1. Scope & Application
This Privacy Policy describes how WARDORX collects, uses, discloses, retains, and protects personal information of: (a) visitors to wardorx.com; (b) prospective clients who complete a contact form, request a site audit, or book a call through our scheduling provider; (c) clients who engage our productized website and SEO services; and (d) individuals whose personal information is processed on behalf of our clients (for example, contact information embedded in client websites we build or maintain, or customer leads that flow through forms we host).
This policy applies to all personal information handled by WARDORX regardless of how it is collected - through the Site, by email, by telephone, through our booking provider, through third-party tools embedded in the Site, or in person. It does not apply to third-party websites linked from the Site; once you leave wardorx.com, you are subject to the privacy practices of the destination site.
This policy is designed to comply with the Personal Information Protection and Electronic Documents Act (PIPEDA, R.S.C. 2000, c. 5), the Alberta Personal Information Protection Act (PIPA, SA 2003, c. P-6.5), Canada's Anti-Spam Legislation (CASL, S.C. 2010, c. 23), the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA, Cal. Civ. Code §1798.100 et seq.), and Quebec's Act respecting the protection of personal information in the private sector (Law 25, formerly Bill 64). Where multiple regimes apply, we adhere to the most protective standard.
Where WARDORX processes personal information on behalf of a client (for example, hosting a client's lead form or analytics), the client is the controller and WARDORX acts as a service provider under a separate Data Processing Addendum; in those cases, this policy covers only information about visitors to the Agency's own Site.
2. Data Controller & Privacy Officer
WARDORX is the data controller for personal information collected through the Site and through our direct client relationships. We have designated a Privacy Officer responsible for compliance with this policy and applicable privacy law. The Privacy Officer is your single point of contact for any request related to your personal information.
Privacy Officer: Dane Vasquez Email: privacy@wardorx.com Phone: +1 (403) 460-2211 Mailing address: WARDORX, 1015 4 St SW, Suite 220, Calgary, Alberta, T2R 1J4, Canada
3. What Personal Information We Collect
We collect only the categories of personal information necessary for the purposes described in this policy. The categories below are not exhaustive; in practice, we collect only what is relevant to our relationship with you.
3.1 Information you provide directly
- -Identification & contact information: name, business name, job title, email address, phone number, and postal/mailing address. Collected when you complete the audit form, the contact form, the booking form, or otherwise correspond with us.
- -Business information: industry, business size, current website URL, marketing goals, monthly revenue range (voluntarily disclosed on the booking form), competitor names you mention, and other context you volunteer during inquiry, onboarding, or service delivery.
- -Marketing preferences: which newsletters, alerts, or communications you have opted into. We do not subscribe you to anything without explicit opt-in.
- -Payment information: when you engage paid services, billing name, billing address, and payment instrument details. Payment card numbers are never stored by WARDORX; they are handled by our payment processor, Stripe, in accordance with PCI-DSS.
- -Communications content: the content of emails, chat messages, call notes, and meeting recordings generated during our relationship. We do not record calls without consent.
- -Identity verification information: when responding to data subject requests, we may ask for verifying information (e.g., confirming the email address on file) before disclosing personal information.
3.2 Information collected automatically
- -Device & technical data: IP address (truncated or anonymized where feasible), browser type and version, device type, operating system, screen resolution, language preference, and time zone.
- -Usage data: pages visited, referring URLs, pages viewed, time on page, scroll depth, click patterns, conversion events, and approximate geographic location derived from IP (city/region level, not GPS-grade).
- -Cookies & similar technologies: session cookies, persistent cookies, local storage, and similar identifiers. See Section 11 and our separate Cookie Policy.
- -Form input telemetry: when you use the audit widget, we capture the URL you submitted and the timing of your interactions with the form. We do not capture keystroke content beyond what you submit.
3.3 Information collected from third parties
- -Public directories & professional networks: if you contact us via LinkedIn or another public channel, we may retain information you have made public there.
- -Referral partners: if a referral partner introduces you to us, we may receive the contact information you authorized them to share.
- -Analytics providers: aggregated, anonymized usage data from Google Analytics 4 and Microsoft Clarity.
- -Scheduling provider: Cal.com shares the booking details you submit (name, email, time selected, answers to intake questions) so we can prepare for the call.
3.4 Categories under California law (CCPA/CPRA)
For California residents, the categories of personal information we have collected in the 12 months preceding the effective date of this policy are:
| Category | Collected | Source |
|---|---|---|
| A. Identifiers (name, email, IP, device ID) | Yes | You / automatic |
| B. Personal information categories in Cal. Civ. Code §1798.140(e) | Yes | You |
| C. Protected classification (e.g., age if volunteered) | Generally no | - |
| D. Commercial information (services requested) | Yes | You |
| E. Biometric information | No | - |
| F. Internet or network activity (browsing history, interactions) | Yes | Automatic |
| G. Geolocation data (city/region level) | Yes (approximate) | Automatic |
| H. Audio/visual data | No (we do not record calls or video without explicit consent) | - |
| I. Professional/employment info (job title, company) | Yes | You |
| J. Education info | No | - |
| K. Inferences (derived from above) | Limited | Derived |
| Sensitive personal information (SSN, government ID, financial account, health, etc.) | No - payment instrument is processed by Stripe; we never receive or store raw card data | - |
We do not sell personal information as defined by CCPA. We do not share personal information for cross-context behavioral advertising. We have not sold or shared personal information in the preceding 12 months.
4. How We Collect Information
- -Directly from you when you complete the audit widget form, the contact form, the booking form, email us, message us through live chat, call us, or otherwise interact with us.
- -Automatically when you visit the Site, through cookies, server logs, analytics tools, and similar technologies.
- -From third parties as described in Section 3.3 - only where you have authorized the disclosure or where the information is publicly available.
- -From our clients when they provide us with access to their existing analytics, GBP, CRM, or other systems during service delivery. We access only what is necessary to deliver the engagement.
5. Why We Collect & Legal Bases
We process personal information only for identifiable, legitimate purposes. The table below maps each purpose to its legal basis under PIPEDA, Alberta PIPA, and CCPA.
| Purpose | Legal basis (PIPEDA/PIPA) | CCPA basis |
|---|---|---|
| Respond to inquiries & deliver requested site audits | Consent + legitimate business purpose | Service provider exception |
| Schedule & conduct booking calls | Consent + contractual necessity | Business purpose |
| Onboard & deliver productized services to clients | Contractual necessity | Business purpose |
| Billing, invoicing, accounts receivable | Contractual necessity + legal obligation (CRA record-keeping) | Business purpose |
| Site analytics & product improvement | Consent (via cookie banner) | Business purpose (with opt-out) |
| Security, fraud prevention, abuse mitigation | Legitimate interest | Business purpose |
| Marketing communications (only with express opt-in) | Express consent (CASL-compliant, with audit trail) | Opt-in |
| Cold outreach to prospective clients (only where CASL permits) | Implied consent under CASL §7(1) for existing business relationships, or express consent otherwise | Business purpose |
| Compliance with legal obligations | Legal obligation | Legal obligation |
| Backup, disaster recovery, audit logs | Legitimate interest | Business purpose |
| Aggregate, de-identified analytics for marketing and product decisions | Legitimate interest (de-identified data is not personal information) | Not applicable |
6. Disclosure & Third Parties
We do not sell, rent, or trade personal information. We disclose personal information only in the following circumstances:
- -To service providers who process data on our behalf under written contract (see Section 7). Providers are bound by confidentiality and may use personal information only as instructed by WARDORX.
- -To professional advisors (lawyers, accountants) where necessary for legal, accounting, or audit purposes, subject to professional secrecy obligations.
- -To comply with legal process - subpoenas, court orders, lawful government requests, or where we believe in good faith that disclosure is necessary to protect our rights, property, or safety, or that of others.
- -In connection with a business transaction - merger, acquisition, asset sale, financing, or insolvency. In such cases we will use reasonable efforts to require the recipient to honor this policy, and we will notify affected individuals (where required by law) before transferring personal information.
- -With your consent - we will ask for and document your consent before any disclosure not covered above.
- -Aggregated or de-identified data - we may share aggregated, anonymized statistics (e.g., "WARDORX has shipped 214 sites") publicly or with partners. Aggregated data cannot reasonably be linked to an individual.
7. Third-Party Service Providers
WARDORX uses the following third-party processors. Each is contracted under terms consistent with PIPEDA, PIPA, and (where applicable) GDPR Article 28. We have listed what each processor receives, the purpose, and where data is processed.
| Provider | Service | What they receive | Purpose | Location |
|---|---|---|---|---|
| Cloudflare, Inc. | DNS, CDN, WAF, DDoS protection, Workers hosting | IP address, request metadata, edge logs | Site delivery & security | Global edge (data may transfer to US) |
| Vercel Inc. | Backup hosting / preview deploys | Server logs, IP addresses | Site delivery | US / EU |
| Google LLC | Google Analytics 4 | Anonymized usage data, cookies (only after consent) | Site analytics | US |
| Microsoft Corporation | Microsoft Clarity | Session recordings, heatmaps (text-masked, anonymized) | UX analytics | US |
| Cal.com, Inc. | Scheduling & booking | Name, email, time selection, intake answers | Booking audit calls | US / EU |
| Formspree, Inc. | Form backend | Form submission contents | Contact/audit form processing | US |
| Tawk.to, Inc. | Live chat | Chat transcripts, visitor IP | Real-time support | US |
| Stripe, Inc. | Payment processing | Payment instrument (we never receive card numbers) | Billing & payments | US / Canada |
| HubSpot, Inc. | CRM | Contact records, communication history | Relationship management | US |
| MailerLite | Email marketing | Email, name, engagement | Newsletter (opt-in only) | EU / US |
| Google Workspace | Email & documents | Email contents, attachments | Internal communication | US |
| GitHub, Inc. | Code hosting & version control | Repo access logs; client source code (only under engagement) | Service delivery for client builds | US |
| Figma, Inc. | Design files | Design assets; client review comments | Service delivery for client builds | US |
Some providers may transfer data outside Canada. Where this occurs, we rely on the provider's standard contractual clauses, adequacy decisions, or other lawful transfer mechanisms, and we require equivalent protection in the contract. Specifically: Cloudflare and Google may transfer data to the US under standard contractual clauses approved by the European Commission; Stripe is PCI-DSS Level 1 certified globally; Cal.com offers EU data residency where required.
8. Data Retention
We retain personal information only as long as necessary to fulfill the purposes described in this policy, to comply with legal obligations, to resolve disputes, and to enforce our agreements. Default retention periods:
| Category | Default retention | Reason |
|---|---|---|
| Inquiry / contact form data (no engagement) | 24 months from last contact | Reasonable business follow-up, then deletion |
| Audit widget submissions (URL only, no email) | 90 days | Aggregate analysis, then deletion |
| Audit widget submissions (with email captured) | 24 months from last contact | Follow-up, then deletion |
| Booking form data (no engagement) | 24 months from booking date | Reasonable business follow-up, then deletion |
| Client account & project data | Duration of engagement + 7 years | Tax/contract record-keeping under CRA requirements |
| Communication records (email, chat, call notes) | Duration of engagement + 3 years | Dispute resolution, service quality |
| Billing & payment records | 7 years from transaction | Income Tax Act (Canada) requirement |
| Marketing consent records | Until withdrawal + 30 days | CASL evidence of consent (3-year minimum under CASL) |
| Cold outreach prospect data (no response) | 6 months from last contact attempt | CASL §10 reasonable-period standard |
| Analytics data (aggregated) | 14 months rolling | Trend analysis, then aggregated/anonymized |
| Server logs (security) | 90 days | Fraud/abuse investigation |
| Backups | 30 days rolling | Disaster recovery |
| De-identified / aggregated data | Indefinite | Not personal information under applicable law |
When retention expires, we delete or anonymize the data. Where deletion is not technically feasible (e.g., in encrypted backups), we isolate and restrict the data until the next backup cycle overwrites it.
9. Security Measures
Security is a continuous practice, not a checkbox. WARDORX has implemented the following safeguards appropriate to the sensitivity of the personal information we handle:
- -Encryption in transit. All connections to the Site use TLS 1.2 or higher with HSTS enforced. We do not support legacy protocols.
- -Encryption at rest. Database, object storage, and backups are encrypted at rest using provider-managed AES-256.
- -Access control. Internal access is role-based and least-privilege. Authentication requires strong passwords and MFA. Access logs are retained for 12 months. Onboarding and offboarding access is reviewed quarterly.
- -Vendor security. Service providers are reviewed before onboarding and contractually bound to maintain security at least equivalent to industry standards (SOC 2, ISO 27001, or PCI-DSS where applicable).
- -Network protection. Cloudflare Web Application Firewall, DDoS protection, bot management, and rate limiting are enabled on the Site edge.
- -Separation of environments. Production data is not used in development or staging environments. Client data is never replicated outside the engagement.
- -Payment security. Payment card data is processed exclusively through Stripe (PCI-DSS Level 1). WARDORX never stores, transmits, or processes raw card data on its own infrastructure.
- -Incident response. Documented incident response plan with defined roles, escalation paths, and 72-hour notification timelines where required by law.
- -Training. Anyone with access to personal information receives privacy and security training at onboarding and at least annually thereafter.
- -Backups. Encrypted backups are maintained with tested restore procedures.
- -Source code security. Client source code is stored in private GitHub repositories with branch protection, signed commits, and mandatory review. Access is revoked on engagement end.
- -Data minimization. Audit forms collect only URL and email. Booking forms collect only name, email, website URL, and intake answers. We do not ask for sensitive information (government IDs, health data, financial account numbers) through any Site form.
No system is 100% secure. If a breach occurs that creates a real risk of significant harm to affected individuals, we will notify affected individuals and the relevant privacy commissioner as required by PIPEDA, Alberta PIPA, and Quebec Law 25, generally within 72 hours of confirmation. See Section 19.
10. Cross-Border Transfers
Because our service providers are located primarily in the United States, your personal information may be processed in the US or other jurisdictions. The Office of the Privacy Commissioner of Canada has recognized that personal information may be transferred to third parties in another jurisdiction if that third party provides a comparable level of protection and the transfer is for purposes consistent with those for which the information was collected. We require our providers to maintain such protections and to process data only on our documented instructions.
Specifically: Cloudflare, Google, Microsoft, Stripe, Vercel, Cal.com, Formspree, Tawk.to, HubSpot, GitHub, and Figma may process personal information in the United States. Where the EU GDPR applies, transfers are made under the European Commission's adequacy decision for the EU-US Data Privacy Framework (where the provider participates) or under Standard Contractual Clauses.
11. Cookies & Tracking Technologies
We use cookies and similar technologies (local storage, pixels, fingerprinting-resistant identifiers) for the purposes described in our Cookie Policy. Categories of cookies include strictly necessary, analytics, functional, and (where you opt in) marketing.
Strictly necessary cookies are loaded without consent. All other categories require your affirmative opt-in via our cookie consent banner, and you may withdraw consent at any time by clicking "Cookie Preferences" in the footer or by clearing your browser cookies.
Full details - including the specific cookies set, their duration, and the third parties that set them - are in our Cookie Policy.
12. Your Rights & Choices
You have the following rights regarding your personal information, regardless of where you live. We will respond to verifiable requests within 30 days (or as required by applicable law; Quebec residents: 30 days under Law 25).
- -Right of access. Request a copy of the personal information we hold about you.
- -Right to know. Request the categories of personal information collected, the business purpose, and the third parties to which it was disclosed.
- -Right to correct. Request correction of inaccurate or incomplete personal information.
- -Right to delete. Request deletion of your personal information, subject to legal retention obligations (e.g., tax records under the Income Tax Act).
- -Right to withdraw consent. Withdraw consent for processing that relies on your consent (e.g., marketing emails, analytics cookies). Withdrawal does not affect processing already done.
- -Right to restrict processing. Object to or restrict certain processing activities.
- -Right to data portability. Receive your personal information in a structured, machine-readable format where technically feasible.
- -Right to object to automated decision-making. We do not currently use automated decision-making with legal or similarly significant effects. If we ever do, we will notify you and provide a meaningful right to human review.
- -Right to lodge a complaint. With us first (preferred), and with the relevant privacy commissioner if unsatisfied (see Section 21).
To exercise any right, email privacy@wardorx.com from the email address on file. We will verify your identity before disclosing personal information. There is no charge for行使ing these rights, except where permitted by law for excessive or manifestly unfounded requests.
13. California Consumer Rights (CCPA/CPRA)
If you are a California resident, the rights described above apply to you with the following additions:
- -Right to know the categories and specific pieces of personal information collected, sold, or shared in the past 12 months.
- -Right to delete personal information we collected from you, subject to exceptions under Cal. Civ. Code §1798.105.
- -Right to correct inaccurate personal information.
- -Right to opt-out of sale or share. We do not sell personal information and we do not share it for cross-context behavioral advertising. If we ever change this practice, we will add a "Do Not Sell or Share My Personal Information" link prominently on the Site.
- -Right to limit use of sensitive personal information. We do not collect sensitive personal information as defined by CPRA.
- -Right to non-discrimination. We will not discriminate against you for exercising any CCPA right.
- -Authorized agent. You may designate an authorized agent to submit requests on your behalf, signed in writing. We may still require direct verification of your identity.
For the 12-month period preceding the effective date of this policy, we have not sold or shared personal information as defined by CCPA.
14. Quebec Residents (Law 25)
If you are a Quebec resident, the following additional rights apply under Quebec's privacy law (formerly Bill 64, now Law 25):
- -Right to be informed of the use of automated decision-making systems (we do not currently use them).
- -Right to object to a decision made exclusively by an automated process.
- -Right to access, rectify, or withdraw consent for personal information held about you.
- -Mandatory breach notification where there is a risk of serious injury (we comply with this under Section 19).
- -Right to be forgotten - in limited circumstances you may request that we de-index your personal information or cease disseminating it, subject to our legitimate interests and legal retention obligations.
- -Right to privacy by design - WARDORX has appointed a Privacy Officer and conducts privacy impact assessments for new processing activities that present high risk to individuals.
A French-language version of this Privacy Policy is available upon request to privacy@wardorx.com and will be published at /politique-confidentialite prior to any Quebec-directed marketing.
15. Commercial Electronic Messages (CASL)
Canada's Anti-Spam Legislation requires express or implied consent before sending commercial electronic messages (CEMs). Our practice:
- -Express consent. When you subscribe to a newsletter, request a resource, or opt into marketing, we record the date, time, source URL, and IP address of your consent. This record is retained for the duration of the relationship plus 3 years (CASL evidence requirement).
- -Implied consent. Where we have an existing business relationship (active client or inquiry within the past 24 months), we may send CEMs relevant to that relationship.
- -Cold outreach. Where we send CEMs to prospects without an existing relationship, we rely on CASL §7(1) existing-business-relationship exceptions, published-contact-information exceptions (where the address is published without a "no spam" statement and the message is relevant to the recipient's business), or express consent obtained through the audit widget. We do not purchase or rent email lists.
- -Identification. Every CEM identifies WARDORX as the sender and includes a valid mailing address (1015 4 St SW, Suite 220, Calgary, AB T2R 1J4) and a working unsubscribe mechanism.
- -Unsubscribe. Every CEM includes a one-click unsubscribe link that processes requests within 10 business days (we aim for 24 hours). We do not charge for unsubscribe processing.
- -No hidden senders. We do not use deceptive subject lines, false headers, or harvested email lists. We do not use open relays or proxy servers to send CEMs.
- -Compliance officer. Dane Vasquez is responsible for CASL compliance. Questions about a specific message can be sent to privacy@wardorx.com.
To withdraw consent at any time, use the unsubscribe link in any email or contact privacy@wardorx.com. Withdrawal does not affect messages already sent.
16. Cold Outreach & Prospect Data
WARDORX conducts outbound outreach to prospective clients via email, LinkedIn, and other channels. The data we collect and how we handle it:
- -Source of contact data. We collect prospect contact information from publicly available sources (LinkedIn, company websites, professional directories) or from referral partners. We do not purchase lists from data brokers.
- -What we collect. Name, business email, business name, role, and any publicly available context (e.g., a recent company announcement). We do not collect personal email addresses, home addresses, or phone numbers from public sources.
- -Legal basis. Under PIPEDA and CASL, we rely on legitimate business interest for B2B outreach where the message is relevant to the recipient's business role, and on CASL §7 existing-business-relationship exceptions where applicable.
- -Retention. Prospect data for unresponsive contacts is retained for 6 months from the last contact attempt, then deleted. Prospects who respond are treated as inquiry contacts under Section 8 retention rules.
- -Opt-out. Every outreach message includes a clear opt-out mechanism. Opt-outs are honored within 10 business days and recorded in a suppression list retained for 3 years (CASL evidence requirement).
- -No automated decision-making. Outreach targeting is based on human review of public information. We do not use AI to make autonomous decisions about who to contact or what to say.
17. Children's Privacy
The Site is intended for business use and is not directed to individuals under 16 (under 14 in Quebec, under 13 in the US under COPPA). We do not knowingly collect personal information from children. If you believe a child has provided personal information through the audit widget, contact form, or booking form, contact privacy@wardorx.com and we will delete it within 10 business days.
18. AI Tools & Automated Processing
WARDORX uses AI-assisted tools for specific internal purposes. We do not use AI for autonomous decisions that produce legal or similarly significant effects on individuals.
- -Site audit widget. The audit widget returns a deterministic, rule-based score derived from the URL submitted. It does not use machine learning. The "findings" displayed are template strings, not personalized assessments.
- -Analytics aggregation. Microsoft Clarity may use ML-based aggregation to identify usability patterns. Sessions are anonymized and text-masked before processing.
- -Content drafting. We may use AI writing assistants to draft internal documents, blog posts, or case studies. All AI-drafted content is reviewed by a human before publication. We do not publish AI-generated content without human review.
- -No facial recognition. We do not use facial recognition, emotion detection, or other biometric AI on any visitor data.
- -No profiling with legal effects. We do not profile visitors in a way that produces legal or similarly significant effects (e.g., credit scoring, insurance eligibility, employment decisions).
19. Breach Notification
If we become aware of a breach of security safeguards involving personal information that creates a real risk of significant harm to affected individuals, we will:
- 1.Contain the breach within 24 hours of confirmation and assess the scope.
- 2.Notify affected individuals directly, in writing, as soon as feasible - including the circumstances of the breach, the personal information involved, the steps we are taking to mitigate harm, and the steps individuals can take to protect themselves.
- 3.Notify the Privacy Commissioner of Canada and the Office of the Information and Privacy Commissioner of Alberta as required by PIPEDA and PIPA, generally within 72 hours of confirming the breach.
- 4.Notify the Commission d'accès à l'information du Québec if Quebec residents are affected and the breach presents a risk of serious injury under Law 25.
- 5.Notify California Attorney General if California residents are affected and the breach meets the disclosure threshold under California Civil Code §1798.82.
- 6.Document the breach, our response, and the corrective actions taken. Records are retained for 7 years.
"Real risk of significant harm" is assessed using the standard established by the Office of the Privacy Commissioner of Canada, considering the sensitivity of the information, the probability of misuse, and the potential harm to affected individuals.
20. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Last Updated" date at the top of this page and the version number, and - where the change affects how we process personal information already collected - by providing notice (e.g., email or prominent banner) before the change takes effect.
Continued use of the Site after the effective date of a material change constitutes acceptance of the updated policy. We retain previous versions of this policy in our internal records for 7 years.
21. Contact & Complaints
If you have a question, concern, or complaint about this Privacy Policy or how we handle your personal information, contact our Privacy Officer first. We will acknowledge your message within 5 business days and respond substantively within 30 days.
Privacy Officer: Dane Vasquez Email: privacy@wardorx.com Phone: +1 (403) 460-2211 Mailing address: WARDORX, 1015 4 St SW, Suite 220, Calgary, Alberta, T2R 1J4, Canada
If you are not satisfied with our response, you may complain to:
- -Office of the Privacy Commissioner of Canada - priv.gc.ca | 30 Victoria Street, Gatineau, Quebec K1A 1H3
- -Office of the Information and Privacy Commissioner of Alberta - oipc.ab.ca | 410, 9925 - 109 Street NW, Edmonton, Alberta T5K 2J8
- -Commission d'accès à l'information du Québec - cai.gouv.qc.ca | 800, place D'Youville, Québec, Québec G1R 3P4
- -California Attorney General - oag.ca.gov/privacy/ccpa | 1300 I Street, Sacramento, CA 95814
This Privacy Policy is published under the authority of WARDORX and is effective as of the Last Updated date above. Version 1.0. Reviewed at least annually and upon any material change to our data practices.