DataStealth
Legal

Privacy Policy

How DataStealth collects, uses, and protects your information.

Last updated 2026 · DataStealth Inc.

1. Overview

This Privacy Policy describes how DataStealth Inc. ("DataStealth") treats information that it collects and receives related to your use of DataStealth products or services. DataStealth has established an internal privacy governance framework to support accountability and compliance with applicable privacy laws, including designated privacy leadership, documented policies, regular risk assessments, employee training, and ongoing monitoring.

2. Applicable Privacy Laws

Depending on your location and the nature of the data processed, DataStealth complies with PIPEDA (Canada), Quebec’s Law 25, GDPR (EEA, UK, Switzerland), and CCPA/CPRA (California). The specific law(s) applicable depend on your location, your customers’ locations, and the jurisdiction(s) of data subjects.

3. Data Controller and Data Processor Roles

For customer data processed through DataStealth Solutions, DataStealth acts as a data processor, processing data solely on customer instructions. For Account Information, billing data, and marketing data, DataStealth acts as a data controller.

4. Information Collection and Usage

DataStealth collects Account Information (identifiers, billing, payment) and Usage Information (logs, requests, performance metrics) needed to deliver and support Solutions. Authentication credentials are protected via cryptographic hashing, encryption at rest and in transit, and secure session management; passwords are never stored in plain text.

5. Information Sharing and Disclosure

DataStealth will not share collected information with third parties without consent, except where necessary to comply with law, protect our rights, or protect customers, users, employees, or the public. Any third party receiving information must sign an NDA and limit use to the purpose provided.

6. Security

DataStealth maintains physical, electronic, cyber, and procedural safeguards. Information is stored in secure data centers located primarily in Canada and the United States, accessible only to authorized employees.

7. International Data Transfers and Storage

DataStealth processes and stores personal information primarily in Canada and the United States. Cross-border transfers are protected via Standard Contractual Clauses, Data Processing Agreements, and technical/organizational safeguards.

8. Data Retention and Deletion

Customer data is retained for the duration of the contractual relationship per customer instruction. Billing and financial records are typically retained a minimum of seven years. Upon contract termination, DataStealth will securely delete or return customer data at the customer’s written request.

9. Data Subject Rights

Depending on applicable law, you may have rights of access, correction, deletion, restriction, portability, and objection. PIPEDA requests are answered within 30 days, GDPR within one month (extendable), and CCPA/CPRA within 45 days (extendable).

10. Modification of Privacy Policy

DataStealth may change this Privacy Policy at any time by publishing the update on our website. Continued use of any Solution after posting constitutes acceptance of the modifications.

11. Cookies and Similar Technologies

DataStealth uses strictly necessary, functional, performance/analytics, and marketing/advertising cookies. Marketing cookies require explicit consent under GDPR.

12. Contact Us

Questions regarding this Privacy Policy can be directed to DataStealth’s DPO, Romeo Shakhawat, at info@datastealth.io, or by mail to DataStealth Inc., 5995 Avebury Rd Suite 600, Mississauga, ON L5R 3P9.