The short version: this website sets no cookies and embeds no advertising or social trackers. We count visits with Umami, a cookieless analytics tool we run ourselves, so your visit is never shared with an analytics company. Fonts and images are served from our own domain. The only personal information involved is what our hosting provider records in its server logs, the anonymous visit statistics described below, and anything you choose to tell us through our contact form, by booking a call, or by email.
Who we are
Decoy Privacy Consultants Inc., a company incorporated in Canada and operating as DP Frame.works, is responsible for the personal information described in this notice.
Our Privacy Officer — the individual accountable for our compliance under PIPEDA — can be reached at contact@decoyprivacy.com.
What this site collects
No cookies. We do not set cookies or store anything in your browser's local or session storage, and we run no advertising or session-recording tools.
Cookieless visit statistics. We use Umami, an open-source analytics tool that we host ourselves, to count visits and see which pages are useful. When a page loads, it records the page address, the referring site, your browser, operating system, device type, screen size, language, and the country your connection comes from. Your IP address is used only to work out the country and is not stored. Umami does not set cookies or build a profile of you, and does not track you across other websites. We see the results only as aggregate counts. If your browser sends a Do Not Track signal, Umami records nothing about your visit.
No third-party requests. Web fonts, images, and stylesheets are all served from this website's own domain (decoyprivacy.com or dpframe.works). The only other address your browser contacts is our own Umami server, also hosted on Railway. No font service, ad network, analytics company, or social platform learns that you visited. If you choose to book a call, the “Book a call” link takes you to our Microsoft Bookings page, which is hosted by Microsoft on its own domain; Microsoft's own cookie practices apply while you are on that page.
Server logs. Our hosting provider records standard technical information when a page is served — IP address, timestamp, the page requested, browser user agent, and response status. This is used only to operate and secure the site.
If you contact us
Contact form. If you use the form on our home page, we collect your name, email address, organization (if you give it), the topic you choose, and your message. Our web server checks the submission and passes it straight to our Microsoft 365 mailbox as an email; it is not saved on the web server. To block automated spam, the server keeps your IP address in memory for up to an hour to limit how many messages can be sent from one address, then discards it. We do not send automatic confirmation emails.
Booking a call. If you book a call, Microsoft Bookings collects your name, email address, the time you choose, and any notes you add, and sends you a confirmation and calendar invitation on our behalf.
Email. If you email us directly, we process your address, your name if you give it, and whatever you write.
In each case we use your information to reply and to take forward any engagement you're asking about.
We keep business correspondence for as long as the relationship is live. Where correspondence supports our accounting and tax records, we keep it for six years after the end of the year it relates to, in line with Canada Revenue Agency record-keeping requirements; other correspondence is deleted when no longer needed. We do not add you to a mailing list or use your address for marketing unless you separately ask us to.
Why we may process it
As a Canadian company, our handling of personal information in the course of commercial activity is governed by the Personal Information Protection and Electronic Documents Act (PIPEDA) and its ten fair information principles.
We identify our purposes up front, and they are the narrow ones set out above: keeping this website available and secure, understanding in aggregate how the site is used so we can improve it, and replying to people who write to us. Where you contact us, by form, booking or email, your consent to us using your details to reply is implied by the act of getting in touch. We do not use your information for any further purpose without asking you first, and you can withdraw consent at any time by telling us — though doing so may mean we can no longer correspond with you.
Server logs are generated automatically by our hosting provider as a necessary part of delivering the site, and are used only to operate and secure it. Visit statistics involve no cookies or identifiers and only non-sensitive technical information, and are used only in aggregate to improve the site.
Where the UK GDPR or EU GDPR also apply — because you are in the UK or EEA when you visit or write to us — we additionally rely on:
- Legitimate interests (Article 6(1)(f)) for server logging and contact-form spam protection, to keep the site available and secure; for cookieless visit statistics, to understand how the site is used; and for responding to unsolicited enquiries.
- Steps prior to entering a contract (Article 6(1)(b)) where your enquiry concerns engaging us.
- Legal obligation (Article 6(1)(c)) for retaining correspondence that supports our accounting and tax records.
Who we share it with
We do not sell personal information or share it for advertising. The only routine recipients are the service providers that let us operate:
- Our hosting provider, Railway, which serves this website, runs the server that passes contact-form messages to our mailbox, holds the server logs described above, and hosts our Umami analytics server and its visit statistics.
- Our email and scheduling provider, Microsoft 365 (Exchange Online and Microsoft Bookings), which handles correspondence, receives contact-form messages, and runs our call-booking page.
Both act as service providers under contract, and are permitted to use the information only to provide the service to us.
Processing outside Canada. These providers store and process information primarily in the United States. While it is there it is subject to United States law, and may be accessible to that country's courts and law-enforcement or national-security authorities. We use contractual measures to require a level of protection comparable to that required under PIPEDA. For information covered by the UK or EU GDPR, both providers' data-processing terms incorporate standard contractual clauses or equivalent recognized safeguards.
Note: this notice covers the public website only. The APEX Governance Platform is a separate product with its own privacy terms, provided to customers under their own agreement.
How we protect it
All traffic to this site is encrypted in transit over HTTPS, including contact-form submissions, which are passed to our mailbox without being stored on the web server. Correspondence lives in our business email tenant, protected by multi-factor authentication and accessible only to the people who need it to respond to you. We hold the least information we can — most visits leave nothing behind but a server log line, which our hosting provider retains on a rolling basis, and an anonymous entry in our visit statistics.
Your rights
Under PIPEDA, you can ask us to confirm whether we hold personal information about you and to give you access to it, ask us to correct it if it's inaccurate or incomplete, withdraw your consent to our using it, and challenge our compliance with this notice. We'll respond to an access request within 30 days.
If you are in the UK or EEA, the GDPR gives you a broader set: in addition to access and rectification, you may request erasure or portability, and may restrict or object to our processing. Where we rely on legitimate interests, you may object at any time.
To exercise any of these, email contact@decoyprivacy.com.
If you're unhappy with how we've handled your information you can complain to the Office of the Privacy Commissioner of Canada. Visitors in the UK or EEA may instead complain to their own national supervisory authority.
Changes
If we change how this site handles personal information — for example if we change what the contact form collects or how we measure visits — we'll update this notice and change the date at the top before the change takes effect.