Privacy Policy
Last Updated: August 14, 2026
This Privacy Policy explains how Enom Technologies Inc. ("Impact OS", "we", "us", or "our") collects, uses, and protects information in connection with the Impact OS website and platform (the "Service"). We are committed to complying with the Personal Information Protection and Electronic Documents Act (PIPEDA), applicable provincial privacy legislation, and other relevant privacy standards.
1. Information We Collect
We collect information in a few ways:
- Contact & Account Information — name, organization name, email address, and messages submitted through our demo request or newsletter forms.
- Customer Data — information your organization enters into the Service (client, case, service, and volunteer records); your organization controls this data and we process it strictly on your organization's behalf to provide the Service.
- Usage & Technical Information — pages visited, browser type, IP address, and general device information, collected automatically when you use our website or the Service.
2. Why We Collect It & Consent
We collect and use personal information for these purposes, relying on your implied or explicit consent (which you may withdraw at any time, subject to legal or contractual restrictions):
- To provide, operate, and support the Service, including responding to demo and support requests;
- To send account, billing, and product updates, and — where you have explicitly opted in — newsletter content you can unsubscribe from at any time;
- To maintain the security and integrity of the Service, including detecting, preventing, and investigating fraud, security breaches, or abuse;
- To improve our website and product based on aggregate usage patterns; and
- To comply with applicable legal and regulatory obligations.
3. Sub-processors and Data Residency
To operate the Service efficiently, we rely on a select group of vetted third-party sub-processors:
- Supabase — database, authentication, and file storage; infrastructure regions selected with Canadian organizations in mind.
- Stripe — payment processing and billing.
- Resend — transactional email delivery (e.g. account and notification emails).
Each sub-processor is contractually bound to protect information consistent with this Policy.
Cross-Border Transfers: some of our sub-processors and their servers may store or process personal data outside of Canada (such as in the United States). When data is processed outside of Canada, it is subject to the local laws of that jurisdiction and may be accessible to law enforcement or regulatory authorities under those laws. We will update this policy if our sub-processors change materially. Current hosting and sub-processor infrastructure details are also available upon request.
4. Data Retention
Account, billing, and communication data are retained for as long as necessary to provide the Service and to satisfy legal, accounting, tax, or reporting requirements. Customer Data is retained for the duration of your organization's active subscription and for a limited grace period afterward to allow for data export, after which it is securely deleted from our production systems in accordance with our internal retention practices.
5. Security Safeguards
We implement robust technical and organizational measures to protect personal information, including:
- Encryption in transit (TLS) and encryption at rest;
- Role-based access controls (RBAC) and row-level tenant isolation between organizations; and
- Comprehensive audit trails on Customer Data.
6. Privacy Breaches
In the event of a security incident resulting in a breach of security safeguards involving personal information under our control, we will evaluate whether the breach creates a real risk of significant harm (RRSH). If this threshold is met, we will notify affected organizations, impacted individuals, and the Office of the Privacy Commissioner of Canada (OPC) without undue delay, as required by law.
7. Your Rights Under PIPEDA
Depending on your relationship with us, you may have the right to:
- Access the personal information we hold about you;
- Correct inaccuracies or request updates;
- Request deletion of your personal information;
- Withdraw consent to certain collections, uses, or disclosures.
How to Exercise Your Rights: to submit an access or correction request, contact our Privacy Officer using the details in Section 11. We will respond to formal requests within 30 days of receipt at little or no cost to you. If you are not satisfied with our response, you may contact the Office of the Privacy Commissioner of Canada.
8. Cookies and Tracking Technologies
Our website uses cookies and similar technologies for essential site functionality and security. We may also use analytics cookies to understand how visitors interact with our site in aggregate. You can control, manage, or disable cookies at any time through your browser settings.
9. Children's Privacy
The Service is intended strictly for use by business organizations, enterprises, and their authorized staff — not by children. We do not knowingly collect personal information directly from children under the age of 13.
10. Changes to This Policy
We may update this Privacy Policy periodically to reflect changes in our practices, technology, or legal requirements. If we make material changes, we will provide reasonable advance notice (such as via email or an in-product notification) before the changes become effective.
11. Contact Us & Accountability
Enom Technologies Inc. is accountable for the personal information under its control. Questions, concerns, or formal requests regarding this Policy or your personal information should be directed to our Privacy Officer:
- Attention — Privacy Officer, Enom Technologies Inc.
- Email — privacy@enomtechnologies.ca
- Mailing Address — 103-11440 Ellerslie Rd SW, Edmonton, AB, T6W 3WT