Privacy Policy

Version 1.0  |  Effective 16 September 2026

Digital Fractal Technologies Inc (“Digital Fractal”, “we”, “us”, “our”) builds websites, backend systems, and mobile applications for our clients. This policy explains what personal information we collect, why we collect it, who we share it with, and the choices you have. We have written it in plain language on purpose. If anything here is unclear, write to us and we will explain it.

1. Two different roles, and why the distinction matters

We handle personal information in two quite different capacities, and your rights differ depending on which applies.

As the organization responsible for the information. When you visit our website, contact us, ask for a proposal, subscribe to something we send, apply for a job, or become our client, we decide why and how your information is used. This policy governs that information, and you can exercise all the rights described in section 11 directly with us.

As a service provider to our clients. When we build or maintain a system for a client, that system may contain personal information about the client’s own customers, staff, or users. We do not own that information and we do not decide what it is used for. We act on the client’s documented instructions under our contract with them. If you are an end user of a product we built for someone else, the organization you dealt with is responsible for your information, and you should contact them. If you contact us instead, we will pass your request to them and tell you we have done so. Section 5 describes how we limit our access to this category of information.

2. Information we collect

Information you give us directly. Your name, business name, job title, email address, telephone number, and postal address. The content of enquiries, proposal requests, project requirements, and correspondence. Billing and payment details where you are a client. If you apply for a role with us, your CV and anything else you choose to send.

Information collected automatically when you visit our website. Your IP address, browser type and version, device type, operating system, referring page, the pages you view, and the dates and times of your visits. This is collected through cookies and similar technologies, described in section 12.

Information from other sources. Publicly available business information, referrals from existing clients or partners, and business contact details from professional networks where you have made them available. We do not purchase personal information from data brokers or list vendors.

We do not deliberately collect sensitive personal information such as health data, biometric data, government identification numbers, or financial account credentials through our website. Please do not send these to us by email or web form. If a project requires handling information of this kind, it is governed by a separate written agreement with the client.

3. Why we use your information, and on what basis

We use personal information to respond to your enquiries and provide the information you ask for; to prepare proposals and estimates; to deliver, support, and maintain the services our clients engage us for; to issue invoices and manage payment; to send occasional, targeted communications about our services to people who have asked to receive them or with whom we have an existing business relationship; to understand how our website is used so we can improve it; to protect our systems and our clients’ systems against fraud, abuse, and security threats; to recruit and assess candidates; and to meet our legal, tax, and regulatory obligations.

Under Canadian privacy law we rely on your consent, which may be express or implied depending on the sensitivity of the information and the reasonableness of your expectations. Where the law permits us to collect, use, or disclose information without consent, such as to investigate a breach of an agreement or to comply with a legal requirement, we rely on those provisions. You may withdraw consent at any time, subject to legal and contractual restrictions and reasonable notice, by contacting our Privacy Officer. Withdrawing consent may mean we can no longer provide a service to you.

4. We do not sell your information

We do not sell personal information. We do not rent, trade, or otherwise disclose personal information to third parties for their own marketing purposes. We do not share personal information for cross-context behavioural advertising.

5. Client project data

Our normal practice is to develop and test using masked, anonymized, or synthetic data rather than live records. Where a development or testing environment is seeded from production, the data is de-identified before our developers work with it.

There are limited circumstances in which our personnel may need access to live client data, principally to diagnose a production defect that cannot be reproduced with test data, to carry out a data migration, or to provide urgent operational support. When that happens, access is requested and approved rather than standing, granted only to the individuals who need it, limited to the narrowest scope and shortest period that will resolve the issue, logged, and withdrawn when the work is complete. Data is not copied to local machines or personal accounts, and is not retained after the issue is closed.

All such access is governed by our written agreement with the client, including any data processing terms it contains. Where a client’s own regulatory obligations impose stricter requirements, those requirements govern.

6. Marketing communications

We send commercial messages rarely, and only to people who have consented or with whom we have an existing business relationship within the meaning of Canada’s Anti-Spam Legislation. Our campaigns are small and targeted rather than broadcast. We do not operate a general mailing list.

Every commercial email we send identifies Digital Fractal Technologies Inc, gives our mailing address, and contains a working unsubscribe link that we action promptly. You may also unsubscribe at any time by writing to contact@digitalfractal.com. We honour unsubscribe requests regardless of how they reach us.

7. Telephone and text messaging

Our business telephone number accepts both calls and text messages. Conversations by text begin with you: we reply to messages you send us, or we text you at a number you have given us and asked us to use. We do not run SMS marketing campaigns and we do not text anyone who has not contacted us first.

When you text us, we collect your mobile number, the content of the exchange, and the date and time of each message. We use it to answer your question and to keep a record of our correspondence.

No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. All other categories of data sharing described in this policy exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.

Message frequency varies and depends on your own correspondence with us. Message and data rates may apply, as set by your mobile carrier. Reply STOP to any message to stop receiving texts, or HELP for assistance. Mobile carriers are not liable for delayed or undelivered messages.

Calls to and from our business number may be answered or triaged by an automated assistant, as described in section 8.

8. Artificial intelligence and automated processing

We use artificial intelligence in two ways, and we think you should know about both.

In how we run our own business. We use AI-assisted tools in software development, and an automated assistant may answer or triage calls and messages to our business number. Where an automated assistant handles your call or message, the content of that interaction is processed by the provider of that service on our behalf. A person reviews the output of AI-assisted work before it is delivered or acted upon. We do not use AI to make decisions that produce legal or similarly significant effects about you without human involvement.

In what we build for clients. Some of the systems we develop include AI or machine learning features. Where we build such a system, the client decides what it does and remains responsible for it. We advise clients on transparency, human oversight, and assessing the impact of automated decisions, and we implement the controls agreed in the project.

We do not use personal information that you provide to us, or client project data, to train publicly available or third-party AI models, and we configure the AI tools we use so that our inputs are not used for model training where that option is offered.

9. Who we share information with

We share personal information only as described here.

Service providers. We use third parties to run our business, including cloud hosting and infrastructure providers (Amazon Web Services, Microsoft Azure, and Google Cloud Platform), customer relationship and marketing platforms (HubSpot), website analytics (Google Analytics), telecommunications providers for our telephone and messaging services, and providers of email, file storage, and collaboration tools. Each is bound by contract to use the information only to provide the service to us, to protect it, and not to use it for their own purposes.

Our clients. Where we hold information as a service provider, we return or disclose it to the client whose information it is, as our contract requires.

Professional advisers. Lawyers, accountants, auditors, and insurers, where they need the information to advise us and are bound by professional duties of confidentiality.

Legal and protective disclosures. Where required by law, court order, or a lawful request from a public authority; where necessary to establish, exercise, or defend legal claims; to investigate suspected fraud or a breach of our agreements; or to protect the safety of any person.

Business transactions. If we are involved in a merger, acquisition, financing, or sale of assets, information may be disclosed to the parties involved, subject to confidentiality protections. If such a transaction completes, we will notify affected individuals where the law requires it.

10. Where your information is held

We host data in Canada wherever the project and the provider allow it, and we treat Canadian residency as the default for client project environments unless a client specifies otherwise.

Some of the services we rely on operate outside Canada, principally in the United States. Where information is stored or processed in another country, it is subject to the laws of that country, and courts, law enforcement, and regulatory authorities there may in certain circumstances be entitled to access it. We use providers that commit contractually to protecting the information and we apply safeguards appropriate to its sensitivity. You may ask our Privacy Officer where a particular category of information is held.

11. Your rights and how to exercise them

Subject to the exceptions in applicable law, you may ask us to confirm whether we hold personal information about you and to give you access to it; to correct information that is inaccurate or incomplete; to delete information we no longer need; to tell you how we have used it and who we have disclosed it to; to withdraw your consent; and to stop sending you commercial messages.

If you are a resident of a United States state with comprehensive privacy legislation, you may also have the right to confirm whether we process your personal data, to obtain a copy in a portable format, to correct or delete it, to opt out of sale or targeted advertising (we do neither), and not to be discriminated against for exercising these rights. Where an appeal process is required in your state and we decline your request, we will tell you how to appeal.

Write to our Privacy Officer using the details in section 16. We will acknowledge your request promptly and respond within thirty days, or tell you why we need longer. We may ask you to verify your identity before we act, and we will not charge you for a reasonable request. If you are dissatisfied with our response, you may complain to the Office of the Privacy Commissioner of Canada, or to the Office of the Information and Privacy Commissioner of Alberta.

12. Cookies and analytics

Our website uses cookies that are necessary for it to function, and analytics cookies that help us understand how visitors use the site. Analytics data is aggregated and we do not use it to identify individuals. Where our marketing platform sets a cookie to recognize a returning visitor who has previously contacted us, it is used only to make our own follow-up more relevant, never to build a profile for sale or to serve advertising elsewhere.

Most browsers let you refuse or delete cookies. Blocking necessary cookies may stop parts of the site from working. Our website does not respond to Do Not Track signals, as there is no common standard for how to interpret them.

13. How we protect your information

We maintain administrative, technical, and physical safeguards proportionate to the sensitivity of the information we hold. These include access granted on a need-to-know basis and reviewed periodically; multi-factor authentication on business systems; encryption of data in transit and, where supported, at rest; separation of development, testing, and production environments; logging and monitoring of access to systems holding personal information; formal change control for systems we operate; confidentiality obligations and security training for our personnel; and assessment of the security practices of the providers we rely on.

We are working towards certification of our information security management system against ISO/IEC 27001. We will update this section when that work concludes.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. What we can promise is that we take it seriously, that we test our controls, and that we tell you promptly if something goes wrong.

14. If there is a breach

We maintain a documented procedure for responding to security incidents. If a breach of security safeguards creates a real risk of significant harm to an individual, we will report it to the Office of the Privacy Commissioner of Canada and notify affected individuals as soon as feasible, and we will keep records of breaches as the law requires. Where the affected information belongs to a client, we will notify that client without undue delay so they can meet their own obligations.

15. How long we keep information

We keep personal information only as long as we need it for the purpose we collected it, or as long as the law requires. Enquiries that do not become projects are kept for up to two years, client and project records for seven years after the engagement ends to meet tax and limitation-period requirements, and unsuccessful job applications for one year unless you ask us to keep them longer. When information is no longer needed, we delete it or irreversibly anonymize it.

One honest caveat about deletion. Our systems are backed up, and a backup is a point-in-time copy that cannot be edited selectively. When we delete your information from our live systems, copies may persist in encrypted backups until those backups age out on their normal rotation, after which they are overwritten. Information in backups is not used for any operational purpose and is restored only for disaster recovery. If a restore were to reinstate information you had asked us to delete, we would delete it again.

16. Contact us

Our Privacy Officer is responsible for our compliance with this policy and can be reached at:

Privacy Officer
Digital Fractal Technologies Inc
Unit 102, 2207 90B St. SW
Edmonton, Alberta T6X 1V8
Canada
contact@digitalfractal.com
780-669-0944

17. Children

Our website and services are directed at businesses, not children. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided us with personal information, contact our Privacy Officer and we will delete it.

18. Changes to this policy

We review this policy at least annually and update it when our practices change. The version number and effective date at the top of the page tell you which version you are reading. Where a change materially affects how we handle information we already hold, we will give notice by a prominent notice on our website or by contacting you directly.