Privacy Policy
What personal information Celeris collects, why, where it is stored, how long we keep it and the rights you have.
This Privacy Policy explains how Celeris Realtime Systems Inc. ("Celeris", "we", "us" or "our") collects, uses, discloses and protects personal information. It applies when you visit useceleris.com, create an account or use the Celeris Service. Capitalized terms that are not defined here have the meaning given in our Terms of Service.
1. Our role
We are the controller of personal information about our customers and website visitors. This covers account details, billing records, support conversations, and the logs and metrics about how you use the Service.
We are a processor of personal information contained in Customer Content and about our customers' End Users. This includes message payloads, presence labels, connection identifiers and End User IP addresses. We process this information on our customers' instructions under our Data Processing Addendum. If you are an End User of an application built on Celeris, please contact that application's provider; we will pass any request we receive to them.
2. Information we collect
Information you give us
- Account details: your name, email address and password. We store your password only as an Argon2 hash, never in readable form.
- Sub-users: for sub-users you create, we store the username, a password hash, the assigned role and permissions.
- Verification codes: the one-time codes we email you to verify your address or reset your password. They expire after 30 minutes.
- Support and correspondence: the content of emails you send us.
Billing information
Paddle, our Merchant of Record, collects your payment details, billing address and tax information directly. We never receive or store your full card number. From Paddle we receive:
- your Paddle customer ID;
- your subscription status, plan and billing interval; and
- transaction amounts and dates.
Information collected automatically
- Usage metrics: for each account and application, we record message counts, message sizes and direction, and the number of open connections and active channels over time. We calculate connection minutes and channel minutes from these for billing. These metrics never include message contents.
- Logs:
- Our hosting provider keeps standard access logs for the website and dashboard: your IP address, user agent, the page requested, the time and the response status.
- When a request to our API or realtime servers produces a log entry, such as an error, the entry includes your IP address, user agent and the requested path.
- Network flow logs record IP addresses and connection metadata for security purposes.
- Analytics (only with your consent): if you accept analytics cookies, Google Analytics collects the following about your visits to the website and dashboard:
- the pages you view and the page that referred you;
- your device and browser type;
- your approximate location, derived from your IP address (Google Analytics does not store IP addresses); and
- how you interact with pages.
We turn off Google signals and ad personalization. If you decline, Google Analytics is not loaded. - Cookies: we use strictly necessary cookies, and analytics cookies only with your consent. See our Cookie Policy.
Customer Content we process on our customers' behalf
- Message payloads pass through the Service in transit. We may hold them in the following places:
- in memory, to replay recent messages to reconnecting clients: at most the last 100 messages from the past 2 minutes per channel segment;
- in internal streaming logs that carry messages between our servers. Messages expire there after 5 minutes and are deleted on the next cleanup pass, within about 10 minutes.
A message copied to another server so that a reconnecting client can catch up can stay in that server's replay memory for up to 2 more minutes.
Payloads are never stored durably. We do not access message contents except where needed to maintain the Service, at the customer's request or as required by law. - Presence data: the labels customers assign, connection identifiers and timestamps. It expires 10 minutes after the last activity.
- End User network data: our network sees End User IP addresses in order to establish connections, and they appear in our logs.
What we do not collect
We do not use advertising or cross-site tracking tools, and we use Google Analytics only if you consent. We do not buy data about you from data brokers, and we do not intentionally collect sensitive personal information.
3. How we use information
We use personal information to:
- provide and operate the Service, including sign-in, message routing and the dashboard;
- meter usage and bill for it;
- send you verification codes, password resets, service and billing notices, and notices of changes to our policies;
- secure the Service, prevent fraud and abuse, and enforce our Terms and Acceptable Use Policy;
- provide support and troubleshoot problems;
- improve the Service, using aggregated usage metrics;
- understand how people use our website and dashboard, through Google Analytics, if you consent; and
- comply with our legal obligations.
We do not send marketing emails without your consent. We do not sell personal information, and we do not share it for cross-context behavioural advertising. We do not use Customer Content to train artificial intelligence or machine learning models.
4. Legal bases (EEA and UK)
If you are in the European Economic Area or the United Kingdom, we rely on the following legal bases:
- Contract: to create your account, provide the Service and bill you.
- Legitimate interests: to secure the Service, prevent abuse, send service notices and improve the Service. We rely on these only where our interests are not overridden by your rights.
- Legal obligation: to keep tax and accounting records and respond to lawful requests.
- Consent: for analytics cookies, and wherever else the law requires it. You may withdraw consent at any time; for analytics, use Cookie settings in the site footer.
5. How we share information
We share personal information only:
- With service providers that process it on our behalf under written contracts. They are listed on our Subprocessors page, and include Google, which provides Google Analytics.
- With Paddle. As our Merchant of Record, Paddle is an independent controller of the payment information it collects. Paddle's Privacy Notice describes how Paddle handles it.
- For legal reasons: to comply with a law, court order or lawful request, or to protect the rights, property or safety of Celeris, our customers or others.
- In a business transfer: if we are involved in a merger, acquisition or sale of assets. We will notify you before your information becomes subject to a different privacy policy.
- With your consent or at your direction.
6. Where we store and process information
Celeris is based in Canada. Our infrastructure is hosted in two places:
- United States: your account, billing and usage data is stored with Amazon Web Services in us-east-1, and our usage database runs on ClickHouse Cloud in the same region.
- Germany or the United States, for realtime traffic: traffic is processed in the region closest to the connecting client, either us-east-1 or eu-central-1 (Germany). It is relayed between regions when publishers and subscribers are in different regions.
Our email provider processes email in the United States, and Google Analytics data is processed in the United States. Information stored in another country may be accessible to its courts and law enforcement authorities.
When personal information from the EEA, the UK or Switzerland is transferred to a country without an adequacy decision, we rely on the European Commission's Standard Contractual Clauses and the UK Addendum. For Customer Content, those clauses are incorporated into our Data Processing Addendum.
7. How long we keep information
| Information | Retention |
|---|---|
| Account and sub-user details | For the life of your account; deleted within 30 days after it is closed |
| Verification and password-reset codes | 30 minutes |
| Usage metrics | Raw records for 90 days; per-minute summaries for 365 days |
| Message payloads | Deleted automatically within 15 minutes; never stored durably |
| Presence data | 10 minutes after the last activity |
| Queued outgoing email | Up to 7 days |
| Google Analytics data (with your consent) | 14 months |
| Application, security and network logs | Between 3 and 90 days, depending on the log type |
| Database backups | 14 days |
| Billing and transaction records | As long as tax and accounting law requires, generally 6 years |
| Support correspondence | Up to 2 years after the request is resolved |
8. How we protect information
We protect personal information with:
- TLS encryption in transit;
- encryption at rest for databases, caches and storage volumes;
- Argon2 hashing for passwords and API client secrets, and encrypted storage for signing secrets;
- private networking;
- least-privilege access, with multi-factor authentication for administrative access; and
- replicated databases with regular backups.
No method of transmission or storage is completely secure. If a breach of security creates a real risk of significant harm, we will notify affected individuals and the relevant regulators as required by law.
9. Your rights
Depending on where you live, you may have the right to:
- access the personal information we hold about you;
- correct it;
- delete it;
- receive a copy in a portable format;
- object to or restrict certain processing; and
- withdraw consent.
To make a request, email privacy@useceleris.com from your account's email address. We may need to verify your identity. We respond within 30 days, or within any extended period the law permits.
Complaints. If you are not satisfied with our response, you can complain to a regulator:
- in Canada, the Office of the Privacy Commissioner of Canada;
- in the EEA, your local data protection authority;
- in the UK, the Information Commissioner's Office.
California residents. In the past 12 months we have collected the following categories of personal information, for the purposes described in section 3:
- identifiers, such as your name, email address and IP address;
- commercial information, such as your plan and transactions; and
- internet activity, such as logs, usage metrics and, if you consent, website analytics.
We collected this information from you, from your devices and from Paddle. We disclose it to service providers for business purposes. We do not sell or share personal information, and we do not use sensitive personal information to infer characteristics about you.
You have the right to know, delete and correct your personal information. You also have the right not to be discriminated against for exercising these rights, and you may use an authorized agent to make a request.
10. Children
The Service is not directed to children, and our Terms require users to be at least 18. We do not knowingly collect personal information from anyone under 16. If you believe a child has given us personal information, contact us and we will delete it.
11. Changes to this policy
We may update this Privacy Policy from time to time. For material changes, we will notify you by email or in your dashboard before they take effect. The "Last updated" date at the top of this page shows the current version.
12. Contact our Privacy Officer
Our Privacy Officer is accountable for our compliance with this policy:
Privacy Officer
Celeris Realtime Systems Inc.
2920 Highway 7, Unit 3605
Vaughan, Ontario L4K 0P4
Canada
Email: privacy@useceleris.com