CHIEF OSBETA

Enterprise trust documentation by Megawebvision

RETURN TO CHIEF

PRIVACY / DATA GOVERNANCE

Privacy Policy

This Privacy Policy explains how Megawebvision Inc. handles information in connection with CHIEF, its executive operating system and managed AI operations service.

Last updated: August 9, 2026

01 / Scope

Scope

This Policy applies to CHIEF public pages, customer-requested workflows, connected services and related business communications operated by Megawebvision Inc. It applies together with the applicable customer agreement and Data Processing Addendum where Megawebvision processes information on a customer's behalf.

02 / Organization

Who We Are

CHIEF is provided by Megawebvision Inc., 6860 Av. Irwin, Montreal, Quebec H4E 2S9, Canada.

Megawebvision is the organization responsible for determining how information is handled for its own business purposes and acts as a service provider or processor when handling Customer Personal Data under a customer's documented instructions.

03 / Accountability

Privacy Officer / Privacy Contact

Privacy Officer: Timur Grigorchuk, Founder, Megawebvision.

Contact the Privacy Officer at legal@megawebvision.com or by mail at the address above. This role is responsible for privacy governance, customer privacy inquiries and Québec privacy responsibilities unless a written delegation is documented.

04 / Collection

Information We Collect

The information handled depends on the service and the customer's instructions. It may include:

  • Contact and business identity information
  • Information a customer submits or makes available for a CHIEF workflow
  • Information from connected services the customer authorizes
  • Technical request information needed to operate and protect the service
  • Business communications, support requests and security reports

05 / Customer input

Information Customers Provide to CHIEF

A founding-member request may include name, work email, role, company, website, company size, selected value areas, an operating constraint, timing and the request source. The public intake applies field limits, validation, same-site checks, a honeypot and rate limiting before storing a private JSON object.

Customers should provide only the information reasonably needed for the requested operating work and should not submit regulated or highly sensitive information unless the applicable service and agreement expressly support it.

06 / Connections

Information From Connected Services

When a customer explicitly authorizes a connected service, CHIEF may process the information needed for the requested capability. Current connector configuration identifies Gmail, Google Calendar, GoHighLevel, Jobber, Google Search Console, Google Analytics and Semrush as supported service connections. Access is default-off and scoped to the relevant request, account, client, property or location.

See the Subprocessor Registry for organizations that may process information in connection with those services.

07 / Operations

Technical / Usage Information

The public intake may receive request metadata needed to validate and protect the endpoint, such as request origin information, forwarded network address used for rate limiting, content type, request size and submission time. We do not use this information to create advertising profiles.

08 / Purpose

How We Use Information

  • Provide, operate and secure CHIEF
  • Respond to founding-member, enterprise, privacy and security inquiries
  • Prepare and advance customer-requested operating work
  • Process authorized connected-service and optional AI-assisted workflows
  • Prevent abuse, unauthorized access and unsafe external actions
  • Maintain records needed for contractual, legal and operational accountability
  • Improve the service only in accordance with the applicable agreement and published customer controls

09 / Lawfulness

Legal Bases Where Applicable

Depending on the context and applicable law, Megawebvision may rely on performance of a contract or steps requested before entering a contract, legitimate interests in operating and protecting the service, consent where required, and legal obligations. Where Megawebvision processes Customer Personal Data as a processor, the customer determines the purposes and documented instructions.

10 / AI

AI Processing

AI processing may be used when a customer-requested workflow requires model-assisted synthesis. The documented CHIEF operating path uses an optional OpenAI Responses API integration for non-authoritative draft synthesis and requests `store: false`.

Customer information is sent to an AI provider only to perform the requested functionality, subject to the customer agreement, the DPA and the Subprocessor Registry . Customer content is not used to train, fine-tune, distill, publicly benchmark or improve a shared model unless the customer affirmatively opts into a separately stated purpose.

11 / Providers

Service Providers and Subprocessors

Megawebvision uses selected hosting, storage, AI and connected-service providers to operate CHIEF. Providers may process information only for the documented service function and applicable contractual purposes. The authoritative public provider list is maintained at /subprocessors .

12 / Control

No Sale of Personal Information

We do not sell Customer Personal Data. We do not use Customer Personal Data for cross-context behavioral advertising. Providers receive information only to provide the contracted or customer-requested service, subject to applicable service-provider, processor or contractor restrictions.

13 / Website

Cookies / Analytics

CHIEF uses Google Analytics 4 to measure aggregate use of its public pages and application routes. The CHIEF implementation sends a standardized page category rather than full URLs, query strings, page titles, client names, form values, workspace content, document content or other user-entered text. Google signals and ad-personalization are disabled, and CHIEF does not load Google Tag Manager or client advertising-account tags.

Google Analytics may use analytics cookies or similar technology. Client Workspace routes may also use necessary browser storage for authentication and service operation. Necessary browser storage or cookies may be used by linked protected client workspaces and connected services. Those contexts may have additional notices and controls. If this practice changes, this Policy will be updated and any consent required by law will be requested.

14 / Transfers

International Processing / Transfers

Megawebvision and its providers may process information in Canada, the United States or another location where a provider operates. A specific provider region is not assumed where it is not stated in the applicable service configuration or agreement.

Where required, transfers are supported through applicable contractual safeguards, including the European Commission Standard Contractual Clauses or another lawful transfer mechanism. See the DPA for incorporation terms.

15 / Lifecycle

Data Retention

Megawebvision retains information only for as long as needed for the purpose collected, the customer agreement, legitimate business continuity and security needs, or applicable legal obligations. Specific periods depend on the service component and are provided in the applicable agreement or enterprise review materials.

16 / Safeguards

Data Security

CHIEF uses HTTPS for public transport, scoped and default-off connector access, protected secret handling, request validation, rate limiting, private storage settings and audit controls for security-relevant external writes. More detail is available in Security Architecture & Controls .

No method of transmission or storage can eliminate every risk. Megawebvision maintains safeguards proportionate to the information and service context.

17 / Requests

Individual Privacy Rights

Depending on applicable law, individuals may have rights to access, know, correct, delete, restrict, object to, or port personal information, and to withdraw consent where processing relies on consent. Rights may be limited by law, privilege, identity verification, security requirements or the rights of others.

18 / Europe

GDPR Rights

For processing subject to the GDPR, individuals may request access, rectification, erasure, restriction, portability and objection, and may object to processing based on legitimate interests. They may also withdraw consent and complain to a supervisory authority. Megawebvision supports customers with processor-assistance obligations described in the DPA.

19 / California

California CCPA / CPRA Rights

California residents may have rights to know or access, correct, delete and receive information about disclosures, subject to applicable exceptions. We do not sell or share personal information for cross-context behavioral advertising. Requests may be submitted to the Privacy Officer, and we will not discriminate for exercising a right.

Where Megawebvision processes information as a service provider or contractor, it uses that information only for permitted business purposes and follows the applicable customer instructions.

20 / Canada

Canadian / PIPEDA Rights

For processing subject to PIPEDA, Megawebvision supports accountability, identified purposes, meaningful consent where applicable, limiting collection, use and retention, safeguards, openness, individual access and correction. Individuals may contact the Privacy Officer with questions or complaints and may contact the Office of the Privacy Commissioner of Canada where appropriate.

21 / Québec

Québec Privacy Rights / Law 25

Megawebvision's Privacy Officer is Timur Grigorchuk, Founder, Megawebvision. The Privacy Officer oversees privacy governance, transparency, retention and destruction practices, confidentiality-incident response and assistance with individual requests under Québec privacy legislation.

Individuals may request access to and correction of personal information and may ask questions about collection, use, communication, retention and destruction. Megawebvision will handle confidentiality incidents in accordance with applicable Québec requirements.

22 / Contact

Data Access / Correction / Deletion Requests

Submit a request to legal@megawebvision.com with the request type, the relationship to Megawebvision or the relevant customer, the information needed to locate the record and a safe way to respond. We may need to verify identity and may coordinate with the customer where Megawebvision acts as processor.

23 / Children

Children

CHIEF is a business service and is not directed to children. We do not knowingly collect personal information from children through the public service. Contact the Privacy Officer if you believe a child has provided information.

24 / Updates

Changes to Policy

Megawebvision may update this Policy when the service, law or privacy practices change. The updated version will be posted here with a new effective or updated date. Material changes may also be communicated through the applicable customer relationship.

25 / Contact

Contact

Megawebvision Inc.
6860 Av. Irwin
Montreal, Quebec H4E 2S9
Canada

Privacy Officer: Timur Grigorchuk, Founder, Megawebvision
legal@megawebvision.com