Privacy Policy
Privacy Policy
June 29, 2026
Privacy Policy
Effective Date: June 2026
Last Reviewed: June 2026
Introduction
iTOTEM Analytics ("iTOTEM", "we", "our", or "us") is a data intelligence, analytics, and technology company serving organizations across Canada and the United States.
As an organization operating in Canada and the United States, iTOTEM is committed to protecting personal information in accordance with applicable privacy laws and regulations. For Canadian operations, this includes the British Columbia Personal Information Protection Act (PIPA). iTOTEM also supports the First Nations Principles of OCAP® (Ownership, Control, Access, and Possession) and broader Indigenous data governance practices where applicable. For United States operations, iTOTEM's privacy practices are informed by applicable federal and state privacy laws, including the Texas Data Privacy and Security Act (TDPSA), where applicable.
We understand that privacy is important to our clients, partners, website visitors, and stakeholders. We are committed to protecting personal information and maintaining appropriate safeguards to ensure its confidentiality, integrity, and availability.
This Privacy Policy describes how iTOTEM collects, uses, discloses, stores, retains, and protects personal information obtained through our website, services, communications, and business operations. It also explains the rights available to individuals regarding their personal information.
We recognize that privacy is an ongoing responsibility. This Privacy Policy may be updated periodically to reflect changes in our business practices, technology, legal requirements, or operational needs.
Data Protection Officer
iTOTEM has appointed a Data Protection Officer responsible for overseeing privacy-related inquiries, requests, and compliance activities.
For Canadian privacy matters:
Paul Morgan, L.L.B.
Data Protection Officer
For U.S. privacy matters:
William ("Zac") Duffy
Data Protection Officer
Individuals wishing to exercise privacy rights or submit privacy-related questions may contact the Data Protection Officer using the information above.
How We Collect and Use Personal Information
iTOTEM may collect personal information from website visitors, clients, prospective clients, partners, vendors, contractors, and other stakeholders.
The personal information collected may include:
· Name
· Employer or organization name
· Job title
· Business address
· Business email address
· Business telephone number
· Communications submitted through email, meetings, demonstrations, or inquiries
· Information provided during project discussions, service requests, or consultations
We may use this information to:
· Respond to inquiries and requests
· Deliver products and services
· Schedule demonstrations and meetings
· Establish and maintain business relationships
· Provide customer support
· Fulfill contractual obligations
· Improve services and business operations
· Meet legal, regulatory, and compliance requirements
· Communicate with clients, partners, and prospective customers
iTOTEM does not sell personal information.
From time to time, iTOTEM may receive business contact information from publicly available sources, professional networks, referrals, or other legitimate business sources for the purpose of establishing or maintaining professional relationships.
Use of the iTOTEM Website
Like most websites, the iTOTEM website automatically collects certain technical information when visitors access or interact with the site.
This information may include:
· Internet Protocol (IP) address
· Browser type and version
· Device type
· Operating system
· Pages visited
· Date and time of visits
· Referral sources
· Session information
· Website navigation activity
This information is used to:
· Maintain website functionality
· Improve website performance and user experience
· Understand visitor engagement
· Diagnose technical issues
· Analyze website trends and usage patterns
· Support security and operational monitoring
iTOTEM has a legitimate business interest in understanding how visitors use its website in order to improve services, content, and user experience.
Cookies and Tracking Technologies
The iTOTEM website may use cookies, analytics technologies, and similar tracking mechanisms to improve website functionality and understand visitor interactions.
These technologies may collect information regarding:
· Website usage patterns
· Time spent on pages
· Browser and device characteristics
· Navigation behavior
· General geographic information derived from IP addresses
Analytics services may be provided through website hosting platforms or approved third-party service providers.
Visitors may manage cookie preferences through browser settings; however, certain website features may not function properly if cookies are disabled.
Use of iTOTEM Services
In the course of delivering services, iTOTEM may process information provided by clients, partners, or authorized users.
Such information is processed solely for authorized business purposes and in accordance with contractual obligations, applicable laws, client requirements, and company policies.
Access to information is limited to authorized personnel with a legitimate business need and is managed in accordance with company security and access control requirements.
Sharing Information with Third Parties
iTOTEM does not sell personal information.
Personal information may be shared with trusted third-party service providers that support authorized business activities, including:
· Website hosting providers
· Cloud service providers
· Analytics providers
· Technology vendors
· Security service providers
· Professional advisors
· Contractors supporting authorized business operations
Third-party service providers are expected to protect information in accordance with contractual, legal, and security requirements.
Information may also be disclosed when required by law, court order, regulatory authority, contractual obligations, or to protect the rights, property, security, or operations of iTOTEM, its clients, or other stakeholders.
Cross-Border Processing and International Transfers
iTOTEM operates across Canada and the United States and may utilize service providers located in multiple jurisdictions.
As a result, personal information may be processed, stored, transmitted, or accessed in Canada, the United States, or other jurisdictions where authorized service providers operate.
Where cross-border processing occurs, iTOTEM takes reasonable measures to ensure appropriate safeguards are in place to protect personal information and maintain compliance with applicable privacy requirements.
Data Subject Rights
Subject to applicable privacy laws, individuals may have the right to:
· Be informed regarding how their personal information is collected and used
· Request access to personal information
· Request correction of inaccurate information
· Request deletion of personal information where permitted by law
· Withdraw consent where consent is the basis for processing
· Request restriction of processing where applicable
· Object to certain processing activities where permitted by law
· Request information regarding how personal information is used
· Submit privacy-related questions, concerns, or complaints
Additional rights may apply depending on the individual's jurisdiction, including rights provided under applicable Canadian privacy legislation and certain United States federal or state privacy laws.
Requests may be submitted to the Data Protection Officer using the contact information provided in this Privacy Policy.
Security of Information
iTOTEM maintains administrative, technical, and physical safeguards designed to protect personal information against unauthorized access, disclosure, alteration, misuse, loss, or destruction.
Security measures may include:
· Access controls
· Least privilege principles
· Authentication controls
· Encryption technologies
· Security monitoring
· Incident response procedures
· Vendor security reviews
· Employee security awareness training
While no system can guarantee absolute security, iTOTEM takes reasonable measures to protect information under its control.
Data Storage and Retention
Personal information is retained only for as long as necessary to fulfill legitimate business purposes, contractual obligations, legal requirements, regulatory requirements, or authorized operational purposes.
When information is no longer required, it is securely deleted, anonymized, archived, or otherwise disposed of in accordance with company policies and applicable requirements.
Individuals may request access to, correction of, or deletion of personal information, subject to applicable legal, contractual, regulatory, and operational requirements.
Data Deletion Request Process
iTOTEM has established a formal process for handling client data deletion requests to ensure that only authorized individuals can request the removal of client data and that all deletion activities are properly documented.
Clients who wish to have their data deleted must complete a Data Deletion Request Form and submit it via email to their designated iTOTEM point of contact. To prevent unauthorized deletion requests, requests are only accepted when submitted from the email address of the Client Project Manager or another authorized client representative previously registered with iTOTEM.
Upon receipt of the request, iTOTEM verifies that the request originated from an authorized contact and reviews the requested scope of deletion. The request is documented and tracked through completion.
Authorized personnel identify the applicable data repositories and securely delete the requested data from active systems in accordance with internal data management procedures. Where data exists in backups, deletion is performed in accordance with the organization's backup retention schedule, and such data is not restored except when required for business continuity or disaster recovery purposes.
All deletion requests are logged, including the requester, date received, verification status, data affected, personnel performing the deletion, and completion date. Once the deletion process has been completed, written confirmation is provided to the client.
This process ensures that data deletion requests are properly authorized, reviewed, executed, and documented, supporting the organization's privacy, security, and compliance obligations.
Refer to appendix for data deletion form.
Indigenous Data Governance
As an Indigenous-affiliated organization, iTOTEM recognizes the importance of responsible data governance and Indigenous data sovereignty.
Where applicable, iTOTEM supports and seeks alignment with the First Nations Principles of OCAP® (Ownership, Control, Access, and Possession) and broader Indigenous data governance practices.
We recognize the importance of respecting community rights, self-determination, transparency, and responsible stewardship of Indigenous information.
Children's Data
iTOTEM's website, products, and services are intended for business and professional use.
iTOTEM does not knowingly collect personal information from children. If we become aware that personal information has been collected from a child contrary to applicable law, we will take reasonable steps to delete such information.
Changes to This Privacy Policy
This Privacy Policy will be reviewed at least annually and updated as necessary to reflect changes in business practices, technology, legal requirements, or operational needs.
The most current version will be published on the iTOTEM website and will include the effective date and last reviewed date.
Questions, Concerns, or Complaints
Questions, concerns, complaints, requests regarding personal information, or requests to exercise privacy rights may be directed to the appropriate Data Protection Officer mentioned at the beginning of this document.
If a concern cannot be resolved directly with iTOTEM, individuals may also contact the applicable privacy regulator or supervisory authority in their jurisdiction.