Legal
Privacy Policy
How personal information reaches Skyfal Security, what we do with it, how long we keep it, and what you can ask us to do about it.
Review required before launch
This policy is a starting template. It must be reviewed by the business owner and, where required, by legal counsel before this site goes live.
Every statement below describes an intended practice. Any statement that does not match what the business actually does must be corrected before publication. A privacy policy that overstates a safeguard is worse than one that says less.
Scope and legal framework
This policy applies to this website and to the commercial services provided by SKYFAL SECURITY SYSTEMS INCORPORATED, operating from Ontario, Canada.
Our work is business to business. The personal information we handle is almost entirely workplace contact information belonging to people acting in a professional capacity: facility managers, security managers, IT leads, procurement staff and technicians. We do not run a consumer service and we do not build customer profiles.
We handle personal information in a manner consistent with the Personal Information Protection and Electronic Documents Act (PIPEDA) and its ten fair information principles. Where a provincial statute or a contractual obligation to a public sector client imposes a stricter requirement, the stricter requirement applies.
Last updated: (date to be entered at publication).
What we collect
Four categories, and nothing beyond what the work requires.
- Contact details you give us. Name, organization, job title, email address, phone number, site location and the content of your message, submitted through an enquiry or service request form or sent to us by email.
- Service records. Notes describing reported faults, diagnostic findings, work performed, parts used, testing results, quotations, invoices and the correspondence attached to a job.
- Site visit records. Attendance dates and times, the technician assigned, site contact names, access and escort arrangements, and any sign-in or permit records a facility requires of visiting contractors.
- Basic server logs. The web server records requests to this site, including IP address, date and time, page requested, referring page and browser user agent. These are technical records generated automatically by the hosting infrastructure.
Why we collect it, and how it is used
We collect personal information for identified purposes, and we limit collection to those purposes.
Consent and lawful basis. In most cases consent is express and obvious: you send us your contact details because you want a reply. Where you provide information in the course of a service engagement, consent is implied by the purpose for which it was given and by the agreement between our organizations. Under PIPEDA, business contact information collected and used solely for the purpose of communicating with a person in relation to their employment or profession is treated differently from other personal information, and much of what we hold falls into that category.
You can withdraw consent to further contact at any time, subject to legal and contractual record keeping. Withdrawing consent may mean we can no longer provide a service, and we will say so plainly if that is the case.
We do not use your information for automated decision making, and we do not send marketing email to people who have not asked for it.
- To respond to enquiries. Answering a question, scoping a request, arranging a call or a site visit.
- To deliver service. Diagnosing a fault, performing repair or programming work, ordering parts, scheduling attendance and verifying that a system works after the work is finished.
- To keep a technical history. A record of what was found and what was done, so a recurring fault is recognized as recurring rather than diagnosed from scratch each time.
- To administer the business. Quotations, service agreements, invoicing, accounting and insurance.
- To keep the site running securely. Server logs are used for availability, fault diagnosis and abuse prevention.
- To meet legal and contractual duties. Record keeping required by law, by an auditor, or by a client contract.
Disclosure, and what we never do
Skyfal Security does not sell personal information. We do not rent, trade or otherwise make personal information available to third parties for their own marketing, analytics or commercial purposes.
Disclosure is limited to two circumstances. The first is service delivery: sharing what is strictly necessary with a manufacturer or distributor to obtain a part, a licence or technical support on your behalf, or with a subcontracted technician engaged on your job under equivalent confidentiality obligations. The second is legal obligation: where disclosure is required by a court order, a lawful demand from a government authority, or applicable law.
Where a third party is engaged to process information on our behalf, we require that it be used only for the purpose we specify and be protected by comparable safeguards.
If a service provider we use stores information outside Canada, that information may be subject to the laws of the jurisdiction in which it is held. Where this applies to your engagement, it should be stated in your service agreement.
Client security system information
Some of what we see in the course of service is more sensitive than ordinary business information. Access control databases contain cardholder records. Video systems contain footage of identifiable people. Server documentation contains addressing, credentials and network structure. Site drawings show where doors, sensors and secure areas are.
That information belongs to the client, not to us. We access it only to the extent a specific job requires, only on systems and accounts the client has authorized, and only while the engagement is active. We do not extract, copy or retain cardholder data, credential formats, video footage, system passwords or facility drawings for our own records unless a written agreement expressly requires it and specifies how it is protected.
We do not accept this material through web forms or unsecured email. Where a document must be exchanged, it goes through a channel the client controls, after identity is verified, to a named person on both sides.
Technical staff are bound by confidentiality obligations that survive the end of an engagement.
Retention and safeguards
Retention. We keep personal information only as long as it serves the purpose it was collected for, or as long as a legal, tax, insurance or contractual obligation requires. Enquiries that do not lead to work are kept for a limited period and then deleted. Service records, quotations and invoices are retained for the period required for business, warranty and tax purposes. Server logs are retained for a short operational period. When information is no longer needed it is deleted or destroyed.
Safeguards. Protection is proportionate to sensitivity. Access to client records is limited to staff who need it for their work. Devices used for service work are password protected and encrypted. Remote access to a client system is performed on accounts the client issues and controls, and is revoked when an engagement ends. Paper records, where they exist, are stored securely and destroyed rather than discarded.
No safeguard is absolute, and we do not claim otherwise. If a breach occurs that creates a real risk of significant harm, we will report and notify as required under PIPEDA and inform the affected client without delay.
Cookies, fonts and analytics
This site loads no third-party fonts, no trackers and no advertising scripts. Typefaces are self-hosted and served from the same domain as the pages, so viewing this site does not send a request to any outside company.
The site does not set advertising or cross-site tracking cookies. A cookie may be set by the content management system if you log in as an administrator, or to support a security function such as spam prevention on a form once forms are live. Any such cookie exists to make the site work, not to follow you.
There is currently no third-party analytics on this site. If analytics is added later, it will be disclosed on this page before or at the time it goes live, along with the provider, what it records and how to opt out. If an embedded map, video or form is added, it will also be disclosed here, because embedded content can make requests to the provider that hosts it.
Your browser can be set to refuse cookies. Doing so will not prevent you from reading this site.
Access, correction and complaints
You can ask what personal information we hold about you, what it has been used for and to whom it has been disclosed. You can ask us to correct information that is inaccurate or incomplete. We will respond within the time frame set out in PIPEDA and will not charge for a routine request.
We may ask you to verify your identity before we release information, and we may withhold material where disclosure would reveal information about another person, breach a client confidentiality obligation, or expose the security posture of a facility. Where we withhold something, we will tell you why.
If you are not satisfied with how we have handled your personal information or your request, raise it with us first, in writing, using the contact route below. We will investigate and give you a written answer. If our answer does not resolve the matter, you may bring a complaint to the Office of the Privacy Commissioner of Canada.
How to reach us about privacy
Privacy questions, access requests and corrections should be directed to Mohamad Maktabi maktabi@skyfal.ca.
The organization responsible for the personal information described in this policy is SKYFAL SECURITY SYSTEMS INCORPORATED, at 5063 North Service Rd Burlington, ON L7L 5H6 CANADA.
For anything that is not a privacy matter, use the contact page. For an active technical problem, use request technical service and keep system specifics out of the message.