Great Lakes IT Inc.

Privacy Policy

Effective July 26, 2026

Great Lakes IT Inc. ("Great Lakes IT Inc.", "we", "us" or "our") provides managed IT, cybersecurity, cloud, software development, automation and AI consulting services. We understand that the organizations we work with trust us with access to their systems and information, and we treat that trust as central to how we operate.

This policy explains what personal information we collect through this website and through our business relationships, why we collect it, how we use and protect it, who we share it with, and the rights you have. It is written to be read by people rather than lawyers.

1. Scope and the laws that apply

This policy applies to personal information we collect through this website, through our contact and consultation forms, through email and telephone contact, and in the course of providing services to our clients.

We handle personal information in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA), Canada's federal private-sector privacy law, and its ten fair information principles. Depending on where you live or where an organization operates, additional legislation may also apply:

Quebec
Quebec's Act respecting the protection of personal information in the private sector, as amended by Law 25, applies to the personal information of Quebec residents regardless of our size or revenue. Additional rights for Quebec residents are described in section 12.
Alberta and British Columbia
The Personal Information Protection Act (PIPA) in each province applies to organizations operating there in place of PIPEDA for most commercial activity.
Commercial email
Canada's Anti-Spam Legislation (CASL) governs the commercial electronic messages we send. See section 14.

Where we act as a service provider processing personal information on behalf of a client, we handle that information under our written agreement with that client and under their instructions. That client remains accountable for the information, and their own privacy policy governs it. This policy governs the personal information for which we are accountable.

2. Personal information we collect

We collect only what we need. We do not require you to provide personal information in order to browse this website.

Information you give us directly. When you submit our contact or consultation form, we collect:

  • Your first and last name
  • Your work email address
  • Your telephone number, if you choose to provide it
  • Your organization name and, on the full contact form, its approximate size
  • Your preferred method of contact
  • The service you are interested in
  • The description of your project, question or requirement that you write in the message field
  • A record of the consent you give when submitting the form

We also collect the personal information you share with us over email, by telephone, in meetings, and during the course of an engagement — for example the names, business contact details and roles of the people we work with at a client organization.

Information collected automatically. Our hosting provider records standard technical information when a page is requested, including the IP address making the request, the browser and operating system reported by that browser, the page requested, and the date and time. These server logs exist to keep the site running, to diagnose faults and to detect abuse. We do not use them to build profiles of individual visitors.

Information we do not collect. We do not knowingly collect sensitive personal information through this website, such as health information, financial account details, government identifiers or biometric data. Please do not include information of that kind in the message field of our forms. If you need to send us sensitive information, contact us first and we will arrange a secure method.

3. Why we collect personal information

We identify our purposes before or at the time we collect personal information. We use it to:

  • Respond to your enquiry, quote request or consultation request
  • Understand what you need so we can recommend an appropriate approach
  • Prepare proposals, statements of work and service agreements
  • Deliver, support, monitor and improve the services our clients have engaged us to provide
  • Manage our client relationships, including billing, scheduling and account administration
  • Keep our own systems, and our clients' systems, secure and available
  • Meet our legal, regulatory, insurance, tax and professional obligations
  • Send service and administrative messages relating to work we are doing for you
  • Send commercial messages where you have consented to receive them, or where CASL otherwise permits

If we ever want to use personal information for a purpose that is materially different from the purposes above, we will identify that new purpose and obtain your consent before doing so, unless the law requires or permits otherwise.

5. Cookies, analytics and tracking

This website does not set advertising cookies, analytics cookies or social media tracking pixels. We do not operate behavioural advertising, and we do not track visitors across other websites.

Web fonts used on this site are served from our own domain rather than a third-party font service, so viewing a page does not disclose your visit to a font provider.

Our hosting provider may use strictly necessary cookies or equivalent technologies for security, fraud prevention and load balancing. These are required for the site to function and do not identify you personally for marketing purposes.

If we introduce web analytics or any other tracking technology in the future, we will update this policy before doing so, describe what is collected and why, and implement an appropriate consent mechanism. Most browsers also let you block or delete cookies through their settings.

6. How we share personal information

We do not sell personal information. We do not rent, trade or otherwise make personal information available to third parties for their own marketing purposes.

We disclose personal information only in these circumstances:

Service providers
We use third-party providers for website hosting, email delivery, business communications, scheduling, file storage, ticketing and accounting. They may process personal information on our behalf, only for the purposes we specify, and under contracts that require comparable protection.
Technology vendors used in delivering your services
Where an engagement requires it — for example a Microsoft 365 tenant, a cloud platform or a security tool — information may be processed by that vendor under the agreement you or we hold with them.
Professional advisors
Our lawyers, accountants, auditors and insurers, where they need the information to advise us and are bound by confidentiality obligations.
Legal requirements
Where disclosure is required or permitted by law, including in response to a valid court order, subpoena, warrant or lawful request from a government authority, or to investigate a suspected breach of an agreement or of the law.
Business transactions
In connection with a merger, acquisition, financing or sale of assets, personal information may be disclosed to the parties involved, subject to confidentiality protections and to the requirements of applicable privacy law.

7. Storage location and transfers outside Canada

We prefer service providers that store data in Canada, and we seek Canadian data residency where it is available and practical. However, some of the providers we rely on store or process information in the United States or other countries, or may access it from outside Canada for support purposes.

When personal information is held in another country, it is subject to the laws of that country, and courts, law enforcement and national security authorities there may be able to obtain access to it under those laws. This is true regardless of the contractual protections we put in place.

We remain accountable for personal information transferred to a service provider for processing, and we use contractual and other means to require a comparable level of protection. If you would like to know where the information relating to a specific engagement is stored, contact our Privacy Officer and we will tell you what we can.

8. How long we keep personal information

We keep personal information only as long as it is needed for the purpose it was collected for, or as long as the law requires us to keep it.

  • Enquiries that do not lead to an engagement are generally retained for up to two years so we can recognise follow-up contact and understand demand for our services.
  • Client records, contracts, project documentation and correspondence are retained for the duration of the relationship and then for the period required by our legal, tax, insurance and professional obligations.
  • Server logs are retained for a short operational period for security and troubleshooting.
  • Records relating to a privacy breach are retained for at least 24 months, as PIPEDA requires.

When personal information is no longer required, we destroy, erase or de-identify it. If we have used personal information to make a decision about you, we retain it long enough to give you a reasonable opportunity to request access to it.

9. How we protect personal information

We apply safeguards appropriate to the sensitivity of the information. As a technology and cybersecurity provider, we hold ourselves to the practices we recommend to clients:

  • Multifactor authentication on business systems and administrative accounts
  • Role-based access control, with access limited to staff who need it to do their work
  • Encryption of data in transit, and encryption at rest where our platforms support it
  • Endpoint protection, patch management and monitoring on the devices we use
  • Logging and alerting on administrative and privileged activity
  • Backup and recovery processes that are tested rather than assumed
  • Confidentiality obligations in employment and contractor agreements
  • Security assessment of the service providers we rely on
  • Secure disposal of records and media at end of life

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Email in particular is not a secure channel by default. If you need to send us confidential information, ask us for a secure method first.

10. If a privacy breach occurs

We maintain an incident response process covering detection, containment, assessment, notification and remediation.

Where a breach of security safeguards involving personal information under our control creates a real risk of significant harm to an individual, PIPEDA requires us to report the breach to the Office of the Privacy Commissioner of Canada, to notify the affected individuals as soon as feasible, and to notify any other organization that may be able to reduce the risk of harm. We will do so.

We keep a record of every breach of security safeguards involving personal information, whether or not it meets the reporting threshold, for at least 24 months. Where we are acting as a service provider to a client, we notify that client without unreasonable delay so they can meet their own obligations.

11. Your privacy rights

Subject to limited exceptions in the applicable legislation, you have the right to:

Access
Ask whether we hold personal information about you, what it is, how we have used it, and to whom it has been disclosed, and to receive a copy of it.
Correction
Challenge the accuracy and completeness of the information we hold and have it amended where it is inaccurate or incomplete.
Withdrawal of consent
Withdraw your consent to our use of your personal information, subject to legal and contractual restrictions.
Deletion
Ask us to delete personal information we no longer have a legal or business reason to keep. We will explain if we are required to retain something.
Complaint
Challenge our compliance with this policy and with applicable privacy law.

To make a request, contact our Privacy Officer using the details in section 17. We may ask for information sufficient to verify your identity before we act, and we will use that information only for verification. We respond to access requests within 30 days as PIPEDA requires, or we will tell you in writing why we need an extension and how long we expect to take. Access is provided at little or no cost; if a fee would apply, we will tell you the estimated cost before proceeding so you can decide whether to continue.

In limited cases the law requires or permits us to refuse access — for example where disclosing the information would reveal personal information about another person, where it is protected by solicitor-client privilege, or where it relates to an ongoing investigation. If we refuse, we will explain why and tell you how to challenge that decision.

12. Additional rights for Quebec residents

If you are a Quebec resident, Quebec's Private Sector Act as amended by Law 25 gives you rights in addition to those described above:

  • The right to receive computerised personal information you provided to us in a structured, commonly used technological format, and to have it transferred to another organization where technically feasible.
  • The right to request that we cease disseminating personal information about you, or that a hyperlink giving access to it be de-indexed, where dissemination contravenes the law or a court order.
  • The right to be informed when we use personal information to render a decision based exclusively on automated processing, and to submit observations to a member of our personnel who can review that decision. We do not currently make decisions about individuals by exclusively automated means.
  • The right to be informed, at the time of collection, of the purposes, the means of collection, your rights of access and correction, and the categories of third parties to whom the information may be disclosed — all of which this policy provides.

Quebec residents may also complain to the Commission d'accès à l'information du Québec if they are not satisfied with our response.

13. Children

This website and our services are directed to organizations and to the adults who work in them. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact our Privacy Officer and we will delete it.

14. Commercial electronic messages

We send commercial electronic messages only where we have your express or implied consent under CASL, or where an exemption applies — for example where you have made an enquiry about our services, or where we have an existing business relationship with you.

Every commercial electronic message we send identifies us clearly, provides contact information that remains valid for at least 60 days, and includes an unsubscribe mechanism that works with a single interaction and takes effect within 10 business days. Responding to a request you sent us, or emailing you about work we are doing for you, is service correspondence rather than a commercial electronic message.

15. Third-party websites

This website links to third-party sites, including the websites of organizations we work with and the research sources cited in our articles. We do not control those sites and are not responsible for their privacy practices. We encourage you to read the privacy policy of any site you visit.

16. Changes to this policy

We review this policy periodically and update it when our practices, our technology or the law changes. The effective date at the top of this page tells you when the current version took effect. Where a change is material, we will take reasonable steps to bring it to the attention of the people it affects. Continuing to use this website after an update means you accept the revised policy.

17. Contact our Privacy Officer

We have designated a Privacy Officer who is accountable for our compliance with this policy. Direct any question, access request, correction request or complaint to that person using the contact details on this page.

We take complaints seriously. We will acknowledge your complaint, investigate it, and tell you the outcome in writing. If we find a complaint is justified, we will take appropriate steps, including amending our policies and practices where necessary.

If you are not satisfied with our response, you may contact the Office of the Privacy Commissioner of Canada at 30 Victoria Street, Gatineau, Quebec K1A 1H3, by telephone at 1-800-282-1376, or through priv.gc.ca. Residents of Quebec, Alberta and British Columbia may also contact their provincial privacy regulator.

How to reach us

Great Lakes IT Inc.

Mailing address:
Unit 102, 920 Tungsten St, Thunder Bay, Ontario

You can also reach us through our contact form, and we will route your message to the right person.