QILAK

Privacy policy

Qilak Ontario, Canada — Business Number: 1001635924 Last updated: June 26, 2026

Qilak respects your privacy and is committed to handling personal information in accordance with Canadian privacy law, including the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable Ontario legislation. Where we process personal data of individuals in the European Economic Area or the United Kingdom on behalf of our customers, we do so in accordance with the EU and UK General Data Protection Regulations.

This Privacy Policy applies to personal information Qilak collects in connection with its website, sales process, and direct provision of Services to business customers. It does not describe how our customers handle the personal information of their own end users on the Services — that is governed by each customer's own privacy policy.

1. Who We Are

The data controller for personal information described in this policy is:

Qilak 5-926 Dillingham Road Pickering, Ontario, Canada L1W 1Z6 Privacy Officer: [email protected]

2. Information We Collect

a. Information you provide directly.

  • Business contact information: name, business email, phone, role, company name and address.
  • Account credentials and authentication information.
  • Billing information: business address, payment card details (handled by our payment processor; we do not store full card numbers), tax registration numbers.
  • Support communications: tickets, emails, chat transcripts, call recordings (where notice is given).
  • Information you submit through our website, including form submissions and abuse reports.

b. Information collected automatically.

  • Service usage data: bandwidth, resource utilization, uptime, API and control panel access logs.
  • Network logs: source/destination IPs, ports, traffic volumes, and metadata necessary to operate the network and investigate abuse.
  • Website analytics: pages viewed, referring URL, browser and device information, IP address, approximate location derived from IP.
  • Cookies and similar technologies (see Section 8).

c. Information from third parties.

  • Credit and fraud checks from third-party providers (Fraud Record, credit bureaus) for new accounts and chargeback disputes.
  • Threat intelligence: block list status, reported abuse from third parties.
  • Public business registries and similar sources during onboarding.

3. How We Use Information

We use personal information to:

a. Provide and operate the Services and our network; b. Authenticate users, secure accounts, and prevent fraud and abuse; c. Bill and collect payment, and manage accounts receivable; d. Communicate with customers about Services, including service notices, maintenance, security advisories, and changes to terms; e. Provide support and respond to inquiries; f. Investigate suspected violations of our AUP, terms, or applicable law; g. Comply with legal obligations, respond to lawful access requests, and enforce our rights; h. Improve the Services and develop new features; i. Send marketing communications, where permitted by CASL and applicable law (see Section 9).

4. Legal Basis for Processing (PIPEDA, GDPR)

Under PIPEDA, we collect, use, and disclose personal information with consent (express or implied) or as otherwise permitted by law. Under the GDPR, where applicable, our legal bases are:

a. Contract — to enter into and perform contracts with you; b. Legitimate interests — to operate and secure our network, prevent fraud, and conduct ordinary business; c. Legal obligation — to comply with tax, accounting, and law-enforcement requirements; d. Consent — for direct marketing, where required.

You may withdraw consent at any time, subject to legal or contractual restrictions, by contacting [email protected].

5. Disclosure of Information

We share personal information with:

a. Sub-processors and service providers who help us operate the Services, including data centre operators, payment processors, fraud prevention services, email delivery providers, and IT/security service providers. These parties are contractually required to protect personal information.

b. Affiliates within the Qilak corporate group, for the purposes described in this policy.

c. Law enforcement and regulators, in response to a valid court order, production order, subpoena, or other lawful request, or where required by law. Where permitted, we notify the affected customer first.

d. Professional advisors, including legal counsel and auditors, under confidentiality obligations.

e. In a corporate transaction, such as a merger, acquisition, or sale of assets, subject to appropriate confidentiality protections.

We do not sell personal information.

6. International Transfers and Data Location

a. Primary storage. Customer Data and account information are stored primarily in Canadian data centres.

b. Cross-border processing. Some sub-processors (e.g., payment processors, certain analytics or email providers) may process personal information outside Canada, including in the United States and the European Union. When personal information is processed outside Canada, it may be subject to the laws of that jurisdiction, including lawful access by foreign government authorities.

c. Transfer safeguards. For transfers from the EEA or UK, we rely on standard contractual clauses or equivalent safeguards. A current list of sub-processors and processing locations is available on request to [email protected].

7. Retention

We retain personal information only as long as necessary for the purposes for which it was collected, including to comply with legal, tax, and accounting requirements.

| Category | Retention period | |---|---| | Active account records | Duration of account + 7 years (tax/accounting) | | Billing records | 7 years (Canada Revenue Agency requirements) | | Support tickets | 3 years from closure | | Network logs | 90 days, except where retained for abuse or legal investigation | | Abuse investigation records | Up to 365 days after closure, longer if required by law | | Marketing consents and unsubscribe records | 3 years after last activity (CASL) | | Website analytics | 26 months |

After the applicable retention period, personal information is securely deleted or anonymized.

8. Cookies and Similar Technologies

Our website uses cookies and similar technologies for: essential site functionality, authentication, preference storage, security, and analytics. You can control cookies through your browser. Disabling cookies may limit functionality. Where required, we obtain consent through a cookie banner before non-essential cookies are set.

9. Marketing Communications and CASL

a. We send commercial electronic messages only with the express or implied consent required by CASL, with sender identification, and with a working unsubscribe mechanism.

b. You may unsubscribe at any time using the link in any marketing message or by emailing [email protected]. Unsubscribe requests are honoured within ten (10) business days, as required by CASL.

c. Transactional messages (billing, service notices, security advisories) are not marketing and may continue after you unsubscribe.

10. Your Rights

Under PIPEDA, GDPR, and other applicable law, you may have the right to:

a. Access the personal information we hold about you; b. Correct inaccurate or incomplete information; c. Withdraw consent for processing that relies on consent; d. Erase personal information, subject to legal and contractual exceptions; e. Restrict or object to certain processing; f. Port your personal information to another provider (GDPR); g. Complain to a regulator — in Canada, the Office of the Privacy Commissioner (priv.gc.ca); in Ontario, the Information and Privacy Commissioner (ipc.on.ca); in the EU, your national supervisory authority.

To exercise these rights, contact [email protected]. We respond within thirty (30) days of receiving a verifiable request. We may need to verify your identity before acting.

11. Security

We maintain administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, disclosure, loss, or alteration. Safeguards include access controls, encryption in transit and where appropriate at rest, network segmentation, logging, vulnerability management, and employee training. No safeguards are perfect — we cannot guarantee absolute security.

In the event of a privacy breach involving a real risk of significant harm, we notify affected individuals, the Office of the Privacy Commissioner of Canada, and other regulators as required by law, and maintain records as required under PIPEDA's breach reporting regulations.

12. Children

The Services are intended for business customers and are not directed at children. We do not knowingly collect personal information from children under the age of 13 (or higher where required by local law). If you believe we have inadvertently collected such information, contact [email protected].

13. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated by email to account contacts and posted on our website with an updated "Last updated" date at least thirty (30) days before they take effect.

14. Contact

Privacy Officer [email protected] Qilak 5-926 Dillingham Road Pickering, Ontario, Canada L1W 1Z6

If you are not satisfied with our response to a privacy concern, you may contact:

  • Office of the Privacy Commissioner of Canada — 1-800-282-1376 — priv.gc.ca
  • Information and Privacy Commissioner of Ontario — 1-800-387-0073 — ipc.on.ca