Privacy Policy
- Who We Are & Scope
- An Important Distinction: Our Customers vs. Their Page Visitors
- Information We Collect
- How We Use Information
- Legal Bases for Processing (GDPR/UK GDPR)
- AI Features & Your Data
- How We Share Information
- Cookies & Similar Technologies
- International Data Transfers
- Data Retention
- Security
- Your Privacy Rights
- Children's Privacy
- Do Not Track & Global Privacy Control
- Changes to This Policy
- Contact Us & Complaints
1. Who We Are & Scope
This Privacy Policy describes how Iconic Digital World, Inc., operating the TrueMagna platform ("Company," "we," "us," or "our"), with its principal place of business in Alberta, Canada, collects, uses, discloses, and protects personal information in connection with:
- our websites, including truemagna.com, app.truemagna.com, workspace.truemagna.com, get.truemagna.com, and related subdomains (the "Sites");
- the TrueMagna software-as-a-service platform, including its AI page generator, editor, A/B testing, publishing, lead-management, and related features (the "Service"); and
- our marketing, sales, and support communications.
By using the Sites or the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with it, please do not use the Service. This Policy forms part of, and should be read together with, our Terms & Conditions.
2. An Important Distinction: Our Customers vs. Their Page Visitors
TrueMagna lets our customers ("Customers") build and publish landing pages that may collect information from the people who visit those pages ("End Users"), such as names, emails, form submissions, quiz answers, appointment bookings, and messages sent to chat assistants on those pages, and may send those people automated follow-up emails on the Customer's behalf ("Lead Data").
- For our Customers' account and usage data, we are the organization responsible for the personal information (a "controller" under GDPR-style laws). This Policy applies in full.
- For Lead Data collected through pages our Customers publish, the Customer — not us — decides what is collected and why. We process Lead Data solely on the Customer's behalf and on their instructions, as a service provider / processor. If you submitted your information on a page built with TrueMagna, please direct privacy questions and requests to the business that operates that page. Where required, we will refer requests we receive about Lead Data to the relevant Customer and provide reasonable assistance.
A Data Processing Addendum for Customers whose Lead Data is subject to GDPR-style laws is available on request at info@iconicdigitalworld.com. Each Customer is solely responsible for ensuring its pages, forms, and marketing comply with applicable privacy, anti-spam, consumer-protection, and advertising laws (including PIPEDA, provincial privacy laws, CASL, GDPR, ePrivacy rules, the CAN-SPAM Act, and the TCPA, as applicable), including posting its own privacy policy and obtaining any required consents from End Users.
3. Information We Collect
3.1 Information you provide to us
- Account information: name, email address, password (stored in hashed form), company name, and profile details.
- Billing information: payment card and billing details are collected and processed by our third-party payment processors (e.g., Stripe or a similar PCI-DSS-compliant provider). We do not store full payment card numbers on our systems; we retain limited billing records (e.g., plan, transaction history, last four digits, billing address) for accounting and fraud-prevention purposes.
- Content you create or upload: page, funnel, and website content; images, logos, and brand assets; prompts and inputs you submit to AI features; audio you submit for transcription (and the resulting transcripts); business and knowledge-base information you store in your workspace; email templates and follow-up sequences; domain names you connect; and settings you configure.
- Communications: messages you send us via support channels, in-app support tickets, email, forms, surveys, or reviews.
- Integration data: if you connect a third-party service, we receive the data you authorize that service to share and use it only to provide the feature you enabled. This includes Google Business Profile and Google Calendar; and social accounts — Facebook Pages, Instagram, LinkedIn, TikTok and YouTube — where we receive the identity of the page, profile or channel you select (its name and platform identifier) and an access token permitting the actions you authorized. Access and refresh tokens are encrypted at rest and are used only to carry out actions you have scheduled or requested. You can disconnect any integration at any time in your settings; disconnecting removes the connection from our systems, and we ask the network to revoke the token. Where a network cannot confirm the revocation we tell you so, and you can remove our app from that network’s own settings. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
- Blog and keyword research: the topics and keywords you research are sent to our search-data provider to return search volumes and related terms. We do not send your account identity with them.
- Sender identity: if you configure a sending address on your own domain, we store that address and the results of the DNS checks used to verify it.
3.2 Information collected automatically
- Usage data: features used, pages created, actions taken, timestamps, referring pages, and interaction logs.
- Device and connection data: IP address, browser type and version, operating system, device identifiers, language, and approximate location derived from IP address.
- Cookies and similar technologies: as described in Section 8.
- Published-page analytics: visit, conversion, QR-scan, and A/B test data for pages Customers publish — including technical data such as IP address and browser type recorded with individual events — processed on the relevant Customer’s behalf and made available to that Customer.
3.3 Information from third parties
- Sign-in or integration partners you choose to connect (e.g., OAuth providers, domain registrars, email or CRM tools), limited to what those services share with your authorization.
- Service providers that help us with analytics, security, fraud prevention, and payment processing.
- If a Customer connects Google Business Profile, we store that business’s Google review content (reviewer names, profile photos, ratings, and review text) on the Customer’s behalf so it can be shown on the Customer’s pages. Review authors should direct removal requests to Google or to the business concerned.
We do not intentionally collect sensitive personal information (such as health, biometric, or financial account credentials) through the Service, and we ask that you do not submit it to us or include it in AI prompts.
4. How We Use Information
We use personal information to:
- provide, operate, maintain, and secure the Service, including generating pages, hosting published pages, running A/B tests, and delivering Lead Data to the relevant Customer;
- publish content you have scheduled — where you connect a social account and schedule a post, we send the post’s text and any image you attached to that network on your behalf, at or after the time you scheduled, and store what the network returns (a post identifier, a link, or the reason it was refused). We do not post anything you have not scheduled, and we do not read your existing content, followers or messages on those networks;
- create and manage accounts, authenticate users, and provide customer support;
- process subscriptions, payments, and renewals, and prevent fraud and abuse;
- improve and develop the Service, including troubleshooting, analytics, and research on an aggregated or de-identified basis;
- send service communications (e.g., billing notices, security alerts, changes to terms) — these are not marketing and you cannot opt out of them while you hold an account;
- send marketing communications where permitted by law and consistent with CASL and other anti-spam laws — you may unsubscribe at any time;
- enforce our Terms & Conditions, including our Acceptable Use Policy, and protect the rights, safety, and property of the Company, our Customers, End Users, and the public; and
- comply with legal obligations and respond to lawful requests from public authorities.
We may de-identify or aggregate information so it can no longer reasonably identify you and use it for any lawful purpose, including improving our templates, conversion models, and AI features. We do not use identifiable Customer content or Lead Data to train generalized AI models without consent.
5. Legal Bases for Processing (GDPR/UK GDPR)
Where the EU or UK General Data Protection Regulation applies, we rely on the following legal bases:
| Purpose | Legal basis |
|---|---|
| Providing the Service, accounts, billing | Performance of a contract (Art. 6(1)(b)) |
| Security, fraud prevention, service improvement, defending legal claims | Legitimate interests (Art. 6(1)(f)) |
| Marketing emails, non-essential cookies | Consent (Art. 6(1)(a)), withdrawable at any time |
| Tax, accounting, and regulatory obligations | Legal obligation (Art. 6(1)(c)) |
6. AI Features & Your Data
The Service uses artificial intelligence to generate page layouts, copy, and design suggestions. In connection with these features:
- Prompts, inputs, and relevant account content may be transmitted to and processed by third-party AI model providers under contracts that restrict their use of the data to providing the service to us. This includes messages End Users send to chat assistants Customers enable on their pages, which are processed on the relevant Customer’s behalf to generate replies.
- AI-generated output is produced by statistical models and may be inaccurate, incomplete, or unsuitable for your purposes. You are responsible for reviewing all AI output before publishing it, including for factual accuracy, legal compliance of claims, and intellectual-property considerations.
- Do not include personal information about others, confidential information, or sensitive personal information in AI prompts unless you have the right to do so.
- We do not use your identifiable content to train generalized AI models without your consent, and we require equivalent commitments from our AI providers.
- The in-workspace assistant acts on the content of the workspace you are working in, at your direction, and its actions are recorded so they can be reviewed and undone. It does not act across workspaces.
7. How We Share Information
We do not sell personal information, and we do not share it for cross-context behavioural advertising. We disclose personal information only:
- To service providers that host and support the Service under contractual confidentiality and data-protection obligations — for example: cloud hosting and content-delivery providers (e.g., Vercel), managed database providers (e.g., Neon), payment processors, email-delivery services, analytics providers, customer-support tooling, and AI model providers. A current list of the sub-processors we use, and what each one receives, is set out in Annex A at the end of this Policy; we update it before adding a new sub-processor that processes personal information, and material changes are notified as described in Section 15;
- To the relevant Customer, in the case of Lead Data and page analytics for that Customer's pages;
- For legal reasons, where we believe in good faith that disclosure is required by law, subpoena, court order, or other legal process, or is necessary to investigate or protect against fraud, security incidents, or violations of our Terms;
- In business transfers, in connection with a merger, acquisition, financing, reorganization, or sale of assets, in which case personal information may be transferred as a business asset subject to this Policy or successor terms with equivalent protection; and
- With your direction or consent, such as integrations you enable.
8. Cookies & Similar Technologies
We and our providers use cookies, pixels, local storage, and similar technologies to:
- Strictly necessary: authentication, session management, security, load balancing, and fraud prevention (always active);
- Functional: remembering preferences and settings;
- Analytics: understanding how the Sites and Service are used so we can improve them; and
- A/B testing: assigning visitors of published pages to page variants and measuring conversions on behalf of the relevant Customer.
Where required by law, non-essential cookies are used only with consent, which you may withdraw at any time through your browser settings. Blocking some cookies may affect Service functionality. Customers are responsible for any cookie notices or consents required for technologies used on their own published pages, including tracking pixels and chat widgets they enable.
9. International Data Transfers
We are based in Canada, and our service providers process data in Canada, the United States, and other jurisdictions. Where personal information subject to GDPR/UK GDPR is transferred outside the EEA, UK, or Switzerland, we rely on appropriate safeguards such as adequacy decisions (including, for commercial organizations, Canada's adequacy status under PIPEDA) and Standard Contractual Clauses (or the UK equivalent), together with supplementary measures where appropriate. Information processed in a foreign jurisdiction may be accessible to the courts, law enforcement, and national-security authorities of that jurisdiction in accordance with its laws.
10. Data Retention
We retain personal information only as long as reasonably necessary for the purposes described in this Policy, including:
- Account data: for the life of the account and a reasonable period afterward for backup rotation, dispute resolution, and legal compliance;
- Billing records: as required by tax and accounting laws (typically 6–7 years);
- Customer content and Lead Data: for the duration of the Customer's subscription and a limited wind-down period after termination, after which it is deleted or de-identified in the ordinary course, subject to the Terms;
- Logs and security data: for limited periods appropriate to security and fraud-prevention purposes.
When retention is no longer required, we delete or irreversibly de-identify the information.
11. Security
We use commercially reasonable administrative, technical, and physical safeguards appropriate to the sensitivity of the information, including encryption in transit, access controls, and vendor due diligence. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your credentials confidential and for the security of devices you use to access the Service. We will notify affected individuals and regulators of data breaches where and as required by applicable law, including PIPEDA's breach-reporting requirements and Alberta's Personal Information Protection Act.
12. Your Privacy Rights
12.1 All users
Subject to applicable law and certain exceptions, you may request to: access the personal information we hold about you; correct inaccurate information; delete your information; withdraw consent (where processing is based on consent); and receive a copy of information you provided in a portable format. You may exercise these rights by emailing info@iconicdigitalworld.com. We may need to verify your identity before acting on a request, and we will respond within the timelines required by applicable law. We will not discriminate against you for exercising your rights.
12.2 Canada (PIPEDA, Alberta PIPA, Quebec Law 25)
Canadian residents may request access to and correction of their personal information and may challenge our compliance with applicable privacy law. Quebec residents additionally have rights regarding de-indexing and data portability and the right to be informed of decisions based exclusively on automated processing. Our designated privacy contact is reachable at info@iconicdigitalworld.com.
12.3 European Economic Area, UK & Switzerland
You have the rights of access, rectification, erasure, restriction, portability, and objection (including to processing based on legitimate interests and to direct marketing), and the right not to be subject to solely automated decisions with legal or similarly significant effects. You may lodge a complaint with your local supervisory authority.
12.4 United States state privacy laws
Residents of California and other U.S. states with comprehensive privacy laws (including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and others) may have rights to know/access, correct, delete, and obtain a portable copy of personal information, and to opt out of "sales," "sharing," and targeted advertising. We do not sell or share personal information as those terms are defined under the California Consumer Privacy Act. We honour opt-out preference signals where required. California residents may designate an authorized agent and have the right not to receive discriminatory treatment; if we deny a request, you may appeal by replying to our decision, and, where applicable, contact your state attorney general.
12.5 If you are an End User of a Customer's page
Please direct requests to the business operating the page you visited. If you contact us instead, we will pass your request to that Customer where we can identify them and provide reasonable assistance as their service provider.
13. Children's Privacy
The Service is a business tool intended for adults. It is not directed to anyone under 18, and we do not knowingly collect personal information from children under 13 (or the higher age required by local law, such as 16 in parts of the EEA). If you believe a child has provided us personal information, contact us and we will delete it.
14. Do Not Track & Global Privacy Control
Some browsers transmit "Do Not Track" signals; because no common standard exists, we do not respond to them. Where legally required, we treat recognized Global Privacy Control (GPC) signals as a valid opt-out of sale/sharing for the browser or device sending the signal.
15. Changes to This Policy
We may update this Policy from time to time. The "Last Updated" date shows the latest revision. For material changes, we will provide reasonable advance notice (for example, by email or in-app notice). Your continued use of the Service after the effective date of an updated Policy constitutes acceptance of it to the extent permitted by law.
16. Contact Us & Complaints
Privacy Officer
Iconic Digital World, Inc. (TrueMagna)
Alberta, Canada
Email: info@iconicdigitalworld.com
If we cannot resolve your concern, you may contact the Office of the Privacy Commissioner of Canada (priv.gc.ca), the Office of the Information and Privacy Commissioner of Alberta (oipc.ab.ca), your EU/UK supervisory authority, or your state or provincial regulator, as applicable.
Annex A — Sub-processors
The providers below process personal information on our behalf under contractual confidentiality and data-protection obligations. We update this list before adding a new sub-processor that processes personal information.
| Sub-processor | What it does | What it receives |
|---|---|---|
| Vercel | Hosting and content delivery | All request data, including IP addresses |
| Neon | Managed database | All stored data |
| Stripe | Payment processing | Billing details; full card numbers never reach us |
| Resend | Email delivery | Recipient addresses and message content |
| OpenRouter | AI model routing | Prompts and the account content sent with them |
| AI generation (Gemini); Business Profile and Calendar integrations | Prompts; and the Google data you authorize | |
| Composio | Connecting social accounts | Social account tokens and post content |
| DataForSEO | Keyword and search-volume data for the blog planner | The keywords and topics you research |
| Jina | Reading and extracting page content | URLs you ask the Service to read |
| Browserless, HCTI, ScreenshotOne | Rendering pages to images for thumbnails and previews | The HTML of your pages, which may contain your content |