Legal
Privacy Policy
Hoardy, a brand of 11371096 Canada Inc.
1. Who we are
11371096 Canada Inc., operating as Hoardy ("Hoardy", "we", "us", "our"), is a Canadian corporation that designs, builds, and quality-assures software. Our registered office is at 220 Missinnihe Way, Suite 1411, Mississauga, Ontario L5H 0A9, Canada.
This policy explains how we handle personal information in the course of our business: when you visit hoardy.ai, when you contact us, when you engage us for work, and when we work with clients, suppliers, and partners.
2. The law we follow
We are a private-sector organization based in Ontario, so the Personal Information Protection and Electronic Documents Act (PIPEDA) governs how we collect, use, and disclose personal information in the course of commercial activity.
PIPEDA sets out ten fair information principles, and this policy is built on them: accountability; identifying purposes; consent; limiting collection; limiting use, disclosure, and retention; accuracy; safeguards; openness; individual access; and challenging compliance.
Where another law gives you stronger rights, we honour it. That includes Quebec's privacy legislation, known as Law 25, for individuals in Quebec.
Canadian federal privacy law is being modernized. Bill C-36, which would enact the Protecting Privacy and Consumer Data Act and replace the privacy provisions of PIPEDA, received first reading on June 15, 2026 and remains before Parliament. It is not law yet, and PIPEDA governs until it is. We will update this policy if the law changes.
3. What we collect
We limit collection to what we need for the purposes described below. In practice that is:
- Information you give us. Your name, email address, telephone number, company name, role, and anything you write to us, including through the contact form on our site.
- Enquiry and correspondence records. Emails, call notes, meeting notes, and support requests between us.
- Project information. When you engage us, the business details, documents, specifications, systems access, and materials you share so we can do the work. Some of this may contain personal information about your staff, customers, or users. In those situations you remain the organization responsible for that information, and we handle it as your service provider, on your instructions and under our agreement with you.
- Technical information. When you visit our site, our systems and our hosting provider may record your IP address, browser type and version, operating system, the pages you view, the time of your visit, and the page that referred you.
- Cookies and similar technologies. Small files placed on your device, described in section 7.
- Recruitment information. If you apply to work with us, the information in your application and our notes on it.
We do not collect information about children, and we do not buy personal information from data brokers.
4. Why we collect it
We use personal information to:
- respond to your enquiry and answer your questions;
- prepare proposals, statements of work, and invoices;
- deliver, support, and improve the services you engage us for;
- keep our records accurate and our accounts in order;
- protect our site, our systems, and our clients from fraud, abuse, and security incidents;
- understand in aggregate how our site is used, so we can improve it;
- meet our legal, tax, and accounting obligations; and
- send you updates and marketing, but only where you have consented or the law otherwise allows.
We do not use personal information for purposes that a reasonable person would consider inappropriate, and we do not sell it.
5. Consent
We collect, use, and disclose personal information with your consent, except where the law allows us to proceed without it. Consent may be express (for example, when you submit a form or tick a box) or implied by your conduct (for example, when you email us asking for a reply).
You may withdraw your consent at any time, subject to legal and contractual restrictions and reasonable notice. If you withdraw consent, we may no longer be able to provide something that depends on that information.
There are limited situations where the law allows us to collect, use, or disclose personal information without consent. These include where it is required by law, where we must comply with a subpoena, warrant, or court order, where we need to collect a debt, where it is needed to investigate a breach of an agreement or a contravention of law, where there is an emergency that threatens someone's life, health, or security, and where we need advice from our lawyers or other professional advisers.
6. Email and Canada's anti-spam law
We follow Canada's Anti-Spam Legislation (CASL). When we send a commercial electronic message, we have your consent, we identify ourselves, we include our mailing address and a way to reach us, and every message includes a working unsubscribe mechanism. If you unsubscribe, we act on it within 10 business days. We do not bury consent in fine print, and we do not use pre-ticked boxes.
7. Cookies and analytics
Our site uses cookies and similar technologies for two reasons: to make the site work, and to understand how it is used.
Essential cookies are required for the site to function. Analytics cookies tell us which pages are read and how visitors arrive, in aggregate. Analytics data is used to improve the site, not to build profiles of individuals.
You can control and delete cookies through your browser settings. If you block cookies, parts of the site may not work as intended. If you are in Quebec, we ask for your consent before placing non-essential cookies on your device.
8. When we share information
We do not sell, rent, trade, or licence personal information. We share it only in these situations:
- Service providers. Companies that help us run our business, such as our web hosting provider, email and communications providers, analytics providers, and accounting and payment services. They may use the information only to provide their service to us, and we require them to protect it.
- Professional advisers. Our lawyers, accountants, and insurers, where needed.
- Legal requirements. Where we are required or permitted by law, including in response to a lawful request from a public authority. Where a request comes from an organization claiming legal authority, we take reasonable steps to confirm that authority.
- A business transaction. If we merge, amalgamate, sell assets, or are otherwise reorganized, personal information may be transferred as part of that transaction. The receiving organization would be required to protect it consistent with PIPEDA and this policy.
- With your consent. Any other sharing happens only with your consent.
9. Where your information is stored
We are based in Canada. Some of the service providers we rely on store or process information in Canada, the United States, or the European Union. Information handled outside Canada is subject to the laws of the jurisdiction where it is held, and a foreign government may be able to obtain access to it under a lawful order.
We remain responsible for personal information under our control. We use contractual and technical measures to keep the level of protection consistent with PIPEDA, and where we transfer information of individuals in Quebec outside Quebec, we complete a privacy impact assessment as Law 25 requires.
10. How long we keep it
We keep personal information only as long as we need it for the purposes described in this policy, or as long as the law requires. Retention periods depend on the type of information: enquiry records, client project records, invoices and tax records, and security logs each have their own life.
When information is no longer needed, we destroy or erase it securely, having regard to how sensitive it is. We keep records of any breach of security safeguards for at least two years, as the Breach of Security Safeguards Regulations require, whether or not the breach had to be reported.
11. How we protect it
We use safeguards that reflect the sensitivity of the information we hold. These include access controls and least-privilege permissions, encrypted connections, secure storage, account and device security, and reviews of the vendors we work with. Only people who need access to do their work have it, and everyone who handles personal information is expected to follow this policy.
Two honest caveats. Email is not a secure channel, so please do not send us sensitive information such as passwords, identity documents, or payment details by email. And we will never send you an email asking you to click a link and enter personal information. If you receive a message that appears to come from us and asks for that, treat it as fraudulent and tell us.
12. If there is a breach
If a breach of our security safeguards involves personal information and it is reasonable to believe that the breach creates a real risk of significant harm, we report it to the Privacy Commissioner of Canada as soon as feasible and notify affected individuals directly. The notification explains what happened, what information was involved, what we have done, and what the person can do to reduce the risk of harm. We also keep a record of every breach of security safeguards under our control, whether or not it had to be reported.
13. Your rights
You have the right to:
- Know. Ask what personal information we hold about you, how we use it, and to whom we have disclosed it.
- Access. Request a copy of that information.
- Correct. Ask us to correct information that is inaccurate or incomplete.
- Withdraw consent. Ask us to stop collecting, using, or disclosing your information, subject to legal and contractual limits.
- Complain. Raise a concern with us, and if you are not satisfied, with the Privacy Commissioner of Canada.
To make a request, use the contact details in section 16. We will ask for enough information to confirm your identity, and we use that information only for that purpose. We respond within 30 days, or explain why we need more time. There is normally no cost. If a request is unusually large, we may charge a reasonable fee, and we will tell you before doing any work.
In some circumstances we cannot give access, for example where it would reveal personal information about another person, where it would threaten someone's life or security, where it would reveal confidential commercial information, where it is protected by privilege, or where it was created in relation to a settlement or the investigation of a breach of law. If we refuse, we explain why and tell you how to challenge the decision.
14. Children
Our services are for businesses and our site is not directed at children. We do not knowingly collect personal information from anyone under 18. If you believe a child has given us personal information, contact us and we will delete it.
15. Links to other sites
Our site may link to websites we do not control. Their privacy practices are their own and this policy does not cover them. Read the privacy policy of any site you visit.
16. How to contact us
Hoardy, a brand of 11371096 Canada Inc. Privacy contact: contact@hoardy.ai Contact form: hoardy.ai/#contact Registered office: 220 Missinnihe Way, Suite 1411, Mississauga, Ontario L5H 0A9, Canada
If you are not satisfied with how we have handled your concern, you may contact the Office of the Privacy Commissioner of Canada:
Office of the Privacy Commissioner of Canada 30 Victoria Street Gatineau, Quebec K1A 1H3 Toll-free: 1-800-282-1376 Telephone: 819-994-5444 priv.gc.ca
17. Changes to this policy
We review this policy regularly and update it when our practices or the law change. The effective date at the top of this page tells you which version you are reading. If a change is significant, we will make that clear on our site.
Questions about this policy? Contact us.
