Policies and Documents

Privacy and Data Protection

Definitions

  • Client means any person or entity that engages Mark Pitblado Consulting to provide Services.
  • Personal Identifiable Data means any data that can be used to identify a person, including but not limited to: names, emails, addresses, or Personal Health Numbers.
  • Services means any services provided by Mark Pitblado Consulting to a Client.
  • Agreement means any contract or agreement between Mark Pitblado Consulting and a Client that outlines the Services to be provided, the terms of payment, and any other terms and conditions agreed to by both parties.


Mark Pitblado Consulting (“I”, “my”, "me") operates https://www.consulting.markpitblado.me, https://consulting.markpitblado.me, and any other related Mark Pitblado Consulting site, and Mark Pitblado Consulting services (hereinafter referred to as “Services”).

This Privacy Policy governs your visit to https://www.consulting.markpitblado.me and explains how I collect, safeguard and disclose information that results from your use of my Services.

Nothing in this Privacy Policy shall take precedence over any other agreement between Mark Pitblado Consulting and a Client. When there is a conflict between this Privacy Policy and any other agreement between Mark Pitblado Consulting and a Client, the terms of agreement between Mark Pitblado Consulting and the Client shall take precedence.

Information Collection and Use

  • Web Analytics. I host Plausible Analytics on a server rented from DigitalOcean, based in Toronto, Canada. For a complete overview of what is collected by the Plausible Analytics software, visit their data policy here.
  • Email The email address used by Mark Pitblado Consulting is run through a domain registered to me, and hosted through Proton Mail, based in Switzerland. Proton Mail provides zero-access encryption for email at rest. Email is not to be used for the transmission of Personal Identifiable Data protected by any ethics protocol, legislation, or organizational policy. Any emails that contain such information will be deleted on arrival, and the sender of the information informed of this policy. If the sending of such information constitutes a privacy breach by an agent acting on behalf of the Client under the Agreement between the Client and Mark Pitblado Consulting, I will inform the appropriate representative of the Client of the breach immediately, and undertake any other necessary actions as outlined in the Agreement.
  • Internal Business Documents Internal business documents for the operation of Mark Pitblado Consulting are stored through Sync.com, a cloud storage provider that offers end-to-end encrypted file storage within Canada. The SOC compliance report for Sync.com can be viewed here. Sync.com is not used to store any Personal Identifiable Data of the Client.
  • Invoicing and Time Keeping Time keeping and invoicing is done through an instance of Kimai, hosted on a DigitalOcean server in Toronto, Canada. Kimai is an open source time tracking software. The public business contact information of the Client, the hourly rate for Services, and brief descriptions of billable activities shall be stored on this server for the purposes of generating invoices for the Client.
  • Credentials Required for Access to Client Resources Unless otherwise agreed to, any credentials used by Mark Pitblado Consulting will be stored in a password manager. The details of this password management service will be outlined to the Client as part of the Agreement, including the security protocols in place to safeguard access. The Client may request that Mark Pitblado Consulting use a password manager of their choosing or to forgo use of a password manager entirely, and Mark Pitblado Consulting will make every effort to accommodate this request.

Disclosure of Privacy Incidents and Breaches

In the event of a privacy incident or breach of a service used by Mark Pitblado Consulting, Mark Pitblado Consulting will communicate the incident to the Client as soon as possible, and will take any other necessary steps as outlined in the Agreement between Mark Pitblado Consulting and the Client. The services outlined above are used for internal, business related purposes for Mark Pitblado Consulting, and are not used to store or process any Personal Identifiable Data of the Client.