Privacy Policy
How GenAspect Inc. collects, uses, stores, shares and protects personal information in FieldValve.
Summary. FieldValve is business software for field-service companies. We collect the information you give us to run your account, the operational data your team enters (customers, jobs, invoices, photos, signatures, time entries, and technician location while they have an open time entry or an unfinished visit that day), and technical data needed to keep the service secure. We use it to provide, secure, support and improve FieldValve, to bill you, to protect our customers and our platform, and to meet legal obligations — and, with your consent, to send you marketing email; Sections 4 and 8 give the full list. We do not sell personal information, and we do not run advertising or third-party analytics trackers. For most data in FieldValve, the business you work for or buy services from (our customer) decides why it is collected; we process it on their behalf. Questions and requests: support@fieldvalve.com.
1. Who we are and scope
FieldValve is operated by GenAspect Inc., a corporation incorporated in Ontario, Canada ("GenAspect", "we", "us"). This Policy covers personal information processed through:
- the marketing website at fieldvalve.com (the "Site");
- the staff web application at app.fieldvalve.com and the FieldValve mobile apps for iOS and Android (the "App");
- the customer portal at portal.fieldvalve.com (the "Portal");
- our APIs, integrations (including QuickBooks Online and Stripe), support channels and emails.
Together these are the "Services". This Policy is part of our License Agreement & Terms of Service (the "Agreement"). Capitalized terms not defined here have the meaning given there.
2. Our roles: controller and service provider
FieldValve holds information about several kinds of people, and our role differs for each:
| Who | Example data | Our role |
|---|---|---|
| Site visitors and prospects | Contact-form and newsletter submissions | Controller / accountable organization. |
| Account owners and billing contacts of a company that subscribes ("Customer") | Name, email, company, billing details, support history | Controller. |
| Authorized Users (a Customer's staff: owners, managers and technicians) | Name, work email, role, skills and certifications, activity, time entries, ratings left by End Customers, location while on an open time entry or an unfinished visit (Section 6) | Customer is the controller / accountable organization; we are its service provider / processor. Your employer decides what is collected and why. |
| End Customers (the Customer's clients, including Portal users) | Name, address, phone, email, service history, quotes, invoices, signatures, payments | Customer is the controller; we are its service provider / processor. |
Where we act as a service provider, we process personal information only on the Customer's documented instructions (this Policy, the Agreement and the Customer's configuration of the Services) and for the purposes in Section 4. Requests about data held in a Customer's account should be directed to that Customer; we will assist them, and if you contact us directly we will forward your request to them where appropriate.
Two access paths inside a Customer's account are worth knowing about. First, a Customer's owner can open a read-only view of the Portal exactly as a given End Customer sees it, to help with support; every such view is recorded in an audit log. Second, GenAspect platform staff can access Customer accounts for support, security and engineering purposes, under confidentiality obligations.
3. Information we collect
3.1 Information you provide
- Account and profile: name, email address, password (stored as an argon2id hash, never in clear text), phone number, avatar, role, skills and certifications, and the company name and locations (branches) you set up.
- Billing: when paid subscriptions are available to you, the plan, seat count, billing contact and the payment-method token returned by our payment provider. We do not store full card numbers. (Payments your own customers make to you are separate and are described in Section 10.)
- Customer Data: customer and site records, service requests, quotes, jobs, visits, schedules, checklists, line items, invoices, payment records, refunds, time entries, comments, notes, ratings of visits, and photos or file attachments your team uploads. These may contain personal information about End Customers and staff. Photos uploaded from the staff app are usually re-encoded, which removes embedded camera metadata. The original file is stored as uploaded, including any location metadata the camera recorded, when it is uploaded through the Portal, taken with the in-app camera, in a format we cannot re-encode (for example HEIC), or when its correct rotation depends on that metadata. We do not strip metadata on our servers.
- Signatures: an image of the handwritten signature an End Customer draws to approve a quote or acknowledge an invoice, with the signer's name and time.
- Portal submissions: service requests, uploaded photos, approvals, ratings and messages that End Customers submit through the Portal.
- Site forms: the contact form (name, company, email, team size, optional phone) and the newsletter form (email).
- Support and communications: anything you send us by email or in-app.
3.2 Information collected automatically
- Technical and security data: IP address, browser and device type, operating-system version, app version, request timestamps, pages or screens accessed, error reports and browser security (CSP) violation reports. The IP address and browser identifier used to sign in are also stored on your session and sign-in-token records for as long as those records exist.
- Activity records: who created or changed a job, visit, invoice or payment and when (the job activity feed, audit fields, and audit logs of permission changes and Portal support views).
- Location data: see Section 6.
- Push-notification subscriptions: if an End Customer enables Portal notifications, the browser push endpoint needed to deliver them.
- Device notifications in the App: the App may ask permission to show notifications on your device. Those alerts are generated locally by the App from records you can already see; nothing is sent to a push service and no subscription is stored.
- Device storage: see Section 7.
3.3 Information from third parties
- QuickBooks Online: when a Customer connects QuickBooks, we receive the accounting data described in Section 9, including change notifications (webhooks) that Intuit sends us.
- Stripe: payment status, dispute and payout events, and the type of payment method used (for example card or bank debit). We never receive full card numbers.
- Referrals and invitations: if another user invites you or refers you, we receive your name and email from them.
Other than the technician location described in Section 6 and the signature images described above, we do not intentionally collect sensitive categories of information (health, biometrics, government ID numbers, precise financial account numbers). Please do not enter them in free-text fields.
4. How we use information
- To provide, operate, secure and support the Services, including syncing data between devices and the server.
- To create and manage accounts, authenticate users, and enforce roles and location-scoped permissions.
- To process subscriptions and payments, send invoices and receipts, and prevent fraud.
- To deliver integrations you enable (QuickBooks Online, Stripe, maps, email, push).
- To send transactional and service messages: invitations, magic links, password resets, quote and invoice emails on behalf of the Customer, receipts, security alerts and important changes to the Services.
- To respond to support requests and to communicate with you about your account.
- To monitor, debug and improve performance, reliability and security, using logs and de-identified or aggregated statistics.
- To comply with law, enforce our agreements, and protect the rights, safety and property of GenAspect, our customers and others.
- To send marketing emails with your consent (Section 18).
We do not use Customer Data to train machine-learning or generative-AI models, to build advertising profiles, or for any purpose other than those above. We do not make decisions about you that have legal or similarly significant effects solely by automated means.
5. Legal bases
Where the GDPR, UK GDPR or a similar law applies, we rely on: performance of a contract (providing the Services to the Customer); our legitimate interests (security, fraud prevention, service improvement, and business communications, balanced against your rights); compliance with legal obligations (tax, accounting, responding to lawful requests); and consent, where required (for example marketing emails). Under Canadian law (PIPEDA and provincial equivalents), we collect personal information with consent that is express or implied by the circumstances, and we limit collection to what is reasonable for the purposes identified.
6. Technician location data
FieldValve includes a live-presence feature that shows a Customer's dispatchers where technicians currently are on a map. It works as follows:
- Location is collected from the App only while the App is open, and only when both (a) the technician has an open time entry (running or paused) or a visit assigned to them for that day that is not yet finished, and (b) either the device's location permission has already been granted to the App or the technician taps "Start travel" (labelled "Start drive" on the job screen) for a visit, which is what asks for that permission. The App does not collect location in the background. It also never captures location in a desktop browser: capture runs only in the mobile app, in an installed (home-screen) app, or on a touch device.
- The App sends the device's current position, its accuracy and the time it was taken to our server periodically (at most about once every 30 seconds). It sends nothing else — no heading, speed, altitude or battery level.
- We store only the latest position per user; each new report overwrites the previous one. We do not keep a location history or movement trail. Positions older than five minutes are treated as stale and are no longer shown on the map. The last reported position stays in our database until the Customer's account is deleted, or until you or the Customer ask us to delete it; removing a user from the account hides them from the map but does not by itself erase that last position.
- Location is visible only to users of the same Customer account who hold the "See presence" permission (owners and managers by default), scoped to their location (branch), and to GenAspect platform staff for support.
- How to turn it off: deny or revoke the App's location permission in your browser or device settings, or close the App. The App does not currently have a separate in-app switch.
- Site addresses are a separate thing. Addresses a Customer enters for a job site are geocoded through a mapping provider (Section 8) so they can be shown on a map and used to estimate travel. That is not technician location data and is unrelated to live presence.
Live presence is a standard feature of the App: GenAspect decides how it works technically — when it captures, how often, and that only the latest position is kept — while the Customer (your employer) decides whether to act on it and is responsible for informing you and meeting its obligations under applicable employment and privacy law. A Customer that does not want its technicians located can ask us to switch the feature off for its account at support@fieldvalve.com. We do not rely on your individual consent for this collection. Your employer collects your work location in order to dispatch and coordinate field work, and directs us to process it on its behalf: in Canada this is employee personal information collected for purposes that are reasonable in the circumstances (section 5.3 of PIPEDA, and the employee-information provisions of Alberta's and British Columbia's Personal Information Protection Act); where the GDPR applies, the basis is your employer's legitimate interest in coordinating field work. You can still stop the collection at any time by revoking the App's location permission on your device; that switches off live presence and does not otherwise affect your use of the App.
7. Offline storage on your device
The App is offline-first. To let field staff work without connectivity, it stores on your device a copy of the Customer Data you are authorized to see: customers, sites, jobs, line items, visits, comments, activity history, time entries, the price book, attachment lists, and a cache of attachment files (up to about 50 MB), pre-loaded from the jobs and service requests already synced to your device. It also keeps a queue of changes you made offline, including any photos you attached, until they are uploaded, plus your access credentials, your permissions, a directory of your co-workers, sync bookmarks and interface preferences. If you sign in with a password, the App also stores a salted, irreversible verifier derived from it so that you can sign in again while offline; the password itself is never stored on the device.
This data stays on the device until you sign out or clear the browser or app data. Signing out removes the local database, the attachment cache and your credentials; your permissions and a small number of preference, diagnostic and not-yet-uploaded change records remain until the browser or app data is cleared. Anyone with access to an unlocked device may be able to view local data, so please use a device passcode and keep the device secure. If the Customer revokes your access, the App stops syncing; because it is offline-first, a device that is not signed out keeps its local copy until it is signed out or its data is cleared, so Customers should sign out removed users and, if a device is lost, wipe it with their device-management tools.
8. Sharing, sub-processors and third-party links
We share personal information only as described here. We do not sell or rent personal information, and we do not share it for cross-context behavioural advertising.
- Within the Customer's account. Customer Data is visible to the Customer's Authorized Users according to their roles and locations, and to End Customers through the Portal for their own requests, quotes and invoices.
- Service providers (sub-processors). These process data on our behalf under written contracts that limit them to processing personal information on our documented instructions and for the purpose stated in the table, forbid any other use, and require them to protect that information at least as well as this Policy describes, including confidentiality, security safeguards and prompt breach notification:
Provider Purpose Data Location Render Services, Inc. Application hosting, managed PostgreSQL database, backups and platform logs All Services data United States Stripe, Inc. / Stripe Payments Canada Ltd. Payment processing, connected-account onboarding, payouts, disputes, saved payment methods, fraud prevention Customer business and owner identity details for onboarding; End Customer name, email, payment method and amounts; on a disputed payment, the invoice, the signature image and job photos submitted as evidence; the browser's IP address, because Stripe's scripts run in the App and the Portal United States, Canada Intuit Inc. QuickBooks Online accounting sync (only if connected) See Section 9 United States Cloudinary Ltd. Storage and delivery of photos and file attachments Uploaded files and their metadata; the browser's IP address when a file is viewed United States, European Union Resend, Inc. Transactional and marketing email delivery; the newsletter subscriber list is held there Recipient email, name, message content, delivery events United States Mapbox, Inc. Geocoding and address suggestions as an address is typed (in the App and the Portal) Address text being typed, site addresses, and the IP address of the browser — or of our server, when we geocode stored addresses in bulk United States CARTO Map imagery (basemap tiles) in the App The browser's IP address and map tile coordinates United States, European Union Google LLC (Google Fonts) Typeface delivery on the Site, App and Portal The browser's IP address and browser details United States Browser push services (Apple, Google, Mozilla) Delivery of Portal notifications using the Web Push standard, if an End Customer enables them Push subscription endpoint and notification content United States - Links that open other apps. The App and Portal offer buttons that open a customer's address in Google Maps, start a call or text message, or open a WhatsApp chat with a phone number. These open a third-party app or site on your device and pass it the address or number; that provider's own privacy policy then applies. Nothing is sent to those providers unless you tap the link.
- Professional advisers. Lawyers, accountants and auditors, under confidentiality obligations.
- Legal and safety. When required by law, subpoena, court order or governmental request; to enforce our agreements; or to protect the rights, property or safety of GenAspect, our customers or the public. Where lawful, we will notify the affected Customer before disclosing its data.
- Business transfers. In connection with a merger, acquisition, financing or sale of assets, subject to this Policy.
- With your direction. When you ask us to share data, for example by exporting it or connecting an integration.
We will update this list when we add or replace a sub-processor. Customers who need notice of sub-processor changes may request it at support@fieldvalve.com.
9. QuickBooks Online integration
FieldValve offers an optional integration with Intuit® QuickBooks® Online. This Section explains exactly what happens when a Customer connects it. Intuit and QuickBooks are registered trademarks of Intuit Inc. FieldValve is an independent application and is not affiliated with, endorsed by or sponsored by Intuit Inc.
9.1 Authorization
- Connection uses Intuit's OAuth 2.0 authorization flow. We never see or store your Intuit username or password. We request a single scope,
com.intuit.quickbooks.accounting; we read your company name through the Accounting API so we can show which QuickBooks company is connected. - The resulting access and refresh tokens are encrypted at rest with AES-256-GCM under keys held separately from the database, are never written to logs or returned to a browser, and are used only to call the QuickBooks API for your company file.
- Only the account owner can connect, disconnect or reset the integration — the "connect QuickBooks" permission is reserved to the owner role and cannot be granted to other roles — and each FieldValve location (branch) connects to exactly one QuickBooks company.
9.2 Data we read from QuickBooks
We read: company information and preferences (name, currency, tax settings); the chart of accounts (income and deposit accounts); items and services; classes, if class tracking is used; customers; employees; and estimates, invoices and payments. We read this data to map your FieldValve records to your books and to detect and reconcile differences; invoices and payments are read across your company file for the period being reconciled, not only the records FieldValve created. If you run the optional one-time import, we also copy your QuickBooks customers, items and invoices for a period you choose into FieldValve, where they are then held as Customer Data and retained under Section 12. Intuit also sends us change notifications (webhooks) for your company; we verify their signature and keep the notification payloads, for up to 90 days, to process them and to diagnose sync problems.
9.3 Data we write to QuickBooks
We write: customers and their addresses and contact details; estimates (from quotes); invoices and invoice lines; payments; refund receipts; deposits mirroring Stripe payouts; employees and time activities, if time sync is enabled; classes mirroring your business units, if class tracking is used; and items and services mirroring your price book, plus two FieldValve service items used for lines that have no matching item. We write only records derived from your FieldValve data and the sync options you enable. Some writes are triggered by an event rather than by a person — for example a deposit created when Stripe reports a payout — and the two FieldValve service items are created by us so that lines with no matching item can be posted.
9.4 How QuickBooks data is used and shared
- QuickBooks data is used solely to operate the synchronization you configured, to show you sync status and errors, and to support you when you ask. It is not used for advertising, profiling, model training, benchmarking or any purpose unrelated to your sync.
- QuickBooks data is not sold, rented or shared with any third party other than the hosting sub-processor that stores all FieldValve data (Section 8), and is not transferred to any other integration. The only other circumstances in which it could be disclosed are the ones in Section 8 that apply to all data: where disclosure is required by law or legal process, to establish or defend a legal claim, to our own professional advisers under confidentiality obligations, or to a successor in a business transfer. We do not disclose QuickBooks data for any other reason.
- Access within GenAspect is limited to personnel who need it for support or engineering, under confidentiality obligations. Diagnostic logs may include error responses from QuickBooks, which can echo the field values that were submitted; these logs are kept for up to 12 months, in line with Section 12.
9.5 Disconnecting and deleting QuickBooks data
- You can disconnect at any time from FieldValve (Settings → Integrations → QuickBooks → Disconnect) or by disconnecting FieldValve from inside QuickBooks (Intuit's "My Apps"). On disconnect we ask Intuit to revoke the access and refresh tokens, and we stop all sync, pause any queued writes and delete the stored credentials immediately. When you disconnect from inside QuickBooks, Intuit revokes the tokens itself and sends your browser to FieldValve; we confirm the revocation with Intuit and then delete our copy in the same way. If Intuit revokes our access for any other reason (for example an expired authorization), the credentials are deleted as soon as we learn of it.
- The "Reset connection" action in FieldValve removes the remaining connection record. Sync mapping records that link FieldValve invoices, payments, customers and other records to their QuickBooks counterparts, the integration's activity log and its configuration are retained for the single purpose of keeping your history consistent and preventing duplicates if you reconnect; they are deleted when the Customer's account is deleted or on request.
- You may request deletion of all QuickBooks-derived data we hold, including credentials and mapping records, by emailing support@fieldvalve.com; we will complete it within 30 days, subject to legal retention obligations.
Your use of QuickBooks itself is governed by the Intuit privacy statement and Intuit's own terms.
10. Payments through Stripe
Card and bank payments, including a payment a technician collects on site through a payment link, are processed by Stripe. When a Customer enables payments, Stripe collects the business and owner identity information it needs for onboarding and compliance directly through Stripe-hosted pages; we receive only the resulting account status. When an End Customer pays, card details are entered into Stripe-hosted elements and go straight to Stripe; FieldValve stores only the amount, status, payment-method type and Stripe identifiers. If a payment is disputed, we may submit the related invoice, the End Customer's signature image, job photos and the Customer's written explanation of the charge to Stripe as evidence on the Customer's behalf. Stripe's processing of personal information is described in the Stripe Privacy Policy. Stripe may also act as an independent controller for fraud prevention and regulatory purposes.
11. Cookies, tokens and similar technologies
- Site (fieldvalve.com): sets no cookies and runs no analytics or tracking scripts. The only third-party request the Site makes is to Google Fonts.
- App: uses strictly necessary technologies to keep you signed in and working offline: a secure, HttpOnly refresh-token cookie, a copy of the refresh token in the browser's local storage (or, on a mobile device, the app's own storage) so you can re-open the App offline, short-lived access tokens held in memory, and browser storage and caches for the offline data described in Section 7.
- Portal: a secure, HttpOnly refresh-token cookie, a copy of that refresh token in the browser's local storage (or, in the mobile app, the app's own storage) so the Portal can restore your session, a short-lived session token held only in memory, and browser storage holding your name, email address and phone number so the Portal can recognize you, an identifier used to remember a payment device, and your display preferences.
- These are essential and cannot be switched off while using the Services. We do not use advertising cookies, third-party analytics, session replay or fingerprinting. Because we do not sell or share personal information or track you across sites, "Do Not Track" and Global Privacy Control signals do not change how we process it.
12. Data retention and deletion
- Customer Data is retained for as long as the Customer's account is active. Records that users delete in the App are soft-deleted: they are marked as deleted so that offline devices can sync the deletion, are hidden from all users, and remain in our database as deletion markers until the Customer's data is deleted under this Section or on request. Deleting a photo or file removes it from view; the stored file itself is deleted when the Customer's account or location is deleted, or on request.
- Backups are retained by our hosting provider for up to seven days and then overwritten; data deleted from active systems may persist in backups for up to that period.
- Trial accounts that do not convert to a subscription are deleted 30 days after the trial ends.
- After termination or cancellation, we keep Customer Data for 60 days so the Customer can export it or reactivate, then delete it from active systems, except where we must keep it for legal, tax or accounting reasons (for example, records of payments and invoices, which are retained in restricted-access form for the period required by tax and accounting law, generally 6 to 7 years).
- Location data: latest position only, overwritten on each report. It is retained until the Customer's account is deleted or until you or the Customer ask us to delete it; removing a user from the account does not by itself delete it.
- Security data: platform and application logs are kept for up to 12 months. Sign-in records (IP address and browser identifier) live with the session or sign-in-token record they belong to: those sessions and tokens stop working after at most 30 days, and the record itself is retained until the Customer's data is deleted or on request.
- Site form submissions: contact-form submissions are kept in our database until you ask us to delete them. Newsletter subscriptions are not kept in our database at all: they are held by our email provider (Section 8) until you unsubscribe or ask us to delete them.
- Portal links and sessions: sign-in magic links expire after 15 minutes and can be used once; guest payment links expire after 45 minutes (scanned in person) or 7 days (sent by email); a Portal session ends after 7 days without use. Expired links stop working at once, and their records, which include the IP address that created them, are deleted within 30 days, or within 90 days for a link that was used.
Customers can remove users from their organization and delete customers, jobs and attachments from within the Services. To delete your whole account, or to have your personal information deleted, email support@fieldvalve.com from the address on the account; we complete deletion within 30 days, subject to the legal-retention exceptions above.
13. Security
We use administrative, technical and physical safeguards appropriate to the sensitivity of the information, including TLS encryption for all connections, encryption at rest by our database and storage providers, encryption of integration credentials with keys held separately from the database, argon2id password hashing, role-based access control with location scoping, short-lived access tokens, request rate limiting, security headers on all three surfaces with a strictly enforced content-security policy on the Site and the Portal, and stripping of secrets from request data before it can reach application logs. Our Trust & Security page describes current measures and our roadmap; roadmap items are not commitments. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a breach of security affecting your personal information, we will notify the affected Customer without undue delay and, where required, individuals and regulators, in accordance with applicable law.
14. International transfers
GenAspect is located in Canada. Our primary hosting and most sub-processors are in the United States, and some providers operate in the European Union. Personal information you provide is therefore stored and processed outside your province or country, where it may be accessible to local law-enforcement and national-security authorities under local law. We rely on contractual safeguards with each provider (including standard contractual clauses where required) for these transfers, and before communicating personal information outside Quebec we carry out the privacy impact assessment required by Quebec law. Our Privacy Officer (Section 20) can answer questions about these transfers.
15. Your rights and choices
Depending on where you live, you may have the right to access the personal information we hold about you, to correct it, to have it deleted, to receive a portable copy, to object to or restrict certain processing, to withdraw consent, and to complain to a privacy regulator. To exercise these rights, email support@fieldvalve.com. We verify requests by confirming that they come from the email address on the account (or, for an End Customer, the address the Customer holds for you) and, where necessary, by asking for details only the account holder would know. We respond within 30 days (or the period required by law) and will not discriminate against you for exercising your rights. You may use an authorized agent where the law allows; we will ask for proof of the authorization.
If your information is held in a Customer's account (you are an employee or an End Customer of a business that uses FieldValve), the Customer is responsible for handling your request; we will forward it and assist as its service provider. You can update most of your own account and profile details directly in the App. Customers can export jobs and invoices as CSV from the App and can request a full account export from support.
16. Region-specific disclosures
16.1 Canada
We comply with the Personal Information Protection and Electronic Documents Act (PIPEDA) and substantially similar provincial laws, including the Act respecting the protection of personal information in the private sector (Quebec) and the Personal Information Protection Act of each of Alberta and British Columbia. The person accountable for our compliance is our Privacy Officer, who can be reached at support@fieldvalve.com. You may lodge a complaint with the Office of the Privacy Commissioner of Canada or your provincial commissioner. For Quebec residents: Section 6 describes the technology that allows a technician to be located and how to deactivate it; Section 14 describes transfers outside Quebec; we do not make decisions based exclusively on automated processing.
16.2 United States (including California)
We collect, and in the preceding 12 months have collected, the categories of personal information listed in Section 3 (identifiers, commercial information, internet activity, geolocation, professional information, and the signature images described in Section 3.1) from the sources described there (you, the Customer whose account you are in, your device, and the integrations in Section 3.3), for the purposes in Section 4, and disclose them to the service providers in Section 8. We retain each category for the periods in Section 12. We have not sold or shared (for cross-context behavioural advertising) personal information and we do not knowingly collect personal information of consumers under 16. Precise geolocation is sensitive personal information under the CPRA. We collect it in two ways: technician location for live presence (Section 6), and, in the limited cases described in Section 3.1, location metadata embedded in an uploaded photo. We collect it solely to provide the service the Customer requested and do not use it to infer characteristics about you. California residents have the rights to know, delete, correct, and to non-discrimination described in Section 15, and may use an authorized agent. We operate exclusively online and have a direct relationship with the people whose information we collect, so requests may be submitted by email. For data held in a Customer's account we act as a "service provider" under the CCPA/CPRA and process it only for the Customer's business purposes.
16.3 European Economic Area, United Kingdom and Switzerland
The Services are directed at businesses in Canada and the United States. We do not offer them to individuals in the EEA, the UK or Switzerland, and we do not monitor the behaviour of individuals in those regions; on that basis we have not appointed a representative under article 27 of the GDPR. If we begin offering the Services in those regions we will appoint one and name it here. Where the GDPR or UK GDPR applies, the legal bases in Section 5 apply, you have the rights in Section 15, transfers rely on the safeguards in Section 14, and you may complain to your local supervisory authority.
17. Children and age
The Services are for business use and are not directed to children. Users of the App must be at least 18 (Section 3 of the Agreement). We do not knowingly collect personal information from anyone under 16 through the Portal or the Site. If you believe a child has provided us information, contact us and we will delete it.
18. Marketing emails
We send marketing emails (such as the newsletter) only with your consent as required by Canada's Anti-Spam Legislation (CASL) and CAN-SPAM. Every marketing email includes an unsubscribe link and our contact details; you can also opt out at support@fieldvalve.com. Opting out does not affect transactional or service emails, which are necessary to operate your account. Emails that the Services send to End Customers on a Customer's behalf (quotes, invoices, appointment notices) are sent at the Customer's direction; End Customers can manage those preferences through the unsubscribe link in each message or by contacting the Customer.
19. Changes to this Policy
We may update this Policy from time to time. We will post the new version at fieldvalve.com/privacy with an updated date and, for material changes, notify account owners by email or in-app notice before the change takes effect. Where a change introduces a new purpose for which the law requires your consent, we will obtain that consent before the change applies to you. Continued use of the Services after the effective date otherwise means you accept the updated Policy.
20. Contact
GenAspect Inc. (operating as FieldValve)
A-239 Sunnyside Ave, Ottawa, Ontario K1S 0R4, Canada
Privacy, security, legal and support enquiries all reach us at support@fieldvalve.com. Mark a privacy request "Privacy" in the subject line and it goes to our Privacy Officer.