Skip to main content

Legal

Privacy Policy

Last updated: July 18, 2026

Scope and Controller

This Privacy Policy explains how Arthatech collects, uses, discloses, stores, and protects personal information when you visit this website, contact us, request a proposal, buy or receive services, use a client portal, or otherwise interact with Arthatech.

Arthatech is an Ontario-based web development, automation, hosting, deployment, and quality assurance business. For most direct website and sales interactions, Arthatech acts as the organization responsible for the personal information it collects. For some client projects, Arthatech may process information on behalf of a client under a separate agreement.

This policy is intended to align with Canadian privacy principles, including accountability, identified purposes, consent, limiting collection, limiting use, disclosure and retention, accuracy, safeguards, openness, individual access, and challenging compliance. It also includes additional information for users in other regions where laws such as the GDPR, UK GDPR, or US state privacy laws may apply.

Personal Information We Collect

We collect only what is reasonably necessary for the purposes described in this policy, which may include:

  • Identity and contact information, such as your name, company, role, email address, phone number, mailing address, billing details, and communication preferences.
  • Business and project information, such as website URLs, requirements, budgets, timelines, brand assets, technical environments, access details you choose to provide, support requests, meeting notes, and files shared for project delivery.
  • Account and portal information, such as login identifiers, organization membership, roles, permissions, activity logs, invoices, payment status, documents, and support history.
  • Technical information, such as IP address, device and browser type, operating system, approximate location, referring pages, pages viewed, timestamps, diagnostics, security logs, and cookie or similar technology identifiers.
  • Payment and transaction information, such as invoices, receipts, payment method metadata, tax details, and records needed for accounting. Full card or bank details are typically handled by payment processors and are not intentionally stored by Arthatech unless expressly required for a contracted service.
  • Sensitive or regulated information only where needed for a specific client engagement or submitted by you, such as information related to healthcare, professional services, legal, accounting, HR, or compliance workflows. We ask clients not to send sensitive information unless the project or support context requires it.

Sources of Information

We collect information directly from you, from your business or authorized team members, from forms and communications, from systems used to deliver services, from website analytics or security tools, and from publicly available business sources where relevant to a legitimate inquiry or project.

How We Use Information

Arthatech may use personal information to:

  • Respond to inquiries, schedule calls, prepare proposals, scope projects, and communicate about services.
  • Deliver website, application, hosting, automation, CMS, QA, maintenance, analytics, documentation, and support services.
  • Administer accounts, permissions, invoices, payments, tax records, contracts, and client relationships.
  • Operate, monitor, secure, debug, backup, and improve this website and client-facing systems.
  • Detect, prevent, and investigate spam, fraud, abuse, unauthorized access, service misuse, security incidents, and legal claims.
  • Send service messages, project updates, security notices, billing reminders, and, where permitted, marketing or educational communications.
  • Meet legal, regulatory, accounting, audit, tax, insurance, dispute resolution, and business continuity obligations.

Consent and Legal Bases

We rely on consent where required, including express or implied consent depending on the sensitivity of the information and the context. You may withdraw consent, subject to legal or contractual restrictions and reasonable notice.

Where GDPR, UK GDPR, or similar laws apply, our legal bases may include performance of a contract, steps requested before entering a contract, legitimate interests in operating and securing our business, compliance with legal obligations, consent, and, in limited cases, establishment or defence of legal claims.

Cookies and Analytics

We may use cookies, local storage, analytics, performance, and security technologies to operate the site, remember preferences, understand traffic, improve pages, and protect services. Optional analytics are used to understand aggregate usage and are not used to sell personal information.

You can manage browser cookies through your browser settings and, where available, through our cookie banner. More detail is available in our Cookie Policy.

Disclosure and Service Providers

We do not sell personal information. We may disclose information to trusted vendors, contractors, professional advisers, and platforms that help us provide services, including hosting, cloud infrastructure, databases, email, forms, scheduling, project management, analytics, payment processing, security, error monitoring, backups, legal, tax, and accounting support.

We may also disclose information where required by law, court order, regulator, law enforcement request, corporate transaction, debt collection, insurance claim, security investigation, or to protect rights, safety, property, and service integrity.

International Transfers

Arthatech is based in Canada, but the tools used to operate this website and deliver services may process or store information in Canada, the United States, the European Economic Area, the United Kingdom, India, or other jurisdictions. Privacy laws in those jurisdictions may differ from the laws where you live.

Where required, we use contractual, organizational, and technical safeguards for cross-border transfers, such as data processing terms, confidentiality commitments, access controls, and transfer mechanisms recognized by applicable law.

Security Safeguards

We use administrative, technical, and organizational safeguards appropriate to the sensitivity of the information, such as access controls, least-privilege permissions, encryption in transit where supported, secure hosting providers, private storage for sensitive files, audit logging where available, backups, and incident response practices.

No website, network, or storage system is perfectly secure. If we become aware of a breach of security safeguards involving personal information, we will assess the risk and provide notices required by applicable law.

Retention

We retain personal information only as long as reasonably necessary for the purposes described in this policy, unless a longer period is required or permitted by law. Retention periods vary based on the record type, project status, legal limitation periods, tax and accounting requirements, backup cycles, security needs, and contractual obligations.

When information is no longer required, we delete, anonymize, archive, or restrict it using reasonable measures.

Your Privacy Rights

Depending on where you live, you may have rights to request access, correction, deletion, portability, restriction, objection, withdrawal of consent, information about disclosures, or review of automated decisions. Canadian users may also challenge our compliance with applicable privacy principles.

California and other US state residents may have additional rights to know, access, correct, delete, opt out of certain sales, sharing, or targeted advertising, limit certain uses of sensitive personal information, and not be discriminated against for exercising privacy rights. Arthatech does not sell personal information as that term is commonly understood.

We may need to verify your identity and authority before fulfilling a request. Some information may be retained where required for legal, tax, accounting, security, fraud prevention, contractual, or dispute purposes.

Client Data and End Users

If Arthatech builds, hosts, maintains, or supports a system for a client, the client may be responsible for deciding what personal information is collected from its own customers, patients, employees, users, or vendors. In those cases, Arthatech generally acts as a service provider or processor and handles the information according to the client agreement and documented instructions.

End users of a client-owned website or application should review that client's privacy policy and contact the client directly for privacy rights requests, unless Arthatech is expressly identified as the point of contact.

Children

This website and Arthatech's business services are not directed to children. We do not knowingly collect personal information from children without appropriate consent. If you believe a child has provided information to us, please contact us.

Marketing Communications

We may send business communications to prospects, clients, and contacts where permitted by law. You can opt out of non-essential marketing messages by using any available unsubscribe mechanism or by contacting us. Service, security, legal, and billing messages may still be sent when needed.

Changes to This Policy

We may update this policy to reflect changes in our services, tools, legal obligations, or business practices. The updated version will be posted on this page with a revised date. Material changes may be communicated through additional notice where appropriate.

Contact

For privacy questions, access requests, correction requests, deletion requests, or complaints, contact Arthatech through the contact page or your existing project email thread. Please include enough detail for us to understand and verify the request.