إشعار الخصوصية
What we collect, and what we do not
HawkTel takes bookings for live consultations and seminars. This notice says what we keep when you use it, what happens inside a session, where your data sits, and how to have it erased. It is written to be checked.
Last updated 20 August 2026
In short
- We doKeep what you type into a form — a booking, a seminar registration, an account, the waitlist — and use it to run your session and to email you about it.
- We do notRecord sessions, keep room messages, run advertising or analytics trackers, sell your details, or send your audio to a third-party service.
- Where it sitsOn servers in Europe today, not in Canada. Section 6 says exactly what that means and what it does not.
- You canAsk what we hold, ask us to correct it, or ask us to erase it — and we will answer within thirty days, as the law requires.
1. Who is responsible for your information
HawkTel Innovative Solution, Toronto, Canada, is responsible for the personal information this service handles. Canada’s federal privacy law, the Personal Information Protection and Electronic Documents Act (PIPEDA), requires us to designate a person as accountable for that, and we have: the role of privacy officer is held by the founder. Reach them at [email protected] with “Privacy” in the subject line — that word routes the message to the accountable person rather than to general support.
2. What we collect, and why
We store what you type into a form, and nothing you did not type. Each form collects the least it can, and each item below exists for the one purpose stated next to it:
- A booking: your name, your email address, the language you will speak in the session, and — if you choose to write one — a note about your situation. The note is the most sensitive thing on this list. It exists so the expert can prepare, it goes to that expert and to nobody else outside our staff, and you can leave it empty.
- An instant call: your name, the language you will speak, and optionally your email address. The address does two things: it lets us find the call in your history, and it is how we recognise that you have used your free minutes with an expert before. Give none and you are treated as a new caller.
- A seminar registration: your name, your email address, and the language you speak.
- An account: your name, your email address, and a password. The password is stored only as a hash — we cannot read it. An account is optional: you can book a consultation or attend a seminar without one.
- The waitlist: your email address, and optionally your name, a language and a topic — so we can tell you when we open, and know which languages people need most.
- An expert application: the contact and credential details you give us, so we can start verification with you. We do not ask for a scan of your licence — we check the registration number against the public register instead, so we never hold the document.
- Technical logs: like any web service, the servers that run this site record ordinary logs of requests — network addresses, times, pages asked for. They exist to keep the service running and secure, and for nothing else. We are still fixing an exact retention period for them; this notice will state it once we have.
We use this information only for the purposes written above: running your session, telling you and the expert about it, and verifying experts. We do not sell it, rent it, or use it to build advertising profiles — of you or of anyone.
3. Consent, and email
When you type something into a form here, you are consenting to the purpose written on and around that form — the purposes in section 2. For the note on a booking, which can contain sensitive things in your own words, the consent is express: the form says who will read it, and writing it is your choice each time. You can withdraw consent by asking us to erase your information (section 10), subject to what we must keep — and we will tell you plainly if anything must be kept, and why.
Email, honestly stated: no email leaves our systems today. Sending is built but switched off. When it is switched on, the messages we send are about your own bookings, registrations, seminars and account — confirmations, notifications, password resets. Canada’s anti-spam law (CASL) governs commercial email; messages like these, which complete something you asked for, are not marketing, and we send no marketing email at all. The one exception you may have asked for: if you joined the waitlist, we will send you the launch announcement you signed up to receive. Every message we send says who we are and how to reach us, and if we ever send anything promotional it will carry a working unsubscribe. To leave the waitlist, write to us and we delete the entry.
4. Who else touches your information
Short list, stated in full:
- Our hosting provider (OVH) runs the machines the site, the database, the translation service and the media server live on. It stores everything in section 2 on our behalf. Where those machines are is section 6.
- Cloudflare operates the network layer in front of the site. Requests to hawktel.net pass through its systems in transit, which is what shields the site from attack traffic.
- The expert you book receives your name, the language you said you will speak, and the note you wrote — that is what the note is for. An expert does not receive your email address from us on the booking itself.
- Stripe — planned, not yet active. When payment is switched on, your card details will be entered on Stripe’s own page and never pass through our servers; we never see the number. Today payment is switched off and no page on this site takes a card at all.
Transcription and the call itself are not on this list, deliberately. The machine transcription and translation that produce the written record run on our own hardware, and the calls run through a media server we operate. Where you have both agreed to a record, your audio is processed on machines we run to produce it, and not kept. It does not leave our infrastructure to any third-party service.
Access on our side is limited to the people building HawkTel. Staff can see what the forms collected, and — until the retention pass in section 8 removes them — the contents of emails sent about you.
5. Inside a session
No audio is recorded. There is no audio or video recording feature anywhere in the product — not off by default, not present at all.
A consultation can produce a written record, and only if both of you agree to it in the room.You are each asked separately, and nothing is kept until the second person has said yes. Either of you can withdraw at any moment, and withdrawing deletes what was kept rather than merely stopping the rest — a record that outlived the consent it was collected under would not be consent-based at all.
The record is produced after the session ends, by machine transcription on our own hardware: the audio is processed to build it and not kept. Where a client spoke a supported language other than English, their side is also translated into English in the record. Nothing is transcribed or translated while the session runs.
The expert reads the record, may remove lines from it, and approves it before you receive it. It is kept for 90 daysfrom the session and then deleted. Seminars never produce one.
With no such agreement, nothing is transcribed at all: the session is a live call and no more, and when the room closes, nothing of what was said remains.
Written messages in a room exist only for the people in it, and only while it is open. In a seminar, a question you type goes to the presenter alone — never to the rest of the room.
Two things in a room do carry your name, and you should know them before you speak. The name you booked or registered with is your name in the room, visible to the people in it. And if the presenter gives you the floor in a seminar and you speak, the whole room hears you under that name — that is what asking a question in front of an audience means. Neither your words nor the name outlives the room.
6. Where your information is kept — outside Canada
Our servers are in Europe, not in Canada. The database, the email outbox, the translation service and the media server all run on machines rented from our hosting provider in a European datacentre. That means everything in section 2 — every booking, every registration, every account, and every note a client wrote about their situation — is stored and processed outside Canada today.
Canadian privacy law permits this, and we remain fully accountable under PIPEDA for your information wherever it sits. What the law does not permit is silence about it, so here is what it means: while your information is in another country, it is subject to that country’s laws, and it can be reached by that country’s courts, law enforcement and national security authorities under those laws. We cannot override that, and no contract can.
We intend to move this hosting to Canada. Until that has actually happened, the paragraphs above are the truth, and this section will be rewritten on the day it stops being true — not before, and not after.
One nuance for completeness: requests to the site pass through Cloudflare’s network, which operates globally, so data in transit crosses whatever borders sit between you and the servers. That is true of essentially every website, and it is distinct from where the data is stored, which is what this section is about.
7. How we protect it
Honestly stated — what exists, with no certification implied that nobody holds:
- Traffic to the site is encrypted in transit (HTTPS).
- Passwords are stored only as hashes, using a modern algorithm built for the purpose (Argon2). We cannot read your password.
- A password reset link is stored on our side only as a digest, so reading the database does not hand anyone a working way into an account — and the email quoting the link is itself emptied within ninety minutes (section 8).
- The administration panel answers on one hostname and returns the site’s ordinary “not found” page to a request on any other — including to somebody signed in without the role, because an error saying “you are not allowed” tells whoever asked that the panel is there. That is a barrier, not a secret: the hostname is a public DNS record and we do not treat it as one. Behind it, a signed-in administrator is required. Administrators cannot read passwords, and the ninety-minute rule in section 8 exists precisely so the panel does not become a way into other people’s accounts.
- Session rooms are controlled by tokens minted on our server for the specific person and the specific room; a consultation room holds two people and no more, enforced by the media server.
- Access to the servers and the database is limited to the people building HawkTel.
No security is absolute, and we do not claim ours is. What we claim is narrower and checkable: the design decisions above, plus the one that matters most — recordings of your sessions do not exist, because nothing records, and a written transcript exists only where both people asked for one, under section 5.
8. How long we keep it
Retention with real numbers, not adjectives:
- Room messages — never stored. They exist only in the room, only while it is open.
- Audio for the written record — not kept. Where both of you agreed to a record, audio is processed after the session to produce it, then gone. With no agreement, it is not processed at all.
- The written record — 90 days from the session, then deleted; withdrawal by either person deletes it sooner. Section 5 governs it.
- A delivered email’s contents — removed 30 days after delivery. A full copy of every message we send is stored in our outbox first, and that copy can contain personal data — your name, your address, and, in the message that tells an expert about your booking, the note you wrote. Thirty days after delivery the contents are removed. What stays is the record that it was sent: who it went to, its subject, and when — so that “was this person told?” remains answerable after the words themselves are gone.
- A password reset email’s contents — removed within 90 minutes. Its body is a working link into your account, so it is cleared after the link itself has expired (the link lasts 60 minutes) and long before anything else. The record that a reset was requested and sent stays.
- Bookings and registrations — kept as operating records, so that what happened remains answerable. The identifying details on them are removed on request — section 10.
- Your account — until you ask us to erase it.
- The waitlist — until HawkTel launches and we have contacted you, or until you ask us to delete your entry, whichever comes first.
- Technical logs — retention period being fixed; see section 2.
9. Seeing and correcting what we hold
You can ask what personal information we hold about you, how it is used, and who it has been disclosed to — and ask us to correct anything that is wrong. Email [email protected]. We will respond within thirty days, which is the deadline PIPEDA sets; the law allows a limited extension in defined cases, and if we ever need one we will tell you before the first thirty days end, not after. We will need to confirm the request comes from you — normally by answering to the email address we hold for you — because handing your information to somebody pretending to be you is the failure this check exists to prevent.
If we correct something, we correct it everywhere we hold it. If we disagree that it is wrong, we will record your view next to ours rather than silently keeping only ours.
10. Erasure — what deletion actually reaches
Email [email protected] and ask. For an account, erasure is a single operation that reaches every place the same person’s data sits:
- Your account is deleted.
- On your bookings, your name, your email address and your note are erased. The record that a session happened stays — a session that took place cannot be made not to have happened — but nothing on it identifies you any more.
- On your seminar registrations, your name and email address are erased the same way.
- The emails addressed to you, and the copies sent to an expert that quote you, are deleted outright.
- Any outstanding password reset links for the account die with it.
If you booked or called without an account, tell us the email address you used — or, if you gave none, the booking reference — and we erase the same fields on those records by hand. The reference is on your confirmation page; without either handle, a record with no name we can match cannot be found, which cuts both ways.
The waitlist is simpler: ask, and the entry is deleted outright.
11. If something goes wrong
If personal information is lost, stolen or wrongly exposed, and that creates a real risk of significant harm to you, PIPEDA requires us to report the breach to the Privacy Commissioner of Canada and to notify you — as soon as feasible, not at our convenience. We will do both, we will tell you plainly what happened and what we are doing about it, and we keep a record of every breach, including the ones below that threshold.
12. Cookies
Signing in sets the cookies needed to keep you signed in and to protect the forms you post — a session cookie and a cross-site-request token, nothing else from us. The network service in front of the site (Cloudflare) may set its own technical cookie to tell browsers apart from attack traffic. There are no advertising cookies, no analytics cookies, and no trackers — not “minimal”, none.
13. Children
This service is for adults; the terms of service require users to be 18. We do not knowingly collect information about children, and we do not collect dates of birth at all. If you believe a child’s information has ended up here, write to us and we will erase it.
14. How this notice changes
When this notice changes, the date at the top changes with it, and a change that matters — what we collect, who touches it, where it sits — is stated plainly on this page rather than buried in a revision. Section 6 in particular has a known reason to change: the day the servers move to Canada, it will be rewritten in the same deploy.
15. Complaints
Complain to us first if you are willing: [email protected], with “Privacy” in the subject line. You do not have to. You can complain at any time to the Office of the Privacy Commissioner of Canada, which oversees PIPEDA. If you are in Alberta or British Columbia, your province’s own private-sector privacy law may apply to you instead, overseen by that province’s Information and Privacy Commissioner; in Quebec, the private-sector privacy regime is overseen by the Commission d’accès à l’information. Complaining to a regulator costs nothing and does not require our permission.
Contact
HawkTel Innovative Solution, Toronto, Canada. [email protected]
The rules of using the service are in the terms of service. If you use the translation prototype on this site, the same promise in section 4 applies to it: processed on our own hardware, not stored, not sent to any third-party service.