1. Scope and who we are
Canis Viae Systems & Technologies ("Canis Viae," "we," "us," or "our") develops software and related services for organizations, including the ROOK program. This policy applies when you visit canisviae.com, create or use an account, use an organization portal, submit feedback, communicate with us, or use a Canis Viae service that links to this policy.
An organization may control information it provides to ROOK or directs us to process. In that situation, the organization's policies and agreement with us may also apply. Questions about organization-controlled information should first be directed to that organization.
2. Information we collect
Information you provide
- Account information, such as your name, email address, authentication information, and account status.
- Organization information, including organization name, membership, role, billing contacts, procurement details, and authorized administrator information.
- ROOK administration information, such as officer work identifiers, display names, badge numbers, agency email addresses, roles, device registrations, licensing records, package content, release information, and access or security events.
- Communications and feedback, including messages, ratings, optional contact details, support requests, and information you choose to provide.
- Billing and transaction information, such as invoice, purchase-order, payment status, and transaction references. Payment-card information is handled by our payment provider rather than stored directly by Canis Viae.
Information collected automatically
- Technical and security information, including IP-derived rate-limit identifiers, request timestamps, device or browser information made available in normal web requests, authentication events, and diagnostic or audit information.
- Security-verification information processed through Cloudflare Turnstile, which may include your IP address and browser or device signals.
- Cookies or similar storage that are necessary to authenticate users, maintain sessions, protect the service, and remember essential state. We do not currently use advertising cookies or cross-site behavioral advertising trackers.
3. ROOK location information
ROOK may offer optional device-location features. Under the current design, location is enabled by the user, processed locally on the Windows device, held temporarily in application memory, and used to match locally available reference information. Precise device location is not intended to be sent to or retained by Canis Viae, included in update inquiries, or written to a Canis Viae location history.
Your device, operating-system provider, or organization may apply separate settings or policies to location services. Do not use ROOK's location feature as an emergency, dispatch, tracking, evidentiary, or life-safety system.
4. How we use information
We use information to:
- provide, authenticate, secure, maintain, and improve the website and services;
- manage organization access, licensing, renewals, devices, releases, packages, and authorized officer access;
- process invoices, payments, purchase orders, and service communications;
- respond to support, feedback, security, privacy, and legal requests;
- detect misuse, enforce service limits, investigate incidents, maintain auditability, and protect users and organizations;
- comply with contracts, court orders, legal holds, and applicable law; and
- create aggregated or de-identified information that does not reasonably identify an individual.
We do not sell personal information. We do not use personal information for cross-context behavioral advertising or targeted advertising.
5. AI-assisted features
Authorized organization administrators may choose to send limited text or extracted document text to an AI-assisted support or drafting feature. The feature is designed to return an unsaved draft and is not permitted to save, publish, license, deploy, revoke, or otherwise change production data on its own. Canis Viae configures supported OpenAI API requests not to store the response as API application state, and our application audit logs are designed not to contain prompts, document contents, filenames, or responses.
Do not submit criminal justice information, case information, passwords, PINs, access codes, protected personal information, precise locations, or sensitive operational information to an AI feature. AI output may be inaccurate and must be reviewed by an authorized person before use.
6. When we disclose information
We may disclose information:
- to the organization that controls the applicable account, workspace, or content;
- to service providers that support hosting, databases, authentication, payment processing, email delivery, bot prevention, and optional AI features, subject to appropriate service terms;
- when you direct or authorize the disclosure;
- to comply with law, lawful process, an agency record obligation, or a valid legal hold;
- to investigate fraud, security incidents, abuse, or threats to rights and safety; or
- in connection with a merger, financing, acquisition, reorganization, or sale of assets, subject to applicable confidentiality and notice requirements.
Our principal service-provider categories currently include infrastructure and database hosting, payment processing, email delivery, security verification, and optional AI processing. Their handling of information is also governed by their own terms and privacy commitments.
7. Retention and deletion
We retain information only while it is reasonably needed for the purpose described in this policy, to provide a contracted service, protect the service, maintain required business and financial records, resolve disputes, enforce agreements, or comply with law. Retention varies by record type.
- Short-lived credentials and delivery payloads are deleted, invalidated, or rendered unusable when delivered, revoked, superseded, or expired.
- Routine technical and security records are retained for a limited operational or security period.
- Billing, contract, licensing, administrative audit, and transaction records may be retained for applicable tax, accounting, limitation, audit, and dispute periods.
- Organization content may be retained according to the customer's instructions, contract, legal holds, and applicable government record-retention schedules.
- Backups may retain deleted information for a limited recovery cycle before it is overwritten or expires.
Expiration of a ROOK license does not automatically delete organization packages, releases, officers, device records, or settings. Access may be restricted while the information remains available for renewal, export, legal compliance, or an authorized deletion process. When information is no longer required, we use methods intended to make it unreadable or unrecoverable, subject to backup and legal-hold limitations.
8. Government records and restricted information
ROOK is designed as a distribution and reference tool, not as an official records-management, dispatch, criminal-history, or case-management system. Government customers are responsible for identifying public records, assigning the correct retention schedule, issuing legal holds, and authorizing lawful disposition. We may preserve organization information when instructed by an authorized customer or required by law.
Unless Canis Viae and the customer expressly agree in writing to an approved configuration, users must not place criminal justice information, protected health information, payment-card data, Social Security numbers, protected home addresses, or other regulated or highly sensitive information in ROOK or our public forms.
9. Security and incident response
We use administrative, technical, and organizational safeguards designed for the nature of the information and service, including access controls, organization boundaries, protected communications, credential protections, validation, audit records, and release-integrity controls. No method of transmission or storage is completely secure.
If we discover a qualifying security breach, we will investigate and provide notices to affected individuals, customers, law enforcement, or regulators as required by applicable law. Report a suspected security issue to support@canisviae.com.
10. Your choices and privacy requests
You may ask to access, correct, or delete personal information that Canis Viae controls, subject to authentication and legal, contractual, security, public-record, and backup limitations. You may also ask questions about our processing or appeal the denial of a privacy request. When an organization controls the information, we may direct the request to that organization.
Send requests to contact@canisviae.com. Describe the request and the account or organization involved, but do not email passwords, PINs, criminal justice information, or other sensitive records. We may request information reasonably necessary to verify your identity and authority.
New Jersey residents may have additional rights when the New Jersey Data Privacy Act applies, including rights to access, correct, delete, obtain a portable copy, and opt out of certain sales, targeted advertising, or significant profiling. We do not currently sell personal data or process it for targeted advertising.
11. Daniel's Law and protected address information
Do not submit or publish a home address or unpublished home telephone number protected by New Jersey's Daniel's Law. An authorized person seeking removal of protected information from a Canis Viae-controlled Internet posting may send written notice to contact@canisviae.com. Please identify the specific location of the information and your authority to request removal without including additional protected information beyond what is necessary.
12. Children
Our website and services are intended for organizations and adults and are not directed to children under 13. We do not knowingly collect personal information online from a child under 13. If you believe a child has provided personal information, contact us so we can investigate and take appropriate action.
13. Changes to this policy
We may update this policy as our services or legal obligations change. We will post the revised policy with a new effective date and provide additional notice when required. Material changes apply prospectively unless law permits otherwise.
14. Contact
Questions or requests may be sent to contact@canisviae.com. For more information about our safeguards, visit our Security page.
