Privacy

We take privacy seriously and the first questions regarding personal data we ask ourselves is:

  • Do I need this information to perform any task?
    • If not, do not even collect it.
    • If it is necessary, we ask ourselves:
      • how long do we need to keep it?
      • how can I ensure it is deleted immediately and automatically once not needed?
      • how must it be secured?
  • The thought here is always: you cannot steal what you do not have (hence this reduces our liability risk on top of improving your privacy)
  • Since this is a paid service, we are not dependent on selling your information in order to generate revenues.

As such here is the (personal) information we need and keep:

  • Email:
    • It is used when you log in in the account system where it is kept (authentication purposes)
    • It can be used sparingly to communicate with you (any non-necessary function is opt-in)
    • In other applications, an internal (and unrelated) identifier is used (for application authorization purposes)
    • It is never shared with third-parties
  • IP address:
    • This covers the IP address (IPv4 and/or IPv6) is the address the server sees when you connect to our services
    • In some jurisdictions it may be considered personnally identifiable information (PII), sometimes depending on the usage
    • It is impossible not to see the IP address connected (it is part of what is needed to connect to a site), but again how it is used and how long it is maintained is the issue.
    • IP addresses are used for security reasons, such as:
      • IP addresses may be used to block Denial of Service (Dos) and Distributed DoS (DDoS)
      • IP addresses may be used to block hacking attempts
      • IP addresses may be used to prevent session hijacking to ensure that the user accessing the service
      • IP addresses are used in security event logging
    • In other applications, an internal (and unrelated) identifier is used (for application authorization purposes)
    • IP addresses are never shared with third-parties unless required by law
  • Logs (what you look at - logged in or not):
    • This can include web server logs (logged in or not) and application logs
    • These are used to determine what is mostly used to optimize/improve the application and provide more value (for example, often viewed articles or sections may indicate need for further guidance or clarification)
    • These will never shared with third-parties as a base rule
    • In rare occurrences, limited information could be shared for security purposes (reporting Denial of Service attacks or hacking attempts)
    • Retention sometimes depends on laws and regulations (e.g. PCI DSS requires 12 months with 3 months readily available and the remainder which can be archived)
  • Paymnent Data
    • Account and Cardholder Data (PCI data) is collected only by our trusted third-party payment processor
    • We converve payment data including those required for invoices
  • For Report Generation, we receive data to fill in the document.
    • That data is yours and we become a temporary custodian
    • Your data is present is upload files, intermediary files, and generated files - in memory and written to disk
    • All uploaded data is done in RAM memory
    • All written data is encrypted using AES and proper key management
    • All ecnrypted written data is kept a maximum of 24h (configurable in preferences), after which it can be kept longer (considered archived) if you provided a PGP public key for archival (after which only the owner of the private key can access the data)
    • We may keep metadata like:
      • What type of report was selected (e.g. SAQ A-EP 4.0, to determine what is used)
      • Said data is Anonymized data for security, performance and quality purposes
      • Metadata is never shared with third-parties
      • This is present in the History tab

Use of cookies

  • Cookies are simple storage of bits of data on your computer and linked to a particular web domain.
  • Cookies are separated between first-party, related to the website you are visiting, and third-party, generally related to some form of tracking.
  • We use first-party cookies strictly in order to save your login state and preferences.
  • Cookies are not used to track you, nor do we use third-party cookies for that purpose.

© 2026 8850895 Canada Inc.
An unhandled error has occurred. Reload 🗙

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please retry or reload the page.