Privacy Policy

EFFECTIVE: JULY 31, 2026 · LAST REVIEWED: JULY 31, 2026 · VERSION 1.0

BlueFlex Logic IT ("BlueFlex," "we," "us") is a Canadian compliance consultancy. We advise organizations on how to handle personal information responsibly, so this policy is written the way we tell our clients to write theirs: in plain language, specific about what actually happens, and accountable to a named individual.

1. Who is accountable

Under the Personal Information Protection and Electronic Documents Act (PIPEDA), an organization must designate an individual accountable for its compliance. At BlueFlex, that individual is the Founder, Precious Eze, reachable at innovation@blueflexlogicit.com or +1 437 298 3909. Questions, access requests, corrections, and complaints under this policy all go there, and receive a response within 10 business days.

2. What we collect, and why

We collect only what the interaction requires:

3. AI tools and your information

BlueFlex uses AI tools in its own operations under a written internal AI acceptable-use policy that classifies data by sensitivity and restricts which categories may be processed by which tools. Our current approved tool is Claude, by Anthropic, operated with data-sharing and training settings reviewed and configured before any client material is processed; client-confidential material is handled only in tools whose data-handling terms we have reviewed and approved, and the approved list is maintained in our internal AI register. We tell you this because we believe organizations using AI should say so, it is the standard we advise, so it is the standard we practice.

4. Where information lives, and who else touches it

We use a small number of service providers to operate: Google Workspace (email and documents); Netlify (website hosting); Cal.com (call booking). Each processes information only to provide its service to us, under its own contractual terms. Some providers store data outside Canada (typically in the United States); where they do, the information is subject to the laws of those jurisdictions. We select providers with appropriate security practices and contractual protections.

5. How long we keep it

6. Your rights

You may ask us: what personal information we hold about you, how it has been used, and to whom it has been disclosed; to correct it if it is inaccurate; and to withdraw consent to further contact at any time. Write to innovation@blueflexlogicit.com. We will respond within 30 days as PIPEDA requires. If you are unsatisfied with our response, you may complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca). Quebec residents may also contact the Commission d'accès à l'information du Québec.

7. Safeguards

We protect personal information with measures proportionate to its sensitivity, including multi-factor authentication on all business systems, access limited to those who need it (currently, the accountable individual named above), encryption in transit, and a documented incident response process. In the event of a breach creating a real risk of significant harm, we will notify affected individuals and the Privacy Commissioner as PIPEDA requires.

8. Changes to this policy

When this policy changes materially, we update the version number and dates above and note the change here. We do not retroactively change what we do with information already collected without seeking consent.