What we collect
Depending on your interaction, XORVANIQ may collect identity and contact details, account records, order and billing records, communications, support diagnostics, security events, device or browser data, and service usage needed to operate and protect the service. Payment processors may handle full payment-card details directly.
Why we use it
Information is used to respond to requests, create and secure accounts, provide and improve services, process billing, prevent fraud and abuse, meet legal duties, and communicate operational notices. Marketing messages are sent only where permitted, identify the sender, and provide an unsubscribe method.
Consent and choices
Consent is requested in a way appropriate to the sensitivity and purpose of the information. You may withdraw consent where permitted, though some information may remain necessary to provide a requested service or meet legal obligations.
Service providers and location
Limited information may be shared with hosting, domain, email, payment, security, analytics, and support providers acting for XORVANIQ. Providers may process information outside Ontario or Canada, where it can be subject to local law. XORVANIQ does not sell personal information.
Retention and safeguards
Records are kept only as long as reasonably needed for the stated purpose, legal obligations, security, dispute handling, and legitimate business records, then securely deleted or anonymized. Administrative, technical, and organizational safeguards are selected according to sensitivity and risk.
Access, correction, and complaints
You may request access to or correction of personal information, subject to lawful exceptions. Contact the privacy lead at privacy@xorvaniq.ca. Identity verification may be required before a response.
Privacy incidents
XORVANIQ assesses suspected breaches, maintains required records, and provides legally required reports and notifications where a breach creates a real risk of significant harm.
External guidance
This policy is informed by the Office of the Privacy Commissioner of Canada's PIPEDA guidance and the CRTC's CASL guidance.