PRIVACY POLICY
Last updated: <LAST UPDATED DATE>
- Introduction
<BUSINESS NAME> (“<BUSINESS NAME>,” “we,” “our,” “us”) provides ethics and compliance advisory services. This Privacy Policy explains how we collect, use, disclose, and protect personal information when you use <DOMAIN(S)> (the “Site”) and our related communications.
By using the Site, you agree to this Policy. If you do not agree, please do not use the Site.
- Who We Are and Scope
- Controller: <BUSINESS NAME>, <CONTACT ADDRESS>, <CONTACT EMAIL>.
- Covered services: The public-facing website, contact form, gated resources (“form wall”), and newsletter.
- Not covered: Client engagements governed by separate agreements (if applicable).
- Information We Collect
A) Information you provide
- Contact form: full name, email address, job title, company name, and message.
- Gated resources (“form wall”): first name, last name, email address, job title, company name.
- Newsletter: email address.
B) Information collected automatically - Usage data: IP address, device/browser type, operating system, referring URLs, pages viewed, timestamps.
- Cookies and similar technologies: see Section 9.
- How We Use Personal Information
We use personal information to:
- Respond to inquiries and provide information about our services.
- Provide access to requested resources (e.g., articles, documents).
- Send newsletters and updates (with your consent, where required).
- Operate, maintain, and improve the Site (including analytics).
- Protect the security of the Site, prevent fraud and abuse.
- Comply with applicable laws and enforce our Terms.
- Lawful Bases (Canadian context and other regions)
- Canada (PIPEDA): We rely on consent (express or implied, as permitted by law) and reasonable purposes aligned with your interactions (e.g., responding to your inquiry).
- EU/UK: We do not specifically target EU/UK residents. If we process data of EU/UK residents, we rely on consent (e.g., newsletter) or legitimate interests (e.g., responding to an inquiry), while respecting applicable rights.
- California (CPRA): We do not specifically target California residents and do not “sell” or “share” personal information as defined by CPRA.
- How We Share Personal Information
We do not sell personal information.
We may share personal information with:
- Service providers (processors) that help us operate the Site and communications, including:
- Brevo (newsletter and gated-resource forms/marketing).
- Email and hosting providers: <EMAIL/INFRASTRUCTURE PROVIDERS>.
- Analytics provider(s): Google Analytics (when implemented).
These providers process data on our behalf under appropriate agreements.
- Legal and compliance: To comply with law, respond to lawful requests, protect our rights, or in connection with a business transaction (e.g., merger or asset transfer).
- International Data Transfers
We are located in Ottawa, Canada. Our providers may process data in other jurisdictions. Data processed by Brevo and other providers is handled according to their policies and applicable transfer safeguards. Where data is transferred outside your province/territory or country, it may be subject to the laws of those jurisdictions.
- Brevo privacy information: <LINK TO BREVO PRIVACY PAGE>.
- Other providers’ privacy information: <LINKS TO PROVIDERS>.
- Retention
We retain personal information only as long as necessary for the purposes set out in this Policy, unless a longer period is required or permitted by law.
- Contact form submissions: <RETENTION CONTACT FORM, e.g., “up to 24 months”>.
- Gated-resource (“form wall”) records in Brevo: <RETENTION FORM WALL>.
- Newsletter contacts in Brevo: until you unsubscribe or request deletion; backups may persist for a limited time.
We honor deletion requests and aim to complete them within <DELETION SLA, e.g., “30 days”>, subject to legal retention requirements.
- Cookies and Tracking
- Form-wall cookie: We set a functional cookie flag after you complete a gated form to remember access for that resource. It is used only to suppress repeat prompts for that specific resource.
- Name: <FORM_WALL_COOKIE_NAME(S)>
- Duration: <FORM WALL COOKIE DURATION, e.g., “6 months”>
- Purpose: functional (non-marketing)
- Analytics: We plan to use Google Analytics to understand site usage and improve the Site. You can learn more and opt out via Google’s tools where available.
- Cookie notice and choices: You may control cookies through your browser settings. If operating in regions that require consent for non-essential cookies, we will seek consent where applicable.
- Do Not Track / Global Privacy Control: We will honor applicable signals to the extent required by law.
- Marketing Communications
- We use Brevo to send newsletters and follow-ups related to resources you access. All marketing emails include an unsubscribe link.
- We use double opt-in for newsletter subscriptions.
- You can unsubscribe at any time or contact us at <CONTACT EMAIL>.
- Your Privacy Rights
Depending on your location, you may have rights to:
- Access, correct, or delete your personal information.
- Withdraw consent to marketing communications.
- Object to or restrict certain processing (where applicable).
- Lodge a complaint with a privacy regulator.
To exercise rights, contact <CONTACT EMAIL>. We will verify and respond within applicable timelines.
Canada: You may contact the Office of the Privacy Commissioner of Canada or your provincial authority if concerns are not resolved.
- Security
We take reasonable administrative, technical, and organizational measures to protect personal information, including:
- Encryption in transit (TLS) and provider-level encryption at rest (where applicable).
- Access controls and least-privilege access.
- Vendor due diligence and periodic reviews.
No method of transmission or storage is 100% secure.
- Children’s Privacy
The Site is not directed to children under 16, and we do not knowingly collect personal information from children under 13. If you believe a child has provided information, contact us at <CONTACT EMAIL> to request deletion. - Third-Party Links
The Site may contain links to third-party websites and resources. We are not responsible for their content or privacy practices. Review their policies before providing personal information. - Changes to This Policy
We may update this Policy from time to time. Changes are effective when posted with an updated “Last updated” date. We will provide additional notice if required by law. - Contact Us
For questions or requests regarding this Policy or our practices:
- Email: <CONTACT EMAIL>
- Address: <CONTACT ADDRESS>
- Data controller: <BUSINESS NAME>