We're serious about protecting your data - here's exactly how we do it
Look, we get it - nobody actually enjoys reading privacy policies. But since we're a tech law firm that helps clients navigate data protection issues all day long, we'd be pretty hypocritical if we didn't walk the talk ourselves.
This policy isn't some copy-paste job from a template site. It's written by lawyers who actually care about privacy (and yeah, we practice what we preach). We've tried to make it readable without all the usual legal gobbledygook.
Bottom line? We collect the bare minimum info needed to provide legal services, keep it locked down tight, and never sell or share it without your explicit okay. That's the promise.
We're not in the business of hoarding data. Here's what we typically gather:
We're not doing anything sneaky with your info. Here's the real deal on how we use what we collect:
Obviously the main thing - we need your info to actually represent you, draft documents, give advice, and handle your legal matters properly.
Responding to inquiries, sending updates about your case, scheduling consultations - basically staying in touch about legal stuff.
Creating invoices, processing payments, maintaining financial records as required by law society regulations.
Meeting our professional obligations under Law Society rules, anti-money laundering requirements, and other legal stuff we can't avoid.
We might also use aggregated, anonymized data (where you can't be identified) to improve our services or write blog posts about tech law trends. But that's stripped of anything that could identify you personally.
Alright, this is where our cybersecurity expertise actually shows up. We don't mess around with security:
Your information is stored on Canadian servers with enterprise-grade security. We use encrypted cloud storage services that meet SOC 2 Type II compliance standards. Physical files (when we absolutely need them) are kept in locked cabinets in our secured office.
We're required by Law Society rules to keep client files for at least 10 years after a matter closes. After that retention period, we securely destroy records unless there's a good reason to keep them longer (like ongoing litigation).
Marketing info and website analytics? We typically purge that after 3 years unless you're an active client.
Under PIPEDA and other privacy laws, you've got real rights when it comes to your personal info. Here's what you can do:
| Your Right | What It Means |
|---|---|
| Access | Request a copy of the personal information we hold about you |
| Correction | Ask us to fix any inaccurate or incomplete data |
| Deletion | Request deletion of your data (subject to legal retention requirements) |
| Portability | Get your data in a machine-readable format to take elsewhere |
| Objection | Object to certain types of processing (like marketing) |
| Withdraw Consent | Pull back permission you've given (where consent is the legal basis) |
Just shoot us an email at counsel@ciphernovae.info with the subject line "Privacy Rights Request" and tell us what you're looking for. We'll respond within 30 days (usually faster).
We might need to verify your identity before processing certain requests - nothing personal, just making sure we don't accidentally hand someone's data to the wrong person.
Not happy with our response? You can file a complaint with the Office of the Privacy Commissioner of Canada. We'd prefer to work it out directly, but that's your right.
Yeah, we use cookies. Not the chocolate chip kind (though there's usually some of those in our office kitchen).
The ones that make the site actually work - like remembering you're logged into our client portal. These aren't optional.
Help us understand which pages are popular, where people are coming from, that kind of thing. We use privacy-focused analytics that don't track individuals.
Remember your settings and choices so you don't have to re-enter them every visit.
Most browsers let you refuse cookies or delete them. Just know that blocking essential ones might break some site functionality. Your browser's help section will show you how to manage cookie settings.
We don't use advertising cookies or sell your browsing data to third parties. That's not our business model.
We respect DNT browser settings where technically feasible. Though honestly, the DNT standard is kind of a mess industry-wide.
We're picky about who we work with, but yeah, some info gets shared with trusted third parties. Here's the honest rundown:
All these providers are bound by contracts that require them to protect your data and only use it for the specific services they provide to us.
Sometimes the law makes us share info:
For anything else - like sharing case details with opposing counsel, bringing in expert witnesses, or sending documents to other professionals involved in your matter - we'll get your explicit consent first.
This deserves its own section because it's kinda the cornerstone of what we do.
When you're our client, solicitor-client privilege protects our communications. This is a legal principle that's been around for centuries and it's taken seriously by courts. It means:
Privilege isn't absolute. We may be required to disclose if:
These situations are extremely rare in practice, but we'd be remiss not to mention them.
Privacy law keeps evolving (trust us, we track these changes for our clients), so we might need to update this policy from time to time.
The current version is always available at this URL, and we keep archived versions available on request if you want to see what changed.
We'd recommend checking back occasionally if you're a regular client, but we promise not to make changes just for the sake of it.
Got questions about this policy or how we handle your data? Don't hesitate to reach out. Seriously - we'd rather answer questions upfront than deal with concerns later.
CipherNovae Legal Solutions
Suite 1200, 181 Bay Street
Toronto, ON M5J 2T3
Canada
Phone: (416) 555-0847
Email: counsel@ciphernovae.info
We typically respond within 1-2 business days
For formal privacy inquiries or complaints, you can contact our designated Privacy Officer at the above address/email with "ATTN: Privacy Officer" in the subject line.
PIPEDA Compliant
LSO Regulated
Data Protection Standards
Privacy Certified