Privacy Policy
Version 1.1 Last updated: September 2026
Contact
For inquiries regarding the Privacy Policy, contact the Information Security Officer of Data Century or email [email protected].
1. Purpose
1.1 This Privacy Policy explains how the Company collects, uses, protects, retains, and discloses personal information in the course of its business operations and client service delivery.
1.2 This policy applies to personal information collected from clients, prospective clients, website visitors, event participants, job applicants, contractors, and vendors.
2. Scope
2.1 The Company may collect personal information such as names, business contact information, employment or contractor information, billing and payment information, client contact details, and information required to provide professional services.
2.2 The Company only collects personal information that is necessary for legitimate business, operational, contractual, legal, or security purposes.
2.3 The Company may collect information in the following contexts:
- When you visit or interact with our website (datacentury.ca)
- When you engage us for professional services
- When you subscribe to our newsletter or email communications
- When you attend or register for an event we host, co-host, or sponsor
- When you interact with us at a conference or event where Data Century is a sponsor or exhibitor
- When you apply for a role at Data Century
- When you communicate with us through any channel
2.4 The Company may also collect digital activity information when you visit our website, including:
- Pages viewed, time spent, and date and time of visit
- Browser type, device type, and operating system
- IP address and approximate geographic region
- Referring website or source
- Interaction data such as clicks and form submissions
2.5 The Company uses cookies and similar tracking technologies on its website, including Google Analytics, to understand how visitors use the site. You can disable cookies in your browser settings; most website features will remain accessible.
3. How We Use Personal Information
3.1 The Company uses personal information to:
3.1.1 provide services to clients;
3.1.2 manage employee, contractor, client, and vendor relationships;
3.1.3 administer business operations;
3.1.4 meet legal, contractual, security, and compliance obligations;
3.1.5 protect Company systems, data, and assets.
3.1.6 send marketing communications, event invitations, and newsletters, where the individual has expressly or implicitly consented to receive them. Consent may be withdrawn at any time by clicking the unsubscribe link in any email or by contacting us directly;
3.1.7 analyze website usage to improve our website and service offerings, using aggregated or de-identified data where possible.
4. Disclosure of Personal Information
4.1 The Company does not sell personal information.
4.2 Personal information may be disclosed to service providers, professional advisors, clients, regulators, or other third parties where required to deliver services, support business operations, meet contractual obligations, comply with law, or protect Company interests.
4.3 Where service providers process personal information on behalf of the Company, the Company expects them to protect the information appropriately.
4.4 Categories of third-party service providers used by the Company include:
- CRM and marketing communications platforms
- Web analytics and website infrastructure tools
- Productivity, collaboration, and communications platforms
- Project, time, and financial management tools
- External professional services (accounting, payroll, legal)
4.5 Some service providers are based in the United States and may be subject to U.S. laws, including the USA PATRIOT Act, which may allow U.S. authorities to access information held by those providers.
5. Safeguards
5.1 The Company protects personal information using administrative, technical, and physical safeguards appropriate to the sensitivity of the information. These safeguards may include access controls, authentication requirements, encryption, endpoint protection, secure storage, employee and contractor obligations, and monitoring or review of access.
5.2 The Company maintains a formal information security program as part of its ongoing compliance activities.
6. Retention and Disposal
6.1 The Company retains personal information only as long as necessary for business, legal, contractual, operational, or compliance purposes. When personal information is no longer required, it is securely deleted, destroyed, anonymized, or otherwise disposed of in accordance with Company procedures.
7. Access and Correction
7.1 Individuals may request access to, or correction of, their personal information held by the Company, subject to legal, contractual, security, and operational limitations.
7.2 To submit an access or correction request, contact us at [email protected]. The Company will respond within 30 days.
7.3 If you are not satisfied with how your request is handled, you may contact the Office of the Privacy Commissioner of Canada at www.priv.gc.ca.
8. Cross Border Transfers and Access
8.1 Personal information may be stored, processed, or accessed outside Canada where Data Century uses approved cloud services, service providers, subcontractors, or client-managed systems located in other jurisdictions. In such cases, the information may be subject to the laws of those jurisdictions, including lawful access by courts, law enforcement, or government authorities. Data Century will use appropriate contractual, administrative, and technical safeguards to protect personal information and will comply with applicable legal, contractual, and client data-residency requirements.
9. Privacy Incidents
9.1 Suspected privacy or security incidents involving personal information must be reported promptly to the Company’s designated privacy or security contact. The Company will assess, contain, investigate, document, and respond to incidents in accordance with its incident response procedures.
9.2 If Data Century becomes aware of a privacy incident that affects your personal information, we will take prompt action to assess and contain the incident and, where required by applicable law, notify affected individuals and report to relevant regulatory authorities in a timely manner.
9.3 If you believe your personal information has been compromised or handled incorrectly, please contact us at [email protected].
10. Governing Law
10.1 This policy is governed by the laws of Canada and the province of Ontario. Data Century complies with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation