Privacy Policy
How DataStealth collects, uses, and protects your information.
Last updated 2026 · DataStealth Inc.
1. Overview
This Privacy Policy describes how DataStealth Inc. ("DataStealth") treats information that it collects and receives related to your use of DataStealth products or services. DataStealth has established an internal privacy governance framework to support accountability and compliance with applicable privacy laws, including designated privacy leadership, documented policies, regular risk assessments, employee training, and ongoing monitoring.
2. Applicable Privacy Laws
Depending on your location and the nature of the data processed, DataStealth complies with PIPEDA (Canada), Quebec’s Law 25, GDPR (EEA, UK, Switzerland), and CCPA/CPRA (California). The specific law(s) applicable depend on your location, your customers’ locations, and the jurisdiction(s) of data subjects.
3. Data Controller and Data Processor Roles
For customer data processed through DataStealth Solutions, DataStealth acts as a data processor, processing data solely on customer instructions. For Account Information, billing data, and marketing data, DataStealth acts as a data controller.
4. Information Collection and Usage
DataStealth collects Account Information (identifiers, billing, payment) and Usage Information (logs, requests, performance metrics) needed to deliver and support Solutions. Authentication credentials are protected via cryptographic hashing, encryption at rest and in transit, and secure session management; passwords are never stored in plain text.
5. Information Sharing and Disclosure
DataStealth will not share collected information with third parties without consent, except where necessary to comply with law, protect our rights, or protect customers, users, employees, or the public. Any third party receiving information must sign an NDA and limit use to the purpose provided.
6. Security
DataStealth maintains physical, electronic, cyber, and procedural safeguards. Information is stored in secure data centers located primarily in Canada and the United States, accessible only to authorized employees.
7. International Data Transfers and Storage
DataStealth processes and stores personal information primarily in Canada and the United States. Cross-border transfers are protected via Standard Contractual Clauses, Data Processing Agreements, and technical/organizational safeguards.
8. Data Retention and Deletion
Customer data is retained for the duration of the contractual relationship per customer instruction. Billing and financial records are typically retained a minimum of seven years. Upon contract termination, DataStealth will securely delete or return customer data at the customer’s written request.
9. Data Subject Rights
Depending on applicable law, you may have rights of access, correction, deletion, restriction, portability, and objection. PIPEDA requests are answered within 30 days, GDPR within one month (extendable), and CCPA/CPRA within 45 days (extendable).
10. Modification of Privacy Policy
DataStealth may change this Privacy Policy at any time by publishing the update on our website. Continued use of any Solution after posting constitutes acceptance of the modifications.
12. Contact Us
Questions regarding this Privacy Policy can be directed to DataStealth’s DPO, Romeo Shakhawat, at info@datastealth.io, or by mail to DataStealth Inc., 5995 Avebury Rd Suite 600, Mississauga, ON L5R 3P9.