Effective date: October 10, 2026 · Last updated: October 10, 2026
The Innovates Tech Inc. (“we”, “us” or “our”) is committed to protecting the privacy of the individuals whose personal information we handle. This Privacy Policy explains how we collect, use, disclose, retain and protect personal information, and the rights and choices available to you. It is written to meet our obligations under Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA), Alberta’s Personal Information Protection Act (PIPA), Canada’s Anti-Spam Legislation (CASL), and, where they apply, other privacy laws such as Quebec’s Act respecting the protection of personal information in the private sector (as amended by Law 25), the European Union and United Kingdom General Data Protection Regulations (GDPR) and U.S. state privacy laws. It is also intended to meet the privacy policy requirements of the Apple App Store and Google Play.
Please read this policy carefully. By using our Website, Apps or Services, or by providing personal information to us, you acknowledge that you have read and understood it. If you do not agree with it, please do not use our Website, Apps or Services.
Contents
- Scope and definitions
- Accountability and Privacy Officer
- Personal information we collect
- Mobile and desktop applications
- How and why we use personal information
- Consent and legal bases
- Cookies, analytics and tracking
- How we share personal information
- Storage and transfers outside Canada
- Retention and deletion
- Security safeguards and breach notification
- Your privacy rights
- How to request deletion of your account and data
- Electronic communications (CASL)
- Children’s privacy
- Additional information for specific regions
- Client data we process for our customers
- Third-party websites and services
- Limitations
- Changes to this policy
- Contact us and complaints
1. Scope and definitions
This policy applies to personal information collected by The Innovates Tech Inc., a company based in Alberta, Canada, through:
- our website at www.theinnovates.com and any of its pages (the “Website”);
- any mobile, desktop or web application we publish, including those distributed through the Apple App Store or Google Play (each an “App”); and
- our cybersecurity consulting, training, managed security and related services, and our communications with clients, prospective clients, suppliers and other contacts (the “Services”).
“Personal information” means information about an identifiable individual, as defined by applicable law. It does not include business contact information (such as a name, title, business address, email or telephone number) used solely to communicate with an individual in relation to their employment, business or profession, except where the law treats it as personal information. It also does not include information that has been aggregated or de-identified so that it can no longer reasonably be used to identify an individual.
This policy does not apply to the personal information of our own employees, which is governed by internal policies, or to personal information we process on behalf of clients as a service provider, which is governed by our agreements with those clients (see section 17).
2. Accountability and Privacy Officer
We are responsible for personal information under our control, including information transferred to service providers for processing. We have designated a Privacy Officer who is accountable for our compliance with this policy and with applicable privacy laws, and who can be reached using the contact details in section 21. Our privacy practices are guided by the ten fair information principles in PIPEDA: accountability; identifying purposes; consent; limiting collection; limiting use, disclosure and retention; accuracy; safeguards; openness; individual access; and challenging compliance.
3. Personal information we collect
We collect only the personal information that is reasonably necessary for the purposes described in this policy. We collect it directly from you wherever possible.
3.1 Information you provide to us
- Enquiries and communications: when you email, call or otherwise contact us — for example to book a consultation, request training or ask a question — we collect your name, email address, telephone number, organization, job title and the content of your message and any attachments.
- Client and engagement information: when you or your organization engage us, we collect the contact, billing and business information needed to provide, manage and invoice the Services, and records of our communications and work.
- Training participants: when we deliver training, we may collect participants’ names, work email addresses, attendance, participation and results (for example in exercises or phishing simulations authorized by the participant’s employer), which we report to the organization that engaged us.
- Comments: if you comment on a blog post, we collect the name, email address and optional website you enter, and the content of your comment.
- Accounts: if an App or the Website lets you create an account, we collect the information needed to create and secure it, such as your name, email address and authentication credentials (passwords are stored only in hashed form).
- Job applications and suppliers: if you apply for a position or provide goods or services to us, we collect the information you provide for that purpose.
3.2 Information collected automatically
- Server and security logs: when you visit the Website, our systems automatically record technical information such as your IP address, the date and time of your request, the pages and files requested, the referring page, your browser and operating system, and request outcomes. We use this to operate and secure the Website and to detect, investigate and prevent attacks and misuse.
- Analytics: we use Google Analytics to understand how visitors use the Website, for example which pages are viewed, for how long, and how visitors arrive. Google Analytics uses cookies and collects information such as an online identifier, approximate (city-level) location derived from IP address, device and browser type, and pages visited.
- Comment metadata: when you comment, we record your IP address and browser user-agent to help detect spam.
- App usage and diagnostics: see section 4.
3.3 Information from other sources
We may receive business contact information about you from your employer or colleagues (for example when your organization engages us and names you as a contact), from referrals, or from publicly available professional sources. We use it only for purposes consistent with the reason it was provided.
3.4 Information we do not want
We do not intentionally collect sensitive personal information — such as health, biometric, financial account or government identification information, or information about racial or ethnic origin, religion, sexual orientation or political opinions — through the Website or Apps. Please do not send us sensitive personal information, passwords or confidential credentials by email or through the Website. If you do, we may delete it.
4. Mobile and desktop applications
This section applies if you download or use an App we publish. Each App collects only the data it needs for the features you use. The specific data collected by an App is described in its Apple App Store “App Privacy” label and its Google Play “Data safety” section, and, where helpful, in an App-specific notice shown in the App or listed at the end of this policy. If there is a conflict, the App-specific disclosure for that App applies to that App.
4.1 Data an App may collect
- Account and profile data you provide, such as name and email address, if the App offers an account.
- Content you create or submit in the App, used only to provide the App’s features.
- Device and diagnostic data such as device model, operating-system version, App version, language, crash logs and performance data, used to keep the App working, secure and compatible.
- Usage data such as features used and screens viewed, used in aggregate to improve the App.
- Push-notification tokens, if you allow notifications, used only to send the notifications you have agreed to receive through the notification service of your device’s operating system.
4.2 Device permissions
An App will ask for your permission before accessing device features such as your camera, photos, microphone, contacts, location, Bluetooth, local network or notifications, and only when a feature you choose to use requires it. Each permission is used only for the purpose explained when it is requested. You can refuse or later withdraw any permission in your device settings; some features may then be unavailable, but the rest of the App will continue to work wherever possible. We do not access device data in the background for any purpose that has not been disclosed to you.
4.3 No tracking, advertising or sale
- Our Apps do not display third-party advertising.
- We do not use data from our Apps to track you across apps and websites owned by other companies, as “tracking” is defined by Apple, and we do not access the Apple Identifier for Advertisers (IDFA). If that ever changes, we will first ask for your permission through Apple’s App Tracking Transparency prompt and update this policy and the App’s privacy disclosures.
- We do not use the Android Advertising ID for advertising or profiling, and we do not link it to personal identifiers.
- We do not sell personal information collected through our Apps, and we do not share it with data brokers.
4.4 Third-party software in our Apps
Apps may include software development kits (SDKs) from service providers, for example for crash reporting, analytics, authentication or notifications. We select SDKs that meet our security and privacy standards, configure them to collect only what is needed, and require that they protect the data they receive. The SDKs used by each App, and the data they collect, are reflected in that App’s store privacy disclosures.
4.5 Purchases and sign-in
If an App offers in-app purchases or subscriptions, payments are processed by Apple or Google under their own terms and privacy policies; we do not receive your full payment card details. If an App offers sign-in with Apple, Google or another provider, we receive only the information that provider shares with your permission (such as your name and email address, or Apple’s private relay address).
4.6 Data handling in Apps
Data transmitted between an App and our systems is encrypted in transit. You can request deletion of your App account and associated data at any time, as described in section 13. Where an App offers accounts, it also provides a way to start account deletion from within the App, as required by Apple and Google.
5. How and why we use personal information
We identify the purposes for collecting personal information at or before the time of collection, and we use personal information only for those purposes, for purposes a reasonable person would consider appropriate in the circumstances, or as permitted or required by law. These purposes are to:
- respond to enquiries and requests and communicate with you;
- provide, deliver, manage, support and invoice our Services and Apps, and perform our contracts;
- deliver training and report results to the organization that engaged us;
- create and manage accounts and authenticate users;
- operate, maintain, troubleshoot and improve the Website, Apps and Services, including through aggregated statistics;
- protect the security and integrity of our Website, Apps, systems, clients and visitors, including detecting, investigating and preventing fraud, spam, abuse and cyber attacks;
- send service-related messages and, with consent where required, information about our Services (see section 14);
- evaluate job applicants and manage supplier relationships;
- comply with legal, regulatory, tax, accounting and audit obligations, and respond to lawful requests from authorities; and
- establish, exercise or defend legal claims and protect our rights, property and safety and those of others.
We will not use personal information for a new purpose without first identifying that purpose and obtaining your consent, unless the new use is permitted or required by law. We do not use automated decision-making that produces legal or similarly significant effects on individuals.
6. Consent and legal bases
We obtain your consent to the collection, use and disclosure of your personal information, except where the law permits or requires otherwise. The form of consent depends on the sensitivity of the information and your reasonable expectations: consent may be express (for example, ticking a box or granting an App permission) or implied (for example, when you send us an email asking us to contact you, you consent to our using your contact details to reply). We do not require you to consent to more collection than is necessary to provide a product or service as a condition of providing it.
You may withdraw your consent at any time on reasonable notice, subject to legal or contractual restrictions. We will inform you of the likely consequences, such as our being unable to provide a service. Withdrawal does not affect processing that occurred before it.
Where the GDPR or a similar law applies, we rely on the following legal bases: performance of a contract with you or steps at your request before entering into one; our legitimate interests in operating, securing and improving our business, Website and Apps (balanced against your rights); compliance with legal obligations; and your consent, for example for non-essential cookies, analytics where required, and marketing.
7. Cookies, analytics and tracking
Cookies and similar technologies are small files or identifiers stored on your device. We use:
- Strictly necessary cookies that make the Website work and keep it secure, including cookies that may be set by our content-delivery and security providers to distinguish legitimate traffic from malicious traffic, and cookies used when an authorized user logs in.
- Functional cookies set by the Website if you leave a comment and choose to have your name and email remembered.
- Analytics cookies set by Google Analytics (for example
_gaand_ga_*), which help us measure and improve the Website.
We do not use cookies to serve advertising, and we do not allow third parties to use cookies on the Website for targeted advertising. You can block or delete cookies through your browser settings, use your browser’s private mode, enable signals such as Global Privacy Control, or opt out of Google Analytics using Google’s browser add-on at tools.google.com/dlpage/gaoptout. Blocking non-essential cookies will not prevent you from using the Website. If you are located in a jurisdiction where analytics cookies require your prior consent, you may refuse or withdraw that consent at any time using the options above, and we will not use analytics data from browsers that block or delete these cookies. You can learn how Google uses information from sites that use its services at policies.google.com/technologies/partner-sites.
8. How we share personal information
We do not sell, rent or trade personal information, and we do not share it for cross-context behavioural advertising. We disclose personal information only as described below.
8.1 Service providers
We use carefully selected service providers to operate our business, Website and Apps. They may access personal information only as needed to perform services for us, and we require them by contract or other means to protect it with safeguards comparable to our own and to use it only for the purposes we specify. Our current principal service providers are:
- Google LLC — website analytics (Google Analytics) and other embedded web services such as fonts, maps and videos (video players load only after you choose to play a video); and, for Apps, Google Play distribution and related services. Using these services sends your IP address and browser or device information to Google.
- Security, network and content-delivery providers — protection of the Website against attacks, content delivery and domain-name services; these providers process traffic to the Website, including IP addresses.
- Email and communications providers — business email and communications; messages you send us are stored by our email provider.
- Avatar service — if you comment, a hashed string derived from your email address may be sent to an avatar service to display your profile picture if you have one.
- Apple Inc. — distribution of our iOS and macOS Apps, push notifications and, where offered, Sign in with Apple and in-app purchases.
- Professional advisers (such as lawyers, accountants, auditors and insurers) bound by confidentiality, and IT, hosting and communications providers that support our operations.
8.2 Other disclosures
- Your organization: if we deliver training or Services to your employer, we share relevant results and records with that organization.
- Legal requirements: where required or permitted by law, for example to comply with a subpoena, warrant, court order or other legal process, to respond to a lawful request from a government institution, or to report suspected fraud or illegal activity.
- Protection of rights and safety: where reasonably necessary to investigate a breach of an agreement or a contravention of law, to protect the security of our systems, or to protect the rights, property or safety of The Innovates Tech Inc., our clients or others, including in an emergency threatening someone’s life, health or security.
- Business transactions: in connection with a proposed or completed merger, acquisition, financing, reorganization or sale of all or part of our business, as permitted by PIPEDA and PIPA, subject to agreements that require the information to be protected and used only for the transaction.
- With your consent or at your direction.
9. Storage and transfers outside Canada
Personal information may be stored and processed in Canada and in other countries, including the United States, where we or our service providers operate. When personal information is outside Canada it is subject to the laws of the country where it is held and may be accessible to the courts, law-enforcement and national-security authorities of that country.
We use contractual and other measures to require these providers to protect personal information appropriately. Where the GDPR or UK GDPR applies, transfers are made on the basis of an adequacy decision (Canada benefits from an EU adequacy decision for commercial organizations subject to PIPEDA) or appropriate safeguards such as standard contractual clauses. As required by Alberta’s PIPA, you may obtain written information about our policies and practices for service providers outside Canada, and ask questions about the collection, use, disclosure or storage of personal information by those service providers, by contacting our Privacy Officer.
10. Retention and deletion
We keep personal information only as long as necessary to fulfil the purposes for which it was collected, or as required or permitted by law, and then securely destroy, erase or de-identify it. Where personal information is used to make a decision about an individual, we keep it long enough to allow the individual access to it after the decision. Our general retention periods are:
- Web server access logs: kept only for the short period needed for security and operations, then automatically deleted.
- Security monitoring and incident records: kept only as long as needed to detect, investigate and respond to security events, and longer only if needed for an ongoing investigation or legal matter.
- Website analytics data: retained in Google Analytics for no longer than the retention period configured in our account, then deleted automatically.
- Enquiries from people who do not become clients: generally deleted within 24 months of our last communication.
- Client, contract, training and financial records: kept for the duration of the relationship and for at least six years afterwards to meet tax, accounting and legal obligations and to address potential claims.
- App account data: kept while your account is active, and deleted or de-identified within 30 days after you delete your account, except for limited information we must keep for legal, security or fraud-prevention purposes.
- Published comments: kept until you ask us to remove them or we remove the post.
Backups containing deleted information are overwritten in the normal course of our backup cycle.
11. Security safeguards and breach notification
We protect personal information with safeguards appropriate to its sensitivity, against loss, theft and unauthorized access, disclosure, copying, use, modification or destruction. As a cybersecurity company, we apply to our own systems the practices we recommend to clients, including:
- encryption of data in transit (HTTPS/TLS) for the Website and Apps;
- hardened, regularly patched systems and firewalls;
- continuous security monitoring, logging and daily security assessments;
- access to personal information limited to personnel and providers who need it, under confidentiality obligations; and
- secure deletion and disposal practices.
No method of transmission over the internet or of electronic storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your own account credentials confidential and for notifying us promptly of any suspected unauthorized use.
Breach notification: if a breach of security safeguards involving personal information under our control creates a real risk of significant harm to individuals, we will report it to the Office of the Privacy Commissioner of Canada and/or the Office of the Information and Privacy Commissioner of Alberta, notify affected individuals as soon as feasible, notify other organizations that may be able to reduce the risk of harm, and keep records of breaches, as required by PIPEDA and PIPA. We will also meet any notification obligations under other laws that apply.
12. Your privacy rights
Subject to the exceptions permitted by law, you have the right to:
- Access: be informed whether we hold personal information about you, obtain access to it, and learn how it has been used and to whom it has been disclosed;
- Correction: challenge the accuracy and completeness of your information and have it corrected or annotated;
- Withdraw consent to our collection, use or disclosure of your information;
- Deletion: ask us to delete your information where we no longer need it or are not required to keep it;
- Information about service providers outside Canada (see section 9); and
- Complain to us and to a privacy regulator (see section 21).
Additional rights may apply depending on where you live (see section 16). To exercise your rights, contact our Privacy Officer. We will respond within 30 days, or within any extended period permitted by law, in which case we will tell you the reason and the expected timing. We may need to verify your identity, and an authorized representative may act for you with proof of authority. We do not charge for most requests; if a fee is permitted and applies, we will tell you in advance. If we refuse a request, we will explain why in writing, subject to legal limits, and tell you how to challenge our decision. We will not discriminate against you for exercising your privacy rights.
13. How to request deletion of your account and data
You can ask us to delete your personal information, including any App account and its associated data, at any time:
- In an App: where an App offers accounts, use the account-deletion option in the App’s account or settings screen.
- By email: send a request to [email protected] with the subject “Data deletion request”, the name of the App or service, and the email address or username associated with your account. You do not need to have the App installed to make a request.
We will confirm your request, verify that it comes from the account holder, and delete or de-identify your account and associated personal information within 30 days. We may keep limited information where required by law or for legitimate purposes such as security, fraud prevention, resolving disputes or enforcing our agreements; any information kept is protected and deleted when no longer needed. Deleting an App from your device does not delete your account.
14. Electronic communications (CASL)
We send commercial electronic messages, such as newsletters or promotional emails, only with your consent as required by Canada’s Anti-Spam Legislation. Every such message identifies us and includes a working unsubscribe mechanism, and we act on unsubscribe requests within 10 business days. Even if you unsubscribe from marketing, we may still send you messages that relate to an existing transaction, engagement or account, such as invoices, service notices and security alerts.
15. Children’s privacy
Our Website, Apps and Services are intended for businesses and adults and are not directed to children. We do not knowingly collect personal information from children under 13 (or under the age of digital consent in your jurisdiction, such as 14 in Quebec or up to 16 in parts of Europe) without verified parental or guardian consent. If you believe a child has provided personal information to us, please contact us and we will promptly delete it. None of our Apps is designed for or listed in the children’s or family categories of the Apple App Store or Google Play unless the App’s listing says so, in which case that App will comply with the applicable children’s privacy rules and store policies.
16. Additional information for specific regions
Alberta
We collect, use and disclose personal information only for purposes that are reasonable, and to the extent reasonable for meeting those purposes, as required by PIPA. You may ask our Privacy Officer, whose contact details are below, any questions about our collection of your personal information, and request information about our use of service providers outside Canada.
Quebec
Our person in charge of the protection of personal information is our Privacy Officer (see section 21). Quebec residents may also request that information be communicated in a structured, commonly used technological format (data portability), request the de-indexation of information, and be informed of the use of technologies that identify, locate or profile them. The only such technology on the Website is Google Analytics (see section 7), which you can refuse or disable at any time; our Apps do not profile or track users. You may file a complaint with the Commission d’accès à l’information du Québec.
European Economic Area, United Kingdom and Switzerland
If the GDPR or UK GDPR applies to our processing of your personal information, you also have the right to restrict or object to processing (including processing based on legitimate interests), to data portability, to withdraw consent at any time, and to lodge a complaint with your local data-protection authority. The Innovates Tech Inc. is the controller of personal information described in this policy.
United States
Depending on your state of residence (for example California, Colorado, Connecticut, Virginia or another state with a comprehensive privacy law), you may have rights to know, access, correct and delete personal information, to obtain a copy in a portable format, and to opt out of the sale or sharing of personal information and of targeted advertising and profiling. We do not sell personal information and do not share it for cross-context behavioural advertising, and we have not done so in the past 12 months. We honour Global Privacy Control signals as an opt-out of sale or sharing where required. You may appeal a decision about your request by contacting our Privacy Officer. The categories of personal information we collect, their sources, purposes and recipients are described in sections 3 to 8.
17. Client data we process for our customers
When we provide cybersecurity Services, we may access or process personal information that belongs to, or is controlled by, our clients — for example user accounts, logs or emails within a client’s systems during an assessment, monitoring or incident response. In those cases we act as a service provider (or “processor”) on behalf of the client, the client is responsible for that information, and our handling of it is governed by our agreement with the client, including confidentiality and data-protection terms. We use such information only to provide the Services the client has requested. Individuals whose information is held by one of our clients should direct privacy questions and requests to that client; we will assist the client in responding as required by our agreement and by law.
18. Third-party websites and services
The Website and Apps may contain links to, or integrations with, websites, platforms and services operated by third parties, such as social-media sites, Apple, Google and payment providers. Their collection and use of personal information is governed by their own privacy policies, not this one, and we are not responsible for their content or privacy practices. We encourage you to review their policies before providing them with personal information.
19. Limitations
This policy describes our privacy practices; it does not create contractual rights for any third party, and it does not limit any rights you have under applicable law. The Website and Apps are provided subject to any terms of use we publish. To the fullest extent permitted by applicable law, we are not responsible for: the privacy practices of third parties described in section 18; information you choose to make public, such as published comments; unauthorized access resulting from the compromise of your own devices or credentials; or the interception of information you send to us by unencrypted means such as ordinary email. Nothing in this policy excludes or limits any liability that cannot be excluded or limited by law, including our obligations under PIPEDA and PIPA.
20. Changes to this policy
We may update this policy from time to time to reflect changes in our practices, Services, Apps or applicable law. The updated version will be posted on this page with a new “Last updated” date. If we make material changes, we will take reasonable steps to notify you — for example by a notice on the Website, in the App or by email — before the changes take effect, and we will obtain your consent where required by law before using personal information for a new purpose. Your continued use of the Website, Apps or Services after a change takes effect means you acknowledge the updated policy. This policy is written in English; any translation is provided for convenience, and the English version prevails to the extent permitted by law.
21. Contact us and complaints
If you have a question or concern about this policy or our privacy practices, or wish to exercise any of your rights, please contact our Privacy Officer:
- Privacy Officer, The Innovates Tech Inc.
- Calgary, Alberta, Canada
- [email protected] (subject: “Privacy request”)
- +1 (403) 800-2228
We will investigate all complaints and, if a complaint is justified, take appropriate measures, including amending our policies and practices where necessary. If you are not satisfied with our response, you may contact a privacy regulator:
- Office of the Information and Privacy Commissioner of Alberta
- Office of the Privacy Commissioner of Canada
- Quebec residents: Commission d’accès à l’information du Québec
- Other jurisdictions: your local data-protection or privacy authority
This policy is governed by the laws of the Province of Alberta and the federal laws of Canada applicable in Alberta, without limiting any mandatory rights you have under the laws of the place where you live.