Privacy Policy

Effective Date: August 20, 2026

Last Updated: August 20, 2026

 

  1. Scope and accountability
    This Policy applies when InfoSafe Inc. collects, uses or discloses personal information relating to business representatives, administrators, authorized users, prospects and support contacts through InfoSafe websites and business services. It does not replace a Business’s own privacy notice for individuals whose data it requests or controls. InfoSafe has designated a Privacy Officer to oversee compliance with Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial private-sector privacy laws.
  2. Information we collect
    Depending on your use, we may collect: name, job title, organization, business email and phone; account identifiers and authentication records; subscription, billing and transaction information; consent, request and permission records; device, browser, IP address, timestamps, logs and security events; settings, support communications and feedback; and content or metadata submitted through authorized platform features. We collect information from you, your organization, authorized integrations, service providers and automatically through the service. Please do not submit information that is unnecessary for the stated purpose.
  3. Purposes and consent
    We use information to create and administer accounts; authenticate users and prevent fraud; provide data-request, permission, audit, reward and related functions; process payments; provide support and service notices; monitor reliability and security; comply with law and enforce agreements; and improve the service using aggregated or de-identified information where appropriate. We identify purposes at or before collection and seek meaningful consent where required. You may withdraw consent, subject to legal or contractual restrictions and reasonable notice; withdrawal may limit service features. Marketing messages include an unsubscribe method.
  4. Sharing and service providers
    We disclose personal information only as reasonably necessary: to authorized users and recipients according to configured permissions; to cloud hosting, security, analytics, communications, payment, support and professional service providers bound to protect it; in a business transaction subject to appropriate safeguards; or where required or permitted by law. We do not sell business account personal information. Service providers may process information outside your province or Canada, where it may be accessible under foreign laws. InfoSafe remains accountable for information transferred to service providers and uses contractual or other safeguards appropriate to the circumstances.
  5. Blockchain and platform records
    InfoSafe may use blockchain-based audit functions to verify transactions, permissions or integrity. Depending on the implementation, records may be difficult or impossible to alter. InfoSafe aims to avoid recording raw personal information on a public or immutable ledger and may use hashes, references, tokens or off-chain storage instead. Businesses must not write personal information or confidential content directly to an immutable ledger unless InfoSafe has expressly approved the design and all legal requirements are satisfied.
  6. Retention and safeguardsWe retain personal information only as long as necessary for the identified purposes, contractual commitments, dispute resolution, security, backup cycles and legal requirements, then delete, anonymize or securely dispose of it. Retention periods vary by record type and account configuration. We use safeguards proportionate to sensitivity, including access controls, encryption where appropriate, monitoring, logging, secure development and personnel or vendor controls. No system is completely secure; users must protect credentials and promptly report concerns.
  7. Access, correction and complaints
    Subject to lawful exceptions, individuals may request access to personal information held by InfoSafe, learn how it has been used or disclosed, and request correction. We may verify identity and may direct requests concerning Business-controlled end-user data to that Business. We will investigate complaints and respond within applicable timelines. You may also contact the Office of the Privacy Commissioner of Canada or the relevant provincial privacy regulator.
  8. Cookies, incidents and updates
    We may use essential cookies and similar technologies for login, preferences, security and service performance; optional analytics or marketing technologies should be described in the cookie notice and used with any consent required by law. Where a breach creates a real risk of significant harm, InfoSafe will notify affected individuals and report to the appropriate regulator as required, and will maintain breach records. We may update this Policy and will post the effective date and provide notice of material changes.

 

Issued and approved by:

InfosafeInc.

Toronto, Ontario, Canada

infosafeinc.ca