Privacy Policy
Canadian Aurora Cloud Inc. (“CanAurora”, “we”, “our”, “us”)
Effective Date: June 1, 2026
1. Overview
Canadian Aurora Cloud Inc. (“CanAurora”) is a Canadian corporation incorporated in British Columbia, operating from Trail, British Columbia, Canada. We are committed to protecting the privacy and personal information of our clients, website visitors, and prospective customers.
This Privacy Policy describes how we collect, use, disclose, and safeguard personal information in accordance with Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), the Privacy Act, and applicable British Columbia privacy law.
By visiting https://canaurora.com or engaging our services, you consent to the practices described in this policy.
2. Information We Collect
Information you provide directly:
- Name and job title
- Business and personal email address
- Phone number
- Company name and address
- Details about the IT service you are enquiring about
- Messages and other content you submit via our contact form or email
- Payment and billing information when you engage our services (processed by PCI-DSS compliant third-party processors)
Information collected automatically:
- IP address and approximate geographic location
- Browser type, version, and operating system
- Pages visited, time spent, and referring URLs
- Device identifiers
- Cookies and similar tracking technologies (see Section 7)
We do not collect sensitive personal information such as social insurance numbers, health information, or financial account credentials unless required for a specific contracted service, and only with your explicit consent.
3. How We Use Your Information
We use personal information only for the purposes for which it was collected or for compatible purposes, including:
- Responding to enquiries submitted through our website or by email
- Providing, managing, and improving our IT and cloud services
- Preparing and delivering proposals, contracts, and invoices
- Providing technical support and managed services
- Sending service-related communications (not marketing unless you opt in)
- Complying with legal and regulatory obligations
- Detecting and preventing fraud, security incidents, and abuse
- Analysing website traffic to improve usability and performance
- Sending marketing communications with your express consent (you may withdraw at any time)
We rely on the following legal bases: contractual necessity (to perform services you request), legitimate interests (to operate our business and website securely), legal obligation (compliance with applicable law), and consent (for marketing communications and optional cookies).
4. Disclosure of Your Information
We do not sell, rent, or trade personal information. We may share information with:
- Service providers acting on our behalf (cloud infrastructure providers, payment processors, email delivery services) under written data-processing agreements
- Professional advisors (legal, accounting) bound by confidentiality obligations
- Government authorities or law enforcement where required by applicable Canadian law or valid legal process
- A successor organisation in the event of a merger, acquisition, or sale of assets, provided the successor honours this policy
All third-party service providers are required to handle personal information in a manner consistent with this policy and applicable privacy law.
5. Retention of Information
We retain personal information only as long as necessary to fulfil the purposes for which it was collected, to maintain business records, and to comply with applicable legal, tax, and regulatory requirements.
- Website enquiry records: up to 24 months from the date of last contact
- Client project records: up to 7 years from project completion (consistent with Canadian accounting and tax obligations)
- Automatically collected website data: up to 26 months (Google Analytics default)
- Marketing consent records: until consent is withdrawn plus 2 years
When information is no longer required it is securely deleted or anonymised.
6. Security
CanAurora implements industry-standard technical, administrative, and physical safeguards to protect personal information against unauthorised access, disclosure, alteration, and destruction. Measures include:
- Encryption in transit (TLS 1.2+) and at rest (AES-256)
- Access controls based on the principle of least privilege
- Regular security assessments and vulnerability scanning
- Staff training on data handling and privacy obligations
- Incident response procedures aligned with PIPEDA breach notification requirements
In the event of a privacy breach that poses a real risk of significant harm, we will notify the Office of the Privacy Commissioner of Canada and affected individuals as required under PIPEDA.
8. Your Privacy Rights
Under PIPEDA and applicable provincial law, you have the right to:
- Know what personal information we hold about you
- Request access to your personal information
- Request correction of inaccurate or incomplete information
- Withdraw consent to the collection or use of your information (subject to legal or contractual limitations)
- Challenge our compliance with applicable privacy law
To exercise any of these rights, please contact our Privacy Officer at info@canaurora.com. We will respond within 30 days. If you are not satisfied with our response you may file a complaint with the Office of the Privacy Commissioner of Canada.
9. Children's Privacy
Our services are directed to businesses and professionals. We do not knowingly collect personal information from individuals under the age of 18. If you believe we have inadvertently collected information from a minor, please contact us and we will delete it promptly.
10. Third-Party Links
Our website may contain links to third-party websites. We are not responsible for the privacy practices of those sites and encourage you to review their privacy policies. This policy applies only to information collected by CanAurora.
11. Cross-Border Data Transfers
We are a Canadian company and prefer to keep data within Canada. Some third-party service providers may process data in other jurisdictions. Where such transfers occur, we ensure that appropriate contractual protections are in place and that the receiving jurisdiction provides a comparable level of protection to Canadian privacy law.
Our cloud infrastructure primarily uses Canadian AWS and Azure regions (ca-central-1, Canada East) to support data sovereignty commitments.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. The “Effective Date” at the top of this page indicates when the policy was last revised. We encourage you to review this policy periodically.
For material changes we will provide notice via email (to clients on record) or a prominent notice on our website.
13. Contact Us
Questions, access requests, or privacy complaints should be directed to:
Privacy Officer
Canadian Aurora Cloud Inc. (“CanAurora”)
Trail, British Columbia, Canada
info@canaurora.com© 2026 Canadian Aurora Cloud Inc.. All rights reserved.
