Published using Google Docs
Arolytics Privacy Policy
Updated automatically every 5 minutes

Privacy Notice

Please read the Arolytics Inc. Privacy Notice carefully to understand what information is collected through Arolytics Inc., how this information is used, and when it may be disclosed.

In this Privacy Notice, “Arolytics Inc.” refers to our website, our application, and the products and services offered through our website and application. References to “we”, “us” or “our” means Arolytics Inc.. References to “personal information” includes “personal health information”.

By visiting our website and using Arolytics Inc. services, you provide your consent and agree to the collection of personal data in a lawful and fair manner. We ensure that the collection and processing of personal data adhere to applicable privacy laws and regulations. If you have any questions or concerns about the data we collect and how it is used, please contact Arolytics Inc. directly using the contact information provided in this privacy policy. Even if you do not read the entire Arolytics Inc. Privacy Notice.

Data Controller and Data Processor

Arolytics Inc. serves as the data processor for most information entered into the Arolytics Inc. application, website, and supporting systems, acting on behalf of its business customers who serve as the data controllers. However, Arolytics Inc. also collects certain information directly from users for security, logging, and application performance purposes, where it acts as the data controller and processor. Arolytics Inc. may engage third-party sub-processors (as detailed below) to support its operations. If you have any inquiries about the processing of your personal data, please contact us using the contact information provided in this privacy notice.

Types of Data Collected

Arolytics Inc. strictly limits the collection of personal data to only the information that is necessary to perform and provide services or fulfill a direct business need. We adhere to the principle of data minimization, ensuring that only the minimum amount of personal data required is collected and processed.

When collecting personal data, we strive to be transparent about the purposes for which the data is being collected and how it will be used.

The Arolytics Inc. application and supporting applications collect the following types of personal data: cookies, usage data, email address, phone number, first name, last name, province, state, country, ZIP/Postal code, city, address, and company name.

Certain data may be mandatory for the use of the Arolytics Inc. application, while other data may be optional. When data is mandatory, it is clearly indicated throughout the website and application. Users are free to choose not to provide optional data without any impact on the availability or functionality of the service. If you have any questions about which personal data is mandatory, please contact us using the contact information provided in this privacy notice.

Arolytics Inc. applications may collect personal data that users provide voluntarily or collect usage data while using the website, web application, and supporting applications.

Furthermore, the Arolytics Inc. website and its supporting applications may use cookies and other tracking technologies to enhance the user experience and provide specific functionalities. Please refer to the Cookie Policy below for more information.

Safeguards

At Arolytics Inc., we take the security of your personal data seriously. We implement robust technical and organizational measures to protect your data from unauthorized access, disclosure, alteration, or destruction.

We follow industry best practices and standards to ensure the confidentiality, integrity, and availability of your data. Our security measures include but are not limited to:

Encryption: We employ encryption techniques to safeguard your data during transmission and storage.

Access Control: We restrict access to personal data to authorized personnel only, ensuring that it is accessible on a need-to-know basis.

Regular Audits: We conduct regular security audits and assessments to identify and address any vulnerabilities or risks.

Employee Training: Our employees undergo comprehensive data protection training to ensure they understand the importance of data security and privacy.

We are committed to continuously enhancing our security practices and staying up to date with the latest industry standards to provide a secure environment for your personal data.

While we strive to protect your personal data, no method of transmission or storage is 100% secure. Therefore, we cannot guarantee absolute security. If you have any concerns about the security of your data, please contact us using the contact information provided in this privacy notice.

Mode, Place, and Methods of Processing the Data

Personal data is processed using computers and technology-enabled tools in accordance with organizational policies and procedures related to the stated purposes. In certain cases, personal data may be accessible to Arolytics Inc. employees involved in the operation of the Arolytics Inc. website, application, and supporting applications. External parties, such as third-party technical service providers, hosting providers, and IT companies, may also have access to personal data as data processors or sub-processors appointed by Arolytics Inc..

Legal Basis of Processing

Arolytics Inc. may process personal data when one of the following legal bases applies:

The specific legal basis for processing personal data will be provided upon request, including whether the provision of personal data is a statutory or contractual requirement, or a requirement necessary to enter into a contract.

Place

Data is primarily processed at Arolytics Inc.’s operating offices and hosting facilities, located in Canada. However, some data may be stored and processed in the United States or the European Union through third-party sub-processors. Data transfers may involve transmitting user data to a country outside its own jurisdiction.

Retention Time

Personal data is retained for as long as necessary to fulfill the purposes for which it was collected unless a longer retention period is required or permitted by law.

The retention periods are as follows:

Personal data collected for the performance of a contract between Arolytics Inc. and a business customer is retained until the contract is fully executed, or until the business customer requests deletion of the data.

Personal data collected for Arolytics Inc.’s legitimate interests is retained as long as necessary to fulfill those purposes. For specific information about Arolytics Inc.s legitimate interests, please refer to the relevant sections of this document or contact us using the contact information provided in this privacy notice.

Personal data processed based on user consent may be retained until such consent is withdrawn, provided that it is not otherwise required or permitted by law.

Personal data may be retained for a longer period when necessary to comply with a legal obligation or a lawful order from an authority.

Once the retention period expires, personal data will be securely deleted or anonymized.

The Purposes of Processing

Arolytics Inc. collects and processes personal data for the following purposes:

Processing and Sharing of Personal Data

Arolytics Inc. engages various services and third-party processors to support its operations. The following provides detailed information on the processing of personal data, the involved services, and the third-party processors:

Cookie Policy

The Arolytics Inc. website and web application use cookies to enhance the user experience and provide specific functionalities.

The Rights of Users

Users have the following rights regarding their personal data processed by Arolytics Inc.:

  1. Right to Withdraw Consent: Users have the right to withdraw their consent to the processing of their personal data at any time.
  2. Right to Object: Users can object to the processing of their personal data based on legitimate interests or for direct marketing purposes.
  3. Right of Access: Users can request access to their personal data and obtain information about the processing activities.
  4. Right to Rectification: Users can request the correction or update of inaccurate or incomplete personal data.
  5. Right to Restrict Processing: Users have the right to restrict the processing of their personal data under certain circumstances.
  6. Right to Erasure: Users can request the erasure of their personal data, subject to legal obligations or overriding legitimate grounds.
  7. Right to Data Portability: Users can request to receive their personal data in a structured, commonly used, and machine-readable format, and transmit it to another data controller.
  8. Right to Lodge a Complaint: Users have the right to lodge a complaint with a data protection authority regarding the processing of their personal data.

To exercise these rights or obtain further information, users can contact Arolytics Inc. using the contact details provided in this document.

Changes to This Privacy Notice

Arolytics Inc. reserves the right to modify or update this privacy notice at any time. Changes will be communicated through the Arolytics Inc. website, application, or other appropriate means. It is recommended to regularly review this privacy notice for the latest information.

Contact Us

If you have any questions, concerns, or requests regarding this Privacy Notice, data deletion, accuracy, or any other privacy practices, please contact us at:

Arolytics, Inc, 112 4 Ave SW, East 15th Floor, Calgary, AB T2P 3N3, 403.993.7551

Privacy Officer: Stephan Becker, Stephan.becker@arolytics.com, 403.993.7551

Last updated: January 16th, 2025

Note: This privacy notice is provided as a general template and requires customization to accurately reflect your organization’s specific data processing practices and legal requirements. Please carefully review this template to ensure it accurately reflects your organization’s privacy practices. It is recommended to consult with legal professionals to ensure compliance with the GDPR, HIPAA, CCPA, CPRA, PIPEDA, and other applicable privacy laws.