1. Who We Are
Off Grid Software is operated by Deliri Software Inc., located in Scarborough, Ontario, Canada.
In this Privacy Policy, "Off Grid Software", "we", "us", and "our" mean Deliri Software Inc., operating as Off Grid Software. "You" means a visitor, customer, client, user, administrator, developer, employee, contractor, or other person who uses our websites, marketing sites, landing pages, web application, account dashboard, hosted services, APIs, downloadable binaries, support channels, bug, witness, products, services, or related tools.
2. Scope
This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information when you:
- Visit our websites, marketing sites, landing pages, or public pages.
- Contact us, request support, or communicate with us.
- Buy, subscribe to, download, install, activate, or use bug or witness.
- Create an account, sign in, or use our web application, account dashboard, hosted services, APIs, license systems, update systems, support systems, billing systems, or product telemetry.
- Hire us for websites, applications, APIs, hosting, email setup, maintenance, support, implementation, testing, compliance evidence, or related services.
This policy is intended for business-to-business use. Our products and services are not intended for personal, family, household, child-directed, or consumer use.
Our websites, products, and services are not directed to children. We do not knowingly collect personal information from anyone under the age of majority. If we learn that we have collected personal information from a child without legally required consent, we will delete it.
3. Personal Information We Collect
We may collect the following categories of information, depending on how you use our services:
- Contact and account information: name, business email, phone number, company name, job title, billing contact, technical contact, security contact, and support contact.
- Billing and transaction information: invoices, subscriptions, payment status, payment processor records, tax information, billing address, statement descriptors, chargeback records, dispute records, and collection records.
- Business and project information: requirements, repositories, domains, systems, environments, policies, controls, audit objectives, compliance frameworks, project records, support requests, and client-provided materials.
- Product and license information: downloaded binaries, product version, build hash, license key, activation status, seat count, organization identifier, entitlement, update request, device or environment identifier, device label, operating system, IP address, user agent, per-command usage counters (command name and invocation count only, with the counting window, never command arguments), error reports, and diagnostic events.
- witness evidence and timestamping information: evidence identifiers, hashes, digests, timestamp requests, timestamp responses, timestamp tokens, TSA provider records, audit trail records, request times, response times, account identifiers, license identifiers, IP addresses, and related technical logs.
- bug workflow information: bug records, issue identifiers, proof-of-fix records, test results, command results, repository metadata, branch names, commit identifiers, build metadata, and diagnostic logs stay on your systems and in your repositories; bug's license check-ins do not transmit them. We receive such materials only if you send them to us yourself, for example in a support request.
- Website and analytics information: pages viewed, referrer, approximate location derived from IP address, device/browser information, cookies, pixels, analytics events, and security logs.
- Communications: emails, support tickets, chat messages, call notes, meeting notes, feedback, feature requests, complaints, and dispute records.
We do not intentionally require source code, secrets, private keys, credentials, health information, payment card numbers, government identifiers, or other highly sensitive information unless an agreement or support request expressly requires it. You should not send that information to us unless we have agreed in writing to receive it through an approved channel.
4. witness Timestamping and TSA Records
witness is designed to help create and preserve evidence records. To do that, witness may need to call an Off Grid Software server. Our server may then call a third-party timestamp authority, certificate authority, or related trust service provider to obtain a timestamp token or timestamp response.
For witness, we may keep records needed to prove, verify, audit, troubleshoot, bill, secure, or reproduce the timestamping process. These records may include:
- The request time and response time.
- The account, license, organization, project, or user associated with the request.
- The evidence hash, digest, identifier, or other timestamping input.
- The timestamp authority selected or used.
- The timestamp token, response, certificate chain, verification status, and related metadata.
- Server logs, IP addresses, error logs, retries, and security events.
Unless the product configuration or signed agreement says otherwise, witness should send hashes, digests, identifiers, metadata, and timestamping materials needed for proof, not full source files or full private client datasets. You are responsible for configuring witness correctly and for not submitting regulated data, secrets, credentials, personal information, or confidential materials unless our agreement expressly permits that use.
5. Downloadable Binaries, Updates, and Activation
bug and witness may be distributed as downloadable binaries, CLIs, agents, or other executable software. When you download, install, activate, update, or use those binaries, we may collect information needed to:
- Provide downloads and updates.
- Verify licenses and entitlements.
- Prevent fraud, abuse, unauthorized sharing, and account compromise.
- Maintain compatibility, reliability, security, and auditability.
- Diagnose crashes, defects, installation problems, and support requests.
- Enforce subscriptions, seat limits, quotas, and product terms.
Some product features may not work without contacting our servers. This can include license activation, subscription verification, update checks, witness timestamping, support diagnostics, and abuse prevention.
6. How We Use Information
We use information to:
- Provide, operate, secure, support, bill, and improve our services and products.
- Create and preserve witness timestamping and audit records.
- Deliver downloads, updates, licenses, subscriptions, hosting, email support, maintenance, and professional services.
- Respond to support requests, disputes, complaints, and security incidents.
- Verify identity, authorization, account ownership, and payment status.
- Detect, investigate, prevent, and respond to fraud, abuse, security threats, product misuse, unauthorized access, chargebacks, and legal claims.
- Maintain accounting, tax, compliance, legal, operational, and business records.
- Communicate about service changes, invoices, renewals, product updates, incidents, security notices, and administrative matters.
- Analyze aggregated, de-identified, or statistical usage information.
- Enforce our Terms of Service, orders, invoices, licenses, and agreements.
7. How We Share Information
We may share information with:
- Hosting providers, cloud providers, database providers, storage providers, logging providers, security providers, monitoring providers, and backup providers.
- Payment processors, banks, card networks, billing systems, tax providers, accountants, collection providers, and dispute-resolution providers.
- Timestamp authorities, certificate authorities, trust service providers, and verification providers needed for witness timestamping.
- Email, SMS, communications, customer support, CRM, analytics, and product operations providers.
- Contractors, advisors, auditors, lawyers, insurers, and service providers who need access to help us provide, secure, bill, improve, or defend our services.
- Law enforcement, regulators, courts, arbitrators, government authorities, infrastructure providers, or third parties when required or permitted by law, legal process, security investigation, abuse investigation, or rights enforcement.
- A buyer, successor, lender, investor, acquirer, or restructuring party in connection with a financing, merger, acquisition, asset sale, insolvency, reorganization, or similar transaction.
We do not sell personal information as a standalone data broker. We do not intentionally disclose client confidential information publicly except as authorized, required by law, or needed to provide, secure, enforce, or defend our services.
8. Cookies, Analytics, and Similar Technologies
Our websites and services may use cookies, pixels, local storage, logs, and similar technologies for security, authentication, preferences, analytics, performance, fraud prevention, and product operations.
You can control cookies through your browser settings, but some features may not work correctly if cookies or similar technologies are disabled.
9. Legal Bases and Consent
We collect, use, and disclose personal information for purposes that a reasonable person would consider appropriate in the circumstances, including to provide requested products and services, perform agreements, operate our business, comply with law, protect rights and security, and obtain consent where required.
Some collection, use, or disclosure is necessary to provide the product or service. For example, witness timestamping requires communication with our server and may require communication with a timestamp authority. License activation and subscription verification may require communication with our servers.
Where a use is optional, we will provide available choices where practical.
Subject to legal, regulatory, and contractual restrictions and reasonable notice, you may withdraw consent to our collection, use, or disclosure of your personal information by contacting our Privacy Officer. If you withdraw consent, some products, features, or services may stop working or may no longer be available to you, and we may continue to retain and use information where the law permits or requires it.
10. Retention
We retain information for as long as reasonably needed for the purposes described in this policy, including service delivery, support, security, timestamp verification, audit trails, billing, tax, accounting, dispute resolution, legal compliance, backup, and enforcement.
When personal information is no longer reasonably needed for these purposes, we delete, destroy, or anonymize it within a reasonable time, subject to the rest of this section.
witness timestamping records may be retained for longer periods because their purpose is to provide durable evidence, verification, audit history, and proof of timing. If a client needs a specific retention period, deletion schedule, or evidence-retention obligation, it must be stated in a signed order, data processing addendum, or product configuration.
witness evidence custody is an active paid service unless a signed order says otherwise. Accepted witness evidence may be placed under a default ninety-day technical retention lock. While an account remains paid and in good standing, we may extend the scheduled expiry date for eligible retained evidence according to the active plan and order. If payment fails or the account is cancelled or lapses, we may provide a thirty-day cure period and a further thirty-day export-only wind-down period. After that, unpaid, cancelled, lapsed, or abandoned evidence may be deleted, allowed to expire, made inaccessible, or otherwise disposed of unless a paid-up archive, legal hold, court order, law, technical retention lock not yet expired, or signed order requires retention.
We may retain backup, archival, legal, fraud-prevention, chargeback, accounting, and security records even after an account is closed where reasonably necessary or legally permitted.
11. Security and Breach Notification
We use reasonable administrative, technical, and physical safeguards appropriate to the nature of the information and the size and scope of our business. Safeguards may include access controls, least-privilege access, encryption, logging, monitoring, backups, vendor controls, secure development practices, and incident response procedures.
No system is perfectly secure. You are responsible for securing your own systems, accounts, credentials, repositories, devices, networks, environments, identity providers, backups, and product configurations.
If a breach of security safeguards involving personal information under our control creates a real risk of significant harm to an individual, we will report the breach to the Office of the Privacy Commissioner of Canada, notify affected individuals as soon as feasible, and notify any other organization or government institution that may be able to reduce or mitigate the harm, as required by PIPEDA. If a provincial or other applicable privacy law also requires breach reporting or notice, we will comply with that law as well.
We keep a record of every breach of security safeguards involving personal information under our control, whether or not it creates a real risk of significant harm, and retain those records for as long as required by law. If you are a business customer, you remain responsible for assessing and reporting incidents affecting information you control, and for notifying your own users, employees, customers, and regulators as your own obligations require.
12. Cross-Border Processing
We operate from Scarborough, Ontario, Canada. Our service providers, infrastructure, timestamp authorities, payment processors, support providers, and other vendors may process or store information in Canada, the United States, or other countries where they or their subprocessors operate.
Information processed outside your jurisdiction may be subject to the laws, lawful access rules, courts, regulators, or government authorities of that jurisdiction.
13. Access, Correction, and Requests
You may request access to or correction of your personal information by contacting us. We may need to verify your identity and authority before responding.
We may refuse, limit, or delay a request where permitted by law, including where the request would disclose another person's information, reveal confidential or security-sensitive information, interfere with legal rights, compromise an investigation, or impose disproportionate effort.
If you have a question, concern, or complaint about how we handle personal information, contact our Privacy Officer using the contact information in Section 17. If we do not resolve your concern to your satisfaction, you may complain to the Office of the Privacy Commissioner of Canada or to the privacy regulator responsible for your jurisdiction.
14. Client-Controlled Data
For professional services and business customer accounts, the client may control information about its users, employees, contractors, customers, systems, repositories, evidence, logs, and environments. If your information was provided to us by one of our clients, we may direct you to that client for access, correction, deletion, or consent requests.
15. Regulated and Sensitive Data
Do not provide health information, payment card data, government identifiers, children's information, highly sensitive personal information, export-controlled data, production secrets, private keys, passwords, or credentials unless a signed agreement expressly permits it and the required safeguards, addenda, or channels are in place.
16. Changes to This Policy
We may update this Privacy Policy from time to time. The "Last updated" date will show when the policy was last changed. If changes are material, we will provide notice through reasonable means, such as our website, account portal, email, or product notice.
17. Contact
We have designated a Privacy Officer who is accountable for our compliance with this policy and applicable privacy law.
Privacy contact:
Privacy Officer: Ase Deliri Deliri Software Inc., operating as Off Grid Software 40 Frank Faubert Drive Scarborough, Ontario M1C 5H7, Canada Email: ase.deliri@offgridsoftware.ca
18. Source Notes for Lawyer Review
This policy was prepared for review against Canadian private-sector privacy requirements, including PIPEDA principles described by the Office of the Privacy Commissioner of Canada: accountability, identifying purposes, consent, limiting collection, limiting use/disclosure/retention, accuracy, safeguards, openness, individual access, and challenging compliance.
Counsel's first-pass review should focus only on:
- Whether this policy is adequate for an Ontario-based B2B software and services business.
- Whether witness timestamping records require a separate data-processing or evidence-retention addendum.
- Whether any planned handling of PHI, payment card data, government IDs, secrets, or regulated data requires separate terms before launch.
- Whether the privacy contact email and any required business-name details are correct before publishing.