Privacy Policy
How Aljundi Lab Corporation collects, uses, discloses, and safeguards your personal information.
Contents
- Introduction and Scope
- Information We Collect
- How We Use Your Information
- Legal Bases for Processing
- Disclosure of Your Information
- Data Retention
- Data Security
- Your Privacy Rights
- Cookies and Tracking
- Children's Privacy
- International Data Transfers
- Third-Party Services
- Do Not Track
- Data Breach Notification
- Changes
- Contact Us
1. Introduction and Scope
This Privacy Policy describes how Aljundi Lab Corporation, a Canadian corporation doing business as Aljundi Lab, collects, uses, stores, shares, and protects personal information obtained through our website at www.aljundilab.autos, through any related digital properties, through our professional services, and through any other interactions you may have with our organization. This policy applies to all visitors, users, clients, prospective clients, vendors, and job applicants who interact with Aljundi Lab in any capacity whatsoever.
Aljundi Lab is a computer systems design and related services firm specializing in enterprise systems architecture, cloud infrastructure engineering, systems integration, cybersecurity, and managed IT operations. Our design center is located at 74 Hawktree Ridge, Ottawa, Ontario K2J 5N3, Canada. Throughout this document, references to Aljundi Lab, we, us, and our refer to Aljundi Lab Corporation and its affiliated operating entities. The website was developed and is maintained by the Aljundi Lab engineering team, who designed this site with data privacy and security as foundational requirements embedded in every layer of our platform and operational infrastructure.
By accessing our website or using our services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with any provision contained herein, you should discontinue use of our website and services immediately. We reserve the right to modify this policy at any time, and such modifications will be effective immediately upon posting to this page. Your continued use of our website or services after any changes constitutes your acceptance of the revised policy. We encourage you to review this policy periodically to stay informed about our evolving data handling practices and the choices available to you regarding your personal information.
This Privacy Policy is designed to comply with applicable privacy laws in the jurisdictions where we operate, including but not limited to Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), the California Consumer Privacy Act as amended by the California Privacy Rights Act, the Virginia Consumer Data Protection Act, the Colorado Privacy Act, the Connecticut Data Privacy Act, the Utah Consumer Privacy Act, and applicable provisions of the General Data Protection Regulation to the extent they govern our processing activities. We are committed to the principles of transparency, purpose limitation, data minimization, accuracy, storage limitation, integrity, and confidentiality in all of our data handling practices without exception.
2. Information We Collect
2.1 Information You Provide Directly
We collect information that you voluntarily provide when you interact with our website, communicate with our team, or engage our services. This includes information submitted through our contact forms, email correspondence, phone calls, service inquiry forms, and client onboarding documentation. The categories of information we may collect include your full name, business email address, personal email address if provided, telephone number, job title, organization name, physical business address, billing address, payment information including bank account details and credit card data where applicable, tax identification numbers including GST/HST numbers for Canadian entities, and any other information you choose to include in messages, project descriptions, technical specifications, or service requests.
When you engage Aljundi Lab for professional services, we may also collect additional information necessary for the performance of our contractual obligations. This can include system access credentials provided under strict security protocols, network configuration data, infrastructure documentation, architectural diagrams, server inventories, and other technical information related to your existing systems environment that you authorize us to review, analyze, and optimize as part of the services we provide. We treat all client-provided technical information with the highest level of confidentiality and security.
2.2 Information Collected Automatically
When you visit our website, certain information is collected automatically through standard web technologies. This includes your Internet Protocol address, browser type and version, operating system type and version, device type and manufacturer, screen resolution, referring and exit pages, date and time stamps of your visit, pages viewed and time spent on each page, clickstream data including the sequence of links and buttons you interact with, mouse movement patterns, scroll depth, and form interaction behavior. We use server logs, web beacons, tracking pixels, and similar technologies. Server log data is typically retained for thirty days before being purged unless required for security investigations or legal compliance.
2.3 Information from Third Parties
We may receive information about you from third-party sources to supplement our own records, including business intelligence platforms, publicly available business registries, professional networking platforms, trade association directories, credit reporting agencies, and referral partners. We treat all information received from third-party sources in accordance with this Privacy Policy and applicable law.
3. How We Use Your Information
We use the information we collect for specific business purposes that are necessary to provide our services, operate our business, and comply with legal obligations. Each category is described below.
We use your information to provide, maintain, and improve our services including the delivery of contracted computer systems design, architecture consulting, cloud infrastructure engineering, systems integration, cybersecurity assessment, and managed IT operations services. This includes using your contact information to communicate about project status, deliverables, milestones, change requests, risk assessments, and service-related notifications throughout the entire engagement lifecycle from initial scoping through final delivery and ongoing operational support.
We use your information to respond to inquiries submitted through our website, by email, or by telephone. When you request information about our services, pricing, technical capabilities, or availability, we process your contact details and the content of your inquiry to provide a responsive and personalized reply tailored to your specific situation. We may follow up on inquiries that do not result in an immediate engagement. We use your information to process payments, manage billing and invoicing, maintain financial records, and fulfill accounting obligations including transaction processing, invoice generation, and financial reporting. We send marketing communications where consented or permitted — opt-out available at any time. We analyze website usage and develop aggregate insights. We protect system security, monitor for unauthorized access, investigate incidents, detect fraud, and comply with legal obligations.
4. Legal Bases for Processing
For jurisdictions requiring specified legal bases: Contractual Necessity — processing necessary for contract performance. Legitimate Interests — processing for our legitimate business interests including operating our business, customer support, fraud protection, analytics, and B2B marketing. Consent — where required, obtained before processing for specific purposes, with right to withdraw. Under PIPEDA, we rely on consent as the primary basis for collection, use, and disclosure of personal information, obtained at or before the time of collection. Legal Obligation — processing to comply with laws and regulations. Vital Interests — in rare circumstances, to protect vital interests.
5. Disclosure of Your Information
We do not sell your personal information. We do not rent, trade, or otherwise disclose your personal information to third parties for their independent commercial use. We may share information with service providers and subcontractors who perform functions on our behalf, including cloud hosting providers, payment processors, CRM operators, email services, analytics providers, and professional advisors. Each is bound by contractual obligations limiting their use to the specific purpose and requiring appropriate security measures. We may disclose as required by law or legal process, with reasonable efforts to notify unless prohibited. We may disclose in connection with a corporate transaction. We may disclose aggregated, de-identified information for any lawful purpose including industry analysis and benchmarking.
6. Data Retention
We retain personal information for no longer than necessary to fulfill the purposes for which it was collected, or as required by applicable law. Contact form submissions and inquiry correspondence are retained for two years from last communication. Client engagement records including contracts, project documentation, and communications are retained for the duration of the client relationship plus seven years following termination. Financial records are retained for seven years per Canadian tax law requirements. Server logs are retained for thirty days. Anonymized aggregate data may be retained indefinitely.
7. Data Security
We implement and maintain comprehensive administrative, technical, and physical safeguards designed to protect the confidentiality, integrity, and availability of your personal information. Our security program is aligned with industry standards and is regularly reviewed and updated to address evolving threats and vulnerabilities.
Our technical safeguards include encryption of data in transit using TLS 1.3, encryption of data at rest using AES-256, multi-factor authentication for all administrative access, role-based access controls with the principle of least privilege, automated vulnerability scanning and penetration testing, intrusion detection and prevention systems, endpoint detection and response capabilities across all managed devices, security information and event management with real-time alerting, and regular third-party security assessments and audits of our infrastructure and applications.
Our administrative safeguards include documented security policies reviewed annually, mandatory security awareness training for all personnel, background checks for employees and contractors, formal incident response procedures with defined escalation paths, vendor risk management with security assessments for all third-party service providers, business continuity and disaster recovery plans tested annually, and data classification and handling procedures that define protection requirements. While we implement robust measures, no security system is absolute. In the event of a breach, we will notify you and relevant authorities per PIPEDA mandatory breach notification obligations and the Office of the Privacy Commissioner of Canada reporting framework.
8. Your Privacy Rights
Depending on your jurisdiction, you may have rights including access and data portability, correction of inaccurate information, deletion under certain circumstances, restriction of processing, opt-out of sale or sharing (Aljundi Lab does not sell personal information and has not done so in the preceding twelve months), and non-discrimination for exercising rights. Canadian residents have additional rights under PIPEDA including the right to access personal information held by an organization and to challenge its accuracy and completeness. To exercise rights, submit a verifiable request using the contact information in Section 16. We acknowledge within ten business days and respond within the time required by applicable law. Identity verification will be required before fulfilling any request, and we may require additional verification for sensitive requests.
9. Cookies and Tracking Technologies
Our website uses cookies, web beacons, tracking pixels, local storage, and similar technologies to enhance your browsing experience, analyze website traffic, and understand where our visitors originate. A cookie is a small text file that a website stores on your device through your browser. Cookies may be session-based or persistent. Essential cookies enable core functionality without requiring consent. Analytics cookies help understand interaction patterns anonymously. You may configure browser settings to manage cookies. Disabling essential cookies may affect website functionality.
10. Children's Privacy
Our website and services are directed at business professionals and are not intended for use by individuals under eighteen. We do not knowingly collect, solicit, maintain, or process personal information from children under thirteen. If we become aware we have inadvertently collected such information, we will delete it immediately.
11. International Data Transfers
Aljundi Lab is headquartered in Canada, and our primary data processing activities may occur in Canada, the United States, and other jurisdictions where our service providers or clients maintain operations. When we transfer personal information across international borders, we implement appropriate safeguards to ensure an adequate level of protection as required by PIPEDA and applicable law. By using our services, you acknowledge information may be subject to the laws of jurisdictions where processing occurs.
12. Third-Party Services and Links
Our website may contain links to third-party websites not owned or controlled by Aljundi Lab. We are not responsible for third-party privacy practices. When engaging service providers, we conduct due diligence and enter written agreements with data protection obligations consistent with this policy.
13. Do Not Track Signals
Our website does not currently respond to Do Not Track signals. You may manage tracking preferences through browser cookie controls.
14. Data Breach Notification
In the event of a security incident involving unauthorized access to, disclosure of, or loss of personal information, we will execute incident response procedures to contain the incident, assess the scope and impact, and notify affected individuals and relevant authorities per PIPEDA mandatory breach notification obligations and the Office of the Privacy Commissioner of Canada reporting framework. Notifications will describe the incident, affected categories, likely consequences, and measures taken.
15. Changes
We reserve the right to update this policy at any time. Material changes will be posted with a new Last Updated date and additional notice where required by law.
16. Contact Us About Privacy
ALJUNDI LAB CORPORATION
Attn: Privacy Officer
74 Hawktree Ridge
Ottawa, ON K2J 5N3
Canada
Email: contact@aljundilab.autos
Phone: +1 (743) 263-1693
The Aljundi Lab engineering team developed this website with data privacy as a foundational design principle.