- Home
- Privacy Policy
Privacy Policy
Effective Date: June 17, 2025
Last Updated: June 17, 2026
At MTech Cyber Inc., we respect your privacy. This policy explains how we collect, use, disclose, and protect personal information in compliance with Quebec's Act respecting the protection of personal information in the private sector (the "Act"), as amended by Law 25 (Bill 64), the federal Personal Information Protection and Electronic Documents Act (PIPEDA), and other applicable privacy legislation.
This policy applies to personal information collected through our website, by email, phone, or in the course of providing managed IT and cybersecurity services.
1. Privacy Officer
MTech Cyber has designated a Privacy Officer responsible for compliance with applicable privacy laws and for handling privacy-related inquiries, complaints, and access requests.
Title: Privacy Officer, MTech Cyber Inc.
Email: privacy@mtechcyber.com
Website: mtechcyber.com
Mailing Address: 102-3835 Rue Wellington, Verdun QC H4G 1V1
You may contact the Privacy Officer at any time to exercise your rights, ask questions about this policy, or raise a privacy concern.
2. Information We Collect
We may collect the following types of information:
Personal Information
- Name, job title, and employer
- Email address, phone number, and mailing address
- Information provided through contact forms, consultations, or service agreements
- Login credentials and access information for managed systems (collected under separate service agreements)
Technical and Usage Information
- IP address, browser type, and device information
- Website usage data collected through cookies or analytics tools
- Log data and system telemetry related to IT service delivery
3. Why We Collect Your Information
We collect personal information only for specific, legitimate purposes. The purposes for which we collect and use your information include:
- Responding to inquiries and providing IT and cybersecurity services
- Fulfilling obligations under service agreements
- Scheduling consultations and communicating about active engagements
- Sending service-related notices, updates, and security alerts
- Sending marketing communications where consent has been obtained
- Improving our website and understanding how visitors use it
- Meeting legal, regulatory, and contractual obligations
- Investigating and responding to security incidents
We will not use your personal information for purposes other than those identified above without obtaining your consent, unless otherwise permitted or required by law.
4. Consent
We obtain consent for the collection, use, and disclosure of personal information at or before the time of collection, except where law permits or requires us to do otherwise.
Consent may be express (e.g., signing a service agreement or checking a box) or implied by the nature of the relationship (e.g., providing a business card or contacting us to inquire about services).
You may withdraw consent at any time, subject to legal and contractual restrictions. To withdraw consent, contact our Privacy Officer. We will inform you of the implications of withdrawing consent before acting on your request.
5. Retention of Personal Information
We retain personal information only as long as necessary to fulfill the purposes for which it was collected, or as required by law.
- Client records and service-related information: retained for a minimum of 7 years following the end of the service relationship, as required by applicable tax and commercial law
- Website inquiry records: retained for 2 years unless a service relationship is established
- Marketing contact records: retained until consent is withdrawn
When personal information is no longer required, it is securely destroyed or anonymized.
6. Sharing and Disclosure
We do not sell, rent, or trade your personal information. We may share your information only in the following circumstances:
- With employees, contractors, or subcontractors who need it to provide services on our behalf, under confidentiality obligations
- With third-party service providers for website hosting, email delivery, business analytics, or IT tooling (see Section 7)
- When required by law, court order, regulatory authority, or to protect our legal rights
- In connection with a business transaction such as a merger or acquisition, subject to confidentiality protections
We do not use your personal information for automated decision-making that produces legal or similarly significant effects without your knowledge.
7. Third-Party Services and Cross-Border Transfers
Some of the tools and service providers we use are located outside Quebec or Canada, including in the United States. When personal information is transferred outside Quebec, it may be subject to the laws of the jurisdiction where it is processed, which may differ from Quebec and Canadian privacy laws.
As required by Law 25, we have assessed the privacy practices of our third-party providers and have taken steps to ensure reasonable protection of your personal information, including through contractual agreements. Categories of third-party providers include:
- Website hosting and analytics (e.g., servers located in the United States)
- Email delivery platforms
- Remote monitoring and management tools
- Cloud storage and backup providers
If you would like more information about our third-party providers or cross-border data flows, contact our Privacy Officer.
8. Security Safeguards
We implement administrative, technical, and physical safeguards appropriate to the sensitivity of the information to protect it against unauthorized access, disclosure, alteration, loss, or destruction. These measures include:
- Encryption of data in transit and at rest where appropriate
- Access controls and authentication requirements
- Regular security assessments and staff training
- Incident response procedures
No method of transmission over the internet or electronic storage is completely secure. While we take reasonable precautions, we cannot guarantee absolute security.
9. Privacy Incidents and Breach Notification
In the event of a confidentiality incident involving personal information that presents a risk of serious harm, MTech Cyber will:
- Notify affected individuals as soon as reasonably possible
- Report the incident to the Commission d'acces a l'information (CAI) as required by Law 25
- Take steps to reduce the risk of harm and prevent future incidents
We maintain a register of confidentiality incidents as required by law.
10. Cookies and Tracking Technologies
Our website may use cookies and similar technologies to improve your browsing experience and analyze site traffic. We use only cookies necessary for the functioning of the site and, where applicable, analytics cookies with your consent.
You may adjust your browser settings to refuse cookies. Doing so may affect the functionality of certain features on our website. A cookie consent notice on our website provides options for managing your preferences.
11. Your Privacy Rights
Depending on your location, you may have the following rights under applicable privacy legislation, including Law 25 and PIPEDA:
- Right of access: request confirmation of whether we hold personal information about you and receive a copy
- Right of rectification: request correction of inaccurate or incomplete information
- Right of deletion: request that personal information be deleted where it is no longer necessary for the purposes for which it was collected
- Right to data portability: receive your personal information in a structured, commonly used technological format (Law 25, applicable as of September 2023)
- Right to withdraw consent: for uses of your personal information based on consent
- Right to be informed: about how your personal information is processed
To exercise any of these rights, contact our Privacy Officer at privacy@mtechcyber.com. We will respond within 30 days. If we are unable to fulfill a request, we will explain why in writing.
If you are dissatisfied with our response, you may file a complaint with the Commission d'acces a l'information (CAI) at www.cai.gouv.qc.ca, or with the Office of the Privacy Commissioner of Canada at www.priv.gc.ca.
12. Links to Third-Party Websites
Our website may contain links to third-party websites. We are not responsible for the privacy practices or content of those sites. We encourage you to review the privacy policies of any external sites you visit.
13. Minors
Our services are not directed at individuals under the age of 14. We do not knowingly collect personal information from minors. If you believe we have inadvertently collected such information, please contact our Privacy Officer.
14. Updates to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. The updated policy will be posted on our website with a revised Effective Date. Material changes will be communicated to affected individuals where required by law.
Continued use of our website or services following the posting of changes constitutes acceptance of the updated policy.
Contact Us
Privacy Officer: Randal Wark
Email: privacy@mtechcyber.com
Website: www.mtechcyber.com
102-3835 Rue Wellington, Verdun QC H4G 1V1
This document is intended for public availability on the MTech Cyber website in compliance with Law 25 (Quebec) and PIPEDA (Canada).