Skip to main content

IDENTOS Inc. (“we,” “us,” or “our”) operates the PolicyArc.com website (the “Site”). We respect your privacy and are committed to being transparent about how we handle information. This Privacy Policy explains what personal information we collect when you visit the Site, how we use it, who we share it with, and what choices you have.

This policy applies to visitors of PolicyArc.com and to individuals who register for or use the PolicyArc PBAC Platform (“Platform”), in each case where IDENTOS collects and uses personal information for its own purposes as a data controller. If you subsequently subscribe to the PolicyArc Platform, your use of the Platform will also be governed by our Terms of Use. If your organization executes a Data Processing Addendum with IDENTOS, that agreement governs how IDENTOS processes data on your organization’s behalf.

For information about how your organization’s data is processed through the Platform under your organization’s instructions (where your organization is the data controller and IDENTOS acts as a data processor), please refer to the Data Processing Addendum agreed between your organization and IDENTOS. By using the Site, you agree to the practices described in this Privacy Policy. If you do not agree, please do not use the Site.

1. Who we are

IDENTOS Inc. is a Canadian corporation headquartered at 317 Adelaide St. West, Suite 901, Toronto, M5V 1P9, Ontario, Canada. We develop identity and access management solutions under the PolicyArc brand. For privacy inquiries, contact us at privacy@policyarc.com.

For residents of Quebec: we are responsible for the personal information we collect about you under Quebec’s Act respecting the protection of personal information in the private sector (Law 25).

2. Information we collect

We collect information in two ways: directly from you, and automatically when you use the Site.

2.1 Information you give us

When you fill out a contact form, sign up for updates, or request a demo, we may collect:

  • Your name and job title
  • Work email address
  • Company name
  • Your message or inquiry
  • Any other information you choose to provide

2.2 Information collected automatically

When you visit the Site, we and our service providers automatically collect certain technical information, including:

  • IP address and approximate geographic location (country / city level)
  • Browser type, operating system, and device information
  • Pages visited, time spent on pages, and referring URLs
  • Clicks and navigation patterns
  • Date and time of your visit

We collect this information using cookies and similar technologies. See Section 6 for more detail.

2.3 Information we collect through the Platform

When you register for or use the PolicyArc Platform, we collect:

  • Account information: name, email address, company name, role or title
  • Authentication data: hashed credentials, session tokens, multi-factor authentication status
  • Billing information: billing contact name, email, and payment details (processed securely by our payment processor, Stripe — we do not store full payment card numbers)
  • Usage data: features used, API calls, login frequency, session duration, and Platform interaction patterns
  • Support communications: emails, support tickets, and chat transcripts
  • Audit logs: records of administrative actions, configuration changes, and timestamps
  • Technical data: IP address, browser type, device information, and error or performance logs

2.4 Information we do not collect

We do not collect payment card information, government-issued ID numbers, or sensitive personal information (such as health data, biometrics, or racial or ethnic origin) through the Site.

3. How we use your information

We use the information we collect to:

  • Respond to your inquiries and provide information about our products and services
  • Send you newsletters, product updates, or event invitations (only where you have consented or we have a legitimate basis to do so)
  • Improve the Site and understand how visitors use it
  • Diagnose technical problems and monitor Site security
  • Comply with our legal obligations
  • Enforce our Terms of Use and protect our rights

3.1 Legal bases for processing

Each processing activity maps to a legal basis under applicable law, including GDPR Article 6 and Quebec Law 25.

ActivityLegal basis
Responding to contact form inquiriesLegitimate interest (responding to your request) or performance of a pre-contractual step.
Sending newsletters and marketing communicationsConsent — you may withdraw at any time.
Site analytics and performance monitoringLegitimate interest (improving the Site), provided it does not override your rights.
Legal compliance and enforcementLegal obligation or legitimate interest in protecting our rights.
Account and authentication managementPerformance of contract (providing the Platform).
Billing and payment processingPerformance of contract; legal obligation (tax and financial record-keeping).
Usage analyticsLegitimate interest (improving Platform functionality and user experience).
Support communicationsPerformance of contract (responding to support requests).
Audit logsLegitimate interest (security, integrity, accountability); legal obligation (regulatory requirements).
Technical and error dataLegitimate interest (maintaining Platform stability and diagnosing issues).

For residents of Quebec and the EEA, we will not process your personal information on the basis of legitimate interest where such processing is incompatible with your reasonable expectations or where your fundamental rights override our interests.

4. How we share your information

We do not sell your personal information. We may share it in the following circumstances.

4.1 Service providers

We use third-party service providers to help operate the Site and our business (for example, hosting providers, analytics platforms, email delivery services, and CRM tools). These providers access your information only to perform services on our behalf and are bound by confidentiality obligations. Service providers who help us operate the Platform include infrastructure hosting providers (such as Microsoft Azure), payment processors (such as Stripe), email delivery services (such as SendGrid/Twilio), and application monitoring providers (such as Splunk).

4.2 Business transfers

If IDENTOS Inc. is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will provide notice before your personal information is transferred and becomes subject to a different privacy policy.

4.3 Legal requirements

We may disclose your information if required by law, court order, or government authority, or where necessary to protect our legal rights or the safety of others.

4.4 With your consent

We may share your information for other purposes if you have given us permission to do so.

5. Data retention

We retain your personal information only for as long as necessary to fulfill the purposes described in this policy, or as required by law. Specifically:

  • Contact form and inquiry data: retained for up to 3 years from your last interaction with us
  • Marketing consent records: retained for the duration of the relationship, plus 2 years
  • Analytics data: retained in aggregated or anonymized form for up to 26 months
  • Account information: duration of subscription plus 60 days
  • Authentication data: duration of active account (session data deleted on logout or expiry)
  • Billing information: duration of subscription plus 7 years
  • Usage data: 24 months in identifiable form, then anonymized
  • Support communications: 3 years from resolution
  • Audit logs: 3 years, or longer where required by regulatory obligations
  • Technical and error data: 90 days for operational logs; 12 months for security-relevant logs

When we no longer need your information, we securely delete or anonymize it.

6. Cookies and tracking technologies

6.1 What we use

The Site uses cookies and similar technologies to keep the Site functioning correctly, remember your preferences, understand how visitors use the Site (analytics), and measure the effectiveness of our marketing.

6.2 Your choices

When you first visit the Site, we will ask for your consent before setting non-essential cookies. You can change your cookie preferences at any time via the cookie settings link in the Site footer. You may also configure your browser to block or delete cookies, though this may affect your experience.

6.3 Third-party analytics

We may use tools such as Google Analytics to understand Site usage. These services may set their own cookies. For more information on how Google uses data, visit google.com/policies/privacy/partners.

7. Your privacy rights

Depending on where you are located, you may have the following rights.

7.1 All users

  • Access: request a copy of the personal information we hold about you
  • Correction: ask us to correct inaccurate or incomplete information
  • Deletion: ask us to delete your personal information, subject to legal retention requirements
  • Withdrawal of consent: withdraw consent to marketing communications at any time by clicking “Unsubscribe” in any email or contacting us directly
  • Complaint: lodge a complaint with a supervisory authority
  • Data portability: receive your personal information in a portable form

7.2 Residents of Quebec (Canada)

Under Quebec’s Law 25, you also have the right to know whether we hold personal information about you; request that we stop disseminating your information or de-index certain hyperlinks; the right to data portability; and request that automated decisions made about you be reviewed by a person. To exercise your Quebec rights, contact our Privacy Officer at privacy@policyarc.com or by mail at 317 Adelaide St. West, Suite 901, Toronto, M5V 1P9, Ontario, Canada. Complaints may be referred to the Commission d’accès à l’information du Québec (CAI).

7.3 Residents of California (USA)

Under the California Consumer Privacy Act (CCPA), California residents have the right to know what personal information we collect, use, and disclose; delete personal information we have collected from you, subject to exceptions; opt out of the sale or sharing of personal information (note: we do not sell or share personal information for cross-context behavioural advertising); data portability; correction of inaccurate personal information; and non-discrimination for exercising your rights. You may designate an authorized agent to submit a request on your behalf; we may require verification of the agent’s authorization. We will acknowledge your request within 10 business days and respond substantively within 45 days. To submit a request, contact us at privacy@policyarc.com or by mail at 317 Adelaide St. West, Suite 901, Toronto, M5V 1P9, Ontario, Canada.

7.4 Other Canadian residents

Under PIPEDA and applicable provincial privacy laws, you may access and request correction of your personal information by contacting us at privacy@policyarc.com or by mail at 317 Adelaide St. West, Suite 901, Toronto, M5V 1P9, Ontario, Canada. You may also file a complaint with the Office of the Privacy Commissioner of Canada (OPC) at priv.gc.ca.

7.5 Residents of the European Economic Area and United Kingdom

If you are located in the EEA or UK, you have the following rights under the General Data Protection Regulation (GDPR):

  • Access: request a copy of the personal information we hold about you
  • Rectification: request correction of inaccurate or incomplete data
  • Erasure: request deletion of your personal information in certain circumstances
  • Restriction: request restriction of processing in certain circumstances
  • Data portability: receive your personal information in a structured, commonly used, machine-readable format
  • Object: object to processing based on legitimate interest, including any profiling
  • Withdraw consent: withdraw consent at any time, without affecting the lawfulness of processing before withdrawal

To exercise your rights, contact our Privacy Officer at privacy@policyarc.com or by mail at 317 Adelaide St. West, Suite 901, Toronto, M5V 1P9, Ontario, Canada. We will respond within 30 days. You also have the right to lodge a complaint with a supervisory authority in your country of residence. A list of EEA supervisory authorities is available at edpb.europa.eu. UK residents may contact the Information Commissioner’s Office (ICO) at ico.org.uk.

8. International data transfers

IDENTOS Inc. is based in Canada. If you visit the Site from outside Canada, your information may be transferred to and processed in Canada. We may also use service providers located in the United States or other countries.

When we transfer personal information to the United States, we rely on the following safeguards:

  • For transfers to service providers certified under the EU–US Data Privacy Framework (such as Google), we rely on their DPF certification
  • For transfers to other service providers, we use Standard Contractual Clauses approved by the European Commission or equivalent contractual protections
  • Canada has been recognized by the European Commission as providing an adequate level of data protection for commercial transfers, subject to certain conditions

Copies of applicable transfer mechanisms are available upon request by contacting privacy@policyarc.com.

9. Children’s privacy

The Site is not directed to children. We do not knowingly collect personal information from minors. Specifically, we do not knowingly collect information from children under 13 years of age in the United States (consistent with COPPA), and we do not knowingly collect information from individuals under 16 years of age in Canada (consistent with applicable provincial standards). If you believe a minor has provided us with personal information, contact us at privacy@policyarc.com and we will delete it promptly.

10. Security

We implement administrative, technical, and physical safeguards designed to protect your personal information against unauthorized access, disclosure, alteration, or destruction. Our security program is designed around industry-recognized frameworks, including controls for encryption of data at rest and in transit, access management, and regular vulnerability assessments. No internet transmission or electronic storage is 100% secure, and we cannot guarantee absolute security.

11. Security incidents and breach notification

In the event of a security incident that affects your personal information and creates a real risk of significant harm, we will notify you without undue delay and, where required by law, within 72 hours of becoming aware of the breach. Notification will be provided by email where we hold your contact information, or by prominent notice on the Site where individual notification is not practicable.

We will also notify applicable regulatory authorities as required by law, including the Office of the Privacy Commissioner of Canada under PIPEDA, the Commission d’accès à l’information under Quebec Law 25, and EU or UK supervisory authorities under the GDPR where applicable.

13. Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will: (a) post the updated policy on this page and update the effective date; and (b) notify registered users by email at least 30 days before material changes take effect. Your continued use of the Site after changes are posted constitutes your acceptance of the updated policy.

14. Contact us

If you have questions or concerns about this Privacy Policy or our privacy practices, or to exercise your privacy rights, contact IDENTOS Inc. — Privacy Officer at privacy@policyarc.com, or by mail at 317 Adelaide St. West, Suite 901, Toronto, M5V 1P9, Ontario, Canada.