Privacy Policy
Distronode Corporation • Last Updated: September 10, 2026 • Version 2026-09-10
On this page
01. Overview & Accountability
Distronode Corporation ("we," "us," or "our"), a Canadian corporation federally incorporated under the Canada Business Corporations Act, operates District AI, an AI-powered voice receptionist platform. We are committed to protecting your privacy in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA) in Canada and Quebec's Law 25, the General Data Protection Regulation (GDPR) and the UK GDPR in Europe, and the consumer privacy laws of United States states.
Which role we play depends on whose information it is, and the distinction matters. We are the Data Controller for information about our own visitors, account holders and prospects: what you tell us when you sign up, contact us, or browse this website. For the content inside a customer's workspace, including the information their callers give the AI receptionist, we are that customer's processor and we handle it only on their instructions, as set out in our Data Processing Agreement. If you are a caller wanting your information corrected or deleted, the business you called decides that, and we will help them do it.
Our operations are headquartered at RBC WaterPark Place, 20 Bay Street, 11th Floor, Toronto, Ontario, Canada.
02. What We Collect and Why
This table covers the information we hold as controller, about visitors, account holders and prospects. The last row is the content inside a customer's workspace, which we hold as that customer's processor and touch only on its instructions.
| Category | Examples | Why we collect it | Basis | Source |
|---|---|---|---|---|
| Identity and contact | Name, business name, email address, phone number, business address | Create and administer your account, respond to you, invoice you | Contract; legitimate interests | You |
| Account credentials and sign-in history | Password hash, two-step verification enrolment, and the time, IP address, country and device of each successful sign-in | Authenticate you, detect misuse of your account, notify you of a sign-in from a new location | Contract; legitimate interests (security) | You; your browser |
| Billing | Card details held by Stripe (we see only the last four digits and the card brand), billing address, tax identifiers, invoices | Charge subscriptions and usage, collect tax, keep the records tax law requires | Contract; legal obligation | You; Stripe |
| Usage and device data | Pages visited, features used, browser and operating system, referring campaign, consent choice, edge-detected country | Operate and secure the service, measure our marketing where you consent, remember your preferences | Legitimate interests; consent for analytics and advertising cookies | Your browser; our servers; our edge network |
| Support correspondence | Your name, email address, subject and message text, and the replies in that thread | Answer your request and keep a record of it for the retention period below | Contract; legitimate interests | You |
| Marketing preferences | Newsletter subscription, the express-consent box at checkout, unsubscribe requests | Send you product updates only where you agreed, and stop when you ask | Consent | You |
| Workspace content (as processor) | Caller phone numbers, call audio, transcripts and summaries, contacts, messages, appointments, knowledge-base documents | Provide the receptionist and inbox on the business's instructions | The business's own lawful basis; we act on its instructions under the DPA | Callers; the business; carrier caller-ID lookup; enrichment providers where the business enables them |
03. Lawful Basis for Processing
Contract
To create and run your account, deliver the receptionist and inbox you subscribed to, bill you, and answer your support requests.
Legal obligation
To keep the billing and tax records the law requires, to keep records of consent under anti-spam law, and to answer lawful requests from regulators and courts.
Consent
When you accept analytics and advertising cookies, subscribe to our newsletter, tick the marketing box at checkout, or connect a third-party account such as Google. You can withdraw it at any time.
Legitimate interests
To keep the service secure and prevent fraud, to understand how the product is used so we can improve it, to market to businesses in the ways the law allows without express consent, and to enforce our terms. Where we rely on this basis under the GDPR or UK GDPR you can object, and we will stop unless our grounds override yours.
04. Google Consent Mode v2 & GTM
To maintain compliance with the GDPR, the ePrivacy Directive, and Québec's Law 25, we use Google Consent Mode v2 integrated via Google Tag Manager (GTM-WML4TTR3). For visitors in the European Economic Area, the United Kingdom, Switzerland, and Canada, our site denies the storage of tracking and advertising cookies by default until you explicitly consent.
In these regions, tracking tags stay dormant until you take an explicit "Accept" action, at which point updated consent signals are transmitted to our analytics stack. You can change or withdraw your choice at any time using the Cookie preferences link in the site footer.
05. Cookies & Similar Technologies
We set a small number of first-party cookies. None of them are sold or shared for cross-site tracking.
distronode_session: essential. Keeps you signed in; expires after 14 days.
dn_consent: essential. Remembers your cookie choice for 12 months.
dn_attrib: analytics. Records which campaign or referral first brought you to the site (180 days). In consent-required regions it is set only after you accept.
Google Analytics cookies (_ga and related): analytics and advertising, set through Google Tag Manager only where Consent Mode permits it.
li_fat_id: advertising, set by the LinkedIn Insight Tag and only after you accept. LinkedIn has no Consent Mode equivalent, so where prior consent is required the tag does not load at all until you consent. It identifies your browser to LinkedIn so we can measure which of our LinkedIn ads led to a sign-up, and LinkedIn sets its lifetime at 30 days.
oauth_workspace_id: essential, short-lived (10 minutes). Carries your workspace through an account-connection flow.
dn_country: essential (24 hours). Records the country our edge network detected for your connection, so we can apply the right consent rules and show prices in the right region. It holds a two-letter country code and nothing else.
Workspace selection: essential. When you belong to more than one workspace, remembers which one you are working in so pages load the right data. It holds a workspace identifier and is a preference, never a permission: your access is always re-checked against your membership.
Connection-flow state: essential, short-lived. When you link a Google, Microsoft or social account, a single-use value is stored so we can verify the response came back from the flow you started. Discarded as soon as the connection completes.
We also use browser storage (localStorage) for interface preferences and a copy of your cookie choice. To change your choice, use the Cookie preferences link in the footer.
When you are signed in to the dashboard and have consented to analytics, our product-analytics SDK (Mixpanel) also keeps its identifiers in localStorage rather than in cookies, so it sets no cookies of its own. It is described in section 06.
06. Advertising & Analytics
We measure site usage with Google Analytics 4, loaded through a first-party, server-side Google Tag Manager container hosted in Canada (Stape, at sst.distronode.com). Consent Mode governs what these tags may store, as described above.
We also measure our own LinkedIn advertising, by two paths: the LinkedIn Insight Tag, which runs in your browser and sets the li_fat_id cookie described in section 05, and the LinkedIn Conversions API, which sends conversion events from our servers.
What we send is limited to website and conversion events, a one-way hashed (SHA-256) form of the email address, and that cookie's identifier, so a sign-up can be matched to the ad that led to it; we do not send plaintext email addresses, IP addresses or mobile advertising identifiers. LinkedIn has no Consent Mode equivalent, so where prior consent is required the tag does not load at all until you accept, and you can withdraw at any time via Cookie preferences in the footer.
Purchase conversion reporting
When a purchase completes, we report the conversion to Google Analytics and Google Ads from our servers so campaign performance can be measured. This can include a one-way hashed (SHA-256) form of the account email as a match key. In regions where consent is required, these reports are sent only if you consented to analytics and advertising; you can withdraw at any time via Cookie preferences. We do not sell personal information, and we do not share it for cross-context behavioral advertising beyond this conversion measurement.
Product analytics
Inside the signed-in dashboard we use Mixpanel to understand how the product itself is used. It runs in the dashboard only, never on our marketing pages, and it is not used for advertising. The data is held on a Mixpanel project with European data residency, events are keyed to a one-way hashed (SHA-256) account identifier, and IP geolocation is switched off, so no location is derived from your connection. The in-browser part is consent-gated: where prior consent is required it does not load until you accept, and you can withdraw at any time via Cookie preferences in the footer.
A small number of lifecycle events (an account or workspace being created, a subscription purchased, a workflow run completed, a call handled) are sent from our own servers instead, without cookies and without loading anything in your browser. That is first-party service telemetry about our own platform, and it is described alongside everything else on our sub-processors page.
07. AI Processing Infrastructure
We use Google Cloud Vertex AI and Gemini models. Your content is isolated per workspace by row-level security in our own databases, and it is never used by us to train public or foundational models.
Call audio is transcribed and voiced by specialized speech providers acting on our behalf: Deepgram for the engine a new workspace starts on outside Canada, Amazon Transcribe and Amazon Polly, in Montreal, for the engine a new Canadian workspace starts on. ElevenLabs, AssemblyAI, Inworld, and Cartesia are available as optional voice engines, depending on the voice a workspace selects. Where a workspace enables the optional video avatar, video sessions are rendered by Tavus.
Tenant isolation: row-level security
08. Call Recordings & Caller Data
District AI answers calls on behalf of the businesses that use it. When you call a District AI number, the call is answered by an AI assistant and may be recorded, transcribed, and summarized. The phone number you call from may be checked against a carrier lookup that returns the caller name on record and the type of line, so the business can recognize returning customers. We do not buy spam or risk scoring on callers. This information is stored in the business's private workspace and is controlled by that business; we process it on their behalf.
Where a workspace enables lead enrichment (District Global Intelligence), we supplement business-contact records with professional information, such as company, role, and business email, sourced from licensed B2B data providers (currently People Data Labs and Apollo) and carrier caller-ID lookups (Twilio). Enrichment data is used only inside that workspace's CRM and is never sold.
09. Automated Decision-Making
The receptionist answers, qualifies and books on the instructions of the business you called, and that business can read, correct and override anything it records. We do not use personal information to make decisions that produce legal effects on you, or similarly significant effects, by automated means alone. Where a business chose to use District AI in a way that would, it is responsible under its own law for the notice and the human review that requires, and our Data Processing Agreement asks it to provide them.
10. Data Residency & International Transfers
You choose your workspace's home data region when you sign up: the United States (default, on Google Cloud), Canada (Montreal), Europe (Frankfurt, serving customers across the EU and the UK), or Asia-Pacific (Singapore). Those latter three run on Amazon Web Services, which took them over from their previous hosting providers in August 2026 without any of them changing city. Workspace content, including contacts, call recordings, transcripts, and CRM records, is stored in an isolated database in that region. Since August 2026, the live audio of a call a Canadian workspace makes or receives in the browser is processed in Montreal as well, on Amazon Web Services (ca-central-1).
For a Canadian workspace, the language model runs in Montreal on every engine but the realtime one. Google does not serve that engine's single listen-and-speak model from Montreal, so a Canadian workspace that chooses it is processed in the United States (us-east4), and the engine picker labels it that way. Since September 2026, a new Canadian workspace starts on an all-Canadian engine that runs speech recognition and speech synthesis in Montreal too. It became available in August 2026 and was off by default until September 2026; nothing was changed on a workspace that had already chosen one, and a Canadian workspace on one of the other engines still has speech recognition and speech synthesis run in the United States.
None of the engine changes alter where a telephone call is carried. Since September 2026, a telephone call for a Canadian workspace is handled in Montreal in both directions, provided we issued the number through Telnyx. A call the workspace places is originated there and handed to Telnyx at its Montreal site, and a call arriving on a Canadian number we issue through Telnyx is delivered to us from Telnyx's own Canadian gateway and answered there.
A call arriving on a number issued through Twilio, whether Canadian or a United States one, is still hosted on our United States media node, because Twilio publishes no Canadian point of presence; a call that arrives on a European number is answered in Europe. What a carrier does with a call before it reaches us, or after we hand it over, is the carrier's to describe and not ours.
Some coordination data (account sign-in records, workspace directory and membership, and phone-number routing entries) and payment records processed by Stripe are handled in the United States. Where personal data crosses borders, we use Standard Contractual Clauses (SCCs) and applicable adequacy decisions to ensure your data remains protected.
Five things deliberately do not stay wholly inside your region, and we would rather name them than let you find them. First, support: a support request goes to our support desk, which runs on one Atlassian site hosted in Canada and serving all four regions, so your name, email address and the text of the request are held in Canada. If your workspace is in Canada that is your own region. If it is in Europe, the United States or Asia-Pacific, it is not, and for a European workspace that is a transfer to a country the European Commission recognises as providing adequate protection for personal data held by commercial organisations.
Second, if a workspace switches its knowledge base from the documents it uploads to the linked support knowledge base, the text of each question asked is sent to Atlassian to compose the answer. That second one is off unless a workspace turns it on.
Third, live call telemetry: when a call is carried over the phone network, in either direction, while it is in progress and when it ends, we send an event describing that call to an internal message bus, so the dashboard can show the call as it happens. For a United States or Asia-Pacific workspace that bus is in the United States. For a European workspace it is in Europe: since August 2026 the event is carried and stored in Frankfurt and consumed by our dashboard service in Europe. For a Canadian workspace it is in Canada: since September 2026 the event is carried and stored in Montreal and consumed by our dashboard service in Canada.
What is still United States for a European workspace is the moment the event is created for a call that ARRIVES over the phone network on a number issued through Twilio, because such a call reaches us on United States infrastructure and the systems that generate its events run there. Since August 2026 a call arriving on a European number is answered by our systems in Frankfurt, so its events are created there. For a call we place outbound on a European workspace's behalf, that moment moved as well: since August 2026 those calls are originated from our equipment in Frankfurt, so their events are created there too.
A Canadian workspace has the same split, drawn on the carrier rather than the country. Since September 2026 a call we place, and a call arriving on a Canadian number we issue through Telnyx, both run on our Montreal machine, so their events are created in Montreal. A call arriving on a number issued through Twilio, Canadian or United States, is answered in the United States and its event is created there before it is carried to Montreal and stored.
That event carries the caller's name and the phone numbers, and the transcript, the AI summary and the link to the recording; the call audio itself is not sent. A meeting or video call held in the browser produces no such event.
Fourth, your inbox: when a message reaches you or goes out, we push a routing event to that same message bus so the inbox updates without waiting, carrying the other party's phone number or email address and nothing of what was written. It follows the same split, and for a European workspace it is carried and stored in Europe; it is created in Europe as well whenever our European origin served your request, and in the United States when the geographic router sent you to ours there. A Canadian workspace works the same way from September 2026: carried and stored in Montreal, and created in Montreal whenever our Canadian origin served your request.
Fifth, number registration documents: when you submit a registration for a telephone number in a country whose regulator requires one, the documents you provided are sent to the carrier for that number, Twilio, whose registration service runs in the United States. Handing them to the regulator's process is the entire purpose of collecting them. The copy we store ourselves stays in a storage bucket in your workspace's own region, and the retention section below says when both are deleted. The data residency map sets out each of these per data type.
Separately from those five, and not workspace content, there is the operational state that keeps the service running: rate limits, short-lived caches, webhook idempotency claims and the lock that picks which origin runs a scheduled job. It lives in a shared database in the United States that every region touches on every request, Europe and Canada included. A second database in Frankfurt holds the rate-limit counters for our European origin, and since September 2026 a third in Montreal holds them for our Canadian origin. None of them holds call audio, a transcript, a message or a contact record, and where a key name would otherwise contain an email address, phone number or IP address it carries a one-way hash instead.
The full list of third parties that process data on our behalf, with each one's purpose, data category, and region, is published on our sub-processors page, and the per-data-type breakdown is on the data residency map.
11. Data Retention
Workspace records (contacts, call records, transcripts, messages) are kept while your account is active and deleted when your account is deleted.
Archived call-recording audio is deleted on a rolling retention schedule, 90 days by default; a different default retention window can be arranged as part of an enterprise agreement.
Number registration documents: the registry extracts, proofs of address and, for registrations in an individual's name, government identity documents you provide when registering a telephone number in a country whose regulator requires them are kept while the registration is in use. They are deleted 30 days after the number is released or the registration is withdrawn, and immediately when your account is deleted.
Encrypted database backups expire on a fixed schedule, with all copies deleted within approximately eight weeks.
Erasure requests are honored without undue delay and within 30 days.
Product analytics: when you delete your account, or ask us to erase your data, we forward a deletion request to Mixpanel through its data-deletion API. That request completes within 30 days.
Support requests: a resolved support request is deleted 365 days after it was opened, from our support desk and from our own copy of it. That schedule runs on requests you send us through this website or from the dashboard. A request you raise in our help centre, or start by emailing us, is not on it, because we hold no record of our own to sweep; ask us and we will delete it. Requests being worked on are kept until resolved. Deleting your account, or asking us to erase your data, begins that erasure immediately. Where a conversation cannot be matched to you, or our desk refuses the deletion, we finish it by hand within the 30 days above.
Sign-in history: the time, IP address, country, browser or app, and sign-in method recorded for each successful sign-in to your account, is kept for 90 days and then deleted automatically. We keep it so that you, and we, can answer whether a sign-in was yours, and it is what triggers the notice we email you when your account is used from a country it has not been used from recently. Failed sign-in attempts are not kept here.
Billing and tax records (invoices, receipts and the tax identifiers on them) are kept for six years from the end of the year they relate to, which is what Canadian tax law requires, and then deleted. Stripe holds the payment method itself under its own retention rules.
Contact-form inquiries and marketing preferences are kept until you withdraw consent or ask us to delete them, or until we no longer need them to answer you. An unsubscribe is kept on file so that we do not contact you again.
Web traffic metadata and diagnostics (IP addresses and request metadata at our edge network, and the operational logs and error diagnostics our monitoring providers hold) are kept for short, fixed windows set by each provider and are not used to build profiles of you.
12. Security
We protect personal information with the controls described on our Sovereign page. They are TLS 1.2 or higher on every public endpoint, database storage encrypted at rest by the provider hosting each region, and tenant isolation enforced by PostgreSQL row-level security. Stored credentials are encrypted again with Google Cloud KMS, secrets are managed, access to production is least-privilege, and rate limiting sits in front of authentication. No method of transmission or storage is completely secure, and we do not promise that ours is.
If a breach of our security safeguards creates a real risk of significant harm to you, we notify you and the regulators that PIPEDA, Law 25 and the GDPR require, and we keep a register of such incidents. A customer whose workspace is affected is notified under the timelines in our Data Processing Agreement, so that it can meet its own duties to its callers.
13. Your Rights
Under PIPEDA, Quebec's Law 25, the GDPR and the UK GDPR, you have the right to access, rectify or erase your personal information, to object to processing based on legitimate interests, and to request portability. Workspace owners can export their workspace data as structured JSON from the dashboard, and can delete their account, and the data in it, from the same place.
If you connected a Facebook, Instagram, or Threads account, see data deletion requests for how to have the data tied to that account erased, and to check the status of a request you have already made.
You can withdraw consent at any time where consent is the basis we rely on, without affecting what was done before you withdrew it: for cookies, use Cookie preferences in the footer; for anything else, write to us. We verify that a request comes from the person it concerns before acting on it, and we may ask for enough information to do that. We answer within 30 days; where the law lets us extend that period we will tell you why and by how much. We may decline a request that is manifestly unfounded or excessive, and we will explain why.
If you are not satisfied with our answer, you can complain to the Office of the Privacy Commissioner of Canada, or to the Commission d'acces a l'information du Quebec for Quebec personal information. For information processed under the GDPR or the UK GDPR, you can complain to the supervisory authority in your country or to the UK Information Commissioner's Office. We would rather hear from you first, and legal@distronode.com reaches the person who can fix it.
For anything you cannot do from settings, contact our Privacy Officer at legal@distronode.com, or start with our Sovereign portal:
Sovereign14. Marketing Communications
We send product updates and offers only where the law allows. At checkout, the box that asks whether you want them is unchecked and optional; ticking it is your express consent under Canada's anti-spam law (CASL), and it is recorded with your account. Where CASL or your own law permits it, we may also email a business contact about services relevant to their role without express consent. Every marketing email carries an unsubscribe link, and an unsubscribe takes effect at once. Service messages about your own account, such as invoices, security notices and changes to our terms, are not marketing and continue for as long as you have an account.
15. Children
Our services are for businesses and are not directed to anyone under 18. We do not knowingly collect personal information from a child, and if you believe a child has given us some, write to legal@distronode.com and we will delete it.
16. United States Residents
For residents of California and other US states with consumer privacy laws: we do not sell personal information. The consent-gated conversion measurement in section 06 sends a one-way hashed email to Google Ads and LinkedIn, matching a sign-up to its ad. Under California law that may count as sharing for cross-context behavioral advertising, so you can opt out at any time: choose Decline, or the Cookie preferences / Do Not Sell or Share link in the footer. A Global Privacy Control signal from your browser is treated as that opt-out automatically, without asking you to confirm, unless you have chosen Accept here. We honor requests to know, correct, and delete in any state, without discrimination, through section 13's channels.
17. Changes to This Policy
We may update this policy as the service and the law change. Each version is identified by the date at the top of this page, and our sitemap carries the same date. For a material change we give account holders at least 30 days' notice by email or in the dashboard before it takes effect; for anything else the new version applies from the date shown. Earlier versions are available from legal@distronode.com on request.
18. Contact
For any inquiries, please contact our Privacy Officer, Sean Dean, founder and CEO:
19. SMS & Messaging
Distronode Corporation uses SMS for critical service notifications to account holders, such as an alert about your own account or service. We verify accounts by email, not by text message, and we send no SMS one-time passcodes: a message claiming to be a Distronode login code is not from us.
Businesses on the Platform can also send and receive SMS, MMS, and WhatsApp messages with their customers through our telephony partners (Twilio, Sinch, and Telnyx); those conversations are stored in the workspace's inbox and controlled by that business. Where a business uses District AI to answer its phone, we may also send a text on that business's behalf to a member of the public who telephoned it and asked for one during the call. That number comes from the record of that call, and it is never supplied by the caller or chosen by the AI model.
No Sharing of Messaging Consent Data
We do not share, sell, or provide your mobile phone number or messaging consent data to third parties or affiliates for marketing or promotional purposes. All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
Opt-Out
You may opt-out of SMS communications at any time by replying STOP to any message received from our system. For assistance, reply HELP. Message frequency varies and is typically one or two messages per call. Message and data rates may apply. The full messaging programme is described in section 20 of our Terms of Service.
20. Google User Data & Limited Use
When you connect a Google account to Distronode, we request only the scopes needed to power the features you enable:
Google Calendar
Used solely to check your availability and create or update appointments that you or your AI agent schedule on your behalf. We do not read or store calendar data beyond what is required to complete these actions.
Google Contacts (read-only)
Used solely to let you import your existing contacts into your workspace CRM. We access this data only at your explicit request and never modify your Google Contacts.
Distronode's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Limited Use Commitments
- We do not use Google user data for advertising, and we do not sell it.
- We do not use Google user data to train, or improve, generalized or foundational AI/ML models.
- We do not transfer Google user data to third parties except as necessary to provide or improve the connected feature, to comply with applicable law, or as part of a merger/acquisition with appropriate notice.
- Humans do not read Google user data unless you give explicit consent to view specific messages, it is necessary for security or to comply with law, or the data has been aggregated and anonymized.
- You may disconnect a Google account at any time from your workspace settings. We delete the stored credentials and ask Google to revoke the grant, so access ends at both ends rather than only at ours. You can confirm it, or remove access yourself at any time, from the third-party access section of your Google account.

