Privacy Policy
Effective July 26, 2026
Great Lakes IT Inc. ("Great Lakes IT Inc.", "we", "us" or "our") provides managed IT, cybersecurity, cloud, software development, automation and AI consulting services. We understand that the organizations we work with trust us with access to their systems and information, and we treat that trust as central to how we operate.
This policy explains what personal information we collect through this website and through our business relationships, why we collect it, how we use and protect it, who we share it with, and the rights you have. It is written to be read by people rather than lawyers.
1. Scope and the laws that apply
This policy applies to personal information we collect through this website, through our contact and consultation forms, through email and telephone contact, and in the course of providing services to our clients.
We handle personal information in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA), Canada's federal private-sector privacy law, and its ten fair information principles. Depending on where you live or where an organization operates, additional legislation may also apply:
- Quebec
- Quebec's Act respecting the protection of personal information in the private sector, as amended by Law 25, applies to the personal information of Quebec residents regardless of our size or revenue. Additional rights for Quebec residents are described in section 12.
- Alberta and British Columbia
- The Personal Information Protection Act (PIPA) in each province applies to organizations operating there in place of PIPEDA for most commercial activity.
- Commercial email
- Canada's Anti-Spam Legislation (CASL) governs the commercial electronic messages we send. See section 14.
Where we act as a service provider processing personal information on behalf of a client, we handle that information under our written agreement with that client and under their instructions. That client remains accountable for the information, and their own privacy policy governs it. This policy governs the personal information for which we are accountable.
2. Personal information we collect
We collect only what we need. We do not require you to provide personal information in order to browse this website.
Information you give us directly. When you submit our contact or consultation form, we collect:
- Your first and last name
- Your work email address
- Your telephone number, if you choose to provide it
- Your organization name and, on the full contact form, its approximate size
- Your preferred method of contact
- The service you are interested in
- The description of your project, question or requirement that you write in the message field
- A record of the consent you give when submitting the form
We also collect the personal information you share with us over email, by telephone, in meetings, and during the course of an engagement — for example the names, business contact details and roles of the people we work with at a client organization.
Information collected automatically. Our hosting provider records standard technical information when a page is requested, including the IP address making the request, the browser and operating system reported by that browser, the page requested, and the date and time. These server logs exist to keep the site running, to diagnose faults and to detect abuse. We do not use them to build profiles of individual visitors.
Information we do not collect. We do not knowingly collect sensitive personal information through this website, such as health information, financial account details, government identifiers or biometric data. Please do not include information of that kind in the message field of our forms. If you need to send us sensitive information, contact us first and we will arrange a secure method.
3. Why we collect personal information
We identify our purposes before or at the time we collect personal information. We use it to:
- Respond to your enquiry, quote request or consultation request
- Understand what you need so we can recommend an appropriate approach
- Prepare proposals, statements of work and service agreements
- Deliver, support, monitor and improve the services our clients have engaged us to provide
- Manage our client relationships, including billing, scheduling and account administration
- Keep our own systems, and our clients' systems, secure and available
- Meet our legal, regulatory, insurance, tax and professional obligations
- Send service and administrative messages relating to work we are doing for you
- Send commercial messages where you have consented to receive them, or where CASL otherwise permits
If we ever want to use personal information for a purpose that is materially different from the purposes above, we will identify that new purpose and obtain your consent before doing so, unless the law requires or permits otherwise.
4. Consent
We obtain your express consent when you tick the consent box on our forms before submitting them. That consent covers our use of the information you provide to respond to your request.
In some circumstances consent may be implied — for example, if you email us directly with a question, it is reasonable to infer that you want us to use your email address to reply. We rely on implied consent only where the purpose is obvious and the information is not sensitive.
You may withdraw your consent at any time, subject to legal or contractual restrictions and reasonable notice. Withdrawing consent may mean we can no longer provide a service or continue a conversation with you. To withdraw consent, contact our Privacy Officer using the details in section 17.
6. How we share personal information
We do not sell personal information. We do not rent, trade or otherwise make personal information available to third parties for their own marketing purposes.
We disclose personal information only in these circumstances:
- Service providers
- We use third-party providers for website hosting, email delivery, business communications, scheduling, file storage, ticketing and accounting. They may process personal information on our behalf, only for the purposes we specify, and under contracts that require comparable protection.
- Technology vendors used in delivering your services
- Where an engagement requires it — for example a Microsoft 365 tenant, a cloud platform or a security tool — information may be processed by that vendor under the agreement you or we hold with them.
- Professional advisors
- Our lawyers, accountants, auditors and insurers, where they need the information to advise us and are bound by confidentiality obligations.
- Legal requirements
- Where disclosure is required or permitted by law, including in response to a valid court order, subpoena, warrant or lawful request from a government authority, or to investigate a suspected breach of an agreement or of the law.
- Business transactions
- In connection with a merger, acquisition, financing or sale of assets, personal information may be disclosed to the parties involved, subject to confidentiality protections and to the requirements of applicable privacy law.
7. Storage location and transfers outside Canada
We prefer service providers that store data in Canada, and we seek Canadian data residency where it is available and practical. However, some of the providers we rely on store or process information in the United States or other countries, or may access it from outside Canada for support purposes.
When personal information is held in another country, it is subject to the laws of that country, and courts, law enforcement and national security authorities there may be able to obtain access to it under those laws. This is true regardless of the contractual protections we put in place.
We remain accountable for personal information transferred to a service provider for processing, and we use contractual and other means to require a comparable level of protection. If you would like to know where the information relating to a specific engagement is stored, contact our Privacy Officer and we will tell you what we can.
8. How long we keep personal information
We keep personal information only as long as it is needed for the purpose it was collected for, or as long as the law requires us to keep it.
- Enquiries that do not lead to an engagement are generally retained for up to two years so we can recognise follow-up contact and understand demand for our services.
- Client records, contracts, project documentation and correspondence are retained for the duration of the relationship and then for the period required by our legal, tax, insurance and professional obligations.
- Server logs are retained for a short operational period for security and troubleshooting.
- Records relating to a privacy breach are retained for at least 24 months, as PIPEDA requires.
When personal information is no longer required, we destroy, erase or de-identify it. If we have used personal information to make a decision about you, we retain it long enough to give you a reasonable opportunity to request access to it.
9. How we protect personal information
We apply safeguards appropriate to the sensitivity of the information. As a technology and cybersecurity provider, we hold ourselves to the practices we recommend to clients:
- Multifactor authentication on business systems and administrative accounts
- Role-based access control, with access limited to staff who need it to do their work
- Encryption of data in transit, and encryption at rest where our platforms support it
- Endpoint protection, patch management and monitoring on the devices we use
- Logging and alerting on administrative and privileged activity
- Backup and recovery processes that are tested rather than assumed
- Confidentiality obligations in employment and contractor agreements
- Security assessment of the service providers we rely on
- Secure disposal of records and media at end of life
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Email in particular is not a secure channel by default. If you need to send us confidential information, ask us for a secure method first.
10. If a privacy breach occurs
We maintain an incident response process covering detection, containment, assessment, notification and remediation.
Where a breach of security safeguards involving personal information under our control creates a real risk of significant harm to an individual, PIPEDA requires us to report the breach to the Office of the Privacy Commissioner of Canada, to notify the affected individuals as soon as feasible, and to notify any other organization that may be able to reduce the risk of harm. We will do so.
We keep a record of every breach of security safeguards involving personal information, whether or not it meets the reporting threshold, for at least 24 months. Where we are acting as a service provider to a client, we notify that client without unreasonable delay so they can meet their own obligations.
11. Your privacy rights
Subject to limited exceptions in the applicable legislation, you have the right to:
- Access
- Ask whether we hold personal information about you, what it is, how we have used it, and to whom it has been disclosed, and to receive a copy of it.
- Correction
- Challenge the accuracy and completeness of the information we hold and have it amended where it is inaccurate or incomplete.
- Withdrawal of consent
- Withdraw your consent to our use of your personal information, subject to legal and contractual restrictions.
- Deletion
- Ask us to delete personal information we no longer have a legal or business reason to keep. We will explain if we are required to retain something.
- Complaint
- Challenge our compliance with this policy and with applicable privacy law.
To make a request, contact our Privacy Officer using the details in section 17. We may ask for information sufficient to verify your identity before we act, and we will use that information only for verification. We respond to access requests within 30 days as PIPEDA requires, or we will tell you in writing why we need an extension and how long we expect to take. Access is provided at little or no cost; if a fee would apply, we will tell you the estimated cost before proceeding so you can decide whether to continue.
In limited cases the law requires or permits us to refuse access — for example where disclosing the information would reveal personal information about another person, where it is protected by solicitor-client privilege, or where it relates to an ongoing investigation. If we refuse, we will explain why and tell you how to challenge that decision.
12. Additional rights for Quebec residents
If you are a Quebec resident, Quebec's Private Sector Act as amended by Law 25 gives you rights in addition to those described above:
- The right to receive computerised personal information you provided to us in a structured, commonly used technological format, and to have it transferred to another organization where technically feasible.
- The right to request that we cease disseminating personal information about you, or that a hyperlink giving access to it be de-indexed, where dissemination contravenes the law or a court order.
- The right to be informed when we use personal information to render a decision based exclusively on automated processing, and to submit observations to a member of our personnel who can review that decision. We do not currently make decisions about individuals by exclusively automated means.
- The right to be informed, at the time of collection, of the purposes, the means of collection, your rights of access and correction, and the categories of third parties to whom the information may be disclosed — all of which this policy provides.
Quebec residents may also complain to the Commission d'accès à l'information du Québec if they are not satisfied with our response.
13. Children
This website and our services are directed to organizations and to the adults who work in them. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact our Privacy Officer and we will delete it.
14. Commercial electronic messages
We send commercial electronic messages only where we have your express or implied consent under CASL, or where an exemption applies — for example where you have made an enquiry about our services, or where we have an existing business relationship with you.
Every commercial electronic message we send identifies us clearly, provides contact information that remains valid for at least 60 days, and includes an unsubscribe mechanism that works with a single interaction and takes effect within 10 business days. Responding to a request you sent us, or emailing you about work we are doing for you, is service correspondence rather than a commercial electronic message.
15. Third-party websites
This website links to third-party sites, including the websites of organizations we work with and the research sources cited in our articles. We do not control those sites and are not responsible for their privacy practices. We encourage you to read the privacy policy of any site you visit.
16. Changes to this policy
We review this policy periodically and update it when our practices, our technology or the law changes. The effective date at the top of this page tells you when the current version took effect. Where a change is material, we will take reasonable steps to bring it to the attention of the people it affects. Continuing to use this website after an update means you accept the revised policy.
17. Contact our Privacy Officer
We have designated a Privacy Officer who is accountable for our compliance with this policy. Direct any question, access request, correction request or complaint to that person using the contact details on this page.
We take complaints seriously. We will acknowledge your complaint, investigate it, and tell you the outcome in writing. If we find a complaint is justified, we will take appropriate steps, including amending our policies and practices where necessary.
If you are not satisfied with our response, you may contact the Office of the Privacy Commissioner of Canada at 30 Victoria Street, Gatineau, Quebec K1A 1H3, by telephone at 1-800-282-1376, or through priv.gc.ca. Residents of Quebec, Alberta and British Columbia may also contact their provincial privacy regulator.
How to reach us
Great Lakes IT Inc.
- Email:
- abdul@greatlakesit.ca
- Telephone:
- +1 (647) 355-5017
- Mailing address:
- Unit 102, 920 Tungsten St, Thunder Bay, Ontario
You can also reach us through our contact form, and we will route your message to the right person.
