Privacy Policy

Last updated: 30 July 2026

This policy explains what personal information we collect through enginely.ai, why we collect it, who we share it with, where it is stored, and how you can access, correct or delete it.

1. Who we are

Enginely and Enginely.ai are operating names of Reyas Solutions Inc., a company incorporated in Canada. In this policy, “we”, “us” and “Enginely” refer to Reyas Solutions Inc.

Registered address: 145 Hillcrest Avenue, Mississauga, Ontario L5B 3Z1, Canada
Privacy contact: privacy@enginely.ai
General enquiries: info@enginely.ai

We are responsible for the personal information under our control and comply with the federal Personal Information Protection and Electronic Documents Act (PIPEDA). Where we handle information about individuals in other jurisdictions, additional laws may apply and we address the main ones below.

2. Scope of this policy

This policy covers personal information collected through the enginely.ai website and through enquiries made to us by email or form. It also covers information we handle about our clients' staff in the course of providing services.

It does not cover personal information that our clients collect on their own websites and systems. Where we work on a client's website or accounts, that client remains responsible for their own privacy obligations, and we act on their instructions as a service provider.

3. Information we collect

Information you give us

When you request an audit or contact us, we collect:

  • First and last name
  • Email address
  • Website address of the organization you are asking about
  • The page you submitted from, so we know which service prompted the enquiry
  • Anything else you choose to include in an email or conversation with us

We do not ask for, and do not want, sensitive personal information through this site. Please do not send us health information, financial account details, government identifiers or confidential client material by web form or unencrypted email.

Information collected automatically

Like most websites, ours records limited technical information when you visit — including your IP address, browser and device type, referring page, the pages you view and the approximate region you are in. This comes from our analytics provider and our hosting provider's standard logs.

4. Why we collect it

We use personal information only for purposes a reasonable person would consider appropriate:

  • To prepare and send the audit or information you asked for
  • To respond to your enquiry and, if relevant, to discuss working together
  • To provide, support and improve our services under an agreement with your organization
  • To understand how the website is used, so we can improve it
  • To meet legal, accounting and regulatory obligations

We do not sell personal information. We do not share it with third parties for their own marketing purposes. We do not use it to make decisions about you by automated means alone.

For individuals in the European Economic Area or the United Kingdom, our lawful bases are consent (for marketing and non-essential analytics), performance of a contract (to deliver services you or your organization requested), and legitimate interests (to run and secure our business), balanced against your rights.

We rely on your consent to collect and use your information for the purposes described above. Submitting a form is an express indication of consent for us to respond and to send you the material you requested.

You can withdraw consent at any time, subject to legal or contractual restrictions and reasonable notice. Email privacy@enginely.ai and we will act on it. Withdrawing consent may mean we can no longer provide a service you have asked for; we will tell you if that is the case.

6. Cookies and analytics

Nothing optional loads until you agree. On your first visit we ask whether you are happy for us to use Google Analytics. Until you accept, no analytics script is downloaded, no request is made to Google and no analytics cookie is set. Declining takes one click and the site behaves identically either way.

Aside from analytics, the site uses one piece of local storage to remember your choice, a referral cookie set only if you arrive through an Enginely partner link, and one cookie set only for our own staff previewing unpublished articles. We do not use cookies for advertising, retargeting or cross-site tracking.

Our Cookie Policy lists every cookie and storage item by name, with its purpose and duration, and is the page we keep up to date when anything changes. You can review your analytics choice at any time.

7. Service providers

We use a small number of providers to run the website and our business. They may process personal information on our behalf, and only for the purpose we engaged them for:

Provider What they do for us Information involved
Attio Customer relationship management — where enquiries are recorded. Name, email, website, source page
Google Analytics Website measurement. IP address, device and usage data
Cloudflare Website hosting, content delivery and security. IP address, request logs
Sanity Content management for our articles. No visitor personal information

We may also disclose personal information where required by law, to enforce our agreements, or in connection with a corporate transaction — in which case the recipient would be bound to use it consistently with this policy. A current list of providers is available on request.

8. Storage and cross-border transfer

Your information may be stored or processed outside Canada, including in the United States. Our providers operate globally, and personal information held by an organization in another country is subject to the laws of that country, including lawful access requests by courts and government authorities there.

In addition, while client contracting, strategy and account management run through our Canadian practice, technical delivery and reporting are carried out by a dedicated global specialist team. That means personnel outside Canada may access information necessary to perform the work. We use contractual protections requiring comparable safeguards, and we limit access to what each person needs to do their job.

We say this plainly because PIPEDA requires it, and because organizations in regulated fields should be able to weigh it before engaging us.

9. How long we keep it

We keep personal information only as long as needed for the purpose it was collected, or as required by law:

  • Enquiries that do not become clients — kept in our CRM while there is a realistic prospect of working together, then deleted on request or during routine review
  • Client records — kept for the duration of the engagement and afterwards for as long as needed for legal, tax and accounting purposes
  • Analytics data — retained according to our analytics provider's configured retention period
  • Consent records — retained as required by CASL for marketing communications

You can ask us to delete your information at any time and we will do so unless we are required to keep it.

10. Safeguards

We protect personal information with safeguards appropriate to its sensitivity: encrypted connections (HTTPS) across the site, credentials and API keys held as server-side secrets and never exposed in the browser, access limited to people who need it, and reputable providers with their own security programmes.

No method of transmission or storage is completely secure. If a breach occurs that creates a real risk of significant harm, we will report it to the Office of the Privacy Commissioner of Canada and notify affected individuals as PIPEDA requires.

11. Your rights

Under PIPEDA you have the right to:

  • Access the personal information we hold about you
  • Correct information that is inaccurate or incomplete
  • Withdraw consent, subject to legal or contractual restrictions
  • Ask how your information is used and who it has been disclosed to
  • Complain about how we have handled it

If you are in the EEA or UK, you additionally have rights to erasure, restriction of processing, data portability, and to object to processing based on legitimate interests. If you are in Quebec, Law 25 gives you further rights including data portability and the right to be informed about automated decision-making.

Email privacy@enginely.ai to exercise any of these. We will respond within 30 days, as PIPEDA requires. Where the law permits an extension — for example if your request needs consultations that make the deadline impractical — we will tell you within those first 30 days, explain why, and let you know you may complain to the Privacy Commissioner about the delay. We may ask you to verify your identity before releasing information. There is no charge for a reasonable request.

12. Marketing email and CASL

Canada's Anti-Spam Legislation governs commercial electronic messages. We only send them where we have express or implied consent, and every one identifies us, gives a valid contact mechanism, and contains a working unsubscribe link.

Unsubscribing takes effect promptly and in any event within 10 business days, and the mechanism stays functional for at least 60 days after a message is sent. We keep records of consent as CASL requires. You can unsubscribe from any message, or email privacy@enginely.ai. Requesting an audit does not sign you up to a mailing list.

13. Client data we access

Delivering our services often means being granted access to client systems — analytics properties, search console accounts, business profiles, content management systems. Where that happens:

  • We act on the client's instructions, as a service provider, under a written agreement
  • We request the minimum level of access needed, and read-only where that is sufficient
  • Ownership of accounts and profiles stays with the client at all times
  • Access is removed when an engagement ends, on request or at our own routine review

We do not use client data to train models, and we do not repurpose one client's information for another's benefit.

14. Children

Our services are for organizations and are not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child has given us information, contact privacy@enginely.ai and we will delete it.

15. Changes to this policy

We may update this policy as our services, providers or the law change. The date at the top shows when it was last revised. Material changes will be highlighted on this page. Continuing to use the site after a change means you accept the updated policy.

16. Contact and complaints

For any privacy question, request or complaint, contact us first — we would rather resolve it directly:

Privacy enquiries
privacy@enginely.ai
Reyas Solutions Inc.
145 Hillcrest Avenue, Mississauga, Ontario L5B 3Z1, Canada

If you are not satisfied with our response, you may complain to the Office of the Privacy Commissioner of Canada. If you are in the EEA or UK, you may complain to your local supervisory authority. If you are in Quebec, you may contact the Commission d'accès à l'information du Québec.