Privacy Policy

CyberXOne Inc. (“CyberXOne”, “we”, “us”, or “our”) respects the privacy of visitors, prospective clients, clients, business contacts, and others who communicate with us. This Privacy Policy explains the personal information practices that apply to our public website and to enquiries made to CyberXOne.

This policy does not govern personal information that CyberXOne processes solely on behalf of a client under a professional services agreement. Such information is handled under the applicable engagement terms, client instructions, confidentiality obligations, and any applicable data processing or privacy agreement.


1. Accountability and scope

CyberXOne Inc. is accountable for personal information under its control. We have designated a Privacy Officer to oversee our privacy program, respond to privacy enquiries and requests, and support compliance with applicable Canadian privacy law, including the Personal Information Protection and Electronic Documents Act (PIPEDA) where it applies.

Privacy Officer

CyberXOne Inc.

Markham, Ontario, Canada

privacy@cyberxone.ca


2. Personal information we collect

2.1 Information you provide

When you submit a website form, request a consultation, schedule a meeting, email us, or otherwise communicate with us, we may collect information you choose to provide, such as:

  • Name and contact information, including email address and telephone number.
  • Organization, job title, or role, where provided.
  • The content of your enquiry or correspondence, including information about cybersecurity needs or requirements.
  • Preferred dates and times for a consultation, meeting, or call.

PLEASE NOTE: Do not submit passwords, authentication secrets, private keys, detailed system diagrams, vulnerability details, incident evidence, personal health information, or other highly sensitive information through a general website form or ordinary email unless CyberXOne has specifically requested it and provided an appropriate secure method.




2.2 Information collected automatically

CyberXOne does not currently use website analytics, behavioural advertising, session recording, heatmaps, or advertising pixels on cyberxone.ca. We do not use the website to build advertising profiles or intentionally track visitors across unrelated websites.

Our hosting, domain, content-delivery, and security infrastructure may nevertheless process standard technical information when your browser connects to the site. Depending on the service involved, this can include IP address, browser and device information, operating system, requested page or resource, referring information, timestamps, and security or diagnostic events. We use this information to deliver, operate, troubleshoot, protect, and maintain the website, not for behavioural advertising.

The website currently loads certain typefaces from Google Fonts. When fonts are requested directly from Google, Google may receive technical request information such as your IP address. CyberXOne does not use that request for marketing or profiling.


2.3 Cookies and similar technologies

The website currently uses a first-party cookie named “visits” so the site can determine whether a page has previously been viewed during a visit. We do not currently use analytics or advertising cookies. Because the cookie is used for website functionality rather than advertising or cross-site tracking, CyberXOne does not currently present a marketing-cookie consent banner.

You can configure your browser to block or delete cookies. Blocking a functional cookie may affect some website behaviour. If CyberXOne later introduces non-essential analytics, advertising, or similar technologies, we will update this policy and implement any consent mechanism required by applicable law.


3. Purposes for collection, use, and disclosure

We collect, use, and disclose personal information only for purposes that a reasonable person would consider appropriate in the circumstances, including to:

  • Respond to enquiries and requests and arrange consultations, meetings, or demonstrations.
  • Assess, discuss, or provide cybersecurity advisory and professional services.
  • Provide information specifically requested from us.
  • Maintain business, client, prospective-client, and professional records.
  • Operate, troubleshoot, secure, and maintain our website and business systems.
  • Prevent, detect, investigate, and respond to suspected fraud, abuse, or security incidents.
  • Meet legal, regulatory, contractual, insurance, accounting, and professional obligations.
  • Establish, exercise, or defend legal claims where permitted by law.

We do not sell or rent personal information. We do not add a person to a marketing mailing list merely because they submitted an enquiry. If we introduce optional marketing communications, we will use an appropriate opt-in or other lawful basis and provide a practical way to unsubscribe.


4. Consent and limiting collection

Where consent is required, CyberXOne seeks consent that is meaningful in the circumstances. We identify the relevant purposes at or before collection and limit collection to information reasonably necessary for those purposes. The form of consent may depend on the sensitivity of the information and the reasonable expectations of the individual.

You may withdraw consent to future collection, use, or disclosure that is based on consent, subject to legal or contractual restrictions and reasonable notice. We will explain material consequences of withdrawal where appropriate. Withdrawal does not necessarily require CyberXOne to delete information that we are legally or contractually required, or otherwise permitted by law, to retain.

PIPEDA and other applicable laws permit certain collections, uses, or disclosures without knowledge or consent. CyberXOne will rely on such exceptions only where the legal requirements are met.


5. Service providers and other disclosures

CyberXOne uses service providers to support its website and business operations. Personal information may be transferred to a service provider for processing on CyberXOne’s behalf. CyberXOne remains responsible for personal information under its control and uses contractual or other measures appropriate to the circumstances to require service providers to protect it.

PROVIDER

PURPOSE

INFORMATION THAT MAY BE PROCESSED

Hostinger

Website hosting

Website form contents and technical/server-log information

Zoho

Business email and appointment scheduling

Enquiries, contact details, scheduling information, and correspondence

Google Workspace / Drive

Business document and file storage

Business records relating to enquiries or engagements, where used

Google Fonts

Delivery of website typefaces

Technical request information, including IP address when fonts are loaded directly

Cloudflare

DNS, content delivery, performance, and security services

Technical request, network, and security information



5.1 Other circumstances

We may also disclose personal information where permitted or required by law, including in response to a valid court order, subpoena, warrant, regulatory requirement, or other lawful demand; to investigate or respond to fraud, misuse, or a security incident; to protect the rights, property, or safety of CyberXOne or others; to obtain professional advice; or in connection with a proposed or completed merger, financing, reorganization, acquisition, sale, or transfer of all or part of our business or assets, subject to applicable legal requirements.


6. Cross-border processing

CyberXOne operates from Ontario, Canada. Some service providers may process or store information in other provinces or countries, including the United States. When personal information is processed outside the jurisdiction in which it was collected, it may be subject to the laws of that jurisdiction and may be accessible to courts, law-enforcement, national-security, or regulatory authorities in accordance with local law.

CyberXOne uses measures appropriate to the circumstances to protect personal information transferred to service providers. You may contact the Privacy Officer for additional information about our use of service providers and cross-border processing.


7. Retention and disposal

CyberXOne retains personal information only for as long as reasonably necessary to fulfil the identified purposes, meet legal, contractual, professional, insurance, accounting, security, or dispute-resolution requirements, and maintain appropriate business records. When information is no longer required, we securely delete, destroy, or anonymize it, subject to technical limitations such as backup cycles and legal holds.

RECORD CATEGORY

TYPICAL RETENTION APPROACH

Enquiries that do not lead to an engagement

Normally up to 12 months after the enquiry is closed, unless a longer period is reasonably required.

Client engagement and related business records

Commonly up to seven years after the end of the engagement, or longer where required by law, contract, professional obligation, legal hold, or another legitimate recordkeeping requirement.

Website/server/security logs

According to the operational and security settings of the relevant provider and only as long as reasonably necessary for those purposes.




8. Safeguards

CyberXOne maintains administrative, technical, and physical safeguards appropriate to the sensitivity, amount, format, location, and risks associated with personal information. Measures may include role-based or need-to-know access restrictions, multi-factor authentication on business systems, encryption in transit, endpoint and account security controls, secure configuration, logging and monitoring, confidentiality obligations, provider due diligence, backup and recovery measures, and secure disposal practices.

No security control or method of electronic transmission or storage can eliminate all risk. CyberXOne therefore cannot guarantee absolute security, but we maintain safeguards designed to reduce the risk of loss, theft, unauthorized access, disclosure, copying, use, modification, or disposal.


9. Privacy and security incidents

CyberXOne maintains processes to identify, assess, contain, investigate, document, and respond to suspected privacy and security incidents. Where a breach of security safeguards involving personal information under our control creates a real risk of significant harm, CyberXOne will notify affected individuals and report the breach to the Office of the Privacy Commissioner of Canada as required by PIPEDA. We will also notify other organizations or authorities where required by law and maintain breach records as required.


10. Access, correction, and other privacy requests

Subject to applicable law and permitted exceptions, you may ask whether CyberXOne holds personal information about you, request access to that information, ask how it has been used or disclosed, and request correction of information that is inaccurate or incomplete. You may also withdraw consent where our processing depends on consent and ask us to delete information that is no longer required, recognizing that a deletion request may be limited by legal, contractual, professional, security, backup, or record-retention obligations.

Send a request to privacy@cyberxone.ca. We may need to verify your identity before disclosing or changing personal information. We will respond within the time required by applicable law. Under PIPEDA, access requests are generally addressed within 30 days, subject to permitted extensions.

If you are dissatisfied with our response, you may raise the matter with the Office of the Privacy Commissioner of Canada. Current contact information is available at priv.gc.ca.


11. Visitors outside Canada

CyberXOne is based in Canada. If you access our website or communicate with us from another jurisdiction, local privacy laws may apply in addition to Canadian law depending on the circumstances. Nothing in this policy is intended to limit rights that cannot lawfully be limited. If you wish to exercise a privacy right under a law that applies to your interaction with CyberXOne, contact our Privacy Officer and identify the jurisdiction and request.


12. Children

Our website and professional services are directed to organizations and business contacts and are not designed for children. We do not knowingly solicit personal information from children through the website. If you believe a child has provided personal information to us inappropriately, contact the Privacy Officer so we can assess and address the matter.


13. Third-party websites

Our website may contain links to websites or services operated by third parties. Their privacy and security practices are governed by their own policies and are not controlled by CyberXOne. We encourage you to review the applicable privacy information before submitting personal information to a third party.


14. Changes to this Privacy Policy

We may update this Privacy Policy when our practices, service providers, website technologies, or legal obligations change. The current version will be posted on cyberxone.ca with its effective date and version number. Where a change materially affects how we collect, use, or disclose personal information, we will provide additional notice or obtain consent where required by applicable law. We do not treat continued website use as consent to a new purpose where applicable law requires fresh consent.


15. Contact

Questions, access or correction requests, consent withdrawals, privacy concerns, or complaints may be directed to:

Privacy Officer

CyberXOne Inc.

Markham, Ontario, Canada

privacy@cyberxone.ca


Revision history

VERSION

DATE

SUMMARY OF CHANGE

1.0

2025-08-01

Initial publication.

1.1

2026-08-24

Updated privacy-law language; clarified consent, automatic collection, service-provider accountability, cross-border processing, retention, safeguards, breach response, individual requests, and policy-change practices; removed obsolete analytics-retention wording.



Scroll to top