WarmLoop Privacy Policy
In brief
This summary points to the sections below, which give the detail.
- WarmLoop Ltd. is responsible for the personal information described in this policy. Its Privacy Officer can be reached at privacy@warmloop.com or by mail at 2100 Scarth Street, Regina, Saskatchewan S4P 2H6. See section 2.
- For each person who uses the Service, WarmLoop keeps account and sign-in details, device and usage records, a record of each acceptance of the Terms of Service, and an audit log. See section 3.
- In an organization account, the organization's owner and administrators see the email address, role and status of each of its users and the invitations they have sent, and WarmLoop keeps a record of each invitation and each change. See section 3.
- When an organization certifies that it holds the rights to a collection of licensed documents, WarmLoop keeps a record of the certification, including who made it, the name typed, the time and the network address. On a licensor's written request, WarmLoop may tell it which organizations have access to its collection and on what basis, who certified, how many users are covered and how many times each document was served each month, but never query text, users' email addresses or anything about an organization's matters. See sections 3 and 13.
- Once WarmLoop opens its suggestion form at https://warmloop.com/suggest, anyone may suggest or request a document, or consent to WarmLoop's use of one, through it. WarmLoop keeps what is submitted, scans every file in isolation, and deletes an unverified submission after 7 days, one it has not decided after 90 days, and most of a decided one 30 days after the decision. See sections 9 and 14.
- The text of each research query is stored with the identifier of the user who sent it. It is deleted from the query log 30 days after it is recorded, and query text recorded up to September 28, 2026 can remain for about 12 months more in encrypted backups. The text of some searches also appears in the request logs of WarmLoop's corpus server, which are deleted within 12 months. See sections 4 and 14.
- WarmLoop does not use the text of your research queries to develop the Service, does not send it to an artificial-intelligence tool outside Canada, and does not use your content to train artificial-intelligence models. See section 4.
- For Records, WarmLoop keeps what the publishing Customer uploads, the readers it names, and a log of each view and each attempt to open a Record, with the email address entered or proven where there is one, the network address and the browser identification. That log, and the records of one-time codes and access requests, are deleted 6 months after the Record is erased, which for a Record deleted on the Records page is 30 days after its deletion. See section 5.
- The Service runs on WarmLoop's own server in Saskatchewan and in Amazon Web Services' Canadian regions. Some service providers, for payments, sign-in, delivery of the website, code hosting, WarmLoop's mailboxes and its development tools, process information in locations WarmLoop does not control, some of them outside Canada, including in the United States. See section 11.
- Your own AI assistant's vendor receives every query you send and every result the Service returns. See section 12.
- WarmLoop does not sell personal information or use it for advertising, and it makes no personal information of its users available to Phillips & Co. or to any other related organization, other than what any Customer receives about its own account and its own Records. See section 13.
- You may ask for access to your personal information and for its correction, and you may complain to the Privacy Commissioner of Canada. See sections 17 and 19.
1. About this policy
This policy describes how WarmLoop Ltd. ("WarmLoop"), a corporation incorporated under the Canada Business Corporations Act with its registered office at 2100 Scarth Street, Regina, Saskatchewan S4P 2H6, collects, uses, discloses and keeps personal information in connection with:
- the WarmLoop legal research and verification service at https://mcp.warmloop.com, which a user reaches through an artificial-intelligence assistant of the user's own choosing, and the service's sign-in and account pages at https://account.warmloop.com;
- the hosted records service at https://record.warmloop.com, through which a Customer publishes a document it has written, with the exhibits it cites, to readers it chooses (a "Record"); and
- the website at https://warmloop.com, which is also reached at warmloop.ca, including, once WarmLoop opens it, the form at https://warmloop.com/suggest through which a person suggests or requests a document or consents to WarmLoop's use of one, and the intake service at https://intake.warmloop.com that receives what the form sends (a "submission").
In this policy, "the Service" means the research service and the records service together, as the Terms of Service define it. A "Customer" is the law firm, legal department, business or government body that subscribes to the Service, and an "Authorized User" is an individual a Customer permits to use the Service under one of its accounts. An individual account has one Authorized User. An organization account has several, each in a seat, and is managed by its owner and its administrators, as the Terms of Service describe in section 6. This policy does not cover any other WarmLoop product, and it does not cover the AI assistant you use, which its own vendor's terms and policies govern.
This policy is written for Authorized Users, for people who are invited to an organization account, for people who read a Record or ask for access to one, for visitors to the website, for people who make a submission, and for people whose personal information appears in the court decisions and legislation WarmLoop holds or in material a Customer sends to the Service. The Service is sold only for business, professional or governmental use. It is not offered to individuals for personal use, and it is not directed to children.
This policy is WarmLoop's notice, under privacy law, of how it handles personal information. It describes WarmLoop's practices. It is not a contract and does not form part of the Terms of Service. WarmLoop's contractual commitments to its Customers about their content and data are in the Terms of Service at https://warmloop.com/terms, principally in section 10 (data), section 3 (Records), section 20 (confidentiality), section 27 (rights materials) and section 28 (submissions). Section 8 of this policy lists the email messages the Service sends, and the page at https://warmloop.com/email describes them.
WarmLoop handles personal information in accordance with the Personal Information Protection and Electronic Documents Act, which governs the personal information WarmLoop collects, uses and discloses in the course of its commercial activities.
A Customer that sends WarmLoop personal information about its own clients or about other people, in a query, a Record or an exhibit, remains responsible for that information under privacy law, and WarmLoop processes it on the Customer's behalf and on its instructions. The Customer remains responsible for its own obligations in collecting that information and in sending it to WarmLoop.
2. The Privacy Officer
WarmLoop is responsible for the personal information under its control, including information it transfers to a service provider for processing. It has designated a Privacy Officer who is accountable for WarmLoop's compliance with the privacy principles of the Personal Information Protection and Electronic Documents Act, and to whom questions, requests and complaints can be sent:
Privacy Officer, WarmLoop Ltd.
Email: privacy@warmloop.com
Mail: 2100 Scarth Street, Regina, Saskatchewan S4P 2H6
The name of the individual currently designated as Privacy Officer is available on request. Questions about the Service that do not concern personal information go to info@warmloop.com.
3. Information about Authorized Users and accounts
WarmLoop uses the information in this section to create and secure accounts, to let an organization manage its account and its Authorized Users, to record certifications of rights, to sign users in, to apply the device rules and usage limits, to record acceptance of the Terms of Service, to bill, to provide support, and to investigate faults and misuse.
Sign-in and account details
An account is created the first time an approved person signs in. WarmLoop keeps the email address, the display name, the sign-in method used (Google, Microsoft, or email and password), the identifier the sign-in provider assigns, when the account was created, whether it has been disabled, and any further sign-in methods linked to it. An account is named with the email address of the person who created it, and the owner or an administrator of an organization account may give the organization account another name.
Sign-in with email and password, and the connection to Google sign-in, are handled by Amazon Cognito in Amazon Web Services' Canada (Central) region. Amazon Cognito keeps a sign-in record, with the email address, for each person who signs up that way, including a person whose sign-up WarmLoop then refuses because the email address is not approved. A Google sign-in is processed by Google, and a Microsoft sign-in (work, school or personal Microsoft account) is processed by Microsoft; each confirms to WarmLoop who you are.
After a Google sign-in, and after a Microsoft sign-in that does not show that a second factor was used, WarmLoop's system emails a six-digit code to the account's email address, and the sign-in completes only when that code is entered, in the same browser, within 10 minutes. WarmLoop keeps a record of each such code, with the account, the sign-in provider, a one-way hash of the code and of a token held in the browser, the number of codes sent and of attempts made, and the times. Each time it sends a code, it deletes the records of codes made more than a day before. After 5 wrong codes, the Service stops sending and accepting codes for the account for 15 minutes, and after every 3 more wrong codes it does so again, for longer each time, up to 24 hours at a time, and 7 days without a wrong code start this again from the beginning; WarmLoop keeps a count of the account's wrong codes and pauses for that purpose, and its system emails WarmLoop's operator, with the account's identifier, its email address partly hidden and the sign-in provider, when an account is paused for the second time and when it is first paused for 24 hours.
Until WarmLoop opens sign-up more widely, it approves email addresses or email domains before an account can be created. It keeps its approvals of email addresses, with its notes on them, and it records whether an account is provided without charge. An invitation to an organization account (below) is an approval of the invited email address.
Organization accounts and invitations
For an organization account, WarmLoop keeps the account's name and kind, the role of each of its Authorized Users (owner, administrator or member), when each joined and whether each has been removed, the number of seats, and any email domains WarmLoop has recorded for the organization.
When the owner or an administrator invites a person, WarmLoop keeps the invited email address, the role offered, who sent the invitation, when it was sent, resent, accepted or revoked, when it expires, and which account accepted it. Its database keeps only a one-way hash of the link in the invitation, although the link can appear in the logs of requests described below. WarmLoop's system emails the invitation to the invited address, naming the person who sent it and the organization. If the invited person uses the link in the invitation to stop further invitations, WarmLoop records that address, with the date and the invitation, and refuses any later invitation to it (section 14).
The owner and the administrators of an organization account can see, in the account portal, the email address, role, date joined and status of each of its Authorized Users, the invitations that are pending, and the account's seats and subscription, and they may see the usage counts described below for each of its Authorized Users. Every Authorized User of an organization account can list the account's Records and their readers through the Service. On the Records page of the Service the owner and the administrators see every Record of the account, and a member sees only the Records he or she published (section 5).
When a person with an individual account joins an organization account, the account moves to the organization. The Records published under the individual account stay with it, and the person can no longer list or manage them through the Service.
Certifications of rights
Some documents WarmLoop holds are licensed by their publishers, and an organization's owner or an administrator may certify that the organization holds the rights to read them (Terms of Service, section 27). For each certification WarmLoop keeps the collection and the documents it contains when the certification is made, the legal name of the organization given, the text and version of the statement accepted and a hash of that text, the certifier's account, whether the certifier acted as owner or administrator, and the name the certifier typed, the Authorized Users it covers, any licence reference and any evidence of the rights given with it, the time, and the network address and browser identification from which it was made, together with each later change, suspension or revocation and the reason given. It emails the certifier, and the owner where the certifier is an administrator, a confirmation with the statement, the provisions of the Terms of Service that govern it and a link to revoke the certification. The owner and the administrators of the organization account can see the organization's certifications. When WarmLoop accepts evidence of rights, it is scanned for malware, is kept encrypted in Amazon Web Services' Canada (Central) region, and can be seen at WarmLoop only by the individuals who administer the Service. WarmLoop also keeps a record of each grant of access it makes to an account or a user, with a note of the reason.
The Service's sign-in and account pages accept requests only from Canada or from the network addresses WarmLoop uses to administer the Service, and limit the number of requests from any one address. Requests to the Service, to Records and to the sign-in pages pass through web application firewalls that WarmLoop runs in Amazon Web Services' Canada (Central) region, and requests to the Service and to Records also pass through a load balancer there. A firewall refuses a request that does not meet WarmLoop's rules, such as a request to the sign-in or account pages from outside Canada, and WarmLoop keeps a log of each refused request, with the network address and its country, the page requested without its query string, the request's headers other than cookies and credentials, and the time, for 30 days. When WarmLoop tests a new firewall rule, the firewall also logs each request that the rule would have refused but let through, with the same details as a refused request, and that log is deleted after 30 days. Records can be opened only from network addresses WarmLoop has approved, and WarmLoop keeps the list of approved addresses. A request to a Record from any other address is refused. WarmLoop's system keeps a list of the addresses it refuses, with the site and page requested and the times, in memory for up to 24 hours, so that WarmLoop can recognize and approve an address it expects; the list is lost when the system restarts.
When an account is created, when a sign-up is refused because the email address is not approved, and when an email address already in use signs in through a different sign-in provider, WarmLoop's system emails WarmLoop's operator the person's email address and sign-in provider, and records the event in the audit log.
Devices and connections
Each connection of an AI assistant to the Service is a device. For each one, WarmLoop records the name and identifier the assistant's software registered, when the connection was made, when it last obtained access and last made a request, whether and why it was disconnected, and the version of any setup files installed through it. It also keeps a record of each authorization attempt, with the connecting software and the user. WarmLoop detects, from each connection, the name and version of the AI assistant software, uses it to give setup instructions suited to that software, and records the software and platform detected when setup is run.
Acceptance of the Terms
Each time an Authorized User accepts a version of the Terms of Service, WarmLoop records the user, the version, the time and the network address from which it was accepted.
Usage counts
WarmLoop counts, for each user, tool and day, the requests made, the errors returned and the full documents retrieved, and on its corpus server it counts searches, reranking work and documents retrieved for each user and day. These counts contain no query text. WarmLoop uses them to apply usage limits and to monitor the Service. An hourly count of requests, used to apply the hourly limit, is deleted after 6 hours.
The audit log
WarmLoop keeps an administrative audit log of events on the platform. It records account creation (with the email address, sign-in provider and provider identifier), refused sign-ups (with the email address, sign-in provider and provider identifier), linked sign-in methods, whether each Google or Microsoft sign-in showed that a second factor was used, each emailed sign-in code sent, sent again or that could not be sent, entered correctly or wrongly, expired or refused, and each pause of an account's codes (with the sign-in provider), approvals of email addresses and their withdrawal, accounts disabled or enabled (with the email address), changes to the list of approved network addresses, devices connected, disconnected or refused under the device limit, requests refused for exceeding a limit (with the network address, where the refusal was at the registration or sign-in endpoint), setup runs (with the assistant software and platform detected and the setup option chosen), the version of guidance served, changes in subscription status, invitations to an organization account sent, resent, revoked and accepted, changes of an Authorized User's role, removals, changes in the number of seats and of an organization account's name, certifications made, changed, suspended and revoked, grants of access to rights material, and Record events such as publication, readers added or removed through WarmLoop's operator console, which can do so only for the Records of the operator's own account (with the reader's email address), malware found in an upload, and the deletion, restoration and erasure of a Record. WarmLoop uses it for security and to establish what happened on the platform.
Cookies on the account pages
The Service's sign-in and account pages at https://account.warmloop.com set a cookie that keeps you signed in to those pages for up to 30 minutes, and cookies that hold the state of a sign-in while it completes, for up to 10 minutes, or for up to 30 minutes while an emailed sign-in code is awaited. A Record sets the access cookie described in section 5.
Server and network logs
The research service's web application records a line for each web request it receives, with the method and the address requested, including part or all of any query string in that address, but without the codes, tokens and email addresses that the Service's links and sign-in steps carry in an address. The content of the requests your assistant makes to the Service's tools is not in those lines. The corpus server keeps request logs too, which section 4 describes. Server logs are held on the servers that write them, in Canada. WarmLoop has set no period after which the web application's logs are deleted; the corpus server's request logs are deleted within 12 months (section 4).
WarmLoop's web server also keeps an access log of each request to the Service and to Records, with the time, the network address, the address requested with its query string, the request's headers other than cookies, credentials and the address of the previous page, and the response's status, size and headers other than cookies and the address to which it redirects. The codes, tokens and email addresses that the Service's links and sign-in steps carry in an address, and the words searched for on the Records page, are removed from the address before it is logged. In entries written before that change took effect on September 28, 2026, only the codes and state values that a sign-in passes were removed, and the address of the previous page and of a redirect were kept, so those entries could hold the one-time code and email address in the link sent to a Record's reader (section 5), the link in an invitation to an organization account, and other codes and tokens; all of them were deleted on September 28, 2026. That log is held on the web server, in Canada, and each entry in it is deleted within about a month of being written.
WarmLoop's web database keeps a log of its errors, which can include the text of a database instruction that failed and, in rare cases, a value such as an email address, with the time and the database account. That log is stored in Amazon Web Services' Canada (Central) region, encrypted, and is deleted after 14 days.
WarmLoop's network in Amazon Web Services keeps a record of each connection that its firewall rules refuse, with the network addresses and ports at each end, the protocol, the number of packets and bytes, and the times, but no content. Those records are stored in Amazon Web Services' Canada (Central) region, encrypted, and are deleted after 30 days.
4. Research queries and results
When you search or research through the Service, WarmLoop stores the text of each search or research query ("query text") with the identifier of the Authorized User who sent it and of the assistant software registration it came through, together with the time, the surface used, the kind of search, and operational measurements such as the number of results and how long the search took. This query log is kept on WarmLoop's own server in Saskatchewan. WarmLoop uses it to operate and monitor the Service, including its speed and reliability, and to investigate faults and misuse.
Query text is deleted from the query log 30 days after it is recorded, by a deletion that runs daily. WarmLoop stopped copying the query log into its backups on September 28, 2026, and query text recorded up to that day can remain for a further period, of about 12 months, in WarmLoop's encrypted backups (section 14).
The text of some searches also appears in the request logs of WarmLoop's corpus server. That server records the address of each request it receives. Up to September 28, 2026 it recorded the whole address: for some kinds of search that address includes the search text, and for a citation lookup or a document request it includes the citation looked up and any passage sent to be located in a decision. Since then it records the address without its query string, which keeps the citation looked up or the document requested but leaves out the search text and any passage. A citation looked up and a passage sent to be located are not query text. Those request logs are deleted no later than 12 months after they are written, so the query text and the citations and passages in them are not deleted at 30 days, but are deleted within 12 months, except so far as section 14 requires WarmLoop to keep them because of a request for access.
Where a citation you look up resolves to a decision WarmLoop holds, the form of the citation you sent may be kept as a permanent alias for that decision, so that the same form is recognized in future.
To rank results, the text of each search or research query, with the candidate passages, is sent to a reranking model (Cohere Rerank) hosted by Amazon Web Services in its Canada (Central) region. The query is converted into a search vector on WarmLoop's own server, and that step sends nothing outside it.
WarmLoop does not keep a copy of the results the Service returns to you, beyond the counts and measurements described in this policy, except for a short time in one case: so that your assistant can read the full answer to a citation check page by page, the Service may hold that answer, including the quotations and propositions your assistant sent with the check, in its working memory for up to 30 minutes from the check. That answer is never written to storage, can be read only by the user whose assistant made the check, and is discarded when the 30 minutes end or the Service restarts.
WarmLoop does not use your content to train or fine-tune artificial-intelligence models, and it does not use your query text to develop the Service or send it to an artificial-intelligence tool outside Canada. Where WarmLoop records a detailed trace of a search for the purpose of improving retrieval, it does so only for its own development accounts, which are not Customer accounts. Feedback you choose to send is used as section 6 describes.
Two things keep that promise. First, the Service sends query text to no artificial-intelligence model other than the reranking model in Canada, and the features that could send a request to such a model when a user asks for it are switched off. Second, WarmLoop's development tools run on WarmLoop's own computers and servers, including the corpus server that holds the query log and the request logs, and send what they read to Anthropic's Claude, which is hosted outside Canada (section 11), so WarmLoop's rule for its own development work is that those tools are not used to read a Customer's query text, whether in the query log, in the request logs or in a backup. That rule is kept by WarmLoop's own practice, not by a technical control.
Queries often concern a Customer's matters and can contain personal information about its clients or about other people. That information is the Customer's responsibility, as section 1 explains.
5. Records
What the publishing Customer provides
When an Authorized User publishes a Record, WarmLoop stores the source text of the document for every version, the verified document built from it and the results of verification, each exhibit as uploaded and a viewing copy made from it, the matter reference and title, and the readers named for it by its author, by the owner of the account under which it was published or, for an organization account, by one of its administrators. Readers are named by email address, by email domain, or by reference to WarmLoop's list of court email domains. An exhibit is stored once for the Customer's account and can be reused by later Records of that account.
Each new exhibit is scanned for malware on WarmLoop's own systems before it is processed. An infected upload is deleted and the author is told; the deleted copy stays in the Record store for 90 days, as "Keeping and removing Records" below describes.
Exhibits are kept in WarmLoop's Record store, and the rest of a Record in WarmLoop's web database, both in Amazon Web Services' Canada (Central) region and both encrypted. Public access to the Record store is blocked, and every read passes through WarmLoop's access-controlled viewer.
Records often contain personal information about clients, witnesses and other people. The Customer that publishes a Record decides what it contains and who may read it, and is responsible for having the right to publish it. WarmLoop does not review, approve or endorse a Record, and it accesses a Record's content only so far as is needed to operate, secure, support and troubleshoot the Service, to act on a notice of the kind described at the end of this section, or where the law requires. The checks it runs are mechanical, for example that cited cases resolve and that quoted passages are located where the document says they are.
Publications that are not completed
WarmLoop also stores the source text submitted to start a publication. The source text of a trial run is deleted about 2 hours after it is sent, and a publication plan that is never carried out is deleted about 2 hours after it is made, together with any upload that was not completed. Where a publication fails, or stops short of publishing because the checks found a problem, WarmLoop keeps the source text submitted for it and the exhibits already uploaded for it, other than an infected one, with no set period, although nothing was published. The planned title and matter reference of a Record that was never published are kept with no set period.
Readers
A Record is restricted by default. A reader proves control of an email address named for the Record, or one within an email domain named for it, by entering a one-time code sent to that address, or by following the link sent with it. The code expires 10 minutes after it is sent and works once, and WarmLoop's database stores only a one-way hash of it. The link sent with the code carries the code and the email address. The web server's access log no longer records either, and the entries that held both for a visit made through the link before September 28, 2026 were deleted that day (section 3). Once the code is accepted, the reader's browser receives a signed cookie for that Record, which lasts 90 days from the code, unless the reader signs out of the Record sooner, and is not extended by later visits. The reader's access is checked again on each view, so a revoked reader loses access within about a minute. A reader's access carries over to new versions of the Record and lasts until it is revoked. A reader other than the Record's author sees only the current version.
The access page tells a reader, below the form in which the email address is entered, and again where a reader who is not on the list can ask for access, that WarmLoop records the email address entered, with the reader's network address, browser and the time, to control access to the Record, and that the publishing Customer can see who read it, with a link to this policy. The email that carries the one-time code says the same. While WarmLoop restricts Records to approved network addresses, as it does at the date of this policy, a reader can open a Record, whether restricted or public, only from a network address WarmLoop has approved (section 3). A reader who cannot open a Record for that reason may ask the Customer that published it, or WarmLoop at info@warmloop.com, to have the address approved.
A person without access may ask for it on the Record's access page. The request, with the requester's email address and the Record's title, is stored and emailed to the Record's author, or to a WarmLoop address if no author address is found. The author, the owner of the account and, for an organization account, its administrators may approve or refuse it, and if it is approved the requester is told by email.
Exhibits a reader opens may be kept in that reader's own browser cache for up to 90 days.
Public Records
The owner of the account under which a Record was published or, for an organization account, one of its administrators may make it public, so that anyone with its address can read it and every exhibit it cites, with no email gate, subject to the network-address restriction described above while it applies. WarmLoop still records each view of a public Record, with the viewer's network address and browser identification, but not the viewer's identity. Returning a Record to restricted access does not recall a copy made while it was public. Every Record, public or restricted, carries an instruction to search engines not to index it.
The access log
For each Record, WarmLoop keeps a log of views, of each exhibit opened, of one-time codes sent, accepted and failed, of attempts to open the Record, including by an email address that is not on its list of readers, of access requests and the decisions on them, of readers added and revoked, and of changes between restricted and public access. Each entry records the time and, where they are available, an email address, a network address and a browser identification, and an entry for a view records the version viewed. WarmLoop also keeps a record of each change between restricted and public access, with the Authorized User who made it and the reason given.
The access log is part of the Record's audit trail and is available to the Customer. The Customer can list its latest entries, with readers' email addresses and network addresses, through its own AI assistant, whose vendor then receives them (section 12).
Keeping and removing Records
A Record and each hosted document is kept until it is removed, and does not expire on its own. On the Records page of the Service, the owner and the administrators of an organization account may delete any Record of the account, and an Authorized User may delete a Record he or she published. From the moment a Record is deleted no one can read it, and 30 days later its text, the exhibits it cites that no other Record of the account cites, and its list of readers are erased; until then WarmLoop restores it, with its readers, as a restricted Record, at the written request of the owner of the account. A Customer may also ask for removal at info@warmloop.com, and WarmLoop acts on the request within 30 days, except so far as it must keep information by law. Removal does not recall a copy a reader has already made.
A Record's access log, the records of the one-time codes sent to its readers and the requests made for access to it are kept while the Record is kept and for 6 months after it is erased, and are then deleted. The record of each change between restricted and public access, and the audit entries for a Record, are kept as section 14 describes. When a Record is erased, WarmLoop keeps a record of it that holds none of its content: the Record's identifier, its account, its author's identifier, its address, its dates and the one-way hashes of what was erased. Copies of the Record's database entries, including the source text of the document, remain in WarmLoop's encrypted database backups for up to about 120 days after they are deleted. When an exhibit, or the viewing copy made from it, is deleted or replaced, including an infected upload, an exhibit removed at a Customer's request and an exhibit erased with a deleted Record, the Record store keeps the earlier copy for 90 days, encrypted, served to no one and open only to the individuals who administer the Service for WarmLoop, and then deletes it.
If a Record contains your personal information, a request for access or correction should be directed to the Customer that published it, and WarmLoop will assist that Customer in responding. A request about what WarmLoop records when you open a Record or ask for access to one goes to the Privacy Officer (section 17). WarmLoop may restrict access to a Record on receiving a notice that credibly asserts that it breaches the publishing Customer's obligations under the Terms of Service (for example a publication ban, a sealing order, a confidentiality obligation or privacy law), infringes someone's rights, or breaches an order of a court or tribunal.
When two accounts are merged
If an account is merged into another at the written request of the owners of both accounts (Terms of Service, clause 6.12), its Records, their reader lists, the requests made for access to them and their access logs are then held by the receiving account, whose owner and administrators can see them. The files the Records cite stay where they were stored and are still served with them.
6. Feedback
You can send feedback about the Service through your assistant. Your assistant is instructed to send feedback only when you ask it to and have approved the text, and to leave out client and party names, court file numbers and confidential facts, but WarmLoop cannot check that it has done so.
WarmLoop stores feedback on its own server in Saskatchewan, as it was sent, with your user identifier, the assistant software registration and platform it came from, and the version of the setup files. WarmLoop's review of an item may be recorded with it. WarmLoop does not remove identifying detail from the feedback it stores.
Feedback is kept indefinitely. WarmLoop reviews it and uses it to evaluate and improve the retrieval quality of the Service, including by deriving test queries from it. WarmLoop reviews feedback, as it was sent, using artificial-intelligence development tools that run on WarmLoop's own computers and servers and send what they read to Anthropic's Claude, which is hosted outside Canada (section 11). Summaries of feedback, WarmLoop's records of its review, and test queries derived from feedback are kept in private code repositories hosted by GitHub.
Do not put client-confidential or privileged information in feedback. Sending feedback is optional.
7. Billing
When a Customer subscribes, payment is taken on Stripe's payment page. Card details are entered there and held by Stripe; they do not reach WarmLoop's systems, and WarmLoop never receives or keeps a card's number, expiry date or security code. Stripe's payment page may ask for the card's country and postal code, which Stripe collects under its own policy.
Before Stripe's payment page, the owner or an administrator gives the billing name and address on WarmLoop's own page. WarmLoop keeps them in its own database, uses the province or territory of the address to choose the tax charged, and does not give the address to Stripe. To change that name or address, the Customer writes to info@warmloop.com.
WarmLoop gives Stripe the account's email address, the billing name and WarmLoop's identifier for the account, and, for each payment, the amount as lines (the seats and each tax), WarmLoop's identifier for the charge and a fixed description.
WarmLoop records:
- the text of the authorization of automatic charges that was shown and accepted, with a hash of that text, who accepted it, when, and the version of the Terms of Service in force;
- Stripe's identifiers for the customer, the payment page, each payment, the saved card, a new card given on the Organization page and each refund, but never a card detail;
- each charge and each automatic attempt to make it, with its outcome, Stripe's decline and advice codes and the days of the further attempts; when a card's bank asked for the cardholder's confirmation, until when that payment is offered for confirmation and who opened it; and a record of each run of the renewal job, with counts only;
- each change of seats, with who made it, when, the seats and the amount charged or carried to the next charge;
- the invoices and credit notes WarmLoop issues, with the card's brand and last four digits as Stripe reports them, and the tax treatment of each invoice and the reason for it;
- the kind of purchaser the Customer declares and any written claim of exemption, and, for a band's certification (Terms of Service, clause 11.9), the band's legal name and number, the reserve, the billing name and address when the certification was accepted, the text, version and fingerprint of the declaration, the authorized officer's name, title and email address and the date of the declaration, who accepted it on the account and when, WarmLoop's check of it against its own list and the result, and WarmLoop's decisions;
- the status of the subscription, the number of seats billed, the end of the current billing period and the date from which any payment became overdue; and
- a nightly reconciliation of Stripe's balance, with amounts, fees and identifiers.
WarmLoop keeps a monthly export of its sales in its own books, which its accountant receives (section 13). On request, WarmLoop's operator sends a copy of an invoice of an account that has been joined to or merged into another by email to the person who was the owner of that account when the invoice was issued, at the address the invoice was issued to. Stripe processes what it receives under its own terms, in locations WarmLoop does not control.
8. Email the Service sends
The Service sends these messages about Records through Amazon Simple Email Service in Amazon Web Services' Canadian regions, from no-reply@mail.warmloop.com, each to one recipient, without attachments, as plain text with an HTML version:
- a one-time code and link to a person who asks to open a Record, with the notice described in section 5 and a link to this policy;
- an access request to the Record's author, or to a WarmLoop address if no author address is found, with the requester's email address and the Record's title;
- a notice to a requester whose request has been approved, with the Record's title;
- a notice to the publishing user that a Record has been published, with its matter reference, version and address, a link to the changes where there is an earlier version, and the publication's reference number;
- a notice to the publishing user that a publication needs attention or has failed, with its matter reference, the number of problems found or the reason for the failure, and the publication's reference number; and
- a notice to the owner of an organization account that an administrator or a member deleted one of its Records on the Records page, naming who deleted it, with the Record's title and address, the date of the deletion and the date on which the Record will be erased.
WarmLoop's system sends these messages about organization accounts, rights materials and submissions in the same way:
- an invitation to join an organization account, sent at the request of a named owner or administrator of that organization to the invited address, naming that person and the organization, with WarmLoop's name and mailing address, a link that expires after 7 days, and a way to stop further invitations to that address;
- a confirmation of a certification of rights, to the certifier and, where the certifier is an administrator, to the owner, with the statement accepted, the provisions of the Terms of Service that govern it and a link to revoke the certification;
- a link and a code, to a person who has made a submission, to verify the email address given, which expire after 48 hours;
- a confirmation of a verified submission, to the submitter, which for a consent includes a link to revoke it; and
- a message about a submission, to the submitter, where WarmLoop needs more information or has decided what to do with it.
WarmLoop's system sends these messages about billing in the same way, to the owner and the administrators of the account, each with a link to the invoice where there is one and none with an attachment or a card detail:
- a receipt when a subscription starts, and a receipt for each renewal;
- a notice that a payment did not go through, a last notice, and a notice that the subscription has ended; and
- a notice of a change of seats, of a cancellation and of its undoing, and of a new card given on the Organization page.
WarmLoop's system also emails, in the same way, the sign-in code described in section 3 to the account's email address, and emails WarmLoop's operator the account alerts described in section 3. Amazon Simple Email Service keeps a list of the addresses to which a message could not be delivered or whose recipient complained about a message, so that no further message is sent to them, and it tells WarmLoop's operator of each such event. WarmLoop uses the account email address to send legal, account, billing, security and service notices. WarmLoop sends no marketing email (section 15).
9. The website, and submissions made through it
Pages on warmloop.com load their fonts, styles and images from warmloop.com itself. They contain no analytics, advertising or tracking code. Except for the suggestion page described below, they contain no code that sets a cookie or stores information in your browser, and they make no request to another site. A link to another site loads nothing until you follow it. The suggestion page, when it is open, is the website's only form. To contact WarmLoop otherwise you use an email link, and your own email program sends the message.
The website is delivered by Cloudflare, which receives each request, including your network address, the page requested and your browser's identification, in order to deliver the page. Cloudflare processes that information in locations WarmLoop does not control. WarmLoop has turned on Cloudflare's logging feature for the website; what that feature records, and for how long, is set by Cloudflare.
Email you send to WarmLoop is held in WarmLoop's mailboxes, which are hosted by Microsoft 365, and is used to answer you.
The suggestion page
When the suggestion page at https://warmloop.com/suggest is open, it loads Cloudflare's Turnstile challenge from Cloudflare. Turnstile runs in your browser and collects information about your browser and device in order to tell a person from an automated program, and Cloudflare processes that information under its own terms, in locations WarmLoop does not control. To check the result, WarmLoop's intake service sends Cloudflare the response the challenge produced and may send your network address, and it keeps the result with the submission.
What WarmLoop keeps about a submission
A submission is sent to WarmLoop's intake service at https://intake.warmloop.com, on WarmLoop's web server in Amazon Web Services' Canada (Central) region. WarmLoop keeps the kind of submission; the name, email address, organization, and role and authority the submitter gives; the jurisdiction, the description of the document, the reason given and any addresses; for a consent, the scope chosen, and the version and text of the consent accepted with a hash of that text; the network address and browser identification from which the submission was sent; the result of the Turnstile check; the times the submission was made, verified and decided; and WarmLoop's decision, its notes, its check of the email domain of a consent and its countersignature. Files are kept in a separate storage area in Amazon Web Services' Canada (Central) region, encrypted, closed to public access and stored under random names.
How submitted files are handled
Nothing sent with a submission is scanned or read until the email address is verified (section 8). WarmLoop then treats each file as potentially harmful. It opens a file only inside an isolated environment on its web server that has no access to WarmLoop's other systems. There the file is checked for malware, any active content, such as scripts, is removed into a sanitized copy, or the file is turned into page images, and text is extracted from the sanitized copy and checked for hidden text and for instructions aimed at artificial-intelligence systems. The malware check may use Amazon Web Services' malware scanning or an open-source scanner run inside that environment. When WarmLoop enables it, the extracted text may also be sent to an artificial-intelligence model provided by Anthropic, which may process it outside Canada, only to classify whether it contains such instructions. That feature is off at the date of this policy. A person at WarmLoop reviews every submission before anything is done with it, and sees the extracted text and page images of the sanitized copy, never the file as it was sent.
An address given in a submission is stored as text and is not visited when it is submitted. If WarmLoop decides to obtain a document from it, WarmLoop fetches it later from the publisher's site, and the file goes through the same checks.
Submitted documents in the corpus
If WarmLoop adds a submitted document to the corpus, it keeps the sanitized copy with a record of where the document came from: the submission's identifier, the verified email address of the submitter and, for a consent, the consent. It keeps that copy only outside its write-once archive: on its own computers and its own server in Saskatchewan and, if it copies it to Amazon Web Services, only in encrypted storage in that provider's Canada (Central) region from which WarmLoop can delete it. It deletes the copy within 30 days after a consent under which it holds the copy is revoked or the rights holder demands its deletion in writing, and as an order of a court requires; a copy in its backups is deleted as section 14 describes. The Service serves the document with a label that names the organization that supplied it. A countersigned consent is kept as the record of WarmLoop's licence to use the document.
10. Personal information in court decisions and legislation
The Service searches and serves court and tribunal decisions and legislation. Decisions name parties, witnesses, lawyers, judges and others, and can contain other personal information about them.
WarmLoop acquires decisions as their sources publish them, including in anonymized form where the court or tribunal anonymized them. It keeps what it acquires in a write-once archive in Amazon Web Services' Canada (Central) region, from which it does not delete, and in further copies on its own server and backup drives. If a source later withdraws a decision or replaces it with an anonymized version, the copy WarmLoop acquired earlier remains in the archive. Where WarmLoop has identified a decision as one whose source withholds its text, for example because of a publication ban, the Service serves only information the source published about it, such as its style of cause, date and court, or nothing at all, and not its text.
WarmLoop collects, uses and discloses this information for one purpose: legal research and the verification of legal authority by the law firms, lawyers, legal departments, businesses and government bodies that use the Service. The Personal Information Protection and Electronic Documents Act, with the Regulations Specifying Publicly Available Information made under it, permits an organization to collect, use and disclose, without consent, personal information that appears in a record or document of a court or tribunal that is available to the public, where the collection, use and disclosure relate directly to the purpose for which the information appears there. WarmLoop relies on that permission for the corpus.
To prepare the Service's stored analysis of how decisions have been treated, WarmLoop processes the text of decisions with artificial-intelligence models, including Anthropic's Claude, hosted outside Canada. That work is done by WarmLoop in advance, never at a user's request. WarmLoop computes search vectors for decisions and legislation on its own server and on Amazon Web Services computing in Canada. This work uses the published decisions and legislation, not your content.
WarmLoop makes the corpus available through the Service to its users, and uses it to build and test the Service. It does not publish the corpus on the open web or make it available to search engines.
If you are named in a decision WarmLoop holds and have a question or a concern, write to the Privacy Officer.
11. Service providers, and where information is processed
WarmLoop remains responsible for personal information it transfers to a service provider for processing. These run in Canada:
- Amazon Web Services, in its Canadian regions (currently Canada (Central)), runs WarmLoop's web application and its database, with the database's log of errors (section 3), the Record store, the web database backups, Amazon Cognito (sign-in with email and password, and the connection to Google sign-in), Amazon Simple Email Service (outbound email), the reranking model that receives the text of each search or research query with candidate passages (section 4), the write-once archive of decisions and legislation (section 10), the evidence of rights given with a certification (section 3), the load balancer and the web application firewalls through which requests to the Service, to Records and to the sign-in pages pass, with the firewalls' logs of refused requests and of requests a rule under test would have refused, and the records of connections refused by WarmLoop's network there (section 3), and, once the suggestion page is open, the intake service, the storage of submitted files, the isolated environment in which they are checked and, where WarmLoop uses it, Amazon Web Services' malware scanning (section 9). It also holds the logs of WarmLoop's administrative sessions on its servers, and copies of the transcripts of WarmLoop's development work made on its web server up to September 24, 2026, which are deleted about 120 days after they were made. WarmLoop also uses Amazon Web Services computing in Canada to compute search vectors for the corpus.
- WarmLoop's own server in Saskatchewan holds the corpus and its search indexes, the query embedder, the query log, the corpus server's request logs, the usage counts kept on the corpus server, citation aliases and feedback, and backs them up.
WarmLoop's encrypted backup drives are rotated off its premises.
These providers process information in locations WarmLoop does not control:
- Stripe processes payments (section 7).
- Google processes a Google sign-in, for a user who chooses it.
- Microsoft processes a Microsoft sign-in, for a user who chooses it, and hosts WarmLoop's mailboxes through Microsoft 365, including email sent to privacy@warmloop.com and info@warmloop.com.
- Cloudflare delivers the website and provides the domain name service for warmloop.com, and, once the suggestion page is open, provides the Turnstile challenge on it (section 9). Cloudflare also delivers the setup files your assistant downloads during WarmLoop's guided setup, and WarmLoop's signed release record against which your assistant checks them, and receives each of those requests, including the network address it came from. Other requests to the Service, and requests to Records, do not pass through Cloudflare.
- GitHub hosts WarmLoop's private code repositories, including summaries of feedback, WarmLoop's records of its review of feedback and test queries derived from feedback (section 6).
- Anthropic provides Claude, which WarmLoop's development tools use to develop and support the Service, including to review feedback (section 6), and which WarmLoop uses to prepare the stored analysis of decisions (section 10). Through those tools Anthropic processes feedback as it was sent and any other content WarmLoop examines in that work, which does not include a Customer's query text (section 4). The tools run on WarmLoop's own computers and servers, where Customers' content is held, and send what they read to Claude, which Anthropic hosts outside Canada. WarmLoop's standing practice is to run its sessions with those tools with Remote Control, a feature of Anthropic's Claude Code, turned on, so that a session can be followed from WarmLoop's other devices. While Remote Control is connected, the transcript of the session, including the messages, Claude's responses and the tools' activity, and so any content examined in the session, is stored on Anthropic's servers and kept as Anthropic's data-usage policy provides (section 14). When WarmLoop enables it, Anthropic also provides the model that classifies text extracted from submitted files (section 9); that feature is off at the date of this policy.
Some of these providers process information outside Canada, including in the United States. Information held outside Canada is subject to the laws of the country where it is held, and may be disclosed to that country's courts and authorities under those laws.
Before WarmLoop adds a service provider to whom a Customer's content, or personal information under WarmLoop's control, may be disclosed, it gives Customers notice as section 20 describes.
12. Your own AI assistant
Every query you send and every result the Service returns, including the full text of documents and the content of Records, passes through the artificial-intelligence assistant and the vendor you have chosen. That vendor handles them under your agreement with it and outside WarmLoop's control. It is not WarmLoop's service provider, and this policy does not govern what it does. If you choose WarmLoop's guided setup and your assistant has a remote-control feature, the setup asks you whether you want it on for WarmLoop sessions; it stays off unless you say on, and the instructions the setup adds to your assistant record your answer. That feature is your vendor's, and whether to use it is your choice. Your assistant reads the files on your computer itself, and WarmLoop does not receive them: it receives only what your assistant sends in a request to the Service, such as a search, a passage sent to be checked or a document you choose to publish as a Record. The method WarmLoop serves tells your assistant to read, for a piece of work, only inside the folder the work runs in and the other folders you name when the work starts, and not to list or search anything above or beside that folder. You are responsible for satisfying yourself that using that assistant is consistent with your own confidentiality and privacy obligations.
13. Other disclosures
Apart from its service providers, which receive information only as section 11 describes, WarmLoop discloses personal information only:
- to the users of the Service, the personal information that appears in the court and tribunal decisions and the legislation it serves, as section 10 describes;
- to the readers a Customer approves for a Record, and to the Customer, which has the access log of each of its Records (section 5);
- to the owner and the administrators of an organization account, the information about its Authorized Users, its invitations and its certifications that section 3 describes;
- to a licensor or other rights holder of a collection of licensed documents, only as clause 27.13 of the Terms of Service describes: on its written request, the Customer's name, whether and since when the Customer's account has had access to the collection and on what basis, the certifier's name, the number of Authorized Users covered, and the number of times each document was served under that account in each month, but no query or search text, no user's email address, no other user's name, no network address and nothing about the Customer's matters or clients; where the licensor alleges use beyond the licence, WarmLoop first tells the Customer and gives it 10 business days to respond;
- to the users of the Service, the name of the organization that supplied a submitted document, on the label served with it (section 9);
- to WarmLoop's professional advisers, who owe it a duty of confidence;
- to a successor to which WarmLoop assigns the Terms of Service, which takes the information on the same terms; Customers are given notice of the assignment, and individuals are told of it where the law requires;
- to a court or tribunal in a dispute between WarmLoop and a Customer, including a proceeding to collect fees;
- to a person who needs it because of an emergency that threatens an individual's life, health or security, in which case WarmLoop tells the individual where the law requires; and
- otherwise only where the law requires it, for example to comply with a subpoena, a warrant or an order of a court, or to report and give notice of a breach of its security safeguards as section 18 describes.
Where a lawful demand concerns a Customer's content, WarmLoop will tell the Customer, unless it is legally prevented from doing so, so that the Customer can assert privilege or object.
WarmLoop makes no personal information of its users available to Phillips & Co. or to any other related organization, other than what any Customer receives about its own account and its own Records. WarmLoop's owner also practises law with Phillips & Co., and his access to WarmLoop's data is on WarmLoop's behalf only. Phillips & Co. is a separate organization and a customer of WarmLoop. Acquisition work run for WarmLoop on Phillips & Co.'s server handles public legal materials and no information about WarmLoop's users.
WarmLoop does not sell personal information, and does not use it for advertising or share it with advertisers.
14. How long information is kept
- Query text (section 4) is deleted from the query log 30 days after it is recorded. Query text recorded up to September 28, 2026, when WarmLoop stopped copying the query log into its backups, can remain for a further period, of about 12 months, in WarmLoop's encrypted backups, on the schedule described below. The text of some searches, and the citations looked up and passages sent to be located, also appear in the corpus server's request logs, which are deleted within 12 months (section 4). A citation form kept as an alias is kept permanently.
- Account records, linked sign-in methods, approvals of email addresses for sign-up, the records of organization accounts, of invitations and of changes to Authorized Users, roles and seats, the records of certifications and grants, with any evidence of rights given with a certification, device and connection records, usage counts by user, tool and day, subscription records, terms acceptances, the administrative audit log, and, for each published Record, the record of each change between restricted and public access with the reason given for it, are kept for as long as WarmLoop operates the Service, and are not purged on a schedule.
- The list of email addresses to which further invitations to an organization account were stopped through the link in an invitation (section 3), with the date and the invitation, is kept for as long as WarmLoop operates the Service, so that an address that has been stopped stays stopped.
- For each published Record, its access log, the records of the one-time codes sent to its readers and the requests made for access to it are kept while the Record is kept and for 6 months after it is erased, and are then deleted.
- A Record, its versions and its exhibits are kept until they are removed (section 5). A Record deleted on the Records page is erased 30 days after its deletion, and the record of an erased Record, which holds none of its content, is kept for as long as WarmLoop operates the Service (section 5). When an exhibit, or its viewing copy, is deleted or replaced, the earlier copy is kept in the Record store for 90 days and then deleted (section 5). The source text of a trial run, and a publication plan that is never carried out, are deleted about 2 hours after they are made. The source text and exhibits of a publication that failed or stopped short of publishing, and the planned title and matter reference of a Record that was never published, are kept with no set period (section 5).
- Hourly request counts are deleted after 6 hours.
- The answer to a citation check that the Service holds so that it can be read page by page (section 4) is discarded no later than 30 minutes after the check.
- The record of each authorization attempt (section 3) is deleted about 31 days after the attempt is made.
- The counts kept on the corpus server for each user and day (section 3) are deleted 365 days after the day they count.
- The records of emailed sign-in codes (section 3) that are more than a day old are deleted each time a code is sent. The count of an account's wrong sign-in codes and pauses has no set deletion period.
- A submission whose email address is not verified is deleted, with its files, 7 days after it is made.
- A verified submission that WarmLoop has not decided within 90 days after it was made is deleted, with its files and the other details of the submission described in section 9.
- For a submission WarmLoop has decided, the files as sent, the sanitized copies, the extracted text and the page images kept for review are deleted 30 days after the decision, and so are the other details of the submission described in section 9, except those that follow.
- When a submission is deleted under the three items above, WarmLoop keeps a stub of it for as long as it operates the Service: the submission's identifier, kind, state and dates, the one-way hashes of its files and WarmLoop's decision, if there was one, but none of the personal details described in section 9.
- The record of a countersigned consent, and of its revocation, is kept for as long as WarmLoop operates the Service: the organization, the submitter's name, email address, and role and authority, the scope, the text of the consent and its hash, the network address and times, WarmLoop's check of the email domain and its countersignature.
- A submitted document WarmLoop adds to the corpus is kept, with the record of where it came from described in section 9, outside the write-once archive, until a consent under which WarmLoop holds it is revoked or the rights holder demands its deletion in writing, and WarmLoop then deletes it within 30 days; it is also deleted as an order of a court requires. A copy in backups is deleted as the backups that hold it age out (below).
- Feedback is kept indefinitely. Summaries of feedback, WarmLoop's records of its review and test queries derived from it are kept in WarmLoop's code repositories with no set period.
- Transcripts of WarmLoop's development and support work, which can contain feedback and any other content examined in that work (section 11), are kept on WarmLoop's own equipment in Canada, with no set deletion period. Copies of those made on WarmLoop's web server up to September 24, 2026 remain in Amazon Web Services until they are deleted, about 120 days after they were made; no copies have been saved there since. The transcripts of sessions run with Anthropic's Remote Control feature connected, which is WarmLoop's standing practice (section 11), are also stored on Anthropic's servers, in locations WarmLoop does not control, for as long as Anthropic's data-usage policy provides; WarmLoop does not set that period.
- WarmLoop has set no deletion period for email in its mailboxes, which include the account alerts and access requests described in sections 3 and 5 and email sent to WarmLoop.
- Server logs of the web application have no set deletion period. Each entry in the web server's access log is deleted within about a month of being written (section 3). The corpus server's request logs are deleted no later than 12 months after they are written (section 4). The list of network addresses refused by WarmLoop's own access check is kept in memory for up to 24 hours. The web application firewalls' logs of refused requests, and of requests a rule under test would have refused, are deleted after 30 days, and so are the records of connections refused by WarmLoop's network in Amazon Web Services (section 3). The web database's log of errors is deleted after 14 days (section 3).
- Detailed traces recorded for WarmLoop's own development accounts (section 4) have no set deletion period.
- WarmLoop has set no deletion period for Amazon Cognito's sign-in records or for the list Amazon Simple Email Service keeps of addresses that could not be reached or that complained. The logs of WarmLoop's administrative sessions on its servers are kept for 365 days.
- Court decisions and legislation are kept for as long as WarmLoop operates the Service, and the copies in the write-once archive are not deleted (section 10). Rights material (Terms of Service, section 27) and submitted copies are not kept in the write-once archive, and are deleted as clauses 27.8 and 28.9 of the Terms of Service provide.
- Records of breaches of security safeguards are kept for at least 24 months (section 18).
- The billing records described in section 7, including the invoices, the credit notes, the charges, the billing names and addresses and the records of tax treatment and of certifications, are kept for at least six years after the end of the year they relate to (for a certification, the year of the last invoice it supports), even after the account ends, and are not deleted with it.
Information deleted from a live system remains in backups until the backups that hold it age out. WarmLoop's web database, which holds account records, the audit log and the database entries and access logs of Records, has automated backups kept for 14 days and nightly copies kept for up to about 120 days. The database on WarmLoop's corpus server, which holds the query log, the usage counts kept there and feedback, is copied nightly, and the copies made after September 28, 2026 leave out the query log: the two most recent copies are kept, unencrypted, on the corpus server itself, and each copy is also saved to encrypted backup drives, which keep the latest copy for each of the last 7 days, the last 4 weeks and the last 12 months in which the drive was used. That schedule is what governs the "about 12 months" this policy gives for backups. It is applied to a drive when it is connected, so a drive kept off the premises, or connected less often than once a month, can hold a copy older than 12 months.
When a subscription ends, WarmLoop keeps what this section describes for the periods it gives.
Where personal information is the subject of a request for access, WarmLoop keeps it for as long as is necessary to allow the person who asked to exhaust any recourse they have under the Personal Information Protection and Electronic Documents Act, even if it would otherwise be deleted.
15. Consent and choices
Using the Service involves the collection and use of personal information described in sections 3 and 4, and subscribing involves that described in section 7. The Service needs that information in order to be provided, secured, supported and billed. The Terms of Service, which are shown for acceptance before an account is used, describe these uses in section 10 and refer to this policy.
These are optional, and WarmLoop does not require them as a condition of using the Service: sending feedback, publishing a Record, making a Record public, certifying rights, making a submission, and receiving marketing email.
A reader gives an email address in order to open a Record. WarmLoop uses it to send the one-time code and to control and log access to that Record, and it tells the reader so on the access page and in the email that carries the code (section 5).
You may withdraw your consent at any time, subject to legal and contractual restrictions and reasonable notice. If you withdraw consent to the collection and use the Service needs, WarmLoop can no longer provide the Service to you. You can stop sending feedback at any time, and you may ask for feedback you have sent to be deleted (section 17).
Accepting the Terms of Service is not consent to receive marketing messages. WarmLoop sends no marketing email. If it does in future, it will send it only to a person who has given a separate consent, which may be withdrawn at any time. Each such message will identify WarmLoop, give its mailing address and include a way to unsubscribe, and WarmLoop will give effect to an unsubscribe request within 10 business days, as Canada's Anti-Spam Legislation requires.
16. Safeguards
WarmLoop's safeguards include:
- encryption of connections to the Service and to Records, and an encrypted tunnel between WarmLoop's web application and its corpus server;
- encryption of the web database, the Record store, the web database backups and the backup drives that are rotated off WarmLoop's premises;
- sign-in through Amazon Cognito, Google or Microsoft, a limit on the number of connected devices, web application firewalls in front of the Service, access to the sign-in and account pages limited to Canada and to WarmLoop's own administrative addresses, with a limit on the number of requests from any one address, and, while WarmLoop applies that restriction, access to Records limited to approved network addresses;
- for Records, restricted access by default, one-time codes stored in WarmLoop's database only as a one-way hash, signed access cookies, a fresh check of each reader's access on every view, and malware scanning of new exhibits; and
- an operator console that only WarmLoop can use, from approved network addresses;
- for organization accounts, invitation links that expire after 7 days, work once and are stored in WarmLoop's database only as a one-way hash, and management pages open only to the owner and the administrators; and
- for submissions, no file scanned or read until the submitter's email address is verified, files kept encrypted and closed to public access, and every file opened only inside an isolated environment and reviewed only as a sanitized copy.
17. Access, correction and deletion
You may ask WarmLoop whether it holds personal information about you, what it has used it for and to whom it has disclosed it, and for access to it. Make the request in writing to the Privacy Officer (section 2). If you need help preparing a request, tell WarmLoop and it will help. WarmLoop may ask for information it needs to identify you and to find your information, and will use that information only for that purpose.
WarmLoop will respond within 30 days after it receives the request. It may extend that time by up to 30 more days where meeting it would unreasonably interfere with WarmLoop's activities, or where consultations needed to respond would make it impracticable, or for as long as is needed to convert the information into an alternative format. If it extends the time, it will tell you within the first 30 days, giving the new time limit, its reasons and your right to complain to the Privacy Commissioner of Canada about the extension. WarmLoop does not charge a fee for responding to a request. If you have a sensory disability, you may ask for the information in an alternative format.
WarmLoop may refuse access, in whole or in part, where the law requires or permits it to, for example where giving access would likely reveal personal information about someone else, or where the information is protected by solicitor-client or litigation privilege or would reveal confidential commercial information. Where the protected part can be separated, WarmLoop gives access to the rest. If WarmLoop refuses a request, it will tell you in writing, with its reasons and the recourse available to you.
WarmLoop relies on the details that you and your sign-in provider give it, and sends notices to the account email address, so keep that address current. You may challenge the accuracy and completeness of your personal information and have it corrected, completed or deleted as appropriate. Where appropriate, WarmLoop passes the correction to third parties that have access to the information. If a challenge is not resolved to your satisfaction, WarmLoop records it.
The Service has no self-service function to export or delete an account or its data. A request to delete personal information is made to the Privacy Officer, and WarmLoop will respond within 30 days, subject to what it must keep by law and to the records kept for the periods the second and fourth items of section 14 give, which clause 10.5 of the Terms of Service also states. Information deleted from a live system remains in backups until they age out. A request to remove a Record is made as section 5 describes.
If you read a Record or asked for access to one, what WarmLoop recorded about you when you did so is kept while the Record is kept and for 6 months after the Record is erased, as the fourth item of section 14 says, and a request to delete it is subject to that period, as clauses 10.5 and 10.10 of the Terms of Service also provide. Whether and when the Record is deleted or removed is for the Customer that published it to decide (section 5), and the 6 months run from the Record's erasure. You may ask the Privacy Officer for access to that information, and for its correction, at any time.
If your personal information is in material a Customer sent to the Service, such as a query or a Record, the Customer is responsible for it, and a request for access or correction should be directed to the Customer. WarmLoop will assist the Customer in responding.
18. Breaches of security safeguards
If a breach of WarmLoop's security safeguards involving personal information under its control creates a real risk of significant harm to an individual, WarmLoop will report it to the Privacy Commissioner of Canada and, unless the law prohibits it, notify the individual, in each case as soon as feasible after it determines that the breach has occurred. The notice to an individual is conspicuous and is given directly, except in the circumstances where the law requires indirect notice, such as a public announcement. It describes the circumstances of the breach, when it occurred, the personal information involved, the steps WarmLoop has taken to reduce the risk of harm, the steps the individual can take to reduce or mitigate that risk, and how to contact WarmLoop about it. WarmLoop will also notify the Customer where the information is in the Customer's content, and any other organization or government institution that WarmLoop believes may be able to reduce the risk of harm.
WarmLoop keeps a record of every breach of its security safeguards involving personal information under its control, whether or not the breach creates a real risk of significant harm, for at least 24 months after it determines that the breach occurred, and gives the Privacy Commissioner of Canada access to those records on request.
19. Questions and complaints
Send questions and complaints about WarmLoop's handling of personal information to the Privacy Officer (section 2). WarmLoop investigates every complaint, and where a complaint is justified it takes appropriate measures, including changing its policies and practices where necessary. It will tell you about the complaint procedures available to you.
You may also file a written complaint with the Privacy Commissioner of Canada: https://www.priv.gc.ca. A complaint arising from a refused access request must be filed within six months after the refusal, or after the time for responding to the request expired, or within any longer period the Commissioner allows.
20. Changes to this policy
WarmLoop may change this policy. The current version is published at https://warmloop.com/privacy, with its version identifier at the top, and earlier versions are available on request to the Privacy Officer.
Where a change materially reduces the protection given to a Customer's content or to personal information under WarmLoop's control, including the addition of a service provider to whom either may be disclosed, WarmLoop will give each Customer at least 30 days' notice by email to the account email address, and the change does not take effect against that Customer until the notice period has ended. A Customer may cancel before the change takes effect, and clause 13.4 of the Terms of Service provides for a refund of the unused part of a prepaid period. Other changes take effect when the new version is published.
Before WarmLoop uses personal information for a purpose this policy does not describe, it will identify the new purpose and, unless the new purpose is required by law, obtain the consent of the individual concerned.