Cobnect Privacy Policy

Effective date: July 24, 2026

Applies to: Cobnect Inc. websites, applications, products, and related online services (the “Services”).

Cobnect Inc. (“Cobnect”, “we”, “us”, “our”) respects your privacy. This Privacy Policy explains how we collect, use, disclose, and protect personal information in Canada, including under the Personal Information Protection and Electronic Documents Act (PIPEDA) and substantially similar provincial private-sector laws in Québec, British Columbia, and Alberta.

About Cobnect:  Cobnect Inc. is a Canadian technology company that provides web-based tools, reports, dashboards, and related services to help homeowners, real estate professionals, home inspectors, contractors, municipalities, organizations, and other users better understand residential home performance, including energy, comfort, greenhouse gas, retrofit, benchmarking, and sustainability-related indicators.

1. Who we are and how to contact us

Organization: Cobnect Inc.
Privacy Contact: Cobnect Privacy Officer
Privacy Email Address: privacy@cobnect.com


Cobnect’s Privacy Officer is responsible for compliance with this Policy and applicable privacy laws.

2. Scope and legal framework

This Policy explains how we collect, use, disclose, store, and protect personal information in connection with the Services.

  • Primary law: PIPEDA (Personal Information Protection and Electronic Documents Act) applies to Cobnect’s private-sector activities and to interprovincial/international data flows.
  • Province-specific: For activities occurring within the provinces of Québec, British Columbia, and Alberta, Cobnect also complies with those provinces’ private-sector privacy laws (Québec’s private-sector law as amended by Law 25; BC PIPA; AB PIPA).
  • If any provision of this Policy conflicts with applicable law in your jurisdiction, the law prevails.
  • For information about the EnerGuide status of Cobnect outputs and eligibility for incentives, see our Terms of Use.

3. Definitions

  •  “Personal information” means information about an identifiable individual and includes information that can reasonably be linked to an individual (e.g., a specific property address provided by a user). Certain business contact information, such as a person’s name, title, business address, business telephone number, and business email address, may be excluded from the definition of personal information under PIPEDA when used solely to communicate with that person in their employment, business, or professional capacity. Where applicable law treats business contact information as personal information, Cobnect will handle it in accordance with this Policy and applicable law.
  • “Service provider” means third-party vendors, consultants, hosting providers, analytics providers, and other organizations engaged by Cobnect to process personal information strictly on Cobnect’s behalf and under Cobnect’s instructions.
  • “Partner” means third-party entities that collaborate with Cobnect but determine their own purposes and means in certain activities. Independent Partners are not under Cobnect’s control and may process personal information in accordance with their own privacy practices. Examples include municipalities, licensed real estate brokerages and their affiliated platforms, utilities, and program administrators responsible for incentives and rebates.

4. What we collect

Depending on how you use the Services, we may collect:
A. Identification, account, and contact information — name, email address, province, user role, organization name where provided, account credentials, account preferences, and authentication information.
B. Property & household — street address, postal code, dwelling type, year built, number of storeys, equipment and building-envelope attributes and retrofit history.
C. Utility & usage — self-reported bills; where you authorize, consumption/interval data from utilities or connected devices; incentive eligibility inputs.
D. Images & media — photos/video you upload for remote assessment (e.g., equipment nameplates, attic/basement).
E. Device & technical — IP address, device/browser/OS, pages viewed, timestamps, approximate geolocation derived from IP, and cookie identifiers (see Section 10).
F. Communications — emails, messages, support tickets, survey responses, and call recordings where notice is given.
G. Transactional — subscriptions, purchases; Cobnect does not store full payment card numbers (payments are processed by PCI-compliant providers).
H. Professional, B2B, municipal, and organizational information — business contact information, organization name, role/title, brokerage or inspection-firm information, contractor or supplier business details, licence or certification information where provided, service areas, municipal/program affiliation, and information related to authorized professional, client-related, portfolio, program, API, widget, or white-label use.


We collect personal information (i) directly from you; (ii) automatically from your device/browser; (iii) from service providers; and (iv) from third-party data sources and APIs with your authorization or as permitted by law (e.g., municipal/assessment records, utility interfaces, smart-home platforms, building-permit/open-data registries, mapping/geo datasets, and licensed data providers). When such data relates to an identifiable individual, we treat it as personal information.

5. Purposes for collection, use, and disclosure

Cobnect collects and uses personal information only for purposes a reasonable person would consider appropriate, including to:

  1. Provide and maintain the Services — account creation, identity/authentication, reports/dashboards, benchmarks, troubleshooting.
  2. Generate indicators and recommendations — statistical/AI models produce informational outputs to help you understand a property and potential upgrades.
  3. Marketplace & matching (at your request) — connect you with contractors, suppliers, energy advisors, utilities, and program administrators; share only what is necessary to obtain quotes, validate incentives, schedule, or perform work.
  4. Support & communications — respond to inquiries, send service notices and policy updates; marketing communications only with consent (see Section 13).
  5. Security & integrity — prevent, detect, and investigate fraud, abuse, and security incidents; protect accounts and our platform.
  6. Compliance — meet legal, tax, accounting, and regulatory obligations; manage disputes; enforce agreements.
  7. Research & product development — de-identify and aggregate information to improve models and features (see Section 9).


Consent and lawful authority: Cobnect relies on consent, contractual necessity, legal obligations, and other lawful bases permitted by applicable Canadian privacy laws. Consent may be express or implied depending on the context, the sensitivity of the information, the user’s reasonable expectations, and applicable law. Where required, including for sensitive information, connected accounts, utility or device data, partner disclosures, marketing communications, or non-essential cookies, Cobnect will seek express consent. You may withdraw consent at any time, subject to legal or contractual restrictions and reasonable notice. If you withdraw consent, some Services or features may no longer be available or may not function properly.

6. Disclosures (who we share with and why)

Cobnect does not sell or rent personal information. We disclose personal information only as follows:

a) Service providers: Hosting/cloud, analytics, email and communications tools, payment processors, customer support, security and logging. These providers act on Cobnect’s instructions under written terms that require appropriate safeguards and prohibit secondary use.

b) Newsletters and mailing lists: If you subscribe to newsletters or similar communications, your name and email may be shared with a third-party provider that manages our mailing lists and delivers emails on our behalf.

c) Strategic partnerships: We may cooperate with municipalities, brokerages, utilities, program administrators, or similar partner organizations to deliver incentives or products, collect voluntary survey insights, or conduct joint outreach/education. We disclose only what is necessary and only with your consent or as otherwise permitted by law. You may opt out of partner marketing at any time (see Section 13).

d) API providers and data licensors. Where we retrieve house characteristics or usage data via an API or licensed feed (e.g., assessment attributes, energy usage, device telemetry), the provider may act (i) as our service provider (processing under contract) or (ii) as an independent organization (processing under its own privacy policy). We limit requests to the minimum fields needed and keep audit logs of access. We prohibit uses inconsistent with this Policy. Where feasible, we identify the API provider at the time of connection. We do not disclose raw third-party data onward except (i) to provide the Services you request, (ii) to our service providers under contract, or (iii) as required or permitted by law.

e) Contractors and suppliers at your request. When you ask us to connect you with a contractor/supplier/energy advisor/utility/program administrator, we disclose only the information required to fulfill your request.

f) Legal and regulatory. Courts, regulators, or law enforcement where required or permitted by law (e.g., subpoenas, lawful requests, protection of rights, safety, and security).

g) Corporate transactions. In a merger, acquisition, financing, or sale, personal information may be transferred under confidentiality obligations and only as permitted by law.

7. Third-party APIs & connected accounts

  1. Authorization and revocation. Where required, we will request your authorization before connecting to third-party APIs or data feeds. You may revoke access at any time; upon revocation we cease further pulls and invalidate tokens, subject to legal/operational retention requirements.
  2. Minimization and purpose limitation. We request only the minimum fields needed for the stated purpose (e.g., generating a report, validating incentives) and do not use API data for unrelated purposes.
  3. Security of credentials. We do not store your third-party account passwords. Tokens are encrypted, access-controlled, rotated as appropriate, and logged.
  4. Accuracy and corrections. If you dispute the accuracy of third-party data, contact us. We will annotate or update our records and, where feasible, help direct you to the source or transmit a correction request.
  5. Independent organizations. Where the API provider is an independent organization, its privacy policy governs how it handles data. Cobnect limits its own use and disclosure to the purposes described in this Policy.

8. Google Sign-In & OAuth Data

If you choose to sign in or connect an account using Google or another third-party authentication provider, Cobnect receives the account information you authorize, such as your user ID, name, email address, and profile image. Cobnect uses this information to authenticate you, create and manage your account, secure access, and personalize your experience. Cobnect does not sell Google user data, use Google user data for advertising, or disclose Google user data except to operate the Services, support account security, comply with law, or work with service providers acting on Cobnect’s behalf. We do not store your Google password. OAuth tokens, where used, are protected using technical and organizational safeguards such as encryption, access controls, logging, and revocation controls. You may revoke Cobnect’s access through your Google Account permissions or by contacting Cobnect. If you disconnect Google or close your Cobnect account, we will cease further access and delete or de-identify OAuth-derived data unless retention is required for legal, tax, accounting, security, fraud-prevention, or dispute-resolution purposes.

If Cobnect requests access to sensitive or restricted Google scopes in the future, such as Gmail, Drive, or Calendar data, Cobnect will request explicit consent and will use that data only for user-facing features you authorize, in accordance with applicable Google API Services User Data Policy requirements and applicable law.

9. De-identified and aggregated information

Cobnect may de-identify, anonymize, or aggregate information derived from use of the Services so that it no longer identifies an individual, or so that it is not reasonably capable of identifying an individual when used alone or in combination with other reasonably available information. To the fullest extent permitted by applicable law, Cobnect may use, retain, disclose, and otherwise process de-identified, anonymized, or aggregated information for analytics, benchmarking, model training, model validation, quality assurance, product development, research, security, reporting, business planning, and improving Cobnect’s services and technology. Cobnect takes reasonable measures designed to prevent re-identification and does not attempt to re-identify anonymized or de-identified information except where permitted or required by law, including for security, fraud prevention, debugging, legal compliance, or testing and improving de-identification safeguards. Where Québec law or another applicable law imposes additional requirements, Cobnect will comply with those requirements.

10. Cookies and similar technologies

Cobnect uses cookies and similar technologies (such as pixels, local storage, and software development kits) to operate the Services, remember your preferences, understand usage, and, where permitted, deliver relevant content. A cookie is a small file stored on your device when you visit a website.

We use the following categories:

  • Strictly necessary cookies: required for core functions such as signing in, session management, security, and load balancing. These are always active and cannot be disabled through our cookie banner, as the Services will not function properly without them.

 

  • Analytics and performance cookies: These help us understand how the Services are used so we can measure traffic, identify errors, understand feature usage, improve pages and reports, and improve the performance and reliability of the Services.

 

  • Marketing and preference cookies: Where used, these help us understand referral sources, measure campaign performance, deliver or measure relevant content, promotions, or advertisements, and understand the effectiveness of our outreach.

 

Where required by applicable law, Cobnect will obtain consent before enabling non-essential cookies or similar technologies, including analytics, functional, preference, marketing, advertising, or tracking technologies. In Québec, where applicable, technologies that identify, locate, or profile a user will remain disabled by default and will be activated only after the user provides consent through Cobnect’s cookie banner.

You can accept or decline non-essential cookies through Cobnect’s cookie banner where available. If you decline non-essential cookies, Cobnect will not enable non-essential analytics, functional, preference, marketing, advertising, or tracking technologies, but strictly necessary technologies will remain active. You can also manage or delete cookies through your browser settings. Disabling certain technologies may affect website functionality or prevent parts of the Services from working properly.

11. Data residency, transfers, and accountability

Cobnect’s primary application hosting and core data storage are located in Canada, using Canada-based cloud infrastructure. Some service providers that support the Services, such as analytics, email delivery, authentication, customer support, security, or payment processing providers, may process or access limited personal information outside Canada.
Where personal information is processed, accessed, stored, or transferred outside Canada, it may be subject to the laws of that jurisdiction. Cobnect remains accountable for personal information under its control and uses contractual, technical, and organizational safeguards designed to provide a level of protection comparable to that required under Canadian privacy law.
Where Québec privacy law applies, Cobnect will conduct any required assessment before communicating personal information outside Québec and will implement required contractual or other safeguards.

12. Security

We employ safeguards appropriate to the sensitivity of the information, including encryption in transit and at rest where feasible, role-based access controls, multi-factor authentication for administrative systems, network monitoring and logging, vulnerability management, personnel training, vendor due-diligence, and incident response procedures. No method of transmission or storage is absolutely secure; Cobnect strives to prevent loss, theft, misuse, and unauthorized access. Users are also responsible for maintaining the confidentiality of their login credentials and for using secure devices, browsers, networks, and email accounts when accessing the Services.

13. Marketing and your choices

We send commercial electronic messages only with consent (express or implied) and include identification details and a functional unsubscribe. You can:

  • Unsubscribe from Cobnect marketing at any time using the link in our emails;
  • Opt out of partner marketing (municipalities/utilities/programs) by contacting privacy@cobnect.com;
  • Accept or decline non-essential cookies through Cobnect’s cookie banner, where available.

Withdrawing consent does not affect service or transactional notices.

We maintain records of marketing consents and unsubscribe requests in accordance with CASL.

14. Automated decision-making and profiling

Cobnect uses algorithms, statistical methods, AI, and machine-learning models to generate informational, asset-based outputs, such as energy-related scores, predicted energy use, greenhouse gas indicators, heat-loss indicators, comfort-related indicators, benchmarking, retrofit opportunity flags, and potential incentive-related information. These outputs are informational and are not, by themselves, determinative of legal rights, financial rights, rebate eligibility, lending outcomes, insurance outcomes, property value, official audit results, or regulatory status.

Cobnect does not use automated processing to make decisions that produce legal or similarly significant effects concerning you unless we inform you as required by applicable law. Where applicable law provides rights regarding decisions based exclusively on automated processing, including Québec privacy law where applicable, Cobnect will provide required notice, information about the principal factors and parameters, correction rights, and human review or contestation rights where required.

15. Access, correction, and other rights

Subject to identity verification, legal exceptions, and applicable law, you may have the right to:

  • Access your personal information and obtain information about how it has been used and disclosed;
  • Request corrections to incomplete or inaccurate information;
  • Withdraw consent to further collection, use, or disclosure (we will explain any implications);
  • Request source information for data originating from third parties, where feasible and lawful;
  • Request explanations for decisions made exclusively by automated processing that significantly affect you and seek human review where provided by law.
  • Delete your account and associated personal information. We will delete it unless we are required to retain certain records for legal, tax, accounting, fraud-prevention, or dispute-resolution purposes.

Requests should be directed to privacy@cobnect.com. Cobnect will respond within applicable statutory timelines (generally 30 days, with permitted extensions).

16. Retention

We retain Personal Information only as long as needed for the purposes described in this Policy or as required by law. Unless a longer period is required for legal, tax, accounting, fraud-prevention, or dispute-resolution purposes (or due to a legal hold), our standard retention periods are: (a) account, profile, and property data: account life and up to 24 months after closure or last activity; (b) communications and support records: 24 months; (c) transaction and billing records: 7 years; (d) web logs and analytics: 12–24 months (shorter for analytics, longer for security). When the original purposes have been achieved, we destroy the data or anonymize it in accordance with applicable law; anonymized (irreversibly non-identifiable) data may be retained without a fixed limit for research and statistical purposes.

17. Breach response and notification

Cobnect maintains incident-response procedures and keeps records of all security incidents.

  • Under PIPEDA, Cobnect reports to the federal privacy regulator and notifies affected individuals if a breach of security safeguards creates a real risk of significant harm, and it keeps required records.
  • Under Alberta PIPA, Cobnect notifies the Alberta regulator without unreasonable delay where there is a real risk of significant harm; the regulator may require notice to individuals.
  • Where other provincial requirements apply (e.g., Québec), Cobnect will comply with incident reporting and notification obligations.

consumer protection laws, you agree that the courts located in Toronto, Ontario will have exclusive jurisdiction over any dispute arising out of or relating to these Terms or the Services, unless Cobnect and you agree in writing to binding arbitration or another dispute-resolution process.

18. Children’s privacy

The Services are intended for adults. Consistent with our Terms of Use, you must be at least 18 years of age, or the age of majority in your province or territory (whichever is greater), to create an account or use the Services. Cobnect does not knowingly collect personal information from anyone under the age of majority. If we become aware that we have collected personal information from a person under the applicable age without valid consent, we will delete it. Where personal information relating to a minor is provided by an authorized adult (for example, a property owner’s information submitted by an authorized professional), it is handled in accordance with this Policy.

19. Third-party links and external services

The Services may link to or integrate with third-party websites, applications, payment processors, mapping tools, analytics tools, contractors, suppliers, energy advisors, utilities, program administrators, incentive providers, or other external services. Those third parties are governed by their own terms, privacy policies, and practices. Cobnect is not responsible for third-party privacy practices, security practices, content, services, eligibility determinations, or decisions.

Where you connect a third-party account or data source, Cobnect will explain the requested access and will use the data as authorized and consistent with this Policy. Where you ask Cobnect to share information with a third party, such as a contractor, supplier, utility, program administrator, municipality, brokerage, or partner organization, that third party may process the information under its own privacy policy unless acting as Cobnect’s service provider.

20. Changes to this Policy

We may update this Policy to reflect changes in our practices or legal requirements. The updated Policy will be posted with a new effective date. Where required, we will provide notice or seek renewed consent.

21. Complaints

If you have a question, request, or complaint about Cobnect’s privacy practices, please contact:

Cobnect Privacy Officer
Cobnect Inc.
Suite 1201, 1200 Bay Street, Toronto, ON, Canada, M5R 2A5
Email: privacy@cobnect.com
General inquiries: info@cobnect.com

We will review and respond to privacy requests and complaints in accordance with applicable law. If your concern is not resolved, you may contact the Office of the Privacy Commissioner of Canada or, where applicable, your provincial privacy regulator.