Privacy Policy
Effective Date: March 24, 2025
1. Introduction
Data Evangelist Central Inc. (“we,” “our,” or “us”) is a technology consulting company based in Langley, British Columbia, Canada. We offer specialized services in data analytics, data engineering, software development, web development, and cloud solutions. Serving clients across the globe, we are committed to maintaining the confidentiality, integrity, and security of the data we handle. This Privacy Policy outlines how we collect, use, store, and protect personal and business-related information in accordance with applicable privacy regulations, including Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) and, where applicable, the General Data Protection Regulation (GDPR).
2. Scope of the Policy
This Privacy Policy applies to all personal and business data that we collect or process while delivering services to our clients. It governs data collected through our applications (including but not limited to timesheet systems), cloud platforms, websites, and any direct communication channels. The policy also applies to data received from client systems for analysis, transformation, or backend development.
3. Types of Data We Collect
The types of data we handle depend on the nature of the services provided. This typically includes personally identifiable information such as names, job titles, email addresses, and login credentials used within web and mobile applications. For solutions involving workforce and financial management, we may process financial data such as practitioner payments, payer reimbursements, and logged work hours.
We also collect system usage data, including IP addresses, timestamps, session logs, and interactions within applications, to support performance tracking and platform security. In the case of backend management for custom applications, we process structured business data provided by the client, such as treatment schedules, practitioner availability, and session-level records. Any support tickets, communication logs, or feedback forms submitted during a project may also contain additional information relevant to service delivery.
4. How We Use Your Information
We use the data collected to deliver and maintain the solutions contracted by our clients. This includes developing and supporting custom applications, analyzing workforce productivity, and generating dashboards and reports for operational and strategic insights. The information enables us to provide tailored analytics, improve software performance, and respond to user feedback or support requests.
Internally, we use information to manage project workflows, billing, client communication, and resource planning. System usage data helps us enhance application security, detect unusual activity, and ensure compliance with contractual obligations. In some cases, aggregated data may be used for product improvement or internal research, always in a non-identifiable format unless explicitly authorized by the client.
5. Data Sharing and Disclosure
We do not sell or rent any personal data. Information may be shared with trusted third-party service providers—such as Microsoft Azure—only to the extent necessary to support cloud hosting, storage, or infrastructure operations. These providers are contractually obligated to maintain strict confidentiality, security, and compliance with relevant data protection laws.
Within our organization, access to data is strictly limited to authorized personnel who require it to fulfill their job functions. We may disclose data if legally required by governmental or regulatory authorities, or as part of a corporate transaction such as a merger or acquisition. In all other cases, data will only be shared with external parties if explicit written consent is provided by the client.
6. Data Storage and Transfers
All data is stored in secure environments, primarily within Microsoft Azure data centers located in Canada and other jurisdictions that comply with industry-standard protections. If data must be transferred across borders, we implement safeguards such as Standard Contractual Clauses or other lawful mechanisms to ensure that your data remains protected and handled in accordance with applicable regulations.
Clients are informed if their data will be stored or accessed outside of Canada, as required by PIPEDA. Regardless of geographic location, we enforce consistent security and privacy standards across all environments.
7. Data Security
We are committed to protecting data through a combination of technical, administrative, and physical safeguards. This includes encryption of data both at rest and in transit, role-based access controls, secure API handling, and multi-factor authentication for system access.
Our internal team is trained in best practices for data handling and confidentiality. We regularly monitor systems for vulnerabilities, perform backups, and follow a structured incident response process in the event of any data breach. Our Azure-based infrastructure benefits from high-availability features and compliance with multiple global certifications (e.g., ISO 27001, SOC 2).
8. Data Retention
We retain personal and business data only for as long as it is needed to fulfill the purpose for which it was collected or to meet legal, regulatory, or contractual obligations. For example, client data used in project delivery is stored for the duration of the engagement and securely deleted or returned upon completion, as agreed.
Financial records and transactional logs are retained according to applicable tax and audit requirements (e.g., 7 years in Canada). Usage data and logs may be kept temporarily for troubleshooting or security monitoring, after which they are anonymized or deleted.
9. Your Rights
Depending on your location and applicable laws, you may have rights including: access to your personal data, correction of inaccurate information, deletion of data no longer needed, restriction or objection to processing, and data portability.
If you wish to exercise any of these rights, you may contact us directly. We will verify your request and respond within the timeframes set by applicable privacy laws. Where legal limitations apply, we will explain the basis for any refusal or delay.
10. Compliance
Data Evangelist Central Inc. complies with PIPEDA and, where applicable, international privacy laws such as GDPR. We follow the principles of accountability, transparency, consent, limited use, and robust safeguards. Regular reviews are conducted to ensure our data practices remain aligned with legal requirements and industry best practices.
11. Changes to This Policy
We may update this Privacy Policy as needed to reflect changes in legal requirements, services, or internal practices. When we do, the "Effective Date" at the top of this page will be updated. Clients will be notified of material changes through email or platform notices, and continued use of our services indicates acceptance of the updated policy.
12. Contact Us
For questions about this policy or your data, please contact us:
Data Evangelist Central Inc.
8716 Walnut Grove Drive, Unit 32
Langley City, BC V1M 2K2