| Field | Value |
|---|---|
| Legal entity | CYBER WAVE INC. |
| Version | PRIVACY_2026_09_V1 |
| Effective date | 2026-09-13 |
| Contact | support@cyberwave.ca |
1. Who we are, and what this policy is
CYBER WAVE INC., a corporation existing under the laws of Ontario, Canada (Ontario Corporation Number 1000780137), located in Markham, Ontario, Canada ("CyberWave", "we", "us" or "our") provides CyberWave Sentinel, a cybersecurity readiness platform, together with related advisory and readiness services.
This policy explains what personal information we handle, why, who we share it with, where it is processed, how long we keep it, and what you can do about it. Where we cannot yet honour something we would like to promise, we say so instead of promising it.
It applies to the cyberwave.ca website, the CyberWave Sentinel application at sentinel.cyberwave.ca, and CyberWave's advisory and readiness services. Read it together with our Terms of Service, Cookie Notice, Data Processing Addendum, Subprocessors list and AI Features & Data Use Notice.
CyberWave is subject to Canada's Personal Information Protection and Electronic Documents Act ("PIPEDA"), which has no small-business exemption and no revenue threshold; selling only to businesses does not remove us from it. Provincial privacy law — including Quebec's private-sector Act — may apply in addition, not instead. Section 20 maps PIPEDA's ten principles to the parts of this policy that give them effect.
The audience for the Services. They are sold to organisations for business use. When you accept the Terms or create an account, you represent that you are of legal age to contract, that you are using the Services for business or professional purposes and not for personal, family or household purposes, and that you have authority to bind the organisation you act for. Where mandatory consumer protection or privacy law nonetheless applies to you, that law prevails over anything here that would give you less. A term of ours that conflicts with a mandatory right is read down, not enforced.
Not covered here: our own personnel and job applicants, whose employment information is handled separately; a customer's own notice obligations for what it puts into its workspace (Part B); and third-party sites we link to.
What CyberWave is not — stated here because privacy expectations follow from what a product actually is:
- Sentinel supports readiness, governance, assessment, evidence organisation and control management. CyberWave does not certify compliance, issue audit opinions, guarantee compliance, or replace independent auditors, certification bodies or legal counsel. Framework references are informational readiness mappings.
- CyberWave is not an insurer or an insurance broker. We do not bind coverage and do not guarantee coverage, premium reduction, claim payment or insurer acceptance. You remain responsible for complete and truthful representations to your insurer or broker.
- We do not operate a security operations centre or provide 24/7 monitoring, and we do not provide managed detection and response, incident response retainers, penetration testing or forensics. Nothing here commits us to monitor your environment or detect an incident inside your systems.
- AI features are assistive and optional. Outputs may contain errors, must be reviewed, and do not replace professional judgement. You remain responsible for decisions made using them.
2. Defined terms
| Term | Meaning |
|---|---|
| Personal information | Information about an identifiable individual, read broadly: a work email used as a credential, an account id tied to a person, an IP address in a security record, an audit trail, or a free-text field naming someone. |
| Customer | The organisation with a subscription, or evaluating one on a trial. |
| Customer Data | Everything a Customer or its users put into or generate inside a Sentinel workspace: policies, risks, vendor records, control registers, assessments, uploaded evidence, comments, actions, reports and AI results. |
| Authorised User | An individual a Customer permits to use its workspace. |
3. The two roles — the distinction that shapes this policy
Most small-vendor policies fail the same way: they describe one relationship, then cover two different ones with the same sentences. CyberWave handles personal information in two capacities, and "why is this here?" and "who do I ask?" have different answers in each.
| Role A — our own purposes | Role B — on a Customer's instructions | |
|---|---|---|
| Whose information | Website visitors, trial and account holders, Authorised Users, billing contacts, support correspondents, people who make sales enquiries | Individuals described inside a Customer's workspace: its personnel, control owners, vendor contacts, anyone named in evidence |
| Who decides why it is held | CyberWave | The Customer |
| Accountable for lawful authority and notice | CyberWave | The Customer |
| Rules | This policy | This policy (Part B), the DPA, the Terms |
| Where a request goes | To us — section 18 | Ordinarily to the Customer — section 6.4 |
PIPEDA does not use "controller" and "processor"; its obligations follow control and purpose. So this is not a convenient label — it describes who actually decides why each piece of information exists. Section 6.6 sets out the things we will not do that would cross the line.
PART A — INFORMATION WE HANDLE FOR OUR OWN PURPOSES
4. What we collect in Role A
This lists what we actually collect — and section 4.5 lists what we do not, because over-disclosing misrepresents where data goes just as surely as under-disclosing.
4.1 Website visitors — cyberwave.ca
When you visit the website we receive ordinary request metadata: IP address, page requested, timestamps, referring page, and the browser and device information your browser sends. The website is hosted by Vercel in the United States (section 11).
The website uses no analytics, advertising or tracking cookies or scripts. Section 10 covers cookies and similar technologies.
4.2 Trial and account holders, and Authorised Users
| What | Why we have it |
|---|---|
| Name and work email address | To create and identify your account |
| Sign-in identity and authentication records, incl. session and refresh tokens | To keep you signed in, and let you sign out everywhere |
| Organisation (tenant) membership and role | To decide what you may see and do |
| Invitation records | To let an administrator add a colleague, and show who invited whom |
| Workspace activity in our audit trail | Security, internal accountability, abuse prevention |
| A timestamped record of your acceptance of the Terms and this policy | To show what you agreed to, and when |
Trials. A 14-day free trial is available on Essentials or Full Platform, and it is a trial of the plan you select. No payment card is required. There is no automatic charge and no automatic conversion to a paid subscription. Because no card is required, starting a trial collects no payment information. A trial is not a paid plan and includes no fees. Continuing after the trial means choosing a paid subscription — your data is not deleted because a trial ended. What happens to it afterwards is governed by section 12, not by trial expiry. Plan names, included users and prices are set out in the Terms and on the pricing page, in USD.
4.3 Billing, support and sales contacts
Billing: for a paid subscription, the billing contact's name and email, the organisation name, plan and number of users, and subscription, invoice and payment records. Payments are processed by Stripe. Card details are entered directly with Stripe and never reach CyberWave systems — we see that a payment succeeded or failed and the plan, not your card number.
Support: if you write to support@cyberwave.ca we receive whatever you put in the message, including attachments, in a Microsoft 365 mailbox provided through GoDaddy. Please do not send credentials, or paste more of your people's personal information into a support email than the question needs.
Sales enquiries: if you contact us about the Services — including plans and services arranged through a conversation with us, such as Managed vCISO Lite, Managed vCISO, a Custom arrangement or the Cyber Insurance Submission Pack — we receive what you send us, typically your name, work email, organisation and the request you made, and use it to answer you. We do not send marketing email (section 9).
4.4 Security, integrity and abuse-prevention records
Authentication and access audit records; application error records, written to an internal log inside our own Canadian database because we use no third-party error-tracking service; short-lived abuse-prevention counters keyed to the requester; and readiness score snapshots generated from a Customer's own workspace.
4.5 What we do not collect
Stated because the absence is meaningful:
- No analytics or tracking cookies or scripts, and no product behavioural analytics, on the website or in the application.
- No advertising or retargeting technology on the website or in the application — no advertising cookie, no pixel, no conversion tag, no cross-site tracker.
- No third-party error tracking or session replay.
- No card, bank or government identification numbers; no biometric information; no precise geolocation; no device fingerprinting.
- No live integrations pulling data from your identity, endpoint, service-management or productivity platforms. Integrations exist only as connection templates and configuration, and webhooks and API keys are disabled.
5. Why we handle it — our identified purposes
PIPEDA requires purposes identified at or before collection, in specific terms. "To improve our services" is not a purpose. Ours are:
| Purpose | Basis |
|---|---|
| Create and secure your account; authenticate you | Necessary for a service you asked for |
| Provide the Services you subscribed to | Necessary to provide the Services |
| Bill you and keep financial records | Contract performance; partly required by law |
| Send service, security, account and billing messages | Necessary to operate your account |
| Answer support and sales enquiries | Consent implied by your enquiry |
| Keep the Services secure; prevent abuse, fraud, unauthorised access | Operational necessity, and an obligation to our other customers |
| Meet legal, tax and accounting obligations; establish or defend claims | Legal requirement |
Marketing is not among these purposes: we do not send marketing email and do not collect marketing consent (section 9).
Two commitments follow, meant literally. Every use must pass a reasonableness test independent of consent — a purpose that survives only because someone clicked "accept" is not one we will pursue. And we do not repurpose information you have already given us without identifying the new purpose and obtaining consent first. Editing this policy afterwards is not a substitute for asking.
PART B — CUSTOMER DATA WE PROCESS ON A CUSTOMER'S INSTRUCTIONS
6. Personal information inside a Customer's workspace
6.1 What it may contain
A readiness programme is, in practice, a description of an organisation and the people who run it. A workspace may therefore contain personal information about individuals with no direct relationship with CyberWave: named control owners, risk owners, assignees, approvers and authors; vendor, supplier, broker and advisor contacts; individuals named inside uploaded evidence such as policy acknowledgements, access reviews, training records, minutes and incident notes; and anything else typed into a free-text field.
Some of this is sensitive in context though none of it is a "sensitive category" by label: a record that a named individual owns a failing control can create real risk of harm to that person if exposed. So: please do not paste an employee roster into a free-text evidence field when a role name would do.
6.2 Who decides why it is there, and who can see it
The Customer does. It determines the purposes, decides what may be collected, and is responsible for lawful authority, including any consent or notice its people or vendors are owed. We process Customer Data to provide, support and secure the Services and otherwise on the Customer's documented instructions; we do not decide what belongs in a workspace. The Data Processing Addendum sets this out contractually.
Our access is limited to what is needed to deliver, support, secure and bill the Services, and is subject to the confidentiality obligations in the Terms of Service. Beyond what operating and securing the Services requires, three situations put a person at CyberWave inside a workspace: support, when a Customer asks us to look at something; Managed vCISO Lite and Managed vCISO, where a CyberWave advisor works with the Customer (for Managed vCISO, on the scope and cadence agreed in a statement of work); and the Cyber Insurance Submission Pack, which a Customer arranges by contacting us and for which our personnel assemble a submission package from the Customer's own content. Each is on the Customer's instructions. On Managed vCISO Lite the CyberWave advisor does not use one of the plan's 5 included users.
6.3 Tenant separation
Sentinel is multi-tenant. Separation between Customers is enforced by PostgreSQL row-level security in the database and by server-side authorisation in the application — not by interface behaviour, and not by instructions written into an AI prompt.
6.4 Where a data-subject request goes
If you are an individual whose information appears inside a Customer's workspace — an employee or vendor contact of one of our Customers — the organisation that put it there is the right place to start. It decides what is held and why, and can act on your request directly in the product.
If you contact us instead, we will not simply refuse on the basis that our contract is with your employer. We will acknowledge your request promptly; not disclose the contents of a Customer's workspace without that Customer's authority, because that would itself be an unauthorised disclosure; refer the request to that Customer and tell you so, unless legally prevented; and, where PIPEDA obliges us as an organisation in control of the information — as it does for Part A — respond to you directly under section 18.
6.5 AI features
Full detail is in the AI Features & Data Use Notice. AI features are assistive and optional; their outputs may contain errors and must be reviewed before anyone relies on them.
What is sent. A signed-in user triggers a feature; our server authorises the caller and resolves their tenant; and the request is sent from our servers — never from your browser — to Anthropic, our AI model provider, in the United States. A request contains the item the user asked about and, often, a summary drawn from that tenant's own workspace: record names, statuses, counts and saved answers. Content goes to the provider only to fulfil the request the user made; what the provider may do with it is governed by its own commercial terms.
What is not sent. No AI model reads uploaded evidence files: evidence uploads receive text extraction and keyword classification only. Policy review and contract review do send document text to the model: policy review sends the policy text, and contract review sends the contract text the user pastes.
What is kept. We store each AI result in the Customer's workspace: the output, a short summary, and a short excerpt or label of the request of up to 300 characters. We also record a short excerpt of the request in an append-only audit log. Some features write AI output directly into workspace records — for example vendor and contract summaries and evidence review notes — where it becomes part of those records.
Usage limits. AI use is metered against a monthly credit allowance that depends on the plan. A request is declined when the remaining allowance is too low. There is no automatic overage charge; extra usage, where offered, is an optional purchase an owner or admin chooses.
6.6 What we will not do with Customer Data
Using Customer Data for a purpose of our own would make us the organisation accountable for it, acquiring consent, notice, access and breach duties toward people we have never met. That must not happen by accident in a product decision.
- We do not sell, rent or trade Customer Data.
- We do not use Customer Data to train or fine-tune AI models. There is no training pipeline, no fine-tuning job and no export of customer content for model development anywhere in our system. This is a statement about our own conduct; what our AI provider may do with content sent to it is governed by its own commercial terms (section 6.5).
- We do not aggregate one Customer's data with another's to produce cross-tenant benchmarks, industry comparisons, threat-intelligence products or marketing statistics.
- We do not use Customer Data in case studies, sales demonstrations or marketing material.
- Any of these would require a separate, express, unbundled opt-in obtained in advance and independently refusable without degrading the core service — and a privacy review before the feature was built.
PART C — HOW WE HANDLE IT
7. Consent, and what is genuinely optional
Notice. This policy tells you what we collect, what we do with it, who we share it with, and the meaningful risks. Where a decision carries particular privacy weight — inviting a colleague, uploading evidence that may name employees, or using a feature that sends content to the AI provider — sections 4.2, 6.1 and 6.5 describe what happens, so you can weigh it before you act.
No bundling. None of the following is a condition of using the Services. If we offer any of them, it will be optional and independently refusable, refusing it will not degrade the core service, and refusing will be as easy as accepting: marketing email; product analytics; use of your organisation's name or content in a case study; any use of Customer Data beyond providing the Services. We do not send marketing email or use product analytics.
The B2B wrinkle is real. The organisation that signs a contract is not the individual whose consent PIPEDA contemplates, and a clause inside a subscription agreement that an Authorised User never saw does not obtain that user's consent to anything. So where we act for our own purposes toward an individual — creating their account or emailing them — we give that individual notice, or obtain consent, at the point of collection.
Withdrawal. You may withdraw consent to anything optional at any time (section 18.4). We tell you the consequences rather than let you discover them: withdrawing consent to something the Services genuinely require means you can no longer use that feature, and in some cases the account.
8. Accuracy
We keep personal information as accurate, complete and up to date as its purpose requires. You can correct your own profile in the product; section 18.2 covers the rest.
One case deserves particular care. Sentinel produces output that attributes things to named people: a control owner, an action assignee, a finding recording who is responsible for a gap. An incorrect attribution of that kind is the specific harm the accuracy principle exists to prevent. Where it sits in a Customer's workspace, the Customer can correct it and is the right party to ask. Where it is ours, we correct it and push the correction to any downstream system holding a copy.
9. Marketing, and Canada's anti-spam law
Canada's Anti-Spam Legislation ("CASL") governs commercial electronic messages sent to recipients in Canada.
We do not send marketing email, and we do not collect marketing consent.
| Message type | Examples | What we do |
|---|---|---|
| Service, security, account and billing | Sign-up confirmation, password reset, workspace invitation, security or account notices, billing and payment messages, notice of a material change to this policy | Sent as needed to operate your account. There is no unsubscribe, because they are required. |
| Marketing | Product news, offers, event invitations, newsletters, upgrade promotions | Not sent. |
Accepting the Terms of Service is not consent to marketing. No clause in our Terms or this policy tries to obtain marketing consent by acceptance of those terms, and we use no purchased, rented or scraped contact lists.
If that ever changes. Marketing would be a new purpose under section 5, so we would identify it before sending any marketing message, and would send one only with separate express consent or where a documented business-relationship basis genuinely applies. Any express consent would be separate from acceptance of the Terms, optional, never pre-checked, recorded, used only for the purpose it was given for, and withdrawable at any time. Every marketing message would carry a working unsubscribe link and our identification details, and we would give effect to an unsubscribe without delay and well inside the ten business days CASL allows.
Opting out of marketing would never stop the service, security, account and billing messages required to operate your account. Conflating the two would mean a customer who wanted fewer newsletters stopped receiving security notices.
10. Cookies and similar technologies
Full detail is in the Cookie Notice. In summary:
The Sentinel application. Essential authentication session cookies, set by Supabase, keep you signed in; without them there is no session. The application also keeps several entries in your browser's localStorage to hold interface state, and uses a service worker that keeps an offline cache of pages on your device. There are no analytics, advertising or tracking cookies or scripts.
The website. The cyberwave.ca website, hosted by Vercel, has no analytics, advertising or tracking cookies or scripts.
No consent banner, because nothing needs one. We set no non-essential cookie, so there is no cookie consent banner or cookie settings control. If we ever deploy a non-essential cookie, we will ask first, per category, with a control as easy to refuse as to accept. See section 16.
11. Service providers, and where your information is processed
We do not say that all data stays in Canada, because it does not. Our primary datastore is in Canada, which is real and deliberate. But the application and the website run on United States infrastructure, and several supporting services process data outside Canada. The accurate statement: Customer Data is stored primarily in Canada. Application hosting, AI features, email delivery, payment processing and our support mailbox involve service providers that may process data outside Canada, including in the United States.
| Provider | What it does | What it can see | Location |
|---|---|---|---|
| Supabase | Database, authentication, file storage | Account records, tenant data, uploaded evidence, assessments, AI results, audit records, billing metadata | Canada (ca-central-1) |
| Vercel | Hosting and compute for the application; hosting for the cyberwave.ca website | Any data in transit through a request to the application or the website. No primary storage. | United States |
| Anthropic | AI model provider, called from our servers and never from your browser | Content in an AI request made by a signed-in user: the item asked about and, often, a summary of that tenant's workspace (section 6.5) | United States |
| Stripe | Payment processing for paid subscriptions | Billing contact, organisation name, subscription and payment records. Card data goes directly to Stripe. | United States / global |
| Resend | Application email, and account emails such as sign-up confirmation and password reset | Recipient address and message content | United States |
| GoDaddy, including Microsoft 365 mail provided through GoDaddy | Domain registration and DNS; the support@cyberwave.ca mailbox | For the mailbox, anything you put in an email to us | May be processed outside Canada |
The Subprocessors document lists our service providers, and also explains providers that appear in our source code but are not configured in production and therefore receive nothing.
Foreign lawful access. While personal information is processed outside Canada it is subject to the laws of the country where it is processed. That includes the possibility of lawful access by that country's courts, law enforcement and national security authorities, on terms we do not control and without any obligation to notify us. That is a material fact about the service, not a technicality.
Our accountability does not transfer. Under PIPEDA, transferring information to a service provider for processing is a use, not a disclosure. It needs no separate consent per provider — and reduces our accountability not at all. A provider using your information for its own purposes would be a disclosure and a different question entirely.
Other disclosures. Only: with your consent or on a Customer's instruction; where required by law or by a valid legal demand — assessed on its validity rather than accepted on receipt, and challenged or narrowed where overbroad; to protect our rights, safety or the security of the Services and investigate suspected abuse; to professional advisors under confidentiality duties; and in a merger, acquisition, financing or sale of assets, where the information stays subject to a policy no less protective than this one.
12. How long we keep it, and what deletion actually does
We keep personal information only as long as the identified purpose requires, plus any period the law requires. This policy describes what deletion does rather than stating fixed retention periods.
12.1 Deletion in the active systems
| Data | What deletion looks like |
|---|---|
| Tenant records — policies, risks, vendors, evidence metadata, assessments, actions | A Customer can delete individual records in the product. Deleting a whole workspace is not a self-service action: the Customer requests it by contacting support at support@cyberwave.ca. Owners and admins can export workspace data in the product first. |
| Uploaded evidence files | Deleted through the application |
| AI results stored in the workspace | Held as part of the Customer's workspace (section 6.5). AI output that a feature wrote into a workspace record is part of that record. |
| Workspace audit log, including short excerpts of AI requests | Append-only by design. Entries are not edited or removed through the product. |
| Accounts and sessions | Deleted by us through the authentication platform |
| Readiness score snapshots | No automatic expiry |
| Application error records | Kept in our Canadian database; no fixed retention period is stated |
| Abuse-prevention counters | Short-lived |
| Your acceptance of the Terms and this policy | Append-only by design. See 12.3 |
| Billing records | Stripe's retention, plus statutory financial-record retention |
| Transactional email | The email provider's retention |
| Support correspondence | In the mailbox; deleted manually |
12.2 Backups — described separately, and honestly
Our database platform maintains managed backups on its own schedule and lifecycle. A backup is not the active database, and deletion in the active database does not reach into a backup already taken. We cannot selectively remove one record, or one tenant, from a backup snapshot.
What we can truthfully say: once information is deleted from the active systems it stops being available to you, to us and to the Services. Any copy remaining in a backup is used for no other purpose, remains subject to the same security and confidentiality obligations, and ages out with that lifecycle.
We will not tell you your data has been permanently and immediately erased everywhere, because that would be false. A vendor selling security readiness should not make a deletion promise its own architecture contradicts.
12.3 Two deliberate exceptions, and one clarification
Consent and acceptance records. The record that you accepted the Terms and this policy, at a particular time, is append-only; its whole purpose is to survive. Deleting it would destroy the evidence of the agreement it documents. If you ask us to delete your information we will tell you which records fall here.
Requests in progress. Where you have made an access request we must retain the information it concerns until your recourse is exhausted; deletion can be suspended for an individual for that reason.
Trials, again, because it matters. Your data is not deleted because a trial ended. The end of a trial is not a deletion event. Deletion happens on request (sections 12.1 and 18.3).
13. How we protect it
We apply safeguards proportionate to sensitivity. They include separation between Customers enforced by PostgreSQL row-level security and server-side authorisation (section 6.3); hosting our database, authentication and file storage in Canada (ca-central-1); and encryption of data in transit using HTTPS.
Two honest caveats. No service can promise a breach is impossible, and we do not. And we do not operate a security operations centre or provide 24/7 monitoring — we do not monitor your internal environment.
14. If there is a security incident
- For information we control (Part A): where an incident creates a real risk of significant harm to an individual, we report it to the Office of the Privacy Commissioner of Canada and notify affected individuals directly, as soon as feasible. The trigger is risk to a single individual; there is no volume threshold, and loss or unauthorised access counts whether or not anything was exfiltrated. We also notify any other organisation that could reduce the resulting harm.
- For Customer Data (Part B): the Customer is ordinarily the organisation that must assess and report. Our obligation is to notify it and give it what it needs to make that assessment and meet its own deadline. Timing is set in the Data Processing Addendum, section 11. We will not commit to a fixed hour count we have not tested; no Canadian privacy statute requires one, and a promise missed during a real incident is worse than an honest one kept.
- Where we hold no contact details for people described inside a workspace we cannot notify them directly, so we work with the Customer, which does.
To report a vulnerability, see our Responsible Disclosure Policy; to report a suspected incident, email support@cyberwave.ca with "Security" in the subject line.
15. Children
The Services are business tools sold to organisations. They are not directed at children, we do not knowingly collect personal information from children, and we do not knowingly solicit it. If you believe a child has given us personal information, contact CyberWave's privacy contact at support@cyberwave.ca (subject: Privacy) and we will delete it.
This conclusion is recorded deliberately rather than inherited. Creating an account includes the business-use representation in section 1, and we will revisit this conclusion if we ever offer a free public tier, a public community, an awareness product for general audiences, or anything sold into schools.
16. "Selling" personal information, and advertising
We do not sell, rent or trade personal information. That is not careful wording; it describes the technical facts: there is no advertising technology on the website or in the application — no pixel, no conversion tag, no retargeting cookie, no data-broker integration; we run no cross-context behavioural advertising; and we disclose personal information to nobody for their own advertising purposes.
Advertising in future. CyberWave may run paid advertising. If that introduces advertising or measurement technology onto the website, it is a material change under section 21, and no non-essential cookie will be set before you are asked (section 10).
17. Automated processing
Sentinel generates readiness scores, insights, suggested actions and generated text. These are assistive outputs about an organisation's security posture, not decisions about individuals.
CyberWave does not use automated processing to make a decision about an individual. We do not score people and make no employment, credit, eligibility or access decisions about anyone. AI features decide nothing; a person does, and remains responsible. A Customer could use workspace output when deciding something about one of its own people — that is the Customer's responsibility, including any obligation to inform that individual and offer human review. Where such output names an individual, section 8 applies.
18. Your rights, and exactly how to use them
Send any request to CyberWave's privacy contact at support@cyberwave.ca (subject: Privacy), telling us what you want and enough about yourself for us to find your information. We may need to verify your identity, proportionately. We do not charge for responding to an access request.
We respond in writing within 30 days. If we need an extension permitted by law we tell you before the 30 days are up, with the reason and the new date. If we refuse, in whole or part, we tell you why in writing and how to complain.
18.1 Access. You may ask what personal information we hold about you, how we have used it, and to whom we have disclosed it or may have disclosed it. Two limits, stated up front. We must sever information that would reveal another person's personal information — a real constraint in a multi-user platform, because audit trails, comment threads and shared assessments routinely contain several people's information in one record, so we will not answer an access request by exporting a raw log. And where law requires or permits us to withhold something — privilege, an ongoing investigation, confidential commercial information — we say we have withheld it and on what basis. For a Customer's workspace, see section 6.4.
18.2 Correction. If information we hold about you is inaccurate or incomplete we correct it and pass the correction to any system or provider holding a copy. Where we disagree, we record the substance of your unresolved challenge alongside the information, so anyone later relying on the record sees it was disputed. That step is routinely skipped elsewhere; we treat it as mandatory.
18.3 Deletion, where applicable. We will delete personal information we hold about you where we no longer need it for an identified purpose and no legal or contractual requirement obliges us to keep it. Read section 12 first: it explains what deletion reaches, what can remain in a backup, and the records we deliberately keep. In a Customer's workspace, the Customer controls deletion, and a Customer may request deletion of a whole workspace by contacting support.
18.4 Withdrawing consent. You may withdraw consent to anything optional at any time. We tell you the consequences before they take effect. Withdrawal stops future use; it does not undo something lawfully done while consent was in place.
18.5 Marketing opt-out. We do not send marketing email. If that changes, you will be able to opt out as described in section 9. Service, security, account and billing messages continue regardless.
18.6 Portability, where applicable. Owners and admins can export workspace data in the product. Beyond that: in Quebec, you have a statutory right to receive computerised personal information you provided to us in a structured, commonly used technological format, unless that raises serious practical difficulties. Federally, a data-mobility right under PIPEDA is not in force, and we will not describe a right you do not yet have as though you had it.
19. Accountability, our privacy contact, and complaints
CyberWave is accountable for compliance with this policy and with PIPEDA. Privacy questions, requests and complaints go to CyberWave's privacy contact at support@cyberwave.ca (subject: Privacy).
- Email: support@cyberwave.ca — subject line "Privacy"
- Location: CYBER WAVE INC. is located in Markham, Ontario, Canada.
Please use the email route; putting "Privacy" in the subject line helps us recognise your message as a privacy request. There is no privacy@cyberwave.ca mailbox; if you have seen that address anywhere, it is wrong.
Challenging our compliance. If you think we have got something wrong, tell us. We acknowledge every complaint; we investigate every complaint, with no triage-out for ones we consider minor; we tell you the outcome in writing with reasons; and where a complaint is justified we change the practice, not just the answer. You can also complain to a regulator at any time, without coming to us first — the Office of the Privacy Commissioner of Canada (priv.gc.ca) under PIPEDA, the Commission d'accès à l'information du Québec (cai.gouv.qc.ca) if Quebec law applies to you, or the privacy commissioner of Alberta or British Columbia where theirs applies.
20. How this policy gives effect to PIPEDA's ten principles
Each principle is given effect in the sections named rather than restated here:
| # | Principle | Sections |
|---|---|---|
| 1 | Accountability — a published privacy contact, and accountability that does not transfer with the data | 19, 11 |
| 2 | Identifying purposes — specific, identified before collection, no silent repurposing | 5, 6.2, 7 |
| 3 | Consent — meaningful, unbundled, always withdrawable | 7, 9, 18.4 |
| 4 | Limiting collection — what a documented purpose needs, and we publish what we do not collect | 4, 4.5, 6.1 |
| 5 | Limiting use, disclosure, retention — no silent repurposing; deletion and backups described separately | 5, 6.6, 11, 12 |
| 6 | Accuracy — self-service correction, with care where an attribution names an individual | 8 |
| 7 | Safeguards — tenant isolation enforced in the database and the application; incident notification | 13, 6.3, 14 |
| 8 | Openness — one published policy, naming our providers and our foreign processing | 11, 19 |
| 9 | Individual access and correction — 30 days, no charge, severance, challenges recorded | 18 |
| 10 | Challenging compliance — every complaint investigated, and your route to a regulator | 19 |
21. Changes to this policy
- Versioning. Every version has a stable version string — this one is
PRIVACY_2026_09_V1— which is never reformatted or reused. When a version is superseded, it is archived and remains retrievable, not overwritten. - Non-material changes — clarifications, corrections, formatting — are published with a new version string and effective date.
- Material changes — a new purpose, a new category of collection, a new subprocessor location, or the introduction of advertising technology — are notified to account administrators by email before they take effect, with a plain-language summary of what changed and why.
- A new purpose requiring consent will be asked for, not announced. Subprocessor changes are published in the Subprocessors document, with advance notice as set out there. And statements here about Canadian law describe the law in force at the effective date of this version: where a bill has not become law, we do not describe it as though it had.
Contact. CyberWave's privacy contact at support@cyberwave.ca (subject: Privacy).
CyberWave Privacy Policy, version PRIVACY_2026_09_V1, effective 2026-09-13. © 2026 CyberWave.
Questions about this document: support@cyberwave.ca. See the full legal centre for related documents.