TheBizAutomater
Privacy Policy
- 01Who We Are→
- 02Scope of This Policy→
- 03Information We Collect→
- 04Purposes of Collection, Use & Disclosure→
- 05Legal Basis & Consent→
- 06Disclosure of Personal Information→
- 07Cookies & Tracking Technologies→
- 08Retention of Personal Information→
- 09Security Safeguards→
- 10Your Rights as an Individual→
- 11Cross-Border Transfers→
- 12Children's Privacy→
- 13Links to Third-Party Websites→
- 14Changes to This Policy→
- 15Contact Our Privacy Officer→
Who We Are
TheBizAutomater ("Company," "we," "us," or "our") is a business automation consulting firm headquartered in Ontario, Canada. We provide workflow automation, systems integration, and operational consulting services to business owners, construction firms, real estate professionals, and solopreneurs. Our website is located at https://thebizautomater.com.
TheBizAutomater is a private sector organization subject to the federal Personal Information Protection and Electronic Documents Act (PIPEDA) in carrying out commercial activities, including in the Province of Ontario.
Scope of This Policy
This Privacy Policy applies to all personal information collected, used, or disclosed by TheBizAutomater in the course of commercial activity, including through:
- Our website at thebizautomater.com and any subdomains;
- Online booking and consultation scheduling tools;
- Email correspondence and contact form submissions;
- Service delivery, including onboarding, project management, and client support;
- Marketing, newsletters, and business communications.
This Policy does not apply to the practices of third-party companies we do not own or control, or to individuals we do not employ or manage.
Information We Collect
We collect only the minimum personal information necessary to provide our services and communicate with you. "Personal information" means information about an identifiable individual, as defined under PIPEDA.
3.1 Information You Provide Directly
- Identification data: Full name, job title, company name;
- Contact data: Email address, telephone number, mailing address;
- Business information: Industry, company size, automation goals, current systems;
- Communications: Content of emails, messages submitted via contact or booking forms;
- Financial data: Billing name, billing address, and payment details (processed through our PCI-compliant payment processor — we do not store full payment card numbers).
3.2 Information Collected Automatically
- Device & technical data: IP address, browser type and version, operating system, device identifiers;
- Usage data: Pages visited, referring URLs, time and date of access, session duration, clickstream data;
- Cookie data: See Section 7 for full details.
3.3 Information from Third Parties
We may receive personal information about you from third-party sources, such as:
- Referral partners or affiliates who recommend our services;
- Publicly available business directories or LinkedIn profiles where you have made such information available;
- Scheduling tools (e.g., Calendly) when you book a consultation.
Purposes of Collection, Use & Disclosure
In accordance with PIPEDA Principle 4.2, we collect personal information only for purposes that a reasonable person would consider appropriate in the circumstances. We use personal information for the following identified purposes:
- To respond to enquiries and fulfil consultation requests;
- To provide, manage, and improve our business automation services;
- To communicate project updates, deliverables, and invoices;
- To process payments and maintain financial records;
- To send promotional emails, newsletters, or service announcements — with your consent, and subject to your right to withdraw consent at any time;
- To analyze website usage and improve our online presence;
- To comply with applicable laws, regulations, court orders, or governmental requests;
- To detect, prevent, or address fraud, security issues, or technical problems;
- To enforce our Terms of Service and other agreements.
We will not use or disclose personal information for purposes other than those for which it was collected, except with your consent or as required or permitted by law.
Legal Basis & Consent
Under PIPEDA, knowledge and consent are required for the collection, use, or disclosure of personal information, except where an exception applies (e.g., emergency circumstances, legal proceedings, law enforcement purposes).
Consent may be express (e.g., checking a box, signing an agreement) or implied (e.g., providing your contact information to receive a quoted service). We rely on implied consent for information reasonably required to fulfill the specific transaction you have initiated.
For marketing communications, we rely on your express opt-in consent in accordance with Canada's Anti-Spam Legislation (CASL), S.C. 2010, c. 23. You may withdraw consent at any time by using the unsubscribe link in any marketing email or by contacting our Privacy Officer (see Section 15).
Withdrawal of consent may mean we are unable to provide certain services to you. We will advise you of the implications of withdrawing consent before it takes effect.
Disclosure of Personal Information
We do not sell, rent, or trade personal information to third parties for their own marketing purposes. We may share personal information only in the following circumstances:
6.1 Service Providers
We engage trusted third-party service providers who process personal information on our behalf. These may include:
- Website hosting and cloud infrastructure providers;
- CRM and project management platforms;
- Email marketing and communication platforms;
- Payment processors;
- Analytics providers (e.g., Google Analytics);
- Scheduling software (e.g., Calendly or equivalent).
All service providers are contractually bound to use personal information solely for the purposes we specify and to maintain appropriate security measures.
6.2 Legal Requirements
We may disclose personal information if required to do so by law, regulation, or valid legal process, or if we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others.
6.3 Business Transfers
In the event of a merger, acquisition, restructuring, or sale of assets, personal information may be transferred to a successor organization. We will provide notice before personal information is transferred and becomes subject to a different privacy policy.
Cookies & Tracking Technologies
Our website uses cookies and similar tracking technologies to enhance your browsing experience and gather usage analytics.
Types of Cookies We Use
- Strictly Necessary Cookies: Required for the website to function. These cannot be disabled.
- Analytical / Performance Cookies: Help us understand how visitors interact with our site (e.g., Google Analytics). Data collected is aggregated and anonymized where possible.
- Functional Cookies: Remember your preferences and settings to improve your experience.
- Marketing / Targeting Cookies: Used to deliver relevant advertisements and track campaign effectiveness. These are only placed with your consent.
You may control or disable cookies through your browser settings at any time. Note that disabling certain cookies may affect the functionality of our website. For detailed information about the cookies we use, please refer to our Cookie Policy or the cookie consent banner displayed on your first visit.
Retention of Personal Information
We retain personal information only as long as necessary to fulfill the purposes for which it was collected, or as required by applicable law.
- Client records (including contracts and financial data): Retained for a minimum of 7 years following the end of the client relationship, consistent with Ontario's Limitations Act, 2002, S.O. 2002, c. 24, Sched. B, and the Income Tax Act (Canada);
- Consultation and enquiry records: Retained for up to 2 years following the last contact;
- Marketing preferences: Retained until you withdraw consent;
- Website analytics data: Retained in aggregated form for up to 26 months.
When personal information is no longer required, we securely destroy, delete, or anonymize it in a manner appropriate to the sensitivity of the information.
Security Safeguards
In accordance with PIPEDA Principle 4.7, TheBizAutomater protects personal information with security safeguards appropriate to the sensitivity of the information. Our safeguards include:
- Technical measures: SSL/TLS encryption for data in transit, access controls, password policies, and secure cloud infrastructure;
- Organizational measures: Limiting access to personal information to authorized personnel on a need-to-know basis, confidentiality agreements with staff and contractors;
- Physical measures: Secure disposal of physical records containing personal information.
In the event of a privacy breach that poses a real risk of significant harm to an individual, we will notify the Office of the Privacy Commissioner of Canada and affected individuals as required under PIPEDA sections 10.1–10.3.
Your Rights as an Individual
Under PIPEDA, you have the following rights with respect to your personal information:
- Right of Access: You have the right to request access to the personal information we hold about you, and to be informed of the purposes for which it is being used and to whom it has been disclosed (PIPEDA s.8);
- Right to Correction: You have the right to challenge the accuracy and completeness of your personal information and request amendments where appropriate (PIPEDA s.8(7));
- Right to Withdraw Consent: You may withdraw consent to the collection, use, or disclosure of your personal information at any time, subject to legal and contractual restrictions and reasonable notice;
- Right to Lodge a Complaint: You have the right to file a complaint with the Office of the Privacy Commissioner of Canada (OPC) if you believe we have not complied with PIPEDA.
To exercise any of these rights, please contact our Privacy Officer at the details provided in Section 15. We will respond to access requests within 30 days, or notify you if an extension is required, in accordance with PIPEDA s.8(3).
We may deny or limit access in limited circumstances permitted under PIPEDA, including where disclosure would reveal personal information about a third party, is subject to solicitor-client privilege, or is otherwise exempted by law.
Cross-Border Transfers
Some of our service providers are located outside of Canada, including in the United States. When personal information is transferred to a service provider in another jurisdiction, it may be subject to the laws of that jurisdiction, including lawful access by government authorities.
We take contractual steps to ensure that personal information transferred outside Canada receives comparable protection to that provided under PIPEDA, including by entering into data processing agreements with our service providers.
By providing your personal information to us and using our services, you acknowledge and consent to the transfer of your information outside of Canada as described in this Policy.
Children's Privacy
Our services are directed to businesses and business professionals and are not intended for individuals under the age of 18. We do not knowingly collect personal information from minors. If we become aware that we have inadvertently collected personal information from a child under 18, we will take steps to delete such information promptly.
If you believe we have collected information from a minor, please contact our Privacy Officer immediately.
Links to Third-Party Websites
Our website may contain links to third-party websites that are not operated by us. If you click on a third-party link, you will be directed to that third party's website. We strongly advise you to review the privacy policy of every website you visit.
We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or for other operational reasons. When we make material changes, we will:
- Update the "Last Reviewed" date at the top of this Policy;
- Post the revised Policy on our website; and
- Where required or appropriate, notify you by email or through a notice on our website.
We encourage you to review this Policy periodically. Your continued use of our website or services after changes have been posted constitutes your acceptance of the revised Policy.
Contact Our Privacy Officer
TheBizAutomater has designated a Privacy Officer who is accountable for our compliance with PIPEDA and this Privacy Policy. If you have any questions, concerns, or complaints regarding this Policy or our privacy practices, or wish to exercise your rights, please contact:
Privacy Officer
TheBizAutomater — Privacy Officer
Website: https://thebizautomater.com/contact/
Jurisdiction: Ontario, Canada
We will acknowledge receipt of your inquiry within 5 business days and respond substantively within 30 calendar days, as required by PIPEDA.
If you are not satisfied with our response, you have the right to file a complaint with the Office of the Privacy Commissioner of Canada (OPC) — an independent officer of the Government of Canada appointed by Parliament to oversee compliance with PIPEDA and the Privacy Act:
- Website: www.priv.gc.ca
- Toll-free: 1-800-282-1376
- Address: 30 Victoria Street, Gatineau, Quebec K1A 1H3
PIPEDA (Personal Information Protection and Electronic Documents Act) — the federal privacy law governing private-sector organizations in Canada, enacted by the Parliament of Canada:
• Full text: laws-lois.justice.gc.ca
• PIPEDA guidance for businesses: priv.gc.ca — PIPEDA overview
Canada's Anti-Spam Legislation (CASL) — federal law governing commercial electronic messages, administered by the Canadian Radio-television and Telecommunications Commission (CRTC), a Government of Canada body:
• CASL information: fightspam.gc.ca
• CRTC: crtc.gc.ca