1. Who is responsible for your information
eSora Labs Ltd., a Canadian company headquartered in Toronto, Ontario, is responsible for personal information handled through this website, which it operates for its eSora Studio division. “eSora Studio” is a brand and division of eSora Labs Ltd., not a separate legal entity.
Accountability for privacy rests with eSora Labs Ltd. as an organisation. You can reach the people responsible for privacy at info@esoralabs.com (attention: “Privacy”). We handle privacy questions ourselves rather than through an automated system, and we respond as promptly as applicable law requires.
This policy is written to satisfy the openness and accountability principles of the Personal Information Protection and Electronic Documents Act (PIPEDA), which is our starting legal framework, together with provincial requirements where they apply.
2. Scope of this policy
This policy covers personal information handled through the eSora Studio website: principally project enquiries and privacy requests, both of which reach us by email, plus limited technical information processed by the content-delivery and font services that serve the Site’s assets.
It does not cover: (a) information we handle for a client under that client’s signed agreement — that processing is governed by the client’s instructions and any data processing agreement between us, and the client’s own privacy policy applies to it; or (b) the websites of third parties we link to. Where Studio acts on a client’s instructions, this policy is not a substitute for a data processing agreement.
3. What we collect — and what we do not
We collect only what a person actively sends us or what serving infrastructure necessarily processes:
- Enquiry contents. If you use the quote configurator or contact us, we receive the business contact details and project information you choose to send: typically your name, work email, company, role, and a description of the project, timeline, and budget.
- Privacy request details. If you submit a privacy request, we receive the request type, your name and email, and the details you provide so we can locate and act on your information.
- Correspondence. If you email us, we receive your email address and whatever the message contains.
- Technical log data (third parties). The services that deliver the Site’s fonts and code libraries — Google Fonts, Fontshare, and the jsDelivr CDN — necessarily process your IP address, browser user-agent, and similar request data in their standard server logs when your browser downloads those assets. We do not receive those logs in the ordinary course.
What this Site does not do: there are no user accounts, no payments or subscriptions, no file uploads, no recruitment forms, no chat widgets, no embedded videos, no scheduling tools, no client portals, no analytics, and no advertising or social-media pixels. We do not collect precise location data, and we do not buy data about you from data brokers. The only browser storage we use is described in the Cookie Policy and stays on your device.
4. How we collect it
Directly from you, through your own email client. Both the quote wizard and the privacy-request form work the same way: they compose a pre-filled message on your device and open it in your email application, addressed to info@esoralabs.com. Nothing is transmitted until you press send. This Site has no server-side form processing and no database of submissions.
Automatically, at the infrastructure layer only. When your browser loads the Site, it requests fonts and libraries from Google Fonts, Fontshare, and jsDelivr. Those providers process standard connection data (IP address, user-agent, timestamp) to serve the files, under their own privacy policies. This Site itself sets no tracking cookies and runs no analytics.
Point-of-collection notice. The following notice appears next to our forms, so you do not have to dig through this policy to learn the essentials:
5. Why we use it
We use personal information for these purposes, and only these:
- Responding to enquiries — reading what you sent, replying, and discussing a potential project;
- Establishing and delivering engagements — if an enquiry becomes a signed agreement, using your business contact details to plan, staff, invoice, and deliver the work;
- Processing privacy requests — verifying, locating, and acting on access, correction, deletion, withdrawal, or complaint requests within applicable deadlines;
- Legal and security purposes — keeping records needed to demonstrate consent or comply with law, and protecting the Site and our correspondence from misuse; and
- Marketing, only with separate opt-in permission — see section 7. We do not add enquirers, privacy requesters, or clients to promotional campaigns by default.
We do not use personal information submitted through this Site to train artificial-intelligence models. We do not sell personal information, and we do not share it for third parties’ own marketing.
6. Data practices at a glance
This table connects each category of information to its purpose, its recipients, and how long it is kept. Retention is expressed as criteria rather than invented fixed periods; the decisions behind it are recorded in our internal retention register.
| Category | Purpose | Recipients | Retention |
|---|---|---|---|
| Enquiry contents (name, work email, company, project brief) | Respond to the enquiry; scope a potential engagement | eSora Labs Ltd. staff handling new business (info@esoralabs.com mailbox) | Kept for the life of the conversation; enquiries that do not proceed are deleted within 24 months of last contact unless a longer period is required by law |
| Client business contact details (post-engagement) | Deliver the engagement; contractual and accounting records | eSora Labs Ltd. project and finance staff | Duration of the engagement plus the limitation/retention period required for tax and legal records under Canadian law (generally up to 7 years) |
| Privacy request records | Verify, process, and document the response to your request | Privacy-responsible staff at eSora Labs Ltd. | Kept only as long as needed to fulfil the request and demonstrate compliance, then deleted or anonymised (target: 24 months) |
| Consent record (esora-consent) and quote draft (esora-cfg) | Remember your cookie choices and quote prefill | Nobody — stored in your browser’s localStorage on your device only; never transmitted to us | On your device until you clear it; consent record re-asked after 12 months |
| Technical log data (IP, user-agent) at asset CDNs | Serving font and code files to your browser | Google Fonts, Fontshare, jsDelivr (their own logs, under their own policies) | Set by each provider’s standard log retention; we do not receive these logs |
| Marketing contact (only if you separately opt in) | Sending the specific communications you asked for | eSora Labs Ltd.; any sending platform identified at opt-in | Until you unsubscribe; suppression entries kept as needed to honour the unsubscribe |
7. Enquiries and marketing permission (CASL)
An enquiry is never a subscription. You can send a project enquiry without joining any mailing list, and submitting a privacy request, an application, or client work does not add you to promotional campaigns.
Any commercial electronic messages we send — consistent with Canada’s Anti-Spam Legislation (CASL) — follow these rules:
- marketing opt-in is optional, unchecked by default, and specific about the sender (eSora Labs Ltd. / eSora Studio) and the kind of communications;
- every message identifies the sender and includes our contact information;
- every message includes a working unsubscribe mechanism, and unsubscribe requests are honoured without delay and in any event within 10 business days;
- opt-ins are recorded separately from enquiries so we can demonstrate consent; and
- we do not claim a marketing integration works until its subscription, suppression, and unsubscribe behaviour has actually been tested.
As of the date above, this website operates no mailing list and no marketing automation. If that changes, this section will be updated before any campaign runs.
9. International processing
We are headquartered in Canada, and eSora Labs publicly lists offices in Toronto, New York, Miami, Dubai, Madrid, and Dhaka. Team members in those locations may access enquiry correspondence where they are involved in responding or delivering work. We therefore do not claim that all information stays in Canada.
In addition, the asset providers named above operate global infrastructure, so serving a font file may involve a server outside Canada. When personal information is processed outside your province or country, it may become subject to the laws of that jurisdiction, including lawful access by foreign authorities. We protect cross-border handling through contractual and organisational measures appropriate to the sensitivity of the information — principally, by collecting very little of it and by restricting access to those who need it.
10. How long we keep it
We keep personal information only as long as needed for the purposes in section 5 or as required by law, using the criteria in the section 6 table. When information is no longer needed, we delete it or anonymise it.
Deletion is subject to two practical limits: (a) legal holds — we retain information we are legally required to preserve, for example for litigation or tax purposes; and (b) backups — information in routine email or system backups cannot always be deleted immediately, in which case it is isolated from active use and disappears as backups cycle out. Browser-side storage (esora-consent, esora-cfg) is under your control and can be cleared at any time through your browser settings.
11. How we protect it
Our security posture follows from how little this Site collects. It is a static website: there are no accounts to breach, no payment data, and no submission database on the Site itself. Information you send travels as ordinary email to a mailbox with access restricted to the people who handle it, and the only browser storage we use stays on your device.
Beyond that, we apply generally accepted organisational and technical measures proportionate to the sensitivity of what we hold — access limited to those who need it, current software, and care in how correspondence is handled. The Security page describes this in more detail and explains how to report a vulnerability. We do not publish claims about certifications or specific controls we have not verified.
12. Privacy breaches
If a breach of security safeguards involving personal information occurs, we will assess it under applicable law. Where PIPEDA’s breach provisions apply — a real risk of significant harm — we will notify affected individuals and the Office of the Privacy Commissioner of Canada as required, and keep records of breaches as the law requires. Equivalent obligations under other applicable regimes will be honoured where they apply.
13. Your rights and how to exercise them
Subject to applicable law, you may have the right to:
- Access — confirm whether we hold personal information about you and receive a copy or account of it;
- Correction — have inaccurate or incomplete information amended;
- Deletion — have information deleted where the law provides for it, subject to legal retention duties;
- Withdrawal of consent — withdraw consent for any consent-based processing (including cookie choices and any marketing opt-in), effective going forward; and
- Complaint — complain to us about our handling, and escalate to the regulator (section 14).
Exercise any of these through the Privacy Requests page, which provides a working submission route with a reference number, or by emailing info@esoralabs.com (attention: “Privacy”). No account is required, and we will never require marketing consent to process a privacy request. We use proportionate identity verification — enough to be sure we are disclosing to the right person, not identity documents for every request. We respond within the deadlines the applicable law sets rather than one invented universal period.
14. Complaints and the regulator
If you are concerned about how we handle personal information, contact us first at info@esoralabs.com (attention: “Privacy”) or via the Privacy Requests page; we will investigate and respond.
You also have the right to complain to the Office of the Privacy Commissioner of Canada (30 Victoria Street, Gatineau, Quebec; priv.gc.ca) about our handling of your personal information. Where a provincial or foreign regulator has jurisdiction over your complaint, you may escalate there as well.
15. Regional notices
These notices apply where the respective law applies to our handling of your information; they are stated conditionally because applicability depends on the activity, not added as decoration.
Quebec (Law 25)
Where the Act respecting the protection of personal information in the private sector applies, you have rights of access, rectification, and — for information subject to the Act’s newer provisions — erasure, de-indexing, data portability for computerised personal information, and to be informed of certain processing. The person responsible for the protection of personal information can be reached at info@esoralabs.com (attention: “Privacy”).
European Union and United Kingdom (GDPR / UK GDPR)
We do not have an establishment in the EU or UK and this Site is not directed at EU or UK residents; we do not monitor their behaviour. If the GDPR or UK GDPR nevertheless applies to a specific interaction, the lawful bases would typically be consent (which you may withdraw) or legitimate interests (responding to your enquiry), and you would have the rights to access, rectification, erasure, restriction, portability, and objection, plus the right to complain to your supervisory authority. We do not currently appoint an EU/UK representative because we do not believe the appointment criteria are met; this is reviewed if our activities change.
California (CCPA/CPRA)
We do not sell personal information and do not share it for cross-context behavioural advertising, and this Site runs no advertising technology. Where the CCPA/CPRA applies, California residents have rights to know, delete, correct, and to non-discrimination for exercising their rights, exercisable through the Privacy Requests page. Our honouring of the Global Privacy Control signal (see the Cookie Policy) applies here as well.
17. Children
The Site is a business-to-business marketing site and is not directed at children. We do not knowingly collect personal information from anyone under the age of majority. If you believe a child has sent us personal information, contact us and we will delete it.
18. Changes and contact
We may update this policy as our practices or the law evolve. Material changes will be reflected in the version and “Last updated” line above and, where significant, announced more prominently on the Site. Changes are posted deliberately and dated by hand — our publication process does not silently re-date policies on every deployment.
Privacy questions, requests, and complaints: info@esoralabs.com (attention: “Privacy”), or the Privacy Requests page. Operator: eSora Labs Ltd. (eSora Studio division), Toronto, Ontario, Canada.