Legal

Privacy, in plain words

This page says what happens to information about you when you use this site. It is written to satisfy Canada's PIPEDA, but the reason it exists is simpler than that: you should be able to find out what we know about you without reading a contract.

In effect
Last changed
Applies to canaanagency.com and its subdomains

01Who we are

Canaan (كنعان) is a software agency in Mississauga, Ontario. The enterprise responsible for the information described here — the controller, in the language of the law — is Canaan Digital, carrying on business as Canaan Agency.

PIPEDA requires us to name someone accountable for how personal information is handled here, and to make that person reachable. That is our CEO, reachable at [email protected]. Everything in §10 goes to that address.

We are in Ontario, so this page is built on PIPEDA, the federal law. Ontario has no private-sector privacy statute of its own. We work with clients across Canada, and three provinces — Quebec, British Columbia and Alberta — have their own. Where one of those gives you more than PIPEDA does, we apply the stronger standard rather than asking which side of a provincial border you were standing on. It is one policy, set at the higher of the two, because the alternative is asking you to work out which rules you got.

02The short version

We collect what you type into the contact form, and nothing else that identifies you. We do not sell it, rent it, trade it, or hand it to advertisers. There are no advertising cookies and no cross-site tracking on this site. If you want your information gone, write to us and it will be gone.

The rest of this page is the same statement with the details attached, because "we take your privacy seriously" is not a fact anyone can check.

03What we collect

What you type into the contact form

The form on the Start page asks for four things: your name, your email address, a description of the project, and a rough date. You may also tag which kind of work is closest to yours. All of it is optional in the sense that you can leave the page instead — none of it is collected unless you choose to send it.

Please do not put confidential material, credentials, or anyone else's personal information into that box. A paragraph about the problem is what we ask for, and it is genuinely all we need to answer you.

Email you send us directly

If you write to [email protected], we hold that message and your address for as long as §8 describes.

Technical records created by visiting

Loading any web page leaves a trace on the server that served it. Our host processes your IP address, the page requested, the time, your browser's user-agent string, and the referring page, in order to deliver the site and to block attacks. We do not build these into profiles and we do not try to work out who you are from them. See §5 for what is and is not stored on your device.

What we do not collect

  • No accounts. There is nothing to sign up for, so there are no passwords and no profiles.
  • No payment information. Nothing is sold through this site.
  • No advertising identifiers. No pixels, no remarketing tags, no data brokers, no social-network trackers.
  • No sensitive information. We never ask for health, financial, biometric, or similar categories, and we ask you not to volunteer them.

04Why, and on what basis

PIPEDA requires us to identify why we collect personal information before or when we collect it, to collect no more than those purposes need, and to come back and ask if we ever want it for something else. Here is the whole list.

  • To answer you. We read every enquiry and reply within two business days, including the ones we say no to. This is why the form exists and it is the only reason we need what it asks for.
  • To decide whether to work together, and then to do the work. If an enquiry turns into a project, the same information becomes the start of the client file.
  • To keep the site up and turn attacks away. Technical records, handled by our host, for security and reliability.
  • To count visits. Aggregate, non-identifying measurement, described in §5.
  • To meet legal and accounting obligations. Where a law tells us to keep something, we keep it for as long as that law says and no longer.

We do not use your enquiry to market to you. Sending us a message does not put you on a list, because there is no list. If we ever start one, joining it will be a separate question with a separate answer, asked before the fact.

05Cookies and measurement

A cookie is a small file a site asks your browser to keep. Some are needed for a site to function or to stay safe; others exist to follow people around. We use the first kind and not the second.

What is stored on your device

__cf_bm

Set by Cloudflare, our host, to tell automated traffic from human traffic. Strictly necessary for the site's bot protection. Cloudflare encrypts its contents and does not use it to follow you between sites.

≤ 30 min
cf_clearance

Set by Cloudflare only if you are shown a security challenge, to record that you passed it so you are not asked again. Strictly necessary.

session
canaan.cookie.v1

Not a cookie — a single entry in your browser's local storage, set by us, recording that you dismissed the notice at the bottom of the page so it does not reappear on every visit. It contains a date and one word. It never leaves your browser.

180 days
Turnstile

On the contact form only. The spam check keeps a short-lived value in your browser's session storage while the page is open, to stop the same result being replayed. If it decides it needs to ask you something, Cloudflare may also set a first-party cookie recording that you passed. Both are strictly necessary to tell a person from a bot, and neither follows you to another site.

page / 1 hr

Cloudflare may set a small number of further strictly-necessary cookies if we turn on features that need them (load balancing, rate limiting, a waiting room). Their current list is published at Cloudflare's cookie reference.

How we count visits

We use Cloudflare Web Analytics, which measures page views and loading speed without setting a cookie, without reading anything already stored on your device, and without a fingerprint. Your IP address is used to work out a country and is then discarded at the nearest Cloudflare data centre rather than written to a log. The result is a count of pages and countries — not a record of you.

There is no Google Analytics on this site, and no other third-party analytics, advertising or social tracking of any kind. That is a deliberate choice, not an oversight.

Because nothing here identifies, locates or profiles you, and because nothing non-essential is stored on your device, we are not required to ask your permission — only to tell you, which is what the notice at the bottom of the page does. The spam check is part of that: keeping bots off a contact form is security, not measurement, which is why it runs without asking and why it is the only thing on the site that does. If any of that ever changes, the notice becomes a real choice with a refuse button that costs you nothing, defaulted to off, and this section gets rewritten before the change ships.

You can also refuse cookies in your browser's settings. Blocking the strictly-necessary ones above may mean Cloudflare challenges you more often; nothing else on the site will break.

06Who else sees it

We do not sell, rent, or trade personal information, and we never will. A short list of suppliers processes it on our behalf, under contract, only on our instructions, and only for what they are listed here to do. Handing information to a supplier does not hand over responsibility for it — we stay accountable for your information while they hold it.

  • Cloudflare, Inc. — hosting, security and the cookieless analytics in §5. Processes technical records described in §3.
  • Google LLC — receives and stores the messages you send us. Cloudflare Email Routing forwards each enquiry into a Gmail mailbox, and that is where it comes to rest. Google stores it in the United States; see §7.
  • Cloudflare Turnstile — the spam check on the contact form. It decides whether the form is being filled in by a person without asking you to identify bicycles, and it runs on Cloudflare's servers, not ours. See §5 for what it puts on your device.
  • Cloudflare Pages Functions and Cloudflare Workers — receive the submitted form, verify the Turnstile result, and pass the message on. They run on the same Cloudflare network that serves this page.
  • Cloudflare Email Routing — carries the enquiry from the form to our inbox. Same account, same network: no third-party mail service takes part in sending.

Beyond that, we disclose personal information only when a law or a court requires it, or when it is necessary to establish or defend a legal claim. If we are ever compelled to hand something over, we will tell you unless we are legally forbidden from doing so.

If the agency is ever sold or merged, personal information may transfer with it. You would be told before that happened, and this policy would continue to apply until you were told otherwise.

07Information outside Canada

Both suppliers in §6 are American companies. Cloudflare serves this site from a network spanning many countries, and Google stores the mail you send us on servers in the United States. So your information leaves Canada. You should hear that from us rather than work it out.

Under PIPEDA, giving information to a supplier to process on our behalf counts as a use of it rather than a disclosure, and it needs no separate consent so long as it is used only for what you gave it to us for. What it does need is that we stay responsible. We remain accountable for your information while a supplier holds it, and we are required to secure comparable protection by contract — which is what our arrangements with Cloudflare and Google do.

There is one thing no contract can fix, and it is the part worth reading. While your information is in the United States it is subject to American law. American courts, law enforcement and national security authorities may be able to reach it on terms Canadian law does not control, and potentially without our knowing. We cannot contract our way out of that and neither can anyone else. What we can do is keep the amount involved small: technical records not tied to your name, and whatever you chose to type into the form.

We assess a supplier before relying on it — what it would hold, where, under which country's law, and what it commits to contractually — and we keep that assessment. That is due diligence, not a filing. PIPEDA does not require the assessment to be lodged with anyone, and Ontario has no provincial privacy regulator to lodge it with.

08How long we keep it

  • Enquiries that go nowhere. Deleted within 24 months of our last exchange, unless you ask us to delete them sooner — in which case, sooner.
  • Enquiries that become projects. Kept for the length of the engagement, then for seven years afterwards, which is what Canadian tax and limitation rules require of business records.
  • Technical records. Retained by Cloudflare on their schedule, which is short and measured in days, not years.
  • Analytics. Aggregate counts only. There is nothing in them to attach to a person, and nothing to delete.

When a retention period ends, the information is deleted or anonymised. We do not keep things "just in case".

09How we protect it

The site is served over HTTPS and nothing else is accepted. Access to the inbox and to client files is limited to the people who need it, protected by multi-factor authentication. Suppliers are bound by contract to confidentiality and to security measures at least equal to our own.

No system is perfect, and a policy that claimed otherwise would be worth nothing. If a breach of our security safeguards creates a real risk of significant harm to you, PIPEDA requires us to report it to the Office of the Privacy Commissioner of Canada and to tell you, in both cases as soon as feasible. We also keep a record of every breach, including the ones we judge not to meet that threshold, for at least 24 months. The Commissioner can ask to see those records, and our reasoning about the ones we did not report is part of what they are for.

10Your rights

Write to [email protected] and we will answer within 30 days, at little or no cost. The law allows a further 30 days in narrow circumstances; if we ever needed them we would tell you inside the first 30, say why, and tell you that you can complain to the Commissioner about the delay. We may ask you to confirm who you are first, so that we are not handing your information to someone else. Any refusal will be in writing, with reasons and with the recourse available to you.

  • Access. Ask what personal information we hold about you and get a copy, together with an account of who we have disclosed it to.
  • Correction. Challenge the accuracy and completeness of what we hold and have it amended where you are right. If we passed the information to anyone else, we send them the correction too.
  • Withdrawal of consent. Change your mind at any time, on reasonable notice and subject to legal or contractual restrictions. It applies from the moment you tell us, not retroactively.
  • Deletion. Ask us to delete what we hold. Unless a law requires us to keep it — and if one does, we will tell you which and for how long — it goes.
  • An explanation. Ask why we hold something and what it is used for, and get an answer in plain language rather than in the terms of this page.

Two things you may have read about elsewhere — data portability and de-indexing — are not rights under PIPEDA. They come from Quebec's Law 25. Whether that law also reaches an Ontario business with clients in Quebec is a question without a settled answer, and we are not going to make you depend on how it resolves.

So: ask for a copy of what you sent us in a format you can use and you will get it. Ask us to stop publishing something about you and we will. We are committing to both here, in writing, which is the part you can hold us to whichever law turns out to apply.

11Complaints

Tell us first — [email protected] — because most of what goes wrong is something we can fix directly.

If our answer does not satisfy you, you can complain to the Office of the Privacy Commissioner of Canada, which oversees PIPEDA, at priv.gc.ca. Ontario has no separate private-sector privacy regulator, so for a business like ours the federal Commissioner is the office. Coming to us first is not a condition of going there.

12Children

This site is aimed at businesses and is not directed at children. We do not knowingly collect personal information from anyone under 13. PIPEDA sets no age, but the Commissioner's position is that a child under 13 cannot meaningfully consent for themselves, so that is the line we use. If you believe a child has sent us something, write to [email protected] and we will delete it.

13Automated decisions and profiling

We do not make decisions about you by automated means, and we do not profile you. Every enquiry is read by a person, and the answer is written by one. PIPEDA would not require us to tell you if that changed. We would tell you anyway, at the time of the decision, and let you put your case to a person.

14Changes to this page

When this policy changes, the date at the top changes with it. If a change materially affects what we do with your information, we will say so on the site rather than rely on you re-reading this page, and where the law requires fresh consent we will ask for it before the change takes effect.

15Contact

Privacy matters — [email protected], attention the CEO.

Everything else — [email protected].