Plain about what we collect, how fast we delete it, and the rights you have. One standard, written to satisfy the strictest law that applies to you.
Golden Pod is a deterministic financial-ledger analysis service ("the Service") operated by Assay Systems, a sole proprietorship operating from Ottawa, Ontario, Canada ("Assay Systems", "we", "us", "our"). For any privacy question, or to exercise a right below, contact contact@golden-pod.com.
This policy is written to a GDPR-grade standard so that one document satisfies PIPEDA (Canada), the CCPA/CPRA (California/US), the Australian Privacy Act and APPs, and the EU/UK GDPR at once.
When you upload your own business data, we act as the controller of the limited account data we hold about you, and as a processor of the file you submit. When an accounting firm uploads a file containing its own clients' information, that firm is the controller and we are its processor, governed by a separate Data Processing Addendum that takes precedence for that data.
To provide the analysis you request and authenticate your account (performance of a contract); to bill you and prevent fraud, and to protect the Service from abuse and bots (legitimate interests); and to comply with law. We do not sell your personal information, and we do not use your uploaded content for advertising.
Your uploaded file and the generated report are deleted from our systems within 48 hours of processing, by an automated sweep — not a job you have to trust. We do not keep your source ledger beyond that window. The finding bundle behind your report link is retained only so the link keeps working; the original file is never part of it. Account and metering records are kept for the life of your account and a reasonable period afterward for tax and legal-record obligations, then deleted or anonymised. The one-way free-preview identifier (§3) is retained for up to 24 months so the one-preview-per-person limit works, then deleted.
We use the following providers to run the Service. Each processes data only to provide its service to us. This list is kept current and updated as it changes.
| Provider | Function | Region |
|---|---|---|
| Vultr Holdings | Cloud hosting, compute & temporary file storage (your file is stored on the server only while processing, then deleted per §5) | Toronto, Canada |
| RunPod, Inc. | LLM inference for the Strategy Summary | US / global |
| Cloudflare, Inc. | CDN, DNS, security & bot protection | Global edge |
| Resend | Magic-link sign-in emails | US (us-east-1) |
| Stripe, Inc. | Payment processing (billing only) | US / global |
Model-improvement scope limit. We improve our analysis models offline using synthetic and internally generated data. Your uploaded client files are not sent to third-party model providers (including Anthropic) for training. If this ever changes, we will update this policy and the list above before doing so.
We may also disclose data where required by law, to enforce our Terms, or in a business transfer, with notice where legally required.
We serve customers in Canada, the United States, Australia and elsewhere, and some providers operate outside your country. Where we transfer personal data across borders, we rely on appropriate safeguards — adequacy decisions where available, and Standard Contractual Clauses (or the UK IDTA / equivalent) with the relevant provider — so protection travels with your data.
Depending on where you live, you have some or all of these rights: to access, correct, delete, port, restrict, or object to our processing, and to withdraw consent. California residents also have the right to opt out of "sale"/"sharing" — we do neither. We will not discriminate against you for exercising a right.
Email contact@golden-pod.com to exercise a right; we respond within the time the law requires (generally 30 days; 45 under the CCPA) and may need to verify your identity. Where a firm is the controller of the data, we refer your request to that firm. You may also complain to your regulator — the Office of the Privacy Commissioner of Canada, the California Privacy Protection Agency, the Office of the Australian Information Commissioner, or an EU/UK supervisory authority.
Scope & applicable law. We voluntarily hold your data to this standard everywhere we operate — a commitment about how we handle data, not a statement that every regional law governs us regardless of the facts. Any given country's data-protection law, and any extra obligations it adds (such as appointing a local representative), applies where that law's own tests are met — for example where we offer the Service to, or monitor, people in that region. We take on those region-specific obligations if and when we begin serving customers there.
We protect data with encryption in transit, access controls, network-edge filtering, short retention (§5), and least-privilege handling of identifiers. No system is perfectly secure; if a breach affecting your personal data occurs, we will notify you and the relevant regulator as required by law.
The Service is for businesses and is not directed to children. We do not knowingly collect data from anyone under 16.
We may update this policy. Material changes will be posted here with a new "Last updated" date and, where required, notified to you directly. Continued use after changes take effect means you accept the updated policy.
Assay Systems — Privacy · contact@golden-pod.com · 150 Gloucester St, Ottawa, ON K2P 0A6, Canada.