Open Stack Forge ("we," "us," "our") respects your privacy. This policy explains what information we collect, how we use it, and your rights. We are based in Lower Sackville, Nova Scotia, Canada, and we operate in accordance with applicable Canadian privacy laws, including the Personal Information Protection and Electronic Documents Act (PIPEDA).
By using our website (openstackforge.ca / openstackforge.com) or engaging our migration, infrastructure, and managed services, you acknowledge the terms described herein.
1. Information We Collect
We collect only the minimum personal and technical information necessary to deliver our consulting services, evaluate your current software stack, and execute reliable infrastructure migrations.
Information you provide directly
- Contact details: Name, email address, phone number, company name, and job title when you contact us, book a call, or request a quote via our website contact forms or direct communications.
- Business information: Details regarding your current proprietary software subscriptions (e.g. Google Workspace, Microsoft 365, Dropbox, 1Password, Slack), monthly software spend, active team size, operational workflows, and migration timelines โ provided voluntarily during discovery calls or through our SaaS audit intake form.
- Account credentials: During migration projects, you may share administrative credentials or API access to existing systems (e.g., email routing, file-sharing platforms, identity providers) solely for the purpose of executing the agreed migration. We treat these credentials as highly sensitive under dedicated security protocols (see Section 5).
Information collected automatically
- Website analytics: Basic, non-identifying operational data such as pages visited, referring URLs, browser type, operating system, and approximate geographic location (region/country), collected via privacy-respecting hosting logs and telemetry.
- Cookies: We use strictly essential cookies and local storage tokens required for core website functionality (such as remembering your light/dark theme preference). We do not deploy advertising, tracking pixels, or third-party behavioral profiling cookies.
Information from third parties
If you connect or authorize a third-party tool during an active implementation project, we receive only the access scopes and data you explicitly authorize. We do not purchase, license, or enrich records from commercial data brokers.
2. How We Use Your Information
We use personal and corporate information strictly to:
- Respond to your initial inquiries, deliver custom SaaS escape assessments, and issue fixed-price proposals.
- Deliver consulting, open-source migration, cloud provisioning, and managed infrastructure services you have engaged us for.
- Schedule, coordinate, and conduct technical discovery sessions, architecture reviews, and sprint debriefs.
- Issue project milestone communications, service advisories, and invoices.
- Continuously improve website performance, documentation accuracy, and migration tooling.
- Comply with applicable legal, accounting, tax, and contractual requirements in Canada.
Zero Data Monetization Guarantee: We do not sell, rent, license, or trade your personal or business information to any third parties for marketing, advertising, or commercial exploitation.
3. Legal Basis and Consent
Where Canadian privacy law (PIPEDA) or other applicable data protection regimes require a lawful basis for processing, we rely on:
- Your Informed Consent: Manifested when you contact us, complete an intake form, request an architecture review, or engage our consulting desk.
- Performance of a Contract: Processing necessary to fulfill obligations under your signed Engagement Agreement, Statement of Work, or Managed Maintenance SLA.
- Legitimate Business Interests: Maintaining network security, preventing fraud or system abuse, and fulfilling statutory business recordkeeping obligations.
You may withdraw your consent at any time for non-essential communications by emailing info@openstackforge.ca.
4. How We Share Information
We share information solely under the following limited conditions:
- With you: Providing complete audit logs, configuration runbooks, and records of your migrated data.
- With vetted service providers: Specialized infrastructure sub-processors who assist us in operating our business (e.g. edge hosting infrastructure, secure email delivery, transactional accounting) under strict confidentiality and non-disclosure agreements that meet or exceed this policy.
- Legal compliance: When mandated by valid Canadian court order, search warrant, subpoena, or statutory legal requirement, or when necessary to protect our legal rights, property, and system integrity.
Sub-processors we may utilize include edge web hosting providers, authenticated SMTP mail relay services, and encrypted scheduling tools. A current list of third-party sub-processors is available upon written request.
5. How We Protect Client Data and Credentials
Given the critical and sensitive nature of enterprise IT migrations, sovereign cloud provisioning, and password vault transitions, we apply rigorous administrative, technical, and physical safeguards:
Enterprise Credential Handling: Credentials shared for migration are handled exclusively through client-isolated, end-to-end encrypted password management systems (such as Vaultwarden), transmitted via TLS 1.3 encrypted channels, and accessible solely by designated senior engineers assigned to your project.
- Documented, Auditable Migration Procedures: Data migrations (emails, documents, calendars, contacts, vault items) are processed using idempotent scripts with verifiable hash verification. We do not retain copies or backups of your migrated content on our local machines or intermediate servers beyond what is strictly necessary to verify complete transfer.
- Least-Privilege Role-Based Access: Access is provisioned on a strictly needed basis with MFA enforcement. Administrative credentials and SSH keys are systematically revoked the moment an engagement reaches completion or upon client request.
- Zero-Telemetry Architecture: Deployed open-source platforms (Nextcloud Hub, Vaultwarden, Fastmail, Mattermost) are configured with telemetry disabled and client-owned encryption keys.
- Incident Notification: In the unlikely event of a security breach or unauthorized access affecting client records, we will notify affected organizations without undue delay in accordance with applicable Canadian notification requirements under PIPEDA.
Please note: While no electronic transmission over the internet or cloud storage environment can guarantee 100% absolute security, we employ industry-standard enterprise safeguards proportional to the high sensitivity of the data handled.
6. Data Retention Schedules
We adhere to strict data minimization principles. We do not keep your information longer than necessary to serve business, operational, and statutory legal purposes.
| Data Category | Retention Duration | Action Upon Expiration |
|---|---|---|
| Prospect & Inquiry Records Contact form submissions, audit assessments, ROI estimates |
Up to 24 months from the date of last communication | Permanently deleted or anonymized unless converted into an active client engagement |
| Client Project & Billing Records Signed agreements, invoices, statements of work, correspondence |
Duration of engagement + up to 7 years | Securely purged in accordance with Canadian Revenue Agency (CRA) statutory accounting rules |
| System Credentials & Access Tokens Admin credentials, server keys, API tokens used for migration |
Immediate purge upon milestone sign-off | Permanently deleted unless you have enrolled in an ongoing Managed Maintenance SLA |
7. Your Privacy Rights
Under Canadian privacy laws (including PIPEDA) and comparable international standards, you have substantive rights regarding your personal information:
- Right of Access: You may request confirmation and an itemized copy of the personal information we maintain concerning you.
- Right of Rectification: You may request immediate correction of inaccurate, outdated, or incomplete records.
- Right of Deletion / Erasure: You may request the deletion of your personal data, subject to mandatory statutory tax, legal, or accounting retention obligations.
- Right to Withdraw Consent: You may revoke consent for voluntary processing activities at any time without retroactive penalty.
- Right to Lodge a Complaint: If you believe our information handling practices fail to meet statutory standards, you have the right to lodge a complaint with the Office of the Privacy Commissioner of Canada (OPC) at priv.gc.ca.
Exercising Your Rights: To submit a verified privacy request, please email our privacy desk at info@openstackforge.ca. We investigate, confirm identity, and deliver written responses to all formal requests within 30 calendar days without charge.
8. Cookies and Web Storage
Our website utilizes strictly essential browser storage and session cookies necessary to maintain site functionality, such as:
- Storing your selected user interface theme preference (light or dark mode) via
localStorage ('osf-theme'). - Protecting form submissions against automated spam bots and cross-site request forgery.
We do not load third-party ad retargeting tags, canvas fingerprinting scripts, social network tracking beacons, or cross-site tracking cookies. You may configure your web browser to reject cookies or clear local storage; please note that doing so may reset your theme preference to default.
9. Children's Privacy
Our website and professional services are exclusively intended for commercial enterprises, business owners, and corporate IT professionals. We do not knowingly solicit or collect personal information from individuals under 16 years of age. If you become aware that a minor has submitted personal information to our site, please contact us immediately for immediate investigation and removal.
10. International and Inter-Provincial Data Transfers
Open Stack Forge is based in Lower Sackville, Nova Scotia, Canada, serving clients throughout Canada and select international organizations. Your information may be processed and stored on cloud infrastructure located within Canadian provinces or other jurisdictions where our edge hosting partners operate.
When data is transferred across provincial or international borders, it remains protected under contractual safeguards and the standards defined in this policy, subject to the lawful disclosure rules of the destination jurisdiction.
11. Changes to This Policy
We review and update this Privacy Policy periodically to reflect technological enhancements, operational changes, or statutory legal developments. Whenever updates are published:
- We will post the revised policy on this page and refresh the "Effective Date" at the top of this document.
- For material modifications that materially alter how personal data of active clients is processed, we will provide advance direct notification via email.
12. Contact & Privacy Officer
For questions, data access requests, or inquiries regarding our privacy compliance practices, please reach our Privacy Officer:
Entity
Open Stack Forge
Phone
Headquarters
Lower Sackville, Nova Scotia, Canada
Statutory & Operational Notice: This Privacy Policy is provided as an operational document for Open Stack Forge. We recommend having a qualified legal professional periodically review it to ensure it continuously reflects your specific organizational practices and all obligations under applicable provincial and federal statutes.