WORKING DRAFT — NOT APPROVED FOR PRODUCTION, CUSTOMER ACCEPTANCE OR CONTRACTUAL USE. External legal review is required. This draft is an engineering/legal-preparation artifact, not legal advice. The contracting party is intentionally not named until the owner confirms the correct legal entity. Document: Sovariq Privacy Notice Document ID: SOVARIQ-PRIVACY-NOTICE Version ID: DRAFT-2026-08-25-01 Locale: en-CA Status: PRE-RELEASE DRAFT / EXTERNAL PRIVACY-LEGAL REVIEW REQUIRED 1. Purpose This draft describes the current Website/service data flows in plain language and records items that must be confirmed before production. It is not a final privacy notice. 2. Privacy contact / accountable person [BLOCKING — OWNER + LEGAL REVIEW REQUIRED] The final notice must identify the accountable privacy contact and the approved method for privacy questions, access/correction requests and complaints. 3. Information the public Website may collect The public Website is designed to minimize personal and congregation information. Depending on the feature used, current Website services may process: - support request reply email, category, subject and message; - technical anti-abuse/security metadata needed to protect support and public endpoints; - minimal congregation identity/licence/entitlement metadata used by trusted backend services; - payment/checkout references, status, amount/currency and other bounded business evidence returned by the payment processor; - internal administrator identity, authorization and security/audit records. 4. Information the public Website is not intended to store as general business data - congregation Master Workbooks; - publisher/person lists or profiles; - meeting schedules, assignments or other congregation operational scheduling content; - raw payment-card numbers, CVV values or bank-account credentials; - passwords, MFA secrets, access tokens or private keys in business records/logs. 5. Why information is used Current purposes are limited to: - answering support, feedback, bug and security reports; - establishing/maintaining authorized service, congregation identity and licence entitlement; - initiating and reconciling payment/licensing activity without storing payment instruments; - delivering approved software/release information; - detecting abuse, securing the service, auditing privileged actions and investigating incidents; - meeting legal/accounting obligations once the applicable production policy is approved. 6. Payments Payment entry occurs on Stripe-hosted Checkout. Sovariq application components are not intended to receive or store raw card or bank credentials. Bounded processor references and transaction/business status may be retained where needed for entitlement, support, accounting, refund/dispute and audit purposes. 7. Service providers Current Website infrastructure uses Google Cloud/Firebase services. Payment processing uses Stripe. Other providers (for example, a future transactional-email provider) must be added to the production notice only after they are selected, approved and actually used. 8. Cookies, browser storage and analytics Current accepted Website source has no Sovariq advertising analytics, Google Analytics/gtag, marketing pixels, analytics cookies, or Sovariq-created localStorage/sessionStorage analytics identifiers. The Website therefore does not add a tracking-consent banner merely to imply tracking that is not implemented. Essential provider-controlled mechanisms may be used where required for security/authentication functionality on protected internal surfaces. If non-essential analytics or tracking is introduced later, privacy/consent review must be reopened before production enablement. 9. Retention [BLOCKING — LEGAL/ACCOUNTING/OWNER REVIEW REQUIRED] The engineering policy is to keep personal information only as long as needed for the approved purpose, while preserving legally/operationally necessary security, financial, contractual, release and immutable identity evidence. Exact production retention periods have not been approved and must not be invented in this draft. 10. Access, correction and deletion [BLOCKING — LEGAL PROCESS REQUIRED] The final notice must explain how an individual may request access/correction/deletion where applicable, how identity is verified, and what information may need to be retained for security, contractual, accounting, fraud-prevention or legal reasons. Deletion must not break the congregation’s non-recyclable technical identity or erase other people’s congregation operational data. 11. Security Sovariq uses technical and organizational controls intended to limit access, keep public client data access fail-closed, separate staging from production, avoid long-lived deployment keys where practical, and prevent secrets/payment instruments from being stored in ordinary Website business data. No system can be represented as risk-free; final legal wording requires review. 12. International/region processing [BLOCKING — LAUNCH-JURISDICTION REVIEW REQUIRED] The final notice must accurately identify applicable processing/storage locations, cross-border disclosures and legal safeguards for the production architecture and selected launch regions. 13. Children / age restrictions [BLOCKING — LEGAL/PRODUCT REVIEW REQUIRED] No final age/minor-use statement is approved in this draft. The final notice/terms must reflect the actual intended customer population and applicable law. 14. Changes to this notice Material privacy-notice changes must receive a new version/hash and be communicated as required by applicable law. Historical approved versions should remain traceable. 15. Reference compliance baseline for review This draft is prepared for external review against applicable Canadian/Québec privacy requirements and the actual launch jurisdictions. Engineering references used for the review checklist include the Office of the Privacy Commissioner of Canada’s PIPEDA business guidance/fair-information principles and Québec Commission d’accès à l’information Law 25 guidance. These references are not a claim that a particular statute applies in every transaction or that compliance has been legally certified. End of working draft.