Effective and last updated: October 4, 2026.
Scope and person responsible
This policy covers factavue.com, its contact form and FactaVue’s private administration. It does not cover external websites linked from our stories.
Information collected
Reading the public website
Audience measurement is off by default. If you accept it, FactaVue receives the page path without query parameters or fragments, the validated article identifier when applicable, a broad source category and active time while the page is visible in the foreground. These events contain no IP address, user agent, full referring address, search query or persistent visitor identifier. They are used only to produce totals. To limit abuse of the collection endpoint, the server transforms the IP address into a separate HMAC fingerprint that expires after ten minutes; the raw address is not stored.
Your choice is stored locally in your browser under fv-analytics-consent. Refusing does not disable any website feature. You may withdraw your choice with the website privacy control; the banner will then be shown again.
Contact form
When you write to us, we collect your name, email address, reason, message and form language. To limit abuse, the server immediately transforms the IP address into a non-reversible HMAC fingerprint using a FactaVue secret; the raw IP address is not stored with the message. The browser user agent, time, delivery status and number of delivery attempts are also kept.
This information is used to receive the message, transfer it to the editorial mailbox, reply, handle a report and limit abusive submissions. The message is saved in MongoDB before being transferred by SMTP to FactaVue’s mailbox.
Private administration
Authorized accounts have a name, email address, role and a password transformed with scrypt. An administration session uses a secure, HTTP-only, SameSite=Lax cookie valid for no more than 14 days. Editorial actions and calls to Resource Manager services may be logged to preserve the audit trail. This part does not concern ordinary readers.
Disclosure and infrastructure
Information is available to authorized people who administer FactaVue. The website passes through a Cloudflare tunnel; application data is held in private MongoDB and S3-compatible object storage; contact messages pass through FactaVue’s SMTP server. Editorial artificial-intelligence services are restricted to the administration and do not receive contact-form submissions in the current operation.
An Internet connection or technical service may process data in another jurisdiction. FactaVue does not publish an unverified hosting country. You may ask the person in charge for available information about categories of service providers and the possibility of disclosure outside Quebec.
Retention
- Consented audience-measurement events are automatically deleted after 90 days.
- No automatic expiry is currently configured for contact messages. They remain in the administration until they are manually deleted. FactaVue must adopt and configure a period before it can state one.
- Administration sessions expire after no more than 14 days and may be revoked sooner.
Security and incidents
FactaVue restricts access to administration tools, encrypts integration secrets, keeps MongoDB and object storage off the public Internet and rate-limits the form. No measure removes every risk. An incident involving personal information is assessed, recorded and handled according to the risk of harm, with notice to individuals and the Commission d’accès à l’information when required by law.
Your rights and choices
You may request access to personal information about you, its correction, details about its use and retention, or withdraw consent where consent is the basis for processing. A request may be subject to exceptions in the law. You may also complain to the person in charge or to Quebec’s Commission d’accès à l’information.
Use the contact page.
Changes
Any material change will be announced on the website and the date above will be updated. This policy reflects technical flows verified on October 4, 2026. The Act respecting the protection of personal information in the private sector remains the official authority.