Privacy Policy
What we collect, why we collect it, how long we keep it, and the rights you have over it — written to be read, not skimmed.
Who this policy covers
NextGenix Technologies Inc. (“NextGenix”, “we”, “us”) is a software development company incorporated in Ontario, Canada. This policy explains what personal information we collect through nextgenix.ca, through our sales and recruitment processes, and in the course of delivering services to our clients — and what we do with it.
We handle personal information in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation, including Quebec’s Law 25 where it applies to individuals in that province.
Two different roles
Where you contact us, apply for a job or browse our site, NextGenix decides why and how your information is used. Where we build or operate software for a client, we process personal information on that client’s instructions under a written services agreement — the client’s own privacy policy governs that data, and requests about it should go to them.
Information we collect
Information you give us
You choose what to send us. Depending on the form or conversation, that may include:
- Name, job title, employer, email address and telephone number
- The content of your enquiry, including any project details, budget range or timeline you describe
- Documents you send us, such as a brief, a specification or a CV
- Records of correspondence, meetings and calls relating to a prospective or active engagement
Information collected automatically
When you visit nextgenix.ca, our hosting and analytics tooling records limited technical information:
- IP address, truncated for analytics purposes, and approximate region
- Browser type, operating system, device type and screen size
- Pages visited, referring URL and time spent on each page
- Server logs of requests, used for security monitoring and troubleshooting
Information from third parties
We may receive your business contact details from a colleague who refers you, from a mutual introduction, or from public professional sources such as a company website or LinkedIn profile. We do not buy marketing lists.
How we use your information
We use personal information only for the purposes it was collected for, namely:
- Responding to enquiries — answering your question, preparing a proposal and scheduling a consultation
- Delivering services — managing an engagement, its contacts, invoicing and support
- Recruitment — assessing an application and communicating with candidates
- Improving the website — understanding which pages are useful and where visitors get stuck
- Security and integrity — detecting abuse, spam submissions and unauthorised access attempts
- Legal and accounting obligations — keeping records we are required by Canadian law to keep
We do not sell personal information, we do not rent or share it with third parties for their own marketing, and we do not use it to make automated decisions that produce legal or similarly significant effects.
Consent and your choices
For most of what we do, consent is express: you fill in a form, send an email or sign an agreement. Where we rely on implied consent — for example, replying to a business enquiry you initiated — the purpose is one a reasonable person would expect in the circumstances.
You may withdraw consent at any time, subject to legal and contractual restrictions and reasonable notice. Withdrawing consent may mean we can no longer provide a service or continue a conversation. To withdraw consent, email privacy@nextgenix.ca.
We send marketing email only to people who have asked for it. Every such message carries an unsubscribe link, and we comply with Canada’s Anti-Spam Legislation (CASL).
Where information is stored
We host this website and store business records primarily in Canadian data-centre regions. Some of our service providers operate infrastructure in the United States or the European Union, which means information may be stored or processed outside Canada and may be accessible to the courts and law-enforcement authorities of those countries.
Where information crosses a border, we use contractual protections requiring a comparable level of protection to that provided under Canadian law. Client engagements with a Canadian data-residency requirement are architected and contracted to keep data within Canada; we confirm that in writing before an engagement begins.
How long we keep it
We keep personal information only as long as it serves the purpose it was collected for, or as long as the law requires:
- Unsuccessful enquiries and proposals — 24 months from last contact
- Client engagement records — for the life of the engagement plus 7 years, to meet Canadian accounting and limitation-period requirements
- Recruitment applications — 12 months, or longer if you ask us to keep you on file
- Marketing subscriptions — until you unsubscribe, then a suppression record so we do not contact you again
- Web server logs — 90 days
At the end of a retention period, records are securely deleted or irreversibly anonymised.
How we protect it
We maintain an information security programme aligned with ISO 27001 and audited under SOC 2 Type II. Controls include:
- Encryption in transit (TLS 1.2 or higher) and at rest for stored records
- Role-based access control, least-privilege provisioning and mandatory multi-factor authentication
- Quarterly access reviews and prompt de-provisioning when someone leaves or changes role
- Centralised logging, alerting and a documented incident-response plan tested at least annually
- Background checks, confidentiality agreements and annual privacy and security training for personnel
- Vendor security assessments before a provider is given access to personal information
No system is perfectly secure. If a breach creates a real risk of significant harm, we will notify affected individuals and the Office of the Privacy Commissioner of Canada as PIPEDA requires, and we will keep a record of the incident.
Your rights
Subject to the limited exceptions in PIPEDA, you may:
- Access the personal information we hold about you and be told how it has been used and to whom it has been disclosed
- Correct information that is inaccurate or incomplete
- Withdraw consent to a use or disclosure, subject to legal and contractual restrictions
- Request deletion of information we no longer have a lawful basis or business need to keep
- Request portability of information you provided to us, in a commonly used electronic format
- Complain to us and, if unsatisfied, to the Office of the Privacy Commissioner of Canada
Write to privacy@nextgenix.ca. We respond within 30 days, and will tell you in advance if we need an extension the legislation permits. We may ask for enough information to confirm your identity before acting, and we do not charge a fee for a routine request.
Children
Our website and services are directed at businesses, not at children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us with personal information, contact our Privacy Officer and we will delete it.
Changes to this policy
We review this policy at least annually and whenever we make a material change to how we handle personal information. The “last updated” date at the top of this page always reflects the current version. Where a change materially affects how we use information you have already given us, we will contact you directly rather than relying on a silent update.
Contact our Privacy Officer
Questions, access requests and complaints about privacy go to our Privacy Officer, who is accountable for our compliance with this policy:
Privacy Officer, NextGenix Technologies Inc.
200 Bay Street, Suite 1400, Toronto, ON M5J 2J2, Canada
privacy@nextgenix.ca · +1 (647) 555-0142
If you are not satisfied with our response, you may contact the Office of the Privacy Commissioner of Canada at priv.gc.ca or 1-800-282-1376. Individuals in Quebec may also contact the Commission d’accès à l’information du Québec.