Privacy Policy
Effective 2 May 2026 · PIPEDA · Law 25 · GDPR-alignedPlain-English privacy policy for 4UIT Inc. — compliant with the Personal Information Protection and Electronic Documents Act (PIPEDA), Quebec’s Law 25, and aligned with GDPR best practice for visitors outside Canada. If any of it is unclear, that is a defect and we would like to hear about it.
01. Who we are
4UIT Inc. (“4UIT,” “we,” “us”) is an Ottawa-based managed IT and cybersecurity firm, federally incorporated in Canada, registered at 5-2000 Thurston Drive, Ottawa, ON K1G 4K7. This policy covers personal information we handle when you visit this site, use our services, or otherwise deal with us.
Our Privacy Officer — required under Quebec’s Law 25 and recommended under PIPEDA — is Amanjot Singh (Founder), reachable at hello@4uit.ca or 1-833-721-4848.
02. What we collect
- Contact details — name, email, phone, mailing address, when you fill in a form, request a quote or sign a contract.
- Business details — company name, role, business address.
- Communication records — emails, support tickets, call notes, scoping documents.
- Service-delivery information — IT inventory, network configuration, access credentials and system logs for managed clients, only as needed to deliver the service.
- Billing information — invoicing address and transaction history. Payment methods are handled by our payment processor; we do not store full card numbers.
Technical information: server logs (IP address, browser, device, pages visited) collected automatically to keep the site running and stop abuse; cookies as described in the Cookie Policy; and Google Analytics — only with your consent, with anonymised IP and no cross-site tracking.
We may also receive information from referrals, public business directories or partners — only with a legitimate business purpose and where the source has appropriate consent.
03. What we use it for
- Service delivery — the managed IT, security, cloud, web and repair work we contracted to do.
- Support and account management — answering enquiries, troubleshooting, billing, contracts, quarterly reviews.
- Marketing, only with consent — occasional service updates and industry notes; withdraw any time.
- Legal compliance — tax, regulatory and lawful-disclosure obligations.
- Site analytics, only with consent — understanding which pages get used so we can improve them.
04. Who we share with
We share information with carefully selected service providers who help run the business, each bound by a written agreement. The categories: website hosting and content delivery (Canada and the US), database and form storage (Canadian-region cloud where supported), transactional email, consent-based analytics, DNS and edge routing (no personal data stored), managed-security telemetry to our cybersecurity vendor’s analysts under a Data Processing Addendum, tenant administration under a separate engagement letter, and our own mailbox hosting.
A current named list of sub-processors and their jurisdictions is available on request — email hello@4uit.ca with the subject “Sub-processor list.”
Beyond processors: named business partners only with your explicit consent; disclosure where the law requires it (court orders, valid government requests, fraud or security investigations); and, in a merger or sale of assets, transfer under these same protections with notice to affected individuals first.
We do not sell, rent or trade personal information to third parties for their marketing. Period.
05. Where it lives
Primarily in Canadian-region cloud infrastructure. Where a provider processes data in another country — most often the United States — the transfer is covered by contractual safeguards (standard contractual clauses, data-processing agreements) and the relevant category above says so.
06. Security, retention and breach
We follow the security discipline we sell, because it would be embarrassing not to: TLS 1.2+ in transit and encryption at rest, MFA on all administrative accounts, EDR on every endpoint, immutable backup copies, network segmentation, a written security policy, joiner-mover-leaver process, quarterly access reviews and an incident runbook rehearsed annually.
Retention: only as long as the purpose requires or the law demands (tax records: seven years). After that, data is deleted or fully anonymised — backups included.
If a breach of safeguards creates a real risk of significant harm (PIPEDA’s threshold), we notify the Office of the Privacy Commissioner of Canada as soon as feasible, notify affected individuals directly in plain language, and notify any organisation that can reduce the harm, per s. 10.2. We work to a 72-hour discovery-to-notification discipline internally and keep breach records — including sub-threshold events — for 24 months. Quebec residents are notified through our Privacy Officer, with the Commission d’accès à l’information notified on Law 25’s timelines.
07. Your rights
- Access a copy of what we hold about you, and correct anything inaccurate.
- Withdraw consent for marketing or any optional processing, at any time.
- Delete your personal information, subject to legal retention obligations.
- Restrict or object to processing, particularly direct marketing.
- Data portability — your data in a structured, machine-readable format.
- No automated decisioning — under Law 25, no significant decision about you made solely by automation.
Email hello@4uit.ca with the subject “Privacy Request.” We respond within 30 days and may require ID verification first. Unsatisfied? Complain to the Office of the Privacy Commissioner of Canada, the Information and Privacy Commissioner of Ontario, or the Commission d’accès à l’information du Québec.
08. Children
Our services are designed for businesses, not children. We do not knowingly collect information from anyone under 13; if we discover we have, we delete it. Parents and guardians: contact us and it is removed immediately.
09. Quebec residents — Law 25
Quebec residents additionally have the right to know when automated decisions are made about them (with explanation), data portability, and specific consent for biometric data, geolocation and profiling. The designated Privacy Officer for Law 25 inquiries is reachable at hello@4uit.ca.
10. Changes and contact
This policy changes when our practices, processors or the law change; the effective date above moves with it. Material changes — a new processor, a new data category, a new use — are notified to customers by email and flagged on the homepage for at least 30 days before taking effect. This version supersedes all prior 4UIT privacy policies.
4UIT Inc. — Privacy Officer · 5-2000 Thurston Drive, Ottawa, ON K1G 4K7 · hello@4uit.ca (subject “Privacy Request”) · 1-833-721-4848 · Sales Mon–Fri 08:00–18:00 ET.