Privacy Policy
At Truvo Cyber, we are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy outlines how we collect, use, and safeguard your data when you visit our lead generation website.
Truvo Cyber Privacy Policy
Effective Date: October 23, 2025
1. Our Commitment, Scope, and Jurisdictional Compliance
As a cybersecurity and compliance firm, we hold this policy to the same standard we hold our clients to.
This policy is governed by, and aims to exceed the requirements of:
- The Personal Information Protection and Electronic Documents Act (PIPEDA), Canada's federal private-sector privacy law.
- Quebec's Act respecting the protection of personal information in the private sector (Law 25 / Bill 64).
- The EU General Data Protection Regulation (GDPR), to the extent we process personal data of individuals located in the European Economic Area (EEA) or the United Kingdom, whether in connection with offering services to those individuals or monitoring their behaviour.
This policy applies to data collected when you interact with our website, use our online assessment tools, communicate with us by SMS/text message, or inquire about our services.
2. Information We Collect
We collect information that falls into two main categories:
A. Information You Provide Voluntarily
This data is collected when you fill out forms, subscribe to our content, opt in to SMS communications, or use our compliance assessment tools.
- Contact & Identity Data: Name, email address, company name, phone number, job title/role.
- Assessment & Compliance Data: Information provided via our online assessment regarding your company's size, industry, current security tools, and compliance maturity level.
- SMS Opt-In Data: Mobile phone number and consent timestamp captured when you opt in to receive text messages from us.
B. Information Collected Automatically
This data is collected as you browse our website and is used for security, performance, and analytics purposes.
- Technical Data: IP address, browser type, operating system, device type, and referring website addresses.
- Usage Data: Pages viewed, time spent on our website, and interaction with our content (collected via tools like Google Analytics).
3. How We Use Your Information and Legal Basis
We use your information only for identified purposes, based on a specific legal basis as required by Canadian privacy law and, where applicable, Article 6 of the GDPR.
| Purpose of Use | Legal Basis (PIPEDA / Law 25) | Legal Basis (GDPR, where applicable) |
|---|---|---|
| Service Delivery (responding to inquiries, quotes, or contracts) | Contractual Necessity or Legitimate Interest | Performance of a Contract (Art. 6(1)(b)) |
| Personalized Assessments (generating your compliance report) | Express Consent (provided when you actively submit the form) | Consent (Art. 6(1)(a)) |
| Marketing & Communications (sending updates, resources, and promotions, including SMS) | Express Consent (requires a separate opt-in for marketing) | Consent (Art. 6(1)(a)) |
| Platform Security & Analysis (monitoring for threats and improving our website) | Legitimate Interest (ensuring the security and function of our services) | Legitimate Interest (Art. 6(1)(f)) |
Where we rely on consent as our legal basis, you may withdraw that consent at any time without affecting the lawfulness of processing carried out before withdrawal.
4. Disclosure of Your Information and Data Transfers
We do not sell your personal information. We only share it with trusted third-party service providers (data processors) who perform essential business functions on our behalf and are bound by strict confidentiality agreements.
A. Third-Party Processors
These providers help us operate and deliver our services. By using our website, you acknowledge that your data is shared with the following key processors:
- Customer Relationship Management (CRM) & Marketing Platform (e.g., HubSpot) for managing contacts, email campaigns, and hosting website content.
- Website Analytics (e.g., Google Analytics) for collecting anonymized usage data to help us improve our website and services.
- GRC Automation Platforms (e.g., Secureframe) for managing compliance projects.
- Lead Generation/Assessment Tools for distributing compliance assessments.
- SMS/Text Messaging Platform (e.g., JustCall) for sending and receiving SMS communications you have opted in to receive. See Section 5, SMS Communications, below.
B. Cross-Border Data Transfer (PIPEDA, Law 25, and GDPR)
Your personal information may be transferred to, stored in, and processed in jurisdictions outside of Canada (including the United States), where our service providers or their servers are located. By using our website, you acknowledge this transfer.
Truvo Cyber commits to conducting a Privacy Impact Assessment (PIA) on all such transfers to ensure that the data continues to receive a level of protection at least equivalent to that provided under Canadian and Quebec law.
Where personal data of individuals in the EEA or UK is transferred outside those regions, Truvo Cyber relies on appropriate safeguards recognized under the GDPR, such as the European Commission's Standard Contractual Clauses (SCCs), to ensure an equivalent level of protection.
5. SMS Communications
If you opt in to receive text messages from Truvo Cyber, the following terms apply in addition to the rest of this Privacy Policy.
- Consent: By providing your mobile phone number and opting in through our website form, verbal consent, or another approved method, you agree to receive SMS/text messages from Truvo Cyber related to the purpose for which you opted in (e.g., appointment reminders, service updates, or marketing communications, as applicable).
- No Sharing for Marketing Purposes: No mobile information will be shared with third parties/affiliates for marketing or promotional purposes. This does not apply to our SMS platform provider or other service providers who process this data solely to deliver the service on our behalf, subject to confidentiality obligations.
- Message Frequency: Message frequency may vary depending on your interactions with us.
- Message and Data Rates: Message and data rates may apply, depending on your mobile carrier and plan.
- Opt-Out: You may opt out of receiving SMS messages at any time by replying STOP to any message you receive from us. You may receive a one-time confirmation message that your opt-out was processed.
- Help: Reply HELP to any message for assistance, or contact us using the information in Section 9 below.
- Carrier Liability: Carriers are not liable for delayed or undelivered messages.
- Supported Carriers: Not all mobile carriers or devices may be supported.
6. Data Security, Confidentiality, and Retention
We implement and continuously monitor technical, physical, and administrative safeguards aligned with SOC 2 and ISO 27001 principles.
Confidentiality of Client Business Data (NDA)
The confidentiality of your company's proprietary and trade secret information is protected by a separate, legally binding Non-Disclosure Agreement (NDA). This NDA is signed prior to the exchange of any detailed business, financial, or technical information related to your operations. The NDA serves as a dedicated contractual safeguard for Confidential Business Information, distinct from the personal information covered by this Privacy Policy.
Data Retention
We retain your personal information only for as long as necessary to fulfill the purposes for which it was collected, including satisfying any legal, accounting, or reporting requirements. When personal information is no longer required, it is securely destroyed, deleted, or anonymized in accordance with our internal retention schedule.
Incident and Breach Notification (Law 25 and GDPR)
In the event of a confidentiality incident involving personal information that presents a risk of serious injury, Truvo Cyber will notify the Commission d'acces a l'information du Quebec (CAI) and affected individuals, in accordance with Law 25. Where the incident involves personal data of individuals in the EEA or UK, Truvo Cyber will notify the relevant supervisory authority and affected individuals in accordance with the notification timelines and thresholds set out in the GDPR. We maintain an internal register of confidentiality incidents as required by Law 25.
7. Your Privacy Rights
In accordance with PIPEDA, Law 25, and, where applicable, the GDPR, you have specific rights concerning your personal information, which you may exercise by contacting our Privacy Officer:
- Right of Access & Rectification: To access and request corrections to any inaccuracies in your personal information.
- Right to Withdraw Consent: To withdraw your consent to the use or disclosure of your information, particularly for marketing communications (including SMS), at any time.
- Right to De-indexation (Law 25): To request that we cease disseminating or de-index any hyperlink providing access to your personal information, provided the dissemination causes you injury.
- Right to Data Portability (Law 25 / GDPR): To request that your personal information be communicated to you, or where technically feasible to a third party of your choosing, in a structured, commonly used, machine-readable format.
- Right to Erasure (Right to be Forgotten) (GDPR): To request deletion of your personal information, subject to applicable legal or contractual retention requirements.
- Right to Restriction of Processing (GDPR): To request that we limit how we use your personal information in certain circumstances.
- Right to Object (GDPR): To object to our processing of your personal information where we rely on legitimate interest as our legal basis, including for direct marketing.
- Right to Lodge a Complaint (GDPR): If you are located in the EEA or UK, you have the right to lodge a complaint with your local data protection supervisory authority if you believe our processing of your personal information violates the GDPR.
We will respond to verified requests within the timeframes required by applicable law.
8. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the effective date.
9. Contact Our Privacy Officer
For any questions, concerns, or to exercise your privacy rights, please contact our designated Privacy Officer:
| Name: | Ali Aleali |
| Title: | Privacy Officer (Responsible for the Protection of Personal Information) |
| Email: | privacy@truvo.ca |
| Address: | 1000 Innovation Dr, Suite 500, Ottawa, ON K2K 3E7, Canada |
If you are located in the EEA or UK and have concerns we have not resolved, you also have the right to contact your local data protection supervisory authority.