Privacy
Privacy Policy
We respect your privacy. This policy explains what personal information we collect through our website and related channels, why we use it, how we secure it, and the choices you have under PIPEDA, GDPR, CCPA/CPRA, and similar laws where they apply.
This policy describes our general practices for the public website and pre-sales channels. If you enter into a separate agreement with us (for example, a consulting or development contract, BAA, or DPA), additional or different terms may apply and will be referenced in that agreement.
1. Who is responsible for your information?
KT Informatik is the organization responsible for personal information collected through this website and the contact points we publish here. Privacy contact: contact@ktinformatik.com, phone +1 (343) 700-0633, or our Contact page. Mailing address: 536 Oldenburg Ave, Richmond, ON K0A 2Z0, Canada. Security vulnerability reports: see security.txt.
2. What this policy covers
This policy applies to personal information we collect when you visit ktinformatik.com, use contact or newsletter forms, submit lead forms, or otherwise interact with us online for marketing and pre-sales. Third-party sites we link to have their own policies.
3. Information we may collect
- Contact and inquiry data: name, email, phone, company, and message content.
- Newsletter data: email address and consent timestamp when you subscribe.
- Lead data: name, email, phone, and related fields you submit.
- Technical and usage data: IP address, browser/device data, pages viewed, timestamps, and security logs.
- Cookie / preference data: necessary session cookies and, if you accept, optional analytics preferences (see Cookie Policy).
4. How we use personal information
- Respond to inquiries and follow up on consulting or product interest;
- Send newsletters or marketing emails only where you have opted in, and honor unsubscribe requests;
- Operate, secure, and improve our website (troubleshooting, abuse prevention, aggregate analytics if consented);
- Meet legal, regulatory, contractual, or insurance requirements;
- Protect the rights, property, and safety of KT Informatik, our clients, and the public.
5. PIPEDA (Canada)
Where Canada’s Personal Information Protection and Electronic Documents Act (PIPEDA) applies, we rely on consent that a reasonable person would consider appropriate—for example, submitting a contact form. For commercial electronic messages we rely on express consent where required (CASL/PIPEDA). You may withdraw consent with reasonable notice. You may request access or correction and contact the Office of the Privacy Commissioner of Canada if you have a concern.
6. GDPR / UK GDPR (EEA and UK visitors)
Where the GDPR or UK GDPR applies, we process personal data under one or more of these bases:
- Consent (Art. 6(1)(a)) — optional cookies/analytics and marketing emails;
- Contract / pre-contract steps (Art. 6(1)(b)) — responding to service inquiries you initiate;
- Legitimate interests (Art. 6(1)(f)) — securing the site, preventing abuse, and B2B relationship management, balanced against your rights;
- Legal obligation (Art. 6(1)(c)) — where we must retain or disclose information by law.
You may have rights to access, rectification, erasure, restriction, portability, and objection, and to withdraw consent at any time without affecting prior lawful processing. You may lodge a complaint with your local supervisory authority. Contact us using section 1 to exercise rights.
7. CCPA / CPRA (California)
We do not sell personal information and do not share it for cross-context behavioral advertising as those terms are commonly defined under the CCPA/CPRA. California residents may request to know, delete, or correct personal information, and are protected from discrimination for exercising rights. Use our Privacy choices page or email contact@ktinformatik.com with subject “Privacy request — CCPA”. We honor Global Privacy Control (GPC) signals as an opt-out of optional cookies.
8. HIPAA note (United States health data)
This public marketing website is not intended to collect protected health information (PHI) and is not a substitute for a HIPAA-covered clinical system. Where KT Informatik provides services to a covered entity or business associate that involve PHI, those engagements are governed by a written Business Associate Agreement (BAA) and project-specific administrative, technical, and physical safeguards—not by this website privacy notice alone. Do not submit PHI through public contact or lead forms.
9. Cookies and similar technologies
Necessary cookies support session security and preferences. Optional analytics cookies load only after consent via our cookie banner. Details: Cookie Policy.
10. When we share information
We do not sell your personal information. We may share it with:
- Service providers (hosting, email, security, analytics if consented) under contracts requiring appropriate protection;
- Professional advisers where necessary;
- Authorities when required by law or to protect safety and legal rights.
Some providers may process data outside your country (including the United States/Canada). We use reasonable contractual and organizational safeguards for cross-border transfers.
11. Retention
We retain personal information only as long as needed for the purposes described, including business records, dispute resolution, and legal obligations. Lead and contact records are typically reviewed within 24 months of last meaningful contact unless a longer period is required. Newsletter subscriptions are kept until you unsubscribe or we delete inactive lists.
12. Security measures
We apply layered safeguards aligned with industry practice for a public business website, including:
- Encryption in transit (HTTPS / TLS) and HSTS;
- Security response headers (CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy);
- Access-controlled administration interface on a non-default path with authentication;
- Secure session cookies (HttpOnly, Secure where HTTPS, SameSite);
- Least-privilege access to production systems and logging for security events;
- Vendor due diligence for hosting and email providers.
No method of Internet transmission is completely secure; we cannot guarantee absolute security.
13. Children’s privacy
Our website is directed at businesses and adults. We do not knowingly collect personal information from children under 16 (or the age required in your jurisdiction). Contact us to request deletion if you believe we collected such information in error.
14. Changes
We may update this policy and will revise the effective date. Material changes may be highlighted on the website or emailed to subscribers where appropriate.
15. Contact
Privacy questions and rights requests: contact@ktinformatik.com or Contact (include “Privacy” in the subject). Related pages: Cookie Policy · Privacy choices · Terms.