Legal
Privacy Policy
Last updated: August 4, 2026
1. Scope and Who We Are
This Privacy Policy explains how KONCYBER Inc. (“KONCYBER,” “we,” “us,” or “our”), an Ontario, Canada-based cybersecurity advisory, incident response, and education firm, collects, uses, discloses, and protects personal information. It applies to information we collect through koncyber.com, through direct engagements with clients and prospective clients, and through related business communications (email, phone, in-person, and events).
This policy is written to reflect the principles of Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable Ontario law. If KONCYBER engages clients or handles personal information subject to other privacy regimes (for example, the EU/UK GDPR for a cross-border engagement), we will apply the additional safeguards those laws require for that specific engagement, but PIPEDA is the default framework governing this website and our general business.
2. Consent
By using this website, submitting a form, or engaging KONCYBER for services, you consent to the collection, use, and disclosure of your personal information as described in this policy. Where we seek personal information for a new or unrelated purpose, we will ask for your consent again at that time. You may withdraw consent at any time, subject to legal or contractual restrictions and reasonable notice — see Section 14. Withdrawing consent may limit or prevent our ability to provide certain services, particularly ongoing advisory or incident response engagements.
3. Information We Collect
We collect different categories of information depending on how you interact with us:
Website and contact information
- Name, business email, phone number, organization, and role, when you submit the contact form or a consultation request.
- Newsletter subscriber email address and, optionally, first name.
- General, non-sensitive information you choose to include in a message (e.g. a summary of your inquiry).
- Basic website usage data (see Section 11).
Engagement and services information
- Information you or your organization provide to enable an advisory, exercise, or training engagement (e.g. organizational context, risk priorities, participant lists).
- For incident response and investigative engagements specifically: technical records, timelines, device or account activity, and other materials relevant to understanding and responding to a cyber incident. This category can include highly sensitive information and is handled under the additional safeguards described in Section 8.
Information we do not want you to send us
See Section 15 for categories of information you should never submit through a standard web form.
4. How We Use Your Information
- To respond to inquiries and schedule consultations.
- To deliver the specific service you've engaged us for — advisory, incident response, exercises, training, or private-client work.
- To send newsletter content, only to subscribers who opted in, and only until you unsubscribe.
- To maintain the security, integrity, and proper functioning of our website and systems.
- To meet legal, regulatory, insurance, or professional obligations.
- To improve our services, based on aggregated, de-identified information where possible.
We do not sell personal information, and we do not use engagement or investigative data for marketing purposes.
5. The Privacy Principles We Follow
Our practices are organized around the ten principles that underpin PIPEDA and are widely treated as the Canadian standard for handling personal information:
- Accountability — we are responsible for personal information under our control and have designated a privacy contact (Section 19).
- Identifying purposes — we identify why we're collecting information before or at the time of collection.
- Consent — we obtain meaningful consent for collection, use, and disclosure, except where law permits otherwise.
- Limiting collection — we collect only what's necessary for the identified purpose.
- Limiting use, disclosure, and retention — we use and disclose information only for the purposes collected (or a compatible purpose), and retain it only as long as necessary.
- Accuracy — we aim to keep personal information as accurate, complete, and current as necessary.
- Safeguards — we protect information with security measures appropriate to its sensitivity (Section 13).
- Openness — we make our policies and practices about information handling readily available, as in this document.
- Individual access — you may request access to, and correction of, your personal information (Section 14).
- Challenging compliance — you may challenge our compliance with these principles by contacting us or the Office of the Privacy Commissioner of Canada.
6. When We Disclose Information Without Consent
Consistent with PIPEDA's permitted exceptions, we may disclose personal information without consent when:
- Required or authorized by law, regulation, court order, or lawful request from a public authority or law-enforcement body.
- Necessary to investigate a breach of an agreement, or an actual or suspected offence.
- Necessary to respond to an emergency that threatens life, health, or safety.
- The information is publicly available, as defined by applicable regulations.
- Necessary to establish, exercise, or defend a legal claim.
7. Our Role: When We Control Data vs. When We Process It for a Client
For general business and website interactions, KONCYBER is the “organization” responsible for your personal information under PIPEDA, and this policy governs directly.
In some engagements — particularly incident response and investigative work — KONCYBER handles information strictly on a client's instructions and on their behalf (for example, reviewing a client's own user-activity logs or device data during an investigation). In that context, the client organization is the party responsible for that information, and KONCYBER acts in a support/processor capacity under the terms of the engagement agreement. If we receive a privacy request relating to information we hold only on a client's instructions, we will direct you to that client wherever permitted by law, rather than act on the request ourselves.
8. Confidentiality in Incident Response & Investigative Engagements
KONCYBER's incident response and investigation work often involves sensitive, high-consequence information — potential evidence, financial records, or details of a security compromise. In addition to the general safeguards in this policy:
- Engagement-specific information is shared internally only with personnel directly supporting that engagement.
- We follow evidence-handling practices designed to preserve the integrity and chain of custody of materials that may later be used in legal, insurance, or law-enforcement proceedings.
- We may be unable to fully action a personal-information request (for example, deletion) where doing so would compromise an active investigation, a legal hold, or a duty of confidentiality owed to another party. Where this applies, we will explain the limitation to the extent we're able.
- KONCYBER is not a law firm, forensic laboratory, or law-enforcement agency, and this policy does not create a privileged or legally protected relationship beyond what a specific signed engagement agreement establishes.
9. Third-Party Service Providers
We use a small number of service providers to operate this website and our communications, and we only share the minimum information necessary for them to perform their function:
- Vercel Inc. — website hosting and infrastructure.
- Resend — processes contact-form submissions and newsletter delivery on our behalf.
For client engagements, we may also work with subcontractors, forensic partners, or specialist consultants under confidentiality obligations, disclosed to you as part of that specific engagement. We do not permit any service provider to use your information for their own marketing purposes.
10. Cross-Border Data Transfers
Some of our service providers (including hosting and email infrastructure) may store or process information outside of Canada, including in the United States. Where information is transferred internationally, it becomes subject to the laws of the jurisdiction in which it is held, which may differ from Canadian privacy law. We select providers that maintain appropriate security and privacy commitments, and we limit cross-border transfers to what's necessary to operate the website and deliver services.
11. Cookies and Website Analytics
This website may use cookies or similar technologies to understand basic, aggregated usage patterns (e.g. which pages are visited) and to keep the site functioning correctly. We do not use this data to build individual profiles for advertising, and we do not currently run third-party advertising trackers. If that changes, this section will be updated, and where required, we will provide a cookie-consent mechanism appropriate to your location.
12. Data Retention
We retain personal information only as long as necessary to fulfill the purposes it was collected for, plus any additional period required by law, regulation, insurance requirements, or legitimate business need (for example, engagement records that may later be relevant to a legal or insurance matter). Newsletter subscriber information is retained until you unsubscribe. Contact-form inquiries that do not lead to an engagement are retained only as long as reasonably necessary to address the inquiry. Specific retention schedules for client engagement data are set out in individual engagement agreements.
13. Security Safeguards
We apply administrative, technical, and physical safeguards appropriate to the sensitivity of the information involved, including access controls limiting engagement data to personnel who need it, encrypted transmission for website form submissions, and vetted third-party service providers. No system is completely secure, and we cannot guarantee absolute security of information transmitted to us over the internet.
14. Your Privacy Rights
Subject to limited legal exceptions, you may:
- Request access to the personal information we hold about you.
- Request correction of inaccurate or incomplete information.
- Withdraw consent to future collection, use, or disclosure (see Section 2 on the effect this may have).
- Unsubscribe from newsletter communications at any time, using the link in any email or by contacting us directly.
- Ask questions about how your information has been handled, or file a complaint (see Section 19).
We may need to verify your identity before actioning a request, and, as described in Section 8, some requests related to active investigations or client-controlled data may be limited or redirected.
15. Information We Ask You Not to Submit
Standard web forms are not a secure channel for highly sensitive material. Please do not submit passwords, full financial account numbers, government identification numbers (e.g. SIN, passport numbers), privileged legal material, or malware samples through any form on this site. If your matter involves this kind of material, wait for a secure channel to be set up as part of a confirmed engagement.
16. Fraud, Phishing, and Impersonation Alert
As a cybersecurity firm, KONCYBER is itself a plausible target for impersonation. We will never ask you, by unsolicited email or text, to send payment, credentials, or sensitive personal information. If you receive a message claiming to be from KONCYBER or Kenrick Bagnall that asks for this kind of information, treat it as suspicious and verify independently before responding — contact us directly using the details in Section 19.
17. Children's Privacy
This website and KONCYBER's services are directed at organizations, professionals, and adults, not children. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.
18. Changes to This Policy
We may update this policy from time to time to reflect changes in our practices or legal requirements. The “Last updated” date at the top of this page reflects the most recent revision. Material changes will be reflected here before they take effect.
19. Contact Us and How to Escalate a Complaint
Questions, access requests, or complaints about this policy or our handling of your personal information can be directed to our privacy contact:
Privacy Officer: Office of the Privacy Officer — KONCYBER Inc.
Email: legal@koncyber.com
If you're not satisfied with our response, you may contact the Office of the Privacy Commissioner of Canada (OPC), which oversees compliance with PIPEDA:
Office of the Privacy Commissioner of Canada
30 Victoria Street, Gatineau, Quebec K1A 1H3
Toll-free: 1-800-282-1376