Privacy Policy
Last Updated: September 18, 2026
1. Introduction
Output Systems (“Output Systems,” “we,” “us,” or “our”) operates the website located at output.systems, including its subdomains (the “Website”), and provides design, build, integration, and ongoing management of custom AI-powered systems for modern businesses (the “Services”). Output Systems is operated by Output Inc., a corporation organized under the laws of Canada with its principal place of business in Toronto, Ontario, Canada.
This Privacy Policy describes how Output Systems collects, uses, discloses, retains, and protects personal information when you visit the Website, interact with the Output AI Receptionist on the Website, communicate with us, respond to our advertising on Meta (Facebook and Instagram), Google, or LinkedIn, or engage our Services as a client or prospective client.
This Privacy Policy is intended to comply with: the Personal Information Protection and Electronic Documents Act (PIPEDA) in Canada; An Act respecting the protection of personal information in the private sector, as modernized by Quebec Law 25; the General Data Protection Regulation (GDPR) in the European Union and the UK GDPR in the United Kingdom; the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA); Canada’s Anti-Spam Legislation (CASL); and other applicable data protection and electronic-marketing laws in the jurisdictions where our visitors and clients are located.
By using the Website, submitting a form, chatting with the Output AI Receptionist, or engaging the Services, you acknowledge that you have read this Privacy Policy. Where consent is required by law, we ask for it separately, at the point of collection.
2. Data Controller and Contact Information
For all privacy-related inquiries, requests, or complaints, please contact:
Privacy Officer: Curtis Grier-Coward
Email: connect@output.systems
Phone: 647 622 3799
Address: 375 University Ave, Toronto, Ontario, Canada
Output Systems acts as the data controller for personal information collected through the Website and directly from prospective clients. When we deliver the Services under a client agreement, personal information contained in or processed by the custom systems we build for a client is processed on behalf of that client, who is the controller of that information; Output Systems acts as the processor. Data processing terms are set out in the client agreement.
We will acknowledge every privacy inquiry within a reasonable time and respond substantively within thirty (30) days, or such shorter period as required by applicable law. Where an inquiry is complex, we may extend the response time as permitted and will tell you when to expect a full reply.
3. Information We Collect
3.1 Information You Provide Directly
Full name, email address, telephone number, business name and role, business website URL (for assessments and consultations), industry and business size, information about your business operations relevant to the Services requested, billing information (processed by Stripe, our third-party payment processor; we do not store full payment card numbers, and Stripe’s privacy policy applies to its processing), communication preferences, form and campaign identifiers indicating which ad or landing page brought you to us, and any other information you voluntarily provide in a form, an email, a chat message, or a call.
If you request a free business assessment or a consultation, we ask you to confirm you are authorized to request it for the business whose information is used. If you decline to provide required information for a Service, we may be unable to deliver that Service.
3.2 Conversations with the Output AI Receptionist
The Website features a conversational AI agent, the Output AI Receptionist. When you interact with it, we collect the messages you send, the responses provided, the page you were viewing, the time of each turn, a session identifier, and whether the conversation reached a next step (for example, a link click, a lead capture, or a handoff request). Conversations on the Website are with an AI assistant, not a human.
Conversation records are reviewed and analyzed by us to answer your questions, improve response quality, identify what visitors are asking that the Website does not answer, and refine our Services. Aggregate and anonymized conversation data may be used for internal research and to improve the Services. We do not permit our AI infrastructure providers to use your conversation content to train their general-purpose AI models.
Please do not share sensitive personal information in the chat, such as government identification numbers, health information, or financial account details. If a visitor begins to share sensitive information, the Receptionist is designed to steer the conversation to a human contact instead.
3.3 Information Collected Automatically
IP address, browser type and version, operating system, device identifiers, screen resolution, language, referring URL, pages visited, buttons clicked, date and time of access, approximate geolocation derived from IP address, campaign parameters carried in the URL (such as UTM tags), and cookies and similar tracking technologies as described in Section 7.
3.4 Website Analytics and Session Data
We use Google Analytics 4 to understand Website traffic and usage, and Microsoft Clarity to understand how visitors use the Website through heatmaps, scroll data, and session replays. Session replays may capture mouse movement, clicks, and page interactions, but are configured to mask text entered in form fields and to exclude keystrokes. These tools are deployed subject to your cookie consent where required by law and can be declined through the Website cookie banner or your browser controls.
3.5 Advertising Data — Meta (Facebook and Instagram), Google, and LinkedIn
We advertise on Meta’s platforms (Facebook and Instagram), on Google (search and display), and on LinkedIn. To measure ad performance, understand which campaigns are working, and reach audiences likely to be interested in the Services, we deploy the following tags on the Website, subject to your cookie consent where required by law:
- Meta Pixel (Facebook and Instagram). The Meta Pixel is a small piece of code that reports events back to Meta when you visit our Website, view a landing page, submit a form, or request an assessment or consultation. Meta uses this information to attribute ad clicks to outcomes, to help us build custom audiences (visitors who took a specific action), and to build lookalike audiences (people similar to those who converted). The Meta Pixel operates the same way across Facebook and Instagram, since both platforms are Meta properties.
- Google Ads tag and Google Analytics 4. The Google Ads conversion tag reports form submissions and other conversion events to Google Ads so campaigns can be optimized. GA4 provides aggregate Website analytics and, where advertising features are enabled, may contribute to Google’s ad personalization signals for our campaigns.
- LinkedIn Insight Tag. The LinkedIn Insight Tag reports page views, conversions, and professional attributes (industry, seniority, company size where inferred by LinkedIn) to LinkedIn for the purpose of measuring campaign performance and building matched audiences for LinkedIn ads.
Meta, Google, and LinkedIn act as independent controllers of the data they collect through their tags, and their own privacy policies apply to their processing. The information they receive may include your IP address, information about the ad you clicked, the page you visited, the action you took, cookie identifiers, and, where you are logged in to their platforms on the same browser or device, an association with your account there. These providers may combine what they receive from us with other data they hold about you.
You can control advertising cookies through the Website cookie banner and the “Cookie Settings” link in the footer. You can also opt out of interest-based advertising at the platform level through:
- Meta: your Facebook and Instagram Ad Preferences.
- Google: adssettings.google.com and Google account controls.
- LinkedIn: your LinkedIn account Ads settings.
- Industry opt-outs: the Digital Advertising Alliance (optout.aboutads.info), the Network Advertising Initiative (optout.networkadvertising.org), and the European IAB (youronlinechoices.eu).
3.6 Sensitive Personal Information
We do not knowingly collect sensitive personal information such as government IDs, health information, biometric data, racial or ethnic origin, religious beliefs, political opinions, trade union membership, genetic data, or sexual orientation, and we ask that you do not provide it, including within chat conversations. If we become aware that we have inadvertently received sensitive personal information, we will delete it promptly unless required by law to retain it.
4. Legal Bases for Processing (GDPR / UK GDPR)
For individuals in the EU, UK, or Switzerland, we process personal information on the following bases:
- Consent. For analytics and advertising cookies, for marketing communications, and for any processing that specifically requires it under local law.
- Contract. To deliver Services you have requested, including free assessments, consultations, and paid engagements, and to respond to pre-contractual inquiries.
- Legitimate interests. To operate, secure, and improve the Website and Services; to conduct internal research on aggregated conversation data; to prevent fraud and abuse; and to communicate with existing clients about their engagement. We balance our interests against your rights and interests and provide the right to object where the balance so requires.
- Legal obligation. To meet tax, accounting, regulatory, and lawful-request obligations.
You may withdraw consent at any time without affecting the lawfulness of processing carried out before the withdrawal. Where processing relies on legitimate interests, you may object on grounds relating to your particular situation.
5. How We Use Personal Information
We use personal information for the following purposes:
- Responding to you. To answer inquiries submitted through forms, email, phone, or the Output AI Receptionist, and to schedule assessments, consultations, and follow-ups.
- Delivering the Services. To design, build, integrate, deploy, test, launch, and maintain the custom AI-powered systems we provide to clients; to configure connected applications, credentials, permissions, and knowledge sources in scope; and to conduct the ongoing reviews and updates described in the client agreement.
- Improving the product. To analyze aggregate and anonymized Website and conversation data for insights into what visitors ask, how the Receptionist performs, and where the Services can be improved.
- Advertising and measurement. To measure and optimize our advertising on Meta, Google, and LinkedIn, including conversion tracking, custom audiences, and lookalike audiences, subject to consent where required.
- Communications. To send transactional messages (for example, assessment delivery, engagement updates, service notices, billing) and, where permitted and with the appropriate consent, marketing emails.
- Billing and administration. To process payments through Stripe, issue invoices, and keep financial records.
- Security and integrity. To detect, prevent, and respond to fraud, abuse, spam, and misuse of the Website, forms, and Receptionist; and to protect the rights, property, and safety of Output Systems, our clients, and our users.
- Compliance and enforcement. To comply with legal obligations, respond to lawful requests, and enforce our terms.
AI processing. Conversations with the Output AI Receptionist are processed by third-party AI infrastructure providers acting as our service providers under written agreements. We do not permit these providers to use your conversation content to train their general-purpose AI models. Anonymized and aggregated conversation data may be used for our own internal research and product improvement.
No sale of personal information. We do not sell personal information. We do not use personal information for solely automated decision-making that produces legal or similarly significant effects without explicit consent. Data we collect is used for the purposes above; it is not sold to or shared with third parties for their own commercial use.
6. Disclosure of Personal Information
We do not sell personal information. We may share personal information only with the categories of recipients below, in each case bound by appropriate contractual or legal protections:
- Service providers. Cloud hosting, database, backup, and edge providers; AI infrastructure providers that power the Receptionist and the systems we build for clients; email delivery and support platforms; CRM; analytics vendors (Google Analytics 4, Microsoft Clarity); payment processors (Stripe); automation and workflow tools; professional advisors (legal, accounting, privacy).
- Advertising platforms. Meta (Facebook and Instagram), Google, and LinkedIn as described in Section 3.5, where you have consented to advertising cookies.
- Legal and regulatory recipients. Courts, regulators, law enforcement, and other parties where required by law, legal process, or to protect our rights, users, or clients.
- Successor entities. A successor in the event of a merger, acquisition, financing, reorganization, or sale of assets, subject to continued protection under this Policy or a policy at least as protective.
- With your consent. Any other party you specifically ask us to share your information with, or for any other purpose you consent to.
California note. Although we do not sell personal information, the use of advertising cookies and pixels may constitute “sharing” for cross-context behavioral advertising under the CCPA/CPRA. You may opt out of such sharing at any time through the Website cookie consent tool or by using a recognized opt-out preference signal such as Global Privacy Control (see Section 20).
7. Cookies and Tracking Technologies
Cookies are small text files placed on your device. We also use similar technologies such as pixels, tags, local storage, and session storage. The Website uses three categories:
- Strictly necessary. Website operation, chat session continuity, form protection, load balancing, and storing your cookie consent choice. These cannot be turned off and do not require consent.
- Analytics. Google Analytics 4 and Microsoft Clarity to understand Website usage. Enabled only with consent where required by law.
- Advertising. Meta Pixel, Google Ads tag, and LinkedIn Insight Tag to measure advertising performance and build audiences on Meta, Google, and LinkedIn. Enabled only with consent where required by law.
When you first visit the Website, a consent banner gives you the choice to accept or decline non-essential cookies. Declining is as easy as accepting. You can change your choice at any time through the “Cookie Settings” link in the footer, or by clearing site data in your browser. Non-essential cookies are not deployed until consent is given for users in jurisdictions requiring prior consent.
8. Data Retention
We retain personal information only for as long as necessary for the purposes for which it was collected, including to satisfy legal, accounting, or reporting requirements:
- Inquiry data (no engagement). Up to 24 months, then deleted or anonymized.
- Website chat conversations. Up to 24 months, after which they are deleted or anonymized for aggregate analysis.
- Active client data. Duration of the engagement plus 7 years, unless the client agreement specifies otherwise.
- Marketing data. Until unsubscribe or withdrawal of consent, plus a short suppression period to honor the opt-out.
- Website analytics. Up to 26 months.
- Advertising audiences and conversion data on platforms. Governed by the retention rules of Meta, Google, and LinkedIn; we do not control retention within those platforms beyond opting out and requesting deletion where offered.
- Legal and billing records. As required by tax, corporate, and regulatory law (generally at least 7 years in Canada).
Data no longer required is securely deleted or anonymized so it can no longer identify an individual.
9. International Data Transfers
Output Systems is based in Canada and primarily serves clients in Canada, the United States, the United Kingdom, and the European Union. Canada has been recognized by the European Commission as providing adequate data protection for commercial organizations subject to PIPEDA.
Some of our service providers — including AI infrastructure, cloud hosting, analytics, and advertising providers — process data in the United States and other jurisdictions. For such transfers, we rely on appropriate safeguards, including the European Commission’s Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum, the EU-US Data Privacy Framework where applicable to a given provider, and supplementary technical and organizational measures.
10. Data Security
We implement encryption in transit (TLS/SSL) and at rest, access controls including role-based access and multi-factor authentication for administrative accounts, network segmentation, application-level rate limiting and bot protection, regular security assessments and dependency updates, staff confidentiality obligations, vendor due diligence, and incident response procedures. No method of electronic transmission or storage is completely secure. In the event of a personal-data breach, we will notify affected parties and regulatory authorities as required by applicable law and in the timeframes specified by each regulator.
11. Your Rights
Subject to verification of your identity and applicable law, the following rights apply:
All users. Access, correction, deletion, withdrawal of consent, and complaint.
EU / UK / Switzerland (GDPR). Restriction of processing, data portability in a machine-readable format, right to object to processing based on legitimate interests or for direct marketing, right not to be subject to solely automated decision-making with legal or similarly significant effects, and the right to lodge a complaint with your local data protection authority.
California residents (CCPA/CPRA). The right to know what personal information is collected, to request deletion, to correct inaccurate information, to opt out of sale or sharing (Output Systems does not sell personal information; see Section 6 regarding advertising), to limit use and disclosure of sensitive personal information, and non-discrimination for exercising rights.
Quebec (Law 25). Access, correction, cessation of dissemination, de-indexing, and portability, together with the right to be informed of the reasons and factors used in an automated decision-making process.
Canada (PIPEDA). Access to personal information held by us and challenge to its accuracy, and the ability to escalate to the Office of the Privacy Commissioner of Canada if unresolved.
To exercise any right, including requesting a copy of your personal information or the deletion of your personal information and chat conversation records, email connect@output.systems with the subject line “Privacy Request”. We will verify your identity, generally by matching details in your request against information we already hold, and respond within thirty (30) days. Where you request deletion, we will delete or anonymize your personal information unless we are legally required to retain it, and we will confirm once completed. You may authorize an agent to submit a request on your behalf; the agent must provide proof of authorization, and we may still ask you to verify identity directly.
12. Children’s Privacy
The Website and Services are not directed to, and are not intended for use by, individuals under the age of 18. Output Systems is a business-to-business service, and every function of the Website — requesting a free business assessment, booking a consultation, engaging Output Systems, and communicating with our team — assumes an adult acting in a business capacity. We set the threshold at 18 rather than a lower statutory minimum because we would rather err on the side of caution than approach the edges of any jurisdiction’s children’s-privacy rules.
We do not knowingly collect personal information from anyone under the age of 18. We do not target advertising to minors on Meta, Google, or LinkedIn, and we do not build audiences, lookalikes, or retargeting pools that include minors. Where our advertising platforms provide controls to exclude minors from ad targeting, we use those controls.
If we become aware that we have received personal information from an individual under the age of 18, we will delete that information promptly, remove any related chat records, and take reasonable steps to prevent further collection. If you are a parent or legal guardian and believe your child has provided personal information to us, please contact connect@output.systems with the subject line “Minor Data Request”. We will treat the request confidentially and confirm the deletion in writing.
This threshold does not affect the age-of-consent thresholds that apply between our clients and their own end users on client-facing systems; that relationship is governed by the client’s own privacy notice and applicable law.
13. Third-Party Links and Embedded Content
The Website may contain links to third-party websites and embedded content (such as scheduling widgets, video, or social embeds). Embedded content behaves as if you had visited the third-party website directly. These third parties may collect data, set cookies, and monitor your interaction with their content according to their own policies. We encourage you to review the privacy policy of any third-party service you interact with through the Website.
14. Marketing Communications, CASL, and Anti-Spam Compliance
We send marketing communications in compliance with Canada’s Anti-Spam Legislation (CASL), the US CAN-SPAM Act, the GDPR and UK GDPR consent rules, and other applicable electronic-marketing laws.
CASL (Canada). We send commercial electronic messages only where we have express consent (you asked to hear from us) or implied consent (for example, an existing business relationship or a published business email used for the purpose it was published for). Every commercial electronic message identifies Output Systems, gives our mailing address and a way to contact us electronically, and contains a clearly visible unsubscribe mechanism that works for at least 60 days and is honored within 10 business days.
US CAN-SPAM. Marketing emails include a valid physical mailing address, accurate sender information, non-deceptive subject lines, and a one-click unsubscribe honored promptly.
EU/UK. Direct marketing to individuals in the EU or UK is generally sent only with consent (or on the soft opt-in for similar products where permitted), and every message includes a straightforward way to opt out.
Your controls. You may opt out at any time by clicking unsubscribe in any marketing email, replying with the word “unsubscribe”, or contacting us at connect@output.systems. Opting out of marketing does not affect transactional messages you need to receive as a client (for example, billing, delivery of an assessment, or notices about a live system Output Systems operates on your behalf).
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. The updated version will be posted on the Website with a revised Last Updated date. Material changes will be communicated through additional means where practicable, such as an on-site notice or a direct message to active clients. Continued use of the Website after the effective date constitutes acceptance of the revised Policy.
16. Regulatory Authorities
If you believe your privacy rights have been violated, you may contact the appropriate regulator:
- Canada — Office of the Privacy Commissioner (priv.gc.ca).
- Quebec — Commission d’accès à l’information (cai.gouv.qc.ca).
- EU — your local Data Protection Authority (edpb.europa.eu).
- UK — Information Commissioner’s Office (ico.org.uk).
- California — California Privacy Protection Agency (cppa.ca.gov).
We ask that you contact Output Systems first so we can attempt to resolve your concern directly.
17. Governing Law
This Privacy Policy is governed by the laws of the Province of Ontario and the federal laws of Canada applicable therein. Disputes will be subject to the exclusive jurisdiction of the courts of the Province of Ontario, except where prohibited by applicable law in your jurisdiction. Nothing in this Policy limits your right to bring a complaint under the mandatory provisions of your local data protection laws.
18. Automated Decision-Making and AI
The Output AI Receptionist on the Website generates responses using artificial intelligence based on approved business information provided by Output Systems. The Receptionist does not make legally or similarly significant decisions about you on a solely automated basis. Its role is to answer questions, offer next steps, and hand a conversation to a person when the visitor requests one or the situation calls for it.
Where Output Systems designs and builds AI-powered systems for clients, those systems operate against approved knowledge and boundaries defined with the client, and any information they capture from an end user (for example, a lead capture or an appointment request) is passed to a human at that business to act on.
Where we use automation for spam filtering, fraud detection, or rate limiting, we do so on the basis of legitimate interests, and the outputs are used to protect the Website and its users rather than to make decisions with legal effect about individuals.
19. Data Breach Notification
In the event of a personal-data breach that creates a real risk of significant harm, we will report to the applicable regulator and notify affected individuals in accordance with the notification standards and timelines of each governing law (for example, without unreasonable delay under GDPR; as soon as feasible under PIPEDA; and consistent with US state breach-notification statutes where applicable). We maintain records of every breach involving personal information as required by law.
20. Do Not Track and Global Privacy Control
Web browsers offer a “Do Not Track” signal. There is no consistent industry standard for how to respond to Do Not Track, and we do not currently take separate action based on it. However, we do recognize the Global Privacy Control (GPC) signal for browsers that support it: when GPC is enabled, we treat it as an opt-out of the sale or sharing of personal information for cross-context behavioral advertising under the CCPA/CPRA and similar US state laws.


