Privacy Policy
How Axiah Lab Inc. collects, uses, discloses, and safeguards your personal information.
Contents
- Introduction and Scope
- Information We Collect
- How We Use Your Information
- Legal Bases for Processing
- Disclosure of Your Information
- Data Retention
- Data Security
- Your Privacy Rights
- Cookies and Tracking
- Children's Privacy
- International Data Transfers
- Third-Party Services
- Do Not Track
- Data Breach Notification
- Changes
- Contact Us
1. Introduction and Scope
This Privacy Policy describes how Axiah Lab Inc., a Canadian corporation doing business as Axiah Lab, collects, uses, stores, shares, and protects personal information obtained through our website at www.axiahlab.lat, through any related digital properties, through our professional services, and through any other interactions you may have with our organization. This policy applies to all visitors, users, clients, prospective clients, vendors, and job applicants who interact with Axiah Lab in any capacity.
Axiah Lab is a computer systems design and related services firm specializing in enterprise systems architecture, cloud infrastructure engineering, systems integration, cybersecurity, and managed IT operations. Our laboratory is located at 39 135e Avenue, Saint-Hippolyte, Quebec J8A 2J2, Canada. Throughout this document, references to Axiah Lab, we, us, and our refer to Axiah Lab Inc. and its affiliated operating entities. The website was developed and is maintained by the Axiah Lab research team, who designed this site with data privacy and security as foundational requirements embedded in every layer of our platform.
By accessing our website or using our services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree, discontinue use immediately. We reserve the right to modify this policy, effective upon posting. Continued use after changes constitutes acceptance. This Privacy Policy complies with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), Quebec's Act respecting the protection of personal information in the private sector (Law 25), the California Consumer Privacy Act, and applicable GDPR provisions. We are committed to transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity, and confidentiality.
2. Information We Collect
2.1 Information You Provide Directly
We collect information you voluntarily provide when interacting with our website, communicating with our team, or engaging our services. This includes contact form submissions, email correspondence, phone calls, service inquiry forms, and client onboarding documentation. Categories include your full name, business email, telephone number, job title, organization name, physical business address, billing address, payment information, tax identification numbers including GST/QST numbers for Quebec-based entities, and any other information you include in messages or service requests.
When you engage Axiah Lab for professional services, we may also collect additional information necessary for contractual obligations including system access credentials under strict security protocols, network configuration data, infrastructure documentation, architectural diagrams, and other technical information. We treat all client-provided technical information with the highest level of confidentiality and security, employing the same rigorous safeguards we apply to our own most sensitive research data.
2.2 Information Collected Automatically
When visiting our website, information is collected automatically including your IP address, browser type and version, operating system, device type, screen resolution, referring and exit pages, timestamps, pages viewed, time spent, clickstream data, and form interaction behavior. We use server logs, web beacons, and tracking pixels. Server log data is typically retained for thirty days before being purged.
2.3 Information from Third Parties
We may receive information from third-party sources including business intelligence platforms, public registries, professional networking platforms, and referral partners. We treat all third-party information in accordance with this Privacy Policy and applicable law.
3. How We Use Your Information
We use the information we collect for specific business purposes that are necessary to provide our services, operate our business, and comply with legal obligations. Each category of use is described below with the corresponding business purpose and legal justification for the processing activity.
We use your information to provide, maintain, and improve our services including the delivery of contracted computer systems design, architecture consulting, cloud infrastructure engineering, systems integration, cybersecurity assessment, and managed IT operations services. This includes using your contact information to communicate about project status, deliverables, milestones, change requests, risk assessments, and service-related notifications throughout the entire engagement lifecycle from initial scoping through final delivery and ongoing operational support.
We use your information to respond to inquiries submitted through our website, by email, or by telephone. When you request information about our services, pricing, technical capabilities, or availability, we process your contact details and the content of your inquiry to provide a responsive and personalized reply tailored to your specific situation and technical requirements. We may follow up on inquiries that do not result in an immediate engagement to determine whether your needs have changed, whether additional information would be helpful to your evaluation process, or whether new developments in our service offerings might be relevant to the challenges you previously described.
We use your information to process payments, manage billing and invoicing, maintain financial records, and fulfill our accounting obligations. This includes the use of payment information for transaction processing, invoice generation, payment reconciliation, collection activities where necessary and in compliance with applicable Canadian debt collection laws, and financial reporting and auditing purposes required by applicable law and professional accounting standards.
We use your information to send marketing communications about our services, industry insights, technical research papers, event invitations, and company updates where you have provided consent or where otherwise permitted by applicable law. You may opt out of marketing communications at any time by using the unsubscribe link included in every marketing email or by contacting us directly at our published contact address. We use your information to analyze website usage patterns, improve user experience, optimize website performance, and develop aggregate statistical insights about our audience. We use your information to protect the security and integrity of our systems, networks, and data, including monitoring for unauthorized access attempts, investigating security incidents, detecting and preventing fraud, enforcing our Terms of Service, and complying with legal obligations including responding to lawful requests from law enforcement and regulatory authorities.
4. Legal Bases for Processing
For jurisdictions requiring specified legal bases: Contractual Necessity — processing necessary for contract performance. Legitimate Interests — processing for our legitimate business interests including operating our business, customer support, fraud protection, analytics, and B2B marketing. Consent — where required, obtained before processing for specific purposes, with right to withdraw. Under Quebec Law 25 and PIPEDA, we rely on consent as the primary basis for collection, use, and disclosure of personal information, obtained at or before the time of collection. Legal Obligation — processing to comply with applicable laws. Vital Interests — in rare circumstances, to protect vital interests.
5. Disclosure of Your Information
We do not sell your personal information. We may share information with service providers bound by contractual obligations including cloud hosting, payment processing, CRM, email, analytics, and professional advisors. We may disclose as required by law or legal process. We may disclose in connection with a corporate transaction. We may disclose aggregated, de-identified information for any lawful purpose. Under Quebec Law 25, we ensure that any third party to whom we communicate personal information maintains appropriate safeguards and complies with applicable legal requirements.
6. Data Retention
We retain personal information for no longer than necessary. Contact form submissions are retained for two years. Client engagement records are retained for the relationship duration plus seven years. Financial records are retained for seven years per Canadian tax law requirements. Server logs are retained for thirty days. Anonymized data may be retained indefinitely.
7. Data Security
We implement and maintain comprehensive administrative, technical, and physical safeguards designed to protect the confidentiality, integrity, and availability of your personal information. Our security program is aligned with industry standards and is regularly reviewed and updated to address evolving threats and vulnerabilities in the technology landscape.
Our technical safeguards include encryption of data in transit using TLS 1.3, encryption of data at rest using AES-256, multi-factor authentication for all administrative access, role-based access controls with the principle of least privilege, automated vulnerability scanning and penetration testing, intrusion detection and prevention systems, endpoint detection and response capabilities across all managed devices, security information and event management with real-time alerting, and regular third-party security assessments and audits of our infrastructure and applications.
Our administrative safeguards include a documented information security policy reviewed and updated annually, mandatory security awareness training for all personnel, background checks for employees and contractors with access to sensitive systems, formal incident response procedures with defined escalation paths and communication protocols, a vendor risk management program with security assessments for all third-party service providers, business continuity and disaster recovery plans tested at least annually, and data classification and handling procedures that define protection requirements based on information sensitivity levels.
While we implement robust security measures, no method of electronic transmission or storage is perfectly secure, and we cannot guarantee absolute security. In the event of a data breach that affects your personal information, we will notify you and relevant authorities per applicable legal requirements including PIPEDA and Quebec Law 25 breach notification obligations and the Commission d'acces a l'information du Quebec reporting framework.
8. Your Privacy Rights
Depending on your jurisdiction, you may have rights including access and data portability, correction, deletion under certain circumstances, restriction of processing, opt-out of sale or sharing (Axiah Lab does not sell personal information), and non-discrimination. Canadian residents have additional rights under PIPEDA. Quebec residents have enhanced rights under Law 25 including the right to data portability, the right to be informed of automated decision-making, and the right to request cessation of dissemination. To exercise rights, submit a verifiable request using contact information in Section 16. We acknowledge within ten business days and respond within the time required by applicable law. Identity verification will be required.
9. Cookies and Tracking Technologies
Our website uses cookies and similar technologies. Essential cookies enable core functionality without requiring consent. Analytics cookies help understand interaction patterns anonymously. You may configure browser settings to manage cookies. Under Quebec Law 25, we obtain consent for non-essential cookies through our cookie preference manager, accessible on first visit to our website.
10. Children's Privacy
Our website and services are directed at business professionals and not intended for individuals under eighteen. We do not knowingly collect personal information from children under fourteen, the age of consent in Quebec under Law 25.
11. International Data Transfers
Axiah Lab is headquartered in Quebec, Canada. Data processing may occur in Canada, the United States, and other jurisdictions. We implement appropriate safeguards for cross-border transfers as required by PIPEDA and Quebec Law 25, including conducting privacy impact assessments for transfers outside Quebec. By using our services, you acknowledge information may be subject to the laws of jurisdictions where processing occurs.
12. Third-Party Services
Our website may contain links to third-party websites. We are not responsible for third-party privacy practices. When engaging service providers, we conduct due diligence and enter written agreements with data protection obligations.
13. Do Not Track Signals
Our website does not currently respond to Do Not Track signals. Manage tracking preferences through our cookie preference manager or browser controls.
14. Data Breach Notification
In the event of a security incident, we will execute incident response procedures and notify affected individuals and relevant authorities per applicable legal requirements including PIPEDA and Quebec Law 25 mandatory breach notification obligations to the Commission d'acces a l'information du Quebec.
15. Changes
We reserve the right to update this policy. Material changes will be posted with a new Last Updated date and additional notice where required by law.
16. Contact Us About Privacy
For questions, concerns, or to exercise privacy rights:
AXIAH LAB INC.
Attn: Privacy Officer
39 135e Avenue
Saint-Hippolyte, QC J8A 2J2
Canada
Email: help@axiahlab.lat
Phone: +1 (484) 759-9750
Website: www.axiahlab.lat
You may also contact the Commission d'acces a l'information du Quebec or the Office of the Privacy Commissioner of Canada. The Axiah Lab research team developed this website with data privacy as a foundational design principle.