Privacy Policy
Last updated: August 2, 2026
Status of this document. Rewritten on August 2, 2026 to describe how each workflow on this site actually handles data, rather than a generic template. It has not yet been reviewed by Ontario counsel. Where a retained engagement has its own confidentiality terms, those prevail over this page.
Critical Path Partners ("CPP", "we", "us") is a forensic scheduling and claims consulting practice in Ontario, Canada. This policy explains what happens to your information when you use this website, its free tools, or its intake forms.
Schedule files are commercially sensitive and frequently sit inside live disputes, so this policy is written to be precise about each workflow separately rather than reassuring in general.
Data Handling at a Glance
Every workflow on this site handles data differently. This is the summary. Each row is explained in full below. One workflow sits outside the table because it does not start on this website: the forensic tool endpoint that an AI client can call, covered under Connected AI Clients further down.
| Workflow | Leaves your browser? | Processed by | Stored? | Retention |
|---|---|---|---|---|
| CPP Lens — XER or XML | No | Your browser | No | None |
| CPP Lens — MPP conversion | Yes | CPP engine at mcp.criticalpathpartners.ca | For the conversion | Kept only as needed to convert |
| Lens Deep Forensic (opt-in) | Yes, only if you click it | CPP engine at mcp.criticalpathpartners.ca | For the duration of the run | Kept only as needed to return your result |
| Free Claim Check | Yes | CPP server (Hostinger) | Yes | 12 months, or on request |
| Contact form | Yes | Web3Forms, then email | Yes, in email | 24 months, or on request |
| Ask (AI assistant) | Yes | CPP server, then Anthropic | Rate-limit counters only | Counters reset hourly |
| Engagement files | Yes, sent by you | CPP analyst | Yes | Per engagement letter |
CPP Lens and the Free P6 Viewer
CPP Lens at criticalpathpartners.ca/viewer/ is a single static HTML file. For a Primavera P6 .xer or .xml schedule, opening it in Lens makes no network request at all. Parsing, the CPM solve, the DCMA screening, the Gantt, and every export run inside your own browser tab. Those files are never transmitted to CPP, and CPP never sees them. You can confirm this yourself in your browser's network tab.
There are two exceptions, both set out below. Outside them, nothing is transmitted, nothing is stored, and there is no retention period. Closing the tab ends it.
Exception 1: Microsoft Project (.mpp) files are converted on our server
An .mpp file cannot be read in the browser, so Lens uploads it to the CPP engine, which converts it to XER and returns it. That is the entire operation: a format conversion. It happens as part of opening the file, not as a separate opt-in step, and the file is sent as it is, with no anonymization step, because anonymizing it would change the schedule you asked to view. Lens tells you on screen while it happens. The upload is used only to perform the conversion and hand the converted schedule back to your browser. It is not analysed, not used for any other purpose, never used as a public sample, and never disclosed to a third party.
If a schedule is commercially sensitive or sits inside a live dispute, and you do not want it leaving your machine at all, export it from MS Project as .xer or .xml first. Those formats are parsed entirely in your browser and are never uploaded.
Exception 2: Deep Forensic
Lens includes an optional Deep Forensic feature that submits your schedule to the CPP engine for analysis that cannot run in a browser. This happens only when you click to run it. The schedule is anonymized before transmission by default, replacing activity and WBS names with opaque tokens. The submission is kept only as long as needed to compute and return your result, and is never used for any other purpose, never used as a public sample, and never disclosed to a third party. If you do not click it, nothing is sent.
The CPP engine host
Both exceptions send data to mcp.criticalpathpartners.ca, the CPP forensic engine, which is hosted on Railway. It is operated by CPP, not by a third party, and is subject to this policy. Requests are rate-limited and, for conversion, subject to a daily quota. The same host also serves the Ask assistant and the public forensic tool endpoint, both covered further down this page.
Free Claim Check
The Free Claim Check at criticalpathpartners.ca/claim-check.html does upload your files, because a human reads them.
What is collected
- What you type. Name, email, phone if given, which side of the dispute you are on, a description of the matter, and the contract completion date if given.
- Your files. Accepted as .xer, .xml, or .zip, up to 100 MB per file, 200 MB per submission, and 25 files.
- Technical data. Your IP address and browser user-agent string are recorded alongside the submission, for abuse prevention and to help diagnose failed uploads.
Where it goes
Files are stored on CPP's own server, hosted by Hostinger, inside a directory that denies all web access and disables directory listing. Each submission gets its own folder under a randomly generated name, and files are saved under opaque sequential names rather than their originals. A manifest file inside the folder records the form fields, the original filenames, your IP address, and your user-agent. A notification email goes to dana@criticalpathpartners.ca.
How long it is kept
Claim Check submissions are retained for up to 12 months from the date received, then deleted. If you ask for deletion sooner, it will be actioned within 30 days and confirmed by email. Where a submission leads to a retained engagement, the engagement letter governs retention instead.
What is never done with it
- Claim Check files are never used as public samples. Every sample dashboard on this site is built from demonstration data and labelled as such.
- They are never sold, shared, or disclosed to third parties, except where compelled by law or a tribunal.
- They are treated as confidential on the same footing as a retained engagement, whether or not you ever retain CPP.
Contact Form
The form on Talk to CPP is processed by Web3Forms, a third-party form-delivery service, which receives your submission at api.web3forms.com and forwards it to CPP by email. The fields transmitted are your name, email address, phone number if given, the role you select, and your message. Web3Forms processes this data under its own privacy policy, which you should review if that matters to you.
If you would rather not involve a third-party processor, email dana@criticalpathpartners.ca or call 519-532-6300 directly. Both reach the same person.
Contact submissions live in CPP's email and are retained for up to 24 months, or deleted sooner on request.
Ask (AI Assistant)
The Ask assistant at mcp.criticalpathpartners.ca/ask forwards your typed question to Anthropic for processing by a Claude model, and streams the response back. Your question and the response are not stored by CPP. The service is rate-limited per IP address, so a short-lived request counter is held in memory and resets hourly. Do not paste confidential project detail into Ask. Use the Claim Check or email instead.
Connected AI Clients (MCP)
CPP publishes its forensic tools as an endpoint at mcp.criticalpathpartners.ca/mcp, so an AI client you connect yourself can call them. Setup is described on Connect to Claude. This is the same CPP-operated engine described above, and the same commitments apply: your data is used only to answer the call, is never used as a public sample, and is never disclosed to a third party.
Two things about it are worth knowing before you connect. The endpoint is open, with no account and no key. And when you ask a connected client to analyse a schedule, that client sends the schedule to the endpoint as it is, with no anonymization step. If a file must not leave your machine, do not point a connected client at it. Use CPP Lens with a .xer or .xml instead, which stays in your browser.
What a connected client sends, and to whom, is governed by that client's own privacy policy as well as this one. If your client is Claude, Anthropic's policy applies to your side of the conversation.
Hosting and Analytics
- Hostinger hosts criticalpathpartners.ca and, like any web host, keeps standard server access logs including IP addresses.
- Railway hosts mcp.criticalpathpartners.ca, which serves the Ask assistant and the forensic engine endpoints.
- Google Analytics is present on one blog article only, not across the site. Where it loads it sets cookies and reports usage data to Google. No analytics runs on the Claim Check page, the viewer, or the legal pages.
- No session recording, heatmapping, advertising pixels, or cross-site trackers are used anywhere on this site.
Fonts are self-hosted rather than loaded from a content delivery network, so viewing this site does not report your visit to a font provider.
Payments
CPP does not collect or process payment card details through this website. There is no checkout, no stored card, and no payment form. Fees for retained engagements are invoiced and settled under the engagement letter, outside this site.
Cookies
CPP sets no cookies of its own for tracking. The only cookies that may be set are those from Google Analytics on the single blog article noted above. Blocking cookies in your browser does not impair any function of this site, including CPP Lens.
Your Rights
Under Canadian federal privacy law, and applicable Ontario law, you may:
- Ask what personal information CPP holds about you and receive a copy.
- Ask for correction of anything inaccurate.
- Ask for deletion of your data, including any Claim Check submission.
- Withdraw consent for further processing.
- Complain to the Office of the Privacy Commissioner of Canada if you believe your information has been mishandled.
Requests go to dana@criticalpathpartners.ca and are actioned within 30 days.
Data Location and Transfers
CPP is based in Ontario. Its hosting and processing vendors may store or process data outside Canada, including in the United States and the European Union. Where that happens, the data may be subject to the laws of those jurisdictions. If data residency matters to your matter, say so before sending anything and it can be handled by direct transfer instead.
Changes to This Policy
Changes are posted on this page with a revised date. Material changes affecting an active engagement will be raised with you directly rather than left to a page update.
Contact
Questions about this policy, or about what CPP holds on you, go to dana@criticalpathpartners.ca or 519-532-6300.