phillips & Co. is a separate organization and a customer of WarmLoop. Acquisition work run for WarmLoop on Phillips & Co.'s server handles public legal materials and no information about WarmLoop's users.

WarmLoop does not sell personal information, and does not use it for advertising or share it with advertisers.

14. How long information is kept

Information deleted from a live system remains in backups until the backups that hold it age out. WarmLoop's web database, which holds account records, the audit log and the database entries and access logs of Records, has automated backups kept for 14 days and nightly copies kept for up to about 120 days. The database on WarmLoop's corpus server, which holds the query log, the usage counts kept there and feedback, is copied nightly, and the copies made after September 28, 2026 leave out the query log: the two most recent copies are kept, unencrypted, on the corpus server itself, and each copy is also saved to encrypted backup drives, which keep the latest copy for each of the last 7 days, the last 4 weeks and the last 12 months in which the drive was used. That schedule is what governs the "about 12 months" this policy gives for backups. It is applied to a drive when it is connected, so a drive kept off the premises, or connected less often than once a month, can hold a copy older than 12 months.

When a subscription ends, WarmLoop keeps what this section describes for the periods it gives.

Where personal information is the subject of a request for access, WarmLoop keeps it for as long as is necessary to allow the person who asked to exhaust any recourse they have under the Personal Information Protection and Electronic Documents Act, even if it would otherwise be deleted.

15. Consent and choices

Using the Service involves the collection and use of personal information described in sections 3 and 4, and subscribing involves that described in section 7. The Service needs that information in order to be provided, secured, supported and billed. The Terms of Service, which are shown for acceptance before an account is used, describe these uses in section 10 and refer to this policy.

These are optional, and WarmLoop does not require them as a condition of using the Service: sending feedback, publishing a Record, making a Record public, certifying rights, making a submission, and receiving marketing email.

A reader gives an email address in order to open a Record. WarmLoop uses it to send the one-time code and to control and log access to that Record, and it tells the reader so on the access page and in the email that carries the code (section 5).

You may withdraw your consent at any time, subject to legal and contractual restrictions and reasonable notice. If you withdraw consent to the collection and use the Service needs, WarmLoop can no longer provide the Service to you. You can stop sending feedback at any time, and you may ask for feedback you have sent to be deleted (section 17).

Accepting the Terms of Service is not consent to receive marketing messages. WarmLoop sends no marketing email. If it does in future, it will send it only to a person who has given a separate consent, which may be withdrawn at any time. Each such message will identify WarmLoop, give its mailing address and include a way to unsubscribe, and WarmLoop will give effect to an unsubscribe request within 10 business days, as Canada's Anti-Spam Legislation requires.

16. Safeguards

WarmLoop's safeguards include:

17. Access, correction and deletion

You may ask WarmLoop whether it holds personal information about you, what it has used it for and to whom it has disclosed it, and for access to it. Make the request in writing to the Privacy Officer (section 2). If you need help preparing a request, tell WarmLoop and it will help. WarmLoop may ask for information it needs to identify you and to find your information, and will use that information only for that purpose.

WarmLoop will respond within 30 days after it receives the request. It may extend that time by up to 30 more days where meeting it would unreasonably interfere with WarmLoop's activities, or where consultations needed to respond would make it impracticable, or for as long as is needed to convert the information into an alternative format. If it extends the time, it will tell you within the first 30 days, giving the new time limit, its reasons and your right to complain to the Privacy Commissioner of Canada about the extension. WarmLoop does not charge a fee for responding to a request. If you have a sensory disability, you may ask for the information in an alternative format.

WarmLoop may refuse access, in whole or in part, where the law requires or permits it to, for example where giving access would likely reveal personal information about someone else, or where the information is protected by solicitor-client or litigation privilege or would reveal confidential commercial information. Where the protected part can be separated, WarmLoop gives access to the rest. If WarmLoop refuses a request, it will tell you in writing, with its reasons and the recourse available to you.

WarmLoop relies on the details that you and your sign-in provider give it, and sends notices to the account email address, so keep that address current. You may challenge the accuracy and completeness of your personal information and have it corrected, completed or deleted as appropriate. Where appropriate, WarmLoop passes the correction to third parties that have access to the information. If a challenge is not resolved to your satisfaction, WarmLoop records it.

The Service has no self-service function to export or delete an account or its data. A request to delete personal information is made to the Privacy Officer, and WarmLoop will respond within 30 days, subject to what it must keep by law and to the records kept for the periods the second and fourth items of section 14 give, which clause 10.5 of the Terms of Service also states. Information deleted from a live system remains in backups until they age out. A request to remove a Record is made as section 5 describes.

If you read a Record or asked for access to one, what WarmLoop recorded about you when you did so is kept while the Record is kept and for 6 months after the Record is erased, as the fourth item of section 14 says, and a request to delete it is subject to that period, as clauses 10.5 and 10.10 of the Terms of Service also provide. Whether and when the Record is deleted or removed is for the Customer that published it to decide (section 5), and the 6 months run from the Record's erasure. You may ask the Privacy Officer for access to that information, and for its correction, at any time.

If your personal information is in material a Customer sent to the Service, such as a query or a Record, the Customer is responsible for it, and a request for access or correction should be directed to the Customer. WarmLoop will assist the Customer in responding.

18. Breaches of security safeguards

If a breach of WarmLoop's security safeguards involving personal information under its control creates a real risk of significant harm to an individual, WarmLoop will report it to the Privacy Commissioner of Canada and, unless the law prohibits it, notify the individual, in each case as soon as feasible after it determines that the breach has occurred. The notice to an individual is conspicuous and is given directly, except in the circumstances where the law requires indirect notice, such as a public announcement. It describes the circumstances of the breach, when it occurred, the personal information involved, the steps WarmLoop has taken to reduce the risk of harm, the steps the individual can take to reduce or mitigate that risk, and how to contact WarmLoop about it. WarmLoop will also notify the Customer where the information is in the Customer's content, and any other organization or government institution that WarmLoop believes may be able to reduce the risk of harm.

WarmLoop keeps a record of every breach of its security safeguards involving personal information under its control, whether or not the breach creates a real risk of significant harm, for at least 24 months after it determines that the breach occurred, and gives the Privacy Commissioner of Canada access to those records on request.

19. Questions and complaints

Send questions and complaints about WarmLoop's handling of personal information to the Privacy Officer (section 2). WarmLoop investigates every complaint, and where a complaint is justified it takes appropriate measures, including changing its policies and practices where necessary. It will tell you about the complaint procedures available to you.

You may also file a written complaint with the Privacy Commissioner of Canada: https://www.priv.gc.ca. A complaint arising from a refused access request must be filed within six months after the refusal, or after the time for responding to the request expired, or within any longer period the Commissioner allows.

20. Changes to this policy

WarmLoop may change this policy. The current version is published at https://warmloop.com/privacy, with its version identifier at the top, and earlier versions are available on request to the Privacy Officer.

Where a change materially reduces the protection given to a Customer's content or to personal information under WarmLoop's control, including the addition of a service provider to whom either may be disclosed, WarmLoop will give each Customer at least 30 days' notice by email to the account email address, and the change does not take effect against that Customer until the notice period has ended. A Customer may cancel before the change takes effect, and clause 13.4 of the Terms of Service provides for a refund of the unused part of a prepaid period. Other changes take effect when the new version is published.

Before WarmLoop uses personal information for a purpose this policy does not describe, it will identify the new purpose and, unless the new purpose is required by law, obtain the consent of the individual concerned.