Privacy Policy
BlueFlex Logic IT ("BlueFlex," "we," "us") is a Canadian compliance consultancy. We advise organizations on how to handle personal information responsibly, so this policy is written the way we tell our clients to write theirs: in plain language, specific about what actually happens, and accountable to a named individual.
1. Who is accountable
Under the Personal Information Protection and Electronic Documents Act (PIPEDA), an organization must designate an individual accountable for its compliance. At BlueFlex, that individual is our designated Privacy Officer, reachable at innovation@blueflexlogicit.com or +1 437 298 3909. The identity of the accountable individual is available on request, as PIPEDA provides. Questions, access requests, corrections, and complaints under this policy all go to that address, and receive a response within 10 business days.
2. What we collect, and why
We collect only what the interaction requires:
- When you contact us or book a call: your name, email address, company, and whatever you choose to tell us about your situation. Used to respond to you and prepare for the conversation. Legal basis: your consent, given by reaching out.
- When you download a free resource: free guides such as the Questionnaire Decoder are delivered through Payhip, which asks for your name and email address so it can send you the file. If you tick the box to receive our emails, we add you to our mailing list and send a short series about answering client questionnaires, then occasional updates. If you do not tick it, you receive the file and nothing else. Every email includes a working unsubscribe. Legal basis: your consent.
- When you buy a digital product: checkout is handled by Payhip, which collects your name, email address and payment details in order to process the purchase and deliver the download. We receive your name and email address and the record of the purchase; we never see your card details. Used to deliver the product, send you updates to it, and respond if you have a problem with it. Legal basis: performance of the purchase you asked for.
- When you become a client: business contact details, engagement records, and the documents you share for the purposes of the engagement. Used solely to deliver the services in our agreement. Client materials are governed by the confidentiality terms of that agreement, which prevail over this policy where they are stricter.
- When you receive our emails: we send commercial electronic messages in compliance with Canada's Anti-Spam Legislation (CASL). Every message identifies us and includes a working unsubscribe, honoured within 10 business days. We record the consent basis for every address we contact.
- When you visit this website: we keep it simple. This site sets no cookies, runs no analytics, and uses no advertising trackers. Our hosting provider generates standard, short-lived server logs (such as IP address and pages requested) to operate and secure the service; we do not use these to identify visitors. If we ever add analytics, we will choose a privacy-respecting, cookieless service and update this policy first. We do not sell or rent personal information, to anyone, ever.
3. AI tools and your information
BlueFlex uses AI tools in its own operations under a written internal AI acceptable-use policy that classifies data by sensitivity and restricts which categories may be processed by which tools. Our current approved tool is Claude, by Anthropic, operated with data-sharing and training settings reviewed and configured before any client material is processed; client-confidential material is handled only in tools whose data-handling terms we have reviewed and approved, and the approved list is maintained in our internal AI register. If we adopt an additional tool, including an AI tool, during an active engagement, it goes through our vendor due-diligence process first; where it would touch client or personal information, we notify affected clients before use and reflect the change in this policy at its next review. We tell you this because we believe organizations using AI should say so, it is the standard we advise, so it is the standard we practice.
4. Where information lives, and who else touches it
We use a small number of service providers to operate: Google Workspace (email and documents); Netlify (website hosting); Cal.com (call booking); Payhip (digital product checkout and delivery, which also acts as merchant of record for Canadian sales tax on those purchases). Each processes information only to provide its service to us, under its own contractual terms. Some providers store data outside Canada (typically in the United States); where they do, the information is subject to the laws of those jurisdictions. We select providers with appropriate security practices and contractual protections. This list is reviewed whenever our tools change; new providers are assessed before adoption and reflected here at the next policy update.
5. How long we keep it
- Inquiries that don't become engagements: deleted within 18 months.
- Free resource sign-ups: kept while you remain subscribed; removed within 30 days of unsubscribing, apart from the suppression record described below.
- Digital product purchase records: retained 7 years, consistent with Canada Revenue Agency requirements for sales records, then securely deleted.
- Client engagement records: retained 7 years from engagement end, consistent with Canada Revenue Agency requirements, then securely deleted.
- Client evidence files containing personal information: returned or deleted at engagement closeout per the engagement terms, with deletion logged.
- Email unsubscribes: suppression records kept indefinitely so we never contact you again by mistake.
6. Your rights
You may ask us: what personal information we hold about you, how it has been used, and to whom it has been disclosed; to correct it if it is inaccurate; and to withdraw consent to further contact at any time. Write to innovation@blueflexlogicit.com. We will respond within 30 days as PIPEDA requires. If you are unsatisfied with our response, you may complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca). Quebec residents may also contact the Commission d'accès à l'information du Québec.
7. Safeguards
We protect personal information with measures proportionate to its sensitivity, including multi-factor authentication on all business systems, access limited to those who need it (currently, the accountable individual named above), encryption in transit, and a documented incident response process. In the event of a breach creating a real risk of significant harm, we will notify affected individuals and the Privacy Commissioner as PIPEDA requires.
8. Changes to this policy
When this policy changes materially, we update the version number and dates above and note the change here. We do not retroactively change what we do with information already collected without seeking consent.
BLUEFLEX